StrongSuit
StrongSuit is a legal AI platform for litigators and transactional lawyers, sold by the month to individual practitioners and on a firm plan to larger teams. Its research module runs agentic retrieval over a proprietary database of more than ten million United States federal and state cases, enriched with metadata, summaries and issue tags, and returns answers, memos and early brief drafts with linked citations to the authorities relied on; a case validation feature launched in November 2025 checks whether cited cases have been overturned or superseded. Around that sit a general legal assistant, contract drafting from scratch or from the user's own templates, contract comparison and redlining against a chosen gold standard, a Microsoft Word add-in for negotiation, discovery document review across large sets, a timeline and statement-of-facts generator in beta, proofreading with multiple lenses, and an oral argument simulator. The vendor states that every draft, review and decision stays under the lawyer's control, that no model is trained on user content, and that the platform is hosted in a private Microsoft Azure tenant with data stored only in the United States, using models from OpenAI, Google and Anthropic. The company is StrongSuit AI, Inc., a Delaware corporation based in McKinney, Texas, formerly Callidus Legal AI until a rebrand on 12 November 2025; it publishes its terms of service, privacy policy and pricing openly, names ABA Formal Opinion 512 among the guidance it follows, and lists a chief legal officer and several solo and small-firm attorneys as customers by name.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The artificial intelligence is the product. Every module the site sells, research over the proprietary case database, memo and brief drafting, the assistant, contract drafting and redlining, discovery review, the timeline generator, proofreading and the oral argument simulator, is generative or agentic execution, and the home page describes the foundation as frontier models with retrieval-grounded reasoning. The case database is the one asset that would survive removing the models, and it is sold only as the corpus the research agents retrieve from rather than as a search product in its own right. The company was AI-native from its 2023 founding as Callidus Legal AI. Home page, solutions navigation and the November 2025 rebrand release read 6 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real and documented, and the accuracy figures are asserted rather than tested. Research output cites and links the authorities relied on, the home page states 100 per cent reference links to legal authorities and describes retrieval-grounded reasoning over a proprietary database of more than ten million federal and state cases enriched with summaries and issue tags, sample memos and a sample brief are downloadable, and the Search Cases pages show the underlying case records. Case validation, added at the November 2025 rebrand, checks whether cited cases have been overturned. Against that, the home page publishes 0 per cent hallucinations of case names in the research module with no test set, sample size, period or method, and the FAQ refers to proprietary anti-hallucination checks and rigorous evaluations without publishing any. Under the standing reading the bare-claim limb does not fire where architectural controls are documented alongside the claim, and they are here, but a percentage with nothing behind it does not reach the measured limb either. A Vals AI benchmark from February 2025 under the Callidus name exists as third-party material and is not credited to the current product. Home page, FAQ, solutions pages and rebrand release read 6 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A written commitment that the models work alongside a supervising lawyer with real review surfaces, short of the full control structure. The home page's lawyer-in-the-loop section states that every draft, review and decision stays under the lawyer's strategic control, the FAQ describes work traditionally handled by junior associates while the user retains final judgement, and the terms of service make the user solely responsible for reviewing, verifying and editing generated work before relying on it. Review surfaces are concrete: redlined Word files from proofreading, tracked edits through the Word add-in, and inline citations on research output. What is absent is the control structure the A band asks for: no thresholds, modes or escalation rules are described because the product does not act unattended, and nothing states what happens after an output is found wrong beyond the user's own correction. Home page, FAQ and terms section 2 read 6 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers without figures, and figures without named customers. Seven testimonials carry full names and roles: Erin Abrams, Chief Legal Officer at Via; Doug Johnston, a former general counsel; and five solo or small-firm attorneys including Yandy Reyes, Bryan Schwartz, Andrew Ayers, David Holt and Lindsey Lewis, each describing use in practice. Logos include Cooley and Klinedinst. None is joined to a measured change. The figures sit elsewhere and unattributed: 80 per cent time savings on a first redline, a 30-page memo in 15 minutes, and a CEO quote in the November 2025 awards release that many attorneys report doubling their output. A claim of 1,000-plus legal organisations is a count rather than evidence. Home page and rebrand-period releases read 6 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
All five limbs are in writing a buyer can read before signing, and the privilege limb is addressed in the agreement itself. No training: terms of service section 5.6 states that StrongSuit will not train any AI model with User Content, and the privacy policy of 16 March 2026 extends the guarantee to third-party models including sub-processors. Privilege and work product: terms section 5.3 acknowledges that user content may be privileged, deems StrongSuit a confidential agent of the user for support and maintenance, and states that any access is not intended to waive privilege, invoking Federal Rule of Evidence 502; the privacy policy repeats the position and treats sub-processors as functional equivalents of internal staff for that purpose. Segregation at the firm level: the FAQ states role-based permissions confine access to specific projects or documents within an organisation, and the security page describes session management and encryption to prevent leakage between sessions. Retention and deletion: unsaved inputs are discarded after generating the output, saved content is retained until subscription end and deleted after an administrative wind-down the policy gives as, for example, 90 days. Third-party providers: OpenAI, Google and Anthropic are named, processing occurs in a private tenant, and content is stated never to enter their public training sets. This is the first record in the pull to reach every limb and the note says so; the segregation limb rests on an FAQ description rather than a documented mechanism, which is the softest of the five. Terms, privacy policy, security page and FAQ read 6 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The vendor states plainly what the product is and is not, who may use it, and how it supports supervision duties. Terms of service section 2 states in capitals that StrongSuit is not a law firm, does not provide legal advice and does not practise law, that the services function only as a research, drafting and review tool, that they are intended solely for use by or under the supervision of a licensed attorney aged 18 or over, that no attorney-client relationship is created, and that the user is solely responsible for reviewing and verifying generated work. The security and ethics page names ABA Formal Opinion 512, Model Rule 1.6 and Resolution 604 and states that they require human oversight of AI-generated work and reasonable safeguards, which is the supervision and competence dimension stated with its source. The jurisdiction limb is met by scope rather than by a named exclusion: the corpus is United States federal and state law and the terms bar use from sanctioned jurisdictions. There is no consumer-facing surface, so that limb does not bite. One claim is carried as a claim: the page states the product is 100 per cent compliant with every US state's ethical rules as of March 2025, which is an assertion about the vendor's own review rather than a published mapping. Terms, security and ethics page read 6 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Responsible AI statements without a mechanism, a testing regime or anything a buyer could audit. The security and ethics page carries a Responsible Use of Generative AI section, but its content is data handling, that inputs are not trained on, not shared and discarded after output, and the home page refers to rigorous evaluations engineered for professional practice without publishing any. No governance framework, accountable owner, pre-release testing description, or statement about uneven output across practice areas or jurisdictions is published, and no ISO 42001 or equivalent certification is claimed. Security controls are graded elsewhere and do not count here. Home page, security and ethics page, FAQ and terms read 6 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy covering most of the ground, short of a stated incident practice and a formal sub-processor list. Retention: the security page states inputs are processed to generate the output and then discarded unless the user saves them, and privacy policy section 3 states client data is retained for an administrative wind-down after subscription end, given as for example 90 days, then permanently deleted subject to legal hold; user account data is deleted or anonymised within 90 days of closure and billing records kept seven years. Deletion: stated as above and made unrecoverable. Access control: two-factor authentication for staff touching customer data, role-based permissions, least-access support policy in the privacy policy, and audit trails on infrastructure and application activity. Sub-processors: Microsoft Azure for hosting and OpenAI, Google and Anthropic for models are named in prose in the privacy policy and terms section 6, with an open-ended and others and no list, locations or change notice. Incident practice: no breach notification commitment or incident process was located on any surface. Privacy policy, terms, security page and FAQ read 6 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Liability is addressed through a published limitation clause that disclaims the exposure the product creates, and a buyer can read the allocation of loss before signing, which is what separates this from D. Terms of service section 7.1 disclaims all warranties including any warranty about accuracy, completeness or reliability; section 7.2 excludes indirect and consequential damages including court-imposed fines and caps aggregate liability at fees paid in the twelve months before the claim; section 2 has the user assume all risk for decisions taken on the output, acknowledge that output may contain errors, and hold StrongSuit harmless for them; section 7.3 provides beta features without warranty or indemnity; section 8 is an indemnity running from the user to the vendor only. No vendor indemnity, insurance or warranty on output exists, and the terms state that a signed master services agreement governs over them where one exists, which is not published. Terms of service of 26 March 2026 read in full 6 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The integration surface is Microsoft Word and nothing else located. A Word add-in is sold as the Negotiate module and on the pricing page as seamless Word integration, and the terms define software add-ins such as for Microsoft Word as part of the services; the home page says it drafts contracts in Word and provides insights and clause suggestions on a document open there. That is a feature description rather than implementer documentation, though a Help Documents section exists and was not opened. No document management, practice management, e-billing, filing or matter system integration is named anywhere, and the FAQ's answer on replacing a patchwork of tools describes consolidation inside StrongSuit rather than connection to the systems a firm already runs. Home page, pricing page, solutions navigation, FAQ and terms read 6 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Tenancy and region are both stated, with the residency detail partial. The security page states hosting on a Microsoft Azure private tenant with high availability across multiple data centres, and the privacy policy states that all client data is stored on geographically redundant servers located exclusively in the United States and that model processing occurs within a secure private tenant environment. That gives the tenancy model, a single region and the processing location. What is not published is any region option beyond the United States, or any deployment difference between the Individual and Firm plans, although the home page refers to flexible licensing and deployment without saying what varies. Security page, privacy policy and pricing page read 6 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real and stated, short of accessible evidence. The security page states the company is SOC 2 certified with independent third-party verification, the pricing page lists SOC 2 Type II as a feature of every plan, and the home page carries a SOC 2 Type II image. No auditor, coverage period, scope or route to the report is published, no trust centre or request portal exists, and the security page's offer to walk through architecture and protocols is a sales conversation. The control descriptions themselves are specific, naming AES encryption at rest and in transit, two-factor authentication, routine vulnerability assessments, blue-green deployment and audit trails, and an optional PII scrub and end-to-end encryption for customers with heightened needs. Security page, pricing page and home page read 6 September 2026; security@strongsuit.com was not contacted.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Providers are named and the models are not. The privacy policy states the intelligence layer uses third-party large language models from OpenAI, Google, Anthropic and others under contracts requiring confidentiality, with processing in a private tenant so that data never enters the providers' public training sets, and that hosting is on Microsoft Azure; terms section 6 repeats OpenAI, Anthropic and Google as external providers whose terms the user must respect. The home page adds that the platform is powered by frontier models. No model is named, the list is open-ended, and no commitment to notify customers when a provider or model changes is published. Under the standing reading naming the provider does not satisfy the separate limb that the models are named. Privacy policy, terms and home page read 6 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Real pricing is published for part of the range with the firm tier withheld. The pricing page states an Individual plan at 249 dollars per month with its feature set, a Firm plan on custom quote adding onboarding, a success manager, centralised billing, user access management and collaboration, and a five-day free trial with a card required; the FAQ repeats the figure and mentions volume discounts. Terms section 4 publishes the mechanics: monthly or annual auto-renewal, 30 days' notice of price changes, no refunds, a fair usage policy on plans marketed as unlimited, and usage caps on documents, module use and model tokens whose limits are not published. Nothing states what implementation adds, and the Firm price is not published. Pricing page, FAQ and terms read 6 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment and practice coverage described with substance, with the boundaries left open. Segments are stated as solos and boutiques on the Individual plan and larger firms on the Firm plan, with in-house use evidenced by a chief legal officer testimonial; practice pages exist for family law, litigation and corporate work with an All Practice Areas page and a Topical Expertise page, and the corpus is stated as United States federal and state law with more than ten million cases. The vendor does not say where the product stops: no practice area, court or jurisdiction is named as unsupported, and coverage outside the United States is neither claimed nor excluded beyond the sanctioned-jurisdiction bar in the terms. Home page, pricing page, footer practice links and terms read 6 September 2026.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The published terms prohibit training on customer content. Not a policy page, the agreement.
The commitment is in the agreement. Terms of service section 5.6, last updated 26 March 2026, states that StrongSuit will not train any artificial intelligence models with User Content, defined in section 5.4 as the content and data the user provides to and creates with the services. The privacy policy of 16 March 2026 extends it as an explicit, non-negotiable guarantee covering proprietary and third-party large language models including those of sub-processors, and the security page and pricing page repeat it. Usage Data, defined in section 5.7 to exclude confidential information, may be used to develop and improve the services, which is telemetry rather than customer content. Surfaces checked 6 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
The customer sets the retention window and no retention is an available setting.
The customer decides what is retained and no retention is the default path: the security page states the AI processes an input only to generate the output and then discards it unless the user explicitly chooses to save it to their own account history. Saved content is governed by privacy policy section 3, which retains it for the subscription term, then for an administrative wind-down given as, for example, 90 days, before permanent deletion subject to legal hold; the customer is responsible for exporting before termination. The control is a per-output save decision rather than a configurable window, and the post-termination wind-down is the vendor's, which is why this value is recorded with that qualification rather than as a clean fit. Surfaces checked 6 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
The product maintains its own permission model and documents it at the level of a description. The data privacy FAQ states that access is controlled by role-based permissions so that only authorised users within an organisation can access specific projects or documents, the Firm plan lists user access management, and the security page describes session management and encryption to prevent leakage between sessions. Nothing describes how walls are enforced at query time or whether the model's retrieval respects project permissions, and the product does not inherit a document management system's access model because it connects to none. Surfaces checked 6 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.
Disclosure to authorities is addressed and customer notice is not reached. Privacy policy section 2 permits employee access to client data to comply with a legal order or regulatory obligation, and section 5 permits sharing user data to comply with laws, legal processes or other governmental requests; terms of service section 5.4 licenses processing of user content as may be required by applicable law. No commitment or reservation regarding notice to the customer appears in the terms, the privacy policy or the security page, and no transparency report is published. Surfaces checked 6 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Coverage is described by jurisdiction with no identification of the underlying corpus.
Coverage is described by jurisdiction and scale without identifying the underlying corpus or its rights basis. The home page and pricing page state a comprehensive database of more than ten million federal and state cases, the rebrand release adds that the company gathered the cases and built agents to enrich them with metadata, summaries and issue tags, and a Search Cases section exposes individual case records. Nothing states where the opinions were sourced, under what licence or public domain basis, or how often the corpus is updated; statutory and local materials are mentioned in third-party descriptions but not characterised on the estate. Surfaces checked 6 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
The vendor computes and surfaces subsequent history itself, with the method described.
The vendor computes and surfaces subsequent history itself. The rebrand release of 12 November 2025 introduces automated case validation, described as the most requested feature, which checks whether cases cited have been overturned, superseded or otherwise invalidated by later rulings, work the release says traditionally takes hours of tracing case history chains. No commercial citator is named, so the signal is the vendor's own. The method is described only at that level of generality; nothing published states how the history chain is computed, what sources feed it or how a negative treatment is surfaced to the user. Surfaces checked 6 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
No located public material describes what the product does when it cannot ground an answer. The home page refers to proprietary anti-hallucination checks and retrieval-grounded reasoning and publishes a 0 per cent hallucination figure for case names, and the terms require the user to verify all output, but nothing describes an abstention path, a confidence signal or the behaviour when the case database returns no support for a proposition. Home page, FAQ, solutions pages, security page and terms checked 6 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
No court order, opinion or disciplinary record naming StrongSuit or Callidus Legal AI was located as of 6 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on both names together with a general search for court findings; results returned sanctions involving general-purpose chatbots and other named legal tools, none of which is this product. This is a statement about the public record, not a finding about the product.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Public materials engage with at least one named ethics opinion.
Public materials engage with named ethics guidance. The security and ethics page states the company follows all ABA guidance including Formal Opinion 512 of July 2024, Model Rule 1.6 and Resolution 604, and summarises what they require as confidentiality, human oversight of AI-generated work and safeguards against unauthorised disclosure. It also claims the product is 100 per cent compliant with every US state's ethical rules as of March 2025 and that every relevant rule has been reviewed and mapped, but the mapping itself is not published; the linked slides covering the ABA, Texas and Florida opinions are attributed to another panellist rather than to the vendor. Surfaces checked 6 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure, and the product sits inside a fee relationship between a lawyer and a client where those savings would change the bill.
Time savings are published and nothing addresses the bill. The home page states 80 per cent time savings on a first contract redline, a well-cited memo of up to 30 pages in 15 minutes, guidance on a legal question in one minute, and the awards release quotes the CEO that many attorneys report doubling their output; the rebrand release describes good-law verification as frequently unbillable work now automated. The buyer is a law firm or solo practitioner billing clients, so the product sits inside the fee relationship. No per-matter record of AI-assisted work is described as available, and no guidance on fee or disclosure treatment is published. Surfaces checked 6 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
A current statement of which model providers see client content is published, as prose rather than a register. Privacy policy section 2 names Microsoft Azure for hosting and OpenAI, Google, Anthropic and others for models, states that processing occurs in a private tenant and that content never enters the providers' public training sets, and terms section 6 names the same three providers. The list is open-ended, carries no locations or change notice, and no client-facing disclosure pack or data processing agreement is published that a firm could forward; the privacy policy's privilege and no-training language would serve that purpose in part but is not drafted as a forwardable annex. Surfaces checked 6 September 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Some elements of a disclosure record are available and no document-level export is described. Research and drafting output carries inline citations with links to the authorities relied on, the home page states 100 per cent reference links and full traceability, and the security page describes audit trails at the application level. Nothing states that a per-document record of the model used, the sources retrieved and the human verification performed can be exported, and the models are not named on the estate. The terms require the user to verify output before relying on it but supply no certification template. Surfaces checked 6 September 2026.