The material-change blind spot

Your control framework assumes a capability your stack doesn't have.

Every framework you're audited against — GDPR Art. 28, DORA, SOC 2, ISO 27001 — assumes you'll know when a vendor materially changes. Driftline is the layer that actually knows: continuous monitoring of the legal documents themselves, with the change, the meaning, and the impact on your portfolio.

Why nothing else does this

Four categories of tooling claim vendor monitoring. Each watches something — none watch the legal layer.

  • GRC / TPRM suites

    Watches: Questionnaire workflow — self-reported, point-in-time.

    Misses: The vendor's actual documents changing between annual reviews.

  • Security ratings

    Watches: Outside-in technical posture: ports, certs, breach chatter.

    Misses: A training-rights clause isn't a port scan; legal drift is invisible to them.

  • Compliance automation

    Watches: Your controls, plus a vendor inventory.

    Misses: Vendor “review” is an annual checkbox, not surveillance of the vendor.

  • Page-diff tools

    Watches: Raw text changes on URLs you typed in.

    Misses: Raw text diffs with no legal context — blind to PDFs, and no idea what a change means for you.

The blind spot isn't a missing feature in one of these. It's a missing data plane. That's what Driftline is.

The capabilities

  • Reads the legal layer — including PDFs

    The documents with the most legal weight are the ones most likely to change invisibly.

    Driftline continuously monitors terms of service, privacy policies, DPAs, subprocessor disclosures and security pages — including PDF documents, where many DPAs and subprocessor lists exclusively live and most tools quietly give up.

  • Knows who a vendor is

    You have a contract with a company. Most monitoring watches a URL.

    Driftline understands the company behind every document — parent companies, subsidiaries and regional entities alike. When a change lands on the parent's DPA or a regional entity's disclosure, it still surfaces against the vendor you actually signed with.

  • Each vendor's AI posture, kept current

    “Which vendors can train on our data?” is a board question nobody can answer continuously.

    Driftline surfaces each vendor's AI posture — training rights, objection windows, notification commitments — and keeps it current as the documents change. Not a survey answer; the vendor's own commitments, dated and kept current.

  • The subprocessor exposure graph

    You assessed 25 vendors individually. Nobody assessed that six of them route to the same AI provider.

    Driftline maps the subprocessors disclosed across your portfolio into a single view: which providers sit behind which of your vendors. nth-party AI concentration, rendered — a view no register produces.

  • Changes are events, not noise

    Annual reviews assume vendors change annually. They change on a Tuesday.

    Every detected change is reviewed and prioritized; the material ones fan out to your risk register, reopen previously-accepted risks, and trigger reassessment of the five vendors that changed — not the 300 that didn't.

  • Feeds the stack you already own

    Your suite runs the workflow. Something still has to watch the documents.

    Material changes land where your team works — Slack cards and HMAC-signed webhooks today — with the vendor, a summary of what changed, and a link to the change. Driftline is the intelligence layer; nothing gets replaced.

  • History you can't backfill

    “What changed since we signed?” is unanswerable unless someone was recording.

    Driftline keeps every version of every monitored document. The archive compounds daily and can't be recreated after the fact — once a document changes, the prior version is gone unless someone was already keeping it. For monitored vendors, the retroactive question has an answer.

Which of your vendors can train on your data?

Send us your vendor list and we'll map — free, within 48 hours — which vendors add AI subprocessors or reserve the right to train on your data, and where your nth-party exposure concentrates.

Request your free AI exposure report