L
Legl

Legl is a client onboarding, anti-money-laundering and payments platform for law firms, operated by The Justice Platform Ltd of London and used by more than 600 firms in the United Kingdom and Australia. The platform covers client onboarding workflows, individual and business due diligence, source of funds, digitised risk assessments, ongoing monitoring and client payments, with a compliance dashboard built for money laundering reporting officers.

Its AI layer is presented as one of three platform pillars under the name Risk Agents. The agents gather and parse documents, research and structure screening data, run remediation loops that go back to the client for missing or non-conforming information, read bank statements to surface income, large one-off payments, balance trends and higher-risk activity, and analyse trust deeds to identify trustees, settlors and beneficiaries.

Screening matches are returned with a recommendation, a confidence level and the supporting evidence, and in source of funds a mathematical validation step confirms the figures are consistent before a reviewer sees them. A separate governance layer lets a firm codify its own risk policies into rules the agents enforce, so escalation to a named reviewer happens automatically where a high-risk factor appears, with decisions and overrides recorded alongside their reasoning.

The vendor's stated position is that agents flag matters for human attention and the decision stays with the reviewer. Legl is listed on the UK government's Digital Verification Services register under its registered name and is a certified Identity Service Provider under the Digital Identity and Attributes Trust Framework. It publishes a dated sub-processor policy naming sixteen suppliers with their processing activities, and holds ISO/IEC 27001 certification under certificate number 0174467.

The platform integrates with law firm systems including iManage, NetDocuments, Clio, Elite 3E, Litera Foundation 365, Quill, Proclaim and Partner for Windows. Named users include Lewis Silkin, Michelmores, Stephens Scown, Taylor Rose, Cripps, gunnercooke, Tollers and Hall Brown Family Law.

Vendor siteLondon, United Kingdom
Last verifiedSeptember 7, 2026
Compare with other vendors

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The AI is a platform layer rather than a feature, and the vendor's own information architecture says so: Risk Agents is one of three items under Platform, alongside the Governance Layer and Integrations, and sits above the six solution modules rather than inside one of them. The agents are described as operating across the client lifecycle: researching and structuring screening matches, triaging ongoing monitoring alerts, reading bank statements in source of funds, analysing trust deeds for trustees, settlors and beneficiaries, auto-populating risk assessments, and running remediation loops back to the client.

Screening and monitoring are described as running continuously using the agents. What holds this below the top band is the size of the non-AI spine underneath. Client payments and reconciliation, digital onboarding workflows, company registry retrieval, e-signature, dashboards and reporting all predate the agents and work without them, and the compliance value a firm buys, being a defensible file for an SRA or MLR audit, is produced by the workflow and the audit trail rather than by inference. The AI removes manual effort from a compliance process that would still run without it. Checked 7 September 2026.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Grounding is real and documented and a verification step is described, short of any accuracy figure an outsider could test. Screening matches are returned with a recommendation, a confidence level and the supporting evidence, so the reviewer sees what the model relied on rather than a bare conclusion, and the underlying sources are named suppliers a firm can identify. In source of funds the vendor describes a specific control: the AI reads the statements and surfaces income, large one-off payments, balance trends and higher-risk activity, with a mathematical validation step confirming the figures are consistent before they reach the reviewer.

That is a described method with an arithmetic check on the model's output, which is more than most records on this axis publish. What is absent is measurement: no accuracy figure, no false positive or false negative rate, no test set, no evaluation and no named failure mode, on a product whose core function is deciding whether a flagged record really is the firm's client. One tension is recorded because a reader who finds it unaided should see it in the note: the published Terms of Use state that Legl makes no representations or warranties as to the truth, accuracy, quality or completeness of information provided in connection with the services, which sits against a product that returns confidence levels and validated figures.

Grounding to primary legal authority does not bite on a due diligence product and is counted neither way. Checked 7 September 2026.

Source: Vendor Published
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a lawyer checks it are all published: modes, thresholds, review surfaces, and the route a matter takes back to human judgement.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

All four limbs of the top band are published separately and explicitly, which is rare enough on this axis to state limb by limb. What the system runs alone: screening, ongoing monitoring and remediation are described as running continuously, with clients re-screened daily, agents gathering and parsing documents, researching and structuring data, reading bank statements, analysing trust deeds, and operating remediation loops directly with the firm's client to collect missing information.

What constrains it: the governance layer codifies the firm's own risk policies into Risk Rules the agents enforce, and administrators control screening configuration firm-wide, choosing which categories are screened, which PEP seniority levels, which source jurisdictions, how widely to search and how sensitive matching should be. How a lawyer checks it: matches are returned with a recommendation, a confidence level and the supporting evidence, the compliance dashboard gives a firm-wide view with downloadable reports, decisions and overrides are recorded with their reasoning, confirmed false positives can be whitelisted, and a weekly summary reaches the MLRO.

The route back to human judgement: the vendor states that agents exist to flag discrepancies and non-conformity for human attention and that the decision stays with the reviewer, high-risk factors escalate automatically by email to the MLRO or nominated reviewers with the assessment queued for review, alerts can be assigned to a named reviewer, and reassessment dates are set by risk level. The published position is a division of labour rather than a slogan: agents do the gathering, research and structuring, and people decide. Checked 7 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Adoption evidence is strong and unusually well attributed to the buying role. Named firms include Lewis Silkin, Michelmores, Stephens Scown, Taylor Rose, Cripps, gunnercooke, Tollers, Wilkes, Blacks, Higgs, Woodstock, Wolferstans, Hall Brown Family Law, Harold Benjamin, Burnett and Reid, Robertsons, Sharmans and Laytons ETL. Testimonials carry full names and job titles, and the titles are the ones that matter for this product: Helen Strachan, Practice Director and MLRO at Burnett and Reid; Shivani Patel, Compliance Supervisor at gunnercooke; Guy Hurst, Compliance Manager at Wilkes; Will Taylor, CFO and COO at Hall Brown; Natasha Boyland, Director and Head of Risk and Operations at Woodstock; Simon Bagshaw, Director of Finance and IT at Tollers.

Two concrete figures are published, both customer-stated: half of due diligence requests completed within 24 hours of being sent at gunnercooke, and three risk assessments in about twenty minutes against roughly an hour for one under the previous system at Sharmans. Two things hold this at B. The figures sit in testimonials with no method, sample, baseline date or independent basis, and only the Sharmans figure is a before-and-after.

And the headline adoption count is inconsistent across the vendor's own current surfaces: the marketing site says more than 600 law firms while the trust centre description says more than 400 including 40 of the top 200. Both are the vendor's own live material and neither is reconcilable from outside, so the discrepancy is recorded and nothing is graded on either figure. Checked 7 September 2026.

Source: Vendor Published
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

The commitments that exist are real, but the instrument that would govern the buyer is not published, and that is what decides this. The only agreement on the site is the Terms of Use, which by its own first clause governs the individual submitting a payment or completing a workflow, not the law firm. The firm-facing agreement exists and is named: the sub-processor policy refers throughout to the Legl Services Agreement and states that undefined terms take their meaning from it.

It is published nowhere. A buyer therefore cannot read the confidentiality obligations, the data handling terms or the security commitments that would actually bind Legl to the firm. What is published and does count: a strong biometric commitment, under which neither Legl nor the firm ever receives the biometric identifier generated from the client's images, it is held by the provider only until Legl says it is no longer needed, and Legl states it does not use, disclose or retain biometric information for any other commercial purpose; a destruction obligation on the firm's request or when processing is no longer needed; and contractual safeguards imposed on all sixteen sub-processors, including confidentiality obligations on their personnel and prompt breach notification.

Privilege and work product appear nowhere, and the product holds client identity and source-of-funds material rather than matter files. Checked 7 September 2026.

Source: Vendor Published
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

An express disclaimer exists in a published agreement and no conduct framework sits behind it. The Terms of Use state that nothing in the Legl Services, or in emails Legl sends on the law firm's behalf, is or should be construed as legal advice, and separately that the individual's use of the service is not determinative of their status as a client of the firm, with appropriate contractual arrangements to be put in place directly.

Both are directed at the firm's client rather than at the firm, which is the right audience for a platform that communicates with clients under the firm's brand, and the second is a genuinely useful clarification of where the retainer sits. The product is also built around the firm's own regulatory obligations, with MLRO dashboards, defensible records of how each client was assessed and why, and audit-ready reporting.

What is not addressed is professional responsibility in the firm's use of the AI: nothing names a conduct rule or regulator, nothing addresses supervision obligations when an agent acts, and nothing states what a firm must still do itself to discharge its duties. Limbs of this axis that turn on producing legal work product do not bite on a due diligence platform and are counted neither way. Checked 7 September 2026.

Source: Vendor Published
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

No governance disclosure was located. There is no AI policy, no responsible AI or ethics statement, no governance framework, no bias or fairness discussion, no ISO 42001 or NIST AI RMF alignment, no named internal owner for AI decisions, no model evaluation or testing description, and no AI provision in any published agreement. The gap is conspicuous rather than incidental on this record for two reasons that belong on it.

First, the vendor markets its agents as auditable and sells a governance layer to firms, so governance is the vocabulary of the product, applied to the customer's risk policy and not to Legl's own models. Second, the platform runs biometric identity verification and AI risk scoring on individuals whose onboarding depends on the result, and demographic differential performance is a well-documented property of that class of system.

Nothing published addresses fairness, error rates across populations, testing, or what recourse an individual has when a check goes against them. The ISO/IEC 27001 certification governs information security and is not read as covering this. Surfaces read on 7 September 2026: the Risk Agents page, the KYC, KYB and AML page, the pricing page, the Terms of Use in full, the sub-processor policy in full, the trust centre entry point and the site footer.

Source: Vendor Published
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Real stewardship is documented for the data supply chain and almost nothing is documented for the AI. On the credit side the sub-processor policy is a working governance artifact rather than a list: it describes a commercially reasonable selection process evaluating security, privacy and confidentiality practices, and requires sub-processors to satisfy obligations equivalent to Legl's own, including processing only on documented controller instructions, using personnel bound to confidentiality, providing regular security and data protection training, maintaining technical and organisational measures, promptly informing Legl of any actual or potential breach, and cooperating with controller, data subject and regulator requests.

Biometric handling is specific and restrictive. Destruction follows the firm's request or the end of the processing need. What is missing is the part this axis is about. No published surface states how client documents, bank statements or trust deeds are handled once an agent has read them, whether anything is retained from an inspection, whether client content is segregated from model operations, or what happens to the material a remediation loop collects.

No AI-specific commitment of any kind was located, and the one improvement right in the published Terms covers de-identified technical device and system telemetry rather than client content. The firm-facing Legl Services Agreement, which is where terms would sit, is named in the sub-processor policy but is not published. Checked 7 September 2026.

Source: Vendor Published
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Nothing establishing recourse to the buyer could be located, and the one published agreement excludes liability comprehensively. The Legl Services Agreement is named twice in the sub-processor policy as the instrument governing the client relationship and is published nowhere on the site, whose legal footer carries only the Terms of Use, website terms, privacy policy and a link to the trust centre. A firm therefore cannot establish before purchase what warranty, cap, indemnity, service level or remedy it would have.

The instrument that is published runs the other way throughout. Use is on an as-is and as-available basis at the user's sole risk. Legl makes no representations or warranties as to the truth, accuracy, quality or completeness of information provided in connection with the services, and explicitly excludes all other conditions, guarantees and implied or statutory warranties. It accepts no liability for loss or damage of any kind arising from access to or use of the services, disclaims responsibility for the acts or omissions of any third-party service provider, and states that as a data processor it is not liable to the individual for any act or omission in relation to their personal data.

The only indemnities run from the user to Legl. No cap figure, uptime commitment, service credit, cure period or termination-for-degradation right appears anywhere published. The grade records what is establishable on the date: the buyer's own agreement is unpublished and the available instrument allocates risk away from the vendor. Checked 7 September 2026.

Source: Vendor Published
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

The integration surface is the deepest in this lane and it is specifically legal. Ten named systems appear on the product pages, and they are practice systems rather than general business tools: iManage and NetDocuments on document management; Clio Manage and Clio Operate, the latter named as Sharedo; Elite 3E on finance and practice management; Litera Foundation 365, named as Peppermint; Unity Practice Management, named as NebuLAW; Quill; Proclaim, named as DPS; and Partner for Windows.

The parenthetical former names are worth noting as a mark of care, since a UK firm buying this will know several of these products by the older brand. That set spans the two major document management systems, a major international finance platform and four UK-specific practice systems, which is a materially different position from a vendor naming Zapier and a CRM. What holds this below the top band is that the depth of each connection is not described on any surface read: nothing states whether the integration writes back, what triggers a sync, whether an API is public, or what a firm must build.

The integrations index page was not opened in this pass and is named as the artifact that would settle it, and the row is amendable on that evidence. Checked 7 September 2026.

Source: Vendor Published
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Neither limb is stated, which is what the band requires. Infrastructure suppliers are named in the sub-processor policy, being Amazon Web Services EMEA, Heroku, Microsoft Ireland Operations and Snowflake for cloud and data services, and the corporate entities named are European. That identifies who hosts, not where the data sits: no data centre location, no region, no residency option and no residency commitment appears on any surface read, and naming an Irish or Luxembourg contracting entity is not a statement about storage location.

Tenancy is equally absent: nothing states whether the service is single-tenant, pooled or configurable, and no separation model is described beyond the fact that screening configuration changes apply firm-wide. The nearest thing to a residency term sits in the consumer Terms of Use, which bar the individual from accessing the services in any jurisdiction other than the United Kingdom where doing so would require Legl or its providers to physically store data in that jurisdiction without prior written consent.

That is a restriction on the user rather than a commitment by the vendor, though it implies a United Kingdom storage default. A separate Australian estate exists across the site, which implies a second region without describing one. No self-hosted or private deployment option was located. Checked 7 September 2026.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Multiple current certifications, one of them independently checkable, presented through a real trust centre whose contents could not be read. Legl publishes its ISO/IEC 27001 certificate number, 0174467, in the footer of every page, which is more than most records on this axis offer: a number a buyer can take to the certification body rather than a badge. It is listed on the UK government's Digital Verification Services register maintained by the Office for Digital Identities and Attributes, under its registered name The Justice Platform Ltd, and is a certified Identity Service Provider against the Digital Identity and Attributes Trust Framework.

A government register entry is verifiable entirely independently of the vendor, which is the strongest form this evidence takes. A dedicated trust centre exists at a subdomain, hosted on Vanta's European instance and linked from the site footer as Security. Two things hold this at B. No certification body or auditor is named, no certificate validity window is given, no certificate document is published on the main site, and no SOC 2 report for Legl itself was located.

And the trust centre returned only page metadata: its body renders client-side and no document list, access tier or request flow could be read. That is recorded as a retrieval limit and is not graded against the vendor, but it does mean the access flow could not be assessed, so no credit is taken for what the portal may offer. The certifications named for sub-processors and payment partners belong to those companies and are not credited here. Checked 7 September 2026.

Source: Vendor Published
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

A thorough supplier disclosure programme that has not been extended to the models. The sub-processor policy is genuinely good: sixteen suppliers named as at 3 June 2025, each with its processing activity stated, a described due diligence and contractual safeguard process, notice of changes by email or in the customer's own environment, a ten day objection window, and a dated update log explaining why Mitek Systems and Dun and Bradstreet were added in July 2024.

Against that, no model or model provider appears anywhere in it. The list contains cloud and data infrastructure, being Amazon Web Services, Heroku, Microsoft Ireland, Snowflake and Fivetran; identity and data suppliers, being ComplyAdvantage, Equifax, Entrust Identity, Mitek, Creditsafe, Dun and Bradstreet and TrueLayer; and tooling, being Datadog, Sentry, HelloSign and an email provider. Not one entry is a foundation model provider, and no surface names a model, a version, a family, or states that the models are built in house.

For a platform whose own navigation calls its AI layer Risk Agents and which describes those agents reading bank statements and analysing trust deeds, that is a real gap: a firm cannot tell whose model processes its client's financial documents. Naming the cloud providers says where the software runs and has been credited on deployment, not here. Checked 7 September 2026.

Source: Vendor Published
CC on Commercial TransparencyPricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

The charging model is published and no price is. What a buyer can establish first-party: pricing is modular, with the firm choosing the modules it needs and paying only for what it uses; billing is monthly and described as predictable; there are no implementation fees; and there is no long-term lock-in, a point a named customer reinforces by contrasting it with competitors requiring fixed contracts of up to thirty-six months and usage forecasts.

ROI reporting and cost-savings insights are offered as part of the product. That is a described model rather than an invitation to call, and it lifts the axis off the floor. What is absent is every figure: no price per module, per check, per seat or per firm, no volume band, no minimum, no term length and no currency. The page carries no plan table of any kind, and the only route to a number is booking a demo. One tension is recorded because it is the vendor's own framing against its own page: the page is titled transparent, value-based pricing and its meta description promises a transparent, surprise-free pricing structure, on a page that publishes no cost.

Transparency about how a buyer will be charged is real here; transparency about what they will pay is not. Checked 7 September 2026.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Deep in one workflow, broad across firm types, narrow across jurisdictions. The buyer surface is unambiguously legal: every solution page addresses law firms directly, the named customers are all law firms, and the roles quoted are legal compliance roles rather than generic operations. Firm coverage spans the range a UK vendor would want to show, from national and international names such as Lewis Silkin and Michelmores through strong regional practices including Stephens Scown, Cripps, Tollers and Wilkes, an alternative-structure firm in gunnercooke, a Scottish firm in Burnett and Reid, and specialist family practices including Hall Brown.

The trust centre description claims forty of the top two hundred. What holds this at B is that coverage means firm types rather than practice areas: the product addresses one workflow, client onboarding and anti-money-laundering diligence with payments attached, and applies it identically whatever the matter is. No practice-area breakdown, matter-type coverage statement or area-specific configuration is published beyond risk assessment templates a firm builds to its own policy.

The regulatory frame is also single-jurisdiction, resting on the SRA, the Money Laundering Regulations, HM Land Registry expectations, the DVS register and the Digital Identity and Attributes Trust Framework, with a separate Australian estate as the only other market. Checked 7 September 2026.

Source: Vendor Published
Pricing

No published figure

  • Legl publishes how it charges but not what it charges. Pricing is modular, so a firm buys only the modules it needs and pays for what it uses, billed monthly, with no implementation fee and no long-term contract. No figure appears anywhere: no price per module, per check or per seat, no volume band, no minimum and no term. The only route to a number is booking a demo.

Published model, no published figure. The pricing page states that pricing is modular, with the firm choosing the modules it needs and paying only for what it uses; that billing is monthly and described as predictable; that there are no implementation fees; and that there is no long-term lock-in. ROI reporting and cost-savings insights are listed as part of what a customer gets. A named customer, the Operations Director at Harold Benjamin, reinforces the no-lock-in point by contrasting it with competitors requiring fixed contracts of up to thirty-six months and usage forecasts, with higher charges for overuse; that is a comparative marketing claim rather than a term, and it is recorded as corroboration of the published model only.

No figure of any kind was located on any first-party surface: no rate per module, per check, per seat or per firm, no volume band, no minimum commitment, no contract term and no currency, and the page carries no plan table. The route to a price is a demo booking. One tension is recorded because it is the vendor's own framing measured against its own page: the page is headed transparent, value-based pricing and its meta description promises a transparent, surprise-free pricing structure, on a page that publishes no cost.

A row is owed here because the published charging model lifts Commercial Transparency off the floor, which is the test for whether a row exists. Surfaces read on 7 September 2026: the pricing page, the Terms of Use in full, the Risk Agents page, the KYC, KYB and AML page and the sub-processor policy.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

No agreement published

No customer agreement, terms of service or equivalent contract is published on any surface located, and no policy page states a position on training. Nothing is granted and nothing is withheld, so a client has no term to hold the firm to. Where a policy page does state a position, the row takes the matching policy value instead and the summary records that no agreement exists.

The governing agreement is not published, so the question cannot be answered from the vendor's surfaces. The Legl Services Agreement exists and is named twice in the published sub-processor policy, which states that Legl engages sub-processors as described in that agreement and that undefined terms take their meaning from it. It appears nowhere on the site: the legal footer carries only the Terms of Use, website terms, privacy policy and a link to the trust centre.

The Terms of Use govern the individual submitting a payment or completing a workflow rather than the law firm, so they are not the customer agreement for this purpose. Their one improvement right was tested and does not reach this signal: it permits Legl to collect technical data about the user's device, system and application software and to use it, in a form that does not personally identify the user, to improve products or provide services.

That operates on device telemetry rather than client content and does not name machine learning, training or model improvement, so it is not read as a training permission. No statement anywhere on the product pages, the Risk Agents page or the sub-processor policy says whether client documents, bank statements or screening data train or refine the agents. This is recorded as an agreement a buyer cannot obtain rather than as vendor silence.

Source: Vendor PublishedAs of Sep 7, 2026

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Not addressed

No located public material states how long prompts and outputs are retained.

Nothing addresses the retention of what the agents read or produce. A general destruction obligation exists in the published Terms of Use: on the law firm's request, or when Legl or its engaged providers no longer need to process the personal data, whichever is earlier, Legl will cease all use and destroy it, subject to any legal retention requirement. That governs the individual's personal data at the level of the workflow and carries no period, no outer limit and no trigger a buyer can plan against.

It says nothing about the AI layer specifically: no surface states whether a bank statement or trust deed persists after an agent has read it, whether the structured output of an analysis is retained separately from the report, or how long screening research and monitoring alert triage are kept. The biometric identifier is the one item with a described lifecycle, held by the third-party provider until Legl states it is no longer needed, which is a condition rather than a period.

The firm-facing Legl Services Agreement, where a retention schedule would ordinarily sit, is not published. Surfaces read on 7 September 2026: the Terms of Use in full, the sub-processor policy in full, the Risk Agents page, the KYC, KYB and AML page and the pricing page.

Source: Operator VerifiedAs of Sep 7, 2026

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Claimed, not documented

Segregation is asserted in public materials with no published detail on how it is enforced.

Role-based control is claimed and the separation model behind it is not documented. What is published concerns who sees what by function: administrators control screening configuration and changes apply firm-wide, monitoring alerts can be assigned to a named reviewer, high-risk escalations route by email to the MLRO or other nominated reviewers, and the compliance dashboard is presented as a firm-wide view for the compliance function.

Those are real access and routing controls and they show that the platform distinguishes roles inside a firm. What is absent is the segregation model. Nothing describes how one firm's data is separated from another's, nothing addresses partitioning between teams or departments inside a single firm, nothing states whether a conflicted fee earner can be excluded from a client's file, and nothing says whether the risk agents are scoped to the requesting user's permissions when they research a match or read a document.

There is no document management system integration inheriting an existing access control list for this purpose either, although Legl integrates with iManage and NetDocuments for other functions. The absence matters more than usual on a product that holds counterparty identity material in transactional work.

Source: Vendor PublishedAs of Sep 7, 2026

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Disclosure addressed, notice absent

Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.

Disclosure is addressed twice in the published Terms of Use and notice is absent from both, expressly so in one. On compelled disclosure, the terms state that Legl will not pass personal data to third parties except in accordance with its privacy policy or where required by law to disclose that information. Disclosure is acknowledged as a live possibility and no undertaking to tell the firm or the individual accompanies it.

The second instance is stronger and goes the wrong way: where Legl suspects fraudulent, criminal or improper activity via the payment system, it may report or disclose information about the user and their use of the system to relevant law enforcement, at its sole discretion and without notice to them. That is an express reservation of disclosure without notice rather than an omission. The proactive fraud-reporting context is not the same as a compelled government demand, and the distinction is recorded rather than collapsed, but the pattern across both provisions is the same: the vendor addresses disclosure and commits to no notification anywhere.

No challenge undertaking, no minimisation term, no record-keeping obligation and no transparency report were located. The firm-facing agreement, which might treat this differently for the customer, is not published.

Source: Vendor PublishedAs of Sep 7, 2026
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Sources named, basis unstated

Sources are identified without stating the licence or rights basis.

The sources are named thoroughly and their licence terms are not published. Naming is the strong half: the sub-processor policy identifies sixteen suppliers as at 3 June 2025 with the processing activity of each, so a buyer can see that ComplyAdvantage supplies screening, Equifax, Entrust Identity and Mitek Systems supply identity verification, Creditsafe and Dun and Bradstreet supply business data, and TrueLayer supplies account information services, with payment partners Adyen, Stripe and Banked identified separately with their regulatory status.

The Terms of Use add that information uploaded is disclosed to Equifax as a credit reference agency and link the industry-standard CRAIN notice explaining how credit reference agencies process the data, which is a genuine provenance disclosure to the data subject. What is not published is the licensing. No flow-down terms, permitted-use conditions, territorial restrictions or intellectual property provisions for any supplier appear anywhere, and the sub-processor policy states expressly that it grants clients no additional rights or remedies and should not be construed as a binding agreement.

A buyer can therefore establish where the data comes from but not on what terms it may be used. Separately, nothing states what the risk agents themselves were trained on, which is recorded on the model supply chain row.

Source: Vendor PublishedAs of Sep 7, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

The product ships no citator and makes no good-law claim, which is the expected position for a client onboarding, due diligence and payments platform rather than a disclosure gap. Nothing Legl produces cites legal authority: the outputs are due diligence reports, screening results, company structure reports, source of funds analyses and risk assessments. The currency question that does arise here is currency of reference data rather than currency of law, and it is answered elsewhere, with clients re-screened daily against sanctions and PEP lists and business clients monitored for ownership, structure, financial and legal proceedings changes.

Recorded at the floor because the value set requires a value, with the reason stated so a reader does not take it as a finding against the vendor. Nothing in this record depends on it.

Source: Operator VerifiedAs of Sep 7, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Confidence signal only

The product exposes a confidence or grounding score without an explicit abstention path.

A confidence signal is published and a fuller account of behaviour under uncertainty is not. The concrete mechanism is stated plainly: AI-assisted screening matches are returned with a recommendation, a confidence level and the supporting evidence, and the vendor describes the agents as weighing the evidence and providing signals as to whether a flagged record really is the firm's client, with the decision remaining with the reviewer.

The agents are also described as identifying high likelihood matches among monitoring alerts, which is the same graded-confidence shape, and as flagging discrepancies and non-conformity with the firm's risk policies for human attention. That is more than most records carry and it is why this sits above the floor. What is not published is the behaviour around the score. No threshold is stated at which the system declines to recommend, abstains or escalates on uncertainty as opposed to on risk level, nothing describes what an agent does with a document it cannot parse or a statement it cannot reconcile, and no refusal or abstention policy appears anywhere.

The one adjacent control, the mathematical validation step confirming source of funds figures are consistent before they reach the reviewer, is an output check rather than an account of what happens when the check fails.

Source: Vendor PublishedAs of Sep 7, 2026

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

None located

No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.

No matter naming Legl or The Justice Platform Ltd was located in the hallucination case tracking maintained by Damien Charlotin or in the sanctions reporting drawn from it, searched on 7 September 2026 on both the trading name and the registered company name. The reporting reviewed names the tools involved where they are known and spans a corpus now exceeding 650 documented instances across multiple jurisdictions, including the English decisions in Ayinde and Al-Haroun.

Legl appears in none of it. This is consistent with the product class: the platform produces due diligence reports, screening results and risk assessments and generates no citations to legal authority, so the exposure this signal tracks is structurally absent rather than merely unrealised. Recorded as none located rather than as a positive finding about vendor conduct.

Source: Operator VerifiedAs of Sep 7, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

Regulatory alignment is substantial and none of it is guidance on artificial intelligence. What Legl documents is identity and anti-money-laundering standards: listing on the UK government's Digital Verification Services register maintained by the Office for Digital Identities and Attributes, certification as an Identity Service Provider against the Digital Identity and Attributes Trust Framework, and a product built around the firm's obligations under the Money Laundering Regulations, with MLRO dashboards, escalation paths and a defensible record of how each client was assessed and why.

Its payment partners are identified with their Financial Conduct Authority regulatory status. That is real alignment and it is named here so it is not mistaken for silence. It is not what this signal asks. No bar, law society or regulator guidance on the use of artificial intelligence is named, mapped or referenced anywhere, and nothing addresses what a firm's own obligations are when an autonomous agent gathers evidence, scores a client's risk or corresponds with that client on the firm's behalf.

For a product that runs remediation loops directly with the firm's client under the firm's brand, that is the guidance a solicitor would want mapped.

Source: Vendor PublishedAs of Sep 7, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure, and the product sits inside a fee relationship between a lawyer and a client where those savings would change the bill.

Time savings are published and the fee consequence is not addressed. The claims are customer-attributed and specific: half of due diligence requests completed within 24 hours of being sent at gunnercooke, and three risk assessments in about twenty minutes against roughly an hour for a single assessment previously at Sharmans. The vendor also offers ROI reporting and cost-savings insights as part of the product, which is a savings claim in its own right.

Nothing addresses what happens to a client bill when compliance work that took an hour takes twenty minutes, no per matter record of AI-assisted work is described, and no guidance on fee or disclosure treatment is offered. Two qualifications belong on the record. The savings described are the firm's internal compliance overhead rather than billable client work, and compliance time is often absorbed rather than billed, so the compression this signal was written for operates differently here.

And the vendor sells a payments product handling client money and reconciliation, which puts it closer to the firm's billing than most, yet nothing connects the two: no surface addresses how the cost of checks or the saving from automation is reflected on a client account.

Source: Vendor PublishedAs of Sep 7, 2026

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Subprocessors listed

A current subprocessor or model provider list is published.

The supplier list is exemplary and the model provider limb is empty, which is what holds this below the top value. The list itself meets every reasonable test: sixteen sub-processors named as at 3 June 2025, each with its processing activity stated, published openly rather than on request, with a described due diligence process, contractual safeguards flowing equivalent obligations down to each supplier, change notification by email or within the customer's own Legl environment, a ten calendar day objection window with a right to state reasons, and a dated update log recording the July 2024 additions of Mitek Systems and Dun and Bradstreet with the reason for each.

Forwardable client-facing material exists too: the Terms of Use are written for the individual being verified, name the workflow providers, explain the biometric handling and link the industry CRAIN notice, so a firm has something drafted to be passed to its client. What is missing is a statement of which model providers see client content. No foundation model provider appears anywhere in the sixteen, no model is named, and nothing states that the agents run on Legl's own infrastructure.

Naming Amazon Web Services, Microsoft Ireland and Snowflake says where software runs rather than whose model reads a client's bank statement, and infrastructure alone does not satisfy this signal. A firm asked that question by a client could not answer it from what is published.

Source: Vendor PublishedAs of Sep 7, 2026

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

An exportable, audit-facing record exists and it does not disclose the AI's part in producing it. The record is real and is central to what the product sells: a defensible record of how each client was assessed and why, a compliance dashboard covering CDD, AML and audit history for every individual and business client, downloadable reports for internal review or audit preparation, CSV export of flagged contacts for regulatory or internal reporting, decisions and overrides recorded with their reasoning, and an audit trail the vendor describes as building itself as each step is recorded.

The intended reader is an SRA inspector or an MLRO preparing for one, which is close to but not the same as a court. What is not established is the AI disclosure limb. The vendor's own phrase for the layer is auditable AI risk agents, but no surface describes what an agent's entry in the audit trail contains, whether the record distinguishes a conclusion an agent reached from one a reviewer reached, or whether a firm could show which parts of an assessment were automated.

Recording overrides with reasoning implies some of this and does not state it. Crediting a full exportable record here would read an AI disclosure capability into an audit trail built for a different question.

Source: Vendor PublishedAs of Sep 7, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 12, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746