Transcend

Transcend is a data permissioning and decision layer that sets out to answer a single operational question, whether a given piece of customer data can be used for a given purpose, and to enforce that answer inside the systems that process the data rather than in a document. Its Policy Engine encodes business policy, jurisdictional regulation and individual consent into a single real-time decision that other systems and agents can call before they act, exposed through an API described as MCP-native. Around it sit consent and preference management across web, mobile and downstream marketing systems, data subject request automation that fulfils requests across connected systems and produces system-level proof of completion, and an AI governance use case built around honouring do-not-train signals through data pipelines. The distinguishing piece of architecture is Sombra, a security gateway the customer runs inside its own infrastructure: every integration request passes through it tokenised, authenticated and encrypted, the customer keeps its own API keys with optional delegation to its own key management service, and Transcend states that customer data never leaves the customer environment and that Transcend does not see it. Integrations span systems including AWS, Azure, Databricks, Workday, Okta, Slack, Twilio, Google Workspace and Google Ads, with public developer documentation and open-source repositories. Transcend publishes its full contractual estate openly, including the services agreement, data processing addendum with a named subprocessor list, service level agreement and acceptable use policy. Transcend Inc. is a Delaware corporation based in San Francisco, holds SOC 2 Type II and ISO 27001, and counts Robinhood among named customers.

Vendor siteSan Francisco, California, United States
Last verifiedSeptember 1, 2026

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The decision layer is rules, not models, and the vendor says so in its own framing. Transcend's pitch is policy as code: business policy, jurisdictional regulation and consent encoded into a deterministic real-time decision that systems and agents call before acting. That is deliberately not inference, and the marketing leans on it, promising every use defined and enforced with audit-ready records. AI Features do exist and are defined contractually as large language models or other machine learning features of the Services, and the AI-related use cases are largely about governing someone else's models, honouring do-not-train signals through data pipelines and clearing data for AI initiatives. Strip the models out and the product a buyer pays for remains intact: the permissioning layer, consent propagation, DSR fulfilment, the Sombra gateway and the integration estate. Third consecutive privacy platform at this grade for the same structural reason.

Source: Vendor Published
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Accuracy is asserted in the marketing, measured nowhere, and disclaimed squarely in the agreement. The claims are quantified but unsourced: 174 billion automated data decisions, 99 per cent addressable audience per purpose, column-level classification updated in real time, and a customer quote putting data visibility at roughly 100 per cent. Against that, section 7.4 of the services agreement disclaims any warranty that the Services, **including any Outputs from the AI Features, are accurate, complete, or reliable**, which is the most direct AI-output accuracy disclaimer located anywhere in this pull and is the more candid of the two positions. No precision or recall figure, benchmark or error rate for classification or for the AI Features was located on any surface read on 1 September 2026. The retrieval-and-citation limbs of this axis do not apply, since the product returns permissioning decisions rather than legal authority.

Source: Vendor Published
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Human involvement is offered as a configuration option and never described as a control over model output. The home page states that policy as code runs with humans in the loop only where you want them, and elsewhere that the review queue is encoded automatically and that runtime policy enforcement replaces manual compliance reviews. That is a claim about where a customer may choose to place a checkpoint, and the product's selling proposition is explicitly the removal of manual review, so the axis has to ask what happens when an automated decision is wrong. Nothing located answers it: no confidence threshold, no deferral path, no description of a review surface for the AI Features specifically, and no remediation route beyond the audit record. Two things pull in the customer's favour and belong on the record: every decision is logged with system-level proof, and section 3.3 of the agreement gives the customer a perpetual licence in Outputs while retaining its rights in Inputs, so the customer controls what it does with what the system produces.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

One named customer with a named individual, and no figures attached to either. Robinhood is named on the home page with a quote from Karthik Rangarajan, Head of Security, describing Transcend's role in giving customers control over their data. A second quote is attributed to a named chief executive with **no organisation identified**, which is unusual and reduces its value. The security page carries two further quotes attributed by role and sector only, a CISO and data protection officer at a global staffing firm and a chief information security officer at a global fintech, the latter carrying the only outcome figure located, data visibility improved to roughly 100 per cent. Platform-level claims of 1.9 billion dollars of revenue unlocked, 174 billion automated decisions and 418 million operations and agents governed are unsourced and carry no method. IDC recognised Transcend as a Leader in its 2025 MarketScape for worldwide data privacy compliance software. A customer stories library exists and **was not opened on 1 September 2026**, so a dated outcome with figures was neither located nor excluded.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

This is the strongest confidentiality record in the lane and it stops short of the top band on two named limbs. What carries it. **Section 3.3 of the services agreement provides that Transcend may not use Inputs or Outputs to train or otherwise improve AI Features except solely for the benefit of the Customer**, which is a contractual training prohibition rather than a policy statement, and the only one located in this lane. The Customer Data licence at 3.2 is drawn narrowly, solely to provide the Services, with improvement rights confined to Usage Data that excludes Customer Data. Architecture reinforces the contract: Sombra runs inside the customer's own infrastructure, the customer retains its own API keys with optional delegation to its own key management service, and Transcend states it cannot connect to customer systems directly and does not see the data. Customer Data is defined as the customer's Confidential Information, compelled disclosure carries a prior-notice obligation, and the DPA commits to deletion within thirty days of termination on request. What is absent is privilege and work product treatment, which is never mentioned despite a named Privacy, Legal and Risk buyer, and any position on third-party model providers behind the AI Features.

Source: Vendor Published
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

A responsibility allocation sits in the terms while the marketing sells the removal of legal review. Section 7.4 of the services agreement states that the customer is solely responsible for its compliance with any laws and that Transcend disclaims all liability related to that compliance, and section 2.3 requires the customer to obtain the permissions and consents and comply with the privacy laws necessary for the Services to operate. That is a clear allocation of who owns the legal judgement, and it is not a statement about the line between an information tool and legal advice: nothing located says the output is not legal advice, that no professional relationship arises, or that a user should take advice on their own facts, and no jurisdiction limit or supervision dimension appears. The tension is sharper here than elsewhere in the lane because of how the product is sold, with the marketing promising real-time campaign clearance and **no three-week legal review cycles**, which is an explicit offer to displace a legal review step, published alongside a disclaimer of all liability for the compliance outcome.

Source: Vendor Published
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Nothing published addresses governance of Transcend's own models. The company publishes a substantial amount about AI governance as a subject, including an AI Governance solution built around do-not-train enforcement and a blog arguing that AI governance is enforcement rather than documentation, and all of it concerns the customer's AI rather than Transcend's. No responsible-AI page, AI policy, ethics statement, governance committee, named accountable owner, pre-release testing regime or bias evaluation was located. The site navigation and the full footer were read on 1 September 2026 across platform, solutions, partners, resources, company and developer sections, and contain no such surface. Two things sit adjacent without answering the axis and are credited elsewhere to avoid spending one fact twice: the contractual no-training term is a data commitment and is credited on confidentiality, and the open-source repositories and public documentation are engineering transparency rather than model governance. **The third vendor in this lane to sell AI governance while publishing none of its own.**

Source: Operator Verified
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Every limb this band names is published, specific and dated, in a data processing addendum last updated 27 August 2026. Retention and deletion: on termination Transcend deletes all Customer Personal Data in its possession or control within a maximum of thirty days of a customer request, with backup copies securely isolated and protected from further processing, and absent a request deletion follows standard retention policies. Incident practice: notification without undue delay and **within seventy-two hours** of becoming aware of a Security Breach, with a specified content list covering the nature of the breach, categories and approximate numbers of data subjects and records, likely consequences and measures taken. **Subprocessors are named on a maintained public list** at the documentation site, with fifteen days' prior notice of additions, a commercially reasonable objection route and a mutual termination right if no cure is available. Access control is described concretely: SSO with enforced MFA, least privilege and role-based access, segregation of duties, and quarterly access reviews. Encryption is AES-256 at rest and TLS 1.2 or higher in transit, with annual third-party penetration testing, threat modelling at design, static analysis and dependency checking in the code pipeline, and daily backups tested at least annually. Transfers run on the EU SCCs with module and clause elections set out, the UK addendum and the FADP variations.

Source: Vendor Published
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

The allocation is published, current and readable, and the indemnity is narrower than the best in this corpus. What is there: a services agreement last updated 9 July 2026, published openly and independently assessed under the TermScout certification programme; a mutual cap at fees paid or payable in the twelve months before the event; a defined set of Excluded Claims sitting outside the cap covering customer breaches of use restrictions, indemnity amounts payable to third parties, and either party's breach of confidentiality; a conformance warranty that the Services will operate in substantial conformity with the Documentation and that functionality will not be materially reduced during the term, with correction, re-performance or a refund of prepaid fees as the exclusive remedy; and, unusually, a **standalone warranty that Transcend will comply with all applicable laws in providing the Services**. Two things hold it below the top band. The Transcend indemnity covers third-party intellectual property claims only, with no indemnity for misuse or unauthorised disclosure of Customer Data, and the confidentiality carve-out from the cap **expressly excludes claims related to Customer Data**, so a data incident stays inside the twelve-month cap. No insurance position was located. Nothing addresses an AI output being wrong except to disclaim it.

Source: Vendor Published
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Named systems, a described flow and public developer documentation, short of a stated approach to what is not covered. Integrations are named across the home and security pages and span the categories that matter for this product: identity and HR in Okta and Workday, data platforms in Databricks, AWS and Azure, communications in Slack and Twilio, marketing in Google Ads and AdRoll, and productivity in Google Workspace, with Segment named in the agreement as a worked example of a customer third-party service. What moves is described rather than implied: consent decisions propagate to the CDP, ad tech and loyalty systems, DSR fulfilment runs across connected systems and returns system-level proof, and every request passes through Sombra tokenised, authenticated and encrypted before reaching Transcend. The connector model is real and documented, with public documentation at docs.transcend.io, an API described as MCP-native for agent access, and open-source repositories published on GitHub. **The integrations library and the documentation site were not opened on 1 September 2026**, so depth beyond the named systems was not verified and this grade is deliberately conservative.

Source: Vendor Published
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

The deployment model is the clearest in the lane and the residency detail is thin. Transcend publishes a genuine two-part architecture rather than a hosting note: a hosted control plane, and **Sombra, a security gateway the customer deploys inside its own infrastructure**, through which every integration request passes. The consequences are stated concretely, that customer data never leaves the customer environment, that Transcend cannot connect to customer systems directly, and that the customer retains its own API keys with optional delegation to its own key management service for hardware-backed key management. The data processing addendum confirms the effect in its transfer schedule, recording that where the customer uses Sombra the scope of personal data collected is narrower because it is an on-premises solution using end-to-end encryption. That answers where processing happens more directly than a region list would. What is missing is the region list itself: the DPA states that by default customer data is stored and processed in a secure cloud environment hosted on AWS, and no available regions are enumerated, no residency option is offered, and nothing describes what changes between deployment tiers.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

The standards are named and none of the confirming detail is published. The security page states that Transcend regularly attains SOC 2 Type II and ISO 27001 compliance and displays the AICPA SOC and ISO 27001 marks, and the data processing addendum repeats both, recording that Transcend has obtained SOC 2 Type II certification and maintains an ISO 27001 certification with its security and privacy programmes externally audited annually. Supporting practice is described in more depth than most: annual third-party penetration testing, external audits, threat modelling in the design phase, static code analysis and dependency checking in the pipeline, manual application security testing, and alignment claimed to the Cloud Computing Compliance Controls Catalogue, the NCSC Cloud Security Principles and NIST cloud standards. What is absent is everything that would let a buyer verify it. **No trust centre exists and no report is downloadable or stated to be available on request**; no auditor or certification body is named for either standard; and no certificate date, examination period or scope statement appears. The phrase regularly attains is looser than a current certification claim and is recorded as the vendor's own wording.

Source: Vendor Published
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The AI Features are defined and nothing underneath them is identified. The services agreement defines AI Features as large language models or other machine learning or artificial intelligence features of the Services, which confirms that third-party model categories are in play, and no model, model family or provider is named on any surface read on 1 September 2026, nor is one excluded. A misreading worth guarding against: OpenAI and Perplexity appear in the integration strip on the home and security pages, and they sit there as customer systems Transcend connects to on the customer's behalf, not as providers of Transcend's own AI Features. AWS is named as the default hosting environment in the DPA, which identifies infrastructure rather than models. No commitment to notify customers when the model set changes was located. The maintained subprocessor list is the surface most likely to resolve this, since a model provider processing customer personal data would have to appear on it, and **that list was not opened on 1 September 2026**, so this grade is rebuttable on one fetch.

Source: Vendor Published
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

No pricing information is published at any level, including the unit of charge. The site navigation and the full footer were read on 1 September 2026 across platform, solutions, partners, resources, company and developer sections and contain no pricing page; every commercial route is a demo request. What the published agreement supplies is billing mechanics rather than price or structure: fees are set in an order form, invoice or an in-account billing page, payable in US dollars, invoiced in advance with usage-based fees possibly invoiced monthly in arrears, non-refundable and not subject to set-off, with subscriptions auto-renewing and Transcend able to revise rates on forty-five days' notice before renewal, and past due amounts carrying 1.5 per cent monthly. Usage limits are said to be set in the order form or documentation without naming what is metered. A separate Customer Support document defines support tiers with a Standard tier included at no additional charge, which is the only tier structure published anywhere and concerns support rather than the platform.

Source: Operator Verified
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Coverage is segmented three ways with real pages behind each, and the boundary is left open. By team, five audiences each have their own page, and **one of them is Privacy, Legal and Risk**, which makes Transcend the only vendor in this lane so far to address a legal function on a surface of its own rather than only through a compliance or data label. By use case, five are named and are specific rather than generic: AI transformation and do-not-train, personalisation and audience activation, retail media networks, loyalty and multi-brand programmes, and regulated and sensitive data use. By business type, six are named: AI, consumer, healthcare, fintech, media and business-to-business. The use-case set is unusually revealing about who the product is really for, since retail media networks and loyalty programmes point at consumer-facing enterprises with large first-party data estates rather than at regulated industry generally. What is not stated is where the product stops: no organisation size, data volume, jurisdiction or system type is identified as out of scope, and the regulated and sensitive data use case is framed as a capability rather than a limit.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Never, in the contract

The published terms prohibit training on customer content. Not a policy page, the agreement.

**The first contractual no-training commitment located in this lane.** Section 3.3 of the Online Services Agreement defines AI Features as large language models or other machine learning or artificial intelligence features of the Services, defines Inputs as customer data submitted to them including prompts and queries, and provides that Transcend may not use Inputs or Outputs to train or otherwise improve AI Features, except solely for the benefit of the Customer. It sits in the agreement itself rather than in a policy page, so it binds. Two supporting terms narrow the surrounding position in the same direction: the Customer Data licence at 3.2 is granted solely to provide the Services, and the improvement right Transcend does reserve is confined to Usage Data, which is defined to exclude Customer Data and must be aggregated and anonymised before it appears in any published material. The customer retains all intellectual property rights in its Inputs. The one limit worth recording is the carve-out itself, since improvement solely for the customer's benefit is undefined.

Source: Vendor Publishedmay not use Inputs or Outputs to train or otherwise improve AI FeaturesAs of Sep 1, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Disclosed without a period

Retention is acknowledged in public materials with no stated period.

Deletion is committed with an outer limit and no standing retention period is published. Section 9 of the data processing addendum provides that on termination or expiry Transcend will, at the customer's election and written request, delete all Customer Personal Data in its possession or control as soon as reasonably practicable and within a maximum of thirty days, with the exception of data it must retain by law and data archived on backup systems, which it will securely isolate and protect from further processing. Absent such a request, deletion follows Transcend's standard retention policies, which are not published. The transfer schedule states retention only as the period needed to accomplish the purposes of processing. Nothing separates prompts submitted to the AI Features or their Outputs from customer data generally, and no zero-retention option is described. The architecture reduces the exposure structurally, since data handled through the self-hosted Sombra gateway is described as never leaving the customer's environment.

Source: Vendor Publisheddelete all Customer Personal Data in its possession or controlAs of Sep 1, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Own model, documented

The product maintains its own permission model, documented, requiring the firm to keep it aligned.

Transcend documents its own separation model and answers the question architecturally rather than by tenancy. Sombra is a security gateway the customer deploys inside its own infrastructure, and Transcend states that it enforces every data decision under the customer's security policies, that customer data never leaves the customer environment, and that Transcend does not see it. The key position is stated in the same terms: Transcend's backend never has access to customer API keys, Sombra manages that access with a built-in key management system that can optionally delegate to the customer's own service such as AWS KMS for hardware-backed keys, and Transcend cannot connect to customer systems directly because Sombra always sits in between. Every integration request passes through it tokenised, authenticated and encrypted. The data processing addendum confirms the effect, recording that where Sombra is used the scope of personal data collected is narrower. What is not addressed is separation inside a single customer, with nothing describing walls between teams, brands or matters.

Source: Vendor PublishedSombra sits inside your infrastructure, not oursAs of Sep 1, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Notice committed

Terms commit to notice where lawfully permitted. No transparency report located.

A notice commitment is published in two places and goes further than notice alone, without a transparency report to complete the top value. The data processing addendum requires Transcend to promptly notify the customer of any government requests for access to or information about its processing of customer personal data unless prohibited by law, to provide reasonable cooperation and assistance, and, where it is barred from disclosing the details, to inform the customer that it can no longer comply with the customer's instructions and await further instructions. It adds an undertaking to **use all available and reasonable legal mechanisms to challenge demands for data access through national security process, as well as any non-disclosure provisions attached**, which is a stronger commitment than most vendors publish. The services agreement adds a general compelled-disclosure clause requiring prior notice where permitted, reasonable assistance to contest or limit at the disclosing party's cost, and disclosure of the minimum necessary. **No transparency report was located**, which is what holds this below the top value.

Source: Vendor Publishednotify Customer of any government requests for access to or informationAs of Sep 1, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Not addressed

No located public material identifies the corpus behind the product’s answers.

No legal corpus is published and the product does not retrieve primary law. Transcend's decision layer encodes three inputs, described on the home page as business policy, jurisdictional regulation and customer permissions, so a maintained body of regulatory rules sits behind the jurisdictional limb, and nothing is published about it: no regulator, source, publisher or licensing basis is named, no jurisdictions are enumerated, and no update cadence is stated for how a change in law reaches the encoded rules. That is a narrower gap than for a research product, since the decisive corpus here is the customer's own data estate and consent record rather than a body of law, but it is not immaterial given the platform is sold on producing a defensible answer to whether data can be used. Checked the home page, the security page, the services agreement, the data processing addendum and the full footer on 1 September 2026.

Source: Operator VerifiedAs of Sep 1, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

No citator applies and the row is recorded rather than skipped. The platform returns a permissioning decision about a piece of data, not a legal authority whose subsequent history a user would need to verify. The nearest analogue is whether the encoded jurisdictional rules remain current as law changes, and nothing published describes how that currency is maintained or how quickly an amendment propagates into the Policy Engine. Searched the home page, the platform and solutions navigation, the services agreement and the data processing addendum on 1 September 2026.

Source: Operator VerifiedAs of Sep 1, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

Nothing located describes what the system does when it cannot decide. No confidence score, abstention path, coverage indicator or fallback rule is published for the Policy Engine or the AI Features, which matters more than usual here because the product is explicitly sold as returning a real-time decision that other systems and agents act on before proceeding, so an uncertain or absent answer has to resolve to something. The two published statements closest to the question are disclaimers rather than behaviours: section 7.4 disclaims any warranty that Outputs from the AI Features are accurate, complete or reliable, and section 1.6 acknowledges that trial and beta features may generate or produce inaccurate information or unexpected or incorrect results. Searched the home page, the security page, the platform navigation and both published agreements on 1 September 2026.

Source: Operator VerifiedAs of Sep 1, 2026

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name and on the Sombra product name. No court order, opinion or disciplinary record naming Transcend was located. This is a statement about the public record rather than a finding about the product. The failure mode fits poorly, since the output is a permissioning decision consumed by a downstream system rather than a citation prepared for filing; the analogous exposure would be a wrong clearance allowing data to be used for a purpose it was not permitted for, which would surface in a regulatory action or a class claim rather than in a sanctions docket.

Source: Operator VerifiedAs of Sep 1, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No engagement with professional responsibility or ethics guidance was located. Nothing references ABA Formal Opinion 512, any state bar opinion, Law Society or SRA guidance, or any regulator statement addressed to counsel using AI tools, and no general acknowledgement appears that a practitioner's own professional obligations survive use of the platform. The agreement does allocate legal responsibility to the customer, stating that the customer is solely responsible for its compliance with any laws, but that is an allocation of liability rather than a reference to guidance. The absence is more pointed here than at some peers because Transcend publishes a dedicated Privacy, Legal and Risk buyer page and markets the product as removing legal review cycles. Searched the home page, the security page, the Legal document index, both published agreements and the full footer on 1 September 2026.

Source: Operator VerifiedAs of Sep 1, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure.

Savings and revenue claims are central to the marketing and no billing or disclosure treatment exists. Transcend leads with 1.9 billion dollars of revenue unlocked, publishes a preference management return-on-investment calculator, and sells on removing three-week legal review cycles and eliminating the data subject request ticket queue. Nothing accompanies that on how AI-assisted or automated compliance work should be disclosed or billed where an adviser performs it for a client. The buyer is an in-house privacy, legal, data or marketing function rather than a firm billing a client, so the question lands obliquely, and it is not absent given the platform produces system-level proof of every decision that could in principle support such a disclosure. No per-matter record framed for that purpose is described.

Source: Vendor PublishedAs of Sep 1, 2026

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Subprocessors listed

A current subprocessor or model provider list is published.

Two of the three artifacts a client's AI clause asks for are openly published, and the model provider limb is missing. On the open side, and this is strong: the services agreement, the data processing addendum, the service level agreement and the acceptable use policy are all published without gating, each dated, and the DPA carries completed EU standard contractual clauses with the module and clause elections set out, the UK addendum and the FADP variations, plus **a maintained subprocessor list published at the documentation site with fifteen days' notice of additions and an objection route**. That is forwardable material a firm can send a client without negotiation. The gap is the AI surface: **no model provider is named anywhere**, and the agreement confirms that large language models are in scope of the Services without identifying whose. Under the coverage test a firm can therefore describe the processing chain but not say which models see its content, which is what keeps this below the top value.

Source: Vendor PublishedAs of Sep 1, 2026

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

The record is real, produced automatically, and built for a regulator rather than for an AI-use disclosure. Transcend markets audit-ready records by default, complete records for regulators, mergers and acquisitions and litigation, closed-loop data subject request fulfilment with system-level proof of every request, and a decision log in which every use is defined and enforced. The data processing addendum adds an events logging measure recording that all key actions such as logins, data writes and configuration changes are attributable to particular users with date and time stamps, centralised and protected from change. That is a stronger evidentiary trail than most vendors in this lane publish, and litigation is named as a use for it. What it does not do is identify the machine's contribution: nothing states that the record distinguishes decisions produced by the AI Features from deterministic policy decisions, or captures which model produced an output, so a user could not assemble an AI-use disclosure from it.

Source: Vendor PublishedAs of Sep 1, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 1, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746