B
BRYTER

BRYTER sells two things that are designed to work together: a no-code automation platform for legal and compliance teams, and BEAMON AI, an artificial intelligence suite for lawyers that the company markets on its own domain and prices separately. The platform, BRYTER Workflows, is the older half and was the whole company from 2018. It lets legal engineers build applications without writing code, covering approval workflows and risk assessment, legal intake and triage, client portals and legal front doors that connect to Microsoft Teams, Slack and email, document automation, red-flag contract review, mass claims handling and compliance tools, with a rules engine that executes the process end to end.

BEAMON AI is the newer half and comprises three named products. Assist is a chat assistant that drafts from templates, summarises contracts and legal documents, compares contracts against playbooks and benchmarks clauses, translates, and answers from a firm's own knowledge bank. Extract reviews and extracts structured data across large document sets for real estate and M&A due diligence, employment and commercial contract review, regulatory reviews including DORA and the EU AI Act, and contract remediation, exporting to Excel or feeding the extracted data into workflows.

A Word add-in brings drafting, editing and redlining into Microsoft Word. Above them sit Hybrid Agents, packaged combinations of AI and workflow aimed at specific jobs including claims processing, file-to-timeline conversion, court document handling, billing guideline review and ISDA review. The published use-case library runs to around twenty tasks from clause extraction to horizon scanning. BEAMON AI is sold at three published per-user tiers with a self-serve free trial, while Workflows is quoted.

Integrations include SharePoint, Salesforce, DocuSign, iManage, DeepL and the Otto Schmidt legal database, alongside an open API. Customers named by the company include Linklaters, Ashurst, Hausfeld, Deloitte, PwC, KPMG, McDonald's, ING Bank, Rakuten and Telefónica. BRYTER GmbH was founded in 2018, contracts from Frankfurt am Main under German law, and operates from Frankfurt, London and New York. In Austria it works with the national bar association, the Österreichischer Rechtsanwaltskammertag, on access to AI for its members.

Vendor siteFrankfurt am Main, GermanyFounded 2018
Last verifiedSeptember 12, 2026
Compare with other vendors

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The models are the engine of a core capability layered on a platform that would still function without them, which is the B band, and the vendor's own architecture says so. BRYTER's formula is stated on every page as the power of AI with the precision of workflows, and it names two halves. BRYTER Workflows is a rules-based no-code automation platform that was the entire company from 2018 and still sells on its own, covering intake and triage, approval workflows, document automation, client portals and compliance tools; strip the AI out and it remains a complete product.

BEAMON AI is the AI half and it is substantial rather than decorative: three named products in Assist, Extract and a Word add-in, its own domain, its own three-tier price list, its own free trial, and its own place in the master agreement's definition of the Software. What keeps this off A is that the record is BRYTER and BRYTER is both halves. The strongest argument the other way is recorded rather than suppressed: BEAMON AI is separately purchasable at published per-user rates and a buyer can acquire the AI without the workflow platform, which on a narrower record definition would read as the model being the product.

On the record as scoped, the honest reading is a rules engine with an AI suite bolted alongside it and increasingly through it, which is what the B band describes. Verified 12 September 2026.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Grounding is real and documented and no accuracy figure is published, which is the B band. What is documented: hallucination control and references are named as product capabilities; summaries are described as source-linked with citations kept attached and the level of detail selectable; Assist is described as returning verified answers based on the customer's own knowledge bank and playbooks; and the retrieval surfaces are named rather than implied, with a web search processor identified in the sub-processor schedule and a direct API integration to the Otto Schmidt legal database for research on the top tier.

The agreement adds a disclosure that is rare and worth quoting in substance: it states that the accuracy and reliability of Output may be affected where features such as web search or access to legal sources are not enabled, that in those cases the service is more likely to produce inaccuracies, and that the vendor therefore recommends enabling them. That is a vendor telling a buyer the conditions under which its own product gets worse.

What holds it off A is measurement. No accuracy figure, error rate, test set or evaluation is published anywhere, and the one comparative claim is unquantified marketing, that the proprietary AI outmatches generic tools like ChatGPT or Copilot on answer quality and accuracy. The agreement is markedly less confident than that page, stating that the vendor does not guarantee Output is accurate, complete, original, fair, unbiased or free from errors. R37 rule 1 gives it to the agreement and the gap is recorded here. Verified 12 September 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

A written commitment that the models work alongside a supervising lawyer, with real controls, short of the full structure, which is the B band. The commitment is contractual and stated three times over. The agreement provides that the customer is responsible for reviewing and validating all results before relying on them for business, legal or other decisions; that use of Output without proper human oversight, especially for decision-making or compliance, is at the customer's own risk; and that Output must be verified and validated prior to any use.

A fourth clause bars the customer from misleading any person that Output is human generated, which is an oversight provision pointed at the reader of the output rather than its author. The genuine control, and the best of them, is model governance rather than task governance: an administrator determines which language models are enabled for the tenant and may disable any of them at any time, and within that set the author selects the model for each individual input, with both selections expressly constituting instructions under the data processing addendum.

In the delivery state only the default model is enabled and no customer data reaches any other provider until an administrator turns it on. Access is role-restricted, actions are logged and changes traceable. R124(2) decides the ceiling. Nothing here attaches a boundary to a named tier and states what that tier's output may not be used for; what is published is a general assurance of human review, however carefully drafted, plus a model-enablement control. Verified 12 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Named customers in unusual quality and no figures attached to any of them, which is the B band. The naming is specific and spans three buyer types that rarely appear together: global law firms in Linklaters, Ashurst and Hausfeld; professional services firms in Deloitte, PwC and KPMG; and corporate legal departments at McDonald's, ING Bank, Rakuten and Telefonica. A published customer story covers the Telefonica legal team, and one attributed testimonial carries a named individual with title and firm, a counsel and AI expert at REIUS.

For a vendor of this size that is a strong reference base and it is treated as attribution rather than outcome. What is absent is measurement. Not one figure is attached to a named customer on the surfaces read, nothing is dated to a deployment, and the benefit claims are generic, saving hundreds of hours reviewing contracts for key clauses and freeing teams from repetitive work, with no basis, population or period given.

Nothing published measures BEAMON AI specifically as against the workflow platform, which matters because the AI is what is being graded. Two artifacts are named and not opened under R25, each corroborating rather than carrying this grade: the customer stories library and the guides and reports section, and they are what would move this row if any study carries a dated figure with a stated method. Verified 12 September 2026.

Source: Vendor Published
AA on Privilege and Confidentiality PostureWritten commitments a buyer can read before signing: no training on client data, segregation documented at the level the buyer segment requires (matter level walls for a firm, tenant level separation for an in house team), privilege and work product handling addressed directly, retention and deletion stated, and the position on third party model providers made explicit.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

All five limbs are met in instruments a buyer can read before signing, and the limb R33 makes decisive is met more substantively than on any record in this corpus. Privilege and professional secrecy: the data processing addendum carries a dedicated section on the processor's obligation to maintain professional secrecy, which applies wherever the customer is subject to such duties, and which provides that the processor shall treat all data as potentially subject to professional secrecy obligations unless clearly determined otherwise, shall obtain knowledge of professional secrets only to the extent strictly necessary, with obtaining knowledge expressly defined to include any technical or organisational access regardless of whether human review occurs, shall keep them strictly confidential, may disclose them to sub-processors only where those sub-processors are contractually barred from onward disclosure and must flow the obligation down, and shall ensure its own personnel undertake in writing not to disclose them.

Alongside it the vendor states compliance with the German professional rules and the criminal professional-secrecy provision, and states that it upholds attorney-client privilege. Training: prohibited contractually. Retention and deletion: a retention table by data category, deletion or return at the customer's choice on termination, and a bounded backup window. Third-party model provider: the providers are named with their processing locations and the default model's processing is stated to occur in the European Union.

Segregation: tenant separation and a role concept documented in the technical and organisational measures. Recorded against it, because a reader should weigh both: the master agreement separately makes the customer solely responsible for ensuring that any Input complies with privilege and professional secrecy obligations, so the vendor undertakes to protect the material and disclaims liability for the decision to submit it. Verified 12 September 2026.

Source: Vendor Published
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

A real position on advice versus tooling, published contractually and reaching into supervision, short of A on jurisdiction. What is published: the agreement states in terms that Output shall not be viewed as legal advice, that BRYTER is not a law firm, does not practise law and does not give legal advice, and that it bears no legal responsibility for Output or anything derived from it. The usage restrictions add two provisions most records lack, a bar on misleading any person that Output is human generated, and a bar on offering tailored financial advice without a qualified person reviewing the information, which is the supervision idea applied to an adjacent regulated activity.

Supervision of the legal output itself is addressed through the review and validation obligations graded on the autonomy row. Beyond the agreement the vendor engages professional conduct directly in at least two jurisdictions, mapping the AI suite to named Austrian provisions and stating compliance with the German professional rules and the criminal professional-secrecy provision, which is graded on the bar guidance signal.

What holds it off A is that jurisdiction limits are not stated. Nothing tells a buyer where the product may or may not be used, which is a live question for a German-contracting vendor selling in the United States through a separate entity, operating in at least three language markets, and publishing bespoke supplementary terms for Austrian and Swiss professional-secrecy holders without stating what that implies for anyone else.

Nor is who may operate the tool addressed beyond the licensing concepts of Authorized User and Author. Verified 12 September 2026.

Source: Vendor Published
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

A published governance framework with real substance, short of testing results and a named owner, which is the B band. What lifts it well clear of a principles page is that the framework is contractual. The master agreement carries a dedicated AI Terms section governing every feature enabled by machine learning or other AI functionality, and that section does governance work rather than risk-shifting alone: it prohibits training on customer content, it governs model selection and model change, it requires human oversight, and it sets out an acceptable-use regime barring generation of hateful, harassing or violent content, exploitation of children, self-harm encouragement, misuse of personal data, malware, high-risk economic harm, health advice, political campaigning and lobbying, and use that infringes privacy or confidentiality.

The bias limb is addressed expressly and in the agreement rather than in marketing, the customer acknowledging that Output may reflect or amplify biases inherent in training data and undertaking to verify and validate all Output before use. That is a vendor putting the bias risk on the face of the contract. Around it sits real organisational governance, an ISO 27001:2022 certification, a data protection management system with reporting lines to senior management, records of processing under Article 30, privacy-by-design training for product teams, and internal and external audits.

What A asks for is still absent. Nobody is named as accountable for AI, nothing describes what is evaluated before a model or feature ships, no testing results are disclosed, and the bias acknowledgement is a warning rather than a mitigation. R124(3) is not the binding constraint here, because this framework governs the vendor's own conduct as well as the customer's, but the vendor-side testing limb is what separates this from A. Verified 12 September 2026.

Source: Vendor Published
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Every limb this band asks for is published, and the sub-processor limb, which most records fail, is answered in a table. Retention is stated by data category rather than in general terms: security and audit logs up to ninety days, contact, credential and customer content until termination and then deletion under the addendum's deletion clause, and backup copies for a bounded thirty days thereafter. Deletion is a commitment with a choice attached, the processor deleting or returning and deleting all personal data and processing results at the controller's election on termination, alongside a switching and porting right under the EU Data Act with a documented technical process.

Access control is documented control by control across twelve headings covering physical access, user and data access, separation, pseudonymisation and encryption, input control, order control, transmission, availability, resilience, security management, purpose limitation and data protection management. Sub-processors are named individually with service, corporate location and server location, and changes require prior written notice with a twenty business day objection right.

Incident practice is specific: notification without undue delay and where feasible within seventy-two hours, with the four contents of that notice enumerated, plus tested business continuity, incident response and disaster recovery plans. Two disclosures are unusually candid and belong on the record rather than being smoothed over: the addendum discloses monitoring of AI-powered processing described as LLM observability, and discloses that the provider of the selected language model performs automated screening of inputs and outputs against its own usage terms with case-by-case human review of flagged content. Verified 12 September 2026.

Source: Vendor Published
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

A real published position on liability, short of the full picture, which is the B band, and it is better than most records reach because it contains actual warranties rather than only exclusions. The vendor warrants that it has power to grant the rights, that the Software will be provided with reasonable skill and care and in compliance with applicable laws, that it will materially conform to the Documentation and the Order, and that it will not materially decrease functionality during the term, with a remedy of prompt correction or an alternative means of performing the task.

There is an uptime commitment with a support and maintenance appendix behind it, and published support response targets of forty-eight hours standard and twenty-four hours on the top tier. The liability regime is German-law shaped and therefore more favourable at the top than an American cap: unlimited liability for intent, gross negligence and injury to life, body or health, with slight negligence limited to breaches of material contractual obligations and capped at the fees payable for the current subscription period.

What holds it off A, and the note names it plainly because it is the crux, is that the AI is carved out of the strongest protections. The agreement states that the support and maintenance services apply to the AI Service only to the extent that it may suffer downtime, interruptions and errors without any guaranteed response or resolution time, and separately that the vendor does not warrant the availability, accuracy or completeness of results delivered through credit-based features.

So the uptime commitment covers the platform and expressly not the models. No indemnity running to the customer was located, no insurance position is published, and the only indemnities run the other way. Verified 12 September 2026.

Source: Vendor Published
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Real integrations, named individually across several classes, with conditions published, short of documentation an implementer could work from. The catalogue is broad and specific. Document and knowledge systems: iManage and SharePoint, described as connecting repositories so the right precedents appear in context. Business systems: Salesforce and DocuSign. Collaboration: Microsoft Teams, Slack and email as intake channels into the legal front door.

Authoring: a Microsoft Word add-in for drafting, editing and redlining, sold as a named product. Publishers and data: a direct API integration to the Otto Schmidt legal database, Haufe Lexware, the Winsolvenz insolvency product via Septeo, and Handelsregister company data via Company.info. Language: DeepL, which also appears in the sub-processor schedule with its processing locations. Platform: BRYTER Connect and an open API, with published API terms of use, a licence to build against the API, software development kits and code samples, and a stated ability to trigger modules from a third-party system and export data to an internal dashboard.

Commercial conditions are published per connector on the pricing table, which is better than most records manage, stating which integrations require the customer's own subscription to the third party and which are purchasable add-ons. What holds it off A is documentation depth: no public API reference or connector register was located, the help centre was not opened, and for most connectors nothing states what objects move in which direction or what configuration a firm must perform. Verified 12 September 2026.

Source: Vendor Published
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Real residency detail is published, in more depth than almost any record in this corpus, and the vendor's own documents contradict each other twice on the central fact, which is what holds this at B rather than A. What is published: hosting in the EU stated on the pricing table for every tier; a sub-processor schedule giving a server location for each named party, with cloud hosting in Frankfurt, the default language model hosted by Microsoft Azure in the European Union, and other locations named individually; and a clause stating that in the delivery state only the default model is enabled, whose processing takes place within the European Union, and that until an administrator enables another model no customer data is transferred to that model provider.

Tenancy is addressed through the Tenant concept used throughout the agreement and through documented separation of customer data into separate systems. That is a buyer being told both where the data sits and where inference happens, which is the distinction most records never draw. The two contradictions are recorded under R37 rule 2 and neither is resolved in the vendor's favour. First, within the data processing addendum, the sub-processor schedule gives server locations in Frankfurt, the EU, Sweden and the Netherlands, while the technical and organisational measures schedule in the same document states that all personal data is stored and processed in United States data centres of AWS and Microsoft Azure.

Second, the security page states that customer data, prompts and outputs are never shared outside the EU and EEA, while the same schedule lists an optional language model provider and a web search processor with server locations in the USA. A buyer cannot reconcile these from what is published. Verified 12 September 2026.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Certification is real, current and named to the standard's own version, and the route to the evidence is broken, which holds this at B. The claims are made first-party in two places, on the pricing comparison table against every tier and again on the security page, and they are specific: SOC 2 Type II and ISO/IEC 27001:2022, the latter named with its version year rather than as a bare standard number. The data processing addendum corroborates from a different angle, recording internal and external ISO 27001 audits under its security management measures and setting out twelve headings of technical and organisational measures in detail, and it separately names the certifications held by the two cloud sub-processors.

C does not fire: these are explained claims in the vendor's own voice sitting on top of a documented control set, not badges. What is missing for A is the evidentiary apparatus and, concretely, a working route to it. No auditor is named, no report period or observation window is published, no certificate or report number appears, and the trust centre was not reached. The access flow could not be graded under R5 because of a published-surface defect recorded here as a finding about the vendor rather than a limit on this index: the pricing table links a trust centre at trust.bryter.io, which returns a 404, while the security page links trust.bryter.com.

The working address was identified and not opened, and it is named as the artifact that would move this row. Verified 12 September 2026.

Source: Vendor Published
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The supply chain is partly disclosed, and the part that is disclosed is stronger than any record so far, which is B by design on this band. Providers are named, in the agreement and in the sub-processor schedule: Microsoft Azure is identified as the cloud server and host of the default language model used within the AI suite, Anthropic Ireland is identified as an optional language model engaged only upon enablement by a customer administrator, a web search processor is named for the AI suite, and the usage restrictions separately name OpenAI and Azure OpenAI among the third parties involved in providing the AI Service.

Each is given a corporate location and a server location. Change notification exists and is a real mechanism rather than a promise: prior written notice before any addition or replacement of a sub-processor, with a twenty business day objection right on materially important grounds and a defined consequence if the objection stands. Customer control over which provider processes what is documented at two levels, administrator enablement per tenant and author selection per input.

R34 decides the ceiling and it is applied strictly here because the temptation to round up is real. The A band requires that the models underneath are named and their providers identified as separate limbs, and no model is named anywhere: the pricing table says only that available models are updated continuously, and the agreement states that the vendor may add, replace, upgrade or discontinue underlying models at any time and that the customer has no claim to the availability of any specific model or model version.

A buyer knows whose infrastructure runs the inference and does not know which model is answering. Verified 12 September 2026.

Source: Vendor Published
AA on Commercial TransparencyA buyer can learn what this costs without entering a sales process: published rates, the unit being charged, and what implementation adds.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

A buyer can price the AI suite to the euro without speaking to anyone, and can then read the commercial mechanics that will govern the contract, which is the A band met twice over. Rates, per user per month: Single at 99 euros annual or 118 euros monthly, for solo practitioners without team collaboration; Team at 149 euros annual or 176 euros monthly, adding shared projects, documents and grids with a central prompt library; Pro at 199 euros annual or 234 euros monthly, adding workflow automation, single sign-on, integrations and priority support.

Both billing cadences are shown side by side so the annual discount is calculable. Structure sits underneath in a comparison table of roughly eighteen rows across core AI features, enterprise features, integrations and publishers, and compliance and support, and it is unusually honest at the edges, marking which integrations require the customer's own third-party subscription and which are purchasable add-ons. The purchase path is genuinely self-serve, with a free trial and sign-up rather than a demo request, and a published set of purchase terms for buying through Stripe.

What is rarer still is that the agreement publishes the mechanics a buyer normally discovers later: annual invoicing in advance, an uplift capped at ten per cent a year, ninety days' notice and a termination right for renewal-term fee changes, thirty days' notice for credit rate changes, a monthly credit cap with non-rollover and forfeiture, a stated token consumption limit with notification at eighty per cent, thirty-day payment terms and the interest rate on late payment.

Two limits are recorded and neither displaces the grade: BRYTER Workflows is not priced publicly and is quoted, and premium model access may carry additional fees set in the Order. Verified 12 September 2026.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Coverage is documented with real substance across segments and tasks, short of the stated limits the A band asks for. Segments are addressed on surfaces of their own rather than in a list: a Law Firms solution area and a Corporate Legal solution area, each with its own landing page and its own named use cases, and the customer roster demonstrates all three of the buyer types claimed, global law firms, professional services firms and corporate legal departments.

Firm size is addressed through the pricing tiers, which are described by the shape of the practice rather than by seat count, the entry tier stated to be for solo practitioners and expressly without team collaboration features, the middle tier for teams needing shared projects and a prompt library, and the top tier for firms and legal departments needing a full enterprise environment. Task coverage is the strongest part and is enumerated rather than asserted, a published use-case library of around twenty items running from clause extraction and contract review to due diligence, discovery summarisation, litigation and matter summary, horizon scanning, invoice summarisation, redlining and NDA generation.

Jurisdictional reach is evidenced indirectly but concretely, through English, German and Spanish estates, German and Austrian legal database integrations, and bespoke supplementary terms for Austrian and Swiss professional-secrecy holders. What holds it off A is that the limits are not stated. Nothing identifies a practice area or a firm type the product is not for, nothing addresses government use, and the jurisdictional position is left to be inferred from which language sites and which national integrations exist rather than being written down. Verified 12 September 2026.

Source: Vendor Published
Sources on file

6 public documents

The public pages on file for BRYTER, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.

Pricing

From €99 per user per month on an annual planEUR, as published, never converted

  • BRYTER publishes what its AI costs, in euros, with both the monthly and the annual price side by side so you can work out the discount yourself. That is still unusual in this market.
  • There are three tiers, all per person per month. Single is 99 euros on an annual plan or 118 euros month to month, and it is only for solo practitioners, with no team collaboration. Team is 149 euros annual or 176 euros monthly, and adds shared projects, documents and a central prompt library. Pro is 199 euros annual or 234 euros monthly, and adds workflow automation, single sign-on, integrations and faster support.
  • You can start a free trial and sign up yourself rather than booking a demo, and there is a route to buy through Stripe.
  • Two things to watch. Several of the integrations need you to already pay someone else: the Otto Schmidt legal database and Haufe both require your own subscription, and company register data and DeepL translation are paid add-ons. And this price list covers the AI suite only. If you want BRYTER Workflows, the no-code automation platform, there is no published price and you will be quoted.
  • The contract is more informative than most. It caps annual price rises at 10 per cent, gives you 90 days' notice and a right to leave if fees change at renewal, and tells you the usage limits before you hit them.

Three published tiers for BEAMON AI, priced per user per month in euros, with monthly and annual rates both shown. Single at 99 euros annual or 118 euros monthly, stated to be only for solo practitioners and without team collaboration features. Team at 149 euros annual or 176 euros monthly, for legal teams requiring shared projects, documents and grids with a central prompt library. Pro at 199 euros annual or 234 euros monthly, for firms and legal departments needing a full enterprise environment with workflow automation, integrations and priority support.

Every tier includes unlimited AI chats, the Assist assistant, the Word add-in, Extract document review and continuously updated available models; Team adds shared profiles and the prompt library; Pro adds published workflows, single sign-on and the Otto Schmidt API. The comparison table runs to roughly eighteen rows across core AI features, enterprise features, integrations and publishers, and compliance and support, and states the commercial condition attached to each integration: Otto Schmidt and Haufe Lexware require the customer's own subscription, Winsolvenz requires a Septeo subscription, and Handelsregister company data and DeepL translation are purchasable add-ons.

Support response is published as a service level, forty-eight hours standard and twenty-four hours on Pro. Purchase is self-serve, with a free trial and sign-up rather than a demo gate, and a published set of terms for buying through Stripe. The master agreement publishes the mechanics that usually surface only in negotiation: fees invoiced annually in advance; an annual uplift permitted only in good faith, proportionate to cost increases, and capped at ten per cent; ninety days' prior notice and a customer termination right for fee or usage-limit changes taking effect at renewal; thirty days' notice for changes to credit consumption rates; a monthly credit cap for credit-based features with unused credits forfeited at month end and suspension on exhaustion; a consumption limit of ten million tokens per tenant per month for AI connectors with notification at eighty per cent; thirty-day payment terms with interest at six per cent per annum; and ninety days' notice to terminate before a renewal term. A status discount tied to bar association membership is named.

Confidentiality and data terms: No business associate agreement is offered and none would be expected: this is a German-contracting vendor selling to legal and compliance teams in Europe and the United States, and HIPAA is addressed nowhere on either estate. What stands in its place is a fuller European instrument set than any record in this corpus, and it is published rather than offered on request. Data processing addenda exist in two regional versions, Germany and EMEA and a separate United States version contracted through BRYTER US Inc., each versioned in parallel with the master agreement and each carrying a sub-processor schedule with server locations and a twelve-heading schedule of technical and organisational measures. A CCPA addendum is published for United States customers. The addendum carries a dedicated professional secrecy section for customers subject to statutory confidentiality duties, expressly extending to legal, tax and healthcare professionals, which is the nearest functional analogue to a BAA on this estate and is graded on the privilege row. Certifications claimed first-party are SOC 2 Type II and ISO/IEC 27001:2022; no auditor, report period or certificate number is published and the trust centre was not opened.

Note: Figures and tier contents read directly from the vendor's own pricing comparison table on 12 September 2026, published ungated at beamon.ai/pricing and reached through bryter.com/pricing/aisuite/; page last modified 4 September 2026. Commercial mechanics read from the Master Service Agreement (German law) version 11.0, August 2026, read in full, which the vendor publishes with a version history of seventeen versions back to November 2022 and a downloadable PDF. All figures are euro and entryPriceCurrency is set accordingly; entryPriceUsd carries the numeral 99, the lowest published paid rate, being the annual-plan Single tier at 99 euros per user per month, with entryPriceDisplay carrying the figure and its condition only per R10 and R19. Third-party aggregator figures quoting the same tiers in US dollars were located and are expressly not used, first-party or nothing. Two scope limits are recorded rather than smoothed over. These rates price BEAMON AI, the artificial intelligence suite, and BRYTER Workflows, the no-code automation platform, is not priced publicly at all; a buyer wanting the workflow engine is quoted. And the agreement provides that premium models may carry additional fees or usage limitations set in the Order, the pricing page or the documentation, so the top of the range is not fully knowable in advance. The vendor's own footnote is recorded because it is honest and unusual: the table is stated to be for overview purposes only, with the exact scope of services governed by the published BEAMON Service Description.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Never, in the contract

The published terms prohibit training on customer content. Not a policy page, the agreement.

The prohibition is in the master agreement, in a dedicated AI Terms section, under a heading that states the position before the clause does: Customer Input will not be used for AI Training. The operative words are that BRYTER does not use Customer Content to train the machine learning models, and that the customer's use of the AI Service does not grant BRYTER any right or licence to the Customer Content to train machine learning models.

The second limb matters as much as the first, because it forecloses the licence route rather than only the practice, and it sits against a separate clause granting BRYTER a licence to use and create derivative works of Customer Data solely in connection with providing the software, which is therefore expressly not a training licence. The commitment is repeated outside the agreement, on the pricing comparison table against every tier as we never train models on customer data, and on the security page as customer data, prompts and outputs are never used to train AI models.

R43(1) is discharged: the agreement exists, is published, is versioned, and says the same thing as the marketing. One carve-out is recorded because it is the only one: the vendor may use data collected from the customer's use of the AI Service where the customer volunteers feedback or gives permission. Two further facts belong on the record without displacing the value. The customer is separately barred from using the AI Service to develop competing foundation models.

And the data processing addendum discloses that the provider of the selected language model performs automated screening of inputs and outputs against its own usage terms, with case-by-case human review of flagged content, which is not training but does mean a third party may read customer content.

Source: Vendor PublishedBRYTER does not use Customer Content to train the machine learning modelsAs of Sep 12, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Disclosed fixed window

A specific retention period is published and the customer cannot change it.

Retention is stated as a period, and stated category by category rather than in one sentence, which is this value. The data processing addendum carries a table setting out, for each type of data, the purpose and the duration: contact and account data and authentication credentials until termination of the agreement; network and device identifiers, log files and audit trails for up to ninety days where applicable and otherwise until termination; and customer-provided and derived content, which the table expressly defines to include uploaded documents, free text, extracted fields and structured content, and AI output to the extent it contains personal data, until termination and then deletion under the addendum's deletion clause.

Deletion is then specified rather than left open: on termination the processor deletes, or returns and deletes, all personal data and processing results at the controller's choice, with backup copies permitted for a bounded thirty days and remaining subject to the addendum during that period. So a buyer can trace a prompt from submission to deletion. Two disclosures in the same table are unusually candid and are recorded because they qualify what retention means here: the stated purposes include quality assurance, error analysis and monitoring of AI-powered processing, described in terms as LLM observability; and automated screening of inputs and outputs by the provider of the selected language model for violations of its usage terms, with case-by-case review of flagged content by that provider. What is not published is any shorter, AI-specific window at the model layer of the kind some vendors state.

Source: Vendor PublishedFor security/audit logs up to 90 days where applicable, otherwise until termination of MSAAs of Sep 12, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Own model, documented

The product maintains its own permission model, documented, requiring the firm to keep it aligned.

The product maintains its own permission model and documents it, which is this value. The documentation is in the technical and organisational measures rather than in marketing, and it is specific. A separation control heading states that customer data in the data centre is administered in strict separation and in separate systems from the vendor's own data, and that customer data, customer test data, contact data and employee data are separated from one another.

An access control heading sets out central rights management separated for system and application access, controls preventing users from changing their own rights, and controls requiring approval before a rights change. A further heading on preventing concatenation describes a role concept with phased access rights based on identity management. The agreement supports it from the licensing side, requiring an individual login and password per Authorized User, prohibiting account sharing, restricting reassignment, and providing that users may only use the software in accordance with the roles assigned to them, with an audit right over compliance.

Matter-level structure exists as a product feature, projects being described as a way to structure chats and documents by case or project. The stronger value is not taken and the reason is recorded: the vendor integrates with iManage and SharePoint, but nothing published states that retrieval enforces those systems' access models at query time per user, so the burden of keeping the two aligned sits with the firm's administrator rather than being discharged by inheritance. Nothing published describes a conflicts or ethical wall function by name.

Source: Vendor PublishedCustomer data in data center is administered in strict separation and in separate systemsAs of Sep 12, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Notice committed

Terms commit to notice where lawfully permitted. No transparency report located.

Notice is committed in the agreement and no transparency report exists, which is this value, and the commitment appears twice in two different shapes. The master agreement's confidentiality section permits disclosure in response to a valid order by a court or other governmental or regulatory body, or as otherwise required by law, and provides that the receiving party will promptly give notice to the disclosing party of such compelled disclosure and allow it to object or to seek a protective order, to the extent legally permitted.

That is notice plus the opportunity to resist, which is the full shape this signal looks for. The data processing addendum adds a second and differently-framed commitment covering the physical case rather than the legal one: where personal data becomes subject to search and seizure, an attachment order, confiscation in insolvency proceedings or similar measures by third parties while in the processor's control, the processor shall notify the controller without undue delay, and shall notify all parties to that action that the data is the controller's sole property and that the controller is the responsible body.

A third, adjacent provision is recorded: where the processor is required by law to process personal data outside the controller's instructions, it must inform the controller before processing unless the law prohibits that on important grounds of public interest. What is absent is publication after the fact. No transparency report, cadence or aggregate figure was located, which is what separates this value from the one above it.

Source: Vendor Publishedwill promptly give notice to the disclosing Party of such compelled disclosure and allow the disclosing Party to object or to seek a protective orderAs of Sep 12, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Sources named and licensed

The vendor names its primary law sources and the licence or public domain basis for each, with an update cadence.

The content sources are named individually and the rights basis is stated for each, which is this value, though the shape is unusual and the note says so plainly rather than letting the value overstate it. This vendor assembles no legal corpus of its own. What it publishes instead is a set of named external sources reached through integrations, each with its licensing position stated on the pricing comparison table: the Otto Schmidt legal database via direct API for integrated research, available on the top tier and marked as requiring an existing Otto Schmidt subscription; Haufe Lexware, marked on every tier as requiring an additional Haufe subscription; the Handelsregister company register via Company.info as a purchasable add-on; and translation through DeepL as a purchasable add-on, with DeepL also appearing in the sub-processor schedule with its processing locations.

Separate published terms exist for the Otto Schmidt Legal Data Hub. So the rights basis is stated and it is that the customer brings its own licence, which is a clearer answer to the provenance question than most vendors give even though it discharges the obligation rather than assuming it. Two limits are recorded. The web search capability, which the sub-processor schedule identifies as running through a named third-party search processor, carries no stated basis for what it retrieves.

And nothing is published about what the underlying language models were trained on, the agreement reserving the right to change models at any time, which is graded on the model supply chain row.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

No located public material describes a treatment or currency check on legal authority, and R15 governs how heavily that reads. This is a contract and workflow product before it is a research product: the published use-case library runs to clause extraction, contract review and drafting, due diligence, document comparison, redlining, NDA generation, timelines and obligation tables, with research legal sources appearing as one item among about twenty.

Where research does happen it runs through a licensed publisher's database that the customer subscribes to separately, and whatever currency signals that publisher carries are the publisher's rather than this vendor's. Nothing published describes flagging overruled, superseded or negatively treated authority, and no citator relationship is claimed. Two adjacent things are recorded and neither is credited, because crediting either would answer a different question.

Summaries are described as source-linked with citations kept attached, which is provenance rather than treatment and is graded on the citation accuracy row. And the agreement discloses that accuracy may be lower where access to legal sources is not enabled, which tells a buyer that currency depends on a setting without describing any check performed once it is on. The surfaces read on the date shown were the security page, the pricing comparison table, the product and use-case navigation, and the AI Terms section of the master agreement.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

No located public material describes what the system does when it cannot produce a reliable answer, and the gap is recorded carefully because this vendor comes closer than most without arriving. Hallucination control appears as a named key feature on the security page and nowhere is it described: no abstention, no confidence signal, no threshold, no behaviour on ambiguous input. Under R22 a capability cannot be credited from its title, and it is not credited here.

What is published, and is genuinely unusual, is a disclosed accuracy-degradation condition in the agreement rather than a runtime behaviour: the customer acknowledges that the accuracy and reliability of Output may be affected if additional features such as web search or access to legal sources are not enabled, that in such cases the service may produce responses more likely to contain inaccuracies, and that the vendor recommends enabling those features.

That is a vendor naming the configuration under which its own output becomes less reliable, which is honest and is a different thing from the model saying so at the point of answering. The remaining material is disclaimer rather than mechanism: the agreement states that the vendor does not guarantee Output is accurate, complete, original, fair, unbiased or free from errors, and requires the customer to verify and validate all Output before use.

Recorded as the practical shape of the gap: a user of Extract running a large due diligence set is told to check everything and is not told which extractions the system was least sure of.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

None located

No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.

Searched on 12 September 2026, on the company name and on the AI suite name, against published trackers and coverage of decisions on AI-generated fabricated citations, including coverage of the Damien Charlotin database, which that coverage reports as listing more than 1,353 affected filings globally, and reporting on the 2025 and 2026 sanctions decisions across the United States federal circuits and state appellate courts.

None located. Under R119 this signal records fabricated citations and nothing else, so it is not a litigation history and no other proceeding involving the vendor would appear here. One point of context is recorded because it bears on how the absence should be read rather than on the vendor's conduct: the exposure this signal tracks arises where a product generates legal authority for filing, and this product's centre of gravity is contract review, extraction, drafting against the customer's own templates and workflow automation.

Research against a licensed publisher database is available on the top tier, so the exposure is real rather than absent, but it is narrower than for a research platform and the search result should be read in that light.

Source: Bar Guidance or Court RecordAs of Sep 12, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Named guidance addressed

Public materials engage with at least one named ethics opinion.

Named professional guidance is addressed and the product is mapped to it, which is this value, and the Austrian material is the strongest instance located in this corpus. On a dedicated page the vendor states that BEAMON AI meets the data protection and professional law requirements applying to Austrian lawyers, and it names them by provision: section 9 of the Rechtsanwaltsordnung, section 40 paragraph 3 of the RL-BA 2015, and the GDPR with the Austrian Data Protection Act 2018.

It then states how, listing unlimited-in-time confidentiality, a processing agreement under Article 28 GDPR, EU data processing and the express prohibition on using customer data to train AI models. Most concretely, it states that it has completed in full and signed at company level the checklist for AI providers issued by the Austrian Bar Association, and that supplementary provisions for Austrian professional-secrecy holders apply; those supplementary provisions are published as a standing instrument in the legal terms index.

Germany is addressed separately and more briefly, the security page stating compliance with the BRAO and with section 203 of the Criminal Code, and the agreement carrying a status discount tied to bar association membership. The higher value was considered and not taken, and the reason is recorded so a later grader can revisit it: Austria is a genuine mapping, Germany is a compliance assertion naming instruments rather than a mapping, and the published supplementary notes for Swiss and German professional-secrecy holders were not opened. Those three German-language instruments are what would move this row.

Source: Vendor PublishedDie vom Österreichischen Rechtsanwaltskammertag (ÖRAK) herausgegebene Checkliste für KI-Anbieter haben wir vollständig ausgefülltAs of Sep 12, 2026Evidence

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure, and the product sits inside a fee relationship between a lawyer and a client where those savings would change the bill.

Time savings are claimed, the product sits inside a lawyer-to-client fee relationship, and nothing addresses billing or disclosure, which is this value. The claims are published throughout and are unambiguous: save time and reduce costs, save hundreds of hours reviewing contracts for key clauses or information, free the legal team from repetitive time-consuming tasks, and accelerate work that previously took thousands of hours of manual contract review.

The buyer includes global law firms that bill those hours to clients, so the compression this signal exists for is squarely in scope and is the vendor's own selling proposition. Nothing published addresses what happens to the bill. There is no per-matter record of AI-assisted work, nothing identifies output as machine-produced for fee purposes, and no guidance on fee or disclosure treatment appears anywhere, including in an otherwise detailed agreement that runs to sixteen sections and a dedicated AI regime.

Two features are recorded and expressly not credited, because both point at the customer's billing rather than at the customer's own AI use: a billing guidelines hybrid agent that reviews and corrects invoices and matter descriptions against guidelines, and an invoice summarisation use case. Under R124(1) a pipeline that touches invoices is not by itself a record of AI-assisted work, and neither of these produces one.

The one usage restriction that touches the territory is aimed elsewhere but worth naming, a contractual bar on misleading any person that Output is human generated.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Disclosure pack published

A subprocessor and model provider list plus client facing disclosure material is published or available without an agreement in place.

All three artifacts exist, are published without an agreement or a request, and are forwardable, which is this value. The sub-processor list is a table in Schedule 1 of the data processing addendum giving, for each party, the service provided, the corporate location and the server location: cloud hosting in Frankfurt, a monitoring tool, a file conversion processor, a translation provider, and a web search processor. The model provider statement is in the same table rather than being left to inference, identifying Microsoft Azure as the cloud server and host of the default language model used within BEAMON, and Anthropic Ireland as an optional language model engaged only upon enablement by an administrator of the customer.

A firm asked which third party sees its client content can therefore answer by name, by role and by location, and can say which are on by default and which require its own action. The client-facing material is the addendum itself, which under R29 is the paradigm forwardable artifact because it is drafted to be handed to a client, and it is reinforced by a sub-processor change regime giving prior written notice and a twenty business day objection right on materially important grounds.

Two things strengthen it further and are recorded rather than double-counted: the addendum's professional secrecy section requires sub-processors to be contractually barred from onward disclosure of professional secrets, and a completed bar association checklist for AI providers exists as a forwardable document in one jurisdiction.

Source: Vendor PublishedOptional LLM used within BEAMON; engaged only upon enablement by an Admin of ControllerAs of Sep 12, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Not addressed

No located public material addresses court disclosure or verification certification.

No located public material addresses disclosure of AI involvement in legal work, and the note records how close two published things come without reaching it. The first is an audit claim: the security page states that access is restricted by role and need, that actions are logged and changes are traceable, and that lawyers remain responsible for decisions with clear audit trails supporting internal governance and external requirements.

The phrase external requirements is the closest the estate comes to this signal, and it is not credited, because nothing states that the trail identifies which passages a model produced, distinguishes machine-drafted from human-edited text, survives export, or is capable of being put before a tribunal. It reads as a security and governance log rather than a disclosure record. The second is a usage restriction and it points the right way without being a mechanism: the customer must not mislead any person that Output is human generated.

That is a duty of candour imposed on the customer, not a product feature that makes candour possible. Nothing published provides a disclosure template, a certification, a model identifier attached to output, or an export designed for filing. The gap has a specific edge on this product because the hybrid agents include court document handling and claims processing, so output does reach the vicinity of a tribunal, and a firm asked afterwards which parts of a filing a model drafted would have nothing published to work from.

Source: Vendor PublishedAs of Sep 12, 2026Evidence
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 13, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746