04 / For Technology Law Partners

What a product does with data is written in its code.

Technology matters turn on facts about a system—what it collects, where it sends it, which third parties it calls, what the model retains. No questionnaire answers those reliably.

Aumirah Analytics examines the product itself. We review source code, dependencies, data flows and AI systems, and give the legal team verified findings with the evidence attached—alongside the regulatory research and contract analytics the matter needs.

Why This Matters

The questionnaire and the code often disagree

Privacy and AI advice is usually built on what the business believes its product does. That belief is assembled from memory, from documentation written at design time, and from engineers answering a form between other work.

The product ships what the code says. Where the two diverge, the advice is built on a fact that is not true—and that gap surfaces in diligence, in a regulator’s questions, or after an incident.

Asserted

What the questionnaire says

  • The vendor and processor list the business believes it has
  • Data categories as described by the product team
  • Transfers as understood when the system was designed
  • Retention and deletion as stated in the policy
  • Consent behaviour as written in the requirements
  • Model usage as described in the vendor’s materials

Evidenced

What the code shows

  • Every SDK, library and endpoint actually shipped
  • The fields actually collected, logged and transmitted
  • The regions and providers the data actually reaches
  • What the deletion routines actually remove
  • Whether trackers fire before consent is given
  • What is actually sent to the model, and what is retained

Counsel can only advise on the facts. We establish them from the product itself.

Capability 01

Source Code and Data-Flow Assessment

Establishing what a product collects, stores and transmits by examining the codebase, its dependencies and its outbound traffic.

  • Personal-data collection and handling review
  • Data-flow mapping derived from the codebase
  • Third-party SDK, library and tracker inventory
  • Outbound endpoint and destination analysis
  • Cross-border transfer verification from code and configuration
  • Logging, telemetry and analytics review
  • Retention and deletion implementation review
  • Consent and preference enforcement verification
  • Device permissions and platform data access review
  • Open-source licence and obligation identification
  • Discrepancy reporting against notices, DPAs and records

Capability 02

AI and LLM System Assessment

The same discipline applied to AI systems, where the data path runs through models, vendors and retrieval layers that conventional review does not reach.

  • Prompt and inference data-flow mapping
  • Personal data exposure in prompts, context and logs
  • Third-party model and API vendor data-handling review
  • Model, dataset and dependency inventories
  • Training and fine-tuning data provenance research
  • Retrieval and RAG data-boundary review
  • Output logging, retention and human-review pathways
  • Memorisation and data-leakage exposure review
  • Output filtering and guardrail review
  • Model documentation and technical-file preparation
  • Vendor terms compared against observed system behaviour
  • Open-weight model licence and obligation review

Capability 03

Incident and Breach Response Support

When something has happened, the questions are what was actually affected and who must be told—against notification clocks that start running immediately.

  • Scope determination from logs, code and system records
  • Affected data-category and data-subject analysis
  • Affected-system and dependency identification
  • Incident chronology development
  • Multi-jurisdiction notification requirement research
  • Notification deadline and threshold matrices
  • Regulator and data-subject notification drafting support
  • Contractual notification obligation review
  • Comparable enforcement and precedent research
  • Regulator question and information-request response packs
  • Evidence registers and open-item trackers
  • Post-incident remediation tracking

Capability 04

Privacy and Digital Regulation

The regulatory research that turns technical findings into an assessment of exposure.

  • Multi-jurisdiction privacy law research
  • Applicability and territorial-scope assessments
  • Cross-border transfer mechanism research
  • Impact-assessment and transfer-assessment support
  • Breach-notification requirement research
  • AI regulation applicability and risk classification
  • Online safety, platform and digital-market obligations
  • Cybersecurity and operational-resilience regimes
  • Regulator guidance and enforcement monitoring
  • Obligation registers and control mapping
  • Draft client alerts and partner briefings
  • Recurring regulatory intelligence desks

Capability 05

Technology Contracting and Transactions

Contract analytics across SaaS, cloud, AI and licensing arrangements—and technical diligence on the target in a transaction.

  • SaaS, cloud and licensing agreement abstraction
  • Clause extraction, comparison and deviation analysis
  • Clause library and playbook development
  • Data-processing addendum review
  • AI and data clauses in vendor agreements
  • Open-source licence identification and obligation review
  • IP ownership and assignment provisions
  • Service-level and liability benchmarking
  • Technology M&A diligence, including code and data review
  • Renewal, obligation and deadline tracking

Deliverables

What the technology team receives

  • Code-derived data-flow maps
  • Third-party SDK, tracker and dependency inventories
  • Finding registers with severity, location and evidence
  • Discrepancy reports against notices, DPAs and records of processing
  • AI system, model and dataset inventories
  • Model documentation and technical files
  • Obligation registers and control maps
  • Incident chronologies and notification matrices
  • Remediation trackers and re-review records
  • Source-linked memoranda with review notes and limitations

Scope and Access

How this work is set up

Code assessment needs access, authority and a defined boundary. All three are agreed with the responsible lawyer before anything begins.

01

Authorised access only

We work on repositories, builds and systems the client provides, under written authority from the party entitled to grant it, and within the scope the instructing firm sets.

02

Your environment where required

Where source code cannot leave the client’s estate, we work inside their environment under their access controls. Handling, retention and destruction terms are agreed in advance.

03

Not a security audit

Aumirah does not carry out penetration testing, vulnerability assessment or security certification. Our work establishes what a system does with data and how that maps to legal obligations. Where a matter needs security testing, we will say so rather than stretch our scope.

04

Findings, with evidence

Every finding cites the file, the dependency or the request that supports it, so your lawyers—and the client’s engineers—can verify it rather than take it on trust.

Why Through Counsel

A technical finding is also a written record

A client can commission a code or AI assessment directly from a consultancy. If they do, the report that documents a compliance gap exists as an ordinary business record—available in diligence, in litigation, and to a regulator asking what the company knew.

The same assessment, commissioned by the law firm for the purpose of advising the client, is far better positioned. That is a reason for the client to route this work through you rather than around you.

01

We work to the firm’s instruction

Aumirah is engaged by the law firm, takes its scope from the responsible lawyer, and reports to the legal team. We do not hold a direct advisory relationship with the client on the matter.

02

Findings go to the legal team first

Reports are addressed to the instructing lawyers. Onward distribution to the client, to engineering or to a board is the firm’s decision, made once counsel has read the findings.

03

Scoped as advice-supporting work

The engagement letter, the scope and the deliverable format can be drawn so the work sits clearly within the retainer’s purpose, and marked in accordance with the firm’s own practice.

04

Your call, not ours

Whether privilege attaches, and on what basis, is a matter of law for the firm in the relevant jurisdiction. We will work to whatever arrangements you specify—we do not advise on the question.

Start a Conversation

Is the product doing what the client says it does?

Tell us the system, the questions your team needs answered and the access that can be arranged.

We will propose a scoped assessment and the form the findings should take.