Ethyca vs Privado AI: how they compare in 2026
Ethyca and Privado AI are both privacy engineering platforms that find personal data across a company's systems and turn it into records, assessments and enforcement for in house privacy and legal teams. Ethyca sits in the top two bands on thirteen of fifteen axes and Privado on ten of fifteen, identical on seven. Ethyca's lead is evidence about its own AI. It publishes precision and recall for its data classifier, over 95 percent against benchmarks drawn from real systems, with the test set described and three failure modes named. Its classifier reads database metadata only, never table contents, and its agreement states plainly that it gives no legal advice. Privado's lead is commercial. It publishes a rate card, from $600 per website a month, and terms that lift the liability cap for privacy breaches and require $1 million each of errors and omissions and cyber insurance. Its Wren agent reads contracts, transcripts and source code to populate assessments, and no model provider appears on its subprocessor list.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Remove the models and a data governance platform remains, which is the B band. Fides is an ontology and policy language, Janus is consent and preference management, Lethe is policy-based data rights fulfilment and de-identification, and the data inventory can be populated from existing DSPM tools and catalogues: none of that requires a model. The models are the engine of two core capabilities. Helios classifies discovered data with a large language model applied to database metadata, and Astralis performs continuous agentic risk assessment and enforces purpose-based access at runtime, including rewriting an agent's query where the inferred purpose is not permitted. The vendor's own positioning is a governance harness for AI rather than a product that is itself a model. Verified 12 September 2026.
The model is the engine of a core capability, layered on a product the vendor itself sells without it. Wren is a named AI agent that runs the privacy assessment cycle: monitoring internal tools for reviewable activity, triaging against the customer's playbook, researching the question, reading imported documentation, contracts, interview transcripts, code and connected applications, generating evidence and populating the assessment, then routing it to approvers. That is model work at the centre of the assessment product. The reason this is not the top grade is the vendor's own statement: the pricing page confirms the platform includes a base assessment module that can be purchased without Wren, and the web auditor, app auditor and code scanning modules are separately priced products whose mechanisms are live scanning, static analysis and simulated consent journeys rather than models. So a substantial and separately saleable part of what Privado sells does not depend on a model at all. Wren product page, pricing page and Annexure A of the subscription terms read 7 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
The strongest published accuracy evidence located in this corpus, and the A rests on the limbs that bite. A first-party engineering account dated 23 December 2025 and attributed to a named author publishes precision, recall and F1 for the Helios classifier, improving from roughly 50% at baseline to over 80% against an adversarial benchmark suite and over 95% against benchmarks drawn from real-world systems, with validation against customer-provided datasets reported at over 90% and a comparison showing positive AI labels wrong 5% of the time against 14% for human labels. The test set is described: around 2,000 tagging tasks across 43 data categories, benchmark examples for 46 categories, fully synthetic schemas generated without reference to customer data, and the ground-truth labelling method including the disagreement-review pass that grew the labelled set from 449 to 825 fields. Three failure modes are named and diagnosed with the fix for each: laziness, shallowness and credulity. The vendor also publishes a critique of naive accuracy metrics, showing that a classifier which does nothing scores 98.6% on a typical enterprise distribution, which is the opposite of the bare claim the D band was written for. R15 governs two limbs that do not apply to the product class: the product cites no legal authority, so grounding to primary authority and citator status are neither credited nor penalised. What the A does not rest on: no accuracy figure appears on any product page, only in the engineering post, and the category-by-category breakdown is shown in screenshots rather than in text. Verified 12 September 2026.
Grounding is real and the retrieval path is described, short of any measurement. The vendor states which sources Wren reads to populate an assessment, naming them individually: imported documentation such as product requirement documents, technical specifications, support documents, interview transcripts and notes; contracts, from which data processing terms are extracted; source code through a source control integration; connected SaaS applications through API integrations; and internet research, with a cookie agent described as verifying cookie categorisation by researching the internet in real time. The output carries evidence excerpts back to the material they came from, and gaps Wren could not fill are surfaced rather than filled in. What is absent is measurement of any kind: no accuracy rate for populated assessments, no evaluation, no test set, no error analysis, and no statement of how often an evidence excerpt supports the conclusion drawn from it. Several limbs of this band do not bite and are named rather than penalised, since the outputs are assessments and data maps rather than legal assertions citing authority. Wren product page and pricing FAQ read 7 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Real review surfaces and a described control structure, short of the limb the B band names as commonly absent. What the system does alone is published plainly: Astralis checks every agent call through an MCP gateway before it runs, rewrites a query whose inferred purpose is not permitted, re-evaluates the risk register nightly, and drafts assessments and mitigations for approval. What constrains it is customer-defined: a purposes taxonomy, policy definitions, and the Fides ontology the customer versions itself. Review surfaces are the risk register, the assessment report and the audit record of how and why each access decision was made. What is not published is the threshold structure: where the gateway blocks rather than rewrites, what happens when an enforcement decision is wrong, and whether a human approves a mitigation before it is applied. The classifier post's human-in-the-loop discussion concerns Ethyca's own evaluation work rather than the customer's oversight of the shipped product, and is not credited here. Verified 12 September 2026.
A real division of labour is published with genuine review surfaces, short of the threshold that would settle where the boundary sits. What is published: Wren triages incoming activity and triggers the appropriate assessment or record of processing based on the risk value and the playbook and privacy policies defined by the customer's team, which makes the constraint the buyer's own document rather than a vendor default; assessments are routed to approvers; gaps Wren cannot fill are surfaced for a person to answer in chat; and risks it identifies are tracked alongside those raised by privacy stakeholders. That is a workflow with a person in it at named points. What is missing is the limb this band names as commonly absent. The vendor states that Wren eliminates manual threshold assessments and immediately communicates privacy guidance for low-risk activity, so it does answer some questions without review, and nothing published defines what counts as low risk, what Wren may finalise unattended, or what happens when an assessment it populated is wrong and a decision has already been taken on it. Wren product page and pricing FAQ read 7 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers and published figures, never joined, which is the B band exactly. Sixteen customers are named on the customers page, each with its own profile page, including The New York Times, Ramp, SurveyMonkey, WeTransfer, Vercel, Lush, Zola, Casper and American City Business Journals. Platform figures are specific: 744m preferences processed annually, more than 4m access requests processed, 200+ global brands, $74m+ saved by automation, subject request fulfilment from 15 hours to 17.2 seconds, 1 PB governed daily, 150,000 policy decisions enforced per second. None is attributed to a named customer and no method is stated for any of them. The New York Times profile page was opened and carries the customer's own business metrics (11.7m subscribers, $2.59bn revenue, 139 Pulitzer Prizes) and a chief executive quote about the newspaper's subscription strategy rather than about the product: on that page alone the evidence is the C shape. The breadth of named customers and the specificity of the platform figures carry the row to B. Fifteen further customer pages were not opened. Verified 12 September 2026.
Named customers with named people in named roles, and no figures. Three deployments are published with attributed quotations and linked case studies: HP, where a Privacy Innovation and Assurance Leader describes visibility of personal data across the technology stack and automation of manual controls such as privacy reviews; HERE Technologies, where a Director and Head of Product Trust says compliance reports match data flows as the product evolves; and Headspace Health, where a chief information security officer describes building privacy into the software development lifecycle to prevent accidental sharing or tracking. Those are real deployment statements from identifiable people rather than logos. What is absent is the quantified half: no figure for review time, assessment volume, issues found or cost, no dates on the deployments, and no method behind any claim. The customers page carrying the full case studies was not read this pass and is the route to a higher grade. Wren product page read 7 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive contractual commitments readable before signing, and the A band's privilege limb is absent, which R33 makes decisive. Published and read in full: MSA section 4.1 licenses Customer Data only to provide the Service and fulfil Ethyca's obligations, with a separate narrow licence over Audit Data, defined as three enumerated fields, for legal compliance alone; section 4.2 commits to using Customer Data solely for legitimate operational needs such as audit trail creation and system monitoring, or where required by law; section 9 is a mutual confidentiality regime with need-to-know limits and written obligations on personnel; DPA section 3(f) commits to deletion or return within 90 days of termination; the CCPA schedule bars retention, use or disclosure for any purpose beyond the business purpose and bars sale. The design fact that answers the model-provider question in this product's own idiom is that the classifier is metadata-only and, in the vendor's words, requires no access to sensitive data. Two limbs keep this at B: nothing located addresses privilege or work product treatment, and no third-party model provider's retention position is stated anywhere, the inference platform being unnamed. MSA last modified 10 February 2023; DPA 17 October 2024. Verified 12 September 2026.
Substantive published commitments, unusually well enforced, short of segregation and of the model provider question. The subscription terms make Customer Content, including source code and data elements and the reports generated from them, the customer's Confidential Information, and put the ordinary five-year confidentiality survival aside for exactly that material so the obligation runs until an exception applies rather than expiring. Use is confined by a limited-term licence to host, copy, transmit, analyse, process, store and configure Customer Content solely as necessary to provide the services, with all intellectual property in the generated reports vesting in the customer. Enforcement is real rather than nominal: a contractual penalty of twelve months' fees for any breach of the confidentiality obligation, which does not release Privado from performance and does not displace the customer's damages claim, and a liability cap that is lifted entirely for confidentiality and privacy breaches. The security page adds role-based access control and a stated internal procedure preventing employee or administrator access to user data except for limited support exceptions, with staff under confidentiality agreements. Two limbs are missing: nothing addresses segregation between customers or between matters inside a tenant, and nothing states what the model providers behind Wren may retain, since none is named. Subscription terms and security page read 7 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
A real published position on advice versus tooling, in the instrument that governs the product and unusually plain. MSA section 10.4 is headed No Legal or Regulatory Advice and states that Ethyca is not providing legal, accounting, tax or regulatory services, is not advising on compliance with or interpretation of any privacy or security law, that any recommendation it gives concerns the functionality of the Service only and is given from a business perspective, that the customer should not rely on it as legal advice, and that the customer retains sole responsibility for identifying and complying with its own obligations. Section 10.3 goes further than most: the vendor expressly does not warrant that use of the Service will result in compliance with applicable laws, which is the claim a governance product is most tempted to make. Who may use it is stated as Authorized Users under an Order Form for internal business purposes. Short of the full band: nothing addresses a supervising lawyer's competence or supervision duties, and no jurisdiction limit is placed on the guidance the product emits. R15 applies to the consumer-facing limb, which does not bite on an enterprise platform with no public advice surface. Verified 12 September 2026.
A disclaimer sits in the terms while the product issues guidance, and nothing addresses where the output stops and a legal judgement begins. The live question here is sharper than in most records on this axis: the vendor states that Wren eliminates manual threshold assessments and immediately communicates privacy guidance for low-risk activity, which means a model is telling a business stakeholder that an activity does not need a data protection impact assessment. Nothing published says that such guidance is not legal advice, that the privacy counsel or data protection officer remains responsible for the determination, or what happens if the threshold call was wrong. What exists in the agreement is adjacent rather than on point: section 5 records the customer's acknowledgement that it relied on its own skill and judgment to check the applicability of the software and to validate suitability for its intended use, and section 9 disclaims fitness for a particular purpose. Those are suitability and warranty provisions, not a statement about the advice line. Same grade and reasoning as the comparable records in this lane. Subscription terms, Wren page and pricing FAQ read 7 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A published testing regime with real substance, short of an owner and short of disclosed findings on uneven output, which is B. What is published is a quantitative pre-release evaluation framework for the vendor's own classifier: an accuracy metric defined and defended, an adversarial benchmark suite, per-category metric reporting implemented in a purpose-built workbench, model-size threshold findings, and an explicit account of precision and recall trade-offs between models described as more conservative and more creative. That is more evaluation detail than any other record in this lane publishes about its own models. What is absent is the governance structure the A band asks for: no accountable owner inside the vendor is named, no AI policy, model card, governance committee or review board is published, and no finding is disclosed about uneven output across populations or data subject groups, as distinct from across data categories. Worth recording because of where this record sits: this lane's standing finding is that vendors selling AI governance publish least about their own, and this vendor is the counter-example on testing while still publishing no governance structure. Verified 12 September 2026.
No governance position for the vendor's own AI was located, for a product whose agent drafts data protection impact assessments. Nothing published names who inside Privado is accountable for Wren's behaviour, describes what is evaluated before it ships or changes, reports any result from such evaluation, discloses whether its output is uneven across regimes, languages or document types, or offers a model card or system card. The two things that come closest are neither: the statement that customer data and code are never used to train machine learning models is a commitment and is credited on the training signal instead, and the SOC 2 programme with continuous control monitoring is security assurance rather than AI governance. The gap is worth stating precisely because of what the agent does: an assessment Wren populates becomes the customer's record of its own compliance reasoning, shown to regulators and auditors, and the buyer has no published basis on which to judge how that reasoning is produced or checked. The unread data processing addendum and the product documentation site are the rebuttal routes. Wren page, pricing FAQ, security page and subscription terms checked 7 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
All five A limbs are published, contractual and specific enough to hold the vendor to. Retention: processing is bounded to the term of the Agreement, in-product controls let the customer retrieve, correct, delete or restrict Personal Data, and the Audit Data licence that survives is defined as three enumerated fields rather than left open. Deletion: DPA section 3(f) commits to deleting or returning all Personal Data within 90 days of termination, with the backup carve-out named and those copies required to be isolated, protected from further processing and deleted under stated practices. Access control: Annex 2 documents it control by control, covering authentication, an authorisation model validating user permissions against the attributes of each data set, API access by key or OAuth, VPC and firewall segmentation, intrusion detection, static code analysis, annual third-party penetration testing, a responsible disclosure programme, least-privilege employee access reviewed quarterly and third-party background checks. Subprocessors: named in Annex 1.H with purpose and location, being Amazon Web Services for cloud infrastructure in Virginia and Twilio SendGrid for transactional email, with contractual notification of additions or removals and a 30-day objection right for European and Colorado data. Incident practice: notification without undue delay after becoming aware, with timely information and assistance for the customer's own notification duties. Theta Lake was held at B one build ago on the single limb of a subprocessor list the fetcher could not read; that limb is satisfied here, and the A follows from the same reasoning applied consistently. Agreement dates 10 February 2023 and 17 October 2024 go to the confidence rather than the grade, there being no recency floor. Verified 12 September 2026.
Retention, deletion, access control, subprocessors and incident practice are all published and specific, once the data processing addendum is read alongside the security page. The addendum's Annex II sets out the measures: background checks on all new employees, annual security training, written agreements with every vendor carrying confidentiality, privacy and security obligations, role-based access control, a stated password policy with credentials held in AWS Cognito, a formal change management process with review before production deployment, TLS in transit and strong encryption at rest, vulnerability assessment and penetration testing twice a year, and backups taken every fifteen minutes to a private S3 bucket encrypted with AES-256 and restore-tested twice a year. Retention has periods rather than gestures: personal data is deleted once a user is deleted by an administrator and within six months if the customer leaves, and clause 12 requires return or deletion of all personal data within at least thirty days of the end of the agreement with copies deleted as soon as practicable. Incident practice is defined at clause 11, with maintained breach procedures, notification without undue delay unless the breach is unlikely to risk rights and freedoms, and assistance to notify the authority and data subjects; the incorporated Standard Contractual Clauses add the content a notification must carry. Subprocessors are published individually in Annex II with purpose, data centre locations and which products each supports. The security page's own age is recorded on the certifications row and does not move this grade. Data processing addendum of 7 April 2023, security page and subscription terms read 7 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A real published position, specific on the numbers, and it stops where R117 settled this shape one build ago. MSA section 8.1 gives a defence and indemnity against third-party claims that the Service infringes a US patent, trademark, copyright or trade secret, with six named Excluded Activities and an express sole-and-exclusive-remedy statement. Section 11 caps liability unusually precisely: 150% of the fees paid in the twelve months before the act or omission for each party generally, and 300% of those fees for the section 8.1 indemnity, with carve-outs for gross negligence, wilful misconduct, payment obligations and the customer's own indemnity. Section 10.2 gives a limited warranty that the Service conforms in material respects to the Documentation, with a defined path of notice, correction and a right to terminate if it cannot be corrected, which is a warranty a buyer can actually invoke. What keeps this off A is the same thing as on the previous build: no indemnity reaches wrong output, section 10.3 disclaims all warranty as to the Service and any reports or outputs and expressly disclaims that use will produce compliance with law, and no insurance is named anywhere. Verified 12 September 2026.
The fullest published liability position in this lane, and the only one in the pull carrying an insurance schedule. The indemnity at section 12 is broader than the usual intellectual property clause: it covers third-party claims arising from Privado's breach of applicable law, from infringement or misappropriation by the software or by the customer's lawful use of it, and from Privado's own breach of confidentiality, with three named exclusions and the modify, procure or terminate-with-refund ladder. The cap at section 13 is twelve months of subscription fees, and section 13(b) then lifts both the cap and the exclusion of indirect damages for privacy and security breaches, confidentiality breaches, the indemnification obligations and death or personal injury, so the indemnity sits outside the cap rather than inside it. Section 11(f) adds a fixed contractual penalty of twelve months' fees for any confidentiality breach, without releasing Privado from performance and without prejudice to damages. Section 14 requires and maintains commercial general liability at $1,000,000 per occurrence and in aggregate, technology errors and omissions at $1,000,000 per claim, cyber and privacy liability at $1,000,000 per claim and umbrella cover at $1,000,000, with four years of tail on claims-made policies. Warranties at section 5 include material conformance to the documentation and a commitment not to materially decrease functionality. Annexure B commits to 99.9 per cent uptime with service credits graded from 5 to 30 per cent, and support response and resolution goals with a named escalation path. Subscription terms read in full 7 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real, documented integrations into the systems this product's work lives in, short of established depth. Named on the vendor's own surfaces: Snowflake and BigQuery warehouses, AWS infrastructure, identity providers, website cookies, tags and SDKs, third-party applications, and an ingestion path by API, SFTP, manual and web upload. The commercial model itself evidences a connector catalogue, since the MSA prices Connector Integrations as a separate line calculated pro rata. Verifiability is unusually high for this corpus: the Fides core and its connectors are public on GitHub, the API documentation and the release changelog are both published without a login, and Astralis exposes an MCP gateway that policy-checks agent calls. What holds the row at B is that the integrations catalogue and the documentation site were not opened, so what each connector moves and in which direction was not established beyond what the home page and the agreement state. R15 applies to the legal-stack limb: a data infrastructure product bought by privacy counsel integrates with warehouses and identity systems rather than with a document management system, and no document management or practice management connection was located or is expected. Verified 12 September 2026.
Documented integrations into the systems this work already lives in, with what moves, in which direction, and what the customer must configure, stated per product. Wren connects to Jira, Confluence, Linear and procurement tools to capture activity warranting a privacy review, and pushes automated development tickets back into Jira and Linear. Data maps are built from source code through a source control management integration, from third-party applications including customer data platforms, tag managers, CRM, contract lifecycle management, human resources, marketing, procurement and database tools through API integrations, and from imported documents. The integration with OneTrust is described with its direction stated: the personal data inventory, assessments and risks held in OneTrust are automatically updated with information from Privado. Configuration effort is published per module rather than left to a sales call: the web auditor needs only URLs and the geographies to scan from, the app auditor needs the app store URL or the APK and IPA files, neither requires implementation, Wren takes a few days to connect internal tools, set up playbooks and import documents, and the full platform typically takes one to three weeks. What is not established from the pages read is per-connector documentation, which lives on the documentation site and was not opened. Pricing FAQ and Wren page read 7 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Deployment model stated clearly with partial residency detail, which is the B band. Two delivery paths are published: the open-source Fides core, which a customer can run in its own infrastructure from the public repository, and Hosted Fides, the subscription service. Tenancy is stated for the hosted path, and stated against the customer's interest rather than for it: DPA Annex 2 records that Customer Data is held in multi-tenant storage systems reachable only through application interfaces and APIs, with no direct customer access to the underlying infrastructure. Residency is partly published: the subprocessor annex places cloud infrastructure with Amazon Web Services in Virginia, United States, and DPA section 6 states that Personal Data will be transferred to and processed by Ethyca, Inc. in the United States and in other jurisdictions where its affiliates and subprocessors operate, with the EU controller-to-processor Standard Contractual Clauses as the transfer mechanism. What is not published is a list of available regions, any choice of region, what changes between the four commercial tiers, or where processing happens as distinct from where data is stored. Verified 12 September 2026.
The regions are stated and the deployment model is not. The data processing addendum's subprocessor annex gives a data centre location for each entry, and the two that hold customer material are specific: Amazon Web Services, described as the primary cloud infrastructure where all Privado applications are hosted and where all data stored, processed and transmitted through the products resides, is listed for the United States, the European Economic Area and India, and MongoDB, the primary product database, for the same three. So a buyer can establish the countries in which its data may sit, which lifts this off the floor. Transfers out of the EEA run on the 2021 Standard Contractual Clauses set out in full in Schedule 1, governed by Irish law with the Irish Data Protection Commission as competent supervisory authority and onward transfers restricted by clause 8.8. What is absent is everything on the deployment side: no tenancy model, no single-tenant or self-hosted option, no statement that a customer can choose or pin a region, and nothing addressing where processing happens as distinct from where data is stored beyond the transfer mechanism. One adjacent fact is recorded so it is not mistaken for residency: the web and app auditors let a customer choose the geography a scan runs from, which is where the simulated user appears, not where data is held. Data processing addendum, security page and subscription terms read 7 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The grade records an unusual state and the note has to carry it, because neither adjacent band reads cleanly, which is the band gap logged open at R16. No unsupported badge appears on any surface read: the site footer carries no certification marks at all. The only named standards are SOC 2 Type II and ISO 27001, and the DPA attributes both to Ethyca's data centre partners who maintain independently validated security programmes, not to Ethyca: under R16 that is the hosting provider's scope and does not credit to this product, and there is no scope connector naming the Service. Ethyca's own published assurance is real but is assessment rather than attestation: annual penetration testing by industry-recognised third parties, with a summary report supplied on a confidential basis on request, plus a responsible disclosure programme and static code analysis, all set out in DPA Annex 2. A trust centre exists at trust.ethyca.com, is reachable without a sales call, and states that audit reports and security policies are available on it. Its body is Vanta-hosted and returned page metadata with no readable content to this index's fetcher on 12 September 2026, and an R8 step 4 search did not recover it. That is a limit on the reader and not a finding about the vendor, and if the trust centre names an attestation of Ethyca's own the row is regraded and redated under the corrections backstop. One drafting discrepancy to record: the DPA's Virginia and Colorado section reads ISO 29001 where its European section reads ISO 27001. Verified 12 September 2026.
A badge and a monitoring tool, with no scope, no date and no report route. The footer and the security page carry a SOC 2 mark with the AICPA logo, and the security page states that Privado uses Drata's automation platform to monitor more than one hundred internal security controls continuously with automated alerts and evidence collection. What is absent is everything that would let a buyer check it: no type is stated, so Type I and Type II are not distinguished; no trust services criteria are named; no auditor, examination period or report date appears; and no route to a report, a questionnaire response or a gated portal was located, since there is no trust centre. Continuous control monitoring is a real practice and is credited as substance, but it evidences a programme rather than an attestation. The date on the page matters to the confidence rather than the grade and is recorded here: the security page states it was last updated on 17 February 2022. Security page and site footer read 7 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Partly disclosed, which is B, and the disclosure is in an engineering post rather than on a product surface. The models are named, which R34 requires for the top band and which almost nothing in this corpus does: the classifier was built and benchmarked against Qwen's QwQ-32B and DeepSeek-V3 among state-of-the-art models tested, with a published finding that accuracy stops improving above roughly 32B parameters and that models below 18B produce uncorrectable errors. The architecture is described in detail: one request per field to defeat skipped fields, chain-of-thought discussion of tagging considerations, prompt caching, prompt optimisation rather than fine-tuning, and metadata-only inputs. What is absent for A: no provider of inference is identified, the post referring only to cloud inference platforms, and no commitment to notify customers when any of the model supply chain changes is published. Note the gap between two of the vendor's own documents, which is recorded rather than resolved: the contractual subprocessor list names only AWS and Twilio SendGrid, so no model or inference provider appears on the list a customer would be notified about. Post dated 23 December 2025. Verified 12 September 2026.
The vendor sells a named AI agent, publishes a subprocessor list, and no model provider appears on it. This is the sharpest version of this gap in the pull, because the absence is visible rather than inferred. Annex II of the published data processing addendum lists five subprocessors with purpose, data centre locations and the products each supports: Amazon Web Services for infrastructure, MongoDB as the primary product database, SendGrid for transactional email, Intercom for customer support and Amplitude for product analytics. None of them is a model provider, and no model, model family, provider, hosting arrangement or inference location for Wren is named on any surface read. Wren demonstrably runs on a model, since the vendor's own pricing FAQ states that customer data and code are never used to train AI or ML models, so either an unlisted third party sees the documentation, contracts, interview transcripts and source code Wren reads, or the models run inside the AWS footprint already listed, and nothing published tells a buyer which. No commitment is given to notify customers when the arrangement changes, and the subprocessor mechanism at clause 10 gives an objection route without an advance notice period, though the incorporated Standard Contractual Clauses require thirty days' notice of changes to the agreed list for EEA transfers. Data processing addendum, Wren page, pricing FAQ and security page read 7 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The shape is visible and the number is not, which is C. The site publishes no pricing page and no figure: every call to action is a demo request, a free-trial request or a contact form. The structure, unusually, is published in the agreement rather than in marketing. MSA section 6.1 names four commercial tiers, Fides True, Fides Team, Fides Plus and Fides Enterprise, and states that Connector Integrations are charged as a separate line and that moving between tiers or adding connectors is calculated pro rata for the duration of use. Section 6.2 states monthly invoicing in advance on 30-day terms with fees non-refundable except on Ethyca's breach, and section 6.3 limits price increases to renewal terms on at least 60 days' notice and requires any increase to be applied generally rather than to one customer. The open-source core is separately free to self-host, which is described in the note rather than as a price. No rate, no band and no implementation figure appears anywhere located, which is what holds the row off B. A pricing row is owed under R17 because this evidence lifts the axis above D, and is written with no figure. Verified 12 September 2026.
A published rate card with figures, units, minimums and what changes between products, which no other record in this lane offers. The pricing page states that the web auditor starts at $600 per website per month billed annually with a four-website minimum and bulk page-based pricing available; the app auditor at $800 per app per month billed annually, with iOS and Android versions counted as two apps; and Wren at $4,200 per month billed annually for up to 500 assessments. Only the full privacy management platform is on request, and the page states what it adds. Each tier lists its included features, so a buyer can see what the money buys before speaking to anyone, and volume discounts are disclosed rather than implied. Annexure A of the subscription terms then defines the units precisely: a developer is a user who has committed to a scanned repository in the last ninety days, a website is each unique URL entered, an app is each platform version, a scan is one execution against one website from one geography, so running the same site from three geographies is three scans. The agreement adds fees in advance, a twelve-month initial term, non-refundable fees and 1.5 per cent monthly interest on late payment. A VendorPricing row is written, with the floor recorded as a figure. Pricing page and subscription terms read 7 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described with substance and the boundaries are left open, which is B. Who this serves is evidenced by named customers labelled by industry on the vendor's own customers page: publishing (The New York Times, Axios, American City Business Journals), internet software (WeTransfer, SurveyMonkey, Vercel, Podium), fintech (Ramp), retail and consumer brands (Lush, Casper, Away, Parachute, Zola), and marketplace and services businesses (JustPark, Slice, Snackpass). Scale is stated as enterprise, with a separate enterprise page and a statement that the company works as a technical partner rather than selling an out-of-the-box SaaS tool. The buying functions are evidenced by the workflows rather than by a roles page: the current site has no roles or buyer-segment tier at all, which is itself the reason route A was not relied on at the membership screen. What is not stated is where coverage stops: no jurisdictional limit, no statement of which regimes are not supported, and no statement of who the product is not for. R15 applies to the firm-segment and practice-area limbs, which do not bite on a data infrastructure product bought by an in-house privacy and legal function rather than by a practice group. Verified 12 September 2026.
Coverage is described with substance across buyers, regimes and surfaces, and the boundaries are left open. The buyers are addressed by function and evidenced by the customer voices: privacy leaders and privacy teams for assessments and records of processing, engineering for code scanning, and security leadership, with the three named deployments spanning a technology manufacturer, a mapping and location company and a digital health provider. Regulatory coverage is named rather than gestured at, with CCPA, CIPA and GDPR called out, more than fifty pre-built compliance checks, dedicated GDPR and CCPA solution pages, and consent framework handling for GPP, TCF and TAG. The processing surfaces covered are enumerated: websites, mobile apps, internally developed software, third-party SaaS applications and business processes. What is not stated is any limit. No jurisdiction, sector or organisation size is named as out of scope, no coverage boundary is given for the compliance checks, and nothing describes what a law firm rather than an in-house privacy function would do with the platform, which for an index of legal buyers is the boundary that matters. Pricing page, Wren page and solution navigation read 7 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The agreement binds Customer Data to service provision and no surface located names training in either direction. MSA section 4.1, last modified 10 February 2023, licenses Customer Data to Ethyca only to provide the Service and fulfill its obligations under the Agreement, for the term, with a separate and narrower irrevocable license over Audit Data, defined as three enumerated fields, for legal compliance alone. Section 4.2 commits to using Customer Data solely for legitimate operational needs such as audit trail creation or monitoring system functionality, or where required by law.
The DPA's CCPA schedule bars retaining, using or disclosing California personal information for any purpose beyond the business purpose and bars sale outright. Two things belong on the record. The DPA's processing-operations annex describes storage and processing necessary to provide, maintain and improve the Services provided to Customer, so improvement is named while training, models and machine learning are not, and the R28 test of whether the clause names the thing is not met.
Separately, the vendor's engineering post discloses that its classifier was benchmarked on fully synthetic schemas generated without reference to customer data, and then validated against real-world datasets provided by customers; that is evaluation rather than training, it is disclosed in the vendor's own words, and the classifier reads database metadata only, never table contents.
Public material states plainly that customer content is not used for training, and no matching term is located in the published agreement. The pricing page FAQ answers the question directly and in the negative, adding that customer data and code are never stored or shared to third parties. The discipline that attaches to this value was run before taking it: the agreement is published, was read in full, and contains no training term in either direction.
What it does contain is section 4(e), permitting anonymized usage and analytical data derived from processing Customer Content, aggregated with like data from other customers, to be used for Privado's internal purposes including research, analytics and improvement of the services, on condition that the customer and its users cannot be identified. That is an improvement right over aggregated derivatives and it does not name training or models.
One ambiguity in the FAQ sentence is recorded rather than resolved against the vendor: never stored reads either as never stored anywhere, which section 10(c) contradicts by granting an express license to host, copy, store and process Customer Content to provide the services, or as never stored with third parties, which it does not contradict. On the training question itself the policy and the agreement do not conflict. Pricing FAQ and subscription terms read 7 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
The customer controls the window and no zero-retention setting is stated. DPA section 4 records that the Services provide the customer with controls to retrieve, correct, delete or restrict Personal Data, which the customer may exercise itself; section 3(f) commits to deletion or return of all Personal Data within 90 days of termination, with backup copies isolated and deleted under stated practices; and Annex 1.C bounds processing to the duration of the Agreement.
What is not published is a retention period for live data, or any statement that retention can be set to zero. The carve-out that must be named: MSA section 4.1(b) grants an irrevocable license over Audit Data until Ethyca's own compliance obligations expire, and Audit Data is defined narrowly as the primary identifier of the subject of a rights request, a timestamp, and the number and list of affected systems, rather than the underlying content.
For this product class the retained material is the configured data inventory and the record of rights requests rather than a lawyer's prompts to a drafting assistant.
A specific period is published and the customer cannot change it. Annex I.B of the published data processing addendum states the retention position for the personal data transferred: deleted once a user is deleted by administrators, and within six months if the customer leaves Privado. Clause 12 adds the end-of-contract mechanism, requiring return of all personal data or, at the customer's instruction, deletion, within at least thirty days of the end of the agreement or the cessation of services, with all copies deleted as soon as reasonably practicable thereafter; the incorporated Standard Contractual Clauses repeat the choice of deletion or return with certification.
Two limits are recorded so the row is not read as more than it is. The six-month figure and the deletion mechanism address personal data as defined by the GDPR, not every artifact the platform holds, so how long a generated assessment, evidence excerpt or code scan result persists in the account during the subscription is not separately stated; and the security page's own retention section covers usage data only, removable on request.
No zero-retention option is offered. Data processing addendum, security page and subscription terms read 7 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product runs its own documented permission model rather than enforcing a source system's access model at query time. DPA Annex 2 states that authorization to data sets is performed by validating the user's permissions against the attributes associated with each data set, that Customer Data sits in multi-tenant storage reachable only through application interfaces and APIs with no direct customer access to the underlying infrastructure, that a uniform password policy applies and that public APIs are reached by API key or OAuth.
Astralis adds a purpose-based layer on top: access is granted by purpose rather than identity alone, and every agent call is policy-checked before it runs. No ethical wall, conflicts check or matter-level segregation construct was located on any surface, which is unsurprising for a product whose unit of segregation is a data set and a purpose rather than a matter, and a firm would have to align the product's roles and purposes with its own walls itself.
No located public material addresses segregation between customers or inside a customer's own tenant. The nearest published feature is role-based access control, offered on all accounts and described as allowing users to define roles and permissions, and that is a mechanism the customer operates over its own people rather than a statement about how Privado separates one organization's assessments, data maps and code scan results from another's. The vendor-side control that is published is different again and is credited on the confidentiality row: an internal procedure preventing employee and administrator access to user data, with limited exceptions for support.
Nothing read describes tenancy, isolation, or whether Wren's research across imported documents and connected tools respects permissions at retrieval time, which matters for a product that reads a customer's contracts and source code. Security page, subscription terms and Wren page checked 7 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Notice is committed in the agreement and no transparency report is published. MSA section 9.3 permits disclosure of the other party's confidential information on a subpoena or other government process only where the receiving party promptly informs the issuing entity of the existence of the Agreement, promptly informs the disclosing party of the receipt of the subpoena, and does not oppose any effort by the disclosing party to quash or limit it; it further requires that confidential status be maintained and reasonable steps taken during any compelled use.
That non-opposition covenant is more than most agreements in this corpus offer. The DPA adds that where a legal requirement prevents Ethyca from following the customer's processing instructions it will promptly notify the customer to the extent the law permits, and will cease processing beyond storage until new instructions are issued. No transparency report and no figures on requests received were located on any surface, which is what separates this from the top value.
The commitment appears in both instruments, and the stronger of the two is the one incorporated by the data processing addendum. Section 11(b) of the subscription terms requires prompt notice of any compelled disclosure of Confidential Information so the disclosing party can seek a protective order, cooperation at its expense in seeking that order, and disclosure of only the portion legally required; Customer Content, including source code and data elements and the generated reports, is expressly the customer's Confidential Information, so the clause reaches what the platform holds.
The addendum then sets out the 2021 Standard Contractual Clauses in full, and clause 15 is included without disapplication: on a legally binding request from a public authority the importer must notify the exporter and, where possible, the data subject, with the data requested, the requesting authority, the legal basis and the response given; must use best efforts to obtain a waiver of any prohibition on notifying and document those efforts; must provide the exporter with periodic statistics on requests received and challenged; must review the legality of the request, challenge it where there are reasonable grounds and seek interim measures pending a decision; and must disclose the minimum permissible.
That is a notice and challenge regime rather than a bare notice promise, and it is what a buyer transferring EEA personal data gets. No separate transparency report or law enforcement guidelines page was located, and no notice timeline is given in the subscription terms themselves. Subscription terms and data processing addendum read in full 7 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Coverage is described by regime and the underlying corpus is not identified. This product holds no case law, but it does encode regulatory obligation: the vendor states that Astralis knows the internal and external policies a customer must follow and continually analyses risk against them, and names the regimes on its own surfaces, including GDPR, the EU AI Act, CPRA, CCPA, the Virginia CDPA, the Colorado Privacy Act and California's Delete Act, with material published per regime.
What is not published is where that regulatory content comes from, how it is maintained, or on what basis, so a buyer cannot tell whether an obligation set is licensed, built in-house or derived. The one corpus whose provenance is fully open is the taxonomy rather than the law: Fideslang is published as an open-source ontology under the vendor's own repository and mirrored by the IAB Tech Lab, and is inspectable and versionable by the customer.
The regimes behind the product's checks are named and nothing states how the content is maintained. The pricing page advertises more than fifty pre-built compliance checks for CCPA, CIPA and GDPR among others, with dedicated GDPR and CCPA solution pages, consent framework handling for GPP, TCF and TAG, and worked examples such as flagging advertising cookies or third-party SDK data collection where a California user has opted out.
So a buyer can see which instruments the checks derive from, which is more than the lowest value describes, and the sources are public law rather than licensed material. What is absent is the maintenance half: no statement of who maintains the check library, how quickly it absorbs a change in guidance or a new state regime, when each check was last reviewed, or how a customer learns that a check has changed and whether a completed scan was run against a superseded version. Pricing page and solution navigation read 7 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
The product cites no legal authority, so nothing located addresses checking subsequent history, and nothing would be expected to. The nearest published analog is currency of rules rather than currency of authority: the risk register is stated to be re-evaluated nightly against the customer's data, purpose and vendor inventories and against the regimes named on the product pages. That keeps an obligation set current; it is not a treatment signal on a cited case, and the row states the position rather than leaving a reader to infer it from silence.
No located public material addresses whether the authority behind the product's outputs is checked for currency. The ordinary subject of this signal, the subsequent history of reported cases, does not bite for a platform whose outputs are assessments, records of processing, data maps and scan findings rather than citations to case law, and that is recorded rather than penalized. The analog that would bite is whether the compliance check library and the assessment templates track changes in the regimes they encode, and nothing published commits to it.
That question is recorded on the corpus provenance row rather than counted twice here. Wren page, pricing FAQ and solution pages checked 7 September 2026.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
An explicit no-finding path is documented and the published evaluation measures it. The classifier's default output where no privacy-relevant category applies is the system.operations tag in the open Fideslang taxonomy, and the vendor's engineering post of 23 December 2025 sets out both that the default exists and why counting it toward accuracy is misleading, working the arithmetic to show that a classifier which always returns the default would score 98.6% on a typical enterprise distribution.
The same post publishes recall and false-negative measurement, which is the rate at which the system wrongly returns nothing, and discusses the precision and recall trade-off in terms of what each failure costs a governance program. The limit worth naming: this is documented for the classifier, and no equivalent abstention behavior is published for the Astralis assessment or the agentic query path.
An uncertainty path is documented and nothing demonstrates it. The vendor states that when Wren populates an assessment it surfaces the gaps it could not fill and asks the user to supply more context through chat, so the product has a published behavior for the case where it cannot establish an answer: it marks the hole and routes it to a person rather than completing the form regardless. On a product whose output is a data protection impact assessment that a regulator may later read, that behavior is the right one and is credited.
What is missing is the demonstration: no transcript, worked example, evaluation or measurement shows the path operating, no confidence or grounding score is exposed, and nothing states what proportion of an assessment Wren typically leaves open or how it decides that context is insufficient. The live instrument file was read before this value was assigned. Wren page and pricing FAQ read 7 September 2026.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record naming this product, the Fides platform or Ethyca, Inc. was located as of 12 September 2026. Searches were run on both the product name and the company name against published trackers of AI hallucination decisions, including coverage of the Charlotin AI Hallucination Cases database, and returned nothing involving this vendor. This is a statement about the public record on that date and not a finding about the product.
The product classifies data and enforces access policy rather than producing legal citations, which is the conduct those records address.
No court order, opinion or disciplinary record naming Privado or Wren was located as of 7 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on both names alongside a general search of the sanctions coverage; the decisions naming specific tools name general-purpose chatbots and legal research products. This is a statement about the public record, not a finding about the product.
Exposure is structurally remote for a platform whose outputs are internal privacy assessments and data maps rather than filings, though those assessments are produced to regulators and auditors, an audience with its own accuracy expectations.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance. The vendor publishes extensively on regulatory obligation, including GDPR, the EU AI Act, CPRA, state privacy statutes and California's Delete Act, and it addresses professional responsibility in one direction only: MSA section 10.4 states plainly that it provides no legal, accounting, tax or regulatory advice and that the customer retains sole responsibility for its own compliance.
That is a disclaimer of the advice line rather than engagement with the guidance a lawyer buyer is bound by, and nothing located addresses ABA Formal Opinion 512 or any state bar opinion on generative AI. Recorded as of 12 September 2026.
No located public material engages with bar or ethics guidance, or with lawyers' professional obligations in general terms. Privado engages regulation in detail and addresses privacy counsel and data protection officers as buyers, and all of that concerns the obligations of the organizations buying the product. Nothing names an ethics opinion, a bar association guidance document or a regulator's guidance on lawyers' use of AI, and nothing addresses the position of a privacy lawyer who signs off an assessment a model populated.
The lower value was tested before this one was taken: a generic reference would require some engagement with professional responsibility as such, and none was located. Wren page, pricing FAQ, subscription terms and security page checked 7 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The product does not touch a fee between a lawyer and a client. It is bought by an in-house privacy, legal, governance or data engineering function to govern that organization's own data estate, and no client is billed for the work the classifier or the policy engine performs. Savings claims are published and are aimed at the buyer's own operating cost rather than at a client invoice: $74m+ saved by automation, subject request fulfillment from 15 hours to 17.2 seconds, data access service levels from six weeks to five minutes, and a published cost of $0.603 per thousand fields classified.
Under the value's own terms those are recorded here and do not make this a savings-claims row, because no client bill is in the loop. R21 noted: the signal is specific to AI-assisted billable work, which this product does not produce.
The product does not touch a fee between a lawyer and a client. Privado is licensed by an organization to assess and map its own data processing, and the buyers are in-house privacy, legal, security and engineering functions that bill no client for the work. The efficiency claims on the product page, freeing up resources and increasing assessment bandwidth, are aimed at the buyer's own capacity, which the value text records as not making the row a savings claim.
Nothing addresses billing, fee or disclosure treatment because there is no client invoice for it to address. What the vendor does publish about its own charging is unusually complete and is graded on Commercial Transparency, not here. Pricing page, Wren page and subscription terms checked 7 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor list is published in the agreement itself and the model provider limb is not met. DPA Annex 1.H names each subprocessor with its purpose and country: Amazon Web Services for cloud infrastructure in Virginia, United States, and Twilio SendGrid for transactional email in the United States. DPA section 5 and section 7(d) commit to notifying the customer of additions or removals by updating the list, with email notification on opt-in and a 30-day objection right on data protection grounds, and to imposing equivalent terms on each subprocessor.
Forwardable client-facing material exists and is ungated: both the DPA and the Master Subscription Agreement are published in full, which under R29 satisfies the third limb of the top value. The reason the row is not disclosure-pack is the second limb, and the gap is between two of the vendor's own documents rather than an absence: its engineering post names the models used for classification and refers to cloud inference platforms, while no model or inference provider appears anywhere on the contractual subprocessor list a customer would be notified about. A firm forwarding this pack to its client could name the infrastructure and could not say who runs the model.
A current subprocessor list is published, and the model provider question still has no published answer. Annex II of the data processing addendum lists five subprocessors, each with its purpose, its data center locations and the products it supports: Amazon Web Services as the primary cloud infrastructure holding all data stored, processed and transmitted through the products, in the United States, the European Economic Area and India; MongoDB as the primary product database across the same three; SendGrid for registration, password and notification email; Intercom for customer support; and Amplitude for product analytics on the code scanner.
The forwardable material sits alongside it and needs no agreement to obtain: the addendum itself, the Standard Contractual Clauses set out in full with Irish law and the Irish Data Protection Commission named, the technical and organisational measures in Annex II, and the public subscription terms carrying the confidentiality, indemnity and insurance provisions a client questionnaire asks about. What stops this reaching the top value is the limb an AI clause turns on: no model provider is named anywhere, and none appears on the subprocessor list, so a firm cannot tell its client whose models see the documents, contracts, transcripts and source code that Wren reads to populate an assessment. Data processing addendum read in full 7 September 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Elements of a record exist and they are not a filing-level certification. What the product records is published: every alert, user action and access decision is logged with how and why it was resolved, policies are stated to prove how data was used rather than only who accessed it, every agent call through the Astralis gateway carries an inferred purpose and a policy check, assessment reports are generated with mitigations attached, and classification decisions carry the model's own discussion of tagging considerations.
That is a per-call and per-decision record of what an AI system did with which data under which purpose, and it is exportable and stated to be audit-ready. What it does not produce is a document-level record tying a named model, the sources it retrieved and a named human verifier to a filing, because the record is of data access and governance rather than of a brief's drafting. A firm asked to certify AI use in a matter would have material to draw on and would have to assemble the certification itself.
Some elements of a record exist and none is built for disclosure. What the product does produce is substantial: evidence excerpts tying assessment answers back to the documents they came from, risks documented per assessment with remediation tracked, approval routing that records who signed off, and application logs collected as an audit trail on the security side. A privacy team could reconstruct a good deal of what happened from that.
What is absent are the elements this signal asks for: no per-item export stating which model or agent produced a given answer, what it read and what a person verified before approval; nothing addressing a court's standing order on AI use; and no template or certification a filer could attach. The distinction worth naming is that the record the platform keeps is a record of the customer's compliance decisions, not a record of the model's work in reaching them. Wren page, pricing FAQ and security page checked 7 September 2026.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Good Law Verification
- Bar Guidance Alignment
Which one fits
Choose Ethyca if
- You want to see how accurate the classifier is before you trust it. Ethyca publishes precision, recall and F1 for its Helios classifier, describes a test set of about 2,000 tagging tasks across 43 data categories, and names the failure modes it found and how each was fixed.
- You want an open standard you can inspect or run yourself. Ethyca's Fides taxonomy and policy language is open source on GitHub, and a customer can self host the Fides core or subscribe to the hosted service.
- You need access decisions enforced for AI agents. Ethyca's Astralis checks every agent call through a policy gateway before it runs, rewrites a query whose inferred purpose is not permitted, and records how and why each access decision was made.
Choose Privado AI if
- You want to price the tool before a sales call. Privado publishes $600 per website per month for its web auditor, $800 per app per month for its app auditor, and $4,200 per month for Wren covering up to 500 assessments, all billed annually.
- You want an agent to draft privacy assessments from your team's tools. Privado's Wren watches Jira, Confluence, Linear and procurement tools for activity needing review, triages it against your playbook, populates PIAs and DPIAs with evidence excerpts, and flags the gaps it cannot fill.
- You want insurance and service credits in the contract. Privado's subscription terms require $1 million each of general liability, errors and omissions, cyber and umbrella cover, commit to 99.9 percent uptime with graded credits, and set a penalty of twelve months' fees for any confidentiality breach.
In summary
Ethyca
Ethyca, based in New York, is a data governance and privacy engineering platform built on Fides, the open source privacy taxonomy it maintains on GitHub. Helios discovers and classifies personal data, Janus captures consent, Lethe fulfills data subject requests and deletion, and Astralis enforces purpose based access at runtime, including for AI agents, and assesses risk against regimes such as GDPR, the EU AI Act and CPRA. The AI Legal Index grades it in the top two bands on thirteen of fifteen capability axes, with A grades on citation accuracy and data stewardship. It publishes its agreement and data processing addendum, and names The New York Times, Ramp and SurveyMonkey among customers. As of 12 September 2026 the index located no published price or attestation of its own.
Privado AI
Privado AI is a privacy engineering company whose platform finds personal data across websites, apps, source code and SaaS tools and turns it into privacy assessments and records of processing. Its AI agent, Wren, triages activity from Jira, Confluence and procurement tools and populates assessments, alongside data maps, code scanning and web and app auditors that simulate consent journeys. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes, with A grades on data stewardship, liability, integration depth and pricing. It publishes a rate card and subscription terms with an insurance schedule, and names HP, HERE Technologies and Headspace Health among customers. As of 7 September 2026 the index located no named model provider or AI governance position.
Questions buyers ask
Ethyca vs Privado AI: which privacy engineering platform is better?
Ethyca sits in the top two bands on thirteen of fifteen AI Legal Index capability axes and Privado on ten of fifteen, identical on seven. Ethyca publishes more about its own AI, including measured accuracy and a testing method. Privado publishes more about its commercial terms, including a rate card, insurance and service credits. Buyers weighing AI risk have more to read from Ethyca; buyers weighing cost, from Privado.
How accurate is Ethyca's data classifier?
Ethyca's engineering post of 23 December 2025 reports precision, recall and F1 rising from roughly 50 percent at baseline to over 80 percent on an adversarial benchmark and over 95 percent on benchmarks drawn from real systems, with validation on customer data above 90 percent. It describes the test set and names three failure modes. The figures are the vendor's own. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
How much does Privado AI cost?
Privado publishes a rate card: $600 per website per month for the web auditor with a four website minimum, $800 per app per month for the app auditor, and $4,200 per month for Wren covering up to 500 assessments, all billed annually. The full platform is priced on request. Ethyca names four tiers in its agreement without publishing a figure. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Do Ethyca and Privado AI train AI on customer data?
Ethyca's agreement limits customer data to providing the service and names no training right. Privado's pricing FAQ states that it never uses customer data or code to train AI models, and its terms allow only aggregated, anonymized usage data to improve the service. Ethyca's classifier also reads database metadata only, never table contents. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What do Ethyca and Privado AI both leave unpublished?
An independent security attestation of their own and the inference provider behind their AI. Ethyca's SOC 2 and ISO 27001 references belong to its hosting partners, and Privado shows a SOC 2 mark without a type, date or report route. Neither lists a model or inference provider among its contractual subprocessors. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Three readings to weigh. Ethyca's accuracy figures come from a first party engineering post dated 23 December 2025 rather than an independent evaluation, and its SOC 2 and ISO 27001 references belong to its hosting partners. Privado's security page was last updated in February 2022 and carries a SOC 2 mark without a type or report route. Neither vendor names a model or inference provider on its contractual subprocessor list. Ethyca was verified on 12 September 2026 and Privado AI on 7 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.