Eight team workspaces checked against the same vendor checklist: sub-processors, certifications, deletion rights, hosting regions and what an admin can verify
Sep 1, 2026 · 13 min read
A team should not approve an AI vendor from a no-training statement alone. Ask for the current data-processing agreement, a dated sub-processor list, a security report and a deletion test before sensitive work moves in, and check every answer against the exact plan you would buy. The eight workspaces compared on the same criteria below are Playgram, WorkLLM, nexos.ai, Langdock, TeamAI, Aymo, Magai and TypingMind.
Every major vendor now publishes some version of a no-training promise, so that claim alone rarely separates one product from another. What actually differs is how much of the rest a buyer can verify: who receives the data downstream, where it is processed, how long each copy is kept, and what an administrator can inspect, restrict and delete.
This guide sets out the evidence to collect before a vendor gets real company data, prices the single-vendor stack most teams start from, and compares eight team workspaces on disclosure rather than on promises.
You approve new AI tools and need evidence rather than a policy statement.
You run the due-diligence process and have to reconcile a contract with a marketing page.
Client files, contracts, source code or employee data pass through prompts every week.
One or two people work only with public information on a single approved product.
Each subscription creates its own processing boundary, and nobody is looking at all of them at once.
Each AI subscription creates a separate processing boundary, and a privacy page may describe the front-end vendor while saying little about the model provider, hosting region or connected tool that also handles the prompt. As an example, four single-vendor team plans came to about $101 per person a month at July 2026 list prices, so five fully provisioned people cost roughly $5051, 2, 3, 4. That total buys availability rather than review, and security or legal staff must still read a contract, a DPA and a sub-processor register for every product added.
People move a document between browser tabs, copy prompts, download an output and re-upload it elsewhere, so one sensitive file can be stored by several workspace vendors and their underlying model providers in an afternoon. A person may remember that one account carries business terms and forget that another chat sits inside a personal one, and web search, plugins and MCP connections add further destinations that never show up in the model-selection menu.
Separate accounts lose project instructions and prior decisions, so people repeat them in new prompts, creating more copies of potentially sensitive material. Memory adds a further concern, since a deleted chat may already have contributed to a stored summary, extracted fact or embedding, and deleting the visible transcript does not prove those derived records were removed too.
An administrator needs to know who submitted the data, which model and provider received it, which tools or connectors ran, where the request was processed, what was retained by the workspace and by the model provider, and whether that history, files and memory can be deleted and confirmed. Consumer accounts cannot answer these questions centrally, so a workspace only helps once its administrator can inspect and control those paths rather than just manage billing.
Five checks that turn a policy statement into something an administrator can show an auditor.
Model access should sit behind one policy naming approved providers, and admins should disable a model whose region or retention fails review. The workspace itself must use business or API terms that stop providers training on prompts.
Check each product for web research, document and spreadsheet work, image and video generation, code review and chats that leave no history, and MCP or API connections. Each one is another path company data can leave the workspace through.
Workspace history, backups, memory databases, logs and model-provider retention are different periods, and most vendors publish only one. Ask for all five and look for a setting an admin controls rather than a paragraph about general practice.
Logs should identify person, model, period and project, and deletion should appear as a recorded event rather than a promise. Add a dated sub-processor register with change notices and permissions that follow the user.
A signed processing agreement naming the vendor as processor, a hard budget an admin can set before spend occurs, and a documented mode that leaves no history matter as much as the model list. Price the plan you would actually buy against these controls, not a features page.
The multi-model workspaces a security-minded team is most likely to weigh up, judged on the same criteria and to one standard.
This table compares multi-model team workspaces with each other. The single-vendor plans a team usually starts from are priced further down, under 'Priced per seat', and are not rows here. Pricing is the lowest-priced paid plan that covers five users, at the monthly rate. Each cell cites the page that documents that cell rather than one pricing page per row. Figures checked September 2026, and cells marked 'Manual test required' could not be confirmed from public documentation.
The same products again, on the criteria this topic turns on: what each one does besides chat, what it connects to, what an admin can see and cap, and what evidence backs its data claims.
'Not publicly documented' means the official sources checked did not state it, and 'Manual test required' means the behaviour cannot be confirmed without trying it. Neither means the feature is absent, so read them as questions to put to the vendor. Public documentation is also not a substitute for the signed processing agreement itself. Checked September 2026.
The published per-seat price of each major single-vendor team plan, billed monthly. Each one also brings its own contract, DPA and sub-processor register to review.
Buying all four for one person came to about $101 a month at July 2026 list prices, so five fully provisioned people cost roughly $505. Read that as one example stack rather than a going rate. On this topic the review effort matters as much as the price, since four products mean four contracts, four sub-processor registers and four sets of terms for a legal team to read. Figures checked July 2026.
Cost is the secondary question on this topic, and two of these are paid in legal and security hours rather than in subscription fees.
Six setups, led by the one this guide is about, ordered by how much of the processing chain a team has to review.
One vendor routes requests to several providers under one contract, one sub-processor register and one set of logs. That vendor becomes an additional processor, so it has to document what it sends onward, stores and logs.
Best for: Teams putting non-public work through more than one model.
Strengths
Trade-offs
Each person keeps a personal account with no shared administration, so there is no common register or contract at all. It stays workable until company information starts moving through those accounts.
Best for: One or two people using only public information.
Strengths
Trade-offs
Standardising on one vendor's business plan means one contract, one sub-processor register and one security review to keep current.
Best for: Teams whose work fits one approved ecosystem.
Strengths
Trade-offs
Buying each vendor's business plan for the departments that need it gives strong native controls inside each one, at the cost of repeating the whole review for every vendor.
Best for: Regulated teams that need each vendor's own terms.
Strengths
Trade-offs
Engineers choose the endpoints, storage, logs and deletion jobs directly, so every processor in the chain is a decision the team made rather than one it accepted.
Best for: Organisations with engineering capacity and strict requirements.
Strengths
Trade-offs
The same governed workspace, plus context saved once and retrieved automatically, which creates another retained dataset that needs its own scope, correction and deletion controls.
Best for: Teams with frequent handoffs on the same sensitive material.
Strengths
Trade-offs
A vendor-review project keeps the evidence, the extraction and the decision in one place, so procurement is not repeated at renewal.
A person marks each extracted claim as contractual, marketing-only or unconfirmed before a second model checks for contradictions between the privacy page and the contract, and sends anything unclear back for more evidence. The approved risk register is saved to the project so procurement and legal can continue the review without asking the same questions twice.
Memory is a storage system with a friendlier name, so on this topic it belongs in the retention review, not in the convenience column.
A context window is how much text a model reads in one request, and it empties when the chat ends. Memory is context stored outside the chat and pulled back into later ones, which makes it a data store with its own retention rule.
Some keep chat history only. Some let a person attach files and build a knowledge base by hand. Some learn automatically but keep it private to one account. Some save it at a level the whole team can reach, and that is the one worth the closest review.
Find out whether an entry is a verbatim message, a summary, an embedding or an extracted fact, and which providers receive it when it is retrieved. Then ask whether a sensitive session can bypass memory and history entirely.
Check that a person can inspect and correct an entry, that an admin can delete one, and that deleting a chat also removes anything derived from it. A demo cannot show any of this, so it has to be tested on a real account.
A vendor-neutral process that collects evidence rather than assurances, and ends by checking that deleted content is really gone.
Record vendor, plan, billing owner, active members, models and tools used, business data stored, sub-processors, processing regions, and renewal or deletion terms for everything already in use.
Request the current data-processing agreement, sub-processor list, SOC 2 report or ISO certificate, penetration-test summary and retention schedule for the exact plan you would buy, not a general marketing page.
Ask a model to produce a table of data categories, providers, countries, retention periods, deletion rights and audit rights from the documents, then have a person mark each line as contractual, marketing-only or unconfirmed.
Ask a second, stronger model to find contradictions such as a privacy page promising deletion while the contract allows indefinite retention, or a residency claim that does not cover every model.
Delete a chat, a file and a memory entry, confirm each disappears from search and retrieval, and record what remains in backups and logs rather than accepting a policy statement about it.
The strongest pre-purchase test is whether a vendor lets a team reconstruct and control the whole data path, not whether it states a no-training promise. That claim answers who trains on the content. It does not say who receives it, where it is processed, what remains after deletion or who can verify the vendor's own security claims.
Public disclosure varies sharply across this shortlist. Some workspaces publish a dated sub-processor list and a specific deletion deadline, and others leave the processor chain, audit scope or regional processing unclear. None of that is a ranking on its own, since a thin public page can still sit behind a strong signed contract, and a detailed page can still hide a broad content licence in the fine print.
What a team is actually choosing between is a vendor whose claims can be checked against a document, and one whose claims have to be taken on trust. Collect the evidence for every shortlisted product before comparing any of them, and test deletion yourself rather than reading about it.
Upgrade as needed, and only pay for what you actually use
Save ~17% with the annual plan
Pro
Perfect for small and medium teams
Unlimited users & infinite memory
Multi-LLM chats
Granular access control to models
EU data residency
Ultra
Best for large, growing teams
Unlimited users & infinite memory
Multi-LLM chats
Unlimited use of DeepSeek V4 Flash
Granular access control to models
Choose US or EU data residency
Enterprise
Get in touch
For organizations with advanced needs
Unlimited users & SSO
Priority Support
Unlimited use of DeepSeek V4 Flash
Granular access control to models
Choose US or EU data residency
30-days money back guarantee
Playgram will automatically choose the most cost-efficient model suitable for the task. It will be chosen by users in approximately 80% of requests. Your models for the remaining 20%:
If you bought each separately: