Guide · Perplexity

How to use Perplexity for vendor risk assessment. With live data from ClauseTrail.

Perplexity searches the web well, but a search shows a vendor's documents as they are today. ClauseTrail knows what changed, when, and what it said before. Connect the two and Perplexity finds the story behind every new subprocessor, DPA edit and AI clause.

Add your vendors to ClauseTrail and create an API key. In the Perplexity Mac app, add ClauseTrail as a local MCP connector with one command, then turn it on under Sources. Ask Perplexity what your vendors changed, and let its web search explain why.

Which subprocessors did our vendors add this month, and who are they?

Perplexity · ClauseTrail + web

Three. Northwind CRM added Anthropic, PBC (AI models, United States). Parcelly added Mailbridge, an email delivery company based in Ireland with no public incidents. Lumen Analytics added a data warehouse in Frankfurt. Sources for each company are below.

Changes from ClauseTrail; company background from the web

Illustrative thread with fictional vendors.

Step by step

Set up Perplexity as your vendor risk analyst.

  1. 1

    Add your vendors to ClauseTrail.

    Sign up and add the vendors that handle your customers' data, or import them from a CSV. ClauseTrail checks each one's subprocessor list, DPA, privacy policy, terms and AI terms every day and keeps every version, so Perplexity can answer what changed and when.

  2. 2

    Create an API key.

    In ClauseTrail, open Settings → API & MCP and create a key, on Pro, Team, and Business. It is shown once, it can only read, and you can revoke it at any time.

  3. 3

    Add ClauseTrail to the Perplexity Mac app.

    Open Settings → Connectors, install the PerplexityXPC helper when asked, then choose Add Connector. On the Simple tab, name it ClauseTrail and paste the command below. Save and wait for the Running status. You need Node.js installed for npx.

    Connector command

    npx -y mcp-remote https://clausetrail.com/mcp --header "Authorization: Bearer YOUR_KEY"

    Perplexity supports local MCP connectors in the Mac app today. Remote connectors for the web and mobile apps are announced as coming soon.

  4. 4

    Turn ClauseTrail on under Sources.

    On the Perplexity home screen, switch ClauseTrail on under Sources. Keep web search on as well, so one question can use both.

  5. 5

    Ask what changed, then why.

    Use ClauseTrail for the facts and Perplexity's search for the context around them. This is where Perplexity is strongest.

    “Use ClauseTrail to list the subprocessors our vendors added this month, then search the web for what each new company does and any security incidents it has had.”

  6. 6

    Save the answer as a Page or share it.

    Turn a good answer into a Perplexity Page or share the thread with your team, so the assessment lives somewhere people can find it.

Workflows to copy

Six vendor risk workflows for Perplexity.

New subprocessor background check

A vendor added a company you've never heard of. Find out who they are.

“List the subprocessors our vendors added this month from ClauseTrail, then search the web for who owns each one and where it is based.”

Your vendors' changes Subprocessor lists

New vendor assessment

The vendor's own documents, plus what the web says about it.

“We're evaluating Notion. From ClauseTrail, summarize its DPA terms and AI terms, then search for any breaches or regulatory actions in the last two years.”

DPA terms AI terms

AI provider watch

Know which AI providers your vendors use, and what's in the news about them.

“List the AI providers our vendors use from ClauseTrail, then search for recent news about how each one handles customer data.”

Who uses a company

Incident impact

A company is in the news for an outage or breach. Know who it touches.

“Which of our vendors use Amazon Web Services according to ClauseTrail? Then search for today's AWS status reports.”

Who uses a company Shared subprocessors

Change context

A vendor changed its DPA. Find the announcement behind it.

“Show HubSpot's latest changes from ClauseTrail, then search for HubSpot's announcement or blog post that explains them.”

A vendor's history

Weekly vendor brief

What your vendors changed this week, and what to review.

“List the vendor changes in ClauseTrail we haven't reviewed, highest severity first, with the date to object by.”

Your vendors' changes

Available over MCP

Everything Perplexity can read from ClauseTrail.

10 read-only tools on ClauseTrail's MCP server. Perplexity chooses the right one from your question, so you never call them by name.

Your vendors' changes
clausetrail_list_workspace_changes
Every change published for the vendors you track, newest first, with where it stands for your team, the decision and who made it. Filter by status, vendor or date.
Ask: “What changed at our vendors this week that we haven't reviewed?”
Who uses a company
clausetrail_find_vendors_using
Which of your vendors name a given company as a subprocessor, or every AI provider your vendors use, with where each one processes data. On Team and Business.
Ask: “Which of our vendors send data to OpenAI?”
Shared subprocessors
clausetrail_list_dependencies
The companies your vendors rely on, most shared first. A company several of your vendors use is concentration risk. On Team and Business.
Ask: “Which subprocessors do most of our vendors depend on?”
Dependency graph
clausetrail_get_workspace_dependency_graph
Your vendors and the companies behind them as nodes and edges, with the purpose and locations each list gives. On Team and Business.
Ask: “Map our vendors to the AI providers behind them.”
A vendor's history
clausetrail_get_vendor_changes
The changes published for any vendor in the catalog: subprocessors added or removed, new locations, and changes to its DPA, policies, terms and AI terms, each with a severity and the date to object by.
Ask: “What has Notion changed in the last year?”
Subprocessor lists
clausetrail_get_subprocessors
A vendor's current subprocessor list as it publishes it: each name, purpose, location and data category, and the company behind the name.
Ask: “Which of Slack's subprocessors process data outside the EU?”
DPA terms
clausetrail_get_dpa_terms
What a vendor's DPA commits to: breach notice, notice before a new subprocessor, transfer mechanisms, deletion after the contract, liability and audit rights, each with the sentence behind it.
Ask: “How fast does HubSpot report a personal data breach?”
AI terms
clausetrail_get_ai_usage_terms
What a vendor's documents say about AI: whether it trains models on customer data, which model providers get it, the opt-out and how long AI data is kept, with quotes.
Ask: “Does Zendesk train AI models on our customer data?”
A vendor's dependencies
clausetrail_get_vendor_dependencies
The companies one vendor relies on, when each first and last appeared on its lists, and which are AI providers.
Ask: “Which AI providers does Intercom rely on?”
Vendor search
clausetrail_search_vendors
Search the catalog of vendors whose subprocessor lists, DPAs and policies ClauseTrail tracks, by name, domain or category.
Ask: “Which analytics vendors does ClauseTrail track?”

Safe to hand to Perplexity

Read-only, workspace-scoped, revocable.

Perplexity can read ClauseTrail data, never change it. Every tool is read-only and tells the client so. A key reads only your own workspace's vendors and decisions. Keys are stored hashed, shown once, and revoked instantly from Settings → API & MCP. The same data answers as JSON in the API reference.

Questions, answered.

Can Perplexity do vendor risk assessment?
Yes, for the research half of it. Connect ClauseTrail and Perplexity reads your vendors' tracked subprocessor lists, DPA terms, AI terms and changes, then searches the web for the context around them.
How do I connect Perplexity to ClauseTrail?
In the Perplexity Mac app, open Settings → Connectors, add a connector and paste the command npx -y mcp-remote https://clausetrail.com/mcp with your key in an Authorization header. Then turn ClauseTrail on under Sources.
Does it work in Perplexity on the web or on my phone?
Not yet. Perplexity runs local MCP connectors in its Mac app today, and has announced remote connectors for the web and mobile apps as coming soon.
What vendor data can Perplexity read through ClauseTrail?
Ten read-only tools: your vendors' changes with your team's decisions, which vendors use a company, shared subprocessors and the dependency graph (on Team and Business), and for any vendor in the catalog its change history, subprocessor list, DPA terms, AI terms and dependencies, plus vendor search.
Can Perplexity change my ClauseTrail data?
No. Every ClauseTrail MCP tool is read-only and tells the client so. A key reads only your workspace's vendors and decisions, and you can revoke it at any time.
Does ClauseTrail have an API?
Yes. The same data answers as JSON from the REST API at https://clausetrail.com/v1, and the MCP server is at https://clausetrail.com/mcp. Both take an API key from Settings → API & MCP, on Pro, Team, and Business.
Is ClauseTrail affiliated with Perplexity?
No. Perplexity is a product of Perplexity AI. ClauseTrail is an independent vendor monitoring tool.

Perplexity does the work. ClauseTrail brings the facts.

Add your vendors once. ClauseTrail checks their documents every day, and Perplexity reads the result.

Perplexity is a product of Perplexity AI. ClauseTrail is not affiliated with or endorsed by Perplexity AI.