1. What we read
We retrieve a vendor’s publicly published legal documents — terms of service, privacy policy, cookie policy, EULA, acceptable use policy, security page, and where they publish them, the agreements a business signs. We then assess the full text against 15 governance categories.
We rate what a vendor actually publishes. We do not infer terms we cannot read, and we do not soften a finding because a vendor is well regarded. Where a policy is silent on a topic, that silence is reported as a finding rather than given the benefit of the doubt.
2. The overall rating is not an average
Averaging 15 categories would let good behaviour offset dangerous behaviour — a vendor could share your personal data with third parties and compensate with a tidy retention schedule. Safety labels do not work that way. An air quality index reports the worst pollutant rather than the mean of them, and a film rating reflects its most severe content, not its average scene.
So severity dominates. Four categories act as disqualifiers, because each describes an irreversible loss of control over data you submit:
- Input Data Ownership
- Training Data Usage
- Third-Party Data Sharing
- PII & SPI Data Inventory
A high-risk finding in any one of those sets the overall rating to RED, however favourable everything else looks.
A further set carries real weight but is usually mitigable by contract or configuration — a high-risk finding here prevents a green rating without forcing a red one: Output Data Ownership, Data Retention & Deletion, Opt-Out Rights, Security Practices & Breach History, Human Review of User Inputs.
3. What each colour means
- GREEN — Low risk. No disqualifying findings. Every gating category is favourable and clearly addressed in writing. A policy that is merely silent cannot earn green. This is deliberately rare: in today’s market a genuinely clean set of terms is unusual, and a label that most tools pass would tell you nothing.
- YELLOW — Moderate risk. Nothing disqualifying, but at least one question is unresolved. Every yellow card names which one.
- RED — High risk. A disqualifying finding in a critical data-control category, or the vendor’s own documents contradict each other on something material — in which case none of the terms can be relied upon.
- UNKNOWN. No readable policy documents were found, so no assessment was made. This is not a judgement about the vendor.
4. Consumer versus enterprise terms
Most vendors publish only the standard terms an individual agrees to on signup. That is what we rate by default, and it is what most people are actually bound by.
Enterprise agreements are frequently negotiated privately, and a Data Processing Agreement often changes the picture materially — commonly by carving out model training. Where a vendor publishes those documents we rate them separately and show both views. Where a vendor does not, we say so and tell you what to request. We never estimate an enterprise posture from consumer terms.
5. Reproducibility
Three things keep results stable. The overall rating is derived from the category findings by rule, so it cannot drift independently of them. Sampling is pinned to zero wherever the underlying model supports it. And a re-analysis is skipped entirely when a vendor’s documents are byte-for-byte unchanged — which is the strongest guarantee of the three, because it means a reported change reflects a vendor editing their terms rather than our system reaching a different conclusion about the same text.
We will not claim more than that. Language models are not perfectly deterministic, and the categorical findings underneath a rating can still vary at the margins.
6. Limitations we will state plainly
- Analysis is generated by a large language model reading published documents. It is not legal advice and should not be the only input to a procurement decision.
- We can only read what is public. Terms behind a login, an unsigned NDA, or a sales conversation are invisible to us.
- Ratings describe the documents as at the date shown on the card. Vendors change terms without notice.
- A vendor’s practice may be better or worse than its written terms. We rate the terms.