Driftline
Driftline watches every vendor's terms, privacy policy, DPA and subprocessor list, reads each change, and keeps a risk register that updates itself — reopening accepted risks the day the facts beneath them move.
Alert · A vendor changed its terms
Every public trust artifact a vendor publishes, watched around the clock — nothing slips by between reviews.
Training rights, objection windows, notification commitments, AI subprocessors — read from the vendor's own terms, kept current.
AI reviews every change and ranks it — plain-language summaries, prioritized so your team works signal, not noise.
Findings promote into a register with a full lifecycle — and a detected change can reopen a risk you already accepted.
Vendors' subprocessor disclosures resolve into one graph — how far your data reaches, and which paths end at an AI lab.
Pick any vendor and trace their Nth-party exposure through every tier of the graph — who routes data in, and where it flows on.
AI posture monitoring
The answer is buried in the terms you already accepted. Driftline extracts it from each vendor's own documents — dated, evidenced, kept current — and flags the day it changes.
When any row shifts, it becomes a change event — summarized, prioritized, and pushed to your risk register.
Privacy policy · change detected
We will not use Customer Data to train machine-learning models.
We may use de-identified Customer Data to improve our models.
The clause your annual review would find next March. Driftline flags it the day it ships.
Send us your vendor list and we'll map — free, within 48 hours — which vendors add AI subprocessors or reserve the right to train on your data, and where your nth-party exposure concentrates.