Litify
Litify is a legal operating platform built natively on Salesforce that runs a firm's work end to end: client intake with dynamic questionnaires and voice agents, matter management, document generation and PDF editing, timekeeping and billing, legal spend management with budgets and line-item invoice review, and no-code reporting. It sells four named solution lines covering personal injury, insurance defense, immigration and corporate legal departments, against a claim of more than fifteen practice areas, and names Brooklyn Defenders, Quintairos Prieto Wood & Boyer, AmTrust, Cole Scott & Kissane and the United States Postal Service among its customers. Litify AI is the intelligence layer: the Agentic Case Expert, or ACE, works across a firm's cases and documents, and eight further named agents cover intake qualification, treatment-plan follow-up, policy-limit review, medical record retrieval, case-value detection, demand letter drafting, interrogatory responses and deposition preparation. Several AI features come from partners rather than being built in house, with the Damages Assistant and Instant Demands powered by Supio, AI Time Capture by Billables.ai, and conflict checking and invoice review by Salesforce Agentforce. The vendor states that its AI runs in a closed, isolated environment on Anthropic models reached through Amazon Bedrock, and that customer data is never retained by or used to train the model. Litify is distributed as a Salesforce managed package and requires a Salesforce platform licence alongside its own subscription, which the vendor lists from $200 per user per month.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The home page calls Litify the only AI-native platform of action, and the product's own history contradicts the claim: the Taylor King Law case study describes a 2021 deployment whose measured gains came from the analytics engine, phone-tree routing and matter plans, with no AI in the account at all. What sits on top now is substantial rather than decorative. Litify ACE is positioned as the AI nerve centre, eight further named agents run from intake qualification through deposition preparation, and machine learning is embedded in document generation, time capture and line-item invoice review. Remove the models and a working intake, matter, billing and reporting platform remains, which is the shape of a legacy system that added a real AI layer rather than one built around it.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is claimed repeatedly and measured nowhere. The Litify AI page asserts that being fully native to the platform ensures greater accuracy than standalone AI tools, and the Damages Assistant is described as reconciling bills against records for total accuracy. No test set, no benchmark, no error rate and no failure mode is published on any surface checked on 31 August 2026. The product does not retrieve primary law, so the citator limb of this axis does not bite; what it does do is draft demand letters and interrogatory responses from a firm's own medical records and matter data, and no grounding mechanism is described for that output. Nothing was located that would let a reader open a drafted assertion and trace it to the source page it came from, which is the specific thing a comparable plaintiff product in this pull does publish.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Litify sells autonomy in plain terms and publishes no control structure for it. ACE is described as a proactive, autonomous partner that anticipates risk and executes tasks in the background, the platform page describes autonomous AI agents that execute tasks in the background, and the Demand Agent drafts demand letters automatically as damages approach policy limits while the Discovery Agent auto-drafts interrogatory responses. Against that, the only oversight position located is a philosophical one in the Pillars of Responsible AI Development post of 9 July 2024, which states that AI is not a replacement for legal professionals and is not well positioned to engage in the art of case strategy. That is a statement of intent rather than a mechanism: no review point, no approval step, no threshold at which an agent stops, and nothing on what happens after an agent is wrong was located on the product, platform or AI pages. A stated belief about the division of labour is not the same as a published place where a lawyer signs off.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
This is the strongest evidence set located in the plaintiff lane. The Taylor King Law study names the firm, its size at 75-plus employees, its states, its COO Emily Merryman, and a 2021 go-live migrating from Needles, then gives a baseline of a 30 per cent intake conversion rate moving to 50 per cent and a 46 per cent rise in average attorney fees. A published baseline is rare in this corpus and it is what makes the figure assessable. The method is described step by step rather than asserted: identifying high-performing intake agents from captured workflow data, routing existing-case calls away from them by phone tree, replacing uniform follow-up with if/then timing logic, and adding an automated quality-of-life questionnaire to surface non-economic damages. Further named studies carry their own figures, including EllisDon at 100 per cent faster reporting, McFarlane Law at a 10 per cent lift in billing collection and Cesar Ornelas at 33 per cent more case production without added headcount. Two limits belong on the record: no study carries a publication date or a measurement window, and not one of the located figures is attributed to an AI capability, so the outcome evidence is for the platform rather than for Litify AI.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The commitments are specific, readable before signing, and none of them is contractual, because no customer agreement is published anywhere on the property. The Litify AI page states that customer data is never retained or used to train the model, the Pillars post of 9 July 2024 describes single-tenant architecture giving each client a walled-off cloud environment, and the security post states that customer data sits in Salesforce data centres to which Litify is not an authorised administrator, with support access requiring the customer to run a Grant Litify Support Team Access process. It also states that third parties including Litify employees, investors, shareholders and board members are not permitted to access customer information. What is missing is what the band expects to be missing at this level: segregation is described between customers rather than between matters inside a firm, which is the level a plaintiff or defence firm buyer actually needs, and nothing addresses what Anthropic or AWS may retain when a prompt reaches Bedrock. Privilege and work product are not mentioned on any surface checked, and the only published legal document, the privacy policy, expressly excludes data held on behalf of customers.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Searched the home page, the Litify AI page, the platform page, the privacy policy, the CA notice link, the responsible AI post, the security post, the customers section and the Salesforce AppExchange listing on 31 August 2026: no disclaimer, no statement of what the product is and is not, no supervision or competence discussion, no jurisdiction limit and no engagement with ABA Formal Opinion 512 or any state bar guidance was located. There is no terms of service on the property to carry a boilerplate disclaimer, so the record here is a true absence rather than a thin clause. This matters more than it would for a reporting tool, because the shipped agents draft demand letters and interrogatory responses and the platform is sold to firms whose staff include non-lawyer case managers and intake agents. The absence is the finding.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Litify publishes a governance post, Our Pillars of Responsible AI Development, dated 9 July 2024 and by-lined to VP of Engineering Andrew Heffernan, which is more than most of this lane offers. Read for governance specifically, most of its substance belongs to other questions: the Claude 3 selection, Amazon Bedrock and single-tenant storage are supply-chain and deployment facts, and the value-first pillar is a philosophy about not replacing lawyering. What remains as governance is a set of principles with nothing attached to them. No accountable owner for AI governance is named, no pre-release testing regime is described, no evaluation results are disclosed, and nothing at all was located on bias or uneven output across matter types, claimant populations or case values. That last gap is worth stating plainly on a product whose Case Value Agent and Policy Agent make value judgements about individual injury claims.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Access control is genuinely well described and the rest of the ground is not covered. The security post of 30 June 2022 states that customer data sits in Salesforce data centres where Litify is not an authorised administrator, that documents are held on AWS behind a strict internal approval process, that the support team must be granted access through a named customer-run process, and that employees, investors, shareholders and board members may not access customer information. Against that single strong element: no retention period, no deletion route, no subprocessor list and no incident or breach-notification practice was located on any surface checked on 31 August 2026. The privacy policy that would ordinarily carry some of this states in its opening that it does not apply to personal information held on behalf of users of the services, which removes matter data from its scope entirely. The access-control material is also four years old and has no current counterpart.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
No customer agreement of any kind is published. The escalation ladder was run in full on 31 August 2026: the footer of every rendering page carries only a Privacy Policy and a CA Notice at Collection, a search anchored on agreement language returned no Litify terms, and the Salesforce AppExchange listing carries Salesforce's own Terms of Use rather than the provider's. No master subscription agreement, order form, indemnity, liability cap, warranty on output or insurance position was located, and there is no trust portal or documents page from which one could be requested. This is an absence rather than a retrieval failure: the pages that would hold such a document render normally and simply do not exist. A buyer cannot learn who bears the loss when an agent drafts a wrong demand until they are already in a sales process.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The platform page displays roughly thirty integration logos, and the names are the right ones for legal work: iManage, NetDocuments, Outlook, DocuSign, Aderant, Epiq, QuickBooks, Chrometa, Time by Ping, RingCentral, Vonage and Case Status among them. The See All Integrations link on that same page resolves to a bare anchor and goes nowhere, and no integrations directory, developer index or connector documentation was located anywhere else on 31 August 2026. So an implementer can learn that a NetDocuments or iManage connection exists but not what it moves, in which direction, or what a firm must configure. Being a Salesforce managed package does bring genuine API reach, but that is the platform's extensibility rather than a documented Litify integration, and it is credited on the deployment question instead of here.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The tenancy model is stated and the location is not. The Pillars post of 9 July 2024 describes single tenant architecture in which each client has a unique cloud environment walled off from other organisations, extended to single tenant storage for the AI features, and the product is delivered as a Salesforce managed package requiring a Salesforce platform licence. Beyond that, nothing: no region list, no data residency options, no distinction between where data is stored and where it is processed, and no statement of which Salesforce or AWS regions a firm's matter data occupies. The privacy policy does say servers are in the United States, but it scopes itself to the marketing site and expressly excludes data held on behalf of customers, so it cannot answer the question for the product. Graded against the bands: the C band requires that neither the tenancy model nor the region be stated, and the tenancy model is stated, so C is not available. What holds the grade below A is that the residency half is wholly absent and the tenancy claim rests on a blog post from July 2024 with no current specification page behind it. Regraded from C on 1 September 2026 for consistency with records publishing one of the two limbs.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Litify names its auditor, which most of this lane does not. The security post states that Litify has completed SOC 2 Type I and Type II audits, both performed by Sensiba, and that it undergoes annual independent security audits. What is absent is everything that would let a buyer act on it: no scope, no trust services categories, no coverage period, no report date, no trust portal and no route to request the report short of a demo. The post is dated 30 June 2022 and no current attestation was located, so a reader in 2026 cannot tell whether the annual cadence held. Separately, the Litify AI page claims the product is fully configurable to meet HIPAA, GDPR and SOC II standards, which is a statement about configurability rather than an attestation and should not be read as one.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Litify names its model provider in the marketing hero, which almost nothing else in this pull does: the home page describes the platform as built on the infrastructure of Salesforce, AWS and Anthropic, identified as its closed AI model. The Pillars post of 9 July 2024 goes further and names the model to a version, the Claude 3 family from Anthropic, reached through Amazon Bedrock and run inside closed AWS services so client data is not exposed to the broader internet or to open models. Two things hold this below the top of the axis. No commitment to notify customers when the model or provider changes was located, and the version naming is two generations stale, with the current AI page naming Anthropic and no model at all. The supply chain also extends further than the model pages admit, since the Damages Assistant and Instant Demands are powered by Supio, AI Time Capture by Billables.ai and conflict checking by Salesforce Agentforce, and no subprocessor list ties those parties to what customer data they see.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
There is no pricing page on litify.com and no pricing entry in its navigation, but the vendor's own Salesforce AppExchange storefront publishes a figure and a unit: a default plan at $200 USD per user per month, marked as the lowest starting price, with discounts noted for nonprofits. The listing also states that the package requires Platform Cloud, so a buyer can see that a Salesforce licence sits on top of the Litify subscription even though the size of that addition is not given. What is withheld is the rest of the range: no tier names, no feature splits between packages, no statement of what the AI capabilities cost, and nothing on implementation, which is substantial for a Salesforce-native deployment. A buyer can therefore learn the floor and the unit of charge without entering a sales process, and nothing above the floor.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described with real substance. Four solution lines each have their own page and named buyer: personal injury firms handling high-volume intake, firms doing high-volume defence work for insurance carriers, consumer and business immigration practices, and corporate legal departments managing internal matters and outside counsel. The AppExchange listing adds government agencies and nonprofits as named segments, and the customer roster bears the breadth out, running from Brooklyn Defenders to the United States Postal Service. The claim that the platform works across fifteen-plus practice areas is not itemised, and no statement of where the product stops was located: nothing on firm size floors or ceilings, on practice areas that are not supported, or on jurisdictions outside the United States, though the platform-of-action framing and the Salesforce licence requirement both point away from the very small firm.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
A public policy or trust page states no training on customer content, with no matching term located in the published agreement.
The Litify AI page states the position twice, in a Zero Model Training panel and again in the FAQ, where it says the closed and secure model ensures customer data is never used to train the model. The Pillars of Responsible AI Development post of 9 July 2024 says the same of the single-tenant AI architecture. No customer agreement, master subscription agreement or data processing addendum is published anywhere on the property, so the commitment is a policy statement on a product page rather than a term a firm could hold Litify to.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
What Litify publishes covers the model, not the platform: the quoted line and the Zero Model Training panel both address whether the AI model persists customer data, and say it does not. Nothing located states how long prompts and generated outputs are kept inside the Litify application itself, whether a firm can configure that window, or whether zero retention is available. Searched the home page, the Litify AI page, the platform page, the privacy policy, the security post and the responsible AI post on 31 August 2026; the privacy policy states a general as-long-as-necessary standard but scopes itself out of data held on behalf of customers.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses walls or matter level segregation.
The segregation Litify describes is between customers rather than within a firm: the responsible AI post of 9 July 2024 says each client has a unique cloud environment walled off from other organisations. Nothing located addresses ethical walls, matter-level access restriction, or whether retrieval enforces a firm's own permissions at query time, which is a live question for a product whose ACE agent is described as working natively across all of a firm's cases and documents and whose conflict checker searches an entire case history. Searched the home page, the Litify AI page, the platform page, the security post, the responsible AI post and the privacy policy on 31 August 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located term or policy addresses third party requests for customer data.
The privacy policy of 3 June 2026 says Litify may disclose personal information to law enforcement and government authorities and in response to valid requests by public authorities, with no commitment to notify the affected party and no transparency report. That policy states at its opening that it does not apply to personal information held on behalf of users of the services, which places a firm's matter data outside its scope, and no customer agreement exists to address the question instead. Searched the privacy policy, the CA notice, the security post and the AppExchange listing on 31 August 2026; no notice or subpoena commitment covering customer data was located.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
The product does not retrieve primary law. Litify AI works on a firm's own matter data, medical records and documents, so there is no case law or statutory corpus behind its output and no licensing question of the kind this signal tracks. Recorded as not addressed rather than skipped; searched the Litify AI and platform pages on 31 August 2026 and located no reference to a primary law source.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
No citator function is offered and none would apply in the ordinary way, because the product does not return authority to be checked for subsequent history. The nearest adjacent behaviour is drafting: the Demand Agent produces demand letters and the Discovery Agent auto-drafts interrogatory responses, neither of which is described as citing or verifying case law. Searched the Litify AI and platform pages on 31 August 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
No located material describes what any Litify agent does when it cannot support an answer from the matter file. No abstention path, no confidence or grounding score and no described behaviour on missing data was found, although the Record Retrieval Agent is described as identifying missing medical records, which is gap detection in the case file rather than uncertainty about its own output. Searched the Litify AI page, the platform page and the responsible AI post on 31 August 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, along with 2026 sanctions trackers and trade coverage, on 31 August 2026. The product name and the company name are the same word, so a single search covers both filing conventions. No court order, opinion or disciplinary record naming Litify was located. This is a statement about the public record rather than a finding about the product, and the failure mode is live here rather than theoretical, since the shipped agents draft demand letters and interrogatory responses.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No engagement with ABA Formal Opinion 512 or with any state bar opinion on generative AI was located. The vendor publishes buyer-education material on AI, including a Legal AI Buyer's Guide and a 2025 State of AI in Legal report, and a responsible AI post that names NIST, the Global Partnership on AI and the Partnership on AI as bodies its model providers engage with, none of which is ethics guidance binding its customers. Searched the home page, the Litify AI page, the responsible AI post, the resources index and the privacy policy on 31 August 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Litify markets efficiency and realisation gains without addressing the client's side of the invoice. The home page says configurable workflows and autonomous agents let a firm handle twice as many matters with the same staff, and the platform page describes AI Time Capture as recommending time entries so that work such as quick emails is never left off the bill. Nothing located addresses how AI-assisted work should be billed or disclosed to a client, and no per-matter record of what the AI itself did is described, though AI Time Capture is said to generate review-ready entries.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
A firm answering a client's AI clause can point at named providers on current pages: the home page names Salesforce, AWS and Anthropic, the responsible AI post names the Claude 3 family reached through Amazon Bedrock, and the Litify AI page names Supio, Billables.ai and Salesforce Agentforce as the parties behind specific features. That is a model provider disclosure rather than a subprocessor list, and it is recorded as the closest true value rather than an exact one. No formal subprocessor register, no data processing addendum and no client-facing consent or notification pack was located, and there is no trust portal from which to request one.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located public material addresses court disclosure or verification certification.
Nothing located addresses producing an AI-use disclosure or a verification certification for a court. No export of which model produced which passage, what was retrieved, or who reviewed it is described for any of the nine named agents. The conflict checker is said to create a permanent report, but that is a conflicts artifact rather than an AI disclosure record. Searched the Litify AI page, the platform page and the responsible AI post on 31 August 2026.