Exterro vs Nuix Neo: how they compare in 2026
Exterro and Nuix Neo meet in forensic processing and investigations, where Exterro's FTK and the Nuix Engine are sold for the same job, and both extend into ediscovery review. Nuix Neo sits in the top two bands on ten of fifteen axes and Exterro on six of fifteen. Most of the gap comes from one published document. Nuix's end user license agreement, effective 30 September 2025, has the customer install the software in its own environment and own its data, licenses that data to Nuix only for support, commits to notice before any compelled disclosure, caps liability at twelve months of fees, and defines the charging unit as one terabyte processed a year. Nuix also lets a customer run its own AI models in that environment. Exterro publishes no customer agreement, no liability position and no pricing. Its counterweight is independent security evidence: ISO 27001 certified in January 2026, SOC 2, HITRUST e1, TISAX and a FedRAMP Moderate authorization anyone can check in the public marketplace. It also states that its new agentic layer runs under rules of no training, no access and no storage.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The brief flagged this name to check the AI bar. It clears the bar and lands low on centrality, which is the same split found on Onspring. Real and shipped: AI driven classification and filtering to reduce review volume and identify key custodians, custodian relationship visualisation surfacing communication patterns, contextual label suggestions that read content and prior labelling decisions to recommend tags, and Exterro Intelligence, an agentic layer announced 26 August 2026 with Exterro Assist for Data as its core. But the platform is a decade plus orchestration and workflow business covering legal hold, preservation, processing, production, privacy and forensics, and every one of those functions works without a model. Independent comparison material makes the same reading, describing the AI as an enhancement to a traditional GRC platform rather than the foundation it was built on, and Exterro's own framing of AI extending ediscovery says the same thing from the other direction. Graded below Everlaw and Relativity at B, where the model layer is core to what is sold. Note the recency: the agentic layer is three days old at the date of this record, so centrality here is a moving target and this grade should be revisited on the next pull rather than assumed stable.
The models are the engine of a core capability layered on a product that would still function without them. Nuix Neo's AI classifies and contextualises data, applies language models described as trained for the customer's use case to cut review volume, and drives automated redaction; remove them and the Nuix Engine, processing more than a thousand file types into searchable form, plus early case assessment, review in Nuix Neo Discover and investigation workflows remain, which is the product the company has sold for years. The EULA restricts use to internal ediscovery, investigations and information governance projects and describes the licence by data volume processed, not by AI. Home page, products page, Neo Legal and Discover pages and EULA read 6 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Explainability is claimed as a design principle and nothing measured is published. Exterro Intelligence is positioned as turning complex data into explainable actions and insights, and the platform's defensibility architecture means outputs sit alongside chain of custody records and complete audit logs, so an action can be traced to the data it rests on. That is grounding of a kind, and for ediscovery the corpus is the collected data set rather than the law, so the failure mode is misclassification rather than invented authority. Absent: no accuracy figure for classification or filtering, no precision or recall for label suggestion or custodian identification, no false negative rate for review reduction, no hallucination statement for the agentic layer, and no published evaluation. The gap that matters most in this category is unaddressed by every vendor in it including this one: a filter that wrongly excludes a responsive document produces a defensibility failure that no audit log will surface, and nobody publishes a recall figure. Checked the ediscovery product pages, the platform and intelligence pages, the litigation use case page and the comparison material on 29 Aug 2026.
Accuracy is asserted without measurement, and the primary-authority limbs do not apply. The vendor states that its language models improve accuracy and reduce the data to review, and the telecommunications page claims elimination of up to ninety-five per cent of non-relevant data early, with no test set, method or recall figure published; EULA section 10.1 disclaims any warranty of truth or accuracy of data or information generated and makes the licensee responsible for determining whether generated information is accurate. The product classifies and culls documents rather than citing law, so the citation limbs are not held against it; what the band asks of a review tool, a measured statement of how often its classification is wrong, is not published on the surfaces read. Product pages and EULA read 6 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Autonomy is named as a direction of travel and bounded in the same breath, which is a more honest posture than most. ARMOUR is published as an explicit strategic vision for autonomous risk management, describing a shift from AI assisted tasks to orchestration of legal, privacy and security workflows, so the vendor states plainly where it is going rather than leaving agentic capability to be discovered. Against that, Exterro Intelligence is described as keeping humans in control at critical decision points, and the platform's chain of custody and audit logging mean agent actions land in a record designed to be defensible. Held at B because the bounding is stated rather than specified: no definition of what a critical decision point is, no list of actions an agent may take unattended, no confidence or escalation behaviour, and no description of how an agent action is distinguished from a human one in the audit log. Naming a threshold concept without defining it is the gap between this and an A.
A written commitment that the models work alongside reviewing people, with real review surfaces, short of the full control structure. The review product is described as responsive review with AI-enabled workflows that support faster and more precise human review, the bring-your-own-AI option is described by a named customer as running within its own environment under its own compliance controls, and automated workflow templates run culling and redaction that a reviewer then works from. What is not published is the threshold at which a document is excluded from review, what executes without a person, or a stated route back after a misclassification beyond ordinary review. Discover, Neo Legal and Neo pages read 6 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Independent analyst placement is the strongest element and it is dated and checkable. Named a Market Leader in the IDC MarketScape for eDiscovery 2025 and a Major Player in the IDC MarketScape for Data Privacy Compliance Software 2025, which are third party evaluations rather than vendor claims. Further recognition: LegalTech Breakthrough Award for overall eDiscovery, KM World Best eDiscovery Solution, British Legal Technology Award for Innovation in Legal Services, Golden Stevie American Business Award, and an Oregon Tech Award. Verified customer commentary appears on an independent review platform, including a detailed account crediting a fully integrated end to end lifecycle that let the customer bring matters in house rather than sending data to outside vendors. Held at B because no customer is named in vendor material: the most substantial published case describes a major global insurance company with more than 35,000 employees without identifying it, and outcome claims of measurable ROI and significant reduction in outside counsel costs carry no figure, baseline or period.
A named customer without figures, and figures without a named customer. Donn Hoffman, Chief Privacy Officer and Deputy District Attorney at the Los Angeles County District Attorney's office, is quoted on the on-premises Discover page about implementing bring-your-own-AI within the office's own environment, with no measured outcome; IAV GmbH is named on the same page as an ediscovery services customer. The up-to-ninety-five-per-cent data reduction figure on the telecommunications page is unattributed and undated. Nothing joins a named customer to a figure. Discover on-premises page and telecommunications page read 6 September 2026; customer stories were not opened.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Platform confidentiality is the best evidenced on this index and privilege specifically is not addressed. The certification set is unusually broad and is graded on the Security axis rather than double counted here, but its practical effect on confidentiality is real: FedRAMP Moderate and HITRUST both carry confidentiality control requirements that an independent assessor has tested. Chain of custody and complete audit logs support defensible handling at every stage. What was not located: any treatment of legal professional privilege or attorney work product, any statement about privilege review workflows within the platform despite privilege log production being a standard ediscovery task, and any description of how privileged material identified during review is protected from the wider platform where privacy and IT teams also operate. That last point matters because the unified Legal GRC architecture is the selling proposition: legal, compliance, security and IT work in one system, and the boundary around privileged material inside that system is not described. Checked the ediscovery pages, the platform pages, the security and privacy material and the about page on 29 Aug 2026.
Substantive published commitments, structural and contractual, short of the full picture. The deployment is on-premises under the EULA: one copy installed in the licensee's own production environment, so matter data stays with the licensee, and EULA section 3.4 has the licensee own Licensee Data and license it to Nuix solely to provide support. Section 9 treats licensee data as confidential information and sections 9.3 and 9.4 commit, on any legally compelled disclosure, to prompt notice where permitted, assistance in seeking a protective order, and disclosure of no more than counsel advises is required. The bring-your-own-AI option keeps third-party models inside the customer environment. Not located: any statement on training use, since the agreement is silent on machine learning, any description of matter-level segregation inside the review product, and any treatment of privilege or work product. EULA read in full; product pages read 6 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
Not located. The platform makes responsiveness and privilege adjacent determinations at scale through AI driven classification and filtering, and an agentic layer now acts across workflows, so the question of what a supervising lawyer must review is squarely engaged by the product. Nothing published addresses it: no statement on the reviewing attorney's role over AI classification decisions, no positioning on the professional responsibility of a legal team relying on automated culling, and no engagement with any bar guidance or judicial expectation on the use of AI in discovery. Checked the ediscovery product pages, the platform and intelligence pages, the litigation use case page and the resource material on 29 Aug 2026. Note for consistency: no vendor in this category on the index engages the Federal Rules or technology assisted review case law, and this record does not break that pattern.
The advice line is not drawn and the audience is broad. The EULA confines use to the licensee's internal ediscovery, investigations and information governance projects and makes the licensee responsible for the accuracy of generated information, but no surface read states that the product does not provide legal advice or how it supports a supervising lawyer's duties; the buyers named span law firms, corporate legal, law enforcement, financial regulators and telecommunications companies. No jurisdiction limit is named beyond export control and the territory clause. EULA and product pages read 6 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Governance vocabulary is present and consistent, and nothing behind it is published. The AI is described as governed and trusted, ARMOUR is a named framework, humans are stated to remain in control at critical decision points, and the vendor publishes analysis for customers on EU AI Act enforcement including transparency obligations and general purpose AI rules, so the subject is engaged rather than avoided. That places it ahead of the several records in this pull with no governance language at all. What is missing is every artifact a reader could inspect: no AI policy, no model card, no bias or fairness testing methodology or result, no accuracy monitoring, no drift statement, no named internal governance body, and no ISO 42001 despite holding ISO 27001. The specific untested question: classification and filtering decide what a reviewer ever sees, and any systematic tendency in that filtering shapes the evidentiary record of a matter without appearing anywhere in the audit log. Checked the platform and intelligence pages, the ediscovery pages, the about page and the published EU AI Act material on 29 Aug 2026.
Responsible-use language without a published mechanism, testing regime or accountable owner. The review product is marketed as powered by ethical AI, the Neo page describes language models trained to the customer's use case, and the vendor writes about capturing AI productivity responsibly; no governance framework, ISO 42001 or equivalent, pre-release testing description or statement about uneven classification across document types or languages is published on the surfaces read. Product pages read 6 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
One of very few records on this index to state an AI data handling position rather than leave it to inference. The published in platform processing rules for Exterro Intelligence are no training, no access and no storage, which answers three separate questions most vendors leave open: customer data is not used to train models, the model layer does not retain it, and access is bounded. For a platform holding entire collected data sets under legal hold, including custodian communications and forensic images from live endpoints, that is the disclosure a buyer most needs and it is made plainly. Held at B rather than A because the statement is short and unelaborated: it appears as a product architecture note rather than in a contract or a policy document, no scope is given for whether it covers every AI feature or only the agentic layer, nothing states whether the same rules apply to the pre existing classification and labelling models, no retention figure is attached to the surrounding platform as distinct from the AI layer, and no third party attestation covers the claim. A short true sentence still needs somewhere durable to live.
Some of the ground is covered, much of it by the deployment model rather than by published policy. Under the EULA the licensee installs the software in its own environment and is solely responsible for backing up and securing Licensee Data, Nuix processes personal information only with prior written consent and then under a DPA that prevails over the licence, and Usage Data sent to the licensing server excludes Licensee Data. No retention period, deletion commitment, sub-processor list or incident-notification practice for hosted deployments was located; the DPA at the URL the EULA names and the 2020 Discover SaaS terms of use were not opened and are the rebuttal route for the hosted product. EULA read in full 6 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
No published position located. Nothing was found on liability for AI output, warranty, indemnity, service levels or remedy where classification, filtering or an agent action is wrong. The exposure is concrete in this category rather than theoretical: an AI driven cull that wrongly excludes responsive material creates a discovery failure attributable to the customer in front of a court, and the customer carries that consequence with no published vendor position on it. Checked the ediscovery pages, the platform and intelligence pages, the about page and the site navigation on 29 Aug 2026. Research limitation: enterprise agreements govern this and are not public, and no public terms page was located in this pass.
A real published position on liability, short of the full picture because the vendor gives no indemnity. EULA section 11.2 caps Nuix's aggregate liability at the licence fee paid under the applicable order form in the preceding twelve months, section 11.1 excludes indirect, consequential, and lost-profit claims and bars claims not brought within a year, both carving out intentional misconduct, gross negligence and bodily injury; section 10.3 gives repair, replacement or a prorated refund as the sole remedy for a warranty that cannot be excluded, section 10.1 disclaims accuracy of generated information, and section 11.5 states that Nuix is not an insurer and the licensee looks to its own insurance. Only the licensee indemnifies, under 11.6. A signed direct agreement supersedes the EULA. EULA read in full 6 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The largest published connector footprint on this index and the only record to state a count. More than 190 native connectors supporting in place operations across email, cloud storage, collaboration platforms and endpoints, with more than 120 data sources reachable for in place preservation, and Microsoft 365, email systems and archiving tools named specifically. In place is the operative distinction and it is a substantive capability claim rather than a list: preserving and collecting where data lives, without copying it out first, is what prevents accidental deletion during a hold and is the hard part of the problem. A dedicated connectors page is published. Held at B rather than A on a stated limitation: the connector list itself was not read in this pass, so the count is credited from vendor summary material and the composition of the 190 is unverified, and no API or export documentation was reviewed. Correction candidate in the upward direction if the list is read and holds up.
Integrations are referred to without documentation an implementer could use on the surfaces read. The Engine's ingestion of more than a thousand file types and connection to data sources is the product's core, the EULA contemplates APIs as ancillary software licensed for use with the software, and the Neo Legal page describes orchestrating business applications across the enterprise, but no integrations page or documentation was opened and no document, matter or review system connection is described with what moves and in which direction. Product pages and EULA read 6 September 2026; the documentation is the rebuttal route.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Deployment posture is partly established by a certification rather than by a deployment statement. FedRAMP Moderate authorization is meaningful here beyond security: it establishes that the SaaS platform runs an authorised boundary meeting United States federal cloud requirements, which carries residency and control implications a reader can verify independently through the FedRAMP marketplace. TISAX similarly implies assessed European handling for automotive supply chain customers. What is absent as a direct statement: no hosting provider is named, no region list or data residency commitment is published, no single tenant or dedicated instance option is described, and nothing states where non federal customer data is processed and stored. Credited at C because the certifications carry real deployment information that a buyer can check, and held there because the vendor never states the position itself. Checked the security and privacy material, the about page, the platform pages and the ediscovery pages on 29 Aug 2026.
The deployment model is stated clearly and residency for hosted deployments is not. Nuix Neo Discover is offered as a native on-premises deployment for organisations with data sovereignty and chain-of-custody requirements, the EULA licenses one copy installed in the licensee's production environment, and the vendor's own description is that the customer keeps complete control over its sensitive information; a hosted route exists through service provider partners and third-party hosting providers under separate terms. For on-premises use residency is wherever the licensee puts it, which answers the question fully; for the hosted route no region, tenancy model or processing location is stated on the surfaces read. Discover on-premises page and EULA read 6 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The strongest security record on this index. Five distinct frameworks, named, with a published Trust Center bringing together security controls, privacy practices, certifications and audits. ISO/IEC 27001 certification announced 29 January 2026, so both current and dated, with the Chief Information Security Officer named as Anthony Diaz and quoted on what the certification covers, which is a risk based information security management system under continuous surveillance audit. SOC 2. HITRUST e1 certification of the SaaS platform. TISAX, derived from ISO 27001 and governing automotive sector handling. And FedRAMP Moderate authorization, which is the element that lifts this above every other record: FedRAMP requires third party assessment organisation review and authorisation by a government authority, and the resulting status is listed publicly, so an outsider can verify it without contacting the vendor or entering a portal. That is the definition of the top of this axis. The vendor also publishes its own reasoning on why third party audits are useful internally, quoting the CISO on audits identifying gaps the company would not otherwise have found, which is a notably unmarketing thing to say. Calibration ladder for later records: Regology and Onspring B, Lexis+ AI A on scope, currency and a self serve portal, Exterro A on five frameworks including one independently verifiable in a public government registry with a named CISO and a dated certification.
Certification is stated on the product's own surface, short of a report reachable without asking. The Nuix Discover page states that the product holds globally recognised certifications including ISO 27001 and SOC 2. No auditor, coverage period, report type or route to the report is published, and no trust centre was located on the surfaces read; the EULA adds no security warranty beyond the licensee's own obligations. Discover page and EULA read 6 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The handling rules are disclosed and the parties are not. The no training, no access, no storage statement establishes how the model layer treats customer data, which is a supply chain adjacent disclosure of real value, and it implies bounded relationships with whatever models sit underneath. But no foundation model provider, model family or version is named anywhere located, no subprocessor list was found, and nothing distinguishes proprietary classification models built over years from whatever powers the agentic layer announced three days ago. A buyer knows the rules governing the models and not their identity, which is the inverse of Onspring, the only record on this index naming its provider outright while saying less about handling. Checked the platform and intelligence pages, the ediscovery pages, the security and privacy material and the about page on 29 Aug 2026.
The supply chain is partly disclosed. The vendor describes proprietary AI in the Engine and bespoke language models trained for the customer's use case, and a bring-your-own-AI option that lets the customer run its chosen models inside its own environment, which places the third-party model, where it runs and who controls it with the customer; a named customer describes using the latest AI advancements within its own environment on that basis. What is not published is the name of any model Nuix supplies, any provider behind its own models, or a change-notification commitment. Neo page, Discover on-premises page and EULA read 6 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing at any level. No price, no range, no unit of charge, and no indication of how the modular structure prices, which is the specific question this product raises: the platform is explicitly sold as individual products or as a complete orchestrated suite, so a buyer starting with Legal Hold Pro and expanding cannot determine what expansion costs. Independent software directories list pricing as available on request and carry no figure. Every route is a demo request. Checked the product pages, the about page, the site navigation and independent directory listings on 29 Aug 2026.
The unit and structure are stated in the agreement without the figure. EULA section 5.2 defines a consumption-based licence with a unit of one terabyte of uncompressed data processed per annum, aggregated across instances, expiring unused at the end of each twelve-month term, with quarterly usage reporting and true-up at order-form overage rates; section 7.2 sets automatic twelve-month renewals with ninety days' notice and section 4.1 folds standard support into fixed-term licence fees while premium tiers cost extra. No figure, tier name or price page was located. EULA read in full 6 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is enumerated where it counts for this category, which is data reach rather than jurisdiction. More than 190 native connectors and more than 120 in place preservation sources across email, cloud storage, collaboration platforms and endpoints, spanning the full EDRM from legal hold and preservation through collection, processing, early case assessment, review, production and defensible deletion. Adjacent coverage extends to digital forensics through FTK, data privacy including subject access request fulfilment, data inventory and mapping, retention, vendor risk profiling and consent management. The buyer set is enterprise legal, compliance and IT, described consistently. Held at B rather than A because coverage is stated as counts and categories rather than as an inspectable list in the material read, no jurisdictional scope is given for the privacy modules despite privacy regimes being jurisdiction specific, and nothing indicates which capabilities are available in which deployment or region.
Segment and coverage are described with substance; the boundaries are partly stated. Primary users are listed on the Neo Legal page as law firms managing large-scale ediscovery, corporate legal teams handling regulatory matters and disputes, financial services firms, compliance officers, investigation teams and security leaders, with separate solution lines for investigations, data privacy and industry pages for telecommunications, integrity agencies and financial regulators; the Engine's coverage of more than a thousand file types is stated. The EULA's territory clause and the on-premises option are stated boundaries; no matter type or practice area is named as unsupported. Product pages and EULA read 6 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Policy never. The quoted phrase is published as the in platform processing rules governing Exterro Intelligence and its Exterro Assist for Data core, and it is one of the few unambiguous statements on this signal anywhere in the pull: customer data is not used to train models. Recorded as policy never rather than contractual never because it appears as a product architecture statement on a vendor page rather than in terms, a data processing agreement or any document a customer signs, and the value set separates those two for exactly this reason.
Two limits on scope worth recording: the rule is stated for the agentic layer and nothing confirms it extends to the pre existing classification, filtering and label suggestion models that have been in the platform for years, and no third party attestation covers the claim despite five certifications being held. Checked the platform and intelligence material, the ediscovery pages, the security and privacy material and the about page on 29 Aug 2026.
The published agreement does not name training either way. EULA section 3.4 has the licensee own Licensee Data and grants Nuix a license to use, reproduce, store and process it solely to provide support, and section 3.3 grants a broad license over Usage Data, which is defined to exclude Licensee Data, for development and improvement of the software. A license confined to support does not permit training, but no clause names machine learning or model training, and the vendor's product pages describe language models trained for the customer's use case without saying on what. The deployment is on-premises, so Licensee Data does not ordinarily reach Nuix. Surfaces checked 6 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Disclosed fixed, at zero, for the AI layer only. The published in platform processing rules state no storage alongside no training and no access, which is a stated retention position rather than a vague assurance and is the strongest value recorded on this signal in the pull. It is fixed rather than customer configurable: nothing indicates a customer can vary it, and nothing needs to, since zero is the floor. Bounded carefully: this covers the AI processing layer.
The surrounding platform is a system of record that retains collected data, legal hold records, audit logs and chain of custody entries by design and for defensibility reasons, and no retention period is published for that, nor for how long a matter workspace persists after a matter closes. A reader should not carry the zero across from the model layer to the platform.
No located public material addresses how long prompts or outputs are retained, and under the EULA the question mostly does not arise: the software is installed in the licensee's own environment, the licensee is solely responsible for backing up and securing Licensee Data, and Nuix receives only Usage Data, which excludes Licensee Data, through the licensing server. For hosted deployments through partners, the 2020 Discover SaaS terms of use and the DPA were not opened and are the rebuttal route. EULA read 6 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Claimed and not documented. Matter based structure, role separation across legal, compliance and IT users, and complete audit logging are all asserted, so an access model plainly exists. Nothing published describes its granularity: no statement of whether access is enforced per matter or per custodian, whether a privacy or IT team member working in the same unified platform can reach material collected under a litigation hold, or how privileged review material is walled once identified.
The unified Legal GRC architecture makes this sharper than for a single purpose ediscovery tool, because the whole selling proposition is that separate functions share one system. No document management system integration exists that would let permissions be inherited from a firm's own estate. Checked the ediscovery pages, the platform pages and the security and privacy material on 29 Aug 2026.
No located public material describes how matters or cases are segregated inside the review product. The on-premises deployment gives each licensee its own installation, which is separation between organizations rather than between matters, and the product documentation that would describe case-level security in Nuix Neo Discover was not opened. Product pages and EULA checked 6 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Not addressed. No government or law enforcement request clause, no commitment to notify a customer before producing their data, and no transparency report were located. The question carries additional weight for this vendor because FedRAMP Moderate authorization means United States federal agencies are customers, and because the platform holds collected litigation data and forensic images from live endpoints. Checked the security and privacy material, the about page, the Trust Center references, the platform pages and the site navigation on 29 Aug 2026. Correction candidate: the Trust Center was identified but its contents were not read in this pass.
The published agreement commits to notice. EULA section 9.3 requires a party legally compelled to disclose the other's confidential information to give prompt written notice if legally permitted so that a protective order or other remedy can be sought, and to provide reasonable assistance in opposing the disclosure; section 9.4 limits any disclosure that remains required to the portion counsel advises is legally required, with commercially reasonable efforts to obtain confidential treatment.
Licensee Data is confidential information under section 1.5. No transparency report is published. Surfaces checked 6 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Not addressed, and inapplicable in the ordinary sense. This platform has no primary law corpus: it operates over the customer's own collected data, custodian communications, endpoints and documents, so there is no external legal source to name, license or date. Recorded rather than omitted because the underlying question still has an unanswered form here, which is what the classification, filtering and label suggestion models were trained on.
Nothing published states whether those models are general purpose, trained on legal or discovery specific corpora, or tuned on prior customer matters, and the last possibility is the one a litigant would care about most. The no training rule announced for the agentic layer speaks to future data and not to what already built the models. Checked the platform and intelligence pages and the ediscovery pages on 29 Aug 2026.
No located public material identifies a legal corpus behind the product's answers, and the product is not built on one: it processes and classifies the customer's own collected data and cites no law. The vendor describes language models trained for the customer's use case without stating the training material. Product pages checked 6 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Not addressed, and inapplicable on the facts of the product. Exterro processes and analyses the evidence in a matter rather than researching legal authority, so no citation to case law is produced and a citator would have nothing to check. Recorded as a scope fact so that a reader comparing this record against a legal research product does not read an empty row as a disclosure failure. Consistent with the treatment of the same row on TrialView. Checked the ediscovery pages, the platform and intelligence pages and the litigation use case page on 29 Aug 2026.
No located public material addresses whether authority is checked for subsequent history, and the product does not retrieve or cite primary law; its output is processed, classified and redacted evidence for review. Recorded as the honest value for a product without a citator function. Surfaces checked 6 September 2026.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
Not addressed. No explicit no answer path, abstention behavior or confidence signal is documented for classification, filtering, label suggestion or the agentic layer. The vendor's published control is that humans stay in control at critical decision points, which bounds who decides rather than describing what the system does when it is unsure. The consequence is specific to discovery: a classifier that is uncertain about responsiveness and resolves it silently produces a cull no audit log will flag, and nothing published indicates whether uncertain items are surfaced for human review, scored, or simply decided. Checked the platform and intelligence pages, the ediscovery pages and the litigation use case page on 29 Aug 2026.
No located public material describes what the classification or review models do when they cannot classify a document with confidence. The vendor describes AI that zeroes in on relevant data and identifies gaps or inconsistencies in collections, which is a detection claim rather than an abstention path, and no confidence signal or no-answer behavior is described. Product pages checked 6 September 2026.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
None located, with the instrument named. General web searches combining the vendor and product names with court, order, opinion, sanction, spoliation and discovery failure terms returned nothing on 29 Aug 2026. No named docket database or court record tracker was searched. The exposure shape differs from a research product: this platform generates no citations to authority, and the analogous adverse finding would be a court addressing a defective collection, cull or production run through the tool, which is a class of order that does exist in this category generally and was not searched for systematically here.
Recorded as a statement about what this search found, not as a clearance, and flagged as worth a proper docket search on a later pass.
No court order, opinion or disciplinary record naming Nuix, Nuix Neo or Nuix Discover was located as of 6 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on the company and product names together with a general search for court findings; results returned sanctions involving general-purpose chatbots and industry commentary, none of which names this product. This is a statement about the public record, not a finding about the product; a processing and review platform that cites no authority carries a remote exposure on this signal.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Not addressed. No named ethics opinion, no ABA Formal Opinion 512, no state bar guidance and no engagement with judicial expectations on AI in discovery was located. The vendor does publish substantial regulatory analysis for customers, including on EU AI Act enforcement and transparency obligations, so the capability to engage a rules framework exists and has been pointed at the customer's compliance obligations rather than at the professional duties of the lawyers supervising discovery on the platform. Checked the ediscovery pages, the platform pages, the resource and blog material and the about page on 29 Aug 2026.
No located public material engages with bar or ethics guidance. The EULA confines use to internal ediscovery and investigations projects and the marketing describes ethical AI, but no ethics opinion, bar rule or professional responsibility framework is named on any surface read. EULA and product pages checked 6 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Savings claims only, and the savings claimed are unusually specific in kind while carrying no figure. The vendor states measurable ROI and a significant reduction in outside counsel costs, and published customer commentary describes bringing matters fully in house rather than sending data to outside vendors for processing, which is a cost shift with real substance behind it. None of it is quantified with a baseline or period.
Nothing appears on the client's side of the equation: no position on billing for AI assisted review, and no exportable record showing what portion of a review was machine determined. Checked the litigation use case page, the ediscovery pages and independent review material on 29 Aug 2026.
Law firms and legal service providers are named buyer segments, and the published position on the bill is a savings claim: AI-driven data reduction is said to eliminate up to ninety-five percent of non-relevant data early, saving time and review resources, and the consumption license is priced per terabyte processed. Nothing addresses how AI-assisted review is recorded on a client's bill or what a firm has to disclose when AI culls the review set; the product keeps processing and review audit records for defensibility rather than fee purposes. Surfaces checked 6 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
On request, through the best resourced route on this index. A Trust Center is published and described as bringing together security controls, privacy practices, certifications and audits in one place, and behind it sits an unusually strong set to forward: ISO 27001 dated January 2026, SOC 2, HITRUST e1, TISAX and FedRAMP Moderate. FedRAMP status is separately verifiable in a public government registry, so one element of the pack requires no vendor cooperation at all.
A firm responding to an outside counsel guideline questionnaire has a defined destination and named, current attestations to cite. Held at on request rather than at disclosure pack because nothing is published open: no subprocessor list, no named model provider, no downloadable summary and no data processing agreement were located outside the Trust Center, and the Trust Center's own gating was not tested in this pass.
No sub-processor list, model provider list or client-facing AI disclosure material was located. The EULA names a DPA that prevails over the license and applies where Nuix processes personal information with consent, but that document was not opened; the bring-your-own-AI option places the model choice with the customer, and Nuix's own models are not attributed to any provider. For on-premises use a firm can answer its client's AI clause from its own configuration rather than from the vendor's disclosure. Surfaces checked 6 September 2026; the DPA is the rebuttal route.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Partial record, and the strongest process trail in the category. Defensibility is the organizing principle of the product rather than a feature of it: end to end chain of custody and complete audit logs are published as supporting defensible actions at every stage, legal holds are issued, tracked and enforced with automated notifications and full audit trails, and defensible deletion is a named capability. A party can evidence what was preserved, when, from whom, and what happened to it, which is the record a court asks for in a spoliation dispute and is materially better than most of this index.
The AI limb is where it stops. Nothing indicates that the record identifies which decisions were machine made, which model made them, what the confidence was, or whether a human confirmed a classification before a document was culled. With an agentic layer now acting across workflows, the distinction between a human decision and an agent decision inside the audit log is exactly what an opposing party would probe, and no published export or audit view addresses it.
Some elements of a disclosure record are available and no export of an AI verification record is described. The Neo Legal page states that chain of custody is designed in for litigation and regulatory matters, the on-premises Discover page describes defensible review and reporting, and the platform's processing produces forensic audit records; that is a record of what was collected and processed and by whom. Nothing states that a per-document record of the model used, its classification decision and the human verification can be exported for a court or opposing party. Product pages checked 6 September 2026.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Primary Law Corpus Provenance
- Good Law Verification
- Refusal and Uncertainty Behavior
- Bar Guidance Alignment
Which one fits
Choose Exterro if
- Your client or regulator needs security evidence it can check independently. Exterro holds ISO 27001 certification awarded in January 2026, SOC 2, HITRUST e1, TISAX and FedRAMP Moderate authorization, whose status can be checked in the public FedRAMP marketplace, and it names its chief information security officer.
- You need to preserve data where it lives rather than copy it out first. Exterro states more than 190 native connectors for in place operations and more than 120 sources for in place preservation across email, cloud storage, collaboration platforms and endpoints, with Legal Hold Pro issuing and tracking holds with automated notices and audit trails.
- You want a plain statement of what the AI does with your data. Exterro publishes the processing rules for its Exterro Intelligence layer as no training, no access and no storage. The rules appear on a product page rather than in a contract, and they are stated for the agentic layer rather than its older classification models.
Choose Nuix Neo if
- You want to read the license before you buy. Nuix's published end user license agreement leaves your data with you, licenses it to Nuix solely to provide support, commits to prompt notice and help seeking a protective order before any compelled disclosure, and caps Nuix's liability at twelve months of fees.
- Your evidence cannot leave your own environment, including when AI reads it. Nuix Neo Discover is offered as a native on premises deployment, and a bring your own AI option lets you run the models you choose inside that environment, which the Los Angeles County District Attorney's office describes doing.
- You want a pricing unit you can forecast. Nuix licenses by consumption at one terabyte of uncompressed data processed per year, aggregated across instances, with quarterly usage reporting, true up at order form rates and twelve month renewals on ninety days' notice. No figure is published.
In summary
Exterro
Exterro is a legal governance, risk and compliance platform from Portland, Oregon, combining ediscovery from legal hold through production, digital forensics through FTK, data privacy and information governance for enterprise legal, compliance and IT teams. Its AI classifies and filters data for review, maps custodian relationships and suggests labels, and Exterro Intelligence, an agentic layer announced on 26 August 2026, runs under stated rules of no training, no access and no storage. The AI Legal Index grades it in the top two bands on six of fifteen capability axes, with an A on security certifications, including FedRAMP Moderate authorization. As of 29 August 2026 the index located no published customer agreement, no pricing, no named model provider and no position on privilege in the platform.
Nuix Neo
Nuix Neo is an investigative analytics and ediscovery platform from Nuix Limited of Sydney, listed on the Australian Securities Exchange, built on the Nuix Engine, which processes more than a thousand file types into searchable form. It is sold for ediscovery, investigations and data privacy to law firms, corporate legal teams, regulators, government agencies and law enforcement. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes. Its published license agreement leaves data with the licensee, commits to notice before compelled disclosure and caps liability at twelve months of fees, and customers can run their own AI models on premises. As of 6 September 2026 the index located no accuracy measure, no retention commitment for hosted use and no AI governance framework.
Questions buyers ask
Exterro vs Nuix Neo: which is better for forensics and investigations?
On published evidence Nuix Neo sits in the top two bands on ten of fifteen AI Legal Index capability axes and Exterro on six of fifteen, mostly because Nuix publishes its license agreement, a pricing unit and an on premises deployment. Exterro publishes stronger security evidence, including FedRAMP Moderate authorization, and broader preservation reach across more than 190 connectors. A team that needs certifications in hand has more to read from Exterro; one that needs contract terms has more from Nuix.
Can Nuix Neo run on premises with our own AI models?
Yes. Nuix Neo Discover is offered as a native on premises deployment for organizations with data sovereignty and chain of custody requirements, and the license agreement has the licensee install the software in its own production environment. A bring your own AI option lets a customer run the models it chooses inside that environment. Nuix does not name any model it supplies itself or the provider behind it. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
Is Exterro FedRAMP authorized?
Yes. Exterro holds FedRAMP Moderate authorization, which requires review by a third party assessment organization and authorization by a government authority, and is listed in the public FedRAMP marketplace. It also holds ISO 27001 certification announced in January 2026, SOC 2, HITRUST e1 for its SaaS platform and TISAX, with a trust center and a named chief information security officer. Nuix states ISO 27001 and SOC 2 for Nuix Discover. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
Does Exterro or Nuix train AI on client data?
Exterro states that its Exterro Intelligence layer runs under rules of no training, no access and no storage, on a product page rather than in a contract, and does not say whether the rule covers its older classification models. Nuix's license agreement allows Nuix to use licensee data only to provide support and never names training either way; with an on premises deployment, customer data does not ordinarily reach Nuix at all. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
What do Exterro and Nuix Neo both leave unpublished?
How accurate the AI is, and what it does when unsure. Neither publishes a recall or error figure for the classification that culls documents before review, and neither says what happens to a document the AI cannot classify with confidence. Neither publishes an AI governance framework or bias testing, engages with bar guidance, or offers a record showing which documents a model culled and who checked it. Both claim review savings without saying how they should reach a client's bill. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
Three readings to weigh. Nuix's license gives no indemnity from Nuix to the customer, disclaims the accuracy of generated information, and states that Nuix is not an insurer; those are published terms, not gaps. Exterro's no training, no access and no storage rules are stated for its agentic layer on a product page, and nothing published extends them to the classification and label suggestion models already in the platform. Exterro's low grades on liability and pricing record that no customer agreement or price is published, since its enterprise agreements are not public. Exterro was verified on 29 August 2026 and Nuix Neo on 6 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.