DecoverAI vs Discernis: how they compare in 2026
DecoverAI and Discernis both run their AI across every document in a collection to call responsiveness and privilege, explain each call, and hand the result to a reviewer to confirm or override. DecoverAI sits in the top two bands on fourteen of fifteen axes and Discernis on eight of fifteen. DecoverAI's lead is written into its terms: a clause barring training on customer data without written consent, a statement that nothing in the agreement waives privilege, named ABA Model Rules on competence and confidentiality, breach notice within 72 hours, and a dated subprocessor list naming each AI provider. Discernis states its data commitments in an FAQ rather than its terms, which date from May 2024 and carry no training or confidentiality clause. Discernis answers on where the AI runs. It builds and hosts its own models, calls no outside AI service, and runs in its own cloud, a private cloud, on the customer's premises or air gapped, with the hardware for a local installation published. DecoverAI's inference goes to OpenAI, Anthropic and Google, partly through a routing layer that does not disclose the model behind each request.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The machine learning is the mechanism the buyer pays for. Classification for responsiveness, privilege and confidentiality is what compresses the review, and every downstream artifact depends on it: the privilege log is generated from the AI's privilege calls, redaction is driven by automated detection with attorney override, and the headline claim is 80 per cent less review because the model triages every document. The company markets a webinar on how it post-trains an LLM to run document review at under five cents a document, which is a statement that the model is the product rather than a feature on one. Remove the models and what remains is document storage with Bates numbering. Checked 4 September 2026.
The models are the product. Discernis Discovery takes the questions from a review protocol and has the company's own models read every document in the collection, assess its responsiveness, prioritise it, flag likely privileged communications and explain each call; Discernis Investigations reads the same kind of collection against chosen topics to build timelines and map parties. The FAQ states that the company builds and hosts its own models rather than calling an outside AI service, and the pricing, deployment options and review workflow are all organised around that model output. Take the models away and there is nothing left to buy. Verified 22 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real and documented at the supplier level, which is unusual and more useful than most architecture claims. The published subprocessor list names Parallel Web Systems for web search grounding of AI-generated answers and citations, Cohere for search result re-ranking to improve relevance, and UniCourt for legal case-law and litigation research data feeding AI-assisted legal research features. A reader can therefore see what the answers are grounded in and which supplier provides each part. Failure modes are named in the agreement rather than avoided: clause 13.5 refers expressly to incorrect, inaccurate or hallucinated information generated by the AI features, including case citations and regulatory references. What is missing is measurement. No accuracy figure is published anywhere, no test set is described, and no evaluation is linked. A white paper on AI review defensibility is published but was not opened in this pass and is not credited for its contents.
Each tag is tied to the document it describes and carries the model's explanation, which reviewers check in a side pane, and results export with a score and an explanation for every responsive document. The product reads every document in the collection rather than retrieving a sample. Accuracy figures are published but cannot be tested from outside: the FAQ states about 99 per cent accuracy with recall above 95 per cent and precision above 90 per cent, and says inter-annotator agreement is indistinguishable from top reviewers, while the Discovery product overview gives about 95 per cent or more on relevance classification, about 90 per cent precision and about 95 per cent recall. Neither set of figures describes a test set, matter type, sample size or date, and no failure modes are named. Verified 22 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A written commitment that the models work alongside a supervising lawyer, with real review surfaces. The product position is that every classification is reviewable and every redaction overridable, with redactions burned without touching originals so the underlying document survives an override. The commitment is contractual as well as marketing: clause 2.5 makes the customer solely responsible for supervising and verifying all AI-generated outputs before professional reliance, and clause 13.5 requires independent review and verification by a licensed attorney. Clause 4.3 keeps access and activity logs for at least twelve months and makes them available on written request, which is a real oversight surface rather than a claim. What is absent is the rest of the control structure: no threshold is published at which the system stops or escalates, no confidence signal is described as visible to the reviewer, and nothing states what happens after a misclassification is found beyond the customer's own override.
The models run first-pass review across the whole collection on their own, and the review surfaces around them are real. The FAQ states that reviewers can override or correct any AI suggestion, that a built-in quality-control workflow validates the AI tags, that a side pane shows each AI answer for human validation, and that an audit log records extraction, editing and validation by date, time and person and cannot be edited by users. The home page presents the explanations as the basis for a second-pass human review. What is not published is the rest of the control structure: no threshold at which a document is routed to a person rather than tagged, no statement of what the output may not be relied on for without review, and nothing on what happens when a tag proves wrong. Verified 22 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Deployment evidence with unusually tight attribution, held below the top band by the absence of dates. Six case studies are published and three name the firm: Clayton Trial Lawyers, with a 15.4 million dollar jury verdict after a five-week trial; Schaff Law Group, with more than 100 hours saved on case preparation; and Gregor Wynne Arney PLLC, processing more than a million documents in a 35 million dollar healthcare fraud and anti-kickback investigation. Three further studies carry figures without the firm named, including 30,000 documents produced in three days saving 147,000 dollars and 25 days, a production remediation of more than 360,000 documents resolving six of six defects under federal scrutiny, and a construction defect matter covering a terabyte across three buildings. Unlike most records on this axis the figures are attached to the named firms rather than floating free, which is the limb this band usually fails. No case study carries a date, no methodology is stated on the summary cards, and the case study pages were not opened in this pass, so they are credited for existing and for the attribution visible on the index rather than for their contents.
Results are quoted with no basis stated. The home page claims 90 per cent faster review, 70 per cent lower cost and about 99 per cent accuracy; the law firm page claims a 40 to 50 per cent cost reduction; and the funding announcement of 25 August 2026 says the product is in use at Am Law firms on active matters. No customer is named, no matter or date is attached to any figure, and no method is given for how the savings were measured. No named case study was located on the case studies page, in the newsroom or on the blog. Checked the home page, both product pages, the law firm page, the case studies page, the Discovery product overview, the newsroom and the blog on 22 September 2026. Verified 22 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Every limb is met and the privilege limb, which is the one this axis exists for, is met directly rather than by implication. Clause 7.3 states that DecoverAI treats all Customer Data as Confidential Information and that nothing in the agreement constitutes a waiver of any legal privilege or protection applicable to it. Clause 10.4 goes further: Customer Data constituting Privileged Information is afforded the highest level of protection, DecoverAI personnel are instructed not to review Customer Data except as strictly necessary for technical support and only with the customer's prior authorisation, and all personnel with potential access are bound by written confidentiality obligations. Training is prohibited by clause 7.9 absent prior written consent. Segregation is documented at the level a firm needs, with single-tenant deployment, private VPC, an option to deploy inside the customer's own VPC, role-based access control on least privilege, and processing described as taking place in isolated environments destroyed once the job completes. Retention and deletion are specific under clause 7.10, with irreversible deletion and written certification available. The position on model providers is the most complete in this pull: nine AI and machine learning subprocessors are named individually with the function each performs and the country it operates in.
The confidentiality commitments sit in the FAQ and on the home page, not in the published terms. The FAQ says no data is retained for training and that data is removed from all systems within 30 days of a user deleting it; the home page says the company builds and hosts its own models so documents are never sent to outside AI companies; and the platform can run on the customer's own premises or air-gapped, which keeps documents inside the customer's control. The published Terms of Use, last updated 1 May 2024, carry none of this: they contain no confidentiality or training term, state that the company may access, store, process and use any information and personal data a user provides, and say the Services are not tailored to comply with HIPAA, while the FAQ states HIPAA compliance. Nothing is published on privilege or work product handling, or on separation between matters or users. Verified 22 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
The professional responsibility treatment is the most specific located in this pull and it sits in the agreement rather than in a footer. Clause 2.5 states plainly that the Services are productivity tools and do not constitute legal advice, and names the duties engaged: competence under ABA Model Rule 1.1, confidentiality under ABA Model Rule 1.6, and supervision. Clause 11.4 states in terms that the Services are not a substitute for professional legal judgment and that no content generated constitutes legal advice. Clause 13.5 requires independent review and verification by a licensed attorney before professional reliance and puts the risk of unverified reliance on the customer. Clause 4.4 goes to a question most vendors ignore, requiring the customer to warrant it has obtained any client consent required under bar rules or ethics opinions governing cloud-based legal technology. Clause 2.3 prohibits use in violation of applicable professional responsibility rules and bar regulations. The one limb not squarely met is a stated jurisdiction limit for substantive coverage, which bites weakly on a product that operates on the customer's own document set rather than on jurisdiction-specific law; the named authorities are American and the agreement is governed by California law.
Checked the home page, both product pages, the FAQ, the Terms of Use, the Privacy Notice, the Discovery product overview and the blog on 22 September 2026. Nothing states what the product is and is not, that its tags and explanations are not legal advice or a substitute for a lawyer's judgement, or who may use it, and the Terms of Use carry no advice disclaimer. The blog advises in-house counsel to keep meaningful, documented oversight of AI findings and calls private deployment a professional responsibility requirement, which is guidance to buyers rather than a statement about this product. The Investigations product is marketed for HR complaints and staff-activity reviews as well as legal matters, and no audience limit is stated for it. Verified 22 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
This is the weakest disclosure on an otherwise strong record. No AI governance framework is published: nobody inside DecoverHQ is named as accountable for model behaviour, no pre-release evaluation regime is described, no testing results are published, and there is nothing at all on bias or uneven output, which matters more than usual on a product whose core function is classifying documents as responsive or privileged. What exists is adjacent rather than on point: SOC 2 Type II covers security, availability and confidentiality; controls are said to be monitored continuously and published live in a trust centre; and a white paper on what courts expect from AI-assisted document review is published but was not opened. Security certification is a different subject from AI governance and is credited on its own axis rather than here.
The product explains every tag it makes, and the FAQ says the company measures its models against human reviewers, including inter-annotator agreement. That is the extent of it: no governance framework, accountable owner, pre-release testing regime or bias finding is published. The gap matters most on the Investigations product, which is marketed for HR discrimination complaints and for reviewing staff activity for signs of burnout and disengagement after layoffs, uses where uneven output across groups of people is the central risk, and no statement addresses it. Checked the home page, both product pages, the FAQ, the Terms of Use, the Privacy Notice and the blog on 22 September 2026. Verified 22 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
The full set is published, current and specific enough to hold the vendor to. Retention is a stated period rather than a gesture: clause 7.10 retains Customer Data for the subscription term plus thirty days for export, then irreversibly deletes or destroys it, with written certification of deletion on request, and clause 7.7 lets the customer request removal at any time with a thirty-day processing commitment. Access control under clause 7.4 covers TLS 1.2 or higher in transit, AES-256 or equivalent at rest, role-based access and least privilege for DecoverAI personnel, and regular penetration testing and vulnerability scanning by independent third parties. Incident practice is contractual: clause 3.5 commits to notifying the customer of any confirmed security breach affecting Customer Data within seventy-two hours of confirmation. The subprocessor position is exceptional, with a dated and versioned public list naming every provider, its function and its country, thirty days' prior written notice before any addition, and a subscribable change-notification list. Clause 4.3 retains access logs for at least twelve months and releases them on request, and clause 7.11 gives an annual customer audit right.
The FAQ answers the questions that matter for documents under review: nothing is retained for training, data is removed from all systems within 30 days of a user deleting it, hosting defaults to a US-based Azure cloud with other regions or clouds available on request, the platform can run on premises or air-gapped so documents never leave the customer, and an audit log records every extraction, edit and validation by person and time and cannot be altered by users. What is missing is a named subprocessor list and any stated incident or breach notification practice. The Privacy Notice, last updated 1 May 2024, covers website visitors and account details and does not address documents loaded for review. A trust centre is linked from the FAQ; it could not be opened on 22 September 2026, so its contents are not reflected here. Verified 22 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A real published position on liability, and the shortfall is the subject rather than the structure. What is present is substantial: clause 12.1 gives an intellectual property indemnity covering patent, copyright, trademark and trade secret claims with five named exclusions at 12.3 and remedies at 12.2; clause 13.2 caps each party at twelve months of fees; clause 13.3 lifts that cap entirely for breach of confidentiality, gross negligence or wilful misconduct, and for DecoverAI's own indemnity obligations, which leaves confidentiality breach uncapped; clause 11.2 gives six warranties including that the Services will perform materially in accordance with the Documentation and, unusually, that DecoverAI maintains SOC 2 Type II certification, which converts a marketing claim into a contractual promise; and clause 14.1 commits to 99.9 per cent uptime with service credits. No insurance position was located. What holds this off the top band is clause 13.5, which disclaims liability under any theory for incorrect, inaccurate or hallucinated information generated by the AI features, naming case citations and regulatory references among them, and places all risk of reliance on the customer. The allocation is published and unusually clear, and on the question this axis asks the published answer is that the vendor stands behind nothing when the output is wrong.
Liability is handled only by the standard clauses of the Terms of Use, last updated 1 May 2024. The Services are provided as is, with all warranties disclaimed, including any warranty on the accuracy or completeness of content; the company's liability is capped at the amount paid in the six months before the claim arose; and the user indemnifies the company, with no indemnity running the other way. The Discovery product overview carries the heading Remarkable Accuracy, Guaranteed, but no guarantee terms are published anywhere, and the terms themselves disclaim accuracy. Verified 22 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Documented integrations into the systems litigation work actually lives in, with direction and configuration described. The subprocessor page lists customer-authorised connections individually: Microsoft SharePoint, OneDrive and Microsoft 365 through the Graph API, Google Drive and Gmail, Dropbox, Box, customer-owned Amazon S3 buckets, and two legal-specific systems that matter here, iManage and Clio. The same page describes the direction of travel and who controls it, stating that DecoverAI accesses those sources solely at the customer's direction and under the customer's own agreement with that provider, and that the connections are configured by the customer rather than engaged by DecoverAI on its own behalf. Appendix A of the agreement records connectors to document management systems, email platforms and cloud storage providers as a contracted service element specified in the Order Form. Naming iManage and Clio is what distinguishes this from generic cloud connectivity: those are the systems a firm's matter files already sit in.
No integration with a review platform, document management system or matter system is named. Data moves in and out by file: the FAQ says the platform accepts load files, .dat files and native files, and exports load files, .dat files and a CSV listing responsive documents with their scores and explanations, with no ingestion or export fees. That keeps it compatible with the load file exchange review platforms already use, but a firm moving work between Discernis and its existing systems does so by export and import rather than through a connection. Checked the home page, both product pages, the FAQ and the Discovery product overview on 22 September 2026. Verified 22 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The deployment model is stated clearly and offered in tiers, with residency detail that is partial rather than absent. Three postures are published: default multi-tenant, single-tenant with dedicated infrastructure, and deployment inside the customer's own VPC for organisations requiring full isolation, with AES-256 at rest and TLS 1.2 or higher in transit across all of them and processing described as taking place in isolated environments destroyed when the job completes. That publishes both the tenancy limb and what changes between tiers. Residency is answerable only indirectly: the subprocessor list gives a country for every provider, placing AWS hosting and storage in the United States, optical character recognition with Mistral AI in France, and search re-ranking with Cohere in Canada, which distinguishes where processing happens from where data is stored. What is not published is a residency offering: no region is named as available or selectable, and nothing states that a customer can require its data to remain in a given jurisdiction.
Deployment and residency are published in detail. The product overview names three options, Discernis Cloud, Discernis Private Cloud and on-premises, and the FAQ adds air-gapped installation, deployment on any Kubernetes cluster and any major cloud provider, naming Google Cloud, AWS and Azure; the home page states full functionality in each. Hosted data sits in a US-based Azure cloud by default, and the company will deploy to any region or other cloud on request. Processing is stated separately from storage: the funding announcement says all inference runs inside the environment the customer chooses, with no third-party or commercial AI service called, and the FAQ publishes the compute a local deployment needs, about 32 CPUs, 128 GB of RAM, 2 TB of storage and eight H100 GPUs for a terabyte of data a month. Cloud offerings scale with demand, while local throughput depends on the compute allocated. Verified 22 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real, stated, and scoped, which is more than most records in this band carry. SOC 2 Type II is claimed with the trust services criteria named as security, availability and confidentiality, and with the distinction drawn that it is verified over an observation period rather than at a single point in time. HIPAA compliance is claimed with a Business Associate Agreement available on request. Clause 11.2(f) warrants on an ongoing basis that DecoverAI maintains SOC 2 Type II certification, and clause 7.11 gives an annual audit right that DecoverAI may satisfy by producing its most recent SOC 2 Type II report and third-party penetration testing summary. A trust centre operates at trust.decover.ai and is said to publish control monitoring live; it was not opened in this pass and is credited for existing rather than for its contents. What is missing is the accessible evidence: no auditor or certification body is named, no report date or observation period is published, and the full report is available only under NDA. Applying the third-party verifiability test, a buyer cannot check the claim against the auditor without contacting DecoverAI. GDPR is described as certification in progress, which is intent and is credited to nothing.
No independent security attestation is held. The FAQ states compliance with HIPAA, which has no certification scheme of its own, and says the company is working to finalise ISO 27001 and SOC 2; neither is claimed as achieved, and no auditor, scope or date is given. The published Terms of Use, by contrast, say the Services are not tailored to comply with HIPAA and may not be used where HIPAA applies. A trust centre is linked from the FAQ; it could not be opened on 22 September 2026, so its contents are not reflected here. Verified 22 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The most granular supply chain disclosure located in this pull. The published subprocessor list, dated August 2026 and version-numbered, names nine artificial intelligence and machine learning providers individually, states what each one does, and gives the country it operates in: OpenAI, Anthropic and Google under its Gemini API for model inference across document analysis, classification and question answering, all in the United States; OpenRouter as a routing layer used to reach additional supported models; Mistral AI in France for optical character recognition of scanned documents; Cohere in Canada for search result re-ranking; E2B for sandboxed isolated code execution supporting agent workflows; Parallel Web Systems for web search grounding of answers and citations; and UniCourt for case-law and litigation research data. AWS is separately identified for hosting, storage, database, managed search, authentication and content delivery. Change notification is committed at thirty days' prior written notice before any addition, with a subscribable notification list, and clause 7.5 of the agreement repeats it. The one limb only partly satisfied is model naming: Gemini is identified as a model family and the rest are named at provider level, and the OpenRouter routing layer means the specific model behind a given request is not disclosed. Adjudicated to B on 4 September 2026 under R34: provider identification and model naming are separate limbs of the A band, and the second is not met. The routing layer makes the gap structural rather than an omission, since the model behind a given request is undisclosed by design.
The FAQ states that the company builds and hosts its own models, purpose-built for discovery, and the funding announcement says no third-party or commercial AI service is called at any point, with inference running inside the deployment the customer chooses and hosted by default on a US-based Azure cloud. The architecture, and any base model the proprietary models are built from, is not identified, and no commitment to notify customers when the models change is published. Verified 22 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
A buyer can learn what this costs without speaking to anyone. The rate is published as 60 US dollars per gigabyte per month, described as all-in with no seat fees, no enterprise tier and no contract required, and the page states what that covers: AI classification for responsiveness, privilege and confidentiality, automated redaction detection with attorney override, an auto-generated privilege log as a spreadsheet, Bates numbering to firm conventions, a full audit trail for regulatory productions, and SOC 2 compliant encrypted hosting. A second unit is published alongside it at two cents per document, with a worked illustration that most teams process five to twenty gigabytes per matter for a 300 to 1,200 dollar all-in cost, and a cost estimator tool is offered on the site. Self-serve signup is available. One tension is recorded rather than smoothed over: the marketing says no contracts and no seat fees, while the agreement contemplates Order Forms with authorised user seats, service capacity limits, overage rates, annual invoicing in advance, sixty-day non-renewal notice and fees due through the end of the subscription term. Both are published and a buyer should read both.
The unit and structure are published without a figure. The Discovery page states per-document pricing with no per-gigabyte, per-user or storage charges; the FAQ adds no ingestion or export fees; the pricing page offers matter and annual pricing options, fast setup and cancellation at any time; and the Terms of Use describe a monthly subscription that renews automatically. A blog post explains that the per-document price is meant to be quoted before a matter starts. No rate is published, and the law firm page describes the offer as having no per-document charges, which conflicts with the per-document unit stated on the Discovery page and in the pricing blog post. Verified 22 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described with substance across two dimensions and its outer edge is left open. Four stages of the litigation lifecycle each carry their own page: eDiscovery, early case assessment, internal investigations covering cyber breaches, whistleblower actions, subpoenas and regulatory inquiries, and trial preparation. Matter types are evidenced rather than claimed, through case studies spanning commercial litigation, personal injury, white collar crime, a tax credit investigation, a federal production remediation and a multi-party construction defect matter. The buyer is stated as law firms and in-house legal teams, and HIPAA is positioned specifically as the baseline for personal injury, medical malpractice and healthcare investigation matters. Clause 2.4 addresses United States Government use rights under FAR and DFAR, which is a segment most vendors leave silent. What is missing is the boundary: no firm size is stated, no matter volume floor or ceiling is given, and nothing says which matter types or data types the product does not handle.
The buyer segments are set out on separate pages for in-house legal departments, law firms and legal service providers, and the use is clear: first-pass responsiveness and privilege review in litigation discovery, and fact-finding in internal investigations, compliance reviews and case strategy. Where the product stops is not stated: no document types, matter sizes or practice areas are named as unsupported, and the Investigations examples reach beyond legal work into HR, manufacturing and operational risk. Verified 22 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Clause 7.9 of the published agreement, headed No Training on Customer Data, provides that DecoverAI will not use Customer Data or Inputs to train, fine-tune or improve any artificial intelligence or machine learning model without the customer's prior written consent, and adds that its models are trained exclusively on licensed datasets and public information sources. The consent gate is what decides the value: training is prohibited by default and can occur only where the customer affirmatively agrees in writing, which is opt-in rather than an unqualified prohibition.
Clause 7.6 is consistent, licensing Inputs and Customer Data solely to operate the Services, address technical problems and meet legal obligations, and expressly withholding any commercial purpose unrelated to the Services absent prior written consent. Recorded for completeness: the home page states the position more absolutely than the agreement does, as your data never trains our models, without the consent carve-out.
The FAQ answers no to whether any data is retained for training, and the home page says the company builds and hosts its own models so documents are never sent to outside AI companies. The published Terms of Use, last updated 1 May 2024, carry no training term in either direction: they state that the company may access, store, process and use any information and personal data a user provides, without naming training. The commitment a buyer can read sits on a policy page, not in the agreement.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Clause 7.10 publishes a specific window: Customer Data is retained for the subscription term plus thirty days, during which the customer may export, after which DecoverAI irreversibly deletes or destroys it except where law requires retention, with written certification of deletion available on request. The customer controls that window by contractual instruction rather than being fixed to it, because clause 7.7 allows removal of Customer Data from the Services to be requested in writing at any time, with DecoverAI committing to process such requests within thirty days.
Zero retention is not stated as an available setting, although the security material describes documents being processed in isolated environments that are destroyed once the job completes.
The customer controls how long documents stay: the FAQ says data is completely removed from all systems within 30 days of a user deleting it, and on-premises or air-gapped deployments keep the collection inside the customer's own environment. A setting that retains nothing is not described. The Privacy Notice keeps account information for as long as an account exists, and addresses website and account data rather than documents under review.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
DecoverAI maintains its own documented permission and isolation model rather than inheriting a source system's access control at query time. Published detail covers single-tenant deployment and private VPC, with dedicated infrastructure or deployment inside the customer's own VPC for organizations requiring full isolation, AES-256 at rest and TLS 1.2 or higher in transit by default, enterprise single sign-on through the customer's own identity provider, role-based access controls and enforced multi-factor authentication.
Clause 7.4 adds role-based access and least privilege for DecoverAI personnel, and clause 10.4 restricts personnel from reviewing Customer Data except as strictly necessary for technical support and only with the customer's prior authorization. The customer administers its own Authorized User access under clauses 2.2 and 3.2, which is the alignment burden this value describes. No material addresses segregation between separate matters inside one customer account.
Checked the home page, both product pages, the FAQ, the Terms of Use, the Privacy Notice and the Discovery product overview on 22 September 2026. No material addresses ethical walls or separation between matters or users within an account. The FAQ describes an audit log of who extracted, edited and validated what, and an on-premises deployment leaves access to the system with the customer, but neither is a published permission model at the matter level.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Clause 10.3, headed Compelled Disclosure, commits that a party required by law or court order to disclose the other's Confidential Information will provide prompt written notice where legally permissible, cooperate in seeking a protective order, and disclose only what is legally required. Customer Data is Confidential Information under the agreement and clause 10.4 gives Privileged Information the highest level of protection, so the notice commitment reaches the material a firm most cares about.
No transparency report of government or third-party requests was located on any surface, which is what separates this from the top value. Searched the terms of service, the subprocessor list, the security material and the home page on 4 September 2026.
The Privacy Notice, last updated 1 May 2024, says information may be processed to comply with legal obligations and respond to legal requests, and the Terms of Use reserve the right to report users to law enforcement. Neither document commits to telling the customer before its data is disclosed, or reserves a discretion to do so. The FAQ presents deployment inside the customer's own environment as keeping data out of reach of outside legal requests, which applies where the platform runs on the customer's premises.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Clause 7.9 states that DecoverAI's AI models are trained exclusively on licensed datasets and public information sources, which characterizes the rights basis without identifying any dataset, publisher or collection. The published subprocessor list separately names UniCourt as the supplier of legal case-law and litigation research data feeding AI-assisted legal research features, which identifies a supplier rather than a corpus.
No primary law source, jurisdictional coverage or update cadence is published, and the product's principal corpus is the customer's own document set rather than an external legal collection. Searched the home page, the terms of service, the subprocessor list and the security material on 4 September 2026.
Checked the home page, both product pages, the FAQ and the Discovery product overview on 22 September 2026. The product works on the customer's own document collection, and no body of primary law behind its output is identified anywhere.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Nothing on any located surface addresses whether authority is checked for subsequent history. The product is an eDiscovery platform whose core work is classification, redaction and production over the customer's own documents, so the question bites only through the AI-assisted legal research features referred to in clause 13.5 and supplied with data by UniCourt. No treatment signal, currency check or citator relationship is described anywhere.
Searched the home page, the product pages listed in the navigation, the terms of service and the subprocessor list on 4 September 2026.
Checked the home page, both product pages, the FAQ and the Discovery product overview on 22 September 2026. The product classifies and explains documents from the customer's own collection rather than citing legal authority, and nothing addresses checking authority for subsequent history.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
No located public material describes what the product does when it cannot ground an answer. Hallucination is acknowledged squarely in clause 13.5, which disclaims liability for incorrect, inaccurate or hallucinated information generated by the AI features, but acknowledgment of the risk is not a description of behavior. No abstention path, no no-answer state and no confidence or grounding score visible to the reviewer is described, and the published control is human override of every classification rather than anything the system does itself. Searched the home page, the product pages, the terms of service and the subprocessor list on 4 September 2026.
Every document receives a responsiveness score and an explanation, which export together in a CSV, and reviewers validate the tags in a side pane with a quality-control workflow. No path is described in which the system declines to classify a document it cannot assess.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
The AI Hallucination Cases database maintained by Damien Charlotin was searched on 4 September 2026 on both the product name DecoverAI and the corporate name DecoverHQ. No court order, opinion or disciplinary record naming the product was located. This records the state of the public record on that date and is not a finding about the product.
Searched the AI Hallucination Cases database maintained by Damien Charlotin on 22 September 2026 for Discernis, and no recorded case was returned. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
The agreement engages named professional conduct rules directly. Clause 2.5 makes the customer responsible for compliance with applicable Rules of Professional Conduct and names three duties with their sources: competence under ABA Model Rule 1.1, confidentiality under ABA Model Rule 1.6, and supervision. Clause 4.4 requires the customer to warrant that uploading client materials does not violate any court order or rule of professional conduct and that it has obtained any client consent required under applicable bar rules or ethics opinions governing cloud-based legal technology, which engages the specific ethics question this product raises.
Clause 2.3 prohibits use of the Services in violation of applicable professional responsibility rules and bar regulations. The guidance engaged is that of one jurisdiction and no clause-by-clause mapping of product behavior to named opinions is published.
A blog post on defensible AI investigations says several bar ethics committees have weighed in on using AI tools with client confidential information, and calls private deployment for sensitive matters a professional responsibility requirement. No ethics opinion is named, and the product pages, FAQ and terms do not engage with professional guidance.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim cost savings without addressing what happens to a client bill. Published claims include 98 percent cost reduction against traditional attorney review, 147,000 dollars and 25 days saved on a 30,000-document production, 20,000 dollars saved on a subpoena response, and pricing framed as 300 to 1,200 dollars per matter against weeks of associate hours. A cost estimator tool estimates the customer's own review spend rather than anything disclosable to a client.
Nothing addresses how AI-assisted work should be billed or disclosed, and although the product generates detailed per-matter artifacts including privilege logs and audit trails, none is described as a record of AI-assisted work for fee purposes.
The home page claims review that is 90 percent faster and 70 percent cheaper than traditional review, and the law firm page claims a 40 to 50 percent cost reduction. A blog post on per-document pricing discusses predictable budgets and easier cost conversations with clients, but nothing addresses how AI-assisted review is billed or disclosed to the client when the hours fall.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
All three limbs are evidenced separately. Subprocessor list: a dated and version-numbered page published at decover.ai/legal/subprocessors, last updated August 2026, naming every subprocessor engaged for Customer Data with its function and country. Model provider statement: the same page names nine artificial intelligence and machine learning providers individually and states what each does, covering inference by OpenAI, Anthropic and Google Gemini, routing by OpenRouter, optical character recognition by Mistral AI, re-ranking by Cohere, sandboxed execution by E2B, web search grounding by Parallel Web Systems and case-law data by UniCourt, so a firm can tell its client precisely who touches its content and for what.
Forwardable client-facing material: the page states it is the subprocessor list referenced in the Data Processing Agreement, records that each subprocessor is bound by obligations no less protective including Standard Contractual Clauses where applicable, commits to thirty days' prior written notice before any addition, and offers a countersigned DPA and SCCs on request. The DPA is published at decover.ai/legal/dpa and incorporated into the terms by clause 7.2; that page was not opened in this pass, and the third limb is credited on the published subprocessor annex itself rather than on the DPA's contents.
No subprocessor or model provider list was located on the home page, product pages, FAQ, Terms of Use or Privacy Notice on 22 September 2026, and the trust center linked from the FAQ could not be opened that day. What a firm can forward to a client is the vendor's stated position: its own models, no third-party AI service called, no data retained for training, and a US-based Azure cloud by default. For an on-premises deployment, a firm can answer its client's AI clause from its own configuration.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Substantial elements of a record are produced by the product, short of a per-document export covering the model used. Published: an auto-generated privilege log delivered as a spreadsheet, Bates numbering applied to firm conventions, a full audit trail described as supporting regulatory productions and defensibility before a regulator, and access and activity logs retained under clause 4.3 for at least twelve months and released to the customer on written request.
A white paper on what courts expect from AI-assisted document review and how to document it is published, though it was not opened in this pass. What is missing is the model dimension: nothing states that the model behind a given classification is recorded or disclosed, and the OpenRouter routing layer means the specific model handling a document is not surfaced.
Exports include a CSV listing responsive documents with their scores and the model's explanations, and the audit log records extraction, editing and validation by date, time and person. No per-document record combining the model used, the basis for the call and the human verification is described as an export, and no disclosure guidance or template is published.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Primary Law Corpus Provenance
- Good Law Verification
Which one fits
Choose DecoverAI if
- You want your data commitments in the agreement you sign. DecoverAI's terms bar training on customer data without your prior written consent, state that nothing in the agreement waives privilege, restrict its staff from reviewing your data except for authorized support, and delete data 30 days after the term ends, with written certification on request.
- You want to price a matter before you start. DecoverAI publishes $60 per gigabyte per month with no seat fees, a second unit at two cents per document, a worked range of $300 to $1,200 for a typical matter, a cost estimator and self serve signup.
- Your documents live in iManage, Clio or Microsoft 365. DecoverAI names customer authorized connections to iManage, Clio, SharePoint, OneDrive, Microsoft 365, Google Drive, Gmail, Dropbox, Box and customer owned Amazon S3, each configured by the customer, and produces privilege logs and Bates numbering to firm conventions.
Choose Discernis if
- You cannot send a collection to an outside AI company. Discernis states that it builds and hosts its own models, that no third party or commercial AI service is called at any point, and that inference runs inside whichever environment you choose.
- Your documents cannot leave your building. Discernis runs in its own cloud on US based Azure by default, in a private cloud, on any major cloud or Kubernetes cluster, or on your premises, including air gapped, and publishes the hardware a local installation handling a terabyte a month needs: about 32 CPUs, 128 GB of RAM, 2 TB of storage and eight H100 GPUs.
- You want to pay per document with no charge for storage or users. Discernis prices Discovery per document, on matter or annual terms, with no per gigabyte, per user, storage, ingestion or export charges, and allows cancellation at any time. The rate itself is quoted before a matter starts.
In summary
DecoverAI
DecoverAI is an eDiscovery platform from DecoverHQ, Inc. of San Mateo, California, that takes a document set from upload to production: AI classification for responsiveness, privilege and confidentiality, redaction with attorney override, generated privilege logs, Bates numbering and an audit trail, plus chronologies and evidence analysis. The AI Legal Index grades it in the top two bands on fourteen of fifteen capability axes, with A grades on six, including privilege posture, professional responsibility and pricing. Its terms bar training on customer data without written consent and name ABA Model Rules 1.1 and 1.6, and its subprocessor list names each AI provider it uses. Pricing is published at $60 per gigabyte per month. As of 4 September 2026 the index located no AI governance framework and no accuracy figure.
Discernis
Discernis is an AI document review platform from Discernis, Inc. of New York, sold to law firms, corporate legal departments and legal service providers. Its Discovery product runs the company's own models across every document against a review protocol written in plain English, scoring responsiveness, flagging likely privilege and explaining each call, and Discernis Investigations reconstructs timelines and maps parties across a collection. The AI Legal Index grades it in the top two bands on eight of fifteen capability axes, with A grades on AI centrality and on deployment: it runs in its own cloud, a private cloud, on premises or air gapped, and calls no outside AI service. As of 22 September 2026 the index located no security attestation, no named customer and no training or confidentiality term in its published Terms of Use.
Questions buyers ask
DecoverAI vs Discernis: which is better for AI document review?
On published evidence DecoverAI sits in the top two bands on fourteen of fifteen AI Legal Index capability axes and Discernis on eight of fifteen, because DecoverAI's agreement, subprocessor list and pricing say far more. Discernis leads on one thing that may decide it for some buyers: it runs its own models and can be installed on premises or air gapped, so documents never reach an outside AI company. DecoverAI's inference runs through OpenAI, Anthropic and Google.
Does DecoverAI train on client documents?
Not without written permission. Clause 7.9 of DecoverAI's agreement, headed No Training on Customer Data, provides that it will not use customer data or inputs to train, fine tune or improve any AI model without the customer's prior written consent, and says its models are trained only on licensed datasets and public sources. Its home page states the position more absolutely, that customer data never trains its models. Discernis says in its FAQ that no data is retained for training. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
Where does Discernis host data, and can it run on premises?
Yes to on premises. Discernis hosts by default in a US based Azure cloud and will deploy to other regions or clouds on request, and it also offers a private cloud, installation on any Kubernetes cluster or major cloud, and on premises or air gapped installation. It states that all inference runs inside the environment the customer chooses. DecoverAI offers multi tenant and single tenant hosting in the United States, and deployment inside the customer's own VPC. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
Which AI models does DecoverAI use?
DecoverAI's dated subprocessor list names OpenAI, Anthropic and Google's Gemini for inference, OpenRouter as a routing layer to further models, Mistral AI for OCR, Cohere for reranking search results, E2B for sandboxed code execution, Parallel Web Systems for web search grounding and UniCourt for case law data, with each provider's country, and commits to 30 days' notice before any addition. Because of the routing layer, the specific model behind a given request is not disclosed. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
What do DecoverAI and Discernis both leave unpublished?
How their models are governed. Neither names anyone accountable for model behavior, describes testing before a release, or addresses whether classification is uneven across document types, languages or people. Neither says what the system does when it cannot classify a document with confidence, and neither publishes a record showing which model made each call. Neither describes walls between matters inside one account, and both advertise large savings without saying how they should reach a client's bill. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
Two readings to weigh. Discernis's published documents disagree with each other: its FAQ states HIPAA compliance while its Terms of Use say the service is not tailored to comply with HIPAA and may not be used where it applies, and one page says there are no per document charges while others state per document pricing. The terms are the binding text and should be read first. DecoverAI's home page says customer data never trains its models, while its agreement allows training with the customer's prior written consent. Discernis's trust center could not be opened when checked. DecoverAI was verified on 4 September 2026 and Discernis on 22 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.