This tool is not currently part of our weekly active audit cycle
You are viewing historical data. We actively monitor only the top 20 enterprise AI tools. If you need a fresh, up-to-date risk intelligence report for Exa, let us know and we'll prioritize it.
Verified Compliance Facts
Cited and timestamped — every claim traceable to an official vendor source.
Enterprise Verdict
Detailed community analysis available in report body
AI Training Data Policy Not Explicitly Disclosed in ToS
Risk Assessment
Seven-category enterprise risk analysis derived from community and vendor signals. Each card shows the evidence tier and the underlying finding.
Medium risk — DPA available but specific data handling clauses need review. Derived from aggregated community data.
Medium risk — certifications partially verified, residual gaps remain. Based on verified vendor documentation.
Medium risk — some export options exist but depend on vendor cooperation. Derived from aggregated community data.
Medium risk — some AI governance signals found but not fully verified. Derived from aggregated community data.
Medium risk — limited reliability data; monitor SLA adherence. Derived from aggregated community data.
Medium risk — base pricing clear but add-on/usage costs not fully transparent. Based on verified vendor documentation.
Due Diligence Alerts
Priority reviews, recommended inquiries, and verified strengths — based on 75+ community data points
Security & Compliance
Data Security
Security Features
IT Hardening Guide
Deployment Checklist
Legal & IP Risk
IP Ownership
unknown
unknown
Liability & Indemnification
unknown
Exit Terms
unknown
unknown
ToS Red Flags
Exposes sensitive enterprise data to potential use in vendor's AI models, creating IP leakage and compliance risks.
Creates ambiguity over who owns the intellectual property of AI-generated content, leading to potential legal disputes.
Leaves the enterprise vulnerable to third-party intellectual property infringement claims without vendor protection.
Increases vendor lock-in and complicates data migration to alternative solutions upon contract termination.
Hinders compliance with data protection regulations (e.g., GDPR, CCPA) requiring specific data retention and deletion policies.
Data & Migration Lock-in Risk
- Proprietary API integration for specialized search types and content extraction.
- Undisclosed data export formats, making data migration complex and potentially costly.
- Reliance on vendor-specific search types and content processing logic within AI agent workflows.
Enterprise Contract Intelligence
DPA availability, data residency, and contract risk signals for procurement teams
DPA not publicly available; procurement teams must request a signed Data Processing Addendum directly from the vendor before contract execution to ensure compliance with data protection regulations.
Data residency options are not publicly documented. This lack of transparency poses a significant procurement blocker for EU and other regulated customers requiring specific data sovereignty controls and cross-border transfer mechanisms. Without explicit documentation, data is assumed to be processed in the US, which may not meet all regional compliance requirements.
⚠ 5 contract risk flags — click to review
The contract terms present a high lock-in risk (score 75) due to undisclosed policies on data portability, deletion, and IP ownership. The absence of clear auto-renewal or unilateral change clauses also creates uncertainty. Termination notice days are not specified. A thorough legal review and specific contractual amendments are required to mitigate these risks before contract execution.
Security Certifications
| Certification | Status | Auditor | Valid Until | Source |
|---|---|---|---|---|
| ⏳ Scanning in progress — check back after next weekly audit. | ||||
Data Privacy Documents
| Document | Status | URL | AI Assessment |
|---|---|---|---|
| Sub-processors | ❌ Not Found | — | ❌ Not found |
| AI/Model Training Policy | ❌ Not Found | — | — Unclear |
| Data Retention Policy | ❌ Not Found | — | ❌ Not found |
| Data Flow Diagram | ❌ Not Found | — | — |
| GDPR Compliance Statement | ❌ Not Found | — | ❌ Not found |
| KVKK Compliance Statement | ❌ Not Found | — | ❌ Not found |
| CCPA Compliance Statement | ❌ Not Found | — | ❌ Not found |
Legal Contracts
See Legal & IP Assessment section above for full analysis of ToS, DPA, MSA, SLA, EULA, and AUP.
Operational Readiness
| Document | Status | URL | AI Assessment |
|---|---|---|---|
| Business Continuity Plan (BCP) | ❌ Not Found | — | ❌ Not found |
| Disaster Recovery Plan (DRP) | ❌ Not Found | — | ❌ Not found |
| Incident Response Plan | ❌ Not Found | — | ❌ Not found |
| 3rd Party Penetration Test | ❌ Not Found | — | ❌ Not found |
Technical Transparency
| Document | Status | URL | AI Assessment |
|---|---|---|---|
| SBOM | ❌ Not Found | — | ❌ Not found |
| OSS License Inventory | ❌ Not Found | — | ❌ Not found |
| Vulnerability Management Policy | ❌ Not Found | — | ❌ Not found |
| Patch Management Policy | ❌ Not Found | — | ❌ Not found |
| Offboarding / Data Export Guide | ❌ Not Found | — | ❌ Not found |
| SIG Questionnaire | ❌ Not Found | — | — |
| CAIQ | ❌ Not Found | — | — |
Financial Resilience
| Item | Status | Details |
|---|---|---|
| Cyber Liability Insurance | ❌ Not Found | ❌ Not mentioned |
| TCO Disclosed | ✅ Available | Annual: $18,316/year for 100 users |
Community Intelligence
Recurring issues and curated signals from GitHub, Hacker News, Reddit, Stack Overflow, web sources, and enterprise review platforms.
Recurring Issues
Enterprise Impact: Reported by community on GitHub with 3 comments.
Enterprise Impact: Reported by community on GitHub with 3 comments.
Enterprise Impact: Reported by community on GitHub with 2 comments.
Enterprise Impact: Reported by community on GitHub with 2 comments.
Enterprise Impact: Discussed on Hacker News.
Enterprise Impact: Discussed on Hacker News.
Source Signals
Financial Impact Panel
Cost intelligence and pricing signals for enterprise procurement decisions
Pricing Tiers
Free
- 1,000 requests per month
Search
- Real-time search data (up to 10 results)
- Webpage text and highlights
- Configurable latency: 180ms to 1s
Deep Search
- Research with structured outputs
- Optimized for complex queries
- Multi-step agent workflows
Contents
- Full page web contents
- Token efficient highlights
- Configurable livecrawl policies
Monitors
- Track new events and updates across the web
- Runs searches at a specified cadence
- Receive updates with webhooks
Answer
- Fast web grounded answers
- Streaming responses
- Web grounded citations
Enterprise
- High volume
- Custom datasets
- Enterprise security
- SLAs and MSAs
- Volume discounts
Pricing Observations
The pricing model is consumption-based, with costs per 1,000 requests or pages. This can lead to unpredictable costs for high-volume or complex AI agent workflows if not carefully managed. The free tier is limited to 1,000 requests per month, which is quickly exhausted in enterprise scenarios. Additional results and AI page summaries incur extra charges. Enterprise pricing requires direct contact, indicating potential for opaque negotiations and custom terms.
Pricing data from public sources — enterprise rates differ. Verify with vendor.
TCO Calculator
Calculate the real monthly cost for your team. Adjust seats, usage, and pricing tier below.
Estimated Monthly Cost
Swanum Independent Estimate (100 users)
Base $693/mo × 12 = $8316 + Implementation $5000 + Training $2000 + Integration $3000 = $18316 total. This estimate assumes 100 users each making 1000 'Search' requests per month, exceeding the free tier. cost factors that may not be immediately visible in initial pricing include potential overage for deep search or content extraction, and costs for custom datasets or higher rate limits at the Enterprise tier. The estimate does not account for potential re-platforming costs if vendor viability becomes an issue.
Synthesized from 20+ independent public sources: developer forums & repositories, security databases, vendor disclosures, regulatory filings, and community review platforms. Not affiliated with any vendor. Corrections?
Download PDF Report
Create a free account to download the full enterprise audit PDF.
Sign up — it's free →Already have an account? Log in