Relativity
Ediscovery and legal data intelligence platform, delivered as RelativityOne on Microsoft Azure, covering legal hold and preservation, collection, processing, review, production and analytics for law firms, corporations, government and legal service providers. Relativity aiR is a suite of five generative AI products built into the platform: aiR for Review, aiR for Privilege, aiR for Case Strategy, aiR for Data Breach Response and aiR Assist, alongside AI Help. Output is designed to be transparent, reviewable and defensible, with each aiR decision accompanied by a rationale and aiR for Privilege generating privilege log descriptions automatically. Governed by published Relativity AI Principles. Technology assisted review has been in the platform for years, predating the generative layer. States adoption by 192 of the Am Law 200 and more than 110 legal service provider partners. Runs a formal user certification programme covering generative AI and individual aiR products.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of a core capability layered on a platform that would function without them. RelativityOne is an end to end ediscovery system covering legal hold, preservation, collection, processing, review, production and analytics, and it has sold for two decades. The aiR suite of five generative products sits on top of that and drives substantial capability rather than peripheral features, which is why this is not a C. Worth recording precisely because it distinguishes this record from the AI native vendors: technology assisted review has existed in this platform for years, so the generative layer is the newest of several model based capabilities rather than the first, and third party analysis characterises the aiR features as evolutionary within that lineage. Sixth B on this axis.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real and documented through an explainability mechanism, short of published measurement. The vendor states that aiR for Review surfaces impactful content backed by transparent rationale and that aiR for Privilege explains every decision, so each output carries a stated basis a reviewer can inspect against the document rather than a bare classification. The suite is described as designed to be transparent, reviewable and defensible, with safeguards derived from published AI Principles. That is a documented verification surface tied to specific documents. Searched the aiR product pages, the artificial intelligence overview, the corporate data solutions pages and the learning centre on 29 Aug 2026 and located no accuracy figure, no precision or recall number, no hallucination rate, no test set, no published evaluation methodology and no independent benchmark participation. A partner published case study describes predictions as highly accurate, which is a customer's characterisation rather than a measurement and was not treated as evidence.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A real published commitment with documented review surfaces and an explicit control philosophy, short of published thresholds. The vendor's AI Principles state the aim of technology that is clear, fair and gives customers the utmost control, and the aiR suite is described as transparent, reviewable and defensible. The review surface is concrete: every decision carries a rationale, and aiR for Privilege predictions are positioned to guide counsel's second pass review rather than to replace it. The vendor also invests in operator competence in a way no other record here does, running a certification programme covering generative AI and individual aiR products, with published guidance on building, testing and trusting prompts. Third party analysis states the product does not make autonomous privilege designations and that a human reviewer still makes every privilege call, which corroborates the position without being vendor material. Not located as of 29 Aug 2026: a published threshold at which a document routes to a human, and what the vendor commits to when an output is wrong.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers and a specific, checkable adoption figure, short of vendor published outcome numbers. Adoption is quantified precisely rather than vaguely: 192 of the Am Law 200 firms and more than 110 legal service provider partners use RelativityOne, which is a figure a reader can test against the published Am Law list. Named organisations are published as aiR success stories including Alvarez and Marsal, Cimplifi and Gilbert and Tobin, with Alvarez and Marsal stated to have used aiR for Review, aiR for Privilege and aiR for Case Strategy on a single complex matter. Quantified results exist but sit in partner published material rather than vendor material: a Relativity Gold Partner published a case study covering 30,000 documents analysed with aiR for Privilege and 610 hours saved in privilege review, with auto generated log descriptions replacing a manual process. That is a named scope, a named figure and a described method, and it is recorded here as partner published rather than treated as the vendor's own evidence.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments including one control no other record on this index discloses, short of the training and retention limbs. The distinctive element is specific and consequential: the vendor states it has opted out of the abuse and harmful content monitoring offered by Microsoft, so that no unauthorised users have access to raw inputs or outputs. Abuse monitoring is the standard route by which provider staff may review customer prompts, and opting out of it is the single most concrete confidentiality decision disclosed anywhere in this pull. Alongside it: a privileged access management solution and a classification schema dictating how confidential data is handled, and a vendor risk management team reviewing Azure's security and privacy posture at least annually to validate controls are operating effectively. Two gaps hold this off an A. No statement on whether customer content may be used to train models was located, either at the vendor or provider layer. No retention or deletion terms were located. Both matter for a platform holding entire document universes for live matters.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The audience is professional and the position is unstated. Users are law firms, corporate legal departments, government and regulatory response teams, and legal service providers, with no consumer surface located, and the product is a review and investigation platform rather than an advice tool, so the advice line question arises less sharply than for a research or drafting product. Searched the aiR product pages, the artificial intelligence overview, the data solutions pages and the learning centre on 29 Aug 2026 and located no published position on advice versus tooling, no treatment of competence or supervision duties as professional obligations, and no jurisdiction limits. Worth recording as adjacent rather than as credit: the vendor runs a substantial user certification programme, which addresses operator competence as a commercial and training matter rather than as the professional duty it also is.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A published governance framework with real substance, short of testing results, a named owner and any bias disclosure. Relativity AI Principles are published as a standing document and the vendor states they guide everyday decision making toward technology that is clear, fair and gives customers the utmost control, with aiR safeguards described as inspired by them. The vendor states directly that it recognises the value AI can create along with its risks and commits to processes that are thoughtful, disciplined and trusted, which is an acknowledgement of risk rather than an unqualified capability claim. Governance is also operationalised through vendor risk management, with an annual in depth review of the underlying platform provider's security and privacy posture. Not located as of 29 Aug 2026: an AI management certification such as ISO 42001, published pre release testing results, a named accountable owner for model governance, and anything on uneven output across matter types, parties or populations. The word fair appears in the principles without any published work behind it, which is the gap this axis exists to mark.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
CORRECTED 29 Aug 2026 during the trust portal sweep. Previously graded C because access control appeared to be the only well covered element. That reading came from marketing surfaces without reaching the dedicated trust site, and understated the published controls. Now located and published: customer managed encryption keys, so a customer can hold its own key material; Customer Lockbox, a default on control restricting the vendor's own system administrators from accessing customer workspaces unless the customer explicitly grants it, which is a strong and specific limit on vendor side access; client domains providing data separation between clients; Security Center, a monitoring application shipped to customers; SIEM integration giving customers access to their own security logs; and round the clock monitoring by the named in house security team, Calder7. Previously recorded and still standing: privileged access management, a classification schema for confidential data, the opt out from Microsoft abuse and harmful content monitoring, and annual vendor risk review of Azure. That is a substantive published policy covering most of what this axis asks. Not located as of 29 Aug 2026: a stated retention period or deletion control for customer data, prompts or aiR outputs, and a named subprocessor list. Those two absences are what hold this at B rather than A.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Searched the aiR product pages, the artificial intelligence overview, the corporate and data solutions pages and the learning centre on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer agreement or master terms was located on the surfaces reached. Recorded as a pure absence on those surfaces. The shape is worth naming for this vendor specifically: aiR for Privilege exists to reduce the risk of inadvertent production of privileged material, which is among the most consequential errors in litigation, and nothing published addresses who bears the loss if a privileged document is produced on the strength of an AI prediction. Rebuttable with one link.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations exist, are named individually, and target the systems evidence actually lives in. Named as out of the box integrations for collections: Microsoft, Google, Slack and Box, with in place preservation from what the vendor calls the top productivity platforms, which is the integration that matters most for defensible legal hold. A published .NET Platform API for RelativityOne is documented through the learning programme, and the platform is explicitly built for shared working across internal teams, outside counsel and service providers, with more than 110 legal service provider partners in the ecosystem. Not located as of 29 Aug 2026: a consolidated integrations index page, per integration documentation of what moves in which direction and what an administrator configures, and legal document management connectors such as iManage or NetDocuments.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The hosting platform is named and residency is not addressed. RelativityOne is stated to be built on Microsoft Azure, and the vendor adds a substantive point about that choice, that it is the same platform chosen by global regulators, alongside an annual vendor risk review of Azure's security and privacy posture. Naming the hosting provider and evidencing ongoing oversight of it is more than several records here manage. Searched the aiR pages, the artificial intelligence overview, the data solutions pages and the learning centre on 29 Aug 2026 and located no named regions, no customer selectable residency, no tenancy model, and no statement of where processing happens as distinct from where data is stored. For a platform serving 192 of the Am Law 200 across international matters, published residency options would be expected and none was located on the surfaces reached.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
CORRECTED 29 Aug 2026 during the trust portal sweep. Previously graded C on the finding that the vendor claimed several industry certifications without naming any. That was wrong. It came from reading product and solutions marketing pages without reaching the dedicated trust site at relativity.com/trust and its compliance and privacy page, where the certifications are named individually and with versions. Published there: ISO/IEC 27001:2022 certification, ISO/IEC 27018:2019 certification, FedRAMP Moderate ATO, HIPAA compliance, IRAP assessed at Protected, a SOC 2 Type II report, a SOC 3 report, and a Cloud Security Alliance CAIQ, alongside a published request route for compliance certificates. Naming ISO 27001 at the 2022 revision and 27018 at 2019 is precise, and the set is unusually broad, spanning the US federal authorisation, the Australian government assessment at Protected level, a healthcare framework and a standardised cloud control questionnaire. A SOC 3 report is a public summary report, which is a materially more open disclosure than SOC 2 alone. The vendor also names its in house security team, Calder7, publishes a Security Center monitoring application to customers, and offers SIEM integration giving a customer access to their own security logs. Short only of a published coverage period, report date and named auditing firm, none of which was located as of 29 Aug 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The provider is identified, where the models run is stated, and the terms binding the relationship are described, short of naming the models themselves. Microsoft Azure is named as the platform the product is built on, and the vendor's disclosure about opting out of Microsoft's abuse and harmful content monitoring identifies Microsoft as the party that would otherwise have had access to raw inputs and outputs, which locates the generative processing in the Microsoft stack more precisely than most vendors manage. The relationship is governed rather than assumed: a vendor risk management team performs an in depth review of Azure's security and privacy posture at least annually to validate controls are operating effectively. Not located as of 29 Aug 2026: which specific models serve which aiR product, any subprocessor list beyond the platform provider, and any commitment to notify customers when the model supply chain changes.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
A real commercial term is published without a rate, and the term itself is unusual enough to record. The vendor states that aiR for Review and aiR for Privilege are included in the standard pricing and packaging for RelativityOne, so a buyer learns that two of the five generative products carry no separate charge, which is a meaningful commercial fact and one almost no vendor on this index discloses about its AI features. Flexible pricing models are referenced without being enumerated. Searched the aiR pages, the data solutions pages and the corporate pages on 29 Aug 2026 and located no rate, no unit of charge, no tier structure, and no published packaging for the remaining aiR products, aiR for Case Strategy, aiR for Data Breach Response and aiR Assist. Recorded at C on the strength of the published inclusion statement.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment and practice coverage is described with substance and quantified where it can be. Segments named: law firms with a stated 192 of the Am Law 200, corporations, government, and more than 110 legal service provider partners, with the platform explicitly designed as shared working space across internal teams, outside counsel and providers. Practice coverage is enumerated by product rather than claimed broadly, five aiR products each with a distinct purpose spanning document review, privilege, case strategy, data breach response and assistance, plus legal hold, preservation, collection, processing, production and analytics. Regulatory response is named down to the agency: EPA, DOJ, FDA, SEC and third party subpoenas. Not located as of 29 Aug 2026: firm size segmentation below the Am Law tier, jurisdictional or language coverage, and any statement of what the platform is not built for.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way.
Searched the aiR product pages, the artificial intelligence overview, the corporate and data solutions pages and the learning centre on 29 Aug 2026. No located material states whether customer content may be used to train models, either at the vendor layer or by the underlying platform provider. Recorded as silent under the rule that a value is never inferred from the absence of a contradiction, and specifically not inferred from the published opt out of Microsoft abuse and harmful content monitoring, which stops provider personnel accessing raw inputs and outputs and is a different question from whether anything trains on them. Notable as an absence given how specific this vendor is elsewhere about its data handling decisions.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
Searched the aiR product pages, the artificial intelligence overview, the corporate and data solutions pages and the learning centre on 29 Aug 2026. No public material on these surfaces states how long prompts, aiR outputs or rationales are retained, whether a customer controls the window, or whether deletion is available. The gap has a particular edge for this product: aiR generates a rationale for every decision and auto generated privilege log descriptions, so the system produces a substantial body of derived commentary about a customer's documents, and nothing located governs how long that commentary persists.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
CORRECTED 29 Aug 2026 during the trust portal sweep. Previously recorded at claimed but not documented, on the basis that internal controls were asserted without customer side segregation being described. That was wrong: the product documentation describes two distinct mechanisms and describes them concretely. Client domains provide a secure way to isolate users, workspaces, groups and matters by client, with data separation such that only certified partners have access across their own clients, and client domain admins administer within that boundary. Separately, Customer Lockbox restricts the vendor's own system administrators from accessing customer workspaces unless the customer explicitly grants it, enabled by default, with system admins additionally required to belong to a group within a workspace to reach it. Isolation by matter is stated explicitly, which is the level a firm facing product needs, and vendor side access is constrained by a default on control rather than a policy promise. Recorded at own model documented rather than the positive value because the product operates its own permission structure rather than inheriting a document management system's access model at query time, and because no material was located stating that aiR retrieval and generation respect those boundaries per user when the AI runs across a workspace. Ethical walls are still not named as such. Previously recorded and still standing: privileged access management and a classification schema governing vendor handling of confidential data.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located term or policy addresses third party requests for customer data.
Searched the aiR product pages, the artificial intelligence overview, the corporate and data solutions pages and the learning centre on 29 Aug 2026, and no published customer agreement or data processing agreement was reached. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. Worth recording as context: the vendor markets consolidated regulatory response across EPA, DOJ, FDA, SEC and third party subpoenas, so its customers use the platform precisely to manage government demands for their own data, and what happens when a government instead demands data from the platform is unaddressed on the surfaces reached.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
No primary law corpus is identified because the product does not hold one. Retrieval and analysis run against the customer's own collected evidence, ingested through legal hold, preservation and collection from named enterprise sources, so the corpus is the document universe for the matter and its provenance is the discovery process. Searched the aiR pages, the artificial intelligence overview and the data solutions pages on 29 Aug 2026 and located no vendor supplied legal corpus, no licence basis and no update cadence, and none would be expected. One adjacent capability was considered and not treated as a corpus: the platform can carry coding decisions, compliance workflows and privilege calls from prior matters into new ones, which reuses the customer's own past work product rather than any vendor held material.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Searched the aiR product pages, the artificial intelligence overview, the data solutions pages and the learning centre on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is an ediscovery and investigation platform whose corpus is collected evidence rather than published case law, so a citator is outside its design entirely, including for aiR for Case Strategy, which builds argument from the document record rather than from authority.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Searched the aiR product pages, the artificial intelligence overview, the data solutions pages and the learning centre on 29 Aug 2026. No published material describes what the product does when the evidence does not support a determination, and no explicit no answer path was located. Two adjacent features were considered and not treated as satisfying this signal. Every aiR decision carries a rationale, which explains a determination that was made rather than declining to make one. And aiR for Privilege produces a prioritised queue surfacing high probability privileged documents, which is ranking by confidence rather than an abstention path, and no confidence threshold exposed to the user was located. For a privilege product the question of what happens on a genuinely ambiguous document is the sharpest version of this signal and it is unaddressed.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note the exposure differs from a research tool: this product analyses collected evidence rather than generating citations to authority, so its characteristic failure would be a wrong privilege call or a mischaracterised document rather than an invented case, and neither would ordinarily surface in a hallucination database.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
Searched the aiR product pages, the artificial intelligence overview, the data solutions pages, the certification programme pages and the learning centre on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512 and state bar guidance. Also not located, and more surprising for this vendor: any engagement with the Federal Rules of Civil Procedure or with the substantial body of case law on technology assisted review and defensible process, which is the natural professional touchstone for an ediscovery platform marketing defensibility. The vendor publishes AI Principles governing its own conduct and a certification programme establishing operator proficiency, neither of which engages with the professional rules binding its users.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Savings are claimed and quantified in partner material with nothing published on the client's side of the equation. The vendor's framing is cost and time reduction: automating privilege review to increase productivity and reduce cost, identifying impactful content in substantially less time, and reducing cost and response time across matters by carrying prior coding decisions forward. A Relativity Gold Partner published a case study recording 610 hours saved in privilege review on a 30,000 document analysis. Privilege review is billed work, and 610 hours is a large number in that context. Searched the aiR pages, the data solutions pages and the learning centre on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment. Recorded at savings claims only.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
Some genuinely useful material is published and the artifacts this signal names are not. Available: identification of Microsoft Azure as the platform, the disclosure that the vendor opted out of Microsoft abuse and harmful content monitoring so provider personnel cannot reach raw inputs and outputs, and a statement that Azure's security and privacy posture is reviewed in depth at least annually. A firm could forward the abuse monitoring point usefully, since it answers a question client AI clauses increasingly ask. But searched the aiR pages, the artificial intelligence overview, the data solutions pages and the learning centre on 29 Aug 2026 and located no subprocessor list, no named security certification, no published data processing agreement, and no client facing consent or notification pack. Recorded as not addressed because no assembled material exists to point a client to.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
The most complete disclosure material of any ediscovery record here, assembled from product features rather than offered as a single artifact. Every aiR decision carries a rationale, so the basis for each determination is recorded per document rather than reconstructed afterwards. The vendor states full audit trails and documented data governance across the platform, and describes the aiR suite as designed to be transparent, reviewable and defensible, with defensibility a stated design goal rather than a marketing adjective. aiR for Privilege generates privilege log descriptions automatically, which is a court facing artifact produced as a by product of the AI work itself. Two elements are missing: no single per document export combining model used, sources retrieved and human verification was located, and no model is named in published material so the model used could not be stated. Recorded at partial record on that basis.