OneTrust vs Securiti: how they compare in 2026
OneTrust and Securiti are the marquee privacy and data governance comparison, and the grid puts them close: OneTrust in the top two bands on ten of fifteen axes, Securiti on nine. The tie breaks on what each publishes about its own data handling, and it breaks in both directions. OneTrust publishes its Master Terms, data processing addendum and standard contractual clauses openly with full version histories, and its trust centre carries SOC 2 Type II reports, ISO 27001, 27701 and 27017 certificates and a statement of applicability as direct downloads, yet neither its contract nor any policy addresses whether customer content is used to train models. Securiti operates no trust centre and routes every attestation through a request, and its agreement does reach the question, granting a licence to use customer data for the purpose of enhancing product or services with no carve out for training. Securiti carries the stronger recourse position, including a data handling indemnity, a one million dollar ceiling and published insurance cover.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Artificial intelligence is present, shipped and contractually confirmed, and it is a layer on a product whose value stands entirely without it. The core is registry and workflow software: a data and activity map, consent banners and preference centres, data subject request automation, vendor and third-party inventories, assessment templates across more than fifty standards, and policy approval workflows. Remove every model and all of that continues to work, which is the distinction this axis asks about. Where AI appears it accelerates an existing step rather than constituting one, with an AI-assisted risk assessment producing a summary and key findings that then route to human approval. Worth separating two things that are easy to conflate here: OneTrust sells AI governance as a subject matter, maintaining registers of a customer's models, agents and datasets and applying runtime controls to them, and that is the product managing someone else's AI rather than the product being AI. The Master Terms confirm the vendor's own use, answering the question of whether AI is used in the services with a plain yes.
AI is present in three distinct ways here and none of them makes the models the product a legal buyer is paying for. First, as subject matter: AI Governance, EU AI Act and NIST AI RMF pages sell the ability to govern a customer's AI, which is the product managing someone else's models. Second, as infrastructure for the customer: Gencore AI vectorises and sanitises data for training, runs prompt, retrieval and response firewalls, and builds copilots, which is AI plumbing rather than AI doing the buyer's work. Third, and closest to this axis, as technique inside classification and the DataAI Command Graph. Strip the models out and what remains is fully saleable and is most of the platform: data discovery and scanning across a stated thousand-plus integrations, a catalogue, lineage, a data map producing records of processing activity, DSR workflow, consent capture, assessment templates and breach notification. Consistent with the comparable platform in this lane, which took the same grade for the same structural reason.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is not asserted loudly and it is not measured either, and the document that would answer it is obtainable rather than published. The AI-assisted assessment shown on the home page produces a risk summary and graded findings across personal data processing, model accuracy and transparency, which is an output a compliance officer will act on, and no accuracy rate, benchmark, test set or error mode for it was located on any public surface. Several limbs of this axis do not bite: the product does not retrieve primary legal authority, so grounding to openable sources and citator checking are not the relevant questions, and the applicable risk is a wrong risk rating rather than a fabricated citation. The AI Systems Transparency Report is the artifact that would carry this and the Master Terms describe it as available upon request, which under the gated-is-not-absent rule is the middle tier rather than an absence, but its contents could not be read on 1 September 2026. Checked the home page, the trust centre, the pricing and packaging page and the published contracting explainer.
Accuracy is asserted repeatedly in the marketing and measured nowhere. The claim appears in the product copy as accurately classifying data, discovering shadow and cloud-native assets, and delivering unified intelligence, and classification precision is the decisive quality metric for a discovery and posture-management product: a missed store of personal data is the failure mode that matters, and an over-broad match creates work that erodes trust in the tool. No precision or recall figure, benchmark, test set or false-positive rate was located on any surface read on 1 September 2026. Two limbs of this axis do not bite, since the platform does not retrieve legal authority and produces no citations a reader would open. The agreement is more candid than the marketing on this point and is graded on the liability row: Securiti warrants substantial conformity with the Documentation rather than accuracy of any classification result.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A review point is not merely claimed but drawn, with named roles, and the surrounding control structure is incomplete. The AI use case workflow published on the home page runs intake, then AI risk assessment, then a review and approve stage showing three pending reviewers identified as Privacy, Security and Legal, then continuous monitoring described as real-time oversight and alerts after workflow completion. That places the machine output before a human gate and says who holds it, which is more than most vendors in this lane publish. The AI Governance package reinforces it commercially, listing configurable approvals, attestations and evaluation gates before AI systems move to production, and runtime controls across prompts, outputs, data access and allowed AI actions. What is missing is the rest: nothing states what the assessment does unattended, at what confidence it defers, or what happens after it is wrong, and no statement was located about the behaviour of OneTrust's own models as distinct from the governance gates it sells.
Oversight is sold as a product and not described as a control over the vendor's own output. Securiti ships genuine runtime controls, with context-aware prompt, retrieval and response firewalls for large language models and Agent Commander for detecting and undoing AI agent mistakes, but every one of those governs the customer's AI systems rather than Securiti's classification and assessment engine. On its own side, nothing located states what runs unattended, what confidence threshold causes the system to defer, where a reviewer sits relative to a classification decision, or what happens after a classification is wrong. Assessment Automation implies human authorship of assessments without describing a checkpoint over machine output. The agreement is the only place a supervision expectation is stated and it points at the customer: the disclaimer records that the product augments rather than replaces professional advisors, and that the customer must confer with legal counsel as needed. That places responsibility rather than describing a mechanism.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
A named customer, a named individual and real figures are published, and nothing carries a date. The GOL customer story quotes Bruna Boccini, Head of Compliance and Data Protection Officer at the airline, and gives specific before-and-after numbers in her own account: vendor approval falling from almost thirty days to between five and zero, and request completion falling from fourteen or fifteen days to a few minutes, against a described estate of seven billion identifiers and thousands of data flows and vendors. A commissioned Forrester Total Economic Impact study adds a 227 per cent three-year return and a seven-month payback, which is a figure attached to a documented methodology a reader can assess. Around those sit a large named logo set including Adobe, Samsung, Pfizer, Walgreens, Aetna, Atlassian, Maersk and Bristol Myers Squibb, and a claim of more than 14,000 customers with more than half the Fortune 500. What holds this below the top band is dating: no located customer story or study carries a date, and the operational figures are the interviewee's own account rather than a measured study.
Named organisations, named individuals with titles and dates, and no figures for what changed. The Spotlight Talks series carries on-the-record interviews with a director of global analytics at Dye and Durham, an SVP of product at Walker and Dunlop discussing a 135 billion dollar portfolio, and named executives at Sanofi, Volkswagen and International Flavors and Fragrances, each dated between April and June 2025. That is materially better attribution than most of this corpus, and it is interview material rather than outcome measurement: no before-and-after metric, deployment scale or time saving is attached to any of them. Analyst recognition is extensive but is not deployment evidence, spanning GigaOm, Frost and Sullivan, IDC MarketScape, Forrester Wave, Gartner Cool Vendor and an RSA Conference Innovation Sandbox win. **One piece of context belongs on this row**: section 9.2 of the customer agreement obliges customers to join Securiti's reference programme and to develop a profile including an executive quote and logo, so the supply of testimonials is a contractual term rather than purely voluntary.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The published commitments are substantive and contractual, and the training question is not answered. What a buyer can read before signing: a Data Processing Addendum published openly with version history, purpose limitation providing that personal data is processed only for the limited purposes described in the agreement and that OneTrust will not buy or sell customer personal data, customer retention of ownership of all data input into the services, tenant separation with data held in a logically-separated cloud database and a single production environment per customer, ISO 27701 certification for privacy information management, and deletion or export rights exercisable at any time during the term and for sixty days after it ends. Against that, nothing located states whether customer content is used to train or improve models, which is the first question this axis asks and a conspicuous silence for a company selling AI governance; the position on third-party model providers is equally absent; and privilege and work product are never mentioned, which matters because the platform is sold to privacy counsel and the workflow assigns a legal reviewer.
The architecture is documented with unusual specificity and the question is answered in the vendor's favour rather than the customer's. On the strong side, and all of it published in the agreement or its security exhibit: per-customer virtual database instances logically separating one customer's data from another's and destroyed when the customer stops using the service; personal data identified by the platform subjected to a one-way irreversible hash, with a commitment that personal data is at no point captured in clear text in logs or databases; mutual contractual confidentiality with a notice-and-opportunity-to-contest provision for legally compelled disclosure; customer ownership of Customer Data; and deletion of all Customer Data from online systems within one business week of a confirmed request. Against that sits the term that decides this axis. **Section 2.1 grants Securiti a royalty-free, worldwide licence to use Customer Data both to provide the service and for the purpose of enhancing product or services**, with no carve-out for model training and no definition of what enhancement covers. Privilege and work product are not addressed, and no position on third-party model providers exists.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Nothing located addresses the line between an information tool and legal advice, on a product that produces compliance determinations for a professional audience. The platform assigns risk ratings, generates assessments against named regimes including the EU AI Act, GDPR and US state privacy laws, and routes them to a reviewer identified as Legal, so the output is consumed as a compliance judgement. What is published in its place is a performance commitment rather than an advice-line position: the Master Terms warrant that the cloud services will materially conform to the OneTrust User Guide throughout the subscription term. No statement was located that outputs are not legal advice, that OneTrust is not a law firm, that no professional relationship arises, or that a user should take advice on their own facts, and no jurisdiction limit or supervision and competence discussion appears. **This is the row most likely to move on this record**: the Master Terms PDF itself and the Legal and Compliance Information page were not opened on 1 September 2026, and a disclaimer may sit in either, so the grade rests on the home page, trust centre, pricing page and published contracting explainer.
A real position on advice versus tooling is published in the agreement itself, which is more than most of this lane manages. The disclaimer at section 5.4 states in terms that the customer acknowledges the product is intended only to augment the customer's privacy practices but not replace legal and other professional advisors, and that the customer is a data controller responsible for what data it collects and for its own privacy policies. Section 2.5 reinforces it operationally: the customer assumes full responsibility as controller, warrants that it has complied with transparency obligations and obtained the necessary consents and legal bases, and, in an unusually direct sentence, records that it is the customer's responsibility to confer as needed with legal counsel to confirm and maintain compliance with applicable laws. That is a published allocation of the professional judgement, addressed to the person who will rely on the output. What is missing is the rest of the treatment: no jurisdiction limit is named for the tool's own coverage, nothing addresses the supervision or competence duties of the practitioner using it, and no professional guidance is referenced anywhere.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A governance framework with real substance is published and its results are not. The trust centre states that OneTrust's AI governance programme is managed by an interdisciplinary AI Governance Committee, supported by AI governance processes across the organisation and the AI systems lifecycle, an internal AI use policy and employee training. That is an accountable body, a lifecycle scope and two named instruments rather than a list of adjectives, and it is backed by a dedicated Responsible AI section, a published Journey to AI Governance toolkit and an AI Systems Transparency Report. Two things keep it below the top band. No individual is named as accountable, the committee being identified only by function. And nothing has been disclosed about uneven output: no bias evaluation, no testing regime and no result appears on any public surface, which is a notable gap for a vendor whose own product sells bias and drift monitoring to others. The AI Systems Transparency Report is available on request rather than published, so it sits in the middle disclosure tier and its contents were not read.
Nothing published addresses governance of Securiti's own models, and the contrast with what the company sells is the point. Securiti publishes extensive material on AI governance frameworks as product capability, with dedicated pages for the EU AI Act, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM Applications and CDMC, and an AI Governance module sold to establish controls for the safe adoption of AI. None of that is Securiti's own governance. No responsible-AI page, AI policy, ethics statement, AI governance committee, named accountable owner, pre-release testing regime or bias evaluation was located. The site navigation was read in full on 1 September 2026 across products, solutions, resources and company sections and contains no such surface; the Company menu offers About Us, Partner Program, Contact, News Coverage, Press Releases and Careers, and the footer offers terms, security, cookie preferences and privacy request routes. The security exhibit designates a security official and a cross-functional Security Council, which is information security governance rather than AI governance. **A vendor selling AI governance publishes none of its own.**
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Every limb this band names is published, current and specific enough to hold the vendor to, and this is the strongest stewardship record located in the corpus. Retention is customer-configurable rather than merely stated, with services shipping built-in data minimisation functionality including auto-deletion and retention periods, and OneTrust expressly encouraging customers to configure them down. Deletion is contractual and time-bounded: customers may delete or export their data in a structured, commonly used and machine-readable format at any point during the term and for up to sixty days after termination, after which remaining data is deleted under a destruction policy. Access control runs through customer-administered user access plus ISO 27001, 27017 and 27701 certification, with the security obligations set out in Appendix 1 of the published DPA. Subprocessors are maintained on a list with a thirty-day advance notice commitment for changes and a right to object on reasonable data protection grounds, remedied by an alternative provider or termination of the affected subscription. Incident practice is stated: notification without undue delay, continuing updates on material developments, and cooperation with the customer's own reporting obligations. Encryption is given concretely at AES-256 at rest and in backup and a minimum of TLS 1.2 in transit, and the trust centre publishes a 2026 penetration test executive summary alongside disaster recovery and business continuity exercise memos. The one soft edge is that the subprocessor list itself sits on the customer portal rather than the open trust centre.
Substantive, specific and published across most of the ground, short of a named subprocessor list. The security exhibit to the customer agreement is unusually concrete. Deletion carries a stated window: on a customer request filed by ticket or email, Securiti deletes all Customer Data from online systems within one business week of confirmation, with retention only where applicable law requires. Incident practice carries a stated deadline and method: notification of a security breach as soon as practicable and no later than seventy-two hours after Securiti becomes aware, by email with a read receipt to a designated address, with Securiti barred from informing third parties without approval and the customer holding sole right to decide whether affected consumers are notified. Access control is role-based, reviewed regularly and monitored, with a stated subset of personnel able to reach customer data. Testing is described with dates attached to cadence: annual third-party penetration tests and audits, weekly internal scans, disaster recovery tested twice a year with an executive summary available to customers on request. Devices carry a minimum of AES-128 full disk encryption. What is absent is the subprocessor limb: third parties appear only as categories such as IT service providers and cloud providers, with none named, and the CCPA addendum has the customer pre-approve transfers to Securiti's affiliates, service providers, third parties and vendors without identifying them.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
What the vendor stands behind is published, specific, versioned and independently assessed, which no other record in this pull matches. The Master Terms of Service are published in full at a dedicated legal centre, currently version 5.1 effective 23 March 2026, with every prior version back to August 2020 downloadable alongside the DPA, Standard Contractual Clauses, Business Associate Agreement and product-specific supplemental terms. The liability position is stated and benchmarked rather than buried: a cap on each party's liability equal to the total annual fees paid or payable in the preceding year, which OneTrust expressly notes is broader than the more common cap tied to fees for the applicable service only, with willful misconduct and intellectual property claims carved out and uncapped. An indemnity with stated scope covers third-party IP infringement claims arising from use of the cloud services, with OneTrust controlling the defence. A warranty a buyer can invoke commits the cloud services to conform materially to the User Guide throughout the term. OneTrust also publishes a plain-language explainer, Contracting with OneTrust, setting all of this out for a reviewer, and states plainly what it will not do, refusing uncapped liability for data breach and giving its reasoning. The Master Terms carry an independent TermScout assessment rating them 70 per cent customer favourable with a perfect score against buy-side deal breakers. What is absent is anything specific to AI output being wrong and any insurance position.
Every limb this band names is published and specific, and one of them appears here for the first time in the corpus. The indemnity runs two ways rather than one and covers more than intellectual property: Securiti defends the customer against third-party claims that use of the product infringes a US patent, copyright, trade secret or trademark, **and separately against claims arising out of any use or disclosure of Customer Data by Securiti in breach of the agreement**, which is a indemnity rather than the IP-only indemnity that is standard in this corpus. The cap is stated with a hard ceiling: direct damages limited to the lesser of amounts paid under the applicable order form in the preceding twelve months **or one million dollars**, with the usual consequential-damages exclusion running mutually and the customer's payment obligations carved out. A warranty a buyer can invoke commits the product to substantially meet the order form requirements, substantially conform to the documentation and be free of malicious code, with re-performance, termination and a pro-rata refund as the exclusive remedy. **An insurance position is published, which no other record in this pull carries**: errors and omissions, professional liability and cyber cover of not less than three million dollars per claim and in the annual aggregate, maintained through the term and for two years after, with thirty days' notice of cancellation. A service level agreement adds 99.5 per cent availability, tiered credits and a termination right below 92 per cent for three consecutive months. Nothing is specific to an AI output being wrong.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integration is plainly a real part of the offering and no individual connection could be named from the surfaces read. A dedicated Integrations page sits in the platform navigation and is described as an extensive set of integrations for adding data management to existing workflows, the Third-Party Management package refers to automating vendor assessments with ecosystem integrations, the Consent product is described as scaling through APIs to collect and enforce consent across emerging channels, and some services ship components that a customer implements on its own systems and websites such as cookie consent scripts and data discovery agents. OneTrust is additionally distributed through the Azure Marketplace, which has its own published supplemental terms. What is missing is the naming and the depth: no specific system is identified anywhere on the pages read, no API reference or developer documentation was located, and nothing describes what moves in which direction. **The Integrations page was not opened on 1 September 2026**, so this grade is rebuttable upward on one fetch and is recorded conservatively rather than assumed.
Real integrations exist, are named, and stop short of documented depth. Securiti states more than a thousand integrations across data systems and names the principal ones on its own navigation: AWS, Google Cloud, Azure, Snowflake and Databricks each carry a dedicated page, with a connectors index behind them. What travels is describable at a high level from the product set, since discovery, classification, access intelligence and lineage all operate by reaching into those systems and reading their contents, and downloadable components are deployed inside the customer's own environment for parts of the platform. What is missing is the implementer's view: no API reference or connector specification was located on the pages read, and nothing describes the direction or granularity of what moves for any individual system. A documentation site exists at docs.securiti.ai, listed among the company's own internet-facing assets in the published system description, and **was not opened on 1 September 2026**, so depth was neither confirmed nor excluded.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The tenancy model is stated plainly, residency is offered, and the processing question is left open. The published contracting explainer describes cloud services delivered on a shared architecture, codebase and infrastructure, with customer data held in a logically-separated cloud database and each customer receiving a single production tenant environment, with non-production environments included in some subscriptions and further environments purchasable. Residency is a customer choice: customers can select from various geographic hosting locations for their tenant environment. What changes between tiers is also addressed, with HIPAA-compliant and PCI-compliant environments available for customers with specialised requirements, backed by a published PCI attestation of compliance and a HITRUST certification. Two things hold it below the top band. The available regions are referred to collectively rather than enumerated, so a buyer cannot see the list without asking. And where processing happens is nowhere distinguished from where data is stored, which matters for the AI features specifically since no model or provider is identified.
The deployment model is stated plainly with partial residency detail. The published system description sets out a multi-tenant cloud service hosted on AWS and GCP, with per-customer virtual database instances providing logical separation, and adds a genuine hybrid element in downloadable components that must be deployed inside the customer's own environment. Residency is real rather than gestural: platform instances sit in multiple geographically distributed data centres, and the company states that **each instance serves customers from a specific geography as a standalone offering with no data exchange between instances**, which answers the processing question more directly than most vendors manage. Two clouds are identified concretely by their own endpoints, a Global Production Cloud and an **EU Production Cloud** at app.eu.securiti.ai with its own status page. Resilience detail is published, with daily backups copied to a different data centre in a different region, a pilot-light disaster recovery strategy, multi-availability-zone failover and a stated 24-hour RTO and RPO. What keeps this below the top band is that the full list of available regions is never enumerated beyond the EU and Global clouds, and nothing describes what changes between deployment tiers.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
This is the trust centre the band describes and the first record in this pull to reach the top of this axis. Attestations are current, independent, and downloadable directly as PDFs with no form, no email capture and no NDA click-through: a SOC 2 Type II report, a second SOC 2 Type II for Certification Automation, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27017 and ISO 9001 certificates, and, decisively for the scope limb, **a published Statement of Applicability** setting out which controls are in scope. Industry and sector records sit alongside them: a PCI DSS attestation of compliance signed November 2025 with a third-party responsibility matrix, a HITRUST certification letter, TISAX, TX-RAMP, the Spanish ENS conformity statement, and a CAIQ v4.0.3 self-assessment lodged on the Cloud Security Alliance STAR registry. Security documentation goes beyond certificates to a 2026 penetration test executive summary, a completed standard SIG questionnaire, a security, privacy and architecture whitepaper, and disaster recovery and business continuity exercise memos, with a live system status page. Under the gated-is-not-absent tiers this is open publication rather than the self-serve request tier, which is what separates it from every other record graded on this axis so far.
The certifications are real and named, and none of the evidence is reachable without asking. Securiti states SOC 2 Type II certification with a copy of the report available on request to prospective and current customers, and holds **ISO 27001:2022 and ISO 27701:2019**, the latter being the privacy information management standard and a sensible one for this product. The customer agreement backs the SOC 2 position contractually, committing Securiti to provide its most recently completed SOC 2 report or an industry-standard successor on request. Supporting detail is unusually good for a vendor with no trust portal: the published system description names AWS and GCP as the underlying providers and describes the shared responsibility split, annual third-party penetration tests and audits, weekly internal scans, and a disaster recovery test executive summary available on request. What holds it below the top band is access and specificity. There is no trust centre and nothing is downloadable; no auditor or certification body is named for any of the three; no certificate date, examination period or scope statement appears; and every route to the evidence runs through a request. Under the gated-is-not-absent tiers this is the self-serve request tier, materially better than absent and short of open publication.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
AI use is confirmed and nothing underneath it is identified publicly. The Master Terms answer the question of whether OneTrust uses artificial intelligence in the services with a plain yes, and direct the reader to the AI Systems Transparency Report, described as available upon request. No model, model family, provider or architecture is named on any public surface read on 1 September 2026, and no statement excludes a third-party foundation model either, so a customer cannot tell from published material whose model processes the assessments and documentation it generates. Where inference runs is not addressed separately from where data is stored. No commitment to notify customers when the model set changes was located, though the subprocessor change process does carry a thirty-day notice commitment and would capture a model provider engaged as a subprocessor. This sits above the bottom band because a dedicated transparency artifact exists and is obtainable rather than absent, which is the middle disclosure tier, and below the band above because nothing is actually named where a reader can see it.
The platform is built around models and identifies none of them. Securiti describes a knowledge graph at the core, classification across structured and unstructured data, vectorisation and ingestion into vector databases, curation and sanitisation of data for model training and tuning, and prompt, retrieval and response firewalls for large language models. Every one of those implies models, and no model, model family, provider or architecture is named anywhere on the surfaces read on 1 September 2026. Nothing states whether a third-party foundation model is called at any point in classification or in the copilot products, and nothing excludes one. AWS and GCP are named as infrastructure providers, which identifies where workloads run rather than whose models they are, and does not answer this axis. No commitment to notify customers when the model set changes was located. This sits above the bottom band because the architecture is described in real terms rather than gestured at, and below the band above because nothing underneath it is identified.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The unit and the structure are published in more detail than anywhere else in this corpus, and no figure appears. A dedicated pricing and packaging page sets out nine named packages across five solution families, each with its key capabilities listed so the feature split between base and suite editions is visible, and, unusually, **each with its own charging meter stated explicitly**: AI Governance priced on admin users and AI inventory; the Consent Management Platform on average daily visitors aggregated across channels and properties; Universal Consent and Preference Management on total data subject profiles captured; Privacy Automation on users and privacy asset inventory; Tech Risk and Compliance on admin users and asset inventory; and Third-Party Management on admin users and third-party inventory. Published FAQs explain what a solution package is, that pricing runs on value-based usage meters, and that a tiered model applies with an account executive moving a customer up a tier when usage consistently exceeds limits. What is absent is the number: no rate, band, floor or currency appears anywhere, every package routes to a Get Pricing form, and nothing states what implementation or professional services add.
No figure and no tier are published anywhere, and the charging unit is nonetheless readable, which is an unusual combination worth recording precisely. The site navigation was read in full on 1 September 2026 and contains no pricing page; every commercial route on every page is a demo request or a contact form. What is published sits in the customer agreement rather than in marketing: the number of Authorized Users accessing the product is capped by the figure specified in the order form, which identifies the unit of charge as named users; fees are quoted and payable in United States dollars; payment obligations are non-cancellable, non-pro-ratable for partial months and non-refundable; late payment carries interest at one and a half per cent per month; and subscriptions renew automatically for successive terms equal to the initial term unless either party gives thirty days' written notice. The service level agreement adds a published credit schedule of four, six and ten per cent against availability bands. So a buyer can read the shape of the commercial relationship in advance while learning nothing about what it costs, with no rate, band, package or tier name published at any point.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described across three deliberate axes with substance behind each, and the boundary is left open. Solutions are organised by function into six families, by role into data, marketing, privacy, and security and risk teams, and by regulation with dedicated pages for GDPR, US privacy law and the EU AI Act plus a wider regulatory index. Practice depth is real: the Tech Risk and Compliance package cites templates and guidance across more than fifty standards, regulations and frameworks, the AI Governance package names the EU AI Act, NIST and ISO 42001 as the frameworks assessments align to, and third-party screening reaches politically exposed persons, sanctions and watchlists through Dow Jones data. The customer base spans regulated industry, retail, pharmaceutical, technology and non-profits on the published logo set. Two gaps keep it here. Nothing states where the product stops, with no statement of organisation size, data volume or the situations it does not fit. And the By Role navigation, which is where a legal buyer would look, offers privacy, security and risk, data and marketing teams and **no page for legal or counsel**, even though the product's own published workflow assigns a legal reviewer.
Coverage is documented across three axes with real substance behind each, and the boundary is left open. Six industries carry dedicated pages: financial services, healthcare, telecom, retail, travel and hospitality, and manufacturing. Regulatory coverage is named rather than gestured at, with individual pages for GDPR, California's CPRA, Brazil's LGPD, Canada's PIPEDA, China's PIPL, the EU AI Act, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM Applications and CDMC, behind a wider index. Technology coverage is quantified at more than a thousand integrations with the major cloud and data platforms named. What is not stated is where the product stops, with no statement of organisation size, data volume, or the environments and obligations it does not reach. The buyer picture carries the same gap seen across this lane: the Roles navigation offers Data+AI Builders, Data Security, Data Privacy, Data Governance and Marketing, and **no page for legal or counsel**, even though the privacy pillar is the work a data protection officer or privacy counsel owns and the agreement itself tells the customer to confer with legal counsel.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way, which is the single most surprising gap on this record. OneTrust publishes a Master Terms of Service, a Data Processing Addendum and Standard Contractual Clauses openly with full version histories, confirms in the contracting explainer that artificial intelligence is used in the services, and states that personal data is processed only for the limited purposes described in the agreement and that customer personal data will not be bought or sold. None of that reaches model training. The purpose limitation is the nearest thing and it is a general processing restriction rather than a training prohibition, and it is expressed over personal data rather than over the assessments, policies and inventories a customer builds in the platform. The document that would answer it, the AI Systems Transparency Report, is described as available upon request rather than published. Searched the trust centre, the legal centre including the contracting explainer, the pricing page and the home page on 1 September 2026.
The agreement grants an affirmative right rather than withholding one. Section 2.1 of the customer agreement has the customer grant Securiti a royalty-free, worldwide, non-exclusive, fully paid-up licence to use Customer Data in order to perform and provide the product and professional services for the customer's benefit **or for the purpose of enhancing product or services**. The second limb is the operative one: it is a service-improvement right with no carve-out for model training, no definition of what enhancement covers, and no opt-out. Two adjacent terms narrow the picture without closing it. Securiti owns System Data, defined as anonymised user and other data about the product used for performance, availability and security reporting, so some improvement use is expressly anonymised. And the CCPA addendum certifies that Securiti will not sell customer personal information and will not retain, use or disclose it outside the direct business relationship or for purposes other than performing the services, which pulls against the enhancement limb for CCPA-covered data specifically. **A buyer cannot tell from the published documents whether its content trains models.**
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is under the customer's control as a product configuration rather than a contractual instruction, which is rarer than the value name suggests. The published contracting explainer states that some services include built-in functionalities for data minimisation including auto-deletion and retention periods, and that OneTrust encourages customers to configure the services to reduce the amount of personal data held in its environment at any point. Alongside that sits an explicit deletion and portability right: customers may delete or export their data in a structured, commonly used and machine-readable format at any time during the subscription term and for up to sixty days after termination, after which remaining data is deleted under a destruction policy. What is not stated is a zero-retention option, and no separate window is published for AI prompts or generated assessments as distinct from customer records generally.
Deletion is customer-initiated with a stated window, and no retention period is published for anything held before that request. Section 17 of the security exhibit provides that a customer may request deletion by filing a support ticket or emailing support, and that on receiving confirmation of the request Securiti will delete all Customer Data from online systems within one business week, retaining data only to the extent and for the period applicable law requires. Customer Data may also be deleted following termination or suspension. That is a real and unusually specific control, and it is a deletion mechanism rather than a retention policy: nothing states how long inputs, classification outputs, assessment records or scan results are kept absent a request, and no zero-retention option is described. The separate privacy notice covers only personal data Securiti holds as a controller and sets qualitative criteria rather than a period.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
OneTrust operates its own documented permission and separation model, and it is described at the tenant and user level rather than below it. The contracting explainer states that customer data is held in a logically-separated cloud database, that each customer receives a single production tenant environment for all subscribed services, and that the customer's own users control access to the cloud services as well as the volume and types of data submitted, with OneTrust not having specific access to what a customer chooses to submit. ISO 27701 certification covers the privacy information management system around it. What is not addressed is separation inside a single customer account: nothing describes walls between teams, business units or matters, which is a live question because the published workflow routes a single AI use case to privacy, security and legal reviewers who sit in different functions.
Securiti operates its own separation model and documents it at the tenant level in concrete architectural terms. The published system description states that the platform uses per-customer virtual database instances to logically separate one customer's data from another's, and that when a customer stops using the service the corresponding virtual database instance is destroyed. It adds a second, unusual control: any customer data identified and catalogued as personal data is subjected to a one-way irreversible hash and stored in that customer's instance, with a commitment that personal data is at no point captured in clear text in logs or databases. Geographic separation reinforces it, since instances serving different regions are described as standalone with no data exchange between them. What is not addressed is separation inside a single customer account: nothing describes walls between business units, teams or matters, and customer-side control is described only as managing which end users receive access, with optional two-factor authentication, IP restrictions and single sign-on.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
A position is published, a transparency report exists, and the notice limb rests on a document other than the customer agreement. The contracting explainer states that OneTrust does not voluntarily disclose or grant access to any personal data of its customers to government authorities unless required by law, and directs the reader to a published policy and transparency report on government and law enforcement requests. The notice commitment located sits in the Mutual Nondisclosure Agreement, which provides that confidential information may be disclosed as required by law or valid legal order after using reasonable efforts to provide notice of the disclosure; that document governs pre-contract confidential information rather than platform data. The Data Processing Addendum PDF, which is where a notice commitment for customer data would sit, was not opened on 1 September 2026, so this row may move up to notice and report on reading it.
A notice commitment exists in the confidentiality clause and goes further than notice alone. Section 4.3 of the customer agreement permits either party to disclose the other's confidential information as required by law, and requires the disclosing party in that event to provide prior written notification, to give the other party the opportunity to contest the disclosure, and to use reasonable efforts to minimise the disclosure to the extent permitted by applicable law. That reaches Customer Data, because the agreement defines Customer Data and information identifying the customer's business practices as the customer's confidential information. A related provision in the security exhibit bars Securiti from informing any third party of a security breach without approval and gives the customer sole right to decide whether affected consumers are notified. Two limits: **no transparency report is published**, and the separate privacy notice describes sharing personal data with regulators, courts and law enforcement in response to a search warrant, subpoena or other valid process without repeating the notice undertaking.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The product does not retrieve primary law, and the reference datasets it does carry are named, which is more than most vendors manage. Three are identified on the pricing page: a database of more than 45 million categorised cookies and trackers behind the consent product; risk intelligence data on millions of third parties behind third-party management; and, named to its provider, Dow Jones ethics and compliance databases supplying politically exposed person, sanctions and watchlist screening in the Third-Party Management Suite. Regulatory change intelligence is attributed to DataGuidance within Privacy Automation. What is absent is the rights basis: no licence, ownership or public-domain footing is stated for any of them, and no update cadence is published beyond the claim that inventories are evergreen. Checked the pricing and packaging page, the home page and the trust centre on 1 September 2026.
The product carries a regulatory knowledge layer whose sources are never identified. Securiti maintains regulation-specific coverage across GDPR, CPRA, LGPD, PIPEDA, PIPL, the EU AI Act, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM Applications and CDMC, publishes a knowledge centre and regulation summaries, and markets a privacy centre described as regulation-intelligent everywhere, all of which implies a maintained corpus of regulatory text and obligations. No regulator feed, publisher, data supplier or licensing basis is named for any of it, and no update cadence is stated. The corpus that matters most for this product is in a sense the customer's own estate rather than a body of law, since the platform's primary intelligence is discovered from the customer's systems, which makes the provenance question narrower here than for a research tool but not absent. Checked the home page, the solutions and regulations navigation and the terms page on 1 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No citator applies and the row is recorded rather than skipped. The platform does not return legal authority whose subsequent history could be checked; it maintains registers, runs assessments and enforces controls. The nearest analogue is regulatory currency rather than treatment: Privacy Automation is described as helping customers understand the operational impact of regulatory changes through DataGuidance intelligence, and the AI Governance package aligns assessments to named frameworks including the EU AI Act, NIST and ISO 42001, so the platform tracks whether a requirement has moved without purporting to tell a user whether an authority still stands. Searched the pricing and packaging page, the home page, the trust centre and the published contracting explainer on 1 September 2026.
No citator applies and the row is recorded rather than skipped. The platform does not return legal authority whose subsequent history a user would need to check; it discovers and classifies data, maps it, and runs privacy and AI governance workflows against regulatory frameworks. The nearest analogue is regulatory currency rather than treatment, and it is asserted rather than described: Securiti maintains dedicated coverage pages for individual regimes and publishes regulation summaries and roundups, without stating how quickly a change in a covered law reaches the assessment templates or compliance checks that depend on it. Searched the home page, the solutions and regulations navigation, the knowledge centre entry points and the terms page on 1 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Nothing located describes what the AI does when it cannot assess reliably. The published workflow shows an AI-assisted assessment returning a risk summary graded medium with findings graded medium and low, so the output carries a severity rating, but a risk grade is a conclusion about the subject rather than a statement of the model's own confidence, and nothing indicates what a user sees when the system cannot reach one. No abstention path, confidence score or coverage indicator is documented. The structural mitigation is the approval gate rather than a model behaviour: every assessment routes to named human reviewers before a use case proceeds, so an uncertain output is caught by process rather than flagged by the system. Searched the home page, the pricing and packaging page, the trust centre and the contracting explainer on 1 September 2026.
Nothing located describes what the system does when it cannot classify or assess reliably. No confidence score, abstention path, coverage indicator or low-certainty flag is published for data classification, sensitive data identification or assessment generation, and the marketing claim runs the other way in asserting accurate classification without qualification. The distinction worth drawing is that Securiti sells uncertainty controls for other systems: context-aware prompt, retrieval and response firewalls sit in front of a customer's large language models, and Agent Commander is marketed on detecting AI risk and undoing AI mistakes. Those are controls over the customer's AI, and none of them is described as operating over Securiti's own classification engine. Searched the home page, the product navigation, the security page and the terms page on 1 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name. No court order, opinion or disciplinary record naming OneTrust was located. This is a statement about the public record rather than a finding about the product. The failure mode this signal tracks fits poorly: the platform's AI output is a risk rating or a piece of model documentation consumed inside a governance workflow and gated by human approval, not a citation to legal authority prepared for filing, so the analogous exposure would be a mis-rated assessment surfacing in a regulatory examination rather than in a court.
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name and on the Gencore product name. No court order, opinion or disciplinary record naming Securiti was located. This is a statement about the public record rather than a finding about the product. The failure mode fits poorly, since the platform's output is a data classification, an assessment record or a consent state rather than a citation to legal authority prepared for filing; the analogous exposure would be a misclassification leaving regulated personal data undiscovered and surfacing in a regulatory examination or a breach investigation.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No engagement with professional responsibility or ethics guidance was located, which is worth separating carefully from what OneTrust does publish. The company engages extensively with regulation as subject matter, naming GDPR, US state privacy laws, the EU AI Act, NIST, ISO 42001, DORA and more than fifty standards and frameworks in its packages, and maintains a public glossary of AI governance and privacy terms. None of that is guidance binding the professional who relies on the output. Nothing references ABA Formal Opinion 512, any state bar opinion, Law Society or SRA guidance, or any equivalent addressed to counsel using AI tools, and no general statement that a user's own professional obligations survive use of the platform was found. Searched the home page, the trust centre, the pricing page, the legal centre and the published contracting explainer on 1 September 2026.
Professional responsibility is engaged in general terms in the agreement and no guidance is named. The disclaimer records that the product augments but does not replace legal and other professional advisors, and section 2.5 states that it is the customer's responsibility to confer as needed with legal counsel to confirm and maintain compliance with applicable laws. That is a real acknowledgement that professional judgement remains with the customer's lawyers, which is more than most vendors in this lane publish, and it names no source. Nothing references ABA Formal Opinion 512, any state bar opinion, Law Society or SRA guidance, or a regulator statement on AI use within a privacy or compliance function. The extensive regulatory material Securiti does publish, covering the EU AI Act, NIST and OWASP, binds Securiti and its customers as developers and deployers rather than binding the practitioner relying on the output.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Savings are quantified and billing treatment is never addressed. A commissioned Forrester Total Economic Impact study is promoted with a 227 per cent three-year return on investment and a seven-month payback, and the GOL customer story gives operational time reductions from thirty days to five or fewer for vendor approval and from a fortnight to minutes for request completion. The buyer is an in-house privacy, legal or risk function rather than a firm billing a client, so the fee question lands obliquely, but it is not absent: outside counsel and consultancies use platforms of this kind on client engagements, and nothing published addresses how AI-assisted assessment work should be disclosed or billed where that happens. No per-matter record of AI-assisted work is described for that purpose, as distinct from the audit-ready evidence the product generates about a customer's own AI systems.
Efficiency and cost claims are made and no billing or disclosure treatment exists. The marketing promises automated data minimisation to reduce cost and risk, elimination of disjointed point products, and acceleration of AI adoption, and the product set is sold on replacing manual privacy operations. Nothing accompanies that on how AI-assisted work should be billed or disclosed. The buyer is an in-house privacy, security or legal function rather than a firm billing a client, so the question lands obliquely, but consultancies and advisers use platforms of this kind on client engagements and nothing addresses that position. No per-matter or per-assessment record of machine-assisted work is described for disclosure purposes, as distinct from the audit and assessment records the product generates about the customer's own compliance posture.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
Half of what a client's AI clause asks for is openly published and the half about AI is obtainable rather than public. On the open side, and this is unusually strong: the Data Processing Addendum, the Standard Contractual Clauses and the Master Terms are all downloadable from the legal centre without an agreement in place, with full version histories, which is precisely the forwardable contractual material the signal contemplates. On the gated side, the subprocessor list is maintained on the customer portal rather than the open trust centre, though with a thirty-day advance notice commitment for changes and a right to object on reasonable data protection grounds. And **no model provider is named anywhere**: the AI Systems Transparency Report is described as available upon request. Under the coverage test a firm therefore cannot tell its client which systems see its content without first contracting or requesting, which is what places this at the request tier rather than higher.
The contractual half is obtainable and the disclosure half does not exist. A data processing agreement is published, with the customer agreement directing customers to download and execute Securiti's DPA from its website, and a CCPA service provider addendum is reproduced in full on the terms page, so forwardable contractual material is available. Against that, **no subprocessor list is published anywhere**: the privacy notice identifies recipients only as categories such as IT service providers, email marketing providers and cloud and software service providers, and the CCPA addendum has the customer pre-approve transfers to Securiti's other entities, service providers, third parties and vendors without naming any of them. **No model provider is identified at any point**, and AWS and GCP are named as infrastructure rather than as model providers, which under the coverage test does not answer the question. The SOC 2 report is available on request. A firm therefore cannot tell its client which systems see its content without contracting first.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
There is an inversion worth naming here: OneTrust sells the capability to produce exactly this record about a customer's own AI, while its own equivalent is available on request. The AI Governance package automates model documentation, audit-ready evidence and regulatory reporting outputs, configures approvals, attestations and evaluation gates, and correlates runtime behaviour with purpose, data sensitivity and regulatory obligations, which is a disclosure record about the customer's systems. For OneTrust's own AI, the published workflow logs a review and approve step naming privacy, security and legal reviewers, so who signed off is captured. What is not established is whether that record identifies which output was machine-generated or which model produced it, and no document-level export covering model, sources and verification is described. OneTrust's own AI Systems Transparency Report is available upon request rather than published.
Part of the record exists and it is aimed at a regulator rather than a court, with the same inversion seen across this lane. The platform generates records of processing activity, assessment records demonstrating compliance, data subject request logs from intake through secure report delivery, breach impact analyses and notification records, and audit controls described in the security exhibit as mechanisms that record and examine activity in systems containing customer data. That is a defensible account of what was assessed and when, which is what a supervisory authority asks for. What it does not do is identify the machine's contribution: nothing states that the record captures which classifications or assessment outputs were machine-generated, which model produced them, or who verified them, and no per-document export tying an output to its model and reviewer is described. Securiti's own AI use is not covered by any published transparency artifact.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- Good Law Verification
- Refusal and Uncertainty Behaviour
Which one fits
Choose OneTrust if
- You have to evidence a vendor, not just believe it. OneTrust's trust centre publishes SOC 2 Type II reports, ISO 27001, 27701, 27017 and 9001 certificates and a statement of applicability as direct downloads with no form, no email capture and no NDA, alongside a 2026 penetration test executive summary and a PCI attestation of compliance.
- You want to read the contract before the sales call. The Master Terms sit at version 5.1 effective 23 March 2026 with every prior version back to 2020 downloadable beside the data processing addendum and standard contractual clauses, and the cap runs to total annual fees rather than fees for the affected service, with intellectual property claims and willful misconduct uncapped.
- You need to hold less data rather than explain why you hold it. The services ship data minimisation functionality including auto deletion and retention periods that OneTrust encourages customers to configure down, and customers may delete or export their data in a machine readable format at any time during the term and for sixty days after it ends.
Choose Securiti if
- You want recourse that reaches the vendor's own handling of your data. Securiti's indemnity covers third party claims arising from its use or disclosure of customer data in breach of the agreement as well as intellectual property claims, the cap is the lesser of twelve months of fees or one million dollars, and it publishes insurance cover of not less than three million dollars for errors and omissions, professional liability and cyber.
- European data cannot leave Europe. Securiti runs a separate EU production cloud with its own endpoint and status page, states that each instance serves a specific geography with no data exchange between instances, and describes per customer virtual database instances that are destroyed when a customer stops using the service.
- You want incident and deletion mechanics with clocks on them. Securiti commits to notifying a security breach no later than seventy two hours after becoming aware, by email with read receipt, leaves the decision on notifying affected consumers with the customer, and deletes all customer data from online systems within one business week of a confirmed request.
In summary
OneTrust
OneTrust is a governance platform for privacy, data and AI, sold to privacy, security and risk, data and marketing teams across privacy automation, consent and preferences, AI governance, tech risk and third party management. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes, with A grades on AI safety and data stewardship, AI liability and recourse, and security certifications. Its trust centre publishes SOC 2 Type II reports, ISO 27001, 27701 and 27017 certificates and a statement of applicability as direct downloads with no form or NDA, and its Master Terms sit at version 5.1 effective 23 March 2026 with every prior version available. As of 1 September 2026 the index located no named model or provider and no position on whether customer content trains models.
Securiti
Securiti sells the DataAI Command Platform, built on a knowledge graph that maps data and AI across hybrid cloud, SaaS and on premise estates, with a privacy pillar covering data mapping, subject requests, assessments, consent and breach management that privacy counsel own. The AI Legal Index grades it in the top two bands on nine of fifteen capability axes, with an A on AI liability and recourse: the agreement carries an indemnity reaching Securiti's own misuse of customer data, a cap at the lesser of twelve months of fees or one million dollars, and published insurance cover of not less than three million dollars. It runs a separate EU production cloud with no data exchange between instances. As of 1 September 2026 the index located no trust centre, no named subprocessor and no AI governance material covering Securiti's own models.
Questions buyers ask
OneTrust vs Securiti: which is better for a privacy team?
The AI Legal Index places OneTrust in the top two bands on ten of fifteen capability axes and Securiti on nine, which is close enough that the tie breaks on specifics rather than totals. OneTrust publishes its contracts and its attestations openly, so a reviewer can evidence it without asking. Securiti publishes the stronger recourse position, including a data handling indemnity, a stated liability ceiling and insurance cover, and a separate EU production cloud. Neither states whether customer content trains models.
Does Securiti use customer data to improve its products?
Section 2.1 of Securiti's customer agreement grants it a royalty free worldwide licence to use customer data to perform the service or for the purpose of enhancing product or services. That second limb carries no carve out for model training and no definition of enhancement. Two other terms narrow it: Securiti separately owns anonymised System Data about product performance, and its CCPA addendum certifies that covered personal information will not be retained, used or disclosed outside the direct business relationship. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
What can you download from OneTrust's trust centre?
Directly and without an NDA: SOC 2 Type II reports, ISO/IEC 27001, 27701, 27017 and ISO 9001 certificates, and a statement of applicability showing which controls are in scope. Alongside them sit a 2026 penetration test executive summary, a PCI DSS attestation of compliance signed November 2025, a HITRUST certification letter, a completed standard SIG questionnaire and disaster recovery exercise memos. Its Master Terms, data processing addendum and standard contractual clauses are published separately with version histories. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
What happens if the vendor mishandles your data?
Securiti publishes more of the answer. Its indemnity covers claims arising from its own use or disclosure of customer data in breach of the agreement, it commits to breach notification no later than seventy two hours after becoming aware, and it publishes insurance cover of not less than three million dollars maintained through the term and for two years after. OneTrust commits to notification without undue delay and publishes no insurance position at all. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
What do OneTrust and Securiti both leave unpublished?
Neither names a model or a provider behind the AI inside its own platform. Neither publishes an accuracy measurement for the classification or assessment output a compliance officer acts on. Neither publishes a price, although OneTrust publishes the charging meter for every package. Neither describes separation inside a single customer account, only between customers. And neither names a bar or professional guidance instrument, though Securiti's agreement does tell the customer to confer with legal counsel. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
One thing cuts against each side. Securiti's agreement grants a licence to use customer data to perform the service or for the purpose of enhancing product or services, with no carve out for model training and no definition of what enhancement covers, so a buyer cannot tell from the published documents whether its content trains models. Two adjacent terms narrow that without closing it: a separate anonymised System Data definition, and a CCPA addendum certifying no retention, use or disclosure outside the direct business relationship. OneTrust publishes far more paperwork and does not answer the same question in any of it, and its AI Systems Transparency Report is available on request rather than published. Both records were verified on 1 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.