AInora
Internal KnowledgeComparisonData ResidencyGDPREnterprise Search

Sana Alternatives After the Workday Acquisition, 2026

JB
Justas ButkusFounder, Ainora
··14 min read

Workday completed its acquisition of Sana on 4 November 2025 and relaunched the product on 17 March 2026. Sana Enterprise, the general-purpose company-knowledge tier, is now sold with Workday Human Capital Management or Workday Financial Management, so a company that does not run Workday cannot buy that tier on the published terms. What is left outside that world is a standalone $30 per user per month Team tier, still on sale on sanalabs.com, whose future Workday has not addressed.

If you are reading this because your vendor was bought, the useful question is not whether the acquisition was good news. It is narrower: what did the packaging change do to the thing you were buying, and what else buys the same outcome. This page answers both from primary documents, and it includes a correction to something we previously had wrong about Sana.

Every claim below comes from a vendor document or an archive, read on 6 September 2026. Nothing here comes from an analyst summary or a competitor's description of a rival. Two qualifications worth knowing up front. Dust's pricing and security pages are client-rendered and return no body text to a fetch, so the Dust figures come from the page's own JavaScript data structures rather than its rendered pixels. And Sana's sub-processor list is a PDF whose extracted text carries doubled spaces, which is why the quotes below are copied rather than retyped.

What Happened to Sana, and What It Means for You

Sana sold two things that used to be one purchase: a learning product and a general-purpose assistant that searched a company's systems and answered questions from them. Workday bought the company for approximately $1.1 billion, closed on 4 November 2025, and spent four and a half months rebuilding the commercial packaging before relaunching in March 2026.

The relaunch is where a buyer's position changed. Two of the three products now travel inside a Workday subscription. Workday writes that “Sana for Workday and the Sana Self-Service Agent are now available to all Workday customers through Workday Flex Credits, no extra license, no separate paywall,” and that customers “receive an allocation of Flex Credits as part of their Workday subscription.” If you run Workday, that is a genuinely good deal and this page is not for you. If you do not, the same sentence is the problem.

USD 1.1 billion
What Workday agreed to pay for all outstanding shares of Sana, announced 16 September 2025
Source: Workday Newsroom, definitive agreement to acquire Sana
4 Nov 2025
The date Workday announced the acquisition had completed
Source: Workday Newsroom, acquisition completed
$30 per user
The monthly Team-tier price still published on sanalabs.com on 6 September 2026, ten months after the deal closed
Source: Sana, pricing page

The Deal, With Dates

Three announcements, all on Workday's own newsroom, settle the timeline. Anyone can check them, which is the point of printing them rather than summarising them.

DateWhat happenedWorkday’s own words
16 September 2025Source: Workday Newsroom, definitive agreement to acquire SanaWorkday signs a definitive agreement to acquire Sana“Under the terms of the definitive agreement, Workday will acquire all of the outstanding shares of Sana for approximately $1.1 billion.” The release expected the deal to close in the fourth quarter of Workday’s fiscal year 2026.
4 November 2025Source: Workday Newsroom, acquisition completedThe acquisition closesWorkday “today announced it has completed its acquisition of Sana, a leading AI company building the next generation of enterprise knowledge tools.” Sana’s CEO Joel Hellermark is quoted in the same release.
17 March 2026Source: Workday Newsroom, introducing Sana from WorkdayWorkday relaunches the product and states how it is sold“Sana Enterprise is now available with Workday Human Capital Management (HCM) or Workday Financial Management and through Workday Flex Credits.”

One detail in the closing release is worth keeping, because it explains the packaging that followed. Workday described the purpose of the acquisition as making Workday “the new front door for work, bringing a company's most critical applications and insights into Workday's platform, enabling employees to start and complete their day in Workday without needing to switch contexts.” A front door is not a standalone product. The commercial design follows directly from the strategic one.

Can You Still Buy Sana If You Do Not Run Workday?

The sentence that decides it

From Workday's launch release of 17 March 2026: “Sana Enterprise is now available with Workday Human Capital Management (HCM) or Workday Financial Management and through Workday Flex Credits.” Sana Enterprise is the tier that reaches beyond Workday into the rest of your stack, with connectors listed for Box, Confluence, Gmail, Google Calendar, Google Drive, Jira, Linear, Microsoft Outlook, Miro, Notion, Salesforce, ServiceNow, SharePoint, Slack and Zoom. It is also the tier attached to a Workday licence. A prospect who does not run Workday HCM or Workday Financial Management cannot buy it on those terms.
Source: Workday Newsroom, introducing Sana from Workday

What remains buyable without Workday is the self-serve tier on sanalabs.com. On 6 September 2026 that page still published a Free tier and a Team tier at $30 per user per month, with “unlimited queries and meeting recordings”, “up to 50 members per workspace”, “OpenAI and Claude model selection” and “10,000 documents per integration”. The Enterprise column on the same page reads “Custom pricing” and lists an enterprise data processing agreement and an extended range of models.

So the commercial state is genuinely transitional, and it is worth stating as a fact about what is published rather than as a prediction. Ten months after the acquisition closed, a $30 per user per month self-serve tier is still being sold on the acquired company's own domain, while the acquirer bundles the same technology into its own subscriptions with no separate licence. Workday has published nothing about how long both things coexist. Neither “it is being killed” nor “it is safe” is a supportable sentence today. What is supportable: the tier you can buy without Workday is the smaller one, capped at 50 members per workspace, and its roadmap is undeclared. That is enough to justify running an evaluation now rather than after a renewal notice.

Two other things changed underneath the branding, and both are visible in compliance documents rather than marketing. The 27 May 2026 sub-processor list now labels the learning product “Sana Learn / Workday Learn, powered by Sana” throughout, and closes by stating that “Sana engages affiliated entities within the Workday group as sub-processors to deliver the Services, including support and maintenance,” pointing to the Workday sub-processor list for the authorised affiliates. If your data protection impact assessment names Sana alone and stops there, it is now out of date.

Where Does Sana Actually Process Your Data?

A correction: Sana’s default hosting is not the United States

Our earlier reading of Sana, and a claim still repeated in comparison content elsewhere, was that Sana defaults to US hosting with an EU region available on request. That is wrong, and the vendor's own document says the opposite. The sub-processor list of 27 May 2026 gives the Google Cloud hosting row as “EEA/EU (default) USA (option for US customers)” and the Microsoft Azure row as “EEA/EU”, both annotated “regional hosting at rest”. The line that was being misread is generic scope boilerplate near the top of the same document, about requesting a different region: “You may also request to have your Subscribe Data for a Service or feature hosted in a different region, which may be accommodated, subject to availability.” That is about moving away from the default, not about the default itself.
Source: Sana sub-processor list, last updated 27 May 2026

Correcting that makes the real finding sharper rather than softer, because the interesting part of Sana's stack is not the hosting row. It is everything the hosting row does not cover.

Sub-processorWhat Sana uses it forLocation stated in the document
Google Cloud, contracted through Google Ireland Ltd., DublinHosting infrastructure, search infrastructure, content generation, web application firewall and DDoS protection“EEA/EU (default) USA (option for US customers)”, described as regional hosting at rest
Microsoft Azure, contracted through Microsoft Ireland Operations Ltd.Search infrastructure and cloud services“EEA/EU”, regional hosting at rest
Redis, Inc., San FranciscoConnector processing, cloud infrastructure for core products, and the “Primary data store”USA
Amazon Web Services, Inc., Seattle“Cloud services / infrastructure for core products”USA
Anthropic“Search and model infra”, with a zero data retention configuration notedUSA
Merge API, Inc., San FranciscoThird-party integrations providerUSA
OpenAI, contracted through OpenAI Ireland Ltd., DublinSearch infrastructure and content generation, on an enterprise API in a private instance with zero data retention“Worldwide routing OR EEA/EU & Switzerland (option only for EU only customers)”

Read the table as a whole and the picture is not “EU vendor” or “US vendor”. It is a European hosting layer sitting on top of several core services that are United States to United States with no stated option: the primary data store, the cloud infrastructure for core products, the integrations provider, and one of the model providers.

The most citable sentence in the document

Against the OpenAI row, under routing, Sana writes: “Routing is dependent on configurations as agreed between the Subscriber and Sana. If no specific agreement has been entered into, default worldwide routing will apply.” That is a vendor stating, in its own compliance document, that customer content goes to the model wherever the model happens to be, unless the customer has negotiated otherwise. It is not a scandal and it is not unusual. It is the field's honest default written down, and it is the single most useful sentence to bring to a procurement meeting, because the correct response to it is a contractual one: get the routing configuration into the agreement, in writing, before signature.
Source: Sana sub-processor list, last updated 27 May 2026

This is the distinction the whole category blurs, and it is not specific to Sana. Storage residency and inference residency are separate purchases, and only one of them is usually on the marketing page. We have written that up across the whole field, vendor by vendor, in what EU data residency actually covers in an internal AI assistant, and the same split shows up in general-purpose assistants in does your AI vendor train on your data.

Does Sana Train on Your Content?

Sana's answer is no for third-party models, and the accurate version of it carries two hedges that a tick in a table would erase. Both are verbatim from the security page. The first sits inside the main commitment: “No customer data, e.g., external content indexed by our service (‘Content Data’), are used outside of the isolated tenant, unless specifically agreed upon.” The second sits on the retention commitment: “We utilize enterprise security arrangements and, whenever possible, a Zero-Day Retention (ZDR) policy with our third-parties.”

And query logs are retained. Sana states that “to improve ranking, we also log the queries asked by users, and how a user interacts with the results or Sana Agents, so that we can serve the types of queries users need the most in the best way possible,” adding that “such data is pseudonymized to ensure confidentiality.” A ranking system that never sees a query cannot improve, so this is a reasonable engineering decision, honestly disclosed. It is simply not the same claim as “your data is never used”, and in a regulated sector the difference between anonymised and pseudonymised is a legal one rather than a stylistic one.

On retention of the indexed content itself, Sana publishes nothing. We searched its security and pricing pages on 6 September 2026 for retention, retain, delete and days. The only match was “Zero-Day Retention”, which is a commitment about third-party model calls rather than about Sana's own storage of your documents, chat history or query logs. We are not going to invent a number to fill that cell. The absence is the finding, and the right place to resolve it is the contract.

The Alternatives, Compared Honestly

Four products come up in every replacement shortlist for this category: Glean, Dust, Guru and Notion AI. Here is what each of them actually publishes, next to what we publish about ourselves. The Ainora row is deliberately the least impressive on certifications, because it is true.

VendorPublished priceEU hosting regionDoes the vendor say residency covers the model call?SOC 2 and ISO
Sana, now WorkdaySource: Sana sub-processor list, last updated 27 May 2026Team tier $30 per user per month, still listed on sanalabs.com. Enterprise is custom, and available with Workday HCM or Workday Financial Management.Yes. Google Cloud Ireland, “EEA/EU (default) USA (option for US customers)”.No. “Routing is dependent on configurations as agreed between the Subscriber and Sana. If no specific agreement has been entered into, default worldwide routing will apply.”SOC 2 and ISO 27001, and the security page adds HITRUST.
GleanSource: Glean, sub-processor list, last updated 28 July 2026None published since January 2023.Yes, europe-west4 is one of three preferred regions, but the default tenant region is us-central1 and a different region has to be requested.No. Its own sub-processor list places all seven dedicated LLM providers in the United States, and the customer-discretion footnote is attached only to the three cloud providers and to its speech-to-text vendor.SOC 2 Type II, ISO 27001 and ISO 42001, per its platform security page.
DustSource: Dust, pricing pagePro seat $30 per seat per month, or $24 per seat per month on annual billing. Max seat $150 or $120. Excluding VAT, metered in credits that do not roll over.Yes, and on the self-serve Business plan: the pricing feature matrix reads “Data residency: US / EU” for both Business and Enterprise.Not documented either way. Dust says it lets you “host in the EU or US to meet your regulatory needs” and publishes nothing about where the model call runs.SOC 2 Type II. ISO 27001 is not claimed on the pricing feature matrix or the security page.
GuruSource: Guru, privacy policyNone published. The pricing page sells a scoped engagement instead of a per-seat licence.None. “Personal Data that you provide while in the EU or an EAA member state will be transferred to the United States.” The typo is Guru’s own.No EU region exists, so the question does not arise. Guru relies on the EU-U.S. Data Privacy Framework for the transfer.SOC 2 Type II. ISO 27001 is not claimed on its security, privacy or pricing pages.
Notion AISource: Notion help, data residencyBusiness €19.50 per member per month on the EU-served pricing page. Enterprise is quoted as custom.Frankfurt or Ireland, on the Enterprise plan only, and “until you contact Notion and receive confirmation that migration is complete, your workspace data will remain hosted in the United States”.No, and Notion is the one vendor here that says it outright: processing outside the data region “can include: Customer Data processed by Notion subprocessors, including LLM providers”.SOC 2 Type 2 and four ISO certifications: 27001, 27701, 27017 and 27018.
AinoraIndividual pricingEU hosting. EU-only processing is available on request rather than as an unconditional default.We publish the same limit as everyone else. On a standard deployment the model call is not guaranteed to stay inside the EU, and EU-only processing has to be asked for and configured.None. No SOC 2 of any type and no ISO certification. All five vendors above hold at least SOC 2. We hold none of it.

Two structural things fall out of that table before any individual vendor does. None of the five publishes a promise that the model call happens inside the customer's chosen EU region. Sana documents worldwide routing as the default absent an agreement, Notion documents that its sub-processors including LLM providers process outside the region, Glean's sub-processor list places every dedicated model provider in the United States, Dust says nothing either way, and Guru has no region to begin with. And two of the four alternatives publish no price at all, which shapes the evaluation as much as any feature does.

Glean: The Most Certified, and the Least Priced

Glean is the strongest compliance story in the set and the weakest transparency story. On its platform security page it lists SOC 2 Type II, ISO 27001, ISO 42001, HIPAA, TX-RAMP Level 2 and GDPR. Ainora holds none of those. If an RFP scores certifications, Glean wins that section against everyone here, including us.

A verified absence: Glean has published no price since January 2023

Three independent checks on 6 September 2026, each of which you can repeat. One: the live URL. A request to glean.com/pricing returns HTTP 301 with a location header pointing to the site root. Two: the sitemap. Glean's sitemap contains no pricing page at all; a search across its URLs for pricing, plan and cost returns only a cost-controls product page and two press releases. Three: the archive. The Wayback Machine holds ten captures of glean.com/pricing, the first on 23 September 2021 and the last on 31 January 2023, and none since. That capture history is what distinguishes a withdrawn page from a URL that never existed. Even the archived version carried no figure, only the line: “We offer flexible deployment and pricing options that reflect your preferences and practices.” A company valued at $7.2 billion in its June 2025 Series F has not published a price in over three years.
Source: Wayback Machine, glean.com/pricing captured 31 January 2023

The only numbers available are third-party buyer data, and they should be labelled as such every time they are used. Vendr, a buyer-side negotiation service that aggregates anonymised contract data, reports a median annual Glean spend of $98,890 “based on data from 174 purchases”, with a low of $29,880 and a high of $208,897. Vendr does not publish the fielding window or the buyer-size mix behind that median, and its own page contradicts itself elsewhere by referring to “Glean's published pricing” while also stating that “the platform does not publish transparent list pricing publicly”. Use the median as an order of magnitude and ignore the narrative around it.

On residency, Glean does offer Europe, but not by default. Its own deployment documentation states that “the default region for tenants hosted by Glean is us-central1, which is located in North America,” and asks customers to advise Glean if they want a different region; europe-west4 is one of three preferred regions. The sub-processor list then settles the inference question. Amazon, Google and Microsoft carry a footnote saying customers may select a different cloud provider and location, and its speech-to-text vendor carries a similar one. The seven dedicated model providers carry no footnote and are each listed as United States. So the accurate sentence is that Glean lets an EU customer choose where the tenant sits, while placing every dedicated model provider in the United States with no stated customer discretion.

Two operational details are worth taking from Glean regardless of whether you buy it, because they are good practice. Its chat retention is an organisation-level policy the admin configures, with options of off, 30 days, 90 days, 6 months or 1 year, and Glean warns that turning history off “controls only whether past chats are stored and visible in the chat history panel” and does not affect event logs. And its access model is honest about what it guarantees: “Glean respects the permissions set in your company's connectors. If you have permission to view a document in Google Drive or a thread in a public Slack channel, it can appear in your results.” That is a promise about what you could already reach, not about what you were meant to see, and the gap between those two is the oversharing failure mode that every permission-mirroring assistant inherits.

One thing not to read into this section: Glean and Workday are not enemies. Glean's own newsroom announced that it is teaming up with Workday on agent-to-agent collaboration across both platforms. Workday now owns Sana and partners with Glean, and both facts sit on vendor newsrooms.

Dust: Where EU Hosting Is Not a Differentiator

Where we are not the answer

Dust is a French company that offers EU data residency on its self-serve tier at a published price. Its pricing feature matrix lists data residency as “US / EU” for the Business plan as well as for Enterprise, and eu.dust.tt resolves. Against Dust, “we host in the EU” is not a differentiator and we are not going to pretend it is one. If EU hosting on a self-serve plan at a listed price is the whole requirement, Dust already meets it.
Source: Dust, pricing page

Dust is also the price anchor of the field, and the only vendor here that publishes a per-seat figure with a stated metering model. Its Business plan sells three seat types: a free seat with a lifetime allocation of 500 credits, a Pro seat at $30 per seat per month or $24 on annual billing with 8,000 credits per seat per month, and a Max seat at $150 or $120 with 40,000 credits, all excluding VAT. Its documentation is explicit that “individual seat credits reset monthly, on the anniversary of your subscription start date” and that “unused credits do not carry over to the following month,” with consumption proportional to model, context length and query complexity.

The honest wedge against Dust is narrow, and it is not about hosting. Dust's DPA is Enterprise-only. Its own feature matrix lists “Custom legal terms (MSA, DPA)” as false for Business and true for Enterprise. For a smaller EU buyer sitting on the Business plan, that is a live GDPR Article 28 problem: the controller is required to have a processor contract with specified content, and a plan that does not offer one on standard terms leaves that requirement unresolved. It is a narrow objection and it deserves to be stated narrowly rather than inflated into a security story.

One architectural difference matters for anyone migrating from a permission-mirroring product. Dust's access model is Dust-native, declared after ingestion rather than mirrored from the source at query time. Its documentation describes “spaces” as “containers in Dust that let admins organize and control access to data,” and states that “permissions are granted to groups rather than directly to individual people” and that “permissions are additive. If a person belongs to several groups, they receive the combined permissions granted by those groups.” Additive group permissions can only widen access, so a mis-scoped group over-grants silently. That is a real operational difference from a product that reads the source ACL on every query, and it is worth deciding deliberately rather than discovering later. The same architectural question, framed for buyers, is in retrieval versus agentic assistants.

Guru: No EU Region At All

Guru is the clearest case in the set, and the clarity runs against it for a European buyer. Its privacy policy states that “Personal Data that you provide while in the EU or an EAA member state will be transferred to the United States,” naming the performance of the contract, explicit consent or legitimate interest as the basis and binding corporate rules, standard data protection clauses or consent as the safeguard. The “EAA” is Guru's own typo, and it is worth reproducing exactly, because a quote that does not match the source is worthless.

We searched Guru's security, privacy and pricing pages on 6 September 2026 for residency, region, us-east, Ireland, Frankfurt and hosted in. The only match across all three pages was a disaster-recovery sentence: “We copy our database daily and save it to a disaster recovery site in an entirely separate region.” Guru offers no customer-selectable EU hosting region on any published page. Its security page confirms the shape of the deployment, describing content as stored “in a highly secure AWS database, separated and protected from other client content by a unique team ID,” and names its participation in the EU-U.S. Data Privacy Framework. For an EU buyer whose policy requires in-region storage, that is disqualifying before price is discussed.

On certifications, Guru holds SOC 2 Type II and says so twice, with the report available under NDA. It does not claim ISO 27001: a search for ISO 27001, ISO27001 and ISO/IEC across its security, privacy and pricing pages on 6 September 2026 returned zero matches. That is an absence on those pages rather than proof that no certificate exists anywhere, and it should be described that way. It matters for EU public-sector and regulated tenders that require ISO 27001 from the supplier itself.

Guru also repositioned. Its pricing page no longer sells a per-seat tool: “Guru is a platform and expertise solution, not just a per-seat tool. Your investment is tailored to your organization's scale, knowledge complexity, and AI maturity.” There is no figure of any kind on the page. Vendr reports a median of $39,168 a year across 167 purchases, with a range from $8,159 to $121,023, and again its narrative prose about three published tiers contradicts the vendor's own live page, so only the median, range and sample size are usable.

One inconsistency is worth flagging because it is the kind of thing that decides a security review. Guru's pricing page states flatly that “permissions are inherited from your existing systems and enforced in real time.” Its own help documentation describes inherited permissions as one of two models, “supported for some sources”, requiring “an admin from the Source system (like a Slack Admin or Google Admin) to connect the Source.” The other model, and the one the default path describes, is that “Guru connects as a single user and indexes only what that user can access. Access is controlled entirely within Guru, independent of Source app permissions.” Both sentences are Guru's. Ask which model your sources will actually use.

Notion AI: Residency That Stops at the Model Call

Notion is the cheapest way into this category on paper and the most explicit about its own limits, which is an unusual and creditable combination. Notion AI is “included with Notion's Business and Enterprise plans, with core features like Notion Agent, AI Meeting Notes, and Enterprise Search,” and the EU-served pricing page shows Business at €19.50 per member per month on annual billing, with Enterprise as custom pricing.

Its data residency is Enterprise-only and it does not cover inference, and Notion says both parts itself. The residency page offers EU-Central-1 in Frankfurt and EU-West-1 in Ireland, states that residency “is available free of charge to customers on the Enterprise Plan,” and warns that “until you contact Notion and receive confirmation that migration is complete, your workspace data will remain hosted in the United States.” Under its own heading about when customer data is processed outside the data region, it answers that this “can include: Customer Data processed by Notion subprocessors, including LLM providers.” Its AI FAQ then answers a narrower question than the one it poses: the model providers “utilize zero data retention for Enterprise Plan workspaces, so no data is stored with LLM providers.” Nothing stored is not nothing processed. Storage in Frankfurt, inference wherever the sub-processor runs.

Two things Notion does better than most of this field. Training is opt-in, which is the correct polarity, and its AI security practices documentation states it: “By default, Notion and its AI Subprocessors do not use Customer Data to train any models,” with contractual prohibitions on the sub-processors, and the pricing page adds that Notion AI “will not use your data to train our models unless you opt in to a request to share your data.” And its retention position is published as a number rather than left blank: zero data retention at the model provider for Enterprise, and “for all non-Enterprise plan workspaces, LLM providers only retain Customer Data for 30 days or fewer before deletion.” On certifications, its security page enumerates rather than samples: Notion “has achieved certifications for four ISO standards: ISO 27001, ISO 27701, ISO 27017, and ISO 27018,” which establishes by the vendor's own sentence that ISO 42001 is not among them.

The trajectory is worth a buyer's attention too. Notion bundled unlimited AI into Business and Enterprise in May 2025, and by 2026 the same product page carries both a throttle, “your access to AI features can be temporarily reduced depending on your usage,” and a meter: “Starting May 4, 2026: Custom Agents will start using Notion credits when they run.” Bundle to win, then meter, is the pattern across this whole category rather than a Notion quirk. Model the second year, not the first.

How to Choose a Replacement

Four questions, in this order, decide it for most European companies.

1. Do you run Workday? If yes, the cheapest path is almost certainly the one Workday published: Sana for Workday and the Self-Service Agent arrive through Flex Credits with no extra licence, and Sana Enterprise attaches to HCM or Financial Management. Evaluating alternatives against something already inside your subscription is a high bar for a challenger to clear. If no, that entire option is closed to you and the shortlist is the other four.

2. Is your requirement storage residency, or inference residency? These are different products and only one is usually on the marketing page. If you need storage in the EU, Dust meets it on a self-serve plan at a published price, Notion meets it on Enterprise after a migration you have to request, Sana's hosting layer defaults to it, Glean meets it if you ask for europe-west4, and Guru does not meet it at all. If you need the model call in the EU, no vendor in this comparison publishes that promise, which makes it a contract negotiation rather than a product selection. Sana's own sentence about default worldwide routing is the best possible thing to put in front of a vendor at that meeting.

3. Does your procurement require certificates from the supplier itself? If an ISO 27001 certificate from the contracting entity is a hard gate, the shortlist narrows to Glean, Sana and Notion, and it rules us out today. Say so at the first meeting. A supplier who discovers that requirement at the security review has wasted two months of your time and its own.

4. Who is going to own the permission model? This is the question that decides whether the rollout succeeds, and it has nothing to do with the model. A product that mirrors source permissions surfaces everything a user could already technically reach, including the over-shared drive nobody has audited since 2019. A product with its own native spaces requires somebody to re-declare access after ingestion, and additive group rules mean mistakes widen access rather than narrow it. Neither is safer in the abstract. What is unsafe is buying either one without naming the person who owns it.

Where Ainora Fits, and Where It Does Not

We build internal AI assistants that connect to a company's systems and answer from them, hosted in the EU, and we are not in the same commercial category as most of the products above. What we can say plainly, and what we cannot, is worth setting out on the same page as the comparison rather than in a footnote.

What we do not have. No SOC 2, of any type. No ISO 27001 and no ISO 42001. We will not badge an infrastructure provider's certificate as if it were ours, because it is theirs. Every vendor in the table above holds at least SOC 2, and Glean holds more than any of them. If certification is your gate, that is a real reason to choose someone else, and we would rather you knew it now.

What we do say. Customer data is processed and stored on servers in the European Union, and EU-only processing is available on request for deployments that require it rather than being an unconditional default. That is the same honest limit every vendor on this page has, stated in the same words we use on our own security page, and it is why the routing question belongs in your contract with whoever you choose.

Where a smaller supplier is genuinely the better answer. When the requirement is multilingual, when the assistant has to reach a system with no off-the-shelf connector, when a signed DPA is needed on a plan a large vendor gates to Enterprise, and when the deployment has to answer to a European regulator rather than to a US procurement template. If you want to see the shape of it, our AI teammate page covers what one does day to day, and the provider comparison puts the platforms side by side. Pricing is individual and it is quoted after a conversation about scope, not before one.

How This Page Is Kept Honest

Last verified 6 September 2026

Every vendor claim here comes from that vendor's own page, documentation or compliance PDF, or from a named archive, read on 6 September 2026. Where a figure comes from a third party rather than a vendor, it is labelled as such with its sample size, which applies to both Vendr medians. Acquisition terms, plan structures and sub-processor lists change, sometimes without a changelog: Sana's sub-processor list is dated 27 May 2026 and Glean's 28 July 2026, so both are recent enough to move again. This page is re-checked quarterly, and the next scheduled re-verification is December 2026.

What we dropped, and why. Four claims were available and are not on this page.

  • The adoption figures in Workday's launch release. The release carries a named customer saying their organisation reached a given adoption percentage within 40 days and retired several hundred licences of another tool. That is a customer testimonial in a vendor press release with no method behind the percentages, and we do not restate testimonials as findings, our own or anyone else's.
  • Sana's retention period. There is not one published on the pages we searched, so the page states the absence and the search terms rather than a number.
  • A claim that Dust holds no ISO 27001. Dust does not claim ISO 27001 on its pricing feature matrix or its security page, and that is all we can evidence. Its trust portal could not be read by an automated fetch, so the absence of a claim on two surfaces is not proof of the absence of a certificate, and the page says only the former.
  • Vendr's narrative pricing prose. Both Vendr pages carry generated marketing sentences that contradict the vendors' own live pages, in Glean's case within the same paragraph as the data. Only the median, the range and the sample size are used here.

And one claim was corrected rather than dropped: our earlier reading that Sana defaults to United States hosting. The vendor's own sub-processor list says EEA/EU is the default for hosting infrastructure, so the correction is on the page above rather than quietly edited out of it. If you find a row that no longer matches the document it links to, the link is there so you can check it before we do.

Frequently Asked Questions

Yes. Workday announced a definitive agreement on 16 September 2025 to acquire “all of the outstanding shares of Sana for approximately $1.1 billion,” and announced on 4 November 2025 that it “has completed its acquisition of Sana, a leading AI company building the next generation of enterprise knowledge tools.” Workday then relaunched the product on 17 March 2026 as Sana from Workday. All three announcements are on Workday’s own newsroom.Source: Workday Newsroom, acquisition completed

Not the enterprise tier on the terms Workday published. The 17 March 2026 launch release states that “Sana Enterprise is now available with Workday Human Capital Management (HCM) or Workday Financial Management and through Workday Flex Credits,” and that Sana for Workday and the Sana Self-Service Agent reach Workday customers through Flex Credits with “no extra license, no separate paywall.” Those are attachments to a Workday subscription. What remains outside that world is the standalone Team tier at $30 per user per month, which was still being sold on sanalabs.com on 6 September 2026, ten months after the acquisition closed. Workday has published nothing about how long that tier continues, so treat its future as undeclared rather than as either safe or doomed.Source: Workday Newsroom, introducing Sana from Workday

The hosting layer is, by default. Sana’s sub-processor list, last updated 27 May 2026, gives the Google Cloud row as “EEA/EU (default) USA (option for US customers)” and the Microsoft Azure row as “EEA/EU”. That corrects a claim, including one we had previously read the same way, that Sana defaults to United States hosting. It does not. The sharper finding is one row further down the same document: Redis is listed as the “Primary data store” in the USA, Amazon Web Services provides “Cloud services / infrastructure for core products” in the USA, and Anthropic and Merge are USA to USA. And for the model call itself, Sana writes that “Routing is dependent on configurations as agreed between the Subscriber and Sana. If no specific agreement has been entered into, default worldwide routing will apply.” EU hosting and EU inference are two different purchases.Source: Sana sub-processor list, last updated 27 May 2026

Sana says it does not train third-party models on customer content, and the sentence carries two hedges that belong in any honest summary. The first: “No customer data, e.g., external content indexed by our service (‘Content Data’), are used outside of the isolated tenant, unless specifically agreed upon.” The second, about zero-day retention with third parties, is “whenever possible”. Sana also states that it logs queries: “To improve ranking, we also log the queries asked by users, and how a user interacts with the results or Sana Agents … Such data is pseudonymized to ensure confidentiality.” Pseudonymised query logs retained for ranking work is a defensible design. It is not the same claim as “we never use your data”, and a comparison table that flattens it to a tick is misleading.Source: Sana, security page

It does not say. On 6 September 2026 we searched Sana’s security and pricing pages for retention, retain, delete and days. The only match was “Zero-Day Retention”, which is a commitment about third-party LLM calls, not about Sana’s own storage of indexed content, chat history or query logs. So the honest answer is an absence rather than a number: Sana publishes no default retention period and no admin retention control on those pages. If retention matters to your policy, it is a contract question, not a documentation question, and it should be asked in writing before signature.Source: Sana, security page

Glean does not say, and has not said since January 2023. Its pricing URL now returns an HTTP 301 redirect to the homepage, there is no pricing page anywhere in its sitemap, and the Wayback Machine holds ten captures of glean.com/pricing running from 23 September 2021 to 31 January 2023 and none after that. Even the archived page carried no figure, only the line that “we offer flexible deployment and pricing options that reflect your preferences and practices.” The only numbers available are third-party buyer data: Vendr, a buyer-side negotiation service that aggregates anonymised contract data, reports a median annual spend of $98,890 based on 174 purchases, with a range from $29,880 to $208,897. Vendr does not publish the fielding window or the buyer-size distribution behind that median, so use it as an order of magnitude and nothing more.Source: Wayback Machine, glean.com/pricing captured 31 January 2023

No. Guru’s privacy policy states that “Personal Data that you provide while in the EU or an EAA member state will be transferred to the United States,” with EU-U.S. Data Privacy Framework participation and standard contractual clauses named as the safeguards. We searched Guru’s security, privacy and pricing pages on 6 September 2026 for residency, region, us-east, Ireland, Frankfurt and hosted in. The only match across all three was a disaster-recovery sentence about copying the database to “a disaster recovery site in an entirely separate region.” If your policy requires in-region storage, that is disqualifying regardless of what Guru costs.Source: Guru, privacy policy

Not the model call. Notion offers EU-Central-1 in Frankfurt and EU-West-1 in Ireland, free of charge but on the Enterprise plan only, and states that “until you contact Notion and receive confirmation that migration is complete, your workspace data will remain hosted in the United States.” Under its own heading asking when customer data is processed outside the data region, Notion answers that this “can include: Customer Data processed by Notion subprocessors, including LLM providers.” Its FAQ then answers a narrower question than the one it asks: the LLM providers “utilize zero data retention for Enterprise Plan workspaces, so no data is stored with LLM providers.” Nothing stored is not the same as nothing processed in the EU. Read precisely, that is storage in Frankfurt and inference wherever the sub-processor runs.Source: Notion help, data residency

No. We hold no SOC 2 of any type and no ISO certification, and we will not borrow an infrastructure provider’s certificate to imply otherwise. Every vendor compared on this page holds at least SOC 2, and Glean holds ISO 27001 and ISO 42001 on top of it. If your procurement process requires an ISO 27001 certificate from the supplier itself, that requirement rules us out today, and you should say so early rather than discover it at the security review. We would rather lose the deal at the first meeting than at the last one.

JB
Justas Butkus

Founder & CEO, AInora

Building AI digital administrators that replace front-desk overhead for service businesses across Europe. Previously built voice AI systems for dental clinics, hotels, and restaurants.

View all articles

Ready to try AI for your business?

Hear how AInora sounds handling a real business call. Try the live voice demo or book a consultation.