Eudia vs Harvey: how they compare in 2026

Eudia profileHarvey profile
Last verifiedSeptember 3, 2026

Eudia and Harvey both sell an AI platform to the in house legal department, and Eudia positions itself directly against Harvey for that buyer. Harvey sits in the top two bands on twelve of fifteen axes, Eudia on seven, and the gap is certification and measurement. Harvey holds ISO/IEC 42001 with a published statement of applicability and an AIUC-1 certification conducted by Schellman, names Schellman again as the auditor behind its SOC 2 Type II and ISO 27001, and names NCC Group and Bishop Fox as its penetration testing and red teaming partners. Its accuracy has also been measured by a third party, scoring between 65.0 and 94.8 per cent across six tasks in the February 2025 Vals Legal AI Report and beating the measured lawyer baseline on five of them. Eudia answers on customer evidence and architecture. It names Duracell, Graybar and Cargill with a figure against each, and it holds no repository of its own, connecting instead to the systems where the work already sits.

At a glance

Category
EudiaGeneral Legal Assistants
HarveyGeneral Legal Assistants
Founded
EudiaNot published
Harvey2022
Headquarters
EudiaNot published
HarveySan Francisco, California, United States
Last verified
EudiaSep 2, 2026
HarveyAug 29, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Eudia
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

There is no conventional product underneath. Eudia holds no repository, no matter management and no contract lifecycle system of its own: the systems of record stay where they are, at Google Drive, SharePoint, Box, Salesforce, DocuSign, Onit and LinkSquares, and Eudia connects to them. What it sells is the intelligence layer, described as codifying proprietary data and institutional knowledge into enterprise-grade legal agents, marketed as expert digital twins and an Enterprise Brain. Remove the models and nothing remains to sell, because everything Eudia adds is model-produced. The one qualification worth naming is that delivery is partly human: Forward-Deployed Engineers is one of the seven listed solutions, and the separately branded Eudia Counsel arm runs on the same platform. Neither displaces the models as the thing the buyer pays for. Verified 2 September 2026.

Harvey
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

The models are the product. Assistant, Vault, Knowledge and Workflow Agents are all generative systems, and there is no underlying document or workflow system that would stand without them. Vendor material describes every module in model terms.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Eudia
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

One grounding claim is published and nothing stands behind it. The home page states that Eudia connects systems, documents and workflows to ensure every decision is grounded in real-time, organization-specific context. No retrieval method is described, no source-linking behaviour is documented, no accuracy figure appears anywhere, and no test set or evaluation is published on any surface read. The trust centre lists AI Security and AI Risk Management as items but their contents sit behind an access request and were not read, so nothing in them is credited here. Checked the home page, integrations page, success stories, terms of use, privacy policy and the trust centre index on 2 September 2026. The claim is what keeps this off D; the absence of any mechanism or measurement is what holds it at C. Verified 2 September 2026.

Harvey
AA on Citation Accuracy and Hallucination DisclosureMeasured accuracy is published with the test set described and the failure modes named. Output grounds to primary authority the reader can open, citation status is checked, and the system states when it found no support.

CORRECTED 29 Aug 2026, second correction to this row. Previously graded B on two stated grounds, both of which are now resolved. Ground one was that BigLaw Bench is the vendor's own framework rather than independent evidence. That remains true of BigLaw Bench, but independent evidence also exists and was missed: Harvey Assistant participated in the February 2025 Vals Legal AI Report, a third party benchmark against a measured lawyer baseline, and was evaluated across six tasks scoring between 65.0 and 94.8 percent, surpassing the lawyer baseline on five of the six, with 94.8 percent on document question answering at 24.7 points above baseline and 77.8 percent on scanned and messily formatted court transcripts at 24.1 points above baseline, all at sub minute response times. Those figures sit on the evaluator's own site and are checkable without reference to any vendor claim. Ground two was that the citator and refusal limbs failed. That was a double count and is withdrawn: both are separately measured by their own signal rows on this record, and applying them again to the capability grade penalised the same absence twice. It was also inconsistent, since three legal research vendors on this index hold an A on this axis with both of those signals recorded as not addressed. The vendor's own disclosure is unchanged and remains substantial: BigLaw Bench with task categories and grading rubrics on a public repository, measured hallucination rates and source scores by model, a hallucination defined as a factual claim disprovable against a source of truth with reasoning errors tracked separately, and output linking to the specific document passages supporting each assertion. Two limits recorded rather than deducted for: the February 2025 study measured task accuracy rather than citation validity or hallucination rate specifically, and this vendor did not participate in the later Vals study that measured citation authoritativeness. The full BigLaw Bench dataset also sits behind a direct request rather than open publication.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Eudia
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

The autonomy claim is unusually explicit and the oversight account is a word. Eudia sells Decision Self-Service, described as delivering governed intelligence across the enterprise, and the site's own framing is that the Enterprise Brain makes the business self-sufficient without scaling headcount. That describes business users obtaining legal answers without the legal team in the loop, which is the strongest autonomy position of any record built in this pull. Against it, oversight appears only as adjectives: intelligence is said to be secure, governed and auditable. Nothing published names a review point, an approval step, a confidence threshold, a mode in which an agent stops, or what happens after an agent is wrong. Human in the loop appears as a phrase rather than a described control, which is the C band exactly. Verified 2 September 2026.

Harvey
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

States in published material that the product is designed to assist lawyers rather than replace them and that it is built to make verification easy. Review surfaces are real and documented: inline links to source passages, role based permissions and conditionals in the workflow builder, and admin level workspace governance. Not located as of 29 Aug 2026: the threshold at which an agent stops and hands back to a lawyer, or what the vendor commits to when an agent is wrong.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Eudia
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Three named enterprises, each with a figure and a dedicated case study. Duracell is reported at 50 per cent savings on contracting costs using the AI Contracting MIND; Graybar at 98 per cent faster diligence, described as contract review falling from four hours to five minutes using the AI M&A MIND; and Cargill at a 50 per cent reduction in contracting research time using Contract Insights, with Rishi Varma, Chief Legal and Compliance Officer, quoted by name and title on the home page. These are Fortune 500 legal departments rather than logos, which is real deployment evidence. What holds it below A is that the success stories index carries no dates and no measurement basis for any of the three figures, and the individual case studies were not opened this pass. Verified 2 September 2026.

Harvey
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Named customers appear in vendor material with attributed quotes, including Blank Rome on the iManage integration and a published Burges Salmon selection story. Vendor states 700 plus customers across 58 plus countries. Not located as of 29 Aug 2026: dated outcome figures with a stated method a reader could assess, which is what separates this from an A.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Eudia
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

For a platform sold to Fortune 500 legal departments, nothing a buyer can read before signing addresses how client confidences are handled. No customer agreement, master subscription agreement or data processing addendum is published: the only agreement on the site is a website terms of use, and the privacy policy states expressly that it does not apply to personal information stored on behalf of customers, which is governed instead by contracts with the relevant customer. That leaves every question this axis asks unanswered in public. No training commitment for customer content, no privilege or work product treatment, no matter or tenant segregation, no retention or deletion terms, and no statement of what the named model providers may retain. The commitments are not absent from the business, they are unreadable in advance: a Data Protection Policy and an AI Training Data and Bias document exist on the trust centre behind an access request that was not completed. A commitment that lives only in a sales conversation is what the C band describes. Verified 2 September 2026.

Harvey
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Substantive published commitments: no training on customer data by default, a contractual prohibition on model providers training, zero data retention enforced on model providers, logical workspace separation, role based access, ethical wall sync with the firm's own walls provider, and processing in the EU, Switzerland or Australia. Two gaps keep this off an A. The security page defines customer data as uploaded documents and customer content as queries and responses as separate contractual terms, so the no training commitment reads plainly on one and not on both. Attorney client privilege and work product handling is not addressed directly in located public material as of 29 Aug 2026.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Eudia
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

The only disclaimers published are in the website terms of use and they are scoped to the website. Section 5.1 says site content is for informational purposes and that the reader is solely responsible for verifying its accuracy, and section 11 disclaims all warranties for the Site and the Technology used to operate it. Nothing states that platform output is not legal advice, and nothing addresses supervision, competence or jurisdiction limits. Against that, the marketing describes the product in decision terms: Decision Self-Service delivering governed intelligence across the enterprise, agents encoding expert judgment, and an Enterprise Brain that makes the business self-sufficient. The audience question is live rather than theoretical, because that positioning points at business users outside the legal department. Boilerplate in the terms alongside marketing that describes the product in advice terms is the C band. No bar or ethics guidance is engaged on any surface read. Verified 2 September 2026.

Harvey
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

One sentence in a security blog post states the product is designed to assist lawyers rather than replace them. Checked the vendor site, security page, security addendum and help center on 29 Aug 2026 and did not locate a published position on the advice line, on competence and supervision duties, or on jurisdiction limits. The intended audience is unambiguously lawyers and legal departments, which is why this sits at C rather than lower.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Eudia
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

Eudia holds ISO/IEC 42001:2023, listed as a current certification in the public compliance section of its trust centre alongside SOC 2 Type 2, ISO/IEC 27001 and GDPR. That is a published, independently audited AI management system standard rather than a self-authored principles page, and it is the strongest governance evidence located in this pull so far. The trust centre also carries a dedicated AI section listing AI Training Data and Bias, AI Security and AI Risk Management, so the vendor has assembled bias material; its contents sit behind an access request and were not read, and nothing in them is credited here. What the top band asks for beyond a framework is still missing from anything public: no individual or function is named as accountable for model behaviour, and no testing result or bias finding is disclosed. Verified 2 September 2026.

Harvey
AA on AI Governance and Bias DisclosureGovernance is documented and owned: who inside the vendor is accountable, what is tested before release, and what has been found and disclosed about uneven output across matter types or populations.

CORRECTED 29 Aug 2026, third correction to this record. Previously graded C on the finding that no AI specific governance regime was located and that the published testing was security testing rather than model behaviour testing. That was wrong, and it came from reading the vendor's marketing surfaces rather than opening its trust centre, where the governance material actually sits. What is published on the trust centre, publicly and without a request: ISO/IEC 42001:2023 certification, the international standard for AI management systems, accompanied by a published Statement of Applicability, which is the document identifying which controls apply and why and is therefore a published scope rather than a bare badge. Alongside it, AIUC-1 certification, an AI specific assurance standard, conducted by Schellman, which the vendor states is the first accredited AIUC-1 certification body, and which the vendor describes as validating adversarial testing and its AI security programme specifically. EU AI Act conformity is separately listed. The trust centre carries a dedicated AI section with AI Governance, AI Monitoring and AI Overview items, and an AI Acceptable Use Policy sits in the published policy set. ISO 27701 for privacy information management and an IRAP attestation are also held. Two independent AI specific certifications, one of them adversarially tested, with published statements of applicability and a named accredited certifier, is the strongest AI governance position on this index, ahead of the four other A grades on this axis, each of which rests on ISO 42001 alone or on a single certification plus a framework document. One gap remains and is recorded rather than waived: no disclosure was located about uneven output across matter types, parties or populations, so bias specifically is still unaddressed, and no named individual owner of model governance was located.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Eudia
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

Of the five things this axis names, one is publicly readable. The subprocessor list is public and specific, naming Elastic, Amazon Web Services, Anthropic, OpenAI and Microsoft Azure. The other four are not. Retention and deletion for customer content are addressed nowhere: the privacy policy's retention section covers personal information Eudia holds as controller and says only that it is kept as long as necessary, and that policy expressly excludes data held on behalf of customers. No incident or breach notification commitment is published, and no access control detail beyond the fact of SOC 2 Type 2 and ISO 27001 attestation. The trust centre inventory shows the material exists, listing Data Breach Notifications, Certificates of Destruction, Data Asset Classification, Access Monitoring, a Data Protection Policy and a Backup Policy, all behind an access request that was not completed. This is a grade about publication rather than about whether the controls exist, and one request would likely change it. Verified 2 September 2026.

Harvey
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Publishes retention under customer control with documented vault retention triggers and deletion timelines, role based access control, logical workspace separation, encryption in transit and at rest, and a current named subprocessor list with an update FAQ. Not located as of 29 Aug 2026: a published incident and breach notification practice, which is the remaining element of the A bar.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Eudia
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

The published allocation of loss does not reach the product. Eudia's only published agreement is a website terms of use, which by its own first sentence governs use of content available at www.eudia.com. It carries a total cumulative liability cap of five hundred dollars at section 13, an indemnity running only from the user to Eudia at section 12, and a full warranty disclaimer at section 11. Section 5.2 states that access to specific areas of the Site is subject to a further agreement called an Annex, which is where platform terms sit and which is not published. So a buyer evaluating the Enterprise Brain cannot read any indemnity, cap, carve out or output warranty that applies to it. What is locatable is the existence of cyber insurance, listed as a document on the trust centre behind an access request. A standard limitation clause that disclaims the exposure, with the operative terms reachable only through a negotiated agreement, is the C band. The five hundred dollar figure is recorded because a reader will find it, not because it governs the platform. Verified 2 September 2026.

Harvey
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

Checked the vendor site, its published legal pages including the security addendum and the subprocessor FAQ, and the trust center on 29 Aug 2026. No published indemnity scope, liability cap, carve out, warranty or insurance position located. Commercial terms appear to be reached through a negotiated enterprise agreement rather than published.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Eudia
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Seven integrations are named and grouped by function into document storage, contract management, revenue and business systems, and agreement execution: Google Drive, SharePoint, Box, Onit, Salesforce, LinkSquares and DocuSign. That is a genuine reach into the systems an in-house department's work already lives in, including two legal-specific ones in Onit and LinkSquares. Each carries a single line of marketing copy describing an outcome rather than a mechanism, for instance that the Salesforce connection links legal workflows with deal and customer data. Nothing states what synchronises, in which direction, on what trigger, or what a customer must configure, and no developer documentation, API reference or implementation guide was located anywhere on the site. Named connections without a description of what they actually move is the B band. Verified 2 September 2026.

Harvey
AA on Practice Systems Integration DepthDocumented, verifiable integrations into the systems legal work already lives in, with the depth described: what syncs, in which direction, and what a firm must configure.

Documented native integrations with iManage, NetDocuments, SharePoint and OneDrive, Google Drive, Box, Microsoft Word, Outlook, EDGAR and PitchBook, plus an MCP connector library. Help center articles describe what each integration moves, in which direction, what an admin must configure, and what a given integration does not support. The iManage connection is a direct OAuth integration with an embedded web extension rather than third party middleware.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Eudia
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Cloud delivery is evident and neither of the two things this axis asks for is stated. The trust centre names Azure under infrastructure and the subprocessor list adds Amazon Web Services, so the hosting providers are known, but naming a cloud provider identifies infrastructure rather than answering where a customer's data sits. No region or residency option is published anywhere, and the privacy policy points the other way, saying only that Eudia is headquartered in the United States, works with service providers in the United States and other countries, and that information may be stored in those or other locations outside the reader's home country. No tenancy model is stated: nothing describes the platform as multi-tenant, single-tenant or privately deployed. Under the co-equal limbs rule either one would clear this band and neither is present. Verified 2 September 2026.

Harvey
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed.

States processing in the EU and Switzerland or Australia for customers with data localization requirements, and states that this applies to subprocessors as well. Tenancy is multi tenant with logical workspace separation and enforced role based access. Not located as of 29 Aug 2026: where data is stored as distinct from where it is processed, and what changes between tiers.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Eudia
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

This is the strongest trust surface located in the pull so far. A SafeBase-hosted trust centre at trust.eudia.com renders publicly and lists four current standards by name, SOC 2 Type 2, ISO/IEC 27001, GDPR and ISO/IEC 42001:2023, alongside an inventory of thirteen documents including a SOC 2 Report, a Pentest Report, a Security Whitepaper, a Network Diagram and a Data Flow Diagram, plus third-party security grades from SecurityScorecard and Qualys SSL Labs. What is public is the inventory; the reports themselves sit behind a Get access flow. The portal describes that flow as starting a security review and requesting access without stating whether it fulfils on an email and a click-through or routes to a sales conversation, so the access tier could not be established and the lower tier is graded, which is why this is not an A. No auditor is named and no coverage period appears on any public page. Verified 2 September 2026.

Harvey
AA on Security Certifications and Trust CenterCurrent independent attestation with named scope, reachable without a sales call: a trust center carrying reports, dates and the standards actually covered.

SOC 2 Type II attestation and ISO 27001 certification with the auditor named as Schellman, renewed annually, and the 2026 cycle announced publicly. Penetration testing and red teaming partners are named as NCC Group and Bishop Fox. Certified under the EU US Data Privacy Framework. A live trust portal at trust.harvey.ai carries the current reports. Reports sit behind a portal request rather than an open download, which is a request flow rather than a sales call.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Eudia
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

The providers are named publicly, which most of this pull does not manage. The trust centre's subprocessor entry lists Anthropic and OpenAI as model providers alongside Elastic, Amazon Web Services and Microsoft Azure as infrastructure, and it is readable without completing any access request. Two of the four things the top band asks for are absent. The models themselves are not named, only the houses they come from, and naming a provider does not satisfy the separate limb requiring the models underneath be identified. Nothing commits to notifying customers when the supply chain changes, and no subprocessor change-notification term is published, which is unsurprising given that no customer agreement or data processing addendum is published at all. Where the models run is not stated. Verified 2 September 2026.

Harvey
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Publishes a subprocessor list naming model and infrastructure providers including OpenAI, Anthropic, Google Cloud, AWS and Microsoft, alongside a subprocessor update FAQ and a security diagram showing model access through Bedrock and Vertex AI. States zero data retention and ephemeral processing at the model providers. Not located as of 29 Aug 2026: a published commitment to notify customers before the model supply chain changes, as distinct from an FAQ describing a change that has already happened.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Eudia
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing information is published at any level, including the unit of charge. Checked the home page, the full navigation and footer, the five solution pages as listed in the navigation, the government page, the integrations page, the success stories index, the terms of use, the privacy policy and the trust centre on 2 September 2026. No pricing page exists in the site's own navigation or footer, and the only commercial route offered anywhere is Schedule a demo or Book a demo. Solution areas are named and so are three product units, the AI Contracting MIND, the AI M&A MIND and Contract Insights, but a product structure is not a pricing structure: no tier, no seat or consumption unit, no term and no figure appears. Verified 2 September 2026.

Harvey
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Checked the vendor home page, the platform and product pages, the help center and the trust center on 29 Aug 2026. No pricing page, no published rate, no stated unit of charge and no published tier structure located. Access to pricing runs through a demo request, which is sales gated and earns no credit. Third party per seat estimates exist in trade coverage but are not vendor published and do not move this axis.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Eudia
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Coverage is described with real substance on both dimensions the band asks about. Practice areas are enumerated as five named solutions: marketing compliance, contracting and deal acceleration, decision self-service, mergers and acquisitions, and litigation. Buyer segments are stated and separated, with an enterprise track and a distinct government track described as purpose-built for government acquisition teams, which is an unusual and specific addition. The named customers bear out the enterprise claim at the top of the market, with Duracell, Graybar and Cargill. What is left open is the boundary. Nothing states what the platform does not support, no company size floor is given, no jurisdiction or geography is named, and the relationship between the platform and the separately branded Eudia Counsel services arm is not explained in coverage terms, so a buyer cannot tell where the software stops and the service begins. Verified 2 September 2026.

Harvey
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Describes its segments with substance: large law firms first, expanding into corporate legal departments and professional services, with 700 plus customers across 58 plus countries and practice coverage spanning litigation, transactional diligence, regulatory and tax. Not located as of 29 Aug 2026: a statement of the boundaries, meaning which firm sizes or practice areas the product is not built for, which is what the A bar asks for.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Eudia
Terms silent

Nothing published addresses whether customer content trains models, in either direction. The quoted line is real and a buyer will find it, but it must be read with its scope: it sits in the privacy policy's table of legal bases for European residents, and that policy states at the outset that it does not apply to personal information stored or maintained on behalf of customers, which is governed instead by contracts with the relevant customer. So Training AI System is disclosed as a processing purpose for the data Eudia holds as controller, which is website, marketing and account information, and the customer content question is left to unpublished agreements. No customer agreement or data processing addendum is published. An AI Training Data and Bias document exists on the trust centre behind an access request that was not completed. Checked the home page, terms of use, privacy policy, integrations, success stories and trust centre index on 2 September 2026.

Harvey
Never, in policy only

The vendor security page states that by default it never trains on customer data and that it contractually prohibits model providers from training on customer data. A subprocessor FAQ states customer data is never used to train models unless explicitly authorized by both the customer and the vendor. The same page defines customer data as uploaded documents and customer content as queries and responses as separate contractual terms. No matching term was located in a published agreement as of 29 Aug 2026.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Eudia
Not addressed

Checked the home page, terms of use, privacy policy, integrations page, success stories and trust centre index on 2 September 2026. No public material states how long prompts, outputs or uploaded documents are retained. The privacy policy has a retention section but it governs personal information Eudia holds as controller, says only that data is kept as long as necessary to fulfil the purpose of collection, and expressly excludes data held on behalf of customers. The trust centre lists Certificates of Destruction and a Backup Policy, which indicates a retention and destruction practice exists, but both sit behind an access request that was not completed and neither was read.

Harvey
Customer controlled, no zero option

REGRADED 29 Aug 2026 after the value set was amended; previously recorded at disclosed without a period, which understated real customer control. The security page states that customers determine what data to upload, how long it is retained, and whether it can be shared internally, and help centre documentation covers configuring vault retention settings including triggers and deletion timelines. That is retention configured by the customer inside the product, which is the strongest form of the control this value describes. Recorded at customer controlled rather than the top value because no zero retention setting for the vendor's own storage was confirmed in public material as of 29 Aug 2026, and no default period is published, so a customer knows they can set the window without knowing what it is before they do. Zero data retention is stated separately as a requirement imposed on model providers, which is a different layer.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Eudia
Not addressed

Checked the home page, integrations page, terms of use, privacy policy and trust centre index on 2 September 2026. Nothing addresses walls, matter separation or whether retrieval respects the access model of the systems it draws from. This matters more here than for most records because the platform indexes across Google Drive, SharePoint, Box, Salesforce, Onit and LinkSquares, so the question of whose permissions govern at query time is live, and the marketing answers it only with the assertion that intelligence is secure, governed and auditable, meeting enterprise requirements for access control. The trust centre lists Environment Segregation under infrastructure, which concerns separation of environments rather than of matters or users, and its contents were not read.

Harvey
Inherits document system permissions

Help center documentation states the product follows existing NetDocuments permissions, that a user sees only the cabinets, matters, folders and files they can already access, and that the product does not expand or modify permissions. The iManage integration is documented as a direct OAuth connection that respects iManage permissions and ethical walls. Separate admin documentation covers connecting, syncing and monitoring the firm's own ethical walls provider.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Eudia
Disclosure addressed, notice absent

The privacy policy addresses compelled disclosure in two places, stating that Eudia will use personal information as it believes necessary to comply with lawful requests and legal process, including responding to subpoenas, and that it may be required to disclose to law enforcement, government authorities and other parties in response to valid requests by public authorities. No commitment to notify the customer, and no reservation of discretion over notice, is located anywhere on any surface read. That is the state this value was created for: the vendor has told the reader data can leave and has said nothing about whether they hear of it. The scope qualification belongs on the record, since the policy governs data Eudia holds as controller and expressly excludes customer content, for which no agreement is published at all.

Harvey
Not addressed

Checked the security page, the published security addendum and the subprocessor update FAQ on 29 Aug 2026. No located term or policy addresses government or law enforcement requests for customer data, and no transparency report was located.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Eudia
Not addressed

Checked the home page, the solutions listing, integrations page, terms of use, privacy policy and trust centre index on 2 September 2026. No public material identifies a corpus. The platform's material is the enterprise's own contracts, policies, precedent and institutional knowledge, drawn from the customer's existing systems, rather than a published body of primary law, so the coverage and title risks this signal tracks do not arise in their usual form. Nothing published suggests the product retrieves primary authority, and no jurisdiction coverage statement of any kind was located.

Harvey
Sources named, basis unstated

The published subprocessor material identifies RELX and LexisNexis as a source provider behind an Ask LexisNexis feature, alongside web search providers, and product material refers to premium legal databases and curated public sources. The identification appears in the subprocessor list rather than a coverage page. No licence or rights basis, jurisdiction list or update cadence for the primary law corpus was located as of 29 Aug 2026.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Eudia
Not addressed

Checked the home page, the solutions listing including the litigation solution, integrations page and trust centre index on 2 September 2026. No public material addresses subsequent history, treatment flags or citator coverage. The product is built on enterprise documents rather than primary authority and claims no citator function, so this is a case where the question does not bite on the product class; the honest value is that it is not addressed rather than that a weaker form of checking exists.

Harvey
Not addressed

Checked product pages for the research module, the help center and the subprocessor material on 29 Aug 2026. A LexisNexis sourced research feature is documented, but no public material was located addressing whether authority returned by the product carries a treatment signal or is checked for subsequent history.

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Eudia
Not addressed

Checked the home page, the solutions listing, integrations page, terms of use and trust centre index on 2 September 2026. Nothing describes what the platform does when it cannot ground an answer. No abstention path, no no-answer behaviour and no confidence or grounding score is documented, so the weaker values are false of this record too. The only adjacent published statement is that decisions are grounded in real-time, organization-specific context, which asserts grounding without addressing what happens when the context does not contain the answer.

Harvey
Not addressed

The vendor publishes measured hallucination rates and describes how hallucinated claims are detected and scored. Checked that research material, the product pages and the help center on 29 Aug 2026 and did not locate published material describing an explicit no answer or abstention path when the product cannot ground an answer.

Fabricated Citation Record

Does a public court record exist involving output from this product?

Eudia
None located

Searched the AI Hallucination Cases database maintained by Damien Charlotin, and reporting drawing on it, on 2 September 2026 on both the product name Eudia and the corporate name Cicero Technologies. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product. Worth noting for a future grader that the same company operates a legal services arm and law firm under the Eudia Counsel brand, so a future search should cover that name as well.

Harvey
None located

No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published sanctions summaries from Norton Rose Fulbright covering 2026 and two vendor maintained trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance, and it is bounded by what that database covers.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Eudia
Not addressed

Checked the home page, the solutions listing, integrations page, success stories, terms of use, privacy policy and trust centre index on 2 September 2026. No public material engages with ABA Formal Opinion 512, any state bar opinion, or any other named ethics guidance, and nothing addresses professional responsibility even in general terms. The absence is worth noting against the product's positioning, which contemplates business users outside the legal department obtaining legal answers through Decision Self-Service.

Harvey
Generic reference

Published material refers in general terms to aligning with the high standards expected of legal work and to designing the product so that verification is easy. Checked the blog, resource pages and help center on 29 Aug 2026 and did not locate engagement with any named ethics opinion, including ABA Formal Opinion 512 or state bar guidance.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Eudia
Savings claims only

Savings claims are the published position: 50 per cent savings on contracting costs at Duracell, 98 per cent faster diligence at Graybar, and a 50 per cent reduction in contracting research time at Cargill. The Duracell story is framed as a shift from billed hours to billed outcomes, but that describes how the customer pays for legal work rather than how AI-assisted work is recorded or disclosed, and no per matter record of AI-assisted work was located. The direction this signal assumes is also inverted here, as it is for other in-house products: Eudia's buyer is the legal department that receives bills rather than the firm that issues them, so the compression it markets lands on outside counsel spend and internal capacity.

Harvey
Savings claims only

Vendor material offers impact and return on investment resources framed around what the product does for a firm or business, and the help center documents usage analytics dashboards and reporting APIs. Checked those surfaces on 29 Aug 2026 and did not locate a per matter record of AI assisted work intended for fee purposes, or any published guidance on billing, fee or client disclosure treatment.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Eudia
Subprocessors listed

A current subprocessor list is published on the trust centre and is readable without completing any access request, naming Anthropic and OpenAI as model providers alongside Elastic, Amazon Web Services and Microsoft Azure as infrastructure. That clears the test that infrastructure alone never satisfies this signal, and it means a department asked which providers see its content can answer. The top value is not reached because the third limb is missing: the forwardable client-facing material exists but is gated. The Data Processing Agreement, Security Whitepaper and Data Protection Policy all appear on the trust centre inventory behind a Get access flow whose tier could not be established, so none is published or available without a request.

Harvey
Subprocessors listed

UPDATED 29 Aug 2026 during the trust portal sweep; value unchanged, evidence enumerated. The trust centre was opened directly and its published inventory is the most complete outside counsel readiness pack on this index. Available without a request, as named items: a Data Processing Addendum, a Business Associate Addendum, a Data Subject Requests item, completed self assessment questionnaires in three standard formats being CAIQ v4.0.3, SIG Core and SIG Lite, a Data Flow Diagram, a Network Diagram, a HIPAA report, a report titled Security and Privacy of Customer Data, and a Security Welcome Packet. A Subprocessors section is published as a standing part of the trust centre. Sensitive documents sit behind a self serve access request with a bulk download option. Compliance items are listed individually and include statements of applicability for ISO 27001, 27701 and 42001, which tell a client's reviewer what each certification actually covers. A firm answering a client AI clause could assemble a complete response from this without a sales conversation. One limitation recorded honestly: the subprocessors list renders client side and its contents were not retrieved in this pass, so the section's existence is established rather than the identity of the subprocessors in it.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Eudia
Not addressed

Checked the home page, the solutions listing including the litigation solution, integrations page, terms of use and trust centre index on 2 September 2026. Nothing addresses judicial standing orders, AI use disclosure or verification certification, and no exportable record of model use, sources retrieved or human review is described. The marketing states that intelligence is auditable, but no audit artifact is documented and nothing indicates it could be produced at document level. The product class is relevant: this platform is sold to in-house departments, so a filing disclosure obligation would usually fall on the outside counsel handling the matter rather than on the buyer.

Harvey
Partial record

Published material documents audit logs as a default enterprise control, inline links from assertions to the specific source passages behind them, and usage analytics available through a dashboard and APIs. Checked those surfaces on 29 Aug 2026 and did not locate a per document export covering model used, sources retrieved and human verification together.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • Commercial Transparency
Signals neither addresses in public material
  • Good Law Verification
  • Refusal and Uncertainty Behaviour

Which one fits

Choose Eudia if

  • You want named enterprises with figures attached rather than a logo wall. Eudia publishes Duracell at 50 per cent savings on contracting costs, Graybar at 98 per cent faster diligence with contract review falling from four hours to five minutes, and Cargill at a 50 per cent reduction in contracting research time, with Cargill's chief legal and compliance officer quoted by name and title.
  • You are not moving your systems of record. Eudia holds no repository, no matter management and no contract lifecycle system of its own, and connects instead to Google Drive, SharePoint, Box, Salesforce, DocuSign, Onit and LinkSquares, so the documents stay where they are and what the platform adds is the layer over them.
  • You need to name the model providers today, without asking. Eudia's trust centre renders publicly and its subprocessor list is readable without completing any access request, naming Anthropic and OpenAI as model providers alongside Elastic, Amazon Web Services and Microsoft Azure, with SOC 2 Type 2, ISO/IEC 27001, ISO/IEC 42001:2023 and GDPR listed as current.

Choose Harvey if

  • You want the AI itself certified and adversarially tested. Harvey holds ISO/IEC 42001 with a published statement of applicability identifying which controls apply, and an AIUC-1 certification conducted by Schellman that the vendor describes as validating adversarial testing of its AI security programme, with EU AI Act conformity listed separately.
  • You want accuracy measured by somebody else. Harvey Assistant took part in the February 2025 Vals Legal AI Report, an independent benchmark against a measured lawyer baseline, scoring between 65.0 and 94.8 per cent across six tasks and exceeding the baseline on five of them, and it separately publishes BigLaw Bench with task categories and grading rubrics on a public repository.
  • Your firm's walls have to hold when the AI reads. Harvey states that it follows existing NetDocuments permissions so a user sees only what they can already open, documents the iManage connection as a direct OAuth integration respecting permissions and ethical walls, and publishes admin documentation for syncing the firm's own ethical walls provider.

In summary

Eudia

Eudia is an AI platform for large in house legal departments that codifies a company's own contracts, policies and institutional knowledge into what it calls an Enterprise Brain and runs legal agents on top of it, across marketing compliance, contracting, decision self service, mergers and acquisitions and litigation, with a separate track for government acquisition teams. The AI Legal Index grades it in the top two bands on seven of fifteen capability axes, with an A on AI centrality: it holds no repository or matter system of its own and connects to the systems the work already sits in. Duracell, Graybar and Cargill are published as named customers with a figure against each. As of 2 September 2026 the index located no customer agreement, no training position for customer content and no published price.

Source: AI Legal Index, 2026

Harvey

Harvey is an enterprise legal AI platform for law firms, in house departments and professional services firms, shipping Assistant for chat and drafting, Vault for bulk cross document review, Knowledge for research with citations, and Workflow Agents for multi step automation. The AI Legal Index grades it in the top two bands on twelve of fifteen capability axes, with A grades on AI centrality, citation accuracy, AI governance, security certifications and integration depth. It holds ISO/IEC 42001 with a published statement of applicability alongside an AIUC-1 certification conducted by Schellman, and its accuracy has been measured independently in the February 2025 Vals Legal AI Report. As of 29 August 2026 the index located no published liability position and no pricing at any level.

Source: AI Legal Index, 2026

Questions buyers ask

Eudia vs Harvey: which is better for an in house legal team?

The AI Legal Index places Harvey in the top two bands on twelve of fifteen capability axes and Eudia on seven, and the gap is certification and measurement rather than ambition. Harvey publishes two AI specific certifications, named auditors and independent accuracy figures. Eudia publishes three named Fortune 500 customers with figures attached and a subprocessor list a buyer can read today. Neither publishes a price or a liability position covering the platform.

Has either had its accuracy measured independently?

Harvey has. Harvey Assistant participated in the February 2025 Vals Legal AI Report, an independent benchmark measured against a lawyer baseline, scoring between 65.0 and 94.8 per cent across six tasks and exceeding that baseline on five of them, and it publishes its own BigLaw Bench framework with task categories and grading rubrics. On Eudia the index located one grounding claim, that decisions are grounded in organisation specific context, with no accuracy figure, test set or evaluation published anywhere. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Do either say whether client content trains their models?

Harvey states on its security page that it never trains on customer data by default and contractually prohibits its model providers from doing so, with a subprocessor FAQ adding that customer data is never used to train models unless explicitly authorised. No matching term was located in a published agreement. On Eudia nothing addresses customer content either way: its privacy policy lists training AI systems as a processing purpose, and that policy states expressly that it does not apply to information held on behalf of customers. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Which one respects your document management permissions?

Harvey does, and documents it. It states that it follows existing NetDocuments permissions, that a user sees only the cabinets, matters, folders and files they can already access, and that it does not expand or modify permissions, with the iManage integration documented as respecting permissions and ethical walls and a separate admin route for syncing a firm's walls provider. Eudia indexes across Google Drive, SharePoint, Box, Salesforce, Onit and LinkSquares, and nothing published states whose permissions govern at query time. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

What do Eudia and Harvey both leave unpublished?

Neither publishes a price, a tier structure or a unit of charge. Neither publishes a liability position covering the platform, so no indemnity, cap, warranty on output or insurance commitment is readable in advance on either record. Neither names an ethics opinion, including ABA Formal Opinion 512. Neither documents what the product does when it cannot ground an answer. And neither addresses legal professional privilege or work product directly. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Disclosure

The same question is unanswered on both sides and it is the one a buyer should press. Neither publishes a liability position that reaches the platform: on Harvey no indemnity, cap, warranty or insurance position was located and commercial terms run through a negotiated agreement, and Eudia's only published agreement is a website terms of use which by its own first sentence governs the website, carries a five hundred dollar cap, and points platform terms to an unpublished annex. Several of Eudia's middle grades also record what is published rather than what exists: a data protection policy, an AI training data and bias document and a cyber insurance certificate are listed on its trust centre behind an access request that was not completed. Eudia was verified on 2 September 2026 and Harvey on 29 August 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 2, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746