C
Canopy
Canopy is data breach response software from Canopy Software, Inc. of Reston, Virginia, used by review and legal service providers, digital forensics and incident response firms, breach counsel and cyber insurers after a cyber incident. Its patented Data Breach Response product uses hundreds of machine learning models to find personal and health information in compromised data of any file type without normalisation, produces an impact assessment report of what was found, speeds document review, consolidates records into a deduplicated list of affected people, and exports notification lists for GDPR, HIPAA, FERPA and other notification duties.
Auto Review automates first-level review with confidence levels that direct human quality control. It runs on AWS in the United States, Canada, the European Union, the United Kingdom and Australia. Law firms typically reach it through Canopy's partner providers. Pricing is not published.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the product. Canopy says hundreds of machine learning models detect personal and health information in any file type, deduplicate records into unique affected people and build the notification list, and Auto Review carries out first-level review itself. Without the models there is little left to sell. Verified 22 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted, not measured. The site says Canopy's detection is more precise than ediscovery keyword and regex searching and that Auto Review avoids the hallucinations of generic language models, and gated case studies report hours saved and records consolidated. No detection rate, error rate or test set is published. The product does not cite legal authority. Verified 22 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Automated first-level review with a confidence-guided human check. Auto Review is described as replacing the first-level review team, and its confidence-level reporting tells review managers which documents need a second look in quality control; in Data Breach Response, people review the documents the models flag. Nothing states a limit on sending a notification list without human review. Verified 22 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Unattributed results. Case studies, gated behind download forms, report one review team saving 2,000 hours, one partner finishing review in about a third of the time and saving its client over $300,000, and 4.28 billion entities consolidated to 3 million unique people. No customer is named on the pages read. Verified 22 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Confidentiality is asserted in general terms, with no agreement published. The Privacy Notice says Canopy processes client data only as a litigation-support service provider on its clients' instructions and that employees sign confidentiality agreements, and the security pages describe encryption and a virtual private cloud in the customer's jurisdiction. No customer agreement is published, and nothing says whether customer data trains Canopy's models, which the product pages describe as continuously trained. Privilege is not addressed. Verified 22 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
Checked the home, law firm, review and LSP, product and About pages and the Privacy Notice on 22 September 2026. The software produces the lists breach counsel rely on to advise clients on notification duties, but nothing states that it gives no legal advice or addresses counsel's review of its output. Verified 22 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Checked the home, product, About and security pages and the Privacy Notice on 22 September 2026. No AI governance position, accountable owner, testing before release, or finding on how detection performs across document types, languages or regions was located. Verified 22 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Security controls are published; retention, subprocessors and incidents are not. The site describes encryption at rest and in transit, a virtual private cloud within the customer's jurisdiction, tenant administrator permissions, penetration testing and staff security training. The Privacy Notice, last updated in November 2023, does not say how long case data is kept or how it is deleted. No subprocessor list or incident notification commitment was located; the trust centre requires a login. Verified 22 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Checked the home, product and About pages, the site map and the Privacy Notice, and tried the /terms and /terms-of-service addresses, on 22 September 2026. No customer agreement is published, so nothing states Canopy's liability, warranties or indemnities. Verified 22 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Checked the home, product and review and LSP pages on 22 September 2026. Canopy exports entity and notification lists in formats suited to different jurisdictions, but no connection to a review platform, case management or other practice system was located. Verified 22 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Regions and isolation are stated for a single hosted service. The software runs on AWS with separate instances and logins for the United States, Canada, the European Union, the United Kingdom and Australia, more regions on request, and data resides in a virtual private cloud within the customer's jurisdiction. Where model processing runs is not stated separately, and no other deployment option is offered. Verified 22 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
A named certification without a reachable report. The site says Canopy maintains ISO 27001 certification and regularly runs third-party penetration tests. The trust centre linked from the footer requires a member login, and no certificate, scope or date is published on the pages read. Verified 22 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Canopy's own models are claimed without detail. The site describes hundreds of patented machine learning models, continuously trained, and says Auto Review's agentic approach outperforms generic language models, without naming any model, provider or architecture or committing to notice of changes. Verified 22 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Checked the home, product, solutions and partners pages on 22 September 2026. No price, unit or tier is published; every route to a price is a demo request. Verified 22 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Buyers and incident types are named, short of limits. The site addresses digital forensics and incident response firms, review and legal service providers, law firms and cyber insurers, covers ransomware and business email compromise, and names GDPR, HIPAA and FERPA notification duties across five hosting regions. What data types, languages or jurisdictions it does not handle is not stated. Verified 22 September 2026.
5 public documents
The public pages on file for Canopy, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.
-
canopyco.io/privacy1 signal
Third Party Request and Subpoena Notice
Read Sep 22, 2026
-
canopyco.io/product/auto-review1 signal
Refusal and Uncertainty Behaviour
Read Sep 22, 2026
-
Billing and Fee Posture
Read Sep 22, 2026
-
Ethical Walls and Matter Segregation
Read Sep 22, 2026
-
Fabricated Citation Record
Read Sep 22, 2026
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No customer agreement, terms of service or equivalent contract is published on any surface located, and no policy page states a position on training. Nothing is granted and nothing is withheld, so a client has no term to hold the firm to. Where a policy page does state a position, the row takes the matching policy value instead and the summary records that no agreement exists.
Checked the home, product, About and security pages, the site map and the Privacy Notice on 22 September 2026, and tried the /terms and /terms-of-service addresses. No customer agreement is published, and the Privacy Notice takes no position on training; the product pages say Canopy's models are continuously trained without saying on what data.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
Checked the Privacy Notice and the product and security pages on 22 September 2026. The Privacy Notice says client data is processed on clients' instructions but states no retention period for breach data, review decisions or generated lists.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
Access is set in Canopy's own permission model, maintained by the customer's tenant administrators, covering who can see data and who can export entity lists; each customer's data sits in a virtual private cloud in its jurisdiction. Nothing describes separating individual matters within a tenant or inheriting permissions from another system.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.
The Privacy Notice says Canopy does not disclose personal information to third parties except as required by law in response to lawful requests by public authorities, including for national security or law enforcement. Nothing addresses notifying the customer, and no customer agreement is published.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
Checked the product and law firm pages on 22 September 2026. Canopy works on each customer's breached data; notification rules are said to vary by jurisdiction and industry, but no source of those rules is identified.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Checked the product and law firm pages on 22 September 2026. The product does not cite legal authority, and nothing addresses checking authority for later treatment.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
The product exposes a confidence or grounding score without an explicit abstention path.
Auto Review reports a confidence level for its first-level review decisions, and the site says this tells review managers which documents need a second look in quality control. No path in which the system declines to classify a document is described.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.
Searched the AI Hallucination Cases database maintained by Damien Charlotin on 22 September 2026 for Canopy, and no recorded case was returned. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
Checked the home, law firm, review and LSP and About pages and the Privacy Notice on 22 September 2026. No material engages with lawyers' professional or ethical obligations or names any ethics opinion.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.
Canopy is licensed by incident response and review providers who bill the breached organisation for the work; law firms reach it through those partners and advise the client on the results. It does not sit in a lawyer's own time billing, and nothing addresses how its use is reflected in legal fees.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
Checked the security, product and review and LSP pages and the Privacy Notice on 22 September 2026. No subprocessor or model provider list and no client-facing disclosure material was located; the trust centre requires a member login.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located public material addresses court disclosure or verification certification.
Checked the product and law firm pages on 22 September 2026. The regulator, not a court, usually receives this work; the site describes an impact assessment report and defensible detection, but nothing records which decisions the models made and which a person verified, or addresses disclosing AI use.