C
Canopy

Canopy is data breach response software from Canopy Software, Inc. of Reston, Virginia, used by review and legal service providers, digital forensics and incident response firms, breach counsel and cyber insurers after a cyber incident. Its patented Data Breach Response product uses hundreds of machine learning models to find personal and health information in compromised data of any file type without normalisation, produces an impact assessment report of what was found, speeds document review, consolidates records into a deduplicated list of affected people, and exports notification lists for GDPR, HIPAA, FERPA and other notification duties.

Auto Review automates first-level review with confidence levels that direct human quality control. It runs on AWS in the United States, Canada, the European Union, the United Kingdom and Australia. Law firms typically reach it through Canopy's partner providers. Pricing is not published.

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The models are the product. Canopy says hundreds of machine learning models detect personal and health information in any file type, deduplicate records into unique affected people and build the notification list, and Auto Review carries out first-level review itself. Without the models there is little left to sell. Verified 22 September 2026.

Source: Vendor Published
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Accuracy is asserted, not measured. The site says Canopy's detection is more precise than ediscovery keyword and regex searching and that Auto Review avoids the hallucinations of generic language models, and gated case studies report hours saved and records consolidated. No detection rate, error rate or test set is published. The product does not cite legal authority. Verified 22 September 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Automated first-level review with a confidence-guided human check. Auto Review is described as replacing the first-level review team, and its confidence-level reporting tells review managers which documents need a second look in quality control; in Data Breach Response, people review the documents the models flag. Nothing states a limit on sending a notification list without human review. Verified 22 September 2026.

Source: Vendor Published
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Unattributed results. Case studies, gated behind download forms, report one review team saving 2,000 hours, one partner finishing review in about a third of the time and saving its client over $300,000, and 4.28 billion entities consolidated to 3 million unique people. No customer is named on the pages read. Verified 22 September 2026.

Source: Vendor Published
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Confidentiality is asserted in general terms, with no agreement published. The Privacy Notice says Canopy processes client data only as a litigation-support service provider on its clients' instructions and that employees sign confidentiality agreements, and the security pages describe encryption and a virtual private cloud in the customer's jurisdiction. No customer agreement is published, and nothing says whether customer data trains Canopy's models, which the product pages describe as continuously trained. Privilege is not addressed. Verified 22 September 2026.

Source: Vendor Published
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Checked the home, law firm, review and LSP, product and About pages and the Privacy Notice on 22 September 2026. The software produces the lists breach counsel rely on to advise clients on notification duties, but nothing states that it gives no legal advice or addresses counsel's review of its output. Verified 22 September 2026.

Source: Operator Verified
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Checked the home, product, About and security pages and the Privacy Notice on 22 September 2026. No AI governance position, accountable owner, testing before release, or finding on how detection performs across document types, languages or regions was located. Verified 22 September 2026.

Source: Operator Verified
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Security controls are published; retention, subprocessors and incidents are not. The site describes encryption at rest and in transit, a virtual private cloud within the customer's jurisdiction, tenant administrator permissions, penetration testing and staff security training. The Privacy Notice, last updated in November 2023, does not say how long case data is kept or how it is deleted. No subprocessor list or incident notification commitment was located; the trust centre requires a login. Verified 22 September 2026.

Source: Vendor Published
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Checked the home, product and About pages, the site map and the Privacy Notice, and tried the /terms and /terms-of-service addresses, on 22 September 2026. No customer agreement is published, so nothing states Canopy's liability, warranties or indemnities. Verified 22 September 2026.

Source: Operator Verified
DD on Practice Systems Integration DepthNo integration into practice systems located, or the product stands alone and requires work to move to it.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Checked the home, product and review and LSP pages on 22 September 2026. Canopy exports entity and notification lists in formats suited to different jurisdictions, but no connection to a review platform, case management or other practice system was located. Verified 22 September 2026.

Source: Operator Verified
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Regions and isolation are stated for a single hosted service. The software runs on AWS with separate instances and logins for the United States, Canada, the European Union, the United Kingdom and Australia, more regions on request, and data resides in a virtual private cloud within the customer's jurisdiction. Where model processing runs is not stated separately, and no other deployment option is offered. Verified 22 September 2026.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

A named certification without a reachable report. The site says Canopy maintains ISO 27001 certification and regularly runs third-party penetration tests. The trust centre linked from the footer requires a member login, and no certificate, scope or date is published on the pages read. Verified 22 September 2026.

Source: Vendor Published
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Canopy's own models are claimed without detail. The site describes hundreds of patented machine learning models, continuously trained, and says Auto Review's agentic approach outperforms generic language models, without naming any model, provider or architecture or committing to notice of changes. Verified 22 September 2026.

Source: Vendor Published
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Checked the home, product, solutions and partners pages on 22 September 2026. No price, unit or tier is published; every route to a price is a demo request. Verified 22 September 2026.

Source: Operator Verified
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Buyers and incident types are named, short of limits. The site addresses digital forensics and incident response firms, review and legal service providers, law firms and cyber insurers, covers ransomware and business email compromise, and names GDPR, HIPAA and FERPA notification duties across five hosting regions. What data types, languages or jurisdictions it does not handle is not stated. Verified 22 September 2026.

Source: Vendor Published
Sources on file

5 public documents

The public pages on file for Canopy, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

No agreement published

No customer agreement, terms of service or equivalent contract is published on any surface located, and no policy page states a position on training. Nothing is granted and nothing is withheld, so a client has no term to hold the firm to. Where a policy page does state a position, the row takes the matching policy value instead and the summary records that no agreement exists.

Checked the home, product, About and security pages, the site map and the Privacy Notice on 22 September 2026, and tried the /terms and /terms-of-service addresses. No customer agreement is published, and the Privacy Notice takes no position on training; the product pages say Canopy's models are continuously trained without saying on what data.

Source: Operator VerifiedAs of Sep 22, 2026

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Not addressed

No located public material states how long prompts and outputs are retained.

Checked the Privacy Notice and the product and security pages on 22 September 2026. The Privacy Notice says client data is processed on clients' instructions but states no retention period for breach data, review decisions or generated lists.

Source: Operator VerifiedAs of Sep 22, 2026

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Own model, documented

The product maintains its own permission model, documented, requiring the firm to keep it aligned.

Access is set in Canopy's own permission model, maintained by the customer's tenant administrators, covering who can see data and who can export entity lists; each customer's data sits in a virtual private cloud in its jurisdiction. Nothing describes separating individual matters within a tenant or inheriting permissions from another system.

Source: Vendor PublishedTenant admins can set user permissions for everything from accessing data to exporting entity lists.As of Sep 22, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Disclosure addressed, notice absent

Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.

The Privacy Notice says Canopy does not disclose personal information to third parties except as required by law in response to lawful requests by public authorities, including for national security or law enforcement. Nothing addresses notifying the customer, and no customer agreement is published.

Source: Vendor Publishedin response to lawful requests by public authoritiesAs of Sep 22, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Not addressed

No located public material identifies the corpus behind the product’s answers.

Checked the product and law firm pages on 22 September 2026. Canopy works on each customer's breached data; notification rules are said to vary by jurisdiction and industry, but no source of those rules is identified.

Source: Operator VerifiedAs of Sep 22, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

Checked the product and law firm pages on 22 September 2026. The product does not cite legal authority, and nothing addresses checking authority for later treatment.

Source: Operator VerifiedAs of Sep 22, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Confidence signal only

The product exposes a confidence or grounding score without an explicit abstention path.

Auto Review reports a confidence level for its first-level review decisions, and the site says this tells review managers which documents need a second look in quality control. No path in which the system declines to classify a document is described.

Source: Vendor PublishedAs of Sep 22, 2026Evidence

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

None located

No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.

Searched the AI Hallucination Cases database maintained by Damien Charlotin on 22 September 2026 for Canopy, and no recorded case was returned. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product.

Source: Bar Guidance or Court RecordAs of Sep 22, 2026Evidence
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

Checked the home, law firm, review and LSP and About pages and the Privacy Notice on 22 September 2026. No material engages with lawyers' professional or ethical obligations or names any ethics opinion.

Source: Operator VerifiedAs of Sep 22, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Outside the fee relationship

The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.

Canopy is licensed by incident response and review providers who bill the breached organisation for the work; law firms reach it through those partners and advise the client on the results. It does not sit in a lawyer's own time billing, and nothing addresses how its use is reflected in legal fees.

Source: Vendor PublishedAs of Sep 22, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Not addressed

No located public material supports a client side disclosure obligation.

Checked the security, product and review and LSP pages and the Privacy Notice on 22 September 2026. No subprocessor or model provider list and no client-facing disclosure material was located; the trust centre requires a member login.

Source: Operator VerifiedAs of Sep 22, 2026

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Not addressed

No located public material addresses court disclosure or verification certification.

Checked the product and law firm pages on 22 September 2026. The regulator, not a court, usually receives this work; the site describes an impact assessment report and defensible detection, but nothing records which decisions the models made and which a person verified, or addresses disclosing AI use.

Source: Operator VerifiedAs of Sep 22, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 22, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746