L
Luthor
Luthor is an enterprise marketing compliance platform from Luthor, Inc. of San Francisco, sold to legal and compliance teams in regulated companies and to the marketing teams whose work they review. Content is uploaded before publication — text, images, video, audio, SMS, social posts and live URLs — and the AI runs a first-pass review against rule sets the customer configures, flagging performance claims, guarantees, missing disclosures, testimonials, unsupported assertions, off-brand language and personally identifiable information, explaining which rule was hit and what to change.
Every review carries provenance showing what was flagged and the reasoning, and rule hits, edits and approvals are timestamped for an examiner. Published rule coverage includes the SEC Marketing Rule, FINRA Rule 2210, Regulation Z, NMLS and state licensing lines, RESPA, UDAAP and FTC advertising rules, alongside brand and internal policy checks, and the vendor's policy and legal engineers build the rule sets with each customer.
Two dated case studies describe deployments at a wealth manager and a regional mortgage lender, one of them with the customer named. Luthor states SOC 2 compliance, US processing, per-organisation data isolation, and that submitted content is not retained by model providers. Pricing is not published; the vendor says the figure varies by review volume, policy coverage, workflow complexity and implementation scope.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the mechanism, not a feature bolted to a workflow tool. Content goes in — text, images, video, audio, SMS, social posts, PDFs and live URLs — and the system classifies it, flags performance claims, guarantees, missing disclosures, testimonials, unsupported assertions, off-brand language and personally identifiable information, then says which rule was hit and what to change. The vendor describes natural language processing for context, machine learning classification and large language models for the written output.
The approval routing and the audit trail exist to carry that output rather than the other way round, and the published case for buying is that human review alone cannot enforce every policy at the volume AI-generated content now arrives in. One qualification a buyer should hold: part of the enforcement is plainly rule-based — banned phrases, trigger words, required disclosure lines — and nothing published separates what the rules catch from what the models catch.
Read on the home page platform and policy library sections, both solutions pages, the Financial Services page and the 19 June 2026 guide. Verified 20 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted repeatedly and measured nowhere. The PCM Encore case study of 28 October 2025 puts review accuracy at 64% before and up to 96% after, described as accuracy with zero critical defects; the Regional Bank study of 8 December 2025 reports 86% of advertising issues self-corrected by the field and licensing errors near zero. Neither gives a sample, a period, a method, or a definition of what a correct review is, and nothing anywhere addresses the failure that matters most in a product like this, which is the violation the system does not flag.
A 98.4% detection rate and a 99.2% figure sit inside product mockups on the home and Legal & Compliance pages next to invented assets, so they describe the interface rather than a result. What is real is the grounding: every review shows what was flagged, which rule applied and the reasoning behind it, and the bank study shows that explanation reaching the person who has to fix the ad. A figure an outsider could test is what this row is short of. Verified 20 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The review point is described and it sits with people, short of a full control structure. The AI runs the first pass; assets come back approved, needing review or escalated, and each review carries provenance showing what was flagged, which rule applied and the reasoning. The Regional Bank study of 8 December 2025 describes the tightest version in production: the field could fix findings and re-upload until an ad passed, and only compliance could override a finding.
Role-based permissions, multi-factor authentication and single sign-on are published, and every action is logged. Two things hold this where it is. The override rule and the risk thresholds that drive escalation are the customer's own configuration — escalation criteria and risk thresholds are listed among the things a customer encodes — rather than a limit the vendor places on its own product. And nothing published says what the system does at the point it cannot tell, or what happens after a review turns out to be wrong.
An auto-approve control appears in a product mockup on the Marketing Teams page and is described nowhere in text. Verified 20 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Two dated deployments are published with figures, and the figures do not entirely agree with each other. PCM Encore, an employee-owned fiduciary wealth manager in Bellevue with more than $1.2 billion under management and over 50 client families, is named and its Chief Compliance Officer is quoted: weekly reviews up from 6, accuracy from 64% to up to 96%, median turnaround from three business days to roughly four hours, live in three days (28 October 2025).
A regional mortgage lender, unnamed, reports reviews 82% faster, 86% of issues corrected by the field before compliance saw them, NMLS and licensing errors near zero, and more than 60 custom rules built (8 December 2025). Neither states a method or a measurement window. The bank study headlines 82% faster and its own text says about 70 per cent; PCM Encore's weekly figure reads 45 on one page and 46 on another; the same customer quote appears in two wordings across the site. Three further logos and two anonymous testimonials carry no figures. Verified 20 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Real written commitments, with the confidences peculiar to legal work left unaddressed. The Terms of 07.11.25 carry a mutual confidentiality obligation with reasonable care and the ordinary exceptions, leave the customer owning its data outright, and commit to deleting all customer data within thirty days of termination. The security page adds AES-256 at rest and TLS 1.2+ in transit with keys held in a rotating key management service, per-organisation isolation with data never co-mingled across customers, access confined to authorised users within the account, and a statement that submitted content is not retained by model providers.
Three things keep this short of the top. Privilege and work product are never mentioned, on an estate that sells to legal teams. No model provider is named, so the retention commitment made on their behalf cannot be checked against anyone. And the training position lives on a policy page while the Terms grant a licence to use customer data to provide and improve the Services. Verified 20 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
Nothing published addresses the advice line, on a product whose whole function is telling people what a regulation requires. The Regional Bank study of 8 December 2025 sets out the shape: a loan officer or a marketer uploads an ad and the system returns pass or fail, the rule that was hit and what to change — Regulation Z trigger terms and the disclosures they require, the loan officer's and company NMLS identifiers, state licence lines, the Equal Housing legend, wording in builder co-marketing that could imply a referral arrangement.
The home page shows the same thing, calling a return guarantee a FINRA 2210 problem and offering the disclosure to add. No statement that this is not legal advice appears anywhere, including the Terms of 07.11.25, which disclaim warranties and outcomes and say nothing about advice. Nothing addresses the competence or supervision of the lawyer or compliance officer who owns the judgement, and no jurisdiction limit is named.
Checked the home page, both solutions pages, the Financial Services page, the security page, the Terms, the Privacy Policy and both case studies on 20 September 2026. Verified 20 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
No governance position is published about this vendor's own models. There is no statement of who inside Luthor owns model behaviour, nothing on what is tested before a change ships, and nothing on whether output differs across content types, channels, or the populations an advertisement reaches. The estate publishes a good deal of governance material aimed the other way: guides telling regulated firms how to govern AI agents used in marketing review, test the AI, define reviewer authority, require a rationale for overrides, monitor drift and preserve evidence.
That is advice to buyers about their own programmes, not a commitment about the product they would be buying. The one mechanism on the product side is the provenance carried on every review, which shows a reader what was flagged and why; that is an output explanation rather than governance over the model, and it is recorded on the oversight row. Read across the home page, the security page, both solutions pages and the resources library. Verified 20 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Most of the ground is covered in published detail, with one clear gap. The security page states AES-256 at rest and TLS 1.2+ in transit with automatic key rotation, per-organisation data isolation, role-based access with multi-factor authentication and single sign-on through OAuth or SAML, immutable audit logs of who did what and when retained to the SEC's 17a-4 requirements, automated vulnerability scanning, DDoS protection and continuous monitoring, and a documented incident response plan with severity levels, escalation paths and notification of affected customers within regulatory timeframes.
Processing and storage are stated to be in the United States. The Terms commit to deleting all customer data within thirty days of termination. The gap is the subprocessor list: none is published, and the vendor's own trust centre records zero subprocessors and zero documents. Nothing states how long submitted content is held during the term. Verified 20 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
The published position is a standard limitation clause, and it disclaims the exposure this product creates. Section 6 of the Terms of 07.11.25 provides the services as is, disclaims all warranties including fitness for a particular purpose, states that no particular outcome is guaranteed, excludes indirect, incidental, special, consequential and exemplary damages including lost revenue and goodwill, and caps total liability at the fees paid in the preceding twelve months.
Carve-outs run the vendor's way and the customer's alike: personal injury or death, fraudulent misrepresentation, intellectual property infringement and anything that cannot be limited by law. No indemnity of any kind is offered to the customer, and nothing addresses the loss a buyer actually fears here, which is an advertisement that cleared review, went to the public, and drew a regulator. Warranty of effort is offered instead: commercially reasonable efforts to minimise errors and interruptions. Verified 20 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
No integration into the systems legal and compliance work already lives in is named anywhere on the estate. What is published is ingestion by format and channel — text, images, video, audio, SMS, social posts, PDFs, email drafts, rate sheets and live web pages — and monitoring of published content after it goes out. The Regional Bank study describes the position it replaced rather than one it connects to: reviews that had been running through email chains, Asana tasks, shared drives and design folders moved into Luthor's own upload and vault.
No document management, matter management, marketing automation, social publishing or archiving system is named as a connection, no directional sync is described, and no developer or integration documentation is published. Immutable retention to the SEC's 17a-4 standard is offered inside the product rather than through an archiving partner. Read on the home page, both solutions pages, the Financial Services page and the two case studies. Verified 20 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Both halves are stated plainly, and neither is offered as a choice. Tenancy: each organisation's data sits in a siloed environment, isolated from other customers and never co-mingled, with access limited to authorised users inside the account. Region: the security page says the platform runs on SOC 2 certified cloud infrastructure in the United States and that all processing happens in controlled environments with network isolation and continuous monitoring, so storage and processing are answered together rather than left apart.
What is not published is any option. No single-tenant, private or on-premises deployment is described, no second region is offered, no cloud provider is named, and nothing says what changes between tiers, because no tiers are published. For a buyer with data outside the United States, the international transfer clause in the Privacy Policy points to standard contractual clauses and nothing further. Verified 20 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The vendor names a standard, and its two surfaces name different levels of it. Four product pages carry a SOC 2 Type II Compliant badge with a line that the company is independently audited and certified on a continuous basis, alongside GDPR compliance, SEC 17a-4 readiness and regular third-party penetration testing; the security FAQ says the SOC 2 Type II report goes to customers and prospective customers under an NDA, requested through the trust centre.
The trust centre at trust.inc/luthor, linked from those same pages and read on 20 September 2026, records SOC 2 Type 1, two frameworks, and zero policies, zero subprocessors and zero documents behind a request-access button. Both are the vendor's own, both are recorded here with their surface and date. What a buyer can reach is a named standard at a stable address and a route to ask for the report. What is not published anywhere is the audit period, the scope of the examination or the auditor, and nothing on the portal is shown to be obtainable. Verified 20 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The vendor commits on behalf of model providers it never names. The security page states that submitted content is not retained by model providers or used for training, and describes model provenance among the layers it protects, but no provider, model or version appears anywhere on the estate, and nothing says where inference runs beyond the statement that processing happens on US cloud infrastructure. The architecture is described only in categories: natural language processing for context, machine learning classification, and large language models generating the written output.
No subprocessor list is published and the trust centre records none, so the chain cannot be reconstructed from another surface either. Nothing commits to telling customers when a model or provider changes. For a buyer in a regulated industry the practical effect is that the zero-retention promise cannot be checked against the party who would have to keep it. Verified 20 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Nothing about cost is published, including the unit being charged. There is no pricing page and no pricing link in the footer; every route ends at a demo request, and the demo page offers help with pricing and plans without naming a plan. The ROI calculator models savings against what it calls the Luthor investment and says only that the investment varies by review volume, policy coverage, workflow complexity and implementation scope, which names the things that move the price and neither a rate nor a unit.
The Terms of 07.11.25 refer to fees payable under an applicable Subscription Form for a subscription term, which fixes a billing period rather than a unit of charge, and the liability cap is expressed as the fees of the preceding twelve months without saying what those fees buy. No tier names, no feature splits, no implementation figure, and nothing on what an enterprise agreement adds. Verified 20 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Who this is for is described with real substance, and where it stops is not. Two buyer pages name the users: legal and compliance teams who review, and the marketing teams whose work they submit. Four industry pages name the segments: asset managers, registered investment advisers and broker-dealers; banks and credit unions; mortgage and consumer lenders; and consumer-regulated industries including food, pharmaceuticals, alcohol and tobacco.
The subject matter is equally specific — the SEC Marketing Rule, FINRA 2210, ADV Part 2, Regulation Z, NMLS and state licensing, RESPA, UDAAP and FTC advertising rules — and the named customers sit in three of the four segments. What is absent is the boundary. Nothing says which regimes are not covered, nothing describes the position of a law firm reviewing its own advertising, and the claim that rules can be configured for any regulatory framework is made without an example of one built outside the published list. Verified 20 September 2026.
8 public documents
The public pages on file for Luthor, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.
-
luthor.ai/security2 signals
Prompt and Output Retention, Ethical Walls and Matter Segregation
Read Sep 20, 2026
-
Primary Law Corpus Provenance, Refusal and Uncertainty Behaviour
Read Sep 20, 2026
-
trust.inc/luthor1 signal
Outside Counsel Guideline Readiness
Read Sep 20, 2026
-
luthor.ai/customers/pcm-encore1 signal
Client Data in Training
Read Sep 20, 2026
-
Court Disclosure Support
Read Sep 20, 2026
-
luthor.ai/roi-calculator1 signal
Billing and Fee Posture
Read Sep 20, 2026
-
Good Law Verification
Read Sep 20, 2026
-
luthor.ai/terms1 signal
Third Party Request and Subpoena Notice
Read Sep 20, 2026
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Public material states that customer content trains, refines or personalises models, with no matching term located in the published agreement. Any de identification, anonymisation or aggregation qualifier is recorded in the summary.
The estate says two different things and the more specific one describes training. The security FAQ answers the question flatly: customer data is never used to train, fine-tune or improve any AI model, and submitted content is not retained by model providers or used for training. The PCM Encore case study of 28 October 2025 describes the opposite behaviour in that firm's deployment, a continuous-learning loop that captured every human override with the model re-training nightly and precision improving week over week.
A described behaviour carries further than a general assertion, so this records the training as it is described. Two limits on how far that goes: nothing suggests one customer's overrides reach another customer's model, and cross-customer use is not stated either way. The Terms of 07.11.25 never mention training and grant a licence to use customer data to provide and improve the Services, so the contract settles nothing here.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is acknowledged in public materials with no stated period.
Retention is addressed at both ends and left open in the middle. At the model provider, the commitment is zero: submitted content is not retained there. At the end of the relationship, the Terms of 07.11.25 commit to deleting all customer data within thirty days of termination, subject to retention laws. Between those two points nothing states how long Luthor itself holds submitted content, review output or the drafts that failed, and no setting is offered to a customer who wants a shorter window.
The product pulls the other way by design: audit logs are immutable and retained to the SEC's 17a-4 requirements, and one customer's deployment keeps an archive of approved assets for state examinations. A buyer who needs a defined retention period for content held during the term will not find one published.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
Separation is documented at the organisation level and configurable within it. Each organisation's data sits in its own siloed environment, is never co-mingled with another customer's, and is reachable only by authorised users inside that account. Inside the account the controls are described rather than claimed: role-based permissions, multi-factor authentication, single sign-on through OAuth or SAML, and an audit log of every action with who did it and what changed.
One customer's deployment shows what that buys in practice — the field could submit and correct but only compliance could override a finding, and the archive produced for a state examiner carried the approved assets without internal comments or rejected drafts. What is not addressed, because the product is not built around matters, is any wall between one piece of work and another inside the same organisation.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Terms commit to notice where lawfully permitted. No transparency report located.
A notice commitment exists and its scope is narrower than it first looks. Section 4 of the Terms of 07.11.25 lets either party disclose the other's confidential information where law or regulation requires it, provided notice is given where that is legally permissible. That is a real commitment, it is mutual, and it sits in the agreement rather than a policy page. It attaches to confidential information under that clause, and the Privacy Policy of 08.31.26 takes a different line for personal information, listing disclosure to authorities in response to legal requirements with no notice attached to it.
Nothing published describes what happens operationally when a demand arrives — no named contact, no stated practice of challenging or narrowing a request, no commitment to a timeframe — and no transparency report is published.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Sources are identified without stating the licence or rights basis.
The rules the system checks against are named; where the rule content comes from is not. Published coverage runs to the SEC Marketing Rule, FINRA Rule 2210, ADV Part 2, Regulation Z, NMLS and state licensing lines, RESPA, UDAAP, FTC truth-in-advertising, GDPR, CCPA and CPRA, CAN-SPAM and TCPA, alongside FCA for firms that need it. The other half of the corpus is the customer's own: policies, past decisions, brand guidelines, approved claims, product specifications and historical claims, plus a knowledge base the system checks assertions against.
Nothing states who writes the regulatory rule content, how it is kept current as rules change, or on what basis any licensed source is used; the vendor's policy and legal engineers are described as building rule sets with each customer. One customer built more than sixty custom rules of its own.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
This product cites no authority a reader could check, so there is nothing for a treatment signal to sit on. Flags name the rule behind them — a return guarantee against FINRA 2210, a trigger term against Regulation Z — but the output is a finding and a fix rather than a citation to primary text, and no linked source accompanies it. The nearest question, whether the rule the system applied is still the current one, is answered on the customer's side: rules can be added, updated or overridden as regulations change, and the vendor publishes regulatory updates on its blog.
Nothing published describes how the shipped rule content is maintained against amendments, who reviews it, or how a customer would learn that a rule it relies on has moved.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
The product exposes a confidence or grounding score without an explicit abstention path.
Uncertainty is expressed as a risk level, and nothing describes what happens when the system cannot tell. Assets come back banded — low, moderate or high risk — and routed accordingly: pre-cleared, needing review, or escalated, with one industry page illustrating the split as roughly three quarters pre-cleared, a fifth flagged and the remainder escalated. Risk thresholds and escalation criteria are among the things a customer encodes, so where the bands fall is the customer's decision rather than the vendor's. What is missing is any statement that the system says so when it has no basis for a judgement: no published behaviour for a claim it cannot substantiate, no abstention, and no description of what a reviewer sees when confidence is low as distinct from when risk is high. The two are not the same and only the second is described.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.
No record was located of this product's output being found fabricated or inaccurate in a proceeding, a regulatory action or a published account. Searches on 20 September 2026 across the vendor's estate, press coverage and directory profiles returned nothing of the kind. The exposure this product carries is a different one from the fabricated-citation problem in litigation tools: it does not draft legal assertions or cite authority, and the harm a buyer should worry about is a violation the review missed rather than a source it invented. Nothing published describes such a miss, and no customer account of one was found.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No rule of professional conduct, ethics opinion or bar guidance is named anywhere on the estate, and professional responsibility is not referred to in general terms either. The regulation this vendor engages with in depth binds the firm advertising rather than the practitioner reviewing: the SEC Marketing Rule, FINRA 2210, Regulation Z, NMLS licensing, RESPA, UDAAP and FTC advertising rules. Nothing addresses the duties of the lawyer or compliance officer who owns the judgement the product informs, and the Terms of 07.11.25 carry no statement that no legal advice is given and no professional relationship is created.
The closest material sits in buyer-facing guides about governing AI in review workflows, which discuss reviewer authority and override rationale as programme design rather than as professional obligation. Checked the home page, both solutions pages, the Financial Services page, the security page, the Terms, the Privacy Policy, the resources library and both case studies.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.
This product sits outside the relationship between a lawyer and a paying client. Its buyers are in-house legal and compliance functions and the marketing teams they review, its work never reaches a client bill, and no fee is charged onward for anything it produces. The published economic case is internal: reviewer hours redirected from first-pass checks to edge cases, approvals arriving in minutes rather than days, and a calculator that models year-one savings against a firm's current manual review baseline.
The cost of the tool itself is not published in any form. Nothing here bears on how a fee is disclosed to a client, because no client fee is in the path.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The material exists behind a sales conversation or an executed agreement.
The diligence materials exist behind a request and almost nothing is published. The trust centre linked from the product pages carries a request-access button and a security questionnaire, and the security FAQ says the SOC 2 report goes to customers and prospective customers under an NDA. Read on 20 September 2026, that trust centre records zero policies, zero subprocessors and zero documents, and it states SOC 2 Type 1 where the product pages state Type II.
So a buyer working through an outside counsel guideline checklist can obtain the pack by asking and can verify none of it in advance: no subprocessor list, no named model provider, no penetration test summary, no audit period or scope. What is published without asking is the security page's control description and the confidentiality, deletion and terms.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
The record this product produces is built for an examiner rather than a court, and read through that reader it is real but partial. Every review carries provenance showing what was flagged, which rules applied and the reasoning behind each decision; rule hits, edits and approvals are timestamped and described as exportable for regulators; audit logs are immutable and retained to the SEC's 17a-4 requirements. One customer's deployment shows the export in use: a state-specific set of approved advertisements produced in minutes for a state examination, carrying date, submitter, channel and states of distribution, and excluding internal comments and rejected drafts.
What is not published is any description of the export as a disclosure of AI involvement — no statement of which output the model produced as against the human edit, no format, and nothing addressed to a tribunal. No court sits in this product's path.