The material-change blind spot
Every framework you're audited against — GDPR Art. 28, DORA, SOC 2, ISO 27001 — assumes you'll know when a vendor materially changes. Driftline is the layer that actually knows: continuous monitoring of the legal documents themselves, with the change, the meaning, and the impact on your portfolio.
Why nothing else does this
Four categories of tooling claim vendor monitoring. Each watches something — none watch the legal layer.
Watches: Questionnaire workflow — self-reported, point-in-time.
Misses: The vendor's actual documents changing between annual reviews.
Watches: Outside-in technical posture: ports, certs, breach chatter.
Misses: A training-rights clause isn't a port scan; legal drift is invisible to them.
Watches: Your controls, plus a vendor inventory.
Misses: Vendor “review” is an annual checkbox, not surveillance of the vendor.
Watches: Raw text changes on URLs you typed in.
Misses: Raw text diffs with no legal context — blind to PDFs, and no idea what a change means for you.
The blind spot isn't a missing feature in one of these. It's a missing data plane. That's what Driftline is.
The documents with the most legal weight are the ones most likely to change invisibly.
Driftline continuously monitors terms of service, privacy policies, DPAs, subprocessor disclosures and security pages — including PDF documents, where many DPAs and subprocessor lists exclusively live and most tools quietly give up.
You have a contract with a company. Most monitoring watches a URL.
Driftline understands the company behind every document — parent companies, subsidiaries and regional entities alike. When a change lands on the parent's DPA or a regional entity's disclosure, it still surfaces against the vendor you actually signed with.
“Which vendors can train on our data?” is a board question nobody can answer continuously.
Driftline surfaces each vendor's AI posture — training rights, objection windows, notification commitments — and keeps it current as the documents change. Not a survey answer; the vendor's own commitments, dated and kept current.
You assessed 25 vendors individually. Nobody assessed that six of them route to the same AI provider.
Driftline maps the subprocessors disclosed across your portfolio into a single view: which providers sit behind which of your vendors. nth-party AI concentration, rendered — a view no register produces.
Annual reviews assume vendors change annually. They change on a Tuesday.
Every detected change is reviewed and prioritized; the material ones fan out to your risk register, reopen previously-accepted risks, and trigger reassessment of the five vendors that changed — not the 300 that didn't.
Your suite runs the workflow. Something still has to watch the documents.
Material changes land where your team works — Slack cards and HMAC-signed webhooks today — with the vendor, a summary of what changed, and a link to the change. Driftline is the intelligence layer; nothing gets replaced.
“What changed since we signed?” is unanswerable unless someone was recording.
Driftline keeps every version of every monitored document. The archive compounds daily and can't be recreated after the fact — once a document changes, the prior version is gone unless someone was already keeping it. For monitored vendors, the retroactive question has an answer.
Send us your vendor list and we'll map — free, within 48 hours — which vendors add AI subprocessors or reserve the right to train on your data, and where your nth-party exposure concentrates.