OneTrust vs Transcend: how they compare in 2026
OneTrust and Transcend are direct competitors in privacy operations, and they compete on different things. OneTrust sits in the top two bands on ten of fifteen axes and Transcend on eight. OneTrust's advantage is that a buyer can verify it without asking: its trust centre publishes SOC 2 Type II reports, ISO 27001, 27017 and 27701 certificates and a statement of applicability as direct downloads with no form and no non disclosure agreement, and its master terms are published in full with every version back to 2020, capping liability at total annual fees, a figure it points out is broader than the more common per service cap, with intellectual property claims and wilful misconduct uncapped. Transcend competes on architecture. Sombra runs inside the customer's own infrastructure so integration requests never expose data to the vendor, the customer keeps its own API keys, and its agreement bars it from using inputs or outputs to train its AI features except for that customer's benefit.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Artificial intelligence is present, shipped and contractually confirmed, and it is a layer on a product whose value stands entirely without it. The core is registry and workflow software: a data and activity map, consent banners and preference centres, data subject request automation, vendor and third-party inventories, assessment templates across more than fifty standards, and policy approval workflows. Remove every model and all of that continues to work, which is the distinction this axis asks about. Where AI appears it accelerates an existing step rather than constituting one, with an AI-assisted risk assessment producing a summary and key findings that then route to human approval. Worth separating two things that are easy to conflate here: OneTrust sells AI governance as a subject matter, maintaining registers of a customer's models, agents and datasets and applying runtime controls to them, and that is the product managing someone else's AI rather than the product being AI. The Master Terms confirm the vendor's own use, answering the question of whether AI is used in the services with a plain yes.
The decision layer is rules, not models, and the vendor says so in its own framing. Transcend's pitch is policy as code: business policy, jurisdictional regulation and consent encoded into a deterministic real-time decision that systems and agents call before acting. That is deliberately not inference, and the marketing leans on it, promising every use defined and enforced with audit-ready records. AI Features do exist and are defined contractually as large language models or other machine learning features of the Services, and the AI-related use cases are largely about governing someone else's models, honouring do-not-train signals through data pipelines and clearing data for AI initiatives. Strip the models out and the product a buyer pays for remains intact: the permissioning layer, consent propagation, DSR fulfilment, the Sombra gateway and the integration estate. Third consecutive privacy platform at this grade for the same structural reason.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is not asserted loudly and it is not measured either, and the document that would answer it is obtainable rather than published. The AI-assisted assessment shown on the home page produces a risk summary and graded findings across personal data processing, model accuracy and transparency, which is an output a compliance officer will act on, and no accuracy rate, benchmark, test set or error mode for it was located on any public surface. Several limbs of this axis do not bite: the product does not retrieve primary legal authority, so grounding to openable sources and citator checking are not the relevant questions, and the applicable risk is a wrong risk rating rather than a fabricated citation. The AI Systems Transparency Report is the artifact that would carry this and the Master Terms describe it as available upon request, which under the gated-is-not-absent rule is the middle tier rather than an absence, but its contents could not be read on 1 September 2026. Checked the home page, the trust centre, the pricing and packaging page and the published contracting explainer.
Accuracy is asserted in the marketing, measured nowhere, and disclaimed squarely in the agreement. The claims are quantified but unsourced: 174 billion automated data decisions, 99 per cent addressable audience per purpose, column-level classification updated in real time, and a customer quote putting data visibility at roughly 100 per cent. Against that, section 7.4 of the services agreement disclaims any warranty that the Services, **including any Outputs from the AI Features, are accurate, complete, or reliable**, which is the most direct AI-output accuracy disclaimer located anywhere in this pull and is the more candid of the two positions. No precision or recall figure, benchmark or error rate for classification or for the AI Features was located on any surface read on 1 September 2026. The retrieval-and-citation limbs of this axis do not apply, since the product returns permissioning decisions rather than legal authority.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A review point is not merely claimed but drawn, with named roles, and the surrounding control structure is incomplete. The AI use case workflow published on the home page runs intake, then AI risk assessment, then a review and approve stage showing three pending reviewers identified as Privacy, Security and Legal, then continuous monitoring described as real-time oversight and alerts after workflow completion. That places the machine output before a human gate and says who holds it, which is more than most vendors in this lane publish. The AI Governance package reinforces it commercially, listing configurable approvals, attestations and evaluation gates before AI systems move to production, and runtime controls across prompts, outputs, data access and allowed AI actions. What is missing is the rest: nothing states what the assessment does unattended, at what confidence it defers, or what happens after it is wrong, and no statement was located about the behaviour of OneTrust's own models as distinct from the governance gates it sells.
Human involvement is offered as a configuration option and never described as a control over model output. The home page states that policy as code runs with humans in the loop only where you want them, and elsewhere that the review queue is encoded automatically and that runtime policy enforcement replaces manual compliance reviews. That is a claim about where a customer may choose to place a checkpoint, and the product's selling proposition is explicitly the removal of manual review, so the axis has to ask what happens when an automated decision is wrong. Nothing located answers it: no confidence threshold, no deferral path, no description of a review surface for the AI Features specifically, and no remediation route beyond the audit record. Two things pull in the customer's favour and belong on the record: every decision is logged with system-level proof, and section 3.3 of the agreement gives the customer a perpetual licence in Outputs while retaining its rights in Inputs, so the customer controls what it does with what the system produces.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
A named customer, a named individual and real figures are published, and nothing carries a date. The GOL customer story quotes Bruna Boccini, Head of Compliance and Data Protection Officer at the airline, and gives specific before-and-after numbers in her own account: vendor approval falling from almost thirty days to between five and zero, and request completion falling from fourteen or fifteen days to a few minutes, against a described estate of seven billion identifiers and thousands of data flows and vendors. A commissioned Forrester Total Economic Impact study adds a 227 per cent three-year return and a seven-month payback, which is a figure attached to a documented methodology a reader can assess. Around those sit a large named logo set including Adobe, Samsung, Pfizer, Walgreens, Aetna, Atlassian, Maersk and Bristol Myers Squibb, and a claim of more than 14,000 customers with more than half the Fortune 500. What holds this below the top band is dating: no located customer story or study carries a date, and the operational figures are the interviewee's own account rather than a measured study.
One named customer with a named individual, and no figures attached to either. Robinhood is named on the home page with a quote from Karthik Rangarajan, Head of Security, describing Transcend's role in giving customers control over their data. A second quote is attributed to a named chief executive with **no organisation identified**, which is unusual and reduces its value. The security page carries two further quotes attributed by role and sector only, a CISO and data protection officer at a global staffing firm and a chief information security officer at a global fintech, the latter carrying the only outcome figure located, data visibility improved to roughly 100 per cent. Platform-level claims of 1.9 billion dollars of revenue unlocked, 174 billion automated decisions and 418 million operations and agents governed are unsourced and carry no method. IDC recognised Transcend as a Leader in its 2025 MarketScape for worldwide data privacy compliance software. A customer stories library exists and **was not opened on 1 September 2026**, so a dated outcome with figures was neither located nor excluded.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The published commitments are substantive and contractual, and the training question is not answered. What a buyer can read before signing: a Data Processing Addendum published openly with version history, purpose limitation providing that personal data is processed only for the limited purposes described in the agreement and that OneTrust will not buy or sell customer personal data, customer retention of ownership of all data input into the services, tenant separation with data held in a logically-separated cloud database and a single production environment per customer, ISO 27701 certification for privacy information management, and deletion or export rights exercisable at any time during the term and for sixty days after it ends. Against that, nothing located states whether customer content is used to train or improve models, which is the first question this axis asks and a conspicuous silence for a company selling AI governance; the position on third-party model providers is equally absent; and privilege and work product are never mentioned, which matters because the platform is sold to privacy counsel and the workflow assigns a legal reviewer.
This is the strongest confidentiality record in the lane and it stops short of the top band on two named limbs. What carries it. **Section 3.3 of the services agreement provides that Transcend may not use Inputs or Outputs to train or otherwise improve AI Features except solely for the benefit of the Customer**, which is a contractual training prohibition rather than a policy statement, and the only one located in this lane. The Customer Data licence at 3.2 is drawn narrowly, solely to provide the Services, with improvement rights confined to Usage Data that excludes Customer Data. Architecture reinforces the contract: Sombra runs inside the customer's own infrastructure, the customer retains its own API keys with optional delegation to its own key management service, and Transcend states it cannot connect to customer systems directly and does not see the data. Customer Data is defined as the customer's Confidential Information, compelled disclosure carries a prior-notice obligation, and the DPA commits to deletion within thirty days of termination on request. What is absent is privilege and work product treatment, which is never mentioned despite a named Privacy, Legal and Risk buyer, and any position on third-party model providers behind the AI Features.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Nothing located addresses the line between an information tool and legal advice, on a product that produces compliance determinations for a professional audience. The platform assigns risk ratings, generates assessments against named regimes including the EU AI Act, GDPR and US state privacy laws, and routes them to a reviewer identified as Legal, so the output is consumed as a compliance judgement. What is published in its place is a performance commitment rather than an advice-line position: the Master Terms warrant that the cloud services will materially conform to the OneTrust User Guide throughout the subscription term. No statement was located that outputs are not legal advice, that OneTrust is not a law firm, that no professional relationship arises, or that a user should take advice on their own facts, and no jurisdiction limit or supervision and competence discussion appears. **This is the row most likely to move on this record**: the Master Terms PDF itself and the Legal and Compliance Information page were not opened on 1 September 2026, and a disclaimer may sit in either, so the grade rests on the home page, trust centre, pricing page and published contracting explainer.
A responsibility allocation sits in the terms while the marketing sells the removal of legal review. Section 7.4 of the services agreement states that the customer is solely responsible for its compliance with any laws and that Transcend disclaims all liability related to that compliance, and section 2.3 requires the customer to obtain the permissions and consents and comply with the privacy laws necessary for the Services to operate. That is a clear allocation of who owns the legal judgement, and it is not a statement about the line between an information tool and legal advice: nothing located says the output is not legal advice, that no professional relationship arises, or that a user should take advice on their own facts, and no jurisdiction limit or supervision dimension appears. The tension is sharper here than elsewhere in the lane because of how the product is sold, with the marketing promising real-time campaign clearance and **no three-week legal review cycles**, which is an explicit offer to displace a legal review step, published alongside a disclaimer of all liability for the compliance outcome.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A governance framework with real substance is published and its results are not. The trust centre states that OneTrust's AI governance programme is managed by an interdisciplinary AI Governance Committee, supported by AI governance processes across the organisation and the AI systems lifecycle, an internal AI use policy and employee training. That is an accountable body, a lifecycle scope and two named instruments rather than a list of adjectives, and it is backed by a dedicated Responsible AI section, a published Journey to AI Governance toolkit and an AI Systems Transparency Report. Two things keep it below the top band. No individual is named as accountable, the committee being identified only by function. And nothing has been disclosed about uneven output: no bias evaluation, no testing regime and no result appears on any public surface, which is a notable gap for a vendor whose own product sells bias and drift monitoring to others. The AI Systems Transparency Report is available on request rather than published, so it sits in the middle disclosure tier and its contents were not read.
Nothing published addresses governance of Transcend's own models. The company publishes a substantial amount about AI governance as a subject, including an AI Governance solution built around do-not-train enforcement and a blog arguing that AI governance is enforcement rather than documentation, and all of it concerns the customer's AI rather than Transcend's. No responsible-AI page, AI policy, ethics statement, governance committee, named accountable owner, pre-release testing regime or bias evaluation was located. The site navigation and the full footer were read on 1 September 2026 across platform, solutions, partners, resources, company and developer sections, and contain no such surface. Two things sit adjacent without answering the axis and are credited elsewhere to avoid spending one fact twice: the contractual no-training term is a data commitment and is credited on confidentiality, and the open-source repositories and public documentation are engineering transparency rather than model governance. **The third vendor in this lane to sell AI governance while publishing none of its own.**
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Every limb this band names is published, current and specific enough to hold the vendor to, and this is the strongest stewardship record located in the corpus. Retention is customer-configurable rather than merely stated, with services shipping built-in data minimisation functionality including auto-deletion and retention periods, and OneTrust expressly encouraging customers to configure them down. Deletion is contractual and time-bounded: customers may delete or export their data in a structured, commonly used and machine-readable format at any point during the term and for up to sixty days after termination, after which remaining data is deleted under a destruction policy. Access control runs through customer-administered user access plus ISO 27001, 27017 and 27701 certification, with the security obligations set out in Appendix 1 of the published DPA. Subprocessors are maintained on a list with a thirty-day advance notice commitment for changes and a right to object on reasonable data protection grounds, remedied by an alternative provider or termination of the affected subscription. Incident practice is stated: notification without undue delay, continuing updates on material developments, and cooperation with the customer's own reporting obligations. Encryption is given concretely at AES-256 at rest and in backup and a minimum of TLS 1.2 in transit, and the trust centre publishes a 2026 penetration test executive summary alongside disaster recovery and business continuity exercise memos. The one soft edge is that the subprocessor list itself sits on the customer portal rather than the open trust centre.
Every limb this band names is published, specific and dated, in a data processing addendum last updated 27 August 2026. Retention and deletion: on termination Transcend deletes all Customer Personal Data in its possession or control within a maximum of thirty days of a customer request, with backup copies securely isolated and protected from further processing, and absent a request deletion follows standard retention policies. Incident practice: notification without undue delay and **within seventy-two hours** of becoming aware of a Security Breach, with a specified content list covering the nature of the breach, categories and approximate numbers of data subjects and records, likely consequences and measures taken. **Subprocessors are named on a maintained public list** at the documentation site, with fifteen days' prior notice of additions, a commercially reasonable objection route and a mutual termination right if no cure is available. Access control is described concretely: SSO with enforced MFA, least privilege and role-based access, segregation of duties, and quarterly access reviews. Encryption is AES-256 at rest and TLS 1.2 or higher in transit, with annual third-party penetration testing, threat modelling at design, static analysis and dependency checking in the code pipeline, and daily backups tested at least annually. Transfers run on the EU SCCs with module and clause elections set out, the UK addendum and the FADP variations.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
What the vendor stands behind is published, specific, versioned and independently assessed, which no other record in this pull matches. The Master Terms of Service are published in full at a dedicated legal centre, currently version 5.1 effective 23 March 2026, with every prior version back to August 2020 downloadable alongside the DPA, Standard Contractual Clauses, Business Associate Agreement and product-specific supplemental terms. The liability position is stated and benchmarked rather than buried: a cap on each party's liability equal to the total annual fees paid or payable in the preceding year, which OneTrust expressly notes is broader than the more common cap tied to fees for the applicable service only, with willful misconduct and intellectual property claims carved out and uncapped. An indemnity with stated scope covers third-party IP infringement claims arising from use of the cloud services, with OneTrust controlling the defence. A warranty a buyer can invoke commits the cloud services to conform materially to the User Guide throughout the term. OneTrust also publishes a plain-language explainer, Contracting with OneTrust, setting all of this out for a reviewer, and states plainly what it will not do, refusing uncapped liability for data breach and giving its reasoning. The Master Terms carry an independent TermScout assessment rating them 70 per cent customer favourable with a perfect score against buy-side deal breakers. What is absent is anything specific to AI output being wrong and any insurance position.
The allocation is published, current and readable, and the indemnity is narrower than the best in this corpus. What is there: a services agreement last updated 9 July 2026, published openly and independently assessed under the TermScout certification programme; a mutual cap at fees paid or payable in the twelve months before the event; a defined set of Excluded Claims sitting outside the cap covering customer breaches of use restrictions, indemnity amounts payable to third parties, and either party's breach of confidentiality; a conformance warranty that the Services will operate in substantial conformity with the Documentation and that functionality will not be materially reduced during the term, with correction, re-performance or a refund of prepaid fees as the exclusive remedy; and, unusually, a **standalone warranty that Transcend will comply with all applicable laws in providing the Services**. Two things hold it below the top band. The Transcend indemnity covers third-party intellectual property claims only, with no indemnity for misuse or unauthorised disclosure of Customer Data, and the confidentiality carve-out from the cap **expressly excludes claims related to Customer Data**, so a data incident stays inside the twelve-month cap. No insurance position was located. Nothing addresses an AI output being wrong except to disclaim it.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integration is plainly a real part of the offering and no individual connection could be named from the surfaces read. A dedicated Integrations page sits in the platform navigation and is described as an extensive set of integrations for adding data management to existing workflows, the Third-Party Management package refers to automating vendor assessments with ecosystem integrations, the Consent product is described as scaling through APIs to collect and enforce consent across emerging channels, and some services ship components that a customer implements on its own systems and websites such as cookie consent scripts and data discovery agents. OneTrust is additionally distributed through the Azure Marketplace, which has its own published supplemental terms. What is missing is the naming and the depth: no specific system is identified anywhere on the pages read, no API reference or developer documentation was located, and nothing describes what moves in which direction. **The Integrations page was not opened on 1 September 2026**, so this grade is rebuttable upward on one fetch and is recorded conservatively rather than assumed.
Named systems, a described flow and public developer documentation, short of a stated approach to what is not covered. Integrations are named across the home and security pages and span the categories that matter for this product: identity and HR in Okta and Workday, data platforms in Databricks, AWS and Azure, communications in Slack and Twilio, marketing in Google Ads and AdRoll, and productivity in Google Workspace, with Segment named in the agreement as a worked example of a customer third-party service. What moves is described rather than implied: consent decisions propagate to the CDP, ad tech and loyalty systems, DSR fulfilment runs across connected systems and returns system-level proof, and every request passes through Sombra tokenised, authenticated and encrypted before reaching Transcend. The connector model is real and documented, with public documentation at docs.transcend.io, an API described as MCP-native for agent access, and open-source repositories published on GitHub. **The integrations library and the documentation site were not opened on 1 September 2026**, so depth beyond the named systems was not verified and this grade is deliberately conservative.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The tenancy model is stated plainly, residency is offered, and the processing question is left open. The published contracting explainer describes cloud services delivered on a shared architecture, codebase and infrastructure, with customer data held in a logically-separated cloud database and each customer receiving a single production tenant environment, with non-production environments included in some subscriptions and further environments purchasable. Residency is a customer choice: customers can select from various geographic hosting locations for their tenant environment. What changes between tiers is also addressed, with HIPAA-compliant and PCI-compliant environments available for customers with specialised requirements, backed by a published PCI attestation of compliance and a HITRUST certification. Two things hold it below the top band. The available regions are referred to collectively rather than enumerated, so a buyer cannot see the list without asking. And where processing happens is nowhere distinguished from where data is stored, which matters for the AI features specifically since no model or provider is identified.
The deployment model is the clearest in the lane and the residency detail is thin. Transcend publishes a genuine two-part architecture rather than a hosting note: a hosted control plane, and **Sombra, a security gateway the customer deploys inside its own infrastructure**, through which every integration request passes. The consequences are stated concretely, that customer data never leaves the customer environment, that Transcend cannot connect to customer systems directly, and that the customer retains its own API keys with optional delegation to its own key management service for hardware-backed key management. The data processing addendum confirms the effect in its transfer schedule, recording that where the customer uses Sombra the scope of personal data collected is narrower because it is an on-premises solution using end-to-end encryption. That answers where processing happens more directly than a region list would. What is missing is the region list itself: the DPA states that by default customer data is stored and processed in a secure cloud environment hosted on AWS, and no available regions are enumerated, no residency option is offered, and nothing describes what changes between deployment tiers.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
This is the trust centre the band describes and the first record in this pull to reach the top of this axis. Attestations are current, independent, and downloadable directly as PDFs with no form, no email capture and no NDA click-through: a SOC 2 Type II report, a second SOC 2 Type II for Certification Automation, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27017 and ISO 9001 certificates, and, decisively for the scope limb, **a published Statement of Applicability** setting out which controls are in scope. Industry and sector records sit alongside them: a PCI DSS attestation of compliance signed November 2025 with a third-party responsibility matrix, a HITRUST certification letter, TISAX, TX-RAMP, the Spanish ENS conformity statement, and a CAIQ v4.0.3 self-assessment lodged on the Cloud Security Alliance STAR registry. Security documentation goes beyond certificates to a 2026 penetration test executive summary, a completed standard SIG questionnaire, a security, privacy and architecture whitepaper, and disaster recovery and business continuity exercise memos, with a live system status page. Under the gated-is-not-absent tiers this is open publication rather than the self-serve request tier, which is what separates it from every other record graded on this axis so far.
The standards are named and none of the confirming detail is published. The security page states that Transcend regularly attains SOC 2 Type II and ISO 27001 compliance and displays the AICPA SOC and ISO 27001 marks, and the data processing addendum repeats both, recording that Transcend has obtained SOC 2 Type II certification and maintains an ISO 27001 certification with its security and privacy programmes externally audited annually. Supporting practice is described in more depth than most: annual third-party penetration testing, external audits, threat modelling in the design phase, static code analysis and dependency checking in the pipeline, manual application security testing, and alignment claimed to the Cloud Computing Compliance Controls Catalogue, the NCSC Cloud Security Principles and NIST cloud standards. What is absent is everything that would let a buyer verify it. **No trust centre exists and no report is downloadable or stated to be available on request**; no auditor or certification body is named for either standard; and no certificate date, examination period or scope statement appears. The phrase regularly attains is looser than a current certification claim and is recorded as the vendor's own wording.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
AI use is confirmed and nothing underneath it is identified publicly. The Master Terms answer the question of whether OneTrust uses artificial intelligence in the services with a plain yes, and direct the reader to the AI Systems Transparency Report, described as available upon request. No model, model family, provider or architecture is named on any public surface read on 1 September 2026, and no statement excludes a third-party foundation model either, so a customer cannot tell from published material whose model processes the assessments and documentation it generates. Where inference runs is not addressed separately from where data is stored. No commitment to notify customers when the model set changes was located, though the subprocessor change process does carry a thirty-day notice commitment and would capture a model provider engaged as a subprocessor. This sits above the bottom band because a dedicated transparency artifact exists and is obtainable rather than absent, which is the middle disclosure tier, and below the band above because nothing is actually named where a reader can see it.
The AI Features are defined and nothing underneath them is identified. The services agreement defines AI Features as large language models or other machine learning or artificial intelligence features of the Services, which confirms that third-party model categories are in play, and no model, model family or provider is named on any surface read on 1 September 2026, nor is one excluded. A misreading worth guarding against: OpenAI and Perplexity appear in the integration strip on the home and security pages, and they sit there as customer systems Transcend connects to on the customer's behalf, not as providers of Transcend's own AI Features. AWS is named as the default hosting environment in the DPA, which identifies infrastructure rather than models. No commitment to notify customers when the model set changes was located. The maintained subprocessor list is the surface most likely to resolve this, since a model provider processing customer personal data would have to appear on it, and **that list was not opened on 1 September 2026**, so this grade is rebuttable on one fetch.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The unit and the structure are published in more detail than anywhere else in this corpus, and no figure appears. A dedicated pricing and packaging page sets out nine named packages across five solution families, each with its key capabilities listed so the feature split between base and suite editions is visible, and, unusually, **each with its own charging meter stated explicitly**: AI Governance priced on admin users and AI inventory; the Consent Management Platform on average daily visitors aggregated across channels and properties; Universal Consent and Preference Management on total data subject profiles captured; Privacy Automation on users and privacy asset inventory; Tech Risk and Compliance on admin users and asset inventory; and Third-Party Management on admin users and third-party inventory. Published FAQs explain what a solution package is, that pricing runs on value-based usage meters, and that a tiered model applies with an account executive moving a customer up a tier when usage consistently exceeds limits. What is absent is the number: no rate, band, floor or currency appears anywhere, every package routes to a Get Pricing form, and nothing states what implementation or professional services add.
No pricing information is published at any level, including the unit of charge. The site navigation and the full footer were read on 1 September 2026 across platform, solutions, partners, resources, company and developer sections and contain no pricing page; every commercial route is a demo request. What the published agreement supplies is billing mechanics rather than price or structure: fees are set in an order form, invoice or an in-account billing page, payable in US dollars, invoiced in advance with usage-based fees possibly invoiced monthly in arrears, non-refundable and not subject to set-off, with subscriptions auto-renewing and Transcend able to revise rates on forty-five days' notice before renewal, and past due amounts carrying 1.5 per cent monthly. Usage limits are said to be set in the order form or documentation without naming what is metered. A separate Customer Support document defines support tiers with a Standard tier included at no additional charge, which is the only tier structure published anywhere and concerns support rather than the platform.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described across three deliberate axes with substance behind each, and the boundary is left open. Solutions are organised by function into six families, by role into data, marketing, privacy, and security and risk teams, and by regulation with dedicated pages for GDPR, US privacy law and the EU AI Act plus a wider regulatory index. Practice depth is real: the Tech Risk and Compliance package cites templates and guidance across more than fifty standards, regulations and frameworks, the AI Governance package names the EU AI Act, NIST and ISO 42001 as the frameworks assessments align to, and third-party screening reaches politically exposed persons, sanctions and watchlists through Dow Jones data. The customer base spans regulated industry, retail, pharmaceutical, technology and non-profits on the published logo set. Two gaps keep it here. Nothing states where the product stops, with no statement of organisation size, data volume or the situations it does not fit. And the By Role navigation, which is where a legal buyer would look, offers privacy, security and risk, data and marketing teams and **no page for legal or counsel**, even though the product's own published workflow assigns a legal reviewer.
Coverage is segmented three ways with real pages behind each, and the boundary is left open. By team, five audiences each have their own page, and **one of them is Privacy, Legal and Risk**, which makes Transcend the only vendor in this lane so far to address a legal function on a surface of its own rather than only through a compliance or data label. By use case, five are named and are specific rather than generic: AI transformation and do-not-train, personalisation and audience activation, retail media networks, loyalty and multi-brand programmes, and regulated and sensitive data use. By business type, six are named: AI, consumer, healthcare, fintech, media and business-to-business. The use-case set is unusually revealing about who the product is really for, since retail media networks and loyalty programmes point at consumer-facing enterprises with large first-party data estates rather than at regulated industry generally. What is not stated is where the product stops: no organisation size, data volume, jurisdiction or system type is identified as out of scope, and the regulated and sensitive data use case is framed as a capability rather than a limit.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way, which is the single most surprising gap on this record. OneTrust publishes a Master Terms of Service, a Data Processing Addendum and Standard Contractual Clauses openly with full version histories, confirms in the contracting explainer that artificial intelligence is used in the services, and states that personal data is processed only for the limited purposes described in the agreement and that customer personal data will not be bought or sold. None of that reaches model training. The purpose limitation is the nearest thing and it is a general processing restriction rather than a training prohibition, and it is expressed over personal data rather than over the assessments, policies and inventories a customer builds in the platform. The document that would answer it, the AI Systems Transparency Report, is described as available upon request rather than published. Searched the trust centre, the legal centre including the contracting explainer, the pricing page and the home page on 1 September 2026.
**The first contractual no-training commitment located in this lane.** Section 3.3 of the Online Services Agreement defines AI Features as large language models or other machine learning or artificial intelligence features of the Services, defines Inputs as customer data submitted to them including prompts and queries, and provides that Transcend may not use Inputs or Outputs to train or otherwise improve AI Features, except solely for the benefit of the Customer. It sits in the agreement itself rather than in a policy page, so it binds. Two supporting terms narrow the surrounding position in the same direction: the Customer Data licence at 3.2 is granted solely to provide the Services, and the improvement right Transcend does reserve is confined to Usage Data, which is defined to exclude Customer Data and must be aggregated and anonymised before it appears in any published material. The customer retains all intellectual property rights in its Inputs. The one limit worth recording is the carve-out itself, since improvement solely for the customer's benefit is undefined.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is under the customer's control as a product configuration rather than a contractual instruction, which is rarer than the value name suggests. The published contracting explainer states that some services include built-in functionalities for data minimisation including auto-deletion and retention periods, and that OneTrust encourages customers to configure the services to reduce the amount of personal data held in its environment at any point. Alongside that sits an explicit deletion and portability right: customers may delete or export their data in a structured, commonly used and machine-readable format at any time during the subscription term and for up to sixty days after termination, after which remaining data is deleted under a destruction policy. What is not stated is a zero-retention option, and no separate window is published for AI prompts or generated assessments as distinct from customer records generally.
Deletion is committed with an outer limit and no standing retention period is published. Section 9 of the data processing addendum provides that on termination or expiry Transcend will, at the customer's election and written request, delete all Customer Personal Data in its possession or control as soon as reasonably practicable and within a maximum of thirty days, with the exception of data it must retain by law and data archived on backup systems, which it will securely isolate and protect from further processing. Absent such a request, deletion follows Transcend's standard retention policies, which are not published. The transfer schedule states retention only as the period needed to accomplish the purposes of processing. Nothing separates prompts submitted to the AI Features or their Outputs from customer data generally, and no zero-retention option is described. The architecture reduces the exposure structurally, since data handled through the self-hosted Sombra gateway is described as never leaving the customer's environment.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
OneTrust operates its own documented permission and separation model, and it is described at the tenant and user level rather than below it. The contracting explainer states that customer data is held in a logically-separated cloud database, that each customer receives a single production tenant environment for all subscribed services, and that the customer's own users control access to the cloud services as well as the volume and types of data submitted, with OneTrust not having specific access to what a customer chooses to submit. ISO 27701 certification covers the privacy information management system around it. What is not addressed is separation inside a single customer account: nothing describes walls between teams, business units or matters, which is a live question because the published workflow routes a single AI use case to privacy, security and legal reviewers who sit in different functions.
Transcend documents its own separation model and answers the question architecturally rather than by tenancy. Sombra is a security gateway the customer deploys inside its own infrastructure, and Transcend states that it enforces every data decision under the customer's security policies, that customer data never leaves the customer environment, and that Transcend does not see it. The key position is stated in the same terms: Transcend's backend never has access to customer API keys, Sombra manages that access with a built-in key management system that can optionally delegate to the customer's own service such as AWS KMS for hardware-backed keys, and Transcend cannot connect to customer systems directly because Sombra always sits in between. Every integration request passes through it tokenised, authenticated and encrypted. The data processing addendum confirms the effect, recording that where Sombra is used the scope of personal data collected is narrower. What is not addressed is separation inside a single customer, with nothing describing walls between teams, brands or matters.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
A position is published, a transparency report exists, and the notice limb rests on a document other than the customer agreement. The contracting explainer states that OneTrust does not voluntarily disclose or grant access to any personal data of its customers to government authorities unless required by law, and directs the reader to a published policy and transparency report on government and law enforcement requests. The notice commitment located sits in the Mutual Nondisclosure Agreement, which provides that confidential information may be disclosed as required by law or valid legal order after using reasonable efforts to provide notice of the disclosure; that document governs pre-contract confidential information rather than platform data. The Data Processing Addendum PDF, which is where a notice commitment for customer data would sit, was not opened on 1 September 2026, so this row may move up to notice and report on reading it.
A notice commitment is published in two places and goes further than notice alone, without a transparency report to complete the top value. The data processing addendum requires Transcend to promptly notify the customer of any government requests for access to or information about its processing of customer personal data unless prohibited by law, to provide reasonable cooperation and assistance, and, where it is barred from disclosing the details, to inform the customer that it can no longer comply with the customer's instructions and await further instructions. It adds an undertaking to **use all available and reasonable legal mechanisms to challenge demands for data access through national security process, as well as any non-disclosure provisions attached**, which is a stronger commitment than most vendors publish. The services agreement adds a general compelled-disclosure clause requiring prior notice where permitted, reasonable assistance to contest or limit at the disclosing party's cost, and disclosure of the minimum necessary. **No transparency report was located**, which is what holds this below the top value.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The product does not retrieve primary law, and the reference datasets it does carry are named, which is more than most vendors manage. Three are identified on the pricing page: a database of more than 45 million categorised cookies and trackers behind the consent product; risk intelligence data on millions of third parties behind third-party management; and, named to its provider, Dow Jones ethics and compliance databases supplying politically exposed person, sanctions and watchlist screening in the Third-Party Management Suite. Regulatory change intelligence is attributed to DataGuidance within Privacy Automation. What is absent is the rights basis: no licence, ownership or public-domain footing is stated for any of them, and no update cadence is published beyond the claim that inventories are evergreen. Checked the pricing and packaging page, the home page and the trust centre on 1 September 2026.
No legal corpus is published and the product does not retrieve primary law. Transcend's decision layer encodes three inputs, described on the home page as business policy, jurisdictional regulation and customer permissions, so a maintained body of regulatory rules sits behind the jurisdictional limb, and nothing is published about it: no regulator, source, publisher or licensing basis is named, no jurisdictions are enumerated, and no update cadence is stated for how a change in law reaches the encoded rules. That is a narrower gap than for a research product, since the decisive corpus here is the customer's own data estate and consent record rather than a body of law, but it is not immaterial given the platform is sold on producing a defensible answer to whether data can be used. Checked the home page, the security page, the services agreement, the data processing addendum and the full footer on 1 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No citator applies and the row is recorded rather than skipped. The platform does not return legal authority whose subsequent history could be checked; it maintains registers, runs assessments and enforces controls. The nearest analogue is regulatory currency rather than treatment: Privacy Automation is described as helping customers understand the operational impact of regulatory changes through DataGuidance intelligence, and the AI Governance package aligns assessments to named frameworks including the EU AI Act, NIST and ISO 42001, so the platform tracks whether a requirement has moved without purporting to tell a user whether an authority still stands. Searched the pricing and packaging page, the home page, the trust centre and the published contracting explainer on 1 September 2026.
No citator applies and the row is recorded rather than skipped. The platform returns a permissioning decision about a piece of data, not a legal authority whose subsequent history a user would need to verify. The nearest analogue is whether the encoded jurisdictional rules remain current as law changes, and nothing published describes how that currency is maintained or how quickly an amendment propagates into the Policy Engine. Searched the home page, the platform and solutions navigation, the services agreement and the data processing addendum on 1 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Nothing located describes what the AI does when it cannot assess reliably. The published workflow shows an AI-assisted assessment returning a risk summary graded medium with findings graded medium and low, so the output carries a severity rating, but a risk grade is a conclusion about the subject rather than a statement of the model's own confidence, and nothing indicates what a user sees when the system cannot reach one. No abstention path, confidence score or coverage indicator is documented. The structural mitigation is the approval gate rather than a model behaviour: every assessment routes to named human reviewers before a use case proceeds, so an uncertain output is caught by process rather than flagged by the system. Searched the home page, the pricing and packaging page, the trust centre and the contracting explainer on 1 September 2026.
Nothing located describes what the system does when it cannot decide. No confidence score, abstention path, coverage indicator or fallback rule is published for the Policy Engine or the AI Features, which matters more than usual here because the product is explicitly sold as returning a real-time decision that other systems and agents act on before proceeding, so an uncertain or absent answer has to resolve to something. The two published statements closest to the question are disclaimers rather than behaviours: section 7.4 disclaims any warranty that Outputs from the AI Features are accurate, complete or reliable, and section 1.6 acknowledges that trial and beta features may generate or produce inaccurate information or unexpected or incorrect results. Searched the home page, the security page, the platform navigation and both published agreements on 1 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name. No court order, opinion or disciplinary record naming OneTrust was located. This is a statement about the public record rather than a finding about the product. The failure mode this signal tracks fits poorly: the platform's AI output is a risk rating or a piece of model documentation consumed inside a governance workflow and gated by human approval, not a citation to legal authority prepared for filing, so the analogous exposure would be a mis-rated assessment surfacing in a regulatory examination rather than in a court.
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name and on the Sombra product name. No court order, opinion or disciplinary record naming Transcend was located. This is a statement about the public record rather than a finding about the product. The failure mode fits poorly, since the output is a permissioning decision consumed by a downstream system rather than a citation prepared for filing; the analogous exposure would be a wrong clearance allowing data to be used for a purpose it was not permitted for, which would surface in a regulatory action or a class claim rather than in a sanctions docket.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No engagement with professional responsibility or ethics guidance was located, which is worth separating carefully from what OneTrust does publish. The company engages extensively with regulation as subject matter, naming GDPR, US state privacy laws, the EU AI Act, NIST, ISO 42001, DORA and more than fifty standards and frameworks in its packages, and maintains a public glossary of AI governance and privacy terms. None of that is guidance binding the professional who relies on the output. Nothing references ABA Formal Opinion 512, any state bar opinion, Law Society or SRA guidance, or any equivalent addressed to counsel using AI tools, and no general statement that a user's own professional obligations survive use of the platform was found. Searched the home page, the trust centre, the pricing page, the legal centre and the published contracting explainer on 1 September 2026.
No engagement with professional responsibility or ethics guidance was located. Nothing references ABA Formal Opinion 512, any state bar opinion, Law Society or SRA guidance, or any regulator statement addressed to counsel using AI tools, and no general acknowledgement appears that a practitioner's own professional obligations survive use of the platform. The agreement does allocate legal responsibility to the customer, stating that the customer is solely responsible for its compliance with any laws, but that is an allocation of liability rather than a reference to guidance. The absence is more pointed here than at some peers because Transcend publishes a dedicated Privacy, Legal and Risk buyer page and markets the product as removing legal review cycles. Searched the home page, the security page, the Legal document index, both published agreements and the full footer on 1 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Savings are quantified and billing treatment is never addressed. A commissioned Forrester Total Economic Impact study is promoted with a 227 per cent three-year return on investment and a seven-month payback, and the GOL customer story gives operational time reductions from thirty days to five or fewer for vendor approval and from a fortnight to minutes for request completion. The buyer is an in-house privacy, legal or risk function rather than a firm billing a client, so the fee question lands obliquely, but it is not absent: outside counsel and consultancies use platforms of this kind on client engagements, and nothing published addresses how AI-assisted assessment work should be disclosed or billed where that happens. No per-matter record of AI-assisted work is described for that purpose, as distinct from the audit-ready evidence the product generates about a customer's own AI systems.
Savings and revenue claims are central to the marketing and no billing or disclosure treatment exists. Transcend leads with 1.9 billion dollars of revenue unlocked, publishes a preference management return-on-investment calculator, and sells on removing three-week legal review cycles and eliminating the data subject request ticket queue. Nothing accompanies that on how AI-assisted or automated compliance work should be disclosed or billed where an adviser performs it for a client. The buyer is an in-house privacy, legal, data or marketing function rather than a firm billing a client, so the question lands obliquely, and it is not absent given the platform produces system-level proof of every decision that could in principle support such a disclosure. No per-matter record framed for that purpose is described.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
Half of what a client's AI clause asks for is openly published and the half about AI is obtainable rather than public. On the open side, and this is unusually strong: the Data Processing Addendum, the Standard Contractual Clauses and the Master Terms are all downloadable from the legal centre without an agreement in place, with full version histories, which is precisely the forwardable contractual material the signal contemplates. On the gated side, the subprocessor list is maintained on the customer portal rather than the open trust centre, though with a thirty-day advance notice commitment for changes and a right to object on reasonable data protection grounds. And **no model provider is named anywhere**: the AI Systems Transparency Report is described as available upon request. Under the coverage test a firm therefore cannot tell its client which systems see its content without first contracting or requesting, which is what places this at the request tier rather than higher.
Two of the three artifacts a client's AI clause asks for are openly published, and the model provider limb is missing. On the open side, and this is strong: the services agreement, the data processing addendum, the service level agreement and the acceptable use policy are all published without gating, each dated, and the DPA carries completed EU standard contractual clauses with the module and clause elections set out, the UK addendum and the FADP variations, plus **a maintained subprocessor list published at the documentation site with fifteen days' notice of additions and an objection route**. That is forwardable material a firm can send a client without negotiation. The gap is the AI surface: **no model provider is named anywhere**, and the agreement confirms that large language models are in scope of the Services without identifying whose. Under the coverage test a firm can therefore describe the processing chain but not say which models see its content, which is what keeps this below the top value.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
There is an inversion worth naming here: OneTrust sells the capability to produce exactly this record about a customer's own AI, while its own equivalent is available on request. The AI Governance package automates model documentation, audit-ready evidence and regulatory reporting outputs, configures approvals, attestations and evaluation gates, and correlates runtime behaviour with purpose, data sensitivity and regulatory obligations, which is a disclosure record about the customer's systems. For OneTrust's own AI, the published workflow logs a review and approve step naming privacy, security and legal reviewers, so who signed off is captured. What is not established is whether that record identifies which output was machine-generated or which model produced it, and no document-level export covering model, sources and verification is described. OneTrust's own AI Systems Transparency Report is available upon request rather than published.
The record is real, produced automatically, and built for a regulator rather than for an AI-use disclosure. Transcend markets audit-ready records by default, complete records for regulators, mergers and acquisitions and litigation, closed-loop data subject request fulfilment with system-level proof of every request, and a decision log in which every use is defined and enforced. The data processing addendum adds an events logging measure recording that all key actions such as logins, data writes and configuration changes are attributable to particular users with date and time stamps, centralised and protected from change. That is a stronger evidentiary trail than most vendors in this lane publish, and litigation is named as a use for it. What it does not do is identify the machine's contribution: nothing states that the record distinguishes decisions produced by the AI Features from deterministic policy decisions, or captures which model produced an output, so a user could not assemble an AI-use disclosure from it.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- Good Law Verification
- Refusal and Uncertainty Behaviour
- Bar Guidance Alignment
Which one fits
Choose OneTrust if
- You want the evidence today rather than after a call. OneTrust's trust centre publishes its SOC 2 Type II reports, ISO/IEC 27001, 27701, 27017 and ISO 9001 certificates and a Statement of Applicability as direct downloads with no form, no email capture and no non disclosure agreement, alongside a PCI attestation of compliance, a HITRUST certification letter, a cloud security questionnaire lodged on the CSA STAR registry, a 2026 penetration test executive summary and a completed standard security questionnaire.
- You want to read the contract and its history. OneTrust publishes its master terms in full at a legal centre, currently version 5.1 effective March 2026, with every prior version back to 2020 downloadable alongside the data processing addendum, standard contractual clauses and business associate agreement, capping each party's liability at total annual fees, which it points out is broader than the more common per service cap, with intellectual property claims and wilful misconduct uncapped and a conformance warranty attached.
- You want to know what drives the bill before you ask. OneTrust publishes nine packages across five solution families with each charging meter stated: AI governance on admin users and AI inventory, consent management on average daily visitors, universal consent on total data subject profiles, privacy automation on users and privacy asset inventory, and third party management on admin users and third party inventory, with a tiered model explained in published FAQs.
Choose Transcend if
- The data should never reach the vendor at all. Transcend runs Sombra, a security gateway deployed inside the customer's own infrastructure, through which every integration request passes tokenised, authenticated and encrypted, with the customer holding its own API keys and optional delegation to its own key management service, and Transcend stating that customer data never leaves the customer environment and that it cannot connect to customer systems directly.
- You want the training bar in the agreement rather than on a page. Transcend's services agreement provides that it may not use inputs or outputs to train or otherwise improve its AI features except solely for the benefit of that customer, confines its data licence to providing the services, and its data processing addendum carries a maintained public subprocessor list with fifteen days notice of additions, seventy two hour breach notification and deletion within thirty days of a request.
- You want one decision your systems can call. Transcend's policy engine encodes business policy, jurisdictional regulation and individual consent into a single real time decision exposed through an API described as MCP native, so systems and agents ask before they act, with consent propagating to downstream marketing systems, data subject requests fulfilled across connected systems with system level proof, and public developer documentation and open source repositories behind it.
In summary
OneTrust
OneTrust is a governance platform for privacy, data and AI, spanning privacy automation with data mapping, assessments and subject request fulfilment, consent and preference management across web, mobile and connected TV, AI governance maintaining a register of AI initiatives, models, agents and datasets aligned to the EU AI Act, NIST and ISO 42001, and tech risk and third party management. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes, with A grades on data stewardship, liability and recourse, and security certifications: its trust centre publishes certificates and a statement of applicability as direct downloads and its master terms are published with full version history. As of 1 September 2026 the index located no named model provider and no published price.
Transcend
Transcend is a data permissioning and decision layer that encodes business policy, jurisdictional regulation and individual consent into a single real time decision that systems and agents call before they act, with consent and preference management, data subject request automation producing system level proof, and Sombra, a gateway the customer runs inside its own infrastructure so that customer data never reaches Transcend. The AI Legal Index grades it in the top two bands on eight of fifteen capability axes, with an A on data stewardship. Its services agreement bars it from using inputs or outputs to train its AI features except for that customer's benefit, and its data processing addendum carries a public subprocessor list. As of 1 September 2026 the index located no AI governance material and no published price.
Questions buyers ask
OneTrust vs Transcend: which is better for privacy operations?
The AI Legal Index places OneTrust in the top two bands on ten of fifteen capability axes and Transcend on eight, and they compete on different things. OneTrust's strength is verifiability, publishing its certificates, its statement of applicability and its full contract history openly. Transcend's is architecture, running a gateway inside the customer's own infrastructure so that data does not reach the vendor, with a contractual bar on training.
What can you download today?
On OneTrust, a great deal without asking: SOC 2 Type II reports, four ISO certificates, a statement of applicability, a PCI attestation, a HITRUST letter, a 2026 penetration test summary and a completed security questionnaire, all as direct downloads. On Transcend, the contractual estate is open, covering the services agreement, data processing addendum, service level agreement and acceptable use policy with a public subprocessor list, while the SOC 2 and ISO reports themselves are neither downloadable nor stated to be available on request. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Where does the data sit?
OneTrust states a shared architecture with each customer holding a logically separated database and a single production tenant, and lets customers select from various geographic hosting locations, though the available regions are referred to collectively rather than listed. Transcend answers it by keeping the data out of its own environment: Sombra sits inside the customer's infrastructure and the default hosted environment is stated as AWS, with no regions enumerated. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Who is accountable for the AI?
OneTrust publishes more here. Its trust centre states that an interdisciplinary AI governance committee manages its AI governance programme, supported by processes across the AI systems lifecycle, an internal AI use policy and employee training, with an AI systems transparency report available on request, though no individual is named and no evaluation result is disclosed. On Transcend nothing was located about governance of its own models at all. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What do OneTrust and Transcend both leave unpublished?
Neither publishes a price, though OneTrust publishes the meter for every package and Transcend publishes only billing mechanics. Neither names a model or provider. Neither publishes an evaluation of uneven output, which is notable on two vendors that sell bias and drift monitoring to their own customers. And neither addresses the professional line, so a privacy counsel relying on a generated assessment has no published statement about what that output is. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Neither vendor names the model or provider behind its own AI. OneTrust's master terms answer the question of whether it uses artificial intelligence in the services with a plain yes and point to an AI systems transparency report available on request; Transcend defines AI features contractually and then, at section 7.4, disclaims any warranty that their outputs are accurate, complete or reliable. Neither addresses privilege or work product anywhere, and neither states that its output is not legal advice, on products sold to privacy counsel: OneTrust's own published workflow assigns a legal reviewer while its by role navigation offers pages for privacy, security, data and marketing teams and none for legal. On Transcend, the confidentiality carve out from its liability cap expressly excludes claims related to customer data, so a data incident stays inside the twelve month cap. OneTrust was verified on 1 September 2026 and Transcend on 1 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.