Vendor drift
Classified material changes to Abnormal Security’s public trust documents, from continuous monitoring.
Data as of 2026-09-10 — refreshed on a rolling bake, not live. · abnormalsecurity.com
Documents are silent on training · verified
as of 2026-08-11
high · AI subprocessor added · 2026-08-27 · subprocessor_list
Abnormal Security added 2 subprocessor(s): Microsoft Corporation, Twilio Inc.; removed 8: Microsoft Corporation (Azure OpenAI Service), Twilio Inc. (SendGrid), Abnormal AI Australia Pty Ltd, Abnormal AI Canada LTD., Abnormal AI PTE. LTD, Abnormal AI Netherlands B.V., Abnormal AI UK Ltd, Abnormal Security India Private Limited.
medium · Data retention changed · 2026-08-21 · dpa
Abnormal Security expanded the scope of customer data subject to retention and transfer to their servers. The DPA now explicitly includes data that "Customer configures or elects the Service to process, analyze, or retain in connection with a capability of the Service," broadening the categories of data retained beyond just identified security risks and malicious activity.
high · AI subprocessor added · 2026-08-11 · subprocessor_list
Abnormal Security added 3 subprocessor(s): Microsoft Corporation (Azure OpenAI Service), IPQualityScore, Inc., Abnormal AI Netherlands B.V.; removed 2: Microsoft Corporation (Azure), Microsoft Corporation (Azure OpenAI).
high · AI feature launched · 2025-05-12 · ai_disclosure
Abnormal Security published a new Abnormal AI Acceptable Use Policy (effective May 12, 2025) that discloses AI-powered features including "Output" and "Anomaly Determinations" that process customer data. The policy explicitly prohibits customers from using these outputs to train or improve their own AI/ML models, indicating Abnormal is now offering AI-driven capabilities that generate and return processed customer content.
high · AI feature launched · 2025-05-12 · ai_disclosure
Abnormal Security has newly disclosed an Artificial Intelligence Governance section (Section 18) in its Information Security Policy, effective May 12, 2025, establishing policies for AI development, deployment, and use within the Service. The disclosure includes commitments to responsible AI design, bias minimization, hallucination reduction, and human involvement for corrective action, with plain-language AI governance information to be made available at security.abnormalsecurity.com for customer assessment.
high · Training rights changed · 2026-05-27 · ai_disclosure
Abnormal Security's new Cloud Terms of Service (effective May 27, 2026) introduces explicit AI model training rights in Section 3.5, permitting use of customer data for customer-specific models and incorporation of anomaly determination learnings into shared models across the customer base, with de-identification and aggregation safeguards but no explicit opt-out mechanism for the shared model training.
medium · AI feature launched · 2025-05-12 · ai_disclosure
Abnormal Security disclosed in its Support and Service Level Agreement Policy (effective May 12, 2025) that it may use automated systems, including generative artificial intelligence, to assist in providing customer support. The policy explicitly states such AI systems will not be used to train third-party models, but the introduction of AI-powered support processing represents a new customer content processing path that warrants review.
Paste your vendor list, confirm your email, and our engine builds your report automatically — which vendors add AI subprocessors or reserve the right to train on your data, and where your nth-party exposure concentrates. Free, usually within the hour.