DeepJudge vs Fileread: how they compare in 2026

D
DeepJudge profile
F
Fileread profile
Last verifiedSeptember 27, 2026

DeepJudge and Fileread both use AI to search a legal team's own documents, and are rarely weighed against each other because the documents differ. DeepJudge searches a firm's accumulated knowledge across its document management system, email and intranets, while Fileread reads a litigation production to find facts for one matter. DeepJudge sits in the top two bands on fourteen of fifteen axes and Fileread on eleven of fifteen, identical on eight. DeepJudge's terms are published in full: no training on customer data, a mutual liability cap, an infringement indemnity, and cloud, on premises or hybrid hosting. Its search inherits the firm's existing permissions and ethical walls. Fileread's lead is AI governance: its trust center lists an AI management system plan and an evaluation policy, and it publishes a taxonomy of how legal AI fails. It pins every answer to its place in the production. Its agreements sit behind a request, and it states no retention period for uploaded productions.

At a glance

Category
DeepJudgeLegal Research
FilereadLitigation & eDiscovery
Founded
DeepJudgeNot published
FilereadNot published
Headquarters
DeepJudgeZurich, Switzerland
FilereadNot published
Last verified
DeepJudgeSep 2, 2026
FilereadSep 7, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

DeepJudge
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

There is no content asset and no conventional product underneath. Unlike the other research records in this lane, DeepJudge licenses nothing and publishes nothing of its own: the material it works on belongs entirely to the customer and stays in the customer's systems. What DeepJudge supplies is the retrieval itself, described as intent-based search that understands content, context and relevance, with automatic classification into a taxonomy and near-duplicate and redline detection across collections the vendor describes as billions of unstructured and structured data points. Strip the models out and what remains is a set of connectors and a permissions synchronizer, which is plumbing rather than something a firm would buy. The founders' own framing, that search rather than models is the wedge, is a claim about which machine learning matters, not a claim that machine learning is peripheral. Verified 2 September 2026.

Fileread
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

The product is the model work and nothing survives its removal. Fileread exists to read a document production and answer questions about it: users query the full collection in plain language rather than by keyword, and the vendor's own framing is that the point is asking the question you cannot turn into a keyword. Generation is the deliverable, not a feature bolted onto a repository: fact memos, chronologies, contradiction reports, character lists, org charts, deposition outlines and factual briefs are produced from the record, and a module called Workbench runs longer chains of research to assemble them. Retrieval spans formats that defeat keyword tooling, including images, handwritten notes, audio, video and spreadsheets, which is model work rather than indexing. The vendor's positioning sentence is an AI claim about its own architecture, that most legal AI is built to generate and this one is built to be checked, with every answer pinned to the location in the source. Strip the models out and there is no residual product: no case law database, no docket service, no document management system, only a customer's own production which the customer already holds. Homepage, product framing and the vendor's human oversight paper read 7 September 2026.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

DeepJudge
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is structural rather than asserted: every result is a document the firm already holds, in its own system, which the user can open and read in full, so the verification path is the shortest of any record in this pull. The retrieval method is described at a working level, covering intent-based search, automatic taxonomy classification, near-duplicate and redline detection, and multi-level combination of client, matter, document and people data. Section 4(j) of the subscription terms places a contractual obligation on the customer to verify, including through human review, the accuracy, reliability and appropriateness of the AI features. What is absent is measurement. No accuracy figure, evaluation, test set or benchmark appears anywhere, and nothing addresses hallucination in the workflow and agent layer, which is where generated text rather than retrieved documents is produced. The one published number nearby is a satisfaction measure, that 90 percent of users report finding results faster than with existing tools, which is not an accuracy claim. Verified 2 September 2026.

Fileread
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is real, documented and architecturally central, and no accuracy figure exists. What is published: every answer returns pinned to the exact location in the source document, a claim traces to its page so checking takes a glance, and generated work product retains its connection to the underlying material so a reviewer can inspect where a finding came from. The vendor states the design intent plainly, that the system is built to be checked rather than to be trusted, and maintains a dedicated paper on source citation and verification. It also publishes an authored, dated and practitioner-reviewed taxonomy of seven ways legal AI fails, with a detection control for several of them: unsupported generation, correct source with incorrect interpretation, context loss, missed evidence, conflicting evidence presented as certainty, identity confusion, and date and sequence errors. That is an unusually candid document and one of the failure modes has a product answer, since contradiction reports exist to surface the conflicts that the fifth mode describes being flattened. What keeps this off the top grade is the distinction between naming the failure modes of a class and measuring your own. The taxonomy is written as guidance about legal AI generally, not as disclosure about this system: no accuracy figure, no error rate, no test set, no benchmark and no evaluation result is published for Fileread itself. A buyer can see that the vendor understands how such systems fail and cannot see how often this one does. Homepage, failure modes paper of 17 August 2026 and human oversight paper read in full 7 September 2026.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

DeepJudge
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

The human review requirement is contractual and the excluded uses are unusually explicit. Section 4(j) requires the customer to verify the accuracy, reliability or appropriateness of AI features through human review, and the same clause prohibits use in judicial decision-making by judges, in the professional activities of lawyers serving as arbitrators, mediators or other alternative dispute resolution neutrals, and in any use restricted under the EU Artificial Intelligence Act. Naming the roles that may not use the product is rarer and more useful than the usual disclaimer. What is not published is the operating boundary. The workflow layer is described as agentic reasoning that executes complex multi-step tasks, retrieving from multiple sources and taking actions, and the customer builds those workflows itself using a low-code builder, so the threshold at which a workflow acts without a human is set by the firm and described nowhere. Governance of agents is offered as a capability without any account of what the governance controls are. Verified 2 September 2026.

Fileread
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Substantive published commitments with the autonomy boundary stated, short of anything the product enforces. The boundary is stated, which is what keeps this off the middle grade: Workbench performs longer chains of research and assembles chronologies, factual briefs, contradiction reports and deposition outlines, and the vendor states that the resulting work remains a draft for professional review and refinement. So the reader is told the system runs multi-step work unattended and is told where it stops. Around that sits a published oversight framework, authored, dated and practitioner-reviewed, which is more than most records on this axis offer: oversight is framed as beginning before the prompt, with the task, included and excluded materials, intended audience, acceptable level of uncertainty, claims requiring source support, the person responsible for final review and the record to be retained all settled in advance; review is scaled to risk, with exploratory output to be treated as a starting point, citations sampled, and results not represented as established fact; and a twelve-point review checklist runs from whether cited passages actually support the statements to whether a responsible professional approved the final use. What is absent is the product half. The framework is guidance offered to the buyer rather than a specification of the system's own controls, only one paragraph describes what Fileread itself does, no configurable autonomy level or override is described, and nothing states that the checklist is recorded or enforced anywhere in the product. Human oversight paper and homepage read in full 7 September 2026.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

DeepJudge
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Sixteen firms are named on the home page, spanning global elite practices including Freshfields, Greenberg Traurig, Holland and Knight and Gunderson Dettmer, United States mid-market firms including Cozen O'Connor, ArentFox Schiff and Vorys, Swiss and Austrian practices including Homburger, Lenz and Staehelin, Wenger Vieli, Advestra, Schoenherr and CMS Switzerland, and one in-house function at SBB. Three named individuals speak on the record with title and firm, including two chief innovation officers. Figures are published: 65 hours saved per user per year on searching, 85 percent adoption within two months, 23 queries per user per day, fourfold return in the first year, and 90 percent reporting faster results. One figure is properly attached, with a named M&A partner at Homburger stating that more than 80 percent of the firm's legal professionals had incorporated it into their workflow. What holds this below A is that the headline figures are aggregate and carry no method or measurement basis, and no dates appear on the home page; the individual customer story pages were not opened this pass. Verified 2 September 2026.

Fileread
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Named customers with named people in named roles, and one quantified account, with no method behind any of it. Five attributed testimonials are published: a partner at Kellogg, Hansen, Todd, Figel & Frederick describing use on an expedited case that went to trial; a partner at Fields, Han & Cunniff describing the system retrieving a correct document from an inaccurate description; a senior vice president for innovation and strategy at JND Legal Administration assessing the product on maturity, defensibility and user experience against alternatives; a manager of knowledge and practice support services at Nutter McClennen & Fish on the Relativity integration; and the chief technology officer of Cimplifi on replacing Boolean search. That is a spread across a litigation boutique, a large firm practice-support function, a litigation-support provider and an eDiscovery services company, which tells a buyer who actually runs it. One quantified account is published with the arithmetic shown: a matter arrived as 4,000 text message screenshots, which the platform converted and deduplicated to 725 actual messages, work the vendor states would have consumed more than 20 hours of attorney time. Independent coverage is cited, including a Law360 piece on a firm's generative AI experiments and reporting of a 6 million dollar seed round. What is absent is measurement: no aggregate figures, no recall or precision on retrieval, no customer count, and the time saved rests on a single anecdote rather than a study. Homepage, customer testimonials and cited coverage read 7 September 2026.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

DeepJudge
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Four of the five limbs are met, and the segregation limb is met better here than by any other record in this pull. Section 5(b) of the subscription terms provides that DeepJudge does not use customer data to train the AI or machine learning models underlying the services, which is a contractual prohibition naming the thing rather than a policy statement. Segregation is the product's architecture rather than a claim about it: access permissions are continuously synchronized with the firm's source systems so that existing ethical walls are maintained, which is the matter-level requirement a firm buyer needs, and section 5(e) adds that customer authored workflow logic will not be disclosed or incorporated into the service provided to any other customer. Retention and deletion are stated, with customer data deleted within sixty days of termination. The position on model providers is answered structurally, since the firm selects the models and the hybrid deployment clause discloses exactly when processing leaves the firm's own infrastructure. The limb that fails is privilege and work product handling: neither term appears anywhere, and ethical walls address conflicts rather than privilege. Verified 2 September 2026.

Fileread
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Real controls are published and nothing addresses privilege, which matters more here than on most records because the material this product ingests is an entire litigation production. What exists: a statement that nothing a customer uploads trains a shared model; data encrypted and hosted in Azure and processed through what the vendor calls private large language models; and a trust center control inventory naming least privilege, access monitoring, access log management and data asset classification, alongside HIPAA compliance which bears on the sensitive material productions contain. Those are corporate and infrastructure controls, and they are credited on the stewardship axis rather than counted twice here. What is absent is everything this axis asks. No privilege or work product treatment is published at any level. Nothing states who at the vendor may read customer matter material or under what conditions. No segregation position is published between matters held by the same customer or between customers, and the question is sharpened by the Relativity integration, since nothing states whether the platform inherits the workspace permissions a firm has already built there or maintains a second permission model of its own. The customer agreement that would carry a confidentiality clause is not readable: a Master Services Agreement is listed in the trust center behind an access request, and the website terms render client-side and returned no body on this channel. The vendor's own oversight paper names protecting privileged material as an attorney duty, which is an acknowledgment of the risk rather than a commitment about the product. Homepage, security page and trust center read 7 September 2026.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

DeepJudge
AA on UPL and Professional Responsibility PostureThe vendor states plainly what the product is and is not, who may use it, and how it supports a lawyer’s competence and supervision duties. Jurisdiction limits are named and any consumer facing surface carries a clear disclosure.

This is the most complete professional responsibility position located in the pull, and all of it sits in the operative agreement. Section 4(j) states that DeepJudge is not a law firm and does not engage in the practice of law and that the customer acknowledges it is not relying on the services for legal advice. It states who may use the product and, unusually, who may not, prohibiting use in judicial decision-making or other activities performed by judges, and in the professional activities of lawyers serving as arbitrators, mediators or other alternative dispute resolution neutrals. It reaches competence and supervision through a positive obligation rather than a disclaimer, requiring the customer to verify the accuracy, reliability or appropriateness of the AI features including through human review. And the legal boundary is stated twice: section 4(a) confines use to compliance with the obligations applicable where the customer and its users are located, and section 4(j) excludes any use prohibited or restricted under the EU Artificial Intelligence Act, naming the instrument. The coverage limb that asks about jurisdictional reach of legal content does not bite on a product that searches the firm's own documents rather than any jurisdiction's law, and is recorded here as inapplicable rather than failed. No bar or law society guidance is engaged, which is recorded on the signal rather than here. Verified 2 September 2026.

Fileread
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

Substantive published engagement with where professional responsibility sits, short of a located disclaimer or a named authority. Several limbs of this band do not bite and are named rather than penalized: the product analyses the customer's own document production rather than advising on law, its outputs are factual findings cited to the record rather than legal conclusions citing authority, and it is sold to lawyers and litigation support professionals rather than to the public, so the unauthorised practice risk this axis was written for is structurally remote. On what does bite, the vendor engages directly and in its own authored material. Its oversight paper states that artificial intelligence can assist with parts of litigation work but does not possess responsibility for the representation; that attorneys must interpret contested facts, assess credibility, understand procedural posture, protect privileged material and apply legal standards; that a fluent response may obscure uncertainty, missing context or an incorrect assumption; and that an exploratory question for internal orientation does not require the same process as a factual representation intended for a client, a witness examination or a court filing. Its review checklist ends with the output being reviewed under applicable legal and professional standards and a responsible professional approving the final use. What is missing is the formal half: no disclaimer language was located, because the terms of service render client-side and returned no body, and no bar rule, ethics opinion or court standing order is named anywhere. Human oversight paper and failure modes paper read in full 7 September 2026.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

DeepJudge
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

One binding governance commitment is published and everything around it is missing. Section 4(j) of the subscription terms makes compliance with the EU Artificial Intelligence Act a contractual restriction on use, naming the instrument and excluding the administration-of-justice applications the Act treats as high risk, which is more than a principles page and is enforceable by the customer. The workflow layer is also sold partly on governance, offering to build, deploy, orchestrate and govern AI agents. What no published material supplies is any content behind either. No responsible AI page exists, no governance framework, no individual or function named as accountable for model behavior, no account of what is tested before a release ships, no certification such as ISO 42001, and nothing at all about uneven output across matter types, practices or populations. ISO 27001 and SOC 2 Type II are security attestations, which this axis treats as a different subject. Checked the home page, product page, security page, subscription terms and privacy policy on 2 September 2026. Verified 2 September 2026.

Fileread
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

An AI-specific governance apparatus is disclosed by name, and its contents are gated. The trust center lists two instruments in its policy library that most records in this corpus do not have at all: an AI System Development and Evaluation Policy, and an Artificial Intelligence Management System Plan, the latter using the term of art for the management system that ISO/IEC 42001 defines. It carries a separate AI section with overview, security and monitoring entries, so AI is treated as its own control domain rather than folded into general security, and the whole trust center is described as continuously monitored with automated compliance monitoring and automated alert response. That is real substance, and it is the reason this is not the middle grade. What keeps it off the top is that nothing behind the titles was read and nothing is attested. Both policies sit behind an access request, so their existence and titles are established and their contents are not, and crediting a document by its title is not available here. No ISO/IEC 42001 certification is claimed, in contrast to ISO/IEC 27001:2022 which is claimed with its version. No evaluation result, benchmark or model card is published. Nobody is named as accountable for the system's behavior. And no bias, fairness or representativeness disclosure exists at any level, which is worth naming for a product whose identity confusion failure mode, published by the vendor itself, involves combining information belonging to people with similar names, addresses or roles. Trust center and failure modes paper read 7 September 2026.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

DeepJudge
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

All five elements are established and specific, on the subscription terms and the data processing addendum, version 1.1 of May 2026. Retention and deletion: section 3(a) of the subscription terms deletes all customer data including training data and customer models within sixty calendar days of termination, and DPA clause 11 adds prompt destruction or return on request, extending to data held by subprocessors, with confirmation of destruction. Access control: permissions continuously synchronized from source systems on least privilege principles, access restricted to authenticated users, configurable audit logging, indexing controls over what is crawled at all, and DPA Annex 2 adding multi factor authentication, role based access control, centralized event logging and segregated pre production and production environments. Subprocessors: Annex 3 names five entities with purpose and location, and clause 5 requires equivalent written terms, due diligence, vendor liability for their acts, thirty days notice before a new subprocessor processes anything, and an objection right with termination without liability. Incident practice: clause 7 commits to notice without undue delay and in any event within seventy two hours of discovery, covering breaches at subprocessors as well as at DeepJudge, with the definition at 1.13 expressly including unauthorised internal access, plus cooperation so the customer can meet its own regulator and data subject duties. Encryption is TLS 1.2 or later in transit and AES-256 at rest, with annual penetration testing and controls audited for SOC 2 Type II. Clause 3.4 adds a purpose limitation binding subprocessors: no selling or sharing, no processing for other purposes, no retention or disclosure outside the direct business relationship, and no combining customer personal data with data from other sources.

Fileread
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

The published control inventory is the broadest located in this pull, and one limb is missing. Certifications are named with the standard version: SOC 2 Type 2, ISO/IEC 27001:2022, HIPAA, GDPR and CCPA. Training is addressed: nothing a customer uploads trains a shared model, with data encrypted and hosted in Azure and processed through private large language models. Subprocessors are named on the public page rather than on request, being OpenAI, Baseten, Pinecone, Langfuse and Microsoft Azure, with Amazon Web Services and Azure listed as infrastructure, and a subscribable feed publishes changes to that list with dated entries recording the addition of Langfuse for prompt use and of OpenAI. Incident practice is present, with a documented incident reporting process and designated response personnel. Access control is present, with least privilege, access monitoring, access log management and data asset classification. Around those sit data loss prevention, application and network penetration testing, code analysis, credential management, backups with a backup policy, business continuity and disaster recovery including contingency plan testing and failover, change management with change notification and verification, endpoint controls including mobile device management and threat detection, anti-DDoS and firewalls, and security, privacy and phishing training. The gap, named because every partial names its limitation, is retention and deletion: no retention period, no deletion commitment and no end-of-matter or end-of-engagement disposal position was located anywhere, which is the question a litigation buyer asks about a production it has uploaded. Trust center, security page and homepage read 7 September 2026.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

DeepJudge
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

The whole allocation of loss is published, specific, and mutual, which is rare in this corpus. Section 7(a)(ii) caps each party's total aggregate liability at the fees paid to DeepJudge in the twelve months before the event giving rise to it, and names four express exceptions that sit outside the cap: the customer's payment obligations, breach of the use restrictions at section 4(e), fraud or wilful misconduct, and infringement of intellectual property rights. Section 7(a)(i) excludes indirect and consequential damages symmetrically for both parties, with the same carve-outs. Section 7(b) gives the customer a real indemnity running the right way, with DeepJudge defending third-party claims that the services or underlying software infringe intellectual property rights, and setting out the remedies in order: procure the right to continue, modify or replace to become non-infringing, or terminate the affected portion. There is also a service commitment a buyer can hold: section 1(a)(iii) sets a 99 percent quarterly uptime target with downtime defined and six named exclusions. What is not offered is any warranty on output, since section 6 disclaims accuracy and completeness, and no insurance is mentioned. Verified 2 September 2026.

Fileread
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

Nothing establishable on this date states who bears the loss when the product is wrong, and the cause is two different things which the reader should be able to tell apart. The agreements exist and the vendor says so: a Master Services Agreement and a Data Processing Agreement are both listed by name in the trust center's legal section. Neither is published; both sit behind an access request, which is a disclosure choice about how the terms are made available rather than an absence of terms. Separately, the website terms of service linked in the site footer render client-side and returned the hosting platform's shell with no body on this channel, and a search on clause language did not recover the text, so that document is a limit of this reading rather than a vendor decision. The consequence for a buyer is the same either way and is what the grade records: no indemnity, no liability cap, no warranty, no service level commitment, no exclusive remedy and no insurance position can be read before entering a commercial conversation. The exposure worth naming on this product class is that its outputs become fact statements and pleadings a lawyer signs, and its own published failure taxonomy describes seven ways such outputs go wrong, with nothing published about what the vendor stands behind if they do. Trust center read and terms of service attempted 7 September 2026.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

DeepJudge
AA on Practice Systems Integration DepthDocumented, verifiable integrations into the systems legal work already lives in, with the depth described: what syncs, in which direction, and what a firm must configure.

Integration is not a feature of this product, it is the product, and the depth is documented accordingly. The systems named are the ones firm work actually lives in: the document management system, email, SharePoint, OneDrive, HighQ, intranets and experience management and metadata systems. What moves is described in both directions. Documents are crawled and indexed in place with no migration and no uploading, so the firm's data remains in its source system; permissions travel the other way, continuously synchronized from those systems into the index; and the firm decides through indexing controls what is crawled at all. What a firm must configure is set out contractually rather than left to implementation: section 1(d) requires continued access to the customer databases named on the order form, requires a named technical contact, and warns that withholding access degrades the service, while the on-premises clause makes the customer responsible for meeting stated hardware and configuration requirements. The platform also exposes governed access to other AI systems through the Model Context Protocol and publishes an open agent handoff specification. Verified 2 September 2026.

Fileread
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

One integration, into the system this product class actually runs on, documented on that platform's own marketplace. Fileread is available as a native integration inside Relativity, with a listing on the Relativity app hub, and the integration is described by a customer rather than only by the vendor, a practice support manager at Nutter McClennen & Fish attributing easier adoption to it. That is the deepest integration available in this segment: Relativity is where litigation productions already sit, and the vendor's design position follows from it, that the platform works on the productions a team already has with nothing to migrate. A second distribution surface exists on the Microsoft commercial marketplace, and the trust center lists integrations as a product security control. Cimplifi, an eDiscovery services provider, describes offering the product through its own ecosystem, which is a channel rather than an integration and is recorded as such. What is absent is breadth and documentation. No API or developer documentation was located anywhere in the site navigation or footer. No document management system, case management platform, word processor or e-signature product is named. No integrations page or connector directory exists, and nothing describes what moves in which direction between Fileread and Relativity or how permissions travel across that boundary. Homepage, footer, Relativity app hub listing and trust center checked 7 September 2026.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

DeepJudge
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

Three deployment models are defined in the agreement itself, with the consequence of each spelled out, which is the most complete treatment of this axis in the pull. Cloud deployment hosts the services in a cloud hosting location named on the order form. On-premises deployment runs inside the customer's own infrastructure, with DeepJudge granted access to install and maintain, and the customer responsible for stated system requirements. Hybrid deployment is defined precisely as on-premises with certain processing, expressly including model processing, occurring outside the customer's infrastructure, and the clause states plainly that customer data may be processed in the cloud hosting location and that model processing may involve transfer of customer data outside the customer's systems. That is processing separated from storage, stated by the vendor rather than inferred, and it names the one circumstance in which an on-premises customer's data leaves. The security page adds that the customer runs its choice of model in its choice of residency. The limitation worth recording is that no specific regions are enumerated: residency is selectable and designated on the order form rather than published as a list. Verified 2 September 2026.

Fileread
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Neither co-equal limb is stated, and what is published in their place is infrastructure. The cloud providers are named clearly and in more than one place: data is stated to be encrypted and hosted in Azure and processed through private large language models, and the trust center lists both Amazon Web Services and Microsoft Azure under infrastructure and Microsoft Azure again among the subprocessors. Naming the cloud is where a workload runs, not the tenancy model and not the region, and it is credited on the supply chain and stewardship rows rather than here. On tenancy, nothing states whether customers are separated logically or physically, whether a matter is isolated from another matter, or what single-tenant options if any exist; the phrase private large language models points at dedicated inference rather than at tenancy of the data store and is not treated as a tenancy statement. On region, nothing states a country or region of storage or processing, no region selection is offered, and no data residency commitment appears despite GDPR compliance being claimed, which ordinarily brings a transfer position with it. Two gated artifacts in the trust center would answer this directly and were not read, being a Data Flow Diagram and a Network Diagram, and they are the named rebuttal route on this row. Security page, homepage and trust center checked 7 September 2026.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

DeepJudge
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Two attestations are claimed and one carries its scope. SOC 2 Type II is stated as covering security, availability and confidentiality, and ISO 27001 certification is stated as covering the information security management system, which is more than most records in this pull offer. The data processing addendum, version 1.1 of May 2026, records annual penetration testing in Annex 2 and states that controls are audited for SOC 2 Type II. What the top band asks for is absent from every surface a prospect can reach: no auditor is named, no certificate number, issue date, report date or coverage period is published, and there is no trust center or portal. The route to evidence is a customer route rather than a public one. DPA clause 9 sets it out: certifications and audit reports or written questionnaires are made available first, and a customer audit is permitted only where those cannot demonstrate compliance, at the customer's expense, once per calendar year, with no access to systems, hosting sites or infrastructure. That is a real entitlement for a signed customer and not accessible evidence for a buyer still deciding, which is what keeps this at B.

Fileread
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

A real trust center with a named artifact inventory, and the reports themselves behind a request whose terms the portal does not state. What is ungated and readable: five compliance positions, being SOC 2 Type 2, ISO/IEC 27001:2022 with the standard version given rather than the bare number, HIPAA, GDPR and CCPA; a control inventory spanning roughly twenty categories from continuous monitoring and product security through access control, endpoint, network and application security to incident response, risk management, business continuity, asset management, change management and training; a named subprocessor list; and a subscribable feed of trust center updates carrying dated subprocessor changes. That breadth of ungated detail is more than most records in this corpus publish at all. What sits behind the access flow: the SOC 2 report, an ISO 27001 report, a penetration test report, a data flow diagram, a network diagram, the policy library and the agreements. The portal offers to start a security review, to view and download sensitive information and to request access, and does not state whether access is granted instantly on an email address, by a self-service non-disclosure click-through, or by vendor approval after a sales conversation. Under the standing rule for gated artifacts the lower tier is taken where the portal does not say which it is, and that is why this is not the top grade, alongside the absence of any named auditor, audit period or scope statement. No request was submitted. Trust center and security page read 7 September 2026.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

DeepJudge
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

The original note said that not one provider was named and that no change notification commitment existed. Both are corrected: Annex 3 names Microsoft Ireland Operations Ltd, Google Cloud EMEA Ltd and AWS EMEA SARL, each described as AI provider and cloud infrastructure with location customer selected, and clause 5 commits to at least thirty days notice before any new subprocessor processes customer data, with a right to object on reasonable data protection grounds and termination without liability if the objection cannot be resolved. The grade does not move, and the reason is the shape of what is named. The three entities are hyperscaler platforms rather than model vendors: no discrete model house appears anywhere in the list, no model is named, and no default is stated, so a reader learns which cloud estates the inference runs in but not whose model produced the output. Provider-level naming does not reach the top band and platform-level naming reaches it less. What is genuinely well disclosed is the architecture and the geography: DeepJudge states that its architecture is model-agnostic and that the customer chooses from and may combine any commercial or open-source models, running its choice of model in its choice of residency, and the hybrid deployment clause in the subscription terms discloses that model processing may involve transfer of customer data outside the customer's own infrastructure. Customer-selected location on all three AI providers corroborates the deployment position rather than adding to it.

Fileread
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

The fullest provider-level disclosure located in this lane, and the models are still not named. The trust center publishes the subprocessors on its public page rather than behind the document request, and the list is legible as an AI stack rather than as generic infrastructure: OpenAI, Baseten, Pinecone, Langfuse and Microsoft Azure, with Amazon Web Services and Azure also listed as infrastructure. A reader can therefore establish that a named model provider is in the path, that inference serving and vector storage sit alongside it, and that a prompt observability layer is involved, the update feed recording in terms that Langfuse was added as a subprocessor for prompt use and that OpenAI was added as a subprocessor. Change notification exists as a published mechanism rather than a promise, the trust center carrying a dated subprocessor changes feed with a subscribe option, which is a limb most records on this axis fail outright. Two things keep it off the top grade. No model or model family is named: the site says data is processed through private large language models, and under the standing rule naming a provider is not naming the models underneath. And nothing states which parts of the platform route customer content to which provider, so a reader knows OpenAI is in the stack without knowing what it sees. Trust center and security page read 7 September 2026.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

DeepJudge
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

The unit and the structure are published in the subscription terms without any figure. Fees sit on an order form and are stated to be in United States dollars unless otherwise agreed. The term structure is set out: subscriptions renew automatically for successive one-year periods unless either party gives three months notice before the end of a term, invoices issue within ten days of the effective date and each subsequent term and are payable within thirty days, and late payment attracts the greater of five percent per annum or the statutory maximum. Professional services are separated cleanly, provided only under a mutually agreed statement of work that becomes part of the agreement, which tells a buyer that implementation is priced apart from subscription. Most usefully, the consumption unit is published: section 4(g) sets a hosting threshold of 500,000 documents per user or 250 gibibytes per user, above which DeepJudge may seek volume reduction or charge at standard rates. What is absent is any figure, any tier, and any pricing page; the only commercial route on the site is Book Demo. Verified 2 September 2026.

Fileread
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing information is published at any level, including the unit of charge, and the site's own navigation establishes that no pricing page exists rather than that one could not be reached. The published inventory of the site is Product, Solutions with three segment pages, Customers, Security and Resources, with a footer adding Workflows, Company, Privacy and Terms of Service. There is no pricing entry in either the header or the footer. Every conversion path on every page ends at the same call to action, an invitation to see the product on your matter, which is a demo request. No tier or edition is named, no unit is identified whether by seat, matter, document, gigabyte or production, no band or range appears, no minimum or term is stated, and no free tier or trial is described. The two documents that would carry the commercial mechanics are unavailable: the Master Services Agreement is listed in the trust center behind an access request, and the website terms of service render client-side and returned no body. Where the only route is an invitation to contact sales, no pricing row is owed and none is written. Site navigation, footer, security page and trust center checked 7 September 2026.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

DeepJudge
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Who buys this is evidenced rather than asserted, and the roster does the work: global elite firms including Freshfields, Greenberg Traurig and Holland and Knight, United States mid-market practices including Cozen O'Connor, ArentFox Schiff and Vorys, a technology-sector specialist in Gunderson Dettmer, Swiss and Austrian firms including Homburger, Lenz and Staehelin, Wenger Vieli, Advestra and Schoenherr, and an in-house legal and compliance function at SBB, so both private practice and in-house use are demonstrated. Geographic reach is stated as teams across North America and Europe serving clients worldwide. Practice areas are not enumerated, and on this product that limb does not bite in the usual way, because the platform searches whatever the firm already holds rather than covering any defined body of law. What is genuinely missing is the boundary: no firm size band is named, nothing states a minimum data estate or user count below which the product is not sold, and no statement describes where it stops. The clearest limits published are the prohibited users at section 4(j) rather than any positive statement of scope. Verified 2 September 2026.

Fileread
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

The buyer, the workflow and the material are each described with real specificity, and no boundary is stated. Three buyer segments have their own surfaces: litigation teams, eDiscovery, and corporate legal. Five workflows are published individually, being early case assessment, discovery document review, evidence analysis, deposition preparation, and factual briefs and case narratives, and the lifecycle claim is explicit, from first production to trial. The named customer set matches that spread rather than sitting in one corner of it, running from a Washington litigation firm and a boutique through a large firm's knowledge and practice support function to a litigation administration provider and an eDiscovery services company. Coverage of the material itself is unusually concrete and is the strongest part of this row: text, images, handwritten notes, audio, video and spreadsheets in the same matter, with the vendor claiming the formats that defeat other tools, illustrated by a production that arrived as 4,000 text message screenshots. What is absent is any limit. No jurisdiction is named, and none is excluded, though the customer set and the vocabulary are United States civil litigation throughout. No matter type, case size or practice area is named as in or out of scope. No volume ceiling is published despite scale being the product's central claim. Homepage, solutions and workflow navigation and customer testimonials read 7 September 2026.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

DeepJudge
Never, in the contract

Section 5(b) of the subscription terms is headed No Training and prohibits use of customer data to train the artificial intelligence and machine learning models underlying the services, except where the customer has given prior written consent. It names training and it names the models, which is what puts it in this value, and the consent carve-out is a variation mechanism rather than a product setting. Two adjacent permissions in the same agreement are narrow rather than swallowing it: section 5(c) permits Usage Data collection to improve the services and then defines Usage Data exhaustively as telemetry, listing hardware and storage usage, operating systems, cluster setup and health, uptime and response times, feature usage, interactions and error logs, adding that it is not shared with third parties; and section 5(e) permits reuse of generalized workflow patterns only where no customer data is copied or disclosed.

Clause 3.4 limits processing to providing the services on written instructions, which points the same way as section 5(b), but Annex 1 describes the nature of processing as storage and other processing necessary to provide, maintain and improve the services, and no clause of the addendum addresses model training either way. The addendum is therefore neither a second prohibition nor a permission. The value continues to rest on section 5(b), which is the specific provision and the only one that names training, and a reader should weigh Annex 1's improvement language alongside it.

Fileread
Never, in policy only

A clear public statement with no agreement located to match it, and the wording carries a qualifier worth reading closely. The statement appears on both the homepage and the security page: data is encrypted in Azure and processed through private large language models, and nothing a customer uploads trains a shared model. That is a plain position, published where a buyer will see it before any conversation. The search for a matching contractual term was completed rather than assumed, which is what this value requires.

A Master Services Agreement and a Data Processing Agreement both exist and are listed by name in the trust center, and both sit behind an access request rather than on a public page. The website terms of service linked in the footer render client-side and returned the hosting platform's shell with no body, and a search on clause language did not recover the text. So no published agreement could be read and no contractual training term could be located either way.

The qualifier is the word shared. The commitment as written is that uploads do not train a model used across customers; it does not address whether a customer's own material may be used to tune or adapt a model for that customer, nor whether prompts and outputs may be used for evaluation, debugging or product improvement short of training, a question the presence of a prompt observability subprocessor in the AI path makes worth asking. Security page, homepage and trust center read, terms of service attempted, 7 September 2026.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

DeepJudge
Disclosed fixed window

Section 3(a) of the subscription terms sets a fixed post-termination period the customer cannot vary: DeepJudge deletes all customer data, expressly including any training data and any customer models, within sixty calendar days of termination taking effect, and the customer reciprocally deletes DeepJudge software and data within thirty days and confirms in writing. DPA clause 11 adds an on-request route, requiring prompt destruction or return of data including data held by subprocessors, with confirmation of destruction.

Customer Data is defined broadly at section 1(d)(i) to cover data retrieved from the customer's own databases, anything users upload or enter as Inputs, and the corresponding Outputs, so prompts and answers fall inside both obligations. No in-term retention period is published for Inputs and Outputs, which is what keeps this off the customer-controlled values. What the customer does control is the footprint rather than the clock: documents remain in their source systems rather than being migrated, and indexing controls govern what DeepJudge crawls, indexes and makes accessible at all.

Fileread
Not addressed

No located public material states how long prompts, uploaded productions or generated outputs are kept, or whether a customer can change it. Nothing publishes a retention period, a deletion commitment, an end-of-matter or end-of-engagement disposal position, or any customer-facing control over any of it. This is the one gap in an otherwise broad stewardship disclosure, and it is the gap that matters most for this product class: what is uploaded here is an entire litigation production belonging to a client, and a buyer cannot establish what happens to it when the matter closes or the subscription ends.

Three trust center entries would bear directly on the question and were not readable, being data into system, data out of system and data backups, each an item in the gated control detail rather than a published statement, and they are the named rebuttal route on this row. The two agreements that would ordinarily carry a deletion-on-termination clause are the Master Services Agreement and the Data Processing Agreement, both listed in the trust center behind an access request.

What is published nearby, and is credited on the stewardship axis rather than counted here, is that a backup policy exists and that nothing uploaded trains a shared model, neither of which answers how long anything is kept. Trust center, security page and site navigation checked 7 September 2026.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

DeepJudge
Inherits document system permissions

This is the first record in the pull to reach this value, and it is the product's central architectural claim rather than an add-on. The quoted commitment continues that the synchronization ensures adherence to least-privilege principles and maintains ethical walls, so the access model being enforced is the firm's own, evaluated against the source systems rather than reimplemented inside the vendor's product. Because documents are indexed in place and never migrated, the authority for who may see what stays with the document management system that already holds it.

A customer confirms the effect in its own words on the customers page, describing permission-based search that ensures users only access authorized information. Two limits belong on the record. The published material does not state whether permission evaluation happens per user at query time or through periodic synchronization, and continuously synchronized is compatible with either. And nothing describes what happens to the index in the interval after a permission changes at source.

Fileread
Not addressed

No located public material addresses walls or matter-level segregation, and the product's own architecture makes the omission conspicuous. The platform is designed to read across an entire production and answer from all of it, including across documents, audio, video and spreadsheets in the same matter, which is precisely the retrieval shape this signal was written to test. Nothing published states whether one matter's material is isolated from another matter's inside the same customer, whether a reviewer on one side of a screened matter can query the other side, or how one customer's production is separated from another's. The Relativity integration sharpens the question rather than answering it: a firm running Relativity has already built workspace and matter permissions there, and nothing states whether Fileread enforces that access model at query time or maintains a second permission model the firm would have to keep aligned.

What is published is corporate access control rather than a wall, being least privilege, access monitoring, access log management and data asset classification, all of which govern who at the vendor and on the customer's account may reach data generally, and all of which are credited on the stewardship axis rather than counted twice here. No customer agreement is readable that might carry a segregation term. Trust center, homepage, security page and site navigation checked 7 September 2026.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

DeepJudge
Notice committed

Section 8(b) of the subscription terms commits the party receiving a demand to give the other prompt notice where it is required by applicable law, regulation, court order or legal process to disclose the other's confidential information, and adds that it will request that everything so disclosed is treated confidentially. The commitment reaches customer material because section 8(a) defines Confidential Information to include customer data expressly.

Asking the tribunal for confidential treatment is a step beyond bare notice and few records in this corpus offer it. The obligation is mutual rather than one-directional, and it survives termination. It is not the top value because no transparency report was located: nothing published records how many demands have been received or how they were handled. The website privacy policy separately permits disclosure in response to valid requests by public authorities without a notice commitment, but that document is scoped to website visitors rather than to platform data.

Fileread
Not addressed

No located public material addresses what happens when a third party demands customer data, and the reason is a readable one that belongs on the record. The two surfaces that ordinarily carry a compelled-disclosure position are the privacy policy and the customer agreement. The privacy policy is linked in the site footer, renders client-side on its hosting platform and returned the platform's shell with no body on this channel, and a search on clause language did not recover the text.

The Master Services Agreement and the Data Processing Agreement are both listed by name in the trust center and both sit behind an access request. No transparency report, law enforcement guidelines page or government request policy was located on any surface, and the trust center's legal section lists only the two agreements and a subprocessor entry. So nothing is established either way: no notice commitment, no reservation of discretion over notice, no undertaking to seek a protective order, and equally no statement that disclosure would occur without notice.

This is recorded as what could be established on the date rather than as a finding about the vendor's practice, and the privacy policy and the two agreements are the named rebuttal route. Site footer, trust center and site navigation checked 7 September 2026.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

DeepJudge
Not addressed

Checked the home page, product page, security page, subscription terms and privacy policy on 2 September 2026. No public material identifies any corpus, and none is claimed, because the product ships no content of its own. The material it works on is the customer's: documents retrieved from the customer's own document management system, email, SharePoint, OneDrive, HighQ, intranets and experience systems, indexed in place and never migrated.

Section 1(d)(i) of the subscription terms makes that explicit, defining Customer Data as data retrieved from the customer's databases plus user inputs and generated outputs, and warranting that the customer has the rights to share it. The provenance and licensing risks this signal tracks therefore sit with the firm rather than with the vendor, and the honest record is that the question is not addressed rather than that a corpus was withheld.

Fileread
Sources named, basis unstated

The corpus is identified unambiguously and no rights basis is stated, and most of this signal's limbs do not bite on a product of this shape. The source of every answer is the customer's own document production, which the vendor identifies plainly: the platform works on the productions a team already holds with nothing to migrate, reading across text, images, handwritten notes, audio, video and spreadsheets in the same matter, and every answer is pinned to the location in that material.

There is no vendor-assembled corpus of law behind the outputs, so the two risks this signal exists to price sit differently here. Coverage is not a question about the vendor's collection but about what the customer loaded, and the vendor addresses that directly on the risk side by publishing missed evidence, including incomplete ingestion, as one of its named failure modes. Title is not a question about legal publishing at all: no case law, legislation or editorial content is licensed in, so no third-party corpus could be enjoined and no license could be named.

What is genuinely unstated is the rights position around the customer's own material, since no readable agreement sets out what the vendor may do with an ingested production beyond the statement that nothing uploaded trains a shared model. The limbs that do not apply are named rather than penalized, and this is a structural difference from the research products in this lane rather than a disclosure gap. Homepage, failure modes paper and security page read 7 September 2026.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

DeepJudge
Not addressed

Checked the home page, product page, security page and subscription terms on 2 September 2026. No public material addresses subsequent history, treatment flags or good law checking, and none is claimed. The product does not retrieve primary law at all: it searches the firm's own precedents, advice, negotiation history and work product, so a citator has nothing to operate on. The adjacent risk that does exist is different in kind and is not addressed either, namely whether a precedent surfaced from the firm's own archive still reflects current law, which the platform leaves entirely to the lawyer reading it.

Recorded as not addressed with the reason rather than treated as a failure of a limb that does not bite on this product class.

Fileread
Not addressed

No located public material addresses whether authority is checked for subsequent history, and the limbs do not bite for this product class. Nothing the platform produces cites legal authority: answers, fact memos, chronologies, contradiction reports and deposition outlines cite documents in the customer's own production, so there is no reported decision, statute or secondary source whose treatment a user would need to check, and no citator could be licensed or built for a corpus of that kind.

The analog that does bite is currency within the record rather than currency of law, and the vendor addresses it in its own idiom rather than through this signal: its published failure taxonomy names context loss, where a later correction or the surrounding conversation changes the meaning of a cited passage, and date and sequence errors, where the date an event occurred is confused with the date a document was created, sent, received, modified or produced, with verification against metadata and document versions given as the control.

Those are credited on the Citation Accuracy axis and are not counted again here. Recording this as a non-applicable limb rather than a failure is the honest treatment: a document review platform has no citator, and it should be neither penalized nor credited for that. Failure modes paper, homepage and product surfaces checked 7 September 2026.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

DeepJudge
Not addressed

Checked the home page, product page, security page and subscription terms on 2 September 2026. Nothing describes what the platform does when it cannot ground an answer, and no confidence, relevance or grounding indicator is described as exposed to the user. The workflow layer is characterized as fully transparent, and the search results are documents the user opens, so the verification burden is placed on the reader rather than discharged by the system declining.

Section 4(j) of the subscription terms puts that burden on the customer contractually, requiring verification of accuracy and reliability through human review, which is an allocation of responsibility rather than an account of system behavior.

Fileread
Not addressed

No located public material describes what the system does when it cannot reach a supported answer, and this is the sharpest omission on the record because of what sits next to it. The vendor publishes an authored taxonomy of seven ways legal AI fails, including unsupported generation, missed evidence and conflicting evidence presented as certainty, and it opens by observing that legal AI can fail even when its output is clear, detailed and persuasive.

Its oversight paper adds that a fluent response may obscure uncertainty, missing context, conflicting evidence or an incorrect assumption, and lists showing uncertainty or gaps where practical among the properties a workflow ought to have. Every one of those is a description of the problem or a specification for tools in general; none states what this system does. Nothing published says that Fileread declines a question it cannot ground in the production, reports that it could not find responsive material rather than assembling a plausible answer, exposes a confidence or coverage signal to the reviewer, or flags where a chronology has a gap.

The detection controls in the taxonomy are addressed to the reader, requiring the lawyer to verify that the source supports the proposition and to confirm identity across multiple attributes, which places the uncertainty work on the user. The taxonomy itself is credited on the Citation Accuracy axis and is not counted again here. Failure modes and human oversight papers read in full, homepage and product surfaces checked, 7 September 2026.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

DeepJudge
None located

Searched the AI Hallucination Cases database maintained by Damien Charlotin, and reporting drawing on it, on 2 September 2026 on both the product name DeepJudge and the corporate name DeepJudge AG. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product. One structural note: the platform retrieves the firm's own documents rather than generating citations to primary authority, so the specific failure this signal tracks, a fabricated case reference reaching a filing, is not the failure mode this product creates. Its analogous risk is surfacing a superseded internal precedent, which no tracker records.

Fileread
None located

No court order, opinion or disciplinary record naming Fileread was located as of 7 September 2026. Searches were run on the product name against sanction and hallucination language and against the AI Hallucination Cases database maintained by Damien Charlotin, together with the secondary trackers that summarize it; the decisions naming specific tools name general-purpose chatbots and legal research products. The former name Fileread AI and the announced name Aurelogy were both included in the search terms.

This is a statement about the public record and not a finding about the product. Two features of this record bear on how it should be read. Exposure is structurally different from a research tool's, because the citations in this product's outputs point to documents in the customer's own production rather than to case law, so a fabricated authority in the classic sense is not the failure mode available here; the vendor's own taxonomy names the analogous risks instead, being unsupported generation and citing a real document for a proposition it does not establish.

And the vendor has engaged the question in public rather than avoided it, publishing that taxonomy under its own byline.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

DeepJudge
Not addressed

Checked the home page, product page, security page, subscription terms and privacy policy on 2 September 2026. No public material engages with guidance from any professional body governing the product's users, and neither ABA Formal Opinion 512 nor any state bar, law society or Swiss or Austrian bar guidance is named, despite a customer base spanning United States, United Kingdom, Swiss and Austrian practices. DeepJudge does engage a named legal instrument, making compliance with the EU Artificial Intelligence Act a contractual restriction on use at section 4(j) and excluding judicial and alternative dispute resolution applications, but that regulates the technology and its deployment rather than setting out the professional obligations of the lawyers using it, which is what this signal records.

Fileread
Generic reference

Professional responsibility is engaged substantively and in the vendor's own authored material, and no binding guidance is named. The engagement is real and specific to AI rather than boilerplate. The oversight paper states that artificial intelligence can assist with parts of litigation work but does not possess responsibility for the representation, and enumerates what remains the lawyer's: interpreting contested facts, assessing credibility, understanding procedural posture, protecting privileged material, applying legal standards and making strategic decisions.

It scales the required process to the use, distinguishing an exploratory question for internal orientation from a factual representation intended for a client, a witness examination or a court filing. Its checklist requires that privilege and confidentiality issues were addressed, that the output was reviewed under applicable legal and professional standards, and that a responsible professional approved the final use.

The paper carries an author and a practitioner review line and is dated. What is absent is any named authority. No bar association ethics opinion, no rule of professional conduct cited by number, no state or federal court standing order on AI disclosure and no regulator guidance appears anywhere, and nothing maps obligations by jurisdiction for a product sold into United States litigation where those standing orders are court-specific.

The value records engagement in general terms without named guidance, which is exactly what is published. Human oversight and failure modes papers read in full 7 September 2026.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

DeepJudge
Savings claims only

Time savings are claimed with figures and nothing addresses the bill. The home page publishes 65 hours saved per user per year on searching, a fourfold return in the first year, and 90 percent of users reporting they find results faster than with existing tools. No published material addresses how AI-assisted work is recorded, billed or disclosed to a client, and no per matter record of AI-assisted work was located. The gap has force here because the buyer is overwhelmingly private practice: the named roster is almost entirely law firms that bill clients for the time this product compresses, so the direction this signal assumes holds squarely.

The platform does emit configurable audit logs, described as letting a firm monitor its usage of DeepJudge, but that is described as a security and oversight facility rather than a matter-level record of AI-assisted work.

Fileread
Savings claims only

Time savings are the central marketing claim and nothing addresses the client's side of the bill. The product sits squarely inside a fee relationship: it is sold to case teams at law firms, and the work it compresses is document review and case preparation, which is billed to a client. The savings claims are explicit and quantified in attorney hours rather than in the abstract. One published account describes a production arriving as 4,000 text message screenshots that the platform converted and deduplicated to 725 messages, work stated to be more than 20 hours of attorney time.

Elsewhere the site promises a contradiction report that takes a lawyer eight hours in minutes, key documents and fact-checking during depositions accomplished in minutes as opposed to hours or days, insights to clients in days not weeks, and knowing the lay of the land on day one instead of week three. Against all of that, no published material addresses billing, fee treatment or client disclosure. Nothing tells a firm how to treat eight hours that became minutes, nothing offers a per-matter record of AI-assisted work that could support a fee narrative, and no guidance on disclosing AI assistance to a client was located.

The omission is worth naming precisely because the vendor engages professional responsibility carefully elsewhere, publishing an oversight framework and a failure taxonomy, so this is not a general silence about the lawyer's obligations. Homepage, oversight paper and site navigation checked 7 September 2026.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

DeepJudge
Subprocessors listed

A current subprocessor list is published at Annex 3, naming five entities with purpose and location: Microsoft Ireland Operations Ltd, Google Cloud EMEA Ltd and AWS EMEA SARL, each described as AI provider and cloud infrastructure with location customer selected, plus Intercom for support in Dublin and Gong. Governance around the list is strong: clause 5 requires written agreements on no less restrictive terms, due diligence on each subprocessor, liability for their acts, at least thirty days notice before a new subprocessor begins processing, and a right to object on reasonable data protection grounds with suspension or termination without liability if unresolved.

Clause 3.4 adds a purpose limitation binding subprocessors, barring selling or sharing, processing for other purposes, retention or disclosure outside the direct business relationship, and combining customer data with data from other sources. What stops this reaching the top value is the model provider limb. The three entities named as AI providers are the hyperscaler platforms, and no discrete model vendor appears anywhere.

Under the rule that infrastructure alone never satisfies this signal, a firm using DeepJudge can tell its client which cloud estates process its content but not whose model saw it. That is partly a consequence of the model-agnostic architecture, where the firm selects the model itself, but the gap in what the firm can forward is real.

Fileread
Subprocessors listed

A current subprocessor list is published without a gate and the forwardable pack around it is not. What a firm can take to a client today: a named subprocessor list carrying OpenAI, Baseten, Pinecone, Langfuse and Microsoft Azure, published on the open page of the trust center rather than behind the document request; a statement that a named model provider is in the path rather than only a cloud, which is the distinction a client's AI clause turns on; a subscribable feed of subprocessor changes with dated entries, so the firm can answer how it will learn of a new provider; and five compliance positions including ISO/IEC 27001:2022 with its version and SOC 2 Type 2.

That is a substantive answer to the first half of a client questionnaire. What a firm cannot forward is the material itself. The Data Processing Agreement and the Master Services Agreement are both listed in the trust center behind an access request, so the confidentiality, security and liability terms a client's outside counsel guidelines ask about cannot be sent in advance, and no separate client-facing disclosure pack, AI use notice or consent template was located.

Under the standing rule that the top value needs a forwardable artifact alongside the lists, and that a subprocessor list sitting outside a data processing agreement with no other forwardable document drops a rung, this takes the middle value. No access request was submitted. Trust center and security page read 7 September 2026.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

DeepJudge
Not addressed

Checked the home page, product page, security page and subscription terms on 2 September 2026. Nothing addresses judicial standing orders, disclosure of AI use, or certification that output was verified by a person. Configurable audit logging exists and would record who searched for what, but it is presented as a firm oversight and security facility and nothing describes an exportable per document record capturing which model produced which passage, what was retrieved and who reviewed it.

The product class is relevant: the platform surfaces the firm's own documents rather than generating citations to authority, so the artifact a court would ask about is the work product built afterwards rather than the search itself.

Fileread
Not addressed

No located public material offers a record of AI-assisted work that a lawyer could produce to a court, and the vendor's own writing shows it has thought about the need without meeting it. Its oversight paper tells teams to settle in advance the record that should be retained of the process, and its checklist asks that corrections and unresolved questions were recorded and that a responsible professional approved the final use.

Those are instructions to the firm to keep its own record, not a product that emits one. Nothing published states that Fileread records which model or module produced a given output, what it retrieved, which sources it considered and rejected, or what a person verified before the result was used, and no export, certification or template framed for a court or a standing order is offered. Two adjacent things are named so the grade is read correctly and neither is counted twice.

The source citation on every claim, which links work product to the page it came from, is the product's central mechanism and is credited on the Citation Accuracy axis; it evidences what an output rests on rather than what the system did to produce it. Audit logging appears in the trust center as a product security control, which records access to data rather than the conduct of AI-assisted work, and it is credited on the stewardship axis. Human oversight paper, homepage, trust center and product surfaces checked 7 September 2026.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Signals neither addresses in public material
  • Good Law Verification
  • Refusal and Uncertainty Behavior
  • Court Disclosure Support

Which one fits

Choose DeepJudge if

  • Your problem is finding what the firm already knows. DeepJudge indexes documents where they sit, across the document management system, email, SharePoint, OneDrive, HighQ and intranets, and runs intent based search that syncs permissions so ethical walls hold.
  • Your data cannot leave the building. DeepJudge's terms define cloud, on premises and hybrid deployment, and state that in hybrid mode only model processing leaves the firm's own infrastructure.
  • You want the contract readable before you buy. DeepJudge publishes subscription terms barring training on customer data, capping liability mutually, indemnifying against infringement and setting 99 percent quarterly uptime, plus a data processing addendum with 72 hour breach notice.

Choose Fileread if

  • Your problem is a document production for a live matter. Fileread reads text, images, handwritten notes, audio, video and spreadsheets, answers questions in plain language, and pins every answer to its exact location in the source.
  • Your team works in Relativity. Fileread runs as a native integration inside Relativity on productions already there, and builds chronologies, contradiction reports, deposition outlines and factual briefs as drafts for review.
  • You need to show a client whose AI sees the production. Fileread's trust center lists OpenAI, Baseten, Pinecone, Langfuse and Microsoft Azure as subprocessors, with a subscribable feed of changes, and states SOC 2 Type 2 and ISO 27001:2022.

In summary

DeepJudge

DeepJudge, from DeepJudge AG of Zurich, founded by former Google Brain researchers, is an AI search and workflow platform that indexes a firm's documents where they sit across the document management system, email, SharePoint, OneDrive, HighQ and intranets, keeping the firm's permissions and ethical walls, with a builder for AI agents. The AI Legal Index grades it in the top two bands on fourteen of fifteen capability axes. Its published terms bar training on customer data, and it deploys in its cloud, the firm's cloud or on premises. It states SOC 2 Type II and ISO 27001 and names Freshfields, Greenberg Traurig and Homburger among customers. As of 2 September 2026 the index located no price figure.

Source: AI Legal Index, 2026

Fileread

Fileread is an AI fact finding platform for litigation and investigations, reading a whole document production across text, images, handwriting, audio, video and spreadsheets and answering in plain language with each answer pinned to its source. It produces chronologies, contradiction reports, deposition outlines and factual briefs, and runs natively inside Relativity. The AI Legal Index grades it in the top two bands on eleven of fifteen capability axes, with A grades on AI centrality and data stewardship. It names OpenAI and four other subprocessors, states SOC 2 Type 2 and ISO 27001:2022, and names customers including Kellogg, Hansen and Nutter McClennen & Fish. As of 7 September 2026 the index located no price or retention period.

Source: AI Legal Index, 2026

Questions buyers ask

Are DeepJudge and Fileread the same kind of product?

Both search a legal team's own documents with AI, but for different jobs. DeepJudge searches a firm's accumulated knowledge across its document systems, email and intranets. Fileread reads a litigation production to find facts for a matter. On the AI Legal Index DeepJudge sits in the top two bands on fourteen of fifteen capability axes and Fileread on eleven of fifteen, identical on eight.

Does DeepJudge respect ethical walls?

DeepJudge states that access permissions are continuously synchronized from the firm's source systems, so existing ethical walls are maintained rather than rebuilt, and documents are indexed in place without migration. It does not say whether permissions are checked per user at query time or by periodic sync. Fileread publishes no position on walls between matters. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 27, 2026. No vendor pays for placement.

Which AI providers see the documents?

Fileread's trust center names OpenAI, Baseten, Pinecone, Langfuse and Microsoft Azure as subprocessors and publishes a feed of changes. DeepJudge's data processing addendum names Microsoft, Google Cloud and AWS as AI providers and cloud infrastructure, with location chosen by the customer, since the firm selects its own models. Neither names a specific model. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 27, 2026. No vendor pays for placement.

How are DeepJudge and Fileread priced?

Neither publishes a figure. DeepJudge's terms set a yearly subscription per user on an order form in US dollars, with a threshold of 500,000 documents or 250 gibibytes per user above which it may charge more. Fileread publishes no pricing page, tier or unit; every route leads to a demo. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 27, 2026. No vendor pays for placement.

What do DeepJudge and Fileread both leave unpublished?

An accuracy measure and a disclosure record. Neither publishes an error rate for its AI answers, and neither offers an exportable record of which model produced an output and who checked it. Neither names bar or law society guidance, and neither addresses how AI assisted work should appear on a client's bill. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 27, 2026. No vendor pays for placement.

Disclosure

Three readings to weigh. Fileread's master services and data processing agreements sit behind a trust center request, and it states no retention or deletion position for uploaded productions. DeepJudge's addendum describes processing to improve its services while its terms bar training; the terms name training and the addendum does not. On 17 September 2026 DeepJudge released a ChatGPT plugin, and whether its permission model holds there is not yet published. DeepJudge was verified on 2 September 2026 and Fileread on 7 September 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 26, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746