Relyance AI vs Transcend: how they compare in 2026

Relyance AI profileTranscend profile
Last verifiedSeptember 3, 2026

Relyance AI and Transcend answer different halves of the same question. Relyance finds out where data actually goes, reading source code, watching runtime behaviour and scanning contracts to build a live graph of flows and the obligations attached to them. Transcend decides whether a given piece of data may be used for a given purpose, and enforces that answer inside the systems that process it. Transcend sits in the top two bands on eight of fifteen axes and Relyance on six, and the difference is largely contractual. Transcend publishes its whole estate openly: a services agreement with a mutual cap and named excluded claims, a data processing addendum with a public subprocessor list, seventy two hour breach notification, deletion within thirty days of a request, and a clause barring it from using inputs or outputs to train or improve its AI features except for that customer's benefit. Relyance publishes a trust centre listing around fifty named controls, with the agreement itself available on request rather than in the open.

At a glance

Category
Relyance AIRegulatory & Compliance Counsel
TranscendRegulatory & Compliance Counsel
Founded
Relyance AINot published
TranscendNot published
Headquarters
Relyance AISan Mateo, California, United States
TranscendSan Francisco, California, United States
Last verified
Relyance AISep 2, 2026
TranscendSep 1, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Relyance AI
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

The models are the mechanism and the company draws the distinction itself. Its about page states that it is not a legacy tool retrofitted with AI but was built from first principles for a world where data behaviour is non-deterministic, and that the old paradigm of scan, classify and lock no longer holds because scanners can tell you what your data is but not where it came from or what it is doing. What is sold is the inference: code analysis that reads how data moves through a repository, runtime monitoring, machine learning contract analysis that ties obligations to flows, classification of sensitive data, and behavioural analysis of AI agents, unified into a live graph. There is no content asset and no conventional product underneath; the substrate is the customer's own code, systems and contracts, and the graph exists only because the models build it. The comparator the company names is manual inventories and questionnaires, which is the work the platform replaces rather than accelerates. Verified 2 September 2026.

Transcend
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

The decision layer is rules, not models, and the vendor says so in its own framing. Transcend's pitch is policy as code: business policy, jurisdictional regulation and consent encoded into a deterministic real-time decision that systems and agents call before acting. That is deliberately not inference, and the marketing leans on it, promising every use defined and enforced with audit-ready records. AI Features do exist and are defined contractually as large language models or other machine learning features of the Services, and the AI-related use cases are largely about governing someone else's models, honouring do-not-train signals through data pipelines and clearing data for AI initiatives. Strip the models out and the product a buyer pays for remains intact: the permissioning layer, consent propagation, DSR fulfilment, the Sombra gateway and the integration estate. Third consecutive privacy platform at this grade for the same structural reason.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Relyance AI
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is documented at an architectural level and never measured. The discovery method is described concretely rather than asserted: multi-point discovery through code analysis, runtime monitoring, contract scanning and system integrations, with every data flow stated to be mapped to its business purpose, legal obligation and risk. That is a traceable chain from a finding back to the source that produced it, and it is the design claim the whole product rests on, expressed as reading the story of the data rather than scanning its contents. What is absent is any measurement of whether the inferences are right. No accuracy, precision or false-positive figure is published anywhere, no evaluation or benchmark is described, and nothing states how a classification or an obligation mapping is validated. That gap has weight on this product because a missed flow reads as compliance where none exists, and a wrong obligation mapping produces a record of processing activities that is confidently incorrect. Nothing addresses hallucination in the assessment-drafting features either. Verified 2 September 2026.

Transcend
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is asserted in the marketing, measured nowhere, and disclaimed squarely in the agreement. The claims are quantified but unsourced: 174 billion automated data decisions, 99 per cent addressable audience per purpose, column-level classification updated in real time, and a customer quote putting data visibility at roughly 100 per cent. Against that, section 7.4 of the services agreement disclaims any warranty that the Services, **including any Outputs from the AI Features, are accurate, complete, or reliable**, which is the most direct AI-output accuracy disclaimer located anywhere in this pull and is the more candid of the two positions. No precision or recall figure, benchmark or error rate for classification or for the AI Features was located on any surface read on 1 September 2026. The retrieval-and-citation limbs of this axis do not apply, since the product returns permissioning decisions rather than legal authority.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Relyance AI
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

The action set is enumerated unusually clearly and the control around it is not. Published material states that a request can be resolved in real time as allowed, redacted, masked, narrowed, escalated or blocked, and that the decision is computed at the moment it matters rather than from static allow-lists. Naming escalation as one of six outcomes implies a human path, and the CI/CD integration is described as flagging a risky change before merge, which places a decision point in an existing engineering review. But nothing states what triggers escalation rather than a block, what confidence or severity threshold applies, who reviews an escalated request, or what a privacy team must approve before an automated enforcement takes effect. One scope limit belongs on the record and is treated as such rather than credited: the runtime enforcement layer that performs the blocking and redaction is marked PRIVATE BETA on the vendor's own navigation, so the most autonomous part of the product is not generally available and is not graded here. What ships is posture management that flags and maps. No published agreement places a review obligation anywhere. Verified 2 September 2026.

Transcend
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Human involvement is offered as a configuration option and never described as a control over model output. The home page states that policy as code runs with humans in the loop only where you want them, and elsewhere that the review queue is encoded automatically and that runtime policy enforcement replaces manual compliance reviews. That is a claim about where a customer may choose to place a checkpoint, and the product's selling proposition is explicitly the removal of manual review, so the axis has to ask what happens when an automated decision is wrong. Nothing located answers it: no confidence threshold, no deferral path, no description of a review surface for the AI Features specifically, and no remediation route beyond the audit record. Two things pull in the customer's favour and belong on the record: every decision is logged with system-level proof, and section 3.3 of the agreement gives the customer a perpetual licence in Outputs while retaining its rights in Inputs, so the customer controls what it does with what the system produces.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Relyance AI
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

The reference base is substantial and the individuals are senior and named. Roughly twenty-four logos appear on the home page, spanning consumer technology with Notion, Yelp, DuckDuckGo and MyFitnessPal, hardware and industrial with Logitech, Samsara and Motive, data infrastructure with Grafana, Fivetran and Cribl, and security with Zscaler, alongside Ancestry, Zuora, Navan, Dayforce, Bolt, Insperity and ClickUp. Three customers speak on the record with name, title and a linked video story: Chris Bender, CISO at ClickUp, Jason James, CIO at Aptos, and Karthik Chakkarapani, SVP and CIO at Zuora, and the Zuora quote is substantive rather than promotional in describing the difference between a snapshot and continuous visibility. Two deployment figures are published, that more than 1,600 systems and 100 flows are mapped in under two hours agentless, and that six surfaces are unified in one graph. What holds this below the top band is method and dating: neither figure carries a measurement basis or a date, no figure is attached to any named customer, and the case studies are video rather than written. Verified 2 September 2026.

Transcend
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

One named customer with a named individual, and no figures attached to either. Robinhood is named on the home page with a quote from Karthik Rangarajan, Head of Security, describing Transcend's role in giving customers control over their data. A second quote is attributed to a named chief executive with **no organisation identified**, which is unusual and reduces its value. The security page carries two further quotes attributed by role and sector only, a CISO and data protection officer at a global staffing firm and a chief information security officer at a global fintech, the latter carrying the only outcome figure located, data visibility improved to roughly 100 per cent. Platform-level claims of 1.9 billion dollars of revenue unlocked, 174 billion automated decisions and 418 million operations and agents governed are unsourced and carry no method. IDC recognised Transcend as a Leader in its 2025 MarketScape for worldwide data privacy compliance software. A customer stories library exists and **was not opened on 1 September 2026**, so a dated outcome with figures was neither located nor excluded.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Relyance AI
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Handling controls are published and the four limbs that matter most to a legal buyer are not. What exists is real: the trust centre publishes controls for retention of customer data, restriction of access to customer data on a least-privilege basis, disposal of customer data on request, segregation of development, staging and production environments, and a rule that production data is not used in development or testing except when required to debug a customer issue, all continuously monitored. Encryption is stated at rest and in transit. Against that, nothing addresses whether customer content is used to train or improve models, in either direction. Nothing describes segregation between customers as distinct from between environments. Neither privilege nor work product is mentioned anywhere, which bites here rather than not, because the platform generates and stores data protection impact assessments, transfer impact assessments and legitimate interest assessments, which are legal analyses a privacy counsel would often expect to be privileged. And no model provider is identified. The operative agreement is a master services agreement available only on request, so none of this is testable against a contract a prospect can read. Verified 2 September 2026.

Transcend
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

This is the strongest confidentiality record in the lane and it stops short of the top band on two named limbs. What carries it. **Section 3.3 of the services agreement provides that Transcend may not use Inputs or Outputs to train or otherwise improve AI Features except solely for the benefit of the Customer**, which is a contractual training prohibition rather than a policy statement, and the only one located in this lane. The Customer Data licence at 3.2 is drawn narrowly, solely to provide the Services, with improvement rights confined to Usage Data that excludes Customer Data. Architecture reinforces the contract: Sombra runs inside the customer's own infrastructure, the customer retains its own API keys with optional delegation to its own key management service, and Transcend states it cannot connect to customer systems directly and does not see the data. Customer Data is defined as the customer's Confidential Information, compelled disclosure carries a prior-notice obligation, and the DPA commits to deletion within thirty days of termination on request. What is absent is privilege and work product treatment, which is never mentioned despite a named Privacy, Legal and Risk buyer, and any position on third-party model providers behind the AI Features.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Relyance AI
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Nothing published addresses the advice line, and the marketing runs the other way. Checked the home page, the privacy teams, data and access governance, AI governance and privacy automation solution pages, the terms of use in full, the privacy statement in full and the trust centre on 2 September 2026. There is no statement that output is not legal advice, nothing on supervision or verification duties, and no jurisdictional statement. The terms of use are website terms and address the Website alone. What the vendor does publish points toward legal expertise rather than away from it: the privacy teams page states that Relyance uniquely combines legal expertise with technical discovery to eliminate the gap between documented policies and operational data practices, and company material foregrounds that a co-founder and co-chief executive is a practising data privacy attorney. The outputs are statutory instruments, being records of processing activities, data protection impact assessments, transfer impact assessments and legitimate interest assessments, each of which is a document a regulator may read and a controller must stand behind. A platform generating those, marketing legal expertise, and publishing no statement about the professional boundary sits at the bottom of this axis. Verified 2 September 2026.

Transcend
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

A responsibility allocation sits in the terms while the marketing sells the removal of legal review. Section 7.4 of the services agreement states that the customer is solely responsible for its compliance with any laws and that Transcend disclaims all liability related to that compliance, and section 2.3 requires the customer to obtain the permissions and consents and comply with the privacy laws necessary for the Services to operate. That is a clear allocation of who owns the legal judgement, and it is not a statement about the line between an information tool and legal advice: nothing located says the output is not legal advice, that no professional relationship arises, or that a user should take advice on their own facts, and no jurisdiction limit or supervision dimension appears. The tension is sharper here than elsewhere in the lane because of how the product is sold, with the marketing promising real-time campaign clearance and **no three-week legal review cycles**, which is an explicit offer to displace a legal review step, published alongside a disclaimer of all liability for the compliance outcome.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Relyance AI
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

The product governs AI and nothing published governs the vendor's own. Relyance publishes an AI Security Hub, an AI governance solution, blog material on AI governance failures and a survey on consumer AI trust, all of which concern what a customer should do about its models. Checked the home page, the about page, all four solution pages read, the terms of use, the privacy statement and the trust centre on 2 September 2026: nothing addresses Relyance's own models. There is no responsible AI page for the platform itself, no framework or set of principles, no individual or function named as accountable for model behaviour, no account of what is evaluated before a model or classifier change ships, and no ISO 42001 or equivalent certification. The trust centre's fifty-odd monitored controls are information security controls, and this axis treats those separately. Nothing anywhere addresses uneven output, which is a live question on a system that classifies sensitive data and maps legal obligations across jurisdictions, languages and codebases of varying quality. Verified 2 September 2026.

Transcend
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

Nothing published addresses governance of Transcend's own models. The company publishes a substantial amount about AI governance as a subject, including an AI Governance solution built around do-not-train enforcement and a blog arguing that AI governance is enforcement rather than documentation, and all of it concerns the customer's AI rather than Transcend's. No responsible-AI page, AI policy, ethics statement, governance committee, named accountable owner, pre-release testing regime or bias evaluation was located. The site navigation and the full footer were read on 1 September 2026 across platform, solutions, partners, resources, company and developer sections, and contain no such surface. Two things sit adjacent without answering the axis and are credited elsewhere to avoid spending one fact twice: the contractual no-training term is a data commitment and is credited on confidentiality, and the open-source repositories and public documentation are engineering transparency rather than model governance. **The third vendor in this lane to sell AI governance while publishing none of its own.**

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Relyance AI
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

All five elements are addressed and the trust centre carries more published detail than almost any record in this corpus. Continuously monitored by Secureframe, it lists roughly fifty named controls with descriptions across change management, availability, organisational management, confidentiality, vulnerability management, incident response, risk assessment, network, access and physical security. Retention and deletion are covered by a data retention and disposal policy, a control for retaining customer data to agreed customer requirements, and disposal of customer data on customer request. Access control is granular, with least-privilege restriction on customer data, unique access identifiers, complex passwords with a second factor, scheduled user access reviews and removal of access on termination. Encryption is stated at rest and in transit. Incident practice is published as an incident response plan with documented tracking of identified incidents. A third-party network and application penetration test is conducted at least annually with critical and high findings tracked to resolution, vendor SOC 2 reports are collected annually, and cybersecurity insurance is procured. Two things hold this below the top band: no retention period is published, since retention is stated as whatever the customer agreed, and the subprocessor list exists but sits behind a request rather than on the page. Verified 2 September 2026.

Transcend
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

Every limb this band names is published, specific and dated, in a data processing addendum last updated 27 August 2026. Retention and deletion: on termination Transcend deletes all Customer Personal Data in its possession or control within a maximum of thirty days of a customer request, with backup copies securely isolated and protected from further processing, and absent a request deletion follows standard retention policies. Incident practice: notification without undue delay and **within seventy-two hours** of becoming aware of a Security Breach, with a specified content list covering the nature of the breach, categories and approximate numbers of data subjects and records, likely consequences and measures taken. **Subprocessors are named on a maintained public list** at the documentation site, with fifteen days' prior notice of additions, a commercially reasonable objection route and a mutual termination right if no cure is available. Access control is described concretely: SSO with enforced MFA, least privilege and role-based access, segregation of duties, and quarterly access reviews. Encryption is AES-256 at rest and TLS 1.2 or higher in transit, with annual third-party penetration testing, threat modelling at design, static analysis and dependency checking in the code pipeline, and daily backups tested at least annually. Transfers run on the EU SCCs with module and clause elections set out, the UK addendum and the FADP variations.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Relyance AI
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

The agreement exists, is obtainable, and is not published, so the allocation itself cannot be read. The terms of use on the website are explicit about their own scope and say so plainly: they govern the Website, and where a customer has signed an agreement covering the Relyance Platform, that signed agreement supersedes them. Those website terms disclaim all warranties and exclude liability for damages of any kind under any legal theory, with indemnity running only from the user to Relyance and disputes going to arbitration under California law, but under the rule that credit follows scope none of that describes what a platform customer receives. What lifts this off the floor is that the master services agreement and the data processing addendum are both listed in the trust centre and obtainable through a request flow, which is materially better than absent, and that cybersecurity insurance is published as a continuously monitored control, which is one of the four things this axis asks for and is rarely stated at all. What a prospect still cannot see before contacting the company is any cap, any indemnity, any warranty on output and any service level. Verified 2 September 2026.

Transcend
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

The allocation is published, current and readable, and the indemnity is narrower than the best in this corpus. What is there: a services agreement last updated 9 July 2026, published openly and independently assessed under the TermScout certification programme; a mutual cap at fees paid or payable in the twelve months before the event; a defined set of Excluded Claims sitting outside the cap covering customer breaches of use restrictions, indemnity amounts payable to third parties, and either party's breach of confidentiality; a conformance warranty that the Services will operate in substantial conformity with the Documentation and that functionality will not be materially reduced during the term, with correction, re-performance or a refund of prepaid fees as the exclusive remedy; and, unusually, a **standalone warranty that Transcend will comply with all applicable laws in providing the Services**. Two things hold it below the top band. The Transcend indemnity covers third-party intellectual property claims only, with no indemnity for misuse or unauthorised disclosure of Customer Data, and the confidentiality carve-out from the cap **expressly excludes claims related to Customer Data**, so a data incident stays inside the twelve-month cap. No insurance position was located. Nothing addresses an AI output being wrong except to disclaim it.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Relyance AI
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

Integration is the product's core mechanism and it points at engineering systems rather than legal ones. Discovery is described as multi-point across code repositories, runtime environments, AI models and third-party processors, with an integration framework connecting to the wider data ecosystem, enforcement running inside CI/CD pipelines, and inventory extending to agents, models, retrieval systems and MCP servers. Setup is stated to be agentless with a first map in hours. That is real depth in the direction the product needs. What is missing is naming and documentation. Almost no specific system is identified: no repository host, cloud provider, data warehouse, identity provider or consent platform is named on any page read, the only concrete reference being consent signals captured from consent management platform software development kits. No connector list, no API reference and no developer documentation was located. And no integration into the systems a privacy or legal function itself runs is described, with no document management, matter management or GRC platform named, which matters because the buyer this axis grades for is the privacy team. Verified 2 September 2026.

Transcend
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Named systems, a described flow and public developer documentation, short of a stated approach to what is not covered. Integrations are named across the home and security pages and span the categories that matter for this product: identity and HR in Okta and Workday, data platforms in Databricks, AWS and Azure, communications in Slack and Twilio, marketing in Google Ads and AdRoll, and productivity in Google Workspace, with Segment named in the agreement as a worked example of a customer third-party service. What moves is described rather than implied: consent decisions propagate to the CDP, ad tech and loyalty systems, DSR fulfilment runs across connected systems and returns system-level proof, and every request passes through Sombra tokenised, authenticated and encrypted before reaching Transcend. The connector model is real and documented, with public documentation at docs.transcend.io, an API described as MCP-native for agent access, and open-source repositories published on GitHub. **The integrations library and the documentation site were not opened on 1 September 2026**, so depth beyond the named systems was not verified and this grade is deliberately conservative.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Relyance AI
DD on Deployment Model and Data ResidencyNothing published on where the software runs or where client data sits.

Nothing published addresses where the platform runs or how customers are separated within it. Checked the home page, the privacy teams, data and access governance, AI governance and privacy automation solution pages, the terms of use in full, the privacy statement in full and the trust centre in full on 2 September 2026. No cloud provider is named, no hosting region or country is stated for customer data, no residency option is offered, nothing distinguishes processing location from storage location, and no tenancy or isolation model is described. The trust centre publishes segregation of development, staging and production environments, which is an internal environment boundary rather than a tenancy statement. The only geographic material located concerns personal data transfers rather than platform hosting, with the privacy statement recording certification under the EU-U.S., UK Extension and Swiss-U.S. Data Privacy Frameworks. For a platform that reads a customer's source code and runtime traffic and is sold to European privacy leaders, the absence of any residency statement is a material gap. Verified 2 September 2026.

Transcend
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed.

The deployment model is the clearest in the lane and the residency detail is thin. Transcend publishes a genuine two-part architecture rather than a hosting note: a hosted control plane, and **Sombra, a security gateway the customer deploys inside its own infrastructure**, through which every integration request passes. The consequences are stated concretely, that customer data never leaves the customer environment, that Transcend cannot connect to customer systems directly, and that the customer retains its own API keys with optional delegation to its own key management service for hardware-backed key management. The data processing addendum confirms the effect in its transfer schedule, recording that where the customer uses Sombra the scope of personal data collected is narrower because it is an on-premises solution using end-to-end encryption. That answers where processing happens more directly than a region list would. What is missing is the region list itself: the DPA states that by default customer data is stored and processed in a secure cloud environment hosted on AWS, and no available regions are enumerated, no residency option is offered, and nothing describes what changes between deployment tiers.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Relyance AI
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

The trust surface is the strongest part of this record. A Secureframe-hosted trust centre renders publicly and continuously, listing SOC 2 Type 2, ISO 27001 and Data Privacy Framework participation under compliance, and making ten documents individually available, including the SOC 2 Type 2 report, the ISO 27001 certificate, a penetration test executive report, a CSA CAIQ version 4 self-assessment, a security whitepaper, the subprocessor list, the master services agreement and the data processing addendum. Roughly fifty named controls are published with descriptions rather than as a badge wall, which is more substance than most vendors expose without an agreement, and two documents are freely available, with the privacy statement viewable and the responsible disclosure policy downloadable. What is not established is the evidence itself. Every report and certificate sits behind a request control, and the portal does not state whether access is instant on an email, an NDA click-through or granted after review, so the lower tier is graded and the reason recorded. No auditor or certification body is named, and no report period, issue date or scope statement is published. No request was submitted. Verified 2 September 2026.

Transcend
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

The standards are named and none of the confirming detail is published. The security page states that Transcend regularly attains SOC 2 Type II and ISO 27001 compliance and displays the AICPA SOC and ISO 27001 marks, and the data processing addendum repeats both, recording that Transcend has obtained SOC 2 Type II certification and maintains an ISO 27001 certification with its security and privacy programmes externally audited annually. Supporting practice is described in more depth than most: annual third-party penetration testing, external audits, threat modelling in the design phase, static code analysis and dependency checking in the pipeline, manual application security testing, and alignment claimed to the Cloud Computing Compliance Controls Catalogue, the NCSC Cloud Security Principles and NIST cloud standards. What is absent is everything that would let a buyer verify it. **No trust centre exists and no report is downloadable or stated to be available on request**; no auditor or certification body is named for either standard; and no certificate date, examination period or scope statement appears. The phrase regularly attains is looser than a current certification claim and is recorded as the vendor's own wording.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Relyance AI
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

A proprietary engine is named and nothing underneath it is. The company brands its system Lyo, describing it as the world's first AI-native data defence engineer, and repeats that the platform was built on AI from the ground up rather than retrofitted, but no model is identified, no version, no provider entity, and nothing states whether any component is built in-house or reached through a third party. Nothing describes where inference runs, what any provider may retain, or whether customers would be notified if the model set changed. The subprocessor list that would ordinarily carry the answer exists and is listed in the trust centre, but sits behind a request rather than on the page, so a prospect cannot read it. The gap is more conspicuous here than on most records because the product's own function is to inventory every model, agent and retrieval system inside a customer's estate and tell them which ones touch sensitive data, while the vendor discloses none of its own. Verified 2 September 2026.

Transcend
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The AI Features are defined and nothing underneath them is identified. The services agreement defines AI Features as large language models or other machine learning or artificial intelligence features of the Services, which confirms that third-party model categories are in play, and no model, model family or provider is named on any surface read on 1 September 2026, nor is one excluded. A misreading worth guarding against: OpenAI and Perplexity appear in the integration strip on the home and security pages, and they sit there as customer systems Transcend connects to on the customer's behalf, not as providers of Transcend's own AI Features. AWS is named as the default hosting environment in the DPA, which identifies infrastructure rather than models. No commitment to notify customers when the model set changes was located. The maintained subprocessor list is the surface most likely to resolve this, since a model provider processing customer personal data would have to appear on it, and **that list was not opened on 1 September 2026**, so this grade is rebuttable on one fetch.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Relyance AI
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing information is published at any level. Checked the home page, the platform page, the privacy teams, data and access governance, AI governance and privacy automation solution pages, the terms of use, the privacy statement and the trust centre, together with the full site navigation and footer, on 2 September 2026. There is no pricing page anywhere in the navigation or the footer, no tier or plan is named, no unit of charge is identified, and no structure is described, whether per user, per system, per data source, per scan or by subscription. Nothing states whether implementation or onboarding is charged separately, and no trial or free tier is offered. The only commercial routes are a demo request and an offer of a free exposure map, both of which lead to the same booking form. No pricing row is written, because the rule that triggers one requires published structure and none exists. Verified 2 September 2026.

Transcend
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing information is published at any level, including the unit of charge. The site navigation and the full footer were read on 1 September 2026 across platform, solutions, partners, resources, company and developer sections and contain no pricing page; every commercial route is a demo request. What the published agreement supplies is billing mechanics rather than price or structure: fees are set in an order form, invoice or an in-account billing page, payable in US dollars, invoiced in advance with usage-based fees possibly invoiced monthly in arrears, non-refundable and not subject to set-off, with subscriptions auto-renewing and Transcend able to revise rates on forty-five days' notice before renewal, and past due amounts carrying 1.5 per cent monthly. Usage limits are said to be set in the order form or documentation without naming what is metered. A separate Customer Support document defines support tiers with a Standard tier included at no additional charge, which is the only tier structure published anywhere and concerns support rather than the platform.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Relyance AI
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Regulatory coverage is named precisely and the buyer is described inconsistently across the site. On coverage the material is strong and specific: the platform is stated to support GDPR, CCPA, Global Privacy Control, ePrivacy, HIPAA and emerging EU AI Act requirements, with the consent layer continuously realigning purposes as those frameworks change, and the blog tracks individual state statutes such as Maryland's. That is a clearer statement of what body of law the product operates against than most records in this lane manage. Buyer documentation is where it wavers. A dedicated privacy teams page addresses privacy leaders directly and in their own terms, and the blog carries a Privacy and Legal Professionals category, but the home page is headed as an AI data security and governance platform, describes itself as trusted by security and governance teams, and all three customer voices are a CISO and two CIOs. A reader cannot tell from the site whether the platform is bought by the privacy function, the security function or both. No organisation size band is stated, no industry pages exist, and nothing describes where coverage stops. Verified 2 September 2026.

Transcend
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Coverage is segmented three ways with real pages behind each, and the boundary is left open. By team, five audiences each have their own page, and **one of them is Privacy, Legal and Risk**, which makes Transcend the only vendor in this lane so far to address a legal function on a surface of its own rather than only through a compliance or data label. By use case, five are named and are specific rather than generic: AI transformation and do-not-train, personalisation and audience activation, retail media networks, loyalty and multi-brand programmes, and regulated and sensitive data use. By business type, six are named: AI, consumer, healthcare, fintech, media and business-to-business. The use-case set is unusually revealing about who the product is really for, since retail media networks and loyalty programmes point at consumer-facing enterprises with large first-party data estates rather than at regulated industry generally. What is not stated is where the product stops: no organisation size, data volume, jurisdiction or system type is identified as out of scope, and the regulated and sensitive data use case is framed as a capability rather than a limit.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Relyance AI
Terms silent

Checked the home page, the about page, the privacy teams, data and access governance, AI governance and privacy automation solution pages, the terms of use in full, the privacy statement in full and the trust centre in full on 2 September 2026. Nothing addresses whether customer content is used to train or improve models, in either direction. No clause or statement names training, model training, machine learning or model improvement in relation to customer data. The nearest provision is in the privacy statement, which permits use of personal data to operate the Relyance Platform, provide related services and develop and improve the Relyance Platform and our other services; that is an improvement right, it does not name training, and under the naming test it does not move the value. The master services agreement and data processing addendum both exist and sit behind a request flow in the trust centre. One thing is worth recording because a reader will notice it: the product itself sells the answer to this question, with a published capability framed as proving that customer data was isolated and never used for AI training, logged as verifiable evidence rather than policy language. The vendor offers customers that assurance about their own vendors and publishes no equivalent statement about itself.

Transcend
Never, in the contract

**The first contractual no-training commitment located in this lane.** Section 3.3 of the Online Services Agreement defines AI Features as large language models or other machine learning or artificial intelligence features of the Services, defines Inputs as customer data submitted to them including prompts and queries, and provides that Transcend may not use Inputs or Outputs to train or otherwise improve AI Features, except solely for the benefit of the Customer. It sits in the agreement itself rather than in a policy page, so it binds. Two supporting terms narrow the surrounding position in the same direction: the Customer Data licence at 3.2 is granted solely to provide the Services, and the improvement right Transcend does reserve is confined to Usage Data, which is defined to exclude Customer Data and must be aggregated and anonymised before it appears in any published material. The customer retains all intellectual property rights in its Inputs. The one limit worth recording is the carve-out itself, since improvement solely for the customer's benefit is undefined.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Relyance AI
Disclosed without a period

Retention is acknowledged in two places and quantified in neither. The privacy statement says personal data is retained only for as long as needed for the purposes described or as required by law, after which it is destroyed in accordance with data retention policies. The trust centre publishes three related controls, a data retention and disposal policy, a control stating that procedures are in place to retain customer data based on agreed-upon customer requirements or in line with information security policies, and a control providing that data no longer needed is removed from databases and file stores upon customer request in accordance with agreed customer requirements. Taken together those establish that a retention practice exists and is monitored, and that the period itself is set per customer in the agreement rather than published. No figure appears anywhere, nothing states how long discovered flow data, generated assessments, records of processing activities or scan results persist, and no retention setting is described as available to the customer in the product.

Transcend
Disclosed without a period

Deletion is committed with an outer limit and no standing retention period is published. Section 9 of the data processing addendum provides that on termination or expiry Transcend will, at the customer's election and written request, delete all Customer Personal Data in its possession or control as soon as reasonably practicable and within a maximum of thirty days, with the exception of data it must retain by law and data archived on backup systems, which it will securely isolate and protect from further processing. Absent such a request, deletion follows Transcend's standard retention policies, which are not published. The transfer schedule states retention only as the period needed to accomplish the purposes of processing. Nothing separates prompts submitted to the AI Features or their Outputs from customer data generally, and no zero-retention option is described. The architecture reduces the exposure structurally, since data handled through the self-hosted Sombra gateway is described as never leaving the customer's environment.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Relyance AI
Not addressed

Checked the home page, the four solution pages read, the terms of use in full, the privacy statement in full and the trust centre in full on 2 September 2026. Nothing describes segregation between customers or isolation of one organisation's data from another's. No tenancy model is stated. Two adjacent controls are published and both concern internal boundaries rather than boundaries between customers: development, staging and production environments are segregated, and access to customer data is restricted to personnel who need it on a least-privilege basis, with unique access identifiers and scheduled access reviews. Those describe how Relyance staff and systems are separated from customer data, not how one customer is separated from another. The question has particular weight on this product, because what the platform holds is a complete map of a customer's source code, data stores, identities and AI systems, which is close to a blueprint of the organisation's attack surface.

Transcend
Own model, documented

Transcend documents its own separation model and answers the question architecturally rather than by tenancy. Sombra is a security gateway the customer deploys inside its own infrastructure, and Transcend states that it enforces every data decision under the customer's security policies, that customer data never leaves the customer environment, and that Transcend does not see it. The key position is stated in the same terms: Transcend's backend never has access to customer API keys, Sombra manages that access with a built-in key management system that can optionally delegate to the customer's own service such as AWS KMS for hardware-backed keys, and Transcend cannot connect to customer systems directly because Sombra always sits in between. Every integration request passes through it tokenised, authenticated and encrypted. The data processing addendum confirms the effect, recording that where Sombra is used the scope of personal data collected is narrower. What is not addressed is separation inside a single customer, with nothing describing walls between teams, brands or matters.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Relyance AI
Disclosure addressed, notice absent

Compelled disclosure is addressed and notice is never reached. The privacy statement states that Relyance may share personal data as quoted, and appropriate, to respond to a lawful order such as a subpoena or to comply with other applicable law, and adds that it may disclose personal data to government agencies to protect or enforce its legal rights or to protect, investigate or deter fraudulent, unethical or illegal activity. That second limb is Relyance's own determination rather than a legal compulsion. Nothing anywhere commits to telling the customer that a demand has arrived, nothing undertakes to seek confidential treatment or to allow the customer to intervene, and no transparency report was located. Nor does anything reserve discretion over notice, so the question is not answered in either direction. The master services agreement and data processing addendum sit behind a request flow and may address it; neither was requested.

Transcend
Notice committed

A notice commitment is published in two places and goes further than notice alone, without a transparency report to complete the top value. The data processing addendum requires Transcend to promptly notify the customer of any government requests for access to or information about its processing of customer personal data unless prohibited by law, to provide reasonable cooperation and assistance, and, where it is barred from disclosing the details, to inform the customer that it can no longer comply with the customer's instructions and await further instructions. It adds an undertaking to **use all available and reasonable legal mechanisms to challenge demands for data access through national security process, as well as any non-disclosure provisions attached**, which is a stronger commitment than most vendors publish. The services agreement adds a general compelled-disclosure clause requiring prior notice where permitted, reasonable assistance to contest or limit at the disclosing party's cost, and disclosure of the minimum necessary. **No transparency report was located**, which is what holds this below the top value.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Relyance AI
Not addressed

Checked the home page, the about page, the four solution pages read, the terms of use, the privacy statement and the trust centre on 2 September 2026. Relyance ships no corpus of its own and none is claimed. The material the platform works on belongs entirely to the customer: source code in its repositories, runtime traffic, contracts, cloud infrastructure, identity directories and AI systems, all discovered in place rather than assembled into a collection Relyance holds. The provenance and licensing risks this signal tracks therefore sit with the customer rather than the vendor, and the honest record is that the question is not addressed rather than that a corpus was withheld. One dependency is worth noting and is not described anywhere: the platform states that it maps flows to their legal obligations and continuously realigns them as regulations change, which requires a body of regulatory content from somewhere, and no source, publisher, update cadence or licence basis is identified for it.

Transcend
Not addressed

No legal corpus is published and the product does not retrieve primary law. Transcend's decision layer encodes three inputs, described on the home page as business policy, jurisdictional regulation and customer permissions, so a maintained body of regulatory rules sits behind the jurisdictional limb, and nothing is published about it: no regulator, source, publisher or licensing basis is named, no jurisdictions are enumerated, and no update cadence is stated for how a change in law reaches the encoded rules. That is a narrower gap than for a research product, since the decisive corpus here is the customer's own data estate and consent record rather than a body of law, but it is not immaterial given the platform is sold on producing a defensible answer to whether data can be used. Checked the home page, the security page, the services agreement, the data processing addendum and the full footer on 1 September 2026.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Relyance AI
Not addressed

Checked the home page, the four solution pages read, the terms of use, the privacy statement and the trust centre on 2 September 2026. No public material addresses whether the legal material behind an obligation mapping is current or how a user would know. The product does not retrieve primary law for a reader, so a citator in its usual form has nothing to operate on, but the analogous question is live and unanswered. The platform states that it converts regulatory requirements into operational guardrails, that unified obligations mapping ties every flow to its legal, contractual and policy requirements automatically, and that consent purposes are continuously realigned with evolving legal frameworks with obligations updated automatically as regulations change. Nothing states how quickly a change is reflected, what jurisdictions are monitored, who maintains the regulatory content, or whether a user is shown the version or effective date of the rule an obligation rests on.

Transcend
Not addressed

No citator applies and the row is recorded rather than skipped. The platform returns a permissioning decision about a piece of data, not a legal authority whose subsequent history a user would need to verify. The nearest analogue is whether the encoded jurisdictional rules remain current as law changes, and nothing published describes how that currency is maintained or how quickly an amendment propagates into the Policy Engine. Searched the home page, the platform and solutions navigation, the services agreement and the data processing addendum on 1 September 2026.

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Relyance AI
Not addressed

Checked the home page, the four solution pages read, the terms of use, the privacy statement and the trust centre on 2 September 2026. Nothing describes what the platform does when it cannot determine an answer, and no confidence indicator is described as shown to the user for any classification, flow mapping or obligation assignment. Risk is scored, with compound risk stated to be scored across the graph rather than permission by permission, but that grades the customer's exposure rather than the system's confidence in its own finding. The enforcement action set does include escalation alongside allowing, redacting, masking, narrowing and blocking, which implies a path for cases the system will not decide alone, and nothing states what sends a request down it. A published third-party review notes the absence of ranking among identified risks; that is not first-party and is not relied on here.

Transcend
Not addressed

Nothing located describes what the system does when it cannot decide. No confidence score, abstention path, coverage indicator or fallback rule is published for the Policy Engine or the AI Features, which matters more than usual here because the product is explicitly sold as returning a real-time decision that other systems and agents act on before proceeding, so an uncertain or absent answer has to resolve to something. The two published statements closest to the question are disclaimers rather than behaviours: section 7.4 disclaims any warranty that Outputs from the AI Features are accurate, complete or reliable, and section 1.6 acknowledges that trial and beta features may generate or produce inaccurate information or unexpected or incorrect results. Searched the home page, the security page, the platform navigation and both published agreements on 1 September 2026.

Fabricated Citation Record

Does a public court record exist involving output from this product?

Relyance AI
None located

Searched the AI Hallucination Cases database maintained by Damien Charlotin, and reporting drawing on it, on 2 September 2026 on the product and corporate name Relyance AI and Relyance Inc. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product. The signal fits this product class poorly and the reason is worth recording: the platform produces data maps, records of processing activities, assessments and enforcement decisions rather than legal citations, so its characteristic failure is a missed data flow or a wrong obligation mapping rather than a fabricated authority in a filing. That failure would surface as a regulatory finding, an enforcement action against the customer or a breach, none of which any tracker indexes in the way the hallucination database indexes court sanctions.

Transcend
None located

Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name and on the Sombra product name. No court order, opinion or disciplinary record naming Transcend was located. This is a statement about the public record rather than a finding about the product. The failure mode fits poorly, since the output is a permissioning decision consumed by a downstream system rather than a citation prepared for filing; the analogous exposure would be a wrong clearance allowing data to be used for a purpose it was not permitted for, which would surface in a regulatory action or a class claim rather than in a sanctions docket.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Relyance AI
Not addressed

Checked the home page, the about page, the privacy teams and other solution pages read, the terms of use in full, the privacy statement in full and the trust centre on 2 September 2026. No public material engages guidance from any professional body governing the lawyers who use the product. No bar association material is named, ABA Formal Opinion 512 is not referenced, and nothing addresses the competence, supervision or candour duties of counsel relying on a machine-generated data protection impact assessment or record of processing activities. What the vendor engages extensively is legislation rather than professional conduct: GDPR, CCPA, Global Privacy Control, ePrivacy, HIPAA, the EU AI Act and individual state statutes are all named, and the company participates in privacy profession events. Naming the law a product helps a customer comply with is a different thing from naming the rules that govern the professional using it, and only the first is published.

Transcend
Not addressed

No engagement with professional responsibility or ethics guidance was located. Nothing references ABA Formal Opinion 512, any state bar opinion, Law Society or SRA guidance, or any regulator statement addressed to counsel using AI tools, and no general acknowledgement appears that a practitioner's own professional obligations survive use of the platform. The agreement does allocate legal responsibility to the customer, stating that the customer is solely responsible for its compliance with any laws, but that is an allocation of liability rather than a reference to guidance. The absence is more pointed here than at some peers because Transcend publishes a dedicated Privacy, Legal and Risk buyer page and markets the product as removing legal review cycles. Searched the home page, the security page, the Legal document index, both published agreements and the full footer on 1 September 2026.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Relyance AI
Savings claims only

Savings are claimed in headcount and time terms and the bill is never addressed. The published framing is that a customer can meet every privacy obligation without growing the privacy team, that manual inventories and questionnaires are replaced by continuous discovery, and that more than 1,600 systems and 100 flows are mapped in under two hours agentless from day one. Nothing addresses how AI-assisted work is recorded, billed or disclosed, and no per matter record of AI-assisted work was located. The signal's usual direction is inverted on this record, because the buyer is an in-house privacy or security function rather than a firm billing a client, so the compression accrues to the customer's own headcount rather than to an invoice. The nearest thing to the question the signal asks concerns outside counsel indirectly: assessments and records the platform generates are work that privacy counsel would otherwise scope to a law firm, and nothing published addresses how that shift is reflected in a firm's engagement.

Transcend
Savings claims only

Savings and revenue claims are central to the marketing and no billing or disclosure treatment exists. Transcend leads with 1.9 billion dollars of revenue unlocked, publishes a preference management return-on-investment calculator, and sells on removing three-week legal review cycles and eliminating the data subject request ticket queue. Nothing accompanies that on how AI-assisted or automated compliance work should be disclosed or billed where an adviser performs it for a client. The buyer is an in-house privacy, legal, data or marketing function rather than a firm billing a client, so the question lands obliquely, and it is not absent given the platform produces system-level proof of every decision that could in principle support such a disclosure. No per-matter record framed for that purpose is described.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Relyance AI
On request only

The material exists, is enumerated, and is not published. The trust centre lists a subprocessor list, a data processing addendum and a master services agreement as available documents, alongside a SOC 2 Type 2 report, an ISO 27001 certificate, a CSA CAIQ version 4 self-assessment, a security whitepaper and a penetration test executive report, each reachable through a request control rather than a download. That the artifacts are named and inventoried is itself informative and puts this above the bottom value. Two things are freely available and are the only forwardable material a prospect holds today: the privacy statement, which is public, versioned at 2.3 and links its own previous version, and the responsible disclosure policy. Public certification under the EU-U.S., UK Extension and Swiss-U.S. Data Privacy Frameworks is separately verifiable on the Department of Commerce register. No model provider is named anywhere, so even the requested subprocessor list is the only route to answering which AI providers touch customer content.

Transcend
Subprocessors listed

Two of the three artifacts a client's AI clause asks for are openly published, and the model provider limb is missing. On the open side, and this is strong: the services agreement, the data processing addendum, the service level agreement and the acceptable use policy are all published without gating, each dated, and the DPA carries completed EU standard contractual clauses with the module and clause elections set out, the UK addendum and the FADP variations, plus **a maintained subprocessor list published at the documentation site with fifteen days' notice of additions and an objection route**. That is forwardable material a firm can send a client without negotiation. The gap is the AI surface: **no model provider is named anywhere**, and the agreement confirms that large language models are in scope of the Services without identifying whose. Under the coverage test a firm can therefore describe the processing chain but not say which models see its content, which is what keeps this below the top value.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Relyance AI
Not addressed

Checked the home page, the four solution pages read, the terms of use, the privacy statement and the trust centre on 2 September 2026. Nothing addresses disclosure of the platform's own AI use to a court, regulator or auditor, and no exportable record of which model or classifier produced a given determination, on what confidence, or who reviewed it is described. The distinction matters on this record because evidence generation is a headline capability pointed the other way: the platform is sold on maintaining complete audit trails, delivering defensible evidence of consent state changes to regulators and auditors, logging every data touch as verifiable evidence rather than policy language, and producing audit-ready proof on demand. All of that evidences the customer's data practices to a third party. None of it is described as evidencing how the platform itself reached a conclusion, which is what a customer would need if a regulator questioned a record of processing activities the system generated.

Transcend
Partial record

The record is real, produced automatically, and built for a regulator rather than for an AI-use disclosure. Transcend markets audit-ready records by default, complete records for regulators, mergers and acquisitions and litigation, closed-loop data subject request fulfilment with system-level proof of every request, and a decision log in which every use is defined and enforced. The data processing addendum adds an events logging measure recording that all key actions such as logins, data writes and configuration changes are attributable to particular users with date and time stamps, centralised and protected from change. That is a stronger evidentiary trail than most vendors in this lane publish, and litigation is named as a use for it. What it does not do is identify the machine's contribution: nothing states that the record distinguishes decisions produced by the AI Features from deterministic policy decisions, or captures which model produced an output, so a user could not assemble an AI-use disclosure from it.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • AI Governance and Bias Disclosure
  • Commercial Transparency
Signals neither addresses in public material
  • Primary Law Corpus Provenance
  • Good Law Verification
  • Refusal and Uncertainty Behaviour
  • Bar Guidance Alignment

Which one fits

Choose Relyance AI if

  • Your data map is a spreadsheet somebody last updated in March. Relyance discovers data movement from several points at once, reading source code, watching runtime behaviour, scanning contracts and connecting to systems directly, and assembles the result into a live graph maintained from code through cloud infrastructure to AI models, with setup stated to be agentless and more than 1,600 systems and 100 flows mapped in under two hours.
  • The risk only appears where three things intersect. The Data Exposure Graph joins what data is sensitive, which identities hold permissions over it and how AI agents behave, and the AI governance layer inventories every agent, model, retrieval system and MCP server, detects each one's permission reach, and can block an over scoped agent in the CI/CD pipeline before it ships.
  • Your security reviewer wants to see the controls, not a badge. Relyance publishes a continuously monitored trust centre listing around fifty named controls with descriptions across change management, availability, confidentiality, vulnerability management, incident response, access and physical security, with ten documents available including the SOC 2 Type 2 report, the ISO 27001 certificate, a penetration test executive report, a cloud security questionnaire, the master services agreement and the data processing addendum.

Choose Transcend if

  • You want the whole contract before the first call. Transcend publishes its services agreement, data processing addendum, service level agreement and acceptable use policy openly, with a mutual liability cap, a defined set of excluded claims sitting outside it, a conformance warranty with correction or refund as the remedy, and a standalone warranty that Transcend will comply with all applicable laws in providing the services.
  • The data should not have to leave your environment to be governed. Sombra is a security gateway the customer runs inside its own infrastructure, through which every integration request passes tokenised, authenticated and encrypted, with the customer keeping its own API keys and optional delegation to its own key management service, and Transcend stating that customer data never leaves the customer environment and that it cannot connect to customer systems directly.
  • You want one answer to whether data may be used for a purpose. Transcend's policy engine encodes business policy, jurisdictional regulation and individual consent into a single real time decision that other systems and agents can call before they act, exposed through an API described as MCP native, with consent propagating to downstream marketing systems and data subject requests fulfilled across connected systems with system level proof of completion.

In summary

Relyance AI

Relyance AI maps where personal and sensitive data actually goes inside an organisation and ties each flow to the obligation that governs it, discovering movement from source code, runtime behaviour, contracts and direct system connections rather than from questionnaires, and assembling a live graph that joins data sensitivity, identity permissions and AI agent behaviour. The AI Legal Index grades it in the top two bands on six of fifteen capability axes, with an A on AI centrality. It publishes a continuously monitored trust centre listing around fifty named controls and ten documents available on request. As of 2 September 2026 the index located no hosting region, no tenancy model, no named model provider and no published price.

Source: AI Legal Index, 2026

Transcend

Transcend is a data permissioning and decision layer built to answer whether a given piece of customer data may be used for a given purpose, and to enforce that answer inside the systems that process the data, with consent and preference management, data subject request automation producing system level proof, and Sombra, a security gateway the customer runs inside its own infrastructure. The AI Legal Index grades it in the top two bands on eight of fifteen capability axes, with an A on data stewardship: its data processing addendum carries seventy two hour breach notification, deletion within thirty days and a maintained public subprocessor list. As of 1 September 2026 the index located no AI governance material and no published price.

Source: AI Legal Index, 2026

Questions buyers ask

Relyance AI vs Transcend: which do you need?

They answer different halves of the same question. Relyance finds out where data actually goes and what obligation governs each flow. Transcend decides whether a given piece of data may be used for a given purpose and enforces that decision inside the systems that process it. The AI Legal Index places Transcend in the top two bands on eight of fifteen capability axes and Relyance on six, and most of that gap is contractual rather than functional.

Where does the data actually go?

Transcend answers it architecturally, running Sombra inside the customer's own infrastructure so that integration requests pass through a gateway the customer controls, with its own API keys, and stating that customer data never leaves that environment. Relyance reads source code and runtime traffic and publishes no hosting region, residency option or tenancy model at all, which is a material gap for a platform sold to European privacy leaders. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

What can you read before signing?

On Transcend, the full estate: a services agreement, a data processing addendum with a maintained public subprocessor list and fifteen days notice of additions, a service level agreement and an acceptable use policy, with seventy two hour breach notification and deletion within thirty days of a request. On Relyance, a trust centre listing the documents including the master services agreement and the data processing addendum, each available through a request rather than published. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Do either govern their own AI?

Neither publishes anything about its own. Both publish extensively about AI governance as a customer problem, Relyance through an AI security hub and an agent inventory and Transcend through a do not train enforcement product, and neither states who inside the company is accountable for model behaviour, what is tested before a change ships, or whether output holds evenly. Transcend does publish a contractual bar on using inputs or outputs to train its AI features except for that customer's benefit. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

What do Relyance AI and Transcend both leave unpublished?

Neither publishes a price, a tier or a unit of charge, so a buyer cannot tell whether the meter runs per system, per data source or per seat. Neither names the model or provider behind its own AI features, which is conspicuous on two products whose function is to tell a customer which models touch its sensitive data. And neither publishes an accuracy measurement for the classification and mapping each depends on, where the failure mode is a flow that never surfaces rather than a visible error. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Disclosure

Both vendors sell AI governance and neither publishes any governance of its own models. No responsible AI framework, accountable owner for model behaviour, pre release testing regime or evaluation of uneven output was located on either record. That bites on Relyance because the platform classifies sensitive data and maps legal obligations across jurisdictions, languages and codebases of varying quality, and on Transcend because its agreement defines AI features and then, at section 7.4, disclaims any warranty that outputs of those features are accurate, complete or reliable. Two further points. Transcend's confidentiality carve out from its liability cap expressly excludes claims related to customer data, so a data incident stays inside the twelve month cap. On Relyance, no hosting region, residency option or tenancy model was located, and the master services agreement is available only on request. Both records were verified in early September 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 2, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746