F
Fileread

Fileread is an AI fact-finding platform for litigation and investigations, sold to case teams at law firms, corporate legal departments and litigation support providers. It reads an entire document production and returns answers pinned to the exact location in the source, working across text, images, handwritten notes, audio, video and spreadsheets, including formats the vendor says other review tools cannot open. Users query the record in plain language rather than by keyword, then generate work product from it: fact memos, chronologies, contradiction reports, character lists, org charts, deposition outlines and factual briefs, with every line traced back to the document it came from so a claim can be checked against its page in one click. A module called Workbench runs longer chains of research and assembles those items, with the result presented as a draft for professional review. The platform is used for early case assessment, discovery review, deposition preparation, case analysis and trial support, and is offered both as a standalone application and as a native integration inside Relativity, working on productions already in place rather than requiring migration. The company publishes a set of practitioner-reviewed papers on litigation AI covering source citation and verification, human oversight and a taxonomy of failure modes. Data is encrypted and hosted in Azure and processed through what the vendor describes as private large language models, and the vendor states that nothing a customer uploads trains a shared model. A trust centre publishes the subprocessors in the AI path, being OpenAI, Baseten, Pinecone, Langfuse and Microsoft Azure, together with a subscribable feed of subprocessor changes, and holds SOC 2 Type 2, ISO/IEC 27001:2022, HIPAA, GDPR and CCPA compliance material available on request. Named customers include Kellogg, Hansen, Todd, Figel & Frederick, Nutter McClennen & Fish, Fields, Han & Cunniff, JND Legal Administration and Cimplifi.

Vendor site
Last verifiedSeptember 7, 2026
Compare with other vendors

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The product is the model work and nothing survives its removal. Fileread exists to read a document production and answer questions about it: users query the full collection in plain language rather than by keyword, and the vendor's own framing is that the point is asking the question you cannot turn into a keyword. Generation is the deliverable, not a feature bolted onto a repository: fact memos, chronologies, contradiction reports, character lists, org charts, deposition outlines and factual briefs are produced from the record, and a module called Workbench runs longer chains of research to assemble them. Retrieval spans formats that defeat keyword tooling, including images, handwritten notes, audio, video and spreadsheets, which is model work rather than indexing. The vendor's positioning sentence is an AI claim about its own architecture, that most legal AI is built to generate and this one is built to be checked, with every answer pinned to the location in the source. Strip the models out and there is no residual product: no case law database, no docket service, no document management system, only a customer's own production which the customer already holds. Homepage, product framing and the vendor's human oversight paper read 7 September 2026.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Grounding is real, documented and architecturally central, and no accuracy figure exists. What is published: every answer returns pinned to the exact location in the source document, a claim traces to its page so checking takes a glance, and generated work product retains its connection to the underlying material so a reviewer can inspect where a finding came from. The vendor states the design intent plainly, that the system is built to be checked rather than to be trusted, and maintains a dedicated paper on source citation and verification. It also publishes an authored, dated and practitioner-reviewed taxonomy of seven ways legal AI fails, with a detection control for several of them: unsupported generation, correct source with incorrect interpretation, context loss, missed evidence, conflicting evidence presented as certainty, identity confusion, and date and sequence errors. That is an unusually candid document and one of the failure modes has a product answer, since contradiction reports exist to surface the conflicts that the fifth mode describes being flattened. What keeps this off the top grade is the distinction between naming the failure modes of a class and measuring your own. The taxonomy is written as guidance about legal AI generally, not as disclosure about this system: no accuracy figure, no error rate, no test set, no benchmark and no evaluation result is published for Fileread itself. A buyer can see that the vendor understands how such systems fail and cannot see how often this one does. Homepage, failure modes paper of 17 August 2026 and human oversight paper read in full 7 September 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Substantive published commitments with the autonomy boundary stated, short of anything the product enforces. The boundary is stated, which is what keeps this off the middle grade: Workbench performs longer chains of research and assembles chronologies, factual briefs, contradiction reports and deposition outlines, and the vendor states that the resulting work remains a draft for professional review and refinement. So the reader is told the system runs multi-step work unattended and is told where it stops. Around that sits a published oversight framework, authored, dated and practitioner-reviewed, which is more than most records on this axis offer: oversight is framed as beginning before the prompt, with the task, included and excluded materials, intended audience, acceptable level of uncertainty, claims requiring source support, the person responsible for final review and the record to be retained all settled in advance; review is scaled to risk, with exploratory output to be treated as a starting point, citations sampled, and results not represented as established fact; and a twelve-point review checklist runs from whether cited passages actually support the statements to whether a responsible professional approved the final use. What is absent is the product half. The framework is guidance offered to the buyer rather than a specification of the system's own controls, only one paragraph describes what Fileread itself does, no configurable autonomy level or override is described, and nothing states that the checklist is recorded or enforced anywhere in the product. Human oversight paper and homepage read in full 7 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Named customers with named people in named roles, and one quantified account, with no method behind any of it. Five attributed testimonials are published: a partner at Kellogg, Hansen, Todd, Figel & Frederick describing use on an expedited case that went to trial; a partner at Fields, Han & Cunniff describing the system retrieving a correct document from an inaccurate description; a senior vice president for innovation and strategy at JND Legal Administration assessing the product on maturity, defensibility and user experience against alternatives; a manager of knowledge and practice support services at Nutter McClennen & Fish on the Relativity integration; and the chief technology officer of Cimplifi on replacing Boolean search. That is a spread across a litigation boutique, a large firm practice-support function, a litigation-support provider and an eDiscovery services company, which tells a buyer who actually runs it. One quantified account is published with the arithmetic shown: a matter arrived as 4,000 text message screenshots, which the platform converted and deduplicated to 725 actual messages, work the vendor states would have consumed more than 20 hours of attorney time. Independent coverage is cited, including a Law360 piece on a firm's generative AI experiments and reporting of a 6 million dollar seed round. What is absent is measurement: no aggregate figures, no recall or precision on retrieval, no customer count, and the time saved rests on a single anecdote rather than a study. Homepage, customer testimonials and cited coverage read 7 September 2026.

Source: Vendor Published
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Real controls are published and nothing addresses privilege, which matters more here than on most records because the material this product ingests is an entire litigation production. What exists: a statement that nothing a customer uploads trains a shared model; data encrypted and hosted in Azure and processed through what the vendor calls private large language models; and a trust centre control inventory naming least privilege, access monitoring, access log management and data asset classification, alongside HIPAA compliance which bears on the sensitive material productions contain. Those are corporate and infrastructure controls, and they are credited on the stewardship axis rather than counted twice here. What is absent is everything this axis asks. No privilege or work product treatment is published at any level. Nothing states who at the vendor may read customer matter material or under what conditions. No segregation position is published between matters held by the same customer or between customers, and the question is sharpened by the Relativity integration, since nothing states whether the platform inherits the workspace permissions a firm has already built there or maintains a second permission model of its own. The customer agreement that would carry a confidentiality clause is not readable: a Master Services Agreement is listed in the trust centre behind an access request, and the website terms render client-side and returned no body on this channel. The vendor's own oversight paper names protecting privileged material as an attorney duty, which is an acknowledgement of the risk rather than a commitment about the product. Homepage, security page and trust centre read 7 September 2026.

Source: Vendor Published
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Substantive published engagement with where professional responsibility sits, short of a located disclaimer or a named authority. Several limbs of this band do not bite and are named rather than penalised: the product analyses the customer's own document production rather than advising on law, its outputs are factual findings cited to the record rather than legal conclusions citing authority, and it is sold to lawyers and litigation support professionals rather than to the public, so the unauthorised practice risk this axis was written for is structurally remote. On what does bite, the vendor engages directly and in its own authored material. Its oversight paper states that artificial intelligence can assist with parts of litigation work but does not possess responsibility for the representation; that attorneys must interpret contested facts, assess credibility, understand procedural posture, protect privileged material and apply legal standards; that a fluent response may obscure uncertainty, missing context or an incorrect assumption; and that an exploratory question for internal orientation does not require the same process as a factual representation intended for a client, a witness examination or a court filing. Its review checklist ends with the output being reviewed under applicable legal and professional standards and a responsible professional approving the final use. What is missing is the formal half: no disclaimer language was located, because the terms of service render client-side and returned no body, and no bar rule, ethics opinion or court standing order is named anywhere. Human oversight paper and failure modes paper read in full 7 September 2026.

Source: Vendor Published
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

An AI-specific governance apparatus is disclosed by name, and its contents are gated. The trust centre lists two instruments in its policy library that most records in this corpus do not have at all: an AI System Development and Evaluation Policy, and an Artificial Intelligence Management System Plan, the latter using the term of art for the management system that ISO/IEC 42001 defines. It carries a separate AI section with overview, security and monitoring entries, so AI is treated as its own control domain rather than folded into general security, and the whole trust centre is described as continuously monitored with automated compliance monitoring and automated alert response. That is real substance, and it is the reason this is not the middle grade. What keeps it off the top is that nothing behind the titles was read and nothing is attested. Both policies sit behind an access request, so their existence and titles are established and their contents are not, and crediting a document by its title is not available here. No ISO/IEC 42001 certification is claimed, in contrast to ISO/IEC 27001:2022 which is claimed with its version. No evaluation result, benchmark or model card is published. Nobody is named as accountable for the system's behaviour. And no bias, fairness or representativeness disclosure exists at any level, which is worth naming for a product whose identity confusion failure mode, published by the vendor itself, involves combining information belonging to people with similar names, addresses or roles. Trust centre and failure modes paper read 7 September 2026.

Source: Vendor Published
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

The published control inventory is the broadest located in this pull, and one limb is missing. Certifications are named with the standard version: SOC 2 Type 2, ISO/IEC 27001:2022, HIPAA, GDPR and CCPA. Training is addressed: nothing a customer uploads trains a shared model, with data encrypted and hosted in Azure and processed through private large language models. Subprocessors are named on the public page rather than on request, being OpenAI, Baseten, Pinecone, Langfuse and Microsoft Azure, with Amazon Web Services and Azure listed as infrastructure, and a subscribable feed publishes changes to that list with dated entries recording the addition of Langfuse for prompt use and of OpenAI. Incident practice is present, with a documented incident reporting process and designated response personnel. Access control is present, with least privilege, access monitoring, access log management and data asset classification. Around those sit data loss prevention, application and network penetration testing, code analysis, credential management, backups with a backup policy, business continuity and disaster recovery including contingency plan testing and failover, change management with change notification and verification, endpoint controls including mobile device management and threat detection, anti-DDoS and firewalls, and security, privacy and phishing training. The gap, named because every partial names its limitation, is retention and deletion: no retention period, no deletion commitment and no end-of-matter or end-of-engagement disposal position was located anywhere, which is the question a litigation buyer asks about a production it has uploaded. Trust centre, security page and homepage read 7 September 2026.

Source: Vendor Published
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Nothing establishable on this date states who bears the loss when the product is wrong, and the cause is two different things which the reader should be able to tell apart. The agreements exist and the vendor says so: a Master Services Agreement and a Data Processing Agreement are both listed by name in the trust centre's legal section. Neither is published; both sit behind an access request, which is a disclosure choice about how the terms are made available rather than an absence of terms. Separately, the website terms of service linked in the site footer render client-side and returned the hosting platform's shell with no body on this channel, and a search on clause language did not recover the text, so that document is a limit of this reading rather than a vendor decision. The consequence for a buyer is the same either way and is what the grade records: no indemnity, no liability cap, no warranty, no service level commitment, no exclusive remedy and no insurance position can be read before entering a commercial conversation. The exposure worth naming on this product class is that its outputs become fact statements and pleadings a lawyer signs, and its own published failure taxonomy describes seven ways such outputs go wrong, with nothing published about what the vendor stands behind if they do. Trust centre read and terms of service attempted 7 September 2026.

Source: Operator Verified
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

One integration, into the system this product class actually runs on, documented on that platform's own marketplace. Fileread is available as a native integration inside Relativity, with a listing on the Relativity app hub, and the integration is described by a customer rather than only by the vendor, a practice support manager at Nutter McClennen & Fish attributing easier adoption to it. That is the deepest integration available in this segment: Relativity is where litigation productions already sit, and the vendor's design position follows from it, that the platform works on the productions a team already has with nothing to migrate. A second distribution surface exists on the Microsoft commercial marketplace, and the trust centre lists integrations as a product security control. Cimplifi, an eDiscovery services provider, describes offering the product through its own ecosystem, which is a channel rather than an integration and is recorded as such. What is absent is breadth and documentation. No API or developer documentation was located anywhere in the site navigation or footer. No document management system, case management platform, word processor or e-signature product is named. No integrations page or connector directory exists, and nothing describes what moves in which direction between Fileread and Relativity or how permissions travel across that boundary. Homepage, footer, Relativity app hub listing and trust centre checked 7 September 2026.

Source: Vendor Published
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Neither co-equal limb is stated, and what is published in their place is infrastructure. The cloud providers are named clearly and in more than one place: data is stated to be encrypted and hosted in Azure and processed through private large language models, and the trust centre lists both Amazon Web Services and Microsoft Azure under infrastructure and Microsoft Azure again among the subprocessors. Naming the cloud is where a workload runs, not the tenancy model and not the region, and it is credited on the supply chain and stewardship rows rather than here. On tenancy, nothing states whether customers are separated logically or physically, whether a matter is isolated from another matter, or what single-tenant options if any exist; the phrase private large language models points at dedicated inference rather than at tenancy of the data store and is not treated as a tenancy statement. On region, nothing states a country or region of storage or processing, no region selection is offered, and no data residency commitment appears despite GDPR compliance being claimed, which ordinarily brings a transfer position with it. Two gated artefacts in the trust centre would answer this directly and were not read, being a Data Flow Diagram and a Network Diagram, and they are the named rebuttal route on this row. Security page, homepage and trust centre checked 7 September 2026.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

A real trust centre with a named artefact inventory, and the reports themselves behind a request whose terms the portal does not state. What is ungated and readable: five compliance positions, being SOC 2 Type 2, ISO/IEC 27001:2022 with the standard version given rather than the bare number, HIPAA, GDPR and CCPA; a control inventory spanning roughly twenty categories from continuous monitoring and product security through access control, endpoint, network and application security to incident response, risk management, business continuity, asset management, change management and training; a named subprocessor list; and a subscribable feed of trust centre updates carrying dated subprocessor changes. That breadth of ungated detail is more than most records in this corpus publish at all. What sits behind the access flow: the SOC 2 report, an ISO 27001 report, a penetration test report, a data flow diagram, a network diagram, the policy library and the agreements. The portal offers to start a security review, to view and download sensitive information and to request access, and does not state whether access is granted instantly on an email address, by a self-service non-disclosure click-through, or by vendor approval after a sales conversation. Under the standing rule for gated artefacts the lower tier is taken where the portal does not say which it is, and that is why this is not the top grade, alongside the absence of any named auditor, audit period or scope statement. No request was submitted. Trust centre and security page read 7 September 2026.

Source: Vendor Published
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The fullest provider-level disclosure located in this lane, and the models are still not named. The trust centre publishes the subprocessors on its public page rather than behind the document request, and the list is legible as an AI stack rather than as generic infrastructure: OpenAI, Baseten, Pinecone, Langfuse and Microsoft Azure, with Amazon Web Services and Azure also listed as infrastructure. A reader can therefore establish that a named model provider is in the path, that inference serving and vector storage sit alongside it, and that a prompt observability layer is involved, the update feed recording in terms that Langfuse was added as a subprocessor for prompt use and that OpenAI was added as a subprocessor. Change notification exists as a published mechanism rather than a promise, the trust centre carrying a dated subprocessor changes feed with a subscribe option, which is a limb most records on this axis fail outright. Two things keep it off the top grade. No model or model family is named: the site says data is processed through private large language models, and under the standing rule naming a provider is not naming the models underneath. And nothing states which parts of the platform route customer content to which provider, so a reader knows OpenAI is in the stack without knowing what it sees. Trust centre and security page read 7 September 2026.

Source: Vendor Published
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

No pricing information is published at any level, including the unit of charge, and the site's own navigation establishes that no pricing page exists rather than that one could not be reached. The published inventory of the site is Product, Solutions with three segment pages, Customers, Security and Resources, with a footer adding Workflows, Company, Privacy and Terms of Service. There is no pricing entry in either the header or the footer. Every conversion path on every page ends at the same call to action, an invitation to see the product on your matter, which is a demo request. No tier or edition is named, no unit is identified whether by seat, matter, document, gigabyte or production, no band or range appears, no minimum or term is stated, and no free tier or trial is described. The two documents that would carry the commercial mechanics are unavailable: the Master Services Agreement is listed in the trust centre behind an access request, and the website terms of service render client-side and returned no body. Where the only route is an invitation to contact sales, no pricing row is owed and none is written. Site navigation, footer, security page and trust centre checked 7 September 2026.

Source: Operator Verified
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

The buyer, the workflow and the material are each described with real specificity, and no boundary is stated. Three buyer segments have their own surfaces: litigation teams, eDiscovery, and corporate legal. Five workflows are published individually, being early case assessment, discovery document review, evidence analysis, deposition preparation, and factual briefs and case narratives, and the lifecycle claim is explicit, from first production to trial. The named customer set matches that spread rather than sitting in one corner of it, running from a Washington litigation firm and a boutique through a large firm's knowledge and practice support function to a litigation administration provider and an eDiscovery services company. Coverage of the material itself is unusually concrete and is the strongest part of this row: text, images, handwritten notes, audio, video and spreadsheets in the same matter, with the vendor claiming the formats that defeat other tools, illustrated by a production that arrived as 4,000 text message screenshots. What is absent is any limit. No jurisdiction is named, and none is excluded, though the customer set and the vocabulary are United States civil litigation throughout. No matter type, case size or practice area is named as in or out of scope. No volume ceiling is published despite scale being the product's central claim. Homepage, solutions and workflow navigation and customer testimonials read 7 September 2026.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Never, in policy only

A public policy or trust page states no training on customer content, with no matching term located in the published agreement.

A clear public statement with no agreement located to match it, and the wording carries a qualifier worth reading closely. The statement appears on both the homepage and the security page: data is encrypted in Azure and processed through private large language models, and nothing a customer uploads trains a shared model. That is a plain position, published where a buyer will see it before any conversation. The search for a matching contractual term was completed rather than assumed, which is what this value requires. A Master Services Agreement and a Data Processing Agreement both exist and are listed by name in the trust centre, and both sit behind an access request rather than on a public page. The website terms of service linked in the footer render client-side and returned the hosting platform's shell with no body, and a search on clause language did not recover the text. So no published agreement could be read and no contractual training term could be located either way. The qualifier is the word shared. The commitment as written is that uploads do not train a model used across customers; it does not address whether a customer's own material may be used to tune or adapt a model for that customer, nor whether prompts and outputs may be used for evaluation, debugging or product improvement short of training, a question the presence of a prompt observability subprocessor in the AI path makes worth asking. Security page, homepage and trust centre read, terms of service attempted, 7 September 2026.

Source: Vendor PublishedData is encrypted in Azure and processed through private LLMs. Nothing you upload trains a shared model.As of Sep 7, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Not addressed

No located public material states how long prompts and outputs are retained.

No located public material states how long prompts, uploaded productions or generated outputs are kept, or whether a customer can change it. Nothing publishes a retention period, a deletion commitment, an end-of-matter or end-of-engagement disposal position, or any customer-facing control over any of it. This is the one gap in an otherwise broad stewardship disclosure, and it is the gap that matters most for this product class: what is uploaded here is an entire litigation production belonging to a client, and a buyer cannot establish what happens to it when the matter closes or the subscription ends. Three trust centre entries would bear directly on the question and were not readable, being data into system, data out of system and data backups, each an item in the gated control detail rather than a published statement, and they are the named rebuttal route on this row. The two agreements that would ordinarily carry a deletion-on-termination clause are the Master Services Agreement and the Data Processing Agreement, both listed in the trust centre behind an access request. What is published nearby, and is credited on the stewardship axis rather than counted here, is that a backup policy exists and that nothing uploaded trains a shared model, neither of which answers how long anything is kept. Trust centre, security page and site navigation checked 7 September 2026.

Source: Operator VerifiedAs of Sep 7, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Not addressed

No located public material addresses walls or matter level segregation.

No located public material addresses walls or matter-level segregation, and the product's own architecture makes the omission conspicuous. The platform is designed to read across an entire production and answer from all of it, including across documents, audio, video and spreadsheets in the same matter, which is precisely the retrieval shape this signal was written to test. Nothing published states whether one matter's material is isolated from another matter's inside the same customer, whether a reviewer on one side of a screened matter can query the other side, or how one customer's production is separated from another's. The Relativity integration sharpens the question rather than answering it: a firm running Relativity has already built workspace and matter permissions there, and nothing states whether Fileread enforces that access model at query time or maintains a second permission model the firm would have to keep aligned. What is published is corporate access control rather than a wall, being least privilege, access monitoring, access log management and data asset classification, all of which govern who at the vendor and on the customer's account may reach data generally, and all of which are credited on the stewardship axis rather than counted twice here. No customer agreement is readable that might carry a segregation term. Trust centre, homepage, security page and site navigation checked 7 September 2026.

Source: Operator VerifiedAs of Sep 7, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Not addressed

No located term or policy addresses third party requests for customer data.

No located public material addresses what happens when a third party demands customer data, and the reason is a readable one that belongs on the record. The two surfaces that ordinarily carry a compelled-disclosure position are the privacy policy and the customer agreement. The privacy policy is linked in the site footer, renders client-side on its hosting platform and returned the platform's shell with no body on this channel, and a search on clause language did not recover the text. The Master Services Agreement and the Data Processing Agreement are both listed by name in the trust centre and both sit behind an access request. No transparency report, law enforcement guidelines page or government request policy was located on any surface, and the trust centre's legal section lists only the two agreements and a subprocessor entry. So nothing is established either way: no notice commitment, no reservation of discretion over notice, no undertaking to seek a protective order, and equally no statement that disclosure would occur without notice. This is recorded as what could be established on the date rather than as a finding about the vendor's practice, and the privacy policy and the two agreements are the named rebuttal route. Site footer, trust centre and site navigation checked 7 September 2026.

Source: Operator VerifiedAs of Sep 7, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Sources named, basis unstated

Sources are identified without stating the licence or rights basis.

The corpus is identified unambiguously and no rights basis is stated, and most of this signal's limbs do not bite on a product of this shape. The source of every answer is the customer's own document production, which the vendor identifies plainly: the platform works on the productions a team already holds with nothing to migrate, reading across text, images, handwritten notes, audio, video and spreadsheets in the same matter, and every answer is pinned to the location in that material. There is no vendor-assembled corpus of law behind the outputs, so the two risks this signal exists to price sit differently here. Coverage is not a question about the vendor's collection but about what the customer loaded, and the vendor addresses that directly on the risk side by publishing missed evidence, including incomplete ingestion, as one of its named failure modes. Title is not a question about legal publishing at all: no case law, legislation or editorial content is licensed in, so no third-party corpus could be enjoined and no licence could be named. What is genuinely unstated is the rights position around the customer's own material, since no readable agreement sets out what the vendor may do with an ingested production beyond the statement that nothing uploaded trains a shared model. The limbs that do not apply are named rather than penalised, and this is a structural difference from the research products in this lane rather than a disclosure gap. Homepage, failure modes paper and security page read 7 September 2026.

Source: Vendor PublishedWorks on the productions you already have. Nothing to migrate.As of Sep 7, 2026Evidence

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

No located public material addresses whether authority is checked for subsequent history, and the limbs do not bite for this product class. Nothing the platform produces cites legal authority: answers, fact memos, chronologies, contradiction reports and deposition outlines cite documents in the customer's own production, so there is no reported decision, statute or secondary source whose treatment a user would need to check, and no citator could be licensed or built for a corpus of that kind. The analogue that does bite is currency within the record rather than currency of law, and the vendor addresses it in its own idiom rather than through this signal: its published failure taxonomy names context loss, where a later correction or the surrounding conversation changes the meaning of a cited passage, and date and sequence errors, where the date an event occurred is confused with the date a document was created, sent, received, modified or produced, with verification against metadata and document versions given as the control. Those are credited on the Citation Accuracy axis and are not counted again here. Recording this as a non-applicable limb rather than a failure is the honest treatment: a document review platform has no citator, and it should be neither penalised nor credited for that. Failure modes paper, homepage and product surfaces checked 7 September 2026.

Source: Operator VerifiedAs of Sep 7, 2026Evidence

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

No located public material describes what the system does when it cannot reach a supported answer, and this is the sharpest omission on the record because of what sits next to it. The vendor publishes an authored taxonomy of seven ways legal AI fails, including unsupported generation, missed evidence and conflicting evidence presented as certainty, and it opens by observing that legal AI can fail even when its output is clear, detailed and persuasive. Its oversight paper adds that a fluent response may obscure uncertainty, missing context, conflicting evidence or an incorrect assumption, and lists showing uncertainty or gaps where practical among the properties a workflow ought to have. Every one of those is a description of the problem or a specification for tools in general; none states what this system does. Nothing published says that Fileread declines a question it cannot ground in the production, reports that it could not find responsive material rather than assembling a plausible answer, exposes a confidence or coverage signal to the reviewer, or flags where a chronology has a gap. The detection controls in the taxonomy are addressed to the reader, requiring the lawyer to verify that the source supports the proposition and to confirm identity across multiple attributes, which places the uncertainty work on the user. The taxonomy itself is credited on the Citation Accuracy axis and is not counted again here. Failure modes and human oversight papers read in full, homepage and product surfaces checked, 7 September 2026.

Source: Operator VerifiedAs of Sep 7, 2026Evidence

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

No court order, opinion or disciplinary record naming Fileread was located as of 7 September 2026. Searches were run on the product name against sanction and hallucination language and against the AI Hallucination Cases database maintained by Damien Charlotin, together with the secondary trackers that summarise it; the decisions naming specific tools name general-purpose chatbots and legal research products. The former name Fileread AI and the announced name Aurelogy were both included in the search terms. This is a statement about the public record and not a finding about the product. Two features of this record bear on how it should be read. Exposure is structurally different from a research tool's, because the citations in this product's outputs point to documents in the customer's own production rather than to case law, so a fabricated authority in the classic sense is not the failure mode available here; the vendor's own taxonomy names the analogous risks instead, being unsupported generation and citing a real document for a proposition it does not establish. And the vendor has engaged the question in public rather than avoided it, publishing that taxonomy under its own byline.

Source: Operator VerifiedAs of Sep 7, 2026Evidence
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Generic reference

Public materials refer to professional responsibility in general terms without naming guidance.

Professional responsibility is engaged substantively and in the vendor's own authored material, and no binding guidance is named. The engagement is real and specific to AI rather than boilerplate. The oversight paper states that artificial intelligence can assist with parts of litigation work but does not possess responsibility for the representation, and enumerates what remains the lawyer's: interpreting contested facts, assessing credibility, understanding procedural posture, protecting privileged material, applying legal standards and making strategic decisions. It scales the required process to the use, distinguishing an exploratory question for internal orientation from a factual representation intended for a client, a witness examination or a court filing. Its checklist requires that privilege and confidentiality issues were addressed, that the output was reviewed under applicable legal and professional standards, and that a responsible professional approved the final use. The paper carries an author and a practitioner review line and is dated. What is absent is any named authority. No bar association ethics opinion, no rule of professional conduct cited by number, no state or federal court standing order on AI disclosure and no regulator guidance appears anywhere, and nothing maps obligations by jurisdiction for a product sold into United States litigation where those standing orders are court-specific. The value records engagement in general terms without named guidance, which is exactly what is published. Human oversight and failure modes papers read in full 7 September 2026.

Source: Vendor PublishedAI can assist with parts of that work, but it does not possess responsibility for the representation.As of Sep 7, 2026Evidence

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure, and the product sits inside a fee relationship between a lawyer and a client where those savings would change the bill.

Time savings are the central marketing claim and nothing addresses the client's side of the bill. The product sits squarely inside a fee relationship: it is sold to case teams at law firms, and the work it compresses is document review and case preparation, which is billed to a client. The savings claims are explicit and quantified in attorney hours rather than in the abstract. One published account describes a production arriving as 4,000 text message screenshots that the platform converted and deduplicated to 725 messages, work stated to be more than 20 hours of attorney time. Elsewhere the site promises a contradiction report that takes a lawyer eight hours in minutes, key documents and fact-checking during depositions accomplished in minutes as opposed to hours or days, insights to clients in days not weeks, and knowing the lay of the land on day one instead of week three. Against all of that, no published material addresses billing, fee treatment or client disclosure. Nothing tells a firm how to treat eight hours that became minutes, nothing offers a per-matter record of AI-assisted work that could support a fee narrative, and no guidance on disclosing AI assistance to a client was located. The omission is worth naming precisely because the vendor engages professional responsibility carefully elsewhere, publishing an oversight framework and a failure taxonomy, so this is not a general silence about the lawyer's obligations. Homepage, oversight paper and site navigation checked 7 September 2026.

Source: Vendor Publishedwork that would have consumed more than 20 hours of attorney timeAs of Sep 7, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Subprocessors listed

A current subprocessor or model provider list is published.

A current subprocessor list is published without a gate and the forwardable pack around it is not. What a firm can take to a client today: a named subprocessor list carrying OpenAI, Baseten, Pinecone, Langfuse and Microsoft Azure, published on the open page of the trust centre rather than behind the document request; a statement that a named model provider is in the path rather than only a cloud, which is the distinction a client's AI clause turns on; a subscribable feed of subprocessor changes with dated entries, so the firm can answer how it will learn of a new provider; and five compliance positions including ISO/IEC 27001:2022 with its version and SOC 2 Type 2. That is a substantive answer to the first half of a client questionnaire. What a firm cannot forward is the material itself. The Data Processing Agreement and the Master Services Agreement are both listed in the trust centre behind an access request, so the confidentiality, security and liability terms a client's outside counsel guidelines ask about cannot be sent in advance, and no separate client-facing disclosure pack, AI use notice or consent template was located. Under the standing rule that the top value needs a forwardable artefact alongside the lists, and that a subprocessor list sitting outside a data processing agreement with no other forwardable document drops a rung, this takes the middle value. No access request was submitted. Trust centre and security page read 7 September 2026.

Source: Vendor PublishedSubprocessors * Langfuse.Com * OpenAI * Baseten * Pinecone * Microsoft AzureAs of Sep 7, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Not addressed

No located public material addresses court disclosure or verification certification.

No located public material offers a record of AI-assisted work that a lawyer could produce to a court, and the vendor's own writing shows it has thought about the need without meeting it. Its oversight paper tells teams to settle in advance the record that should be retained of the process, and its checklist asks that corrections and unresolved questions were recorded and that a responsible professional approved the final use. Those are instructions to the firm to keep its own record, not a product that emits one. Nothing published states that Fileread records which model or module produced a given output, what it retrieved, which sources it considered and rejected, or what a person verified before the result was used, and no export, certification or template framed for a court or a standing order is offered. Two adjacent things are named so the grade is read correctly and neither is counted twice. The source citation on every claim, which links work product to the page it came from, is the product's central mechanism and is credited on the Citation Accuracy axis; it evidences what an output rests on rather than what the system did to produce it. Audit logging appears in the trust centre as a product security control, which records access to data rather than the conduct of AI-assisted work, and it is credited on the stewardship axis. Human oversight paper, homepage, trust centre and product surfaces checked 7 September 2026.

Source: Operator VerifiedAs of Sep 7, 2026Evidence
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 7, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746