Augmetec
Augmetec builds LEIAA, a command centre for internal and regulatory investigations. It is designed to hold a whole investigation in one place rather than across the spreadsheets, shared drives and mailboxes such work usually spreads into: case scoping, evidence management, interviews, analysis and reporting from inception through to the final report. The organising idea is the Line of Enquiry, the investigative question a team is actually pursuing, against which the platform automatically identifies relevant evidence, builds fact patterns and surfaces answers, with document fraud detection tools flagging material that has been altered. Around that sit smart actions that identify witnesses and prepare interview questions in real time, build chronologies and timelines of events, produce tagged and searchable notes, and suggest what the team should do next, plus automated evidence bundle creation and historical analysis that finds similarities with previous investigations the organisation has run. Case triage, scoping and categorisation are automated, and the platform ships with reusable templates, customisable workflows and dashboards. Customers get their own dedicated instance on its own subdomain rather than sharing one, with single sign-on and integrations into existing document management systems and the Microsoft and Google estates. Augmetec publishes its master services agreement and data processing addendum openly, including a full schedule of technical and organisational security measures. It is sold to law firms and to in-house legal, ethics and compliance functions, and the company was founded by an investigations lawyer alongside an operations leader and a machine learning technologist. Augmetec Limited is independent and based in London.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models drive several core capabilities and sit on an investigations platform that would work without any of them. The AI functions are named and specific on the platform page as modified in November 2025: identifying relevant evidence and building fact patterns against a Line of Enquiry using what the vendor calls accurate AI algorithms, document fraud detection, automatic identification of witnesses and preparation of interview questions, chronology building, and AI-driven triage, scoping and categorisation of cases. Underneath sits a full case management system that predates the models and delivers a great deal on its own: a centralised datalake, evidence management, reusable templates, customisable workflows, dashboards, collaboration, single sign-on, enterprise integrations and automated evidence bundle creation. Strip the models out and an investigations team still has a working command centre, which is what keeps this off the top band. The master services agreement reinforces the point by never mentioning artificial intelligence in its operative terms at all. Checked 5 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy and defensibility are the central promise and neither is measured. The platform page states that a team can answer questions defensibly, that investigations are conducted accurately and defensibly, and that evidence identification runs on accurate AI algorithms, alongside industry-leading document fraud detection. Not one of those claims carries a figure, a test set, an evaluation, an error rate or a statement of failure modes, and no accuracy or benchmark material appears anywhere on the estate. Nor is grounding described: nothing states whether a finding surfaced against a Line of Enquiry carries a link back to the document and page it came from, which is the control a reader would look for on a product whose output feeds regulatory reporting. The agreement is markedly more candid than the marketing and the gap is the finding: clause 2.5 has the customer acknowledge that the software may contain bugs, errors and other defects, may contain design flaws, and may produce unexpected results from its functionality. A product sold on defensibility and contracted for on an acknowledgement of unexpected results is exactly the marketing-against-agreement shape.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The level of automation is stated with unusual precision for one feature and no control structure is described anywhere. The platform page says case scoping is semi-automated, that smart actions suggest team actions to progress cases, and that witnesses are identified and interview questions prepared automatically in real time. Semi-automated and suggest are real words about where the machine stops, and they are why this is not the floor band. What is absent is everything around them: nothing states which outputs require review before use, what a reviewer sees, at what point the system acts without a person, what happens when a fraud detection flag is wrong, or whether generated material is marked as generated. No abstention behaviour or confidence signal is described. The agreement allocates the consequence without describing the mechanism, clause 10.2 providing that the customer assumes sole responsibility for results obtained from use of the software and for conclusions drawn from such use. On a product that prepares interview questions and identifies witnesses in a fraud or bribery investigation, the unstated review point is the live question.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
No production evidence was located. No customer is named anywhere on the estate, no logo wall appears, no case study exists, and no deployment is described or dated. The single customer voice is one unattributed sentence on the About page, carrying no name, role or organisation, saying that LEIAA is clearly built by practitioners for practitioners. Two figures are published on the platform page and neither is attributed or explained: administrative effort alleviated by up to 45 per cent, and the platform being up to 80 per cent cheaper than other platforms, the second being a competitive pricing claim rather than an outcome and naming no comparator. The founding team's own experience is set out in detail, including more than 150 investigations conducted by the chief executive before founding the company, which is credential rather than deployment evidence and is recorded as such. Searched the home, about, platform and security pages, the master services agreement and the site navigation on 5 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive contractual commitments, a rare express reference to privilege, and no privilege treatment as such. Clause 8.3 of the published master services agreement is the core: the customer retains full title to Customer Content, and without the customer's consent Augmetec will not access, use or disclose it except as reasonably necessary to support the customer's use of the software, respond to support requests, or for any other purpose authorised by the customer in writing. That is a closed purpose list rather than an open licence. Clause 8.4 permits collection of usage and performance data expressly excluding anything that could identify the customer or its own customers or that is confidential or privileged in nature, which names privilege directly. Clause 6 makes Customer Content the customer's confidential information under a five-year regime, and the addendum requires everyone processing the data to be under a strict duty of confidentiality. Separation is documented rather than claimed, with each customer on a dedicated instance and Annex II stating that segregation procedures prevent other customers from accessing customer data. What is missing is treatment rather than acknowledgement: nothing describes how privileged material is handled once inside, no matter-level walls within a customer are described, and no model provider is named.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Nothing published addresses the advice line. No statement that Augmetec is not a law firm, no disclaimer that output is not legal advice, no description of the professional judgement required before a finding is acted on, no jurisdiction limit and nothing on supervision or competence was located on the platform page, the about page, the security page or in the master services agreement, which is the natural home for such a clause and contains none. The nearest provision is clause 10.2, under which the customer assumes sole responsibility for results obtained and conclusions drawn, which allocates liability rather than describing what the product is not. The exposure is specific on this product class: the platform builds fact patterns, identifies witnesses, prepares interview questions and produces investigation reports in matters concerning fraud, bribery and improper conduct, where a conclusion carries consequences for named individuals. The terms of use page governing the website was not opened in this pass and is the rebuttal route.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
No governance position of any kind was located. There is no responsible AI page, no principles statement, no accountable owner or function named for model behaviour, no pre-release evaluation regime, no AI management system and no certification such as ISO 42001. Nothing addresses uneven output, and the omission has a sharp edge on this product: a system that identifies which individuals are witnesses, flags documents as fraudulent and builds fact patterns about alleged improper conduct is making determinations about named people, and nothing published describes how those determinations are tested or governed. The governance material that does exist is security governance and is credited on the stewardship row rather than counted twice, comprising an information governance committee and ISMS group, a dedicated person overseeing information security and compliance, and certified security staff. The chief security officer holds a doctorate in machine learning, which is a credential rather than a governance framework. Navigation and footer inventoried 5 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Among the most completely documented stewardship positions in this corpus, held off the top band by one absence. The published addendum's Annex II runs to several pages of specifics: AES-256 at storage system and storage device level with separately keyed backups, TLS 1.2 or greater in transit, VPN and multi-factor authentication, access control lists on a need-to-know basis with differentiated access profiles, automatic account locking and idle logout, network separation through a DMZ, a web application firewall, logging of access, modification, entry and deletion, intrusion detection, disaster recovery and continuity planning, physical security of data centres described down to visitor logging and video surveillance, an ISMS group and a named accountable security function, internal and external audits, penetration testing with triage and remediation, and a responsible disclosure programme. Incident practice is contractual rather than asserted: clause 2.13 commits to informing the customer of a security incident without undue delay and within 72 hours, with cooperation on the customer's own reporting duties. Deletion is addressed at clause 2.14, destroy or return on written instruction at termination. What is missing is a retention period: nothing states how long data is held while the agreement runs, only that it is retained as required to perform obligations.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A real two-sided position published in full, with a cap a buyer should read before signing. Clause 9.2 commits Augmetec to indemnify the customer against direct damages arising from third-party intellectual property infringement claims connected to use of the software, with a remedy ladder at 9.3 covering procurement of continued rights, replacement or modification on stated equivalence conditions. Clause 10.3 preserves liability for death or personal injury, fraud and wilful misconduct outside all caps. Against that, clause 10.1 provides the software as is with the customer assuming all associated liability, and clause 10.4 sets the ceiling at the lesser of one hundred per cent of a contract year's subscription fees or twenty thousand US dollars, with the intellectual property indemnity capped at the lesser of two hundred per cent or fifty thousand dollars. On an investigations platform sold to enterprises, twenty thousand dollars is a low absolute ceiling and it is the operative number for everything except the IP indemnity. The exclusions at 10.4 are also unusually pointed for this product, expressly excluding loss of privilege and loss of confidentiality. Nothing warrants the accuracy of any output.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integration is claimed as a core proposition and no counterparty is named. The platform page promises core enterprise integrations, single sign-on and secure integrations with existing platforms, document management systems, and Microsoft and Google, which identifies the productivity and identity estates by name and the document management layer only as a category. The agreement contemplates the mechanism at clause 4, covering third-party services the customer connects and single sign-on authentication, and confirms that connecting a service authorises Augmetec to access and store information from it. Nothing published states what data moves between LEIAA and any external system, in which direction, on what trigger, or what a firm must configure, and no API or developer documentation was located; the addendum's data description mentions material from Microsoft Teams, Slack, WhatsApp, Telegram, Amazon Chime and Google Meet, but as categories of personal data that may be uploaded rather than as connectors. A knowledge base exists on a third-party support platform and was not opened in this pass; it is named here as the limit.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The tenancy limb is answered more completely than on any other record in this pull, and the region limb is not answered at all. The security page states it plainly under its own heading, your LEIAA, your environment: each customer's instance is hosted on a separate, dedicated environment available only to and accessible by that customer, on a virtual private cloud architecture segregated for data isolation. The agreement repeats it at clause 10.1, that the instance allocated to a customer will be held on separate, dedicated infrastructure, and the software is defined as reached at a customer-specific subdomain of leiaa.com. Annex II adds that customer data is separated on their own instances with segregation procedures preventing access by other customers, and names Google Cloud Platform as the hosting infrastructure. Against that, no region is named anywhere. The virtual private cloud is described as a global network spanning multiple regions, which describes reach rather than residency, no region choice is offered, and no residency commitment appears in the agreement, though the addendum does carry full restricted-transfer machinery through the EU standard contractual clauses and the UK addendum.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Four certification marks displayed as images, no scope, no date, no auditor, no report, and an agreement that describes something weaker than the badges imply. The security page carries marks for ISO/IEC 27001:2022, HIPAA, GDPR compliance and an AICPA SOC logo, each an image with no accompanying text claiming certification, naming a certifying body or stating a period or scope, and one of the image filenames misspells the statute it refers to. Nothing in the page text asserts that any certification is held. The published agreement is more precise and points lower: Annex II lists regular benchmarking and testing with industry standards, giving ISO 27001, the SANS Top 20 controls and NIST guidelines as examples, and qualifies it as applying on certain systems. Benchmarking against a standard on certain systems is not certification to it, and a buyer reading the badge and then the annex would find two different propositions. A trust page exists at a published subdomain, named twice in the agreement as the location for backup and disaster recovery detail and for subprocessor change notices, and was not opened in this pass; it is the rebuttal route and the cheapest upgrade on this record.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The vendor refers to its algorithms and identifies nothing underneath them. The platform page speaks of accurate AI algorithms and AI-powered analytics, and the addendum's own definition of the services includes the development of future functions, features, tools, algorithms and models, so a model layer is acknowledged as existing. No model is named, no version, no provider and no hosting arrangement for the model layer, and no commitment to notify customers when any of it changes was located. Clause 2.4 concedes the shape of the gap without filling it, stating that the services may use technology and data licensed by Augmetec from third parties, sublicensed to the customer, and naming none of them. One infrastructure provider is named and is not a model: Google Cloud Platform, identified in Annex II as the hosting environment and as the source of the secret management service. The approved subprocessor list at Annex III is referenced in the agreement and fell outside the extraction window of the published PDF, so its contents are unread and nothing is inferred from them in either direction.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The unit and the commercial structure are established from the published agreement, and no figure appears anywhere. There is no pricing page in the site navigation and every route is a demo request. The agreement supplies the shape: the software is licensed under an Order Form as a Package with stated features and pricing, User Rights itemise the number of user licences and the software instance subscribed to, each authorised user holds a single non-shareable account, and the commitment runs across an Initial Term with defined Renewal Terms. A buyer can therefore establish that this is per-user licensing on a committed term with the package defined in an order form, and cannot establish any rate, band, minimum or implementation cost. One published number is a comparative claim rather than a price and is recorded as such: the platform page states that the product is up to eighty per cent cheaper than other platforms, naming no comparator and no basis. The floor band does not fit, because the unit of charge is published even though the price is not.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
The practice is defined with real precision and the buyer boundary is left open. What the product covers is stated repeatedly and consistently: internal and regulatory investigations end to end, from inception through scoping, evidence management, witness interviews and analysis to reporting, extending to ethics, compliance and regulatory reviews. The subject matter is evidenced rather than asserted, with the addendum's own data description naming identity documents, invoices, expense receipts, financial payment data and material from corporate and ephemeral messaging applications, and the founder's stated background covering fraud, money laundering, bribery and corruption. That is a clearer account of the work than most records in this lane manage. Users are addressed as law firms and in-house professionals, and beyond that nothing is stated: no firm or organisation size band, no jurisdiction despite an English-law agreement and a UK base, no statement of which investigation types or regulated sectors the product does not suit, and nothing on languages for a platform ingesting multilingual messaging data.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Training occurs only where the customer has affirmatively enabled it.
Use of customer content is contractually closed except with written authorisation, which is the opt-in shape rather than an outright prohibition. Clause 8.3 of the published master services agreement provides that without the customer's consent Augmetec will not access, use or disclose Customer Content except as reasonably necessary to support use of the software, respond to support requests, or for any other purpose authorised by the customer in writing. Training falls outside the first two limbs and would therefore require written authorisation. Clause 8.4 reinforces it, permitting collection of usage and performance data only where that information could not identify the customer or its customers and is not confidential or privileged in nature, and the addendum adds at clause 2.3 that in no event shall Augmetec process the data for its own purposes or those of any third party. One tension inside the same document is recorded rather than smoothed, because a careful reader will find it: Annex I lists the activities relevant to the transferred data as including development and enhancement of the services, expressly naming the research and development of additional algorithms and models, and the addendum defines the services to include continuous development of future models.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is acknowledged in public materials with no stated period.
Retention is addressed in the published addendum and no period is stated. Clause 2.14 provides that Augmetec retains data as required to perform its obligations under the agreement, and that on termination or expiry it shall, on the customer's written instruction, destroy or make available for retrieval all data including all copies in its possession or control and any subcontracted for processing, with an exception where law requires retention, in which case the data is isolated and protected from further processing until deletion is possible. That is a clear end-state with a customer instruction behind it and no clock attached to the relationship itself. Annex I states the period as the duration of the agreement and refers back to clause 2.14. Nothing separately addresses how long generated material persists, including chronologies, fact patterns, prepared interview questions or fraud detection outputs. Annex II records that published retention policies exist providing guidance on how long data should be kept accessible; those policies were not located on the estate.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
A separation model is documented at architecture level rather than asserted as a claim. Annex II to the published addendum states that customer data is separated on their own instances, that access is available only to authorised users with strong segregation procedures in place, and that these prevent other customers from having access to customer data. The security page describes the same arrangement in product terms, each customer's instance hosted on a separate dedicated environment accessible only to that customer under a virtual private cloud architecture, and clause 10.1 of the agreement confirms dedicated infrastructure, with the software reached at a customer-specific subdomain. Inside a customer, Annex II adds differentiated rights by security group and access control list on a need-to-know basis, with logging of access, modification, entry and deletion. What is not addressed is the level a conflicted matter would need: nothing describes walls between investigation teams within one organisation, which is a live question where an investigation concerns the conduct of colleagues who may also be users.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Terms commit to notice where lawfully permitted. No transparency report located.
A notice commitment exists in the published addendum, and the main agreement's compelled-disclosure clause runs the other way, which a buyer should see. Clause 2.10 of the addendum requires Augmetec to provide reasonable and timely assistance in responding to any request from a data subject and to any other correspondence, enquiry or complaint received from a data subject, regulator or other third party in connection with the processing, and provides that where any such request is made directly to Augmetec it shall promptly inform the customer with full details. That reaches requests from regulators and third parties about customer data. The asymmetry is recorded because it is striking: clause 6.2 of the main agreement, headed mandatory disclosure, imposes the notice obligation on the customer, requiring the customer to give Augmetec as much notice as possible before disclosing Augmetec's confidential information under compulsion, and no reciprocal clause obliges Augmetec to notify before disclosing the customer's. No transparency report is published.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
No corpus stands behind the product's output and the question does not bite on this product class. The material the models work on is the organisation's own investigation dataset, described in the addendum as documents, contracts, invoices, expense receipts, identity documents, financial payment data and messages from corporate and ephemeral messaging applications, all uploaded by the customer. There is no case law database, statutory source, publisher or licensed reference set behind a finding, and the historical analysis feature compares against the customer's own previous investigations rather than any external body. One clause is recorded because it is the only reference to licensed external material and names nothing: clause 2.4 states that the services may use technology and data licensed by Augmetec from third parties, sublicensed to the customer, without identifying any provider or the nature of the data. Searched the platform page, the about and security pages and the master services agreement including both annexes reached on 5 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Nothing addresses checking authority for subsequent history, and the product neither retrieves nor cites primary law. Its outputs are evidence identifications, fact patterns, chronologies, interview questions, fraud detection flags, investigation plans and reports, all drawn from the customer's own material. The nearest adjacent question is regulatory currency rather than case law, since the platform is sold for regulatory investigations and reviews and a regulatory obligation can change, and nothing published describes whether any regulatory content is maintained or checked; that is recorded here so a reader sees it was considered rather than missed. The value is the honest absence rather than a finding against the vendor. Searched the platform, about and security pages and the published agreement on 5 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
No material describes what the system does when it cannot reach a reliable output, and the one candid statement on the subject is a liability acknowledgement rather than a behaviour. Clause 2.5 of the agreement has the customer acknowledge that the software may contain bugs, errors and other defects affecting performance, may contain design flaws or other issues, and may result in unexpected results generated from its functionality. That is an unusually direct admission for a published agreement and it describes the possibility of failure rather than how the system signals or handles it. Nothing states whether a fraud detection flag carries a confidence level, whether an evidence identification against a Line of Enquiry can return nothing, what happens when a document is unreadable or a fact pattern cannot be built, or whether generated interview questions are marked as machine-suggested. No abstention path or confidence indicator is described anywhere. Searched the platform page, the security page and the published agreement on 5 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
The AI Hallucination Cases database maintained by Damien Charlotin was searched on 5 September 2026 on the product name LEIAA and on the corporate name Augmetec. No court order, opinion or disciplinary record naming the product or the company was located. One point of context is recorded rather than left implicit: this tracker records hallucinated content in court filings, and the product's primary output is an internal or regulatory investigation report rather than a filing, so a negative result here covers less of this product's risk surface than it would for a drafting or research tool. This records the state of the public record on that date and is not a finding about the product.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No located material engages with bar or ethics guidance at any level. No bar association, law society, rule of professional conduct, ethics opinion or regulator guidance for lawyers is named or referred to in general terms, and nothing addresses the professional obligations of a solicitor or in-house counsel conducting an investigation through the platform. Nor is there any adjacent statement of the sort that usually accompanies one, since no advice disclaimer and no statement that the company is not a law firm was located either. The regulatory material the vendor does engage with is extensive and sits in a different field, covering UK and EU data protection law, standard contractual clauses and the UK international data transfer addendum. That is notable on a product built and sold by an investigations lawyer to law firms and in-house legal functions. Searched the platform, about and security pages and the published agreement on 5 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure, and the product sits inside a fee relationship between a lawyer and a client where those savings would change the bill.
Efficiency and cost claims are published with figures and nothing addresses the billing consequence. The platform page states that administrative effort is alleviated by up to 45 per cent, that fact-finding timescales are reduced, that time-consuming tasks are automated to free time for analysis and strategy, and that the platform is up to 80 per cent cheaper than other platforms. All of that is directed at the buyer's own cost and capacity. Nothing reaches this signal: no per-matter record of AI-assisted work is described as available, no guidance on fee or disclosure treatment is published, and nothing addresses what a client is told when an investigation report supporting a regulatory response was produced with automated evidence identification and machine-prepared interview questions. The direction is worth recording because one of the two named buyer types is law firms conducting investigations for clients, so the compression falls directly on billable investigative work.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
A published subprocessor regime with real customer rights, and no model provider named in anything read. Clause 2.9 of the addendum requires that Augmetec not subcontract processing without consent, gives at least thirty days prior notice of any addition or removal with details of the processing, publishes those changes at a stated trust subdomain, imposes equivalent data protection terms on subprocessors with the customer as third-party beneficiary, keeps Augmetec fully liable for subprocessor acts, and gives the customer a right to object on reasonable grounds with termination without penalty if no solution is reached. A list of approved subprocessors is stated to be attached at Annex III. Two limits belong on the record. The Annex III list fell outside the extraction window of the published PDF on 5 September 2026, so no subprocessor is named in this note and none is credited. And no artificial intelligence or model provider is identified anywhere in the material read, so a firm could forward a strong governance regime and still not tell a client whose model processed its investigation.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located public material addresses court disclosure or verification certification.
Evidence provenance is well handled and model provenance is not addressed at all. The product is sold on defensibility and the supporting mechanisms are real: automated evidence bundle creation, a centralised datalake holding the whole investigative dataset, notes tagged and stored, chronologies and timelines built from the record, and Annex II committing to logging of data access, modification, entry and deletion together with authentication logging and monitored system access. A team could therefore show what evidence was held, who touched it and when. None of that reaches this signal, which asks for a record of the AI's own contribution: nothing identifies which model or version produced an evidence identification, a fact pattern or a fraud detection flag, nothing marks generated interview questions or report content as machine-produced, and no export is described for producing such a record to a regulator, a court or a client. No disclosure template or guidance is published, and the agreement does not address it.