Harvey vs Litera: how they compare in 2026
Harvey and Litera both sell AI to large law firms from opposite starting points. Harvey was built as an AI platform, while Litera is the drafting, comparison and proofing incumbent that added its Lito agent in 2025. Litera sits in the top two bands on thirteen of fifteen axes and Harvey on twelve of fifteen, identical on five. Harvey's lead is evidence about the AI. It took part in a third party benchmark against a lawyer baseline, publishes its own evaluation framework, and holds ISO 42001 and AIUC-1 certifications for AI management and security, audited by Schellman. Litera's lead is the contract. Its published terms bar Litera and its model providers from training on customer data and commit to incident notice within 72 hours. They cap liability at a year's fees with the intellectual property indemnity carved out, and require Litera to carry cyber and errors and omissions insurance. Litera states that its generative outputs are not tested, and Harvey publishes no liability terms or price.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the product. Assistant, Vault, Knowledge and Workflow Agents are all generative systems, and there is no underlying document or workflow system that would stand without them. Vendor material describes every module in model terms.
The models are the engine of a core capability layered on a product that stands without them, and the vendor says so in its own words. The Lito site describes an agentic layer that routes high-stakes work to Litera's deterministic comparison, document analysis and metadata removal engines, which return the same result every time, and flexible work to skills built on frontier models, and states that generative AI can be switched off entirely while the rules-based engines keep working. Draft Base, the entry package sold from the store, is document comparison; Lito was added to existing subscriptions at no charge in October 2025 rather than sold as the product. The published agreement suite treats the generative features as additional terms layered on the SaaS or on-premise software. Remove the models and a thirty-year drafting, comparison and metadata estate remains, which is the B band exactly. lito.app, litera.com home page, GenAI Terms (Version April 2026) and the October 2025 press release read 7 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Independent measurement exists and the vendor's own disclosure is substantial. Harvey Assistant participated in the February 2025 Vals Legal AI Report, a third party benchmark against a measured lawyer baseline, and was evaluated across six tasks scoring between 65.0 and 94.8 percent, surpassing the lawyer baseline on five of the six, with 94.8 percent on document question answering at 24.7 points above baseline and 77.8 percent on scanned and messily formatted court transcripts at 24.1 points above baseline, all at sub minute response times. Those figures sit on the evaluator's own site and are checkable without reference to any vendor claim. The vendor's own disclosure: BigLaw Bench with task categories and grading rubrics on a public repository, measured hallucination rates and source scores by model, a hallucination defined as a factual claim disprovable against a source of truth with reasoning errors tracked separately, and output linking to the specific document passages supporting each assertion. The citator and refusal questions are measured by their own signal rows on this record rather than counted again here, consistent with how the legal research vendors on this index are graded. Two limits recorded rather than deducted for: the February 2025 study measured task accuracy rather than citation validity or hallucination rate specifically, and this vendor did not participate in the later Vals study that measured citation authoritativeness. The full BigLaw Bench dataset also sits behind a direct request rather than open publication.
Grounding is claimed and accuracy is stated to be unmeasured, by the vendor itself. The Lito site says every recommendation shows its reasoning and its source, and that the agent is grounded in the firm's own templates, clauses, playbooks, precedents and matter data, with web search over public material supplied by You.com per the subprocessor register; no retrieval method is described and no accuracy figure or test set is published. The Generative AI Terms, Version April 2026, section 3(c), state that outputs may be inaccurate or misleading and are not tested, verified, endorsed or guaranteed to be complete or current by Litera, and that the customer is solely responsible for reviewing and verifying any output before use. Two limbs of the band do not bite for this product class and are named rather than penalised: Lito drafts and reviews against firm documents and does not cite primary legal authority, so there is no citator and no authority link to check. What is graded is that grounding to the firm's own sources is asserted with the source shown, while measurement is expressly absent, which is the C band. lito.app, GenAI Terms and the Litera One / Lito subprocessor register read 7 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
States in published material that the product is designed to assist lawyers rather than replace them and that it is built to make verification easy. Review surfaces are real and documented: inline links to source passages, role based permissions and conditionals in the workflow builder, and admin level workspace governance. Not located as of 29 Aug 2026: the threshold at which an agent stops and hands back to a lawyer, or what the vendor commits to when an agent is wrong.
A written commitment that the lawyer keeps judgement, with real controls, short of the full structure. The Lito site states that the lawyer keeps judgement either way, that firms can switch generative AI off entirely while the rules-based engines keep working, and that MCP connectors are governed centrally and enabled firm-wide; the Generative AI Terms, Version April 2026, place sole responsibility for reviewing and verifying output on the customer (3(c)) and prohibit deploying autonomous agents, recursive prompt chains or usage automation outside intended user flows (4(c)), which is a published boundary on what the system may run alone. What is not published is the threshold at which Lito acts without a lawyer in the loop when it chains deterministic engines at workflow milestones, what review surface a chained action presents, or what happens after an output is wrong beyond the customer's verification duty. That is the limb the B band names as commonly absent. lito.app and GenAI Terms read 7 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers appear in vendor material with attributed quotes, including Blank Rome on the iManage integration and a published Burges Salmon selection story. Vendor states 700 plus customers across 58 plus countries. Not located as of 29 Aug 2026: dated outcome figures with a stated method a reader could assess, which is what separates this from an A.
Named customers without figures, and figures without named customers. The Lito site carries attributed testimonials from Brian Corbett, partner at Poyner Spruill LLP, and Joshua Tan, partner at Delta Law Corporation, plus quotes attributed to CCA Law Firm and to unnamed Am Law firm associates; none carries a measured result. The figures on the same page are hero counters with no basis stated: 99 per cent of the Am Law 100, more than 15,000 firms, more than a million daily users and a 90 per cent efficiency gain, and the home page adds 74 per cent of the Fortune 100 for corporate legal. The October 2025 press release states that Litera One was used by roughly 40 per cent of the customer base and that early access firms shaped Lito, with no named firm and no figure. A dated, named deployment with a measured change and a method was not located, which is the limb between B and A. lito.app, litera.com home page and the October 2025 press release read 7 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments: no training on customer data by default, a contractual prohibition on model providers training, zero data retention enforced on model providers, logical workspace separation, role based access, ethical wall sync with the firm's own walls provider, and processing in the EU, Switzerland or Australia. Two gaps keep this off an A. The security page defines customer data as uploaded documents and customer content as queries and responses as separate contractual terms, so the no training commitment reads plainly on one and not on both. Attorney client privilege and work product handling is not addressed directly in located public material as of 29 Aug 2026.
Substantive published commitments on training and the model providers, short of segregation and privilege. The Generative AI Terms, Version April 2026, section 2(c), state that Litera will not and will not permit its third-party providers to develop, train or fine-tune any generative or foundational model with Customer Data, End User Prompts or Outputs unless agreed separately in writing; the Master Terms, Version November 2025, section 5.1, make Customer Data the customer's Confidential Information and section 6.2 leaves ownership with the customer with a licence limited to providing the Services; the SaaS Terms, section 3.2, commit to prompt deletion after termination; and the Litera One / Lito subprocessor register states the position on each model provider, including that Anthropic retains inputs and outputs for up to thirty days for trust and safety and that Amazon Bedrock does not pass inputs to third-party model providers. Two limbs of the A band are not met: no located surface addresses segregation between users, matters or clients inside a firm's tenant, and no located surface addresses privilege or work product handling directly, which R33 makes a required limb. The trust centre's Firm AI Search FAQ and security FAQ sit behind a Get access request and may address segregation; no request was submitted. GenAI Terms, Master Terms, SaaS Terms, subprocessor register and trust.litera.com read 7 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
One sentence in a security blog post states the product is designed to assist lawyers rather than replace them. Checked the vendor site, security page, security addendum and help center on 29 Aug 2026 and did not locate a published position on the advice line, on competence and supervision duties, or on jurisdiction limits. The intended audience is unambiguously lawyers and legal departments, which is why this sits at C rather than lower.
A real published position on advice versus tooling, short of jurisdiction limits and the supervision dimension. The Generative AI Terms, Version April 2026, section 3(d), state that the generative features are not intended as professional advice, cannot replace advice from a qualified professional and do not form any such relationship, naming the attorney-client relationship as the example; section 3(c) places sole responsibility for reviewing and verifying output on the customer. The intended audience is unambiguous: every segment page addresses lawyers, law firms of every size and corporate legal departments, and the Master Terms restrict use to the customer's internal business purposes with no consumer surface located. What is absent is any named jurisdiction limit and any treatment of how the product supports a lawyer's competence and supervision duties beyond the marketing line that the lawyer keeps judgement; a Litera CLE programme is advertised but was not read. GenAI Terms, Master Terms, lito.app and litera.com read 7 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Published on the trust centre, publicly and without a request: ISO/IEC 42001:2023 certification, the international standard for AI management systems, accompanied by a published Statement of Applicability, which is the document identifying which controls apply and why and is therefore a published scope rather than a bare badge. Alongside it, AIUC-1 certification, an AI specific assurance standard, conducted by Schellman, which the vendor states is the first accredited AIUC-1 certification body, and which the vendor describes as validating adversarial testing and its AI security programme specifically. EU AI Act conformity is separately listed. The trust centre carries a dedicated AI section with AI Governance, AI Monitoring and AI Overview items, and an AI Acceptable Use Policy sits in the published policy set. ISO 27701 for privacy information management and an IRAP attestation are also held. Two independent AI specific certifications, one of them adversarially tested, with published statements of applicability and a named accredited certifier, is the strongest AI governance position on this index, ahead of the other A grades on this axis, each of which rests on ISO 42001 alone or on a single certification plus a framework document. One gap remains and is recorded rather than waived: no disclosure was located as of 29 Aug 2026 about uneven output across matter types, parties or populations, so bias specifically is still unaddressed, and no named individual owner of model governance was located.
A position on training data and acceptable use is published; a governance framework, an owner and a testing regime are not readable. What was located: the Generative AI Terms, Version April 2026, commit that no generative or foundational model is trained on customer content and prohibit a listed set of abusive uses (2(b)); the Lito site names a security and governance layer that consists of ISO 27001, SOC 2 Type 2, SOC 3, GDPR, NIS 2 and DORA, which are security and regulatory attestations rather than AI governance; and the SafeBase trust centre inventories an item titled AI Training Data and Bias under an AI section, alongside a Firm AI Search FAQ, both behind a Get access request whose tier the portal does not state. No request was submitted and the document's contents are not credited by its title. Nothing readable names who inside Litera is accountable for AI output, what is tested before a skill ships, or any finding about uneven output. The gated bias document is the rebuttal route and would move this grade on a read. GenAI Terms, lito.app and trust.litera.com read 7 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Publishes retention under customer control with documented vault retention triggers and deletion timelines, role based access control, logical workspace separation, encryption in transit and at rest, and a current named subprocessor list with an update FAQ. Not located as of 29 Aug 2026: a published incident and breach notification practice, which is the remaining element of the A bar.
Retention, deletion, access control, subprocessors and incident practice are all published in binding instruments a buyer can read before signing. The Security Addendum 2023, incorporated by Master Terms section 5.3, commits to notifying the customer of a security incident without undue delay and within seventy-two hours of determining that Customer Data is affected, describes least-privilege access with multi-factor authentication and quarterly access reviews, AES-256 encryption at rest and TLS 1.2 or above in transit, annual third-party penetration testing with an executive summary on request, and deletion of remaining Customer Data after termination and any retrieval period. The SaaS Terms, Version March 2025, section 3.2, commit to prompt deletion after termination with backup copies removed on their normal cycle. The subprocessor register is published per product with hosting locations, and the Litera One / Lito entry names Microsoft Azure, Amazon Bedrock, Anthropic and You.com with what each processes and retains, with a registration link for change notices. The one limb not fully specific is in-term retention: no period is stated for prompts and outputs held on the platform during the subscription, only the provider's thirty-day window and the post-termination deletion. Security Addendum, SaaS Terms, Master Terms and subprocessor register read 7 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Checked the vendor site, its published legal pages including the security addendum and the subprocessor FAQ, and the trust center on 29 Aug 2026. No published indemnity scope, liability cap, carve out, warranty or insurance position located. Commercial terms appear to be reached through a negotiated enterprise agreement rather than published.
What the vendor stands behind is published and specific, including insurance, and including that on wrong output it stands behind nothing. The Master Terms, Version November 2025, section 7.4, give a defence and indemnity for third-party intellectual property claims in WIPO Copyright Treaty countries with five named exclusions and the modify, licence or terminate-and-refund remedies; section 7.8 caps Litera's direct-damages liability at fees paid under the ordering document in the preceding twelve months with the indemnity carved out of the cap; section 7.7 excludes consequential loss for both parties except under the indemnities; section 7.3 disclaims accuracy and results. The SaaS Terms, section 2, warrant substantial conformance with the documentation with a repair-or-refund remedy. The Security Addendum commits Litera to maintain cyber and technology errors and omissions insurance with an A.M. Best rating of at least A- and financial size of at least VII. The Generative AI Terms, Version April 2026, section 3(a), disclaim any liabilities, warranties or representations on output, notwithstanding the Master Terms, so a buyer can read before signing that the recourse for a wrong AI output is the customer's own verification. All documents read in full 7 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Documented native integrations with iManage, NetDocuments, SharePoint and OneDrive, Google Drive, Box, Microsoft Word, Outlook, EDGAR and PitchBook, plus an MCP connector library. Help center articles describe what each integration moves, in which direction, what an admin must configure, and what a given integration does not support. The iManage connection is a direct OAuth integration with an embedded web extension rather than third party middleware.
Real integrations are named and documented, short of what moves in which direction. The Lito site states that Litera is delivered inside Microsoft Word and Outlook, Google Workspace, a web app, Apple iOS and a Windows and Mac desktop client, names iManage and NetDocuments as connected document management systems, lists documents, emails, timecards, financial data, HR data and legal research as sources Lito reads from and writes back to, and states that MCP connectors are governed centrally by the firm; the October 2025 press release adds that Lito connects with Kira and NetDocuments. The Master Terms, section 3.2, record that the software is intended to be used with third-party office software and document management systems the customer procures. What is not published on any surface read is an implementer's description of what syncs, in which direction, and what a firm must configure; the integrations page at litera.com/integration was not read and is the route to A. lito.app, Master Terms and the October 2025 press release read 7 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
States processing in the EU and Switzerland or Australia for customers with data localization requirements, and states that this applies to subprocessors as well. Tenancy is multi tenant with logical workspace separation and enforced role based access. Not located as of 29 Aug 2026: where data is stored as distinct from where it is processed, and what changes between tiers.
Deployment options, regions and the processing location as distinct from storage are all published. The Master Terms, Version November 2025, section 2.1, define two deployment types, SaaS and on-premise, each under its own incorporated terms, and the Lito site adds a Windows and Mac desktop client for firms whose most sensitive work cannot move to the cloud. The Litera One / Lito subprocessor register states that the application is hosted on Microsoft Azure in United States, Canadian or European geographic regions; that Amazon Bedrock model inference runs in the same regions as the platform and inputs are not transmitted to third-party model providers; and that Anthropic model inference is hosted in the United States with inputs and outputs retained up to thirty days, so a European-hosted customer can read that generative processing may leave the storage region. The Generative AI Terms, section 2(d), commit to hosting models in the same jurisdiction as the SaaS software where commercially and technically feasible and otherwise in a jurisdiction with comparable standards, and direct the customer to the subprocessor disclosures for the location. Single- versus multi-tenant is not stated on any surface read, and the residency options do not differ by Draft package on anything read. Master Terms, GenAI Terms, subprocessor register and lito.app read 7 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
SOC 2 Type II attestation and ISO 27001 certification with the auditor named as Schellman, renewed annually, and the 2026 cycle announced publicly. Penetration testing and red teaming partners are named as NCC Group and Bishop Fox. Certified under the EU US Data Privacy Framework. A live trust portal at trust.harvey.ai carries the current reports. Reports sit behind a portal request rather than an open download, which is a request flow rather than a sales call.
Certification is real and stated on a rendering trust centre, short of scope, dates and a report reachable without a request. The SafeBase portal at trust.litera.com lists SOC 2 Type 2, SOC 3, ISO/IEC 27001:2022 with a statement of applicability, GDPR, DORA and NIS 2, and inventories the reports, a penetration test report, a security whitepaper, cyber insurance, a CAIQ and SIG Lite behind a Get access flow that offers to start a security review without stating whether fulfilment is self-serve on an email or click-through or runs through a sales conversation; the lower tier is graded and no request was submitted. The Security Addendum states that independent auditor reports are made available to the customer on request, that Litera's ISO 27001 certification covers its corporate offices, and that cloud providers are audited under SOC 2 Type II and ISO 27001. No auditor, audit period or scope statement was readable on any surface, which is what separates this from A; the trust centre overview describes the Litera Platform and Lito, so the scope connector to the product graded is present. trust.litera.com and Security Addendum read 7 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Publishes a subprocessor list naming model and infrastructure providers including OpenAI, Anthropic, Google Cloud, AWS and Microsoft, alongside a subprocessor update FAQ and a security diagram showing model access through Bedrock and Vertex AI. States zero data retention and ephemeral processing at the model providers. Not located as of 29 Aug 2026: a published commitment to notify customers before the model supply chain changes, as distinct from an FAQ describing a change that has already happened.
Providers are named, where they run is stated and a change-notice channel exists; the models themselves are not named, and three surfaces give three different provider lists. The Litera One / Lito subprocessor register, which is the binding disclosure, names Anthropic for model inference, hosted in the United States, possibly via Amazon Bedrock or Microsoft Azure Foundry, and Amazon Bedrock for inference in the platform's own region, plus You.com for web search, and offers a registration link for notice of subprocessor changes. The Lito site describes model-agnostic routing across OpenAI, Anthropic and Gemini. The Generative AI Terms, Version April 2026, refer to the terms of Azure OpenAI as terms Litera must abide by and to GPT-4 as an example in the fair usage clause. OpenAI and Google appear on the marketing page and in the agreement and not on the Lito register; a buyer reading the register alone would not learn that OpenAI models may process prompts. No specific model version is named on any surface beyond that one example, so the A band's models-named limb is not met. Subprocessor register, lito.app and GenAI Terms read 7 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Checked the vendor home page, the platform and product pages, the help center and the trust center on 29 Aug 2026. No pricing page, no published rate, no stated unit of charge and no published tier structure located. Access to pricing runs through a demo request, which is sales gated and earns no credit. Third party per seat estimates exist in trade coverage but are not vendor published and do not move this axis.
Real pricing is published for part of the range and the unit and structure are stated; the figure sits on a page this channel could not render. The Litera Store at litera.com/store offers Draft Base, Draft Pro, Clean (Metadact) and pdfDocs with a purchase button each, and the packages page as indexed by search states that firms with ten or more lawyers request a demo and talk to sales; the product detail pages on store.litera.com are rendered client-side and returned no body on 7 September 2026, so the published figure was not read and is recorded as a retrieval limit rather than an absence. The unit is published in the Master Terms: each licence is for a single named individual (3.1), fees and currency are set in the order form, terms auto-renew for twelve months with thirty days' notice (8.2), and overages on end users, lawyers or documents are invoiced (4.2). Lito is included with Draft Base, Pro and Advanced and with Kira at no additional charge, per the site and the October 2025 press release, and a store promotion offered twenty per cent off during ILTACON. Enterprise pricing is sales-gated, which is the B band as written. Store index, Master Terms, lito.app and press release read 7 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Describes its segments with substance: large law firms first, expanding into corporate legal departments and professional services, with 700 plus customers across 58 plus countries and practice coverage spanning litigation, transactional diligence, regulatory and tax. Not located as of 29 Aug 2026: a statement of the boundaries, meaning which firm sizes or practice areas the product is not built for, which is what the A bar asks for.
Segment and role coverage is described with substance, short of the boundaries. The site carries separate solution pages for small law firms, large law firms, global law firms and corporate legal, and role pages for lawyers, knowledge management, marketing and business development, CIO and IT, finance, and talent and HR; the Lito site walks through the associate, partner, transactional lawyer, knowledge manager, COO and marketing seats. Practice coverage is stated by skill rather than by practice area: the October 2025 press release names a launch library of eleven skills with planned additions for capital markets, M&A, business development, litigation and compliance, and the Lito site names contract review and redlining, deal management, precedent surfacing and pitch drafting. Store purchases are scoped to firms under ten lawyers with larger firms routed to sales. What is not stated is what is unsupported: no practice area, jurisdiction or language is named as out of scope, and the home page claims 99 per cent of the Am Law 100 and 74 per cent of the Fortune 100 without a basis. litera.com, lito.app and the October 2025 press release read 7 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The vendor security page states that by default it never trains on customer data and that it contractually prohibits model providers from training on customer data. A subprocessor FAQ states customer data is never used to train models unless explicitly authorized by both the customer and the vendor. The same page defines customer data as uploaded documents and customer content as queries and responses as separate contractual terms. No matching term was located in a published agreement as of 29 Aug 2026.
The published agreement prohibits training. The Additional Terms for Software with Generative AI Features, Version April 2026, incorporated into the Master Terms by section 2.4, state at section 2(c) that neither Litera nor its third-party providers will develop, train or fine-tune any generative or foundational model with Customer Data, End User Prompts or Outputs, with one qualifier carried here: the prohibition lifts only where agreed separately in writing, so any training would require the customer's own signature.
The Litera One / Lito subprocessor register repeats the position for each provider, stating that Amazon Bedrock and Anthropic do not use customer inputs to train underlying models. The Lito marketing site says recommendations are trained on the firm's comparison data, precedents and matter data; that sentence describes grounding within the firm's own tenant and the agreement governs. GenAI Terms and subprocessor register read 7 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
The security page states that customers determine what data to upload, how long it is retained, and whether it can be shared internally, and help center documentation covers configuring vault retention settings including triggers and deletion timelines. That is retention configured by the customer inside the product, which is the strongest form of the control this value describes. Recorded at customer controlled rather than the top value because no zero retention setting for the vendor's own storage was confirmed in public material as of 29 Aug 2026, and no default period is published, so a customer knows they can set the window without knowing what it is before they do. Zero data retention is stated separately as a requirement imposed on model providers, which is a different layer.
Retention is published as fixed periods the customer does not set. The Litera One / Lito subprocessor register states that Anthropic retains inputs and outputs for up to thirty days for trust and safety monitoring and then deletes them, that Amazon Bedrock processes inputs transiently, and that You.com does not retain search queries or results. The SaaS Terms, Version March 2025, section 3.2, commit Litera to delete all Customer Data promptly after termination of a subscription term, with backup copies removed on their normal schedule; the Master Terms define Customer Data to include material generated or processed using the software, so outputs are covered.
No retention period is stated for prompts and outputs held on the platform during the subscription term and no zero-retention setting is offered on any surface read, which is why this is recorded as fixed rather than configurable. Subprocessor register, SaaS Terms and Master Terms read 7 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Help center documentation states the product follows existing NetDocuments permissions, that a user sees only the cabinets, matters, folders and files they can already access, and that the product does not expand or modify permissions. The iManage integration is documented as a direct OAuth connection that respects iManage permissions and ethical walls. Separate admin documentation covers connecting, syncing and monitoring the firm's own ethical walls provider.
No located public material addresses ethical walls or matter-level segregation within a firm's tenant, and the surface most likely to carry it could not be read. The Lito site states that the agent reads from iManage, NetDocuments, documents, emails, timecards and financial data and that MCP connectors are governed centrally, without stating whether retrieval enforces the source system's permissions per user; the Security Addendum addresses separation of Litera's environments and personnel access, not separation between a customer's matters.
The trust center lists a Firm AI Search FAQ and a security FAQ behind a Get access request, and no request was submitted; those documents are the rebuttal route. A customer testimonial describing a closed system is a customer's statement, not the vendor's. Surfaces checked 7 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Checked the security page, the published security addendum and the subprocessor update FAQ on 29 Aug 2026. No located term or policy addresses government or law enforcement requests for customer data, and no transparency report was located.
The published terms commit to notice where lawfully permitted; no transparency report is published. The Master Terms, Version November 2025, section 5.1, make Customer Data the customer's Confidential Information and permit disclosure required by law, court order, subpoena or regulatory demand only to the extent required and after due notice to the other party unless notice is prohibited by law. The commitment is mutual and general rather than specific to law enforcement requests for customer data, and no transparency report or request statistics were located on any surface. Master Terms read 7 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The published subprocessor material identifies RELX and LexisNexis as a source provider behind an Ask LexisNexis feature, alongside web search providers, and product material refers to premium legal databases and curated public sources. The identification appears in the subprocessor list rather than a coverage page. No license or rights basis, jurisdiction list or update cadence for the primary law corpus was located as of 29 Aug 2026.
The sources behind the product's answers are identified and no license basis is stated for the public material. Litera ships no corpus of law: the Lito site describes a knowledge layer of the firm's own templates, clauses, playbooks and precedent and a data layer of the firm's documents, emails, timecards and financial data, and the subprocessor register states that You.com supplies web search over publicly available information to support AI-generated responses.
The firm's own content is the customer's under Master Terms section 6.2; no rights basis or update cadence is stated for the web results, and no legal research corpus is named even though legal research appears as a data source on the Lito site. The signal's law-corpus limbs bite only partly for a drafting and review product and are recorded as such. lito.app, subprocessor register and Master Terms read 7 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Checked product pages for the research module, the help center and the subprocessor material on 29 Aug 2026. A LexisNexis sourced research feature is documented, but no public material was located addressing whether authority returned by the product carries a treatment signal or is checked for subsequent history.
No located public material addresses whether cited authority is checked for subsequent history, and the product is not built to cite authority. Lito drafts, compares and reviews against the firm's own documents and playbooks and searches the public web through You.com; no surface read describes a citator, a treatment signal or a verification prompt for legal citations. A firm using Lito to draft a brief would be relying on its research tool, not on Litera, for good-law status, and the record says so rather than penalizing a product class the signal was not written for. lito.app, GenAI Terms and subprocessor register checked 7 September 2026.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
The vendor publishes measured hallucination rates and describes how hallucinated claims are detected and scored. Checked that research material, the product pages and the help center on 29 Aug 2026 and did not locate published material describing an explicit no answer or abstention path when the product cannot ground an answer.
No located public material describes what the generative features do when an answer cannot be grounded. The Lito site states that every recommendation shows its reasoning and its source, which is a provenance display rather than an abstention path, and the Generative AI Terms, Version April 2026, section 3(c), warn that outputs may be inaccurate or misleading and place verification on the customer without describing a refusal, a confidence score or a no-answer state.
The deterministic engines are described as returning the same result every time, which is a statement about the rules-based layer, not about generative uncertainty. lito.app and GenAI Terms checked 7 September 2026.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published sanctions summaries from Norton Rose Fulbright covering 2026 and two vendor maintained trackers.
The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance, and it is bounded by what that database covers.
No court order, opinion or disciplinary record naming Litera, Lito or Kira was located as of 7 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on all three names together with a general search for sanctions coverage; the results name general-purpose chatbots and other legal research products, and the single match on Kira is a judge's forename in a California appellate decision, not the product.
This is a statement about the public record, not a finding about the product; a drafting and review tool that does not generate legal authority citations carries a remote exposure on this signal.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Published material refers in general terms to aligning with the high standards expected of legal work and to designing the product so that verification is easy. Checked the blog, resource pages and help center on 29 Aug 2026 and did not locate engagement with any named ethics opinion, including ABA Formal Opinion 512 or state bar guidance.
Professional responsibility is engaged in general terms and no ethics opinion or regulator guidance on lawyers' use of AI is named. The Generative AI Terms, Version April 2026, section 3(d), state that the generative features are not professional advice, cannot replace a qualified professional and form no attorney-client relationship, and section 3(c) places verification on the customer; the Lito site says the lawyer keeps judgment.
Litera advertises a CLE program, which was not read. No surface read names ABA Formal Opinion 512, a state bar opinion or any court's standing order. GenAI Terms, lito.app and litera.com checked 7 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Vendor material offers impact and return on investment resources framed around what the product does for a firm or business, and the help center documents usage analytics dashboards and reporting APIs. Checked those surfaces on 29 Aug 2026 and did not locate a per matter record of AI assisted work intended for fee purposes, or any published guidance on billing, fee or client disclosure treatment.
The product sits inside law firms' fee relationships with their clients and the published position on the bill is a savings claim. The Lito site leads with reviewing and redlining contracts in minutes rather than hours, a ninety percent efficiency gain counter, and a framing that saved time should become better work, stronger relationships and profitable growth, and the home page says firms that bought AI to save time rarely know what the time returned.
Nothing on any surface read addresses how AI-assisted drafting or review is recorded on a client matter or disclosed on a bill; the products are sold to law firms that bill clients as well as to in-house teams. lito.app and litera.com checked 7 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The trust center's published inventory is the most complete outside counsel readiness pack on this index. Available without a request, as named items: a Data Processing Addendum, a Business Associate Addendum, a Data Subject Requests item, completed self assessment questionnaires in three standard formats being CAIQ v4.0.3, SIG Core and SIG Lite, a Data Flow Diagram, a Network Diagram, a HIPAA report, a report titled Security and Privacy of Customer Data, and a Security Welcome Packet.
A Subprocessors section is published as a standing part of the trust center. Sensitive documents sit behind a self serve access request with a bulk download option. Compliance items are listed individually and include statements of applicability for ISO 27001, 27701 and 42001, which tell a client's reviewer what each certification actually covers. A firm answering a client AI clause could assemble a complete response from this without a sales conversation.
One limitation recorded honestly: the subprocessors list renders client side and its contents were not retrieved in this pass, so the section's existence is established rather than the identity of the subprocessors in it.
A subprocessor and model provider list and forwardable client-facing material are published without an agreement in place. The subprocessor register is public and organized per product, and the Litera One / Lito entry names Microsoft Azure with its regions, Amazon Bedrock and Anthropic for model inference with what each retains, and You.com for web search, with a registration link for change notices. The Master Data Protection Addendum is published on the website, the Generative AI Terms and Security Addendum are published as standalone documents, and together they state the training prohibition, the retention position and the incident notice a firm needs to answer a client's AI clause.
What a firm cannot forward is the SOC 2 report, which sits behind a Get access request on the trust center. Subprocessor register, DPA page, GenAI Terms and Security Addendum read 7 September 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Published material documents audit logs as a default enterprise control, inline links from assertions to the specific source passages behind them, and usage analytics available through a dashboard and APIs. Checked those surfaces on 29 Aug 2026 and did not locate a per document export covering model used, sources retrieved and human verification together.
No located public material addresses court disclosure of AI use or a verification certification. The Lito site states that recommendations display their reasoning and source inside the product and that the deterministic engines return repeatable results; no surface describes an exportable per-document record of the model used, the sources retrieved and the human verification performed, and no disclosure template or guidance for standing orders was located. lito.app, GenAI Terms and litera.com resources checked 7 September 2026.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Good Law Verification
- Refusal and Uncertainty Behavior
Which one fits
Choose Harvey if
- You want outside evidence of how the AI performs. Harvey Assistant took part in the February 2025 Vals Legal AI Report, scoring between 65.0 and 94.8 percent across six tasks and beating the lawyer baseline on five, and Harvey publishes BigLaw Bench with its task categories and grading rubrics.
- Your risk committee wants AI specific certification. Harvey holds ISO/IEC 42001:2023 with a published statement of applicability and AIUC-1, both through Schellman, alongside SOC 2 Type II and ISO 27001, with penetration testing by NCC Group and Bishop Fox.
- Your documents sit in iManage or NetDocuments. Harvey's integrations follow the permissions a user already has in those systems, respect iManage ethical walls through a direct OAuth connection, and can sync with the firm's own ethical walls provider.
Choose Litera if
- You want the AI terms in a contract you can read before signing. Litera's generative AI terms bar Litera and its providers from training on customer data, prompts or outputs, and its master terms carry an intellectual property indemnity outside a liability cap of twelve months' fees.
- You need on premise deployment or a chosen region. Litera offers its software as a cloud service on Azure in US, Canadian or European regions or as on premise software, and its subprocessor register states where each model provider runs inference.
- You want AI added to drafting tools your lawyers already use. Lito comes at no extra charge with Draft Base, Pro and Advanced and with Kira, runs inside Word and Outlook, and routes comparison and metadata work to rules based engines that keep running with generative AI switched off.
In summary
Harvey
Harvey, founded in 2022 in San Francisco, is an enterprise legal AI platform for law firms, in house legal departments and professional services firms, with Assistant for chat, drafting and document analysis, Vault for bulk review, Knowledge for legal, regulatory and tax research with citations, and Workflow Agents for multi step automation. The AI Legal Index grades it in the top two bands on twelve of fifteen capability axes, with A grades on AI centrality, citation accuracy, AI governance, integration depth and security certifications. It publishes its own evaluation framework, holds ISO 42001, and states more than 700 customers in 58 countries. As of 29 August 2026 the index located no published liability terms, price or advice line.
Litera
Litera, based in Chicago, sells drafting, document comparison, proofing, metadata cleaning, contract review through Kira, transaction and knowledge management products that run inside Word, Outlook and other surfaces, and in 2025 added Lito, an AI legal agent included at no extra charge with its Draft packages and Kira. The AI Legal Index grades it in the top two bands on thirteen of fifteen capability axes, with A grades on data stewardship, liability and deployment. Its published terms bar training on customer data, carry an insurance commitment, and offer cloud hosting in three regions or on premise software. It states 99 percent of the Am Law 100 as customers. As of 7 September 2026 the index located no accuracy measure for its generative outputs.
Questions buyers ask
Harvey vs Litera: which is better for a large law firm?
The grid barely separates them: Litera sits in the top two bands on thirteen of fifteen AI Legal Index capability axes and Harvey on twelve of fifteen, identical on five. Harvey publishes more evidence about its AI, including a third party benchmark and AI specific certifications. Litera publishes more of its contract, including training, liability, insurance and deployment terms, and states that 99 percent of the Am Law 100 use its products.
Does Litera's Lito work without generative AI?
Partly. Litera says Lito routes high stakes work to its rules based comparison, document analysis and metadata removal engines, which return the same result every time, and flexible work to generative models grounded in the firm's own documents. A firm can switch the generative features off entirely and keep the rules based engines running. Harvey's modules are all generative. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Does Harvey train AI on client data?
Harvey's security page states that by default it never trains on customer data and that it contractually prohibits its model providers from doing so, with zero data retention required of them. The same page treats uploaded documents and queries and responses as separate contractual terms, and no matching clause was located in a published agreement. Litera's published terms bar training by Litera and its providers. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Which AI models do Harvey and Litera use?
Harvey's subprocessor list names OpenAI, Anthropic, Google Cloud, AWS and Microsoft, and on 1 September 2026 it added opt in access to Anthropic's Claude Fable 5.1, processed in the United States. Litera's subprocessor register names Anthropic and Amazon Bedrock for inference with where each runs, while its terms and marketing also mention OpenAI and Google. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What do Harvey and Litera both leave unpublished?
Any treatment of privilege and work product, and any check on cited authority. Neither addresses privilege directly in published material, neither checks legal citations for later treatment, and neither describes what its AI does when it cannot ground an answer. Neither publishes guidance on how AI assisted work should appear on a client's bill, although both sell to firms that bill clients. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Three readings to weigh. Litera's generative AI terms state that its outputs are not tested or verified by Litera, and its surfaces name different model providers, with OpenAI in its terms and marketing but not its subprocessor register. Harvey's no training commitment sits on its security page rather than in a published agreement, and its liability and commercial terms are negotiated privately. On 1 September 2026 Harvey offered an Anthropic model processed only in the United States, with zero retention for eligible customers under a time bound exemption. Harvey was verified on 29 August 2026 and Litera on 7 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.