Legl vs Thirdfort: how they compare in 2026
Legl and Thirdfort are both UK platforms that law firms use to verify clients for anti money laundering checks, and both sit on the government's Digital Verification Services register. Thirdfort sits in the top two bands on ten of fifteen axes and Legl on seven of fifteen, identical on seven. Thirdfort publishes its terms, data processing agreement and supplier terms in full. Its terms warrant that reports are materially accurate and cap liability at the higher of 25,000 pounds or a year's fees. Its processing agreement commits it to challenge public authority requests for data and to notify the firm. Legl's firm agreement is named in its own documents but not published, so what it stands behind cannot be read. Legl's counterweight is its AI and the controls around it. Its risk agents screen, monitor and read documents across onboarding, return each match with a confidence level and evidence, and escalate high risk cases to a named reviewer. Thirdfort's AI covers document verification only. Neither says whose model does the work.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The AI is a platform layer rather than a feature, and the vendor's own information architecture says so: Risk Agents is one of three items under Platform, alongside the Governance Layer and Integrations, and sits above the six solution modules rather than inside one of them. The agents are described as operating across the client lifecycle: researching and structuring screening matches, triaging ongoing monitoring alerts, reading bank statements in source of funds, analysing trust deeds for trustees, settlors and beneficiaries, auto-populating risk assessments, and running remediation loops back to the client. Screening and monitoring are described as running continuously using the agents. What holds this below the top band is the size of the non-AI spine underneath. Client payments and reconciliation, digital onboarding workflows, company registry retrieval, e-signature, dashboards and reporting all predate the agents and work without them, and the compliance value a firm buys, being a defensible file for an SRA or MLR audit, is produced by the workflow and the audit trail rather than by inference. The AI removes manual effort from a compliance process that would still run without it. Checked 7 September 2026.
The AI is real and vendor-claimed but it powers one product of five. Thirdfort sells identity verification, document verification, PEPs and sanctions screening, source of funds and know-your-business checks. Only document verification carries an AI claim, and it carries a clear one: a section headed An AI for detail, stating that artificial intelligence inspects every upload for signs of tampering, forgery and counterfeiting across visual, data and metadata elements, repeated in the FAQ in the first person as our AI. The flagship identity check makes no AI claim at all: its published mechanisms are cryptographic reading of the signing keys in an e-passport NFC chip and address matching against Experian data. The remaining products are screening and registry lookups against ComplyAdvantage, Dun and Bradstreet and Kyckr sources. Remove the models and four of the five checks are unaffected while document verification loses its detection engine. That restraint is itself evidence the claim is meant literally rather than decoratively, but it places the machine learning as a component of one module rather than the mechanism a buyer is paying for across the platform. Checked 7 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real and documented and a verification step is described, short of any accuracy figure an outsider could test. Screening matches are returned with a recommendation, a confidence level and the supporting evidence, so the reviewer sees what the model relied on rather than a bare conclusion, and the underlying sources are named suppliers a firm can identify. In source of funds the vendor describes a specific control: the AI reads the statements and surfaces income, large one-off payments, balance trends and higher-risk activity, with a mathematical validation step confirming the figures are consistent before they reach the reviewer. That is a described method with an arithmetic check on the model's output, which is more than most records on this axis publish. What is absent is measurement: no accuracy figure, no false positive or false negative rate, no test set, no evaluation and no named failure mode, on a product whose core function is deciding whether a flagged record really is the firm's client. One tension is recorded because a reader who finds it unaided should see it in the note: the published Terms of Use state that Legl makes no representations or warranties as to the truth, accuracy, quality or completeness of information provided in connection with the services, which sits against a product that returns confidence levels and validated figures. Grounding to primary legal authority does not bite on a due diligence product and is counted neither way. Checked 7 September 2026.
Grounding is real, documented and unusually verifiable, and there is a contractual accuracy undertaking, but nothing measures the result. Every identity document is cross-referenced against the Metropolitan Police's Amberhill database of documents reported lost or stolen, which is an external authoritative check a buyer can name. The identity check validates the cryptographic signing keys inside an e-passport chip rather than inferring from an image. Reference data is attributed to named suppliers with published terms. Clause 6.1(b) of the Terms of Use commits Thirdfort to use all commercially reasonable endeavours to ensure Reports are in all material respects accurate and complete, which is more than most records on this axis carry, and the app applies documented guardrails that block blurry, cropped or oversized uploads before they reach the model. What is absent is measurement. For a forgery detection product the natural figures are a detection rate and a false positive rate, and neither is published, nor a test set, an evaluation, or any named failure mode. One tension belongs on the record: Thirdfort warrants report accuracy in its own terms while the supplier terms it passes through disclaim it, with Experian stating it cannot accept liability for any failure of its services to achieve a particular result and Kyckr disclaiming any warranty of accuracy, completeness or reliability. Grounding to primary legal authority does not bite on a due diligence product and is counted neither way. Checked 7 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
All four limbs of the top band are published separately and explicitly, which is rare enough on this axis to state limb by limb. What the system runs alone: screening, ongoing monitoring and remediation are described as running continuously, with clients re-screened daily, agents gathering and parsing documents, researching and structuring data, reading bank statements, analysing trust deeds, and operating remediation loops directly with the firm's client to collect missing information. What constrains it: the governance layer codifies the firm's own risk policies into Risk Rules the agents enforce, and administrators control screening configuration firm-wide, choosing which categories are screened, which PEP seniority levels, which source jurisdictions, how widely to search and how sensitive matching should be. How a lawyer checks it: matches are returned with a recommendation, a confidence level and the supporting evidence, the compliance dashboard gives a firm-wide view with downloadable reports, decisions and overrides are recorded with their reasoning, confirmed false positives can be whitelisted, and a weekly summary reaches the MLRO. The route back to human judgement: the vendor states that agents exist to flag discrepancies and non-conformity for human attention and that the decision stays with the reviewer, high-risk factors escalate automatically by email to the MLRO or nominated reviewers with the assessment queued for review, alerts can be assigned to a named reviewer, and reassessment dates are set by risk level. The published position is a division of labour rather than a slogan: agents do the gathering, research and structuring, and people decide. Checked 7 September 2026.
The route back to human judgement is contractual rather than advisory, which is rare on this axis. Clause 8 states that the Reports must not be relied on as the sole basis to make business decisions, that the firm is solely responsible for the conclusions drawn from them, and that Thirdfort provides no opinion and makes no recommendation on the treatment of results. The flow-down terms repeat it at supplier level, with ComplyAdvantage stipulating that results must not be used to draw any automatic conclusion or be relied on in isolation about any person flagged or not flagged. There is a review surface behind the words: the report presents flags in three states, showing what has passed, what is not relevant and what requires consideration, and the last of those is an explicit routing of the decision to a person. The uploaded document is stored alongside the report so the reviewer can check the model's input against its output. What is missing is the internal control structure. No threshold is published at which the system flags rather than passes, no confidence signal is described as visible to the reviewer, and nothing states what happens when a forgery is missed or a genuine document is wrongly flagged. Checked 7 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Adoption evidence is strong and unusually well attributed to the buying role. Named firms include Lewis Silkin, Michelmores, Stephens Scown, Taylor Rose, Cripps, gunnercooke, Tollers, Wilkes, Blacks, Higgs, Woodstock, Wolferstans, Hall Brown Family Law, Harold Benjamin, Burnett and Reid, Robertsons, Sharmans and Laytons ETL. Testimonials carry full names and job titles, and the titles are the ones that matter for this product: Helen Strachan, Practice Director and MLRO at Burnett and Reid; Shivani Patel, Compliance Supervisor at gunnercooke; Guy Hurst, Compliance Manager at Wilkes; Will Taylor, CFO and COO at Hall Brown; Natasha Boyland, Director and Head of Risk and Operations at Woodstock; Simon Bagshaw, Director of Finance and IT at Tollers. Two concrete figures are published, both customer-stated: half of due diligence requests completed within 24 hours of being sent at gunnercooke, and three risk assessments in about twenty minutes against roughly an hour for one under the previous system at Sharmans. Two things hold this at B. The figures sit in testimonials with no method, sample, baseline date or independent basis, and only the Sharmans figure is a before-and-after. And the headline adoption count is inconsistent across the vendor's own current surfaces: the marketing site says more than 600 law firms while the trust centre description says more than 400 including 40 of the top 200. Both are the vendor's own live material and neither is reconcilable from outside, so the discrepancy is recorded and nothing is graded on either figure. Checked 7 September 2026.
Real deployment evidence at scale, short of assessable measurement. The published base is more than 1,500 regulated businesses, and named customers appear with attributed quotations rather than logos alone: Boyce Hatton on meeting HM Land Registry's Digital ID Standard, Thomas Legal on client completion times as a competitive differentiator, Mezzle on the client experience, and Direction Law, which states it set a target of a 50 per cent increase in the speed of its compliance process and believes it not only hit but exceeded it. Operational figures are published and specific: 75 per cent of individuals complete their checks within 24 hours, documents verified from 195 jurisdictions, electronic address verification across 17 jurisdictions, and reports returned in minutes. Two things hold this at B. The figures carry no method, sample, baseline or date, and the strongest of them is a customer's own belief about its target rather than a measured result. And none of the outcome evidence is attributed to the AI: the completion and speed claims describe the app and the check workflow, so a buyer assessing the forgery detection specifically has adoption evidence for the platform and none for the model. Checked 7 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The commitments that exist are real, but the instrument that would govern the buyer is not published, and that is what decides this. The only agreement on the site is the Terms of Use, which by its own first clause governs the individual submitting a payment or completing a workflow, not the law firm. The firm-facing agreement exists and is named: the sub-processor policy refers throughout to the Legl Services Agreement and states that undefined terms take their meaning from it. It is published nowhere. A buyer therefore cannot read the confidentiality obligations, the data handling terms or the security commitments that would actually bind Legl to the firm. What is published and does count: a strong biometric commitment, under which neither Legl nor the firm ever receives the biometric identifier generated from the client's images, it is held by the provider only until Legl says it is no longer needed, and Legl states it does not use, disclose or retain biometric information for any other commercial purpose; a destruction obligation on the firm's request or when processing is no longer needed; and contractual safeguards imposed on all sixteen sub-processors, including confidentiality obligations on their personnel and prompt breach notification. Privilege and work product appear nowhere, and the product holds client identity and source-of-funds material rather than matter files. Checked 7 September 2026.
Substantive published commitments across most limbs, short of the one this axis exists for. The Terms of Use define mutual confidentiality with need-to-know access, a 30-day destroy-or-return obligation on request, and liability for the acts of permitted recipients. Clause 12.1 leaves the firm owning the intellectual property in its own data and clause 12.3 licenses that data to Thirdfort only to the extent needed to provide the Services. The data processing agreement makes the firm the controller and Thirdfort the processor, limits processing to the Services and the firm's instructions, and restricts access to personnel who need it. Security measures are specific: AES-256 or stronger at rest, TLS 1.2 or better in transit, two-factor authentication for platform users, least privilege and device encryption for staff, no storage on local machines, and a documented architectural separation of data between different customers. Deletion is concrete, with all initiation and report data removed within 30 days of a written request and the fields covered enumerated down to date of birth and home address. What is absent is privilege and work product, which appear nowhere in the estate. The omission costs a buyer less here than on a matter-facing product, because what Thirdfort holds is client identity and source-of-funds material rather than privileged case files, but the limb is required for the top band and it is not met. Checked 7 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
An express disclaimer exists in a published agreement and no conduct framework sits behind it. The Terms of Use state that nothing in the Legl Services, or in emails Legl sends on the law firm's behalf, is or should be construed as legal advice, and separately that the individual's use of the service is not determinative of their status as a client of the firm, with appropriate contractual arrangements to be put in place directly. Both are directed at the firm's client rather than at the firm, which is the right audience for a platform that communicates with clients under the firm's brand, and the second is a genuinely useful clarification of where the retainer sits. The product is also built around the firm's own regulatory obligations, with MLRO dashboards, defensible records of how each client was assessed and why, and audit-ready reporting. What is not addressed is professional responsibility in the firm's use of the AI: nothing names a conduct rule or regulator, nothing addresses supervision obligations when an agent acts, and nothing states what a firm must still do itself to discharge its duties. Limbs of this axis that turn on producing legal work product do not bite on a due diligence platform and are counted neither way. Checked 7 September 2026.
Responsibility is allocated in the agreement but no professional conduct framework is engaged. Clause 8 does the allocation squarely: the Reports help a firm understand risk and meet its compliance obligations, they must not be the sole basis of a decision, the firm is solely responsible for the conclusions it draws, and Thirdfort gives no opinion and makes no recommendation. The consumer wording in Appendix 1, which the firm is required to send to its client before lite screening and identity document verification, frames the check as part of the professional's own due diligence rather than as advice from Thirdfort. Both are more than most records carry. What is not addressed is professional conduct as such: nothing engages unauthorised practice, nothing names a conduct rule or regulator obligation that the firm's use of the product touches, and the estate contains no professional responsibility statement. Several limbs of this axis do not bite on a due diligence platform that never advises a client or produces legal work product, and they are not counted against the vendor; the grade reflects that a real allocation exists and a conduct framework does not. Checked 7 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
No governance disclosure was located. There is no AI policy, no responsible AI or ethics statement, no governance framework, no bias or fairness discussion, no ISO 42001 or NIST AI RMF alignment, no named internal owner for AI decisions, no model evaluation or testing description, and no AI provision in any published agreement. The gap is conspicuous rather than incidental on this record for two reasons that belong on it. First, the vendor markets its agents as auditable and sells a governance layer to firms, so governance is the vocabulary of the product, applied to the customer's risk policy and not to Legl's own models. Second, the platform runs biometric identity verification and AI risk scoring on individuals whose onboarding depends on the result, and demographic differential performance is a well-documented property of that class of system. Nothing published addresses fairness, error rates across populations, testing, or what recourse an individual has when a check goes against them. The ISO/IEC 27001 certification governs information security and is not read as covering this. Surfaces read on 7 September 2026: the Risk Agents page, the KYC, KYB and AML page, the pricing page, the Terms of Use in full, the sub-processor policy in full, the trust centre entry point and the site footer.
No governance disclosure was located anywhere in a legal estate that is otherwise unusually complete. There is no AI policy, no responsible AI or ethics statement, no governance framework, no ISO 42001 or NIST AI RMF alignment, no named internal owner for AI decisions, no model evaluation or testing description, and no AI-specific provision in the Terms of Use, the data processing agreement or the security measures page. The gap is more consequential here than the grade alone conveys, and the reason should be on the record rather than left to inference: the security measures page states that Thirdfort gathers and processes personal data including biometric information from clients, and the product applies automated document and identity checks to individuals whose onboarding depends on the result. Demographic differential performance is a well-documented property of biometric and document-image systems, and nothing published addresses fairness, differential error rates, testing across populations, or what recourse an individual has if a check wrongly flags them. The ISO/IEC 27001:2022 certification governs information security and is not read as covering this. Surfaces read on 7 September 2026: both AI-bearing product pages, the security measures page, the Terms of Use, the data processing agreement, the third-party products and terms, the terms index and the pricing page.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Real stewardship is documented for the data supply chain and almost nothing is documented for the AI. On the credit side the sub-processor policy is a working governance artifact rather than a list: it describes a commercially reasonable selection process evaluating security, privacy and confidentiality practices, and requires sub-processors to satisfy obligations equivalent to Legl's own, including processing only on documented controller instructions, using personnel bound to confidentiality, providing regular security and data protection training, maintaining technical and organisational measures, promptly informing Legl of any actual or potential breach, and cooperating with controller, data subject and regulator requests. Biometric handling is specific and restrictive. Destruction follows the firm's request or the end of the processing need. What is missing is the part this axis is about. No published surface states how client documents, bank statements or trust deeds are handled once an agent has read them, whether anything is retained from an inspection, whether client content is segregated from model operations, or what happens to the material a remediation loop collects. No AI-specific commitment of any kind was located, and the one improvement right in the published Terms covers de-identified technical device and system telemetry rather than client content. The firm-facing Legl Services Agreement, which is where terms would sit, is named in the sub-processor policy but is not published. Checked 7 September 2026.
Stewardship is documented at contract level and is genuinely tight, though none of it is AI-specific. Processing is purpose-limited twice over: clause 12.3 of the Terms licenses client data only to the extent needed to provide the Services, and clause 2.4(a) of the data processing agreement limits processing to providing the Services on the firm's instructions. No training or model improvement right is reserved anywhere in the estate. The perpetual feedback licence in clause 12.4 is drafted with an express carve-out stating it will not cover any personal data, which is the kind of detail that usually goes missing. Deletion is concrete and time-bound at 30 days with the fields enumerated. Security measures are specific and independently framed, including annual penetration testing commissioned by the vendor rather than by customers, routine vulnerability scanning, security log monitoring, encryption at rest and in transit, and architectural separation between customers. Breach notification runs without undue delay under the processing agreement, and FCA licensing obliges Thirdfort to file quarterly reports on its operational and security risks, which is external supervision of the security posture rather than self-assertion. What holds this at B is that nothing addresses the AI specifically: no statement covers how document images and biometric material are handled by the model, how long the model's inputs and outputs persist, or whether anything is retained from an inspection once the report is produced. Checked 7 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Nothing establishing recourse to the buyer could be located, and the one published agreement excludes liability comprehensively. The Legl Services Agreement is named twice in the sub-processor policy as the instrument governing the client relationship and is published nowhere on the site, whose legal footer carries only the Terms of Use, website terms, privacy policy and a link to the trust centre. A firm therefore cannot establish before purchase what warranty, cap, indemnity, service level or remedy it would have. The instrument that is published runs the other way throughout. Use is on an as-is and as-available basis at the user's sole risk. Legl makes no representations or warranties as to the truth, accuracy, quality or completeness of information provided in connection with the services, and explicitly excludes all other conditions, guarantees and implied or statutory warranties. It accepts no liability for loss or damage of any kind arising from access to or use of the services, disclaims responsibility for the acts or omissions of any third-party service provider, and states that as a data processor it is not liable to the individual for any act or omission in relation to their personal data. The only indemnities run from the user to Legl. No cap figure, uptime commitment, service credit, cure period or termination-for-degradation right appears anywhere published. The grade records what is establishable on the date: the buyer's own agreement is unpublished and the available instrument allocates risk away from the vendor. Checked 7 September 2026.
Quantified recourse exists, which is uncommon, and the AI-relevant exposure is routed away from it, which matters. On the credit side the Terms of Use state figures rather than formulas: liability is capped at the higher of 25,000 pounds or the fees paid in the preceding twelve months, with breaches of data protection obligations carved out and capped separately at 2.5 million pounds in aggregate. Clause 6.1(b) warrants that Reports will be materially accurate and complete, mutual intellectual property indemnities run both ways, uptime is committed at 99.5 per cent monthly, material breach carries a 30-day cure, and clause 16.2(b) lets a firm terminate immediately if an update materially reduces the service and no substitute follows. Clause 18 gives an annual audit right with an undertaking to provide executive summaries of audit reports and copies of current third-party certifications. Against that sit three provisions a buyer should weigh together. Clause 9.3(g) excludes losses caused by Third Party Products, which is precisely where the supplier-provided elements of the checks sit. Clause 9.4 waives all the firm's potential claims arising from the Platform, Services or Reports in connection with the services the firm provides to its own client, which is the scenario a firm relying on a regulated due diligence check most needs covered. And uptime is measured from the moment the customer reports a fault in writing rather than from onset, so the commitment turns partly on the customer's own vigilance. Checked 7 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The integration surface is the deepest in this lane and it is specifically legal. Ten named systems appear on the product pages, and they are practice systems rather than general business tools: iManage and NetDocuments on document management; Clio Manage and Clio Operate, the latter named as Sharedo; Elite 3E on finance and practice management; Litera Foundation 365, named as Peppermint; Unity Practice Management, named as NebuLAW; Quill; Proclaim, named as DPS; and Partner for Windows. The parenthetical former names are worth noting as a mark of care, since a UK firm buying this will know several of these products by the older brand. That set spans the two major document management systems, a major international finance platform and four UK-specific practice systems, which is a materially different position from a vendor naming Zapier and a CRM. What holds this below the top band is that the depth of each connection is not described on any surface read: nothing states whether the integration writes back, what triggers a sync, whether an API is public, or what a firm must build. The integrations index page was not opened in this pass and is named as the artifact that would settle it, and the row is amendable on that evidence. Checked 7 September 2026.
An integration surface exists and is contractually governed, but no legal practice system was located first-party. Thirdfort publishes a separate API Agreement in its terms index, applying to clients, partners and potential partners who access the API to build a direct integration, and clause 21 of the Terms of Use incorporates it. Distribution through Partner Platforms is a first-class part of the model rather than an afterthought: clause 2.2(b) contemplates a firm using the Platform Services entirely through a partner's own platform, clause 19 governs the information exchanged, and a partners list is maintained at a published address. That is real integration depth in architecture. What could not be established is direction: no case management system, practice management system, document management system or legal accounting package is named in any surface read, so a buyer cannot tell from the vendor's own material which systems the product actually plugs into. The partners list itself was not opened in this pass and is named here as the artifact that would settle it; it is the row in this record most likely to move on a further pass, and it is amendable on newly located evidence. Checked 7 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Neither limb is stated, which is what the band requires. Infrastructure suppliers are named in the sub-processor policy, being Amazon Web Services EMEA, Heroku, Microsoft Ireland Operations and Snowflake for cloud and data services, and the corporate entities named are European. That identifies who hosts, not where the data sits: no data centre location, no region, no residency option and no residency commitment appears on any surface read, and naming an Irish or Luxembourg contracting entity is not a statement about storage location. Tenancy is equally absent: nothing states whether the service is single-tenant, pooled or configurable, and no separation model is described beyond the fact that screening configuration changes apply firm-wide. The nearest thing to a residency term sits in the consumer Terms of Use, which bar the individual from accessing the services in any jurisdiction other than the United Kingdom where doing so would require Legl or its providers to physically store data in that jurisdiction without prior written consent. That is a restriction on the user rather than a commitment by the vendor, though it implies a United Kingdom storage default. A separate Australian estate exists across the site, which implies a second region without describing one. No self-hosted or private deployment option was located. Checked 7 September 2026.
Tenancy is addressed and region is not, which clears the floor on the tenancy limb alone. The security measures page states that Thirdfort hosts its technical infrastructure and databases on Google Cloud Platform, that data sits in GCP-managed database services across three data centres at different physical sites, that storage on local machines is not permitted, and that the software architecture ensures separation of data and of information security between different customers and application components. That is a documented multi-customer separation model rather than a bare assertion. Residency is the weaker half. The three data centres are not located for the reader, no region menu or residency choice is offered, and the vendor states plainly that it uses service providers located outside the United Kingdom and European Union, relying on contractual transfer mechanisms rather than on keeping data in region. Those mechanisms are properly specified: the data processing agreement incorporates module 2 of the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, with Thirdfort as importer and the firm as exporter. The completed transfer schedules that would show the actual destinations are published as images and could not be read, which is recorded as a retrieval limit rather than an absence. No self-hosted or private deployment option exists, which is expected for a consumer-app-based verification service. Checked 7 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Multiple current certifications, one of them independently checkable, presented through a real trust centre whose contents could not be read. Legl publishes its ISO/IEC 27001 certificate number, 0174467, in the footer of every page, which is more than most records on this axis offer: a number a buyer can take to the certification body rather than a badge. It is listed on the UK government's Digital Verification Services register maintained by the Office for Digital Identities and Attributes, under its registered name The Justice Platform Ltd, and is a certified Identity Service Provider against the Digital Identity and Attributes Trust Framework. A government register entry is verifiable entirely independently of the vendor, which is the strongest form this evidence takes. A dedicated trust centre exists at a subdomain, hosted on Vanta's European instance and linked from the site footer as Security. Two things hold this at B. No certification body or auditor is named, no certificate validity window is given, no certificate document is published on the main site, and no SOC 2 report for Legl itself was located. And the trust centre returned only page metadata: its body renders client-side and no document list, access tier or request flow could be read. That is recorded as a retrieval limit and is not graded against the vendor, but it does mean the access flow could not be assessed, so no credit is taken for what the portal may offer. The certifications named for sub-processors and payment partners belong to those companies and are not credited here. Checked 7 September 2026.
Multiple current, independently granted certifications, published without a portal. Thirdfort states it holds ISO/IEC 27001:2022, the current revision of the standard rather than a superseded one, and separately holds certification as an Identity Service Provider under the Digital Identity and Attributes Trust Framework operated by the UK government's Department for Science, Innovation and Technology. It is certified under the UK Digital Verification Services trust framework and appears on the GOV.UK register of digital identity services, which is a public register a buyer can check independently of anything the vendor says. Regulatory supervision adds a further layer that is not a certification but functions like one: FCA licensing for account information services means, in the vendor's own account, that the regulator has reviewed its security policies and that Thirdfort must file quarterly reports on operational and security risks. Penetration testing is annual and vendor-commissioned, with remediation routed into engineering priority, alongside routine vulnerability scanning and security log monitoring. What holds this below the top band is artifact access. No certificate document, certificate number or validity period is published, no auditor or certification body is named, there is no SOC 2 report, and there is no trust centre or document portal. Certifications are obtainable, but through clause 18.2 on request during an audit rather than from the website, and clause 18.3 expressly excludes access to non-public external reports. Checked 7 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
A thorough supplier disclosure programme that has not been extended to the models. The sub-processor policy is genuinely good: sixteen suppliers named as at 3 June 2025, each with its processing activity stated, a described due diligence and contractual safeguard process, notice of changes by email or in the customer's own environment, a ten day objection window, and a dated update log explaining why Mitek Systems and Dun and Bradstreet were added in July 2024. Against that, no model or model provider appears anywhere in it. The list contains cloud and data infrastructure, being Amazon Web Services, Heroku, Microsoft Ireland, Snowflake and Fivetran; identity and data suppliers, being ComplyAdvantage, Equifax, Entrust Identity, Mitek, Creditsafe, Dun and Bradstreet and TrueLayer; and tooling, being Datadog, Sentry, HelloSign and an email provider. Not one entry is a foundation model provider, and no surface names a model, a version, a family, or states that the models are built in house. For a platform whose own navigation calls its AI layer Risk Agents and which describes those agents reading bank statements and analysing trust deeds, that is a real gap: a firm cannot tell whose model processes its client's financial documents. Naming the cloud providers says where the software runs and has been credited on deployment, not here. Checked 7 September 2026.
The supply chain is partly disclosed, and the part that is disclosed is done properly. Six suppliers are named in a published, versioned instrument with their full flow-down terms reproduced: Onfido, Experian, IVXS UK trading as ComplyAdvantage, iProov, Dun and Bradstreet, and Kyckr Ireland. A separate third-party service provider page, dated 24 October 2025, distinguishes data providers from technical service providers, explains the two categories of data shared, and offers a subscription to sub-processor notices. Change is governed contractually: clause 16.2 of the Terms gives 30 days' notice of any material change to the data provider list with a right to terminate, and clause 3.3 of the processing agreement requires written notice of new sub-processors within 30 days with a right to object. Experian's own flow-down terms disclose that its services involve models and techniques based on statistical analysis, probability and predictive behaviour, which is supplier-level model disclosure a buyer can read. What is missing is the mapping and the models. No model is named anywhere, no version or family is given, and the vendor never states which of the six suppliers, if any, provides the artificial intelligence behind document verification. Naming Google Cloud Platform tells a reader where the service runs, not whose model inspects a passport, and it is credited on deployment rather than counted twice here. Two artifacts that would close the gap could not be read and are recorded as retrieval limits: the feature-to-provider breakdown on the flow-down page is published as an image, and the provider tables on the service provider page render client-side and returned no content. Checked 7 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The charging model is published and no price is. What a buyer can establish first-party: pricing is modular, with the firm choosing the modules it needs and paying only for what it uses; billing is monthly and described as predictable; there are no implementation fees; and there is no long-term lock-in, a point a named customer reinforces by contrasting it with competitors requiring fixed contracts of up to thirty-six months and usage forecasts. ROI reporting and cost-savings insights are offered as part of the product. That is a described model rather than an invitation to call, and it lifts the axis off the floor. What is absent is every figure: no price per module, per check, per seat or per firm, no volume band, no minimum, no term length and no currency. The page carries no plan table of any kind, and the only route to a number is booking a demo. One tension is recorded because it is the vendor's own framing against its own page: the page is titled transparent, value-based pricing and its meta description promises a transparent, surprise-free pricing structure, on a page that publishes no cost. Transparency about how a buyer will be charged is real here; transparency about what they will pay is not. Checked 7 September 2026.
Commercial mechanics are published in the contract while prices are not published anywhere. The pricing page exists and is structured by buyer type, inviting a reader to select an industry to see available plans, with a custom quote offered for industries not listed. The plan detail sits behind that selector and rendered no content, which is recorded as unrendered rather than absent because the page's own wording states that plans are there to be seen. What is established first-party comes from the Terms of Use, and it is more than a sales invitation: fees are agreed separately and are exclusive of VAT, any increase carries 30 days' notice with an opportunity to stop using the service, disputed invoices must be raised within 30 days, overdue amounts carry interest at 4 per cent above the Barclays base rate, suspension follows 7 days' notice, minimum purchase commitments exist and survive early termination, and a discounted trial period may be offered at the vendor's discretion. Those are real commercial terms a buyer can rely on. What is absent is any figure, band or unit of charge: the product is bought as checks and plans, and no price per check, per seat or per plan appears on any surface read. The grade sits above the floor because published pricing information exists at the level of charging mechanics, and below the middle band because no rate is discoverable without a sales conversation. Checked 7 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Deep in one workflow, broad across firm types, narrow across jurisdictions. The buyer surface is unambiguously legal: every solution page addresses law firms directly, the named customers are all law firms, and the roles quoted are legal compliance roles rather than generic operations. Firm coverage spans the range a UK vendor would want to show, from national and international names such as Lewis Silkin and Michelmores through strong regional practices including Stephens Scown, Cripps, Tollers and Wilkes, an alternative-structure firm in gunnercooke, a Scottish firm in Burnett and Reid, and specialist family practices including Hall Brown. The trust centre description claims forty of the top two hundred. What holds this at B is that coverage means firm types rather than practice areas: the product addresses one workflow, client onboarding and anti-money-laundering diligence with payments attached, and applies it identically whatever the matter is. No practice-area breakdown, matter-type coverage statement or area-specific configuration is published beyond risk assessment templates a firm builds to its own policy. The regulatory frame is also single-jurisdiction, resting on the SRA, the Money Laundering Regulations, HM Land Registry expectations, the DVS register and the Digital Identity and Attributes Trust Framework, with a separate Australian estate as the only other market. Checked 7 September 2026.
Coverage is deep in one practice area and deliberately narrow beyond it. Legal is one of four named sectors with a page of its own, alongside conveyancing, estate agents and accountants, and the insights library carries a dedicated Lawyers industry category with material aimed squarely at solicitors, including guidance on file notes that survive an SRA review and on enhanced due diligence after the 2026 Money Laundering Regulations reforms. Practice depth is strongest in property: the enhanced NFC identity check is built to HM Land Registry's Safe Harbour standard under Practice Guide 81, and the platform supports Authorised Corporate Services Providers meeting the Companies House identity verification standard for directors and persons of significant control. Geographic reach in the checks themselves is broad, covering documents from 195 jurisdictions and electronic address verification across 17. What holds this at B is that the practice surface is a single workflow rather than a range: client onboarding and anti-money-laundering diligence, with no other legal practice area addressed and no matter-type coverage statement. The regulatory frame is also single-jurisdiction, resting on FCA authorisation, HM Land Registry, Companies House, the SRA and English governing law, so a firm outside the United Kingdom sees a product built around a compliance regime that is not its own. The legal sector page redirected to an insights article when fetched and was not read directly; the sector's existence and its content are established from the site navigation and the insights category. Checked 7 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The governing agreement is not published, so the question cannot be answered from the vendor's surfaces. The Legl Services Agreement exists and is named twice in the published sub-processor policy, which states that Legl engages sub-processors as described in that agreement and that undefined terms take their meaning from it. It appears nowhere on the site: the legal footer carries only the Terms of Use, website terms, privacy policy and a link to the trust center.
The Terms of Use govern the individual submitting a payment or completing a workflow rather than the law firm, so they are not the customer agreement for this purpose. Their one improvement right was tested and does not reach this signal: it permits Legl to collect technical data about the user's device, system and application software and to use it, in a form that does not personally identify the user, to improve products or provide services.
That operates on device telemetry rather than client content and does not name machine learning, training or model improvement, so it is not read as a training permission. No statement anywhere on the product pages, the Risk Agents page or the sub-processor policy says whether client documents, bank statements or screening data train or refine the agents. This is recorded as an agreement a buyer cannot obtain rather than as vendor silence.
The terms are silent on training while being unusually tight on use. No training, model improvement or machine learning right is reserved anywhere in the estate, and two provisions cut the other way: clause 12.3 of the Terms of Use licenses client data only to the extent Thirdfort needs it to provide the Services, and clause 2.4(a) of the data processing agreement limits processing to providing the Services on the firm's instructions.
The perpetual feedback license in clause 12.4, which is the clause most likely to carry a improvement right, is drafted with an express carve-out stating it will not cover any personal data. What is absent is a statement either way. Nothing prohibits training and nothing permits it, so a buyer has a purpose limitation to rely on rather than an answer to the question this signal asks. That is the shape the value set does not yet resolve well: silent is the only true value available, but the summary should be read alongside it, because the position here is materially different from a vendor whose agreement addresses data use loosely and says nothing.
The privacy policy was not opened in this pass and is named as the surface that could carry a training statement; the row is amendable on that evidence.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Nothing addresses the retention of what the agents read or produce. A general destruction obligation exists in the published Terms of Use: on the law firm's request, or when Legl or its engaged providers no longer need to process the personal data, whichever is earlier, Legl will cease all use and destroy it, subject to any legal retention requirement. That governs the individual's personal data at the level of the workflow and carries no period, no outer limit and no trigger a buyer can plan against.
It says nothing about the AI layer specifically: no surface states whether a bank statement or trust deed persists after an agent has read it, whether the structured output of an analysis is retained separately from the report, or how long screening research and monitoring alert triage are kept. The biometric identifier is the one item with a described lifecycle, held by the third-party provider until Legl states it is no longer needed, which is a condition rather than a period.
The firm-facing Legl Services Agreement, where a retention schedule would ordinarily sit, is not published. Surfaces read on 7 September 2026: the Terms of Use in full, the sub-processor policy in full, the Risk Agents page, the KYC, KYB and AML page and the pricing page.
Retention is addressed and deletion is time-bound, but no standing retention period is published. What is stated: on a written deletion request from the firm, all initiation and report data is removed from the platform within 30 days, and the security measures page enumerates what that covers, including the client's name, mobile number, date of birth and home address, with the report permanently deleted and unavailable to download or recover.
On termination, clause 16.5(a) gives the firm 30 days to download its data before deletion, and clause 2.4(h) of the processing agreement requires deletion or return on written request unless retention is legally required. What is not stated is how long a report and the document images behind it are held absent any request. The default appears to be indefinite retention until the firm acts, and nothing published sets an outer limit.
Nothing at all addresses the AI layer specifically: whether the uploaded document image persists after inspection, and whether anything the model produces during a check is retained beyond the report itself. The processing schedule that would ordinarily carry retention periods is published as an image and could not be read, which is recorded as a retrieval limit rather than an absence.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Role-based control is claimed and the separation model behind it is not documented. What is published concerns who sees what by function: administrators control screening configuration and changes apply firm-wide, monitoring alerts can be assigned to a named reviewer, high-risk escalations route by email to the MLRO or other nominated reviewers, and the compliance dashboard is presented as a firm-wide view for the compliance function.
Those are real access and routing controls and they show that the platform distinguishes roles inside a firm. What is absent is the segregation model. Nothing describes how one firm's data is separated from another's, nothing addresses partitioning between teams or departments inside a single firm, nothing states whether a conflicted fee earner can be excluded from a client's file, and nothing says whether the risk agents are scoped to the requesting user's permissions when they research a match or read a document.
There is no document management system integration inheriting an existing access control list for this purpose either, although Legl integrates with iManage and NetDocuments for other functions. The absence matters more than usual on a product that holds counterparty identity material in transactional work.
A separation model is documented, at customer level rather than matter level. The security measures page states that Thirdfort employs a variety of measures to segregate data across its estate and that its software architecture ensures the separation of data and the security of information between different customers and application components, supported by GCP-managed database services across three data centers and a prohibition on storage on local machines.
Access control is specified on both sides: two-factor authentication for platform users, and least privilege plus multi-factor authentication for staff with access removed on the last day of employment. That is a documented model rather than a claim. What it does not reach is the wall a firm may need inside its own account. Nothing describes whether users within one firm can be partitioned from one another, whether a conflicted team can be excluded from a client's checks, or whether the AI's access to uploaded documents is scoped to the requesting user's permissions.
For a product that holds counterparty identity material in transactions where two sides may instruct the same firm, that is a real gap, and it is the reason this sits at the neutral value rather than higher.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Disclosure is addressed twice in the published Terms of Use and notice is absent from both, expressly so in one. On compelled disclosure, the terms state that Legl will not pass personal data to third parties except in accordance with its privacy policy or where required by law to disclose that information. Disclosure is acknowledged as a live possibility and no undertaking to tell the firm or the individual accompanies it.
The second instance is stronger and goes the wrong way: where Legl suspects fraudulent, criminal or improper activity via the payment system, it may report or disclose information about the user and their use of the system to relevant law enforcement, at its sole discretion and without notice to them. That is an express reservation of disclosure without notice rather than an omission. The proactive fraud-reporting context is not the same as a compelled government demand, and the distinction is recorded rather than collapsed, but the pattern across both provisions is the same: the vendor addresses disclosure and commits to no notification anywhere.
No challenge undertaking, no minimization term, no record-keeping obligation and no transparency report were located. The firm-facing agreement, which might treat this differently for the customer, is not published.
This is among the strongest compelled-disclosure provisions located in the corpus, and it is contractual on both instruments. Clause 4.3 of the data processing agreement commits Thirdfort, where legally possible, to challenge a public authority's request for access to personal data and promptly notify the firm, not to disclose any personal data without the firm's consent, to notify the firm and provide it with information about such requests, and, where disclosure is compelled, to disclose only the minimum amount required and keep a record of the disclosure.
Four distinct undertakings sit in that clause: resist, notify, minimize and record. Clause 11.5(a) of the Terms of Use adds a mutual obligation on either party to notify the other as soon as possible where it is legally required to disclose confidential information. The qualifier where legally possible is honest rather than evasive, since a gagging order can bar notice as a matter of law and a clause promising otherwise would be unreliable.
It stops short of the top value only because Thirdfort publishes no transparency report: the record of disclosures is kept under the clause but nothing is published about how many requests have been received or how they were handled.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The sources are named thoroughly and their license terms are not published. Naming is the strong half: the sub-processor policy identifies sixteen suppliers as at 3 June 2025 with the processing activity of each, so a buyer can see that ComplyAdvantage supplies screening, Equifax, Entrust Identity and Mitek Systems supply identity verification, Creditsafe and Dun and Bradstreet supply business data, and TrueLayer supplies account information services, with payment partners Adyen, Stripe and Banked identified separately with their regulatory status.
The Terms of Use add that information uploaded is disclosed to Equifax as a credit reference agency and link the industry-standard CRAIN notice explaining how credit reference agencies process the data, which is a genuine provenance disclosure to the data subject. What is not published is the licensing. No flow-down terms, permitted-use conditions, territorial restrictions or intellectual property provisions for any supplier appear anywhere, and the sub-processor policy states expressly that it grants clients no additional rights or remedies and should not be construed as a binding agreement.
A buyer can therefore establish where the data comes from but not on what terms it may be used. Separately, nothing states what the risk agents themselves were trained on, which is recorded on the model supply chain row.
The reference corpus is both named and licensed, in public, which is rare. Every substantive data source behind the checks is identified with its supplier and the license terms are reproduced in full in a published, versioned instrument: Experian for address verification, CCJ and insolvency data and CrossCore fraud assessment; ComplyAdvantage for screening databases; Dun and Bradstreet for business information; Kyckr for company registry extraction across global registries; Onfido and iProov for identity elements.
The Metropolitan Police's Amberhill database of lost and stolen documents is named as the cross-reference for every identity document, and Royal Mail NCOA Alert Data is identified with its own end user agreement. The published terms set out permitted purposes, territorial restrictions, intellectual property ownership and use limits for each source, so a buyer can see not only where the data comes from but on what conditions it may be used and what it may not be used for, including express prohibitions on credit and employment eligibility decisions.
One provenance question is not answered: nothing states what the document verification model itself was trained on. That is a distinct question from the reference corpus and it is recorded on the model supply chain row rather than here.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
The product ships no citator and makes no good-law claim, which is the expected position for a client onboarding, due diligence and payments platform rather than a disclosure gap. Nothing Legl produces cites legal authority: the outputs are due diligence reports, screening results, company structure reports, source of funds analyses and risk assessments. The currency question that does arise here is currency of reference data rather than currency of law, and it is answered elsewhere, with clients re-screened daily against sanctions and PEP lists and business clients monitored for ownership, structure, financial and legal proceedings changes.
Recorded at the floor because the value set requires a value, with the reason stated so a reader does not take it as a finding against the vendor. Nothing in this record depends on it.
The product ships no citator and makes no good-law claim, which is the expected position for a client due diligence and identity verification platform rather than a disclosure gap. Nothing Thirdfort produces cites legal authority: the outputs are verification reports on individuals and companies, presenting flags across data validation, compromised documents, age validation, data consistency and data comparison. The closest analog in this product is currency of reference data rather than currency of law, and that is addressed on the corpus provenance row through the named suppliers and their update terms.
Recorded at the floor because the value set requires a value, with the reason stated here so that a reader does not take the value as a finding against the vendor. Nothing else in this record depends on it. Surfaces read on 7 September 2026 include both AI-bearing product pages, the Terms of Use, the data processing agreement and the third-party products and terms.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
A confidence signal is published and a fuller account of behavior under uncertainty is not. The concrete mechanism is stated plainly: AI-assisted screening matches are returned with a recommendation, a confidence level and the supporting evidence, and the vendor describes the agents as weighing the evidence and providing signals as to whether a flagged record really is the firm's client, with the decision remaining with the reviewer.
The agents are also described as identifying high likelihood matches among monitoring alerts, which is the same graded-confidence shape, and as flagging discrepancies and non-conformity with the firm's risk policies for human attention. That is more than most records carry and it is why this sits above the floor. What is not published is the behavior around the score. No threshold is stated at which the system declines to recommend, abstains or escalates on uncertainty as opposed to on risk level, nothing describes what an agent does with a document it cannot parse or a statement it cannot reconcile, and no refusal or abstention policy appears anywhere.
The one adjacent control, the mathematical validation step confirming source of funds figures are consistent before they reach the reviewer, is an output check rather than an account of what happens when the check fails.
Nothing published describes how the system behaves when it is unsure. The nearest surface is the report itself, which presents results in three states so a reader can instantly see what has passed, what is not relevant and what requires consideration. That third state routes a result to human judgment and is a genuine design feature, but it is a presentation convention for the report rather than a documented account of model behavior: nothing states when the system emits it, what confidence or score sits behind it, or whether it reflects uncertainty as opposed to a positive detection.
It is named here rather than credited, because crediting it would read a disclosed uncertainty behavior into a report layout the vendor has not described in those terms. No confidence score is described as visible to the reviewer, no abstention or escalation threshold is published, and nothing addresses what the model does with a document it cannot parse beyond the pre-submission guardrails that block blurry, cropped or oversized uploads before inspection begins.
Surfaces read on 7 September 2026: the document verification and identity verification pages, the security measures page, the Terms of Use and the data processing agreement.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No matter naming Legl or The Justice Platform Ltd was located in the hallucination case tracking maintained by Damien Charlotin or in the sanctions reporting drawn from it, searched on 7 September 2026 on both the trading name and the registered company name. The reporting reviewed names the tools involved where they are known and spans a corpus now exceeding 650 documented instances across multiple jurisdictions, including the English decisions in Ayinde and Al-Haroun.
Legl appears in none of it. This is consistent with the product class: the platform produces due diligence reports, screening results and risk assessments and generates no citations to legal authority, so the exposure this signal tracks is structurally absent rather than merely unrealised. Recorded as none located rather than as a positive finding about vendor conduct.
No matter naming Thirdfort or Thirdfort Limited was located in the hallucination case tracking maintained by Damien Charlotin or in the sanctions reporting drawn from it, searched on 7 September 2026 on both the product name and the company name. The reporting reviewed names the tools involved where they are known, including instances tied to purpose-built legal AI products, and Thirdfort appears in none of it. This is consistent with the product class: the platform produces identity and due diligence reports and generates no legal citations, so the exposure this signal tracks is structurally absent rather than merely unrealised. Recorded as none located rather than as a positive finding about vendor conduct or product quality.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Regulatory alignment is substantial and none of it is guidance on artificial intelligence. What Legl documents is identity and anti-money-laundering standards: listing on the UK government's Digital Verification Services register maintained by the Office for Digital Identities and Attributes, certification as an Identity Service Provider against the Digital Identity and Attributes Trust Framework, and a product built around the firm's obligations under the Money Laundering Regulations, with MLRO dashboards, escalation paths and a defensible record of how each client was assessed and why.
Its payment partners are identified with their Financial Conduct Authority regulatory status. That is real alignment and it is named here so it is not mistaken for silence. It is not what this signal asks. No bar, law society or regulator guidance on the use of artificial intelligence is named, mapped or referenced anywhere, and nothing addresses what a firm's own obligations are when an autonomous agent gathers evidence, scores a client's risk or corresponds with that client on the firm's behalf.
For a product that runs remediation loops directly with the firm's client under the firm's brand, that is the guidance a solicitor would want mapped.
Regulatory alignment is extensive and none of it is AI guidance, which is the distinction this signal turns on. What Thirdfort does align to, and documents carefully, is identity and anti-money-laundering standards: HM Land Registry's Digital ID Standard, with the enhanced NFC check built to the Safe Harbor standard in Practice Guide 81; the Companies House identity verification standard for directors and persons of significant control; the UK Digital Verification Services trust framework, under which it appears on the GOV.
UK register; and certification as an Identity Service Provider under the DSIT Digital Identity and Attributes Trust Framework. Its insights material addresses solicitors directly on SRA file note expectations and on enhanced due diligence under the 2026 Money Laundering Regulations reforms. That is real and useful, but it is alignment with identity and AML standards rather than with guidance on the use of artificial intelligence in legal practice.
No bar, law society or regulator guidance on AI is named, mapped or referenced anywhere, and nothing addresses what a firm's own AI-use obligations are when it relies on an automated forgery check. The value records the absence of AI guidance alignment; the substantial regulatory alignment is recorded here so it is not mistaken for silence.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Time savings are published and the fee consequence is not addressed. The claims are customer-attributed and specific: half of due diligence requests completed within 24 hours of being sent at gunnercooke, and three risk assessments in about twenty minutes against roughly an hour for a single assessment previously at Sharmans. The vendor also offers ROI reporting and cost-savings insights as part of the product, which is a savings claim in its own right.
Nothing addresses what happens to a client bill when compliance work that took an hour takes twenty minutes, no per matter record of AI-assisted work is described, and no guidance on fee or disclosure treatment is offered. Two qualifications belong on the record. The savings described are the firm's internal compliance overhead rather than billable client work, and compliance time is often absorbed rather than billed, so the compression this signal was written for operates differently here.
And the vendor sells a payments product handling client money and reconciliation, which puts it closer to the firm's billing than most, yet nothing connects the two: no surface addresses how the cost of checks or the saving from automation is reflected on a client account.
Speed and efficiency claims are published; the fee consequence of them is not addressed. The published claims are customer-attributed rather than vendor-asserted, with Direction Law stating it targeted a 50 percent increase in the speed of its compliance process and believes it exceeded that, Thomas Legal describing timely completion as a competitive differentiator, and the vendor publishing that 75 percent of individuals complete checks within 24 hours and that reports return in minutes.
Nothing addresses what happens to a client bill when a check that took a fee earner an afternoon takes minutes, no per matter record of AI-assisted work is described, and no guidance on fee or disclosure treatment is offered. Two qualifications belong on the record. The claims describe the check workflow and the client app rather than the artificial intelligence specifically, so even the claims that exist are not AI-assisted-work claims in the sense this signal asks about.
And the cost of a check is a disbursement a firm commonly passes through to the client rather than billable time it absorbs, so the compression this signal was written for operates differently on a per-check product than on one that displaces professional hours.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The supplier list is exemplary and the model provider limb is empty, which is what holds this below the top value. The list itself meets every reasonable test: sixteen sub-processors named as at 3 June 2025, each with its processing activity stated, published openly rather than on request, with a described due diligence process, contractual safeguards flowing equivalent obligations down to each supplier, change notification by email or within the customer's own Legl environment, a ten calendar day objection window with a right to state reasons, and a dated update log recording the July 2024 additions of Mitek Systems and Dun and Bradstreet with the reason for each.
Forwardable client-facing material exists too: the Terms of Use are written for the individual being verified, name the workflow providers, explain the biometric handling and link the industry CRAIN notice, so a firm has something drafted to be passed to its client. What is missing is a statement of which model providers see client content. No foundation model provider appears anywhere in the sixteen, no model is named, and nothing states that the agents run on Legl's own infrastructure.
Naming Amazon Web Services, Microsoft Ireland and Snowflake says where software runs rather than whose model reads a client's bank statement, and infrastructure alone does not satisfy this signal. A firm asked that question by a client could not answer it from what is published.
All three limbs are met, which is uncommon. The supplier list is current and public: a dedicated third-party service provider page dated 24 October 2025, distinguishing data providers from technical service providers and offering a subscription to sub-processor notices, backed by a published instrument reproducing the full flow-down terms of six named suppliers, being Onfido, Experian, ComplyAdvantage, iProov, Dun and Bradstreet and Kyckr, with Google Cloud Platform named separately as the hosting provider.
Change is governed contractually rather than by courtesy: clause 16.2 of the Terms gives 30 days' notice of any material change to the provider list with a right to terminate, and clause 3.3 of the processing agreement requires written notice of new sub-processors with a right to object under clause 3.4. Forwardable client-facing material exists in two forms: a published data processing agreement incorporating the EU Standard Contractual Clauses and the UK transfer addendum, and Appendix 1 of the Terms, which is consumer wording the firm is contractually required to send to its client before lite screening and identity document verification and which names Experian as the data provider by name and link.
A firm can therefore answer a client's diligence questions from public documents without a bespoke negotiation. One gap should be stated plainly: the vendor never identifies which supplier, if any, provides the artificial intelligence in document verification, so a firm asked specifically whose model examines its client's passport cannot answer precisely from what is published.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
An exportable, audit-facing record exists and it does not disclose the AI's part in producing it. The record is real and is central to what the product sells: a defensible record of how each client was assessed and why, a compliance dashboard covering CDD, AML and audit history for every individual and business client, downloadable reports for internal review or audit preparation, CSV export of flagged contacts for regulatory or internal reporting, decisions and overrides recorded with their reasoning, and an audit trail the vendor describes as building itself as each step is recorded.
The intended reader is an SRA inspector or an MLRO preparing for one, which is close to but not the same as a court. What is not established is the AI disclosure limb. The vendor's own phrase for the layer is auditable AI risk agents, but no surface describes what an agent's entry in the audit trail contains, whether the record distinguishes a conclusion an agent reached from one a reviewer reached, or whether a firm could show which parts of an assessment were automated.
Recording overrides with reasoning implies some of this and does not state it. Crediting a full exportable record here would read an AI disclosure capability into an audit trail built for a different question.
An exportable record exists and is expressly shareable, but it records the check rather than the AI's part in it. Every check produces a downloadable PDF report which is the artifact the firm retains as its compliance evidence, and the uploaded document is stored alongside it so that it is easy to reference or audit later. Sharing is contemplated rather than merely tolerated: clause 7.1 permits the firm to share reports with regulators, insurers and where legally required, which is precisely the disclosure route this signal contemplates, and clause 12.2 licenses the firm to use its reports for internal business purposes for as long as it requires, so the record survives termination of the subscription.
What the report does not do is disclose the AI. Nothing indicates that a report identifies which findings were produced by automated inspection, no log of model involvement is described, and nothing published addresses what a firm should say to a court or regulator about the automated element of a check it relied on. The record is real and usable but partial for this purpose, which is what the value states.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- AI Governance and Bias Disclosure
- Good Law Verification
- Bar Guidance Alignment
Which one fits
Choose Legl if
- You want AI working across onboarding under your own risk policy. Legl's risk agents screen, triage monitoring alerts, read bank statements and trust deeds, and chase clients for missing documents, while its governance layer turns the firm's risk policy into rules the agents enforce, escalating high risk cases to the money laundering reporting officer.
- You want the checks connected to your practice systems. Legl names integrations with iManage, NetDocuments, Clio, Elite 3E, Litera Foundation 365, Quill, Proclaim and Partner for Windows, a set that spans document management, finance and UK practice systems.
- You want client payments in the same workflow as due diligence. Legl covers onboarding, source of funds, risk assessments, ongoing monitoring and client payments with reconciliation, prices by module billed monthly with no implementation fee, and names firms including Lewis Silkin and Michelmores among its users.
Choose Thirdfort if
- You want to read the contract before you sign. Thirdfort publishes its terms, data processing agreement, supplier terms and security measures, warrants that reports are materially accurate, and caps liability at the higher of 25,000 pounds or a year's fees, with data protection breaches capped separately at 2.5 million pounds.
- You need identity checks built to property and company standards. Thirdfort's identity check reads the signing keys in an electronic passport chip, is built to HM Land Registry's Digital ID Standard and the Companies House verification standard, and checks every document against the Metropolitan Police's lost and stolen database.
- You want to know whose data sits behind each check. Thirdfort names Onfido, Experian, ComplyAdvantage, iProov, Dun & Bradstreet and Kyckr with their full terms, gives 30 days' notice of changes to that list with a right to terminate, and hosts on Google Cloud with documented separation between customers.
In summary
Legl
Legl, operated by The Justice Platform Ltd of London, is a client onboarding, anti money laundering and payments platform for law firms in the United Kingdom and Australia, covering due diligence on individuals and businesses, source of funds, risk assessments, ongoing monitoring and client payments. Its risk agents gather and read documents, research screening matches, analyze bank statements and trust deeds, and chase clients for missing information, under rules a firm sets. The AI Legal Index grades it in the top two bands on seven of fifteen capability axes, with an A on autonomy and oversight. It publishes ISO/IEC 27001 certificate number 0174467 and a dated list of sixteen subprocessors. As of 7 September 2026 the index located no published firm agreement, model provider or price.
Thirdfort
Thirdfort, from Thirdfort Limited of London, is a client due diligence platform used by law firms, conveyancers, estate agents and accountants to verify identity and source of funds, with five checks: identity, document verification, politically exposed persons and sanctions screening, source of funds and business checks. Its AI inspects uploaded documents for tampering and forgery, and every identity document is checked against the Metropolitan Police's database of lost and stolen documents. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes. It publishes its terms, data processing agreement and supplier terms in full, is authorized by the Financial Conduct Authority, and serves more than 1,500 regulated businesses. As of 7 September 2026 the index located no published price and no named AI model.
Questions buyers ask
Legl vs Thirdfort: which is better for a UK law firm's AML checks?
On published evidence Thirdfort sits in the top two bands on ten of fifteen AI Legal Index capability axes and Legl on seven of fifteen, identical on seven, mostly because Thirdfort publishes its customer agreement, data processing agreement and supplier terms. Legl applies AI across more of the onboarding workflow, with rules the firm sets and escalation, and connects to more practice systems. Firms that want the contract first have more to read from Thirdfort.
Does Thirdfort use AI in its checks?
In one of its five products. Thirdfort states that its AI inspects every uploaded document for tampering, forgery and counterfeiting across visual, data and metadata elements, covering documents from 195 jurisdictions. Its identity check relies on reading the signing keys in an electronic passport chip and on address matching, not on AI. It does not name the model or say which supplier provides it. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
How do Legl's risk agents reach a decision?
They do not make the final one. Legl returns each screening match with a recommendation, a confidence level and the supporting evidence, confirms source of funds figures with a mathematical check before a reviewer sees them, and escalates high risk factors automatically to the money laundering reporting officer or a named reviewer. Decisions and overrides are recorded with their reasoning, and the vendor states the decision stays with the reviewer. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Do Legl and Thirdfort train AI on client data?
Neither publishes an answer. Legl's firm agreement is not published, and its public terms, written for the individual being checked, do not address training. Thirdfort's terms do not mention training, but they license client data to it only as needed to provide the service, limit processing to the firm's instructions, and exclude personal data from its feedback license. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What do Legl and Thirdfort both leave unpublished?
Any AI governance position and any price. Neither names a model or model provider, describes testing before release, or addresses whether its automated checks perform evenly across the people they verify, although both handle identity documents and biometric data. Neither publishes a figure for any check or module, and neither names regulator guidance on the use of AI. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Three readings to weigh. Legl's firm agreement, the Legl Services Agreement, is referred to in its published subprocessor policy but not published, so its low grades on liability and data handling record what could be read, not a finding that no protection exists. Thirdfort's terms exclude losses caused by third party products, where supplier data sits, and waive a firm's claims connected to the services it provides its own client; those are published terms. Legl states more than 600 firms on its site and more than 400 in its trust center. Both records were verified on 7 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.