Transcend
Transcend is a data permissioning and decision layer that sets out to answer a single operational question, whether a given piece of customer data can be used for a given purpose, and to enforce that answer inside the systems that process the data rather than in a document. Its Policy Engine encodes business policy, jurisdictional regulation and individual consent into a single real-time decision that other systems and agents can call before they act, exposed through an API described as MCP-native. Around it sit consent and preference management across web, mobile and downstream marketing systems, data subject request automation that fulfils requests across connected systems and produces system-level proof of completion, and an AI governance use case built around honouring do-not-train signals through data pipelines. The distinguishing piece of architecture is Sombra, a security gateway the customer runs inside its own infrastructure: every integration request passes through it tokenised, authenticated and encrypted, the customer keeps its own API keys with optional delegation to its own key management service, and Transcend states that customer data never leaves the customer environment and that Transcend does not see it. Integrations span systems including AWS, Azure, Databricks, Workday, Okta, Slack, Twilio, Google Workspace and Google Ads, with public developer documentation and open-source repositories. Transcend publishes its full contractual estate openly, including the services agreement, data processing addendum with a named subprocessor list, service level agreement and acceptable use policy. Transcend Inc. is a Delaware corporation based in San Francisco, holds SOC 2 Type II and ISO 27001, and counts Robinhood among named customers.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The decision layer is rules, not models, and the vendor says so in its own framing. Transcend's pitch is policy as code: business policy, jurisdictional regulation and consent encoded into a deterministic real-time decision that systems and agents call before acting. That is deliberately not inference, and the marketing leans on it, promising every use defined and enforced with audit-ready records. AI Features do exist and are defined contractually as large language models or other machine learning features of the Services, and the AI-related use cases are largely about governing someone else's models, honouring do-not-train signals through data pipelines and clearing data for AI initiatives. Strip the models out and the product a buyer pays for remains intact: the permissioning layer, consent propagation, DSR fulfilment, the Sombra gateway and the integration estate. Third consecutive privacy platform at this grade for the same structural reason.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted in the marketing, measured nowhere, and disclaimed squarely in the agreement. The claims are quantified but unsourced: 174 billion automated data decisions, 99 per cent addressable audience per purpose, column-level classification updated in real time, and a customer quote putting data visibility at roughly 100 per cent. Against that, section 7.4 of the services agreement disclaims any warranty that the Services, **including any Outputs from the AI Features, are accurate, complete, or reliable**, which is the most direct AI-output accuracy disclaimer located anywhere in this pull and is the more candid of the two positions. No precision or recall figure, benchmark or error rate for classification or for the AI Features was located on any surface read on 1 September 2026. The retrieval-and-citation limbs of this axis do not apply, since the product returns permissioning decisions rather than legal authority.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Human involvement is offered as a configuration option and never described as a control over model output. The home page states that policy as code runs with humans in the loop only where you want them, and elsewhere that the review queue is encoded automatically and that runtime policy enforcement replaces manual compliance reviews. That is a claim about where a customer may choose to place a checkpoint, and the product's selling proposition is explicitly the removal of manual review, so the axis has to ask what happens when an automated decision is wrong. Nothing located answers it: no confidence threshold, no deferral path, no description of a review surface for the AI Features specifically, and no remediation route beyond the audit record. Two things pull in the customer's favour and belong on the record: every decision is logged with system-level proof, and section 3.3 of the agreement gives the customer a perpetual licence in Outputs while retaining its rights in Inputs, so the customer controls what it does with what the system produces.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
One named customer with a named individual, and no figures attached to either. Robinhood is named on the home page with a quote from Karthik Rangarajan, Head of Security, describing Transcend's role in giving customers control over their data. A second quote is attributed to a named chief executive with **no organisation identified**, which is unusual and reduces its value. The security page carries two further quotes attributed by role and sector only, a CISO and data protection officer at a global staffing firm and a chief information security officer at a global fintech, the latter carrying the only outcome figure located, data visibility improved to roughly 100 per cent. Platform-level claims of 1.9 billion dollars of revenue unlocked, 174 billion automated decisions and 418 million operations and agents governed are unsourced and carry no method. IDC recognised Transcend as a Leader in its 2025 MarketScape for worldwide data privacy compliance software. A customer stories library exists and **was not opened on 1 September 2026**, so a dated outcome with figures was neither located nor excluded.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
This is the strongest confidentiality record in the lane and it stops short of the top band on two named limbs. What carries it. **Section 3.3 of the services agreement provides that Transcend may not use Inputs or Outputs to train or otherwise improve AI Features except solely for the benefit of the Customer**, which is a contractual training prohibition rather than a policy statement, and the only one located in this lane. The Customer Data licence at 3.2 is drawn narrowly, solely to provide the Services, with improvement rights confined to Usage Data that excludes Customer Data. Architecture reinforces the contract: Sombra runs inside the customer's own infrastructure, the customer retains its own API keys with optional delegation to its own key management service, and Transcend states it cannot connect to customer systems directly and does not see the data. Customer Data is defined as the customer's Confidential Information, compelled disclosure carries a prior-notice obligation, and the DPA commits to deletion within thirty days of termination on request. What is absent is privilege and work product treatment, which is never mentioned despite a named Privacy, Legal and Risk buyer, and any position on third-party model providers behind the AI Features.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
A responsibility allocation sits in the terms while the marketing sells the removal of legal review. Section 7.4 of the services agreement states that the customer is solely responsible for its compliance with any laws and that Transcend disclaims all liability related to that compliance, and section 2.3 requires the customer to obtain the permissions and consents and comply with the privacy laws necessary for the Services to operate. That is a clear allocation of who owns the legal judgement, and it is not a statement about the line between an information tool and legal advice: nothing located says the output is not legal advice, that no professional relationship arises, or that a user should take advice on their own facts, and no jurisdiction limit or supervision dimension appears. The tension is sharper here than elsewhere in the lane because of how the product is sold, with the marketing promising real-time campaign clearance and **no three-week legal review cycles**, which is an explicit offer to displace a legal review step, published alongside a disclaimer of all liability for the compliance outcome.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Nothing published addresses governance of Transcend's own models. The company publishes a substantial amount about AI governance as a subject, including an AI Governance solution built around do-not-train enforcement and a blog arguing that AI governance is enforcement rather than documentation, and all of it concerns the customer's AI rather than Transcend's. No responsible-AI page, AI policy, ethics statement, governance committee, named accountable owner, pre-release testing regime or bias evaluation was located. The site navigation and the full footer were read on 1 September 2026 across platform, solutions, partners, resources, company and developer sections, and contain no such surface. Two things sit adjacent without answering the axis and are credited elsewhere to avoid spending one fact twice: the contractual no-training term is a data commitment and is credited on confidentiality, and the open-source repositories and public documentation are engineering transparency rather than model governance. **The third vendor in this lane to sell AI governance while publishing none of its own.**
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Every limb this band names is published, specific and dated, in a data processing addendum last updated 27 August 2026. Retention and deletion: on termination Transcend deletes all Customer Personal Data in its possession or control within a maximum of thirty days of a customer request, with backup copies securely isolated and protected from further processing, and absent a request deletion follows standard retention policies. Incident practice: notification without undue delay and **within seventy-two hours** of becoming aware of a Security Breach, with a specified content list covering the nature of the breach, categories and approximate numbers of data subjects and records, likely consequences and measures taken. **Subprocessors are named on a maintained public list** at the documentation site, with fifteen days' prior notice of additions, a commercially reasonable objection route and a mutual termination right if no cure is available. Access control is described concretely: SSO with enforced MFA, least privilege and role-based access, segregation of duties, and quarterly access reviews. Encryption is AES-256 at rest and TLS 1.2 or higher in transit, with annual third-party penetration testing, threat modelling at design, static analysis and dependency checking in the code pipeline, and daily backups tested at least annually. Transfers run on the EU SCCs with module and clause elections set out, the UK addendum and the FADP variations.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
The allocation is published, current and readable, and the indemnity is narrower than the best in this corpus. What is there: a services agreement last updated 9 July 2026, published openly and independently assessed under the TermScout certification programme; a mutual cap at fees paid or payable in the twelve months before the event; a defined set of Excluded Claims sitting outside the cap covering customer breaches of use restrictions, indemnity amounts payable to third parties, and either party's breach of confidentiality; a conformance warranty that the Services will operate in substantial conformity with the Documentation and that functionality will not be materially reduced during the term, with correction, re-performance or a refund of prepaid fees as the exclusive remedy; and, unusually, a **standalone warranty that Transcend will comply with all applicable laws in providing the Services**. Two things hold it below the top band. The Transcend indemnity covers third-party intellectual property claims only, with no indemnity for misuse or unauthorised disclosure of Customer Data, and the confidentiality carve-out from the cap **expressly excludes claims related to Customer Data**, so a data incident stays inside the twelve-month cap. No insurance position was located. Nothing addresses an AI output being wrong except to disclaim it.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Named systems, a described flow and public developer documentation, short of a stated approach to what is not covered. Integrations are named across the home and security pages and span the categories that matter for this product: identity and HR in Okta and Workday, data platforms in Databricks, AWS and Azure, communications in Slack and Twilio, marketing in Google Ads and AdRoll, and productivity in Google Workspace, with Segment named in the agreement as a worked example of a customer third-party service. What moves is described rather than implied: consent decisions propagate to the CDP, ad tech and loyalty systems, DSR fulfilment runs across connected systems and returns system-level proof, and every request passes through Sombra tokenised, authenticated and encrypted before reaching Transcend. The connector model is real and documented, with public documentation at docs.transcend.io, an API described as MCP-native for agent access, and open-source repositories published on GitHub. **The integrations library and the documentation site were not opened on 1 September 2026**, so depth beyond the named systems was not verified and this grade is deliberately conservative.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The deployment model is the clearest in the lane and the residency detail is thin. Transcend publishes a genuine two-part architecture rather than a hosting note: a hosted control plane, and **Sombra, a security gateway the customer deploys inside its own infrastructure**, through which every integration request passes. The consequences are stated concretely, that customer data never leaves the customer environment, that Transcend cannot connect to customer systems directly, and that the customer retains its own API keys with optional delegation to its own key management service for hardware-backed key management. The data processing addendum confirms the effect in its transfer schedule, recording that where the customer uses Sombra the scope of personal data collected is narrower because it is an on-premises solution using end-to-end encryption. That answers where processing happens more directly than a region list would. What is missing is the region list itself: the DPA states that by default customer data is stored and processed in a secure cloud environment hosted on AWS, and no available regions are enumerated, no residency option is offered, and nothing describes what changes between deployment tiers.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The standards are named and none of the confirming detail is published. The security page states that Transcend regularly attains SOC 2 Type II and ISO 27001 compliance and displays the AICPA SOC and ISO 27001 marks, and the data processing addendum repeats both, recording that Transcend has obtained SOC 2 Type II certification and maintains an ISO 27001 certification with its security and privacy programmes externally audited annually. Supporting practice is described in more depth than most: annual third-party penetration testing, external audits, threat modelling in the design phase, static code analysis and dependency checking in the pipeline, manual application security testing, and alignment claimed to the Cloud Computing Compliance Controls Catalogue, the NCSC Cloud Security Principles and NIST cloud standards. What is absent is everything that would let a buyer verify it. **No trust centre exists and no report is downloadable or stated to be available on request**; no auditor or certification body is named for either standard; and no certificate date, examination period or scope statement appears. The phrase regularly attains is looser than a current certification claim and is recorded as the vendor's own wording.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The AI Features are defined and nothing underneath them is identified. The services agreement defines AI Features as large language models or other machine learning or artificial intelligence features of the Services, which confirms that third-party model categories are in play, and no model, model family or provider is named on any surface read on 1 September 2026, nor is one excluded. A misreading worth guarding against: OpenAI and Perplexity appear in the integration strip on the home and security pages, and they sit there as customer systems Transcend connects to on the customer's behalf, not as providers of Transcend's own AI Features. AWS is named as the default hosting environment in the DPA, which identifies infrastructure rather than models. No commitment to notify customers when the model set changes was located. The maintained subprocessor list is the surface most likely to resolve this, since a model provider processing customer personal data would have to appear on it, and **that list was not opened on 1 September 2026**, so this grade is rebuttable on one fetch.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. The site navigation and the full footer were read on 1 September 2026 across platform, solutions, partners, resources, company and developer sections and contain no pricing page; every commercial route is a demo request. What the published agreement supplies is billing mechanics rather than price or structure: fees are set in an order form, invoice or an in-account billing page, payable in US dollars, invoiced in advance with usage-based fees possibly invoiced monthly in arrears, non-refundable and not subject to set-off, with subscriptions auto-renewing and Transcend able to revise rates on forty-five days' notice before renewal, and past due amounts carrying 1.5 per cent monthly. Usage limits are said to be set in the order form or documentation without naming what is metered. A separate Customer Support document defines support tiers with a Standard tier included at no additional charge, which is the only tier structure published anywhere and concerns support rather than the platform.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is segmented three ways with real pages behind each, and the boundary is left open. By team, five audiences each have their own page, and **one of them is Privacy, Legal and Risk**, which makes Transcend the only vendor in this lane so far to address a legal function on a surface of its own rather than only through a compliance or data label. By use case, five are named and are specific rather than generic: AI transformation and do-not-train, personalisation and audience activation, retail media networks, loyalty and multi-brand programmes, and regulated and sensitive data use. By business type, six are named: AI, consumer, healthcare, fintech, media and business-to-business. The use-case set is unusually revealing about who the product is really for, since retail media networks and loyalty programmes point at consumer-facing enterprises with large first-party data estates rather than at regulated industry generally. What is not stated is where the product stops: no organisation size, data volume, jurisdiction or system type is identified as out of scope, and the regulated and sensitive data use case is framed as a capability rather than a limit.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The published terms prohibit training on customer content. Not a policy page, the agreement.
**The first contractual no-training commitment located in this lane.** Section 3.3 of the Online Services Agreement defines AI Features as large language models or other machine learning or artificial intelligence features of the Services, defines Inputs as customer data submitted to them including prompts and queries, and provides that Transcend may not use Inputs or Outputs to train or otherwise improve AI Features, except solely for the benefit of the Customer. It sits in the agreement itself rather than in a policy page, so it binds. Two supporting terms narrow the surrounding position in the same direction: the Customer Data licence at 3.2 is granted solely to provide the Services, and the improvement right Transcend does reserve is confined to Usage Data, which is defined to exclude Customer Data and must be aggregated and anonymised before it appears in any published material. The customer retains all intellectual property rights in its Inputs. The one limit worth recording is the carve-out itself, since improvement solely for the customer's benefit is undefined.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is acknowledged in public materials with no stated period.
Deletion is committed with an outer limit and no standing retention period is published. Section 9 of the data processing addendum provides that on termination or expiry Transcend will, at the customer's election and written request, delete all Customer Personal Data in its possession or control as soon as reasonably practicable and within a maximum of thirty days, with the exception of data it must retain by law and data archived on backup systems, which it will securely isolate and protect from further processing. Absent such a request, deletion follows Transcend's standard retention policies, which are not published. The transfer schedule states retention only as the period needed to accomplish the purposes of processing. Nothing separates prompts submitted to the AI Features or their Outputs from customer data generally, and no zero-retention option is described. The architecture reduces the exposure structurally, since data handled through the self-hosted Sombra gateway is described as never leaving the customer's environment.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
Transcend documents its own separation model and answers the question architecturally rather than by tenancy. Sombra is a security gateway the customer deploys inside its own infrastructure, and Transcend states that it enforces every data decision under the customer's security policies, that customer data never leaves the customer environment, and that Transcend does not see it. The key position is stated in the same terms: Transcend's backend never has access to customer API keys, Sombra manages that access with a built-in key management system that can optionally delegate to the customer's own service such as AWS KMS for hardware-backed keys, and Transcend cannot connect to customer systems directly because Sombra always sits in between. Every integration request passes through it tokenised, authenticated and encrypted. The data processing addendum confirms the effect, recording that where Sombra is used the scope of personal data collected is narrower. What is not addressed is separation inside a single customer, with nothing describing walls between teams, brands or matters.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Terms commit to notice where lawfully permitted. No transparency report located.
A notice commitment is published in two places and goes further than notice alone, without a transparency report to complete the top value. The data processing addendum requires Transcend to promptly notify the customer of any government requests for access to or information about its processing of customer personal data unless prohibited by law, to provide reasonable cooperation and assistance, and, where it is barred from disclosing the details, to inform the customer that it can no longer comply with the customer's instructions and await further instructions. It adds an undertaking to **use all available and reasonable legal mechanisms to challenge demands for data access through national security process, as well as any non-disclosure provisions attached**, which is a stronger commitment than most vendors publish. The services agreement adds a general compelled-disclosure clause requiring prior notice where permitted, reasonable assistance to contest or limit at the disclosing party's cost, and disclosure of the minimum necessary. **No transparency report was located**, which is what holds this below the top value.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
No legal corpus is published and the product does not retrieve primary law. Transcend's decision layer encodes three inputs, described on the home page as business policy, jurisdictional regulation and customer permissions, so a maintained body of regulatory rules sits behind the jurisdictional limb, and nothing is published about it: no regulator, source, publisher or licensing basis is named, no jurisdictions are enumerated, and no update cadence is stated for how a change in law reaches the encoded rules. That is a narrower gap than for a research product, since the decisive corpus here is the customer's own data estate and consent record rather than a body of law, but it is not immaterial given the platform is sold on producing a defensible answer to whether data can be used. Checked the home page, the security page, the services agreement, the data processing addendum and the full footer on 1 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
No citator applies and the row is recorded rather than skipped. The platform returns a permissioning decision about a piece of data, not a legal authority whose subsequent history a user would need to verify. The nearest analogue is whether the encoded jurisdictional rules remain current as law changes, and nothing published describes how that currency is maintained or how quickly an amendment propagates into the Policy Engine. Searched the home page, the platform and solutions navigation, the services agreement and the data processing addendum on 1 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Nothing located describes what the system does when it cannot decide. No confidence score, abstention path, coverage indicator or fallback rule is published for the Policy Engine or the AI Features, which matters more than usual here because the product is explicitly sold as returning a real-time decision that other systems and agents act on before proceeding, so an uncertain or absent answer has to resolve to something. The two published statements closest to the question are disclaimers rather than behaviours: section 7.4 disclaims any warranty that Outputs from the AI Features are accurate, complete or reliable, and section 1.6 acknowledges that trial and beta features may generate or produce inaccurate information or unexpected or incorrect results. Searched the home page, the security page, the platform navigation and both published agreements on 1 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name and on the Sombra product name. No court order, opinion or disciplinary record naming Transcend was located. This is a statement about the public record rather than a finding about the product. The failure mode fits poorly, since the output is a permissioning decision consumed by a downstream system rather than a citation prepared for filing; the analogous exposure would be a wrong clearance allowing data to be used for a purpose it was not permitted for, which would surface in a regulatory action or a class claim rather than in a sanctions docket.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No engagement with professional responsibility or ethics guidance was located. Nothing references ABA Formal Opinion 512, any state bar opinion, Law Society or SRA guidance, or any regulator statement addressed to counsel using AI tools, and no general acknowledgement appears that a practitioner's own professional obligations survive use of the platform. The agreement does allocate legal responsibility to the customer, stating that the customer is solely responsible for its compliance with any laws, but that is an allocation of liability rather than a reference to guidance. The absence is more pointed here than at some peers because Transcend publishes a dedicated Privacy, Legal and Risk buyer page and markets the product as removing legal review cycles. Searched the home page, the security page, the Legal document index, both published agreements and the full footer on 1 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Savings and revenue claims are central to the marketing and no billing or disclosure treatment exists. Transcend leads with 1.9 billion dollars of revenue unlocked, publishes a preference management return-on-investment calculator, and sells on removing three-week legal review cycles and eliminating the data subject request ticket queue. Nothing accompanies that on how AI-assisted or automated compliance work should be disclosed or billed where an adviser performs it for a client. The buyer is an in-house privacy, legal, data or marketing function rather than a firm billing a client, so the question lands obliquely, and it is not absent given the platform produces system-level proof of every decision that could in principle support such a disclosure. No per-matter record framed for that purpose is described.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
Two of the three artifacts a client's AI clause asks for are openly published, and the model provider limb is missing. On the open side, and this is strong: the services agreement, the data processing addendum, the service level agreement and the acceptable use policy are all published without gating, each dated, and the DPA carries completed EU standard contractual clauses with the module and clause elections set out, the UK addendum and the FADP variations, plus **a maintained subprocessor list published at the documentation site with fifteen days' notice of additions and an objection route**. That is forwardable material a firm can send a client without negotiation. The gap is the AI surface: **no model provider is named anywhere**, and the agreement confirms that large language models are in scope of the Services without identifying whose. Under the coverage test a firm can therefore describe the processing chain but not say which models see its content, which is what keeps this below the top value.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
The record is real, produced automatically, and built for a regulator rather than for an AI-use disclosure. Transcend markets audit-ready records by default, complete records for regulators, mergers and acquisitions and litigation, closed-loop data subject request fulfilment with system-level proof of every request, and a decision log in which every use is defined and enforced. The data processing addendum adds an events logging measure recording that all key actions such as logins, data writes and configuration changes are attributable to particular users with date and time stamps, centralised and protected from change. That is a stronger evidentiary trail than most vendors in this lane publish, and litigation is named as a use for it. What it does not do is identify the machine's contribution: nothing states that the record distinguishes decisions produced by the AI Features from deterministic policy decisions, or captures which model produced an output, so a user could not assemble an AI-use disclosure from it.