ValaisOS register · version 1.2

AI vendor breach-notification register

This register records, for AI vendors selling into US wealth management, whether the vendor's public documents commit to a breach-notification deadline, what the deadline is, which document contains it, and any qualifier that changes its meaning. It records what the documents say as of the reviewed date. It does not assess any vendor's security or practices.

Method

For each vendor, ValaisOS read the privacy policy, the terms of service, a data processing agreement where one is published, a subscription agreement where one is published, and any security or trust page, on the reviewed date. Each entry names and links the document and section where a deadline appears, with the last-updated date the document shows. Pages that render only in a browser were read in a browser. Gated trust centers were not read; their contents are recorded as not publicly verifiable. Of twenty-seven companies reviewed, nineteen published enough to assess.

Key facts, as of September 17, 2026

  • Ten of the nineteen vendors reviewed publish a specific breach-notification deadline in a public document. Nine say 72 hours; one says 48. All nineteen rows were re-read on September 9, 2026 and none had changed since the August 12 review.
  • Eight of those ten put the deadline somewhere other than the privacy policy: five in a data processing agreement, two in the terms of service, one in a subscription agreement on a different company's website.
  • Two of the nineteen name Regulation S-P in the same document. We found no reference to the FTC Safeguards Rule in any of the nineteen.
  • Nine of the ten published deadlines run to the customer firm or its administrator; Strata AI's runs to its account holders. We found no commitment to notify the firm's clients or a regulator directly.
  • Three of the ten deadlines carry a qualifier that changes what they mean: one counts business hours, one can be replaced by the firm's own master services agreement, and one starts on a suspected breach rather than a confirmed one.

Why the deadline matters to an SEC-registered adviser

Regulation S-P requires an SEC-registered adviser's incident response program to include policies "reasonably designed to require oversight, including through due diligence and monitoring, of service providers," and reasonably designed to ensure a service provider notifies the adviser "as soon as possible, but no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by the service provider" (17 CFR 248.30(a)(5)(i)). The adviser's own duty to notify affected individuals runs "as soon as practicable, but not later than 30 days" (248.30(a)(4)(iii)) and cannot be delegated (248.30(a)(5)(iii)). Regulation S-P does not require a written clause; it requires diligence and monitoring. A vendor's published deadline is one piece of evidence that diligence can rest on. The rule applies only where the vendor is a service provider, that is, where it receives, maintains, processes, or is permitted access to customer information (248.30(d)(10)). Regulatory descriptions are U.S. federal and current as of September 2026.

The register

VendorPublished deadlineWhere we found itRuns to
WealthAi48 hours (as read 2026-08-12; the PDF was not reachable on 2026-09-09)Data processing agreement §9.1, a PDF linked from the customer privacy notice (notice last updated August 2026); the download link returned a 404 on 2026-09-09Customer firm
Egnyte72 hoursData protection addendum §E.5.1 and §F.1.3 (updated July 2026)Customer's administrator
FastTrackr AI72 hoursPrivacy policy, "Data breach notification," and terms of service, "Data Breach Notification" (both last updated November 18, 2025)Customer firm
Hadrius72 hours, scoped to Regulation S-P dataTerms and conditions §5.5 (effective January 1, 2026)Customer firm
Hazel72 business hoursAltruist Software Subscription Agreement §11.3 (v20230403), incorporated by the Hazel Terms of Use (v20260629)Subscriber
Jump72 hours from a suspected breachData processing agreement §7.1 (no date shown)Customer firm
Orion72 hours, mutual between both partiesData protection addendum §V (last updated May 22, 2026)Customer firm
SideDrawer72 hoursData processing agreement §8.1 (last updated November 7, 2022), also Appendix A of the privacy policy (last updated August 28, 2026)Customer firm
Strata AI72 hoursPrivacy policy §19 (last updated July 17, 2026) and security pageAffected users
Zocks72 hours, unless the firm's MSA specifies otherwiseTerms of service §6.4 (last updated October 8, 2025)Customer firm
Hamachi.aiNotice promised, no period statedPrivacy policy §4 (effective February 17, 2026)Affected users
SS&C Black DiamondWe found notice provisions only in the Australian and South African annexesSS&C privacy statement (last updated July 24, 2026); the Black Diamond copy still shows March 27, 2023Not stated for US customers
VerapathNotice by posting to their website, no period statedPrivacy policy, "Data breach" (last updated April 27, 2026)Website visitors
eMoney AdvisorWe did not find a provisionPrivacy policy (last updated July 1, 2025) and terms of use (last revised December 16, 2024)Not applicable
Lira AIWe did not find a provisionPrivacy policy and terms of use (both dated only "2025")Not applicable
MasttroWe did not find a provisionPrivacy policy (last updated January 26, 2024); we could not find a terms document on masttro.comNot applicable
VastAdvisorWe did not find a provisionPrivacy policy (last updated March 25, 2026) and terms and conditions (last updated April 13, 2026)Not applicable
VerloWe did not find a provisionPrivacy statement (effective August 11, 2026) and terms of service (last updated January 6, 2025)Not applicable
WealthFluentWe did not find a provisionPrivacy and security policy (last updated April 13, 2026) and terms of use (last updated July 15, 2025)Not applicable

In prose, for anyone reading without the table: of nineteen vendors, ten publish a deadline (WealthAi at 48 hours; Egnyte, FastTrackr AI, Hadrius, Hazel, Jump, Orion, SideDrawer, Strata AI, and Zocks at 72 hours), three promise notice without a period we could apply to a US advisory firm (Hamachi.ai, SS&C Black Diamond, Verapath), and for six we could not find a provision in the documents read (eMoney Advisor, Lira AI, Masttro, VastAdvisor, Verlo, WealthFluent). The qualified entries are Hazel (business hours), Zocks (overridable by the firm's MSA), and Jump (clock starts on a suspected breach).

Entity and document notes

The reviewed date at the top of this page is the date of the most recent change to any row. Every row was re-read on September 9, 2026; the WealthAi row is the exception, because the document it cites could not be re-read on that date. Document dates in the table are the dates the documents themselves show.

Several vendors publish under more than one name or domain, which matters when a reader goes to check an entry. WealthAi's web privacy notice names WealthAi Holdings Limited while its data processing agreement and policy PDFs name WealthAi Technology Limited; the 48-hour clause is in the PDF, not on a web page. Strata AI's legal documents are at strataai.org and its marketing site at strataadvisor.ai; strata.ai is an unrelated legal-technology company. Verlo's domain is verlo.finance. Verapath's legal documents are hosted off-site on a policy-hosting service. Hazel's operative agreement is the Altruist Software Subscription Agreement, because Hazel is an Altruist product.

Related reading

The narrative review that produced this register is If Your AI Vendor Is Breached, You Have Thirty Days to Tell Your Clients. The diligence questions that follow from it are in Nine Questions to Send Any AI Vendor Before You Sign. The principle the register serves is fiduciary data custody.

Change log

  • 2026-08-12. Register created from the August 12, 2026 review of nineteen vendors' public documents. All rows as of that date.
  • 2026-09-17. Key fact on notice recipients clarified: Strata AI's clause runs to its account holders rather than to the customer firm as an entity, so the fact now reads nine to the customer firm or its administrator, one to account holders, none to the firm's clients or a regulator. No row changed. The register now publishes its rows as JSON and CSV. Version 1.2.
  • 2026-09-09 (second entry). All nineteen rows re-read from the vendors' current documents, with the document URL and its last-updated date now recorded in the table. No published deadline, location, recipient, or qualifier changed. Document dates moved for several vendors (Egnyte data protection addendum July 2026; SideDrawer privacy policy August 28, 2026, now carrying the data processing agreement as Appendix A; Orion data protection addendum May 22, 2026; Verapath privacy policy April 27, 2026; WealthFluent privacy policy April 13, 2026; VastAdvisor privacy policy March 25, 2026 and terms April 13, 2026). One document location corrected, eMoney Advisor's terms of use are at wealth.emaplan.com, not emoneyadvisor.com. WealthAi's document download returned a 404 on this pass, so its row stays as read on August 12 with the note. A terms document for Masttro could not be found on masttro.com; the row now says so. Version 1.1.
  • 2026-09-09. Strata AI row re-verified against the privacy policy at strataai.org (last updated July 17, 2026): section 19 still commits to notifying affected users within 72 hours of becoming aware of a breach. WealthAi row annotated: the data processing agreement PDF read on August 12 was reachable from the site's privacy page; on September 9 the site's document download link returned an HTML page instead of the PDF, so the clause could not be re-read. The entry is retained as recorded on August 12 with that note. Other rows not re-verified on this date.

Right of reply

If you represent a vendor listed here and believe an entry is wrong or incomplete, email hello@valaisos.com with the document and section that contains the commitment. We will read it, update the register, and record the change in the log with the date. We correct entries; we do not remove them. We do not accept terms held under non-disclosure for inclusion, because the register records only what a prospective customer can read before signing.

The editorial rule

Every absence in this register is phrased as "we could not find," because a public-document review can establish what is published and cannot establish what a vendor has. Several vendors hold terms under non-disclosure or in negotiated agreements that public documents do not reflect.

Download the data

The table above is available as JSON and CSV, regenerated with every change to the register. Each JSON row carries the document links from the table.

Questions

Does Regulation S-P require my vendor contract to contain a 72-hour clause?

No. It requires written policies reasonably designed to ensure service providers notify the firm within 72 hours, including through due diligence and monitoring (17 CFR 248.30(a)(5)(i)). A published clause is evidence of diligence, not a requirement in itself.

Is every AI vendor a Regulation S-P service provider?

No. A service provider is an entity that receives, maintains, processes, or is permitted access to customer information through services to the firm (17 CFR 248.30(d)(10)). A vendor that never receives customer information is not one.

Why does the register list where the clause appears?

Because eight of the ten deadlines found in August 2026 were outside the privacy policy, and a reader who checks only the privacy policy would conclude those vendors promised nothing.

How do I correct an entry?

Email hello@valaisos.com with the document and section that contains the commitment. Corrections are recorded in the change log with the date. Entries are corrected, not removed.

Primary sources

ValaisOS is building a more enduring operating foundation for private-wealth professionals.

Request early access