Case Study #1
We audited our own legal compliance. It found 9 risks in 5 minutes.
Before writing a privacy policy or terms, we pointed MegaLens at our own product architecture and asked a simple question: are we legally ready to launch? The answer was no, and the review showed us much more clearly why.
9
Total findings
3
Critical
$0.21
Provider cost, own key
4m 55s
Time
The setup
The product itself worked: authentication, billing and an AI pipeline with multiple engines. Legally, though, almost nothing was in place:
- No privacy policy
- No terms of service
- No data processing agreements with any vendor
- No data retention or deletion system
- An Australian company routing user data through providers in the US, EU, and China
We knew legal review was coming. Before paying for outside counsel, we wanted to understand what the problem looked like. So we fed our own architecture documentation into MegaLens and ran a legal compliance analysis.
The analysis
Configuration
Skill
Legal
Tier
Standard
How it worked
We submitted the full architecture: data flow diagrams, database schema, billing model, API provider list including which vendors are Chinese-owned, our encryption approach, and the fact that we had no published policies.
Several AI models from different companies reviewed the architecture for legal risk. They challenged each other's work, filled gaps, and corrected simple answers.
A second pass then checked their findings, pressed on weak evidence, and looked for what they had missed. Part of it ran in the cloud. Part of it ran locally via MCP at zero extra cost. The second pass added 5 findings the first pass had missed.
What they found
Critical (3)
Complete compliance vacuum
No privacy policy, no terms of service, no data retention limits, no data processing agreements. GDPR, Australian Privacy Act, and UK GDPR all fail simultaneously.
Every model agreed
Processor chain ambiguity
OpenRouter is not a legal shield. Chinese AI providers may be independent data controllers, not sub-processors. Standard DPA assumptions break if providers retain or use prompt data for their own purposes.
Raised in the first pass, confirmed by the second pass as the strongest finding
Cross-border transfer crisis
6 AI providers headquartered in China, subject to China's National Intelligence Law. No Standard Contractual Clauses, no adequacy decision, no transfer risk assessment.
Every model agreed
High (3)
Data subject rights impossible to fulfill
Deletion and access requests can't propagate to OpenRouter and 12 downstream providers. GDPR erasure requirements are operationally broken.
Found in the second pass. The first pass missed it
Trade secret and privilege exposure
Freeform prompts (legal skill, code review) send privileged and confidential content to multiple foreign providers. Attorney-client privilege waiver risk.
Found in the second pass. The first pass missed it
OpenRouter does not resolve transfers
Any suggestion that OpenRouter neutralizes downstream transfer issues is incorrect. Middleware layer doesn't erase where data actually goes.
Found in the second pass
Medium (3)
B2B positioning won't shield from consumer law
$15/mo self-serve tier attracts sole traders and individuals. Unfair-contract rules and consumer protections still apply.
Found in the second pass
Managed-key prepaid balance risk
$9/M token markup with pre-run estimates but no refund policy. If upstream provider goes down, MegaLens remains the counterparty.
First pass agreed
Permanent data retention indefensible
All data grows forever with no auto-delete. Breach blast radius is unlimited. GDPR storage limitation principle violated.
Every model agreed
Where the review got more interesting
The first pass did solid work. It found the obvious gaps: no policies, Chinese provider risk, missing DPAs. The more useful part came afterward.
A second pass checked every first pass finding and added 5 more findings that the first pass had missed:
- Operational impossibility of fulfilling GDPR deletion requests across the provider chain
- Trade secret and attorney-client privilege exposure beyond just "privacy" risk
- The fact that OpenRouter as a middleware provides zero legal protection
- Consumer-law exposure despite B2B positioning
- Service-credit and refund obligations for the managed billing model
No single model caught everything. Models checking each other surfaced risks that one model alone would have missed.
What we did with the results
Within 24 hours of the analysis, we:
Drafted and published a comprehensive Privacy Policy with explicit Chinese provider disclosure
Drafted and published Terms of Service with AI output disclaimers and PAYG credit terms
Added transparent cost breakdowns showing both provider cost and user charges
Documented a 9-point remediation plan prioritized by legal risk
Began implementing data retention auto-delete schedules
Cost breakdown
Provider API cost on our own OpenRouter key (billed by OpenRouter, not a MegaLens charge).
| Component | Cost |
|---|---|
| Review models | $0.15 |
| Evidence extraction | $0.00 |
| Second pass check | $0.06 |
| Local check via MCP | $0.00 (local) |
| Total | $0.21 |
Those are provider charges on our own key, not what a MegaLens customer pays. Pay-as-you-go is billed at $9 per 1M blended tokens, capped at $3 per review.
A comparable manual legal review would cost $2,000-$10,000 and take 2-4 weeks. This is not a substitute for legal counsel. It is a fast way to understand your risks before you engage a lawyer.
Verdict
The verdict agreed with the first pass: MegaLens was at high risk and not compliant. The strongest point was the challenge to how the provider chain was assumed to work. The biggest issues the second pass added: rights requests could not be met across the provider chain, trade secrets could come in with user code, and a B2B label would not protect against consumer law.
AUGMENT means the second pass kept every first pass finding and added its own.
What would a multi-model review find in your product?
MegaLens selects up to four AI models from different companies. Use it for code review, security audits, research, planning and diff audits.
Try it free