Exterro vs Relativity: how they compare in 2026
Exterro and Relativity are the two ediscovery incumbents on this index, and both publish security credentials a buyer can verify without asking. Both hold FedRAMP Moderate authorization, which is assessed by an accredited third party and listed publicly, and both reach the top band on security certifications: Relativity adds ISO 27001:2022, ISO 27018:2019, IRAP at Protected, SOC 2 Type II and a public SOC 3, while Exterro adds ISO 27001 certified in January 2026 with its Chief Information Security Officer named, HITRUST e1 and TISAX. Past that the records separate. Relativity sits in the top two bands on eleven of fifteen axes and Exterro on six. Relativity publishes the more specific confidentiality decisions, including opting out of Microsoft's abuse and harmful content monitoring so that no unauthorised users reach raw inputs or outputs, and a control that stops its own administrators entering a customer workspace unless the customer grants it. Exterro's answer is reach, with more than 190 native connectors and more than 120 in place preservation sources.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The brief flagged this name to check the AI bar. It clears the bar and lands low on centrality, which is the same split found on Onspring. Real and shipped: AI driven classification and filtering to reduce review volume and identify key custodians, custodian relationship visualisation surfacing communication patterns, contextual label suggestions that read content and prior labelling decisions to recommend tags, and Exterro Intelligence, an agentic layer announced 26 August 2026 with Exterro Assist for Data as its core. But the platform is a decade plus orchestration and workflow business covering legal hold, preservation, processing, production, privacy and forensics, and every one of those functions works without a model. Independent comparison material makes the same reading, describing the AI as an enhancement to a traditional GRC platform rather than the foundation it was built on, and Exterro's own framing of AI extending ediscovery says the same thing from the other direction. Graded below Everlaw and Relativity at B, where the model layer is core to what is sold. Note the recency: the agentic layer is three days old at the date of this record, so centrality here is a moving target and this grade should be revisited on the next pull rather than assumed stable.
The models are the engine of a core capability layered on a platform that would function without them. RelativityOne is an end to end ediscovery system covering legal hold, preservation, collection, processing, review, production and analytics, and it has sold for two decades. The aiR suite of five generative products sits on top of that and drives substantial capability rather than peripheral features, which is why this is not a C. Worth recording precisely because it distinguishes this record from the AI native vendors: technology assisted review has existed in this platform for years, so the generative layer is the newest of several model based capabilities rather than the first, and third party analysis characterises the aiR features as evolutionary within that lineage. Sixth B on this axis.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Explainability is claimed as a design principle and nothing measured is published. Exterro Intelligence is positioned as turning complex data into explainable actions and insights, and the platform's defensibility architecture means outputs sit alongside chain of custody records and complete audit logs, so an action can be traced to the data it rests on. That is grounding of a kind, and for ediscovery the corpus is the collected data set rather than the law, so the failure mode is misclassification rather than invented authority. Absent: no accuracy figure for classification or filtering, no precision or recall for label suggestion or custodian identification, no false negative rate for review reduction, no hallucination statement for the agentic layer, and no published evaluation. The gap that matters most in this category is unaddressed by every vendor in it including this one: a filter that wrongly excludes a responsive document produces a defensibility failure that no audit log will surface, and nobody publishes a recall figure. Checked the ediscovery product pages, the platform and intelligence pages, the litigation use case page and the comparison material on 29 Aug 2026.
Grounding is real and documented through an explainability mechanism, short of published measurement. The vendor states that aiR for Review surfaces impactful content backed by transparent rationale and that aiR for Privilege explains every decision, so each output carries a stated basis a reviewer can inspect against the document rather than a bare classification. The suite is described as designed to be transparent, reviewable and defensible, with safeguards derived from published AI Principles. That is a documented verification surface tied to specific documents. Searched the aiR product pages, the artificial intelligence overview, the corporate data solutions pages and the learning centre on 29 Aug 2026 and located no accuracy figure, no precision or recall number, no hallucination rate, no test set, no published evaluation methodology and no independent benchmark participation. A partner published case study describes predictions as highly accurate, which is a customer's characterisation rather than a measurement and was not treated as evidence.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Autonomy is named as a direction of travel and bounded in the same breath, which is a more honest posture than most. ARMOUR is published as an explicit strategic vision for autonomous risk management, describing a shift from AI assisted tasks to orchestration of legal, privacy and security workflows, so the vendor states plainly where it is going rather than leaving agentic capability to be discovered. Against that, Exterro Intelligence is described as keeping humans in control at critical decision points, and the platform's chain of custody and audit logging mean agent actions land in a record designed to be defensible. Held at B because the bounding is stated rather than specified: no definition of what a critical decision point is, no list of actions an agent may take unattended, no confidence or escalation behaviour, and no description of how an agent action is distinguished from a human one in the audit log. Naming a threshold concept without defining it is the gap between this and an A.
A real published commitment with documented review surfaces and an explicit control philosophy, short of published thresholds. The vendor's AI Principles state the aim of technology that is clear, fair and gives customers the utmost control, and the aiR suite is described as transparent, reviewable and defensible. The review surface is concrete: every decision carries a rationale, and aiR for Privilege predictions are positioned to guide counsel's second pass review rather than to replace it. The vendor also invests in operator competence in a way no other record here does, running a certification programme covering generative AI and individual aiR products, with published guidance on building, testing and trusting prompts. Third party analysis states the product does not make autonomous privilege designations and that a human reviewer still makes every privilege call, which corroborates the position without being vendor material. Not located as of 29 Aug 2026: a published threshold at which a document routes to a human, and what the vendor commits to when an output is wrong.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Independent analyst placement is the strongest element and it is dated and checkable. Named a Market Leader in the IDC MarketScape for eDiscovery 2025 and a Major Player in the IDC MarketScape for Data Privacy Compliance Software 2025, which are third party evaluations rather than vendor claims. Further recognition: LegalTech Breakthrough Award for overall eDiscovery, KM World Best eDiscovery Solution, British Legal Technology Award for Innovation in Legal Services, Golden Stevie American Business Award, and an Oregon Tech Award. Verified customer commentary appears on an independent review platform, including a detailed account crediting a fully integrated end to end lifecycle that let the customer bring matters in house rather than sending data to outside vendors. Held at B because no customer is named in vendor material: the most substantial published case describes a major global insurance company with more than 35,000 employees without identifying it, and outcome claims of measurable ROI and significant reduction in outside counsel costs carry no figure, baseline or period.
Named customers and a specific, checkable adoption figure, short of vendor published outcome numbers. Adoption is quantified precisely rather than vaguely: 192 of the Am Law 200 firms and more than 110 legal service provider partners use RelativityOne, which is a figure a reader can test against the published Am Law list. Named organisations are published as aiR success stories including Alvarez and Marsal, Cimplifi and Gilbert and Tobin, with Alvarez and Marsal stated to have used aiR for Review, aiR for Privilege and aiR for Case Strategy on a single complex matter. Quantified results exist but sit in partner published material rather than vendor material: a Relativity Gold Partner published a case study covering 30,000 documents analysed with aiR for Privilege and 610 hours saved in privilege review, with auto generated log descriptions replacing a manual process. That is a named scope, a named figure and a described method, and it is recorded here as partner published rather than treated as the vendor's own evidence.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Platform confidentiality is the best evidenced on this index and privilege specifically is not addressed. The certification set is unusually broad and is graded on the Security axis rather than double counted here, but its practical effect on confidentiality is real: FedRAMP Moderate and HITRUST both carry confidentiality control requirements that an independent assessor has tested. Chain of custody and complete audit logs support defensible handling at every stage. What was not located: any treatment of legal professional privilege or attorney work product, any statement about privilege review workflows within the platform despite privilege log production being a standard ediscovery task, and any description of how privileged material identified during review is protected from the wider platform where privacy and IT teams also operate. That last point matters because the unified Legal GRC architecture is the selling proposition: legal, compliance, security and IT work in one system, and the boundary around privileged material inside that system is not described. Checked the ediscovery pages, the platform pages, the security and privacy material and the about page on 29 Aug 2026.
Substantive published commitments including one control no other record on this index discloses, short of the training and retention limbs. The distinctive element is specific and consequential: the vendor states it has opted out of the abuse and harmful content monitoring offered by Microsoft, so that no unauthorised users have access to raw inputs or outputs. Abuse monitoring is the standard route by which provider staff may review customer prompts, and opting out of it is the single most concrete confidentiality decision disclosed anywhere in this pull. Alongside it: a privileged access management solution and a classification schema dictating how confidential data is handled, and a vendor risk management team reviewing Azure's security and privacy posture at least annually to validate controls are operating effectively. Two gaps hold this off an A. No statement on whether customer content may be used to train models was located, either at the vendor or provider layer. No retention or deletion terms were located. Both matter for a platform holding entire document universes for live matters.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Not located. The platform makes responsiveness and privilege adjacent determinations at scale through AI driven classification and filtering, and an agentic layer now acts across workflows, so the question of what a supervising lawyer must review is squarely engaged by the product. Nothing published addresses it: no statement on the reviewing attorney's role over AI classification decisions, no positioning on the professional responsibility of a legal team relying on automated culling, and no engagement with any bar guidance or judicial expectation on the use of AI in discovery. Checked the ediscovery product pages, the platform and intelligence pages, the litigation use case page and the resource material on 29 Aug 2026. Note for consistency: no vendor in this category on the index engages the Federal Rules or technology assisted review case law, and this record does not break that pattern.
The audience is professional and the position is unstated. Users are law firms, corporate legal departments, government and regulatory response teams, and legal service providers, with no consumer surface located, and the product is a review and investigation platform rather than an advice tool, so the advice line question arises less sharply than for a research or drafting product. Searched the aiR product pages, the artificial intelligence overview, the data solutions pages and the learning centre on 29 Aug 2026 and located no published position on advice versus tooling, no treatment of competence or supervision duties as professional obligations, and no jurisdiction limits. Worth recording as adjacent rather than as credit: the vendor runs a substantial user certification programme, which addresses operator competence as a commercial and training matter rather than as the professional duty it also is.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Governance vocabulary is present and consistent, and nothing behind it is published. The AI is described as governed and trusted, ARMOUR is a named framework, humans are stated to remain in control at critical decision points, and the vendor publishes analysis for customers on EU AI Act enforcement including transparency obligations and general purpose AI rules, so the subject is engaged rather than avoided. That places it ahead of the several records in this pull with no governance language at all. What is missing is every artifact a reader could inspect: no AI policy, no model card, no bias or fairness testing methodology or result, no accuracy monitoring, no drift statement, no named internal governance body, and no ISO 42001 despite holding ISO 27001. The specific untested question: classification and filtering decide what a reviewer ever sees, and any systematic tendency in that filtering shapes the evidentiary record of a matter without appearing anywhere in the audit log. Checked the platform and intelligence pages, the ediscovery pages, the about page and the published EU AI Act material on 29 Aug 2026.
A published governance framework with real substance, short of testing results, a named owner and any bias disclosure. Relativity AI Principles are published as a standing document and the vendor states they guide everyday decision making toward technology that is clear, fair and gives customers the utmost control, with aiR safeguards described as inspired by them. The vendor states directly that it recognises the value AI can create along with its risks and commits to processes that are thoughtful, disciplined and trusted, which is an acknowledgement of risk rather than an unqualified capability claim. Governance is also operationalised through vendor risk management, with an annual in depth review of the underlying platform provider's security and privacy posture. Not located as of 29 Aug 2026: an AI management certification such as ISO 42001, published pre release testing results, a named accountable owner for model governance, and anything on uneven output across matter types, parties or populations. The word fair appears in the principles without any published work behind it, which is the gap this axis exists to mark.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
One of very few records on this index to state an AI data handling position rather than leave it to inference. The published in platform processing rules for Exterro Intelligence are no training, no access and no storage, which answers three separate questions most vendors leave open: customer data is not used to train models, the model layer does not retain it, and access is bounded. For a platform holding entire collected data sets under legal hold, including custodian communications and forensic images from live endpoints, that is the disclosure a buyer most needs and it is made plainly. Held at B rather than A because the statement is short and unelaborated: it appears as a product architecture note rather than in a contract or a policy document, no scope is given for whether it covers every AI feature or only the agentic layer, nothing states whether the same rules apply to the pre existing classification and labelling models, no retention figure is attached to the surrounding platform as distinct from the AI layer, and no third party attestation covers the claim. A short true sentence still needs somewhere durable to live.
CORRECTED 29 Aug 2026 during the trust portal sweep. Previously graded C because access control appeared to be the only well covered element. That reading came from marketing surfaces without reaching the dedicated trust site, and understated the published controls. Now located and published: customer managed encryption keys, so a customer can hold its own key material; Customer Lockbox, a default on control restricting the vendor's own system administrators from accessing customer workspaces unless the customer explicitly grants it, which is a strong and specific limit on vendor side access; client domains providing data separation between clients; Security Center, a monitoring application shipped to customers; SIEM integration giving customers access to their own security logs; and round the clock monitoring by the named in house security team, Calder7. Previously recorded and still standing: privileged access management, a classification schema for confidential data, the opt out from Microsoft abuse and harmful content monitoring, and annual vendor risk review of Azure. That is a substantive published policy covering most of what this axis asks. Not located as of 29 Aug 2026: a stated retention period or deletion control for customer data, prompts or aiR outputs, and a named subprocessor list. Those two absences are what hold this at B rather than A.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
No published position located. Nothing was found on liability for AI output, warranty, indemnity, service levels or remedy where classification, filtering or an agent action is wrong. The exposure is concrete in this category rather than theoretical: an AI driven cull that wrongly excludes responsive material creates a discovery failure attributable to the customer in front of a court, and the customer carries that consequence with no published vendor position on it. Checked the ediscovery pages, the platform and intelligence pages, the about page and the site navigation on 29 Aug 2026. Research limitation: enterprise agreements govern this and are not public, and no public terms page was located in this pass.
Searched the aiR product pages, the artificial intelligence overview, the corporate and data solutions pages and the learning centre on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer agreement or master terms was located on the surfaces reached. Recorded as a pure absence on those surfaces. The shape is worth naming for this vendor specifically: aiR for Privilege exists to reduce the risk of inadvertent production of privileged material, which is among the most consequential errors in litigation, and nothing published addresses who bears the loss if a privileged document is produced on the strength of an AI prediction. Rebuttable with one link.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The largest published connector footprint on this index and the only record to state a count. More than 190 native connectors supporting in place operations across email, cloud storage, collaboration platforms and endpoints, with more than 120 data sources reachable for in place preservation, and Microsoft 365, email systems and archiving tools named specifically. In place is the operative distinction and it is a substantive capability claim rather than a list: preserving and collecting where data lives, without copying it out first, is what prevents accidental deletion during a hold and is the hard part of the problem. A dedicated connectors page is published. Held at B rather than A on a stated limitation: the connector list itself was not read in this pass, so the count is credited from vendor summary material and the composition of the 190 is unverified, and no API or export documentation was reviewed. Correction candidate in the upward direction if the list is read and holds up.
Real integrations exist, are named individually, and target the systems evidence actually lives in. Named as out of the box integrations for collections: Microsoft, Google, Slack and Box, with in place preservation from what the vendor calls the top productivity platforms, which is the integration that matters most for defensible legal hold. A published .NET Platform API for RelativityOne is documented through the learning programme, and the platform is explicitly built for shared working across internal teams, outside counsel and service providers, with more than 110 legal service provider partners in the ecosystem. Not located as of 29 Aug 2026: a consolidated integrations index page, per integration documentation of what moves in which direction and what an administrator configures, and legal document management connectors such as iManage or NetDocuments.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Deployment posture is partly established by a certification rather than by a deployment statement. FedRAMP Moderate authorization is meaningful here beyond security: it establishes that the SaaS platform runs an authorised boundary meeting United States federal cloud requirements, which carries residency and control implications a reader can verify independently through the FedRAMP marketplace. TISAX similarly implies assessed European handling for automotive supply chain customers. What is absent as a direct statement: no hosting provider is named, no region list or data residency commitment is published, no single tenant or dedicated instance option is described, and nothing states where non federal customer data is processed and stored. Credited at C because the certifications carry real deployment information that a buyer can check, and held there because the vendor never states the position itself. Checked the security and privacy material, the about page, the platform pages and the ediscovery pages on 29 Aug 2026.
The hosting platform is named and residency is not addressed. RelativityOne is stated to be built on Microsoft Azure, and the vendor adds a substantive point about that choice, that it is the same platform chosen by global regulators, alongside an annual vendor risk review of Azure's security and privacy posture. Naming the hosting provider and evidencing ongoing oversight of it is more than several records here manage. Searched the aiR pages, the artificial intelligence overview, the data solutions pages and the learning centre on 29 Aug 2026 and located no named regions, no customer selectable residency, no tenancy model, and no statement of where processing happens as distinct from where data is stored. For a platform serving 192 of the Am Law 200 across international matters, published residency options would be expected and none was located on the surfaces reached.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The strongest security record on this index. Five distinct frameworks, named, with a published Trust Center bringing together security controls, privacy practices, certifications and audits. ISO/IEC 27001 certification announced 29 January 2026, so both current and dated, with the Chief Information Security Officer named as Anthony Diaz and quoted on what the certification covers, which is a risk based information security management system under continuous surveillance audit. SOC 2. HITRUST e1 certification of the SaaS platform. TISAX, derived from ISO 27001 and governing automotive sector handling. And FedRAMP Moderate authorization, which is the element that lifts this above every other record: FedRAMP requires third party assessment organisation review and authorisation by a government authority, and the resulting status is listed publicly, so an outsider can verify it without contacting the vendor or entering a portal. That is the definition of the top of this axis. The vendor also publishes its own reasoning on why third party audits are useful internally, quoting the CISO on audits identifying gaps the company would not otherwise have found, which is a notably unmarketing thing to say. Calibration ladder for later records: Regology and Onspring B, Lexis+ AI A on scope, currency and a self serve portal, Exterro A on five frameworks including one independently verifiable in a public government registry with a named CISO and a dated certification.
CORRECTED 29 Aug 2026 during the trust portal sweep. Previously graded C on the finding that the vendor claimed several industry certifications without naming any. That was wrong. It came from reading product and solutions marketing pages without reaching the dedicated trust site at relativity.com/trust and its compliance and privacy page, where the certifications are named individually and with versions. Published there: ISO/IEC 27001:2022 certification, ISO/IEC 27018:2019 certification, FedRAMP Moderate ATO, HIPAA compliance, IRAP assessed at Protected, a SOC 2 Type II report, a SOC 3 report, and a Cloud Security Alliance CAIQ, alongside a published request route for compliance certificates. Naming ISO 27001 at the 2022 revision and 27018 at 2019 is precise, and the set is unusually broad, spanning the US federal authorisation, the Australian government assessment at Protected level, a healthcare framework and a standardised cloud control questionnaire. A SOC 3 report is a public summary report, which is a materially more open disclosure than SOC 2 alone. The vendor also names its in house security team, Calder7, publishes a Security Center monitoring application to customers, and offers SIEM integration giving a customer access to their own security logs. Short only of a published coverage period, report date and named auditing firm, none of which was located as of 29 Aug 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The handling rules are disclosed and the parties are not. The no training, no access, no storage statement establishes how the model layer treats customer data, which is a supply chain adjacent disclosure of real value, and it implies bounded relationships with whatever models sit underneath. But no foundation model provider, model family or version is named anywhere located, no subprocessor list was found, and nothing distinguishes proprietary classification models built over years from whatever powers the agentic layer announced three days ago. A buyer knows the rules governing the models and not their identity, which is the inverse of Onspring, the only record on this index naming its provider outright while saying less about handling. Checked the platform and intelligence pages, the ediscovery pages, the security and privacy material and the about page on 29 Aug 2026.
The provider is identified, where the models run is stated, and the terms binding the relationship are described, short of naming the models themselves. Microsoft Azure is named as the platform the product is built on, and the vendor's disclosure about opting out of Microsoft's abuse and harmful content monitoring identifies Microsoft as the party that would otherwise have had access to raw inputs and outputs, which locates the generative processing in the Microsoft stack more precisely than most vendors manage. The relationship is governed rather than assumed: a vendor risk management team performs an in depth review of Azure's security and privacy posture at least annually to validate controls are operating effectively. Not located as of 29 Aug 2026: which specific models serve which aiR product, any subprocessor list beyond the platform provider, and any commitment to notify customers when the model supply chain changes.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing at any level. No price, no range, no unit of charge, and no indication of how the modular structure prices, which is the specific question this product raises: the platform is explicitly sold as individual products or as a complete orchestrated suite, so a buyer starting with Legal Hold Pro and expanding cannot determine what expansion costs. Independent software directories list pricing as available on request and carry no figure. Every route is a demo request. Checked the product pages, the about page, the site navigation and independent directory listings on 29 Aug 2026.
A real commercial term is published without a rate, and the term itself is unusual enough to record. The vendor states that aiR for Review and aiR for Privilege are included in the standard pricing and packaging for RelativityOne, so a buyer learns that two of the five generative products carry no separate charge, which is a meaningful commercial fact and one almost no vendor on this index discloses about its AI features. Flexible pricing models are referenced without being enumerated. Searched the aiR pages, the data solutions pages and the corporate pages on 29 Aug 2026 and located no rate, no unit of charge, no tier structure, and no published packaging for the remaining aiR products, aiR for Case Strategy, aiR for Data Breach Response and aiR Assist. Recorded at C on the strength of the published inclusion statement.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is enumerated where it counts for this category, which is data reach rather than jurisdiction. More than 190 native connectors and more than 120 in place preservation sources across email, cloud storage, collaboration platforms and endpoints, spanning the full EDRM from legal hold and preservation through collection, processing, early case assessment, review, production and defensible deletion. Adjacent coverage extends to digital forensics through FTK, data privacy including subject access request fulfilment, data inventory and mapping, retention, vendor risk profiling and consent management. The buyer set is enterprise legal, compliance and IT, described consistently. Held at B rather than A because coverage is stated as counts and categories rather than as an inspectable list in the material read, no jurisdictional scope is given for the privacy modules despite privacy regimes being jurisdiction specific, and nothing indicates which capabilities are available in which deployment or region.
Segment and practice coverage is described with substance and quantified where it can be. Segments named: law firms with a stated 192 of the Am Law 200, corporations, government, and more than 110 legal service provider partners, with the platform explicitly designed as shared working space across internal teams, outside counsel and providers. Practice coverage is enumerated by product rather than claimed broadly, five aiR products each with a distinct purpose spanning document review, privilege, case strategy, data breach response and assistance, plus legal hold, preservation, collection, processing, production and analytics. Regulatory response is named down to the agency: EPA, DOJ, FDA, SEC and third party subpoenas. Not located as of 29 Aug 2026: firm size segmentation below the Am Law tier, jurisdictional or language coverage, and any statement of what the platform is not built for.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Policy never. The quoted phrase is published as the in platform processing rules governing Exterro Intelligence and its Exterro Assist for Data core, and it is one of the few unambiguous statements on this signal anywhere in the pull: customer data is not used to train models. Recorded as policy never rather than contractual never because it appears as a product architecture statement on a vendor page rather than in terms, a data processing agreement or any document a customer signs, and the value set separates those two for exactly this reason. Two limits on scope worth recording: the rule is stated for the agentic layer and nothing confirms it extends to the pre existing classification, filtering and label suggestion models that have been in the platform for years, and no third party attestation covers the claim despite five certifications being held. Checked the platform and intelligence material, the ediscovery pages, the security and privacy material and the about page on 29 Aug 2026.
Searched the aiR product pages, the artificial intelligence overview, the corporate and data solutions pages and the learning centre on 29 Aug 2026. No located material states whether customer content may be used to train models, either at the vendor layer or by the underlying platform provider. Recorded as silent under the rule that a value is never inferred from the absence of a contradiction, and specifically not inferred from the published opt out of Microsoft abuse and harmful content monitoring, which stops provider personnel accessing raw inputs and outputs and is a different question from whether anything trains on them. Notable as an absence given how specific this vendor is elsewhere about its data handling decisions.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Disclosed fixed, at zero, for the AI layer only. The published in platform processing rules state no storage alongside no training and no access, which is a stated retention position rather than a vague assurance and is the strongest value recorded on this signal in the pull. It is fixed rather than customer configurable: nothing indicates a customer can vary it, and nothing needs to, since zero is the floor. Bounded carefully: this covers the AI processing layer. The surrounding platform is a system of record that retains collected data, legal hold records, audit logs and chain of custody entries by design and for defensibility reasons, and no retention period is published for that, nor for how long a matter workspace persists after a matter closes. A reader should not carry the zero across from the model layer to the platform.
Searched the aiR product pages, the artificial intelligence overview, the corporate and data solutions pages and the learning centre on 29 Aug 2026. No public material on these surfaces states how long prompts, aiR outputs or rationales are retained, whether a customer controls the window, or whether deletion is available. The gap has a particular edge for this product: aiR generates a rationale for every decision and auto generated privilege log descriptions, so the system produces a substantial body of derived commentary about a customer's documents, and nothing located governs how long that commentary persists.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Claimed and not documented. Matter based structure, role separation across legal, compliance and IT users, and complete audit logging are all asserted, so an access model plainly exists. Nothing published describes its granularity: no statement of whether access is enforced per matter or per custodian, whether a privacy or IT team member working in the same unified platform can reach material collected under a litigation hold, or how privileged review material is walled once identified. The unified Legal GRC architecture makes this sharper than for a single purpose ediscovery tool, because the whole selling proposition is that separate functions share one system. No document management system integration exists that would let permissions be inherited from a firm's own estate. Checked the ediscovery pages, the platform pages and the security and privacy material on 29 Aug 2026.
CORRECTED 29 Aug 2026 during the trust portal sweep. Previously recorded at claimed but not documented, on the basis that internal controls were asserted without customer side segregation being described. That was wrong: the product documentation describes two distinct mechanisms and describes them concretely. Client domains provide a secure way to isolate users, workspaces, groups and matters by client, with data separation such that only certified partners have access across their own clients, and client domain admins administer within that boundary. Separately, Customer Lockbox restricts the vendor's own system administrators from accessing customer workspaces unless the customer explicitly grants it, enabled by default, with system admins additionally required to belong to a group within a workspace to reach it. Isolation by matter is stated explicitly, which is the level a firm facing product needs, and vendor side access is constrained by a default on control rather than a policy promise. Recorded at own model documented rather than the positive value because the product operates its own permission structure rather than inheriting a document management system's access model at query time, and because no material was located stating that aiR retrieval and generation respect those boundaries per user when the AI runs across a workspace. Ethical walls are still not named as such. Previously recorded and still standing: privileged access management and a classification schema governing vendor handling of confidential data.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Not addressed. No government or law enforcement request clause, no commitment to notify a customer before producing their data, and no transparency report were located. The question carries additional weight for this vendor because FedRAMP Moderate authorization means United States federal agencies are customers, and because the platform holds collected litigation data and forensic images from live endpoints. Checked the security and privacy material, the about page, the Trust Center references, the platform pages and the site navigation on 29 Aug 2026. Correction candidate: the Trust Center was identified but its contents were not read in this pass.
Searched the aiR product pages, the artificial intelligence overview, the corporate and data solutions pages and the learning centre on 29 Aug 2026, and no published customer agreement or data processing agreement was reached. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. Worth recording as context: the vendor markets consolidated regulatory response across EPA, DOJ, FDA, SEC and third party subpoenas, so its customers use the platform precisely to manage government demands for their own data, and what happens when a government instead demands data from the platform is unaddressed on the surfaces reached.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Not addressed, and inapplicable in the ordinary sense. This platform has no primary law corpus: it operates over the customer's own collected data, custodian communications, endpoints and documents, so there is no external legal source to name, license or date. Recorded rather than omitted because the underlying question still has an unanswered form here, which is what the classification, filtering and label suggestion models were trained on. Nothing published states whether those models are general purpose, trained on legal or discovery specific corpora, or tuned on prior customer matters, and the last possibility is the one a litigant would care about most. The no training rule announced for the agentic layer speaks to future data and not to what already built the models. Checked the platform and intelligence pages and the ediscovery pages on 29 Aug 2026.
No primary law corpus is identified because the product does not hold one. Retrieval and analysis run against the customer's own collected evidence, ingested through legal hold, preservation and collection from named enterprise sources, so the corpus is the document universe for the matter and its provenance is the discovery process. Searched the aiR pages, the artificial intelligence overview and the data solutions pages on 29 Aug 2026 and located no vendor supplied legal corpus, no licence basis and no update cadence, and none would be expected. One adjacent capability was considered and not treated as a corpus: the platform can carry coding decisions, compliance workflows and privilege calls from prior matters into new ones, which reuses the customer's own past work product rather than any vendor held material.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Not addressed, and inapplicable on the facts of the product. Exterro processes and analyses the evidence in a matter rather than researching legal authority, so no citation to case law is produced and a citator would have nothing to check. Recorded as a scope fact so that a reader comparing this record against a legal research product does not read an empty row as a disclosure failure. Consistent with the treatment of the same row on TrialView. Checked the ediscovery pages, the platform and intelligence pages and the litigation use case page on 29 Aug 2026.
Searched the aiR product pages, the artificial intelligence overview, the data solutions pages and the learning centre on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is an ediscovery and investigation platform whose corpus is collected evidence rather than published case law, so a citator is outside its design entirely, including for aiR for Case Strategy, which builds argument from the document record rather than from authority.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Not addressed. No explicit no answer path, abstention behaviour or confidence signal is documented for classification, filtering, label suggestion or the agentic layer. The vendor's published control is that humans stay in control at critical decision points, which bounds who decides rather than describing what the system does when it is unsure. The consequence is specific to discovery: a classifier that is uncertain about responsiveness and resolves it silently produces a cull no audit log will flag, and nothing published indicates whether uncertain items are surfaced for human review, scored, or simply decided. Checked the platform and intelligence pages, the ediscovery pages and the litigation use case page on 29 Aug 2026.
Searched the aiR product pages, the artificial intelligence overview, the data solutions pages and the learning centre on 29 Aug 2026. No published material describes what the product does when the evidence does not support a determination, and no explicit no answer path was located. Two adjacent features were considered and not treated as satisfying this signal. Every aiR decision carries a rationale, which explains a determination that was made rather than declining to make one. And aiR for Privilege produces a prioritised queue surfacing high probability privileged documents, which is ranking by confidence rather than an abstention path, and no confidence threshold exposed to the user was located. For a privilege product the question of what happens on a genuinely ambiguous document is the sharpest version of this signal and it is unaddressed.
Fabricated Citation Record
Does a public court record exist involving output from this product?
None located, with the instrument named. General web searches combining the vendor and product names with court, order, opinion, sanction, spoliation and discovery failure terms returned nothing on 29 Aug 2026. No named docket database or court record tracker was searched. The exposure shape differs from a research product: this platform generates no citations to authority, and the analogous adverse finding would be a court addressing a defective collection, cull or production run through the tool, which is a class of order that does exist in this category generally and was not searched for systematically here. Recorded as a statement about what this search found, not as a clearance, and flagged as worth a proper docket search on a later pass.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note the exposure differs from a research tool: this product analyses collected evidence rather than generating citations to authority, so its characteristic failure would be a wrong privilege call or a mischaracterised document rather than an invented case, and neither would ordinarily surface in a hallucination database.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Not addressed. No named ethics opinion, no ABA Formal Opinion 512, no state bar guidance and no engagement with judicial expectations on AI in discovery was located. The vendor does publish substantial regulatory analysis for customers, including on EU AI Act enforcement and transparency obligations, so the capability to engage a rules framework exists and has been pointed at the customer's compliance obligations rather than at the professional duties of the lawyers supervising discovery on the platform. Checked the ediscovery pages, the platform pages, the resource and blog material and the about page on 29 Aug 2026.
Searched the aiR product pages, the artificial intelligence overview, the data solutions pages, the certification programme pages and the learning centre on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512 and state bar guidance. Also not located, and more surprising for this vendor: any engagement with the Federal Rules of Civil Procedure or with the substantial body of case law on technology assisted review and defensible process, which is the natural professional touchstone for an ediscovery platform marketing defensibility. The vendor publishes AI Principles governing its own conduct and a certification programme establishing operator proficiency, neither of which engages with the professional rules binding its users.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Savings claims only, and the savings claimed are unusually specific in kind while carrying no figure. The vendor states measurable ROI and a significant reduction in outside counsel costs, and published customer commentary describes bringing matters fully in house rather than sending data to outside vendors for processing, which is a cost shift with real substance behind it. None of it is quantified with a baseline or period. Nothing appears on the client's side of the equation: no position on billing for AI assisted review, and no exportable record showing what portion of a review was machine determined. Checked the litigation use case page, the ediscovery pages and independent review material on 29 Aug 2026.
Savings are claimed and quantified in partner material with nothing published on the client's side of the equation. The vendor's framing is cost and time reduction: automating privilege review to increase productivity and reduce cost, identifying impactful content in substantially less time, and reducing cost and response time across matters by carrying prior coding decisions forward. A Relativity Gold Partner published a case study recording 610 hours saved in privilege review on a 30,000 document analysis. Privilege review is billed work, and 610 hours is a large number in that context. Searched the aiR pages, the data solutions pages and the learning centre on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment. Recorded at savings claims only.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
On request, through the best resourced route on this index. A Trust Center is published and described as bringing together security controls, privacy practices, certifications and audits in one place, and behind it sits an unusually strong set to forward: ISO 27001 dated January 2026, SOC 2, HITRUST e1, TISAX and FedRAMP Moderate. FedRAMP status is separately verifiable in a public government registry, so one element of the pack requires no vendor cooperation at all. A firm responding to an outside counsel guideline questionnaire has a defined destination and named, current attestations to cite. Held at on request rather than at disclosure pack because nothing is published open: no subprocessor list, no named model provider, no downloadable summary and no data processing agreement were located outside the Trust Center, and the Trust Center's own gating was not tested in this pass.
Some genuinely useful material is published and the artifacts this signal names are not. Available: identification of Microsoft Azure as the platform, the disclosure that the vendor opted out of Microsoft abuse and harmful content monitoring so provider personnel cannot reach raw inputs and outputs, and a statement that Azure's security and privacy posture is reviewed in depth at least annually. A firm could forward the abuse monitoring point usefully, since it answers a question client AI clauses increasingly ask. But searched the aiR pages, the artificial intelligence overview, the data solutions pages and the learning centre on 29 Aug 2026 and located no subprocessor list, no named security certification, no published data processing agreement, and no client facing consent or notification pack. Recorded as not addressed because no assembled material exists to point a client to.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Partial record, and the strongest process trail in the category. Defensibility is the organising principle of the product rather than a feature of it: end to end chain of custody and complete audit logs are published as supporting defensible actions at every stage, legal holds are issued, tracked and enforced with automated notifications and full audit trails, and defensible deletion is a named capability. A party can evidence what was preserved, when, from whom, and what happened to it, which is the record a court asks for in a spoliation dispute and is materially better than most of this index. The AI limb is where it stops. Nothing indicates that the record identifies which decisions were machine made, which model made them, what the confidence was, or whether a human confirmed a classification before a document was culled. With an agentic layer now acting across workflows, the distinction between a human decision and an agent decision inside the audit log is exactly what an opposing party would probe, and no published export or audit view addresses it.
The most complete disclosure material of any ediscovery record here, assembled from product features rather than offered as a single artifact. Every aiR decision carries a rationale, so the basis for each determination is recorded per document rather than reconstructed afterwards. The vendor states full audit trails and documented data governance across the platform, and describes the aiR suite as designed to be transparent, reviewable and defensible, with defensibility a stated design goal rather than a marketing adjective. aiR for Privilege generates privilege log descriptions automatically, which is a court facing artifact produced as a by product of the AI work itself. Two elements are missing: no single per document export combining model used, sources retrieved and human verification was located, and no model is named in published material so the model used could not be stated. Recorded at partial record on that basis.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- AI Liability and Recourse
- Third Party Request and Subpoena Notice
- Primary Law Corpus Provenance
- Good Law Verification
- Refusal and Uncertainty Behaviour
- Bar Guidance Alignment
Which one fits
Choose Exterro if
- The data is spread across a hundred systems and must not be moved to be held. Exterro publishes more than 190 native connectors and more than 120 in place preservation sources across email, cloud storage, collaboration platforms and endpoints, with preservation and collection performed where the data lives rather than by copying it out first, which is what prevents accidental deletion during a hold.
- Your assurance list is long and includes sectors outside legal. Exterro publishes ISO/IEC 27001 certification announced in January 2026 with its Chief Information Security Officer named, SOC 2, HITRUST e1 for the SaaS platform, TISAX for automotive sector handling, and FedRAMP Moderate authorization, which is assessed by a third party organisation and listed publicly so an outsider can confirm it without contacting the vendor.
- You want the AI's data rules stated before you turn it on. Exterro publishes in platform processing rules for Exterro Intelligence of no training, no access and no storage, and states that its agentic layer keeps humans in control at critical decision points, alongside chain of custody and complete audit logging designed so that what the system did lands in a defensible record.
Choose Relativity if
- You want to know who can see the prompts. Relativity states that it has opted out of the abuse and harmful content monitoring offered by Microsoft so that no unauthorised users have access to raw inputs or outputs, and publishes Customer Lockbox, a default on control preventing its own system administrators from entering a customer workspace unless the customer explicitly grants it, alongside customer managed encryption keys and client domains separating data between clients.
- Every AI call has to be defensible to a court. Relativity's aiR suite spans review, privilege, case strategy, data breach response and an assistant, with each decision accompanied by a rationale a reviewer can inspect against the document, privilege log descriptions generated automatically, and predictions positioned to guide counsel's second pass rather than to replace it.
- You want the people using it to be trained and the AI included in the price. Relativity states adoption by 192 of the Am Law 200 and more than 110 legal service provider partners, runs a formal user certification programme covering generative AI and the individual aiR products, and states that aiR for Review and aiR for Privilege are included in the standard pricing and packaging for RelativityOne rather than charged separately.
In summary
Exterro
Exterro is a unified data risk management platform combining ediscovery, digital forensics, data privacy and information governance for enterprise legal, compliance and IT teams, covering the lifecycle from legal hold and in place preservation through collection, processing, early case assessment, review and production, with more than 190 native connectors and an agentic layer announced in August 2026. The AI Legal Index grades it in the top two bands on six of fifteen capability axes, with an A on security certifications: it publishes ISO 27001 certified in January 2026, SOC 2, HITRUST e1, TISAX and FedRAMP Moderate authorization. As of 29 August 2026 the index located no customer agreement, no liability position, no residency statement and no published price.
Relativity
Relativity is an ediscovery and legal data intelligence platform delivered as RelativityOne on Microsoft Azure, covering hold, collection, processing, review, production and analytics, with the aiR suite of five generative products spanning review, privilege, case strategy, data breach response and an assistant, each decision accompanied by a rationale. The AI Legal Index grades it in the top two bands on eleven of fifteen capability axes, with an A on security certifications. It publishes confidentiality decisions few vendors make, including an opt out from Microsoft's abuse monitoring and a control preventing its own administrators from entering customer workspaces. As of 29 August 2026 the index located no customer agreement, no liability position, no training statement and no published price.
Questions buyers ask
Exterro vs Relativity: which is better for ediscovery?
The AI Legal Index places Relativity in the top two bands on eleven of fifteen capability axes and Exterro on six, and both reach the top band on security certifications. Relativity publishes more specific confidentiality decisions and a more documented AI review surface. Exterro publishes the larger connector footprint and a broader certification set spanning sectors outside legal, including automotive and healthcare frameworks.
What can be verified independently?
Both hold FedRAMP Moderate authorization, which is assessed by an accredited third party and listed publicly, so a buyer can verify it independently. Relativity adds ISO/IEC 27001:2022, ISO/IEC 27018:2019, IRAP assessed at Protected, SOC 2 Type II, a public SOC 3 summary report and a Cloud Security Alliance questionnaire. Exterro adds ISO/IEC 27001 certified in January 2026, SOC 2, HITRUST e1 and TISAX, with its Chief Information Security Officer named. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What happens to the data the AI sees?
Exterro publishes three rules for its agentic layer: no training, no access and no storage, though the statement sits in product material rather than in a policy or contract and does not say whether it covers the older classification models too. Relativity does not publish a training position, and instead publishes controls over who can reach the data, including the opt out from Microsoft's abuse monitoring, Customer Lockbox and customer managed keys. Neither states a retention period for prompts or generated output. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Do either publish an accuracy figure?
Neither does. Relativity publishes an explainability mechanism instead, with a rationale attached to every aiR decision, and a partner published case study reports 30,000 documents analysed and 610 hours saved on a privilege review. Exterro publishes explainability as a design principle alongside chain of custody and audit logs. No accuracy figure, precision or recall number, test set or published evaluation was located on either record. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What do Exterro and Relativity both leave unpublished?
Neither publishes a price or a unit of charge, though Relativity does state that two of its five generative products carry no separate charge. Neither publishes a liability position or a customer agreement. Neither states a hosting region, a residency option or a tenancy model. And neither publishes an AI governance certification, a named owner of model behaviour or any evaluation of uneven output, which on a system that decides what a reviewer ever sees is the governance question that matters. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Neither vendor publishes a customer agreement, so on neither record is there a liability position, an indemnity, a warranty on output or a service level a buyer can read before signing. That gap has a specific edge on Relativity, whose aiR for Privilege exists to reduce inadvertent production of privileged material, and nothing published states who bears the loss if a privileged document is produced on the strength of an AI prediction. Neither publishes a recall or precision figure for the classification each depends on, which matters more here than in most categories: a filter that wrongly excludes a responsive document produces a failure that no audit log will ever surface. Neither states a hosting region or a residency option, although Relativity names Microsoft Azure as its platform. Exterro's agentic layer was announced days before this record was verified, so its centrality is explicitly a moving target. Both records were verified on 29 August 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.