H
Hebbia
Hebbia is a New York company whose platform, Matrix, runs structured multi-step analysis across large sets of documents a customer uploads, returning answers in a spreadsheet-like grid where each row is a document and each column a question, with sources shown for each cell; Max is its agent product. It is sold to asset managers, investment banks, corporate finance teams and law firms, and its legal surface addresses lawyers directly, naming due diligence, credit agreements and lending documentation, capital markets drafting from filings and precedent transactions, fund formation and portfolio governance, building reusable databases of a firm's past matters, and bespoke firm workflows, with Latham & Watkins, Cleary Gottlieb, Ropes & Gray and Seyfarth shown as customers. The published Main Services Agreement, Data Processing Agreement, acceptable use policy and privacy policy are all available without an account. The data protection agreement carries an unusually complete subprocessor register: it names OpenAI, Anthropic, Google and Microsoft as providers of the large language model capabilities that process user prompts and files, names Cerebras, Groq, Baseten, Fireworks AI and Modal Labs as hosts of parts of the inference infrastructure, gives a processing location for each, and commits to ten days' notice before any new subprocessor is engaged. Hebbia states it does not train on customer data, and its agreement separately permits it to use customer materials to improve machine learning models that are solely for that customer's use and may not be made available to any third party. Customers are contractually prohibited from uploading sensitive personal identifiers, health information or European personal data without Hebbia's prior written approval. Hebbia holds SOC 2 Type II and states ISO/IEC 42001:2023 certification for AI management; the platform is hosted on AWS in United States and European regions, and pricing is quoted per order rather than published.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The artificial intelligence is the product. Matrix is described by the vendor as a platform for building AI agents that complete end-to-end tasks rather than chatting, decomposing a question into structured steps across thousands of uploaded documents and returning a grid where each row is a document and each column a question, with sourcing shown per cell; Max is the agent product sold alongside it. The subprocessor register makes the architecture concrete, naming four large language model providers that process user prompts and files and five separate services that host parts of the inference infrastructure. There is no underlying document system, workflow tool or system of record that survives the removal of the models: strip them out and there is nothing left to sell. Legal solution page, security page, Matrix 2.0 announcement and DPA Annex III read 7 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted and never measured, and the vendor's own agreement contradicts the marketing claim. The security page states that Hebbia is creating the standard for trustworthy large language models that never hallucinate and give correct, verifiable answers. The Main Services Agreement, section 7.1, states in capitals that Hebbia does not warrant that the platform is accurate or complete and that it is provided as is. No accuracy figure, no test set, no evaluation and no described retrieval method appears on any first-party surface read, and the grounding that does exist is real but only asserted: outputs are described as verifiable and structured step by step, over documents the customer uploaded and can therefore open. The bottom limb does not fire, because a hallucination claim standing alongside a real document-grounded architecture is not a bare claim, but a claim that a system never hallucinates, published beside a term disclaiming accuracy, is the marketing-versus-agreement gap in one page. The unread Matrix product page is the rebuttal route and would be the place a described method appears. Security page, MSA and Matrix 2.0 post read 7 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Autonomy is claimed at length and oversight is asserted without a described control. The product is sold as agents that complete end-to-end tasks rather than answering questions, running multi-step analysis across whole document sets and carrying the work through to a memo, a deck or a model; the vendor's framing is an operating system for complex work. What sits on the oversight side is transparency of output rather than a control structure: sourcing is shown for each cell of the grid so a user can check where an answer came from, and the structured step-by-step format is presented as the guarantee of quality. No located material states what an agent may do without a person, at what point it stops, what review the vendor expects before an output is used, or what happens when it is wrong beyond the warranty disclaimer. Legal solution page, security page and Matrix 2.0 announcement read 7 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Logos stand in for evidence on the vendor's own surfaces, and the figures live somewhere else. The legal page displays the marks of Latham & Watkins, Cleary Gottlieb, Ropes & Gray and Seyfarth with no accompanying statement of what any of them does with the product, no attributed quotation and no result. The quantified claims that exist are on third-party pages and are described here rather than credited: OpenAI's case study on Hebbia states that law firms reduce credit agreement review time by 75 per cent, saving $2,000 an hour in legal fees, and that investment bankers save 30 to 40 hours a deal, and Andreessen Horowitz's investment announcement reports unnamed customers saying analyses that took two to three hours now take two to three minutes. None of that is published by the vendor, none names the firm behind the figure, and no method is stated for any of it. A named, dated deployment on Hebbia's own surface is the route to a higher grade. Legal page read and third-party material reviewed 7 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments, short of the segregation and privilege limbs. What is published and binding: Customer Materials are the customer's Confidential Information and the customer owns them (MSA 6.1, 3.3); Hebbia will not access or use Customer Materials to provide technical support without the customer's documented consent (1.2), which is a sharper commitment than most agreements in this corpus make; Customer Materials are deleted within 30 days of termination (5.4(c)) and personal data is deleted on request at any time (DPA Annex II); the position on model providers is explicit, with OpenAI, Anthropic, Google and Microsoft named in the DPA as processing user prompts and files. Two limbs are missing. Nothing located addresses segregation between users, matters or clients inside a customer tenant, which matters for a product sold to four named AmLaw firms. Privilege and work product are not addressed anywhere, which R33 treats as a required limb of the top band. The training position is also adverse and is graded on its own signal: the agreement permits improving machine learning models with Customer Materials where those models are solely for that customer. MSA and DPA read in full 7 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
No position on the advice line was located, for a platform sold to law firms for due diligence, capital markets drafting and matter work. The Main Services Agreement was read in full and addresses use restrictions, warranties, indemnities, liability and arbitration without touching advice, competence or supervision; its disclaimer at 7.1 is a warranty disclaimer rather than a statement of what the product is and is not. The acceptable use policy governs misuse, infringement and harassment, not the practice of law. The legal solution page describes lawyers using the product to advise better and become the trusted adviser clients rely on, without a corresponding statement that the output is not legal advice. The audience is unambiguous and professional, which is recorded rather than credited. This records what is establishable on the date; a product disclaimer inside the application, if one exists, is the rebuttal route. Surfaces checked 7 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A published, independently audited governance framework, short of testing results or a named owner. The legal solution page displays ISO/IEC 42001:2023, the management system standard for artificial intelligence, alongside SOC 2 Type II, and the security page repeats an ISO mark. A certification against an AI management standard is real substance and carries more weight than a self-published principles page, which is the position this index has taken since the Corlytics and Ontra records. What is not published is what the standard's certification would sit on top of: no governance policy, no statement of who inside Hebbia is accountable for model behaviour, no description of what is tested before an agent ships, and no disclosure of any finding about uneven output across matter types or populations. The certificate itself, its scope and its date were not located, and the Vanta-hosted trust centre that would carry them returns page metadata with no body on this channel, which is recorded as a retrieval limit and named as the rebuttal route. Legal page, security page and trust centre attempted 7 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Retention, deletion, access control, subprocessors and incident practice are all published and specific, and the whole set sits in documents a buyer can read before signing. Annex II of the Data Processing Agreement is a full technical and organisational measures table: AES-256 encryption at rest through AWS-managed keys, TLS 1.3 in transit, multi-factor authentication and single sign-on with two-factor required on all production access, hourly backups of production datastores that are periodically tested, monitored security logging with escalation, change management automated through CI/CD, and annual SOC 2 Type II audits covering the security criteria. Deletion is stated twice over: customers may request deletion at any time and delete through self-service, all personal data is deleted following termination, a subject-access form is published for erasure and portability, and MSA 5.4(c) deletes Customer Materials within 30 days of termination. Annex III names every subprocessor with its processing location, and the DPA commits to listing and notifying any new one ten days before it touches personal data, with an objection right. The one softness is the incident clause, which requires Hebbia to inform the customer without undue delay and cooperate to the timescales the law requires rather than committing to a fixed number of hours. DPA and MSA read in full 7 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
What the vendor stands behind is published and specific, including the places where it stands behind nothing. Section 8.2 gives a defence and indemnity against third-party claims that Hebbia's technology infringes a US patent, copyright or trade secret, with three named exclusions and the procure, replace or terminate-and-refund mitigation ladder; section 8.3 makes the indemnities the only remedy for third-party intellectual property claims. Section 9.2 caps aggregate liability at fees paid or payable in the twelve months before the event, expressly including indemnity claims, so a buyer can see that the indemnity is inside the cap rather than outside it, which is less generous than several peers and is stated rather than hidden. Section 9.1 excludes indirect loss and data inaccuracy for both parties, with Excluded Claims at 9.3 lifting that exclusion for the intellectual property indemnities and for a customer breach of the use restrictions. Section 7.1 disclaims all warranties in capitals and states that the platform is not warranted accurate or complete. The invocable remedy is the service level agreement: 99.9 per cent monthly availability with a day of pro-rated fees credited for each hour of downtime, capped at one week of fees a month and claimable within 24 hours. No insurance is stated and no warranty of performance exists. MSA read in full 7 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations are named in a binding document, short of depth and short of the systems legal work actually lives in. The Data Processing Agreement names Merge API as an opt-in subprocessor applicable only to customers who elect to configure a Salesforce or Outlook connector, and Google LLC as providing email and document management capabilities through Google Workspace Enterprise alongside its model role, so the connectors are documented with what they carry and when they apply. The Matrix 2.0 announcement adds a financial data feed, Daloopa, as a connected source. What an implementer would need is not published: no description of direction, sync behaviour or configuration was located. The gap a legal buyer should notice is what is absent from the list rather than what is on it: no document management system, matter management, e-billing or practice management integration was located on any surface read, so a firm's documents reach the platform by upload or through a finance-oriented connector set. DPA, Matrix 2.0 post and product pages read 7 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Residency is published in unusual detail and the deployment tiers are not. Annex III of the Data Processing Agreement gives a processing location for every subprocessor: Amazon Web Services down to the named regions us-east-1, us-west-1, eu-west-1 and eu-central-1, and for each model provider and inference host either all US locations or EU regional processing, with document parsing and telemetry recorded as regional based on tenant. That answers where processing happens as distinct from where data is stored, provider by provider, which is more than most records on this axis publish. Transfers out of the EEA and the United Kingdom run on the 2021 Standard Contractual Clauses with the UK Addendum, completed in the DPA down to the module, the docking clause and Irish governing law. DPA 3.5 states that processing may occur in any country where Hebbia, its affiliates and its authorised subprocessors maintain facilities, subject to law. What is not published is a deployment choice: no single-tenant, private-cloud or on-premise option is described, no statement of tenancy separation was located beyond encryption and logical measures, and nothing states what a customer can select or what changes between tiers. DPA read in full 7 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real and stated in a binding annex, short of accessible evidence. Annex II of the Data Processing Agreement records that Hebbia has undergone a SOC 2 Type 2 audit covering the security trust service criteria and undergoes annual SOC 2 Type II audits, and the customer-facing pages display SOC 2 Type II and ISO/IEC 42001:2023 marks. The DPA also gives a real audit right: the customer or its appointed third-party auditors may audit compliance and Hebbia must make relevant information, policies, records and staff available, once in any twelve months and more often after a security incident. What is missing is the accessible half. No auditor is named, no audit period or report date appears, no scope statement is published, and the trust centre at trust.hebbia.ai is a Vanta-hosted portal that returns page metadata with no body on this channel, so whether any report is self-serve could not be established. That is recorded as a retrieval limit and the portal is the rebuttal route; the lower tier is graded and the reason stated. DPA read in full and trust centre attempted 7 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The supply chain is disclosed further than any other record in this lane, and stops short of naming the models. Annex III of the published Data Processing Agreement names OpenAI, Anthropic, Google and Microsoft as providing large language model capabilities through their APIs, states for each that the subject matter processed is user submitted prompts and files, and gives the processing location as all US locations or EU regional processing. It goes a layer deeper than most: Cerebras, Groq, Baseten, Fireworks AI and Modal Labs are each named as hosting a subset of Hebbia's own inference infrastructure, with Elasticsearch for search and indexing over prompts, files and generated artefacts, MongoDB for embedding and re-ranking, and Reducto for document parsing. Change notification is contractual, with any new subprocessor added to the list and notified ten days before it accesses personal data, and an objection right attached. What is absent is model naming: no specific model or version is identified on any first-party surface, and provider naming is not model naming. Third-party material fills that gap and is described rather than credited, since OpenAI's own case study names o3-mini, o1 and GPT-4o inside Matrix and Anthropic's names Claude as a model customers can select. DPA Annex III read in full 7 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
There is a page called Pricing and it contains no price. It publishes positioning, a product name and three industry links, and every button on it requests a demo; no figure, band, tier or unit appears. What lifts this off the floor is the agreement. Fees are set in an Order Form and payable in US dollars unless the Order says otherwise; the licence is per seat, since administrators may provision Authorized Users up to a maximum stated in the Order Form; orders renew automatically for one-year terms unless either party gives 30 days' notice; Hebbia may notify different renewal pricing at least 45 days in advance, which tells a buyer that renewal increases are unilateral and time-boxed; payment is due within 30 days, late amounts carry 1.5 per cent a month, and invoices must be disputed within 60 days. So the unit and the mechanics are readable before a sales call and the number is not. Third-party seat prices circulating on review sites are not evidence and are not recorded. No VendorPricing row is written, since a row belongs to vendors graded A or B on this axis. Pricing page and MSA read 7 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described with real substance and one significant limit is published, short of the full boundaries. The legal solution page names six areas of legal work the product is built for: banking and finance documentation, buy-side and sell-side due diligence, capital markets drafting from filings and precedent transactions, private equity fund formation and portfolio governance, matter intelligence built from a firm's past work, and firm-tailored workflows. The wider platform serves investing, banking and corporate finance, so a legal buyer can see that the product spans transactional and financial work rather than litigation or contentious practice, and no dispute, court or regulatory practice area is claimed. The limit worth reading before purchase is contractual rather than marketing: MSA 2.4 with definition 12.13 prohibits the customer from submitting Restricted Information without Hebbia's prior written approval, and Restricted Information covers sensitive personal identifiers, protected health information and personal data as defined in the GDPR, with DPA Annex I separately prohibiting special categories. A firm running European matters, employment work or anything touching health records needs that approval first. Firm segments are not broken down, government and in-house use are not addressed, and what is unsupported is otherwise left open. Legal page, MSA and DPA read 7 September 2026.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The published agreement expressly reserves a right to train on customer content, with no opt out located. Any de identification, anonymisation or aggregation qualifier is recorded in the summary.
The published agreement expressly permits training on customer content, in a bounded form, while the marketing says the opposite. Main Services Agreement clause 3.2 grants Hebbia a licence to use Customer Materials to provide and support the platform and then adds that Hebbia may use Customer Materials to improve machine learning models that are solely for use by that customer, and may not license or otherwise make models improved with Customer Materials available to any third party. No opt-out is located. Both halves belong in the record. The security page states that Hebbia is one of the only AI companies that never trains on customer data and the legal page carries a badge reading no training on user data, which is what a buyer sees first. The privacy policy is drafted more carefully than the badge and is consistent with the clause, saying that personal data in customer data is not used to train or improve generalized or third-party models. So the permission is real, it names machine learning models, and it operates on customer content, but it is confined to a model only that customer uses and expressly barred from reaching anyone else, which is narrower than the shapes that carry this value elsewhere in the index. MSA, security page, legal page and privacy policy read 7 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
The customer controls the retention window, by product configuration or by contractual instruction, but zero retention is not stated as available.
The customer controls deletion and no retention period is fixed, with zero retention not offered. Annex II of the Data Processing Agreement states that customers determine what data they route through the service, that they may request deletion at any time, that Hebbia deletes personal data on written request where self-service deletion is not available, and that all personal data is deleted following service termination; a subject-access form is published for erasure and portability, and the Main Services Agreement adds that Customer Materials are deleted within 30 days of termination. This record is more precise than most on what the retained material actually is: Annex III states for each model provider and inference host that the subject matter processed is user submitted prompts and files, so prompts and generated artefacts are squarely inside the regime rather than left to inference, and Elasticsearch is named as indexing prompts, files and generated artefacts. What is not published is an in-term retention period, any statement of how long prompts persist while a subscription runs, or a no-retention setting. DPA and MSA read in full 7 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses walls or matter level segregation.
No located public material addresses ethical walls or matter-level segregation. The agreement covers administrator provisioning of Authorized Users and account credentials, and the security measures annex covers encryption, authentication and logical protections between Hebbia's customers, but nothing read describes whether retrieval inside a customer's own workspace respects walls between matters, clients or teams, or whether an agent running across an uploaded corpus can reach material a particular lawyer should not see. That is a live question for a platform whose legal page names four large law firms and whose core function is analysis across an entire document set at once. The unread Matrix and Max product pages and the gated trust centre are the rebuttal routes. MSA, DPA and legal page checked 7 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Terms commit to notice where lawfully permitted. No transparency report located.
The agreement commits to prior notice where permitted, with assistance to contest. Main Services Agreement clause 6.3 permits either party to disclose the other's confidential information when required by law or regulation only on condition of giving prior notice of the compelled disclosure, to the extent permitted, and providing reasonable assistance at the disclosing party's cost to contest or limit it. Customer Materials are the customer's Confidential Information under 6.1, so the clause reaches uploaded documents rather than only account data. The Data Processing Agreement adds that Hebbia will promptly inform the customer, with full details, of any request or complaint from a data subject, regulator or third party unless prohibited by law. No transparency report, request statistics or law-enforcement guidelines page was located, which is what separates this from the top value. MSA and DPA read in full 7 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Sources are identified without stating the licence or rights basis.
The sources are identified and no licence basis is stated for the ones Hebbia supplies. The product analyses documents the customer uploads, and the agreement puts the rights basis on the customer, who warrants at 2.4 that it has the necessary rights, licences and permissions to provide the materials. Two connected sources sit outside that: Google Workspace Enterprise reaches email and documents through a connector, and the Matrix 2.0 announcement adds Daloopa, described as a financial data feed now available to Hebbia customers, with no statement of the licence, coverage or update cadence behind it. No corpus of law, filings or public authority is claimed anywhere, and the signal's law-corpus limbs do not bite for a platform whose corpus is the customer's own data room. Legal page, MSA, DPA and Matrix 2.0 announcement read 7 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
No located public material addresses whether authority is checked for subsequent history. The product analyses credit agreements, filings, offering memoranda, fund documents and a firm's own past matters, and cites back to the documents the customer supplied; nothing read describes a citator, a treatment signal or a verification prompt for reported authority, and the vendor does not claim to retrieve case law. The signal's limbs do not bite for a transactional document-analysis platform, and that is recorded rather than graded around. Legal page, security page and Matrix material checked 7 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
No located public material describes what the product does when it cannot ground an answer. The vendor's position is the opposite claim, that it is building large language models that never hallucinate and give correct, verifiable answers, which asserts the problem away rather than describing an abstention path. Nothing read sets out a no-answer state, a confidence or grounding score, or any published evaluation in which the system declines. The same page's claim sits against the agreement's disclaimer that the platform is not warranted accurate or complete, and that tension is recorded on the citation accuracy axis rather than counted twice here. Security page, MSA, legal page and Matrix 2.0 announcement checked 7 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
No court order, opinion or disciplinary record naming Hebbia or Matrix was located as of 7 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on both names alongside a general search of sanctions coverage; the decisions that name legal-specific products name other vendors. This is a statement about the public record, not a finding about the product. The exposure profile is worth stating: the platform analyses documents a customer supplies and cites back to them rather than generating legal authority, so the fabricated-citation risk runs through what a user does with an output rather than through invented case law.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No located public material engages with bar or ethics guidance, and none engages with lawyers' professional obligations even in general terms. The legal solution page speaks to winning and keeping clients, closing deals faster and becoming the trusted adviser, which is commercial rather than professional-responsibility framing. The security page's responsibility section commits to responsible use of the platform, and the acceptable use policy addresses illegal, deceptive or infringing use; both are about misuse of software rather than about a lawyer's duties. Nothing names an ABA formal opinion, a state bar opinion, a regulator's AI guidance or a court standing order. The lower value was tested before being taken: a generic reference would require some engagement with professional responsibility, and none was located. Legal page, security page, acceptable use policy and MSA checked 7 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure, and the product sits inside a fee relationship between a lawyer and a client where those savings would change the bill.
The product sits inside law firms' fee relationships with their clients and the published position is a savings claim. The legal page is built on three promises to a firm: close deals faster by speeding up due diligence and contract review, grow the book by freeing the team from repetitive document work, and go deeper on every deal. Third-party material puts numbers on the same claim, with OpenAI's case study reporting that law firms cut credit agreement review time by 75 per cent and save $2,000 an hour in legal fees, which is a statement about billable work compressing. Nothing located addresses what happens to the client's bill when it does: no guidance on recording AI-assisted work on a matter, no disclosure treatment, and no per-matter record of what the agents did. Legal page, MSA and third-party material checked 7 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A subprocessor and model provider list plus client facing disclosure material is published or available without an agreement in place.
A firm can answer a client's AI clause from published material without asking for anything. Annex III of the Data Processing Agreement is a complete subprocessor register: OpenAI, Anthropic, Google and Microsoft are each named as providing large language model capabilities through their APIs, with the subject matter recorded as user submitted prompts and files and the processing location given as all US locations or EU regional processing; Cerebras, Groq, Baseten, Fireworks AI and Modal Labs are named as hosting parts of the inference infrastructure; Amazon Web Services, Auth0, Elasticsearch, MongoDB, Reducto, Merge API and Datadog complete the list with their roles and locations. The forwardable material is the same document: the DPA is published in full with the EU Standard Contractual Clauses and UK Addendum completed in its schedule, the security measures set out in Annex II, and a commitment to list and notify any new subprocessor ten days before it accesses personal data with an objection right. That satisfies the subprocessor list, the statement of which model providers see client content, and the client-facing artefact together. One condition a firm should carry into the conversation: the agreement prohibits submitting personal data as defined in the GDPR without prior written approval. DPA read in full 7 September 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
One element of a record exists and no export is built for disclosure. Outputs are described as verifiable, with sourcing shown for each answer in the grid so a user can trace a cell back to the document it came from, which is source attribution and is genuinely one of the three things a disclosure needs. The other two are absent from everything read: no per-document export covering which model produced an output, and no record of human verification. Nothing addresses court disclosure obligations, standing orders on AI use, or a certification a filer could attach, and no template or guidance is published. The security annex's logging is monitoring of access to systems rather than a user-facing record of what an agent did. Security page, MSA, DPA and legal page checked 7 September 2026.