Vendor checks

AI vendor security comparison
for teams

Eight team workspaces checked against the same vendor checklist: sub-processors, certifications, deletion rights, hosting regions and what an admin can verify

Sep 1, 2026 · 13 min read

The short version
Ask for evidence not a policy page

A team should not approve an AI vendor from a no-training statement alone. Ask for the current data-processing agreement, a dated sub-processor list, a security report and a deletion test before sensitive work moves in, and check every answer against the exact plan you would buy. The eight workspaces compared on the same criteria below are Playgram, WorkLLM, nexos.ai, Langdock, TeamAI, Aymo, Magai and TypingMind.

Every major vendor now publishes some version of a no-training promise, so that claim alone rarely separates one product from another. What actually differs is how much of the rest a buyer can verify: who receives the data downstream, where it is processed, how long each copy is kept, and what an administrator can inspect, restrict and delete.

This guide sets out the evidence to collect before a vendor gets real company data, prices the single-vendor stack most teams start from, and compares eight team workspaces on disclosure rather than on promises.

Who this guide is for
Which teams this fits

Security01

IT security and legal teams

You approve new AI tools and need evidence rather than a policy statement.

Procurement02

Procurement and vendor risk

You run the due-diligence process and have to reconcile a contract with a marketing page.

Sensitive work03

Teams handling sensitive work

Client files, contracts, source code or employee data pass through prompts every week.

Not yet04

Only public information today

One or two people work only with public information on a single approved product.

The real problem
Why one policy cannot cover four tools

Each subscription creates its own processing boundary, and nobody is looking at all of them at once.

01

Cost

Each AI subscription creates a separate processing boundary, and a privacy page may describe the front-end vendor while saying little about the model provider, hosting region or connected tool that also handles the prompt. As an example, four single-vendor team plans came to about $101 per person a month at July 2026 list prices, so five fully provisioned people cost roughly $5051234. That total buys availability rather than review, and security or legal staff must still read a contract, a DPA and a sub-processor register for every product added.

02

Workflow

People move a document between browser tabs, copy prompts, download an output and re-upload it elsewhere, so one sensitive file can be stored by several workspace vendors and their underlying model providers in an afternoon. A person may remember that one account carries business terms and forget that another chat sits inside a personal one, and web search, plugins and MCP connections add further destinations that never show up in the model-selection menu.

03

Context

Separate accounts lose project instructions and prior decisions, so people repeat them in new prompts, creating more copies of potentially sensitive material. Memory adds a further concern, since a deleted chat may already have contributed to a stored summary, extracted fact or embedding, and deleting the visible transcript does not prove those derived records were removed too.

04

Management

An administrator needs to know who submitted the data, which model and provider received it, which tools or connectors ran, where the request was processed, what was retained by the workspace and by the model provider, and whether that history, files and memory can be deleted and confirmed. Consumer accounts cannot answer these questions centrally, so a workspace only helps once its administrator can inspect and control those paths rather than just manage billing.

What to verify
Before real data moves in

Five checks that turn a policy statement into something an administrator can show an auditor.

Coverage

Approved models under one policy

Model access should sit behind one policy naming approved providers, and admins should disable a model whose region or retention fails review. The workspace itself must use business or API terms that stop providers training on prompts.

Tools

The tools that touch the data

Check each product for web research, document and spreadsheet work, image and video generation, code review and chats that leave no history, and MCP or API connections. Each one is another path company data can leave the workspace through.

Memory

Retention split by layer

Workspace history, backups, memory databases, logs and model-provider retention are different periods, and most vendors publish only one. Ask for all five and look for a setting an admin controls rather than a paragraph about general practice.

Control

Evidence an admin can produce

Logs should identify person, model, period and project, and deletion should appear as a recorded event rather than a promise. Add a dated sub-processor register with change notices and permissions that follow the user.

Pricing

Contracts and budgets and a quiet mode

A signed processing agreement naming the vendor as processor, a hard budget an admin can set before spend occurs, and a documented mode that leaves no history matter as much as the model list. Price the plan you would actually buy against these controls, not a features page.

The shortlist
What each product covers and costs

The multi-model workspaces a security-minded team is most likely to weigh up, judged on the same criteria and to one standard.

Product
Best for
Model access
Pricing
Shared team memory
Cross-model context
Notes
Playgram
Teams wanting a named no-training and SOC 2 position on the exact plan they buy
Claude, GPT, Gemini, DeepSeek, Grok and more21
Credits, with no per-seat fee: $60/mo for 10,000 credits billed monthly, so five people pay the same $6020
Yes, at team, project and personal scopes21
Yes, switch mid-thread and the conversation carries over21
A complete dated sub-processor register and a fixed backup-deletion deadline are not publicly published22
WorkLLM
Teams wanting zero retention stated at the model layer
More than 200 models6
Per seat: Basic $20/user/mo billed monthly with 2,000 pooled credits per user, so five users pay $1006
Yes, thread, folder, project, personal and organisation layers, with owner or admin approval before wider entries6
Manual test required
No public sub-processor list or independent certification was found7
nexos.ai
Teams wanting a dated sub-processor list with named regions
More than 200 models8
$39/mo for the 1-month AI Workspace plan with 1,000 credits. The page does not state how many users it covers, so a five-person total is not verified8
Shared Projects keep uploads, searches and instructions, though organisation-wide automatic memory is not documented24
Yes, switch models inside a project without rebuilding it24
No published price for a longer commitment, and no documented user allowance8
Langdock
European teams wanting a fixed post-termination deletion deadline
Claude, GPT, Gemini and others10
Per seat: Business EUR 29/user/mo billed monthly excluding VAT (EUR 22 seat plus EUR 7 for AI model access, both required), so five users pay EUR 14510
Automatic memory is personal only, capped at 50 entries and unavailable in project chats23
Manual test required
No automatic team-wide memory23
TeamAI
Teams comfortable reconciling the terms with the privacy page
Hosted models from several vendors in one selector12
Per workspace: Professional $149/mo for up to 25 users with 20,000 credits, so five users also pay $14912
No, memory is personal and off by default28, and shared context is configured by hand13
Yes, the same conversation and thread, so a model can be switched anytime12
No complete public sub-processor list was found13
Aymo
Small teams whose work stays inside a provider's own terms
Full model access, plus your own keys14
Per workspace: Premium $20/mo billed monthly for up to 10 members, so five users pay $2014
A reusable Team Library is still marked coming14
Yes, switch models without starting a new thread14
No independent certification or sub-processor list was found15
Magai
Creative teams wanting a stated backup purge window
More than 50 models16
Per seat: Standard $20/mo plus $20 for each added user, so five users pay $10016
Not publicly documented, and its context management covers files rather than memory16
Yes, switch mid-chat without losing context16
No complete infrastructure and service sub-processor register was found17
TypingMind
Teams that want the workspace store on their own servers
Many vendors through your own API keys18
Per workspace: Starter $99/mo billed monthly with five seats included, then $8 per extra seat18
Not native, an optional memory server has to be configured18
Manual test required
Product-level SOC 2 or ISO certification is not documented19

This table compares multi-model team workspaces with each other. The single-vendor plans a team usually starts from are priced further down, under 'Priced per seat', and are not rows here. Pricing is the lowest-priced paid plan that covers five users, at the monthly rate. Each cell cites the page that documents that cell rather than one pricing page per row. Figures checked September 2026, and cells marked 'Manual test required' could not be confirmed from public documentation.

Controls and data
Certifications and sub-processors

The same products again, on the criteria this topic turns on: what each one does besides chat, what it connects to, what an admin can see and cap, and what evidence backs its data claims.

Product
Built-in tools
Integrations
Usage visibility
Usage controls
Training on your data
Where the models run
Playgram
Image generation, web search, deep research, document and spreadsheet work, and code execution21
Not publicly documented21
Adoption, query volume and model preference by person21
A credit limit per person, a limit across the whole team, and model access set per user20
No training on your data. SOC 2 Type II22
US-based infrastructure, with a secure US gateway for open-weight and foreign-origin models22
WorkLLM
Web search, deep research, and document, image, audio and video input6
Google Workspace, Slack, Jira, HubSpot, Notion and Salesforce are named, though integrations are separately marked coming soon6
Advanced activity reports and audit logs are listed, though exact dimensions are not public6
Role-based access and model or data controls are documented, but a preventive per-person cap is not6
No, and zero retention is stated at the model layer, with no independent certification published7
Managed cloud, private VPC and on-premises are offered without naming countries7
nexos.ai
Web search, deep research, images, documents, slides and charts26
Slack, Google Drive, SharePoint and other work-tool connectors, plus MCP-connected systems27
Use and cost by user, team, project and model, with per-request logs25
Budgets and hard caps by user, team or project, plus model assignments and guardrails25
No. ISO 27001 certified with a SOC 2 report and a dated sub-processor list naming its cloud and model providers by region9
EU and US hosting options are advertised, though not every model necessarily runs there9
Langdock
Image generation, web search, deep research, document and presentation work11
MCP, Slack, Teams, Excel, Outlook and Drive are documented11
Admin exports can cover user, project, model and period, with up to 12 months of history11
Workspaces on their own provider keys can set workspace, group, user and agent spend limits11
No. ISO 27001 certified and SOC 2 Type II audited, with a DPA requiring deletion within 30 days of termination11
Application and most models run in the EU11
TeamAI
Research mode, document libraries, data analysis and Google Docs or Sheets connections12
An MCP server and connections to Slack and Google Workspace are documented12
Owners see aggregate model usage and trends across the workspace, though a per-person breakdown is not confirmed in public docs13
An owner can set a pre-bill spend cap that stops AI use once it is reached13
States no training, though a broad content licence in its terms still needs reconciling and no public certification was found13
Not publicly documented12
Aymo
Image models, web search, deep research, documents and a private chat that is not saved14
Your own provider keys are documented, and productivity connectors are planned14
Plan-level message and credit caps are visible14
Per-person analytics and member budgets are not publicly documented14
No, though no independent certification is published and it relies on certified infrastructure providers15
Not publicly documented15
Magai
Image and video generation, web search, file work and a document canvas16
More than 130 integrations are advertised, and MCP is not mentioned16
A usage page and top-ups are available16
An owner can set an optional member usage limit16
No, and it claims SOC 2 Type II alignment with a GDPR data-processing agreement17
Servers are in the United States17
TypingMind
Image generation and editing, web search, retrieval and multi-model chats18
Plugins and MCP are supported, and external-system API integration needs Professional18
Starter has none. Professional adds token analytics by member and model18
Per-user and per-model limits are documented on Professional, not on Starter18
Not publicly documented at the product level. Its DPA names sub-processors with processing countries19
US or EU cloud regions, or customer infrastructure when self-hosted19

'Not publicly documented' means the official sources checked did not state it, and 'Manual test required' means the behaviour cannot be confirmed without trying it. Neither means the feature is absent, so read them as questions to put to the vendor. Public documentation is also not a substitute for the signed processing agreement itself. Checked September 2026.

Priced per seat
What the single-vendor plans cost

The published per-seat price of each major single-vendor team plan, billed monthly. Each one also brings its own contract, DPA and sub-processor register to review.

Provider
Plan
Per seat
Models
ChatGPT Business
Business · billed monthly ($20 billed annually)
$25/seat/mo
GPT family (GPT-5 Instant, Thinking) + o-series reasoning models
Claude Team
Team (Standard seat) · billed monthly ($20 billed annually); 5-seat minimum
$25/seat/mo
Full Claude model family (Sonnet, Opus, Haiku)
Gemini Enterprise (Business)
Gemini Enterprise, Business edition · annual commitment (Standard is $30 with commitment)
$21/seat/mo
Gemini via the Gemini Enterprise app
Grok Business
Grok Business · billed monthly, no published annual discount
$30/seat/mo
Grok family (Grok 4, Grok Heavy)

Buying all four for one person came to about $101 a month at July 2026 list prices, so five fully provisioned people cost roughly $505. Read that as one example stack rather than a going rate. On this topic the review effort matters as much as the price, since four products mean four contracts, four sub-processor registers and four sets of terms for a legal team to read. Figures checked July 2026.

The cost drivers
What the review itself costs you

Cost is the secondary question on this topic, and two of these are paid in legal and security hours rather than in subscription fees.

Review per vendor

Every product added means another sub-processor register, another retention policy and another security review, work that repeats whenever a vendor updates its terms.

Plans per person

Each plan is priced per person, so a second one multiplies the total rather than adding to it. Buying four such plans came to about $101 per person a month at July 2026 list prices, so five fully provisioned people cost roughly $5051234.

Stored copies

Moving one task between products creates several stored copies of the same document, each under a different retention rule, which gets expensive the moment somebody has to prove where a file went.

Idle seats

Seats bought by a department or an individual are hard to spot, and Zylo's 2025 index puts the average unused-license waste at $21M a year per organisation5.

The options
Six ways to control where data goes

Six setups, led by the one this guide is about, ordered by how much of the processing chain a team has to review.

A multi-model team workspace

One vendor routes requests to several providers under one contract, one sub-processor register and one set of logs. That vendor becomes an additional processor, so it has to document what it sends onward, stores and logs.

Best for: Teams putting non-public work through more than one model.

Strengths

  • One contract and one register to review instead of four
  • Models whose region or retention fails policy can be disabled centrally
  • Usage and deletion evidence sit in one place for an audit

Trade-offs

  • Below about five people, one or two single-vendor consoles may already answer the question
  • The workspace adds a processor between the team and the model providers
  • A no-training statement on a marketing page can still sit beside a broad content licence in the contract

Separate consumer subscriptions

Each person keeps a personal account with no shared administration, so there is no common register or contract at all. It stays workable until company information starts moving through those accounts.

Best for: One or two people using only public information.

Strengths

  • Nothing to set up centrally
  • Fine while only public information is involved

Trade-offs

  • No common register or contract exists anywhere to review
  • Company data sits inside accounts nobody administers

One provider for the whole team

Standardising on one vendor's business plan means one contract, one sub-processor register and one security review to keep current.

Best for: Teams whose work fits one approved ecosystem.

Strengths

  • One review, one DPA and one region policy
  • The vendor's own controls are usually its most mature

Trade-offs

  • No independent comparison, so a workflow that vendor handles poorly stays on that vendor anyway
  • Work outside that ecosystem tends to reappear in personal accounts nobody reviews

Several enterprise or provider team plans

Buying each vendor's business plan for the departments that need it gives strong native controls inside each one, at the cost of repeating the whole review for every vendor.

Best for: Regulated teams that need each vendor's own terms.

Strengths

  • Each vendor's own security tooling and support are usually mature
  • Contract terms can be negotiated with each provider directly

Trade-offs

  • Four contracts mean four sub-processor registers and four retention policies to keep current
  • The same sensitive document can end up stored in several products at once

A custom API build

Engineers choose the endpoints, storage, logs and deletion jobs directly, so every processor in the chain is a decision the team made rather than one it accepted.

Best for: Organisations with engineering capacity and strict requirements.

Strengths

  • Every storage location and deletion job is documented because the team built it
  • Provider terms can be chosen per endpoint rather than accepted as a bundle

Trade-offs

  • Retrieval security, log hygiene and incident response become the team's own problem
  • This is justified only when those controls are strategically important enough to own

A multi-model workspace with shared memory

The same governed workspace, plus context saved once and retrieved automatically, which creates another retained dataset that needs its own scope, correction and deletion controls.

Best for: Teams with frequent handoffs on the same sensitive material.

Strengths

  • Less repeated uploading of the same sensitive document across products
  • A corrected fact can be fixed once instead of restated to every model

Trade-offs

  • Memory is another data store the team has to be able to inspect, correct and delete
  • A wrong scope can let one client's material reach an unrelated project

In practice
How a vendor review stays evidence-led

A vendor-review project keeps the evidence, the extraction and the decision in one place, so procurement is not repeated at renewal.

Shared review project - contract, DPA, sub-processor list, SOC 2 report Extract a model pulls controls from the documents Human review marks each claim contractual or not Cross-check a second model finds contradictions Risk register owner and deadline set a teammate continues

A person marks each extracted claim as contractual, marketing-only or unconfirmed before a second model checks for contradictions between the privacy page and the contract, and sends anything unclear back for more evidence. The approved risk register is saved to the project so procurement and legal can continue the review without asking the same questions twice.

Shared memory
Treat it as retained data

Memory is a storage system with a friendlier name, so on this topic it belongs in the retention review, not in the convenience column.

Definition01

Memory is not the context window

A context window is how much text a model reads in one request, and it empties when the chat ends. Memory is context stored outside the chat and pulled back into later ones, which makes it a data store with its own retention rule.

Shapes02

Products build it four ways

Some keep chat history only. Some let a person attach files and build a knowledge base by hand. Some learn automatically but keep it private to one account. Some save it at a level the whole team can reach, and that is the one worth the closest review.

Scope03

Ask what is actually stored

Find out whether an entry is a verbatim message, a summary, an embedding or an extracted fact, and which providers receive it when it is retrieved. Then ask whether a sensitive session can bypass memory and history entirely.

Control04

Deletion is the test that matters

Check that a person can inspect and correct an entry, that an admin can delete one, and that deleting a chat also removes anything derived from it. A demo cannot show any of this, so it has to be tested on a real account.

A staged review
How to verify before you buy

A vendor-neutral process that collects evidence rather than assurances, and ends by checking that deleted content is really gone.

01

Audit the current stack

Record vendor, plan, billing owner, active members, models and tools used, business data stored, sub-processors, processing regions, and renewal or deletion terms for everything already in use.

02

Collect the evidence

Request the current data-processing agreement, sub-processor list, SOC 2 report or ISO certificate, penetration-test summary and retention schedule for the exact plan you would buy, not a general marketing page.

03

Extract with one model

Ask a model to produce a table of data categories, providers, countries, retention periods, deletion rights and audit rights from the documents, then have a person mark each line as contractual, marketing-only or unconfirmed.

04

Check for contradictions

Ask a second, stronger model to find contradictions such as a privacy page promising deletion while the contract allows indefinite retention, or a residency claim that does not cover every model.

05

Test deletion for real

Delete a chat, a file and a memory entry, confirm each disappears from search and retrieval, and record what remains in backups and logs rather than accepting a policy statement about it.

Bottom line
Ask for evidence not a promise

The strongest pre-purchase test is whether a vendor lets a team reconstruct and control the whole data path, not whether it states a no-training promise. That claim answers who trains on the content. It does not say who receives it, where it is processed, what remains after deletion or who can verify the vendor's own security claims.

Public disclosure varies sharply across this shortlist. Some workspaces publish a dated sub-processor list and a specific deletion deadline, and others leave the processor chain, audit scope or regional processing unclear. None of that is a ranking on its own, since a thin public page can still sit behind a strong signed contract, and a detailed page can still hide a broad content licence in the fine print.

What a team is actually choosing between is a vendor whose claims can be checked against a document, and one whose claims have to be taken on trust. Collect the evidence for every shortlisted product before comparing any of them, and test deletion yourself rather than reading about it.

The right buy
When it fits and when it does not

Not the right buy when

  • Work that only ever involves public information
  • A contract requires the system to run on infrastructure the team controls
  • One approved single-vendor plan already covers the work

The right buy when

  • Non-public material passes through prompts most weeks
  • More than one model is in use and only one policy should apply
  • An admin has to prove what was used, deleted and by whom

Where Playgram fits
And where it does not

Two questions settle most of this: how much of the work involves material that should not leave a controlled boundary, and whether an administrator could prove today where any of it went.

If restricted material is routine and nobody can currently prove that, you are shopping for evidence rather than a stronger promise. A product there has to state its no-training position for the exact plan you would buy, publish or provide a current sub-processor list, separate workspace retention from model-provider retention, and show an admin who used which model and when. Ask for all four in writing and test deletion yourself.

If the team works only with public information on one approved product, this whole review is more than the job needs, and a single approved plan with a named account owner already covers it.

Playgram belongs on the shortlist beside the others in this guide for the first case: non-public work moving through more than one model, where a single processing policy has to cover all of it. The memory part of that is covered by the four distinctions above, so read those first, then run the estimator with your own numbers.

Team memory

Shared across everyone and every model.

Project memory

Scoped to a campaign or document set.

Personal memory

Your own working style, kept private.

Fair pricing
Pay per usage, not per seat

Upgrade as needed, and only pay for what you actually use

Save ~17% with the annual plan

Pro

$50/ month

Perfect for small and medium teams

Unlimited users & infinite memory

Multi-LLM chats

Granular access control to models

EU data residency

Get started

Ultra

$200/ month

Best for large, growing teams

Unlimited users & infinite memory

Multi-LLM chats

Unlimited use of DeepSeek V4 Flash

Granular access control to models

Choose US or EU data residency

Get started

Enterprise

Get in touch

Unlimited Credits

For organizations with advanced needs

Unlimited users & SSO

Priority Support

Unlimited use of DeepSeek V4 Flash

Granular access control to models

Choose US or EU data residency

Book a call

30-days money back guarantee

Pricing Calculator

Team size
people
Usage per person
messages/day
Usage complexity
Docs, coding help
Auto mode
%

Playgram will automatically choose the most cost-efficient model suitable for the task. It will be chosen by users in approximately 80% of requests. Your models for the remaining 20%:

If you bought each separately:

ChatGPT Business$800 / month
Claude Team$1 760 / month
Gemini Business$840 / month
Grok Business$1 200 / month
Total$4 600 / month

Playgram

$300/ month

~59 000 credits / month · ~$8 / user

Save ~$4 300 / month
Get started

Frequently asked
questions

Six documents, at minimum: the current data-processing agreement naming the vendor as processor, a dated sub-processor list, a SOC 2 report or ISO certificate, a penetration-test summary, a retention schedule and a written deletion procedure. Check the legal entity, product scope, audit period and any exceptions on each one rather than accepting a summary page.

Not by itself. Check which legal entity was audited, whether the report covers the exact product and plan you would buy, the audit period, which hosting and model-processing systems sat in scope, and any auditor exceptions with the vendor's response. A certification badge on a marketing page answers none of that, and an old report with no bridge letter is a separate flag.

Ask for the dated list itself rather than a general statement that sub-processors exist, and ask whether the vendor sends notice before adding a new one. Some vendors in this comparison publish a dated list naming their cloud and model providers by region. A vendor that cannot produce a current, dated list for the plan you would buy has effectively answered the question already.

Delete a chat, a file and a memory entry yourself, then search for them in history, project search and the memory interface. Ask what remains in backups and logs, whether deleting a source chat also removes anything derived from it, and how long each disappearance actually takes. A policy statement about deletion is not the same as a confirmed test on your own account.

No, it shortens the checklist rather than closing it. Self-hosting keeps the workspace's own storage on infrastructure the team controls, which removes one processor from the chain, but model calls still leave for whichever providers are configured. Those model providers, their regions and their own retention terms still need the same review.

All three, with the business owner leading and security or legal verifying the evidence. The team that will use the product knows which workflows and data categories are involved, and a security or privacy reviewer knows how to read a DPA and a SOC 2 report. Running it as one joint review catches gaps that neither group would notice checking alone.

Related comparisons

AI tools that do not train on your dataAI usage visibility and spend controls for teamsPiloting and rolling out an AI tool across a team

Stop paying per seat
Give the whole team every model

Every model, shared team memory, one team plan priced by usage not per seat

Create workspaceEstimate your bill