Legal AI security and certifications in 2026: how to check, and what the badge misses
This page does not tell you which vendors hold which certificates. We could not verify sixty certificates to a standard worth publishing, and a list we cannot stand behind is worse than no list, particularly on a subject where being wrong about a competitor is both unfair and actionable.
What it does instead: point you at where each vendor states its own position, and explain what the badge does not cover. That second part is where most security evaluations go wrong.
Where each vendor publishes
Checked in September 2026. These pages are the vendor's own claims, not our verification of them.
| Vendor | Security or trust page |
|---|---|
| Ironclad | ironcladapp.com/security |
| Juro | juro.com/security |
| LinkSquares | linksquares.com/security |
| Spellbook | spellbook.legal/security |
| Luminance | luminance.com/security |
| Harvey | harvey.ai/security |
| LegalOn | legalontech.com/security |
| DocuSign | docusign.com/trust |
| Relativity | trust.relativity.com |
| OneTrust | onetrust.com/trust |
| GenieAI | genieai.co/security |
Two vendors we checked, Icertis and PandaDoc, had no security or trust page at the conventional paths when we looked. Evisort had one until recently; it now redirects to a Workday product page following the acquisition. None of that is evidence of a weak posture, but it does mean you will have to ask, and asking is slower than reading.
Scope matters more than the badge
The single most common mistake in a security evaluation is treating a certificate as a property of the company. It is a property of a defined system at a defined time, and the definition is chosen by the vendor.
- Ask what the certificate covers. One scoped to a corporate office and its laptops, rather than the product platform your documents will sit on, tells you very little about your risk.
- Ask for the report, not the badge. The badge says an audit happened. The report says what the auditor tested and what they found, including exceptions.
- Check the date and the period. An audit covering a window that closed eighteen months ago describes a system that has since changed.
- Ask which sub-processors are in scope. Your documents commonly pass through a model provider, a hosting provider and an analytics provider, and the certificate may cover only the vendor.
- Ask what happens between audits. Continuous monitoring and an annual point-in-time audit are different assurances at similar prices.
The questions that are not about certificates
For legal software specifically, several risks are not covered by any common certification and have to be asked directly.
- Do you train any model on our documents, and is that the default or an opt-out? The answer varies across vendors and sometimes across tiers of the same vendor.
- Where is our data processed and stored, and will you commit to it contractually? This decides more public sector and regulated shortlists than capability does.
- What is the retention period, and can we require deletion on demand? This constrains what you can promise your own customers.
- Who at the vendor can read our documents, under what circumstances, and is that logged?
- What happens to our data if you are acquired? Several tools on this site changed owner in the last two years.
What we hold
For completeness, since we are asking it of everyone else: this site is published by a company certified to ISO 27001. We hold no other certification and do not claim one.
Method
Trust page URLs were resolved directly in September 2026 and are listed only where the page returned successfully. We deliberately do not reproduce vendor certification claims here, because copying a claim into a comparison table lends it a verification we have not performed. Read the vendor's page, then ask for the report.
If a vendor believes their page is missing or wrongly listed, we would rather correct it than leave it. Corrections are welcome and get made.