Which legal AI vendors publish SOC 2 or ISO 27001 certification?
16 of the 130 legal AI vendors in the AI Legal Index publish current independent attestation a buyer can actually reach, with the standard named, the scope stated and a route to the report that does not run through a sales conversation: Casepoint, Clio, Definely, EvenUp, Everlaw, Exterro, Filevine, Harvey, Legora, Lexis+ AI, Noxtua, OneTrust, Patlytics, Relativity, Vincent AI and Workday Contract Lifecycle Management. That is the honest answer to the question, and it is much smaller than the number of vendors who are certified. A further 70 state a real certification without publishing the scope, the date, or a way to obtain the report, so 86 of 130 claim attestation and 16 make it checkable. 21 display badges with no scope, no date and no report available, and 23 have no independent security attestation located at all.
Most vendor lists answering this question read a trust page and report what it says. This one grades what is behind it. The AI Legal Index assesses all 130 vendors on Security Certifications and Trust Center on a single test: can an outsider obtain current attestation with its scope and date, without contacting the vendor. A badge is not an attestation and a certification nobody can read is not evidence.
Attestation a buyer can open
AA on Security Certifications and Trust CenterCurrent independent attestation with named scope, reachable without a sales call: a trust center carrying reports, dates and the standards actually covered.Current independent attestation with named scope, reachable without a sales call. A trust center carrying reports, dates and the standards actually covered, or a self serve portal that fulfils a request without a sales conversation attached.
Certified and checkable are not the same number
Being certified and publishing the certification are different facts, and only one of them helps a buyer. A SOC 2 Type II report has a scope, a period and a set of trust services criteria, and none of those are visible from a logo. The 70 vendors in the second tier here are not doing anything wrong: they hold the certification and they say so. What they have not done is make it possible to check without asking, which turns a two minute diligence step into a procurement thread. The distinction the index draws is between open publication, a self serve trust portal that fulfils a request without a sales conversation, and material that only arrives after one. The first two can reach an A. The third cannot, because from the buyer's side it is indistinguishable from absent until someone replies.
Certification stated, evidence not reachable
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.- AlexiLegal Research
- AnaquaIP & Patents
- AnkarIP & Patents
- AscentAIRegulatory & Compliance Counsel
- AugustGeneral Legal Assistants
- Bloomberg LawLegal Research
- Blue JLegal Research
- BrightflagLegal Ops & Spend
- Case StatusIntake & Client Development
- CaseMineLegal Research
- ChamelioContract Review & Drafting
- CheckboxLegal Ops & Spend
- CoCounsel LegalGeneral Legal Assistants
- ConsilioLitigation & eDiscovery
- CorlyticsRegulatory & Compliance Counsel
- CosmoLexIntake & Client Development
- DeepIPIP & Patents
- DeepJudgeLegal Research
- DigitalOwlPlaintiff & Claims AI
- DISCOLitigation & eDiscovery
- EudiaGeneral Legal Assistants
- EvePlaintiff & Claims AI
- GC AIGeneral Legal Assistants
- Genie AIGeneral Legal Assistants
- HonaIntake & Client Development
- IPRallyIP & Patents
- IroncladContract Review & Drafting
- IvoContract Review & Drafting
- JosefLegal Ops & Spend
- JuroContract Review & Drafting
- LawVuLegal Ops & Spend
- LEGALFLYGeneral Legal Assistants
- LegalOnContract Review & Drafting
- LexroomLegal Research
- LinkSquaresContract Review & Drafting
- LitemLitigation & eDiscovery
- LitifyPlaintiff & Claims AI
- LuminanceContract Review & Drafting
- MidpageLegal Research
- MyCaseIntake & Client Development
- NeosPlaintiff & Claims AI
- NexlIntake & Client Development
- NextpointLitigation & eDiscovery
- OmnilexLegal Research
- OnspringRegulatory & Compliance Counsel
- OntraLegal Ops & Spend
- Opus 2Litigation & eDiscovery
- PatSnapIP & Patents
- PERSUITLegal Ops & Spend
- QuestelIP & Patents
- RegologyRegulatory & Compliance Counsel
- Relyance AIRegulatory & Compliance Counsel
- RevealLitigation & eDiscovery
- Robin AIContract Review & Drafting
- SandstoneLegal Ops & Spend
- SecuritiRegulatory & Compliance Counsel
- SirionContract Review & Drafting
- Solve IntelligenceIP & Patents
- SpellbookContract Review & Drafting
- StenoLitigation & eDiscovery
- Streamline AILegal Ops & Spend
- SupioPlaintiff & Claims AI
- TavrnPlaintiff & Claims AI
- TradespaceIP & Patents
- TranscendRegulatory & Compliance Counsel
- Unity ELMLegal Ops & Spend
- VesenceGeneral Legal Assistants
- WordsmithGeneral Legal Assistants
- XakiaLegal Ops & Spend
- XLSCOUTIP & Patents
Below that, 21 vendors display badges with no scope, no date and no report available, and 23 have no independent attestation located. An absence here is dated and means not located in public sources on the date shown, so a vendor that stands up a trust center tomorrow is redated the day it does.
What a SOC 2 report does not cover
AA on Model Supply Chain DisclosureThe models underneath are named, their providers identified, where they run is stated, and the vendor commits to notifying customers when any of that changes.A SOC 2 report covers the vendor's own controls. It does not tell a firm which model provider sees client content, where inference runs, or whether any of that can change without notice. Those are separate questions and the index grades them separately: 5 of 130 vendors name the models underneath, identify the providers, state where they run and commit to telling customers when it changes. 11 publish deployment options and data residency at the same standard, and 13 publish retention, deletion, access control, subprocessors and incident practice as a complete set. A certified vendor running on an undisclosed model supply chain has answered one diligence question and left the one specific to AI open.
Full model supply chain disclosure
Reachable attestation and a published subprocessor list, together
A client’s outside counsel guidelines increasingly ask a firm to evidence its vendor, and the two artifacts that answer it are a report the client can read and a current list of who else sees the data. Each is uncommon. Together they are rarer than either count suggests.
5 of 130. The subprocessor half of that pair is recorded as the Outside Counsel Guideline Readiness signal, and the professional responsibility duty it attaches to is answered on what the bar rules require.
What the index cannot tell you
Whether a vendor is secure. This axis measures whether independent attestation exists and whether an outsider can reach it, which is the only part of security an outside party can honestly assess. A vendor may hold every certification in the market and grade lower here because none of it is reachable, and that is a finding about disclosure rather than about the product. The reverse holds too: a published SOC 2 report is evidence that controls were examined against stated criteria in a stated period, not a guarantee about anything outside that scope.
The index also cannot read what sits behind a sales conversation. A vendor that hands a firm its full report in week three of procurement has done the work and gets no credit here, because the record measures what was available before anyone asked. That is deliberate. The reason to publish is that a buyer comparing twenty products cannot open twenty procurement threads, and the vendors who understand that are the ones on the first list above.
Every record behind this page carries a source basis and a verification date. Standards and limits are on the methodology page. The confidentiality questions a security review sits next to are answered on what happens to privilege when a law firm uses a third party AI tool and do legal AI vendors train their models on client data, the accuracy side is on which AI legal research tools publish their hallucination or accuracy rates, the professional duties are on what the bar rules require before a lawyer uses AI on client matters, the integration depth behind a deployment is on which AI legal tools integrate with iManage and NetDocuments, where the software runs and where the data sits is on which legal AI vendors offer on premise or private cloud deployment, and the complete vendor set is in the directory.