I
Intapp

Intapp is a Palo Alto company, listed on NASDAQ as INTA and contracting as Integration Appliance, Inc., selling cloud software to law firms, corporate legal departments, accounting and consulting firms, investment banks and private capital managers. Its legal estate spans the client lifecycle: new business intake with configurable risk questionnaires and embedded third-party data, conflicts management, anti-money-laundering and know-your-client checks, lateral hire onboarding, ethical walls enforcement through Intapp Walls, outside counsel guideline compliance through Intapp Terms, timekeeping through Intapp Time, prebilling and billing through Intapp Billstream, matter-centric Microsoft 365 workspaces, and relationship and client intelligence through DealCloud. Generative AI reaches the buyer two ways. Intapp Assist is embedded in Time, Terms and DealCloud and answers conversational questions against firm-specific data, its Ask Intapp feature running inside Microsoft Teams and returning answers about client contractual obligations with direct links to the underlying source records. Intapp Celeste is the firm-wide AI layer, and its published subprocessor entry states that customers can choose between Anthropic models served through Amazon Bedrock and Azure OpenAI models. The company publishes an unusually complete compliance estate: a dated AI transparency statement covering how its AI products work, what data is and is not used to train them, EU AI Act transparency obligations and the limitations of AI output; a per-product, per-activity and per-location subprocessor list with a subscription feed and prior versions; a data processing addendum; a DORA customer guide; and ISO 27001, 27017, 27018 and 27701 certifications, SOC 1 and SOC 2 reports, CSA STAR registration and a privacy processor certification, each audited by Schellman with certificates linked directly from the compliance page. Cloud hosting is on Microsoft Azure across seven named regions, with DealCloud offered in separate United States, European, United Arab Emirates and Asia-Pacific instances.

Vendor sitePalo Alto, California, United States
Last verifiedSeptember 7, 2026
Compare with other vendors

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Models do real work on top of a platform that ran for two decades without them, and the vendor's own architecture pages say so. The model half is genuine and named twice over. Intapp Assist is embedded in Intapp Time, Intapp Terms and DealCloud, providing natural language answers to conversational queries by analysing firm-specific data, generating insights and automating data entry and relationship tracking; its Ask Intapp feature runs inside Microsoft Teams and answers questions about client contractual obligations with direct links to source records. Intapp Celeste is a firm-wide AI layer with its own use-case library and architecture documentation, and its published subprocessor entry shows customers choosing between Anthropic models on Amazon Bedrock and Azure OpenAI models. The other half is not models and is the larger half: intake, conflicts, anti-money-laundering, ethical walls, timekeeping, prebilling, billing, matter-centric workspaces and relationship management are systems of record that a firm would still buy with the generative features removed, and the vendor describes its AI as built on an Intapp Data Foundation that exists to serve them. The transparency statement is candid about the mixture, describing products that operate by applying rule-based logic, statistical models and machine learning algorithms. Trust page, AI transparency statement, subprocessor list and product navigation read 7 September 2026.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Grounding is real and documented, limitations are published with unusual candour, and nothing is measured. On grounding, the Ask Intapp feature is described as researching an answer exclusively by reference to the firm's own Intapp Terms data and returning it with direct links to the underlying source information, so the answer is bounded to a known corpus and traceable back to it. That is documented grounding with linked sources. On limitations the vendor goes further than most records in this corpus, publishing five explicit statements in its AI transparency statement: outputs may be inaccurate, incomplete or context dependent; performance depends on the quality and context of input data; no specific accuracy level is guaranteed unless explicitly stated; outputs are not a substitute for professional judgment or expertise; and outputs are not guaranteed to be error-free, uninterrupted, consistent, up-to-date, accurate, complete or free from bias. A separate AI Disclaimer is published in the product terms. What is absent is measurement of any kind. No accuracy figure, error rate, test set, benchmark or evaluation result is published for Assist, for Celeste or for any other AI feature, and no verification mechanism beyond the source link is described. A reader can establish what the vendor promises not to promise, and cannot establish how often the products are right. AI transparency statement, Assist and Terms product pages read 7 September 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

The autonomy boundary is stated and the oversight position is stated more bluntly than anywhere else in this corpus. What is published: the products are not intended to perform fully autonomous decision-making; users remain responsible for final decisions and for verifying outputs; the user or customer is ultimately responsible for the action taken or decision made; and users must not use the products for automated decision-making at all, which is listed among the prohibited uses alongside any use that would reclassify the system under the EU AI Act. Transparency at the point of use is addressed: users are informed when they are interacting with an AI system in accordance with EU AI Act transparency obligations, and are made aware that outputs are generated by artificial intelligence. The blunt part, and the reason this row is worth reading closely, is the vendor's statement that its products are operated by users without intervention by Intapp other than standard support, that Intapp therefore does not deploy human oversight in relation to a user's use of the products, and that implementing human oversight over outputs is the customer's and the user's responsibility. That is a clear allocation rather than a claim, and it tells a buyer exactly where the obligation sits. What is missing is the product half: no in-product review step, approval gate, confidence signal or escalation path is described, and no autonomy setting is configurable. AI transparency statement read in full 7 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Institutional evidence of an unusual kind, and no measured AI outcome. The strongest element is structural rather than promotional: the vendor is a public company listed on NASDAQ as INTA, with an investor relations site and the periodic financial reporting that listing requires, which is a form of verifiable operating evidence almost no record in this corpus carries. Around it sit a named legal customer with a published case study, Fredrikson and Byron, described as choosing Intapp Terms to digitise and centralise management of its clients' outside counsel guidelines; a partner ecosystem the vendor states exceeds 100 organisations across data, technology, channel and services; a client community, a training university and a public system status site, all of which evidence an installed base that needs supporting. Dated product milestones are published, including the general availability announcement for Intapp Assist for Terms in August 2024. What is absent is outcome measurement for the AI. No deployment is quantified, no time or cost saving is measured, no adoption figure for Assist or Celeste is published, and the one percentage located, a claim that adopting Activator behaviours can increase partner revenue by up to 32 per cent, is attributed to research rather than to a customer result and concerns a behavioural programme rather than an AI feature. Recorded so the grade is read correctly: a clients page and a client stories library both exist in the navigation and neither was opened on this channel; they are the rebuttal route on this row. Trust page, product pages, investor announcement and site navigation read 7 September 2026.

Source: Vendor Published
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Controls are stated at a high level and the question this vendor is uniquely placed to answer is not answered. What is published about the AI specifically is one paragraph: safeguards described as appropriate to a low-risk AI system, including encryption in transit and at rest, access controls and role-based permissions, data minimisation and retention limits, audit logging and monitoring, and secure development and testing practices. Around it the platform publishes a Tenant Access Policy, a client data stewardship page and matter-centric Microsoft 365 workspaces, none of which was opened on this channel and all of which are the rebuttal route on this row. What is absent is express privilege and work product treatment, which appears nowhere on any surface read, so the limb this axis exists for is untested and the top grade is unavailable. The sharper gap is specific to this vendor and worth naming plainly. Intapp sells Intapp Walls, a product whose stated purpose is to secure, control and enforce access to sensitive client information and to limit access to sensitive matters across applications, in fulfilment of a firm's ethical duty. Nothing published states whether Intapp Assist or Intapp Celeste, reading firm-specific data to answer questions, honour the walls that product enforces. A vendor that sells ethical walls and generative retrieval over the same estate is the one that could answer that question most directly, and on the surfaces read it does not. AI transparency statement, Walls and ethical walls pages, trust page and site navigation checked 7 September 2026.

Source: Vendor Published
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Several limbs do not bite and are named rather than penalised, and what remains is generic. The products do not advise on law: they run new business intake, conflicts searching, anti-money-laundering checks, ethical walls, outside counsel guideline compliance, timekeeping, prebilling and relationship management, and the AI features answer questions about a firm's own contractual obligations and internal data rather than producing legal conclusions citing authority. So the unauthorised practice risk this axis was written for is structurally remote, the buyer is a firm's professional staff rather than the public, and no citator, no legal research output and no client-facing advice surface exists to fence. On what does bite the engagement is thin. The AI transparency statement records that outputs are not a substitute for professional judgment or expertise and that users must verify all outputs before relying on them, which is a general competence statement rather than an engagement with professional responsibility. One phrase comes closer and is recorded because it is the vendor's own framing: the ethical walls solution page describes the product as fulfilling a firm's ethical duty to its clients and profession, which acknowledges the duty while selling against it. No rule of professional conduct, bar guidance, ethics opinion or court practice direction is named anywhere. AI transparency statement, legal solution pages and site navigation read 7 September 2026.

Source: Vendor Published
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

The broadest published AI governance disclosure located in this pull, short of attestation and of a named owner. What exists is a dedicated, dated and versioned AI transparency statement, effective 2 August 2026, applying across all of the vendor's AI products, which is itself rare. Its content is substantive. It describes how the products work, by processing input data and applying rule-based logic, statistical models and machine learning algorithms. It engages the EU AI Act on three fronts: a self-assessed risk classification, describing safeguards appropriate to a low-risk AI system; transparency obligations, committing that users are informed when they are interacting with an AI system and that outputs are identified as AI-generated; and a prohibition on any use that would reclassify the system under the Act. It states prohibited uses including unlawful, discriminatory and harmful purposes and automated decision-making. It publishes a complaints route that expressly includes a user's local data protection authority or regulator. It commits to communicating material changes to the statement. And it acknowledges bias directly, stating that outputs are not guaranteed to be free from bias, which most records at this grade do not concede at all. Three things keep it below the top grade. Nobody is named as accountable for model behaviour. No pre-release evaluation, benchmark, red-team exercise or result is published, and the bias acknowledgement is a disclaimer rather than a measurement. And the statement says in terms that it is not a legally binding document and does not form a contract, so the governance is published as posture rather than obligation. AI transparency statement read in full 7 September 2026.

Source: Vendor Published
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Published policy across every limb this axis asks about, with the attestations independently audited and reachable. Certifications are named with the standards enumerated rather than gestured at: ISO 27001, ISO 27017, ISO 27018 and ISO 27701, SOC 1 and SOC 2, CSA STAR registration, and a Global Privacy Recognition for Processors certification. The auditor is named, Schellman, and the certificates are linked directly from the compliance page rather than sitting behind a request, with the CSA STAR entry pointing at the Cloud Security Alliance's own registry. A Shared Assessments SIG 2024 Lite questionnaire is published as a downloadable resource, which is the artefact a firm's procurement function actually sends. GovRAMP status is stated honestly as membership while a verified offering is pursued, rather than implied as achieved. On the data side the subprocessor disclosure is the most granular in this corpus, listing every subprocessor per product, per processing activity and per location, with routing rules stated where they differ, a subscription feed for changes and prior versions retained. Training is addressed: unless agreed otherwise with a customer, customer data uploaded into the AI products is not used to train them. Security measures are enumerated as encryption in transit and at rest, access controls and role-based permissions, data minimisation and retention limits, audit logging and monitoring, and secure development and testing. Cloud policies are published individually, covering maintenance, tenant access, sandbox and deprecated features, alongside a public status site. Two gaps are named: no incident or breach notification commitment was located on the surfaces read, and retention is described as subject to limits without any period being stated. Compliance page, subprocessor list, AI transparency statement and trust page read 7 September 2026.

Source: Vendor Published
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Nothing establishable on this date states who bears the loss when an AI output is wrong, and the reasons divide into three which a reader should be able to tell apart. First, the customer agreement is not published. The AI transparency statement refers throughout to a Governing Agreement between the vendor and the customer entity, including any applicable orders, and no such document appears anywhere in the site's published inventory, which was read in full from the navigation and footer. So no indemnity, liability cap, warranty, service level, exclusive remedy or insurance position for the products can be read before entering a commercial conversation. Second, the one document on the site that does carry warranty and liability language is scoped to the website rather than to the products: the legal policy disclaims all representations and warranties as to the operation of this site and the information, content, materials or products included on this site, and excludes all damages of any kind arising from use of this site, which tells a buyer about the marketing estate and not about the software. Third, a document titled AI Disclaimer is published in the vendor's product terms and could not be retrieved on this channel; both the direct URL and a targeted search on distinctive clause language failed to return its body, so it is recorded as a limit of this reading rather than as an absence, and it is the primary rebuttal route on this row along with the published data processing addendum, which was not opened. What can be established points one way without settling it. The AI transparency statement says of itself that it is not a legally binding document and does not form a contract, so the most substantive AI-specific document the vendor publishes is expressly outside the bargain. Within it, the vendor states that no specific accuracy level is guaranteed unless explicitly stated, that outputs are not guaranteed to be error-free, accurate, complete or free from bias, and that the customer and user are ultimately responsible for the action taken or decision made. Site inventory, legal policy, AI transparency statement read and AI Disclaimer attempted 7 September 2026.

Source: Operator Verified
AA on Practice Systems Integration DepthDocumented, verifiable integrations into the systems legal work already lives in, with the depth described: what syncs, in which direction, and what a firm must configure.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Integration is the product rather than an adjunct to it, and the named surfaces run deeper into the practice stack than any record in this lane. Microsoft is the spine and is named repeatedly and specifically: Ask Intapp is delivered as a Microsoft Teams application rather than only in a web console, so the AI answers arrive where the firm already works; Intapp Workspaces delivers matter-centric workspaces and content management inside Microsoft 365; a dedicated Microsoft Copilot offering applies the firm's business structure and security requirements to firm, client and engagement data in Microsoft 365 and beyond; and Microsoft Azure is the hosting layer. A dedicated integration product exists in its own right, the Intapp Integration Service, and its published subprocessor entry names Boomi as the cloud integration platform beneath it with customer data processed in the region of the customer's choice, which is an unusually concrete statement of how integration actually runs. Third-party data providers are named as subprocessors rather than described generically, including Dun and Bradstreet, S&P Global Market Intelligence, Grata and ESRI for content and mapping, and Plaid and Gresham for financial institution data feeds. A partner ecosystem is published with more than 100 organisations across data, technology and integration, channel and services partners, each with its own directory. What is not established is the depth of any single connector, because no API or developer documentation was located and the integrations page was not opened. Subprocessor list, product navigation, Copilot and collaboration pages read 7 September 2026.

Source: Vendor Published
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Residency is published in more detail than anywhere else in this corpus and tenancy is not stated. On residency the disclosure is granular to a degree that is genuinely unusual. Hosting regions are named per product across the United States, Ireland, the Netherlands, the United Arab Emirates, Singapore, Australia and Canada, with location stated to depend on the customer's hosting location. Routing rules are published where they differ from the headline, recording that United Arab Emirates traffic for one email service is routed via the European Union and Singapore via Australia. AI processing location is stated separately and specifically: artificial intelligence features are processed in the United States or the European Union depending on the customer's hosting location, and customers located outside both are processed in the European Union. Where a subprocessor's data location is fixed regardless of the customer's region, the list says so explicitly. DealCloud is offered as four separate regional instances with distinct login endpoints for the United States, Europe, the United Arab Emirates and Asia-Pacific. The integration layer states that customer data is processed in the geographic region of the customer's choice. What is absent is the other co-equal limb. No tenancy model is described on the surfaces read: nothing states whether customers are single or multi-tenant, whether isolation is logical or physical, or what changes between tiers. A Tenant Access Policy is published and was not opened, and it is the named rebuttal route on this row. Subprocessor list, compliance page and product navigation read 7 September 2026.

Source: Vendor Published
AA on Security Certifications and Trust CenterCurrent independent attestation with named scope, reachable without a sales call: a trust center carrying reports, dates and the standards actually covered.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Certifications named, auditor named, and the certificates themselves reachable without a request, which is the combination this axis exists to reward and which almost no record in this corpus achieves. The published set is ISO 27001, ISO 27017, ISO 27018 and ISO 27701, each described by what it covers rather than listed as a badge; SOC 1 and SOC 2; CSA STAR registration; and a Global Privacy Recognition for Processors certification. The auditor is identified as Schellman, and the ISO and privacy processor certificates link directly to Schellman's own certificate service while the CSA STAR entry links to the Cloud Security Alliance registry entry for Integration Appliance, Inc., so a reader can verify the claims at source rather than take them on trust. No non-disclosure agreement, email address or sales conversation stands in the way of any of it. A Shared Assessments SIG 2024 Lite questionnaire is published as a resource, a DORA customer guide addresses the EU financial-sector regime, and a public cloud status site operates alongside individually published cloud policies. The vendor also states its GovRAMP position honestly as membership while actively pursuing verified offering status, which is a claim about where it is rather than where it would like to be read as being. What is absent, and it is the only thing: no audit period or scope statement is published on the compliance page itself, so a reader must open the linked certificates to establish what and when was covered, and no SOC report is downloadable from the page. Compliance page read in full and certificate links inspected 7 September 2026.

Source: Vendor Published
AA on Model Supply Chain DisclosureThe models underneath are named, their providers identified, where they run is stated, and the vendor commits to notifying customers when any of that changes.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Models named, providers identified, change notification operating, and the customer given a choice between models, which is the fullest disclosure on this axis located in the corpus. The subprocessor list is organised per product, and the AI entries are specific. For Intapp Celeste it names Amazon AWS Bedrock as a generative AI services provider which hosts Anthropic models, across six named regions, and states in terms that the customer can select Anthropic or Azure OpenAI models; it names Microsoft Azure AI Services for text generation and extraction; and it names Exa Labs for web grounding services. For Intapp Assist it names Microsoft Azure AI Services for text generation and summarisation. Anthropic PBC is separately named as a generative AI services provider for other products in the family. So a reader can establish which model families process their content, which provider serves them, in which region, for which product, and that the choice between two model families is theirs. Change notification is not a promise but a mechanism: the page carries an effective date, a subscription form for update notifications, and retained prior versions, with updates stated to be posted in accordance with the terms of the agreement. What is not published is the specific model version within each family, so a reader knows Anthropic or Azure OpenAI without knowing which release, and nothing states what happens to an in-flight matter when a model is deprecated. Subprocessor list of 11 August 2026 read in full 7 September 2026.

Source: Vendor Published
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

No pricing information is published at any level, including the unit of charge, and the site's own navigation establishes that no pricing page exists rather than that one could not be found. The published inventory was read in full: a products menu spanning fourteen named products, an industries menu spanning seven sectors, a why-Intapp menu covering company, data foundation, cloud infrastructure, partners, client resources, services and trust, and a footer repeating all of it alongside cloud, partner, learning, client and company sections. There is no pricing entry anywhere in either the header or the footer, and no pricing link on the trust, compliance or product pages read. Every conversion path on every page ends at the same two calls to action, scheduling a demo or contacting the company. No tier or edition is named, no unit is identified whether by seat, user, matter, timekeeper or module, no band or range appears, and no minimum or term is stated. Nothing indicates whether the fourteen products are priced separately or bundled. The company is listed on NASDAQ and publishes revenue in its financial reporting, so aggregate figures exist in the public domain, but nothing there tells an individual buyer what the product costs them, which is what this axis asks. Where the only route is an invitation to contact sales, no pricing row is owed and none is written. Full site navigation, footer, trust, compliance and product pages checked 7 September 2026.

Source: Operator Verified
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Buyer and workflow coverage is described with more granularity than any record in this lane, and no boundary is stated. Seven industries have their own solution sets: legal, accounting, consulting, corporate, investment banking and advisory, private capital and real assets. Within legal alone, twelve distinct solutions are published individually, being client intelligence, the Activator programme, Microsoft Copilot enablement, Microsoft 365 collaboration, compliant timekeeping, compliant prebilling, compliant time and billing, new business intake, conflicts management, outside counsel guideline compliance, anti-money-laundering and know-your-client, ethical walls, lateral hire onboarding and partner attestation management. The corporate segment is addressed separately with matter management and relationship management for in-house legal departments, so both sides of the legal market are served by named surfaces. Private capital is broken down further into ten named markets. Geographic reach is evidenced rather than asserted, with offices contactable in the United States, United Kingdom and Asia-Pacific and seven named hosting regions. What is absent is any limit. No firm size, practice area, matter type or jurisdiction is named as in or out of scope; nothing states a minimum deployment; and no coverage statement distinguishes which of the fourteen products carry AI features from those that do not, which matters on a record where the AI reaches only some of the estate. Full product and industry navigation, legal solution pages and contact details read 7 September 2026.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Never, in policy only

A public policy or trust page states no training on customer content, with no matching term located in the published agreement.

A clear public commitment that the vendor expressly declines to make binding. The AI transparency statement of 2 August 2026 states that, unless agreed otherwise with a customer, customer data uploaded into the AI products is not used to train them. That is the commitment, and two features of it are recorded rather than smoothed. First, the document says of itself that it is not a legally binding document and does not form a contract between the vendor and users, so the statement is posture and not obligation; the Governing Agreement it refers to is not published, so no contractual term either way could be located, and the published data processing addendum was not opened on this channel. Second, the same paragraph draws a line most records leave implicit: the vendor does use data collected regarding the administration, configuration, support, use or performance of its products, including the AI products, to operate and improve them. So telemetry and usage data feed improvement while uploaded customer content is carved out of training, and a buyer should read the two halves together. The phrase unless agreed otherwise also leaves the position negotiable per customer rather than fixed. The value's own words require that no matching term be located in a published agreement, and none was, which is what places this here rather than at the contractual grade. AI transparency statement read in full, site legal inventory checked, 7 September 2026.

Source: Vendor PublishedUnless agreed otherwise with a customer, Intapp does not use customer data uploaded into Intapp AI Products to train the Intapp AI Products.As of Sep 7, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Disclosed without a period

Retention is acknowledged in public materials with no stated period.

Retention is addressed and no period is attached to it. The AI transparency statement lists data minimisation and retention limits among the safeguards applied to the AI products, alongside encryption, access controls, audit logging and secure development. That is an acknowledgement that limits exist and that minimisation is a design principle, which is more than silence. What it does not supply is anything a buyer could hold: no retention period for prompts, uploaded content or generated outputs; no distinction between the AI products and the underlying platform; no statement of what happens at the end of a subscription; and no customer-facing control, setting or deletion mechanism. Nothing states whether a firm can shorten the window, reach zero, or export before deletion. Two published documents would bear on this directly and neither was opened on this channel, the data processing addendum and the privacy policy, and they are the named rebuttal route on this row. The distinction matters on a platform of this shape because the material at issue is a firm's timekeeping, intake, conflicts and client-obligation records rather than a chat history. AI transparency statement read in full and site legal inventory checked 7 September 2026.

Source: Vendor Publisheddata minimization and retention limitsAs of Sep 7, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Claimed, not documented

Segregation is asserted in public materials with no published detail on how it is enforced.

Segregation is asserted in general terms and no published detail explains how it is enforced against the AI, which is a conspicuous gap for this vendor in particular. What is asserted: the AI transparency statement lists access controls and role-based permissions among the safeguards applied to the AI products, and the platform publishes matter-centric Microsoft 365 workspaces and a Tenant Access Policy. What makes the gap notable is that this vendor sells the control itself. Intapp Walls is a product whose published purpose is to centrally secure, control and enforce access to sensitive client information and to limit access to sensitive matters across applications, in fulfilment of a firm's ethical duty to its clients and profession, and it is sold to law firms, consulting firms and investment banks for exactly the screening problem this signal tests. Nothing published states whether Intapp Assist or Intapp Celeste, which read firm-specific data to answer conversational questions, enforce those walls at query time; whether a user screened from a matter in Walls is screened from it in Assist; or whether the AI layer inherits the wall model or maintains a separate one. A vendor operating both the wall and the retrieval over one estate is uniquely placed to answer, and on the surfaces read it does not. The Tenant Access Policy and client data stewardship page were not opened and are the rebuttal route. AI transparency statement, Walls and ethical walls pages and site navigation checked 7 September 2026.

Source: Vendor Publishedaccess controls and role-based permissionsAs of Sep 7, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Not addressed

No located term or policy addresses third party requests for customer data.

No located public material on the surfaces read addresses what happens when a third party demands customer data. The AI transparency statement, the trust page, the cloud compliance page and the subprocessor list were each read in full and none contains a compelled-disclosure position, a notice commitment, a reservation of discretion over notice, or an undertaking to seek protective relief. No transparency report, law enforcement guidelines page or government request policy appears anywhere in the site's published inventory, which was itself read from the navigation and footer. This is recorded as what could be established on the date rather than as a finding about the vendor's practice, and the reason matters: the two documents that would ordinarily carry the position, the privacy policy and the data processing addendum, are both published and neither was opened on this channel. Both are named as the rebuttal route on this row, and a later pass that reads them may correct it in either direction. The customer agreement itself, referred to in the transparency statement as the Governing Agreement, is not published at all. Trust page, compliance page, AI transparency statement, subprocessor list and full site navigation checked 7 September 2026.

Source: Operator VerifiedAs of Sep 7, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Sources named, basis unstated

Sources are identified without stating the licence or rights basis.

The corpus is identified precisely and most of this signal's limbs do not bite on a product of this shape. The source of the AI answers is the firm's own records, and the vendor is specific about it: Ask Intapp researches an answer exclusively by reference to the firm's Intapp Terms data, and Intapp Assist is described as analysing firm-specific data. So there is no vendor-assembled corpus of law behind the outputs, no case law or legislation is licensed in, and the two risks this signal exists to price sit differently. Coverage is a question about what the firm loaded rather than what the vendor collected. Title is not a question about legal publishing at all, since no editorial content is republished and no corpus could be enjoined. Where third-party content does enter the platform it is named rather than left generic, the subprocessor list identifying Dun and Bradstreet, S&P Global Market Intelligence and Grata as content providers and ESRI and Mapbox for mapping, each with its processing location, which is more provenance than most records offer. What is not stated for any of them is the licence or rights basis on which their content is redistributed to a firm, and nothing addresses the rights position over the firm's own data beyond the non-training statement. The inapplicable limbs are named rather than penalised. Terms AI page, subprocessor list and AI transparency statement read 7 September 2026.

Source: Vendor PublishedAsk Intapp will research the answer, exclusively referencing your firm's Intapp Terms data.As of Sep 7, 2026Evidence

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

No located public material addresses whether authority is checked for subsequent history, and the limbs do not bite for this product class. Nothing the platform produces cites legal authority. The AI features answer questions about a firm's own client contractual obligations, timekeeping records, conflicts data and relationship information, and the outputs cite the firm's own records rather than reported decisions, statutes or secondary sources. There is therefore no authority whose treatment a user would need to check, no citator could be licensed for a corpus of that kind, and no treatment signal could meaningfully be computed. The nearest analogue is currency within the firm's own record, whether an outside counsel guideline held in Intapp Terms is the version presently in force, and nothing published addresses that either, although the product's stated purpose of maintaining a single source of truth for client obligations implies the firm manages it. Recording this as a non-applicable limb rather than a failure is the honest treatment: a compliance and billing platform has no citator and should be neither credited nor penalised for that. Terms AI page, Assist page, AI transparency statement and product navigation checked 7 September 2026.

Source: Operator VerifiedAs of Sep 7, 2026Evidence

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

No located public material describes what the system does when it cannot reach a supported answer, and the omission sits directly beside a document that catalogues the problem. The AI transparency statement enumerates the ways outputs fail, stating that they may be inaccurate, incomplete or context dependent, that performance depends on the quality and context of input data, that no specific accuracy level is guaranteed unless explicitly stated, and that outputs are not guaranteed to be error-free, consistent, up-to-date, complete or free from bias. Every one of those describes the risk to the reader; none states what the product does about it. Nothing published says that Assist or Celeste decline a question they cannot ground in the firm's data, report that no responsive record was found rather than composing a plausible answer, expose a confidence or coverage signal, or flag where the underlying records are incomplete. The statement's response to uncertainty is to allocate it: users must verify all outputs before relying on them and should report any unexpected or incorrect behaviour to support. Those are instructions to the customer rather than a description of system behaviour, and they are credited on the Autonomy row rather than counted again here. AI transparency statement, Assist and Terms AI pages checked 7 September 2026.

Source: Operator VerifiedAs of Sep 7, 2026Evidence

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

No court order, opinion or disciplinary record naming Intapp or Integration Appliance, Inc. was located as of 7 September 2026. Searches were run on the company and product names against the AI Hallucination Cases database maintained by Damien Charlotin and against the secondary sanction trackers that summarise it. The absence carries more weight here than a bare negative usually would, because that database does name legal-grade products as well as general-purpose assistants, published analyses of it identifying tools including CoCounsel, Lexis+AI and vLex among those whose outputs courts have found fabricated. So the database is capable of naming a vendor of this kind and does not name this one. This remains a statement about the public record and not a finding about the product. Exposure is also structurally different from a research tool's: the AI features answer questions about a firm's own contractual obligations, time records and conflicts data rather than producing citations to authority for filing, so the classic fabricated-citation failure mode is not the one available here, and the vendor's own transparency statement instead warns that outputs may be inaccurate or incomplete.

Source: Operator VerifiedAs of Sep 7, 2026Evidence
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Generic reference

Public materials refer to professional responsibility in general terms without naming guidance.

Professional judgment is referenced in general terms and no bar or regulatory guidance on AI is named. What exists: the AI transparency statement records that outputs are not a substitute for professional judgment or expertise, that users must verify all outputs before relying on them, and that the customer and user are ultimately responsible for the action taken or decision made. The ethical walls solution page frames its product as fulfilling a firm's ethical duty to its clients and profession, which acknowledges the professional obligation while selling against it. Those are the general-terms engagement this value describes. What is absent is any named instrument. No rule of professional conduct, no bar association guidance on generative AI, no ethics opinion and no court practice direction is cited, mapped or linked anywhere on the surfaces read. The gap is worth naming precisely because the vendor demonstrates elsewhere that it is capable of engaging a named regulatory regime in detail: the same transparency statement addresses EU AI Act transparency obligations, states a risk classification under that Act, and prohibits uses that would reclassify the system under it, and a separate DORA customer guide addresses the EU financial-sector regime. Regulatory engagement is therefore real on this record and points at data and AI regulation rather than at the professional conduct rules governing the lawyers who use the products. AI transparency statement, trust page and legal solution pages read 7 September 2026.

Source: Vendor PublishedThe output generated by Intapp AI Products are not a substitute for professional judgment or expertise.As of Sep 7, 2026Evidence

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure, and the product sits inside a fee relationship between a lawyer and a client where those savings would change the bill.

Time savings are claimed inside a product family that exists to govern the bill, and the connection between the two is never made. The savings claim is explicit and is aimed at billable roles: the launch announcement for Intapp Assist for Terms states that Ask Intapp significantly reduces the time lawyers, billing analysts and other professionals spend researching, responding to or awaiting answers to questions about client obligations. What makes this record unusual is what sits around that claim. Intapp Time captures time and checks that drafted entries meet firm and client requirements before submission; Intapp Billstream runs prebilling and billing to the same requirements; Intapp Terms is the single source of truth for client contractual obligations including outside counsel guidelines, which is where billing guidelines live. This vendor operates the compliance layer between the timekeeper and the client invoice, and Intapp Assist is embedded in both Time and Terms. It is therefore better placed than almost any vendor in this corpus to address what happens to the bill when AI compresses the work, and nothing published does so. No guidance on fee or disclosure treatment of AI-assisted time was located, no per-matter record of AI-assisted work is offered as a basis for a narrative, and nothing addresses whether a compressed research task should be billed differently or disclosed. The edge is recorded because it is instructive rather than because the product is defective. Launch announcement, Assist, Time, Billstream and Terms pages checked 7 September 2026.

Source: Vendor Publishedsignificantly reduces the time lawyers, billing analysts, and other professionals spend researching, responding to, or awaiting answers to questions about client obligationsAs of Sep 7, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Disclosure pack published

A subprocessor and model provider list plus client facing disclosure material is published or available without an agreement in place.

A firm can answer a client's AI clause from published material without asking the vendor for anything, which is what this value requires and what almost no record achieves. The subprocessor list is current, dated 11 August 2026, published without a gate, and organised per product, per processing activity and per location, with retained prior versions and a subscription form for change notifications. The AI entries name the providers and the models: Amazon AWS Bedrock hosting Anthropic models for Intapp Celeste, with the customer able to select Anthropic or Azure OpenAI models; Microsoft Azure AI Services for text generation and summarisation in Intapp Assist; Exa Labs for web grounding; Anthropic PBC named directly for other products. So a firm can tell its client whose model processes its content, in which region, for which product, and that the choice is the firm's. The third limb is satisfied by forwardable material rather than by a promise of it: a data processing addendum is published, an AI transparency statement is published and dated, a Shared Assessments SIG 2024 Lite questionnaire is published as a downloadable resource, and a DORA customer guide addresses the EU financial-sector regime. Certifications are verifiable at source, with ISO, SOC and privacy processor certificates linked directly to the auditor and a CSA STAR registry entry. Recorded as a limit: the data processing addendum and the SIG questionnaire were not opened on this channel, so their existence and publication are established and their contents are not. Subprocessor list, compliance page and trust page read 7 September 2026.

Source: Vendor PublishedGenerative AI services provider which hosts Anthropic models ... Customer can select Anthropic or Azure OpenAI models.As of Sep 7, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Not addressed

No located public material addresses court disclosure or verification certification.

No located public material offers a record of AI-assisted work that a lawyer could produce to a court or a client. What exists is a security control rather than a disclosure artefact: the AI transparency statement lists audit logging and monitoring among the safeguards applied to the AI products, which records access and system activity rather than what the model did, and it is credited on the stewardship axis rather than counted again here. The transparency statement does establish two things adjacent to this signal and neither supplies a record. Users are informed when they are interacting with an AI system and are made aware that outputs are generated by artificial intelligence, in accordance with EU AI Act transparency obligations, so the fact of AI involvement is disclosed at the point of use. And the customer is told to verify outputs and is made responsible for decisions taken. Nothing states that the platform records which model produced a given output, what it retrieved, or what a person verified before the result was used, and no export, certification or template framed for a court, a regulator or a client is offered. The source links returned by Ask Intapp evidence what an answer rests on rather than what the system did to produce it, and they are credited on the Citation Accuracy axis. AI transparency statement, Assist and Terms AI pages and trust page checked 7 September 2026.

Source: Operator Verifiedaudit logging and monitoringAs of Sep 7, 2026Evidence
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 7, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746