Legal AI

Harvey

Low risk

Legal AI platform for law firms and in-house teams: research, drafting, document review, and workflow automation built on foundation models.

Verified 2026-08-31Harvey AIwww.harvey.ai

Is Harvey safe for confidential data?

Harvey is an enterprise-only legal AI product: customer data is not used to train models, deployments are contractually scoped, and the platform is sold with the DPA, security review, and audit posture law firms require. The residual risks are operational rather than contractual — matter-level access control, what associates upload, and conflicts hygiene — the same questions you'd ask of any document platform holding privileged material.

Risk by plan

The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.

Enterprise (only tier)
No training

No consumer tier exists — every seat is under the negotiated firm contract.

Data handling

Training on inputs

Customer data is not used to train foundation models; enterprise contracts govern all use.

Retention

Contractually defined per customer; firm content remains firm-controlled within the platform.

Residency

Hosted on Microsoft Azure with customer-selectable processing regions (EU/Switzerland, U.S., or Australia).

Compliance

  • SOC 2Yes
  • GDPR / DPAYes
  • HIPAA BAANot verified

Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.

New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.

Enterprise controls

  • SSO / SAML
  • Matter- and role-based access controls
  • Audit logging
  • Negotiated DPA and security terms

Frequently asked questions

Does Harvey train on our firm's data?

No — Harvey's enterprise terms exclude customer data from model training. Confirm the specifics (including any product-improvement telemetry) in your firm's contract.

Is Harvey safe for privileged documents?

It is designed for them: enterprise-only contracts, access controls, and audit logs. Privilege risk shifts to usage — who can see which matter, and whether uploads respect ethical walls — rather than to the vendor's data handling.

If we have Harvey, do we still have a shadow-AI problem?

Usually yes. A sanctioned legal AI doesn't stop associates using personal ChatGPT for the quick questions Harvey feels too heavy for. Firms typically pair a sanctioned platform with prompt-level monitoring and redaction across the unsanctioned ones.

Policy changelog

  • Initial entry published from Harvey's published security documentation.

Sources

This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.

Harvey is probably already in your organization.

Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.

Get a demo

More AI tool profiles