CUBE
CUBE is an automated regulatory intelligence platform for financial institutions, built to turn unstructured regulatory text into obligations mapped to a particular firm. CUBE RegPlatform is sold in two editions, an enterprise version aimed at the largest institutions and an Intel version for the mid-market, and the platform monitors regulatory change across what the company states as more than 750 jurisdictions, classifying and contextualising rules and obligations by sector and jurisdiction so that compliance teams can track impact and manage change in one place. The technology is presented in unusual detail under the name RegAI, a proprietary framework the company says is trained exclusively on regulatory data. Its architecture runs in three layers: computer vision models convert document images into machine-readable content and recover the document hierarchy from headers to footers; a proprietary language model called RegLM applies deep natural language processing to translate, classify and contextualise regulatory text, fine-tuned for entity extraction, citation extraction, document type classification, obligation identification and summarisation; and graph machine learning places the enriched content into a regulatory knowledge graph that drives recommendations from user behaviour. RegBrain exposes that stack, including agentic AI, summarisation, classification and enrichment, for customers to apply to their own content through APIs or a user interface, and a separate Content Infrastructure offering supplies the underlying regulatory content. CUBE publishes six stated AI principles covering explainability, human input, semantic understanding, scale, security and sustainability. The company is CUBE Content Governance Global Limited, based at Tower 42 in London, reports more than 1,000 customers across banking, insurance, asset and investment management and payments, and announced the acquisition of Silicon Valley regtech 4CRisk for compliance and risk mapping automation.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of the capability being sold, on a content business that would survive without them. RegAI is described as a proprietary regulatory AI framework trained exclusively on regulatory data, and the enrichment it performs, turning unstructured regulatory text into obligations mapped to a firm's risk profile, is what a buyer is paying for rather than the raw feed. The architecture is real and staged: computer vision to recover document structure, a proprietary language model for classification and extraction, graph machine learning over a regulatory knowledge graph. What would remain if the models were removed is nonetheless substantial and is in fact sold separately: CUBE lists Content Infrastructure as its own solution, meaning the underlying regulatory content across a stated 750-plus jurisdictions is a saleable asset in its own right, alongside change workflow and the platform's tracking and reporting. That is the B shape. Third consecutive vendor in this lane at this grade, which is beginning to look like the shape of regtech rather than a coincidence.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
The method is documented more fully than anywhere else in this lane and no figure is attached to any of it. CUBE names its architecture layer by layer: computer vision converting text images to machine-readable content and revealing structural components from headers to body paragraphs to footers; deep NLP and a proprietary model called RegLM fine-tuned for entity extraction, citation extraction, document type classification, obligation identification and summarisation; and graph machine learning placing enriched content into a knowledge graph. Citation extraction as a named capability and the grounding of output in the source regulatory instrument mean a reader can reach the underlying text. Explainability is claimed as a product property, with advanced visualisation and interpretability tools said to show how AI decisions are made. The gap is measurement. RegAI is said to reduce noise by filtering out irrelevant updates, false positives and missed obligations, which names the two error types that matter here and attaches a rate to neither, and no benchmark, test set or accuracy figure was located on any surface read on 1 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Two real review mechanisms are published and the control structure around them is not. The first is inspection: CUBE states that it uses advanced visualisation techniques and interpretability tools to show users how AI decisions are made, offering transparency into model logic and reasoning, which is a described surface a compliance officer can open rather than a claim that a human is involved somewhere. The second is correction: real-time user feedback loops within the platform are said to refine and improve AI performance over time, and RegAI is described as learning from a customer's past decisions and becoming more aligned with its processes. What is missing is the rest of the structure. Nothing states what runs unattended, what threshold causes the system to defer, or what happens after an assessment is wrong. Worth separating one claim that does not carry weight here: the Human Input principle describes data scientists working with regulatory specialists to guide model development, which is a development practice rather than a runtime checkpoint in a customer's workflow.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
A large scale claim stands in for evidence and nothing under it is attributable. The home page states more than 1,000 customers across financial services including banking, insurance, asset and investment management and payments, and describes CUBE as the global market leader on multiple metrics, with no source, method or named institution behind either statement. No customer logo strip, named reference or dated deployment appears on any page read, and no figure for what changed at any customer was located. A Case Studies category exists in the Resources section and **was not opened on 1 September 2026**, so a named, dated outcome was neither located nor excluded and this grade is rebuttable upward on one fetch. The acquisition announcements and market-position claims that do appear are corporate news rather than deployment evidence. Checked the home page, the Technology and AI page, the privacy policy and the full site navigation.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Confidentiality is asserted in general terms and every question this axis asks is unanswered. The strongest statement located is on the Technology and AI page, where CUBE says that given the sensitivity of client data it has implemented security at three levels, backend access to its services, frontend access, and the data pipeline, and that all user data in the cloud is fully anonymised. That is a real architectural claim and it is not a confidentiality commitment a buyer could hold. No position on training customer content was located, which matters because RegBrain is expressly sold as applying CUBE's AI stack to a customer's own content. No retention or deletion commitment for that content exists, no segregation between customers or users is described, and no data processing agreement is published. The privacy policy, recovered through the R8 ladder, covers the website, the RegTrend app, events and recruitment, so it does not reach the platform relationship. **There is no customer agreement of any kind on the property**, so nothing published could be read as a commitment in advance.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Nothing published addresses the advice line for a product that produces regulatory interpretation. There is no terms of service, terms of use, master agreement or customer agreement anywhere on the property: the footer's Company section lists a privacy policy, a cookie policy and a separate RegTrend privacy policy, and nothing else. No statement was located that the output is not legal advice, that CUBE is not a law firm, that no professional relationship is created, or that a user should take professional advice on their own facts. No jurisdiction limit is named, and nothing addresses the supervision or competence of the person relying on the output. This matters because of who CUBE says the product is for: the home page names Risk and Legal Teams as an audience and states that CUBE gives legal teams the clarity they need to interpret the data and assess impact, which is interpretive work delivered to a professional audience with no published advice-line position behind it. Searched the home page, the Technology and AI page, the solutions and sectors navigation, the privacy policy in full and the complete footer on 1 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Six principles are published and nothing behind them is auditable. Under the heading of how it approaches the use of artificial intelligence, CUBE sets out explainability, human input, semantic understanding, built for scale, security and sustainable AI, and the content is more specific than the usual adjective list, describing interpretability tooling, feedback loops, models tuned exclusively on regulatory and legal data, three levels of security and a deliberate choice of smaller curated training datasets to reduce carbon footprint. What is absent is everything that would let a buyer test it. Nobody inside CUBE is named as accountable for model behaviour, no pre-release testing regime is described, no external standard is claimed, with no ISO 42001, no EU AI Act commitment and no third-party assurance located, and **nothing at all is published about uneven output**, which is a notable silence for a system whose core function is deciding which obligations are relevant to which firm, where a systematic miss is the failure that matters. The explainability tooling and feedback loops are real mechanisms but they are product features and are credited on the oversight row rather than counted twice here.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
A website privacy policy covers the marketing relationship without addressing what happens to customer content after processing. What is published, from the policy recovered through the ladder and dated 6 June 2026 at version 1.2: access to personal data restricted to staff, agents and contractors with a business need, all bound by confidentiality and acting only on instruction; procedures for suspected personal data breaches with a commitment to inform both the individual and the relevant supervisory authorities where legally required; retention only as long as reasonably necessary, with deletion or anonymisation afterwards; and transfers outside the UK and EEA under safeguards recognised by the relevant jurisdiction. Against that, no retention period is stated anywhere, no subprocessor list exists with third parties identified only as categories such as service providers and business partners, and the policy's own scope is the website, the RegTrend app, events and recruitment rather than the platform. Nothing published states what happens to the obligations mappings, impact assessments or customer content a firm places in RegPlatform, or to the content a customer submits to RegBrain.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Nothing published addresses who bears the loss when the system is wrong, because no agreement of any kind exists on the property. The complete footer offers a privacy policy, a cookie policy and a separate RegTrend privacy policy; there is no terms of service, no terms of use, no master subscription agreement, no service agreement and no data processing agreement. That is a more complete absence than the website-terms-only pattern seen elsewhere in this corpus, where at least a scoped disclaimer exists. No indemnity, liability cap, carve-out, warranty on output or insurance position was located, and no disclaimer of accuracy or completeness attaches to the regulatory intelligence itself. The only risk allocation located anywhere is a single line in the privacy policy stating that transmission of information over the internet is at the user's own risk, which concerns data in transit rather than the correctness of an obligation mapping. Searched the full footer, the home page, the Technology and AI page and the solutions navigation on 1 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
An integration route is stated and no destination system is ever named. RegBrain is described as delivering CUBE's full AI stack, including agentic AI, summarisation, classification and enrichment, either as APIs or through a user interface, so that customers can apply it to their own content, which establishes that a programmatic route exists and says what travels through it. A Partnering with CUBE page and a Content Infrastructure solution both imply that the regulatory content is designed to feed systems elsewhere. What is absent is anything an implementer could act on: no API reference or developer documentation was located, no integration directory exists in the site navigation, and not one GRC, risk, policy or document platform is named anywhere on the surfaces read, which is the same gap seen at Corlytics and a weaker position than AscentAI, which names five GRC partners on its home page. Checked the home page, the Technology and AI page, the solutions navigation and the footer on 1 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery is stated and neither the tenancy model nor a region is. The Technology and AI page says the models are deployed via cloud and scale with demand, and adds that all user data in the cloud is fully anonymised, but nothing names a hosting provider, a data centre location, a country or region option, or whether customers share infrastructure or receive a dedicated environment. No processing location is addressed separately from storage. The only geography published sits in the privacy policy and concerns personal data rather than platform content, stating that data may be transferred to group companies and service providers outside the United Kingdom and the European Economic Area or other local jurisdictions, with appropriate safeguards recognised by the relevant jurisdiction, and naming no specific mechanism. For a vendor selling to Tier 1 banks across a stated 750-plus jurisdictions, where data residency is routinely a procurement gate, that is a conspicuous silence. Checked the home page, the Technology and AI page, the privacy policy and the full navigation on 1 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
No independent security attestation was located anywhere. There is no security page, no trust centre and no compliance page in the site navigation, which was read in full on 1 September 2026 across the solutions, sectors, resources and company sections. No ISO 27001, SOC 2, ISO 42001 or equivalent is claimed on the home page, the Technology and AI page, the privacy policy or the footer, and no badge, certificate, auditor or report request route appears. The Technology and AI page does carry a Security principle, and it is the natural place a standard would be named: it describes security implemented at three levels covering backend access, frontend access and the data pipeline, and states that all user data in the cloud is fully anonymised, but it names no framework and no assessor. The privacy policy adds appropriate technical measures and breach procedures in general terms. **This is a striking absence rather than a routine one**, given a vendor of this scale selling to the largest regulated institutions, and it is recorded as what the public surfaces show rather than as a claim about what CUBE holds.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The architecture is disclosed in more detail than anywhere else in this lane and the third-party question is left open. CUBE names its own components: RegAI as the framework, **RegLM as a proprietary language model** fine-tuned for translation, classification and contextualisation, and RegBrain as the stack exposed to customers. It describes what each layer does, computer vision for document structure recovery, deep NLP for extraction and classification, graph machine learning over a knowledge graph, and states that the models are tuned exclusively on regulatory and legal data and deployed via cloud. That is architecture described with the vendor's own models named, which is the second limb of this band. What is not answered is whether any third-party foundation model is called at any point: no external provider is named, no statement excludes one either, and RegBrain is said to include agentic AI, which usually implies a general-purpose model somewhere in the chain. No commitment to notify customers when the model set changes was located.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. The site navigation was read in full on 1 September 2026 and contains no pricing entry; every commercial route on every page read is a demo request or a Speak to an expert form. No rate, band, floor, currency or per-seat, per-jurisdiction or per-obligation unit was located, and nothing states what implementation adds, which is material for a platform whose value depends on building a firm-specific obligations map. The only commercial shape visible anywhere is the split of CUBE RegPlatform into two editions aimed at different customer sizes, one for Tier 1 institutions and an Intel edition for the mid-market, which segments the market without pricing it. Those two edition pages were not opened, so if either carries a feature split or a figure this grade is rebuttable upward.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described with real substance across three separate axes and the boundary is left open. CUBE segments its sectors pages by industry, by requirement and by department, which is a more deliberate structure than most vendors publish, and names its industries as banking, insurance, asset and investment management, payments and associated industries. Firm size is addressed explicitly rather than implied, with RegPlatform split into an enterprise edition for Tier 1 institutions and an Intel edition for the mid-market, and audience is broken out into compliance leaders, financial services enterprises, and risk and legal teams. Regulatory scope is quantified at more than 750 jurisdictions and illustrated with named regimes including GDPR, DORA, MiFID II, SOX, FCA and FSB material. What is not stated is where the product stops: no statement of the practice areas, sectors or obligation types the platform does not cover was located, and outside financial services the coverage claim is left to the phrase associated industries.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way.
No located term or policy addresses the question either way, and there is no agreement on the property in which a commitment could sit. The silence is pointed rather than routine because RegBrain is expressly sold as applying CUBE's AI stack to a customer's own content through APIs, so customer material demonstrably enters the system. The two nearest statements do not answer it: the Technology and AI page says the models are tuned exclusively on regulatory and legal data, which describes the training corpus without excluding customer content from future training, and separately says that all user data in the cloud is fully anonymised, which is a handling claim rather than a training prohibition. The privacy policy covers the website, the RegTrend app, events and recruitment and does not reach platform content. Searched the home page, the Technology and AI page, the full privacy policy and the complete footer on 1 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
No located public material states how long customer inputs or generated outputs are kept, and no configurable or zero-retention option is described. The only retention statement published is in the website privacy policy and is qualitative rather than periodic: personal data is kept only as long as reasonably necessary for the purposes it was collected for, including legal, regulatory, tax, accounting and reporting requirements, with longer retention where a complaint or prospective litigation exists, and deletion or anonymisation once it is no longer needed. That is scoped to personal data and to the website and app relationship. Nothing addresses the obligations mappings, impact assessments or submitted content that make up the platform record. Searched the privacy policy in full, the Technology and AI page and the footer on 1 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses walls or matter level segregation.
Nothing located addresses segregation between customers, teams or users. The nearest statement is architectural rather than about permissions: the Technology and AI page describes security implemented at three levels, backend access to services, frontend access to services and the data pipeline, and states that all user data in the cloud is fully anonymised. That describes where controls sit and how data is handled in aggregate, not who can see what inside a customer account. The privacy policy limits access to CUBE staff, agents and contractors with a business need, which governs the vendor's own people rather than the customer's. Nothing states whether RegAI classification or the knowledge graph respect any customer-side boundary at query time, which is a live question because the graph is described as drawing on user data to recommend content. Searched the Technology and AI page, the privacy policy and the solutions navigation on 1 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located term or policy addresses third party requests for customer data.
Disclosure to authorities is described and notice is not addressed at all. The privacy policy provides that CUBE may occasionally pass parts of personal data to authorities where obliged to disclose in order to comply with a legal obligation, to enforce its terms and other agreements, or to protect the rights, property or safety of its customers or others, including sharing with other companies and organisations for fraud protection, and states that it discloses only what is legally necessary. No commitment to notify the customer before or after such a disclosure appears, and no discretion over notice is even reserved, which distinguishes this from the comparable clause at Corlytics where the vendor at least commits to take legal advice and weigh the individual's interests first. No transparency report exists, and the clause is scoped to personal data rather than to platform content. Searched the privacy policy in full and the footer on 1 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Coverage is described by jurisdiction with no identification of the underlying corpus.
Coverage is quantified by jurisdiction and the underlying corpus is never identified. CUBE states surveillance across more than 750 jurisdictions and illustrates scope with named regimes including GDPR, DORA, MiFID II, SOX, and material from the FCA and FSB, describing its input as unstructured regulatory data transformed into actionable intelligence. No regulator feed, publisher, data supplier or licensing arrangement is named anywhere on the surfaces read, and no update cadence is published beyond the claim of real-time and 24/7 surveillance. Content Infrastructure is sold as a distinct solution, so the corpus is a commercial asset in its own right, which makes its provenance a more material question here than for a vendor that only consumes public sources. Checked the home page, the Technology and AI page and the solutions navigation on 1 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
The vendor computes and surfaces subsequent history itself, with the method described.
The regulatory analogue is the product's core function, and it is described less concretely than at the two lane peers. CUBE monitors regulatory change across a stated 750-plus jurisdictions on a continuous basis and maps what has changed to the obligations a firm holds, so the platform is computing and surfacing the subsequent state of a rule over its own corpus rather than licensing a treatment service. Impact analysis and mapping are named as automated capabilities. Two limits belong on the record. **No version comparison or redlining feature was located**, unlike AscentAI and Corlytics which both publish side-by-side old-versus-new rule views, so a user's ability to see exactly what changed is not evidenced. And the currency of the corpus is asserted through the words real-time and 24/7 rather than through any stated lag between a regulator publishing and the platform reflecting it.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Nothing located describes what the system does when it cannot classify or map reliably, which is the question the category editorial makes decisive. No abstention path, confidence score, relevance threshold or coverage indicator is published for classification, obligation identification or summarisation. CUBE names the two failure modes in passing, saying RegAI reduces false positives and missed obligations, without describing what a user sees when either is possible. The explainability tooling comes closest and answers a different question: interpretability tools showing how an AI decision was made give transparency about a decision the system did reach, not a signal that it could not reach one. Searched the home page, the Technology and AI page including the six AI principles, and the solutions navigation on 1 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name and on the product names RegPlatform and RegAI. No court order, opinion or disciplinary record naming CUBE or its products was located. This is a statement about the public record rather than a finding about the product. The failure mode fits obliquely: the output is a regulatory classification or obligation mapping consumed inside a compliance function rather than a citation filed with a court, so the analogous exposure would be a missed or misattributed obligation surfacing during a supervisory examination rather than in a filing.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No engagement with professional responsibility or ethics guidance was located, and no document exists on the property in which it could sit. There is no terms of service, no professional responsibility statement and no ethics page; the footer offers only a privacy policy, a cookie policy and a separate RegTrend privacy policy. Nothing references ABA Formal Opinion 512, Law Society or SRA guidance, or any regulator statement on the use of AI within a compliance or legal function. Nor is there a general acknowledgement that the user's own professional obligations survive use of the tool, which several vendors in this pull do publish. This sits against a home page that names Risk and Legal Teams as a target audience. Searched the home page, the Technology and AI page, the sectors navigation, the privacy policy in full and the complete footer on 1 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Efficiency claims are central to the marketing and billing is never addressed. The home page is built on reducing risk and increasing efficiency, and the Technology and AI page states that RegAI saves valuable time and effort otherwise spent sifting through information, reduces the cognitive load on the compliance team and eliminates reliance on manual tasks. Nothing accompanies that on how AI-assisted regulatory analysis should be billed or disclosed. The buyer here is an in-house compliance or legal function rather than a firm billing a client, so the question lands obliquely, but it is not absent: nothing addresses the position where an adviser uses the platform on a client's behalf, and no per-matter or per-assessment record of AI-assisted work is described that would support such a disclosure.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
Nothing that would support a client-side disclosure obligation is published, and the reason is a distinction worth recording. CUBE names its own models with unusual specificity, RegAI, RegLM and RegBrain, and states they are tuned exclusively on regulatory and legal data. **Naming your own model is not the same as answering whether anyone else's model sees the content**, and that question is left open: no third-party provider is named, no statement excludes one, and RegBrain is said to include agentic AI. No subprocessor list exists, with third parties identified in the privacy policy only as categories such as service providers and business partners. No data processing agreement, consent pack or client-facing disclosure material is published and no route to request one was located. Under the coverage test this fails, since a firm cannot state which systems touch its content. Searched the Technology and AI page, the privacy policy in full and the complete footer on 1 September 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Some elements exist and no document-level export is described. Two things point the right way. The platform is marketed on the ability to centralise, streamline and audit-proof an entire regulatory framework at scale, so an activity record for examination purposes is claimed. And the explainability tooling is directly relevant to this signal in a way it is not for most vendors, since interpretability tools showing how an AI decision was made are part of what an AI-use disclosure would need to contain. What is missing is the export and the attribution: nothing states that the record identifies which outputs were machine-generated, which model produced them, what corpus was drawn on, or who reviewed them, and no per-document extract is described. As with the other vendors in this lane the artifact is built for a supervisor rather than a court. Checked the home page, the Technology and AI page and the solutions navigation on 1 September 2026.