Methodology
What makes a fact good enough to publish
Where facts come from
Every profile field is drawn from the vendor's own public documentation — privacy policies, terms of service, data-processing agreements, sub-processor lists, and trust centers. Each profile lists its sources, and every source URL is checked to be live before a profile ships. Facts we cannot verify are stated as unknown — never guessed.
Human review, always
Research drafting is LLM-assisted, but nothing enters the dataset automatically. A human reviews every new profile and every detected change before it is published. Unverifiable claims are softened or dropped; products that shut down or whose policies cannot be cited are excluded entirely.
Daily change monitoring
Each vendor's data-handling documents are fetched daily — politely: rate-limited, honest user agent, robots.txt respected. Content is normalized, hashed, and diffed against the previous snapshot. Real changes are classified, human-approved, and published as change events with the supporting quote and citation — the same events that power the live feed and per-vendor Watch alerts.
Versioning and evidence
Profiles are version-stamped on every approved change, document snapshots are retained as an evidence chain, and each profile shows the date it was last verified. If a vendor blocks crawling entirely, we say so rather than pretend to monitor it.
Subscriber privacy
Watch subscriptions reveal which AI tools an organization cares about — that is sensitive. Subscriber emails and watchlists are never shown publicly, never shared, and every alert carries a one-click unsubscribe.
Data licensing
The full dataset and change-event feed are available for licensing — API access for GRC platforms, TPRM tools, MSSPs, and insurers, with custom terms.
Contact for licensing