Vendor risk monitoring that watches the documents, every day
Continuous vendor monitoring for privacy and compliance teams. ClauseTrail re-checks each vendor's DPA, privacy policy, terms and subprocessor list, then shows the diff, the AI flags and the objection window before it closes.
Point-in-time vendor reviews go stale the week after the questionnaire is filed.
A new subprocessor, a quieter retention clause, or an AI-training term can land on the vendor's own page with no ticket in your queue.
TPRM programmes need continuous monitoring for vendor risk — not another annual PDF.
What ClauseTrail watches.
-
Subprocessor monitoring — structured rows for who processes data, for what and where; additions and removals flagged, redesign noise stripped out
-
DPA change tracking — retention, breach clocks, transfer terms and liability: the clause that moved, next to the version you filed
-
Privacy policies and terms — line-by-line diffs with a plain-English summary
-
AI flags — new AI providers on the list, and AI-training / opt-out language when the vendor publishes it
-
Objection windows — each alert carries the deadline so accept / object / note stays with the change
Ask the same questions from Claude or your own scripts via the MCP server and API (Pro and up).
The public directory is the same data the product watches.
Example concentration page
See who lists OpenAIHow it works.
-
1
Add your vendor stack
Search the catalog or import a CSV.
-
2
We check every document daily
Evidence kept; lists compared entry by entry; policies line by line.
-
3
Review with the deadline in view
Before/after, summary, objection window, decision on the audit trail.
Plans.
| Plan | Price | Best for |
|---|---|---|
| Free | $0 |
Watch the vendors you found in the directory. Track 3 vendors · includes Email alerts |
| Pro | $49/mo |
Your core vendor stack, with the history auditors ask for. Track 25 vendors · everything in Free, plus Slack alerts and API and MCP access to your workspace's vendors |
| Team | $99/mo |
Your team's whole stack, with Slack alerts and exports for the audit. Track 100 vendors · everything in Pro, plus Vendor dependency graph and Audit exports |
| Business | $179/mo |
200 vendors across the business, unlimited team members and priority vendor additions. Track 200 vendors · everything in Team, plus Priority vendor additions |
Every plan includes:
-
Daily checks of subprocessor lists, DPAs, privacy policies and terms
-
Structured change detection for subprocessor lists: added, removed, new location, new purpose
-
Readable diffs of policy and contract changes, with a plain-English summary
-
AI exposure flags: new AI subprocessors and AI-training terms
-
Email alerts with the estimated objection deadline
-
The full change history of every vendor you track
-
A catalog of pre-tracked SaaS vendors
-
Review decisions recorded per change, per user
Questions, answered.
What is vendor risk monitoring?
Watching the vendors you buy from for changes that affect privacy, security or contract risk — and acting before an objection window or audit finding closes on you.
How is continuous vendor monitoring different from an annual review?
An annual questionnaire is a snapshot. Continuous monitoring re-reads the vendor's published documents on a schedule and surfaces what changed since you last accepted them.
Does ClauseTrail replace our TPRM or GRC tool?
No. It feeds document-level change evidence into the programme you already run — reviews, alerts and history you can show an auditor.
What documents do you monitor?
Subprocessor lists, data processing agreements, privacy policies, terms of service and AI usage terms, read from each vendor's own site.
Is there a free plan?
Yes. Free tracks up to 3 vendors with email alerts. No card needed. Upgrade to Pro ($49/mo, up to 25 vendors) when you need Slack, API/MCP and a larger stack.