A
Altumatim
Altumatim sells altumatimOS, an AI platform for eDiscovery, investigations and litigation built around multi-agent review. Autonomous Review runs responsiveness, privilege, confidentiality redaction and production in one workflow: a team defines the subject matter in plain language, validates a balanced control set to build a gold set, and the system self-iterates its own review instructions until results meet the F1 threshold the team sets, producing confidence-scored decisions with written explanations, auto-generated privilege logs and production-ready exports.
The investigation and litigation products analyse relationships and timelines across large datasets to assemble the facts of a case. Altumatim publishes an AI governance page setting out that customer data is never used to train models, that foundation-model processing runs under enterprise agreements with zero retention, that answers are grounded in the customer's own documents with citations, and that every determination can be accepted, rejected or overridden by the customer's team.
The platform runs on premises, in the cloud or in a hybrid configuration, and the company is based in Birmingham, Michigan.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
There is no product here without the models. altumatimOS is sold as multi-agent AI that reads a dataset for responsiveness, privilege and confidentiality, writes redactions, produces privilege logs and assembles the facts of a case; the eDiscovery page's own claim is a review that thinks for itself, with no prompt engineering required because the agents interpret the criteria and iterate their own instructions. Strip the agents out and what remains is document storage and an export. Verified 20 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is treated as something to measure rather than promise, and the measurements belong to each customer rather than to the public record. The AI governance page says answers are grounded in the customer's own documents through the vendor's retrieval techniques and carry citations to sources in the dataset, and that review quality is validated against human-reviewed control sets using precision, recall and F1, reported per project and refined until results meet the threshold the customer sets, with every iteration logged.
The eDiscovery page shows the same measures in the product. What is not published is a figure an outsider can test: the numbers on the site belong to individual matters, no benchmark or test set is described, and no failure mode is named. Verified 20 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
What the system does alone, what stops it, and how a lawyer checks it are all published. The review runs as a named pipeline: criteria, control set creation, control set review, full run, confidence-scored results with explanations, production. A team validates a balanced control set to build the gold set that directs the full review, and the agents iterate their own instructions until they hit the F1 threshold the team defines, with each iteration logged so the standard applied is visible.
Every determination, including redactions, can be agreed, disagreed with or overridden before export, and the vendor states the position plainly: AI recommends, lawyers decide, and every mission-critical step is human-validated. Verified 20 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
The results are measured and the customers are not named. Three matters are described on the homepage with figures: an AmLaw 200 firm acting for a Fortune 500 company facing more than 10,000 complaints, reporting 75 per cent cost savings; a Fortune 200 company's regulatory analysis, reporting 94 per cent time saved with explainability for every decision; and an AmLaw 10 firm reading carbon copies and microfiche, reporting 99 per cent precision and recall on handwriting and checkboxes.
None of the three identifies the customer or dates the work, and no method is given for how the savings were calculated. A published white paper reports retrieval accuracy and indexing figures for structured data. Verified 20 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The commitments are specific, they are written for this buyer, and they sit on published pages rather than in a contract a customer can read before signing. The AI governance page states that customer data is never used to train models, that foundation-model processing runs under enterprise agreements prohibiting retention and training by the providers, that answers are grounded in the customer's own documents, and that data is returned or deleted at the customer's direction when a matter ends.
The security page adds physical separation of client datasets, encryption in transit and at rest, role-based access with logging, and customisable retention. The Terms of Use cover the website only and say that the platform is governed by separate signed agreements, which are not published, so none of this is readable as a term. Privilege itself is handled as a review task, with dual-analysis privilege detection and generated logs, rather than as a stated position on privilege and work product in the data Altumatim holds. Verified 20 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
The vendor addresses the duties its buyers carry, in its own words and under its own heading. The AI governance page says using AI does not suspend a lawyer's duties and maps the product to three of them: competence, through transparent metrics and grounded citations a lawyer can explain rather than simply trust; confidentiality, through no-training commitments, zero-retention processing, encryption and segregation; and supervision, through human-in-the-loop workflows that keep review decisions attributable to the team with a record of what was validated and by whom.
The Terms of Use state that website content is not legal advice and creates no attorney-client relationship. What is absent is any jurisdiction statement and any treatment of who may operate the review in the first place. Verified 20 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A published framework with real substance, short of the things that would let a buyer audit it. The AI governance page sets out three commitments (no training on customer data, processing under provider agreements that bar retention and training, and lawyers retaining control of every determination), then walks the data's life from ingestion into a SOC 2 Type II environment through grounded answers, human validation and deletion at the customer's direction, and states that review quality is measured against human-reviewed control sets and reported per project rather than asserted in the abstract.
Nobody inside Altumatim is named as accountable for model behaviour, nothing describes what is tested before a release ships, and nothing addresses whether performance is uneven across document types, languages or custodians, which a vendor reporting precision and recall is well placed to answer. Verified 20 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Most of the ground is covered and the gaps are at the edges. The security page publishes encryption in transit and at rest, physical segregation of client datasets, role-based access with all access from source data to results logged and routinely audited, perimeter defences, third-party vulnerability assessments and penetration testing, 24/7 monitoring with a dedicated incident response team, and customer-controlled retention policies; the AI governance page adds that data is returned or deleted at the customer's direction at the end of a matter.
The service providers named in the Privacy Policy (Google, Microsoft, LinkedIn, Calendly, Adobe) relate to the website and marketing rather than to document processing, no model provider is named, and no breach notification timeline to customers is published. Verified 20 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Nothing published says who bears the loss if a review goes wrong. The Terms of Use, last updated September 2026, apply to the public website only and say so: access to altumatimOS is governed by separate written agreements between Altumatim and its customers, and those agreements are not published. The website terms disclaim all warranties, cap liability at one hundred dollars and require the user to indemnify Altumatim, but none of that reaches a missed responsive document, an incorrect privilege call or a redaction that fails.
The site also states that product descriptions are not a binding offer and that features, terms and performance are defined exclusively in customer agreements. Checked the terms, the privacy policy, the security and AI governance pages and the three product pages on 20 September 2026. Verified 20 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
No integration into the systems a litigation team already runs was located. The workflow is self-contained: documents are ingested, reviewed and exported as production packages with privilege logs, and the platform can be deployed on the customer's own infrastructure. Nothing names a review platform, document management system, matter management system or eDiscovery processing tool it connects to, no API or developer documentation exists, and no import or export format is specified.
Checked the homepage, the eDiscovery, investigation, litigation and OS pages, the security and AI governance pages, the terms and the privacy policy on 20 September 2026. Verified 20 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The deployment choice is stated clearly and the geography is not. The eDiscovery page offers three options and says what changes between them: on premises for complete data sovereignty with the customer controlling storage and processing, cloud for scale, and hybrid configurations that keep sensitive data on premises while using cloud compute. The security page names Google Cloud and AWS as the underlying infrastructure with dedicated virtual private clouds and network segmentation.
No region is named for the cloud option, and the Privacy Policy says information is stored and processed in the United States and any other country where Altumatim, its group companies or its providers maintain facilities. Verified 20 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The certification is real and stated, with the supporting evidence still behind a conversation. The security page states SOC 2 Type II certification, describes it as formal validation of controls protecting client data, and says Altumatim works with a third-party security auditor using compliance software and real-time monitoring for continuous verification and evidence collection, alongside regular vulnerability assessments and penetration testing by outside firms.
The auditor is not named, no report period or scope statement appears, there is no trust portal, and no route to obtain the report is published; the page invites buyers to bring their security team and procurement checklist to a demo. Verified 20 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The terms attached to the models are published and the models are not. The AI governance page says that where leading foundation models process customer data it happens under enterprise agreements carrying zero data retention and an explicit prohibition on training, which is a meaningful commitment about the supply chain without identifying anything in it: no model, version or provider is named, and nothing states which provider handles which part of the work.
Google Cloud and AWS are named as infrastructure on the security page. No commitment to notify customers when the models behind a review change was located. Verified 20 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. Checked the homepage, the eDiscovery, investigation, litigation and OS pages, the security and AI governance pages, the newsroom and blog indexes, the Terms of Use and the Privacy Policy on 20 September 2026: there is no pricing page, no tier, no per-document or per-gigabyte rate and no trial, and every route ends at a one-hour demo booking.
The terms state that the features, terms and performance of the products are defined exclusively in written customer agreements. Verified 20 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
The work the platform covers is described in detail and the edges are left open. Three product lines are set out: eDiscovery through to production, investigations across relationships and timelines, and litigation support for case preparation, with compliance analysis appearing in the published matter descriptions. The buyers addressed are law firms, enterprises and government organisations, and the matters described run from a 10,000-complaint litigation to regulatory review to digitised microfiche archives, including the vendor's published work on reading spreadsheets and other structured evidence.
What is not stated is any limit: no practice area, matter size, language or data type is named as outside the platform's scope. Verified 20 September 2026.
6 public documents
The public pages on file for Altumatim, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.
-
altumatim.com/security/ai-governance3 signals
Client Data in Training, Prompt and Output Retention, Bar Guidance Alignment
Read Sep 20, 2026
-
altumatim.com/e-discovery2 signals
Refusal and Uncertainty Behaviour, Court Disclosure Support
Read Sep 20, 2026
-
altumatim.com/privacy-policy2 signals
Third Party Request and Subpoena Notice, Outside Counsel Guideline Readiness
Read Sep 20, 2026
-
altumatim.com1 signal
Billing and Fee Posture
Read Sep 20, 2026
-
altumatim.com/security1 signal
Ethical Walls and Matter Segregation
Read Sep 20, 2026
-
Fabricated Citation Record
Read Sep 20, 2026
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
A public policy or trust page states no training on customer content, with no matching term located in the published agreement.
The AI governance page commits that customer data is never used to train AI models, Altumatim's or anyone else's, and that where foundation models process the data it happens under enterprise agreements with zero retention and an explicit prohibition on training. The commitment sits on a published page; the platform itself is governed by signed customer agreements that are not published, so a buyer sees the promise but not the term.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
The customer controls the retention window, by product configuration or by contractual instruction, but zero retention is not stated as available.
The customer sets the window. The security page lists customisable data retention policies among the client controls, and the AI governance page says data remains the customer's and is returned or deleted at the customer's direction when a matter concludes. Model providers are separately barred from retaining anything. No default period is published and no zero-retention setting is stated for the platform's own store.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
Altumatim runs its own permission model and documents it: client datasets are physically separated to prevent cross-contamination, role-based authentication restricts access to authorised individuals, and all access from source data to results is logged and routinely audited, with single sign-on integration and granular permission settings listed among client controls. Separation between matters or teams inside one customer, which is what an ethical wall turns on, is not addressed, so a firm keeping walls between its own matters would need to configure and maintain that itself.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.
The Privacy Policy, last updated September 2026, reserves the right to disclose personal information as required by law, including to comply with a subpoena, warrant or court order and to respond to government requests, and says nothing about notifying the customer. It covers personal information rather than the case data in a review, and the signed customer agreements that govern the platform are not published.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
Checked the homepage, the eDiscovery, investigation, litigation and OS pages, the security and AI governance pages, the Terms of Use and the Privacy Policy on 20 September 2026. The platform works over the documents a customer loads for a matter, and answers are grounded in that dataset; no external legal corpus is described or needed.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Checked the same pages on 20 September 2026. The product classifies and analyses the customer's own documents rather than citing legal authority, so no subsequent-history check arises and none is described.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
The product exposes a confidence or grounding score without an explicit abstention path.
Uncertainty is surfaced as a score rather than as a refusal. The eDiscovery pipeline ends in confidence-scored output with written explanations for each determination, the published classification breakdown carries a Needs Review bucket alongside responsive and non-responsive, and review quality is reported per project as precision, recall and F1 against a human-reviewed control set. Nothing published describes the system declining to answer or flagging that a question cannot be grounded in the dataset.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.
Searched the AI Hallucination Cases database maintained by Damien Charlotin on 20 September 2026 on the product names Altumatim and altumatimOS. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Public materials refer to professional responsibility in general terms without naming guidance.
The AI governance page engages with professional duties directly, under the heading that using AI does not suspend a lawyer's duties, and works through competence, confidentiality and supervision in turn; it also says the accuracy approach matches the standard courts have applied to technology-assisted review for a decade. No ethics opinion, bar guidance, court rule or decision is named anywhere, so the engagement is with the duties in general terms rather than with the guidance a buyer is bound by.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure, and the product sits inside a fee relationship between a lawyer and a client where those savings would change the bill.
The published matter descriptions lead on cost and time: 75 per cent cost savings for one client, 94 per cent time saved for another, and review time cut by up to 80 per cent on the eDiscovery product. Law firm buyers bill review work to clients, and nothing published addresses how those savings reach a client's bill or whether platform charges pass through as a case expense.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
A service provider list is published in the Privacy Policy, naming Google for cloud infrastructure, email and analytics, plus Microsoft, LinkedIn, Calendly and Adobe; the security page names Google Cloud and AWS as the platform's infrastructure. No foundation model provider is identified anywhere, so the part of the list a client's AI clause most often asks about is missing, although the AI governance page is written as material a firm could hand to a client.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Most of the elements of a defensible record are published: written explanations for every determination, an audit trail with chronological version history for each document, a record of which decisions a person validated, precision, recall and F1 scores reported per project against a human-reviewed control set, and auto-generated privilege logs exported with the production. What is not recorded is which model produced which determination, so the export shows the review and its validation rather than the AI's own provenance.