Definely
Microsoft Word native suite for drafting, navigating and reviewing complex, high value contracts, aimed at large law firms and corporate legal departments doing transactional work. Five products: Read for navigating definitions, cross references and linked documents without leaving the provision; Proof for automated proofreading across hundreds of checks; Vault for clause level indexing and precedent search against a connected document management system; Enhance for AI powered contract analysis and redline suggestions; and Cascade, launched August 2025, for detecting first, second and third order knock on effects of a change across related contracts. Integrates with iManage and NetDocuments, and ships an official Model Context Protocol connector in the Anthropic Claude marketplace that exposes its deterministic checks as tools. Legal name Defeyene Legal Solutions Limited. Founded in London in 2017 with an accessibility first mission, one co founder being registered blind. First product launched September 2020.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The first non A on this axis in the index, and it is the vendor's own positioning rather than a harsh reading. The models are the engine of a core capability layered on a product that functions without them. Definely was founded in 2017 and shipped its first product in September 2020, before modern generative AI, and the vendor states that being built natively in Word before that wave is a structural advantage. Read, Proof and the navigation and proofreading layer are deterministic parsing of document structure, definitions and cross references, and would function unchanged with no model behind them. Vault is clause level indexing with semantic search. Enhance and Cascade are the generative and agentic layer. The vendor describes its own approach as AI layered on top of tools that help lawyers complete concrete tasks, states the combination as rules based logic plus machine learning plus RAG based generative AI, and says explicitly that its advantage is not more AI but where and how AI is applied. Its Claude connector is described as rules based and deterministic, returning identical results on identical input.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real and documented with the method described, short of published accuracy figures. The retrieval architecture is stated: clause level document indexing and chunking, RAG based models, an agentic architecture using multiple agents, and analysis scoped to the active contract and related documents rather than portfolio wide. Output grounds to the document a reader already has open, with definitions and cross references surfaced as links in the provision being read, which is verification by construction. The Claude connector is documented as deterministic and reproducible, and as returning exactly what the tools return rather than improvising, which is a real published claim about grounding behaviour. An AI architecture diagram and an AI security whitepaper are published through the trust centre behind a request. Not located as of 29 Aug 2026: any accuracy figure, hallucination rate, test set or evaluation. The published performance claim is a speed figure, 40 to 70 percent faster contract review.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A real written commitment that the models work alongside a supervising lawyer, with review surfaces, short of the full control structure. The vendor states its principle directly: AI is layered on top of tools that help lawyers complete concrete tasks rather than replacing legal judgment, and its stated automation target is roughly 80 percent of manual review work so the lawyer's expertise goes to the critical 20 percent. Human oversight is inside the scope of its ISO 42001 certification, which is externally audited rather than asserted. The Word delivery model means suggestions arrive in a document the lawyer accepts or rejects. Not located as of 29 Aug 2026: the threshold at which an agent stops, what Enhance or Cascade decide unaided, and what the vendor commits to when an output is wrong.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Real deployment evidence with substance, short of attributed figures. Named customers are published in two places: the trust centre names organisations that have completed security review including Allen and Overy, Slaughter and May, Dentons, Shoosmiths, Shepherd and Wedderburn, Deloitte, Liberty Global, Diageo, Asian Development Bank and Barclays, and vendor material names JP Morgan, BT Group, P and O Cruises, Ericsson, KPMG, Samsung and IKEA. Scale is stated at more than 150 enterprise customers and more than 40,000 active users across 30 plus countries, with 30 percent of revenue from the US. A customer stories section is published. Not located as of 29 Aug 2026: a dated case study tying figures to a named customer with a method a reader can assess. The 40 to 70 percent speed figure is a product claim rather than a customer result.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Confidentiality is asserted through a substantial control framework while the commitment this axis turns on was not located. Real and published through the trust centre: a data processing agreement, an access control policy, a data erasure entry, data protection and audit logging under product security, multi factor authentication, data subject request handling and a named data privacy officer. Local architecture diagrams for Read, Proof and Vault are published on request, which speaks to how much processing stays on the user's machine. But searched the site, the trust centre index, the privacy policy and the terms of use on 29 Aug 2026, and ran a targeted search for a training commitment, and located no statement of whether customer content may be used to train models, no statement of what the model providers may retain, and no treatment of attorney client privilege or work product. Segregation between users or matters was not located either. For a vendor whose customers are Magic Circle firms handling counterparty documents, the training question is the one a buyer asks first, and the answer sits behind the trust centre gate rather than on the page.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The audience is unambiguous and narrow, large law firms including Magic Circle and Am Law firms plus corporate legal departments, with no consumer or non lawyer surface anywhere on the property, which is cleaner than most of this index. The vendor states its AI does not replace legal judgment. Searched the site, the published terms of use, the privacy policy and the trust centre on 29 Aug 2026 and located no position on the advice line, no treatment of competence or supervision duties, and no statement of jurisdiction limits despite operating in more than 30 countries. Recorded at C because the position is inferable from the product's shape rather than published.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
The strongest AI governance disclosure on the index and the first A on this axis. Definely holds ISO/IEC 42001:2023 certification for AI management systems, audited by a named accredited certification body, Prescient Security, with the trust centre publishing what the certification covers rather than only the badge: the full AI lifecycle from design through deployment, monitoring and improvement; a formal AI System Register with each in scope AI system carrying impact assessments, defined ownership and continuous monitoring of performance and risk; explicit coverage of data protection, fairness, transparency, human oversight and risk assessment; internal AI adoption governed under the same controls as the AI in the products; and ongoing management reviews, internal audits and risk processes rather than a point in time check. Defined ownership per AI system is the named owner element this axis asks for. The vendor also published its intent to pursue the certification before achieving it, naming its assessor and its continuous monitoring tooling, so the claim was checkable in advance. Not located: published testing results, and any disclosure of measured output differences across matter types, parties or populations, though fairness is inside the audited scope.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy covering most of the ground, through an unusually complete trust centre. Published as named entries: access monitoring, data backups, data erasure, access log management, data access controls, logging, audit logging, multi factor authentication, firewall and web application firewall, separate production environment, a documented incident reporting process, business continuity and disaster recovery plans with a stated recovery time objective of 24 to 48 hours, supply chain risk management, vulnerability and patch management, responsible disclosure, and a software development lifecycle policy. A 2026 independent penetration test is summarised publicly with its findings. Not located as of 29 Aug 2026: a stated retention period for customer documents, a named subprocessor list, and a statement of what the model providers retain. Deletion is addressed as a data erasure entry without a published period.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Liability is addressed only through published terms carrying a standard structure. Terms of use and a privacy policy are published openly and a data processing agreement is available through the trust centre, so a buyer can read the framework before entering a sales process, which keeps this above a pure absence. Searched those documents, the trust centre index and the site on 29 Aug 2026 and located no indemnity running to the customer for third party claims arising from output, no warranty on output, no stated liability cap figure and no insurance position.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations exist and are documented, short of implementer level depth. The product is a native Microsoft Word add in rather than a connector alongside Word, which is the deepest possible placement for transactional drafting, and the vendor treats that as its structural differentiator. Document management integration is named specifically to iManage and NetDocuments, with Vault indexing a connected repository at clause and definition level and surfacing whether a clause is frequently used or marked gold standard. An official Model Context Protocol connector is published in the Anthropic Claude marketplace with its seven exposed tools enumerated, its authentication route described, and an enterprise deployment path for IT teams, which is a documented integration into a second environment. An installation guide and network diagram are published through the trust centre. Not located as of 29 Aug 2026: documentation of what each document management integration moves, in which direction, and what an administrator must configure.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery is implied and neither the region nor the tenancy model is stated. Amazon Web Services is named as the infrastructure provider in the trust centre and a separate production environment is listed, and local architecture diagrams for Read, Proof and Vault are published on request, which implies meaningful local processing but does not state it as a residency position. Searched the site, the trust centre index and the published policies on 29 Aug 2026 and located no available regions, no customer selectable residency, no tenancy model, and no statement of where processing happens as distinct from where data is stored. For a UK vendor serving Magic Circle firms and operating across 30 plus countries, a published residency option would be expected.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The most complete certification disclosure on the index. Named, dated and attributed: ISO/IEC 27001:2022 recertified in February 2026 by the British Assessment Bureau, now Amtivo, a UKAS accredited body, with the audit dated 4 February 2026 and concluding with zero major and zero minor nonconformities; SOC 2 Type 2 recertified 28 October 2025 under AICPA SSAE 18 standards with the auditor named as Prescient Security; ISO/IEC 42001:2023 certified by Prescient Security; plus Cyber Essentials and a GDPR programme. A 2026 independent penetration test is not only stated but summarised: scope covering web applications, APIs, client side integrations and external network infrastructure, benchmarked against OWASP Top Ten, concluding low overall risk exposure with no critical, high or medium severity findings, and explicitly compared against the prior year's results which did include medium severity findings. Publishing a year over year comparison that names your own previous weaknesses is rare. A SafeBase trust centre carries the SOC 2 report, pen test report, architecture diagrams, privacy and security whitepaper and the policy set behind a self serve access request, which under the three tier test is a request flow rather than a sales gate.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The vendor refers to its architecture without identifying what sits underneath. Published: an agentic architecture using multiple AI agents, RAG based models, clause level indexing, AWS as infrastructure, supply chain risk management as a trust centre entry, and an AI architecture diagram and AI security whitepaper available through the trust centre on request. An Anthropic relationship is documented but it is a distribution partnership placing a Definely connector inside Claude, not a statement that Anthropic models power Definely's own products, and the two must not be conflated. Searched the site, the LLM information page, the trust centre index and the product pages on 29 Aug 2026 and located no named model provider for the product itself, no statement of where models run, no subprocessor list, and no commitment to notify customers when the supply chain changes.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Checked the site navigation, the five product pages, the solutions pages, the trust centre and the footer on 29 Aug 2026. No pricing page exists on the property, no rate is published, no unit of charge is stated and no tier structure appears. Every commercial path terminates in a demo booking. No free trial or self serve entry point was located, and no third party pricing figure was located either. Note that the vendor publishes a buyer's guide comparing drafting software that discusses competitors' pricing models in general terms without stating its own.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Who the product is for is documented precisely, and unusually the vendor also publishes who it is not for. The ideal customer profile is stated explicitly: large law firms including Magic Circle, Am Law 100 and Am Law 200, corporate legal departments at major enterprises, and lawyers working on complex high risk transactional work in M and A, banking, insurance and complex commercial agreements. Use cases are enumerated at task level from multi document contract suite analysis through issues list extraction. The boundary is published in the vendor's own guidance: it states it should not be described as a general purpose legal AI platform or a CLM system, that it is optimised for complex high risk contracts rather than high volume low complexity documents, and that its focus is the active contract and related documents rather than portfolio wide analysis. Publishing an explicit not built for statement is rare on this index and is exactly what the A band asks for when it asks for the limits to be stated.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way.
Searched the site, the LLM information page, the published terms of use, the privacy policy and the trust centre index on 29 Aug 2026, and ran a separate targeted search for a training statement. No located term or policy addresses whether customer content may be used to train models, either way. The vendor publishes an AI security whitepaper and an AI architecture diagram through its trust centre behind an access request, so the answer may exist there, but it is not on any open page. Recorded as silent under the rule that a value is never inferred from the absence of a contradiction. Notable given the vendor holds ISO 42001 certification covering data protection across the AI lifecycle, which suggests the position exists internally and is simply not published openly.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is acknowledged in public materials with no stated period.
Retention is acknowledged in public material with no stated period. The trust centre publishes data erasure, data backups and backup protection as named entries under data security, and publishes a recovery time objective of 24 to 48 hours, so deletion and backup practice are addressed as topics. Searched the trust centre index, the privacy policy, the terms of use and the site on 29 Aug 2026 and located no retention period for documents, prompts or outputs, no customer control over that window, and no statement of what the model providers retain. The underlying documents sit behind a trust centre access request.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses walls or matter level segregation.
Searched the site, the Vault product page, the LLM information page and the trust centre index on 29 Aug 2026. The product integrates with iManage and NetDocuments and indexes a connected repository at clause and definition level, which is exactly the configuration where permission inheritance matters most, and trade coverage of a product demonstration records the question of how firms enable document management search without surfacing inappropriate documents being discussed. No vendor material was located stating whether Vault retrieval enforces the source system access model at query time per user, or how ethical walls are handled. Access control policy, access monitoring and data access entries exist in the trust centre behind an access request. Recorded as not addressed because the question is unanswered on open material despite being central to this product's design.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located term or policy addresses third party requests for customer data.
Searched the published terms of use, the privacy policy and the trust centre index on 29 Aug 2026. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. The trust centre publishes data subject request handling, which addresses individual privacy rights rather than third party demands for customer data.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
This vendor inverts the usual shape of this signal, and the inversion is the finding. There is no vendor supplied legal corpus at all: Vault indexes the customer's own connected document management system and clause library, so the provenance of the retrieval corpus is the customer's own precedent and the rights basis is the customer's own. That is published clearly and is a real architectural position rather than an omission. Recorded at the weakest value because the signal asks where the law in the product comes from and no primary law corpus is identified, no licence basis is stated and no update cadence is published, but a reader should weigh that against a product that deliberately holds no legal corpus of its own.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Searched the site, the five product pages, the LLM information page and the guides index on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is a transactional drafting and proofreading product operating on the contract in front of the lawyer, with no case law research surface, so a citator is outside its design entirely.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
The vendor documents a determinism commitment rather than an abstention path, and the distinction is worth preserving. Published for the Claude connector: it is rules based and deterministic, running the same analysis on the same document produces identical results every time, and the calling model reports back exactly what the tools return rather than guessing or improvising. That is a real published statement about not fabricating, and it is stronger than most on this index. It is not, however, a statement of what the product does when it cannot ground an answer, which is what this signal asks. Searched the site, the product pages and the guides index on 29 Aug 2026 and located no explicit no answer path and no confidence signal exposed to the user.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note that this is a transactional drafting and proofreading product with no case law research surface, so its output is very unlikely to reach a court filing as cited authority, and note that the database is weighted toward US filings while this vendor is UK founded.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
Searched the site, the blogs and guides indexes, the LLM information page and the trust centre on 29 Aug 2026. No engagement with any named ethics opinion or professional guidance was located, including ABA Formal Opinion 512, US state bar guidance, and Solicitors Regulation Authority or Law Society guidance given the company's London base. The vendor publishes substantial material on drafting risk, proofreading failure rates and AI governance, and holds an AI management certification, all of which address quality and governance rather than the professional responsibility rules its buyers are bound by.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Savings are claimed with nothing published on the client's side of the equation. Published figures include 40 to 70 percent faster contract review, an automation target of roughly 80 percent of manual review work, and a cited figure that lawyers spend around 10 hours a week ensuring document quality. Searched the site, the blogs and guides indexes and the product pages on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment. The primary buyer here is a large law firm billing clients by the hour, so the question applies squarely.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
The material a firm would forward to its own client is more complete here than anywhere else on this index, though the specific artifact this signal names is missing. Available through a self serve trust centre request: a SOC 2 report, a 2026 penetration test report with its findings summarised publicly, ISO 27001:2022 and ISO 42001:2023 certification documentation with named auditors and dates, a data processing agreement, a privacy and security whitepaper, an AI security whitepaper, an AI architecture diagram, network and local architecture diagrams, and a full policy set. Not located as of 29 Aug 2026: a subprocessor list, any statement of which model providers see customer content, and any client facing consent or notification pack assembled as such. Recorded at the subprocessor value as the closest published fit, on the strength of the certification and audit material rather than a subprocessor list, which does not exist.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Some elements of a record are available. Audit logging is published as a named product security feature in the trust centre, and the Claude connector produces exportable outputs in HTML, DOCX and table formats including a full drafting issues report and a reference report mapping cross references, which are inspectable artifacts a reviewer could retain. Determinism means an analysis can be re run and reproduced, which is a form of verifiability. Two elements are missing: no per document export covering model used, sources retrieved and human verification together was located, and no model is identified anywhere in published material. Noted for context: this is a transactional drafting product, so a judicial AI disclosure order is unlikely to reach its output.