DISCO
Cloud native ediscovery and litigation platform spanning DISCO Ediscovery, DISCO Review, DISCO Hold, Request and Case Builder, sold to corporate litigation teams, Am Law 200 firms and government. Cecilia AI is the generative layer: Cecilia Q&A answers conversational questions about case evidence with citations always included, Cecilia Auto Review performs first pass review at around 25,000 documents an hour against plain English prompts crafted with the vendor's ediscovery experts, giving a written explanation for each tag suggestion, plus Doc Summaries and Timelines. Agentic Cecilia adds an autonomous multi step reasoning engine to Q&A with user selectable Quick thinking and Advanced research modes, the vendor claiming to be first to bring agentic AI to fact investigation and ediscovery at scale. Operated by CS Disco, Inc., listed on Nasdaq as LAW, which reported 1,549 customers including 330 large customers and a 98 percent dollar based net retention rate as at 31 December 2025, and moved to a usage based pricing model in 2026.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of a core capability layered on a platform that would function without them. DISCO Ediscovery is a cloud native platform covering the EDRM with upload, search, review and production, sold on speed and architecture, and it predates the generative layer: Cecilia AI was released in 2023, roughly a decade after the company was founded. What the models drive is substantial rather than peripheral, which is why this is not a C: Cecilia Q&A, Auto Review performing first pass review at scale, Doc Summaries, Timelines, and an agentic multi step reasoning engine. Fourth ediscovery record and the third B on this axis, distinguishing all three from Reveal, which was graded A because its platform was assembled around acquired model capability rather than having a model layer added to it.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is documented as a hard constraint and measurement exists without being independently checkable. Grounding is stated in absolute terms rather than as a claim about quality: Cecilia Q&A returns an answer crafted only from the customer's evidence, with citations always included, and Agentic Cecilia provides explanations of the logic, reasoning and citations to underlying documents every time. Auto Review gives a written explanation for each individual tag suggestion, so a reviewer sees why a classification was made per document. Figures are published: an Am Law 50 firm evaluating Auto Review on a specific issue tag achieved 92 percent recall and precision with a 97 percent total agreement rate, and the vendor claims performance metrics above industry standards. Those are the right metrics for review classification and they are specific. What holds this off an A is that the evaluating firm is unnamed, the evaluation is undated, and no methodology is published, so an outsider cannot check or reproduce it. Recorded as vendor reported customer results rather than as independent measurement.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A real published commitment with an unusually explicit autonomy control, short of thresholds. The distinctive element is that autonomy is user selectable rather than fixed: Agentic Cecilia offers Quick thinking and Advanced research modes and the vendor tells the customer to choose depending on need, so the depth of autonomous multi step reasoning is a decision the user makes per task. Review surfaces are concrete and per document: written explanations for each tag suggestion in Auto Review, and explanations of logic, reasoning and citations for every agentic answer. Prompts for Auto Review are crafted in collaboration with the vendor's ediscovery experts rather than left to the user alone. The vendor also positions the AI as a check on human work, suggesting it be used to verify the accuracy of review performed by human reviewers, which is an inversion worth recording. Not located as of 29 Aug 2026: any threshold at which an agentic run stops or escalates, and what the vendor commits to when an output is wrong.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
The strongest adoption evidence in the ediscovery category, on a materially better evidence class than marketing copy. Because the operator is a Nasdaq listed company, adoption figures appear in a regulated annual filing rather than on a web page: 1,549 customers including 330 large customers, and a 98 percent dollar based net retention rate as at 31 December 2025. A retention figure of that kind is a stronger signal of whether a product works in production than any testimonial, and it carries securities law consequences if wrong. Outcome figures are also published, though from an unnamed customer: an Am Law 50 firm reduced a first pass issue tag review from a traditional 1,000 hours to under 24 hours using Auto Review, with 92 percent recall and precision. Short of an A because no customer is named, the evaluations are undated, and no assessable method accompanies the outcome figures.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments with the training limb answered plainly, short of the other two. Training is addressed at the layer that matters and in the right direction: the vendor states the language models used in Cecilia AI are not permitted to train on customer data, and separately that confidential data is never sent to train another company's model. That is a contractual constraint on the providers rather than a description of the vendor's intentions. Supporting controls are published: full encryption in transit and at rest, SOC 2 Type 2 covering security, availability and privacy, ISO 27001, and GDPR compliance with the regulated filing detailing EU GDPR, UK GDPR and CCPA obligations and EEA and UK to US transfer mechanisms. Two gaps hold this off an A. No retention or deletion terms were located. No segregation model between users or matters was located, which matters for a platform holding entire document universes and marketed to firms handling multiple concurrent matters.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The audience is professional and the position is unstated. Users are corporate litigation teams, Am Law 200 firms and government legal teams, with no consumer surface located, and the product analyses collected evidence rather than giving advice, so the advice line question arises less sharply than for a research or drafting tool. Searched the offerings pages, the Cecilia and agentic Cecilia pages, the resources index and the security pages on 29 Aug 2026 and located no published position on advice versus tooling, no treatment of competence or supervision duties as professional obligations, and no jurisdiction limits. Worth recording as adjacent rather than credit: Auto Review prompts are crafted in collaboration with the vendor's own ediscovery experts, which places vendor personnel inside the customer's review methodology, and nothing published addresses how that interacts with the supervising lawyer's responsibility for the review.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Risk is acknowledged in a regulated filing without a governance framework being published. The annual filing discusses AI related operational and regulatory risks explicitly alongside cybersecurity, data privacy compliance and reliance on third party model and cloud providers, which is a real acknowledgement that carries legal weight and is more than a marketing page would give. Per document explanations for every tag suggestion and per answer reasoning are genuine transparency mechanisms built into the product. Searched the offerings pages, the Cecilia and agentic Cecilia pages, the security pages and the resources index on 29 Aug 2026 and located no published AI governance framework, no AI principles document, no AI management certification such as ISO 42001, no named owner of model governance, no pre release testing regime, and nothing on uneven output across matter types, parties or populations. For a product performing autonomous first pass classification at 25,000 documents an hour, the absence of any published position on differential performance is the gap this axis exists to mark.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy covering most of the ground, with the control framework enumerated rather than asserted. The vendor names its security control categories individually: Communications Security, System Acquisition, Development and Maintenance, Supplier Relationships, Information Security Incident Management, Business Continuity Management, and Compliance. Naming incident management and supplier relationships as standing control categories is more than most records here provide. Also published: SOC 2 Type 2 audited annually across security, availability and privacy, ISO 27001 certification, third party penetration testing, full encryption in transit and at rest, and AWS hosting with a stated design goal of minimising data footprint. The regulated filing adds cross border transfer mechanisms for EEA and UK to US data movement. Not located as of 29 Aug 2026: a stated retention period or deletion control for customer data, prompts or Cecilia outputs, and a named subprocessor list.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Searched the offerings pages, the Cecilia and agentic Cecilia pages, the security pages, the resources index and available summaries of the annual filing on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer agreement or master terms was located on the surfaces reached. Recorded as a pure absence on those surfaces. Worth recording precisely because this operator is publicly listed and therefore discloses more than a private company must: analysis of the annual filing notes that contractual remedies and insurance coverage are areas future filings should clarify, which indicates the question is open in the regulated disclosure as well as on the marketing surfaces. Rebuttable with one link to published terms.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations exist, are named individually, and cover both directions a litigation platform needs. Collection and hold integrations are named: Microsoft 365 and Google Workspace, with legal hold policies, notifications and audit trails integrated into both, plus cloud storage platforms. Migration in is addressed explicitly and unusually, with tools to ingest or convert data from other discovery systems including Relativity, Eclipse and Excel, which lowers the switching cost the platform's competitors rely on. The vendor also describes horizontal SaaS partnerships across platforms enterprise and legal teams already use. Not located as of 29 Aug 2026: a consolidated integrations index page, per integration documentation of what moves in which direction and what an administrator configures, and any legal document management connector.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery and the hosting provider are stated, and residency is not offered. AWS is named as the hosting infrastructure, with the vendor stating the platform was designed from the outset to operate in the cloud and integrates with AWS to improve security, minimise data footprint and enhance privacy controls. Cloud native architecture is a stated performance position rather than only a delivery model. What is missing is customer choice: searched the offerings pages, the security pages and the resources index on 29 Aug 2026 and located no named regions, no customer selectable residency, no tenancy model, and no on premises or private deployment option. The regulated filing identifies cross border data transfers as among the highest operational risks and details EEA and UK to US transfer mechanisms, which indicates processing concentrated in the United States and is recorded here because it bears directly on residency.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real, named, and stated with scope and cadence, short of auditor and report access. SOC 2 Type 2 is named with the audit cadence stated as annual and the trust services criteria enumerated as security, availability and privacy, which is precise. ISO 27001 is named with its scope stated as the technical and operational delivery of the service offering, and stating what a certificate actually covers is something almost no record on this index does. Third party penetration testing is stated alongside the certifications, and GDPR compliance is claimed with the regulated filing noting that maintaining certifications including ISO 27001 is a key dependency. Not located as of 29 Aug 2026: the SOC 2 coverage period, the named auditing firm for either certification, a report request route, and any trust portal.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The terms binding the model providers are disclosed and the providers are not named. Published: the language models used in Cecilia AI are not permitted to train on customer data, and confidential data is never sent to train another company's model, which tells a buyer that third party models are in the path and what constrains them. AWS is named as the hosting infrastructure. The regulated filing acknowledges reliance on third party cloud providers and software as a standing risk. Searched the offerings pages, the Cecilia and agentic Cecilia pages, the security pages and the resources index on 29 Aug 2026 and located no named model or provider, no statement of where the generative processing runs relative to the platform, no subprocessor list, and no commitment to notify customers when the supply chain changes.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The pricing model is disclosed without a rate, and the disclosure comes from a regulated filing rather than a marketing page. The operator states in its annual filing that it revised its pricing model in 2026 to usage based, which tells a buyer the unit of charge is consumption rather than seats, a materially different commitment for an ediscovery platform where data volume drives cost and where unpredictable bills are the standing complaint of the category. Searched the offerings pages, the resources index and the security pages on 29 Aug 2026 and located no pricing page, no rate, no published unit definition and no tier structure. Recorded at C on the strength of the published pricing model, and short of higher because a buyer still cannot estimate cost from anything published.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is described with substance and quantified through the regulated filing. Segments named: corporate litigation teams, Am Law 200 law firms, and government, the last with a dedicated product overview for DISCO Ediscovery for Government. Scale is quantified precisely rather than claimed, at 1,549 customers including 330 large customers as at 31 December 2025. Practice coverage spans the EDRM end to end across five named products covering hold, request, ediscovery, review and case building, with published practice specific material including a paper on AI for intellectual property litigation. Not located as of 29 Aug 2026: firm size segmentation below the Am Law 200 tier, jurisdictional or language coverage stated as such, and any statement of what the platform is not built for.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
A public policy or trust page states no training on customer content, with no matching term located in the published agreement.
The commitment is stated as a permission constraint on the providers rather than as an intention, which is the stronger form. Published: the language models used in Cecilia AI are not permitted to train on customer data, and separately that confidential data is never sent to train another company's model. Framing it as what the models are not permitted to do implies a contractual term binding the provider rather than a policy the vendor could revise unilaterally. Recorded at policy never on that basis. One limit stated rather than resolved: the located statements address the third party model layer, and no separate statement was found on whether the vendor itself trains or fine tunes any model on customer content, which is a distinct question and unanswered on the surfaces reached.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
Searched the offerings pages, the security features page, the Cecilia and agentic Cecilia pages, the resources index and available summaries of the annual filing on 29 Aug 2026. No public material states how long case documents, Cecilia prompts, generated answers or Auto Review tag explanations are retained, whether a customer controls the window, or whether deletion is available. The gap has a specific edge here: Auto Review produces a written explanation for every tag suggestion across datasets processed at around 25,000 documents an hour, so the product generates a very large body of derived commentary about a customer's evidence, and nothing located governs how long that persists.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses walls or matter level segregation.
Searched the offerings pages, the security features page, the Cecilia pages and the resources index on 29 Aug 2026. No vendor material addresses segregation between users, teams or matters, and no ethical wall concept was located. Third party review material refers to team colour coding and saved filters, which are workflow conveniences rather than access controls and were not treated as segregation. The vendor publishes Supplier Relationships and Communications Security as named control categories, which govern its own supply chain and network rather than customer side walls. No legal document management integration was located whose permissions could be inherited. For a platform marketed to Am Law 200 firms running concurrent matters, this is an unanswered question.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located term or policy addresses third party requests for customer data.
Searched the offerings pages, the security features page, the resources index and available summaries of the annual filing on 29 Aug 2026, and no published customer agreement or data processing agreement was reached. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. The regulated filing does detail extensive privacy and security obligations across EU GDPR, UK GDPR and CCPA, which concern lawful processing rather than notification of third party demands, and the two were not conflated.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
No primary law corpus is identified because the product does not hold one. Cecilia Q&A is stated to craft its answer only from the customer's own evidence, so the corpus is the collected document universe for the matter and its provenance is the discovery process itself. Searched the offerings pages, the Cecilia and agentic Cecilia pages and the resources index on 29 Aug 2026 and located no vendor supplied legal corpus, no licence basis and no update cadence, and none would be expected. Distinguished from Reveal, the other ediscovery record where this signal was recorded as a genuine gap rather than an inapplicable one, because that vendor ships pre trained behavioural classification models whose training data is undisclosed; no equivalent pre trained model library was located here, Auto Review instead running on customer specific plain English prompts.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Searched the offerings pages, the Cecilia and agentic Cecilia pages and the resources index on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is an ediscovery and fact investigation platform whose corpus is collected evidence rather than published case law, so a citator is outside its design entirely, consistent with all four ediscovery records on this index.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Searched the offerings pages, the Cecilia and agentic Cecilia pages, the security features page and the resources index on 29 Aug 2026. No published material describes what the product does when the evidence does not support an answer, and no explicit no answer path was located. Two adjacent statements were considered and not treated as satisfying this signal. The vendor states an answer is crafted only from the customer's evidence, which constrains where an answer may come from rather than describing what happens when nothing there supports one. And agentic answers carry explanations of the logic and reasoning behind them, which explains a conclusion reached rather than declining to reach one. For a product marketed on autonomous multi step reasoning across massive datasets, what it says when the record is silent is a live question and unaddressed.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note the exposure differs from a research tool: this product generates from collected evidence rather than from case law, so its characteristic failure would be a mischaracterised document or an unsupported factual assertion in work product rather than an invented citation, and that failure mode would rarely surface in a hallucination database.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
Searched the offerings pages, the Cecilia and agentic Cecilia pages, the resources index including the published white papers, and the security pages on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512 and state bar guidance. Also not located: any engagement with the Federal Rules of Civil Procedure or with the case law on technology assisted review and defensible process. That absence is now recorded on all four ediscovery vendors on this index, which establishes it as a category pattern rather than a vendor failing, and makes it worth surfacing as a category level finding in the published index.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
The largest quantified displacement of billable time on this index, with nothing published on the client's side of the equation. The vendor publishes that a first pass issue tag review traditionally requiring 1,000 hours was completed in under 24 hours using Auto Review at an Am Law 50 firm, and states its AI reduces errors, costs and risks associated with document review. Document review is the archetypal billed task in litigation and 1,000 hours is a very large number in fee terms. The move to usage based pricing disclosed in the annual filing also changes the cost structure a firm passes through, from a seat cost to a consumption cost tied to data volume. Searched the offerings pages, the resources index and the security pages on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
Useful material is published and the specific artifacts this signal names are not. Available without a sales conversation: named certifications with scope and cadence, SOC 2 Type 2 audited annually across security, availability and privacy and ISO 27001 scoped to technical and operational service delivery, an enumerated security control framework, a statement that the models are not permitted to train on customer data, and AWS named as the hosting provider. A firm could evidence a fair amount of a client AI clause from that. Searched the security features page, the offerings pages and the resources index on 29 Aug 2026 and located no subprocessor list, no statement naming which model providers see client content, no published data processing agreement, no trust portal or report request route, and no client facing consent or notification pack. Recorded as not addressed because no assembled material or access route exists to point a client to.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
The most granular per document record of any ediscovery vendor on this index, short of a consolidated export. Auto Review produces a written explanation for every individual tag suggestion, so the basis for each classification decision across an entire first pass review is recorded at document level as a by product of the review itself. Agentic Cecilia answers carry explanations of the logic, reasoning and citations to underlying documents every time. Legal hold provides policies, notifications and audit trails. Taken together a party could reconstruct what the system decided and why, per document, which is precisely what a challenge to a technology assisted review process would demand. Two elements are missing: no single per document export combining model used, sources retrieved and human verification was located, and no model is named in published material so the model used could not be stated. Recorded at partial record on that basis.