LawVu vs Xakia: how they compare in 2026
LawVu and Xakia both sell a legal operations platform to small and midsize in house teams, so they land on the same shortlist by construction. LawVu sits in the top two bands on eight of fifteen axes, Xakia on four, and the gap is assurance and integration. LawVu has held ISO 27001 since April 2019 with the statement of applicability available beside the certificate, publishes a requestable security pack containing that document and the full SOC 1 report, ships a Microsoft Power Platform connector documented in Microsoft's own catalogue with regional availability listed, an MCP server and a developer centre, and embeds its drafting toolbox natively in Word. Xakia answers on something this index almost never sees, which is what the product costs: named tiers, a per user per month unit, month to month plans with no lock in, a fourteen day trial with no credit card, and AI stated as an add on for two tiers and included in the other two.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of a core capability layered on a platform that would function without them. LawVu sold as a legal workspace for a decade before the AI layer: matters, contracts, intake, spend, reporting and a document repository are workflow and record keeping capabilities that operate with no model behind them, and the vendor's own capability navigation lists them separately from its AI. What the models drive is substantial rather than peripheral, which is why this is not a C: LawVu Intelligence spans an assistant, a self service agentic workflow builder, AI powered intake triage and a drafting and review toolbox in Microsoft Word. The June 2026 LegalOS launch reframes the whole platform around the AI layer, but the underlying workspace predates it. Seventh B on this axis, consistent with the other enterprise workflow platforms on this index.
FIRST C ON THIS AXIS IN THE INDEX. Artificial intelligence is present but peripheral: a feature layer on a product whose value stands without it. The decisive evidence is commercial rather than interpretive. The vendor sells its AI capabilities as a priced add on for the Advance and Professional tiers, included only in the Enterprise and All-In tiers, so a substantial share of its customers run the product with the AI switched off entirely and the vendor prices on that basis. That is the clearest possible statement that the core value stands alone. What the core is: matter management across the lifecycle, intake and triage, contracts, spend and budget management, document management, entity management and reporting, all of which are workflow and record keeping capabilities operating with no model behind them. MEMBERSHIP: the AI bar is nonetheless cleared, and this record is properly enrolled. Shipped AI features exist and are named individually: contract review and redlining, contract summarisation, key terms extraction, smart search and invoice review. The vendor's own framing is candid, describing AI as something it is continuing to expand rather than as what the product is.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted without measurement and the grounding method is described only at feature level. The strongest published element is architectural rather than evidential: LawVu Draft works from the customer's own clauses, precedents and playbooks, so drafting output is anchored to material the customer supplied and can check, and the trust centre carries a section headed Reliance which on its face addresses reliance on output. Searched the trust centre index, the AI governance page, the platform pages and the Microsoft connector documentation on 29 Aug 2026 and located no accuracy figure, no hallucination rate, no test set, no evaluation methodology and no independent benchmark participation. The Reliance page and the AI security and privacy FAQ were not retrieved in this pass and are the two documents most likely to move this row.
Accuracy is asserted without measurement and without a described grounding method. The vendor's published position is that it expands AI capabilities with a focus on things that genuinely save legal teams time without compromising accuracy or security, which asserts accuracy as a constraint on its roadmap rather than reporting it as a result. Searched the platform pages, the FAQ, the security page, the pricing page and the in house hub articles on 29 Aug 2026 and located no accuracy figure, no hallucination rate, no test set, no evaluation methodology and no independent benchmark participation. Nothing describes how contract review, redlining, summarisation or key terms extraction ground their output, whether extracted terms link back to the clause they came from, or what a reviewer sees to check a suggestion. For a product performing redlining and key term extraction on contracts the customer will sign, the absence of any described verification surface is the material gap.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A real control structure, published as a product capability rather than as a policy statement. Agentic workflows are built by the customer through a self service workflow builder, so what an agent is permitted to do in a given workflow is defined by the legal team rather than by the vendor, which is a more concrete allocation of authority than a human in the loop assurance. AI powered intake triage routes work rather than deciding it. The trust centre publishes a dedicated Reliance section, which is an unusual thing for a vendor to name and on its face addresses how far output may be relied on. Not located as of 29 Aug 2026: any threshold at which an agent stops or escalates, what the vendor commits to when an output is wrong, and the contents of the Reliance section itself, which was not retrieved in this pass.
Autonomy is limited by design and the control structure is implied by workflow rather than published. The product's shape places the human at every decisive point: legal teams route and tag intake requests themselves, set up matters from templates, assign tasks, and the AI features act on documents the user is working in, offering redlines, summaries and extracted terms rather than executing anything. Nothing in the located material describes an agent that acts unattended. But that is a description of a workflow rather than a published oversight position. Searched the platform pages, the FAQ, the security page and the in house hub on 29 Aug 2026 and located no statement of what the AI features decide unaided, no review surface described as such, no threshold at which anything escalates, and no statement of what the vendor commits to when an output is wrong.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers with published stories, short of figures and method. Three customer stories are featured with the organisation named: Property Finder on accelerating legal operations, Dentsu on uniting legal teams across more than 40 markets, and Sizzling Platter on scaling legal operations. A full customer stories index is published and is filterable by region across Asia-Pacific, North America, the United Kingdom, Europe and the United Arab Emirates, which lets a prospect find a reference in their own market rather than taking a global claim on trust. Independent review presence exists on G2. Searched the customer stories index, the platform pages and the resources library on 29 Aug 2026 and located no quantified outcome tied to a named customer, no dated case study and no assessable method. Named organisations without figures is the B band.
Testimonials and a logo strip stand in for deployment evidence. Attributed customer quotes are published including one claiming hundreds of hours saved and another that the platform transformed how a team works, alongside a leading brands strip and a stated base of in house legal teams of all sizes worldwide. Independent review presence exists on G2. Searched the site, the in house hub, the pricing page and the review platforms on 29 Aug 2026 and located no named customer paired with figures and a date, no case study with an assessable method, and no adoption count. Hundreds of hours saved is a testimonial rather than a measured result and was not treated as a figure.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
A substantial compliance framework is published without the specific limbs this axis tests being reached. Established: an information security management system designed against ISO 27001, SOC 2, SOC 1 and HIPAA, ISO 27001 certified since April 2019 with annual internal and external audits, a statement of applicability available in the security pack, a risk treatment standard applying ISO 27001 controls against a confidentiality, integrity and availability matrix with senior management review, and a stated practice of quantifying risk and implementing controls before any external party is granted access to sensitive data. The vendor also publishes a dedicated AI security and privacy FAQ and states AI data governance sits within the scope of its security and privacy compliance programme. What was not reached in this pass, and what holds this at C: that FAQ itself, which is where a training position, retention terms and any segregation model would sit. No statement on whether customer content may be used to train models was located, no retention or deletion terms, and no segregation model. This row is rebuttable in one step by retrieving the AI security and privacy FAQ.
Substantive published commitments, with segregation unusually well specified, short of the training and retention limbs. Segregation is the strongest element and is published at the level this axis asks for: role based permissions controlling access at individual user, team or matter level, with the vendor stating explicitly that sensitive matters can be restricted to specific individuals and that external parties such as outside counsel see only what the customer shares with them through the Xakia Connect portal. Matter level restriction plus a bounded external party view is a real confidentiality architecture rather than an assertion, and it addresses the in house version of the walls question directly. Single sign on through the customer's existing identity provider is supported. Certification covers ISO 27001, SOC 2 Type 2 and HIPAA with regular independent audits. Two gaps hold this off an A. No statement was located on whether customer content may be used to train or improve models. No retention or deletion terms were located. Attorney client privilege and work product are not addressed directly.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The audience is corporate and the product is deliberately extended beyond lawyers, with no position on the boundary published. The buyer is the in house legal team, with dedicated pages for general counsel and chief legal officers, legal operations, IT teams and teams with no existing legal technology. But LawVu Assistant is positioned explicitly as the AI legal assistant for legal and the business, and intake is sold as self service triaging, so business users interact with AI generated legal output by design. Searched the trust centre, the platform and solutions pages and the resources library on 29 Aug 2026 and located no published position on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits despite customers across five named regions.
The audience is corporate and the position is unstated. The buyer is the in house legal team, with internal business users submitting requests through intake and outside counsel interacting through the Connect portal, so non lawyers touch the platform by design though the AI features sit on the legal side of that boundary. The product manages legal work rather than giving advice, so the advice line question arises less sharply than for a research or drafting tool. Searched the site, the FAQ, the in house hub and the pricing page on 29 Aug 2026 and located no published position on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits despite the platform being configurable in four languages and supporting all currencies for global teams.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A published governance framework with real structure, short of certification, testing results and bias disclosure. The trust centre carries a dedicated AI Governance section and a separate AI Principles page, described as guidelines the vendor developed for its own use and development of AI tools, so the principles are a standing artifact rather than a marketing line. Governance is placed inside an existing assurance regime rather than alongside it: AI privacy and data governance is stated as provided within the scope of the security and privacy compliance programme, which is ISO 27001 certified with annual external audit, and a dedicated AI security and privacy FAQ is published. Not located as of 29 Aug 2026: an AI management certification such as ISO 42001, a named owner of model governance, published pre release testing results, and any disclosure about uneven output across matter types, parties or populations. The AI Principles page content was not retrieved in this pass.
Searched the site, the FAQ, the security page, the pricing page, the product updates section and the in house hub on 29 Aug 2026. No governance position for model behaviour was located: no AI principles or framework, no named owner of model governance, no pre release testing regime, no AI management certification such as ISO 42001, and nothing on uneven output across matter types, parties or populations. The vendor's only located statement touching governance is that it expands AI capabilities without compromising accuracy or security, which is an intention rather than a mechanism. Recorded as an absence on surfaces that were reached rather than assumed: the security page, FAQ and pricing page were all read and none addresses AI governance. Rebuttable with one link.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy covering most of the ground, with the assurance regime documented at an unusual level of process detail. Published: ISO 27001 certification held since April 2019 and maintained through annual internal and external audits with the statement of applicability available; SOC 1 first audited February 2021 with the full report in the security pack; SOC 2 described as regularly refreshed and covering security, availability and confidentiality; HIPAA named among the frameworks the management system is designed against; a risk assessment standard using a confidentiality, integrity and availability matrix with treatment requiring ISO 27001 controls, senior management review of residual risk, and reassessment triggered after any major change; and a stated requirement that risks from external parties are quantified and controls implemented before access is granted. A public system status page is published. Not located as of 29 Aug 2026: a stated retention period or deletion control, a named subprocessor list, and an incident or breach notification practice.
Certification and access control are published while the rest of the stewardship picture is not. Real and stated: ISO 27001, SOC 2 Type 2 and HIPAA certification, regular comprehensive independent audits of applications, systems and networks, enterprise grade cloud infrastructure, single sign on, role based permissions to matter level, and security documentation available on request with the SOC 2 report obtainable from the team. Searched the security page, the FAQ, the platform pages and the pricing page on 29 Aug 2026 and located no stated retention period or deletion control, no encryption specifics for data at rest or in transit, no named subprocessor list, no hosting provider or region, and no incident or breach notification practice. Recorded at C because access control and certification are covered well and the operational elements this axis names were not located.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Searched the trust centre index, the compliance and AI governance pages, the website terms, the mobile app terms and the platform pages on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer master agreement was located as published on the property. Recorded as a pure absence on the surfaces reached. Noted as the one place where this vendor's otherwise well organised trust centre has nothing: it publishes separate sections for security, privacy, compliance, reliance, AI governance and AI principles, and none of them addresses who bears the loss when an output is wrong. Rebuttable with one link.
Searched the site, the FAQ, the pricing page, the security page and the in house hub on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer terms of service was located as published on the property. Recorded as a pure absence on the surfaces reached. Worth noting the contrast within this record: the vendor is exceptionally clear about commercial terms, publishing tiers, per user pricing, trial conditions, no lock in and explicit statements that outside counsel are never charged and no percentage is taken on invoice value, and says nothing about who bears the loss when an AI redline or extracted term is wrong. Commercial transparency and liability transparency are different things and this record separates them sharply.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The strongest integration position in this category and among the better ones on the index, documented by a third party as well as by the vendor. LawVu Draft is embedded natively in Microsoft Word rather than connected alongside it. A Microsoft Power Platform connector is published in Microsoft's own connector catalogue covering Copilot Studio, Logic Apps, Power Apps and Power Automate, with prerequisites, publisher, support contact and regional availability documented including the specific regions excluded, which is implementer level documentation maintained by the platform owner rather than by the vendor. The vendor additionally ships an MCP server, publishes a dedicated integrations page and operates a developer centre at its own subdomain, so a customer can build against the platform directly rather than waiting for a connector. Spend management includes outside counsel collaboration, so the integration extends to parties outside the customer. Short of nothing material on this axis; no legal document management connector such as iManage or NetDocuments was located, which matters less here because the buyer is an in house team using the platform as its own repository.
Integration routes are named without documentation an implementer could use. Published: an open API available free of charge, which the vendor frames as letting customers connect the platform to their existing tools without a commercial gate, and that is a real position since several vendors on this index treat API access as a paid or contact us item. SharePoint is named for document management, with the vendor offering to keep documents in the customer's own SharePoint rather than requiring migration. Single sign on integrates with the customer's existing identity provider. A dedicated LegalTech integrations section is published. Searched those pages and the FAQ on 29 Aug 2026 and located no API documentation reachable without contacting the vendor, no per integration description of what moves in which direction or what an administrator configures, and no other named connector.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery and the hosting platform are stated and residency is not addressed. The vendor states its AI operates within its existing Microsoft Azure ecosystem, which identifies the platform, and it serves customers across five named regions being Asia-Pacific, North America, the United Kingdom, Europe and the United Arab Emirates. Searched the trust centre index, the security and compliance pages and the Microsoft connector documentation on 29 Aug 2026 and located no named Azure regions for customer data, no customer selectable residency, no tenancy model, and no statement of where processing happens as distinct from where data is stored. Serving customers in five regions is a market statement rather than a residency position and was not treated as one. For a New Zealand headquartered vendor selling into the United Kingdom, Europe and the Gulf, published residency options would be expected.
Searched the security page, the FAQ, the platform pages and the pricing page on 29 Aug 2026. The only located statement on infrastructure is that the platform operates on enterprise grade cloud infrastructure, which names neither a provider nor anything else. No hosting provider, no named regions, no customer selectable residency, no tenancy model, and no statement of where processing happens or where data is stored was located. The product is evidently cloud delivered and multi tenant, but both are inference from how it is sold and inference earns nothing on this axis. The absence is notable for a vendor serving global teams in four languages and all currencies, where a European or Japanese customer would be expected to ask where their data sits.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real, dated and accompanied by scope evidence, short of auditor identification and an open report route. ISO 27001 certification has been held since April 2019 and is maintained through annual internal and external audits, and critically the statement of applicability is available alongside the certificate, which tells a reviewer which controls the certification actually covers rather than only that it exists. SOC 1 was first audited in February 2021 with the full report available, and SOC 2 is described as regularly refreshed covering security, availability and confidentiality. HIPAA is named among the frameworks the management system is designed against. A structured trust centre is published with separate Security, Privacy, Compliance, Reliance, AI Governance and AI Principles sections and a public system status page. Access runs through a requestable security pack described as containing everything needed to start a security assessment, which is a self serve request flow rather than a sales gate. Short of an A because no auditing firm is named for any certification, no SOC 2 type designation or coverage period was located, and no certificate is published without the request step.
Certification is real, named and consistently stated across the property, short of scope and evidence detail. ISO 27001, SOC 2 Type 2 and HIPAA are all named, described by the vendor as third party accreditations, and repeated identically on the security page, the FAQ, the pricing page and each product page, which is more internal consistency than several records here manage. The vendor states it undertakes regular comprehensive independent audits of its applications, systems and networks, and publishes a dedicated information security page explaining what each standard covers rather than only displaying badges. Security documentation is available on request and the SOC 2 report is obtainable by contacting the team, which is a request flow rather than a sales gate. Short of an A because no coverage period, audit scope, report date or auditing firm was located for any of the three, and no trust portal exists, the route being a request to the vendor.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The hosting environment is identified and the models are not. The vendor states its AI capability is provided within its existing Microsoft Azure ecosystem, which locates the processing environment and is more than several records here disclose. Searched the trust centre index, the AI governance page, the platform pages and the Microsoft connector documentation on 29 Aug 2026 and located no named model or model provider, no statement of which models serve which capability, no subprocessor list, and no commitment to notify customers when the supply chain changes. The AI security and privacy FAQ was not retrieved in this pass and is where such disclosure would sit if it exists.
Searched the site, the FAQ, the security page, the pricing page and the product pages on 29 Aug 2026. No model, model provider, hosting location for model processing, or subprocessor was located, and no commitment to notify customers of supply chain changes. The vendor names its AI capabilities individually, covering contract review and redlining, summarisation, key terms extraction, smart search and invoice review, without identifying what powers any of them. A buyer cannot determine from published material whether their contracts are processed by a third party model provider at all, which is the first question a security review would ask about an AI add on.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
A plans page is published in the primary navigation, which is materially different from the demo only pattern that dominates this index, and the vendor separately publishes a return on investment calculator among its buyer resources. That a prospect is offered a plans page at all indicates some packaging is disclosed. What was not established in this pass is what that page contains: it was not retrieved, so no rate, unit of charge or tier structure is confirmed, and the record does not assume any. Recorded at C on the strength of a published plans entry point rather than higher, and flagged as rebuttable in one step by retrieving the plans page. Checked the trust centre, the platform pages and the resources library on 29 Aug 2026.
FIRST A ON THIS AXIS IN THE INDEX, and by a wide margin. A published pricing page sets out named tiers being Advance, Professional, Enterprise and All-In, states the unit of charge as per user per month, offers month to month plans with no lock in alongside discounted annual subscriptions, and provides a free 14 day trial requiring no credit card. Onboarding is disclosed as a separate one off fee with light and full options covering data migration and training, so implementation cost is surfaced rather than discovered later. AI is priced explicitly: an add on for Advance and Professional, included with Enterprise and All-In, so a buyer knows before contact whether the capability they want carries an extra charge. Two further disclosures go beyond what this axis requires and are recorded because they are rare: the vendor states outside counsel are never charged to use the Connect portal to submit invoices, and that it takes no percentage of the value of invoices processed, naming and rejecting the clip of the ticket model some competitors use. Not captured in this pass: the specific rates at each tier, which the pricing page presents but which were not retrieved here. The grade rests on the published structure, unit, trial terms and fee disclosures, which together let a buyer understand the commercial model without contacting anyone.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Who the product serves is documented precisely across three dimensions, each with its own published pages. Eight industries are named individually: healthcare, higher education, software and technology, financial services, government, energy, manufacturing and insurance. Four buyer roles carry dedicated pages: general counsel and chief legal officers, legal operations, information technology teams, and teams with no existing legal technology, the last being an explicit statement about maturity level rather than sector. Geographic coverage is enumerated by region with customer references filterable in each: Asia-Pacific, North America, the United Kingdom, Europe and the United Arab Emirates. Functional scope is stated at capability level across intake, matters, contracts, spend, reporting and documents, with contract lifecycle and spend management described as addable modules rather than bundled, so a buyer learns what is core and what is optional. The self limit is clear and consistent: this is an in house legal function platform, and nothing on the property claims law firm practice management or litigation capability.
Segment coverage is described with substance and includes an explicit self limit, which is rare on this index. The target is stated numerically rather than vaguely: in house legal teams of roughly 2 to 200, which tells a prospect outside that band to look elsewhere. Language coverage is enumerated and used as a differentiator, the platform being configurable in English, Japanese, Spanish and French with the vendor claiming it is the only multi lingual platform in its market, and the spend module supports all currencies for global teams. Functional scope is stated at module level across matters, intake, contracts, spend, documents, entities and reporting. Not located as of 29 Aug 2026: any industry segmentation, jurisdictional coverage stated as such, and any statement of which practice areas or work types the platform is not built for beyond the team size band.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Searched the trust centre index, the AI governance page, the compliance page and the platform pages on 29 Aug 2026. No located material states whether customer content may be used to train or improve models, either way. Recorded as silent under the rule that a value is never inferred from the absence of a contradiction. Flagged clearly for a future pass: the vendor publishes a dedicated AI security and privacy FAQ, linked from its AI governance page under the heading privacy and data governance, and states that AI data governance sits within the scope of its security and privacy compliance programme. That FAQ was not retrieved in this pass and is the single most likely location of a training statement. This value should be treated as unresolved rather than as an established absence.
Searched the security page, the FAQ, the pricing page, the platform pages and the in house hub on 29 Aug 2026. No located material states whether customer content may be used to train or improve models, either way, and no model provider is identified anywhere so no provider side commitment could be located either. Recorded as silent under the rule that a value is never inferred from the absence of a contradiction. The gap is sharper than usual for a product of this shape: the AI features operate on the customer's contracts and invoices, and the vendor sells that capability as a priced add on, so a buyer evaluating whether to switch it on has no published basis for deciding what happens to the documents it reads.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Searched the trust centre index, the AI governance page, the compliance page, the website terms and the platform pages on 29 Aug 2026. No public material located states how long prompts, generated drafts, assistant conversations or agentic workflow outputs are retained, whether a customer controls the window, or whether deletion is available. The platform is a system of record for matters, contracts and spend, so long retention of the underlying business records is inherent to it, and the AI layer generates a further body of derived material on top. As with the training signal, the AI security and privacy FAQ was not retrieved in this pass and is where retention terms would sit if published.
Searched the security page, the FAQ, the pricing page and the platform pages on 29 Aug 2026. No public material states how long documents, AI generated redlines, summaries, extracted terms or search queries are retained, whether a customer controls the window, or whether deletion is available. The platform is a system of record for matters, contracts and spend, so long retention of the underlying records is inherent to what is being bought, and the AI layer generates further derived material on top of it. No deletion route was located either.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Searched the trust centre index, the compliance page, the platform pages and the Microsoft connector documentation on 29 Aug 2026. No vendor material addresses segregation between users, teams or matters. The question has real weight for this product because the vendor positions its assistant as serving both the legal team and the wider business and sells intake as self service triaging, so people outside legal interact with the platform by design, and an in house team routinely runs matters such as employment disputes or internal investigations that others in the business must not see. No document management integration was located whose access model could be inherited.
One of the clearest segregation disclosures on this index for an in house product, and materially better than the category norm. The vendor publishes role based permissions controlling access at individual user, team or matter level, states directly that sensitive matters can be restricted to specific individuals, and states that external parties such as outside counsel see only what the customer chooses to share with them through the Connect portal. That is matter level restriction described as a product capability with a named use case, plus a bounded external party view, which together address both halves of the question this signal asks for a corporate legal buyer. Single sign on through the customer's own identity provider governs authentication. Recorded at own model documented rather than the positive value because the product operates its own permission structure rather than inheriting a document management system's access model at query time, and because nothing located states that the AI features respect those permissions when they read documents.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Searched the trust centre index, the compliance and privacy pages, the website terms and the mobile app terms on 29 Aug 2026. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. The vendor does publish a related but distinct control, stating that risks from external parties are quantified and appropriate controls implemented before access to its data and systems is granted, which governs its own supply chain rather than lawful demands for customer data, and the two were not conflated.
Searched the security page, the FAQ, the pricing page and the site footer on 29 Aug 2026, and no published customer agreement, terms of service or data processing agreement was reached. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. This records a search of the public pages rather than a reading of contract documents, none of which were located as published.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No primary law corpus is identified because the product does not hold one. Retrieval runs against the customer's own material: matters, contracts, documents and spend records held in the platform, with the drafting product working from the customer's own clauses, precedents and playbooks. So the corpus is the customer's institutional knowledge and its provenance is theirs. Searched the trust centre, the platform pages and the resources library on 29 Aug 2026 and located no vendor supplied legal corpus, no licence basis and no update cadence, and none would be expected for an in house workspace of this shape. Same architectural position as the contract platforms on this index.
No primary law corpus is identified because the product does not hold one. The AI features operate on the customer's own contracts, documents and invoices held in the platform, so the corpus is the customer's own material and its provenance is theirs. Searched the platform pages, the FAQ and the in house hub on 29 Aug 2026 and located no vendor supplied legal corpus, no licence basis and no update cadence, and none would be expected for a matter management product of this shape. Same architectural position as the other legal operations records on this index.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Searched the trust centre, the platform and capability pages and the resources library on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is an in house legal workspace whose corpus is the customer's own matters, contracts and documents rather than published case law, so a citator is outside its design entirely.
Searched the platform pages, the FAQ and the in house hub on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is a matter management and legal operations platform whose corpus is the customer's own matters, contracts and invoices rather than published case law, so a citator is outside its design entirely.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Searched the trust centre index, the AI governance page, the platform pages and the Microsoft connector documentation on 29 Aug 2026. No published material located describes what the product does when it cannot ground an answer, and no explicit no answer path or confidence signal exposed to the user was located. Recorded as not addressed with an explicit flag rather than as a settled absence: the vendor publishes a trust centre section headed Reliance, which is an unusual thing to name and on its face concerns how far output may be relied upon. That page was not retrieved in this pass. If it describes abstention or uncertainty behaviour this value should move, and it is the most likely single source on this record to do so.
Searched the platform pages, the FAQ, the security page and the product updates section on 29 Aug 2026. No published material describes what the AI features do when they cannot ground an answer, and no explicit no answer path or confidence signal exposed to the user was located. The vendor's statement that it expands AI capabilities without compromising accuracy is an assertion about quality rather than a description of behaviour under uncertainty, and the two were not conflated. For key terms extraction in particular, what the product does when a term is absent or ambiguous is a live question and is unaddressed.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note the product generates contract drafts and workflow output from the customer's own material rather than citations to authority, so the failure mode this database catalogues does not arise directly, and note also that the database is weighted toward United States filings while this vendor is New Zealand headquartered with customers across five regions.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note the product generates contract redlines, summaries and extracted terms from the customer's own documents rather than citations to authority, so the failure mode this database catalogues does not arise directly, and note the vendor is Australian headquartered while the database is weighted toward United States filings.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Searched the trust centre including the AI governance and AI principles entry points, the resources library including the published guide to AI for in house counsel, and the articles index on 29 Aug 2026. No engagement with any named ethics opinion or professional guidance was located, including ABA Formal Opinion 512, United States state bar guidance, and New Zealand Law Society or Law Council of Australia guidance given the vendor's home market. The vendor publishes substantial educational material for in house counsel on adopting AI, which addresses practice and procurement rather than the professional conduct rules its users are bound by. The AI Principles page was not retrieved in this pass and is a possible location for such engagement.
Searched the site, the FAQ, the in house hub articles and the product updates section on 29 Aug 2026. No engagement with any named ethics opinion or professional guidance was located, including ABA Formal Opinion 512, United States state bar guidance, and Law Council of Australia or state law society guidance given the vendor's home market. The vendor publishes practical guidance for in house teams on evaluating matter management software and on legal operations practice, which addresses procurement and process rather than the professional conduct obligations its users are bound by.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The product contains the raw material this signal looks for without publishing guidance on it. Spend management covers invoicing, e-billing and collaboration with outside counsel, and reporting dashboards run across all legal work, so a legal department using the platform holds a structured per matter record of what outside counsel did and what was paid. The vendor also publishes a return on investment calculator among its buyer resources, which is a savings framing aimed at the purchase decision rather than at the client. Searched the spend management and reporting pages, the resources library and the trust centre on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment. Recorded at savings claims only rather than at the audit record value because the records the platform holds concern outside counsel billing generally rather than AI assisted work specifically, which is the distinction the other legal ops records on this index also failed to cross.
The product holds the raw material and the vendor's published position runs to its own fees rather than to the client's. Spend and budget management tracks legal spend in real time with invoice review among the AI features, and the Connect portal carries invoice submission from outside counsel, so a legal department using the platform holds a structured per matter record of what firms billed. The vendor's distinctive disclosure is about its own charging: outside counsel are never charged to use the portal, there is no limit on invoices received, and no percentage is taken on the value of invoices processed, which it names and rejects as a clip of the ticket. That is a vendor being explicit that it does not profit from the size of its customer's legal spend, and no other record on this index makes that statement. Searched the platform pages, the pricing page and the in house hub on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes and no guidance on billing, fee or client disclosure treatment.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A structured route to diligence material is published and the specific artifacts this signal names were not confirmed within it. The vendor publishes a security pack, described as containing everything an organisation needs to begin a security assessment, obtainable through a request form rather than a sales conversation, and states that the ISO 27001 statement of applicability, the certification documents and the full SOC 1 report are included in it. A trust centre with separate Security, Privacy, Compliance, Reliance, AI Governance and AI Principles sections sits alongside it, plus a dedicated AI security and privacy FAQ. Recorded at on request on that basis. Not located as of 29 Aug 2026: a subprocessor list, any statement naming which model providers see customer content, a published data processing agreement, and any client facing consent or notification material. The security pack contents beyond the three documents named were not retrieved in this pass.
A stated route to diligence material exists and the specific artifacts this signal names do not. The vendor publishes that security documentation can be requested at any time and that the SOC 2 report is obtainable by contacting the team, alongside a dedicated information security page naming ISO 27001, SOC 2 Type 2 and HIPAA and explaining what each covers. Matter level access restriction and the bounded outside counsel view through Connect are genuine answers to part of what a client AI clause asks, since they bear on who can see client material. Searched the security page, the FAQ and the pricing page on 29 Aug 2026 and located no subprocessor list, no statement naming which model providers see customer content, no published data processing agreement, and no client facing consent or notification material. Recorded at on request on the strength of the stated documentation route.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Searched the trust centre, the platform and capability pages and the Microsoft connector documentation on 29 Aug 2026. No per document record covering model used, sources retrieved and human verification was located, and no model is identified in published material so the model used could not be stated. The platform necessarily records matter activity and workflow steps, and the drafting product works from identifiable customer precedents, so elements of a trail plausibly exist, but nothing published describes an export or a defensibility record. Noted for context: this is an in house legal workspace whose output is contracts, matter records and internal advice rather than court filings, so a judicial AI disclosure order is less likely to reach it than a research or litigation product.
Searched the platform pages, the FAQ, the security page and the in house hub on 29 Aug 2026. No per document record covering model used, sources retrieved and human verification was located, and no model is identified in published material so the model used could not be stated. The platform records matter activity, intake routing and spend against each matter, so a workflow trail plausibly exists, but nothing published describes an export or a defensibility record for AI generated output specifically. Noted for context: this is an in house matter management platform whose output is internal records, contracts and reporting rather than court filings, so a judicial AI disclosure order is less likely to reach it.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- AI Liability and Recourse
- Prompt and Output Retention
- Third Party Request and Subpoena Notice
- Primary Law Corpus Provenance
- Good Law Verification
- Refusal and Uncertainty Behaviour
- Bar Guidance Alignment
- Court Disclosure Support
Which one fits
Choose LawVu if
- Your legal team lives inside Microsoft. LawVu embeds its drafting and review toolbox natively in Word, ships a Microsoft Power Platform connector documented in Microsoft's own connector catalogue with publisher, prerequisites and regional availability listed, and additionally publishes an MCP server and a developer centre so a team can build against the platform directly.
- Your security review wants the paperwork, not the badge. LawVu has held ISO 27001 since April 2019, maintains it through annual internal and external audits, and makes the statement of applicability available beside the certificate, with a requestable security pack described as containing everything needed to begin a security assessment, including the full SOC 1 report first audited in February 2021.
- You want to find a reference in your own market and sector. LawVu publishes pages for eight named industries and four buyer roles, including one for teams with no existing legal technology, and a customer stories index filterable across Asia-Pacific, North America, the United Kingdom, Europe and the United Arab Emirates, with Property Finder, Dentsu and Sizzling Platter named.
Choose Xakia if
- You want to know the price before the call. Xakia publishes named tiers, a per user per month unit of charge, month to month plans with no lock in alongside discounted annual terms, a fourteen day trial requiring no credit card, and onboarding disclosed as a separate one off fee with light and full options.
- Some matters cannot be seen by the whole team. Xakia publishes role based permissions controlling access at individual user, team or matter level, states that sensitive matters can be restricted to named individuals, and states that outside counsel see only what the customer shares with them through the Connect portal.
- You do not want your vendor's fee to scale with your legal spend. Xakia states that outside counsel are never charged to use the Connect portal to submit invoices, that there is no limit on invoices received, and that it takes no percentage of the value of invoices processed, naming and rejecting the clip of the ticket model.
In summary
LawVu
LawVu is a legal workspace for in house legal teams, marketed as LegalOS, bringing intake with AI triage, matter management, contract lifecycle management, spend management and e-billing onto one platform, with a drafting and review toolbox embedded in Microsoft Word. The AI Legal Index grades it in the top two bands on eight of fifteen capability axes, with A grades on practice systems integration depth and on firm and practice coverage. It has held ISO 27001 since April 2019 with the statement of applicability available beside the certificate, and publishes a requestable security pack alongside a trust centre split into security, privacy, compliance, reliance, AI governance and AI principles sections. As of 29 August 2026 the index located no model or provider named, no residency statement and no liability position.
Xakia
Xakia is a matter management and legal operations platform for in house teams of roughly two to 200, positioned on affordability and fast implementation against heavier enterprise suites, covering matters, intake, contracts, spend, documents, entities and reporting. The AI Legal Index grades it in the top two bands on four of fifteen capability axes and awards it the only A on commercial transparency in the index: named tiers, a per user per month unit, month to month plans with no lock in, a fourteen day trial with no credit card, onboarding priced separately, and AI sold as an add on for two tiers and included in the other two. As of 29 August 2026 the index located no model named, no hosting or residency statement, no liability position and no training position.
Questions buyers ask
LawVu vs Xakia: which is better for a small in house legal team?
The AI Legal Index places LawVu in the top two bands on eight of fifteen capability axes and Xakia on four. LawVu publishes more assurance and far more integration, including a Microsoft connector documented by Microsoft itself. Xakia publishes what the product costs, which almost nothing else in this index does, and a matter level permission model. A team whose blocker is procurement paperwork and one whose blocker is budget will not reach the same answer.
How is Xakia priced?
Xakia publishes the structure rather than leaving it to a sales call: four named tiers, charging per user per month, month to month plans with no lock in alongside discounted annual subscriptions, a fourteen day free trial with no credit card, and onboarding as a separate one off fee. AI is an add on for the Advance and Professional tiers and included with Enterprise and All-In. The specific rates on that page were not captured during research. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
What security documentation can you get from LawVu?
LawVu publishes a security pack obtainable through a request form rather than a sales conversation, stating that it contains the ISO 27001 statement of applicability, the certification documents and the full SOC 1 report. Around it sits a trust centre with separate security, privacy, compliance, reliance, AI governance and AI principles sections, plus a public system status page. No auditing firm is named for any certification and no SOC 2 coverage period was located. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
Can you use either platform without the AI?
Xakia, plainly. Its AI features are sold as a priced add on for the Advance and Professional tiers and included only with Enterprise and All-In, so a substantial share of customers run matters, intake, contracts and spend with the AI switched off. LawVu integrates its AI layer throughout and relaunched the platform as LegalOS around it in June 2026, although the underlying workspace predates the models and the index grades it accordingly. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
What do LawVu and Xakia both leave unpublished?
Neither publishes a customer agreement, so neither states an indemnity, a liability cap, a warranty on output or an insurance position. Neither states whether customer contracts and matter content are used to train models. Neither names a model or a provider behind its AI features. Neither states a retention period or a deletion route. And neither publishes an accuracy measurement for contract review, extraction or drafting. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
Two limits shape this page. LawVu publishes a trust centre with sections headed Reliance, AI Governance and AI Principles plus a dedicated AI security and privacy FAQ, and none of those pages was retrieved during research, so its middle grades on confidentiality and accuracy, and the silence recorded on training, rest on documents that exist and were not read rather than on absences. On Xakia, the top grade for commercial transparency rests on published structure, being the tiers, the per user unit, the trial terms and the AI add on split, and the specific rates on its pricing page were not captured. Neither vendor publishes a customer agreement, so neither states a liability position. Both records were verified on 29 August 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.