Exterro

Unified data risk management platform positioned as Legal Governance, Risk and Compliance, combining ediscovery, digital forensics, data privacy and information governance in a single architecture for enterprise legal, compliance and IT teams. The ediscovery suite covers the full lifecycle from legal hold and in place preservation through collection, processing, early case assessment, review and production, with Legal Hold Pro for defensible hold issuance, tracking and enforcement with automated notifications and audit trails, legal project management, and defensible deletion. Preservation operates in place across more than 120 data sources and the platform states more than 190 native connectors supporting in place operations across email, cloud storage, collaboration platforms and endpoints. Data governance covers data inventory and mapping, retention, vendor risk profiling and consent management, and privacy covers data subject access request fulfilment through the Data Subject Rights Manager. Digital forensics is delivered through FTK, with the ARMOUR for FTK framework aimed at security teams scoping incidents and investigating insider risk across live endpoints. AI capability includes AI driven classification and filtering to reduce review volume and identify key custodians and data sources, custodian relationship visualisation showing communication patterns, and contextual label suggestions that analyse content and prior labelling decisions to recommend tags. Exterro Intelligence is the agentic AI layer announced 26 August 2026, positioned as a governed layer across the platform turning data into explainable actions while keeping humans in control at critical decision points, with Exterro Assist for Data as its agentic core and stated in platform processing rules of no training, no access and no storage. ARMOUR is the company's stated strategic framework for autonomous enterprise risk management. Holds ISO/IEC 27001 certification awarded January 2026, SOC 2, FedRAMP Moderate authorization, HITRUST e1 certification and TISAX, with a published Trust Center and a named Chief Information Security Officer, Anthony Diaz. Recognised as a Market Leader in the IDC MarketScape for eDiscovery 2025 and a Major Player in the IDC MarketScape for Data Privacy Compliance Software 2025.

Vendor sitePortland, Oregon, United States
Last verifiedAugust 29, 2026

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The brief flagged this name to check the AI bar. It clears the bar and lands low on centrality, which is the same split found on Onspring. Real and shipped: AI driven classification and filtering to reduce review volume and identify key custodians, custodian relationship visualisation surfacing communication patterns, contextual label suggestions that read content and prior labelling decisions to recommend tags, and Exterro Intelligence, an agentic layer announced 26 August 2026 with Exterro Assist for Data as its core. But the platform is a decade plus orchestration and workflow business covering legal hold, preservation, processing, production, privacy and forensics, and every one of those functions works without a model. Independent comparison material makes the same reading, describing the AI as an enhancement to a traditional GRC platform rather than the foundation it was built on, and Exterro's own framing of AI extending ediscovery says the same thing from the other direction. Graded below Everlaw and Relativity at B, where the model layer is core to what is sold. Note the recency: the agentic layer is three days old at the date of this record, so centrality here is a moving target and this grade should be revisited on the next pull rather than assumed stable.

Source: Vendor Published
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Explainability is claimed as a design principle and nothing measured is published. Exterro Intelligence is positioned as turning complex data into explainable actions and insights, and the platform's defensibility architecture means outputs sit alongside chain of custody records and complete audit logs, so an action can be traced to the data it rests on. That is grounding of a kind, and for ediscovery the corpus is the collected data set rather than the law, so the failure mode is misclassification rather than invented authority. Absent: no accuracy figure for classification or filtering, no precision or recall for label suggestion or custodian identification, no false negative rate for review reduction, no hallucination statement for the agentic layer, and no published evaluation. The gap that matters most in this category is unaddressed by every vendor in it including this one: a filter that wrongly excludes a responsive document produces a defensibility failure that no audit log will surface, and nobody publishes a recall figure. Checked the ediscovery product pages, the platform and intelligence pages, the litigation use case page and the comparison material on 29 Aug 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Autonomy is named as a direction of travel and bounded in the same breath, which is a more honest posture than most. ARMOUR is published as an explicit strategic vision for autonomous risk management, describing a shift from AI assisted tasks to orchestration of legal, privacy and security workflows, so the vendor states plainly where it is going rather than leaving agentic capability to be discovered. Against that, Exterro Intelligence is described as keeping humans in control at critical decision points, and the platform's chain of custody and audit logging mean agent actions land in a record designed to be defensible. Held at B because the bounding is stated rather than specified: no definition of what a critical decision point is, no list of actions an agent may take unattended, no confidence or escalation behaviour, and no description of how an agent action is distinguished from a human one in the audit log. Naming a threshold concept without defining it is the gap between this and an A.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Independent analyst placement is the strongest element and it is dated and checkable. Named a Market Leader in the IDC MarketScape for eDiscovery 2025 and a Major Player in the IDC MarketScape for Data Privacy Compliance Software 2025, which are third party evaluations rather than vendor claims. Further recognition: LegalTech Breakthrough Award for overall eDiscovery, KM World Best eDiscovery Solution, British Legal Technology Award for Innovation in Legal Services, Golden Stevie American Business Award, and an Oregon Tech Award. Verified customer commentary appears on an independent review platform, including a detailed account crediting a fully integrated end to end lifecycle that let the customer bring matters in house rather than sending data to outside vendors. Held at B because no customer is named in vendor material: the most substantial published case describes a major global insurance company with more than 35,000 employees without identifying it, and outcome claims of measurable ROI and significant reduction in outside counsel costs carry no figure, baseline or period.

Source: Third Party Estimated
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Platform confidentiality is the best evidenced on this index and privilege specifically is not addressed. The certification set is unusually broad and is graded on the Security axis rather than double counted here, but its practical effect on confidentiality is real: FedRAMP Moderate and HITRUST both carry confidentiality control requirements that an independent assessor has tested. Chain of custody and complete audit logs support defensible handling at every stage. What was not located: any treatment of legal professional privilege or attorney work product, any statement about privilege review workflows within the platform despite privilege log production being a standard ediscovery task, and any description of how privileged material identified during review is protected from the wider platform where privacy and IT teams also operate. That last point matters because the unified Legal GRC architecture is the selling proposition: legal, compliance, security and IT work in one system, and the boundary around privileged material inside that system is not described. Checked the ediscovery pages, the platform pages, the security and privacy material and the about page on 29 Aug 2026.

Source: Vendor Published
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Not located. The platform makes responsiveness and privilege adjacent determinations at scale through AI driven classification and filtering, and an agentic layer now acts across workflows, so the question of what a supervising lawyer must review is squarely engaged by the product. Nothing published addresses it: no statement on the reviewing attorney's role over AI classification decisions, no positioning on the professional responsibility of a legal team relying on automated culling, and no engagement with any bar guidance or judicial expectation on the use of AI in discovery. Checked the ediscovery product pages, the platform and intelligence pages, the litigation use case page and the resource material on 29 Aug 2026. Note for consistency: no vendor in this category on the index engages the Federal Rules or technology assisted review case law, and this record does not break that pattern.

Source: Operator Verified
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Governance vocabulary is present and consistent, and nothing behind it is published. The AI is described as governed and trusted, ARMOUR is a named framework, humans are stated to remain in control at critical decision points, and the vendor publishes analysis for customers on EU AI Act enforcement including transparency obligations and general purpose AI rules, so the subject is engaged rather than avoided. That places it ahead of the several records in this pull with no governance language at all. What is missing is every artifact a reader could inspect: no AI policy, no model card, no bias or fairness testing methodology or result, no accuracy monitoring, no drift statement, no named internal governance body, and no ISO 42001 despite holding ISO 27001. The specific untested question: classification and filtering decide what a reviewer ever sees, and any systematic tendency in that filtering shapes the evidentiary record of a matter without appearing anywhere in the audit log. Checked the platform and intelligence pages, the ediscovery pages, the about page and the published EU AI Act material on 29 Aug 2026.

Source: Vendor Published
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

One of very few records on this index to state an AI data handling position rather than leave it to inference. The published in platform processing rules for Exterro Intelligence are no training, no access and no storage, which answers three separate questions most vendors leave open: customer data is not used to train models, the model layer does not retain it, and access is bounded. For a platform holding entire collected data sets under legal hold, including custodian communications and forensic images from live endpoints, that is the disclosure a buyer most needs and it is made plainly. Held at B rather than A because the statement is short and unelaborated: it appears as a product architecture note rather than in a contract or a policy document, no scope is given for whether it covers every AI feature or only the agentic layer, nothing states whether the same rules apply to the pre existing classification and labelling models, no retention figure is attached to the surrounding platform as distinct from the AI layer, and no third party attestation covers the claim. A short true sentence still needs somewhere durable to live.

Source: Vendor Published
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

No published position located. Nothing was found on liability for AI output, warranty, indemnity, service levels or remedy where classification, filtering or an agent action is wrong. The exposure is concrete in this category rather than theoretical: an AI driven cull that wrongly excludes responsive material creates a discovery failure attributable to the customer in front of a court, and the customer carries that consequence with no published vendor position on it. Checked the ediscovery pages, the platform and intelligence pages, the about page and the site navigation on 29 Aug 2026. Research limitation: enterprise agreements govern this and are not public, and no public terms page was located in this pass.

Source: Operator Verified
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

The largest published connector footprint on this index and the only record to state a count. More than 190 native connectors supporting in place operations across email, cloud storage, collaboration platforms and endpoints, with more than 120 data sources reachable for in place preservation, and Microsoft 365, email systems and archiving tools named specifically. In place is the operative distinction and it is a substantive capability claim rather than a list: preserving and collecting where data lives, without copying it out first, is what prevents accidental deletion during a hold and is the hard part of the problem. A dedicated connectors page is published. Held at B rather than A on a stated limitation: the connector list itself was not read in this pass, so the count is credited from vendor summary material and the composition of the 190 is unverified, and no API or export documentation was reviewed. Correction candidate in the upward direction if the list is read and holds up.

Source: Vendor Published
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Deployment posture is partly established by a certification rather than by a deployment statement. FedRAMP Moderate authorization is meaningful here beyond security: it establishes that the SaaS platform runs an authorised boundary meeting United States federal cloud requirements, which carries residency and control implications a reader can verify independently through the FedRAMP marketplace. TISAX similarly implies assessed European handling for automotive supply chain customers. What is absent as a direct statement: no hosting provider is named, no region list or data residency commitment is published, no single tenant or dedicated instance option is described, and nothing states where non federal customer data is processed and stored. Credited at C because the certifications carry real deployment information that a buyer can check, and held there because the vendor never states the position itself. Checked the security and privacy material, the about page, the platform pages and the ediscovery pages on 29 Aug 2026.

Source: Vendor Published
AA on Security Certifications and Trust CenterCurrent independent attestation with named scope, reachable without a sales call: a trust center carrying reports, dates and the standards actually covered.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

The strongest security record on this index. Five distinct frameworks, named, with a published Trust Center bringing together security controls, privacy practices, certifications and audits. ISO/IEC 27001 certification announced 29 January 2026, so both current and dated, with the Chief Information Security Officer named as Anthony Diaz and quoted on what the certification covers, which is a risk based information security management system under continuous surveillance audit. SOC 2. HITRUST e1 certification of the SaaS platform. TISAX, derived from ISO 27001 and governing automotive sector handling. And FedRAMP Moderate authorization, which is the element that lifts this above every other record: FedRAMP requires third party assessment organisation review and authorisation by a government authority, and the resulting status is listed publicly, so an outsider can verify it without contacting the vendor or entering a portal. That is the definition of the top of this axis. The vendor also publishes its own reasoning on why third party audits are useful internally, quoting the CISO on audits identifying gaps the company would not otherwise have found, which is a notably unmarketing thing to say. Calibration ladder for later records: Regology and Onspring B, Lexis+ AI A on scope, currency and a self serve portal, Exterro A on five frameworks including one independently verifiable in a public government registry with a named CISO and a dated certification.

Source: Vendor Published
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The handling rules are disclosed and the parties are not. The no training, no access, no storage statement establishes how the model layer treats customer data, which is a supply chain adjacent disclosure of real value, and it implies bounded relationships with whatever models sit underneath. But no foundation model provider, model family or version is named anywhere located, no subprocessor list was found, and nothing distinguishes proprietary classification models built over years from whatever powers the agentic layer announced three days ago. A buyer knows the rules governing the models and not their identity, which is the inverse of Onspring, the only record on this index naming its provider outright while saying less about handling. Checked the platform and intelligence pages, the ediscovery pages, the security and privacy material and the about page on 29 Aug 2026.

Source: Vendor Published
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

No pricing at any level. No price, no range, no unit of charge, and no indication of how the modular structure prices, which is the specific question this product raises: the platform is explicitly sold as individual products or as a complete orchestrated suite, so a buyer starting with Legal Hold Pro and expanding cannot determine what expansion costs. Independent software directories list pricing as available on request and carry no figure. Every route is a demo request. Checked the product pages, the about page, the site navigation and independent directory listings on 29 Aug 2026.

Source: Operator Verified
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Coverage is enumerated where it counts for this category, which is data reach rather than jurisdiction. More than 190 native connectors and more than 120 in place preservation sources across email, cloud storage, collaboration platforms and endpoints, spanning the full EDRM from legal hold and preservation through collection, processing, early case assessment, review, production and defensible deletion. Adjacent coverage extends to digital forensics through FTK, data privacy including subject access request fulfilment, data inventory and mapping, retention, vendor risk profiling and consent management. The buyer set is enterprise legal, compliance and IT, described consistently. Held at B rather than A because coverage is stated as counts and categories rather than as an inspectable list in the material read, no jurisdictional scope is given for the privacy modules despite privacy regimes being jurisdiction specific, and nothing indicates which capabilities are available in which deployment or region.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Never, in policy only

A public policy or trust page states no training on customer content, with no matching term located in the published agreement.

Policy never. The quoted phrase is published as the in platform processing rules governing Exterro Intelligence and its Exterro Assist for Data core, and it is one of the few unambiguous statements on this signal anywhere in the pull: customer data is not used to train models. Recorded as policy never rather than contractual never because it appears as a product architecture statement on a vendor page rather than in terms, a data processing agreement or any document a customer signs, and the value set separates those two for exactly this reason. Two limits on scope worth recording: the rule is stated for the agentic layer and nothing confirms it extends to the pre existing classification, filtering and label suggestion models that have been in the platform for years, and no third party attestation covers the claim despite five certifications being held. Checked the platform and intelligence material, the ediscovery pages, the security and privacy material and the about page on 29 Aug 2026.

Source: Vendor Publishedno training, no access, no storageAs of Aug 29, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Disclosed fixed window

A specific retention period is published and the customer cannot change it.

Disclosed fixed, at zero, for the AI layer only. The published in platform processing rules state no storage alongside no training and no access, which is a stated retention position rather than a vague assurance and is the strongest value recorded on this signal in the pull. It is fixed rather than customer configurable: nothing indicates a customer can vary it, and nothing needs to, since zero is the floor. Bounded carefully: this covers the AI processing layer. The surrounding platform is a system of record that retains collected data, legal hold records, audit logs and chain of custody entries by design and for defensibility reasons, and no retention period is published for that, nor for how long a matter workspace persists after a matter closes. A reader should not carry the zero across from the model layer to the platform.

Source: Vendor PublishedAs of Aug 29, 2026

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Claimed, not documented

Segregation is asserted in public materials with no published detail on how it is enforced.

Claimed and not documented. Matter based structure, role separation across legal, compliance and IT users, and complete audit logging are all asserted, so an access model plainly exists. Nothing published describes its granularity: no statement of whether access is enforced per matter or per custodian, whether a privacy or IT team member working in the same unified platform can reach material collected under a litigation hold, or how privileged review material is walled once identified. The unified Legal GRC architecture makes this sharper than for a single purpose ediscovery tool, because the whole selling proposition is that separate functions share one system. No document management system integration exists that would let permissions be inherited from a firm's own estate. Checked the ediscovery pages, the platform pages and the security and privacy material on 29 Aug 2026.

Source: Vendor PublishedAs of Aug 29, 2026

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Not addressed

No located term or policy addresses third party requests for customer data.

Not addressed. No government or law enforcement request clause, no commitment to notify a customer before producing their data, and no transparency report were located. The question carries additional weight for this vendor because FedRAMP Moderate authorization means United States federal agencies are customers, and because the platform holds collected litigation data and forensic images from live endpoints. Checked the security and privacy material, the about page, the Trust Center references, the platform pages and the site navigation on 29 Aug 2026. Correction candidate: the Trust Center was identified but its contents were not read in this pass.

Source: Operator VerifiedAs of Aug 29, 2026
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Not addressed

No located public material identifies the corpus behind the product’s answers.

Not addressed, and inapplicable in the ordinary sense. This platform has no primary law corpus: it operates over the customer's own collected data, custodian communications, endpoints and documents, so there is no external legal source to name, license or date. Recorded rather than omitted because the underlying question still has an unanswered form here, which is what the classification, filtering and label suggestion models were trained on. Nothing published states whether those models are general purpose, trained on legal or discovery specific corpora, or tuned on prior customer matters, and the last possibility is the one a litigant would care about most. The no training rule announced for the agentic layer speaks to future data and not to what already built the models. Checked the platform and intelligence pages and the ediscovery pages on 29 Aug 2026.

Source: Operator VerifiedAs of Aug 29, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

Not addressed, and inapplicable on the facts of the product. Exterro processes and analyses the evidence in a matter rather than researching legal authority, so no citation to case law is produced and a citator would have nothing to check. Recorded as a scope fact so that a reader comparing this record against a legal research product does not read an empty row as a disclosure failure. Consistent with the treatment of the same row on TrialView. Checked the ediscovery pages, the platform and intelligence pages and the litigation use case page on 29 Aug 2026.

Source: Operator VerifiedAs of Aug 29, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

Not addressed. No explicit no answer path, abstention behaviour or confidence signal is documented for classification, filtering, label suggestion or the agentic layer. The vendor's published control is that humans stay in control at critical decision points, which bounds who decides rather than describing what the system does when it is unsure. The consequence is specific to discovery: a classifier that is uncertain about responsiveness and resolves it silently produces a cull no audit log will flag, and nothing published indicates whether uncertain items are surfaced for human review, scored, or simply decided. Checked the platform and intelligence pages, the ediscovery pages and the litigation use case page on 29 Aug 2026.

Source: Operator VerifiedAs of Aug 29, 2026

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

None located, with the instrument named. General web searches combining the vendor and product names with court, order, opinion, sanction, spoliation and discovery failure terms returned nothing on 29 Aug 2026. No named docket database or court record tracker was searched. The exposure shape differs from a research product: this platform generates no citations to authority, and the analogous adverse finding would be a court addressing a defective collection, cull or production run through the tool, which is a class of order that does exist in this category generally and was not searched for systematically here. Recorded as a statement about what this search found, not as a clearance, and flagged as worth a proper docket search on a later pass.

Source: Operator VerifiedAs of Aug 29, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

Not addressed. No named ethics opinion, no ABA Formal Opinion 512, no state bar guidance and no engagement with judicial expectations on AI in discovery was located. The vendor does publish substantial regulatory analysis for customers, including on EU AI Act enforcement and transparency obligations, so the capability to engage a rules framework exists and has been pointed at the customer's compliance obligations rather than at the professional duties of the lawyers supervising discovery on the platform. Checked the ediscovery pages, the platform pages, the resource and blog material and the about page on 29 Aug 2026.

Source: Operator VerifiedAs of Aug 29, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure.

Savings claims only, and the savings claimed are unusually specific in kind while carrying no figure. The vendor states measurable ROI and a significant reduction in outside counsel costs, and published customer commentary describes bringing matters fully in house rather than sending data to outside vendors for processing, which is a cost shift with real substance behind it. None of it is quantified with a baseline or period. Nothing appears on the client's side of the equation: no position on billing for AI assisted review, and no exportable record showing what portion of a review was machine determined. Checked the litigation use case page, the ediscovery pages and independent review material on 29 Aug 2026.

Source: Vendor PublishedAs of Aug 29, 2026

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

On request only

The material exists behind a sales conversation or an executed agreement.

On request, through the best resourced route on this index. A Trust Center is published and described as bringing together security controls, privacy practices, certifications and audits in one place, and behind it sits an unusually strong set to forward: ISO 27001 dated January 2026, SOC 2, HITRUST e1, TISAX and FedRAMP Moderate. FedRAMP status is separately verifiable in a public government registry, so one element of the pack requires no vendor cooperation at all. A firm responding to an outside counsel guideline questionnaire has a defined destination and named, current attestations to cite. Held at on request rather than at disclosure pack because nothing is published open: no subprocessor list, no named model provider, no downloadable summary and no data processing agreement were located outside the Trust Center, and the Trust Center's own gating was not tested in this pass.

Source: Vendor PublishedAs of Aug 29, 2026

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

Partial record, and the strongest process trail in the category. Defensibility is the organising principle of the product rather than a feature of it: end to end chain of custody and complete audit logs are published as supporting defensible actions at every stage, legal holds are issued, tracked and enforced with automated notifications and full audit trails, and defensible deletion is a named capability. A party can evidence what was preserved, when, from whom, and what happened to it, which is the record a court asks for in a spoliation dispute and is materially better than most of this index. The AI limb is where it stops. Nothing indicates that the record identifies which decisions were machine made, which model made them, what the confidence was, or whether a human confirmed a classification before a document was culled. With an agentic layer now acting across workflows, the distinction between a human decision and an agent decision inside the audit log is exactly what an opposing party would probe, and no published export or audit view addresses it.

Source: Vendor PublishedAs of Aug 29, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 31 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
August 29, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746