Legal AI
Relativity aiR
Low riskGenerative AI review suite (aiR for Review, aiR for Privilege, aiR for Case Strategy) built into RelativityOne for e-discovery document and privilege review at scale.
Is Relativity aiR safe for confidential data?
aiR is an enterprise-only product inside RelativityOne, and its data posture is among the strongest in legal AI: processing runs on Azure OpenAI within the RelativityOne environment, submitted documents are not retained beyond the customer's instance or used to train models by Relativity, Microsoft, or anyone else, and Relativity has opted out of Microsoft's abuse-monitoring/human-review program so no Microsoft employee can see review content. RelativityOne carries SOC 2 Type II, ISO 27001, HIPAA, and FedRAMP credentials with 24/7 monitoring by its Calder7 team. The live risk is defensibility rather than confidentiality: aiR for Privilege makes machine privilege calls over entire productions, and an erroneous call — a privileged document produced, or an over-designation challenged — lands on counsel. Courts have accepted technology-assisted review for years, but GenAI-based privilege logging is newer ground, so validation protocols, sampling, and human QC remain the load-bearing controls.
Risk by plan
The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.
Sold only through RelativityOne subscriptions and partner service providers; no self-serve or consumer tier exists.
Data handling
Training on inputs
Data submitted to aiR is not used to train generative AI models from Relativity, Microsoft, or any third party; processing occurs via Azure OpenAI under enterprise terms.
Retention
Documents and prompts are not retained beyond the customer's RelativityOne instance; Relativity has opted out of Microsoft's abuse-monitoring retention and human review.
Residency
RelativityOne runs on Microsoft Azure with customer-selectable geographic instances; confirm that aiR processing stays in your instance's region for cross-border matters (relevant for Canadian and EU discovery obligations).
Compliance
- SOC 2Yes
- GDPR / DPANot verified
- HIPAA BAAConditional
Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.
New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.
Enterprise controls
- Opt-out of Microsoft abuse monitoring (no human review of content)
- SOC 2 Type II, ISO 27001, FedRAMP-authorized environment
- 24/7 security monitoring (Calder7)
- Instance-scoped processing and access controls
- Audit trails for review decisions
Frequently asked questions
Is Relativity aiR safe for privileged and confidential documents?
Its confidentiality posture is strong: processing stays within the customer's RelativityOne instance on Azure OpenAI, nothing is retained by or used to train models for Microsoft or Relativity, and Relativity opted out of Microsoft's human abuse-monitoring review. For data handling, it is one of the lower-risk ways to apply GenAI to a document population you were already hosting in RelativityOne.
Can we rely on aiR for Privilege to make privilege calls?
As a first-pass engine with human validation, not as the final word. The defensibility of AI privilege designations is still being established matter by matter: courts expect a documented, validated protocol, and a produced privileged document is counsel's problem regardless of which model made the call. Sampling, QC review of borderline calls, and a negotiated 502(d) order remain essential.
Does an enterprise tool like aiR cover our firm's wider AI exposure?
No — it governs one controlled workflow run by e-discovery specialists. The same case teams routinely use consumer chatbots for summaries and drafting outside any agreement, which is where confidential material actually leaks. An enterprise-grade review platform and firm-level controls on everyday AI use solve different problems, and most firms need both.
Policy changelog
- Initial entry published from Relativity's published security documentation and cited coverage.
Sources
- Relativity aiR product page
- aiR for Privilege documentation (RelativityOne)
- Relativity Calder7 compliance and privacy
- CDS on aiR data privacy (abuse-monitoring opt-out)
This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.
Relativity aiR is probably already in your organization.
Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.
More AI tool profiles
AI assistant built into Clio Manage, the dominant solo and small-firm practice management platform, answering questions and drafting from the firm's own matter data.
Thomson Reuters' professional AI assistant, delivered inside Westlaw Precision for legal work and as CoCounsel Tax, Audit & Accounting for advisory practices.
Legal AI platform for law firms and in-house teams: research, drafting, document review, and workflow automation built on foundation models.
LexisNexis' generative AI research and drafting assistant, now sold as Lexis+ with Protégé, grounded in the Lexis primary-law and Shepard's citation database.