T
Theta Lake

Theta Lake is a digital communications governance and archiving platform for regulated organisations. It captures, archives and supervises the content of collaboration tools across voice, video, chat, mobile messaging, email and whiteboards through more than a hundred API integrations with platforms including Microsoft Teams, Zoom, Webex, RingCentral, Slack and Symphony, and applies patented machine learning and natural language processing to detect compliance, conduct and data protection risks in what is shared, shown, spoken and typed.

The suite has three products: Unified Capture, Unified Search and Archiving, and Proactive Compliance. Legal teams use it for legal hold, preservation, eDiscovery and defensible production across modern communications, including through an integration with Relativity, and the archive supports SEC 17a-4 WORM retention with customer-set retention rules, selective non-retention and a choice of storage region. A separate AI interaction governance module extends the same capture, detection and legal hold workflow to employees' interactions with AI assistants including Microsoft Copilot, Zoom AI Companion, Anthropic's Claude and OpenAI's tools, with classifiers for prompt injection, jailbreak behaviour, shadow AI and sensitive information sharing.

The company is independent, headquartered in Santa Barbara, California, with a second office in New York, and holds ISO/IEC 42001 certification alongside annual SOC 2 Type 2 and PCI DSS audits.

Vendor siteSanta Barbara, California, United States
Last verifiedSeptember 12, 2026
Compare with other vendors

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Remove the models and a capture, archive, search and legal hold platform remains, which is the B band exactly. Unified Capture and Unified Search and Archiving are ingestion and retrieval across more than 100 certified API integrations, and the SEC 17a-4 WORM archive, the eDiscovery export and the custodian legal hold workflow all function without a model. Proactive Compliance is where the models are the engine of a core capability: patented machine learning and NLP detection across what is shared, shown, spoken and typed, more than 80 built-in and custom policies driving that detection, and the aiComms classifiers for prompt injection, jailbreak behaviour, shadow AI and unethical summary steering.

The vendor's own framing on the AI Communication and Interaction Governance page, modified 14 July 2026, is a governance and detection layer added over the capture substrate. Verified 12 September 2026.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

R15 governs. This product cites no legal authority, so the citator limb and the primary-authority limb do not apply to the product class and are neither credited nor penalised. What bites is grounding and hallucination disclosure, and both are real. Every detection resolves to the captured interaction it came from, with contextual investigation views, timeline views, replay and add-to-case navigation documented on the product and AI governance pages, so a reviewer opens the source content rather than a summary of it, and Proactive Compliance publishes built-in audit and explainability reporting for ML and AI systems.

The hallucination disclosure sits in the agreement rather than the marketing: MSA clause 10(d) states that output is generated by machine learning capabilities, warrants nothing as to accuracy, completeness or reliability, notes that output may differ between runs, and places evaluation on the customer including human review. What keeps this off A is that no measured detection accuracy, recall or precision figure is published on any surface located, and no test set is described. MSA updated 12 March 2026; verified 12 September 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Review surfaces are real and documented: automated multi-party review workflows that route by detection, contextual investigation and timeline views, role-based access control on private links into those views, bidirectional alert integration with SIEM and SOC tools, and customer-parametrised compound detection rules that set what fires. The limb the B band names as commonly absent is absent here. The vendor states in the same material that the system acts alone in places -- patented risk remediation and prevention, automatic application of legal hold to AI summaries for custodians in legal matters, real-time policy notifications and disclaimers inserted into Microsoft Teams conversations, and dynamic retention rules deciding what is not retained -- and the threshold at which any of that proceeds without a reviewer is not published.

R37 rule 2 governs: the tension between assisting reviewers and acting automatically is not a reason to downgrade for the contradiction as such, it identifies the missing limb, and the grade goes there. MSA clause 10(d) allocates evaluation of output to the customer. Verified 12 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

A named customer with a named role and a specific deployment: the Head of Technology at Longview Partners, on MiFID II compliance for Microsoft Teams, quoted on the vendor's own site. No figures accompany it, which is the B band's stated shape of a named customer without measurement. Analyst recognition is extensive and is recorded rather than credited, because analyst placement is not deployment evidence: Furthest in Vision in the 2025 Gartner Magic Quadrant for Digital Communications Governance and Archiving, ranked first in five of six use cases in the Critical Capabilities companion, and a Gartner Peer Insights listing. A case studies library is published and was not opened. Verified 12 September 2026.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

The commitments are contractual and readable before signing, which is more than most of this corpus offers, and the A band's privilege limb is absent, which R33 makes decisive. Published and read: MSA section 1(d) defines Customer Data, Reports and Output as the customer's Confidential Information; the data licence in section 5(a) confines Theta Lake's use of Customer Data to providing the Service, generating Output and Reports, and creating Usage and Anonymized Data, for the Subscription Period only; the DPA's United States schedule states the vendor will not retain, use, disclose, sell or share Personal Data other than to provide the Services on documented instructions, and will not combine it with data from other entities; DPA section 8 commits to deletion or return on written request; retention is customer-set; and MSA section 8(c) commits to notice before any compelled disclosure.

Two limbs keep this at B: nothing located addresses privilege or work product treatment, and no position is published on what any third-party model provider may retain. MSA updated 12 March 2026, DPA updated 2 July 2025, both read in full on the support portal; verified 12 September 2026.

Source: Vendor Published
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

A real published position on advice versus tooling, and it sits in the instrument that governs the product rather than in a website notice. MSA clause 10(d) states that output is machine-generated, may contain errors and misstatements, may be incomplete or inaccurate, does not represent Theta Lake's views, and is the customer's sole responsibility to evaluate for accuracy and appropriateness including by human review.

Who may use it is stated as well: Authorized Users named under an Order Form, for the customer's internal business operations. Real Time Advisor delivers the customer's own policies, training links and disclaimers rather than legal conclusions. Short of the full band on two counts: nothing addresses a supervising lawyer's competence and supervision duties, and no jurisdiction limits are stated for a product sold across the US, UK and EU.

R15 applies to the consumer-facing limb, which does not bite on an enterprise platform with no public-facing advice surface. R50 noted: the separate website terms of use govern the site and are not the instrument graded here. Verified 12 September 2026.

Source: Vendor Published
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

ISO/IEC 42001 certification, and R36 sets the band: an independently audited AI management standard is real substance short of testing results or a named owner. This record carries more than the Ontra precedent and still reaches none of the A limbs. Published: ISO/IEC 42001:2023, a CSA AI Trustworthy Pledge 2025 listing on the trust centre, and classifiers described as certified, safe and transparent for detecting AI interaction risks.

Absent: no accountable owner inside the vendor is named, no pre-release testing regime is described, and nothing is published about uneven output across content types, languages or populations for a detection product whose false negatives are themselves a compliance failure. One discrepancy belongs on the record: the AI governance page claims CSA STAR for AI Level 2 while the trust centre's own compliance list shows CSA STAR Level 1.

A 'How We Use AI' security document is named on the trust centre behind an access request and was not obtained. Verified 12 September 2026.

Source: Vendor Published
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

All five A limbs are published, contractual and specific. Retention is customer-set with explicit non-retention available, recorded in DPA Annex II as limited retention on durations defined by the data exporter and in the privacy policy as customer control with multiple retention periods. Deletion sits in DPA section 8, with deletion certification on written request under the SCC modifications and self-service export to the customer's own S3 bucket, Azure Blob container or O365 account under MSA section 4(b).

Access control covers encryption in transit and at rest, customer-specific keys with an option to manage them independently in AWS or Azure KMS, SAML single sign-on, role-based access control and two-factor authentication. Incident practice is a contractual commitment in DPA section 4(b) to notify without undue delay with available detail, mitigation taken and recommended customer steps. The fifth limb, subprocessor disclosure, is satisfied on the agreement's own terms: the DPA obliges the vendor, on engaging any new subprocessor, to update the Subprocessor Site with that subprocessor's name, location and the activities it will perform; a customer may object in writing on reasonable grounds relating to the protection of personal data, the parties must work in good faith toward a resolution, and if none is reached within thirty days the customer may terminate the agreement as its sole and exclusive remedy.

Execution of the DPA is also execution of the Standard Contractual Clauses and their annexes. AMENDED 12 September 2026, from B, on evidence located after the row was first written. The row previously sat at B because the subprocessor list itself was refused to this index's fetcher and R25 forbids asserting a top band on an unopened artifact. R25 addresses artifacts that are ungated and were simply not read; this one is machine-refused, and holding the grade down for that would turn a limit on the reader into a finding against the vendor, which section 6.6 forbids.

What the vendor publishes is established: a contractual subprocessor disclosure obligation, a named site carrying it, change notification, an objection right and a termination remedy. The identity of the individual subprocessors was not read and is not asserted here. Verified 12 September 2026.

Source: Vendor Published
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

An unusually complete published position that still stops short of what the A band asks. MSA section 11(a) gives a defence and indemnity against third-party patent, trademark and copyright claims arising from the Theta Lake Assets including the customer's permitted use, with named carve-outs for unauthorised use, reproduction or modification, a repair-replace-refund election, and an express statement that this is the sole and exclusive remedy for IP claims.

Section 12 caps collective liability at the fees received in the twelve months before the event and defines Uncapped Claims to include gross negligence, recklessness, intentional misconduct and violation of the other party's IP. Exhibit A warrants 99.999% system availability with a service-credit schedule at three thresholds and a claim procedure a customer can actually run. What the vendor stands behind when its output is wrong is answered expressly and in the negative: clause 10(d) disclaims all warranty as to accuracy, completeness and reliability of machine-generated output, no output indemnity is offered, and no insurance is named anywhere located.

The A band asks what the vendor stands behind when the system is wrong; the published answer is nothing, which is complete disclosure rather than a top-band position. R50 noted: the website terms of use are a different instrument and do not grade the platform. Verified 12 September 2026.

Source: Vendor Published
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

More than 100 API-based capture integrations, built in-house and certified by the platform partners, published by category with a page for each: Microsoft Teams, Zoom, Webex by Cisco, RingCentral, Slack, Symphony, Verizon, Asana, Mural, CrowdStrike Falcon Next-Gen SIEM and others, across unified communications, contact centre, whiteboards, content management, mobile and text, email, voice, cloud storage and archives, social and financial messaging.

Depth is described where it matters for evidence: what is captured per modality, bidirectional alert integration with SIEM and SOC tools, an open developer platform with endpoints to automate workflows and extract interactions and enrichment data, export to the customer's own S3, Azure Blob or O365 under MSA section 4(b), and a documented Relativity integration for full-context eDiscovery and legal hold. The A band asks for the systems legal work already lives in, and that is where the estate thins: Relativity is the one legal system integrated, and no document management or practice management connection was located. Verified 12 September 2026.

Source: Vendor Published
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Tenancy is stated and residency is offered, which is B on the band as amended. The security architecture page states dedicated server environments at AWS and Azure. The AI governance page states that customers can selectively collect and apply dynamic archiving retention rules deciding which records to keep, for how long and in what region, with the ability to store in any and multiple locations to meet any state or national data sovereignty requirement, and the trust centre carries separate AWS and Azure infrastructure entries.

What is not published is the list of regions actually available, what changes between tiers, and where processing happens as distinct from where data is stored, which is the separation the A band asks for. A regional endpoint is visible in a product screenshot. R38 is satisfied on tenancy alone in any event, and the residency material here goes beyond that. Verified 12 September 2026.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

A live SafeBase trust centre at trust.thetalake.com, reachable without a sales call and not linked from the main site's navigation or footer, naming SOC 2, PCI DSS, SEC Rule 17a-4, ISO/IEC 42001:2023, ISO/IEC 27001, TruSight, CSA STAR Level 1, the CSA AI Trustworthy Pledge 2025, GDPR, CCPA, CPRA and PIPEDA, and listing the artifacts behind them: SOC 2 report, ISO 42001 certificate, PCI-DSS AOC, penetration test report, Information Security Policy, STAR3 security architecture and a subprocessors entry.

The privacy policy states the SOC 2 Type II and PCI DSS audits are annual and that SOC 2 controls are mapped to ISO 27001 and HIPAA, and the MSA makes the most recent audit report available to customers on the support portal. What holds this at B is that the reports sit behind a Get access request whose tier the portal does not state, and no attestation scope or date appears on the ungated surface, so R5's closing rule applies: describe what was seen and grade the lower tier.

Two discrepancies belong on the record: the trust centre lists CSA STAR Level 1 while the AI governance page claims CSA STAR for AI Level 2, and the trust centre lists ISO/IEC 27001 as a compliance item while the security architecture page says only that controls are aligned with it. No auditor is named on any ungated surface. Trust centre read 12 September 2026.

Source: Vendor Published
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The detection stack is described as patented, in-house machine learning and natural language processing with built-in classifiers and compound detection rules, and nothing published names a model or identifies a provider underneath it, which is the C band. The AI vendors named on the integrations page -- Anthropic, OpenAI, Microsoft Copilot, Zoom AI Companion -- are the objects this product governs, not disclosed suppliers to it, and spending a governance fact on a supply-chain axis would be the double-credit error the ground rules name.

Customers may bring their own classification tools and models to run against aiComms, which is extensibility on the customer's side rather than disclosure of the vendor's. A 'How We Use AI' security document is named on the trust centre behind an access request and was not obtained: gated, not absent. R34 noted: the DPA's subprocessor change-notification commitment cannot move this axis while the models are unnamed, and it is credited on the outside counsel guideline signal instead. Verified 12 September 2026.

Source: Vendor Published
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Real pricing is published for part of the charge, which is the B band. The vendor's own AWS Marketplace listing, where Theta Lake is the seller of record and the listing content is the vendor's, publishes two platform tiers with annual figures -- SMB covering up to 999 users at $15,000 for a twelve-month contract, Enterprise covering 1,000 or more users at $50,000 -- states that the platform subscription is charged per app integration, and states that both tiers additionally require a separate per-user-per-year content SKU priced by content type across video, voice and chat.

That per-user rate is the part that scales with the organisation and it is not published anywhere located, which is what keeps this off A along with silence on implementation. The vendor's own website carries no pricing page at all: every call to action on thetalake.com is a demo request. The refund position is published on the same listing, with fees non-cancellable and non-refundable except as required by law. Also recorded: RingCentral MVP customers are stated on the vendor's site to receive advanced archiving and eDiscovery capability through that reseller relationship. AWS Marketplace listing read 12 September 2026.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Who this serves is described with real substance and the boundaries are left open, which is B. Industries are named and each carries its own page: financial services, state and local government, healthcare and telemedicine, education, and manufacturing and technology. The buying functions are named directly in the product material rather than as a tricolon: security and governance teams, compliance teams, retention and technology teams, and legal and eDiscovery teams, the last with specific promises about preservation, evidence sets and defensible productions.

Regulatory coverage is specific, with pages for SEC 17a-4, CFTC 1.31, MiFID II, GDPR, HIPAA and CCPA. R15 applies to two limbs: law firm segment sizing and practice-area support do not bite on a platform bought by an enterprise compliance and legal function rather than by a practice group, and are neither credited nor penalised. What is not stated is where coverage stops: no jurisdictional or platform limits are published and nothing addresses what the product does not support. Verified 12 September 2026.

Source: Vendor Published
Sources on file

5 public documents

The public pages on file for Theta Lake, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.

Pricing

From $15,000 per yearUSD, as published, never converted

  • These figures are the AWS Marketplace price, published by Theta Lake as the seller on that marketplace; buying direct from the vendor may cost something different.
  • Theta Lake charges an annual platform fee plus a charge for every person whose messages it watches.
  • The platform fee is $15,000 a year for up to 999 people, or $50,000 a year for 1,000 or more.
  • The per-person charge depends on whether you keep chat, voice or video, and that number is not published anywhere.
  • Nothing about price appears on the company's own website, and once you sign up the fees cannot be cancelled or refunded.

Two annual platform tiers are published on the vendor's AWS Marketplace listing, where Theta Lake is the seller of record: the SMB platform covers up to 999 monitored users at $15,000 for a twelve-month contract, and the Enterprise platform covers 1,000 or more users at $50,000. The platform subscription is charged per app integration. Both tiers additionally require a separate per-user-per-year content SKU priced by content type across video, voice and chat, and that rate is not published on any surface located, so the figure recorded here is a platform floor rather than a total cost.

A user is described as an individual whose communications are captured, archived and supervised, and the same count drives both the tier and the per-user charge. Crossing 999 users moves the subscription to the Enterprise tier and does not happen automatically. Fees are non-cancellable and non-refundable except as required by law. Nothing about price appears on thetalake.com, where every call to action is a demo request.

Separately, the vendor states on its own site that RingCentral MVP customers receive advanced archiving and eDiscovery capability through that reseller relationship.

Confidentiality and data terms: The Data Processing Addendum is published in full on the vendor's support portal and is accepted by conduct rather than negotiated; it incorporates the EU Standard Contractual Clauses and, for UK transfers, the IDTA or UK Addendum. HIPAA controls are stated as implemented and mapped through the annual SOC 2 Type II audit. No business associate agreement was located on any surface.

Note: Figures read from the vendor's AWS Marketplace listing on 12 September 2026. The listing is vendor-authored seller content carrying the vendor's own EULA and refund policy, which is why it is treated as vendor-published rather than as the aggregator or directory listing the ground rules exclude; the surface is named in the Commercial Transparency note for the same reason. No pricing page exists on thetalake.com. The per-user-per-year content rate, which is mandatory on both tiers, is withheld.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Purpose limited, in the contract

The customer agreement or data processing addendum contractually limits use of Customer Data to providing the contracted service, and no surface names training either way. The limit is bound, which a policy page is not, but it is not an express training prohibition. If any surface names training in either direction, one of the other values is true and this one is not.

The Master Services Agreement, updated 12 March 2026, confines Theta Lake's use of Customer Data to three enumerated purposes tied to service provision -- providing the Service, generating Output and Reports for the customer, and creating Usage Data and Anonymized Data -- under a limited licence running only for the Subscription Period, and the DPA's United States schedule states the vendor will not retain, use, disclose, sell or share Personal Data other than to provide the Services on the customer's documented instructions.

No surface located names training in either direction: not the agreement, not the DPA of 2 July 2025, not the privacy policy updated 8 January 2026, not any product page. Two qualifiers belong on the record. Anonymized Data is defined as data derived from Customer Data with all personal identifiers removed and then aggregated, is expressly not Customer Data, and may be used to improve and develop the Service, with the customer able to opt out of its creation and use by emailing the vendor's legal address.

Usage Data is telemetry, anonymised and aggregated, and is also used to improve and develop the Service. Neither clause names machine learning, models or training, so neither is recorded as a training permission.

Source: Vendor PublishedTheta Lake uses Customer Data to: (i) provide the ServiceAs of Sep 12, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Customer set, zero available

The customer sets the retention window and no retention is an available setting.

Retention is customer-set and no retention is an available setting. The AI Communication and Interaction Governance page states that customers can selectively collect and apply dynamic archiving retention rules to decide which records to keep, for how long and in what region, as well as what to explicitly not retain, alongside WORM with 17a-4 attestation options. The privacy policy states customers control retention settings in the Services and can apply multiple retention periods to their data, and DPA Annex II records limited data retention on durations defined by the data exporter.

Deletion is separately committed in DPA section 8. The material retained is captured communications, AI interaction records and generated Reports rather than a lawyer's prompts to a drafting assistant, which is the shape this signal takes on a communications archive; the vendor also states it retains backups for business continuity and disaster recovery.

Source: Vendor Publisheddecide which aiComms records to keep for how long and in what regionAs of Sep 12, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Own model, documented

The product maintains its own permission model, documented, requiring the firm to keep it aligned.

The product runs its own permission model rather than enforcing a document management system's access model at query time. What is documented: role-based access control, including RBAC applied to private links into contextual investigation views, group and role-based policy notifications, SAML single sign-on federated to the customer's identity provider, two-factor authentication, and DPA Annex II measures for user identification and authorisation.

The trust centre carries separate access control, data access, access monitoring and logging entries, all behind an access request. No ethical wall, conflicts check or matter-level segregation construct was located on any surface: legal hold cases exist as a workflow object but are not described as an access boundary, so a firm would have to keep the product's roles aligned with its own walls itself.

Source: Vendor PublishedMeasures for user identification and authorizationAs of Sep 12, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Notice committed

Terms commit to notice where lawfully permitted. No transparency report located.

Both instruments commit to notice and neither publishes a transparency report. MSA section 8(c) permits disclosure of the other party's confidential information where required by law including by court subpoena, but only where written notice is given first so the disclosing party can contest the disclosure, seek to limit it or obtain a protective order, and requires that only the legally required portion be furnished with confidential treatment sought for it; Customer Data, Reports and Output are the customer's Confidential Information under section 1(d).

DPA section 6(b) commits that on receipt of a binding public authority order for Personal Data the vendor will notify the customer unless legally prohibited, and Schedule 1 section 4(l) directs SCC clause 15 notification to the customer rather than to data subjects. No transparency report and no figures on requests received were located on any surface, which is what separates this from the top value.

Source: Vendor PublishedCompany will notify Customer of the request unless otherwise legally prohibitedAs of Sep 12, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Not addressed

No located public material identifies the corpus behind the product’s answers.

No primary law corpus is identified because the product does not use one. This platform answers from the customer's own captured communications -- voice, video, chat, mobile messaging, email and whiteboard content ingested through certified API integrations -- rather than from case law or statute, so the provenance and licensing question does not arise in the form the signal asks it. What stands in its place is a published detection policy library of more than 80 built-in and custom policies mapped to named regimes including SEC 17a-4, CFTC 1.31, MiFID II, GDPR and HIPAA, each carrying its own regulation page. No third-party legal corpus is used, so no licensing basis is owed.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

The product does not cite legal authority, so no located material addresses checking subsequent history, and none would be expected of it. Detections reference the customer's own captured content and the vendor's policy library rather than decided cases. Recorded so the row states the position rather than leaving a reader to infer it from silence.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

No located public material describes an abstention path or what the system does when it cannot ground an answer. The closest published material is MSA clause 10(d), which states that output is machine-generated, may contain errors and misstatements, may be incomplete or inaccurate, may differ from one use to the next, and is the customer's sole responsibility to evaluate including by human review: that allocates responsibility for a wrong answer rather than describing abstention behaviour.

Detection output is surfaced as prioritised alerts into a review workflow, and no confidence or grounding score was located on any surface, so the confidence-signal value is not true of this record either.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

None located

No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.

No court order, opinion or disciplinary record naming this product or Theta Lake, Inc. was located as of 12 September 2026. Searches were run on both the product name and the company name against published trackers of AI hallucination decisions, including coverage of the Charlotin AI Hallucination Cases database, and returned nothing involving this vendor. This is a statement about the public record on that date and not a finding about the product. The product does not generate legal citations, which is the conduct those records address.

Source: Bar Guidance or Court RecordAs of Sep 12, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No located public material engages with bar or ethics guidance. The vendor publishes extensively on regulatory obligation -- SEC, CFTC, MiFID II, GDPR, HIPAA and state privacy law, each with its own page -- and an Ethics Policy is named on its trust centre behind an access request, but a corporate ethics policy is not engagement with the professional responsibility guidance a lawyer buyer is bound by, and nothing located addresses ABA Formal Opinion 512 or any state bar opinion on generative AI. Recorded as of 12 September 2026.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Outside the fee relationship

The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.

The product does not touch a fee between a lawyer and a client. It is bought by an enterprise compliance, security or in-house legal function to supervise and archive that organisation's own communications, and no client is billed for the work the detection performs. Savings claims are published -- reduced alert fatigue, lower investigation and review cost, and the cost of over-retention -- and they are aimed at the buyer's own operating cost rather than at a client invoice, so under the value's own terms they are recorded here and do not make this a savings-claims row. R21 noted: this signal is specific to AI-assisted billable work, which this product does not produce.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Subprocessors listed

A current subprocessor or model provider list is published.

A subprocessor list is published and contractually maintained, and the model provider limb is not met. DPA section 7 and Annex III place the list at a named URL on the vendor's support portal, require it to carry each subprocessor's name, location and the activities it performs, require the vendor to inform customers of intended additions or replacements, and give the customer an objection right with termination as the remedy if no resolution is reached.

The article itself was refused to this index's fetcher on 12 September 2026, so its contents were not read; the trust centre carries a subprocessors entry behind an access request. Forwardable client-facing material does exist in the published DPA, which satisfies the third limb of the top value, but no statement of which model providers see customer content was located on any ungated surface -- a 'How We Use AI' document is named on the trust centre behind the same request -- so the disclosure pack value is not available on the evidence.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

Elements of a record exist, short of a document-level export built for a court's AI disclosure. The product captures AI interactions as records identifying which assistant was used along with the prompts and responses, reconciles them into an interaction timeline, applies legal hold to that content automatically for custodians in a matter, keeps review actions and inserted policy notifications in an audit history that evidences what users were told, generates conversation audit reports, and exports to the customer's own storage.

What it does not produce is a per-document certification tying a named model, the sources it retrieved and a named human verifier to a filing, because the record it holds is of the organisation's communications rather than of a brief's drafting. A firm asked to evidence AI use in a matter would have material to draw on and would have to assemble the certification itself.

Source: Vendor PublishedAs of Sep 12, 2026Evidence
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 12, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746