Legal AI
Harvey
Low riskLegal AI platform for law firms and in-house teams: research, drafting, document review, and workflow automation built on foundation models.
Is Harvey safe for confidential data?
Harvey is an enterprise-only legal AI product: customer data is not used to train models, deployments are contractually scoped, and the platform is sold with the DPA, security review, and audit posture law firms require. The residual risks are operational rather than contractual — matter-level access control, what associates upload, and conflicts hygiene — the same questions you'd ask of any document platform holding privileged material.
Risk by plan
The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.
No consumer tier exists — every seat is under the negotiated firm contract.
Data handling
Training on inputs
Customer data is not used to train foundation models; enterprise contracts govern all use.
Retention
Contractually defined per customer; firm content remains firm-controlled within the platform.
Residency
Hosted on Microsoft Azure with customer-selectable processing regions (EU/Switzerland, U.S., or Australia).
Compliance
- SOC 2Yes
- GDPR / DPAYes
- HIPAA BAANot verified
Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.
New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.
Enterprise controls
- SSO / SAML
- Matter- and role-based access controls
- Audit logging
- Negotiated DPA and security terms
Frequently asked questions
Does Harvey train on our firm's data?
No — Harvey's enterprise terms exclude customer data from model training. Confirm the specifics (including any product-improvement telemetry) in your firm's contract.
Is Harvey safe for privileged documents?
It is designed for them: enterprise-only contracts, access controls, and audit logs. Privilege risk shifts to usage — who can see which matter, and whether uploads respect ethical walls — rather than to the vendor's data handling.
If we have Harvey, do we still have a shadow-AI problem?
Usually yes. A sanctioned legal AI doesn't stop associates using personal ChatGPT for the quick questions Harvey feels too heavy for. Firms typically pair a sanctioned platform with prompt-level monitoring and redaction across the unsanctioned ones.
Policy changelog
- Initial entry published from Harvey's published security documentation.
Sources
This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.
Harvey is probably already in your organization.
Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.
More AI tool profiles
AI assistant built into Clio Manage, the dominant solo and small-firm practice management platform, answering questions and drafting from the firm's own matter data.
Thomson Reuters' professional AI assistant, delivered inside Westlaw Precision for legal work and as CoCounsel Tax, Audit & Accounting for advisory practices.
LexisNexis' generative AI research and drafting assistant, now sold as Lexis+ with Protégé, grounded in the Lexis primary-law and Shepard's citation database.
Generative AI features (document summarization, drafting, text editing, search) embedded in the MyCase practice management platform for small firms, part of AffiniPay's 8am IQ initiative.