Merlin Search Technologies vs OpenText eDiscovery: how they compare in 2026
Merlin Search Technologies and OpenText eDiscovery both run discovery from processing through review and production with generative AI inside the platform: Merlin's Alchemy answers plain language questions across millions of documents with sourced reports, and OpenText's Aviator summarizes, reviews for responsiveness and runs agents. OpenText sits in the top two bands on thirteen of fifteen axes and Merlin on ten of fifteen, with identical grades on nine. The gap is paperwork and naming. OpenText publishes its cloud terms in full, with a section on AI that keeps decisions with people and prohibits uses the EU AI Act treats as unacceptable, and it names its model provider, Anthropic through Amazon Bedrock, with session data deleted when each session closes. Merlin publishes no customer agreement and names no model. Merlin's counterweight is isolation and price. Each client gets its own AWS account and each matter its own servers, URL and login, in any AWS region within 48 hours, in the client's own AWS account or in a FedRAMP environment, and it charges by the hour at about 70 percent less while a site is switched off. OpenText publishes no price or unit.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of a core capability layered on a product that would still function without them. Alchemy's answering and analysis engines and ReviewPartner's AI reviewers sit on a full ediscovery platform with keyword and algorithmic search, review, tagging, production and multi-party workspaces that the company has sold since 2019 under the Sherlock and DiscoveryPartner names; the vendor's own framing is three engines to find and two to analyse and answer. Remove the answering models and a search-and-review platform remains. Home page, security page and launch coverage read 6 September 2026.
The models are the engine of core capabilities layered on a product that would function without them, which is the B band, and this record makes the distinction unusually easy to see because the vendor draws it itself. Its own FAQ states that OpenText eDiscovery Aviator is a suite of LLM-powered features built into OpenText eDiscovery, and lists them: key document summary, summarisation, concept label summaries, Review, Rapid Exploration and Agents. Aviator is also a company-wide brand applied across unrelated products, so it denotes an AI layer rather than a product. What that layer does here is substantial. Aviator Review reduces or eliminates first-pass responsiveness review using large language models, with sampling and token estimates before a full run, and Aviator Agents take a goal described in natural language and plan and execute the multi-step search, review and summarisation behind it. Underneath it, the platform is a complete discovery system that predates the models by many years: collection through more than 45 connectors, processing with deduplication and de-NISTing, predictive search, an integrated viewer with redaction, visualisation, audio and video review, and technology-assisted review with continuous active learning that the company states it has led on for more than fifteen years. Remove the generative layer and a buyer still has an end-to-end eDiscovery platform with a mature machine-learning review engine, which is what settles this at B rather than A. Verified 13 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real and documented with sourced outputs, short of a testable accuracy figure on the surfaces read. The home page states that questions return comprehensive, sourced answers and reports across the document set rather than search hits, the launch coverage describes a dual-window architecture separating analysis prompts from formatting prompts to keep formatting from interfering with document analysis, and the AI services page states that every service undergoes rigorous validation for accuracy, completeness and consistency at scale. No accuracy figure, test set or evaluation is published in the material read; the founder's published book on generative AI for discovery was not opened. The primary-authority limbs do not apply to a tool that reads the customer's own documents. Home page, AI services page and launch coverage read 6 September 2026.
Grounding is real and documented and a measured figure is published without the test set behind it, which lands in the B band. The grounding mechanism is specific and checkable by design: key document summaries are generated complete with document ID citations expressly so that users can confirm veracity, and the material the AI reads is the customer's own collected evidence rather than an external corpus, so a reviewer can always go to the underlying document. A measured figure is published and it is the right one for this product class: 90 per cent or better recall with optimised workflows, recall being the metric that matters in responsiveness review because it measures what the process failed to find. Alongside it sit 88 per cent faster review and 75 per cent cost savings against manual review, which measure effort rather than correctness. The A band asks for the test set described and the failure modes named, and neither is published. Nothing states the matter, corpus, volume or protocol behind the recall figure, and the qualifier optimised workflows does real work in the vendor's favour since it conditions the number on expert prompt engineering and proven workflows without saying what either consists of. One limitation is volunteered and is credited here because it is the closest thing to a named failure mode on the record: the FAQ states that while the model has multilingual capabilities, primary testing and validation have been on English-language documents and prompts. On a platform sold for cross-border investigations that is a material and honest disclosure. Verified 13 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Review surfaces and constraints are published, short of the full control structure. Granular role-based access control exposes every function as an assignable permission, audit logs track each person's views, tags and searches, multi-party sites give user groups private tag sets and shared searches, and the platform delivers sourced reports a lawyer works from; ReviewPartner's AI reviewers are described as applying consistent judgment across files with validation. What is not published is the threshold at which AI review decisions stand without human sampling, what executes without approval, or a stated route back after a wrong classification. Security page, home page and AI services page read 6 September 2026.
A written commitment that the models work alongside human judgement, backed by real review surfaces and by contract, short of the full control structure, which is the B band and a strong instance of it. The commitment is contractual rather than promotional, which is rare on this axis. Clause 11.3 of the published Cloud Services Use and Delivery Terms states that use of AI Components does not replace decision-making and judgement by natural individuals, that they are intended to provide additional knowledge to support such decision-making, and that the customer remains solely responsible for decisions taken as a result of the outputs; the same clause prohibits unacceptable risk use as defined in the EU AI Act. Clause 11.1 acknowledges that customer-chosen parameters and inputs may carry assumptions, biases and limitations affecting output quality. The product surfaces match that framing: the vendor describes its own approach as GenAI human-assisted review, summaries carry document ID citations for verification, and Aviator Review is explicitly iterative, letting a team test criteria against sample data with token estimates and refine before committing to the full set, which is a genuine stopping point rather than an assurance. What the A band requires is absent. No threshold is published at which any feature acts alone or escalates, nothing states what an Agent will not attempt, and nothing describes what happens after an output is found to be wrong. R124(2) was applied to clause 11.3 and it does not qualify: it is a general statement across all AI Components rather than a constraint attached to a named mode or tier stating what that tier's output may not be used for. Verified 13 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
A named customer without figures, and figures without a named customer. Dara Tarkowski, managing partner of Actuate Law, is quoted by name on the 2023 cloud utility pricing launch about adopting the pricing model, with no measured outcome; the home page states most clients save fifty to sixty per cent on hosting costs, unattributed, and the TransPerfect partnership announcement states Reef ECA reduces document sets by over ninety per cent on average, which is the partner's figure. US Legal Support and TransPerfect are named partners rather than customers. Nothing joins a named customer to a figure. Home page, 2023 launch release and April 2026 partnership release read 6 September 2026.
Real deployment evidence with substance, short of joining the names to the figures, which is the B band in its own words. The naming is strong and spans the buyer types this product serves. The UK Serious Fraud Office is named with an attributed individual, Richard Day, quoted saying the platform transformed how the agency investigates and is embedded in its workflows, which is an unusually direct reference from a prosecuting authority. Bosch is named on the corporate side, and three law firms are named: Gleiss Lutz, Eversheds Sutherland and Pillsbury. Figures are published and they are specific: 75 per cent cost savings against manual review, 88 per cent faster document review, 90 per cent or better recall, up to 88 per cent cost savings on the product page, and a review of 48,756 documents completed in under two weeks. The problem is that the two sets do not meet. The customers who are named carry no figures, and the deployments carrying figures are anonymous, being described as a global technology leader and a major housing provider. That is precisely the split the B band names as the common failure. Nothing is dated, so a reader cannot tell when any deployment ran, and no method accompanies any figure, so the 75 per cent and 88 per cent claims cannot be assessed against what they were measured from. The individual customer story pages were not opened; under R25 they corroborate a grade that stands on the product and Aviator pages, and they are what would move this row to A. Verified 13 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments on segregation and work product, short of a training statement and an agreement. Segregation is the strongest in the pull: each client in its own AWS account with no shared database or infrastructure, each matter on its own servers, database and storage with its own URL and login, and multi-party sites with private fields, tag sets and searches that the security page describes as protecting group work products, which is work-product treatment in writing. Confidentiality controls include document lockdown with time-limited authorisation tokens, encryption in transit and at rest, and audit logging. Not located: any statement on training use, since no customer agreement is published and the privacy policy was not opened; any retention or deletion commitment; and the identity of the models the platform runs. Security page, Alchemy page and security FAQ read 6 September 2026.
Substantive published commitments across most of the ground, with two real gaps and one countervailing disclaimer, which is the B band. What is committed is unusually concrete for this axis. Training is excluded in terms: OpenText states it does not train models and that customer data, input prompts and outputs are never used to train the model. Segregation is documented at the level that matters in discovery: each LLM interaction is a separate session scoped to a single project and results are not shared across projects, and the eDiscovery terms require OpenText's conflicts check to be successfully completed before the service is provided for a matter, which is a conflicts mechanism rather than an access control. Third-party model handling is answered rather than assumed, the provider being named and session data stated to be deleted from Amazon Bedrock when the session closes, with Bedrock not storing or logging customer data. Clause 5.2 of the agreement confirms the customer owns its Content and OpenText claims no ownership, and clause 9 binds both parties to strict confidence for the term and three years after. Three things hold it at B. Privilege and work product are not addressed by name anywhere located, on the one product class where privilege review is a defined workflow. Retention and deletion of Content are deferred to Supplemental Terms under clause 6.5, which also states OpenText has no obligation to retain or delete Content except as agreed. And clause 11.4 runs the other way and is recorded because a buyer must weigh it: for AI Components using large language models, OpenText does not guarantee the protection of privacy, rights to use, or the accuracy of outputs. Verified 13 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
No advice line or supervision statement was located. The product is sold to law firms, corporate legal departments and investigators and its AI reviewers are described as applying senior attorney-level judgment, which is a capability claim rather than a position on where the lawyer's responsibility sits; no surface read states that outputs are not legal advice or how the product supports a supervising lawyer's duties, and no customer agreement exists on the site to carry such a statement. Home page, security page and AI services page read 6 September 2026.
A real published position on advice versus tooling, short of the supervision and competence dimension, which is the B band and its named common shape. The position is contractual, which sets this record apart from the two contract-lane records graded D in the same pull. Clause 11.3 of the published agreement states that use of AI Components does not replace decision-making and judgement by natural individuals, that they are intended to provide additional knowledge to support such decision-making and judgement, and that the customer remains solely responsible for any decisions taken and judgements made as a result of the outputs. The same clause prohibits unacceptable risk use as defined in the EU AI Act or per industry standards, and clause 11.6 places responsibility on the customer for identifying and complying with laws applicable to the use of AI Components in its own processes. Clause 3.2 separately makes the customer responsible for compliance with laws on the use of artificial intelligence systems. The scope of the licence reinforces it: the eDiscovery subscription is granted only in connection with the customer's legal or regulatory matters, and access may not be given to a managed service, eDiscovery or document review company or consultant without prior written consent. Marketing is consistent rather than in tension, the vendor describing its own approach as human-assisted review and publishing that agentic AI strengthens rather than replaces legal judgement. What the A band asks for is missing: nothing addresses supervision or competence, no rule of professional conduct or bar authority is named, and no jurisdiction limit is stated. Verified 13 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Security governance is published and AI governance is not. The security page names a chief information security officer reporting to the chief executive and a Technology Governance Committee co-chaired by the CISO and COO providing executive oversight, and the AI services page states rigorous validation of every service; security governance is a different subject from AI governance under the standing rule, and no responsible AI framework, ISO 42001 or equivalent, testing results or statement about uneven output across document types or languages is published. Security page and AI services page read 6 September 2026.
The published position on AI governance is contractual rather than a governance framework, with no mechanism, owner or testing regime behind it, which lands in the C band. What exists sits in the agreement and is a risk allocation rather than a governance programme. Clause 11.1 acknowledges that a customer's chosen parameters and inputs may include assumptions, biases and limitations affecting the effectiveness, quality, relevance and accuracy of outputs, which names bias as a real phenomenon and then assigns responsibility for it to the customer, input quality being the customer's sole responsibility under clause 11.2. Clause 11.3 references the EU AI Act by prohibiting unacceptable risk use, and clause 11.6 places compliance with AI-specific law on the customer. Clause 11.4 states plainly that OpenText does not guarantee the accuracy of outputs from large language model components. So the vendor is candid about limitations and silent about what it does to manage them. What the A and B bands require is absent. No responsible AI or AI principles page for this product was located, no accountable owner for model behaviour is named, no pre-release testing regime is described, and nothing is disclosed about what any evaluation has found. Bias is named as an input problem and never addressed as an output property, which matters here because responsiveness classification across custodians, languages and document types is exactly where uneven behaviour would show. Recorded under R25: the company-level Trusted Data and AI page was not opened and is what would move this row. Verified 13 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy covering most of the ground, with retention and notification not located. Access control: granular role-based access control, document lockdown by time-limited token, audit logs of every view, tag and search, private subnets with no public IP addresses, TLS and AES-256 encryption. Hosting and sub-processors: Amazon Web Services named as the infrastructure provider, with per-client accounts and regions chosen by the client; AI model providers are not named. Incident practice: the SOC 2 Type II scope covers monitoring and incident response, and the single-tenant design is described as limiting the blast radius of any incident to one environment; no customer notification commitment was located. Not located: a retention period or deletion commitment, since no customer agreement is published and the privacy policy was not opened. Security page and security FAQ read 6 September 2026.
Substantive published policy covering most of the ground, short of the full set, which is the B band. The strongest limb is the one most records leave blank, being what happens to material after processing. The Aviator FAQ describes the data flow step by step: a session is created with the model through the Amazon Bedrock API directly from the customer's own OpenText eDiscovery AWS environment, the request carries the prompt and document text, the response returns to that environment, and the session is closed with all data deleted from Bedrock, which does not store or log customer data in its service logs. Interaction is scoped per project with a separate session per feature interaction, and the model has no internet access, Bedrock hosting a deep copy. Training is excluded outright. Access to independent assurance is provided for under clause 7.4, which commits OpenText to supply summaries of third-party audit reports and certifications on written request under a confidentiality agreement. Three gaps hold it at B. No subprocessor list is published: the Data Processing Addendum takes a general authorisation to engage subprocessors, naming none, with a thirty-day objection and termination route, and AWS is named for eDiscovery only in the agreement itself. No incident or breach notification practice was located on the surfaces read. And retention of Content within the platform is deferred to Supplemental Terms under clause 6.5, with clause 10 adding that deletion following termination may be delayed up to 180 days by the third-party cloud infrastructure provider. Verified 13 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
No liability position is published. The site's page inventory, taken from the navigation and footer on 6 September 2026, carries a privacy policy, a GDPR disclosure and a contact page and no terms of service or customer agreement; the security page describes controls and invites contact for security requirements without any warranty, indemnity, cap or insurance statement. This is an absence on the vendor's surfaces rather than a retrieval limit. Security page and footer read 6 September 2026.
A real published position on liability, short of the full picture, which is the B band, and it is more specific to AI than almost anything else in this corpus. The agreement is published in full and carries a dedicated Artificial Intelligence Technologies section rather than folding AI into a general disclaimer. Clause 11.3 states that OpenText shall have no liability resulting from the creation or use of outputs, or from any decisions resulting from their use, with the customer solely responsible for those decisions. Clause 11.4 is unusually blunt and is quoted in substance because a buyer should see it: for AI Components using large language models, the nature of the technology may limit the protection of privacy, rights to use, and the accuracy of outputs, and OpenText therefore does not guarantee any of the three. Clause 11.5 flags that third-party AI components may carry additional terms accepted at the point of use. Recourse of a kind exists elsewhere in the agreement: clause 7.4 entitles the customer to summaries of SOC 1 Type II, SOC 2 Type II and ISO 27001 assurance on request under confidentiality, and clause 2.3 requires OpenText to identify the reason and expected impact of any change with a material adverse effect on functionality and to discuss mitigation. What the A band asks for is not in this instrument. No liability cap appears in these terms, which route commercial caps to the order documents and supplemental terms, no vendor indemnity of any kind was located, no service level accompanies the AI features, and no insurance position is published. Verified 13 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
One integration is named with its function and no documentation an implementer could use was read. The April 2026 partnership release states that TransPerfect's Reef ECA is deployed as the processing engine across all Alchemy cloud instances, giving a unified workflow from ingestion through review; the security page offers hosting in a client's own AWS environment. No document management, review-platform or load-file integration is described with what moves and in which direction, and no integration documentation was located. Partnership release and security page read 6 September 2026.
Real integrations exist and named connections are documented, short of the depth the A band describes, which is the B band. Collection breadth is the substantive limb and is published as a figure: more than 45 connectors feed the platform, which on a discovery product is the integration that matters most, because the systems legal work lives in are the custodian's mail, chat and file estates rather than a practice management suite. A paid add-on, OpenText Connectors for Private Cloud, is listed in the purchase table, so connector coverage is an explicit commercial dimension rather than an implicit one. The platform sits in a Legal Tech family with adjacent products a buyer can combine, being OpenText Investigation, Core Insight, Core Legal Hold and Legal Knowledge Management, and the agreement names AWS as the infrastructure for the eDiscovery Services. Audio and video are ingested and made searchable in native and transcribed form, which is an ingestion capability rather than a connector but bears on the same question. What the A band requires and was not established is depth: no individual source system is named on the surfaces read, no direction of flow is described, and nothing states what a customer must configure for any given connector. The connector catalogue itself and the product overview PDF were not opened; under R25 they corroborate a grade that stands on the published count and the add-on line, and they are what would move this row. Verified 13 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Deployment options are published with tenancy, regions and processing location. The security page states a single-tenant architecture with a separate AWS account, network, servers, databases and storage per client and dedicated resources per matter, deployment into any AWS region to meet local residency rules within forty-eight hours, hosting stated across the United States, European Union, United Kingdom, United Arab Emirates, Australia and Singapore, and the options of hosting in a client's own AWS environment or a government-approved FedRAMP environment; all processing and communication with cloud services occurs inside the client's private VPC over private links. The vendor contrasts this explicitly with shared multi-tenant platforms. Security page, security FAQ and partnership release read 6 September 2026.
Deployment is published in real detail and the tenancy model is stated, with region left general, which is a strong B under R38 where tenancy and region are co-equal limbs. Deployment options are not merely listed but sold as a choice: the purchase table names public cloud, private cloud and managed service, the product page adds on-premises and hybrid, and a deployment checklist is published to help a buyer choose between them. That range is wider than anything else in this lane and is a genuine answer for a buyer with sovereignty constraints, reinforced by a company-level sovereign cloud offering and a published private cloud availability map by geographic region. Tenancy is stated explicitly, which most records never manage: the Aviator FAQ confirms the feature set is available to OpenText eDiscovery cloud customers whether single or multi-tenant, so a buyer knows both that isolation is available and that shared tenancy is the alternative. The agreement names AWS as the cloud infrastructure for the eDiscovery Services and states that the AWS Customer Agreement governs the customer's use of it. What holds this off A is region. Availability is described as all AWS regions, which states reach rather than commitment: no region is named for a given customer, no residency guarantee is published, and nothing states where inference runs relative to where the collected evidence sits, though the FAQ's statement that the Bedrock session is created from the customer's own AWS environment implies they are co-located. Clause 10 adds that deletion after termination may be delayed up to 180 days by the infrastructure provider. Verified 13 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real, dated and scoped, short of a report reachable without a sales conversation. The security page states a SOC 2 Type II audit completed in November 2025 by an independent third-party service auditor covering control environment and governance, risk assessment, logical access, system operations and change management, and monitoring and incident response; a penetration test completed in September 2025 by AppSecure, a CREST-accredited firm, with all findings remediated and verified; and a plan to pursue ISO 27001 in 2026, which is roadmap and not credited. The auditor is not named, and the SOC 2 report and pen-test summary are available to qualified prospects under NDA by contacting the team, which is the sales-gated tier. Security page read 6 September 2026.
Certification is real and stated, short of accessible evidence, which is the B band word for word. The standards are named and the assurance is real: the company describes an information security management system based on ISO/IEC 27001 incorporating the ISO 27002 control set and aligned to the NIST Cybersecurity Framework, states that it conducts regular Service Organization Controls audits, and publishes an information security paper naming SOC 2 with HITRUST, PCI DSS, HIPAA, SWIFT, TISAX, CyberEssentials+ and FedRAMP across its estate. The agreement turns that into an entitlement rather than a claim, clause 7.4 committing OpenText on written request to provide summaries of third-party audit reports and certifications applicable to the Services, naming SOC 1 Type II, SOC 2 Type II and the ISO 27001 certificate, and allowing a customer to verify scope or controls not covered by a report through a Shared Assessments Security Information Gathering form. Two things keep it from A, and both are about access and scope rather than substance. The route to evidence is gated: reports come on written request and only where the customer has entered a confidentiality agreement, which under R5 is the sales-adjacent tier rather than self-service, and no report, date or certificate is reachable without that step. And scope per product is not stated anywhere located, so a buyer cannot establish from the published material whether OpenText eDiscovery specifically sits inside the ISO or SOC boundary. The contrast with Docusign in this pull is instructive: the same class of vendor, the same standards, and an A there turned entirely on published scope and public registries. Verified 13 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The vendor refers to multiple AI models without identifying them on the surfaces read. The Alchemy AI page is headlined three search engines and multiple AI models, the home page describes five AI engines, and a 2024 third-party directory entry refers to GPT-4, which is not credited; the vendor states that all processing occurs inside the client's locked-down AWS VPC, which places inference location with the client environment without naming the provider or model. No change-notification commitment is stated. The Alchemy AI page was not opened and is the rebuttal route. Home page, security page and navigation read 6 September 2026.
The supply chain is partly disclosed, the provider named and the architecture described without the model itself being named, which is the B band. The disclosure is among the most detailed located in this corpus and it sits in a product FAQ rather than a compliance document. The provider is named outright: Anthropic, reached through Amazon Bedrock via the Bedrock API, called directly from the customer's own OpenText eDiscovery AWS environment. Where it runs is stated, with availability in all AWS regions and the session initiated from the customer's own environment. The architecture is described in a way a buyer can actually reason about: Bedrock performs a deep copy of the model and hosts it, the provider has no read or write access and the model has no internet access, each interaction is a discrete project-scoped session, session data is deleted from Bedrock at close, and Bedrock does not store or log customer data in its service logs. The agreement supports it, naming AWS as an OpenText Licensor for the eDiscovery Services. Two A limbs fail and R34 keeps them separate from provider identification. The model itself is never named, no version or family is given, and nothing states what would happen if the underlying model changed. And no change notification commitment was located: the Data Processing Addendum's subprocessor mechanism gives a thirty-day objection and termination right on notice of a new subprocessor, which is a contractual route rather than a published commitment to notify on a model change. Verified 13 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The unit and structure are stated without the figure on the surfaces read. Cloud Utility Pricing charges by the hour while a site is in use and a much lower rate, stated as seventy per cent less, when it is switched off, with scheduling of operating hours and an energy-saver power-down, and the vendor states most clients save fifty to sixty per cent on hosting; the 2023 launch describes a low hourly rate without naming it. A pricing page exists in the navigation and was not opened on 6 September 2026, and is the rebuttal route in either direction. Home page and 2023 launch release read 6 September 2026.
Pricing is gated behind a sales conversation while the capability set and the deployment split are published, so the shape is visible and the number is not, which is the C band. The shape is genuinely visible and better structured than most gated records. A How to buy table sets out what an eDiscovery subscription includes, naming OpenText eDiscovery Aviator, technology-assisted review, self-service data processing, predictive search and an integrated viewer with redaction, and identifies OpenText Connectors for Private Cloud as a paid add-on rather than bundled. A second table names the three commercial delivery options, being public cloud, private cloud and managed service, and a published deployment checklist helps a buyer choose between them. The Aviator page adds a third dimension, describing on-demand, multi-matter subscription and private cloud options for the AI features specifically. What is absent is any figure. No rate, unit, band, per-gigabyte or per-custodian price, minimum commitment or implementation charge appears anywhere located, and every route resolves to Contact us or Speak with an expert. One genuine piece of cost transparency exists inside the product and is recorded because it is unusual, though it is not published pricing: Aviator Review provides upfront token estimates and lets a team test criteria against sample data before committing to a full run, which the vendor markets as cost certainty. That tells a customer what a job will consume once they are already a customer, not what the platform costs. A pricing row is owed under R17 with no figure. Verified 13 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment and coverage are described with substance; the boundaries are left open. The platform is sold to law firms, corporate legal departments and investigators for investigations, discovery and litigation, with the Alchemy page naming complex criminal matters, multi-defendant civil cases and joint defence groups as design targets, AI services extending to medical records, transcripts and scanned documents, review stated in any language, and hosting across six named jurisdictions. No matter type, data type or jurisdiction is named as unsupported. Home page, Alchemy page, security page and AI services navigation read 6 September 2026.
Coverage is described with real substance across buyer types and matter types, with the boundaries left open, which is the B band. Matter coverage is stated in the vendor's own framing rather than as a breadth claim: litigation, internal investigations, regulatory compliance, and personal data protection through automated detection and redaction driven by a pre-configured pattern library and custom regular expressions. Three use cases are published with detail behind each, covering case strategy and early case assessment, end-to-end collection through production, and personal data protection. Buyer coverage is evidenced rather than asserted, and it spans the three constituencies this product class serves: an investigating authority in the UK Serious Fraud Office, a corporate legal department in Bosch, and law firms in Gleiss Lutz, Eversheds Sutherland and Pillsbury, with Gleiss Lutz and the SFO showing the platform is sold outside the United States. A Legal industry solution page and a five-product Legal Tech family sit around it, and the training path is a four-day instructor-led case manager certification, which indicates the depth of configuration a real deployment involves. What is left open is the limit. No practice area or matter type is named as unsupported, no data volume ceiling is published, and no jurisdictional limit is stated. One boundary is stated and is credited to the vendor for candour, though it appears in the AI FAQ rather than on the coverage surfaces: validation of the Aviator features has been primarily on English-language documents and prompts. Verified 13 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No customer agreement is published and no training statement was located. The site's page inventory on 6 September 2026 carries a privacy policy, a GDPR disclosure and a contact page and no terms of service; the security page, security FAQ, Alchemy page and AI services page address isolation, encryption and validation without stating whether customer content trains any model. The privacy policy was not opened and is the rebuttal route. Surfaces checked 6 September 2026.
Training on customer content is excluded in the vendor's published material with no matching term in the agreement, which is this value. The statement is unqualified and covers three things at once: OpenText does not train models, the models reached by the AI features are pre-trained by the provider, and customer data, input prompts and outputs are never used to train the model. A fourth sentence closes the gap most such statements leave open by addressing leakage rather than training, stating that results are not shared across projects.
The architecture published alongside it supports the claim rather than merely asserting it: each interaction is a discrete session created through the Amazon Bedrock API from the customer's own AWS environment, the session closes with all data deleted from Bedrock, Bedrock does not store or log customer data in its service logs, and the model is a deep copy hosted by Bedrock to which the provider has no read or write access and which has no internet access.
A buyer can therefore see why no training could occur, not just be told it does not. R43(1) is discharged. The governing agreement was located and read in full: the Cloud Services Use and Delivery Terms carry a dedicated Artificial Intelligence Technologies section at clause 11 and it contains no training permission, no reservation of rights over inputs or outputs for model improvement, and no matching term in either direction.
The one adjacent provision is clause 12.5, which reserves anonymized Services Statistics to OpenText and is recorded rather than credited, being experience and statistical knowledge rather than model training.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material addresses how long prompts, answers or matter data are retained. The security page describes data protection from ingestion through final disposition without a retention period or deletion commitment, no customer agreement is published, and the privacy policy was not opened and is the rebuttal route. Surfaces checked 6 September 2026.
Retention is addressed with real precision on one leg and left to negotiation on the other, which is why this is the vague value rather than the zero value, and the note separates the two carefully because the difference matters. At the model provider the position is zero and is stated unambiguously: once the session closes, no data from the session remains on the Amazon Bedrock or model side, and Bedrock does not store or log customer data in its service logs.
The session is scoped to a single project, a separate session is created for each feature interaction, and the model is a hosted deep copy with no internet access. That is a complete answer for the third-party leg and it is better than most records in this corpus manage. Within the platform itself no period is published. Clause 6.5 of the agreement provides that any applicable retention period and any return service will be specified in Supplemental Terms, and that OpenText has no obligation to retain or delete Content nor to return it except as provided in the agreement.
So retention of the evidence set, and of the summaries and review determinations the AI produces from it, is a matter for the individual order rather than a published commitment, and Supplemental Terms are not published. Clause 10 adds a further qualifier a buyer should see: requests for deletion of Content following termination may be delayed by up to 180 days by the third-party cloud infrastructure provider, during which the confidentiality and use restrictions continue to apply.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own separation model and documents it at matter level, the most specific in the pull. The security page states a separate AWS account per client, separate servers, database, search and storage per matter, matter-specific URLs with independent authentication, granular role-based access control with every function assignable as a permission, and multi-party sites in which user groups keep private fields, tag sets and searches while sharing folders; the security FAQ adds that each case has its own encryption keys. Surfaces checked 6 September 2026.
Separation is documented at the level this product class requires, which is the matter, and it is documented twice over in two different instruments. In the AI layer the boundary is architectural: interaction with the model is project-level, a separate session is created for each feature interaction, and results are not shared across projects. That is matter isolation described as a mechanism rather than promised as a policy, and it answers the question a litigator would actually ask, which is whether work product from one matter can surface in another.
In the agreement the boundary is contractual and goes further than access control: the eDiscovery terms grant a subscription to use the service only in connection with the customer's legal or regulatory matters, and provide that OpenText shall supply the eDiscovery Services only in connection with matters for which OpenText's own conflicts check has been successfully completed. A vendor-side conflicts check is a genuine ethical-wall instrument and is rare in this corpus.
The same clause bars the customer from giving access to a managed service, eDiscovery or document review company or consultant without prior written consent, which closes the downstream route. Deployment reinforces it, the AI features being available to single-tenant as well as multi-tenant cloud customers. What is not published is the permission model inside a matter: no roles are enumerated, nothing describes how review-team access is granted or revoked, and privilege review as a walled workflow is not described.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located public material addresses whether the customer is told when its data is demanded by a third party. No customer agreement is published, the security page is silent on legal process, and the privacy policy and GDPR disclosure were not opened and are the rebuttal route. Surfaces checked 6 September 2026.
Notice is addressed and reserved to the vendor's discretion for the material this signal is about, which is this value, and the reason turns on a carve-out that is easy to miss. Clause 9 of the agreement contains a strong compelled-disclosure provision: where disclosure is required by law or by order of a court or regulator, the receiving party must promptly notify the disclosing party, where lawfully permitted, so that it may intervene to contest the requirement or seek a protective order.
Read alone that is the notice-committed shape. But the same clause lists what Confidential Information excludes, and limb (iv) excludes Content, which is defined as the customer's own uploaded data and is therefore the entire evidence set the platform exists to hold. Content is governed instead by clause 6, which addresses responsibility, security and retention and says nothing about third-party demands. So the notice commitment protects the parties' commercial confidences and does not, on its face, reach the customer's matter data.
What does address that material is clause 12.2, under which OpenText may notify law enforcement if it observes suspected child sexual abuse material, believes continued performance would aid a crime, or discovers evidence of a planned future crime, and in that event OpenText may notify the customer. That is a disclosure practice published with notice expressly discretionary. No transparency report was located. The gap is worth naming precisely because of the buyer: a discovery platform holds material already under legal process.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies a legal corpus behind the product's answers, and the product is not built on one: it searches, reviews and answers over the customer's own collected documents and cites its sources to them. Home page and Alchemy page checked 6 September 2026.
No located public material identifies a source corpus, and R15 governs the weight. This product answers from no body of law and no licensed content. The corpus is the customer's own collected evidence, ingested through more than 45 connectors from the custodians' mail, chat, file and audio-visual estates, and everything the AI does is performed against that set: summarizing key documents from it, labeling concepts within it, and classifying its documents as responsive or not.
There is no third-party corpus whose provenance or licensing this signal would ordinarily test, and the vendor is not withholding something its product class implies. Two things are recorded rather than credited. The models themselves are stated to be pre-trained by the provider and OpenText states it does not train them, so no training corpus of OpenText's own construction exists to describe; what the provider trained on is not disclosed and is outside what this vendor could disclose.
And the agreement notes at the eDiscovery terms that specific portions of the software may incorporate free or open source code, for which OpenText undertakes to obtain the appropriate authorization, which is a software licensing statement rather than a content provenance one. The surfaces read on the date shown were the product page, the Aviator page including its full FAQ, the Cloud Services Use and Delivery Terms, the privacy center and the certifications material.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history, and the product does not retrieve or cite primary law; its output is sourced reports, review decisions and productions from the customer's documents. Recorded as the honest value for a product without a citator function. Surfaces checked 6 September 2026.
No located public material addresses whether authority is checked for subsequent history, and on this product the question does not arise. Nothing in OpenText eDiscovery cites law. The platform ingests, processes, analyses, reviews and produces the customer's own evidence, and the AI features summarize documents, label concepts and classify responsiveness within that set. No proposition about the state of the law is generated whose treatment a lawyer would verify in a citator, and no case, statute or regulation is cited to the user.
R15 governs and the limb is recorded as inapplicable rather than failed. One adjacency is named so it is not mistaken for the thing, because it is the closest analog and it is a real one in this product class. Discovery outputs must be defensible, meaning a party may have to show later how a document set was culled and why particular material was or was not produced, and the currency question here is whether a determination made early in a matter still holds after the criteria change.
The vendor addresses part of that through iterative review, letting a team refine criteria against sample data before a full run, but nothing published describes how earlier classifications are reconciled when criteria are revised. That is a defensibility question rather than a good-law question and it is not graded here. Surfaces read on the date shown were the product page, the Aviator page and FAQ, the agreement and the privacy center.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
No located public material describes what the answering or review models do when they cannot ground an answer or classify a document with confidence. The platform returns sourced reports and the services are described as validated, but no abstention path or confidence signal is described on the surfaces read; the Alchemy AI page was not opened. Home page and AI services page checked 6 September 2026.
No located public material describes what the system does when it cannot produce a reliable answer. What the vendor publishes addresses the process around the model rather than the model's behavior at the point of doubt, and the distinction is worth drawing because the process material is genuinely good. Aviator Review is iterative by design: a team submits sample data sets, refines its criteria and reads token estimates before committing to a full-scale run, which is a real stopping point and gives a firm a way to discover that the criteria are wrong before the cost is incurred.
Summaries carry document ID citations so a reviewer can verify a statement against the source. A recall figure of 90 percent or better is published, which concedes that some responsive material is missed. None of that says what happens to an individual document the model cannot confidently classify. Nothing states that a low-confidence classification is flagged for human review, that a document is routed to a reviewer rather than coded, that a confidence score attaches to a responsiveness call, or that the system reports it could not summarize a document rather than producing a thin summary.
The gap has consequences specific to discovery: a responsiveness determination the model gets wrong with no uncertainty signal is a document that silently does not reach the review queue. Surfaces read were the product page, the Aviator page and FAQ, the agreement and the privacy center.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record naming Merlin Search Technologies, Alchemy, DiscoveryPartner or Sherlock was located as of 6 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on the company and product names together with a general search for court findings on ediscovery review; results returned directory entries and commentary, none of which is a court record naming this product.
This is a statement about the public record, not a finding about the product; a review platform that cites the customer's own documents carries a remote exposure on this signal.
Searched on 13 September 2026 against the company name, the current product name, the AI feature name and the former product name Axcelerate, across reporting and trackers covering decisions on AI-generated fabricated citations. None located. No decision, sanction or disciplinary referral names OpenText, OpenText eDiscovery, eDiscovery Aviator or Axcelerate. Context is recorded because the field searched is now large and actively tracked, so the absence was tested against something substantial: reporting for the first quarter of 2026 alone tallies at least 145,000 dollars in United States sanctions for fabricated citations, including a Sixth Circuit penalty described as the steepest at federal appellate level and a record Oregon sanction, and the researcher maintaining the principal worldwide database has described days on which ten separate courts flagged AI-fabricated filings.
General-purpose assistants rather than discovery platforms are what those accounts describe. Under R119 this signal records fabricated legal citations in filings and nothing else, so no other proceeding involving this vendor would appear here. One point of product context: the AI features summarize and classify the customer's own evidence and cite documents by identifier within the matter, rather than generating citations to legal authority, so the exposure this signal tracks is structurally low.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material names an ethics opinion, bar rule or professional responsibility framework. The founder publishes books and webinars on generative AI in discovery, which is education rather than guidance alignment, and no customer agreement exists to carry a reference. Home page, security page and headlines navigation checked 6 September 2026.
Professional and regulatory duty is engaged in general terms with no bar or ethics authority named, which is this value. The engagement is contractual and more substantive than the value usually implies. Clause 11.3 of the published agreement states that use of AI Components does not replace decision-making and judgment by natural individuals and that the customer remains solely responsible for decisions taken as a result of the outputs, then prohibits unacceptable risk use as defined in the EU AI Act or per industry standards.
Clause 11.6 records that applicable laws may impose additional requirements on the use of AI Components in particular contexts and makes the customer solely responsible for identifying and complying with them, and clause 3.2 lists compliance with laws on the use of artificial intelligence systems among the customer's responsibilities. So a named legal instrument is invoked and the duty of human judgment is stated in a document the buyer signs.
What is absent is any professional conduct authority. No bar association, no rule of professional conduct, no court guidance or standing order on AI use, and no ethics opinion is cited or mapped to the product, in any jurisdiction. That gap is worth naming on this product specifically because discovery is the area where courts have most actively set expectations about disclosing and validating machine-assisted processes, and the vendor's own marketing engages the judgment question editorially without connecting it to any of that.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Law firms are a named buyer segment and the published position on the bill is a savings claim: most clients save fifty to sixty percent on hosting under hourly on-off pricing, and AI review is offered at a fraction of the cost of manual review. Hosting cost is a technology pass-through a firm may bill onward, and nothing addresses how AI-assisted review is recorded or disclosed on a client's bill. Home page and 2023 pricing release checked 6 September 2026.
Nothing published addresses what happens to the bill when AI-assisted work takes an hour instead of six, which is the floor, and the omission is more pointed here than on most records. This vendor sells to law firms directly, three of them named as customers, and eDiscovery cost is the classic matter disbursement passed through to a client. The vendor's own claims are framed squarely in cost terms: 75 percent cost savings compared to manual document review, 88 percent faster review, document review described as consuming more than 75 percent of discovery costs, and an add-on managed review package marketed as delivering a further 10 to 20 percent saving.
Those figures describe money that, in a firm-and-client relationship, was previously billed onward. Nothing published addresses what becomes of it. No per-matter record distinguishing AI-performed from human-performed review is described, nothing marks an Aviator determination as machine-made for the purposes of a fee narrative, and no guidance on fee or disclosure treatment is offered to a firm passing discovery costs to a client.
Recorded and expressly not credited under R21 and R24, because it answers a different question: Aviator Review publishes upfront token estimates and lets a team test criteria before a full run, which the vendor markets as cost certainty. That prices the vendor's own charge for a job, which is a platform cost, not a record of AI-assisted work for the client's bill.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No sub-processor list or model provider list was located. Amazon Web Services is named as the infrastructure provider, which says where data is hosted and not whose models see it, and the vendor refers to multiple AI models without naming them; no customer agreement or DPA is published, and the SOC 2 report is available only under NDA to qualified prospects. The privacy policy and GDPR disclosure were not opened and are the rebuttal route. Surfaces checked 6 September 2026.
The model provider is named and forwardable contractual material exists, without a maintained subprocessor list, which is this value under R29. The model limb is answered better than almost anywhere in this corpus. The provider is named outright as Anthropic, the delivery path is named as Amazon Bedrock, and the FAQ sets out what each may see and retain: the session runs from the customer's own AWS environment, closes with all data deleted from Bedrock, and Bedrock does not store or log customer data.
So a firm can tell a client exactly which third party processes its evidence and on what terms. Forwardable material exists too: a global Data Processing Addendum effective 1 September 2024 applying across jurisdictions, the Cloud Services Use and Delivery Terms published in full with a dedicated eDiscovery section naming AWS as the infrastructure provider, and clause 7.4 entitling the customer to summaries of SOC 1 Type II, SOC 2 Type II and ISO 27001 assurance on request under confidentiality.
What is missing is the list. No current subprocessor list is published: the Data Processing Addendum takes a general authorization to engage subprocessors, describing them by category as OpenText affiliates and their vendors and as subcontractors, naming none, with a thirty-day objection window and termination as the remedy. R29 is explicit that a category acknowledged without entities identified is not a list, and that is what separates this from the top value. Verified against Docusign in the same pull, where a dated per-service list earned the value above.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of a disclosure record are available and no export of an AI-use record is described. The security page states extensive audit logging of every person's document views, tags, searches and other actions, and the platform's answers are sourced to documents, which together record what was reviewed and by whom; nothing states that a record of the model used, its classifications and the human verification can be exported for a court, and the product's outputs are productions and reports rather than court-facing certifications. Security page and home page checked 6 September 2026.
No located public material addresses disclosure of AI involvement to a court or an opposing party, and on this product that is the most consequential of the floor values recorded. Discovery is the one area of practice where the use of machine assistance is routinely disclosed and sometimes negotiated: technology-assisted review protocols are exchanged between parties, validation methodologies are agreed, and a producing party may have to defend how a set was culled.
The vendor plainly understands this, publishing that defensibility of process is what its technology-assisted review has delivered for more than fifteen years, and publishing a recall figure, which is the metric a validation protocol turns on. What is not published is any artifact a party could put in front of a court. Nothing describes a record of which documents an Aviator feature classified rather than a human, no export or report is offered evidencing the model's involvement in a production, no statistical validation output is described, no certification template is provided, and no guidance is published on when or how the use of the generative features should be disclosed in a protocol or a meet-and-confer.
Recorded and not credited: the iterative sampling and token estimates in Aviator Review are a cost and quality control for the customer's own benefit, not a disclosure instrument, and summaries carrying document IDs point to sources within the matter rather than evidencing how the summary was made. Surfaces read were the product page, the Aviator page and FAQ, and the agreement.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Primary Law Corpus Provenance
- Good Law Verification
- Refusal and Uncertainty Behavior
Which one fits
Choose Merlin Search Technologies if
- You need each matter walled off at the infrastructure level. Merlin deploys each client in its own AWS account with separate servers, databases and storage, gives each matter its own servers, URL, login and encryption keys, and lets joint defense groups share a site while each keeps private tag sets and searches.
- Your data has to sit in a specific country or inside your own cloud. Merlin deploys to any AWS region within 48 hours, states hosting across the United States, EU, UK, UAE, Australia and Singapore, and can run in your own AWS account or a FedRAMP environment, with processing kept inside your private network.
- You want to pay for hosting only while you use it. Merlin charges by the hour while a site is on and about 70 percent less when it is switched off, with scheduled power down at night and on weekends, and states that most clients save 50 to 60 percent on hosting.
Choose OpenText eDiscovery if
- You need to tell a client exactly which AI reads its evidence. OpenText names Anthropic as its model provider, reached through Amazon Bedrock from your own OpenText AWS environment, states that each session is scoped to one project and deleted from Bedrock when it closes, and states that customer data, prompts and outputs never train the model.
- You want the AI terms in writing before you sign. OpenText's published Cloud Services Use and Delivery Terms carry a dedicated AI section stating that the AI does not replace human decision making and prohibiting uses the EU AI Act treats as unacceptable, and entitle you to SOC 1 Type II, SOC 2 Type II and ISO 27001 summaries on request.
- Your custodians' data sits in many systems and you want deployment options kept open. OpenText feeds its platform through more than 45 data source connectors, reviews audio and video in native and transcribed form, and offers public cloud, private cloud, on premises, hybrid or managed service.
In summary
Merlin Search Technologies
Merlin Search Technologies, founded in 2019 in Denver, Colorado, makes Alchemy, an AI ediscovery and investigations platform covering processing, search, review and production, in which a team asks plain language questions across millions of documents and receives sourced reports, with ReviewPartner applying AI reviewers to large reviews. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes, with an A on deployment and data residency: each client runs in its own AWS account and each matter on its own servers, in any AWS region, the client's own AWS account or a FedRAMP environment. It completed a SOC 2 Type II audit in November 2025. As of 6 September 2026 the index located no customer agreement, no named model and no retention period.
OpenText eDiscovery
OpenText eDiscovery, formerly Axcelerate, is the discovery platform of Open Text Corporation, the Canadian information management company, covering collection through more than 45 connectors, processing, technology assisted review, analysis and production for corporate legal departments, law firms and investigating authorities. Its generative layer, eDiscovery Aviator, summarizes key documents with document ID citations, reviews for responsiveness and runs agents on multi step tasks. The AI Legal Index grades it in the top two bands on thirteen of fifteen capability axes. It names Anthropic, through Amazon Bedrock, as its model provider and states that customer data never trains the model. Named customers include the UK Serious Fraud Office and Bosch. As of 13 September 2026 the index located no published price, no subprocessor list and no AI governance framework.
Questions buyers ask
Merlin vs OpenText eDiscovery: which is better for AI eDiscovery?
On published evidence OpenText sits in the top two bands on thirteen of fifteen AI Legal Index capability axes and Merlin on ten of fifteen, mainly because OpenText publishes its agreement and names its model provider. Merlin publishes a more isolated architecture, with a separate AWS account per client and separate servers per matter in the region of the client's choice, and an hourly price structure. Buyers with strict residency or joint defense needs have more to read from Merlin.
Which AI model does OpenText eDiscovery Aviator use?
OpenText names the provider as Anthropic, reached through Amazon Bedrock from the customer's own OpenText eDiscovery AWS environment. It states that Bedrock hosts a copy of the model, that the provider has no read or write access and the model no internet access, that each interaction is a separate session scoped to one project, and that session data is deleted when the session closes. The specific model and version are not named, and no commitment to notify customers of a model change is published. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
How does Merlin keep matters separate?
Merlin deploys each client in its own AWS account with no shared database or infrastructure, and gives each matter its own servers, database, search and storage, its own URL and login, and its own encryption keys. Multi party sites let joint defense groups share folders while each group keeps private fields, tag sets and searches, which the vendor describes as protecting each group's work product. Access control is role based, with every function assignable as a permission. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
How is Merlin priced?
By the hour. Merlin's Cloud Utility Pricing charges an hourly rate while a site is in use and a rate about 70 percent lower when it is switched off, with sites scheduled to run only during working hours or powered down when idle, and it states that most clients save 50 to 60 percent on hosting. AI services are priced separately. OpenText publishes no price, unit or band, and every route ends at a contact form. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
What do Merlin and OpenText eDiscovery both leave unpublished?
How their models are governed and what they do when unsure. Neither names anyone accountable for model behavior, describes testing before release, or addresses whether review quality is uneven across languages or custodians. Neither says what happens to a document its AI cannot classify with confidence. Neither publishes a subprocessor list, and neither offers a court facing record showing which documents the AI classified. Both advertise large savings without saying how they should appear on a client's bill. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
Three readings to weigh. OpenText's agreement states that for its large language model features it does not guarantee privacy, rights to use or the accuracy of outputs, and its compelled disclosure notice clause covers confidential information, which the agreement defines to exclude the customer's uploaded content; both are published terms a buyer should read. OpenText also states that its AI has been validated mainly on English language documents. Merlin publishes no customer agreement, so its grades rest on its security pages, and its pricing page was not read, so an hourly rate may be published there. Merlin was verified on 6 September 2026 and OpenText on 13 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.