T
Thirdfort

Thirdfort is a client due diligence platform used by law firms, conveyancers, estate agents and accountants to verify the identity and source of funds of the people they onboard. Thirdfort Limited is based at Victoria Station in London and is authorised and regulated by the Financial Conduct Authority under the Payment Services Regulations 2017. The platform covers five checks: identity verification, document verification, PEPs and sanctions screening, source of funds, and know-your-business checks on corporate clients. Verification runs either through an app the client downloads after an SMS prompt, or as a desktop check the firm completes without the client's involvement, and each check produces a downloadable PDF report the firm keeps as its compliance record. The identity check reads the cryptographic signing keys in an e-passport's NFC chip and is built to meet HM Land Registry's Digital ID Standard under Practice Guide 81, the Companies House identity verification standard for directors and persons of significant control, and the UK Digital Verification Services trust framework, under which Thirdfort appears on the GOV.UK register of digital identity services. Document verification is the AI capability: Thirdfort states that its artificial intelligence inspects every upload for signs of tampering, forgery and counterfeiting across the document's visual, data and metadata elements, covering documents from 195 jurisdictions, and cross-references every identity document against the Metropolitan Police's Amberhill database of documents reported lost or stolen. The reference data behind the checks comes from named suppliers whose flow-down terms Thirdfort publishes in full, including Onfido, Experian, ComplyAdvantage, iProov, Dun & Bradstreet and Kyckr. The company publishes a versioned legal estate covering terms of use, a data processing agreement, third-party product terms, an API agreement, an app licence and a security measures page, and holds ISO/IEC 27001:2022 certification and a DSIT certification as an Identity Service Provider. More than 1,500 regulated businesses use the platform.

Vendor siteLondon, United Kingdom
Last verifiedSeptember 7, 2026
Compare with other vendors

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The AI is real and vendor-claimed but it powers one product of five. Thirdfort sells identity verification, document verification, PEPs and sanctions screening, source of funds and know-your-business checks. Only document verification carries an AI claim, and it carries a clear one: a section headed An AI for detail, stating that artificial intelligence inspects every upload for signs of tampering, forgery and counterfeiting across visual, data and metadata elements, repeated in the FAQ in the first person as our AI. The flagship identity check makes no AI claim at all: its published mechanisms are cryptographic reading of the signing keys in an e-passport NFC chip and address matching against Experian data. The remaining products are screening and registry lookups against ComplyAdvantage, Dun and Bradstreet and Kyckr sources. Remove the models and four of the five checks are unaffected while document verification loses its detection engine. That restraint is itself evidence the claim is meant literally rather than decoratively, but it places the machine learning as a component of one module rather than the mechanism a buyer is paying for across the platform. Checked 7 September 2026.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Grounding is real, documented and unusually verifiable, and there is a contractual accuracy undertaking, but nothing measures the result. Every identity document is cross-referenced against the Metropolitan Police's Amberhill database of documents reported lost or stolen, which is an external authoritative check a buyer can name. The identity check validates the cryptographic signing keys inside an e-passport chip rather than inferring from an image. Reference data is attributed to named suppliers with published terms. Clause 6.1(b) of the Terms of Use commits Thirdfort to use all commercially reasonable endeavours to ensure Reports are in all material respects accurate and complete, which is more than most records on this axis carry, and the app applies documented guardrails that block blurry, cropped or oversized uploads before they reach the model. What is absent is measurement. For a forgery detection product the natural figures are a detection rate and a false positive rate, and neither is published, nor a test set, an evaluation, or any named failure mode. One tension belongs on the record: Thirdfort warrants report accuracy in its own terms while the supplier terms it passes through disclaim it, with Experian stating it cannot accept liability for any failure of its services to achieve a particular result and Kyckr disclaiming any warranty of accuracy, completeness or reliability. Grounding to primary legal authority does not bite on a due diligence product and is counted neither way. Checked 7 September 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

The route back to human judgement is contractual rather than advisory, which is rare on this axis. Clause 8 states that the Reports must not be relied on as the sole basis to make business decisions, that the firm is solely responsible for the conclusions drawn from them, and that Thirdfort provides no opinion and makes no recommendation on the treatment of results. The flow-down terms repeat it at supplier level, with ComplyAdvantage stipulating that results must not be used to draw any automatic conclusion or be relied on in isolation about any person flagged or not flagged. There is a review surface behind the words: the report presents flags in three states, showing what has passed, what is not relevant and what requires consideration, and the last of those is an explicit routing of the decision to a person. The uploaded document is stored alongside the report so the reviewer can check the model's input against its output. What is missing is the internal control structure. No threshold is published at which the system flags rather than passes, no confidence signal is described as visible to the reviewer, and nothing states what happens when a forgery is missed or a genuine document is wrongly flagged. Checked 7 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Real deployment evidence at scale, short of assessable measurement. The published base is more than 1,500 regulated businesses, and named customers appear with attributed quotations rather than logos alone: Boyce Hatton on meeting HM Land Registry's Digital ID Standard, Thomas Legal on client completion times as a competitive differentiator, Mezzle on the client experience, and Direction Law, which states it set a target of a 50 per cent increase in the speed of its compliance process and believes it not only hit but exceeded it. Operational figures are published and specific: 75 per cent of individuals complete their checks within 24 hours, documents verified from 195 jurisdictions, electronic address verification across 17 jurisdictions, and reports returned in minutes. Two things hold this at B. The figures carry no method, sample, baseline or date, and the strongest of them is a customer's own belief about its target rather than a measured result. And none of the outcome evidence is attributed to the AI: the completion and speed claims describe the app and the check workflow, so a buyer assessing the forgery detection specifically has adoption evidence for the platform and none for the model. Checked 7 September 2026.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Substantive published commitments across most limbs, short of the one this axis exists for. The Terms of Use define mutual confidentiality with need-to-know access, a 30-day destroy-or-return obligation on request, and liability for the acts of permitted recipients. Clause 12.1 leaves the firm owning the intellectual property in its own data and clause 12.3 licenses that data to Thirdfort only to the extent needed to provide the Services. The data processing agreement makes the firm the controller and Thirdfort the processor, limits processing to the Services and the firm's instructions, and restricts access to personnel who need it. Security measures are specific: AES-256 or stronger at rest, TLS 1.2 or better in transit, two-factor authentication for platform users, least privilege and device encryption for staff, no storage on local machines, and a documented architectural separation of data between different customers. Deletion is concrete, with all initiation and report data removed within 30 days of a written request and the fields covered enumerated down to date of birth and home address. What is absent is privilege and work product, which appear nowhere in the estate. The omission costs a buyer less here than on a matter-facing product, because what Thirdfort holds is client identity and source-of-funds material rather than privileged case files, but the limb is required for the top band and it is not met. Checked 7 September 2026.

Source: Vendor Published
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Responsibility is allocated in the agreement but no professional conduct framework is engaged. Clause 8 does the allocation squarely: the Reports help a firm understand risk and meet its compliance obligations, they must not be the sole basis of a decision, the firm is solely responsible for the conclusions it draws, and Thirdfort gives no opinion and makes no recommendation. The consumer wording in Appendix 1, which the firm is required to send to its client before lite screening and identity document verification, frames the check as part of the professional's own due diligence rather than as advice from Thirdfort. Both are more than most records carry. What is not addressed is professional conduct as such: nothing engages unauthorised practice, nothing names a conduct rule or regulator obligation that the firm's use of the product touches, and the estate contains no professional responsibility statement. Several limbs of this axis do not bite on a due diligence platform that never advises a client or produces legal work product, and they are not counted against the vendor; the grade reflects that a real allocation exists and a conduct framework does not. Checked 7 September 2026.

Source: Vendor Published
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

No governance disclosure was located anywhere in a legal estate that is otherwise unusually complete. There is no AI policy, no responsible AI or ethics statement, no governance framework, no ISO 42001 or NIST AI RMF alignment, no named internal owner for AI decisions, no model evaluation or testing description, and no AI-specific provision in the Terms of Use, the data processing agreement or the security measures page. The gap is more consequential here than the grade alone conveys, and the reason should be on the record rather than left to inference: the security measures page states that Thirdfort gathers and processes personal data including biometric information from clients, and the product applies automated document and identity checks to individuals whose onboarding depends on the result. Demographic differential performance is a well-documented property of biometric and document-image systems, and nothing published addresses fairness, differential error rates, testing across populations, or what recourse an individual has if a check wrongly flags them. The ISO/IEC 27001:2022 certification governs information security and is not read as covering this. Surfaces read on 7 September 2026: both AI-bearing product pages, the security measures page, the Terms of Use, the data processing agreement, the third-party products and terms, the terms index and the pricing page.

Source: Vendor Published
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Stewardship is documented at contract level and is genuinely tight, though none of it is AI-specific. Processing is purpose-limited twice over: clause 12.3 of the Terms licenses client data only to the extent needed to provide the Services, and clause 2.4(a) of the data processing agreement limits processing to providing the Services on the firm's instructions. No training or model improvement right is reserved anywhere in the estate. The perpetual feedback licence in clause 12.4 is drafted with an express carve-out stating it will not cover any personal data, which is the kind of detail that usually goes missing. Deletion is concrete and time-bound at 30 days with the fields enumerated. Security measures are specific and independently framed, including annual penetration testing commissioned by the vendor rather than by customers, routine vulnerability scanning, security log monitoring, encryption at rest and in transit, and architectural separation between customers. Breach notification runs without undue delay under the processing agreement, and FCA licensing obliges Thirdfort to file quarterly reports on its operational and security risks, which is external supervision of the security posture rather than self-assertion. What holds this at B is that nothing addresses the AI specifically: no statement covers how document images and biometric material are handled by the model, how long the model's inputs and outputs persist, or whether anything is retained from an inspection once the report is produced. Checked 7 September 2026.

Source: Vendor Published
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Quantified recourse exists, which is uncommon, and the AI-relevant exposure is routed away from it, which matters. On the credit side the Terms of Use state figures rather than formulas: liability is capped at the higher of 25,000 pounds or the fees paid in the preceding twelve months, with breaches of data protection obligations carved out and capped separately at 2.5 million pounds in aggregate. Clause 6.1(b) warrants that Reports will be materially accurate and complete, mutual intellectual property indemnities run both ways, uptime is committed at 99.5 per cent monthly, material breach carries a 30-day cure, and clause 16.2(b) lets a firm terminate immediately if an update materially reduces the service and no substitute follows. Clause 18 gives an annual audit right with an undertaking to provide executive summaries of audit reports and copies of current third-party certifications. Against that sit three provisions a buyer should weigh together. Clause 9.3(g) excludes losses caused by Third Party Products, which is precisely where the supplier-provided elements of the checks sit. Clause 9.4 waives all the firm's potential claims arising from the Platform, Services or Reports in connection with the services the firm provides to its own client, which is the scenario a firm relying on a regulated due diligence check most needs covered. And uptime is measured from the moment the customer reports a fault in writing rather than from onset, so the commitment turns partly on the customer's own vigilance. Checked 7 September 2026.

Source: Vendor Published
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

An integration surface exists and is contractually governed, but no legal practice system was located first-party. Thirdfort publishes a separate API Agreement in its terms index, applying to clients, partners and potential partners who access the API to build a direct integration, and clause 21 of the Terms of Use incorporates it. Distribution through Partner Platforms is a first-class part of the model rather than an afterthought: clause 2.2(b) contemplates a firm using the Platform Services entirely through a partner's own platform, clause 19 governs the information exchanged, and a partners list is maintained at a published address. That is real integration depth in architecture. What could not be established is direction: no case management system, practice management system, document management system or legal accounting package is named in any surface read, so a buyer cannot tell from the vendor's own material which systems the product actually plugs into. The partners list itself was not opened in this pass and is named here as the artifact that would settle it; it is the row in this record most likely to move on a further pass, and it is amendable on newly located evidence. Checked 7 September 2026.

Source: Vendor Published
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Tenancy is addressed and region is not, which clears the floor on the tenancy limb alone. The security measures page states that Thirdfort hosts its technical infrastructure and databases on Google Cloud Platform, that data sits in GCP-managed database services across three data centres at different physical sites, that storage on local machines is not permitted, and that the software architecture ensures separation of data and of information security between different customers and application components. That is a documented multi-customer separation model rather than a bare assertion. Residency is the weaker half. The three data centres are not located for the reader, no region menu or residency choice is offered, and the vendor states plainly that it uses service providers located outside the United Kingdom and European Union, relying on contractual transfer mechanisms rather than on keeping data in region. Those mechanisms are properly specified: the data processing agreement incorporates module 2 of the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, with Thirdfort as importer and the firm as exporter. The completed transfer schedules that would show the actual destinations are published as images and could not be read, which is recorded as a retrieval limit rather than an absence. No self-hosted or private deployment option exists, which is expected for a consumer-app-based verification service. Checked 7 September 2026.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Multiple current, independently granted certifications, published without a portal. Thirdfort states it holds ISO/IEC 27001:2022, the current revision of the standard rather than a superseded one, and separately holds certification as an Identity Service Provider under the Digital Identity and Attributes Trust Framework operated by the UK government's Department for Science, Innovation and Technology. It is certified under the UK Digital Verification Services trust framework and appears on the GOV.UK register of digital identity services, which is a public register a buyer can check independently of anything the vendor says. Regulatory supervision adds a further layer that is not a certification but functions like one: FCA licensing for account information services means, in the vendor's own account, that the regulator has reviewed its security policies and that Thirdfort must file quarterly reports on operational and security risks. Penetration testing is annual and vendor-commissioned, with remediation routed into engineering priority, alongside routine vulnerability scanning and security log monitoring. What holds this below the top band is artifact access. No certificate document, certificate number or validity period is published, no auditor or certification body is named, there is no SOC 2 report, and there is no trust centre or document portal. Certifications are obtainable, but through clause 18.2 on request during an audit rather than from the website, and clause 18.3 expressly excludes access to non-public external reports. Checked 7 September 2026.

Source: Vendor Published
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The supply chain is partly disclosed, and the part that is disclosed is done properly. Six suppliers are named in a published, versioned instrument with their full flow-down terms reproduced: Onfido, Experian, IVXS UK trading as ComplyAdvantage, iProov, Dun and Bradstreet, and Kyckr Ireland. A separate third-party service provider page, dated 24 October 2025, distinguishes data providers from technical service providers, explains the two categories of data shared, and offers a subscription to sub-processor notices. Change is governed contractually: clause 16.2 of the Terms gives 30 days' notice of any material change to the data provider list with a right to terminate, and clause 3.3 of the processing agreement requires written notice of new sub-processors within 30 days with a right to object. Experian's own flow-down terms disclose that its services involve models and techniques based on statistical analysis, probability and predictive behaviour, which is supplier-level model disclosure a buyer can read. What is missing is the mapping and the models. No model is named anywhere, no version or family is given, and the vendor never states which of the six suppliers, if any, provides the artificial intelligence behind document verification. Naming Google Cloud Platform tells a reader where the service runs, not whose model inspects a passport, and it is credited on deployment rather than counted twice here. Two artifacts that would close the gap could not be read and are recorded as retrieval limits: the feature-to-provider breakdown on the flow-down page is published as an image, and the provider tables on the service provider page render client-side and returned no content. Checked 7 September 2026.

Source: Vendor Published
CC on Commercial TransparencyPricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Commercial mechanics are published in the contract while prices are not published anywhere. The pricing page exists and is structured by buyer type, inviting a reader to select an industry to see available plans, with a custom quote offered for industries not listed. The plan detail sits behind that selector and rendered no content, which is recorded as unrendered rather than absent because the page's own wording states that plans are there to be seen. What is established first-party comes from the Terms of Use, and it is more than a sales invitation: fees are agreed separately and are exclusive of VAT, any increase carries 30 days' notice with an opportunity to stop using the service, disputed invoices must be raised within 30 days, overdue amounts carry interest at 4 per cent above the Barclays base rate, suspension follows 7 days' notice, minimum purchase commitments exist and survive early termination, and a discounted trial period may be offered at the vendor's discretion. Those are real commercial terms a buyer can rely on. What is absent is any figure, band or unit of charge: the product is bought as checks and plans, and no price per check, per seat or per plan appears on any surface read. The grade sits above the floor because published pricing information exists at the level of charging mechanics, and below the middle band because no rate is discoverable without a sales conversation. Checked 7 September 2026.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Coverage is deep in one practice area and deliberately narrow beyond it. Legal is one of four named sectors with a page of its own, alongside conveyancing, estate agents and accountants, and the insights library carries a dedicated Lawyers industry category with material aimed squarely at solicitors, including guidance on file notes that survive an SRA review and on enhanced due diligence after the 2026 Money Laundering Regulations reforms. Practice depth is strongest in property: the enhanced NFC identity check is built to HM Land Registry's Safe Harbour standard under Practice Guide 81, and the platform supports Authorised Corporate Services Providers meeting the Companies House identity verification standard for directors and persons of significant control. Geographic reach in the checks themselves is broad, covering documents from 195 jurisdictions and electronic address verification across 17. What holds this at B is that the practice surface is a single workflow rather than a range: client onboarding and anti-money-laundering diligence, with no other legal practice area addressed and no matter-type coverage statement. The regulatory frame is also single-jurisdiction, resting on FCA authorisation, HM Land Registry, Companies House, the SRA and English governing law, so a firm outside the United Kingdom sees a product built around a compliance regime that is not its own. The legal sector page redirected to an insights article when fetched and was not read directly; the sector's existence and its content are established from the site navigation and the insights category. Checked 7 September 2026.

Source: Vendor Published
Pricing

No published figure

  • Thirdfort publishes no prices. The pricing page offers plans selected by industry and a custom quote for industries not listed, but no rate per check, per seat or per plan appears on any page. What the customer agreement does publish is the charging mechanics: fees are agreed separately and exclude VAT, increases carry 30 days notice with a right to walk away, invoices must be disputed within 30 days, overdue amounts attract interest at 4 per cent above the Barclays base rate, and minimum purchase commitments survive early termination. A buyer can therefore understand how they will be charged and on what terms before speaking to sales, but not how much.

Published structure without any published figure. The pricing page is organised by buyer type, inviting the reader to select an industry to see available plans, with a custom quote offered for industries not listed; the plan detail sits behind that selector and returned no content in the extracted body. That is recorded as unrendered rather than absent, because the page's own wording states that plans exist to be viewed, and under the page-inventory rule a thin page and an unreachable one grade in opposite directions. The substantive commercial terms come from the Terms of Use version 4.1.1 and are real: clause 3.1 agrees pricing and payment terms separately with each client and states that all fees exclude VAT; clause 3.2 provides that where a firm comes through a Thirdfort Partner, either the partner or Thirdfort will supply the pricing arrangement; clause 3.3 reserves the right to change fees on 30 days notice with an opportunity to stop using the Services; clause 3.4 sets a 30 day window to dispute an invoice; clause 3.5 permits suspension on 7 days notice and charges interest on overdue amounts at 4 per cent per annum above the Barclays Bank plc base rate; clause 4 provides for a discretionary trial period at discounted Trial Pricing communicated separately; and clause 16.4 confirms that minimum purchase commitments exist and that a firm terminating for convenience remains liable for fees that would have fallen due under them. No unit of charge is named on any surface read, although the product is bought and consumed as individual checks. No figure, band, tier name or term length was located first-party. Surfaces read on 7 September 2026: the pricing page, the Terms of Use in full, the third-party products and terms, and the product pages for identity verification and document verification.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Terms silent

A published agreement or policy exists and none of it addresses the question either way, or the document that would answer it could not be read and the summary names the retrieval limit. The summary states which shape the silence takes: an improvement right granted that never names training, or no improvement right granted at all.

The terms are silent on training while being unusually tight on use. No training, model improvement or machine learning right is reserved anywhere in the estate, and two provisions cut the other way: clause 12.3 of the Terms of Use licenses client data only to the extent Thirdfort needs it to provide the Services, and clause 2.4(a) of the data processing agreement limits processing to providing the Services on the firm's instructions. The perpetual feedback licence in clause 12.4, which is the clause most likely to carry a improvement right, is drafted with an express carve-out stating it will not cover any personal data. What is absent is a statement either way. Nothing prohibits training and nothing permits it, so a buyer has a purpose limitation to rely on rather than an answer to the question this signal asks. That is the shape the value set does not yet resolve well: silent is the only true value available, but the summary should be read alongside it, because the position here is materially different from a vendor whose agreement addresses data use loosely and says nothing. The privacy policy was not opened in this pass and is named as the surface that could carry a training statement; the row is amendable on that evidence.

Source: Vendor PublishedAs of Sep 7, 2026

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Disclosed without a period

Retention is acknowledged in public materials with no stated period.

Retention is addressed and deletion is time-bound, but no standing retention period is published. What is stated: on a written deletion request from the firm, all initiation and report data is removed from the platform within 30 days, and the security measures page enumerates what that covers, including the client's name, mobile number, date of birth and home address, with the report permanently deleted and unavailable to download or recover. On termination, clause 16.5(a) gives the firm 30 days to download its data before deletion, and clause 2.4(h) of the processing agreement requires deletion or return on written request unless retention is legally required. What is not stated is how long a report and the document images behind it are held absent any request. The default appears to be indefinite retention until the firm acts, and nothing published sets an outer limit. Nothing at all addresses the AI layer specifically: whether the uploaded document image persists after inspection, and whether anything the model produces during a check is retained beyond the report itself. The processing schedule that would ordinarily carry retention periods is published as an image and could not be read, which is recorded as a retrieval limit rather than an absence.

Source: Vendor PublishedAs of Sep 7, 2026

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Own model, documented

The product maintains its own permission model, documented, requiring the firm to keep it aligned.

A separation model is documented, at customer level rather than matter level. The security measures page states that Thirdfort employs a variety of measures to segregate data across its estate and that its software architecture ensures the separation of data and the security of information between different customers and application components, supported by GCP-managed database services across three data centres and a prohibition on storage on local machines. Access control is specified on both sides: two-factor authentication for platform users, and least privilege plus multi-factor authentication for staff with access removed on the last day of employment. That is a documented model rather than a claim. What it does not reach is the wall a firm may need inside its own account. Nothing describes whether users within one firm can be partitioned from one another, whether a conflicted team can be excluded from a client's checks, or whether the AI's access to uploaded documents is scoped to the requesting user's permissions. For a product that holds counterparty identity material in transactions where two sides may instruct the same firm, that is a real gap, and it is the reason this sits at the neutral value rather than higher.

Source: Vendor PublishedAs of Sep 7, 2026

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Notice committed

Terms commit to notice where lawfully permitted. No transparency report located.

This is among the strongest compelled-disclosure provisions located in the corpus, and it is contractual on both instruments. Clause 4.3 of the data processing agreement commits Thirdfort, where legally possible, to challenge a public authority's request for access to personal data and promptly notify the firm, not to disclose any personal data without the firm's consent, to notify the firm and provide it with information about such requests, and, where disclosure is compelled, to disclose only the minimum amount required and keep a record of the disclosure. Four distinct undertakings sit in that clause: resist, notify, minimise and record. Clause 11.5(a) of the Terms of Use adds a mutual obligation on either party to notify the other as soon as possible where it is legally required to disclose confidential information. The qualifier where legally possible is honest rather than evasive, since a gagging order can bar notice as a matter of law and a clause promising otherwise would be unreliable. It stops short of the top value only because Thirdfort publishes no transparency report: the record of disclosures is kept under the clause but nothing is published about how many requests have been received or how they were handled.

Source: Vendor PublishedAs of Sep 7, 2026
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Sources named and licensed

The vendor names its primary law sources and the licence or public domain basis for each, with an update cadence.

The reference corpus is both named and licensed, in public, which is rare. Every substantive data source behind the checks is identified with its supplier and the licence terms are reproduced in full in a published, versioned instrument: Experian for address verification, CCJ and insolvency data and CrossCore fraud assessment; ComplyAdvantage for screening databases; Dun and Bradstreet for business information; Kyckr for company registry extraction across global registries; Onfido and iProov for identity elements. The Metropolitan Police's Amberhill database of lost and stolen documents is named as the cross-reference for every identity document, and Royal Mail NCOA Alert Data is identified with its own end user agreement. The published terms set out permitted purposes, territorial restrictions, intellectual property ownership and use limits for each source, so a buyer can see not only where the data comes from but on what conditions it may be used and what it may not be used for, including express prohibitions on credit and employment eligibility decisions. One provenance question is not answered: nothing states what the document verification model itself was trained on. That is a distinct question from the reference corpus and it is recorded on the model supply chain row rather than here.

Source: Vendor PublishedAs of Sep 7, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

The product ships no citator and makes no good-law claim, which is the expected position for a client due diligence and identity verification platform rather than a disclosure gap. Nothing Thirdfort produces cites legal authority: the outputs are verification reports on individuals and companies, presenting flags across data validation, compromised documents, age validation, data consistency and data comparison. The closest analogue in this product is currency of reference data rather than currency of law, and that is addressed on the corpus provenance row through the named suppliers and their update terms. Recorded at the floor because the value set requires a value, with the reason stated here so that a reader does not take the value as a finding against the vendor. Nothing else in this record depends on it. Surfaces read on 7 September 2026 include both AI-bearing product pages, the Terms of Use, the data processing agreement and the third-party products and terms.

Source: Operator VerifiedAs of Sep 7, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

Nothing published describes how the system behaves when it is unsure. The nearest surface is the report itself, which presents results in three states so a reader can instantly see what has passed, what is not relevant and what requires consideration. That third state routes a result to human judgement and is a genuine design feature, but it is a presentation convention for the report rather than a documented account of model behaviour: nothing states when the system emits it, what confidence or score sits behind it, or whether it reflects uncertainty as opposed to a positive detection. It is named here rather than credited, because crediting it would read a disclosed uncertainty behaviour into a report layout the vendor has not described in those terms. No confidence score is described as visible to the reviewer, no abstention or escalation threshold is published, and nothing addresses what the model does with a document it cannot parse beyond the pre-submission guardrails that block blurry, cropped or oversized uploads before inspection begins. Surfaces read on 7 September 2026: the document verification and identity verification pages, the security measures page, the Terms of Use and the data processing agreement.

Source: Operator VerifiedAs of Sep 7, 2026

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

No matter naming Thirdfort or Thirdfort Limited was located in the hallucination case tracking maintained by Damien Charlotin or in the sanctions reporting drawn from it, searched on 7 September 2026 on both the product name and the company name. The reporting reviewed names the tools involved where they are known, including instances tied to purpose-built legal AI products, and Thirdfort appears in none of it. This is consistent with the product class: the platform produces identity and due diligence reports and generates no legal citations, so the exposure this signal tracks is structurally absent rather than merely unrealised. Recorded as none located rather than as a positive finding about vendor conduct or product quality.

Source: Operator VerifiedAs of Sep 7, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

Regulatory alignment is extensive and none of it is AI guidance, which is the distinction this signal turns on. What Thirdfort does align to, and documents carefully, is identity and anti-money-laundering standards: HM Land Registry's Digital ID Standard, with the enhanced NFC check built to the Safe Harbour standard in Practice Guide 81; the Companies House identity verification standard for directors and persons of significant control; the UK Digital Verification Services trust framework, under which it appears on the GOV.UK register; and certification as an Identity Service Provider under the DSIT Digital Identity and Attributes Trust Framework. Its insights material addresses solicitors directly on SRA file note expectations and on enhanced due diligence under the 2026 Money Laundering Regulations reforms. That is real and useful, but it is alignment with identity and AML standards rather than with guidance on the use of artificial intelligence in legal practice. No bar, law society or regulator guidance on AI is named, mapped or referenced anywhere, and nothing addresses what a firm's own AI-use obligations are when it relies on an automated forgery check. The value records the absence of AI guidance alignment; the substantial regulatory alignment is recorded here so it is not mistaken for silence.

Source: Vendor PublishedAs of Sep 7, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure, and the product sits inside a fee relationship between a lawyer and a client where those savings would change the bill.

Speed and efficiency claims are published; the fee consequence of them is not addressed. The published claims are customer-attributed rather than vendor-asserted, with Direction Law stating it targeted a 50 per cent increase in the speed of its compliance process and believes it exceeded that, Thomas Legal describing timely completion as a competitive differentiator, and the vendor publishing that 75 per cent of individuals complete checks within 24 hours and that reports return in minutes. Nothing addresses what happens to a client bill when a check that took a fee earner an afternoon takes minutes, no per matter record of AI-assisted work is described, and no guidance on fee or disclosure treatment is offered. Two qualifications belong on the record. The claims describe the check workflow and the client app rather than the artificial intelligence specifically, so even the claims that exist are not AI-assisted-work claims in the sense this signal asks about. And the cost of a check is a disbursement a firm commonly passes through to the client rather than billable time it absorbs, so the compression this signal was written for operates differently on a per-check product than on one that displaces professional hours.

Source: Vendor PublishedAs of Sep 7, 2026

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Disclosure pack published

A subprocessor and model provider list plus client facing disclosure material is published or available without an agreement in place.

All three limbs are met, which is uncommon. The supplier list is current and public: a dedicated third-party service provider page dated 24 October 2025, distinguishing data providers from technical service providers and offering a subscription to sub-processor notices, backed by a published instrument reproducing the full flow-down terms of six named suppliers, being Onfido, Experian, ComplyAdvantage, iProov, Dun and Bradstreet and Kyckr, with Google Cloud Platform named separately as the hosting provider. Change is governed contractually rather than by courtesy: clause 16.2 of the Terms gives 30 days' notice of any material change to the provider list with a right to terminate, and clause 3.3 of the processing agreement requires written notice of new sub-processors with a right to object under clause 3.4. Forwardable client-facing material exists in two forms: a published data processing agreement incorporating the EU Standard Contractual Clauses and the UK transfer addendum, and Appendix 1 of the Terms, which is consumer wording the firm is contractually required to send to its client before lite screening and identity document verification and which names Experian as the data provider by name and link. A firm can therefore answer a client's diligence questions from public documents without a bespoke negotiation. One gap should be stated plainly: the vendor never identifies which supplier, if any, provides the artificial intelligence in document verification, so a firm asked specifically whose model examines its client's passport cannot answer precisely from what is published.

Source: Vendor PublishedAs of Sep 7, 2026

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

An exportable record exists and is expressly shareable, but it records the check rather than the AI's part in it. Every check produces a downloadable PDF report which is the artifact the firm retains as its compliance evidence, and the uploaded document is stored alongside it so that it is easy to reference or audit later. Sharing is contemplated rather than merely tolerated: clause 7.1 permits the firm to share reports with regulators, insurers and where legally required, which is precisely the disclosure route this signal contemplates, and clause 12.2 licenses the firm to use its reports for internal business purposes for as long as it requires, so the record survives termination of the subscription. What the report does not do is disclose the AI. Nothing indicates that a report identifies which findings were produced by automated inspection, no log of model involvement is described, and nothing published addresses what a firm should say to a court or regulator about the automated element of a check it relied on. The record is real and usable but partial for this purpose, which is what the value states.

Source: Vendor PublishedAs of Sep 7, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 7, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746