Athennian vs DiliTrust: how they compare in 2026
Athennian and DiliTrust both sell entity and governance software to in house legal teams. Athennian is a dedicated entity management platform, while DiliTrust sells a five module suite that adds a board portal, contracts, matters and a dataroom. DiliTrust sits in the top two bands on eleven of fifteen axes and Athennian on ten of fifteen, identical on ten. The difference is where each puts its commitments. Athennian puts them in published terms: its AI terms bar it and its named model providers, Google and Amazon, from training any model on customer data. DiliTrust publishes no customer agreement. It puts its commitments in an AI code of conduct and in certificates anyone can download: ISO 27001 and ISO 27701, both dated 23 February 2026. It states that its models are its own, fine tuned from open source models on synthetic and public data, and run in data centers in the client's region. It also names customers such as BNP Paribas and LVMH, where Athennian names none.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of a core capability layered on a product that would still function without them. Athennian AI extracts and populates governance data, onboards entities and answers governance questions; remove it and the entity records, structure charts, document automation, appointments, controls, tasks and API remain, which is the entity management platform the company has sold for years. The AI Terms define Athennian AI as features and functionality of the Services rather than the Services themselves. AI capabilities page, product navigation and AI Terms read 6 September 2026.
The models are the engine of real capabilities layered on a suite that would function without them, which is the B band, and the gap between the vendor's framing and the product decides it. The framing is maximal: DiliTrust describes itself as the only AI-native, fully integrated platform, and every intelligent feature across the suite now sits under the Lini umbrella. The substance behind that is genuine and unusually broad for this lane: seven named capabilities shipping across all five modules, covering natural-language assistance, extractive data capture with optical character recognition, document summarisation, board minute drafting, audio transcription, contract risk detection with playbook application, and matter snapshots. What the record cannot support is A. The five modules are a board portal, a contract system, an entity register, a matter tracker and a dataroom, and each is a system of record whose core job is holding and organising corporate legal information. Strip Lini out and a firm still has its board pack, its entity structure, its contract repository and its litigation tracker; what it loses is speed. The vendor's own account confirms the layering rather than contradicting it, describing Lini as powering every dimension of legal work rather than constituting the product, and dating its emergence as a named engine to late 2025 against a suite that long predates it. Verified 12 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted without measurement and disclaimed in the agreement. The capabilities page claims data accuracy through automated extraction and the AI landing page claims ninety-two per cent of data entry automated and elimination of human error, with no test set, method or published evaluation; AI Terms section 4 states the probabilistic nature of the models and makes no warranty as to the accuracy, completeness or reliability of output, and section 7 commits to internal periodic evaluations without publishing results. The primary-authority limbs do not apply to a tool extracting governance data from the customer's own documents. AI pages and AI Terms read 6 September 2026.
Reliability is asserted without measurement and no grounding method is described, which is the C band, and R15 governs the weight. This product cites no legal authority. Lini reads the customer's own contracts, board packs and matter files, so the limbs on primary sources, openable citations and citator status do not bite and the record is not penalised for them. What does bite is that several outputs are consequential and the vendor publishes confidence rather than evidence. Risk Detector is described as identifying risky clauses, applying the firm's internal compliance rules and suggesting compliant and reliable edit suggestions; Minutes Generation drafts board minutes, which are a corporate record with legal effect; Document Summarization is offered across regulatory and financial material. For none of these is an accuracy figure, error rate, test set or evaluation published, and no hallucination disclosure of any kind was located on the surfaces read. Two things sit adjacent and are recorded rather than credited. The extraction feature is described as extractive, which is a real architectural constraint tending against fabrication because the output is pulled from the source document rather than generated, but the vendor never makes that argument or evidences it. And the AI Code of Conduct commits to transparency in the sense of explaining how decisions are made, which is a governance statement graded on that row rather than an accuracy one. Verified 12 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A written commitment that the models work under human review, with real review surfaces, short of the full control structure. AI Terms section 5 makes the customer responsible for applying human review and judgment to all output before use; the AI landing page states that human verification ensures the customer retains full control and that every step is tracked, reported and transparent; the capabilities page states that anomalies and missing data points are surfaced for review rather than resolved silently. What is not published is a threshold at which extracted data populates a record without a person or a stated route back after a wrong extraction beyond the reviewer's correction. AI Terms and AI pages read 6 September 2026.
A written commitment that the models support rather than replace human decision-making, published in a governance instrument, short of the full control structure. The commitment is explicit and sits under an Ethical AI heading in the published AI Code of Conduct: AI at DiliTrust is used to enhance human decision-making, not replace it, and the vendor states a firm stance that critical decisions always involve human oversight. That is a position a buyer can hold the vendor to in writing, and it is repeated in the product framing, which describes Lini as existing not to replace people but to empower them. The feature descriptions are consistent rather than contradicting it, each stopping at proposing: Risk Detector suggests validated alternatives, QuickView produces a snapshot, Minutes Generation produces a draft, and the extraction features fill summary sheets a user reviews. Real review surfaces exist in the platform and are documented on the security page: a comprehensive audit trail tracking user interactions, data changes and system events in real time, and granular access control defining who may do what. R124(2) sets the ceiling and it is applied here. Nothing attaches a boundary to a named mode or tier and states what that tier's output may not be used for, which is what a categorical constraint must do to substitute for a numeric threshold. No confidence signal, no stopping condition and no error-handling path is published, and the phrase critical decisions is left undefined, so which decisions the vendor considers critical is the customer's judgement rather than a published boundary. Verified 12 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Figures without a named customer on the surfaces read. The AI landing page states a ninety per cent reduction in document filing time and more than a hundred and twenty hours saved per year, the capabilities page eighty per cent faster centralisation, all unattributed; the vendor states more than five hundred thousand entities managed. A case studies page exists in the navigation and was not opened, and is the rebuttal route. AI pages and navigation read 6 September 2026.
Named customers in quantity and at scale, with no figure attached to any of them, which is the B band. The naming is a logo wall on the vendor's own security page rather than a set of case studies, and it is substantial: Accor, Atos, BNP Paribas, LVMH, Vivendi, Renault, Sodexo, Carrefour, Danone, Veolia, Lavazza, Illy, Geox, Nexi, Webuild, Mahou San Miguel, DIA, Invex and STM. Those are identifiable enterprises across banking, luxury, energy, food, construction and transport, and the concentration of large French and Italian groups is consistent with the vendor's European positioning. Scale is claimed alongside, the company stating support for more than 2,500 businesses across over 60 countries in its own acquisition announcement. What is missing is measurement tied to any of it. No named customer carries a figure, nothing is dated to a deployment, and no result is published with a basis. The vendor's outcome material takes a different and weaker form, five return-on-investment calculators covering the suite and each module, which invite a prospect to generate their own projection rather than reporting what any customer achieved; a projection a buyer produces about itself is not deployment evidence and is not credited. A customer stories library is published and was not opened; under R25 it corroborates rather than carries a grade already resting on the named-customer wall, and it is what would move this row if the stories carry dated figures with a stated basis. Verified 12 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Four of the five limbs are published, and the privilege limb is absent. No training: AI Terms section 9 provides that Athennian does not use, and does not permit its model providers to use, customer data to train any AI or machine-learning model, with input and output defined as customer data under section 2. Segregation at the level an in-house buyer requires: sophisticated user permissions and controls are stated, with a private-markets edition addressing investor operations separately. Third-party model providers: sections 1 and 8 name Google Gemini and Amazon Bedrock among providers on a published sub-processor list, bound to confidentiality and security no less protective than the services agreement. Retention and deletion: the privacy policy states deletion per the terms of the agreement, and the DPA exists in the portal but was not opened. Nothing addresses privilege or work product for a product holding board minutes and governance documents. AI Terms, home page and privacy policy excerpt read 6 September 2026.
Substantive published commitments on confidentiality and training use, failing the limb R33 makes decisive. What is published is stronger than most records at this grade and rests on a specific architectural claim rather than an adjective. The vendor states a zero-access principle in terms: once a customer entrusts it with data, that data is exclusively the customer's and the vendor's own team does not have access to it. Around that sit encryption of data at rest and in transit, a complex data separation solution, granular access control and permissions, document watermarking for traceability, a comprehensive audit trail, mandatory and continuing security training for all employees, and a named Data Protection Officer function reachable by customers. On training use the position is clear enough to grade, the AI Code of Conduct enumerating the training corpus as synthetic data, publicly available datasets and the vendor's own knowledge base, and stating that personal data is processed without any third-party sharing. The limb that fails is privilege and work product, and it fails completely. Neither privilege, professional secrecy, nor the confidentiality duties of in-house counsel is addressed anywhere on the surfaces read, on a platform whose Matter Management module holds live disputes and whose Board Portal holds board deliberations. Two further gaps are recorded: no retention period and no deletion commitment for customer data was located, because the only published privacy instrument governs website visitors rather than the product. Verified 12 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
The agreement places responsibility on the customer without drawing an advice line. AI Terms section 5 requires human review of all output and bars representing output as human-generated, and section 4 disclaims accuracy; no surface read states that the product's outputs are not legal advice, who should rely on them, or how the product supports a supervising lawyer's duties, and the Service Terms were read only in excerpt. Professional services firms are a named buyer segment. AI Terms and Service Terms excerpt read 6 September 2026.
Nothing published on professional responsibility was located, and R15 requires naming which limbs bite before the grade is read as heavier than it is. The advice-line limb applies only lightly. The buyer is a corporate legal department or a board secretariat, not a firm selling advice, and the outputs are internal governance artefacts rather than advice to a client. The audience is unambiguous, addressed through five named departmental pages covering board members, general secretaries, legal operations, contract managers and corporate lawyers, so nobody could mistake who this is for. What is entirely absent is any statement connecting the AI's output to the professional obligations of the lawyers relying on it. There is no statement that output is not legal advice, no disclaimer of any kind on any surface read, and no published agreement in which such a position might otherwise sit. Two places where it would bite are named rather than passed over. Minutes Generation drafts the minutes of a board meeting, which are a corporate record with evidential and statutory consequences and which a company secretary signs. Risk Detector proposes alternative contract clauses and applies compliance rules, which is drafting judgement being exercised by a model on documents a lawyer will approve. Nothing published addresses the supervision either requires, and the vendor's only adjacent statement, that critical decisions always involve human oversight, is an autonomy commitment graded elsewhere and does not identify what the professional obligation is. Verified 12 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A governance commitment with a testing mechanism is published in the agreement, short of published results or a named owner. AI Terms section 7 states that Athennian maintains internal governance practices for Athennian AI, including periodic evaluations and testing to assess the quality and reliability of AI-generated output, and commits to compliance with laws governing its provision; that is a contractual undertaking to test, which carries more weight than a principles page. No test results, bias findings, ISO 42001 or equivalent, or accountable owner is published. AI Terms read 6 September 2026.
A published governance framework with real substance, short of testing results and a named accountable owner, which is the B band, and this is among the more complete frameworks in the corpus. The instrument is a standalone AI Code of Conduct, dated, downloadable as a PDF the vendor expressly invites customers to circulate, and organised into seven numbered sections. Its content is specific rather than aspirational. It sets out how the models are developed and what they are trained on. It states the security standards they operate under and the jurisdictional position of the data centres. It commits to GDPR alignment and privacy by design. Section four does something no other record in this corpus does: it walks through the runtime data path step by step, from user request, through encryption before data leaves the device, transfer to a local data centre, decryption with a unique key, processing, insight extraction and return to the interface. Section six carries three ethical commitments including a bias commitment that claims a mechanism rather than an intention, the vendor stating that it rigorously tests and monitors its models to identify and address potential biases. Alignment with the European AI Act is claimed. What A asks for is still missing. No testing result, evaluation or finding is published, so the bias claim is a described practice with no output. Nobody is identified as accountable for AI: the Data Protection Officer covers data protection and the framework is endorsed by the chief executive, but neither is an AI accountability designation. Verified 12 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy covering most of the ground. Sub-processors: a sub-processor list is published at a stated URL and the AI Terms name the model providers on it. Access control and hosting: SOC 2 Type II certification, annual penetration testing, encryption at rest, user permissions, and Amazon Web Services hosting across multiple availability zones per region with blue-green deployment and twenty-four-hour recovery time and recovery point objectives for tier one services, per the legal portal FAQ. Retention and deletion: the privacy policy states deletion per the agreement; the DPA in the portal, revised for CCPA and standard contractual clauses, was not opened. Incident practice: not located on the surfaces read. AI Terms, legal portal FAQ, security page excerpt and privacy policy excerpt read 6 September 2026.
Substantive published policy covering most of the ground, missing the data lifecycle, which is the B band. Access and protection are documented in detail across two surfaces. The platform carries two-factor authentication and single sign-on, encryption of static and transiting data, granular role and permission control, document watermarking with a unique stamp per document for traceability, secure document sharing with tracked activity, and a comprehensive audit trail capturing user interactions and system events in real time for incident detection. Organisationally the vendor publishes a Data Protection Officer function, mandatory and continuing security training, continuous monitoring and updating of controls, and physically secured server sites with video surveillance and permanent on-site staff. The AI-specific handling is described end to end in the AI Code of Conduct, including encryption before data leaves the user's device and decryption at the destination with a unique key. The zero-access principle is asserted at the strongest level, the vendor stating its own team cannot reach customer information. What is absent is what happens to data over time. No retention period is published for customer content, prompts or outputs, no deletion or return commitment on termination was located, no subprocessor register exists for the platform, and no incident notification commitment to customers was found. The cause is structural and is recorded rather than treated as silence: the only published privacy instrument is scoped to website visitors and the contact form, and no customer agreement is published at all. Verified 12 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Liability is addressed with real gaps in what could be read. Service Terms section 7.2 warrants that security, functionality and continuity measures will not materially decrease during the term, with termination on thirty days' notice as the exclusive remedy, and section 7.3 warrants consulting services with a limited remedy; the Service Terms and AI Terms both refer to provisions that limit Athennian's liability, and the AI Terms disclaim any warranty on output. The cap, exclusions, indemnities and any insurance sit in Service Terms sections not read in the excerpt retrieved, and the Service Terms are the rebuttal route. Service Terms excerpt and AI Terms read 6 September 2026.
Nothing published on who bears the loss when the system is wrong was located, which is the D band. No warranty, indemnity, liability cap, exclusion, service level, service credit or insurance position appears anywhere on the surfaces read. The cause is that no customer agreement is published. The complete legal inventory in this vendor's footer is a privacy policy and a legal notice, the latter being the statutory publisher identification a French site must carry rather than an agreement; there is no master subscription agreement, no terms of service, no data processing addendum and no order form template. An Information System Security Policy is named on the security page and is expressly gated, the vendor asking prospective readers to contact it to access what it calls a confidential document, so even the security position behind the certifications is not readable in advance. This is an enterprise vendor selling to companies of the scale of BNP Paribas and LVMH, so negotiated contracts certainly exist; the point the axis measures is that a buyer cannot read any of it before entering a sales process. The exposure is concrete rather than theoretical on this product, and it is worth naming: the AI drafts board minutes, proposes contract clause alternatives, applies compliance rules and summarises regulatory documents, and every one of those errors lands in a corporate record. Verified 12 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations, documented, with depth described for some. A bi-directional API is stated with public developer documentation and developer terms, an Enterprise Connectivity page exists, and the vendor's own descriptions name Microsoft 365, electronic signature and document management integrations; a third-party listing adds DocuSign and Google Workspace and is not credited. What syncs in which direction is described only at the level of bi-directional; the developer documentation and connectivity page were not opened. Home page, navigation and developer terms excerpt read 6 September 2026.
Real integrations, named individually and organised by class, with the target module and the benefit stated for each, short of the configuration detail an implementer needs. The catalogue is published on a dedicated page and split into three declared categories. Native integrations, described as plug and play and fully embedded, cover Salesforce, HubSpot and Microsoft Dynamics 365 into contract management, with contract generation from opportunities and deals and automated approvals; a Microsoft Word add-in and a Google Docs add-on for drafting against centralised templates and clause libraries; and Microsoft Teams, an Outlook add-in and a Gmail add-in feeding the Board Portal and Matter Management with agendas, meeting invitations, emails and attachments. Partner integrations cover governance and registry work, naming Impal'Act for entity structure and governance events, PF Registres for registry filings, and eWitness for certified timestamping and witness verification. Third-party integrations cover electronic signature at unusual depth, naming DocuSign, Adobe Sign, SignaturIt, Dropbox Sign, BoxSign, Yousign, UniverSign and Connective, and distinguishing between global providers and eIDAS-compliant qualified signature providers for European work. Each entry states which DiliTrust module it connects to and which roles it serves, and direction of flow is described for several. What holds it off A is configuration: no public API reference or developer documentation was located, the page closing on a general reference to plug-and-play and API integrations, and nothing states what a firm must set up or what objects synchronise. Verified 12 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Hosting and regional structure are stated and the tenancy model and region options are not. The legal portal FAQ states cloud infrastructure hosted by Amazon Web Services with multiple availability zones in each region, backups in a separate zone and blue-green deployment; nothing read states which regions a customer may choose, whether customers share infrastructure, or where the model providers' inference runs. Legal portal FAQ read 6 September 2026.
Residency is addressed as a positioning commitment rather than a passing mention, and stops short of the specificity A requires. What is published: server locations across Europe, North America, Africa and the Middle East, physically secured with video surveillance and permanent on-site staff; a commitment in the AI Code of Conduct that data centres are located locally in the regions where clients operate, framed as guaranteeing compliance with data sovereignty laws and protecting against unauthorised cross-border transfers; a statement that the AI operates entirely within a secure encrypted environment hosted on local infrastructure; and, unusually, an express jurisdictional claim that the solutions are not subject to the United States CLOUD Act, qualified as except for US clients. The chief executive puts the same point in the buyer's own language, that data is stored in the client's country and under the same jurisdiction, eliminating the risk of interference from foreign legislation. For a European buyer weighing sovereignty that is a real disclosure and it is the strongest part of this record after the certifications. What holds it off A is that the detail stops at continents and a principle. No specific data centre location or country list is published, so a buyer cannot confirm where its own tenant would sit without asking. No tenancy model is described: complex data separation is asserted in the AI Code of Conduct and separation controls appear on the security page, but nothing states whether the deployment is multi-tenant or isolated, and no single-tenant or on-premises option is offered or refused. Verified 12 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real and stated with a trust centre, short of a report reachable without asking. The security page states SOC 2 Type II certification verified through independent third-party audits covering security, availability and confidentiality, with GDPR compliance and annual penetration testing, and the legal portal FAQ refers to the availability section of the SOC 2 report; a trust centre exists at trust.athennian.com. No auditor or coverage period is named on the surfaces read and the trust centre was not opened, so the access tier is not established. Security page excerpt and legal portal FAQ read 6 September 2026.
Certifications are current and the evidence is reachable without a sales conversation, which is the A band, and this is the first A on this axis in pull 8 after nineteen records without one. The distinguishing fact is that the certificates themselves are published rather than described. A dedicated security documentation page links the ISO 27001 certificate and the ISO 27701 certificate as downloadable documents, both dated 23 February 2026, and a Spanish ENS certificate dated 25 September 2024 under the Esquema Nacional de Seguridad. Alongside them sit two further ungated documents, a consolidated Security Sheet setting out the implemented measures and the AI Code of Conduct, the latter published as a PDF the vendor invites readers to circulate. SOC 2 Type 2 compliance is claimed and its report is offered on request. So a buyer can establish, before speaking to anyone, which standards are held, which entity holds them, when they were issued and where the AI-specific commitments sit. The page also sets out the control environment behind them, covering the Data Protection Officer function, physical server security, the zero-access principle, security training, transparent communication and continuous monitoring. Three limits are recorded and none displaces the grade. The certificate PDFs were not opened, so this grade rests on the published access flow and the standards and dates the page states rather than on the certificates' contents. No auditor is named for the SOC 2. And the Information System Security Policy is expressly gated, the vendor describing it as confidential and directing readers to contact it. Verified 12 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Providers are named in the agreement and the models are identified only as a family. AI Terms section 1 defines model providers as the third parties whose language models and other models power Athennian AI, naming Google (Gemini) and Amazon (Bedrock) and pointing to the published sub-processor list for others, and section 8 states that input and output are processed by those providers under confidentiality and security obligations. Gemini is a model family rather than a named model, no inference location is stated, and the sub-processor list is described as updated from time to time without a stated notice mechanism. AI Terms read 6 September 2026.
The supply chain is partly disclosed and the shape is unusual, because the vendor's answer to who supplies the models is itself. The AI Code of Conduct states that the models are designed and trained exclusively by the vendor's own teams, giving it full ownership and control, and the Lini material draws the contrast explicitly, saying that unlike others relying on open solutions such as ChatGPT the AI is built entirely in-house. Where inference runs is answered: entirely within a secure encrypted environment on the vendor's local infrastructure, in data centres in the regions where clients operate. Customer control over provider choice is published as a feature, the interoperability section stating that organisations can connect their own large language models through secure API connectivity while using the vendor's infrastructure. That is more than most records disclose. What holds it off A is that no model is named and the in-house claim is qualified by the vendor's own words. The same document states that the vendor pre-finetunes and finetunes its legal-specific language model using the most advanced open-source and commercially permissible models available, which means the foundation is third-party open-source work rather than built from nothing, and neither those base models nor the resulting legal model is identified by name or version. R34 requires the models to be named as a limb separate from identifying their providers, and that limb fails. No change notification commitment was located, the vendor stating only that its systems are continuously updated. Verified 12 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Package names are published and the figures were not read. The navigation carries a Pricing and Packages page, third-party listings describe Essentials, Professional and Enterprise packages with an Essentials annual figure that is not credited, and the Service Terms refer to order forms; the pricing page was not opened on 6 September 2026 and is the rebuttal route to a higher grade. Navigation and Service Terms excerpt read 6 September 2026.
No pricing information is published at any level, including the unit of charge, which is the D band, and this is a page-inventory finding rather than a retrieval limit. The full navigation was read and there is no pricing page: the menu runs Home, Product, DiliTrust's AI, ROI, Solutions, Resources, Support and Request a demo, and the single conversion path across every page is a demo request or a conversation with the sales team. Nothing states whether the suite is licensed per user, per module, per entity or per company, no minimum or band appears, and none of the five modules carries a figure. Under R10's closing discipline an estate that only invites a sales conversation is an absence belonging in this note alone, so no VendorPricing row is written for this record. What sits where pricing would be is worth recording because it is a deliberate substitution rather than an oversight: the vendor publishes five return-on-investment calculators, one for the full suite and one for each of contract lifecycle management, board management, matter management and entity management, inviting a prospect to model its own savings. A buyer can therefore generate a projection of what the product might save without being able to learn what it costs, which is an unusual asymmetry and one the note states plainly. No agreement is published either, so the commercial terms are equally unreadable. Verified 12 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment and coverage are described with substance; the boundaries are left open. Team solutions address legal, treasury, finance and tax; company types corporate groups, private markets and professional services; industries real estate, energy, financial services and manufacturing; the vendor states entities managed across a hundred and fifty countries with a global compliance guide library and a UBO guide. No jurisdiction or entity type is named as unsupported, and no law firm use beyond professional services is described. Navigation and home page read 6 September 2026.
Coverage is documented with real substance across buyers, roles and sectors, short of the stated limits the A band asks for. Who this is for is addressed on surfaces of its own rather than asserted: five departmental pages cover board members, general secretaries, legal operations, contract managers and corporate lawyers, so each buyer inside the organisation has a page written to it. The segment is unambiguous throughout, in-house legal departments and corporate boards, and the vendor is explicit that it exists to serve the general counsel's function rather than law firms. Sector coverage is enumerated with four named industry pages for pharmaceuticals, private equity, real estate and energy, and a compliance solution area with a dedicated page for the European DORA regime, which is a specific regulatory workload rather than a generic claim. Geographic reach is evidenced rather than asserted, with contact estates in ten countries and the site published in English, French, Spanish, Italian, German and Canadian French. Functional coverage maps to the five modules and is stated for each. R15 applies to the practice-area limb: this is corporate governance and legal operations infrastructure that does not vary by practice area in the way a research or litigation product does, and the record is neither credited nor penalised for it. What holds it off A is that limits are absent. Nothing identifies an organisation size floor, no segment is named as out of scope, government use is neither claimed nor excluded, and nothing states which modules are available in which of the ten territories. Verified 12 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The commitment is in the agreement and reaches the model providers. AI Terms section 9, last updated 14 April 2026 and forming part of the services agreement, provides that Athennian does not use, and does not permit its model providers to use, customer data to train any artificial intelligence or machine-learning model; section 2 defines input and output as customer data, and section 3 licenses them to Athennian only to the extent necessary to provide Athennian AI. No aggregation or de-identification qualifier appears. Surfaces checked 6 September 2026.
A public policy states the position on training and no agreement exists in which to look for a matching term, which is this value, though the statement is constructive rather than express and the note says so rather than overstating it. The AI Code of Conduct enumerates the training corpus exhaustively under a Strict Data Policy heading: by leveraging synthetic data, publicly available datasets and its own sovereign knowledge base, the vendor has developed an internally-built private dataset, a synthetic legal dataset tailored to legal tasks.
Customer content appears nowhere in that enumeration. Reinforcing it, the security page states a zero-access principle in terms, that once a customer entrusts data to the vendor it is exclusively the customer's and the vendor's own team does not have access to it, and the code states that personal data is processed without any third-party sharing. Read together a buyer would reasonably conclude that customer content is not training material.
What the vendor never does is say so in those words, and that is why this is recorded as constructive: there is no sentence reading that customer data is not used to train the models, only a complete account of what is used instead. R43(1) was run and is why a contractual value is unavailable rather than declined: the estate publishes a privacy policy and a French legal notice and no customer agreement of any kind, so there is no instrument in which a training term could sit.
One counterweight is recorded: the privacy policy states that client employee or user data may be used to improve the performance and quality of the Service, which on the R28 naming test is not a training right because it names neither training nor machine learning.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is acknowledged without a period on the surfaces read. The privacy policy states that personal information is deleted based on the terms of the agreement, which points to the Service Terms and DPA for the period; those documents were read only in excerpt or not opened, and nothing states how long AI input and output are held during the term. The DPA is the rebuttal route. Surfaces checked 6 September 2026.
No located public material states how long prompts, outputs or AI working records are kept, and this is an established absence with a documented cause rather than an untested one. The only published instrument that could carry a period is the privacy policy, last updated 27 January 2025, and it is scoped by its own opening words to data collected when a visitor uses the website and submits the contact form. Its retention clause is correspondingly generic, committing only to retain personal data for no longer than necessary for the purposes collected and to erase it within a reasonable timeframe on request, and directing anyone wanting detail to email the Data Protection Officer.
No customer agreement and no data processing addendum is published, so nothing governs the product's data. The AI Code of Conduct describes the runtime path in unusual detail, from encryption before data leaves the device through processing to delivery of results, and stops at delivery: it says nothing about what persists afterwards, how long a prompt or a generated summary is held, or whether AI working records are retained separately from the documents they were derived from.
The gap is worth stating concretely because of what this AI touches: audio recordings of board meetings, generated minutes, contract risk assessments and matter snapshots are all outputs a company would want a retention position on, and none is published.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Segregation is claimed without documentation of a permission model. The home page states sophisticated user permissions and the third-party listings describe role-based access and controls; a Controls and Governance capability exists in the navigation and was not opened. Nothing read describes how one entity group's records are walled from another's within a professional-services account or how Athennian AI respects those permissions. Surfaces checked 6 September 2026.
The product maintains its own permission model and documents it feature by feature, which is this value. The security documentation sets out granular access control and permissions as a named capability, describing the ability to define roles, permissions and access levels for each user so that only authorized individuals reach specific data and functionality. Around it sit several mechanisms that serve the same purpose: two-factor authentication and single sign-on for identity, a comprehensive audit trail tracking user interactions and data changes in real time so that access can be reconstructed, secure document sharing with per-document access permissions and tracked activity, and document watermarking that stamps each document uniquely to deter and trace unauthorised distribution.
The AI Code of Conduct adds a complex data separation solution at the infrastructure level. Taken together that is a documented model the customer administers, which is what separates this value from a bare claim. Two limits are recorded. Nothing published describes a conflicts or ethical wall function by name, or matter-level walls of the kind an in-house team running contentious matters against the same counterparties would ask about, and the Matter Management module holds exactly that material.
And nothing states whether Lini's retrieval respects the asking user's permissions: the AI is described as operating across the suite, and no published statement confirms that an assistant answering a question cannot surface a document the user could not otherwise open.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located public material addresses whether the customer is told when its data is demanded by a third party. The Service Terms were read only in excerpt and the DPA was not opened; both are published in the legal portal and are the rebuttal route. Surfaces checked 6 September 2026.
Compelled disclosure is addressed substantively and customer notice is absent everywhere, which is this value, and this record is an unusually clear instance because the vendor volunteers the subject rather than being silent on it. The AI Code of Conduct claims exemption from the United States CLOUD Act, qualified as except for US clients, and frames it as safeguarding client data from foreign government access; the same document presents locally sited data centers as protecting against unauthorised cross-border transfers; and the chief executive states on the security page that data stored in the client's own country and jurisdiction eliminates the risk of interference with foreign legislation such as the CLOUD Act.
That is a vendor making resistance to government access a selling point. The privacy policy addresses the other side of the same question for the data it governs, stating that the vendor will refuse government and law enforcement requests it believes unfounded, too broad or unrelated to their stated purpose, while reserving the right to cooperate where it believes disclosure necessary and appropriate to comply with legal process.
What appears nowhere, in either place, is any commitment or reservation about telling the customer. Nothing says the customer would be notified of a demand, given an opportunity to object or seek a protective order, or informed afterwards. No transparency report was located. The asymmetry is the finding: extensive published assurance about which governments cannot reach the data, and silence on what happens when one lawfully can.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies a legal corpus behind the product's AI, and the product is not built on one: Athennian AI extracts data from the customer's own governance documents and answers questions about the customer's entities; the vendor's global compliance guides are editorial content rather than a retrieval corpus for the AI. AI pages checked 6 September 2026.
The material behind the models is described by category and no individual source is named, which is this value, and the shape needs stating because it is not the usual one. This product answers from the customer's own documents rather than from a legal corpus, so the signal's usual object, a body of primary law with a licensing position, does not exist here. What the vendor does publish, and what is graded, is the provenance of its training material, and it is more than most disclose.
The AI Code of Conduct states that the models are trained on synthetic data, publicly available datasets and the vendor's own sovereign knowledge base, combined into an internally-built private synthetic legal dataset covering multiple legal use cases. It goes further on the foundation, stating that the vendor pre-finetunes and finetunes its legal-specific language model using the most advanced open-source and commercially permissible models available.
That phrase is a licensing posture and is recorded as one: it says the base models were licensed for commercial use. What is not published is any individual source. No dataset, no publisher, no jurisdiction and no code or corpus is named, the sovereign knowledge base is not described, and no license is stated for the publicly available datasets, which is the category where a provenance question would ordinarily bite hardest.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history, and the product does not retrieve or cite primary law; its output is entity data, structure charts and governance documents. Recorded as the honest value for a product without a citator function. Surfaces checked 6 September 2026.
No located public material addresses whether authority is checked for subsequent history, and on this product the question does not arise in its usual form. Nothing in the suite cites law. The seven Lini capabilities work on the customer's own material: transcribing board audio, drafting minutes from an agenda and its papers, extracting terms and dates from contracts, summarizing documents the customer uploaded, detecting risky clauses against the customer's own compliance rules, and snapshotting a matter's status.
None produces a proposition about the state of the law whose treatment a lawyer would verify, so R15 governs and the limb is recorded as inapplicable rather than failed. One adjacency is named so it is not mistaken for the thing: Risk Detector applies the firm's playbooks and suggests compliant alternatives, which is currency against an internal policy rather than currency of a legal authority, and it is graded on the citation accuracy row.
A second is worth recording because it is the closest real analog on this estate. The Entity Management module synchronizes with official registries through a named partner integration and the vendor presents that as reducing the risk of outdated or inconsistent records, which is a currency mechanism for corporate registry data rather than for case law. The surfaces read on the date shown were the Lini feature page, the AI Code of Conduct, the security documentation and the integrations page.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
An explicit path for what the model cannot resolve is described: the capabilities page states that anomalies and missing data points are surfaced for review, and the AI Terms require human review of all output before reliance. The behavior is described rather than demonstrated, and no confidence threshold at which extraction is withheld is stated. Capabilities page and AI Terms checked 6 September 2026.
No located public material describes what the system does when it cannot produce a reliable answer. The surfaces where it would appear were read in full on the date shown: the Lini feature page with all seven capability descriptions, the AI Code of Conduct including its section on how the AI works, the security documentation and the integrations page. None states that any feature declines a request, flags low confidence, surfaces uncertainty in a draft, or puts an ambiguous input back to the user.
The published account of the runtime path is unusually detailed and runs from user request to results delivered without a branch: there is no described case in which the system returns nothing or returns a caveat. Two things sit nearby and neither is credited. The code commits to transparency in the sense of making AI processes understandable and providing clear documentation and insight into how decisions are made, which is an explainability commitment about the system in general rather than a behavior at the point of answering.
And the commitment that critical decisions always involve human oversight places the uncertainty burden on the user rather than describing a system behavior, and is graded on the autonomy row. The gap has a specific edge on this product: Minutes Generation drafts the record of what a board decided, and nothing published indicates whether the system signals where the source material was thin or the discussion ambiguous.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record naming Athennian or Paper Interactive was located as of 6 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on the name together with a general search for court findings; results returned a Sixth Circuit sanctions matter concerning unnamed generative tools and no record naming this product. This is a statement about the public record, not a finding about the product; an entity management tool that cites no authority carries a remote exposure on this signal.
Searched on 12 September 2026, on the company name and on the AI engine name, against published trackers and coverage of decisions on AI-generated fabricated citations, including coverage of the Damien Charlotin AI Hallucination Cases database and reporting on the 2025 and 2026 sanctions decisions across United States federal and state courts and other jurisdictions. None located. Under R119 this signal records fabricated citations and nothing else, so it is not a litigation history and no other proceeding involving the vendor would appear here.
One point of context is recorded because it bears on how the absence should be read rather than on the vendor's conduct: the exposure this signal tracks arises where a product generates legal authority for filing, and nothing in this suite does. Its outputs are board minutes, contract extractions, clause suggestions, document summaries and matter snapshots, all drawn from the customer's own material. The analogous failure here would be a fabricated term in an extraction or a misstated resolution in generated minutes, which no tracker records and which would surface, if at all, as a corporate governance dispute rather than as a sanctions order.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material names an ethics opinion, bar rule or professional responsibility framework. The AI Terms address human oversight and accurate representation of output, and the vendor publishes UBO and global compliance guides on corporate law, but no guidance from any bar or regulator on lawyers' use of AI is named on the surfaces read. AI Terms and navigation checked 6 September 2026.
No located public material engages with bar or ethics guidance, in general terms or otherwise. No bar opinion is named anywhere on the estate, no professional conduct rule of any jurisdiction is cited, and nothing maps a product or an AI feature to the obligations of the lawyers using it. Nor is professional responsibility engaged generically: there is no requirement that the customer use the platform consistently with its professional obligations, which is the clause that would ordinarily sit in a customer agreement, and no customer agreement is published.
The absence is worth distinguishing from a lack of regulatory engagement, because the vendor engages regulation heavily and that makes the gap sharper rather than softer. The AI Code of Conduct claims alignment with the European AI Act, commits to GDPR compliance and privacy by design, and the estate carries a dedicated page on the DORA regime. Those are regulatory instruments binding on the customer as an enterprise.
What is missing is the separate body of rules binding on the customer as a lawyer. The point bites on a specific output: minutes of a board meeting drafted by a model and signed by a company secretary sit inside the corporate secretarial duties that professional bodies in several of this vendor's ten territories regulate, and nothing published addresses that.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Professional services firms are a named buyer segment alongside in-house legal, tax and finance teams, and the published position on the bill is a savings claim: more than a hundred and twenty hours saved per year and a ninety percent reduction in document filing time. Nothing addresses how AI-assisted entity work is recorded or disclosed on a client's bill where a firm uses the product for its clients. AI landing page and navigation checked 6 September 2026.
The product sits outside a lawyer-to-client fee relationship, which is this value, and the reasoning is worth setting out because the vendor makes savings claims that could be mistaken for the thing this signal measures. The buyer here is a corporate legal department or a board secretariat, and the lawyers using the product are employees of the company they advise. There is no bill to a client, so the question this signal asks, what happens to the bill when the work takes an hour instead of six, has no addressee: time the AI saves accrues to the company's own operating cost, not to a fee a client pays.
The savings claims are extensive and are recorded rather than credited against the wrong question, taking the form of five published return-on-investment calculators, one for the suite and one for each of contract lifecycle management, board management, matter management and entity management, which invite a prospect to model its own time and money saved. Two boundary facts are recorded. The Matter Management module tracks the cost of disputes, which is outside counsel spend viewed from the payer's side, and nothing published connects it to AI-assisted work or to disclosure.
And the vendor acquired an enterprise legal management business in 2024, a product class that sits closer to the fee relationship; nothing located indicates that capability has reached this suite, and if it does the value should be revisited.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A sub-processor list, a model provider statement and client-facing disclosure material are published without an agreement in place. The AI Terms name Google and Amazon as model providers and point to a published sub-processor list at a stated URL for the rest, the DPA is published in the legal portal with CCPA and standard contractual clause references, and the AI Terms themselves are a forwardable statement of who sees client content and on what conditions.
The sub-processor list page was not opened on 6 September 2026, so its completeness is stated on the AI Terms' description of it.
A forwardable pack exists, is ungated, and answers the model-provider question, which is this value, though it is reached by an unusual route and the gap in it is named. The client-facing artifact is the AI Code of Conduct, published as a PDF the vendor expressly invites readers to download and share with colleagues, sitting alongside an ungated Security Sheet consolidating the implemented measures and downloadable ISO 27001 and ISO 27701 certificates.
That is material drafted to be handed on, which is what R29 means by a consent or notification pack. The model-provider question is answered emphatically rather than by a list: the vendor states that its models are designed and trained exclusively by its own teams, that processing happens on its local infrastructure, and that personal data is processed without any third-party sharing, so a firm asked which third party sees its content can answer that on the vendor's account there is none.
The interoperability section adds that any third-party model in play would be one the customer itself connected. The gap is the platform-level register. No sub-processor list is published for hosting, monitoring, storage or support, so while the AI supply chain is accounted for, the infrastructure around it is not, and a client demanding a full sub-processor schedule would have to ask. Recorded as the artifact that would complete the pack.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of a record are available and no export of an AI-use record is described. The AI landing page states that every step of the AI workflow is tracked, reported and transparent and that human verification is retained, and the platform keeps audit history of entity changes; nothing states that a record of the model used and the human verification can be exported for a court, and the product's outputs are governance records rather than court filings. AI landing page checked 6 September 2026.
No located public material addresses disclosure of AI involvement, and the note records two published features that come close without being it. The first is the audit trail, described as maintaining visibility and traceability of user activities and system events, tracking interactions and data changes in real time to detect and investigate incidents, maintain compliance and ensure data integrity. It is a genuine record of who did what and when, and it is not credited here because nothing states that it identifies which passages a model produced, distinguishes machine-drafted from human-edited text, or survives export in a form anyone outside the organization could rely on.
The second is watermarking, which stamps each document uniquely for traceability against unauthorised sharing; that is a provenance mechanism aimed at leakage rather than at authorship. Nothing published provides a disclosure template, a certification, a model identifier attached to output, or an export designed for a tribunal or a regulator. The gap has a concrete edge on this product and it is not the courtroom. Minutes generated by a model become the formal record of a board's decisions, relied on by auditors, regulators and, in a dispute, by a court; if the question later arose whether a passage recording a resolution was drafted by a person or a model, nothing published would let the company establish which.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Good Law Verification
- Bar Guidance Alignment
Which one fits
Choose Athennian if
- You want the training bar in the contract, covering the model providers too. Athennian's AI terms, part of its services agreement, state that neither Athennian nor its model providers may use customer data to train any model, and name Google Gemini and Amazon Bedrock among those providers.
- Your entity data must flow to other systems. Athennian offers a two way API with public developer documentation and developer terms, alongside Microsoft 365, electronic signature and document management integrations.
- You manage entities across many countries for legal, tax and treasury teams. Athennian states more than 500,000 entities managed across 150 countries, publishes global compliance guides, and its AI extracts governance data from uploaded documents and flags anomalies and missing data for review.
Choose DiliTrust if
- You want board, contract, entity and matter work in one suite. DiliTrust combines a board portal, contract management, entity management, matter management and a dataroom, with its Lini AI drafting board minutes, transcribing meetings, extracting contract terms and flagging risky clauses.
- Your procurement team wants certificates without a sales call. DiliTrust publishes its ISO 27001 and ISO 27701 certificates, dated 23 February 2026, and a Spanish ENS certificate as downloads, with a security sheet and its AI code of conduct, and offers its SOC 2 Type 2 report on request.
- Data sovereignty matters to your board. DiliTrust states that its data centers sit in the regions where clients operate, that its AI runs on its own infrastructure without third party sharing of personal data, and that organizations can connect their own language models through its API.
In summary
Athennian
Athennian, from Paper Interactive, Inc. of Calgary, Alberta, doing business as Athennian, is an entity management platform for in house legal, tax, treasury and finance teams at corporate groups and private markets firms, and for the professional firms that serve them. It holds entity and people records, ownership structures and charts, appointments, documents and compliance tasks across jurisdictions, and its AI extracts governance data from uploaded documents and answers governance questions under human review. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes. Its published AI terms bar training on customer data and name Google and Amazon as model providers. As of 6 September 2026 the index located no named customer, accuracy measure or published price figure.
DiliTrust
DiliTrust, from DiliTrust SAS of Paris La Defense, sells in house legal departments and corporate boards an integrated suite of five modules: a board portal, contract management, entity management, matter management and a dataroom. Its AI engine, Lini, drafts board minutes, transcribes meetings, extracts contract terms, summarizes documents and flags risky clauses. The AI Legal Index grades it in the top two bands on eleven of fifteen capability axes, with an A on security certifications. It publishes an AI code of conduct and downloadable ISO certificates, states that its models are its own and run in regional data centers, and names customers including BNP Paribas and LVMH. As of 12 September 2026 the index located no customer agreement, named model or price.
Questions buyers ask
Athennian vs DiliTrust: which is better for entity management?
The grid barely separates them: DiliTrust sits in the top two bands on eleven of fifteen AI Legal Index capability axes and Athennian on ten of fifteen, identical on ten. Athennian is a dedicated entity management platform with published AI terms and a two way API. DiliTrust adds a board portal, contracts and matters in one suite and publishes its certificates. Teams that want terms in writing have more to read from Athennian.
Does Athennian train AI on customer data?
No, by contract. Section 9 of Athennian's AI terms, updated 14 April 2026 and part of its services agreement, states that Athennian does not use, and does not permit its model providers to use, customer data to train any AI or machine learning model, and it defines input and output as customer data. DiliTrust describes its training data as synthetic, public and its own, with no customer agreement published. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Is DiliTrust subject to the US CLOUD Act?
DiliTrust's AI code of conduct states that its AI solutions are not subject to the US CLOUD Act, except for US clients, and that its data centers sit in the regions where clients operate. Its privacy policy says it will refuse government requests it considers unfounded or too broad. Nothing published commits it to tell a customer when its data is demanded. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Which AI models do Athennian and DiliTrust use?
Athennian's AI terms name Google Gemini and Amazon Bedrock among its model providers and point to a published subprocessor list for others. DiliTrust states that its models are designed and trained by its own teams, fine tuned from open source and commercially permissible models it does not name, and lets organizations connect their own language models through its API. Neither names a specific model or version. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What do Athennian and DiliTrust both leave unpublished?
A measured accuracy figure and any view on professional duties. Neither publishes a test or error rate for its extraction, summaries or drafting, and neither addresses privilege or work product in the board minutes and governance records it holds. Neither names bar guidance on AI, and neither states how long AI prompts and outputs are kept. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Three readings to weigh. DiliTrust publishes no customer agreement, so its commitments on training, data handling and liability rest on a code of conduct and product pages rather than a term a buyer signs. Its models are fine tuned from open source models it does not name. Athennian's service terms were read only in part and its pricing page was not opened, so its liability cap and price are not established here. Athennian was verified on 6 September 2026 and DiliTrust on 12 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.