Case Studies/Legal Compliance

Case Study #1

We audited our own legal compliance. It found 9 risks in 5 minutes.

Before writing a privacy policy or terms, we pointed MegaLens at our own product architecture and asked a simple question: are we legally ready to launch? The answer was no, and the review showed us much more clearly why.

9

Total findings

3

Critical

$0.21

Provider cost, own key

4m 55s

Time

The setup

The product itself worked: authentication, billing and an AI pipeline with multiple engines. Legally, though, almost nothing was in place:

  • No privacy policy
  • No terms of service
  • No data processing agreements with any vendor
  • No data retention or deletion system
  • An Australian company routing user data through providers in the US, EU, and China

We knew legal review was coming. Before paying for outside counsel, we wanted to understand what the problem looked like. So we fed our own architecture documentation into MegaLens and ran a legal compliance analysis.

The analysis

Configuration

Skill

Legal

Tier

Standard

How it worked

We submitted the full architecture: data flow diagrams, database schema, billing model, API provider list including which vendors are Chinese-owned, our encryption approach, and the fact that we had no published policies.

Several AI models from different companies reviewed the architecture for legal risk. They challenged each other's work, filled gaps, and corrected simple answers.

A second pass then checked their findings, pressed on weak evidence, and looked for what they had missed. Part of it ran in the cloud. Part of it ran locally via MCP at zero extra cost. The second pass added 5 findings the first pass had missed.

What they found

Critical (3)

Complete compliance vacuum

No privacy policy, no terms of service, no data retention limits, no data processing agreements. GDPR, Australian Privacy Act, and UK GDPR all fail simultaneously.

Every model agreed

Processor chain ambiguity

OpenRouter is not a legal shield. Chinese AI providers may be independent data controllers, not sub-processors. Standard DPA assumptions break if providers retain or use prompt data for their own purposes.

Raised in the first pass, confirmed by the second pass as the strongest finding

Cross-border transfer crisis

6 AI providers headquartered in China, subject to China's National Intelligence Law. No Standard Contractual Clauses, no adequacy decision, no transfer risk assessment.

Every model agreed

High (3)

Data subject rights impossible to fulfill

Deletion and access requests can't propagate to OpenRouter and 12 downstream providers. GDPR erasure requirements are operationally broken.

Found in the second pass. The first pass missed it

Trade secret and privilege exposure

Freeform prompts (legal skill, code review) send privileged and confidential content to multiple foreign providers. Attorney-client privilege waiver risk.

Found in the second pass. The first pass missed it

OpenRouter does not resolve transfers

Any suggestion that OpenRouter neutralizes downstream transfer issues is incorrect. Middleware layer doesn't erase where data actually goes.

Found in the second pass

Medium (3)

B2B positioning won't shield from consumer law

$15/mo self-serve tier attracts sole traders and individuals. Unfair-contract rules and consumer protections still apply.

Found in the second pass

Managed-key prepaid balance risk

$9/M token markup with pre-run estimates but no refund policy. If upstream provider goes down, MegaLens remains the counterparty.

First pass agreed

Permanent data retention indefensible

All data grows forever with no auto-delete. Breach blast radius is unlimited. GDPR storage limitation principle violated.

Every model agreed

Where the review got more interesting

The first pass did solid work. It found the obvious gaps: no policies, Chinese provider risk, missing DPAs. The more useful part came afterward.

A second pass checked every first pass finding and added 5 more findings that the first pass had missed:

  • Operational impossibility of fulfilling GDPR deletion requests across the provider chain
  • Trade secret and attorney-client privilege exposure beyond just "privacy" risk
  • The fact that OpenRouter as a middleware provides zero legal protection
  • Consumer-law exposure despite B2B positioning
  • Service-credit and refund obligations for the managed billing model

No single model caught everything. Models checking each other surfaced risks that one model alone would have missed.

What we did with the results

Within 24 hours of the analysis, we:

1

Drafted and published a comprehensive Privacy Policy with explicit Chinese provider disclosure

2

Drafted and published Terms of Service with AI output disclaimers and PAYG credit terms

3

Added transparent cost breakdowns showing both provider cost and user charges

4

Documented a 9-point remediation plan prioritized by legal risk

5

Began implementing data retention auto-delete schedules

Cost breakdown

Provider API cost on our own OpenRouter key (billed by OpenRouter, not a MegaLens charge).

ComponentCost
Review models$0.15
Evidence extraction$0.00
Second pass check$0.06
Local check via MCP$0.00 (local)
Total$0.21

Those are provider charges on our own key, not what a MegaLens customer pays. Pay-as-you-go is billed at $9 per 1M blended tokens, capped at $3 per review.

A comparable manual legal review would cost $2,000-$10,000 and take 2-4 weeks. This is not a substitute for legal counsel. It is a fast way to understand your risks before you engage a lawyer.

Verdict

AUGMENTConfidence: 93%

The verdict agreed with the first pass: MegaLens was at high risk and not compliant. The strongest point was the challenge to how the provider chain was assumed to work. The biggest issues the second pass added: rights requests could not be met across the provider chain, trade secrets could come in with user code, and a B2B label would not protect against consumer law.

AUGMENT means the second pass kept every first pass finding and added its own.

What would a multi-model review find in your product?

MegaLens selects up to four AI models from different companies. Use it for code review, security audits, research, planning and diff audits.

Try it free