E
Ethyca

Ethyca is a data governance and privacy engineering platform for enterprises, built on Fides, the open-source data privacy taxonomy and policy language the company authored and maintains publicly on GitHub. The platform has five named parts: Fides, the governance taxonomy; Helios, which discovers and classifies personal and sensitive data across databases, warehouses, websites and third-party applications; Janus, for consent and lawful-basis capture; Lethe, for automated data subject rights fulfilment and de-identification; and Astralis, which enforces purpose-based access policies at runtime, including on calls made by AI agents through a policy-checked gateway, and runs continuous risk assessment across data, purpose and vendor inventories against named regimes including GDPR, the EU AI Act and CPRA.

Helios classifies using a large language model applied to database metadata only, never to table contents, a design the company documents publicly alongside measured precision and recall figures. The privacy and legal teams that buy it use it for records of processing, lawful basis, consent, subject-request fulfilment, deletion across systems, and vendor and cross-border transfer risk. Named customers include The New York Times, Ramp, SurveyMonkey, WeTransfer and Vercel.

The company is independent, headquartered in New York, and publishes its master subscription agreement and data processing addendum in full, including its subprocessor list.

Vendor siteNew York, New York, United States
Last verifiedSeptember 12, 2026
Compare with other vendors

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Remove the models and a data governance platform remains, which is the B band. Fides is an ontology and policy language, Janus is consent and preference management, Lethe is policy-based data rights fulfilment and de-identification, and the data inventory can be populated from existing DSPM tools and catalogues: none of that requires a model. The models are the engine of two core capabilities. Helios classifies discovered data with a large language model applied to database metadata, and Astralis performs continuous agentic risk assessment and enforces purpose-based access at runtime, including rewriting an agent's query where the inferred purpose is not permitted.

The vendor's own positioning is a governance harness for AI rather than a product that is itself a model. Verified 12 September 2026.

Source: Vendor Published
AA on Citation Accuracy and Hallucination DisclosureMeasured accuracy is published with the test set described and the failure modes named. Output grounds to primary authority the reader can open, citation status is checked, and the system states when it found no support.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

The strongest published accuracy evidence located in this corpus, and the A rests on the limbs that bite. A first-party engineering account dated 23 December 2025 and attributed to a named author publishes precision, recall and F1 for the Helios classifier, improving from roughly 50% at baseline to over 80% against an adversarial benchmark suite and over 95% against benchmarks drawn from real-world systems, with validation against customer-provided datasets reported at over 90% and a comparison showing positive AI labels wrong 5% of the time against 14% for human labels.

The test set is described: around 2,000 tagging tasks across 43 data categories, benchmark examples for 46 categories, fully synthetic schemas generated without reference to customer data, and the ground-truth labelling method including the disagreement-review pass that grew the labelled set from 449 to 825 fields. Three failure modes are named and diagnosed with the fix for each: laziness, shallowness and credulity.

The vendor also publishes a critique of naive accuracy metrics, showing that a classifier which does nothing scores 98.6% on a typical enterprise distribution, which is the opposite of the bare claim the D band was written for. R15 governs two limbs that do not apply to the product class: the product cites no legal authority, so grounding to primary authority and citator status are neither credited nor penalised. What the A does not rest on: no accuracy figure appears on any product page, only in the engineering post, and the category-by-category breakdown is shown in screenshots rather than in text. Verified 12 September 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Real review surfaces and a described control structure, short of the limb the B band names as commonly absent. What the system does alone is published plainly: Astralis checks every agent call through an MCP gateway before it runs, rewrites a query whose inferred purpose is not permitted, re-evaluates the risk register nightly, and drafts assessments and mitigations for approval. What constrains it is customer-defined: a purposes taxonomy, policy definitions, and the Fides ontology the customer versions itself.

Review surfaces are the risk register, the assessment report and the audit record of how and why each access decision was made. What is not published is the threshold structure: where the gateway blocks rather than rewrites, what happens when an enforcement decision is wrong, and whether a human approves a mitigation before it is applied. The classifier post's human-in-the-loop discussion concerns Ethyca's own evaluation work rather than the customer's oversight of the shipped product, and is not credited here. Verified 12 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Named customers and published figures, never joined, which is the B band exactly. Sixteen customers are named on the customers page, each with its own profile page, including The New York Times, Ramp, SurveyMonkey, WeTransfer, Vercel, Lush, Zola, Casper and American City Business Journals. Platform figures are specific: 744m preferences processed annually, more than 4m access requests processed, 200+ global brands, $74m+ saved by automation, subject request fulfilment from 15 hours to 17.2 seconds, 1 PB governed daily, 150,000 policy decisions enforced per second.

None is attributed to a named customer and no method is stated for any of them. The New York Times profile page was opened and carries the customer's own business metrics (11.7m subscribers, $2.59bn revenue, 139 Pulitzer Prizes) and a chief executive quote about the newspaper's subscription strategy rather than about the product: on that page alone the evidence is the C shape. The breadth of named customers and the specificity of the platform figures carry the row to B. Fifteen further customer pages were not opened. Verified 12 September 2026.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Substantive contractual commitments readable before signing, and the A band's privilege limb is absent, which R33 makes decisive. Published and read in full: MSA section 4.1 licenses Customer Data only to provide the Service and fulfil Ethyca's obligations, with a separate narrow licence over Audit Data, defined as three enumerated fields, for legal compliance alone; section 4.2 commits to using Customer Data solely for legitimate operational needs such as audit trail creation and system monitoring, or where required by law; section 9 is a mutual confidentiality regime with need-to-know limits and written obligations on personnel; DPA section 3(f) commits to deletion or return within 90 days of termination; the CCPA schedule bars retention, use or disclosure for any purpose beyond the business purpose and bars sale.

The design fact that answers the model-provider question in this product's own idiom is that the classifier is metadata-only and, in the vendor's words, requires no access to sensitive data. Two limbs keep this at B: nothing located addresses privilege or work product treatment, and no third-party model provider's retention position is stated anywhere, the inference platform being unnamed. MSA last modified 10 February 2023; DPA 17 October 2024. Verified 12 September 2026.

Source: Vendor Published
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

A real published position on advice versus tooling, in the instrument that governs the product and unusually plain. MSA section 10.4 is headed No Legal or Regulatory Advice and states that Ethyca is not providing legal, accounting, tax or regulatory services, is not advising on compliance with or interpretation of any privacy or security law, that any recommendation it gives concerns the functionality of the Service only and is given from a business perspective, that the customer should not rely on it as legal advice, and that the customer retains sole responsibility for identifying and complying with its own obligations.

Section 10.3 goes further than most: the vendor expressly does not warrant that use of the Service will result in compliance with applicable laws, which is the claim a governance product is most tempted to make. Who may use it is stated as Authorized Users under an Order Form for internal business purposes. Short of the full band: nothing addresses a supervising lawyer's competence or supervision duties, and no jurisdiction limit is placed on the guidance the product emits.

R15 applies to the consumer-facing limb, which does not bite on an enterprise platform with no public advice surface. Verified 12 September 2026.

Source: Vendor Published
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

A published testing regime with real substance, short of an owner and short of disclosed findings on uneven output, which is B. What is published is a quantitative pre-release evaluation framework for the vendor's own classifier: an accuracy metric defined and defended, an adversarial benchmark suite, per-category metric reporting implemented in a purpose-built workbench, model-size threshold findings, and an explicit account of precision and recall trade-offs between models described as more conservative and more creative.

That is more evaluation detail than any other record in this lane publishes about its own models. What is absent is the governance structure the A band asks for: no accountable owner inside the vendor is named, no AI policy, model card, governance committee or review board is published, and no finding is disclosed about uneven output across populations or data subject groups, as distinct from across data categories. Worth recording because of where this record sits: this lane's standing finding is that vendors selling AI governance publish least about their own, and this vendor is the counter-example on testing while still publishing no governance structure. Verified 12 September 2026.

Source: Vendor Published
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

All five A limbs are published, contractual and specific enough to hold the vendor to. Retention: processing is bounded to the term of the Agreement, in-product controls let the customer retrieve, correct, delete or restrict Personal Data, and the Audit Data licence that survives is defined as three enumerated fields rather than left open. Deletion: DPA section 3(f) commits to deleting or returning all Personal Data within 90 days of termination, with the backup carve-out named and those copies required to be isolated, protected from further processing and deleted under stated practices.

Access control: Annex 2 documents it control by control, covering authentication, an authorisation model validating user permissions against the attributes of each data set, API access by key or OAuth, VPC and firewall segmentation, intrusion detection, static code analysis, annual third-party penetration testing, a responsible disclosure programme, least-privilege employee access reviewed quarterly and third-party background checks.

Subprocessors: named in Annex 1.H with purpose and location, being Amazon Web Services for cloud infrastructure in Virginia and Twilio SendGrid for transactional email, with contractual notification of additions or removals and a 30-day objection right for European and Colorado data. Incident practice: notification without undue delay after becoming aware, with timely information and assistance for the customer's own notification duties.

Theta Lake was held at B one build ago on the single limb of a subprocessor list the fetcher could not read; that limb is satisfied here, and the A follows from the same reasoning applied consistently. Agreement dates 10 February 2023 and 17 October 2024 go to the confidence rather than the grade, there being no recency floor. Verified 12 September 2026.

Source: Vendor Published
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

A real published position, specific on the numbers, and it stops where R117 settled this shape one build ago. MSA section 8.1 gives a defence and indemnity against third-party claims that the Service infringes a US patent, trademark, copyright or trade secret, with six named Excluded Activities and an express sole-and-exclusive-remedy statement. Section 11 caps liability unusually precisely: 150% of the fees paid in the twelve months before the act or omission for each party generally, and 300% of those fees for the section 8.1 indemnity, with carve-outs for gross negligence, wilful misconduct, payment obligations and the customer's own indemnity.

Section 10.2 gives a limited warranty that the Service conforms in material respects to the Documentation, with a defined path of notice, correction and a right to terminate if it cannot be corrected, which is a warranty a buyer can actually invoke. What keeps this off A is the same thing as on the previous build: no indemnity reaches wrong output, section 10.3 disclaims all warranty as to the Service and any reports or outputs and expressly disclaims that use will produce compliance with law, and no insurance is named anywhere. Verified 12 September 2026.

Source: Vendor Published
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Real, documented integrations into the systems this product's work lives in, short of established depth. Named on the vendor's own surfaces: Snowflake and BigQuery warehouses, AWS infrastructure, identity providers, website cookies, tags and SDKs, third-party applications, and an ingestion path by API, SFTP, manual and web upload. The commercial model itself evidences a connector catalogue, since the MSA prices Connector Integrations as a separate line calculated pro rata.

Verifiability is unusually high for this corpus: the Fides core and its connectors are public on GitHub, the API documentation and the release changelog are both published without a login, and Astralis exposes an MCP gateway that policy-checks agent calls. What holds the row at B is that the integrations catalogue and the documentation site were not opened, so what each connector moves and in which direction was not established beyond what the home page and the agreement state.

R15 applies to the legal-stack limb: a data infrastructure product bought by privacy counsel integrates with warehouses and identity systems rather than with a document management system, and no document management or practice management connection was located or is expected. Verified 12 September 2026.

Source: Vendor Published
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Deployment model stated clearly with partial residency detail, which is the B band. Two delivery paths are published: the open-source Fides core, which a customer can run in its own infrastructure from the public repository, and Hosted Fides, the subscription service. Tenancy is stated for the hosted path, and stated against the customer's interest rather than for it: DPA Annex 2 records that Customer Data is held in multi-tenant storage systems reachable only through application interfaces and APIs, with no direct customer access to the underlying infrastructure.

Residency is partly published: the subprocessor annex places cloud infrastructure with Amazon Web Services in Virginia, United States, and DPA section 6 states that Personal Data will be transferred to and processed by Ethyca, Inc. in the United States and in other jurisdictions where its affiliates and subprocessors operate, with the EU controller-to-processor Standard Contractual Clauses as the transfer mechanism. What is not published is a list of available regions, any choice of region, what changes between the four commercial tiers, or where processing happens as distinct from where data is stored. Verified 12 September 2026.

Source: Vendor Published
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

The grade records an unusual state and the note has to carry it, because neither adjacent band reads cleanly, which is the band gap logged open at R16. No unsupported badge appears on any surface read: the site footer carries no certification marks at all. The only named standards are SOC 2 Type II and ISO 27001, and the DPA attributes both to Ethyca's data centre partners who maintain independently validated security programmes, not to Ethyca: under R16 that is the hosting provider's scope and does not credit to this product, and there is no scope connector naming the Service.

Ethyca's own published assurance is real but is assessment rather than attestation: annual penetration testing by industry-recognised third parties, with a summary report supplied on a confidential basis on request, plus a responsible disclosure programme and static code analysis, all set out in DPA Annex 2. A trust centre exists at trust.ethyca.com, is reachable without a sales call, and states that audit reports and security policies are available on it.

Its body is Vanta-hosted and returned page metadata with no readable content to this index's fetcher on 12 September 2026, and an R8 step 4 search did not recover it. That is a limit on the reader and not a finding about the vendor, and if the trust centre names an attestation of Ethyca's own the row is regraded and redated under the corrections backstop. One drafting discrepancy to record: the DPA's Virginia and Colorado section reads ISO 29001 where its European section reads ISO 27001. Verified 12 September 2026.

Source: Vendor Published
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Partly disclosed, which is B, and the disclosure is in an engineering post rather than on a product surface. The models are named, which R34 requires for the top band and which almost nothing in this corpus does: the classifier was built and benchmarked against Qwen's QwQ-32B and DeepSeek-V3 among state-of-the-art models tested, with a published finding that accuracy stops improving above roughly 32B parameters and that models below 18B produce uncorrectable errors.

The architecture is described in detail: one request per field to defeat skipped fields, chain-of-thought discussion of tagging considerations, prompt caching, prompt optimisation rather than fine-tuning, and metadata-only inputs. What is absent for A: no provider of inference is identified, the post referring only to cloud inference platforms, and no commitment to notify customers when any of the model supply chain changes is published.

Note the gap between two of the vendor's own documents, which is recorded rather than resolved: the contractual subprocessor list names only AWS and Twilio SendGrid, so no model or inference provider appears on the list a customer would be notified about. Post dated 23 December 2025. Verified 12 September 2026.

Source: Vendor Published
CC on Commercial TransparencyPricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

The shape is visible and the number is not, which is C. The site publishes no pricing page and no figure: every call to action is a demo request, a free-trial request or a contact form. The structure, unusually, is published in the agreement rather than in marketing. MSA section 6.1 names four commercial tiers, Fides True, Fides Team, Fides Plus and Fides Enterprise, and states that Connector Integrations are charged as a separate line and that moving between tiers or adding connectors is calculated pro rata for the duration of use.

Section 6.2 states monthly invoicing in advance on 30-day terms with fees non-refundable except on Ethyca's breach, and section 6.3 limits price increases to renewal terms on at least 60 days' notice and requires any increase to be applied generally rather than to one customer. The open-source core is separately free to self-host, which is described in the note rather than as a price. No rate, no band and no implementation figure appears anywhere located, which is what holds the row off B. A pricing row is owed under R17 because this evidence lifts the axis above D, and is written with no figure. Verified 12 September 2026.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Coverage is described with substance and the boundaries are left open, which is B. Who this serves is evidenced by named customers labelled by industry on the vendor's own customers page: publishing (The New York Times, Axios, American City Business Journals), internet software (WeTransfer, SurveyMonkey, Vercel, Podium), fintech (Ramp), retail and consumer brands (Lush, Casper, Away, Parachute, Zola), and marketplace and services businesses (JustPark, Slice, Snackpass).

Scale is stated as enterprise, with a separate enterprise page and a statement that the company works as a technical partner rather than selling an out-of-the-box SaaS tool. The buying functions are evidenced by the workflows rather than by a roles page: the current site has no roles or buyer-segment tier at all, which is itself the reason route A was not relied on at the membership screen. What is not stated is where coverage stops: no jurisdictional limit, no statement of which regimes are not supported, and no statement of who the product is not for.

R15 applies to the firm-segment and practice-area limbs, which do not bite on a data infrastructure product bought by an in-house privacy and legal function rather than by a practice group. Verified 12 September 2026.

Source: Vendor Published
Sources on file

5 public documents

The public pages on file for Ethyca, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.

Pricing

No published figure

  • Ethyca sells the hosted product in four levels: Fides True, Fides Team, Fides Plus and Fides Enterprise.
  • It does not publish what any of them costs, and there is no pricing page on its website.
  • Each connection to another system, called a Connector Integration, is charged on top of the level you pick.
  • If you switch level or add a connection partway through, the extra is worked out for the part of the year you use it.
  • The bills come monthly in advance, are not refundable, and the price can only go up at renewal with at least 60 days' notice.

The tiering and the unit of charge are published in the agreement rather than in marketing. MSA section 6.1 names four commercial tiers of the hosted service, Fides True, Fides Team, Fides Plus and Fides Enterprise, and states that Connector Integrations are charged as a separate line, with the fees for a tier change or an added integration calculated pro rata for the duration of use. Section 6.2 states that Ethyca invoices monthly in advance on 30-day terms and that fees are non-refundable except where the agreement is terminated for Ethyca's breach.

Section 6.3 restricts price increases to the start of a renewal term, on at least 60 days' notice, and only where the increase is applied generally to the Service rather than to one customer, and section 2.1 expressly excludes price increases from the vendor's unilateral right to change the Service. Professional Services, which may be described as a Set Up Fee, are charged as a fixed fee stated in the Order Form under section 2.6.

No rate, band or implementation figure appears on any surface located, so no figure is recorded here. Separately, the open-source Fides core is available at no charge from the vendor's public repository for a customer that self-hosts.

Confidentiality and data terms: The Master Subscription Agreement and the Data Processing Addendum are both published in full on the vendor's own site and are accepted by incorporation into an Order Form rather than negotiated from scratch. The DPA incorporates the EU controller-to-processor Standard Contractual Clauses and carries CCPA, Virginia and Colorado schedules. No business associate agreement or HIPAA offer was located on any surface.

Note: Structure read from MSA section 6, last modified 10 February 2023, at ethyca.com/legal/msa-hosted-fides on 12 September 2026. The row exists because the published structure lifted Commercial Transparency above D, which is the R17 test; it carries no figure because none is published on any surface located. No pricing page exists on ethyca.com and the navigation has no pricing entry. The open-source Fides core is separately available at no charge from the vendor's public repository, which is a self-hosting path rather than a tier of the hosted service and is therefore described here rather than recorded as a zero price.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Purpose limited, in the contract

The customer agreement or data processing addendum contractually limits use of Customer Data to providing the contracted service, and no surface names training either way. The limit is bound, which a policy page is not, but it is not an express training prohibition. If any surface names training in either direction, one of the other values is true and this one is not.

The agreement binds Customer Data to service provision and no surface located names training in either direction. MSA section 4.1, last modified 10 February 2023, licenses Customer Data to Ethyca only to provide the Service and fulfil its obligations under the Agreement, for the term, with a separate and narrower irrevocable licence over Audit Data, defined as three enumerated fields, for legal compliance alone. Section 4.2 commits to using Customer Data solely for legitimate operational needs such as audit trail creation or monitoring system functionality, or where required by law.

The DPA's CCPA schedule bars retaining, using or disclosing California personal information for any purpose beyond the business purpose and bars sale outright. Two things belong on the record. The DPA's processing-operations annex describes storage and processing necessary to provide, maintain and improve the Services provided to Customer, so improvement is named while training, models and machine learning are not, and the R28 test of whether the clause names the thing is not met.

Separately, the vendor's engineering post discloses that its classifier was benchmarked on fully synthetic schemas generated without reference to customer data, and then validated against real-world datasets provided by customers; that is evaluation rather than training, it is disclosed in the vendor's own words, and the classifier reads database metadata only, never table contents.

Source: Vendor Publishedthe Customer Data in order to provide the Service for CustomerAs of Sep 12, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Customer controlled, no zero option

The customer controls the retention window, by product configuration or by contractual instruction, but zero retention is not stated as available.

The customer controls the window and no zero-retention setting is stated. DPA section 4 records that the Services provide the customer with controls to retrieve, correct, delete or restrict Personal Data, which the customer may exercise itself; section 3(f) commits to deletion or return of all Personal Data within 90 days of termination, with backup copies isolated and deleted under stated practices; and Annex 1.C bounds processing to the duration of the Agreement.

What is not published is a retention period for live data, or any statement that retention can be set to zero. The carve-out that must be named: MSA section 4.1(b) grants an irrevocable licence over Audit Data until Ethyca's own compliance obligations expire, and Audit Data is defined narrowly as the primary identifier of the subject of a rights request, a timestamp, and the number and list of affected systems, rather than the underlying content.

For this product class the retained material is the configured data inventory and the record of rights requests rather than a lawyer's prompts to a drafting assistant.

Source: Vendor Publishedcontrols that Customer may use to retrieve, correct, delete or restrictAs of Sep 12, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Own model, documented

The product maintains its own permission model, documented, requiring the firm to keep it aligned.

The product runs its own documented permission model rather than enforcing a source system's access model at query time. DPA Annex 2 states that authorisation to data sets is performed by validating the user's permissions against the attributes associated with each data set, that Customer Data sits in multi-tenant storage reachable only through application interfaces and APIs with no direct customer access to the underlying infrastructure, that a uniform password policy applies and that public APIs are reached by API key or OAuth.

Astralis adds a purpose-based layer on top: access is granted by purpose rather than identity alone, and every agent call is policy-checked before it runs. No ethical wall, conflicts check or matter-level segregation construct was located on any surface, which is unsurprising for a product whose unit of segregation is a data set and a purpose rather than a matter, and a firm would have to align the product's roles and purposes with its own walls itself.

Source: Vendor Publishedvalidating the user's permissions against the attributes associated with each data setAs of Sep 12, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Notice committed

Terms commit to notice where lawfully permitted. No transparency report located.

Notice is committed in the agreement and no transparency report is published. MSA section 9.3 permits disclosure of the other party's confidential information on a subpoena or other government process only where the receiving party promptly informs the issuing entity of the existence of the Agreement, promptly informs the disclosing party of the receipt of the subpoena, and does not oppose any effort by the disclosing party to quash or limit it; it further requires that confidential status be maintained and reasonable steps taken during any compelled use.

That non-opposition covenant is more than most agreements in this corpus offer. The DPA adds that where a legal requirement prevents Ethyca from following the customer's processing instructions it will promptly notify the customer to the extent the law permits, and will cease processing beyond storage until new instructions are issued. No transparency report and no figures on requests received were located on any surface, which is what separates this from the top value.

Source: Vendor Publishedpromptly inform the Disclosing Party of the receipt of such subpoenaAs of Sep 12, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Jurisdictions only

Coverage is described by jurisdiction with no identification of the underlying corpus.

Coverage is described by regime and the underlying corpus is not identified. This product holds no case law, but it does encode regulatory obligation: the vendor states that Astralis knows the internal and external policies a customer must follow and continually analyses risk against them, and names the regimes on its own surfaces, including GDPR, the EU AI Act, CPRA, CCPA, the Virginia CDPA, the Colorado Privacy Act and California's Delete Act, with material published per regime.

What is not published is where that regulatory content comes from, how it is maintained, or on what basis, so a buyer cannot tell whether an obligation set is licensed, built in-house or derived. The one corpus whose provenance is fully open is the taxonomy rather than the law: Fideslang is published as an open-source ontology under the vendor's own repository and mirrored by the IAB Tech Lab, and is inspectable and versionable by the customer.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

The product cites no legal authority, so nothing located addresses checking subsequent history, and nothing would be expected to. The nearest published analogue is currency of rules rather than currency of authority: the risk register is stated to be re-evaluated nightly against the customer's data, purpose and vendor inventories and against the regimes named on the product pages. That keeps an obligation set current; it is not a treatment signal on a cited case, and the row states the position rather than leaving a reader to infer it from silence.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Documented and demonstrable

The vendor documents an explicit no answer path and it is observable in the product or in published evaluation.

An explicit no-finding path is documented and the published evaluation measures it. The classifier's default output where no privacy-relevant category applies is the system.operations tag in the open Fideslang taxonomy, and the vendor's engineering post of 23 December 2025 sets out both that the default exists and why counting it toward accuracy is misleading, working the arithmetic to show that a classifier which always returns the default would score 98.6% on a typical enterprise distribution.

The same post publishes recall and false-negative measurement, which is the rate at which the system wrongly returns nothing, and discusses the precision and recall trade-off in terms of what each failure costs a governance programme. The limit worth naming: this is documented for the classifier, and no equivalent abstention behaviour is published for the Astralis assessment or the agentic query path.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

None located

No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.

No court order, opinion or disciplinary record naming this product, the Fides platform or Ethyca, Inc. was located as of 12 September 2026. Searches were run on both the product name and the company name against published trackers of AI hallucination decisions, including coverage of the Charlotin AI Hallucination Cases database, and returned nothing involving this vendor. This is a statement about the public record on that date and not a finding about the product.

The product classifies data and enforces access policy rather than producing legal citations, which is the conduct those records address.

Source: Bar Guidance or Court RecordAs of Sep 12, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No located public material engages with bar or ethics guidance. The vendor publishes extensively on regulatory obligation, including GDPR, the EU AI Act, CPRA, state privacy statutes and California's Delete Act, and it addresses professional responsibility in one direction only: MSA section 10.4 states plainly that it provides no legal, accounting, tax or regulatory advice and that the customer retains sole responsibility for its own compliance.

That is a disclaimer of the advice line rather than engagement with the guidance a lawyer buyer is bound by, and nothing located addresses ABA Formal Opinion 512 or any state bar opinion on generative AI. Recorded as of 12 September 2026.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Outside the fee relationship

The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.

The product does not touch a fee between a lawyer and a client. It is bought by an in-house privacy, legal, governance or data engineering function to govern that organisation's own data estate, and no client is billed for the work the classifier or the policy engine performs. Savings claims are published and are aimed at the buyer's own operating cost rather than at a client invoice: $74m+ saved by automation, subject request fulfilment from 15 hours to 17.2 seconds, data access service levels from six weeks to five minutes, and a published cost of $0.603 per thousand fields classified.

Under the value's own terms those are recorded here and do not make this a savings-claims row, because no client bill is in the loop. R21 noted: the signal is specific to AI-assisted billable work, which this product does not produce.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Subprocessors listed

A current subprocessor or model provider list is published.

A current subprocessor list is published in the agreement itself and the model provider limb is not met. DPA Annex 1.H names each subprocessor with its purpose and country: Amazon Web Services for cloud infrastructure in Virginia, United States, and Twilio SendGrid for transactional email in the United States. DPA section 5 and section 7(d) commit to notifying the customer of additions or removals by updating the list, with email notification on opt-in and a 30-day objection right on data protection grounds, and to imposing equivalent terms on each subprocessor.

Forwardable client-facing material exists and is ungated: both the DPA and the Master Subscription Agreement are published in full, which under R29 satisfies the third limb of the top value. The reason the row is not disclosure-pack is the second limb, and the gap is between two of the vendor's own documents rather than an absence: its engineering post names the models used for classification and refers to cloud inference platforms, while no model or inference provider appears anywhere on the contractual subprocessor list a customer would be notified about. A firm forwarding this pack to its client could name the infrastructure and could not say who runs the model.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

Elements of a record exist and they are not a filing-level certification. What the product records is published: every alert, user action and access decision is logged with how and why it was resolved, policies are stated to prove how data was used rather than only who accessed it, every agent call through the Astralis gateway carries an inferred purpose and a policy check, assessment reports are generated with mitigations attached, and classification decisions carry the model's own discussion of tagging considerations.

That is a per-call and per-decision record of what an AI system did with which data under which purpose, and it is exportable and stated to be audit-ready. What it does not produce is a document-level record tying a named model, the sources it retrieved and a named human verifier to a filing, because the record is of data access and governance rather than of a brief's drafting. A firm asked to certify AI use in a matter would have material to draw on and would have to assemble the certification itself.

Source: Vendor PublishedAs of Sep 12, 2026Evidence
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 12, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746