Securiti
Securiti sells what it calls the DataAI Command Platform, built on a knowledge graph that maps data and AI objects across hybrid multicloud, SaaS and on-premise estates, and organised into four pillars addressed to different teams. The privacy pillar is the one legal and privacy counsel own: data mapping automation producing records of processing activity, data subject request automation covering intake through identity verification, discovery, redaction and secure report delivery, assessment automation for privacy and AI impact assessments, consent management for web and mobile, breach management with impact analysis and notification workflows, a consumer-facing privacy centre, and compliance management against global regimes including GDPR, CPRA, LGPD, PIPEDA and PIPL. The security pillar covers data security posture management, data discovery and classification, access intelligence, data flow governance and breach impact analysis. The governance pillar adds a data catalogue, lineage and quality. The fourth pillar, Gencore AI, is infrastructure for customers building their own AI systems: vectorising and ingesting unstructured files into vector databases, curating and sanitising data for model training and tuning, context-aware prompt, retrieval and response firewalls for large language models, and rule-aware enterprise copilots. Agent Commander, launched with Veeam, addresses risk from AI agents. Securiti maps its coverage to the EU AI Act, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM applications and CDMC, states more than a thousand integrations across systems including AWS, GCP, Azure, Snowflake and Databricks, and runs separate Global and EU production clouds on AWS and GCP with no data exchange between instances. The company is Securiti, LLC. of San Jose, California, led by Rehan Jalil, and was acquired by Veeam.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
AI is present in three distinct ways here and none of them makes the models the product a legal buyer is paying for. First, as subject matter: AI Governance, EU AI Act and NIST AI RMF pages sell the ability to govern a customer's AI, which is the product managing someone else's models. Second, as infrastructure for the customer: Gencore AI vectorises and sanitises data for training, runs prompt, retrieval and response firewalls, and builds copilots, which is AI plumbing rather than AI doing the buyer's work. Third, and closest to this axis, as technique inside classification and the DataAI Command Graph. Strip the models out and what remains is fully saleable and is most of the platform: data discovery and scanning across a stated thousand-plus integrations, a catalogue, lineage, a data map producing records of processing activity, DSR workflow, consent capture, assessment templates and breach notification. Consistent with the comparable platform in this lane, which took the same grade for the same structural reason.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted repeatedly in the marketing and measured nowhere. The claim appears in the product copy as accurately classifying data, discovering shadow and cloud-native assets, and delivering unified intelligence, and classification precision is the decisive quality metric for a discovery and posture-management product: a missed store of personal data is the failure mode that matters, and an over-broad match creates work that erodes trust in the tool. No precision or recall figure, benchmark, test set or false-positive rate was located on any surface read on 1 September 2026. Two limbs of this axis do not bite, since the platform does not retrieve legal authority and produces no citations a reader would open. The agreement is more candid than the marketing on this point and is graded on the liability row: Securiti warrants substantial conformity with the Documentation rather than accuracy of any classification result.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Oversight is sold as a product and not described as a control over the vendor's own output. Securiti ships genuine runtime controls, with context-aware prompt, retrieval and response firewalls for large language models and Agent Commander for detecting and undoing AI agent mistakes, but every one of those governs the customer's AI systems rather than Securiti's classification and assessment engine. On its own side, nothing located states what runs unattended, what confidence threshold causes the system to defer, where a reviewer sits relative to a classification decision, or what happens after a classification is wrong. Assessment Automation implies human authorship of assessments without describing a checkpoint over machine output. The agreement is the only place a supervision expectation is stated and it points at the customer: the disclaimer records that the product augments rather than replaces professional advisors, and that the customer must confer with legal counsel as needed. That places responsibility rather than describing a mechanism.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named organisations, named individuals with titles and dates, and no figures for what changed. The Spotlight Talks series carries on-the-record interviews with a director of global analytics at Dye and Durham, an SVP of product at Walker and Dunlop discussing a 135 billion dollar portfolio, and named executives at Sanofi, Volkswagen and International Flavors and Fragrances, each dated between April and June 2025. That is materially better attribution than most of this corpus, and it is interview material rather than outcome measurement: no before-and-after metric, deployment scale or time saving is attached to any of them. Analyst recognition is extensive but is not deployment evidence, spanning GigaOm, Frost and Sullivan, IDC MarketScape, Forrester Wave, Gartner Cool Vendor and an RSA Conference Innovation Sandbox win. **One piece of context belongs on this row**: section 9.2 of the customer agreement obliges customers to join Securiti's reference programme and to develop a profile including an executive quote and logo, so the supply of testimonials is a contractual term rather than purely voluntary.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The architecture is documented with unusual specificity and the question is answered in the vendor's favour rather than the customer's. On the strong side, and all of it published in the agreement or its security exhibit: per-customer virtual database instances logically separating one customer's data from another's and destroyed when the customer stops using the service; personal data identified by the platform subjected to a one-way irreversible hash, with a commitment that personal data is at no point captured in clear text in logs or databases; mutual contractual confidentiality with a notice-and-opportunity-to-contest provision for legally compelled disclosure; customer ownership of Customer Data; and deletion of all Customer Data from online systems within one business week of a confirmed request. Against that sits the term that decides this axis. **Section 2.1 grants Securiti a royalty-free, worldwide licence to use Customer Data both to provide the service and for the purpose of enhancing product or services**, with no carve-out for model training and no definition of what enhancement covers. Privilege and work product are not addressed, and no position on third-party model providers exists.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
A real position on advice versus tooling is published in the agreement itself, which is more than most of this lane manages. The disclaimer at section 5.4 states in terms that the customer acknowledges the product is intended only to augment the customer's privacy practices but not replace legal and other professional advisors, and that the customer is a data controller responsible for what data it collects and for its own privacy policies. Section 2.5 reinforces it operationally: the customer assumes full responsibility as controller, warrants that it has complied with transparency obligations and obtained the necessary consents and legal bases, and, in an unusually direct sentence, records that it is the customer's responsibility to confer as needed with legal counsel to confirm and maintain compliance with applicable laws. That is a published allocation of the professional judgement, addressed to the person who will rely on the output. What is missing is the rest of the treatment: no jurisdiction limit is named for the tool's own coverage, nothing addresses the supervision or competence duties of the practitioner using it, and no professional guidance is referenced anywhere.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Nothing published addresses governance of Securiti's own models, and the contrast with what the company sells is the point. Securiti publishes extensive material on AI governance frameworks as product capability, with dedicated pages for the EU AI Act, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM Applications and CDMC, and an AI Governance module sold to establish controls for the safe adoption of AI. None of that is Securiti's own governance. No responsible-AI page, AI policy, ethics statement, AI governance committee, named accountable owner, pre-release testing regime or bias evaluation was located. The site navigation was read in full on 1 September 2026 across products, solutions, resources and company sections and contains no such surface; the Company menu offers About Us, Partner Program, Contact, News Coverage, Press Releases and Careers, and the footer offers terms, security, cookie preferences and privacy request routes. The security exhibit designates a security official and a cross-functional Security Council, which is information security governance rather than AI governance. **A vendor selling AI governance publishes none of its own.**
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive, specific and published across most of the ground, short of a named subprocessor list. The security exhibit to the customer agreement is unusually concrete. Deletion carries a stated window: on a customer request filed by ticket or email, Securiti deletes all Customer Data from online systems within one business week of confirmation, with retention only where applicable law requires. Incident practice carries a stated deadline and method: notification of a security breach as soon as practicable and no later than seventy-two hours after Securiti becomes aware, by email with a read receipt to a designated address, with Securiti barred from informing third parties without approval and the customer holding sole right to decide whether affected consumers are notified. Access control is role-based, reviewed regularly and monitored, with a stated subset of personnel able to reach customer data. Testing is described with dates attached to cadence: annual third-party penetration tests and audits, weekly internal scans, disaster recovery tested twice a year with an executive summary available to customers on request. Devices carry a minimum of AES-128 full disk encryption. What is absent is the subprocessor limb: third parties appear only as categories such as IT service providers and cloud providers, with none named, and the CCPA addendum has the customer pre-approve transfers to Securiti's affiliates, service providers, third parties and vendors without identifying them.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Every limb this band names is published and specific, and one of them appears here for the first time in the corpus. The indemnity runs two ways rather than one and covers more than intellectual property: Securiti defends the customer against third-party claims that use of the product infringes a US patent, copyright, trade secret or trademark, **and separately against claims arising out of any use or disclosure of Customer Data by Securiti in breach of the agreement**, which is a indemnity rather than the IP-only indemnity that is standard in this corpus. The cap is stated with a hard ceiling: direct damages limited to the lesser of amounts paid under the applicable order form in the preceding twelve months **or one million dollars**, with the usual consequential-damages exclusion running mutually and the customer's payment obligations carved out. A warranty a buyer can invoke commits the product to substantially meet the order form requirements, substantially conform to the documentation and be free of malicious code, with re-performance, termination and a pro-rata refund as the exclusive remedy. **An insurance position is published, which no other record in this pull carries**: errors and omissions, professional liability and cyber cover of not less than three million dollars per claim and in the annual aggregate, maintained through the term and for two years after, with thirty days' notice of cancellation. A service level agreement adds 99.5 per cent availability, tiered credits and a termination right below 92 per cent for three consecutive months. Nothing is specific to an AI output being wrong.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations exist, are named, and stop short of documented depth. Securiti states more than a thousand integrations across data systems and names the principal ones on its own navigation: AWS, Google Cloud, Azure, Snowflake and Databricks each carry a dedicated page, with a connectors index behind them. What travels is describable at a high level from the product set, since discovery, classification, access intelligence and lineage all operate by reaching into those systems and reading their contents, and downloadable components are deployed inside the customer's own environment for parts of the platform. What is missing is the implementer's view: no API reference or connector specification was located on the pages read, and nothing describes the direction or granularity of what moves for any individual system. A documentation site exists at docs.securiti.ai, listed among the company's own internet-facing assets in the published system description, and **was not opened on 1 September 2026**, so depth was neither confirmed nor excluded.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The deployment model is stated plainly with partial residency detail. The published system description sets out a multi-tenant cloud service hosted on AWS and GCP, with per-customer virtual database instances providing logical separation, and adds a genuine hybrid element in downloadable components that must be deployed inside the customer's own environment. Residency is real rather than gestural: platform instances sit in multiple geographically distributed data centres, and the company states that **each instance serves customers from a specific geography as a standalone offering with no data exchange between instances**, which answers the processing question more directly than most vendors manage. Two clouds are identified concretely by their own endpoints, a Global Production Cloud and an **EU Production Cloud** at app.eu.securiti.ai with its own status page. Resilience detail is published, with daily backups copied to a different data centre in a different region, a pilot-light disaster recovery strategy, multi-availability-zone failover and a stated 24-hour RTO and RPO. What keeps this below the top band is that the full list of available regions is never enumerated beyond the EU and Global clouds, and nothing describes what changes between deployment tiers.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The certifications are real and named, and none of the evidence is reachable without asking. Securiti states SOC 2 Type II certification with a copy of the report available on request to prospective and current customers, and holds **ISO 27001:2022 and ISO 27701:2019**, the latter being the privacy information management standard and a sensible one for this product. The customer agreement backs the SOC 2 position contractually, committing Securiti to provide its most recently completed SOC 2 report or an industry-standard successor on request. Supporting detail is unusually good for a vendor with no trust portal: the published system description names AWS and GCP as the underlying providers and describes the shared responsibility split, annual third-party penetration tests and audits, weekly internal scans, and a disaster recovery test executive summary available on request. What holds it below the top band is access and specificity. There is no trust centre and nothing is downloadable; no auditor or certification body is named for any of the three; no certificate date, examination period or scope statement appears; and every route to the evidence runs through a request. Under the gated-is-not-absent tiers this is the self-serve request tier, materially better than absent and short of open publication.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The platform is built around models and identifies none of them. Securiti describes a knowledge graph at the core, classification across structured and unstructured data, vectorisation and ingestion into vector databases, curation and sanitisation of data for model training and tuning, and prompt, retrieval and response firewalls for large language models. Every one of those implies models, and no model, model family, provider or architecture is named anywhere on the surfaces read on 1 September 2026. Nothing states whether a third-party foundation model is called at any point in classification or in the copilot products, and nothing excludes one. AWS and GCP are named as infrastructure providers, which identifies where workloads run rather than whose models they are, and does not answer this axis. No commitment to notify customers when the model set changes was located. This sits above the bottom band because the architecture is described in real terms rather than gestured at, and below the band above because nothing underneath it is identified.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No figure and no tier are published anywhere, and the charging unit is nonetheless readable, which is an unusual combination worth recording precisely. The site navigation was read in full on 1 September 2026 and contains no pricing page; every commercial route on every page is a demo request or a contact form. What is published sits in the customer agreement rather than in marketing: the number of Authorized Users accessing the product is capped by the figure specified in the order form, which identifies the unit of charge as named users; fees are quoted and payable in United States dollars; payment obligations are non-cancellable, non-pro-ratable for partial months and non-refundable; late payment carries interest at one and a half per cent per month; and subscriptions renew automatically for successive terms equal to the initial term unless either party gives thirty days' written notice. The service level agreement adds a published credit schedule of four, six and ten per cent against availability bands. So a buyer can read the shape of the commercial relationship in advance while learning nothing about what it costs, with no rate, band, package or tier name published at any point.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is documented across three axes with real substance behind each, and the boundary is left open. Six industries carry dedicated pages: financial services, healthcare, telecom, retail, travel and hospitality, and manufacturing. Regulatory coverage is named rather than gestured at, with individual pages for GDPR, California's CPRA, Brazil's LGPD, Canada's PIPEDA, China's PIPL, the EU AI Act, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM Applications and CDMC, behind a wider index. Technology coverage is quantified at more than a thousand integrations with the major cloud and data platforms named. What is not stated is where the product stops, with no statement of organisation size, data volume, or the environments and obligations it does not reach. The buyer picture carries the same gap seen across this lane: the Roles navigation offers Data+AI Builders, Data Security, Data Privacy, Data Governance and Marketing, and **no page for legal or counsel**, even though the privacy pillar is the work a data protection officer or privacy counsel owns and the agreement itself tells the customer to confer with legal counsel.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The published agreement expressly reserves a right to train on customer content, with no opt out located. Any de identification, anonymisation or aggregation qualifier is recorded in the summary.
The agreement grants an affirmative right rather than withholding one. Section 2.1 of the customer agreement has the customer grant Securiti a royalty-free, worldwide, non-exclusive, fully paid-up licence to use Customer Data in order to perform and provide the product and professional services for the customer's benefit **or for the purpose of enhancing product or services**. The second limb is the operative one: it is a service-improvement right with no carve-out for model training, no definition of what enhancement covers, and no opt-out. Two adjacent terms narrow the picture without closing it. Securiti owns System Data, defined as anonymised user and other data about the product used for performance, availability and security reporting, so some improvement use is expressly anonymised. And the CCPA addendum certifies that Securiti will not sell customer personal information and will not retain, use or disclose it outside the direct business relationship or for purposes other than performing the services, which pulls against the enhancement limb for CCPA-covered data specifically. **A buyer cannot tell from the published documents whether its content trains models.**
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
The customer controls the retention window, by product configuration or by contractual instruction, but zero retention is not stated as available.
Deletion is customer-initiated with a stated window, and no retention period is published for anything held before that request. Section 17 of the security exhibit provides that a customer may request deletion by filing a support ticket or emailing support, and that on receiving confirmation of the request Securiti will delete all Customer Data from online systems within one business week, retaining data only to the extent and for the period applicable law requires. Customer Data may also be deleted following termination or suspension. That is a real and unusually specific control, and it is a deletion mechanism rather than a retention policy: nothing states how long inputs, classification outputs, assessment records or scan results are kept absent a request, and no zero-retention option is described. The separate privacy notice covers only personal data Securiti holds as a controller and sets qualitative criteria rather than a period.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
Securiti operates its own separation model and documents it at the tenant level in concrete architectural terms. The published system description states that the platform uses per-customer virtual database instances to logically separate one customer's data from another's, and that when a customer stops using the service the corresponding virtual database instance is destroyed. It adds a second, unusual control: any customer data identified and catalogued as personal data is subjected to a one-way irreversible hash and stored in that customer's instance, with a commitment that personal data is at no point captured in clear text in logs or databases. Geographic separation reinforces it, since instances serving different regions are described as standalone with no data exchange between them. What is not addressed is separation inside a single customer account: nothing describes walls between business units, teams or matters, and customer-side control is described only as managing which end users receive access, with optional two-factor authentication, IP restrictions and single sign-on.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Terms commit to notice where lawfully permitted. No transparency report located.
A notice commitment exists in the confidentiality clause and goes further than notice alone. Section 4.3 of the customer agreement permits either party to disclose the other's confidential information as required by law, and requires the disclosing party in that event to provide prior written notification, to give the other party the opportunity to contest the disclosure, and to use reasonable efforts to minimise the disclosure to the extent permitted by applicable law. That reaches Customer Data, because the agreement defines Customer Data and information identifying the customer's business practices as the customer's confidential information. A related provision in the security exhibit bars Securiti from informing any third party of a security breach without approval and gives the customer sole right to decide whether affected consumers are notified. Two limits: **no transparency report is published**, and the separate privacy notice describes sharing personal data with regulators, courts and law enforcement in response to a search warrant, subpoena or other valid process without repeating the notice undertaking.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Coverage is described by jurisdiction with no identification of the underlying corpus.
The product carries a regulatory knowledge layer whose sources are never identified. Securiti maintains regulation-specific coverage across GDPR, CPRA, LGPD, PIPEDA, PIPL, the EU AI Act, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM Applications and CDMC, publishes a knowledge centre and regulation summaries, and markets a privacy centre described as regulation-intelligent everywhere, all of which implies a maintained corpus of regulatory text and obligations. No regulator feed, publisher, data supplier or licensing basis is named for any of it, and no update cadence is stated. The corpus that matters most for this product is in a sense the customer's own estate rather than a body of law, since the platform's primary intelligence is discovered from the customer's systems, which makes the provenance question narrower here than for a research tool but not absent. Checked the home page, the solutions and regulations navigation and the terms page on 1 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
No citator applies and the row is recorded rather than skipped. The platform does not return legal authority whose subsequent history a user would need to check; it discovers and classifies data, maps it, and runs privacy and AI governance workflows against regulatory frameworks. The nearest analogue is regulatory currency rather than treatment, and it is asserted rather than described: Securiti maintains dedicated coverage pages for individual regimes and publishes regulation summaries and roundups, without stating how quickly a change in a covered law reaches the assessment templates or compliance checks that depend on it. Searched the home page, the solutions and regulations navigation, the knowledge centre entry points and the terms page on 1 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Nothing located describes what the system does when it cannot classify or assess reliably. No confidence score, abstention path, coverage indicator or low-certainty flag is published for data classification, sensitive data identification or assessment generation, and the marketing claim runs the other way in asserting accurate classification without qualification. The distinction worth drawing is that Securiti sells uncertainty controls for other systems: context-aware prompt, retrieval and response firewalls sit in front of a customer's large language models, and Agent Commander is marketed on detecting AI risk and undoing AI mistakes. Those are controls over the customer's AI, and none of them is described as operating over Securiti's own classification engine. Searched the home page, the product navigation, the security page and the terms page on 1 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name and on the Gencore product name. No court order, opinion or disciplinary record naming Securiti was located. This is a statement about the public record rather than a finding about the product. The failure mode fits poorly, since the platform's output is a data classification, an assessment record or a consent state rather than a citation to legal authority prepared for filing; the analogous exposure would be a misclassification leaving regulated personal data undiscovered and surfacing in a regulatory examination or a breach investigation.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Public materials refer to professional responsibility in general terms without naming guidance.
Professional responsibility is engaged in general terms in the agreement and no guidance is named. The disclaimer records that the product augments but does not replace legal and other professional advisors, and section 2.5 states that it is the customer's responsibility to confer as needed with legal counsel to confirm and maintain compliance with applicable laws. That is a real acknowledgement that professional judgement remains with the customer's lawyers, which is more than most vendors in this lane publish, and it names no source. Nothing references ABA Formal Opinion 512, any state bar opinion, Law Society or SRA guidance, or a regulator statement on AI use within a privacy or compliance function. The extensive regulatory material Securiti does publish, covering the EU AI Act, NIST and OWASP, binds Securiti and its customers as developers and deployers rather than binding the practitioner relying on the output.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Efficiency and cost claims are made and no billing or disclosure treatment exists. The marketing promises automated data minimisation to reduce cost and risk, elimination of disjointed point products, and acceleration of AI adoption, and the product set is sold on replacing manual privacy operations. Nothing accompanies that on how AI-assisted work should be billed or disclosed. The buyer is an in-house privacy, security or legal function rather than a firm billing a client, so the question lands obliquely, but consultancies and advisers use platforms of this kind on client engagements and nothing addresses that position. No per-matter or per-assessment record of machine-assisted work is described for disclosure purposes, as distinct from the audit and assessment records the product generates about the customer's own compliance posture.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The material exists behind a sales conversation or an executed agreement.
The contractual half is obtainable and the disclosure half does not exist. A data processing agreement is published, with the customer agreement directing customers to download and execute Securiti's DPA from its website, and a CCPA service provider addendum is reproduced in full on the terms page, so forwardable contractual material is available. Against that, **no subprocessor list is published anywhere**: the privacy notice identifies recipients only as categories such as IT service providers, email marketing providers and cloud and software service providers, and the CCPA addendum has the customer pre-approve transfers to Securiti's other entities, service providers, third parties and vendors without naming any of them. **No model provider is identified at any point**, and AWS and GCP are named as infrastructure rather than as model providers, which under the coverage test does not answer the question. The SOC 2 report is available on request. A firm therefore cannot tell its client which systems see its content without contracting first.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Part of the record exists and it is aimed at a regulator rather than a court, with the same inversion seen across this lane. The platform generates records of processing activity, assessment records demonstrating compliance, data subject request logs from intake through secure report delivery, breach impact analyses and notification records, and audit controls described in the security exhibit as mechanisms that record and examine activity in systems containing customer data. That is a defensible account of what was assessed and when, which is what a supervisory authority asks for. What it does not do is identify the machine's contribution: nothing states that the record captures which classifications or assessment outputs were machine-generated, which model produced them, or who verified them, and no per-document export tying an output to its model and reviewer is described. Securiti's own AI use is not covered by any published transparency artifact.