Monday vendor brief
What your vendors changed this week, and what to review.
“List the vendor changes in ClauseTrail we haven't reviewed, highest severity first, as a five-bullet brief with the date to object by.”
Guide · Claude
Claude is good at turning a stack of vendor documents into a clear assessment. Connect it to ClauseTrail and it works from your vendors' current subprocessor lists, DPA terms and AI terms, with the sentence each answer comes from. Here is the setup for Claude Desktop and Claude Code.
Add your vendors to ClauseTrail and create an API key. Add ClauseTrail to Claude Desktop's config file, or to Claude Code with one command. Then ask Claude about your vendors in plain words and it answers from their own documents. For repeat work, keep your policies in a Claude Project.
Which of our vendors fall short of our breach notice requirement?
Claude · used ClauseTrail
Two of twelve. Parcelly's DPA commits to notice "without undue delay" with no hours stated. Helio Mail gives 96 hours, short of your 72. The other ten state 72 hours or less, and I've quoted each clause in the table below.
Answered from ClauseTrail DPA terms, not model memory
Illustrative thread with fictional vendors.
Step by step
Sign up and add the vendors that handle your customers' data, or import them from a CSV. ClauseTrail checks each one's subprocessor list, DPA, privacy policy, terms and AI terms every day and keeps every version, so Claude can answer what changed and when.
In ClauseTrail, open Settings → API & MCP and create a key, on Pro, Team, and Business. It is shown once, it can only read, and you can revoke it at any time.
In Claude Desktop, open Settings → Developer → Edit Config and add the entry below, then restart Claude. In Claude Code, run one command. Claude Desktop needs Node.js for the npx bridge.
Claude Desktop (claude_desktop_config.json)
{ "mcpServers": { "clausetrail": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://clausetrail.com/mcp",
"--header", "Authorization:${CLAUSETRAIL_AUTH}"],
"env": { "CLAUSETRAIL_AUTH": "Bearer YOUR_KEY" } } } }
Claude Code
claude mcp add --transport http clausetrail \
https://clausetrail.com/mcp \
--header "Authorization: Bearer YOUR_KEY"
Custom connectors on claude.ai in the browser sign in with OAuth, which ClauseTrail does not offer yet, so connect through Claude Desktop or Claude Code.
Ask what you want to know. Claude picks the right ClauseTrail tool, shows you the call, and answers from tracked data.
“Use ClauseTrail to tell me what our vendors changed this week, and which change matters most for our GDPR obligations.”
Create a Claude Project for vendor reviews and put your requirements in its instructions: the regions you allow, the breach notice you need, your stance on AI training. Every chat in the Project judges vendors against them.
“We only allow processing in the EU and the UK, need breach notice within 72 hours, and don't accept AI training on customer data. Use ClauseTrail for facts and flag every vendor that falls short.”
Ask Claude for the output your team reads: a vendor assessment, an objection letter, a note for the DPO or a table for the auditor. It can write a document you download or paste.
Before you connect
Within 48 hours
“Anthropic will notify Customer in writing without undue delay, but in any event within 48 hours, after becoming aware of any Security Breach”DPA, www.anthropic.com ↗
15 days ahead
“Customer may, on the basis of reasonable data privacy or data security concerns, object to Anthropic's use of such Subprocessor by providing Anthropic with written notice of the objection within fifteen (15) days of the date of such notice”DPA, www.anthropic.com ↗
Standard contractual clauses
“The parties agree that, to the extent required by Applicable Data Protection Laws, the terms of the SCCs Module Two (controller to processor) and/or Module Three (processor to processor), as completed as described in Schedule 3 of this DPA, are hereby incorporated by reference”DPA, www.anthropic.com ↗
Deleted within 30 days of the contract ending
“Within thirty (30) days of the date of termination or expiration of the Agreement, Anthropic will:”DPA, www.anthropic.com ↗
Once a year
“a similar Audit has not already been conducted less than twelve (12) months prior, unless there are indications of non-compliance and/or it is required by a supervisory authority or other regulatory authority responsible for the enforcement of Applicable Data Protection Laws”DPA, www.anthropic.com ↗
Workflows to copy
What your vendors changed this week, and what to review.
“List the vendor changes in ClauseTrail we haven't reviewed, highest severity first, as a five-bullet brief with the date to object by.”
The first pass of a vendor review, from the vendor's own documents.
“We're evaluating Notion. From ClauseTrail, list its subprocessors outside the EU, its breach notice and subprocessor notice, and whether it trains AI on customer data, with quotes.”
Hold every vendor to the requirements in your Project.
“Check every vendor we track against our requirements, using ClauseTrail's DPA terms and AI terms, and list the ones that fall short and why.”
Answer the board's question: which vendors send our data to AI?
“Which of our vendors send data to an AI provider, which providers, and do their AI terms say they train on customer data?”
See which companies sit behind many of your vendors at once.
“Map our vendors to the companies behind them from ClauseTrail's dependency graph and tell me where we are most concentrated.”
Before a renewal, know what the vendor changed during the contract.
“Our Zendesk contract renews next month. From ClauseTrail, summarize what Zendesk changed in the last year and its current DPA terms.”
Available over MCP
10 read-only tools on ClauseTrail's MCP server. Claude chooses the right one from your question, so you never call them by name.
Safe to hand to Claude
Claude can read ClauseTrail data, never change it. Every tool is read-only and tells the client so. A key reads only your own workspace's vendors and decisions. Keys are stored hashed, shown once, and revoked instantly from Settings → API & MCP. The same data answers as JSON in the API reference.
Add your vendors once. ClauseTrail checks their documents every day, and Claude reads the result.
Claude is a product of Anthropic. ClauseTrail is not affiliated with or endorsed by Anthropic.