Legal AI Archive

FAQs

What is Legal AI Archive?

An independent directory of AI tools for substantive legal work, compiled entirely from public vendor and project information. It spans the full field, from open-source projects to commercial platforms.

Does Legal AI Archive rank or recommend tools?

No. The archive does not quality-rank, recommend, endorse, verify or certify any tool. Listings are not legal advice and are not a recommendation to use any tool.

How are tools chosen for inclusion?

Inclusion reflects a tool’s public positioning for substantive legal work. Listings are written in the archive’s own neutral language, drawn from the vendor’s or project’s public materials. Where a detail can’t be confirmed from public sources, it is left out rather than assumed.

How are tools categorised?

By area of legal work, not by quality or any judgement of which is better. Categories are broad and non-exclusive — a tool may appear in several — and a category is assigned only where the vendor’s public positioning clearly supports it.

What does a "Vendor confirmed" badge mean?

It means the vendor has reviewed their listing and confirmed it is accurate. Confirmation is free and does not change a listing’s position, wording, or categorisation.

What do the security tags (ISO 27001, SOC 2 Type II, etc.) mean?

They record vendor-stated facts only — never facts independently verified by the Archive. Four security tags are used because they are particularly relevant to legal AI products and recur often enough across vendors to support meaningful comparison. Other security standards, certifications and assurance frameworks may also be relevant and, where useful, are recorded in a tool’s Security Notes.

ISO/IEC 27001 — An international standard specifying requirements for an information security management system, against which organisations may be certified by independent certification bodies.

ISO/IEC 42001 — An international standard specifying requirements for an AI management system covering the responsible governance of AI systems and their risks, against which organisations may similarly be certified by independent certification bodies.

SOC 2 Type II — An independent CPA attestation report on the design and operating effectiveness of a service organisation’s controls over a defined period, assessed against the AICPA Trust Services Criteria.

No training on client data — A vendor-stated commitment that client data is not used to train AI models. For the first three tags, the vendor is stating that an independent body has certified or attested to relevant practices; this tag records the vendor’s own commitment without equivalent third-party assurance.

A tag is applied only where the vendor makes an unqualified, product-wide statement, although relevant qualified claims may still be recorded in Security Notes.

The tags do not establish the scope of the underlying certification or assurance. An ISO certificate applies only to its stated scope, and a SOC 2 report applies to the system and Trust Services Criteria covered by that report. The tags reflect what was publicly stated at the time of research, so users should confirm current status, scope and data handling terms directly with the vendor before relying on them.

For further background, see ISO/IEC 27001, ISO/IEC 42001 and the AICPA’s System and Organization Controls resources.

What do the deployment tags mean?

Three tags record where a tool can run: Cloud, Private Cloud / Dedicated, and Customer-Hosted. Unlike the security tags, these record what the vendor offers rather than what applies universally, so a deployment model available only on an Enterprise plan is still tagged — the listing notes say so. Private Cloud / Dedicated covers a customer-specific dedicated or single-tenant environment operated by the vendor. Customer-Hosted covers deployment into infrastructure the customer controls, whether that is the customer’s own cloud tenant, private servers or on-premises hardware; vendors describe this in different ways, and the listing records their wording.

What about other security or compliance claims — SOC 2 Type I, DPAs, data residency, HIPAA, zero data retention, and similar?

These are recorded as notes on the listing rather than as tags. The security tags are a deliberately small, curated set; everything else a vendor states publicly about security or compliance is still captured, just as plain text rather than a badge. This is not a judgement that these things don’t matter — just that the tag list stays narrow and consistent rather than growing a new badge for every certification or claim that comes up. As with the tags themselves, always confirm current status directly with the vendor before relying on any of these.

Do paid listings (Enhanced profile or Sponsorship) change how a tool is described or ranked?

No. Paid options affect presentation and placement only — they never affect whether a tool is listed, how it is categorised, or how its security and jurisdiction details are recorded. Paid placements are always individually badged and disclosed. See vendor options for detail.

Is Legal AI Archive free to use?

Yes. It is free to browse and requires no account.

How do I suggest a missing tool or correct an error?

Use the submit or correct page. Anonymous submissions are accepted, though providing contact details helps if follow-up is needed.

What does "on our radar" mean?

Tools shown as “on our radar” are ones we are aware of but have not yet reviewed. They are not verified, categorised, or otherwise assessed — appearing there is simply a note that the tool is on our list to look into, not any comment on the tool itself.

What does the jurisdiction information on a listing mean?

It describes which legal system(s) a tool’s content or workflows actually cover — for example, which country’s case law or legislation it searches — not where the vendor is headquartered, which law governs the vendor’s contract, or where the tool is hosted. Confidence varies by listing: where a tool is genuinely jurisdiction-neutral or agnostic, we say so; where there is a clear, publicly stated jurisdiction, we record it; and where the signal is only partial or indicative, we capture what we can, but it is worth confirming directly with the vendor. Like everything else on the site, this reflects what is publicly available, not independent verification by the archive.

Is anything on this site legal or procurement advice?

No. Nothing on the site is legal advice, technology procurement advice, or a recommendation to use any tool. Always confirm features, pricing, security and jurisdiction coverage directly with vendors.