H
Hadrius
Hadrius is an AI compliance platform for firms regulated by the SEC and FINRA, sold by Quantbase Investments, Inc. of New York. It consolidates the supervisory programme a registered investment adviser or broker-dealer is required to run into one system: AI review of marketing and advertising against the SEC Marketing Rule, ADV requirements and performance presentation standards; supervision of email, chat and social across more than sixty channels with FINRA and SEC-aligned archiving under 17a-4 and WORM retention; surveillance of employee and firm trading against restricted lists, blackout windows and personal trading rules; people oversight covering attestations, certifications, outside business activities, gifts and political contributions; a testing programme carrying policies, risk, controls testing, issues and annual reviews; and branch examination management.
Every review, escalation, approval and remediation is timestamped into an audit trail the firm can produce at an examination. Buyers are broker-dealers, RIAs, private funds and the compliance consultants who serve them, and the platform is configured to each firm's own compliance manual. The agreement requires the firm to configure its own surveillance rules and thresholds, and states that AI output is informational and must be independently verified by qualified compliance personnel before it is relied on.
Customers include M1 Finance, Republic Capital, SmartAsset, Csenge Advisory Group and United Advisor Group, each quoted through a named compliance officer.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the proposition and the vendor argues the point itself: if AI is generating the communications, the marketing and the trades, only AI can review them at the same scale. Every module's described value is a machine determination. Marketing review reads content against the firm's rules and disclosure requirements and routes it for approval. Communications supervision normalises threads across more than sixty channels and cuts false positives, which the vendor puts at 99 per cent against legacy tools.
Account surveillance runs pattern tests over employee and firm trading against restricted lists and blackout windows and escalates what matters. The testing programme, attestations and branch examinations sit around those determinations as workflow. Strip the models out and what remains is an archive and a task tracker, which is what the platform is sold against. The agreement calls the same thing by its plainer name, describing AI-generated compliance outputs, automated approvals and recommendations. Verified 20 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Six outcome figures are published and none of them measures whether the determinations are right. The estate carries 99 per cent fewer false positives, a 96 per cent reduction in time spent on communications supervision, a tenfold reduction in marketing review cycle time, 19-plus hours gained back weekly per user, $3,900 average annual cost reduction per representative, and $5 trillion in assets across more than 500 firms.
Not one carries a period, a sample, a baseline or a method. Nothing addresses the failure that matters most in supervision, which is the violation the system does not flag. The agreement is candid where the marketing is not, stating that the services use artificial intelligence which is inherently not error-free, that outputs are informational only, that no warranty is given as to their accuracy, completeness or reliability, and that the customer must independently verify every AI-generated output before relying on it. Verified 20 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The review point is stated and the thresholds belong to the customer. The vendor's own framing is a system of record that executes compliance operations under human governance, and the agreement puts that in enforceable terms: AI-generated outputs, automated approvals and recommendations are informational only, the customer must independently verify them before relying on them, and the vendor disclaims liability for regulatory penalties arising from reliance on automated outputs without independent review by qualified compliance personnel.
Escalation and routing are described, with the AI triaging risk so reviewers clear supervisory queues in priority order. Two things hold it here. The controls are the customer's to set: the agreement makes the firm responsible for configuring surveillance rules, alert thresholds, restricted securities lists and retention periods, and says the vendor does not warrant that any configuration satisfies the firm's regulatory obligations.
And automated approvals are referred to without any published description of what may be approved without a person. Verified 20 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named firms, named officers and real figures, never joined to each other. Five customers are quoted on the home page through the person accountable for the programme: Tealee Hinger, Chief Compliance Officer at M1 Finance; Robert Spake, Chief Compliance Officer at Republic Capital; Michael Schmidtke, Chief Compliance Officer at Csenge Advisory Group; Laurie Williams, Deputy Chief Compliance Officer at SmartAsset; and Raymond Gettins, Director at United Advisor Group.
Three case studies are published, for Stirlingshire Investments, Lifemark Securities and Arrived, the last headlined as a tenfold reduction in weekly marketing review time. Scale is claimed at more than 500 institutions and $5 trillion in assets under management, with fifteen further customer logos. What is missing is the join and the method: no figure is attached to a named firm on the surfaces read, and no measurement period or baseline is given for any of them. Verified 20 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive written commitments, readable before signing, with the training carve-out as the thing to weigh. The Master Services Agreement carries mutual confidentiality on a need-to-know basis with no less than reasonable precautions; deletion of the other party's proprietary information promptly after termination, subject to record-keeping law; and a compelled-disclosure clause requiring reasonable prior notice so the disclosing party can contest the order.
The customer retains ownership of its inputs and is assigned the outputs. A data processing agreement is incorporated by reference and available on request, and the privacy policy is explicit that communications content, trading activity and employee information are processed solely on the customer's instructions with the customer as controller. Against that: the agreement permits the vendor to use inputs and outputs to improve its products, including to train AI models, once aggregated and anonymised. No subprocessor list was located and privilege is not addressed. Verified 20 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
The advice line is drawn in the agreement, in terms, and it names the professional who has to do the checking. The Master Services Agreement states that AI-generated compliance outputs, automated approvals and recommendations are provided for informational purposes only and do not constitute legal, regulatory or professional compliance advice; that the customer must independently verify all AI-generated outputs before relying upon them and assumes sole responsibility for decisions based on them; and that the vendor disclaims liability for regulatory penalties arising from reliance on automated outputs without independent review by qualified compliance personnel.
A separate clause states that the service is designed to assist with SEC and FINRA compliance but does not guarantee compliance, and that the customer remains solely responsible for all compliance obligations, regulatory filings and supervisory decisions. Configuration is handled the same way: the vendor gives implementation assistance and does not warrant that any configuration satisfies the firm's regulatory obligations. Who the product is for, what it is not, and whose judgement governs are each stated. Verified 20 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A governance posture is stated and no mechanism sits behind it. The published position is that the platform executes compliance operations under human governance, that the AI is policy-aware and configured to each firm's compliance manual, and that it runs on zero-data-retention AI; the agreement adds an acknowledgement that artificial intelligence is inherently not error-free. The vendor also publishes a recorded session for compliance officers on what AI can and cannot do in automating compliance work, which is education for buyers rather than a statement about its own model.
Nobody inside the company is named as accountable, nothing is published about what is tested before a change ships, and there is no disclosure of whether output differs across channels, languages, firm types or the populations an adviser communicates with. On a product whose false-positive rate is its headline claim, the absence of any published testing regime behind that number is the gap. Verified 20 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Most of the ground is covered, and the incident clause is stronger than most in this index. Published: TLS 1.2 or above in transit and AES-256 at rest, role-based access control, multi-factor authentication and single sign-on, firewalls, intrusion detection and vulnerability scanning, employee training and confidentiality undertakings. Retention is the customer's to set, with the agreement making the firm responsible for configuring retention periods to its regulatory requirements, alongside write-once archiving to the 17a-4 standard.
The AI layer is described as zero-data-retention. The agreement commits to notifying the customer within seventy-two hours of confirming a security incident involving data subject to Regulation S-P, providing written detail of the incident's scope, preserving forensic evidence, producing incident reports suitable for regulatory examination and cooperating with the customer's own notification obligations. The gaps: no subprocessor list was located, and the security page itself would not render. Verified 20 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A real published position, and the exposure the product creates sits outside it. The Master Services Agreement carries a mutual indemnity with stated scope: the vendor defends claims that its underlying software infringes third-party intellectual property, the customer defends claims arising from its own use and its inputs, with six carve-outs and a defined procedure. Liability is capped at the fees paid or payable in the twelve months before the claim, with consequential, indirect, punitive and lost-profit damages excluded both ways and indemnification obligations sitting outside the cap.
The vendor warrants that the services will be provided in a professional and workmanlike manner by qualified personnel. What is expressly excluded is the loss a compliance officer would actually fear: the agreement states that the vendor is not liable for regulatory enforcement actions, fines or sanctions imposed on the customer or its personnel, and disclaims liability for penalties arising from reliance on automated outputs without independent review. No insurance is referenced. Verified 20 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The systems this work actually lives in are named, in the agreement rather than on a logo wall. The agreement lists what a customer connects: email through Gmail and Microsoft Exchange, communication platforms including Slack, WhatsApp, LinkedIn and Telegram, and financial data providers including Plaid for brokerage account feeds. The estate puts the count at more than sixty communications channels captured, supervised and archived in real time, and a July 2026 integration adds Claude Enterprise, pulling employee conversations from that platform into the same books-and-records archive.
What is not published is depth: nothing describes what syncs in which direction, what a firm must configure beyond the agreement's statement that permissions, authentication and access controls are the customer's responsibility, and no developer documentation or API reference was located. The agreement is also frank that third-party integrations are a convenience, that continued availability is not guaranteed, and that the vendor is not liable for data gaps arising from them. Verified 20 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery is implied throughout and neither half of the question is answered. Nothing published states where the data sits: no region, no country, no cloud provider, and no residency option for a firm with obligations outside the United States, although the agreement's export control clause bars access from embargoed countries. Nothing published states how customers are separated from one another either: no tenancy model, no single-tenant or private option.
The one separation fact that is published sits inside an account rather than between accounts, in the multi-tenant workspaces offered to compliance consultants so they can run several client firms from one login, and in the branch and org-chart structure. The page where residency would normally sit, the vendor's security page, returns navigation only because the site renders client-side, and one search on its own vocabulary recovered nothing; that limit is recorded rather than read as an absence. Verified 20 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Standards are named and no route to the evidence was found. The footer carries three marks on every page: ISO 27001, the AICPA SOC badge and GDPR, and the security page's own published description names SOC 2 compliance alongside bank-level encryption and zero-retention AI. Named standards put this above the floor, which is reserved for a site claiming certification without naming one. What is absent is everything a buyer would check them against.
No audit period, no scope or coverage statement, and no auditor is published anywhere. No trust centre exists and no request route for a report was located, so nothing is shown to be obtainable with or without a sales conversation. The security page itself returns navigation only, the site being client-side rendered, and one search on the vendor's own security vocabulary recovered no body text; that retrieval limit is recorded rather than treated as an absence.
What is contractual rather than certified is the incident clause, recorded on the stewardship row. Verified 20 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
A retention promise is made about model providers who are never identified. The estate repeats that the platform is powered by zero-data-retention AI and that supervision runs through privacy-first, zero-retention models, which is a commitment about what a provider may keep. No provider, model or version is named anywhere for the review engine, nothing says where inference happens, and nothing commits to telling customers when any of it changes.
One name does appear and it is not the model behind the reviews: a July 2026 integration with Claude's Compliance API pulls employee conversations out of Claude Enterprise into the archive, which makes that platform a source of records to supervise rather than the engine doing the supervising, and it is recorded as an integration. The agreement adds nothing on the point beyond permitting the vendor to train on aggregated and anonymised inputs and outputs. Verified 20 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The shape is visible and the number is not. Six modules are published as separate solutions, testing programme, marketing, people oversight, communications, account surveillance and branches, so a buyer can see what the product is divided into. The agreement names the billing structure: fees are set in an order form, invoices fall due within thirty days, past due balances carry the lesser of 1.5 per cent a month or the legal maximum, order terms renew automatically for successive twelve-month periods unless either side gives thirty days' notice, and fees can be raised on thirty days' notice at renewal.
The audit clause names the unit in passing, requiring the customer to keep records of user counts and module usage relevant to its payment obligations. No rate, band, minimum or implementation figure is published anywhere, there is no pricing page in the navigation or footer, and the only route is a demo request that asks for firm size in four bands. Verified 20 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Four buyer segments, each tied to the rules it answers to, and no statement of where the product stops. Broker dealers get supervision under FINRA Rules 3110, 3120 and 3130 with 17a-4 and write-once retention and evidence for the chief executive's annual certification. RIAs get SEC Rule 206(4)-7 operationalised, with programme testing, annual reviews and Marketing Rule workflows. Private funds get personal trading surveillance against restricted lists and blackout windows with Code of Ethics attestations and conflict tracking.
Compliance consultants get multi-tenant workspaces to run several client firms. Firm size is addressed from one to fifty users up to more than five thousand on the demo form, and the named customers span a large retail broker, a wealth platform and small advisory groups. What is absent is the boundary: nothing says which regimes are out of scope, and a firm with banking, insurance or non-US obligations is left to infer. Verified 20 September 2026.
4 public documents
The public pages on file for Hadrius, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.
-
Third Party Request and Subpoena Notice, Bar Guidance Alignment, Outside Counsel Guideline Readiness and 1 more
Read Sep 20, 2026
-
hadrius.com3 signals
Refusal and Uncertainty Behaviour, Billing and Fee Posture, Prompt and Output Retention
Read Sep 20, 2026
-
hadrius.com/solutions3 signals
Primary Law Corpus Provenance, Good Law Verification, Court Disclosure Support
Read Sep 20, 2026
-
Ethical Walls and Matter Segregation
Read Sep 20, 2026
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The published agreement expressly reserves a right to train on customer content, with no opt out located. Any de identification, anonymisation or aggregation qualifier is recorded in the summary.
Training is named in the agreement, permitted, and gated on a condition that is stated precisely. The Master Services Agreement's primary rule is a purpose limit: inputs and outputs are used solely to provide the services, comply with law, enforce the agreement and prevent abuse. The carve-out that follows is what decides the value: the vendor may use inputs or outputs to improve its products and services, including to train AI models, but only after first aggregating and anonymising them so that neither the customer nor any individual may be identified.
No opt out from that use was located in the agreement. Usage data is treated the same way, disclosed only in aggregated or anonymised form. A buyer should read that against the marketing, which repeats that the platform runs on zero-data-retention AI; that promise is about what a model provider keeps during a review, not about what the vendor may do with the material afterwards. The two sit together and only one of them is in the contract. Verified 20 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
A specific retention period is published and the customer cannot change it.
Two retention regimes run side by side and a buyer needs both. At the AI layer the claim is zero: the estate repeats across the home page, the solution pages and the buyer pages that supervision runs on zero-data-retention AI, which is a commitment that what is sent for review is not kept by the model. At the record layer the opposite is the point of the product, because the firm is required to keep things: communications are captured and archived to the SEC's 17a-4 standard with write-once retention, and the agreement makes the customer responsible for configuring retention periods to its own regulatory requirements.
So the window for a prompt is stated as none, and the window for the underlying record is the firm's to set. What is not published is the detail behind the zero: no model provider is named, so the promise cannot be checked against whoever would have to keep it, and no retention period is stated for review outputs held inside the platform.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
Separation is documented at the level this product needs it, which is between client firms inside one account. Compliance consultants are sold the platform expressly to deliver reviews, testing and evidence packs across several client firms from multi-tenant workspaces, and the branches module carries the same structure inside a single firm, managing branch examinations, personnel org chart, questionnaires and remediations as separate units.
Access is controlled by role, with multi-factor authentication and single sign-on, and the agreement puts the configuration of those permissions on the customer. The audit trail records who reviewed, escalated, approved and remediated what, so a determination is attributable to a person. What is not addressed is a conflicts wall in the legal sense, screening a named reviewer from a particular firm or matter, which matters most in the consultant configuration where one reviewer may serve competing advisers.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Terms commit to notice where lawfully permitted. No transparency report located.
The commitment is in the agreement and it is aimed at letting the customer fight. The confidentiality section provides that nothing prevents a party from disclosing the other's proprietary information pursuant to a judicial or governmental order, provided it gives reasonable prior notice of the disclosure so the other party can contest that order. It is mutual, it requires notice before rather than after, and the stated purpose is the contest rather than mere courtesy.
Alongside it sits a related and unusual commitment: the vendor agrees to cooperate with the customer's own regulatory examinations by providing documentation and making personnel available, with the customer reimbursing out-of-pocket costs beyond eight hours a year. What is not published is any operational detail, a named contact, a practice of narrowing what is produced, or a timeframe, and no transparency report exists.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Sources are identified without stating the licence or rights basis.
The rules are named and where the rule content comes from is not. Published coverage runs to the SEC Marketing Rule, ADV requirements and performance presentation standards, FINRA Rules 2210, 3110, 3120 and 3130, Regulation Best Interest and suitability, Rule 17a-4 and write-once retention, Regulation S-P, and the Code of Ethics and personal trading rules that govern an adviser's employees. The other half of the corpus is the customer's own, described as policy-as-code and configuration to each firm's compliance manual, with the agreement making the firm responsible for setting its own surveillance rules, thresholds and restricted lists.
Nothing states who writes or maintains the regulatory rule content, how quickly a rule change reaches the platform, or on what basis any source is used. What matters for membership is that no third-party regulatory content provider is named anywhere, so the analysis is the vendor's own.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
This product cites no authority a reader could open, so there is nothing for a treatment signal to rest on. Its output is a determination about a piece of marketing, a communication or a trade, together with an audit trail, rather than a proposition of law with a citation behind it. The rules it applies are named in the marketing, but no published material describes how the platform keeps current with them: nothing says who monitors SEC or FINRA rule changes, how long a change takes to reach the review logic, or whether a firm is told when a rule it relies on has moved.
For a product sold on being exam-ready that currency question is the nearest analogue to a treatment signal, and it is unanswered. Checked the home page, the solutions overview, the buyer pages, the insights index and the Master Services Agreement on 20 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
The product exposes a confidence or grounding score without an explicit abstention path.
Uncertainty is expressed as risk ranking, and what the system does when it cannot tell is not described. The published behaviour is triage: the AI routes and prioritises the highest-risk trades, communications and marketing materials so reviewers clear supervisory queues in order, with intelligent escalation and a claimed 99 per cent reduction in false positives. That is a confidence-shaped signal applied to workload rather than to knowledge.
Nothing published describes an abstention, a threshold below which the system declines to decide, or what a reviewer sees when the model has no basis for a judgement as distinct from a low-risk one. The agreement approaches the same ground from the other side, requiring the customer to verify every AI-generated output independently before relying on it and disclaiming liability where automated outputs are relied on without review by qualified compliance personnel.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.
No record was located of this product's output being found fabricated or inaccurate in a proceeding, a regulatory action or a published account. Searches on 20 September 2026 across the vendor's estate, press and directory profiles returned nothing of the kind. The exposure here is not an invented citation, because the product asserts no law and cites no authority: the failure that would matter is a communication or an advertisement that cleared automated review and later drew an SEC or FINRA finding, or a trade pattern the surveillance did not escalate. Nothing published describes such a case, and no account of one was found.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Public materials refer to professional responsibility in general terms without naming guidance.
Professional obligation is referred to as such, and no rule, opinion or bar is named. The Master Services Agreement states that AI-generated compliance outputs, automated approvals and recommendations are informational only and do not constitute legal, regulatory or professional compliance advice, and that reliance without independent review by qualified compliance personnel is the customer's own risk. A second clause puts supervisory decisions and all compliance obligations squarely on the customer.
That is the duty engaged in general terms. What the estate names in abundance is regulation binding the firm rather than guidance binding a practitioner: the SEC Marketing Rule, FINRA 2210, 3110, 3120 and 3130, Regulation Best Interest, 17a-4, Regulation S-P, Rule 206(4)-7. None of that is bar or ethics guidance. No rule of professional conduct, ethics opinion or bar publication appears anywhere, and nothing engages the guidance on lawyers' use of generative AI.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.
No lawyer's fee sits in this product's path. The buyer is the regulated firm itself, or a compliance consultant serving several such firms, and the subscription is an operating cost carried by the firm rather than anything billed on to an advisory client. The vendor's economic case is internal efficiency, published as 19 or more hours gained back weekly per user and an average annual compliance cost reduction of $3,900 per registered representative, with the consultant pitch framed as scaling oversight rather than headcount.
Those are savings claims about the firm's own cost base. Nothing here bears on what a client is told about machine-assisted work or how such work is billed, because no client bill is involved; the disclosure obligations the product does engage run to regulators rather than to clients, and are recorded on the court disclosure row.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The material exists behind a sales conversation or an executed agreement.
The diligence pack exists behind a request rather than on the page. The agreement incorporates a data processing agreement by reference and states that it is available upon request, and the same document carries commitments a reviewer would want to see: seventy-two hour notification of a security incident involving Regulation S-P data with written scope, forensic preservation and exam-ready incident reports, and cooperation with the customer's own regulatory examinations including documentation and personnel.
Standards are named in the footer, ISO 27001, the AICPA SOC mark and GDPR. What is not published is the evidence behind any of it: no subprocessor list was located, no audit period, scope or auditor appears anywhere, no trust centre exists, and the security page returns navigation only because the site renders client-side, with one search recovering no body text.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
The record is built for an examiner rather than a court, and read through that reader it is substantial but incomplete. Every review, escalation, approval and remediation is timestamped into an immutable audit trail, communications are archived to the 17a-4 write-once standard, and the estate promises exam packs on demand and regulator-grade evidence produced instantly for FINRA examinations, sweeps or inquiries. The agreement goes further than the marketing, committing the vendor to cooperate with the customer's regulatory examinations by providing documentation and making personnel available.
What is missing is the disclosure question itself: nothing distinguishes a determination the AI made from one a reviewer made once both sit in the trail, nothing describes a format or export addressed to disclosing machine involvement, and no court sits in this product's path. This is the second record in this pull read through a regulatory analogue; the parked item covers it.