Relyance AI

Relyance AI maps where personal and sensitive data actually goes inside an organisation, and ties each flow to the obligation that governs it. Rather than relying on questionnaires and manually maintained inventories, it discovers data movement from multiple points at once, reading source code, watching runtime behaviour, scanning contracts and connecting to systems directly, and assembles the result into a live graph its Data Journeys technology maintains from code through cloud infrastructure to AI models. The Data Exposure Graph joins three things that are usually tracked separately, being what data is sensitive, which identities hold permissions over it, and how AI agents behave, so that risks appearing only at their intersection become visible. On top of that sit three product layers. Privacy automation generates records of processing activities and data maps from live flows and runs consent, assessments and data subject requests end to end, with templates for DPIAs, transfer impact assessments, legitimate interest assessments and vendor reviews. AI governance inventories every agent, model, retrieval system and MCP server, detects each one's permission reach, and can block an over-scoped agent in the CI/CD pipeline before it ships. Data security classifies sensitive information and watches it in motion. A runtime enforcement layer that resolves each request as allowed, redacted, masked, narrowed, escalated or blocked is in private beta. Setup is agentless. Customers include Notion, Yelp, DuckDuckGo, Logitech, Ancestry, Grafana, Samsara, Zuora, ClickUp and Zscaler. Relyance Inc. is based in San Mateo, California, and was co-founded by a data privacy lawyer and a machine learning engineer.

Vendor siteSan Mateo, California, United States
Last verifiedSeptember 2, 2026

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The models are the mechanism and the company draws the distinction itself. Its about page states that it is not a legacy tool retrofitted with AI but was built from first principles for a world where data behaviour is non-deterministic, and that the old paradigm of scan, classify and lock no longer holds because scanners can tell you what your data is but not where it came from or what it is doing. What is sold is the inference: code analysis that reads how data moves through a repository, runtime monitoring, machine learning contract analysis that ties obligations to flows, classification of sensitive data, and behavioural analysis of AI agents, unified into a live graph. There is no content asset and no conventional product underneath; the substrate is the customer's own code, systems and contracts, and the graph exists only because the models build it. The comparator the company names is manual inventories and questionnaires, which is the work the platform replaces rather than accelerates. Verified 2 September 2026.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Grounding is documented at an architectural level and never measured. The discovery method is described concretely rather than asserted: multi-point discovery through code analysis, runtime monitoring, contract scanning and system integrations, with every data flow stated to be mapped to its business purpose, legal obligation and risk. That is a traceable chain from a finding back to the source that produced it, and it is the design claim the whole product rests on, expressed as reading the story of the data rather than scanning its contents. What is absent is any measurement of whether the inferences are right. No accuracy, precision or false-positive figure is published anywhere, no evaluation or benchmark is described, and nothing states how a classification or an obligation mapping is validated. That gap has weight on this product because a missed flow reads as compliance where none exists, and a wrong obligation mapping produces a record of processing activities that is confidently incorrect. Nothing addresses hallucination in the assessment-drafting features either. Verified 2 September 2026.

Source: Vendor Published
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

The action set is enumerated unusually clearly and the control around it is not. Published material states that a request can be resolved in real time as allowed, redacted, masked, narrowed, escalated or blocked, and that the decision is computed at the moment it matters rather than from static allow-lists. Naming escalation as one of six outcomes implies a human path, and the CI/CD integration is described as flagging a risky change before merge, which places a decision point in an existing engineering review. But nothing states what triggers escalation rather than a block, what confidence or severity threshold applies, who reviews an escalated request, or what a privacy team must approve before an automated enforcement takes effect. One scope limit belongs on the record and is treated as such rather than credited: the runtime enforcement layer that performs the blocking and redaction is marked PRIVATE BETA on the vendor's own navigation, so the most autonomous part of the product is not generally available and is not graded here. What ships is posture management that flags and maps. No published agreement places a review obligation anywhere. Verified 2 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

The reference base is substantial and the individuals are senior and named. Roughly twenty-four logos appear on the home page, spanning consumer technology with Notion, Yelp, DuckDuckGo and MyFitnessPal, hardware and industrial with Logitech, Samsara and Motive, data infrastructure with Grafana, Fivetran and Cribl, and security with Zscaler, alongside Ancestry, Zuora, Navan, Dayforce, Bolt, Insperity and ClickUp. Three customers speak on the record with name, title and a linked video story: Chris Bender, CISO at ClickUp, Jason James, CIO at Aptos, and Karthik Chakkarapani, SVP and CIO at Zuora, and the Zuora quote is substantive rather than promotional in describing the difference between a snapshot and continuous visibility. Two deployment figures are published, that more than 1,600 systems and 100 flows are mapped in under two hours agentless, and that six surfaces are unified in one graph. What holds this below the top band is method and dating: neither figure carries a measurement basis or a date, no figure is attached to any named customer, and the case studies are video rather than written. Verified 2 September 2026.

Source: Vendor Published
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Handling controls are published and the four limbs that matter most to a legal buyer are not. What exists is real: the trust centre publishes controls for retention of customer data, restriction of access to customer data on a least-privilege basis, disposal of customer data on request, segregation of development, staging and production environments, and a rule that production data is not used in development or testing except when required to debug a customer issue, all continuously monitored. Encryption is stated at rest and in transit. Against that, nothing addresses whether customer content is used to train or improve models, in either direction. Nothing describes segregation between customers as distinct from between environments. Neither privilege nor work product is mentioned anywhere, which bites here rather than not, because the platform generates and stores data protection impact assessments, transfer impact assessments and legitimate interest assessments, which are legal analyses a privacy counsel would often expect to be privileged. And no model provider is identified. The operative agreement is a master services agreement available only on request, so none of this is testable against a contract a prospect can read. Verified 2 September 2026.

Source: Vendor Published
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Nothing published addresses the advice line, and the marketing runs the other way. Checked the home page, the privacy teams, data and access governance, AI governance and privacy automation solution pages, the terms of use in full, the privacy statement in full and the trust centre on 2 September 2026. There is no statement that output is not legal advice, nothing on supervision or verification duties, and no jurisdictional statement. The terms of use are website terms and address the Website alone. What the vendor does publish points toward legal expertise rather than away from it: the privacy teams page states that Relyance uniquely combines legal expertise with technical discovery to eliminate the gap between documented policies and operational data practices, and company material foregrounds that a co-founder and co-chief executive is a practising data privacy attorney. The outputs are statutory instruments, being records of processing activities, data protection impact assessments, transfer impact assessments and legitimate interest assessments, each of which is a document a regulator may read and a controller must stand behind. A platform generating those, marketing legal expertise, and publishing no statement about the professional boundary sits at the bottom of this axis. Verified 2 September 2026.

Source: Operator Verified
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

The product governs AI and nothing published governs the vendor's own. Relyance publishes an AI Security Hub, an AI governance solution, blog material on AI governance failures and a survey on consumer AI trust, all of which concern what a customer should do about its models. Checked the home page, the about page, all four solution pages read, the terms of use, the privacy statement and the trust centre on 2 September 2026: nothing addresses Relyance's own models. There is no responsible AI page for the platform itself, no framework or set of principles, no individual or function named as accountable for model behaviour, no account of what is evaluated before a model or classifier change ships, and no ISO 42001 or equivalent certification. The trust centre's fifty-odd monitored controls are information security controls, and this axis treats those separately. Nothing anywhere addresses uneven output, which is a live question on a system that classifies sensitive data and maps legal obligations across jurisdictions, languages and codebases of varying quality. Verified 2 September 2026.

Source: Operator Verified
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

All five elements are addressed and the trust centre carries more published detail than almost any record in this corpus. Continuously monitored by Secureframe, it lists roughly fifty named controls with descriptions across change management, availability, organisational management, confidentiality, vulnerability management, incident response, risk assessment, network, access and physical security. Retention and deletion are covered by a data retention and disposal policy, a control for retaining customer data to agreed customer requirements, and disposal of customer data on customer request. Access control is granular, with least-privilege restriction on customer data, unique access identifiers, complex passwords with a second factor, scheduled user access reviews and removal of access on termination. Encryption is stated at rest and in transit. Incident practice is published as an incident response plan with documented tracking of identified incidents. A third-party network and application penetration test is conducted at least annually with critical and high findings tracked to resolution, vendor SOC 2 reports are collected annually, and cybersecurity insurance is procured. Two things hold this below the top band: no retention period is published, since retention is stated as whatever the customer agreed, and the subprocessor list exists but sits behind a request rather than on the page. Verified 2 September 2026.

Source: Vendor Published
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

The agreement exists, is obtainable, and is not published, so the allocation itself cannot be read. The terms of use on the website are explicit about their own scope and say so plainly: they govern the Website, and where a customer has signed an agreement covering the Relyance Platform, that signed agreement supersedes them. Those website terms disclaim all warranties and exclude liability for damages of any kind under any legal theory, with indemnity running only from the user to Relyance and disputes going to arbitration under California law, but under the rule that credit follows scope none of that describes what a platform customer receives. What lifts this off the floor is that the master services agreement and the data processing addendum are both listed in the trust centre and obtainable through a request flow, which is materially better than absent, and that cybersecurity insurance is published as a continuously monitored control, which is one of the four things this axis asks for and is rarely stated at all. What a prospect still cannot see before contacting the company is any cap, any indemnity, any warranty on output and any service level. Verified 2 September 2026.

Source: Vendor Published
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Integration is the product's core mechanism and it points at engineering systems rather than legal ones. Discovery is described as multi-point across code repositories, runtime environments, AI models and third-party processors, with an integration framework connecting to the wider data ecosystem, enforcement running inside CI/CD pipelines, and inventory extending to agents, models, retrieval systems and MCP servers. Setup is stated to be agentless with a first map in hours. That is real depth in the direction the product needs. What is missing is naming and documentation. Almost no specific system is identified: no repository host, cloud provider, data warehouse, identity provider or consent platform is named on any page read, the only concrete reference being consent signals captured from consent management platform software development kits. No connector list, no API reference and no developer documentation was located. And no integration into the systems a privacy or legal function itself runs is described, with no document management, matter management or GRC platform named, which matters because the buyer this axis grades for is the privacy team. Verified 2 September 2026.

Source: Vendor Published
DD on Deployment Model and Data ResidencyNothing published on where the software runs or where client data sits.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Nothing published addresses where the platform runs or how customers are separated within it. Checked the home page, the privacy teams, data and access governance, AI governance and privacy automation solution pages, the terms of use in full, the privacy statement in full and the trust centre in full on 2 September 2026. No cloud provider is named, no hosting region or country is stated for customer data, no residency option is offered, nothing distinguishes processing location from storage location, and no tenancy or isolation model is described. The trust centre publishes segregation of development, staging and production environments, which is an internal environment boundary rather than a tenancy statement. The only geographic material located concerns personal data transfers rather than platform hosting, with the privacy statement recording certification under the EU-U.S., UK Extension and Swiss-U.S. Data Privacy Frameworks. For a platform that reads a customer's source code and runtime traffic and is sold to European privacy leaders, the absence of any residency statement is a material gap. Verified 2 September 2026.

Source: Operator Verified
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

The trust surface is the strongest part of this record. A Secureframe-hosted trust centre renders publicly and continuously, listing SOC 2 Type 2, ISO 27001 and Data Privacy Framework participation under compliance, and making ten documents individually available, including the SOC 2 Type 2 report, the ISO 27001 certificate, a penetration test executive report, a CSA CAIQ version 4 self-assessment, a security whitepaper, the subprocessor list, the master services agreement and the data processing addendum. Roughly fifty named controls are published with descriptions rather than as a badge wall, which is more substance than most vendors expose without an agreement, and two documents are freely available, with the privacy statement viewable and the responsible disclosure policy downloadable. What is not established is the evidence itself. Every report and certificate sits behind a request control, and the portal does not state whether access is instant on an email, an NDA click-through or granted after review, so the lower tier is graded and the reason recorded. No auditor or certification body is named, and no report period, issue date or scope statement is published. No request was submitted. Verified 2 September 2026.

Source: Vendor Published
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

A proprietary engine is named and nothing underneath it is. The company brands its system Lyo, describing it as the world's first AI-native data defence engineer, and repeats that the platform was built on AI from the ground up rather than retrofitted, but no model is identified, no version, no provider entity, and nothing states whether any component is built in-house or reached through a third party. Nothing describes where inference runs, what any provider may retain, or whether customers would be notified if the model set changed. The subprocessor list that would ordinarily carry the answer exists and is listed in the trust centre, but sits behind a request rather than on the page, so a prospect cannot read it. The gap is more conspicuous here than on most records because the product's own function is to inventory every model, agent and retrieval system inside a customer's estate and tell them which ones touch sensitive data, while the vendor discloses none of its own. Verified 2 September 2026.

Source: Vendor Published
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

No pricing information is published at any level. Checked the home page, the platform page, the privacy teams, data and access governance, AI governance and privacy automation solution pages, the terms of use, the privacy statement and the trust centre, together with the full site navigation and footer, on 2 September 2026. There is no pricing page anywhere in the navigation or the footer, no tier or plan is named, no unit of charge is identified, and no structure is described, whether per user, per system, per data source, per scan or by subscription. Nothing states whether implementation or onboarding is charged separately, and no trial or free tier is offered. The only commercial routes are a demo request and an offer of a free exposure map, both of which lead to the same booking form. No pricing row is written, because the rule that triggers one requires published structure and none exists. Verified 2 September 2026.

Source: Operator Verified
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Regulatory coverage is named precisely and the buyer is described inconsistently across the site. On coverage the material is strong and specific: the platform is stated to support GDPR, CCPA, Global Privacy Control, ePrivacy, HIPAA and emerging EU AI Act requirements, with the consent layer continuously realigning purposes as those frameworks change, and the blog tracks individual state statutes such as Maryland's. That is a clearer statement of what body of law the product operates against than most records in this lane manage. Buyer documentation is where it wavers. A dedicated privacy teams page addresses privacy leaders directly and in their own terms, and the blog carries a Privacy and Legal Professionals category, but the home page is headed as an AI data security and governance platform, describes itself as trusted by security and governance teams, and all three customer voices are a CISO and two CIOs. A reader cannot tell from the site whether the platform is bought by the privacy function, the security function or both. No organisation size band is stated, no industry pages exist, and nothing describes where coverage stops. Verified 2 September 2026.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Terms silent

No located term or policy addresses the question either way.

Checked the home page, the about page, the privacy teams, data and access governance, AI governance and privacy automation solution pages, the terms of use in full, the privacy statement in full and the trust centre in full on 2 September 2026. Nothing addresses whether customer content is used to train or improve models, in either direction. No clause or statement names training, model training, machine learning or model improvement in relation to customer data. The nearest provision is in the privacy statement, which permits use of personal data to operate the Relyance Platform, provide related services and develop and improve the Relyance Platform and our other services; that is an improvement right, it does not name training, and under the naming test it does not move the value. The master services agreement and data processing addendum both exist and sit behind a request flow in the trust centre. One thing is worth recording because a reader will notice it: the product itself sells the answer to this question, with a published capability framed as proving that customer data was isolated and never used for AI training, logged as verifiable evidence rather than policy language. The vendor offers customers that assurance about their own vendors and publishes no equivalent statement about itself.

Source: Operator VerifiedAs of Sep 2, 2026

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Disclosed without a period

Retention is acknowledged in public materials with no stated period.

Retention is acknowledged in two places and quantified in neither. The privacy statement says personal data is retained only for as long as needed for the purposes described or as required by law, after which it is destroyed in accordance with data retention policies. The trust centre publishes three related controls, a data retention and disposal policy, a control stating that procedures are in place to retain customer data based on agreed-upon customer requirements or in line with information security policies, and a control providing that data no longer needed is removed from databases and file stores upon customer request in accordance with agreed customer requirements. Taken together those establish that a retention practice exists and is monitored, and that the period itself is set per customer in the agreement rather than published. No figure appears anywhere, nothing states how long discovered flow data, generated assessments, records of processing activities or scan results persist, and no retention setting is described as available to the customer in the product.

Source: Vendor PublishedAs of Sep 2, 2026

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Not addressed

No located public material addresses walls or matter level segregation.

Checked the home page, the four solution pages read, the terms of use in full, the privacy statement in full and the trust centre in full on 2 September 2026. Nothing describes segregation between customers or isolation of one organisation's data from another's. No tenancy model is stated. Two adjacent controls are published and both concern internal boundaries rather than boundaries between customers: development, staging and production environments are segregated, and access to customer data is restricted to personnel who need it on a least-privilege basis, with unique access identifiers and scheduled access reviews. Those describe how Relyance staff and systems are separated from customer data, not how one customer is separated from another. The question has particular weight on this product, because what the platform holds is a complete map of a customer's source code, data stores, identities and AI systems, which is close to a blueprint of the organisation's attack surface.

Source: Operator VerifiedAs of Sep 2, 2026

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Disclosure addressed, notice absent

Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.

Compelled disclosure is addressed and notice is never reached. The privacy statement states that Relyance may share personal data as quoted, and appropriate, to respond to a lawful order such as a subpoena or to comply with other applicable law, and adds that it may disclose personal data to government agencies to protect or enforce its legal rights or to protect, investigate or deter fraudulent, unethical or illegal activity. That second limb is Relyance's own determination rather than a legal compulsion. Nothing anywhere commits to telling the customer that a demand has arrived, nothing undertakes to seek confidential treatment or to allow the customer to intervene, and no transparency report was located. Nor does anything reserve discretion over notice, so the question is not answered in either direction. The master services agreement and data processing addendum sit behind a request flow and may address it; neither was requested.

Source: Vendor Publishedshare your personal data with government or law enforcement agencies as we believe necessaryAs of Sep 2, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Not addressed

No located public material identifies the corpus behind the product’s answers.

Checked the home page, the about page, the four solution pages read, the terms of use, the privacy statement and the trust centre on 2 September 2026. Relyance ships no corpus of its own and none is claimed. The material the platform works on belongs entirely to the customer: source code in its repositories, runtime traffic, contracts, cloud infrastructure, identity directories and AI systems, all discovered in place rather than assembled into a collection Relyance holds. The provenance and licensing risks this signal tracks therefore sit with the customer rather than the vendor, and the honest record is that the question is not addressed rather than that a corpus was withheld. One dependency is worth noting and is not described anywhere: the platform states that it maps flows to their legal obligations and continuously realigns them as regulations change, which requires a body of regulatory content from somewhere, and no source, publisher, update cadence or licence basis is identified for it.

Source: Operator VerifiedAs of Sep 2, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

Checked the home page, the four solution pages read, the terms of use, the privacy statement and the trust centre on 2 September 2026. No public material addresses whether the legal material behind an obligation mapping is current or how a user would know. The product does not retrieve primary law for a reader, so a citator in its usual form has nothing to operate on, but the analogous question is live and unanswered. The platform states that it converts regulatory requirements into operational guardrails, that unified obligations mapping ties every flow to its legal, contractual and policy requirements automatically, and that consent purposes are continuously realigned with evolving legal frameworks with obligations updated automatically as regulations change. Nothing states how quickly a change is reflected, what jurisdictions are monitored, who maintains the regulatory content, or whether a user is shown the version or effective date of the rule an obligation rests on.

Source: Operator VerifiedAs of Sep 2, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

Checked the home page, the four solution pages read, the terms of use, the privacy statement and the trust centre on 2 September 2026. Nothing describes what the platform does when it cannot determine an answer, and no confidence indicator is described as shown to the user for any classification, flow mapping or obligation assignment. Risk is scored, with compound risk stated to be scored across the graph rather than permission by permission, but that grades the customer's exposure rather than the system's confidence in its own finding. The enforcement action set does include escalation alongside allowing, redacting, masking, narrowing and blocking, which implies a path for cases the system will not decide alone, and nothing states what sends a request down it. A published third-party review notes the absence of ranking among identified risks; that is not first-party and is not relied on here.

Source: Operator VerifiedAs of Sep 2, 2026

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

Searched the AI Hallucination Cases database maintained by Damien Charlotin, and reporting drawing on it, on 2 September 2026 on the product and corporate name Relyance AI and Relyance Inc. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product. The signal fits this product class poorly and the reason is worth recording: the platform produces data maps, records of processing activities, assessments and enforcement decisions rather than legal citations, so its characteristic failure is a missed data flow or a wrong obligation mapping rather than a fabricated authority in a filing. That failure would surface as a regulatory finding, an enforcement action against the customer or a breach, none of which any tracker indexes in the way the hallucination database indexes court sanctions.

Source: Operator VerifiedAs of Sep 2, 2026Evidence
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

Checked the home page, the about page, the privacy teams and other solution pages read, the terms of use in full, the privacy statement in full and the trust centre on 2 September 2026. No public material engages guidance from any professional body governing the lawyers who use the product. No bar association material is named, ABA Formal Opinion 512 is not referenced, and nothing addresses the competence, supervision or candour duties of counsel relying on a machine-generated data protection impact assessment or record of processing activities. What the vendor engages extensively is legislation rather than professional conduct: GDPR, CCPA, Global Privacy Control, ePrivacy, HIPAA, the EU AI Act and individual state statutes are all named, and the company participates in privacy profession events. Naming the law a product helps a customer comply with is a different thing from naming the rules that govern the professional using it, and only the first is published.

Source: Operator VerifiedAs of Sep 2, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure.

Savings are claimed in headcount and time terms and the bill is never addressed. The published framing is that a customer can meet every privacy obligation without growing the privacy team, that manual inventories and questionnaires are replaced by continuous discovery, and that more than 1,600 systems and 100 flows are mapped in under two hours agentless from day one. Nothing addresses how AI-assisted work is recorded, billed or disclosed, and no per matter record of AI-assisted work was located. The signal's usual direction is inverted on this record, because the buyer is an in-house privacy or security function rather than a firm billing a client, so the compression accrues to the customer's own headcount rather than to an invoice. The nearest thing to the question the signal asks concerns outside counsel indirectly: assessments and records the platform generates are work that privacy counsel would otherwise scope to a law firm, and nothing published addresses how that shift is reflected in a firm's engagement.

Source: Vendor PublishedAs of Sep 2, 2026

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

On request only

The material exists behind a sales conversation or an executed agreement.

The material exists, is enumerated, and is not published. The trust centre lists a subprocessor list, a data processing addendum and a master services agreement as available documents, alongside a SOC 2 Type 2 report, an ISO 27001 certificate, a CSA CAIQ version 4 self-assessment, a security whitepaper and a penetration test executive report, each reachable through a request control rather than a download. That the artifacts are named and inventoried is itself informative and puts this above the bottom value. Two things are freely available and are the only forwardable material a prospect holds today: the privacy statement, which is public, versioned at 2.3 and links its own previous version, and the responsible disclosure policy. Public certification under the EU-U.S., UK Extension and Swiss-U.S. Data Privacy Frameworks is separately verifiable on the Department of Commerce register. No model provider is named anywhere, so even the requested subprocessor list is the only route to answering which AI providers touch customer content.

Source: Vendor PublishedAs of Sep 2, 2026

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Not addressed

No located public material addresses court disclosure or verification certification.

Checked the home page, the four solution pages read, the terms of use, the privacy statement and the trust centre on 2 September 2026. Nothing addresses disclosure of the platform's own AI use to a court, regulator or auditor, and no exportable record of which model or classifier produced a given determination, on what confidence, or who reviewed it is described. The distinction matters on this record because evidence generation is a headline capability pointed the other way: the platform is sold on maintaining complete audit trails, delivering defensible evidence of consent state changes to regulators and auditors, logging every data touch as verifiable evidence rather than policy language, and producing audit-ready proof on demand. All of that evidences the customer's data practices to a third party. None of it is described as evidencing how the platform itself reached a conclusion, which is what a customer would need if a regulator questioned a record of processing activities the system generated.

Source: Operator VerifiedAs of Sep 2, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 2, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746