LEGALFLY
European legal AI platform for enterprise in house teams, positioned as a legal operating system reaching beyond legal into claims, compliance, HR, procurement and sales. Six products: Discovery for research and advice, Review for contract review and negotiation, Draft for document drafting, Multi Review for due diligence across data rooms, Legal Radar for regulatory monitoring, and Agent Studio for building custom agents and workflows. The signature feature is anonymisation applied before analysis begins, with an option to run that component inside the customer's own environment so sensitive data never reaches a model in identifiable form. LLM agnostic by design, selecting different foundation models per task. Founded in Ghent in 2023 by a team from Tinder, with offices in London and Dubai.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the product. Every surface sold is a generative or machine learning capability: research agents, contracting agents, compliance agents and a studio for building custom agents. The anonymisation layer that differentiates the product is itself a fine tuned model rather than a rules engine. Remove the models and nothing remains.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted and the grounding behind it is not documented. Vendor material states that answers are grounded in verified case law and legislation across more than 130 jurisdictions and that anonymisation preserves full legal and contextual accuracy of every review, which is an accuracy claim with nothing behind it. Searched the site, the six product pages, the Knowledge platform page, the security page and the resources index on 29 Aug 2026 and located no description of the retrieval method, no statement of how output links back to primary sources a reader can open, no accuracy figure, no hallucination rate and no evaluation. Two jurisdiction counts appear on the same home page, 110 plus in one place and 130 plus in another, which is the kind of inconsistency that matters on an accuracy axis.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A real published commitment with described control surfaces, short of the full structure. Agent Studio documentation states that workflows trigger automatically from email, Slack, Teams or manually, that conditional logic routes work and handles follow ups, that the system escalates when needed, and that approval steps keep legal in control without bottlenecking every decision. That is an oversight mechanism described at the point where an agent acts, and the escalation and approval language is more specific than most of this market publishes. Not located as of 29 Aug 2026: the threshold at which an agent escalates rather than proceeds, who configures it, and what the vendor commits to when an agent is wrong.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Real deployment evidence with substance, short of measurement. Three named customer stories are published, ECS on streamlining legal review across departments, PIF Group on speed, consistency and quality, and Wealins of Foyer Group on broader market coverage and reduced external legal spend, alongside a customer logo wall and named enterprise references reported in funding coverage including Slaughter and May and Allianz. Not located as of 29 Aug 2026: figures for what changed at any named customer, dates, or a method a reader could assess. The reduced external legal spend claim carries no number.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments built around an unusual architectural claim, short of the full picture. The vendor states that documents are anonymised before analysis begins, that in the on premise configuration sensitive data never leaves the customer environment in identifiable form, that environments are isolated per client, and that the customer retains data ownership throughout. Anonymisation is configurable, with adjustable levels and term whitelisting. Segregation is documented at the level this buyer segment requires under the amended band, through per client environment isolation and single tenant deployment. Two gaps hold it off an A. Attorney client privilege and work product handling is not addressed directly in located material. No training prohibition on customer content was located on the public pages as of 29 Aug 2026, which for a vendor whose entire pitch is data protection is a conspicuous absence rather than a small one.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The audience is unambiguous, in house legal and business teams at enterprises, and the vendor is explicit that it is built for that rather than for law firm workflows. But the product is sold to non lawyers by design, with dedicated solution pages for HR, procurement, sales, claims and compliance, and a product called Discovery that delivers legal research and advice. Searched the site, the solution pages, the published terms and conditions and the resources index on 29 Aug 2026 and located no position on the advice line, no treatment of competence or supervision duties, and no statement of jurisdiction limits. Selling a legal advice surface to procurement and sales teams is the configuration where a published position matters most, and none was located.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Responsible AI is claimed without a mechanism. The vendor describes itself in published material as setting the global standard for responsible legal AI and states that controls are continuously audited against international standards, and it publishes governed execution and guardrails as product concepts. Searched the site, the security page, the platform pages and the resources index on 29 Aug 2026 and located no named internal owner of model governance, no pre release testing regime for model behaviour, no ISO 42001 or equivalent AI management certification, and nothing on uneven output across matter types, parties or populations. The security governance is real and is a different subject.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy covering most of the ground. Encryption at rest and in transit, per client environment isolation, attribute based access control, multi factor authentication and session governance, SSO across Okta, Azure AD and Google Workspace with SAML 2.0, OIDC and OAuth, annual independent penetration testing, and a trust center published at a stable URL. The anonymisation layer is a genuine data minimisation control rather than a policy statement. Not located as of 29 Aug 2026: a stated retention period or deletion control for documents and prompts, a named subprocessor list, and an incident or breach notification practice. Retention is the notable one, since it is the question this axis asks first.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Liability is addressed through published terms and conditions a buyer can read before signing, which puts this above a pure absence, but what was located is the standard shape rather than a position on AI output. Searched the published terms and conditions, the privacy policy, the security page and the trust center on 29 Aug 2026 and located no indemnity running to the customer for third party claims arising from output, no warranty on output, no stated liability cap and no insurance position. For a vendor selling into banking, insurance and regulated manufacturing, the absence of a published position on who bears the loss is a live buyer question.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations, named and documented at feature level, short of implementer depth. Microsoft Word and Outlook add ins each have their own product page, workflows trigger from email, Slack or Teams, Multi Review reads across data rooms directly from the customer's document system, and a dedicated integrations page describes the product as embedded across existing enterprise systems. Orientation is toward enterprise business systems rather than legal specific document management, which fits an in house buyer. Not located as of 29 Aug 2026: named document management connectors such as iManage or NetDocuments, and per integration documentation of what moves in which direction and what an administrator configures.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The strongest deployment disclosure in the index so far, and the first A on this axis. Three models are published with the differences between them spelled out: fully managed SaaS; single tenant, a dedicated isolated instance deployed in the customer's preferred Azure region, fully managed and completely segregated from other customers; and single tenant plus on premise anonymisation, where the anonymisation component runs inside the customer environment and only anonymised data crosses to the dedicated tenant over private encrypted connections. Residency is stated as customer selected Azure region, and the architecture separates where identifiable data is processed from where the tenant sits, which is precisely the processing versus storage distinction this axis asks for. The public FAQ adds private cloud, hybrid and full on premise. Short of naming the specific regions available.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real and stated with an open access route, short of accessible evidence. ISO 27001 and SOC 2 Type II are both stated as certified, annual independent penetration testing is stated, compliance frameworks across the EU, UK and Middle East are named, and a trust center is published at a stable URL, which under the three tier test is materially better than absent. What was not located as of 29 Aug 2026 is any coverage period, audit scope, report date or named auditor. Worth flagging one noun problem: the security page opens by saying the compliance framework is aligned with ISO 27001, SOC 2 Type II and GDPR, and a later section says certified. Alignment and certification are different claims, and the page makes both about the same standards.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The vendor refers to model selection without identifying what sits underneath. The architecture is disclosed at a structural level and it is a real disclosure: the platform is LLM agnostic and selects the best foundation model for each legal scenario, and a fine tuned anonymisation model runs ahead of any external model call. That tells a buyer how the supply chain is shaped. What it does not tell them is which providers are in it. Searched the site, the security page, the anonymisation platform page, the trust center entry point and the published legal pages on 29 Aug 2026 and located no named model provider, no subprocessor list, no statement of where models run, and no commitment to notify customers when the selection changes.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Searched the site, the navigation, the product pages, the industry and solution pages and the published terms on 29 Aug 2026. There is no pricing page anywhere on the property, no published rate, no stated unit of charge, no tier structure and no seat minimum. The only commercial entry point on every page is a demo booking, which is sales gated and earns no credit. Note that three deployment models are published in detail with no indication of what any of them costs or how they differ commercially.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Who the product serves is documented precisely and the boundary is stated rather than implied. Five industries carry dedicated pages, banking, insurance, transportation and mobility, technology and professional services, and six functions carry their own, legal, claims, compliance, HR, procurement and sales, which is unusually explicit about reaching beyond the legal department. The vendor states plainly that it is built for enterprise legal and business teams rather than law firm productivity workflows, which is a published limit on who it is not for. Jurisdictional coverage is quantified, though inconsistently at 110 plus in one place and 130 plus in another. Named enterprise references span the segments claimed.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way.
Searched the security page, the anonymisation platform page, the published terms and conditions, the privacy policy and the home page on 29 Aug 2026. No located term or policy states whether customer content may be used to train models, either way. The vendor's published position is architectural rather than contractual on this point: documents are anonymised before analysis and, in the on premise configuration, sensitive data never leaves the customer environment in identifiable form. That reduces what a model could receive but is not a statement about training. Under the rule that a value is never inferred from the absence of a contradiction, this records as silent. Conspicuous for a vendor whose entire positioning is data protection.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
Searched the security page, the platform pages, the published terms and conditions, the privacy policy and the trust center entry point on 29 Aug 2026. No public material states how long documents, prompts or outputs are retained, whether the customer controls the window, or whether deletion is available. The vendor states that customers maintain data ownership throughout and that environments are isolated per client, neither of which answers the retention question. First vendor on this index to record an absence rather than a period here.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
The product maintains its own documented permission model rather than inheriting one from a document management system. Published controls are attribute based access control, multi factor authentication and session governance, configurable to the customer's own standards, with SSO through Okta, Azure AD or Google Workspace enforcing the customer's access policies. Environments are isolated per client, and single tenant deployment segregates a customer completely from others. What is not documented is segregation between users or matters inside a customer, and no document management integration was located whose permissions retrieval could enforce at query time.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located term or policy addresses third party requests for customer data.
Searched the published terms and conditions, the privacy policy, the security page and the trust center entry point on 29 Aug 2026. No clause addressing government or law enforcement requests for customer data was located, and no transparency report was located. Worth noting for a future reader that the on premise anonymisation configuration materially changes what a vendor could produce in response to such a request, since identifiable data never reaches it, but the vendor does not make that argument in published material and it is not recorded as a value here.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Coverage is described by jurisdiction with no identification of the underlying corpus.
Coverage is described by jurisdiction with no identification of the underlying corpus. Vendor material states that answers are grounded in verified case law and legislation across more than 130 jurisdictions, with a separate home page figure of more than 110 jurisdictions for global translation and jurisdiction coverage. Neither number is accompanied by a named source or publisher, a licence or public domain basis, or an update cadence. A Knowledge platform page describes verified legal knowledge without saying where it comes from.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Searched the site, the Discovery product page, the Knowledge platform page and the resources index on 29 Aug 2026. No material was located addressing whether authority returned by the product carries a treatment signal, whether subsequent history is checked, or whether any commercial citator is licensed. The vendor describes case law as verified without stating what verification means or when it was performed.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Searched the site, the six product pages, the Agent Studio page and the resources index on 29 Aug 2026. No published material describes what the product does when it cannot ground an answer, and no explicit no answer path or confidence signal was located. Agent Studio documents escalation when needed as a workflow routing behaviour, which is about handing a task to a person rather than about the system declining to answer, and was not treated as evidence for this signal.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance, and it is bounded by what that database covers, which is weighted toward US and other common law filings while this vendor sells primarily into European enterprises.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
Searched the site, the security page, the solution pages and the resources index on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located. The vendor publishes compliance material aligned to information security and data protection standards across the EU, UK and Middle East, which addresses its own regulatory posture rather than the professional responsibility obligations its buyers are bound by. Noted for a future reader: this vendor sells primarily into European enterprises, where the applicable guidance is issued by national bars and law societies rather than the ABA, and none of those was engaged either.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Vendor material is framed around speed and cost reduction, including a published customer story headlined on broader market coverage and reduced external legal spend, and product copy promising review and negotiation in minutes rather than hours. Searched the site, the product pages, the customer stories and the resources index on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no published guidance on billing, fee or client disclosure treatment. The buyer here is an in house team rather than a firm billing a client by the hour, so this signal reads differently for this segment.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
Searched the security page, the trust center entry point, the published terms and conditions and the privacy policy on 29 Aug 2026. No subprocessor list was located, no statement of which model providers see customer content was located, and no client facing consent or notification material was located. A trust center exists at a stable URL, which is an access route rather than the artifacts themselves. Worth recording that this vendor's architecture arguably answers the underlying question differently, since the on premise anonymisation option means identifiable client content need not reach a model provider at all, but the disclosure a firm could forward is not published.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Some elements of a record are available, short of a document level export. Multi Review is documented as exporting audit ready reports intended for deal teams, regulators or internal stakeholders, and the same review logic is stated to apply across every document so results are comparable. That is an exportable artifact, but it is a review output rather than a record of how AI produced it. Not located as of 29 Aug 2026: any export covering model used, sources retrieved and human verification per document, and the model used is not identifiable in any case since the platform selects different models per task.