AI Subprocessor Jurisdiction Report

Know which of your AI vendors can be compelled — and by whom.

A dated, source-cited report on your AI stack: which vendors sit within reach of the U.S. CLOUD Act, which resell a single upstream model, and which train on your data by default. Written to be handed to security, legal, or your board.

$299one-time · on screen as soon as payment clears

Where this fits in a AI Subprocessor Jurisdiction Report

The EDPB’s Recommendations 01/2020 set out six steps. This report produces the evidence for two of them — the two that stall most assessments, because the answer is not in your own systems.

1. Know your transfersCovered, for your AI vendors
2. Identify the transfer toolNot covered — that is your SCCs or BCRs
3. Assess the third country’s lawThis is the report. Who controls each vendor, which jurisdiction can compel disclosure, cited to the vendor’s own documents
4. Adopt supplementary measuresNot covered — encryption, contractual and organisational measures are yours to choose
5. Procedural stepsNot covered
6. Re-evaluate at intervalsNot covered — the record carries the date each document was read, so you re-run it when your own review cycle calls for it

So this is the evidence pack, not the finished assessment. It answers the question your own records cannot — who actually controls the vendor and under whose law — and leaves the transfer tool and the supplementary measures where they belong, with you and your counsel. If you want the whole thing mapped to your own contracts and residency commitments, that is the Concierge audit.

What you get

How this differs from the free check

Which one do you need

What happens to what you paste

Get your report

Paste as many as you like — no cap, and the price does not change. We match them against the 376-tool catalog and tell you exactly what we can and cannot assess before you pay.
Appears as the title of your report. Optional — if you leave it blank we derive one from your email domain (jane@acme‑financial.com becomes “Acme Financial”). Type something here if you would rather it did not.
This is what the report is for. Twenty-nine of the vendors we hold contract through more than one legal entity, split by where the customer is incorporated — and the split is not what most people expect. A UK company contracting with OpenAI signs with a US entity under Irish law. Tell us where you are and we resolve each of those vendors to the entity that actually binds you, quoting the clause so you can check it. Leave it blank and we state the conditions instead of resolving them.
Optional. Some vendors publish different terms for free, paid and enterprise customers, and the training-data answer in particular often changes between them.
Say so and we will not pretend otherwise. A negotiated order form outranks the vendor’s published terms — OpenAI’s own conflict clause ranks it above the Agreement, and Google’s entity table carries “unless previously agreed”. Where you have one, the report tells you the published position and that your own paperwork governs, rather than giving you a confident answer from a document that does not bind you.
We delete the report, your tool list, your email and your organization name 72 hours after we deliver, and your share link stops resolving. We are a U.S. company, so the CLOUD Act reaches us too — this is the only complete answer to that, because we cannot be compelled to produce a list we no longer hold. Leave it unticked and the report stays available for 24 months. You can ask us to erase at any time either way.
Used to deliver your report. No marketing list.
Payment handled by Stripe. Vannus never sees your card details.
No account required.
No vendor can pay for a finding · Every claim cited or marked undisclosed · Try the free check first →