Vendors in the index right now: 241 / documents watched daily: 633

Know when your vendors change how they handle your data. From a new subprocessor to a quiet AI-training clause, see exactly what changed.

Every change a vendor makes, in one place. Watched daily, compared line by line and explained in plain English.

See exactly what changed, down to the word.

A GitHub-style diff of every DPA, privacy policy and terms change, with a summary of what it means for you.

Know the day a vendor adds an AI provider.

Lists become structured rows, so a new model provider is flagged and a page redesign isn't.

Review before the objection window closes.

Every alert carries the deadline. Accept, object or leave a note, and the decision stays with the change.

One timeline per vendor, ready for the auditor.

Every snapshot kept and every change linked to the two versions it came from.

Ask Claude about your vendors.

The ClauseTrail MCP server and API answer inside the tools you already use.

What we watch. Every document that says what a vendor does with your data, read from the vendor's own site.

  • Subprocessor lists. Who processes your data, for what and where. Each list becomes structured rows, so a redesign is never an alert and a new AI provider always is.

  • Data processing agreements. Retention periods, breach-notification windows, transfer mechanisms and liability caps: the exact clause that moved, next to the version you agreed to.

  • Privacy policies. What the vendor collects, how long it keeps it and who it shares it with, with every edit shown line by line rather than behind a new "last updated" date.

  • Terms of service. Changes to the contract you already signed: data rights, renewals and governing law, flagged the day they appear.

  • AI usage terms. Does the vendor train models on your data, which model providers see it, and can you opt out? Tracked as facts, each with the sentence that says so.

  • Security and certifications. SOC 2 and ISO 27001 status from each vendor's trust center, so a lapsed report doesn't surprise you at renewal. Soon

Browse the public vendor directory

From published page to reviewed change. Three steps, every day, for every vendor you track.

  1. 1

    Add your vendor stack

    Search a catalog of pre-tracked SaaS vendors or import a CSV. Every vendor comes with its subprocessor list, DPA, privacy policy and terms already wired up.

  2. 2

    We check every document daily

    Each page is fetched and kept as evidence. Lists are compared entry by entry, policies and contracts line by line with the formatting noise stripped out.

  3. 3

    Review with the deadline in view

    Each alert shows the before and after, a plain-English summary, the objection deadline and a review link. Every decision lands in the audit trail.

The index today. It grows every week.

SaaS vendors in the index
241
documents watched daily
633
subprocessor rows mapped
666
between checks of every document
24h

For the audit, and for your tools

Built to be shown to an auditor. And queried from Claude or your own scripts.

  • An audit-ready history. Every snapshot kept, every change linked to the two versions it came from, every decision timestamped by the person who made it.

  • An API and an MCP server. Search the vendor catalog from a script, or ask Claude which of your vendors changed what, and when.

Stop finding out from the auditor. Start with a few vendors today, or send us your whole stack.

  • Free to start

    Track up to 3 vendors with email alerts. No card needed.

    Create an account
  • A long vendor list?

    Send it to us and we'll set up your workspace with you, every vendor and document included.

    Email us