Harvey
Enterprise legal AI platform for law firms, in house legal departments and professional services firms. Ships Assistant for chat, drafting and document analysis, Vault for bulk cross document review, Knowledge for legal, regulatory and tax research with citations, and Workflow Agents for multi step automation. Connects into iManage, NetDocuments, SharePoint, Box, Word and Outlook. Publishes BigLaw Bench, its own public evaluation framework, with measured hallucination and source scores.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the product. Assistant, Vault, Knowledge and Workflow Agents are all generative systems, and there is no underlying document or workflow system that would stand without them. Vendor material describes every module in model terms.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
CORRECTED 29 Aug 2026, second correction to this row. Previously graded B on two stated grounds, both of which are now resolved. Ground one was that BigLaw Bench is the vendor's own framework rather than independent evidence. That remains true of BigLaw Bench, but independent evidence also exists and was missed: Harvey Assistant participated in the February 2025 Vals Legal AI Report, a third party benchmark against a measured lawyer baseline, and was evaluated across six tasks scoring between 65.0 and 94.8 percent, surpassing the lawyer baseline on five of the six, with 94.8 percent on document question answering at 24.7 points above baseline and 77.8 percent on scanned and messily formatted court transcripts at 24.1 points above baseline, all at sub minute response times. Those figures sit on the evaluator's own site and are checkable without reference to any vendor claim. Ground two was that the citator and refusal limbs failed. That was a double count and is withdrawn: both are separately measured by their own signal rows on this record, and applying them again to the capability grade penalised the same absence twice. It was also inconsistent, since three legal research vendors on this index hold an A on this axis with both of those signals recorded as not addressed. The vendor's own disclosure is unchanged and remains substantial: BigLaw Bench with task categories and grading rubrics on a public repository, measured hallucination rates and source scores by model, a hallucination defined as a factual claim disprovable against a source of truth with reasoning errors tracked separately, and output linking to the specific document passages supporting each assertion. Two limits recorded rather than deducted for: the February 2025 study measured task accuracy rather than citation validity or hallucination rate specifically, and this vendor did not participate in the later Vals study that measured citation authoritativeness. The full BigLaw Bench dataset also sits behind a direct request rather than open publication.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
States in published material that the product is designed to assist lawyers rather than replace them and that it is built to make verification easy. Review surfaces are real and documented: inline links to source passages, role based permissions and conditionals in the workflow builder, and admin level workspace governance. Not located as of 29 Aug 2026: the threshold at which an agent stops and hands back to a lawyer, or what the vendor commits to when an agent is wrong.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers appear in vendor material with attributed quotes, including Blank Rome on the iManage integration and a published Burges Salmon selection story. Vendor states 700 plus customers across 58 plus countries. Not located as of 29 Aug 2026: dated outcome figures with a stated method a reader could assess, which is what separates this from an A.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments: no training on customer data by default, a contractual prohibition on model providers training, zero data retention enforced on model providers, logical workspace separation, role based access, ethical wall sync with the firm's own walls provider, and processing in the EU, Switzerland or Australia. Two gaps keep this off an A. The security page defines customer data as uploaded documents and customer content as queries and responses as separate contractual terms, so the no training commitment reads plainly on one and not on both. Attorney client privilege and work product handling is not addressed directly in located public material as of 29 Aug 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
One sentence in a security blog post states the product is designed to assist lawyers rather than replace them. Checked the vendor site, security page, security addendum and help center on 29 Aug 2026 and did not locate a published position on the advice line, on competence and supervision duties, or on jurisdiction limits. The intended audience is unambiguously lawyers and legal departments, which is why this sits at C rather than lower.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
CORRECTED 29 Aug 2026, third correction to this record. Previously graded C on the finding that no AI specific governance regime was located and that the published testing was security testing rather than model behaviour testing. That was wrong, and it came from reading the vendor's marketing surfaces rather than opening its trust centre, where the governance material actually sits. What is published on the trust centre, publicly and without a request: ISO/IEC 42001:2023 certification, the international standard for AI management systems, accompanied by a published Statement of Applicability, which is the document identifying which controls apply and why and is therefore a published scope rather than a bare badge. Alongside it, AIUC-1 certification, an AI specific assurance standard, conducted by Schellman, which the vendor states is the first accredited AIUC-1 certification body, and which the vendor describes as validating adversarial testing and its AI security programme specifically. EU AI Act conformity is separately listed. The trust centre carries a dedicated AI section with AI Governance, AI Monitoring and AI Overview items, and an AI Acceptable Use Policy sits in the published policy set. ISO 27701 for privacy information management and an IRAP attestation are also held. Two independent AI specific certifications, one of them adversarially tested, with published statements of applicability and a named accredited certifier, is the strongest AI governance position on this index, ahead of the four other A grades on this axis, each of which rests on ISO 42001 alone or on a single certification plus a framework document. One gap remains and is recorded rather than waived: no disclosure was located about uneven output across matter types, parties or populations, so bias specifically is still unaddressed, and no named individual owner of model governance was located.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Publishes retention under customer control with documented vault retention triggers and deletion timelines, role based access control, logical workspace separation, encryption in transit and at rest, and a current named subprocessor list with an update FAQ. Not located as of 29 Aug 2026: a published incident and breach notification practice, which is the remaining element of the A bar.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Checked the vendor site, its published legal pages including the security addendum and the subprocessor FAQ, and the trust center on 29 Aug 2026. No published indemnity scope, liability cap, carve out, warranty or insurance position located. Commercial terms appear to be reached through a negotiated enterprise agreement rather than published.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Documented native integrations with iManage, NetDocuments, SharePoint and OneDrive, Google Drive, Box, Microsoft Word, Outlook, EDGAR and PitchBook, plus an MCP connector library. Help center articles describe what each integration moves, in which direction, what an admin must configure, and what a given integration does not support. The iManage connection is a direct OAuth integration with an embedded web extension rather than third party middleware.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
States processing in the EU and Switzerland or Australia for customers with data localization requirements, and states that this applies to subprocessors as well. Tenancy is multi tenant with logical workspace separation and enforced role based access. Not located as of 29 Aug 2026: where data is stored as distinct from where it is processed, and what changes between tiers.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
SOC 2 Type II attestation and ISO 27001 certification with the auditor named as Schellman, renewed annually, and the 2026 cycle announced publicly. Penetration testing and red teaming partners are named as NCC Group and Bishop Fox. Certified under the EU US Data Privacy Framework. A live trust portal at trust.harvey.ai carries the current reports. Reports sit behind a portal request rather than an open download, which is a request flow rather than a sales call.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Publishes a subprocessor list naming model and infrastructure providers including OpenAI, Anthropic, Google Cloud, AWS and Microsoft, alongside a subprocessor update FAQ and a security diagram showing model access through Bedrock and Vertex AI. States zero data retention and ephemeral processing at the model providers. Not located as of 29 Aug 2026: a published commitment to notify customers before the model supply chain changes, as distinct from an FAQ describing a change that has already happened.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Checked the vendor home page, the platform and product pages, the help center and the trust center on 29 Aug 2026. No pricing page, no published rate, no stated unit of charge and no published tier structure located. Access to pricing runs through a demo request, which is sales gated and earns no credit. Third party per seat estimates exist in trade coverage but are not vendor published and do not move this axis.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Describes its segments with substance: large law firms first, expanding into corporate legal departments and professional services, with 700 plus customers across 58 plus countries and practice coverage spanning litigation, transactional diligence, regulatory and tax. Not located as of 29 Aug 2026: a statement of the boundaries, meaning which firm sizes or practice areas the product is not built for, which is what the A bar asks for.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
A public policy or trust page states no training on customer content, with no matching term located in the published agreement.
The vendor security page states that by default it never trains on customer data and that it contractually prohibits model providers from training on customer data. A subprocessor FAQ states customer data is never used to train models unless explicitly authorized by both the customer and the vendor. The same page defines customer data as uploaded documents and customer content as queries and responses as separate contractual terms. No matching term was located in a published agreement as of 29 Aug 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
The customer controls the retention window, by product configuration or by contractual instruction, but zero retention is not stated as available.
REGRADED 29 Aug 2026 after the value set was amended; previously recorded at disclosed without a period, which understated real customer control. The security page states that customers determine what data to upload, how long it is retained, and whether it can be shared internally, and help centre documentation covers configuring vault retention settings including triggers and deletion timelines. That is retention configured by the customer inside the product, which is the strongest form of the control this value describes. Recorded at customer controlled rather than the top value because no zero retention setting for the vendor's own storage was confirmed in public material as of 29 Aug 2026, and no default period is published, so a customer knows they can set the window without knowing what it is before they do. Zero data retention is stated separately as a requirement imposed on model providers, which is a different layer.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Retrieval enforces the source system access model at query time, per user, and the vendor documents it.
Help center documentation states the product follows existing NetDocuments permissions, that a user sees only the cabinets, matters, folders and files they can already access, and that the product does not expand or modify permissions. The iManage integration is documented as a direct OAuth connection that respects iManage permissions and ethical walls. Separate admin documentation covers connecting, syncing and monitoring the firm's own ethical walls provider.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located term or policy addresses third party requests for customer data.
Checked the security page, the published security addendum and the subprocessor update FAQ on 29 Aug 2026. No located term or policy addresses government or law enforcement requests for customer data, and no transparency report was located.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Sources are identified without stating the licence or rights basis.
The published subprocessor material identifies RELX and LexisNexis as a source provider behind an Ask LexisNexis feature, alongside web search providers, and product material refers to premium legal databases and curated public sources. The identification appears in the subprocessor list rather than a coverage page. No licence or rights basis, jurisdiction list or update cadence for the primary law corpus was located as of 29 Aug 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Checked product pages for the research module, the help center and the subprocessor material on 29 Aug 2026. A LexisNexis sourced research feature is documented, but no public material was located addressing whether authority returned by the product carries a treatment signal or is checked for subsequent history.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
The vendor publishes measured hallucination rates and describes how hallucinated claims are detected and scored. Checked that research material, the product pages and the help center on 29 Aug 2026 and did not locate published material describing an explicit no answer or abstention path when the product cannot ground an answer.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published sanctions summaries from Norton Rose Fulbright covering 2026 and two vendor maintained trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance, and it is bounded by what that database covers.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Public materials refer to professional responsibility in general terms without naming guidance.
Published material refers in general terms to aligning with the high standards expected of legal work and to designing the product so that verification is easy. Checked the blog, resource pages and help center on 29 Aug 2026 and did not locate engagement with any named ethics opinion, including ABA Formal Opinion 512 or state bar guidance.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Vendor material offers impact and return on investment resources framed around what the product does for a firm or business, and the help center documents usage analytics dashboards and reporting APIs. Checked those surfaces on 29 Aug 2026 and did not locate a per matter record of AI assisted work intended for fee purposes, or any published guidance on billing, fee or client disclosure treatment.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
UPDATED 29 Aug 2026 during the trust portal sweep; value unchanged, evidence enumerated. The trust centre was opened directly and its published inventory is the most complete outside counsel readiness pack on this index. Available without a request, as named items: a Data Processing Addendum, a Business Associate Addendum, a Data Subject Requests item, completed self assessment questionnaires in three standard formats being CAIQ v4.0.3, SIG Core and SIG Lite, a Data Flow Diagram, a Network Diagram, a HIPAA report, a report titled Security and Privacy of Customer Data, and a Security Welcome Packet. A Subprocessors section is published as a standing part of the trust centre. Sensitive documents sit behind a self serve access request with a bulk download option. Compliance items are listed individually and include statements of applicability for ISO 27001, 27701 and 42001, which tell a client's reviewer what each certification actually covers. A firm answering a client AI clause could assemble a complete response from this without a sales conversation. One limitation recorded honestly: the subprocessors list renders client side and its contents were not retrieved in this pass, so the section's existence is established rather than the identity of the subprocessors in it.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Published material documents audit logs as a default enterprise control, inline links from assertions to the specific source passages behind them, and usage analytics available through a dashboard and APIs. Checked those surfaces on 29 Aug 2026 and did not locate a per document export covering model used, sources retrieved and human verification together.