Guide · Claude

How to use Claude for vendor risk assessment. With live data from ClauseTrail.

Claude is good at turning a stack of vendor documents into a clear assessment. Connect it to ClauseTrail and it works from your vendors' current subprocessor lists, DPA terms and AI terms, with the sentence each answer comes from. Here is the setup for Claude Desktop and Claude Code.

Add your vendors to ClauseTrail and create an API key. Add ClauseTrail to Claude Desktop's config file, or to Claude Code with one command. Then ask Claude about your vendors in plain words and it answers from their own documents. For repeat work, keep your policies in a Claude Project.

Which of our vendors fall short of our breach notice requirement?

Claude · used ClauseTrail

Two of twelve. Parcelly's DPA commits to notice "without undue delay" with no hours stated. Helio Mail gives 96 hours, short of your 72. The other ten state 72 hours or less, and I've quoted each clause in the table below.

Answered from ClauseTrail DPA terms, not model memory

Illustrative thread with fictional vendors.

Step by step

Set up Claude as your vendor risk analyst.

  1. 1

    Add your vendors to ClauseTrail.

    Sign up and add the vendors that handle your customers' data, or import them from a CSV. ClauseTrail checks each one's subprocessor list, DPA, privacy policy, terms and AI terms every day and keeps every version, so Claude can answer what changed and when.

  2. 2

    Create an API key.

    In ClauseTrail, open Settings → API & MCP and create a key, on Pro, Team, and Business. It is shown once, it can only read, and you can revoke it at any time.

  3. 3

    Add ClauseTrail to Claude.

    In Claude Desktop, open Settings → Developer → Edit Config and add the entry below, then restart Claude. In Claude Code, run one command. Claude Desktop needs Node.js for the npx bridge.

    Claude Desktop (claude_desktop_config.json)

    { "mcpServers": { "clausetrail": { "command": "npx", "args": ["-y", "mcp-remote", "https://clausetrail.com/mcp", "--header", "Authorization:${CLAUSETRAIL_AUTH}"], "env": { "CLAUSETRAIL_AUTH": "Bearer YOUR_KEY" } } } }

    Claude Code

    claude mcp add --transport http clausetrail \ https://clausetrail.com/mcp \ --header "Authorization: Bearer YOUR_KEY"

    Custom connectors on claude.ai in the browser sign in with OAuth, which ClauseTrail does not offer yet, so connect through Claude Desktop or Claude Code.

  4. 4

    Ask in plain words.

    Ask what you want to know. Claude picks the right ClauseTrail tool, shows you the call, and answers from tracked data.

    “Use ClauseTrail to tell me what our vendors changed this week, and which change matters most for our GDPR obligations.”

  5. 5

    Keep your policies in a Project.

    Create a Claude Project for vendor reviews and put your requirements in its instructions: the regions you allow, the breach notice you need, your stance on AI training. Every chat in the Project judges vendors against them.

    “We only allow processing in the EU and the UK, need breach notice within 72 hours, and don't accept AI training on customer data. Use ClauseTrail for facts and flag every vendor that falls short.”

  6. 6

    Turn the answer into something your team uses.

    Ask Claude for the output your team reads: a vendor assessment, an objection letter, a note for the DPO or a table for the auditor. It can write a document you download or paste.

Before you connect

What Anthropic says about your data. From Anthropic's own documents, which ClauseTrail checks daily.

Key terms of Anthropic's DPA

Breach notification

Within 48 hours

“Anthropic will notify Customer in writing without undue delay, but in any event within 48 hours, after becoming aware of any Security Breach”
DPA, www.anthropic.com ↗
Notice of a new subprocessor

15 days ahead

“Customer may, on the basis of reasonable data privacy or data security concerns, object to Anthropic's use of such Subprocessor by providing Anthropic with written notice of the objection within fifteen (15) days of the date of such notice”
DPA, www.anthropic.com ↗
Transfers outside the EU

Standard contractual clauses

“The parties agree that, to the extent required by Applicable Data Protection Laws, the terms of the SCCs Module Two (controller to processor) and/or Module Three (processor to processor), as completed as described in Schedule 3 of this DPA, are hereby incorporated by reference”
DPA, www.anthropic.com ↗
Customer data after the contract ends

Deleted within 30 days of the contract ending

“Within thirty (30) days of the date of termination or expiration of the Agreement, Anthropic will:”
DPA, www.anthropic.com ↗
Audit rights

Once a year

“a similar Audit has not already been conducted less than twelve (12) months prior, unless there are indications of non-compliance and/or it is required by a supervisory authority or other regulatory authority responsible for the enforcement of Applicable Data Protection Laws”
DPA, www.anthropic.com ↗

Anthropic's subprocessors, documents and change history →

Workflows to copy

Six vendor risk workflows for Claude.

Monday vendor brief

What your vendors changed this week, and what to review.

“List the vendor changes in ClauseTrail we haven't reviewed, highest severity first, as a five-bullet brief with the date to object by.”

Your vendors' changes

New vendor assessment

The first pass of a vendor review, from the vendor's own documents.

“We're evaluating Notion. From ClauseTrail, list its subprocessors outside the EU, its breach notice and subprocessor notice, and whether it trains AI on customer data, with quotes.”

Subprocessor lists DPA terms AI terms

Policy check across vendors

Hold every vendor to the requirements in your Project.

“Check every vendor we track against our requirements, using ClauseTrail's DPA terms and AI terms, and list the ones that fall short and why.”

DPA terms AI terms

AI provider inventory

Answer the board's question: which vendors send our data to AI?

“Which of our vendors send data to an AI provider, which providers, and do their AI terms say they train on customer data?”

Who uses a company AI terms

Concentration check

See which companies sit behind many of your vendors at once.

“Map our vendors to the companies behind them from ClauseTrail's dependency graph and tell me where we are most concentrated.”

Shared subprocessors Dependency graph

Renewal prep

Before a renewal, know what the vendor changed during the contract.

“Our Zendesk contract renews next month. From ClauseTrail, summarize what Zendesk changed in the last year and its current DPA terms.”

A vendor's history DPA terms

Available over MCP

Everything Claude can read from ClauseTrail.

10 read-only tools on ClauseTrail's MCP server. Claude chooses the right one from your question, so you never call them by name.

Your vendors' changes
clausetrail_list_workspace_changes
Every change published for the vendors you track, newest first, with where it stands for your team, the decision and who made it. Filter by status, vendor or date.
Ask: “What changed at our vendors this week that we haven't reviewed?”
Who uses a company
clausetrail_find_vendors_using
Which of your vendors name a given company as a subprocessor, or every AI provider your vendors use, with where each one processes data. On Team and Business.
Ask: “Which of our vendors send data to OpenAI?”
Shared subprocessors
clausetrail_list_dependencies
The companies your vendors rely on, most shared first. A company several of your vendors use is concentration risk. On Team and Business.
Ask: “Which subprocessors do most of our vendors depend on?”
Dependency graph
clausetrail_get_workspace_dependency_graph
Your vendors and the companies behind them as nodes and edges, with the purpose and locations each list gives. On Team and Business.
Ask: “Map our vendors to the AI providers behind them.”
A vendor's history
clausetrail_get_vendor_changes
The changes published for any vendor in the catalog: subprocessors added or removed, new locations, and changes to its DPA, policies, terms and AI terms, each with a severity and the date to object by.
Ask: “What has Notion changed in the last year?”
Subprocessor lists
clausetrail_get_subprocessors
A vendor's current subprocessor list as it publishes it: each name, purpose, location and data category, and the company behind the name.
Ask: “Which of Slack's subprocessors process data outside the EU?”
DPA terms
clausetrail_get_dpa_terms
What a vendor's DPA commits to: breach notice, notice before a new subprocessor, transfer mechanisms, deletion after the contract, liability and audit rights, each with the sentence behind it.
Ask: “How fast does HubSpot report a personal data breach?”
AI terms
clausetrail_get_ai_usage_terms
What a vendor's documents say about AI: whether it trains models on customer data, which model providers get it, the opt-out and how long AI data is kept, with quotes.
Ask: “Does Zendesk train AI models on our customer data?”
A vendor's dependencies
clausetrail_get_vendor_dependencies
The companies one vendor relies on, when each first and last appeared on its lists, and which are AI providers.
Ask: “Which AI providers does Intercom rely on?”
Vendor search
clausetrail_search_vendors
Search the catalog of vendors whose subprocessor lists, DPAs and policies ClauseTrail tracks, by name, domain or category.
Ask: “Which analytics vendors does ClauseTrail track?”

Safe to hand to Claude

Read-only, workspace-scoped, revocable.

Claude can read ClauseTrail data, never change it. Every tool is read-only and tells the client so. A key reads only your own workspace's vendors and decisions. Keys are stored hashed, shown once, and revoked instantly from Settings → API & MCP. The same data answers as JSON in the API reference.

Questions, answered.

Can Claude do vendor risk assessment?
Yes. Connect Claude to ClauseTrail over MCP and it reads your vendors' subprocessor lists, DPA terms, AI terms and every change ClauseTrail publishes for them, then turns them into assessments, letters and tables.
How do I connect Claude to ClauseTrail?
Create a key in ClauseTrail under Settings → API & MCP. In Claude Desktop, add a clausetrail entry to claude_desktop_config.json that runs mcp-remote with https://clausetrail.com/mcp and your key, then restart Claude. In Claude Code, run claude mcp add with the URL and an Authorization header.
Does it work on claude.ai in the browser?
Not yet. Custom connectors on claude.ai sign in with OAuth, and ClauseTrail's MCP server takes an API key today. Use Claude Desktop or Claude Code.
What vendor data can Claude read through ClauseTrail?
Ten read-only tools: your vendors' changes with your team's decisions, which vendors use a company, shared subprocessors and the dependency graph (on Team and Business), and for any vendor in the catalog its change history, subprocessor list, DPA terms, AI terms and dependencies, plus vendor search.
Can Claude change my ClauseTrail data?
No. Every ClauseTrail MCP tool is read-only and tells the client so. A key reads only your workspace's vendors and decisions, and you can revoke it at any time.
Does ClauseTrail have an API?
Yes. The same data answers as JSON from the REST API at https://clausetrail.com/v1, and the MCP server is at https://clausetrail.com/mcp. Both take an API key from Settings → API & MCP, on Pro, Team, and Business.
Is ClauseTrail affiliated with Anthropic?
No. Claude is a product of Anthropic. ClauseTrail is an independent vendor monitoring tool.

Claude does the work. ClauseTrail brings the facts.

Add your vendors once. ClauseTrail checks their documents every day, and Claude reads the result.

Claude is a product of Anthropic. ClauseTrail is not affiliated with or endorsed by Anthropic.