Vannus / Catalog / Darktrace

Darktrace

Vannus has not established which model this vendor runs, and does not infer one. Every finding below is quoted to the vendor’s own document, or marked not disclosed where the vendor publishes nothing.

Determination
Contracts with Darktrace Holdings Limited (United Kingdom), under terms this record cannot reach — under US corporate control, and therefore within reach of US legal process through that control.
Controlled by Thoma Bravo (United States), per a release issued by Darktrace [2026-09-12]. The LEI record reports no consolidating parent filed (NON_CONSOLIDATING, [2026-09-12]).
darktrace.com · read 2026-07-29
read from a document of no standard class · neither its heading nor its address says what it is
governing law read from darktrace.com · read 2026-09-16
the entity name read from darktrace.com · read 2026-09-15

Autonomous AI cyber defence platform — self-learning neural networks detect and neutralise novel threats in real-time across network, cloud, email, and OT environments

cybersecurity, AI, compliance
What the vendor's own documentation says
including our unique Self-Learning AI and proprietary large language models
darktrace.com ↗ Vendor-sourcedQuote re-checked 14 Sep 2026
Who controls it
US corporate controlYes — a US parent or US contracting entity is on the public record · clause re-checked 17 Sep 2026
Contracting entityDarktrace Holdings Limited (UK, Maurice Wilkes Building, Cowley Road, Cambridge CB4 0DS), owned by Thoma Bravo; Darktrace, Inc. named as a service-delivery affiliate
Governing lawNot readable here. Darktrace's Master Services Agreement v2.4 (3 August 2026) carries a governing-law table, and it is published as a PDF on a CDN whose robots.txt returns 403 to both clients, so this record has never read it.
Trains on your dataYes, unless you opt out — on the vendor's default plan

Training and retention posture varies by plan. What we publish above describes the vendor’s default plan; enterprise, team and API agreements frequently differ, often materially, and a contract can override the published default entirely. Check your own plan and contract before relying on this row.

This is a separate question from the grade above. The grade measures resilience — whether the tool endures and whether you could leave it. This describes who controls the vendor. A tool can score modestly on one and strongly on the other, and many do.

On U.S. CLOUD Act reach specifically: the statute reaches a provider subject to U.S. jurisdiction over data in its possession, custody or control. Corporate control is a strong indicator of that and it is what we can evidence from published documents — but it is not the whole test. A company founded outside the U.S. can still contract through a U.S. entity or run substantial U.S. operations. Treat this as a starting point for your own review, not a legal determination, and take advice on anything that matters.

Signals on file
Origin
United Kingdom

The vendor's published or catalog-recorded posture — the concrete facts this grade is built from. A full audit verifies each against the vendor's current documentation.

Compliance the vendor states
SOC2ISO 27001GDPR

Taken from the vendor’s own published material. Vannus does not hold these reports and has not reviewed their scope or dates — ask the vendor for the current report before relying on any of them.

How this grade is set

Vannus publishes a nine-dimension trust framework — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →

Related tools we grade
Visit Darktrace ↗ Grade your whole stack →