Securiti

Securiti sells what it calls the DataAI Command Platform, built on a knowledge graph that maps data and AI objects across hybrid multicloud, SaaS and on-premise estates, and organised into four pillars addressed to different teams. The privacy pillar is the one legal and privacy counsel own: data mapping automation producing records of processing activity, data subject request automation covering intake through identity verification, discovery, redaction and secure report delivery, assessment automation for privacy and AI impact assessments, consent management for web and mobile, breach management with impact analysis and notification workflows, a consumer-facing privacy centre, and compliance management against global regimes including GDPR, CPRA, LGPD, PIPEDA and PIPL. The security pillar covers data security posture management, data discovery and classification, access intelligence, data flow governance and breach impact analysis. The governance pillar adds a data catalogue, lineage and quality. The fourth pillar, Gencore AI, is infrastructure for customers building their own AI systems: vectorising and ingesting unstructured files into vector databases, curating and sanitising data for model training and tuning, context-aware prompt, retrieval and response firewalls for large language models, and rule-aware enterprise copilots. Agent Commander, launched with Veeam, addresses risk from AI agents. Securiti maps its coverage to the EU AI Act, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM applications and CDMC, states more than a thousand integrations across systems including AWS, GCP, Azure, Snowflake and Databricks, and runs separate Global and EU production clouds on AWS and GCP with no data exchange between instances. The company is Securiti, LLC. of San Jose, California, led by Rehan Jalil, and was acquired by Veeam.

Vendor siteSan Jose, California, United States
Last verifiedSeptember 1, 2026

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

AI is present in three distinct ways here and none of them makes the models the product a legal buyer is paying for. First, as subject matter: AI Governance, EU AI Act and NIST AI RMF pages sell the ability to govern a customer's AI, which is the product managing someone else's models. Second, as infrastructure for the customer: Gencore AI vectorises and sanitises data for training, runs prompt, retrieval and response firewalls, and builds copilots, which is AI plumbing rather than AI doing the buyer's work. Third, and closest to this axis, as technique inside classification and the DataAI Command Graph. Strip the models out and what remains is fully saleable and is most of the platform: data discovery and scanning across a stated thousand-plus integrations, a catalogue, lineage, a data map producing records of processing activity, DSR workflow, consent capture, assessment templates and breach notification. Consistent with the comparable platform in this lane, which took the same grade for the same structural reason.

Source: Vendor Published
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Accuracy is asserted repeatedly in the marketing and measured nowhere. The claim appears in the product copy as accurately classifying data, discovering shadow and cloud-native assets, and delivering unified intelligence, and classification precision is the decisive quality metric for a discovery and posture-management product: a missed store of personal data is the failure mode that matters, and an over-broad match creates work that erodes trust in the tool. No precision or recall figure, benchmark, test set or false-positive rate was located on any surface read on 1 September 2026. Two limbs of this axis do not bite, since the platform does not retrieve legal authority and produces no citations a reader would open. The agreement is more candid than the marketing on this point and is graded on the liability row: Securiti warrants substantial conformity with the Documentation rather than accuracy of any classification result.

Source: Vendor Published
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Oversight is sold as a product and not described as a control over the vendor's own output. Securiti ships genuine runtime controls, with context-aware prompt, retrieval and response firewalls for large language models and Agent Commander for detecting and undoing AI agent mistakes, but every one of those governs the customer's AI systems rather than Securiti's classification and assessment engine. On its own side, nothing located states what runs unattended, what confidence threshold causes the system to defer, where a reviewer sits relative to a classification decision, or what happens after a classification is wrong. Assessment Automation implies human authorship of assessments without describing a checkpoint over machine output. The agreement is the only place a supervision expectation is stated and it points at the customer: the disclaimer records that the product augments rather than replaces professional advisors, and that the customer must confer with legal counsel as needed. That places responsibility rather than describing a mechanism.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Named organisations, named individuals with titles and dates, and no figures for what changed. The Spotlight Talks series carries on-the-record interviews with a director of global analytics at Dye and Durham, an SVP of product at Walker and Dunlop discussing a 135 billion dollar portfolio, and named executives at Sanofi, Volkswagen and International Flavors and Fragrances, each dated between April and June 2025. That is materially better attribution than most of this corpus, and it is interview material rather than outcome measurement: no before-and-after metric, deployment scale or time saving is attached to any of them. Analyst recognition is extensive but is not deployment evidence, spanning GigaOm, Frost and Sullivan, IDC MarketScape, Forrester Wave, Gartner Cool Vendor and an RSA Conference Innovation Sandbox win. **One piece of context belongs on this row**: section 9.2 of the customer agreement obliges customers to join Securiti's reference programme and to develop a profile including an executive quote and logo, so the supply of testimonials is a contractual term rather than purely voluntary.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

The architecture is documented with unusual specificity and the question is answered in the vendor's favour rather than the customer's. On the strong side, and all of it published in the agreement or its security exhibit: per-customer virtual database instances logically separating one customer's data from another's and destroyed when the customer stops using the service; personal data identified by the platform subjected to a one-way irreversible hash, with a commitment that personal data is at no point captured in clear text in logs or databases; mutual contractual confidentiality with a notice-and-opportunity-to-contest provision for legally compelled disclosure; customer ownership of Customer Data; and deletion of all Customer Data from online systems within one business week of a confirmed request. Against that sits the term that decides this axis. **Section 2.1 grants Securiti a royalty-free, worldwide licence to use Customer Data both to provide the service and for the purpose of enhancing product or services**, with no carve-out for model training and no definition of what enhancement covers. Privilege and work product are not addressed, and no position on third-party model providers exists.

Source: Vendor Published
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

A real position on advice versus tooling is published in the agreement itself, which is more than most of this lane manages. The disclaimer at section 5.4 states in terms that the customer acknowledges the product is intended only to augment the customer's privacy practices but not replace legal and other professional advisors, and that the customer is a data controller responsible for what data it collects and for its own privacy policies. Section 2.5 reinforces it operationally: the customer assumes full responsibility as controller, warrants that it has complied with transparency obligations and obtained the necessary consents and legal bases, and, in an unusually direct sentence, records that it is the customer's responsibility to confer as needed with legal counsel to confirm and maintain compliance with applicable laws. That is a published allocation of the professional judgement, addressed to the person who will rely on the output. What is missing is the rest of the treatment: no jurisdiction limit is named for the tool's own coverage, nothing addresses the supervision or competence duties of the practitioner using it, and no professional guidance is referenced anywhere.

Source: Vendor Published
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Nothing published addresses governance of Securiti's own models, and the contrast with what the company sells is the point. Securiti publishes extensive material on AI governance frameworks as product capability, with dedicated pages for the EU AI Act, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM Applications and CDMC, and an AI Governance module sold to establish controls for the safe adoption of AI. None of that is Securiti's own governance. No responsible-AI page, AI policy, ethics statement, AI governance committee, named accountable owner, pre-release testing regime or bias evaluation was located. The site navigation was read in full on 1 September 2026 across products, solutions, resources and company sections and contains no such surface; the Company menu offers About Us, Partner Program, Contact, News Coverage, Press Releases and Careers, and the footer offers terms, security, cookie preferences and privacy request routes. The security exhibit designates a security official and a cross-functional Security Council, which is information security governance rather than AI governance. **A vendor selling AI governance publishes none of its own.**

Source: Operator Verified
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Substantive, specific and published across most of the ground, short of a named subprocessor list. The security exhibit to the customer agreement is unusually concrete. Deletion carries a stated window: on a customer request filed by ticket or email, Securiti deletes all Customer Data from online systems within one business week of confirmation, with retention only where applicable law requires. Incident practice carries a stated deadline and method: notification of a security breach as soon as practicable and no later than seventy-two hours after Securiti becomes aware, by email with a read receipt to a designated address, with Securiti barred from informing third parties without approval and the customer holding sole right to decide whether affected consumers are notified. Access control is role-based, reviewed regularly and monitored, with a stated subset of personnel able to reach customer data. Testing is described with dates attached to cadence: annual third-party penetration tests and audits, weekly internal scans, disaster recovery tested twice a year with an executive summary available to customers on request. Devices carry a minimum of AES-128 full disk encryption. What is absent is the subprocessor limb: third parties appear only as categories such as IT service providers and cloud providers, with none named, and the CCPA addendum has the customer pre-approve transfers to Securiti's affiliates, service providers, third parties and vendors without identifying them.

Source: Vendor Published
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Every limb this band names is published and specific, and one of them appears here for the first time in the corpus. The indemnity runs two ways rather than one and covers more than intellectual property: Securiti defends the customer against third-party claims that use of the product infringes a US patent, copyright, trade secret or trademark, **and separately against claims arising out of any use or disclosure of Customer Data by Securiti in breach of the agreement**, which is a indemnity rather than the IP-only indemnity that is standard in this corpus. The cap is stated with a hard ceiling: direct damages limited to the lesser of amounts paid under the applicable order form in the preceding twelve months **or one million dollars**, with the usual consequential-damages exclusion running mutually and the customer's payment obligations carved out. A warranty a buyer can invoke commits the product to substantially meet the order form requirements, substantially conform to the documentation and be free of malicious code, with re-performance, termination and a pro-rata refund as the exclusive remedy. **An insurance position is published, which no other record in this pull carries**: errors and omissions, professional liability and cyber cover of not less than three million dollars per claim and in the annual aggregate, maintained through the term and for two years after, with thirty days' notice of cancellation. A service level agreement adds 99.5 per cent availability, tiered credits and a termination right below 92 per cent for three consecutive months. Nothing is specific to an AI output being wrong.

Source: Vendor Published
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Real integrations exist, are named, and stop short of documented depth. Securiti states more than a thousand integrations across data systems and names the principal ones on its own navigation: AWS, Google Cloud, Azure, Snowflake and Databricks each carry a dedicated page, with a connectors index behind them. What travels is describable at a high level from the product set, since discovery, classification, access intelligence and lineage all operate by reaching into those systems and reading their contents, and downloadable components are deployed inside the customer's own environment for parts of the platform. What is missing is the implementer's view: no API reference or connector specification was located on the pages read, and nothing describes the direction or granularity of what moves for any individual system. A documentation site exists at docs.securiti.ai, listed among the company's own internet-facing assets in the published system description, and **was not opened on 1 September 2026**, so depth was neither confirmed nor excluded.

Source: Vendor Published
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

The deployment model is stated plainly with partial residency detail. The published system description sets out a multi-tenant cloud service hosted on AWS and GCP, with per-customer virtual database instances providing logical separation, and adds a genuine hybrid element in downloadable components that must be deployed inside the customer's own environment. Residency is real rather than gestural: platform instances sit in multiple geographically distributed data centres, and the company states that **each instance serves customers from a specific geography as a standalone offering with no data exchange between instances**, which answers the processing question more directly than most vendors manage. Two clouds are identified concretely by their own endpoints, a Global Production Cloud and an **EU Production Cloud** at app.eu.securiti.ai with its own status page. Resilience detail is published, with daily backups copied to a different data centre in a different region, a pilot-light disaster recovery strategy, multi-availability-zone failover and a stated 24-hour RTO and RPO. What keeps this below the top band is that the full list of available regions is never enumerated beyond the EU and Global clouds, and nothing describes what changes between deployment tiers.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

The certifications are real and named, and none of the evidence is reachable without asking. Securiti states SOC 2 Type II certification with a copy of the report available on request to prospective and current customers, and holds **ISO 27001:2022 and ISO 27701:2019**, the latter being the privacy information management standard and a sensible one for this product. The customer agreement backs the SOC 2 position contractually, committing Securiti to provide its most recently completed SOC 2 report or an industry-standard successor on request. Supporting detail is unusually good for a vendor with no trust portal: the published system description names AWS and GCP as the underlying providers and describes the shared responsibility split, annual third-party penetration tests and audits, weekly internal scans, and a disaster recovery test executive summary available on request. What holds it below the top band is access and specificity. There is no trust centre and nothing is downloadable; no auditor or certification body is named for any of the three; no certificate date, examination period or scope statement appears; and every route to the evidence runs through a request. Under the gated-is-not-absent tiers this is the self-serve request tier, materially better than absent and short of open publication.

Source: Vendor Published
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The platform is built around models and identifies none of them. Securiti describes a knowledge graph at the core, classification across structured and unstructured data, vectorisation and ingestion into vector databases, curation and sanitisation of data for model training and tuning, and prompt, retrieval and response firewalls for large language models. Every one of those implies models, and no model, model family, provider or architecture is named anywhere on the surfaces read on 1 September 2026. Nothing states whether a third-party foundation model is called at any point in classification or in the copilot products, and nothing excludes one. AWS and GCP are named as infrastructure providers, which identifies where workloads run rather than whose models they are, and does not answer this axis. No commitment to notify customers when the model set changes was located. This sits above the bottom band because the architecture is described in real terms rather than gestured at, and below the band above because nothing underneath it is identified.

Source: Vendor Published
CC on Commercial TransparencyPricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

No figure and no tier are published anywhere, and the charging unit is nonetheless readable, which is an unusual combination worth recording precisely. The site navigation was read in full on 1 September 2026 and contains no pricing page; every commercial route on every page is a demo request or a contact form. What is published sits in the customer agreement rather than in marketing: the number of Authorized Users accessing the product is capped by the figure specified in the order form, which identifies the unit of charge as named users; fees are quoted and payable in United States dollars; payment obligations are non-cancellable, non-pro-ratable for partial months and non-refundable; late payment carries interest at one and a half per cent per month; and subscriptions renew automatically for successive terms equal to the initial term unless either party gives thirty days' written notice. The service level agreement adds a published credit schedule of four, six and ten per cent against availability bands. So a buyer can read the shape of the commercial relationship in advance while learning nothing about what it costs, with no rate, band, package or tier name published at any point.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Coverage is documented across three axes with real substance behind each, and the boundary is left open. Six industries carry dedicated pages: financial services, healthcare, telecom, retail, travel and hospitality, and manufacturing. Regulatory coverage is named rather than gestured at, with individual pages for GDPR, California's CPRA, Brazil's LGPD, Canada's PIPEDA, China's PIPL, the EU AI Act, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM Applications and CDMC, behind a wider index. Technology coverage is quantified at more than a thousand integrations with the major cloud and data platforms named. What is not stated is where the product stops, with no statement of organisation size, data volume, or the environments and obligations it does not reach. The buyer picture carries the same gap seen across this lane: the Roles navigation offers Data+AI Builders, Data Security, Data Privacy, Data Governance and Marketing, and **no page for legal or counsel**, even though the privacy pillar is the work a data protection officer or privacy counsel owns and the agreement itself tells the customer to confer with legal counsel.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Permitted, in the contract

The published agreement expressly reserves a right to train on customer content, with no opt out located. Any de identification, anonymisation or aggregation qualifier is recorded in the summary.

The agreement grants an affirmative right rather than withholding one. Section 2.1 of the customer agreement has the customer grant Securiti a royalty-free, worldwide, non-exclusive, fully paid-up licence to use Customer Data in order to perform and provide the product and professional services for the customer's benefit **or for the purpose of enhancing product or services**. The second limb is the operative one: it is a service-improvement right with no carve-out for model training, no definition of what enhancement covers, and no opt-out. Two adjacent terms narrow the picture without closing it. Securiti owns System Data, defined as anonymised user and other data about the product used for performance, availability and security reporting, so some improvement use is expressly anonymised. And the CCPA addendum certifies that Securiti will not sell customer personal information and will not retain, use or disclose it outside the direct business relationship or for purposes other than performing the services, which pulls against the enhancement limb for CCPA-covered data specifically. **A buyer cannot tell from the published documents whether its content trains models.**

Source: Vendor Publishedfor the purpose of enhancing product or servicesAs of Sep 1, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Customer controlled, no zero option

The customer controls the retention window, by product configuration or by contractual instruction, but zero retention is not stated as available.

Deletion is customer-initiated with a stated window, and no retention period is published for anything held before that request. Section 17 of the security exhibit provides that a customer may request deletion by filing a support ticket or emailing support, and that on receiving confirmation of the request Securiti will delete all Customer Data from online systems within one business week, retaining data only to the extent and for the period applicable law requires. Customer Data may also be deleted following termination or suspension. That is a real and unusually specific control, and it is a deletion mechanism rather than a retention policy: nothing states how long inputs, classification outputs, assessment records or scan results are kept absent a request, and no zero-retention option is described. The separate privacy notice covers only personal data Securiti holds as a controller and sets qualitative criteria rather than a period.

Source: Vendor Publisheddelete all Customer Data from online systems within one business weekAs of Sep 1, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Own model, documented

The product maintains its own permission model, documented, requiring the firm to keep it aligned.

Securiti operates its own separation model and documents it at the tenant level in concrete architectural terms. The published system description states that the platform uses per-customer virtual database instances to logically separate one customer's data from another's, and that when a customer stops using the service the corresponding virtual database instance is destroyed. It adds a second, unusual control: any customer data identified and catalogued as personal data is subjected to a one-way irreversible hash and stored in that customer's instance, with a commitment that personal data is at no point captured in clear text in logs or databases. Geographic separation reinforces it, since instances serving different regions are described as standalone with no data exchange between them. What is not addressed is separation inside a single customer account: nothing describes walls between business units, teams or matters, and customer-side control is described only as managing which end users receive access, with optional two-factor authentication, IP restrictions and single sign-on.

Source: Vendor Publishedper-customer, virtual database instances to logically separate one customer's dataAs of Sep 1, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Notice committed

Terms commit to notice where lawfully permitted. No transparency report located.

A notice commitment exists in the confidentiality clause and goes further than notice alone. Section 4.3 of the customer agreement permits either party to disclose the other's confidential information as required by law, and requires the disclosing party in that event to provide prior written notification, to give the other party the opportunity to contest the disclosure, and to use reasonable efforts to minimise the disclosure to the extent permitted by applicable law. That reaches Customer Data, because the agreement defines Customer Data and information identifying the customer's business practices as the customer's confidential information. A related provision in the security exhibit bars Securiti from informing any third party of a security breach without approval and gives the customer sole right to decide whether affected consumers are notified. Two limits: **no transparency report is published**, and the separate privacy notice describes sharing personal data with regulators, courts and law enforcement in response to a search warrant, subpoena or other valid process without repeating the notice undertaking.

Source: Vendor Publishedwill provide the disclosing party with prior written notification thereofAs of Sep 1, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Jurisdictions only

Coverage is described by jurisdiction with no identification of the underlying corpus.

The product carries a regulatory knowledge layer whose sources are never identified. Securiti maintains regulation-specific coverage across GDPR, CPRA, LGPD, PIPEDA, PIPL, the EU AI Act, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM Applications and CDMC, publishes a knowledge centre and regulation summaries, and markets a privacy centre described as regulation-intelligent everywhere, all of which implies a maintained corpus of regulatory text and obligations. No regulator feed, publisher, data supplier or licensing basis is named for any of it, and no update cadence is stated. The corpus that matters most for this product is in a sense the customer's own estate rather than a body of law, since the platform's primary intelligence is discovered from the customer's systems, which makes the provenance question narrower here than for a research tool but not absent. Checked the home page, the solutions and regulations navigation and the terms page on 1 September 2026.

Source: Vendor PublishedAs of Sep 1, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

No citator applies and the row is recorded rather than skipped. The platform does not return legal authority whose subsequent history a user would need to check; it discovers and classifies data, maps it, and runs privacy and AI governance workflows against regulatory frameworks. The nearest analogue is regulatory currency rather than treatment, and it is asserted rather than described: Securiti maintains dedicated coverage pages for individual regimes and publishes regulation summaries and roundups, without stating how quickly a change in a covered law reaches the assessment templates or compliance checks that depend on it. Searched the home page, the solutions and regulations navigation, the knowledge centre entry points and the terms page on 1 September 2026.

Source: Operator VerifiedAs of Sep 1, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

Nothing located describes what the system does when it cannot classify or assess reliably. No confidence score, abstention path, coverage indicator or low-certainty flag is published for data classification, sensitive data identification or assessment generation, and the marketing claim runs the other way in asserting accurate classification without qualification. The distinction worth drawing is that Securiti sells uncertainty controls for other systems: context-aware prompt, retrieval and response firewalls sit in front of a customer's large language models, and Agent Commander is marketed on detecting AI risk and undoing AI mistakes. Those are controls over the customer's AI, and none of them is described as operating over Securiti's own classification engine. Searched the home page, the product navigation, the security page and the terms page on 1 September 2026.

Source: Operator VerifiedAs of Sep 1, 2026

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name and on the Gencore product name. No court order, opinion or disciplinary record naming Securiti was located. This is a statement about the public record rather than a finding about the product. The failure mode fits poorly, since the platform's output is a data classification, an assessment record or a consent state rather than a citation to legal authority prepared for filing; the analogous exposure would be a misclassification leaving regulated personal data undiscovered and surfacing in a regulatory examination or a breach investigation.

Source: Operator VerifiedAs of Sep 1, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Generic reference

Public materials refer to professional responsibility in general terms without naming guidance.

Professional responsibility is engaged in general terms in the agreement and no guidance is named. The disclaimer records that the product augments but does not replace legal and other professional advisors, and section 2.5 states that it is the customer's responsibility to confer as needed with legal counsel to confirm and maintain compliance with applicable laws. That is a real acknowledgement that professional judgement remains with the customer's lawyers, which is more than most vendors in this lane publish, and it names no source. Nothing references ABA Formal Opinion 512, any state bar opinion, Law Society or SRA guidance, or a regulator statement on AI use within a privacy or compliance function. The extensive regulatory material Securiti does publish, covering the EU AI Act, NIST and OWASP, binds Securiti and its customers as developers and deployers rather than binding the practitioner relying on the output.

Source: Vendor PublishedAs of Sep 1, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure.

Efficiency and cost claims are made and no billing or disclosure treatment exists. The marketing promises automated data minimisation to reduce cost and risk, elimination of disjointed point products, and acceleration of AI adoption, and the product set is sold on replacing manual privacy operations. Nothing accompanies that on how AI-assisted work should be billed or disclosed. The buyer is an in-house privacy, security or legal function rather than a firm billing a client, so the question lands obliquely, but consultancies and advisers use platforms of this kind on client engagements and nothing addresses that position. No per-matter or per-assessment record of machine-assisted work is described for disclosure purposes, as distinct from the audit and assessment records the product generates about the customer's own compliance posture.

Source: Vendor PublishedAs of Sep 1, 2026

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

On request only

The material exists behind a sales conversation or an executed agreement.

The contractual half is obtainable and the disclosure half does not exist. A data processing agreement is published, with the customer agreement directing customers to download and execute Securiti's DPA from its website, and a CCPA service provider addendum is reproduced in full on the terms page, so forwardable contractual material is available. Against that, **no subprocessor list is published anywhere**: the privacy notice identifies recipients only as categories such as IT service providers, email marketing providers and cloud and software service providers, and the CCPA addendum has the customer pre-approve transfers to Securiti's other entities, service providers, third parties and vendors without naming any of them. **No model provider is identified at any point**, and AWS and GCP are named as infrastructure rather than as model providers, which under the coverage test does not answer the question. The SOC 2 report is available on request. A firm therefore cannot tell its client which systems see its content without contracting first.

Source: Operator VerifiedAs of Sep 1, 2026

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

Part of the record exists and it is aimed at a regulator rather than a court, with the same inversion seen across this lane. The platform generates records of processing activity, assessment records demonstrating compliance, data subject request logs from intake through secure report delivery, breach impact analyses and notification records, and audit controls described in the security exhibit as mechanisms that record and examine activity in systems containing customer data. That is a defensible account of what was assessed and when, which is what a supervisory authority asks for. What it does not do is identify the machine's contribution: nothing states that the record captures which classifications or assessment outputs were machine-generated, which model produced them, or who verified them, and no per-document export tying an output to its model and reviewer is described. Securiti's own AI use is not covered by any published transparency artifact.

Source: Vendor PublishedAs of Sep 1, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 1, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746