Consilio

Global eDiscovery and legal data business that sells software and managed services together, with two platforms at the centre. Sightline is an end-to-end eDiscovery and legal hold product, with modules for eDiscovery, small matters, investigations and legal holds, offered on either a self-service or a full-service basis and used for regulatory response, cyber incident response, data subject access requests, early case assessment, PII and PHI detection, and multimedia review. Aurora is a Digital Enterprise Platform that sits upstream of review rather than replacing it: it unifies a client's legal data portfolio in a repository called DataCore, adds early case intelligence through CoreECI and portfolio dashboards through the Aurora Portal, and deliberately preserves the customer's freedom to run whichever review platform suits each matter, naming Relativity, Everlaw and Sightline among them. Layered across both is a named AI portfolio: Guided AI Review and Native AI Review for responsiveness classification, AI PrivDetect and AI PrivGen for privilege identification and privilege log drafting, AI Summarize, AI Investigate for pattern discovery and semantic search, and Aurora Verity Review, with narrative analysis added through the June 2025 acquisition of the AI research lab TrueLaw. Consilio describes its models as custom-built in house and trained on legal material, with AI PrivGen trained on thousands of court-approved privilege log entries, and it delivers them with staff attached: AI Guides who design reviews and validate prompts, and privilege review experts who quality-check generated output before it reaches the client. Everything runs on Consilio's own private data centres rather than public cloud, which the company presents as its central security position, citing more than fifteen global data centres, over seven thousand servers, more than thirty thousand matters hosted and upwards of 210 terabytes ingested each month. Buyers are multinational law firms, corporations and government organisations, served from offices across North America, Europe, Asia, Australia and the Middle East, with the website published in nine locales. Consilio LLC is privately held and private equity backed, formed by the combination of several businesses including Advanced Discovery and Legility, and has since added Lawyers On Demand, SYKE and TrueLaw.

Vendor siteWashington, DC, United StatesFounded 2009
Last verifiedAugust 31, 2026

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Machine learning is the engine of several capabilities a client pays for, and the businesses underneath it would carry on without it. Nine AI products are named and separately marketed: Guided AI Review and Native AI Review for responsiveness classification, AI PrivDetect and AI PrivGen for privilege work, AI Summarize, AI Investigate, Aurora Verity Review and the narrative analysis acquired with TrueLaw in June 2025. The models are described as custom-built in house and fine-tuned for legal document classification, with AI PrivGen trained on thousands of court-approved privilege log entries, and the scale claimed around them is real: more than 1,300 analytics engagements a year, over 250 million documents analysed, more than 40 dedicated AI team members. Two things hold it at this band rather than higher. Sightline is a complete eDiscovery and legal hold platform without any of it, and Aurora is a data unification and portfolio management layer whose core promise, freedom from platform lock-in and visibility across matters, is not a machine learning promise. And the AI is delivered wrapped in labour: AI Guides validate the prompts, privilege review experts quality-check every generated description, and the company's own framing is a hybrid in which technology enhances rather than replaces judgement. Graded level with Casepoint on the same reasoning.

Source: Vendor Published
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Accuracy is asserted repeatedly and measured nowhere. The claims are specific in language and empty of numbers: descriptions that are accurate, defensible and court-ready, results that are reliable and consistent, documents identified with precision, a system trained on thousands of court-approved privilege log entries so that entries contain all required elements while avoiding common pitfalls. The one figure published is about effort rather than correctness, a reduction in attorney hours of up to seventy per cent on privilege log creation, hedged as what clients report. Searched the Sightline page, the Aurora page, the AI PrivGen page and the privacy policy on 31 Aug 2026 and located no accuracy rate, no recall or precision statistic, no validation protocol, no test set and no error analysis, which is a conspicuous absence for privilege classification, where a false negative discloses a privileged communication and the consequence is not recoverable. Nothing describes grounding either: no citation of the underlying document from a generated log entry, and no retrieval method. The substitute for measurement is people, with privilege review experts providing oversight to ensure accuracy and defensibility, which is a control rather than evidence. One limb does not apply and is neither credited nor penalised: a citator or good-law check is out of scope for a product operating on a client's own collected documents. Eight of the nine AI product pages were not opened and are the rebuttal route.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Human oversight is not a caveat here, it is the delivery model, and it is described with more specificity than most vendors manage. The framing is the AI Trust Gap, and the answer given is a hybrid in which advanced AI is combined with seasoned professionals and guided by human oversight at every step, so that legal teams retain full control. The people are named as roles rather than gestured at: AI Guides bringing three stated types of expertise, review design, legal domain knowledge, and AI prompting and validation, who refine and validate prompts and ensure outputs are relevant and aligned with the matter. AI PrivGen publishes a four-stage flow ending in a named quality assurance step where privilege review experts check generated descriptions before delivery. Aurora adds customer-side control, with AI adopted at the client's own pace and the client choosing which models and review platforms operate on its data. What is not published, checked across those pages and the privacy policy on 31 Aug 2026: no threshold at which a model declines to produce an answer, no confidence or uncertainty signal exposed, no description of what happens when a generated description is wrong, and no correction route. The oversight model is well staffed and undocumented at the point of failure.

Source: Vendor Published
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Operational scale is published in quantity and customer outcomes are not attributed to anyone. The scale figures are real and specific: more than 1,300 analytics engagements a year, over 250 million documents analysed, more than 120 review managers trained on the AI suite, over 40 AI team members, upwards of 210 terabytes ingested monthly, more than 7,000 servers, over 30,000 matters hosted and fifteen or more data centres. Those describe the vendor rather than what changed for a client. On the customer side there is one figure, a reduction in attorney hours of up to seventy per cent on privilege log creation, attributed only to what clients report, with no named organisation, no matter, no date and no method. Searched the Sightline page, the Aurora page, the AI PrivGen page and the site navigation on 31 Aug 2026 and located no named customer anywhere. Two artifacts make the gap concrete rather than theoretical. The customer success section of the flagship AI product page still carries its unfilled template instruction, reading as a headline highlighting customer results with a direction to emphasise time saving and use numbers to maximise credibility. And the Sightline page's expert section renders roughly one hundred cards all reading Full Name and Job Title. A case study library exists and was not opened, which is the rebuttal route.

Source: Vendor Published
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Confidentiality is asserted clearly and in general terms, and the document that would bind it is not published. What is published is not nothing. The privacy policy states that all client data is treated as confidential whether it includes personally identifiable information, protected health information or simply non-public information, and that Consilio's handling policies keep data and devices protected from unauthorised access while in its possession, supported by strict access control policies, network segregation between internet-facing and sensitive storage segments, and background screening of all employees and contractors. The AI PrivGen page goes directly at privilege, stating that privileged content never leaves Consilio's secure environment and that attorney-client confidentiality is maintained, with processing on private data centres rather than public cloud. What is missing is the whole contractual layer. No terms of service, master agreement or data processing addendum is published anywhere on the property, so there is no readable commitment on training with client material, no matter or client segregation model, no ethical wall description, and no work product treatment. The privacy policy itself narrows the point, stating that Consilio acts primarily as data processor for client services, which places the operative terms in client contracts a buyer cannot read in advance. Checked the full footer inventory on 31 Aug 2026.

Source: Vendor Published
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Nothing published addresses the advice line, and there is no document on the property that would carry it. The footer inventory is privacy policy, privacy rights requests, anti-slavery statement, cookies policy, cookies preference manager and a PAIA manual. There is no terms of service, no disclaimer page and no professional responsibility statement, so nothing states that output is not legal advice, that no attorney-client relationship arises with Consilio, or where responsibility sits when a generated privilege description proves wrong. No bar or ethics authority is named anywhere, including ABA Formal Opinion 512. The exposure is sharper here than for a pure software vendor, because Consilio's own reviewers and privilege experts exercise legal judgement on client matters as part of the service, and the published material describes that arrangement warmly without addressing the professional responsibility questions it raises. One thing does exist and is recorded rather than credited: a supervision and competence posture is published, in that human oversight is promised at every step and technology is said to enhance rather than replace critical legal judgement. That is a statement about how the work is done, not about who answers for it. Checked the Sightline, Aurora and AI PrivGen pages and the privacy policy on 31 Aug 2026.

Source: Operator Verified
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Principles and a staffing model are published; a governance framework a buyer could audit is not. The published material is organised around the AI Trust Gap, and it names ethical concerns and the absence of clear governance frameworks as an industry problem Aurora is meant to answer, with the answer given as expert oversight, client choice over which models run, and processing on private infrastructure. Two compliance statements sit in the privacy policy and are the closest thing to a mechanism: the right not to be subject to a decision based solely on automated processing is recited, and Consilio states that it complies with applicable CCPA and CPPA requirements including those relating to risk assessments, cybersecurity and automated decision-making technologies. Beyond that, searched the Sightline, Aurora and AI PrivGen pages and the privacy policy on 31 Aug 2026 and found no responsible AI page, no accountable owner for model behaviour, no pre-release testing regime, no model documentation and nothing at all on bias or uneven output. The gap has an edge on this product: models that classify responsiveness and privilege determine which documents a reviewing lawyer ever sees, and uneven performance across custodians, languages or document types is the question, unaddressed. A chief information security officer is named as a role, for security rather than for AI.

Source: Vendor Published
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

The privacy policy carries a substantial safeguarding section that covers most of this ground, which matters more than usual here because it is the only substantive published document on the property. Certifications are stated with the holding entity distinguished: Consilio is certified to ISO/IEC 27001:2022 and HITRUST CSF, its collocated data centres are certified to either ISO 27001 or SOC 2 Type 2, and its UK data centre and offices hold Cyber Essentials Plus. Named controls follow: a chief information security officer heading the security team, enterprise policies reviewed by management, a vendor management programme requiring vetting and periodic security audits of suppliers, network segregation using a DMZ and multiple firewalls between internet-facing segments and sensitive storage, intrusion detection and prevention, third-party monitoring, background screening of all employees and contractors, an incident management policy, disaster recovery and business continuity policies, and a backup policy specified as data replication plus daily incremental and weekly full backups. A list of current third-party suppliers is published at a stated public URL. What is absent: no retention period for anything, since the Data Retention and Disposal Policy is named but not published and is obtainable only by email; no deletion commitment for client data; and no breach notification timeframe, the incident policy being described rather than published. Policy updated 17 Aug 2026.

Source: Vendor Published
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Nothing is published on who bears the loss when the system is wrong, because no customer agreement of any kind is published. The footer legal inventory was read in full on 31 Aug 2026 and consists of a privacy policy, a privacy rights request portal, an anti-slavery statement, a cookies policy, a cookies preference manager and a PAIA manual. There is no terms of service, no master services agreement, no service level agreement, no data processing addendum and no acceptable use policy. In consequence nothing states a liability cap, an indemnity in either direction, a warranty on the software or on generated output, an insurance position, a limitation period, a governing law or a forum. A buyer evaluating this vendor cannot read the allocation of risk in advance at any level, and the only route to it is a negotiated contract. The contrast within this category is the useful measure rather than the criticism: Casepoint, read the same day, publishes a complete standard agreement including a dedicated clause on AI inputs and outputs, a stated cap, named carve-outs and a seventy-two hour breach notification. Consilio hosts more than thirty thousand matters across fifteen or more data centres and publishes none of it.

Source: Operator Verified
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Integration is the product rather than a feature, and the named connections are to competitors, which is unusual and creditable. Aurora is described as platform-agnostic and deliberately upstream of review, integrating with multiple review platforms and naming Relativity, Relativity Server, Everlaw and Sightline, with the stated purpose of freeing an organisation from single-vendor lock-in so it can select the optimal platform for each matter. Supporting mechanics are named: enhanced auto-loaders and data mapping capabilities that reduce processing volumes, and a version of AI Investigate built for Relativity Server so the AI reaches data held in a third-party platform. On collection, Aurora is said to connect with an organisation's data sources from email servers and cloud storage to collaboration platforms and enterprise systems. What is missing is depth and specificity. No individual data source is named, only categories; no document management system, matter management, e-billing or filing integration is named; no API or developer documentation was located; and nothing describes what moves in which direction or what a client must configure. Checked the Sightline, Aurora and AI PrivGen pages and the navigation on 31 Aug 2026; the technology partners page was not opened and is the rebuttal route.

Source: Vendor Published
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

The deployment model is stated plainly and repeatedly, and it is the company's central differentiator rather than a technical footnote: everything runs on Consilio's own private hosted infrastructure and not on the public cloud, a point made on the Sightline page, the Aurora page and the AI PrivGen page alike, with the argument that privileged content never reaches a public cloud provider. The estate is quantified at more than fifteen global data centres, over seven thousand servers and more than thirty thousand matters hosted, with offices and data centres across North America, Europe and Asia. Residency is addressed in part: Aurora promises complete data sovereignty in the client's chosen jurisdiction, its UK and European launch is stated to be hosted in Consilio's UK data centre with GDPR and UK data protection compliance, ITAR compliance is claimed, and cross-border transfer is handled through an intra-company data transfer agreement incorporating the EU Standard Contractual Clauses and the UK Addendum. What is not published: no list of the data centre locations, so a buyer cannot check which jurisdictions are actually available; no tenancy model; and no distinction between where data is stored and where processing or model inference happens. Read 31 Aug 2026.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

The certifications are real, current and stated with unusual care about which entity holds what, and there is no security page or trust centre anywhere to put them in. What is claimed: Consilio itself certified to ISO/IEC 27001:2022 and HITRUST CSF; its collocated data centres certified to either ISO 27001 or SOC 2 Type 2, which is a meaningful distinction most vendors blur, since the SOC 2 attaches to the facilities rather than to Consilio; UK data centre and offices certified under Cyber Essentials Plus; ITAR compliance; and certification to the EU-US Data Privacy Framework with the UK Extension and the Swiss-US Framework, lodged with the US Department of Commerce and independently verifiable on the public Data Privacy Framework register, with JAMS named as the recourse provider and the Federal Trade Commission named as having jurisdiction. That last item is the one attestation a buyer can confirm without asking. Against it: no security page exists, so all of this sits inside a privacy policy; no auditor is named; no scope, coverage period or report date is given for the ISO or HITRUST certifications; and no route is published for obtaining any report. Footer inventory checked in full on 31 Aug 2026.

Source: Vendor Published
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The vendor says the models are its own and stops there. What is published: AI algorithms described as custom-built and developed in house, hosted on Consilio's private cloud; models fine-tuned for legal document classification; AI PrivGen models described as specifically trained on legal privilege concepts and on thousands of court-approved privilege log entries, which is more than most vendors say about training data; and TrueLaw's technology integrated following the June 2025 acquisition. What a buyer cannot establish: whether any third-party foundation model sits beneath the fine-tuning, and if so whose; no model name, version or provider anywhere; no inference location stated as distinct from the data residency claims; and no notice commitment on model change. One unreconciled tension belongs in the record. The AI product pages say the models are custom-built in house, while Aurora is marketed on letting clients leverage AI models they choose and avoiding lock-in to proprietary models, which implies third-party models in the stack. Nothing published reconciles the two. A list of current third-party suppliers is published at a stated URL and was not opened on 31 Aug 2026; it is the most likely place for a provider name and is the rebuttal route.

Source: Vendor Published
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

No pricing information is published at any level, including the unit of charge, and no pricing page exists. The full primary navigation covering solutions, expertise, technology, resources and about, and the complete footer, were read on 31 Aug 2026: there is no pricing entry in either. No rate, no unit, no tier or package names, no volume band, no term length and no statement of what implementation or managed review adds. Every call to action across the Sightline, Aurora and AI PrivGen pages is a demo request or a contact form. The one place pricing appears at all is as an argument about other vendors: Aurora's marketing states that public-cloud platforms trap legal teams in rigid contracts with annual price hikes of eight to twenty per cent, and offers complete cost visibility across a portfolio as the remedy. A platform sold substantially on controlling and making visible the buyer's legal technology spend publishes nothing about its own.

Source: Operator Verified
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Coverage is documented across several dimensions with real substance, and nowhere states a limit. Practice areas are enumerated as litigation and arbitration, global investigations, antitrust and competition, cyber incident response, corporate transactions, and risk and compliance. Industries are enumerated separately as financial services, pharmaceutical and life sciences and healthcare, insurance, transportation and mobility, consumer brands, and technology. Service lines run to eight, including eDiscovery, analytics and AI, document review, risk management and compliance, talent, cyber incident response, data forensics and investigations, and legal transformation. Product-level coverage is more specific still, with Sightline published against regulatory response, cyber incident response, data subject access requests, early case assessment, PII and PHI detection and review, multimedia review, small matters and investigations, and AI PrivGen against complex litigation, multi-party matters, regulatory investigations and mergers and acquisitions. The buyer types are named as multinational law firms, corporations and government organisations, and the site is published in nine locales. What is absent is any boundary: no practice area or data type is identified as unsupported, no jurisdictional limit is stated, and no matter size threshold appears, though a distinct Small Matters module implies the range is deliberate. Checked 31 Aug 2026.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Terms silent

No located term or policy addresses the question either way.

No located document states whether client material is used to train or refine any model, either way, and the document that would say so is not published. The privacy policy lists improving the Products and Services among the purposes for every category of Personal Data it covers, which is the usual improvement language, but it governs Personal Data such as contact and technical information rather than the collected corpus a client uploads, and it states that Consilio acts primarily as data processor for client services, placing those terms in contracts that are not public. No terms of service, master agreement or data processing addendum exists on the property. What the vendor does say about training data points elsewhere: AI PrivGen models are described as trained on thousands of court-approved privilege log entries and on legal privilege concepts, with no statement about whether client documents contribute. Checked the full footer inventory, the Sightline, Aurora and AI PrivGen pages on 31 Aug 2026.

Source: Vendor Publishedto improve our Products and ServicesAs of Aug 31, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Disclosed without a period

Retention is acknowledged in public materials with no stated period.

Retention is acknowledged, deferred to an unpublished document, and never quantified. The privacy policy states that Personal Data is processed for as long as is reasonably necessary to comply with contractual or legal obligations and to pursue legitimate interests, and that it is retained in accordance with a named internal document, the Data Retention and Disposal Policy, which is not published and is obtainable only by emailing the privacy address. That is better than silence, because the instrument is named and a route to it exists, and it is short of a period a buyer could rely on. Nothing separately addresses prompts submitted to the AI products or the descriptions and summaries they generate: no retention period, no customer-configurable setting, no zero-retention option, and no statement of what happens to generated output at the end of a matter. Policy updated 17 Aug 2026 and read the same day.

Source: Vendor Publishedfor as long as is reasonably necessaryAs of Aug 31, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Claimed, not documented

Segregation is asserted in public materials with no published detail on how it is enforced.

Separation is claimed at the level of security controls and never described as a permission model. The privacy policy states that all client data is treated as confidential whether or not it contains personal or health information, that handling policies keep data protected from unauthorised access while in Consilio's possession, and that networks use a DMZ and multiple firewalls with strict access control policies to separate internet-facing segments from sensitive data storage. The AI PrivGen page adds that privileged content stays inside Consilio's environment and that attorney-client confidentiality is maintained. None of that is a segregation mechanism. Nothing published describes separation between one client's matters and another's, between two matters for the same client, or between review teams inside a matter, and nothing states whether the AI products can retrieve across matter boundaries. The question carries unusual weight for a provider that also staffs managed review, since reviewers move between engagements. Checked the privacy policy and the Sightline, Aurora and AI PrivGen pages on 31 Aug 2026.

Source: Vendor Publishedstrict access control policiesAs of Aug 31, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Disclosure addressed, notice absent

Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.

Disclosure to authorities is contemplated and notice to the customer is never reached. The privacy policy states, in its Data Privacy Framework section, that there may be a requirement for Consilio to disclose personal information in response to lawful requests by public authorities including to meet national security or law enforcement requirements, and its recipients table names government officials, law enforcement or others where permitted by the notice or required by law. Nothing commits Consilio to notifying the affected client before or after disclosure, to seeking a protective order, to resisting or narrowing a demand, or to seeking a waiver where notice is prohibited, and no transparency report or disclosure statistics were located. No terms of service exists that might carry a stronger commitment. Checked 31 Aug 2026.

Source: Vendor Publishedlawful requests by public authoritiesAs of Aug 31, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Not addressed

No located public material identifies the corpus behind the product’s answers.

The question does not arise in its usual form and a related one does. Consilio operates on documents its clients collect and upload, so there is no vendor-assembled corpus of primary law, no third-party content licence and no upstream supplier of legal material to identify. Recorded as not addressed on that basis, with the reason stated rather than left to look like neglect. The adjacent question that does bite is training-set provenance: AI PrivGen is described as trained on thousands of court-approved privilege log entries, and nothing published states where those entries came from, whether they originated in Consilio's own client work, whether any consent or licence underpins their use, or how they were selected. For a model whose output is offered as court-ready, the provenance of the material it learned from is a live question and it is unanswered. Searched the Sightline, Aurora and AI PrivGen pages and the privacy policy on 31 Aug 2026.

Source: Operator VerifiedAs of Aug 31, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

Not applicable to this product class, and neither credited nor penalised. Consilio's platforms search, classify and summarise a client's own collected documents; they do not retrieve primary law or assert propositions whose continued validity would need checking, and no citator or treatment signal is claimed anywhere. Searched the Sightline page, the Aurora page, the AI PrivGen page and the privacy policy on 31 Aug 2026. The accuracy question that does apply to this product is validation of classification and privilege calls, and it is recorded on the Citation Accuracy axis, where no recall, precision or error figure was located.

Source: Operator VerifiedAs of Aug 31, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

Nothing published describes what the models do when they are unsure. Searched the Sightline, Aurora and AI PrivGen pages and the privacy policy on 31 Aug 2026 and located no abstention path, no confidence score or uncertainty indicator surfaced to a reviewer, no statement of behaviour where a document is ambiguous or the basis for privilege is unclear, and no threshold at which a document is routed to a human rather than described automatically. The vendor's answer to uncertainty is organisational rather than technical and is recorded here because it is the substitute: privilege review experts provide quality assurance over generated descriptions, and AI Guides validate prompts, so the design assumes a person catches what the model gets wrong rather than the model flagging it. Nothing states how that review is sampled or scoped.

Source: Operator VerifiedAs of Aug 31, 2026

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

No court order, opinion or disciplinary record naming this company or its products has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, together with several independent 2026 sanctions trackers and law library guides, searched on the company name and on the product names. This is a statement about the public record on the date shown rather than a clearance. The failure mode this signal tracks also sits at an angle to the product: Consilio's AI classifies and describes a client's own documents rather than citing legal authority, so a fabricated citation reaching a filing would originate elsewhere, while an inaccurate privilege log description, which is the risk this product actually carries, would surface as a privilege dispute rather than as a hallucination case.

Source: Operator VerifiedAs of Aug 31, 2026Evidence
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

Defensibility and court-readiness are claimed throughout and no authority is ever named behind them. AI PrivGen is marketed as producing court-ready privilege log descriptions that withstand scrutiny, containing all required elements while avoiding common pitfalls that might compromise privilege claims, and trained on thousands of court-approved entries. Searched the Sightline, Aurora and AI PrivGen pages and the privacy policy on 31 Aug 2026 and located no citation to any rule, standard or opinion: nothing names Federal Rule of Civil Procedure 26(b)(5), which governs what a privilege log must contain, no Sedona Conference commentary, no ABA Formal Opinion 512 and no state bar guidance. For a product whose entire output is a document filed to sustain a privilege claim, the absence of the rule that defines sufficiency is the finding. Nothing maps any feature to a professional obligation a supervising lawyer could evidence.

Source: Operator VerifiedAs of Aug 31, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure.

Savings are the headline and the client's bill is not addressed. The published claims are a reduction in attorney hours of up to seventy per cent on privilege log creation, lower overall review costs through automation of repetitive tasks, and substantial cost reductions without sacrificing thoroughness, alongside Aurora's portfolio-level cost visibility and real-time matter cost alerts. Searched the same pages and the privacy policy on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee purposes and no guidance on billing, fee or client disclosure treatment where AI-generated work product is delivered. The question is unusually direct for this vendor, because Consilio's own charges are frequently a disbursement passed through to a client and its reviewers' output is billed work, so an hours reduction of the size claimed changes what a client pays and nothing published addresses how that is recorded or disclosed.

Source: Vendor PublishedAs of Aug 31, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Subprocessors listed

A current subprocessor or model provider list is published.

A current third-party supplier list is published, which is the core of what this signal asks for. The privacy policy states that Consilio may use third-party sub-processors to deliver services, that engaged processors work under a specified contract with appropriate technical safeguards, and links a list of current third-party suppliers at a public URL requiring no agreement or request. Alongside it a firm can point a client to certifications stated in the same document, ISO/IEC 27001:2022 and HITRUST CSF for Consilio, ISO 27001 or SOC 2 Type 2 for its data centres, Cyber Essentials Plus in the UK, and a Data Privacy Framework certification independently verifiable on the US Department of Commerce register. Two qualifications: the supplier list itself was not opened on 31 Aug 2026, so whether it names AI model providers is unestablished; and no data processing addendum, security page or AI-specific disclosure pack is published, so anything a client's AI clause asks about model handling would need to be negotiated.

Source: Vendor PublishedAs of Aug 31, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Not addressed

No located public material addresses court disclosure or verification certification.

Nothing published would help a lawyer disclose or certify AI use to a court. Searched the Sightline, Aurora and AI PrivGen pages and the privacy policy on 31 Aug 2026: no model is identified or versioned, so which system generated a given privilege log description cannot be established; no audit trail or transparency log of AI decisions is described; nothing states that the expert quality assurance step is recorded, sampled at a stated rate, or producible; and no export, template or guidance exists for an AI-use disclosure or a certification of verification. Aurora publishes dashboards and standardised metrics, but they track matter progress and cost rather than AI provenance. The absence bites hardest on the flagship product, since a privilege log is filed with the court and an opponent challenging it would ask how each description was produced and who checked it.

Source: Operator VerifiedAs of Aug 31, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 1, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746