Jurimesh vs Marveri: how they compare in 2026
Jurimesh and Marveri both run legal due diligence on a transaction's data room, organizing the documents, flagging gaps and producing cited findings for the deal team. Jurimesh sits in the top two bands on eleven of fifteen axes and Marveri on five of fifteen. The gap is a published agreement. Jurimesh's terms bar training on customer information without explicit consent, acknowledge that documents may be covered by professional secrecy, and delete live data within thirty business days of termination. Its data processing policy commits to notice before any disclosure to authorities, keeps data inside the EU, and lists each subprocessor with its hosting location. Marveri publishes no customer agreement, so its statement that customer data never trains models is not backed by a term a buyer can read. Marveri's counterweight is the range of deal work product it produces. It drafts disclosure schedules from every representation and warranty, ties out cap tables against the record, and answers request lists, with exact quote and calculation checks linked to each source.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Remove the models and nothing remains to sell. The agreement itself defines the Solution as a proprietary software platform that leverages artificial intelligence to facilitate and accelerate legal due diligence by enabling customers to upload, analyse and extract insights from legal and other business documents, so the AI is the definition of the product rather than a feature of it. Every published function is inference over an uploaded set: document recognition and classification against a request list, gap analysis identifying what the seller has not provided, agents running more than a thousand authored legal checks across the data room, extraction of change-of-control provisions, uncapped indemnities, auto-renewals and expired insurance, and generation of the due diligence report. There is no document management layer underneath, by design: the product connects to the customer's existing virtual data room rather than replacing it, so what is left without the models is a connector to somebody else's repository. Checked 5 September 2026.
The machine learning is the mechanism the buyer pays for. The product reads an entire data room and produces diligence memos, request-list responses, disclosure schedules, tie-outs and clause tables; remove the models and there is a file organiser. The company was founded in 2023 around this capability and has no non-AI product line. Home page, solutions pages and law-firms page read 6 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is documented as a mechanism rather than claimed as a quality, and none of it is measured. The stated architecture is that every clause in the data room is checked against expert-authored risk guides with every finding cited back to the source, and the product material carries that through: findings are displayed against the clause and schedule they rest on, and the company describes its check library as authored by named practitioners whose reports it publishes separately. For a diligence product that pairing, an authored rule set plus a citation to the source text, is the substantive answer to fabrication, and it is more than most in this lane publish. What is absent is any test of it. No accuracy figure, evaluation, test set, error rate or failure-mode statement appears anywhere, and there is no accuracy or benchmark page. The agreement runs the other way and is recorded here because a buyer should weigh both: article 3.5 expressly disclaims any warranty that the Solution will perform error-free and places on the customer the obligation and responsibility to verify the accuracy and validity of any and all output. The published figures are throughput rather than accuracy.
Grounding is real and documented with links to source, short of a testable accuracy figure. Every output is stated to link back to its source document, the law-firms page lists exact-quote verification, verified math calculations and cross-document references, and exports to Word and Excel carry citations; the vendor's positioning is verifiable results rather than conversational answers. No accuracy figure, test set or evaluation is published, and no hallucination statement was located. The primary-authority limbs do not apply to a tool that reads the customer's own documents. Home page and law-firms page read 6 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Review is built into the artifact and the threshold at which the agents act alone is unstated. The oversight surfaces are real and specific: findings are cited to the clause so a reviewer can open the source, the workspace carries per-item review states with named reviewers and timestamps covering reviewed, waiting for review and modified, and the security page commits that every user action is recorded in full audit trails. The agreement adds the obligation rather than leaving it implied, article 3.5 making verification of all output the customer's responsibility and article 4.1.3 requiring the customer to cease use immediately and notify Artificieel on observing any deficiency. What is missing is the machine's own account of itself. Nothing states what the agents do unattended, what routes a finding into review as against straight into the report, what happens when a check misfires, or whether generated text is marked as generated. The product is marketed as handling the entire diligence process, which makes the unstated boundary the live question rather than an academic one.
The modes are published and the review surface is the cited output, short of the full control structure. The product runs structured analysis automatically without prompting, producing cited work product a lawyer verifies and delivers, with role-based access control and document status tracking; the vendor describes results as auditable and ready for review before a first call. What is not published is any threshold at which an output is treated as final without review or a stated route back after a wrong finding beyond the reviewer's verification of the citation. Home page, law-firms page and trade coverage read 6 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers with roles and firms, published figures, and no join between them. Three testimonials carry full attribution and each links to its own customer story: Bas Mees, Partner M&A at Rutgers and Posch; Christopher Tournis Gamble, Managing Partner at WAD Capital, whose account is the most operational, reporting work a legal team would take months over completed in a couple of hours; and Hans Kayaert, General Counsel at Aikido. The company's own funding release adds Davy Gorselé, managing partner at Quorum. Eleven organisations appear as logos including Andersen, Van Benthem and Keulen, Vriman, One Peterson, Around Partners, Vybros, 9Corporate and Lighthouse. Separately the site publishes sixty to eighty per cent less manual review attributed only to customers generally, a first-pass data room review in under twenty minutes, four thousand contracts screened and more than a thousand authored checks. None of those figures is tied to a named firm, none is dated, and no method is published. One coincidence belongs on the record because a reader will find it: the name Hans Kayaert appears as a customer General Counsel here and, in the company's own funding announcement, as the representative of Syndicate One, the lead investor.
Figures without a named customer. The law-firms page states client onboarding time cut by seventy per cent, unattributed; user quotes reproduced by a third-party directory praise the product without naming a firm; the seed round announcement states a syndicate of early users invested. No named customer with a figure was located on the surfaces read. Law-firms page and coverage read 6 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
A published agreement that engages professional secrecy by name, which is rare, and stops short of treating it. Article 10.2 records that Artificieel acknowledges Confidential Information may be covered by the customer's professional secrecy, and article 10.4 commits that the AI models are not trained on the customer's Confidential Information unless explicit consent is given. Article 9.3 is tighter than most improvement clauses in this corpus: anonymised and aggregated data may be collected to improve the Solution provided that data does not include or reference any User Content unless the customer expressly authorises it in writing, so customer content is carved out rather than carved up. Article 9.2 licences User Content solely to provide the Solution, and the security page states that documents, findings and data rooms never leave the tenant they belong to, alongside SSO and full audit trails, with the data processing policy binding personnel to written confidentiality agreements and limiting access to those performing the assignment. Two limbs hold it here. Professional secrecy is acknowledged rather than given any handling treatment, and no matter-level separation inside a customer is described. The confidentiality obligation also expires three years after termination.
Confidentiality is addressed at the level of general assurance with one specific commitment. The security page states that customer data is never used for training, encryption in transit and at rest, and SOC 2 Type I and II; the law-firms page lists role-based access control. No customer agreement is published, so nothing binds the training statement, no retention or deletion commitment was located, the model providers behind the platform are not named, and nothing addresses privilege or work product for a tool that handles deal data rooms. Security page and law-firms page read 6 September 2026; the site's page inventory shows no terms of service.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
Nothing published addresses the advice line, on a product that produces the due diligence report a transaction is priced on. No statement that Jurimesh or Artificieel is not a law firm, no disclaimer that output is not legal advice, no description of the professional judgement a lawyer must apply before a finding reaches a client, no jurisdiction limit and nothing on supervision or competence was located. The agreement is the natural home for such a clause and has none: article 3.5 requires the customer to verify accuracy and validity, which is a statement about correctness rather than about advice, and articles 4.1.6 and 4.1.7 allocate responsibility for input and for regulatory compliance without touching the question. The exposure is specific rather than formal, since the product classifies contractual risk, flags uncapped indemnities and change-of-control triggers, and generates the report itself. The band above does not fit because it describes a boilerplate disclaimer sitting in the terms and there is no such clause. Searched the home page, the security page, the terms and conditions, the data processing policy and the subprocessor page on 5 September 2026; the product and solutions pages were not opened and are named as the limit.
No advice line or supervision statement was located. The product is marketed to lawyers and deal teams as producing the cited work product they are responsible for delivering, which positions it as a tool for professionals, but no surface read states that outputs are not legal advice, who should use them, or how the product supports a supervising lawyer's duties; no terms of service exists on the site to carry such a statement and the privacy policy PDF was not opened. Home page, solutions pages and security page read 6 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
No governance position was located. There is no responsible AI page, no principles statement, no accountable owner or function named for model behaviour, no pre-release evaluation regime and no AI management system such as ISO 42001, and nothing addresses uneven output. The omission is more pointed here than on most records for two reasons. The vendor is established in Belgium and sells into EU legal transactions, and nothing published engages the EU AI Act at all, in a policy set that is otherwise fastidious about EU regulation and cites the GDPR, the Belgian Privacy Law and the ePrivacy Directive by name. And the product's distinguishing asset is an authored check library, so who authors a check, how it is reviewed, and how a firm would know when one is wrong or out of date is a governance question the estate raises and does not answer. ISO 27001 is an information security standard and is credited on the certification row rather than counted here. Site navigation and footer inventoried 5 September 2026.
Assurance language without a governance framework, testing regime or accountable owner. The security page states that systems are continuously audited by trusted third parties for transparency and security, which is a security assurance, and the product's design of citing every output to source is a control on hallucination rather than a governance disclosure; no responsible AI framework, ISO 42001 or equivalent, pre-release testing description or statement about uneven output is published. Security page read 6 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Most of the ground is covered with real specificity, and the technical annex sits behind a portal that was not opened. Retention and deletion are stated as periods rather than principles: on termination live data is deleted within thirty business days and backup data fully overwritten within a maximum of ninety days after that, with a twenty-day export window before deletion begins, and the processing annex sets one year after termination for account and support data. Access is bounded, with SSO, full audit trails recording every user action, personnel under written confidentiality agreements and access limited to those performing the assignment. Incident practice is committed rather than asserted, requiring notification without undue delay with the information the GDPR requires and assistance with the customer's own reporting duty. The subprocessor position is the strongest element and is graded on its own row. What is missing from the readable surfaces is the technical detail: no encryption standard, key management or tenancy architecture is stated anywhere on the site, because Annex II of the data processing policy defers all technical and organisational measures to the trust centre, which was not opened in this pass and is named here as the limit.
Some of the ground is covered. Access control: role-based access control and encryption in transit and at rest are stated. Not located: any retention period or deletion commitment, any sub-processor list, and any incident-notification practice; the trust centre link on the security page resolves to the security page itself and the privacy policy PDF on the application domain was not opened and is the rebuttal route. Security page and law-firms page read 6 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A real two-sided position, published and readable before signing, short of anything warranting the output. Article 8.5 commits Artificieel to indemnify, defend and hold harmless the customer for direct damages arising from its own breach of the agreement and from infringement of third-party intellectual property rights in connection with the Solution, which is a vendor-side indemnity on both limbs and is uncommon in this corpus. Article 8.2 sets a remedy ladder rather than a bare cap, requiring renewed performance first and, where that is no longer possible or reasonable, compensation for direct damage limited to the fees paid in the preceding twelve months. The data processing policy mirrors it, with mutual indemnity for breach of the policy or the privacy legislation and the same twelve-month ceiling. Against that, article 3.4 provides the Solution as is, article 3.5 disclaims any warranty of error-free performance, article 8.1 excludes indirect and consequential loss including data loss, and article 8.3 carries a long list of exclusions. Nothing warrants the correctness of a finding, no service credit exists and no insurance position is published.
No liability position is published. The site's page inventory, taken from the navigation and footer on 6 September 2026, carries Security, Contact, Solutions and a privacy policy PDF and no terms of service, customer agreement or trust centre document; the security page describes controls and makes no warranty, indemnity, cap or insurance statement. This is an absence on the vendor's surfaces rather than a retrieval limit. Security page and footer read 6 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Named connections into the systems the work actually lives in, with the object of the connection stated, short of implementer documentation. Six counterparties are named on the home page and treated as the product's premise rather than as a badge strip: Ansarada, Virtual Vaults, HighQ and iDeals among virtual data rooms, and Google Drive and SharePoint for file storage, under a claim of direct integrations with every major VDR. What moves is described at workflow level, the platform reading the seller's data room, recognising every document and mapping it to the buyer's request list, and the commercial pitch is explicit that the product works alongside the VDR a firm already uses rather than requiring migration. For a diligence tool the data room is the integration that matters, and it is the one that is named. What is absent is depth: no field mapping, sync direction, trigger condition or permission model is described, no API or developer documentation was located, and nothing addresses document management, matter management or billing systems. The dedicated integrations page was not opened in this pass and is named here as the limit.
Integrations are named without documentation an implementer could use. The law-firms page lists Google Drive integration, SharePoint and OneDrive sync and local folder sync alongside Word and Excel export with citations, and a third-party profile states there is no API; nothing read describes what syncs, in which direction or what a firm must configure, and no document or matter management system is named. Law-firms page read 6 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Residency is answered more completely than anywhere else in this pull, and tenancy is asserted rather than described. The security page states that all data is stored and processed exclusively within the EU on ISO 27001-certified infrastructure, and the data processing policy makes it contractual at article 7.1, with article 7.2 setting out the safeguards that would govern any transfer outside the EEA, naming adequacy decisions, the 2021 standard contractual clauses with a transfer impact assessment, binding corporate rules and certification mechanisms. The subprocessor register carries it down to each provider, naming the contracting entity and the hosting location for every one, so a buyer can see that Google Cloud EMEA, Microsoft Ireland and AWS EMEA SARL all host in the EEA. On tenancy the estate offers one sentence, that documents, findings and data rooms never leave the tenant they belong to, which asserts that tenants exist and are isolated without describing the model, and no dedicated, single-tenant or self-hosted option is offered at any tier. The technical architecture sits in the unopened trust centre.
Cloud delivery is implied by a hosted application and neither tenancy nor region is stated. The product runs at an application subdomain, the security page states encryption and GDPR compliance, and nothing read names a hosting provider, region, residency option or tenancy model. Security page and home page read 6 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
A named standard claimed as achieved, a second claimed as in progress rather than implied, and no scope behind either. ISO 27001 is stated as certified on the home page, the security page and every page footer, the CTO's signed note repeats that the certification is maintained, and the company states that regular third-party audits and penetration tests validate its controls. The handling of SOC 2 is the detail worth crediting: it is labelled implementing, so a buyer is told plainly which standard has been achieved and which has not, where most vendors in this corpus display an undifferentiated badge. A trust centre exists at a published subdomain, is linked from the footer of every page and from the data processing policy as the home of the technical and organisational measures, and a public status page is published alongside it. What is absent is what an assessor would need: no certification body is named, no certificate number or expiry is given, no scope or statement of applicability is published, and no audit or penetration test summary is offered. The trust centre was not opened in this pass, so its contents and whether it is self-serve or gated were not established.
Certification is stated on the vendor's own surface, short of scope, date or a report route. The security page states SOC 2 compliance, Type I and Type II, with a badge, GDPR compliance, encryption in transit and at rest, and continuous auditing by trusted third parties; the law-firms page repeats SOC 2 Type II certified. No auditor, coverage period or report route is published, and the View Our Trust Center link resolves to the security page itself. Security page and law-firms page read 6 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The gap on an otherwise unusually well-disclosed record, and it is visible precisely because the rest is so complete. The vendor's own funding release states that the platform leverages large language models, and the agreement defines the Solution as leveraging artificial intelligence, but no model, version, provider or hosting arrangement for the model layer is named anywhere on the estate, and no commitment to notify customers of a change to it was located. The subprocessor register makes the absence concrete rather than inferred: it is versioned, dated 20 April 2026, and lists eight processors with contracting entity, jurisdiction, nature of processing and safeguard for each, naming Google Cloud, Microsoft Azure, Amazon AWS, ConvertAPI, HubSpot, Slack, tl;dv and Sentry. Those are cloud infrastructure and business tooling. The one AI provider named in the entire document, Anthropic, appears as the processor inside tl;dv, the vendor's meeting recording tool, not as anything touching a customer's data room. Naming where a model might run is not naming whose model reads the deal, and this is the middle band because the architecture is described while what sits under it is not.
No disclosure of what sits underneath was located on any surface read. The vendor describes AI built by machine-learning researchers and states that data is never used for training, but names no model, no provider, no inference location and no change-notification commitment; a third-party profile refers to an internal tooling vendor and is not credited. Security page, home page and law-firms page read 6 September 2026; the privacy policy PDF was not opened and is the rebuttal route.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The metering model is published in more detail than most price pages manage, and no figure appears anywhere. There is no pricing page in the navigation and the only commercial route is a demo request, but the agreement sets out the unit and its arithmetic precisely. The unit is a Transaction, each entitling processing of the documents for one corporate transaction such as an acquisition, investment or restructuring, consumed on completion of the analysis. Each Transaction covers up to 1,500 documents, with a further Transaction charged per additional block of 1,500 or part thereof, a document over fifty pages counted as one document per fifty pages, and a set under 150 documents charged at half a Transaction. Use beyond the purchased allocation is charged at the per-Transaction price increased by twenty-five per cent. Unused Transactions expire at the end of a term with no carry-over or refund. Fees are stated and payable in euro excluding VAT, invoices fall due in thirty days, price changes require two months notice, and annual indexation follows a published formula tied to the Agoria wage index. A buyer can model the shape of an invoice in detail and cannot learn the rate.
No pricing information is published at any level. The site offers a demo and a login and carries no pricing page, unit of charge, tier or figure; a third-party profile states no public pricing. Navigation, footer and solutions pages read 6 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Three buyer segments are defined and differentiated by what each one wants, and the practice boundary is never drawn. Law firms, private equity and corporate in-house teams each carry a dedicated page and a distinct proposition, the law firm framing being the movement of diligence from a cost centre to a profit centre, private equity being a fast read on a target's risk profile, and corporate being diligence brought in house. Practice depth is narrow by design and stated as such: this is transactional diligence for mergers, acquisitions, investments and restructurings, and nothing pretends otherwise. Customer evidence is consistent with the claim, naming M&A practices and investment firms across Belgium and the Netherlands. What is absent is jurisdiction, and on this product that absence is material rather than cosmetic: the value rests on a library of more than a thousand authored legal checks, and nothing published states which legal systems those checks are written against, whether a Belgian check applies to a Dutch or German target, or which languages the document recognition supports. No firm or deal size band is given either.
Segment and coverage are described with substance and the boundary is stated by the vendor. Solutions pages address M&A lawyers, startup and venture lawyers, companies preparing for a deal and companies evaluating targets, with private equity, investment banks and corporate development named; document coverage spans commercial agreements, IP, board minutes, financing documents and HR materials with support for more than a hundred languages. The vendor states its focus is M&A and investment diligence only, which is a stated limit; no jurisdiction is named. Solutions pages and law-firms page read 6 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The commitment sits in the published agreement and is conditioned on consent, which is what this value records rather than an outright prohibition. Article 10.4 of the general terms provides that the AI models are not trained on the customer's Confidential Information unless explicit consent is given, and Confidential Information is defined broadly enough to reach the documents and personal data a customer uploads. Two provisions strengthen it rather than qualify it.
Article 9.3 permits collection of anonymized and aggregated data to improve the Solution only on the express condition that such data does not include or reference any User Content unless the customer expressly authorizes it in writing, which closes the improvement route most agreements in this corpus leave open. Article 9.2 licenses User Content solely to provide the Solution. The marketing is more absolute than the contract and the gap is recorded rather than smoothed: the security page states that documents never feed a model and never train a model, without the consent carve-out the agreement contains.
Public material states that customer content is not used for training, and no agreement exists to carry a matching term: the security page states under the heading Zero Training that customer data is never used for training, and the site's page inventory taken on 6 September 2026 shows no terms of service or customer agreement, only a privacy policy PDF on the application domain, which was not opened. The statement is unqualified and unbound. Surfaces checked 6 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Fixed periods are published in the agreement and in the data processing policy, and they are consistent with each other. On termination all customer data and personal data in active production systems is deleted within thirty business days unless retention is required by law, and backup data, which cannot be deleted immediately, is fully overwritten or deleted within a maximum of ninety days after live data deletion.
A twenty-day export window runs first, during which the customer may request its data back, with any assistance beyond the standard export functionality charged at the vendor's hourly rates. The processing annex adds per-activity periods, retaining account and support data for one year following termination and handling the documents processed for the core diligence function under the deletion articles. What is not separately addressed is in-service retention: nothing states how long generated findings, reports or the prompts behind them persist while a subscription is live, beyond the general statement that personal data is kept only as long as needed to provide the services.
No located public material addresses how long uploaded documents or generated work product are retained. The security page addresses encryption and training only, no customer agreement is published, and the privacy policy PDF was not opened and is the rebuttal route; a third-party profile notes the retention policy is not public and is not credited. Security page, home page and footer checked 6 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Separation between customers is asserted in a single specific sentence and no mechanism is published. The security page states that a customer's documents, findings and data room never feed a model, never train a model and never leave the tenant they belong to, which asserts both that tenants exist and that data is confined to them. Around it sit access controls rather than partitions: single sign-on through the customer's identity provider, full audit trails recording every user action, and a data processing policy that limits personnel access to those performing the assignment and binds them to written confidentiality agreements.
Nothing states whether the platform is single or multi-tenant, and no permission or role model inside a customer's own workspace is documented, which matters on a product built around collaborative review where a deal team, and on the law firm side potentially conflicting deal teams, work in shared spaces. The technical and organisational measures are deferred to the trust center, which was not opened in this pass.
Segregation is claimed without documentation. The law-firms page lists role-based access control among the platform's features and the security page describes robust access controls in general terms; nothing describes how one deal's data room is walled from another within a firm or how the analysis respects those permissions, and no document management system's access model is inherited. Surfaces checked 6 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
A notice commitment that is unusually complete, appearing twice in the published data processing policy. Article 8.1 provides that Artificieel shall not disclose or transfer personal data to third parties without the customer's prior permission, except where disclosure is required by law or by a court or other government decision of any kind, and that in such a case it shall, prior to any disclosure, inform the customer in full transparency as to the scope and manner of it.
Article 9.1 goes further and commits to best efforts to inform the customer as soon as reasonably possible on four triggers, including receipt of a request for information, a subpoena or a request for inspection or audit from a competent public authority, and its own intention to disclose personal data to such an authority. Notice of an intention to disclose, as distinct from notice of a demand received, is rare in this corpus.
Article 7.3 adds a further notice duty before any transfer required by EU or member state law, unless the law prohibits informing on grounds of public interest. No transparency report is published, which is what holds this below the top value.
No located public material addresses whether the customer is told when its data is demanded by a third party. No customer agreement is published on the site, the security page is silent, and the privacy policy PDF was not opened and is the rebuttal route. Security page, home page and footer checked 6 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The product's legal content is described by its method of authorship and by nothing else. The check library is the distinguishing asset, marketed as more than a thousand expert-authored legal checks and as risk guides written by practitioners, with the company publishing separate reports under the line that they come from the people who write the checks Jurimesh runs. That establishes that the content is human-authored rather than derived from an external database, which is a real statement about provenance.
It stops short of what this signal asks for. No author is identified against any check, no jurisdiction is stated for the library or any part of it, no source material is named, no licensing position is published, and nothing describes how a check is reviewed or how often it is refreshed against changing law. The material the models read alongside the checks is the customer's own data room, so there is no external legal corpus behind an output.
Searched the home page, the security page, the terms, the data processing policy and the subprocessor register on 5 September 2026.
No located public material identifies a legal corpus behind the product's output, and the product is not built on one: it analyses the customer's own data room and cites its findings to those documents, citing no law. Home page and solutions pages checked 6 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Nothing addresses checking authority for subsequent history, and the product neither retrieves nor cites primary law. Its citations run to clauses and schedules in the customer's own uploaded documents, and its outputs are risk findings, gap analyses and due diligence reports. The adjacent question on this product is currency of the authored check library rather than currency of an authority, since a check written against one year's law may not hold in the next, and nothing published describes how that is maintained; that gap is recorded on the corpus row rather than forced into this value.
The value is the honest absence rather than a finding against the vendor. Searched the home page, the security page and the published policy set on 5 September 2026.
No located public material addresses whether authority is checked for subsequent history, and the product does not retrieve or cite primary law; its output is diligence work product cited to the customer's documents. Recorded as the honest value for a product without a citator function. Surfaces checked 6 September 2026.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
No located material describes what the system does when it cannot reach a reliable finding. There is no abstention path, no no-answer state, no confidence indicator against a finding, and nothing on behavior where a document is unreadable, a clause is ambiguous, or a check has no clear answer on the text. Two published features sit nearby and neither answers the question, so both are recorded. Gap analysis identifies documents missing from the seller's data room, which reports an absence in the material rather than uncertainty in the model's own output.
And the interface shows a brief reasoning indicator before an answer, which signals that processing occurred rather than describing how confidence is assessed or what happens when it is low. The agreement addresses the same territory as an allocation of risk, article 3.5 making the customer responsible for verifying all output, which places the burden without describing a behavior. Searched the home page, the security page and the published policy set on 5 September 2026.
The product documents how it surfaces what it cannot find rather than what it does when it cannot answer. The law-firms page states that missing documents, signatures and approvals are flagged and a supplemental request list generated, and that figures which do not reconcile across sources are flagged in tie-outs, which is a documented path for gaps in the record; no confidence signal or abstention behavior for uncertain findings is described.
Recorded as documented on the strength of the gap-flagging design, with the limit noted. Law-firms page checked 6 September 2026.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
The AI Hallucination Cases database maintained by Damien Charlotin was searched on 5 September 2026 on the product name Jurimesh and on the corporate name Artificieel BV. No court order, opinion or disciplinary record naming the product or the company was located. This records the state of the public record on that date and is not a finding about the product.
No court order, opinion or disciplinary record naming Marveri was located as of 6 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on the name together with a general search for court findings; results returned sanctions involving general-purpose chatbots and commentary, none of which names this product. This is a statement about the public record, not a finding about the product; a diligence tool that cites the customer's own documents carries a remote exposure on this signal.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Professional responsibility is engaged once, in general terms, and no authority is named. Article 10.2 of the general terms records that Artificieel acknowledges Confidential Information may be covered by the customer's professional secrecy, which is a direct reference to the professional obligation a European lawyer owes rather than a generic confidentiality recital, and it is why this sits above the floor. Nothing builds on it.
No bar or law society, code of conduct, ethics opinion or regulator guidance is named anywhere on the estate, no jurisdiction is identified for the proposition despite the agreement being governed by Belgian law and the customer base spanning several European bars, and nothing maps what a firm must do to discharge its own supervision and competence duties when an authored check and a machine reading produce a finding that reaches a client.
The regulatory material the vendor does publish is extensive but sits in data protection rather than professional conduct, citing the GDPR, the Belgian Privacy Law and the ePrivacy Directive by name.
No located public material names an ethics opinion, bar rule or professional responsibility framework. The product is built by former transactional lawyers for lawyers, but no guidance from any bar or regulator on lawyers' use of AI is named on the surfaces read, and no terms of service exists to carry one. Home page, solutions pages and security page checked 6 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The billing consequence is named as a selling point and never addressed as a disclosure question. The law firm proposition is published as moving due diligence from a cost center to a profit center, which is a direct claim about how a firm's economics change when the work compresses, and it sits alongside sixty to eighty percent less manual review reported by customers and a first-pass data room review in under twenty minutes.
Nothing follows from it. No per-matter record of AI-assisted work is described as available to a firm, no guidance on fee or disclosure treatment is published, and nothing addresses what a client is told when the diligence supporting a transaction was produced by agents running authored checks. The gap is sharper here than on most records precisely because the vendor raises the billing model itself: a product sold on the promise that diligence stops being a cost center is selling a change in what the client pays for, and the estate is silent on whether the client learns of it.
Law firms are a named buyer segment and the published position on the bill is a savings claim: client onboarding time cut by seventy percent and diligence completed in days rather than weeks. Nothing addresses how AI-assisted diligence is recorded or disclosed on a client's bill, in a practice area where the vendor's own founder describes diligence as consuming over half of transaction legal budgets. Law-firms page and coverage checked 6 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current, versioned, ungated subprocessor register with contractual change control, missing only the model layer. The register is published as Annex III to the data processing policy, carries a version number and a date of 20 April 2026, and lists eight processors with, for each, the contracting legal entity, the jurisdiction, the nature of the processing and the transfer safeguard relied on. The policy makes maintenance an obligation rather than a courtesy: the list must be updated whenever a subprocessor changes, changes must be clearly indicated and timestamped with effective dates, the customer must be notified, and the customer may object on reasonable grounds within thirty days with a route to terminate if no solution is found.
That is forwardable material a firm can send a client unaltered, alongside a published data processing policy and an annual audit right. What it does not contain is any statement of which model provider sees client content, and the only AI company named in it, Anthropic, appears as the processor inside the vendor's meeting recording tool rather than anywhere near a data room.
No sub-processor list, model provider list or client-facing AI disclosure material was located. The security page states SOC 2 and no-training assurances without naming any processor, the trust center link resolves to the security page, and no customer agreement or DPA is published; the privacy policy PDF was not opened and is the rebuttal route. Surfaces checked 6 September 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Substantial elements of a record exist as a property of the workflow, short of anything built for disclosure. Every finding is cited back to the clause and schedule it rests on, so the basis of an assertion can be produced; the workspace records per-item review states with named reviewers and timestamps, so who looked at what and when is captured; and the security page commits that every user action is recorded in full audit trails providing transparency into activity, access and data handling.
Taken together that is more of the sources-retrieved and human-verification elements than most records in this corpus can show. What is missing is the model. No model or version is identified against any finding, nothing marks which part of a report was machine-generated as against written by a reviewer, and no export is designed or described for producing the record to a client, a counterparty or a tribunal. No disclosure template or guidance is published, and the agreement, which is otherwise detailed, does not address it.
Some elements of a verification record are available and no record of the model or the human check is described. Every output links to its source document, exports to Word and Excel carry citations, and exact-quote and calculation verification are listed, which is a per-finding record of sources a reader can check; nothing states that the model used or the human verification step can be exported, and diligence work product is not court-facing. Law-firms page checked 6 September 2026.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Primary Law Corpus Provenance
- Good Law Verification
Which one fits
Choose Jurimesh if
- You work from the seller's existing data room. Jurimesh connects directly to Ansarada, Virtual Vaults, HighQ and iDeals, and to Google Drive and SharePoint, classifies every document against the buyer's request list, and shows what is missing before anyone starts reading.
- You need data kept in the EU under a contract you can read. Jurimesh's data processing policy keeps data stored and processed inside the EU, lists each subprocessor with its entity and hosting location, gives 30 days to object to changes, and commits to notice before any disclosure to authorities.
- You want the vendor to indemnify you. Jurimesh's terms indemnify the customer for direct damages from its own breach and from third party intellectual property claims, with renewed performance first and compensation up to a year's fees, and its checks come from a library of more than a thousand authored legal checks.
Choose Marveri if
- You need disclosure schedules and tie outs, not just findings. Marveri drafts disclosure schedules from every representation and warranty and exports them to Word, verifies cap tables against the underlying record, and builds clause tables for change of control, assignment and governing law.
- You want answers you can check without prompting. Marveri runs structured analysis with no chat interface, links every output to its source document with exact quote and calculation verification, and flags missing signatures, board approvals and amendments with a supplemental request list.
- Your data room spans languages and both sides of a deal. Marveri supports more than a hundred languages, answers request lists on the sell side and shows how a target should respond on the buy side, and states SOC 2 Type I and Type II.
In summary
Jurimesh
Jurimesh, from Artificieel BV of Ghent, Belgium, runs legal due diligence on corporate transactions from data room to report: it classifies each document against the buyer's request list, shows what is missing, runs more than a thousand authored legal checks with each finding cited to its clause, and builds a shared report. It connects to data rooms including Ansarada, HighQ and iDeals. The AI Legal Index grades it in the top two bands on eleven of fifteen capability axes, with an A on AI centrality. Its published terms and data processing policy keep data in the EU, bar training without consent and commit to notice before disclosure. As of 5 September 2026 the index located no named model provider, AI governance position or price figure.
Marveri
Marveri, from Cambridge, Massachusetts, founded in 2023 by a former Morrison Foerster associate and MIT machine learning researchers, is an AI due diligence platform for M&A and venture lawyers and deal teams. It organizes a data room, flags missing signatures and approvals, and produces diligence memos, request list responses, disclosure schedules, cap table tie outs and clause tables, each linked to source with exact quote verification. The AI Legal Index grades it in the top two bands on five of fifteen capability axes, with an A on AI centrality. It states SOC 2 Type I and Type II and that customer data is never used for training. As of 6 September 2026 the index located no customer agreement, named model provider or price.
Questions buyers ask
Jurimesh vs Marveri: which is better for M&A due diligence?
On published evidence Jurimesh sits in the top two bands on eleven of fifteen AI Legal Index capability axes and Marveri on five of fifteen, mostly because Jurimesh publishes its terms, data processing policy and subprocessor register. Marveri produces a wider range of deal documents, including disclosure schedules and cap table tie outs. European firms that need EU data residency in writing have more to read from Jurimesh.
Does Marveri train AI on data room documents?
Marveri's security page says customer data is never used for training. It publishes no terms of service or customer agreement, so that statement is not backed by a term a buyer can read before signing. Jurimesh's terms state that its models are not trained on customer information unless explicit consent is given, and bar using customer content for product improvement without written authorization. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
Which data rooms does Jurimesh work with?
Jurimesh names Ansarada, Virtual Vaults, HighQ and iDeals among virtual data rooms, and Google Drive and SharePoint for file storage, and says it works alongside the data room a firm already uses rather than requiring migration. Field mapping and sync direction are not documented. Marveri names Google Drive, SharePoint, OneDrive and local folder sync, with no sync detail published. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
How is Jurimesh priced?
Jurimesh publishes the unit but not the rate. Each Transaction covers one deal's documents up to 1,500, with documents over fifty pages counted per fifty pages, half a Transaction for under 150 documents and a 25 percent surcharge beyond the allocation. Fees are in euro, excluding VAT, and unused Transactions expire at the end of the term. Marveri publishes no pricing at any level. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
What do Jurimesh and Marveri both leave unpublished?
Whose models read the data room, and whether findings are accurate. Neither names the language model or provider behind its analysis, and neither publishes an accuracy figure or test set. Neither states that its output is not legal advice, and neither describes what its AI does when a clause is ambiguous or unreadable. Neither publishes a price figure. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
Three readings to weigh. Marveri publishes no customer agreement or terms of service, only a privacy policy, so its low grades on liability and data handling record what could be read. Jurimesh's security page says documents never train a model, while its terms allow training with explicit consent; the terms are the binding text. Jurimesh quotes Hans Kayaert as a customer's general counsel, and its own funding release names the same person for its lead investor. Jurimesh was verified on 5 September 2026 and Marveri on 6 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.