DataGuard

DataGuard is a European security and compliance platform that runs an organisation's privacy programme and information security management system in one place. The compliance side covers the statutory data protection workflow directly: mapping processing activities into a record of processing, handling data subject requests, running data protection impact assessments, managing incidents and breaches, third-party risk, consent and preference management, cookie management and whistleblowing intake. The security side carries a policy and control library, asset inventory, vendor management, integrated risk management and employee training, with pre-built templates and guided workflows aimed at reaching certification. Supported frameworks are GDPR and UK GDPR, ISO 27001, NIS2, TISAX and the EU AI Act, and the platform is built to run several of them together across multiple entities. AI appears as a layer across that platform rather than as the product: an AI co-pilot, AI-assisted processing of inbound security questionnaires, and automation the company says removes up to forty per cent of manual work. What distinguishes the commercial model is that software and people are sold together. The Base plan is the platform alone for teams working independently; Pro adds hands-on access to DataGuard's own certified consultants; and separate add-ons let a customer nominate DataGuard as its external Data Protection Officer or external Information Security Officer, alongside a global legal analysis add-on that tracks regulatory developments. Pricing is published as package structure with every tier quoted rather than priced. DataCo GmbH trades as DataGuard, is based in Munich and was founded in 2018.

Vendor siteMunich, Germany
Last verifiedSeptember 4, 2026

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Machine learning sits at the edges of a conventional compliance management platform. The substance of what is bought is a policy and control library, a risk register with pre-built treatment plans, an asset inventory, framework templates for ISO 27001, GDPR, NIS2, TISAX and the EU AI Act, evidence collection, and the statutory privacy workflows: record of processing, data subject requests, impact assessments and breach management. Strip the models out and all of that still functions, which is what the platform was before AI. Where AI actually appears is visible in the published plan comparison rather than in the marketing: an **AI co-pilot** listed as a feature line under Admin and Access Controls, and an **AI-assisted questionnaire processing tool for administrative support** under Trust Management, available only with the advanced security platform. AI-powered automation is named as a platform pillar included from the Base tier and the headline claim is up to forty per cent of tasks automated. That is a real layer and it is not the mechanism being sold. Recorded as a limit on this grade rather than glossed: the dedicated AI-Powered Automation page returned navigation and one line of body text, so the detail of the capability could not be read; the grade rests on the plan comparison table, which is explicit about where AI sits.

Source: Vendor Published
Not Rated

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Not yet assessed.

CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Oversight is the explicit selling proposition and no mechanism is described. The published model is experts-in-the-loop: automate when you want it, get expert help when you need it, with certified consultants stepping in for complex decision-making and strategic review, and a dedicated platform page for the concept. That is a genuine position and it is unusual for being sold as a paid tier rather than asserted as a design principle. But the humans in that loop are **DataGuard's consultants, not the customer's own reviewers**, and access to them is what separates the Pro plan from Base, so on the Base plan the oversight described is simply absent from the purchase. Nothing published identifies a review point inside the product, no confidence or uncertainty signal is described against AI output, nothing states which automated actions require approval before taking effect, and nothing addresses what happens when the co-pilot is wrong in a record that later supports a certification audit. The dedicated Experts-in-the-Loop page was not opened in this pass.

Source: Vendor Published
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Scale is asserted at corporate level and every performance figure is disclaimed by the vendor itself. The published claims are specific: more than 4,000 organisations across 50 or more countries, up to forty per cent of tasks automated, certification and compliance seventy-five per cent faster, fifty per cent lower costs, compliance reached in as little as three months, and a hundred per cent first-try pass rate on certification. Third-party standing is real and independently checkable, with G2 category leadership badges for Data Privacy Management across Europe, EMEA and the United Kingdom, a Consent Management high performer badge, a 4.6 rating on both G2 and Capterra, and a Gartner Peer Insights listing. What undercuts the numbers is DataGuard's own footer, which appears on every page: **all data provided is for information only, based on internal estimates, not indicative of KPIs, and given without warranty as to accuracy or reliability.** The vendor is telling a reader not to rely on its own figures, which is candid and leaves the outcome claims without a stated basis. No named customer was read; the Success Stories page was not opened in this pass.

Source: Vendor Published
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Confidentiality is evidenced through security posture rather than through a readable commitment about customer content. What is located and solid: a trust centre publishing an ISO 27001 Statement of Applicability and reports available on request, single sign-on and granular user permissions as published plan features, an Admin and Access Controls feature group, and a company operating from Munich under German and EU data protection law selling data protection compliance as its business. What is not located is the substance this axis measures. Nothing readable states whether customer content is used to train models, no retention or deletion position for customer data was found, and no model provider is identified. **The limit is mine and is stated rather than converted into a finding**: the privacy policy and the separate platform privacy policy both returned navigation and footer with no body across three fetch attempts on two URLs, while the home and pricing pages rendered normally, so this is page-specific rather than a site property. The commitments may well exist in those documents; they could not be read on 4 September 2026 and are not credited either way.

Source: Vendor Published
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

No position on advice versus tooling was located, on a product that sells a regulated advisory role. This matters more here than on most records because of what is actually being offered: an add-on under which the customer **nominates DataGuard as its external Data Protection Officer**, a role with statutory duties and independence requirements under Articles 37 to 39 of the GDPR, alongside an equivalent external Information Security Officer offering and consultants providing information and advice on regulatory obligations and certification requirements. Nothing published addresses where the tooling stops and advice begins, whether the platform's guided workflows and template libraries constitute advice, how the independence of a nominated DPO is preserved when the same company also sells the compliance platform being assessed, or what the customer remains responsible for. Searched the home page, pricing page, product overview, trust centre and the published Consent and Preference Management documentation on 4 September 2026.

Source: Operator Verified
Not Rated

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Not yet assessed.

CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Two limbs are answered and the rest could not be read. Access control is published as product substance rather than assertion, with single sign-on, granular user permissions and a dedicated Admin and Access Controls feature group in the plan comparison, plus role-based permissions reported in the platform's feature set. A trust centre exists at trust.dataguard.com, publishes an ISO 27001 Statement of Applicability and reports, and states its own access route plainly: documents are requested by entering an email address and the team reviews requests within 24 hours. Beyond that the set is unestablished. No retention period, no deletion commitment, no subprocessor list and no incident or breach notification practice for DataGuard's own processing was located, which is a conspicuous gap on a vendor whose product sells incident and breach management to others. As on the confidentiality axis, the reason is stated rather than dressed as an absence: both privacy policies returned no body text across three attempts, and the trust centre's Controls section did not render.

Source: Vendor Published
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

No customer agreement is published anywhere on the site, and this rests on an established page inventory rather than on a failed fetch. The footer carries exactly four legal links: Privacy Policy, Legal Notice, Cookie Policy and Trust Center. The Legal Notice is the Impressum that German law requires of any commercial website and does not govern the customer relationship. There are no terms of service, no general terms and conditions or AGB, no master subscription agreement, no service level document and no acceptable use policy in the navigation, the footer or anywhere else in the site map. No indemnity, liability cap, warranty, uptime commitment or insurance position could therefore be located. A buyer evaluating a platform that will hold its record of processing, its breach register and its certification evidence, and that may supply its nominated Data Protection Officer, has nothing to read on allocation of loss before entering a sales conversation. Checked the full navigation and footer across four rendered pages on 4 September 2026.

Source: Operator Verified
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Named integrations with documentation an implementer could work from, scoped to one module. The published developer documentation covers the Consent and Preference Management product and names its integrations individually with setup guides for each: Salesforce, HubSpot and Microsoft Dynamics for CRM; Braze, Brevo, Mailchimp and Salesforce Marketing Cloud for marketing automation; Auth0 and Ping Identity for identity; Snowflake for data warehousing; FormAssembly, Formstack and WordPress Contact Form 7 for forms. Alongside those sit a documented REST API with an OpenAPI reference and Postman collection, webhooks, bulk data export, import and deletion endpoints, embeddable JavaScript widgets, native and webview mobile integration paths, and single sign-on via Azure Active Directory, SAML and OpenID Connect. Two limits hold this below the top band. The documentation covers the consent module only, which is sold as an add-on rather than as the core platform, and it sits on a separate domain carrying the branding of an acquired product, last updated November 2024. The main platform's own Integrations page was not opened in this pass.

Source: Vendor Published
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Cloud delivery is implied throughout and neither the tenancy model nor a region is stated. European positioning is heavy and consistent, with the company describing itself as the European leader in security and compliance software, operating from Munich, and marketing secure hosting and infrastructure built to meet strict GDPR requirements. None of that is a residency statement: no country, region or data centre is named for where customer data is stored or processed, and secure hosting built for GDPR describes an intention rather than a location. The nearest the published material comes is an enterprise-tier reference to multinationals needing region-specific configurations, which describes a configuration capability rather than a residency option a buyer could select. Nothing states whether the platform is single or multi-tenant, no dedicated or private deployment is offered at any tier, and no separation is drawn between where data sits and where any AI processing happens.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

A real trust centre with a self-serve access route, short of the naming a top grade needs. The portal at trust.dataguard.com renders, is publicly linked from the site footer, and states its own access mechanism plainly, which is the thing most portals leave ambiguous: documents are requested by clicking the document and entering an email address, requests are reviewed by the team typically within 24 hours, and anything not listed can be requested by email. That is a self-serve request fulfilled without a sales conversation rather than a form promising an account executive, which is the distinction that earns credit. One artifact is named specifically and is DataGuard's own ISMS document rather than a badge: an **ISO 27001 Statement of Applicability**, alongside a Resources section listing Reports. What is missing from the top band: no certifying body or auditor is named, no certificate number, scope or observation period is published, no date or validity period appears, and the Reports entry is generic so a buyer cannot tell which reports exist before asking. The Controls section of the portal did not render.

Source: Vendor Published
Not Rated

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Not yet assessed.

CC on Commercial TransparencyPricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Unusually detailed package structure with no figure and no unit of charge anywhere. What is published is genuinely useful: three named tiers with stated audiences, Base as the platform alone for teams with internal expertise, Pro adding hands-on access to in-house experts, Enterprise for complex multi-entity needs; a feature comparison running across roughly fifteen areas covering ISMS documentation, training, risks, controls, vendor management, assets, trust management, admin controls, onboarding, expertise, the annual security programme and information security officer support; explicit markers showing which capabilities require the advanced platform or a dedicated expert; and seven named add-ons that establish what costs extra, including consent management, cookie management, whistleblowing, global legal analysis, exposure management, external Information Security Officer and external Data Protection Officer. A buyer can therefore work out precisely what is in and out of each tier. What no buyer can learn is what any of it costs, or even how it is metered: every tier and every route resolves to Get a quote, and no figure, band, range or charging unit appears anywhere. Nothing states whether pricing runs per seat, per entity, per framework or per employee.

Source: Vendor Published
CC on Firm and Practice CoverageCoverage is claimed broadly, for all firms or all practice areas, without evidence that the breadth is real.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Coverage is described by regulatory framework and by company size, and the buyer this index cares about is never addressed. The framework dimension is precise and is the product's real organising principle: GDPR and UK GDPR, ISO 27001, NIS2, TISAX and the EU AI Act, each with its own page, with multi-entity and multi-framework operation named as a capability and 4,000 organisations across 50 or more countries claimed. The segmentation dimension is thin and revealing. **The Solutions menu contains exactly two entries, DataGuard for SMEs and DataGuard for Corporates**, so the only buyer axis the vendor publishes is headcount. No legal, in-house counsel, data protection officer or compliance function page exists, no role is addressed by title anywhere, and no case study was read that would identify who inside a customer owns the tool. That absence is what makes the membership screen turn on function rather than on the buyer surface, and it is recorded here because it is also a coverage finding: a reader of this index cannot learn from DataGuard's own material whether the legal department is the intended owner.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Not recorded

This signal has not been recorded for this vendor yet. It is not a finding either way.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Not recorded

This signal has not been recorded for this vendor yet. It is not a finding either way.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Own model, documented

The product maintains its own permission model, documented, requiring the firm to keep it aligned.

DataGuard operates its own permission model and publishes it as product substance. The plan comparison names single sign-on and granular user permissions together under an Admin and Access Controls feature group available across tiers, and role-based permissions appear in the platform's documented feature set. The consent module's developer documentation adds the mechanics on that side, with single sign-on via Azure Active Directory, SAML and OpenID Connect, API authentication and separate environments. Multi-entity operation is published as a capability, which is the mechanism by which a group separates one subsidiary's compliance programme from another's. What is not published is how those permissions map to a wall in practice, and nothing addresses separation between engagements where DataGuard's own consultants have access under the Pro tier or as a nominated external Data Protection Officer, which is the segregation question this hybrid model actually raises.

Source: Vendor PublishedAs of Sep 4, 2026

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Not recorded

This signal has not been recorded for this vendor yet. It is not a finding either way.

Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Jurisdictions only

Coverage is described by jurisdiction with no identification of the underlying corpus.

The regulatory material behind the product is described by framework rather than by source. The frameworks covered are named individually and consistently across the site: GDPR, UK GDPR, ISO 27001, NIS2, TISAX and the EU AI Act, delivered through pre-built policy templates, off-the-shelf risk and control libraries and guided workflows, with a global legal analysis add-on that tracks legal requirements and regulatory developments. That tells a buyer which regimes are in scope, which is the jurisdictional description this value records. What is absent is identification of the underlying material: no regulatory data source, publisher or feed is named, no update cadence is published for the template and control libraries or for the legal analysis add-on, and no licensing basis is stated for any standard reproduced in the platform, which is a live question for ISO 27001 and TISAX content specifically since both are proprietary and the site separately disclaims any affiliation with the ENX Association that owns TISAX.

Source: Vendor PublishedAs of Sep 4, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

Currency is addressed as a product capability rather than as verification of authority. The platform is sold on staying current with changing regulation, with a global legal analysis add-on that tracks legal requirements and regulatory development, framework libraries maintained across GDPR, ISO 27001, NIS2, TISAX and the EU AI Act, and continuous monitoring and periodic review workflows. None of that is the check this signal measures: nothing states how or how often the underlying regulatory content is updated, no effective-date or version indicator on template or control content is described, nothing flags when a requirement a customer has already mapped has changed, and no verification prompt exists. The product does not retrieve or cite primary legal authority, so the question lands obliquely, but for a compliance platform the equivalent risk is real, since a control library that has fallen behind a regulation is the same failure in a different form.

Source: Vendor PublishedAs of Sep 4, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

No located public material describes what the AI does when it cannot answer reliably. Nothing describes an abstention path, a no-answer state, or a confidence or grounding signal surfaced against output from the AI co-pilot or the AI-assisted security questionnaire tool. The nearest published concept is the experts-in-the-loop tier, under which DataGuard's certified consultants step in for complex decision-making and strategic review, but that is a commercial escalation to human help rather than a description of the system's own behaviour under uncertainty, and it is available only from the Pro plan upward. Recorded as a limit on this row: the dedicated AI-Powered Automation page returned navigation and a single line of body text, and the Experts-in-the-Loop page was not opened. Searched the home page, pricing page, trust centre and the published consent documentation on 4 September 2026.

Source: Operator VerifiedAs of Sep 4, 2026

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

The AI Hallucination Cases database maintained by Damien Charlotin was searched on 4 September 2026 on both the product name DataGuard and the corporate name DataCo GmbH. No court order, opinion or disciplinary record naming the product was located. The database tracks fabricated legal citations in court filings, and this product supports compliance programme management rather than producing court submissions, so its exposure to that specific failure is structurally low. This records the state of the public record on that date and is not a finding about the product.

Source: Operator VerifiedAs of Sep 4, 2026Evidence
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No located public material engages professional guidance or any professional authority. The regulatory frameworks the product serves are named throughout, but a framework is the subject matter of the compliance work rather than guidance on how a professional should use software in that work. No bar association, law society, supervisory authority, data protection authority or professional body is named, no guidance or opinion is cited, and nothing addresses the professional obligations of a Data Protection Officer using the platform or of DataGuard's own personnel when nominated to that statutory role under the external Data Protection Officer add-on. The European Data Protection Board and national supervisory authorities publish directly relevant guidance and none is referenced on any surface read. Searched the home page, pricing page, product overview, trust centre and consent documentation on 4 September 2026.

Source: Operator VerifiedAs of Sep 4, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure.

Efficiency claims are published prominently and no billing question is engaged. The stated savings are specific and repeated across pages: up to forty per cent of tasks automated, seventy-five per cent less manual effort, fifty per cent lower costs, and certification reached up to seventy-five per cent faster. Nothing addresses what happens to a fee when that work compresses. The question has a particular shape here because DataGuard sells advisory time alongside software through the Pro tier, the dedicated expert upgrades and the external officer add-ons, so automation of the platform work bears directly on the advisory hours a customer buys, and nothing published addresses that relationship. No per-engagement record of AI-assisted work is described. Recorded alongside the claims: DataGuard's own site footer states that all such figures are internal estimates given without warranty as to accuracy.

Source: Vendor PublishedAs of Sep 4, 2026

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

On request only

The material exists behind a sales conversation or an executed agreement.

A working request route exists and the artifacts behind it could not be established. The trust centre at trust.dataguard.com is publicly linked, renders, and publishes its own access mechanism: documents are requested by entering an email address, requests are reviewed typically within 24 hours, and anything not listed can be requested by email to the company. An ISO 27001 Statement of Applicability is named and a Reports section exists. That is a genuine on-request route fulfilled without a sales conversation, which is what this value records. What could not be established is whether it reaches the material a client's AI clause asks for: no subprocessor list was located, no data processing agreement is published, no model provider is identified anywhere, and the portal's Controls section did not render. Both privacy policies returned no body text across three attempts, so nothing forwardable on data handling could be read in advance.

Source: Vendor PublishedAs of Sep 4, 2026

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

Audit-grade recording is core product function and none of it is described as covering the AI. What the platform produces is substantial and is the point of buying it: automated evidence collection, control monitoring, audit-ready reporting, periodic reviews, internal audit functionality under the expert tiers, and, in the consent module, an explicit audit trail of consent transactions with a documented data export endpoint. A customer can therefore evidence what its compliance programme did and when. What is absent is the model dimension entirely: nothing states that output from the AI co-pilot or the AI-assisted questionnaire tool is marked as AI-generated in the record, no model or version is captured against an entry, no record of what a human reviewed or amended before an entry became evidence is described, and no guidance exists for disclosing AI involvement to a certification auditor or supervisory authority. That gap sits directly against the product's purpose, since the evidence it generates is presented to auditors.

Source: Vendor PublishedAs of Sep 4, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 4, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746