P
Privado AI

Privado AI is a Delaware-incorporated privacy engineering company whose platform finds personal data wherever an organisation processes it and turns what it finds into privacy assessments and records of processing. Its named AI agent, Wren, runs the assessment cycle end to end: it watches internal tools such as Jira, Confluence, Linear and procurement systems for activity that warrants a privacy review, triages each one against the customer's own playbook and policies to decide whether a PIA, DPIA, TIA or RoPA is needed or whether immediate guidance will do, then populates the assessment by researching the question, scanning imported documentation, contracts, interview transcripts, source code and connected SaaS applications, generating evidence excerpts, flagging the gaps it could not fill for a person to answer in chat, and routing the result to approvers. Around Wren sit four other modules sold separately: dynamic data maps built from code scans and API integrations; a code scanning platform that performs static analysis of a customer's source code to identify personal data elements, flows and third-party integrations; a web auditor that runs live scans from a chosen geography, simulating accept, reject and no-action consent journeys to detect banners that misbehave, third-party trackers and cookies, and data leaving the site against consent; and an app auditor doing the same for Android and iOS builds. Privado publishes a rate card rather than quoting on request, at $600 per website per month for the web auditor, $800 per app per month for the app auditor, and $4,200 per month for Wren covering up to 500 assessments, all billed annually, with the full platform priced on request. The published subscription terms carry an indemnity, an insurance schedule, a 99.9 per cent uptime commitment with graded service credits and support response times; the company states that customer data and code are never used to train machine learning models, and holds SOC 2 with continuous control monitoring on infrastructure hosted at Amazon Web Services. Named customers include HP, HERE Technologies and Headspace Health.

Vendor siteDover, Delaware, United States
Last verifiedSeptember 7, 2026
Compare with other vendors

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The model is the engine of a core capability, layered on a product the vendor itself sells without it. Wren is a named AI agent that runs the privacy assessment cycle: monitoring internal tools for reviewable activity, triaging against the customer's playbook, researching the question, reading imported documentation, contracts, interview transcripts, code and connected applications, generating evidence and populating the assessment, then routing it to approvers. That is model work at the centre of the assessment product. The reason this is not the top grade is the vendor's own statement: the pricing page confirms the platform includes a base assessment module that can be purchased without Wren, and the web auditor, app auditor and code scanning modules are separately priced products whose mechanisms are live scanning, static analysis and simulated consent journeys rather than models. So a substantial and separately saleable part of what Privado sells does not depend on a model at all. Wren product page, pricing page and Annexure A of the subscription terms read 7 September 2026.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Grounding is real and the retrieval path is described, short of any measurement. The vendor states which sources Wren reads to populate an assessment, naming them individually: imported documentation such as product requirement documents, technical specifications, support documents, interview transcripts and notes; contracts, from which data processing terms are extracted; source code through a source control integration; connected SaaS applications through API integrations; and internet research, with a cookie agent described as verifying cookie categorisation by researching the internet in real time. The output carries evidence excerpts back to the material they came from, and gaps Wren could not fill are surfaced rather than filled in. What is absent is measurement of any kind: no accuracy rate for populated assessments, no evaluation, no test set, no error analysis, and no statement of how often an evidence excerpt supports the conclusion drawn from it. Several limbs of this band do not bite and are named rather than penalised, since the outputs are assessments and data maps rather than legal assertions citing authority. Wren product page and pricing FAQ read 7 September 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

A real division of labour is published with genuine review surfaces, short of the threshold that would settle where the boundary sits. What is published: Wren triages incoming activity and triggers the appropriate assessment or record of processing based on the risk value and the playbook and privacy policies defined by the customer's team, which makes the constraint the buyer's own document rather than a vendor default; assessments are routed to approvers; gaps Wren cannot fill are surfaced for a person to answer in chat; and risks it identifies are tracked alongside those raised by privacy stakeholders. That is a workflow with a person in it at named points. What is missing is the limb this band names as commonly absent. The vendor states that Wren eliminates manual threshold assessments and immediately communicates privacy guidance for low-risk activity, so it does answer some questions without review, and nothing published defines what counts as low risk, what Wren may finalise unattended, or what happens when an assessment it populated is wrong and a decision has already been taken on it. Wren product page and pricing FAQ read 7 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Named customers with named people in named roles, and no figures. Three deployments are published with attributed quotations and linked case studies: HP, where a Privacy Innovation and Assurance Leader describes visibility of personal data across the technology stack and automation of manual controls such as privacy reviews; HERE Technologies, where a Director and Head of Product Trust says compliance reports match data flows as the product evolves; and Headspace Health, where a chief information security officer describes building privacy into the software development lifecycle to prevent accidental sharing or tracking. Those are real deployment statements from identifiable people rather than logos. What is absent is the quantified half: no figure for review time, assessment volume, issues found or cost, no dates on the deployments, and no method behind any claim. The customers page carrying the full case studies was not read this pass and is the route to a higher grade. Wren product page read 7 September 2026.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Substantive published commitments, unusually well enforced, short of segregation and of the model provider question. The subscription terms make Customer Content, including source code and data elements and the reports generated from them, the customer's Confidential Information, and put the ordinary five-year confidentiality survival aside for exactly that material so the obligation runs until an exception applies rather than expiring. Use is confined by a limited-term licence to host, copy, transmit, analyse, process, store and configure Customer Content solely as necessary to provide the services, with all intellectual property in the generated reports vesting in the customer. Enforcement is real rather than nominal: a contractual penalty of twelve months' fees for any breach of the confidentiality obligation, which does not release Privado from performance and does not displace the customer's damages claim, and a liability cap that is lifted entirely for confidentiality and privacy breaches. The security page adds role-based access control and a stated internal procedure preventing employee or administrator access to user data except for limited support exceptions, with staff under confidentiality agreements. Two limbs are missing: nothing addresses segregation between customers or between matters inside a tenant, and nothing states what the model providers behind Wren may retain, since none is named. Subscription terms and security page read 7 September 2026.

Source: Vendor Published
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

A disclaimer sits in the terms while the product issues guidance, and nothing addresses where the output stops and a legal judgement begins. The live question here is sharper than in most records on this axis: the vendor states that Wren eliminates manual threshold assessments and immediately communicates privacy guidance for low-risk activity, which means a model is telling a business stakeholder that an activity does not need a data protection impact assessment. Nothing published says that such guidance is not legal advice, that the privacy counsel or data protection officer remains responsible for the determination, or what happens if the threshold call was wrong. What exists in the agreement is adjacent rather than on point: section 5 records the customer's acknowledgement that it relied on its own skill and judgment to check the applicability of the software and to validate suitability for its intended use, and section 9 disclaims fitness for a particular purpose. Those are suitability and warranty provisions, not a statement about the advice line. Same grade and reasoning as the comparable records in this lane. Subscription terms, Wren page and pricing FAQ read 7 September 2026.

Source: Vendor Published
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

No governance position for the vendor's own AI was located, for a product whose agent drafts data protection impact assessments. Nothing published names who inside Privado is accountable for Wren's behaviour, describes what is evaluated before it ships or changes, reports any result from such evaluation, discloses whether its output is uneven across regimes, languages or document types, or offers a model card or system card. The two things that come closest are neither: the statement that customer data and code are never used to train machine learning models is a commitment and is credited on the training signal instead, and the SOC 2 programme with continuous control monitoring is security assurance rather than AI governance. The gap is worth stating precisely because of what the agent does: an assessment Wren populates becomes the customer's record of its own compliance reasoning, shown to regulators and auditors, and the buyer has no published basis on which to judge how that reasoning is produced or checked. The unread data processing addendum and the product documentation site are the rebuttal routes. Wren page, pricing FAQ, security page and subscription terms checked 7 September 2026.

Source: Operator Verified
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Retention, deletion, access control, subprocessors and incident practice are all published and specific, once the data processing addendum is read alongside the security page. The addendum's Annex II sets out the measures: background checks on all new employees, annual security training, written agreements with every vendor carrying confidentiality, privacy and security obligations, role-based access control, a stated password policy with credentials held in AWS Cognito, a formal change management process with review before production deployment, TLS in transit and strong encryption at rest, vulnerability assessment and penetration testing twice a year, and backups taken every fifteen minutes to a private S3 bucket encrypted with AES-256 and restore-tested twice a year. Retention has periods rather than gestures: personal data is deleted once a user is deleted by an administrator and within six months if the customer leaves, and clause 12 requires return or deletion of all personal data within at least thirty days of the end of the agreement with copies deleted as soon as practicable. Incident practice is defined at clause 11, with maintained breach procedures, notification without undue delay unless the breach is unlikely to risk rights and freedoms, and assistance to notify the authority and data subjects; the incorporated Standard Contractual Clauses add the content a notification must carry. Subprocessors are published individually in Annex II with purpose, data centre locations and which products each supports. The security page's own age is recorded on the certifications row and does not move this grade. Data processing addendum of 7 April 2023, security page and subscription terms read 7 September 2026.

Source: Vendor Published
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

The fullest published liability position in this lane, and the only one in the pull carrying an insurance schedule. The indemnity at section 12 is broader than the usual intellectual property clause: it covers third-party claims arising from Privado's breach of applicable law, from infringement or misappropriation by the software or by the customer's lawful use of it, and from Privado's own breach of confidentiality, with three named exclusions and the modify, procure or terminate-with-refund ladder. The cap at section 13 is twelve months of subscription fees, and section 13(b) then lifts both the cap and the exclusion of indirect damages for privacy and security breaches, confidentiality breaches, the indemnification obligations and death or personal injury, so the indemnity sits outside the cap rather than inside it. Section 11(f) adds a fixed contractual penalty of twelve months' fees for any confidentiality breach, without releasing Privado from performance and without prejudice to damages. Section 14 requires and maintains commercial general liability at $1,000,000 per occurrence and in aggregate, technology errors and omissions at $1,000,000 per claim, cyber and privacy liability at $1,000,000 per claim and umbrella cover at $1,000,000, with four years of tail on claims-made policies. Warranties at section 5 include material conformance to the documentation and a commitment not to materially decrease functionality. Annexure B commits to 99.9 per cent uptime with service credits graded from 5 to 30 per cent, and support response and resolution goals with a named escalation path. Subscription terms read in full 7 September 2026.

Source: Vendor Published
AA on Practice Systems Integration DepthDocumented, verifiable integrations into the systems legal work already lives in, with the depth described: what syncs, in which direction, and what a firm must configure.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Documented integrations into the systems this work already lives in, with what moves, in which direction, and what the customer must configure, stated per product. Wren connects to Jira, Confluence, Linear and procurement tools to capture activity warranting a privacy review, and pushes automated development tickets back into Jira and Linear. Data maps are built from source code through a source control management integration, from third-party applications including customer data platforms, tag managers, CRM, contract lifecycle management, human resources, marketing, procurement and database tools through API integrations, and from imported documents. The integration with OneTrust is described with its direction stated: the personal data inventory, assessments and risks held in OneTrust are automatically updated with information from Privado. Configuration effort is published per module rather than left to a sales call: the web auditor needs only URLs and the geographies to scan from, the app auditor needs the app store URL or the APK and IPA files, neither requires implementation, Wren takes a few days to connect internal tools, set up playbooks and import documents, and the full platform typically takes one to three weeks. What is not established from the pages read is per-connector documentation, which lives on the documentation site and was not opened. Pricing FAQ and Wren page read 7 September 2026.

Source: Vendor Published
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

The regions are stated and the deployment model is not. The data processing addendum's subprocessor annex gives a data centre location for each entry, and the two that hold customer material are specific: Amazon Web Services, described as the primary cloud infrastructure where all Privado applications are hosted and where all data stored, processed and transmitted through the products resides, is listed for the United States, the European Economic Area and India, and MongoDB, the primary product database, for the same three. So a buyer can establish the countries in which its data may sit, which lifts this off the floor. Transfers out of the EEA run on the 2021 Standard Contractual Clauses set out in full in Schedule 1, governed by Irish law with the Irish Data Protection Commission as competent supervisory authority and onward transfers restricted by clause 8.8. What is absent is everything on the deployment side: no tenancy model, no single-tenant or self-hosted option, no statement that a customer can choose or pin a region, and nothing addressing where processing happens as distinct from where data is stored beyond the transfer mechanism. One adjacent fact is recorded so it is not mistaken for residency: the web and app auditors let a customer choose the geography a scan runs from, which is where the simulated user appears, not where data is held. Data processing addendum, security page and subscription terms read 7 September 2026.

Source: Operator Verified
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

A badge and a monitoring tool, with no scope, no date and no report route. The footer and the security page carry a SOC 2 mark with the AICPA logo, and the security page states that Privado uses Drata's automation platform to monitor more than one hundred internal security controls continuously with automated alerts and evidence collection. What is absent is everything that would let a buyer check it: no type is stated, so Type I and Type II are not distinguished; no trust services criteria are named; no auditor, examination period or report date appears; and no route to a report, a questionnaire response or a gated portal was located, since there is no trust centre. Continuous control monitoring is a real practice and is credited as substance, but it evidences a programme rather than an attestation. The date on the page matters to the confidence rather than the grade and is recorded here: the security page states it was last updated on 17 February 2022. Security page and site footer read 7 September 2026.

Source: Vendor Published
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The vendor sells a named AI agent, publishes a subprocessor list, and no model provider appears on it. This is the sharpest version of this gap in the pull, because the absence is visible rather than inferred. Annex II of the published data processing addendum lists five subprocessors with purpose, data centre locations and the products each supports: Amazon Web Services for infrastructure, MongoDB as the primary product database, SendGrid for transactional email, Intercom for customer support and Amplitude for product analytics. None of them is a model provider, and no model, model family, provider, hosting arrangement or inference location for Wren is named on any surface read. Wren demonstrably runs on a model, since the vendor's own pricing FAQ states that customer data and code are never used to train AI or ML models, so either an unlisted third party sees the documentation, contracts, interview transcripts and source code Wren reads, or the models run inside the AWS footprint already listed, and nothing published tells a buyer which. No commitment is given to notify customers when the arrangement changes, and the subprocessor mechanism at clause 10 gives an objection route without an advance notice period, though the incorporated Standard Contractual Clauses require thirty days' notice of changes to the agreed list for EEA transfers. Data processing addendum, Wren page, pricing FAQ and security page read 7 September 2026.

Source: Vendor Published
AA on Commercial TransparencyA buyer can learn what this costs without entering a sales process: published rates, the unit being charged, and what implementation adds.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

A published rate card with figures, units, minimums and what changes between products, which no other record in this lane offers. The pricing page states that the web auditor starts at $600 per website per month billed annually with a four-website minimum and bulk page-based pricing available; the app auditor at $800 per app per month billed annually, with iOS and Android versions counted as two apps; and Wren at $4,200 per month billed annually for up to 500 assessments. Only the full privacy management platform is on request, and the page states what it adds. Each tier lists its included features, so a buyer can see what the money buys before speaking to anyone, and volume discounts are disclosed rather than implied. Annexure A of the subscription terms then defines the units precisely: a developer is a user who has committed to a scanned repository in the last ninety days, a website is each unique URL entered, an app is each platform version, a scan is one execution against one website from one geography, so running the same site from three geographies is three scans. The agreement adds fees in advance, a twelve-month initial term, non-refundable fees and 1.5 per cent monthly interest on late payment. A VendorPricing row is written, with the floor recorded as a figure. Pricing page and subscription terms read 7 September 2026.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Coverage is described with substance across buyers, regimes and surfaces, and the boundaries are left open. The buyers are addressed by function and evidenced by the customer voices: privacy leaders and privacy teams for assessments and records of processing, engineering for code scanning, and security leadership, with the three named deployments spanning a technology manufacturer, a mapping and location company and a digital health provider. Regulatory coverage is named rather than gestured at, with CCPA, CIPA and GDPR called out, more than fifty pre-built compliance checks, dedicated GDPR and CCPA solution pages, and consent framework handling for GPP, TCF and TAG. The processing surfaces covered are enumerated: websites, mobile apps, internally developed software, third-party SaaS applications and business processes. What is not stated is any limit. No jurisdiction, sector or organisation size is named as out of scope, no coverage boundary is given for the compliance checks, and nothing describes what a law firm rather than an in-house privacy function would do with the platform, which for an index of legal buyers is the boundary that matters. Pricing page, Wren page and solution navigation read 7 September 2026.

Source: Vendor Published
Pricing

From $600 per website per month

  • Privado publishes a rate card rather than quoting everything on request. The web auditor starts at $600 per website per month, billed annually, with a minimum of four websites. The app auditor starts at $800 per app per month, billed annually, and an iOS build and an Android build of the same application count as two apps. Wren, the AI privacy agent, starts at $4,200 per month, billed annually, covering up to 500 assessments. The full privacy management platform, which combines assessments, Wren, dynamic data maps, contract scanning, privacy code scanning and SaaS application scanning, is priced on request and scales with the business. Volume discounts are offered on all four, including for adding the auditors or Wren to the platform, and every plan includes a dedicated customer success manager at no extra cost.

Published rate card at privado.ai/pricing, read 7 September 2026, with the charging units defined in Annexure A of the Online Subscription Terms of 2 July 2025. The stated figures are floors rather than rates: $600 per website per month and $800 per app per month, both billed annually, and $4,200 per month for Wren for up to 500 assessments. Bulk page-based pricing is available for the web auditor and bulk pricing for the app auditor. The units are defined precisely in the agreement: a website is each unique URL entered into the dashboard, regardless of domain or subdomain structure; an app is each platform version registered for monitoring; a scan is one execution of the web auditor against one website from one geography, so the same site run from three geographies counts as three scans; a test is a recorded user journey tied to a single geography; and for the code scanning platform a developer is a user who has made one or more commits in the last 90 days to a repository Privado scans. Commercial terms from the agreement: fees payable in advance unless the order form says otherwise, a 12-month initial subscription term, fees non-cancellable and non-refundable, 1.5 per cent monthly interest on amounts more than 30 days late, and suspension available for unpaid renewal fees. Annexure B adds a 99.9 per cent uptime commitment with service credits graded at 5, 10, 15 and 30 per cent of the monthly fee as availability falls, credited against the next invoice and refunded if any remain at termination.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Never, in policy only

A public policy or trust page states no training on customer content, with no matching term located in the published agreement.

Public material states plainly that customer content is not used for training, and no matching term is located in the published agreement. The pricing page FAQ answers the question directly and in the negative, adding that customer data and code are never stored or shared to third parties. The discipline that attaches to this value was run before taking it: the agreement is published, was read in full, and contains no training term in either direction. What it does contain is section 4(e), permitting anonymised usage and analytical data derived from processing Customer Content, aggregated with like data from other customers, to be used for Privado's internal purposes including research, analytics and improvement of the services, on condition that the customer and its users cannot be identified. That is an improvement right over aggregated derivatives and it does not name training or models. One ambiguity in the FAQ sentence is recorded rather than resolved against the vendor: never stored reads either as never stored anywhere, which section 10(c) contradicts by granting an express licence to host, copy, store and process Customer Content to provide the services, or as never stored with third parties, which it does not contradict. On the training question itself the policy and the agreement do not conflict. Pricing FAQ and subscription terms read 7 September 2026.

Source: Vendor PublishedPrivado AI never uses customer data or code for training AI/ML models.As of Sep 7, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Disclosed fixed window

A specific retention period is published and the customer cannot change it.

A specific period is published and the customer cannot change it. Annex I.B of the published data processing addendum states the retention position for the personal data transferred: deleted once a user is deleted by administrators, and within six months if the customer leaves Privado. Clause 12 adds the end-of-contract mechanism, requiring return of all personal data or, at the customer's instruction, deletion, within at least thirty days of the end of the agreement or the cessation of services, with all copies deleted as soon as reasonably practicable thereafter; the incorporated Standard Contractual Clauses repeat the choice of deletion or return with certification. Two limits are recorded so the row is not read as more than it is. The six-month figure and the deletion mechanism address personal data as defined by the GDPR, not every artefact the platform holds, so how long a generated assessment, evidence excerpt or code scan result persists in the account during the subscription is not separately stated; and the security page's own retention section covers usage data only, removable on request. No zero-retention option is offered. Data processing addendum, security page and subscription terms read 7 September 2026.

Source: Vendor PublishedDeleted once user is deleted by admins and within 6 months if the customer leaves PrivadoAs of Sep 7, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Not addressed

No located public material addresses walls or matter level segregation.

No located public material addresses segregation between customers or inside a customer's own tenant. The nearest published feature is role-based access control, offered on all accounts and described as allowing users to define roles and permissions, and that is a mechanism the customer operates over its own people rather than a statement about how Privado separates one organisation's assessments, data maps and code scan results from another's. The vendor-side control that is published is different again and is credited on the confidentiality row: an internal procedure preventing employee and administrator access to user data, with limited exceptions for support. Nothing read describes tenancy, isolation, or whether Wren's research across imported documents and connected tools respects permissions at retrieval time, which matters for a product that reads a customer's contracts and source code. Security page, subscription terms and Wren page checked 7 September 2026.

Source: Operator VerifiedAs of Sep 7, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Notice committed

Terms commit to notice where lawfully permitted. No transparency report located.

The commitment appears in both instruments, and the stronger of the two is the one incorporated by the data processing addendum. Section 11(b) of the subscription terms requires prompt notice of any compelled disclosure of Confidential Information so the disclosing party can seek a protective order, cooperation at its expense in seeking that order, and disclosure of only the portion legally required; Customer Content, including source code and data elements and the generated reports, is expressly the customer's Confidential Information, so the clause reaches what the platform holds. The addendum then sets out the 2021 Standard Contractual Clauses in full, and clause 15 is included without disapplication: on a legally binding request from a public authority the importer must notify the exporter and, where possible, the data subject, with the data requested, the requesting authority, the legal basis and the response given; must use best efforts to obtain a waiver of any prohibition on notifying and document those efforts; must provide the exporter with periodic statistics on requests received and challenged; must review the legality of the request, challenge it where there are reasonable grounds and seek interim measures pending a decision; and must disclose the minimum permissible. That is a notice and challenge regime rather than a bare notice promise, and it is what a buyer transferring EEA personal data gets. No separate transparency report or law enforcement guidelines page was located, and no notice timeline is given in the subscription terms themselves. Subscription terms and data processing addendum read in full 7 September 2026.

Source: Vendor Publishedthe receiving Party shall give the disclosing Party prompt notice of such request so that disclosing Party may seek an appropriate protective order or similar protective measureAs of Sep 7, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Sources named, basis unstated

Sources are identified without stating the licence or rights basis.

The regimes behind the product's checks are named and nothing states how the content is maintained. The pricing page advertises more than fifty pre-built compliance checks for CCPA, CIPA and GDPR among others, with dedicated GDPR and CCPA solution pages, consent framework handling for GPP, TCF and TAG, and worked examples such as flagging advertising cookies or third-party SDK data collection where a California user has opted out. So a buyer can see which instruments the checks derive from, which is more than the lowest value describes, and the sources are public law rather than licensed material. What is absent is the maintenance half: no statement of who maintains the check library, how quickly it absorbs a change in guidance or a new state regime, when each check was last reviewed, or how a customer learns that a check has changed and whether a completed scan was run against a superseded version. Pricing page and solution navigation read 7 September 2026.

Source: Vendor Published50+ pre-built compliance checks for CCPA, CIPA, GDPR, & moreAs of Sep 7, 2026Evidence

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

No located public material addresses whether the authority behind the product's outputs is checked for currency. The ordinary subject of this signal, the subsequent history of reported cases, does not bite for a platform whose outputs are assessments, records of processing, data maps and scan findings rather than citations to case law, and that is recorded rather than penalised. The analogue that would bite is whether the compliance check library and the assessment templates track changes in the regimes they encode, and nothing published commits to it. That question is recorded on the corpus provenance row rather than counted twice here. Wren page, pricing FAQ and solution pages checked 7 September 2026.

Source: Operator VerifiedAs of Sep 7, 2026Evidence

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Documented

The vendor describes refusal or abstention behaviour in public materials.

An uncertainty path is documented and nothing demonstrates it. The vendor states that when Wren populates an assessment it surfaces the gaps it could not fill and asks the user to supply more context through chat, so the product has a published behaviour for the case where it cannot establish an answer: it marks the hole and routes it to a person rather than completing the form regardless. On a product whose output is a data protection impact assessment that a regulator may later read, that behaviour is the right one and is credited. What is missing is the demonstration: no transcript, worked example, evaluation or measurement shows the path operating, no confidence or grounding score is exposed, and nothing states what proportion of an assessment Wren typically leaves open or how it decides that context is insufficient. The live instrument file was read before this value was assigned. Wren page and pricing FAQ read 7 September 2026.

Source: Vendor PublishedSee gaps identified by Wren and provide more context via chat.As of Sep 7, 2026Evidence

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

No court order, opinion or disciplinary record naming Privado or Wren was located as of 7 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on both names alongside a general search of the sanctions coverage; the decisions naming specific tools name general-purpose chatbots and legal research products. This is a statement about the public record, not a finding about the product. Exposure is structurally remote for a platform whose outputs are internal privacy assessments and data maps rather than filings, though those assessments are produced to regulators and auditors, an audience with its own accuracy expectations.

Source: Operator VerifiedAs of Sep 7, 2026Evidence
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No located public material engages with bar or ethics guidance, or with lawyers' professional obligations in general terms. Privado engages regulation in detail and addresses privacy counsel and data protection officers as buyers, and all of that concerns the obligations of the organisations buying the product. Nothing names an ethics opinion, a bar association guidance document or a regulator's guidance on lawyers' use of AI, and nothing addresses the position of a privacy lawyer who signs off an assessment a model populated. The lower value was tested before this one was taken: a generic reference would require some engagement with professional responsibility as such, and none was located. Wren page, pricing FAQ, subscription terms and security page checked 7 September 2026.

Source: Operator VerifiedAs of Sep 7, 2026Evidence

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Outside the fee relationship

The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.

The product does not touch a fee between a lawyer and a client. Privado is licensed by an organisation to assess and map its own data processing, and the buyers are in-house privacy, legal, security and engineering functions that bill no client for the work. The efficiency claims on the product page, freeing up resources and increasing assessment bandwidth, are aimed at the buyer's own capacity, which the value text records as not making the row a savings claim. Nothing addresses billing, fee or disclosure treatment because there is no client invoice for it to address. What the vendor does publish about its own charging is unusually complete and is graded on Commercial Transparency, not here. Pricing page, Wren page and subscription terms checked 7 September 2026.

Source: Vendor PublishedAs of Sep 7, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Subprocessors listed

A current subprocessor or model provider list is published.

A current subprocessor list is published, and the model provider question still has no published answer. Annex II of the data processing addendum lists five subprocessors, each with its purpose, its data centre locations and the products it supports: Amazon Web Services as the primary cloud infrastructure holding all data stored, processed and transmitted through the products, in the United States, the European Economic Area and India; MongoDB as the primary product database across the same three; SendGrid for registration, password and notification email; Intercom for customer support; and Amplitude for product analytics on the code scanner. The forwardable material sits alongside it and needs no agreement to obtain: the addendum itself, the Standard Contractual Clauses set out in full with Irish law and the Irish Data Protection Commission named, the technical and organisational measures in Annex II, and the public subscription terms carrying the confidentiality, indemnity and insurance provisions a client questionnaire asks about. What stops this reaching the top value is the limb an AI clause turns on: no model provider is named anywhere, and none appears on the subprocessor list, so a firm cannot tell its client whose models see the documents, contracts, transcripts and source code that Wren reads to populate an assessment. Data processing addendum read in full 7 September 2026.

Source: Vendor PublishedThe current Subprocessors engaged by the Processors and approved by the Controller are listed in Annex 3 of Schedule 1 hereto.As of Sep 7, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

Some elements of a record exist and none is built for disclosure. What the product does produce is substantial: evidence excerpts tying assessment answers back to the documents they came from, risks documented per assessment with remediation tracked, approval routing that records who signed off, and application logs collected as an audit trail on the security side. A privacy team could reconstruct a good deal of what happened from that. What is absent are the elements this signal asks for: no per-item export stating which model or agent produced a given answer, what it read and what a person verified before approval; nothing addressing a court's standing order on AI use; and no template or certification a filer could attach. The distinction worth naming is that the record the platform keeps is a record of the customer's compliance decisions, not a record of the model's work in reaching them. Wren page, pricing FAQ and security page checked 7 September 2026.

Source: Vendor PublishedAs of Sep 7, 2026Evidence
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 7, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746