Legal AI Positioning Map
A structural read of the legal AI market following ILTACON 2026, and an honest placement of Marcella within it. Two axes, because the conventional one does not describe the contest that matters.
Who made this, and how
This is a self-produced report. We build Marcella, and Marcella is one of the vendors plotted here. Read it with that in mind. Every placement is drawn from publicly announced capability between May and August 2026, and every source is a vendor's own published material or trade press coverage of it. No vendor was consulted and no vendor paid for or influenced any placement.
The format is familiar on purpose. It is not a product of any analyst firm, and it reproduces none of their research or methodology.
Two panels rather than one, because a single chart cannot carry the argument. The first uses the conventional framing a buyer already carries into the room, breadth of capability against scale in market, and places our own product where that framing honestly puts it, which is low. The second re-plots the market on the two properties that determine whether an output survives judicial scrutiny. A self-assessment section further on scores our own product against fourteen criteria, including the ones we fail.
Anyone can check the vendor claims here against the announcements they came from. Every externally sourced claim below is cryptographically sealed, and you can verify the chain without trusting us.
How this document is sealed
This document names competitors, so every externally sourced claim in it is cryptographically sealed. The receipt chain records each claim with the source it was read from and the date it was read. Any alteration to a claim, its source, or their order breaks the chain and the verifier says where.
It was also drafted with an AI system. That is precisely why the seals exist. The tool that wrote it belongs to the same class of tool this document argues cannot be relied on without a verification layer underneath, so we put one underneath. The seal is produced by the same attestation architecture that runs inside Marcella, and the ceiling is the same in both places: it attests that the record is unaltered. It does not attest that any claim is true. Open the sources and check them.
| Field | Value |
|---|---|
| Format | draft-farley-acta-signed-receipts |
| Structure | compound (nested sub-attestations under one outer frame per section) |
| Signature | Ed25519 over RFC 8785 (JCS) canonicalized payload |
| Chain | SHA-256 prev-receipt hash, genesis 64 zeros |
| Issuer | mcf:issuer:8M9L7TqHEMjR |
| Public key | 6d2ad7c652b9829d9900f3dc4b9cf4e87027b50535627e8f02869c4de15755a4 |
| Sealed claims | 22, across 3 compound frames |
| Chain head | 4840f0ce16c71040d015aa45605ec0ae10d5b040f8dc603b717d0b0763b66dbc |
Download the receipt chain Download the verifier
The verifier needs only Python and the cryptography package. No account, no network, and no Technology Outlaws software. Run python3 verify-provenance.py provenance.json.
What carries no seal, and why. Every judgment in this document carries no seal. The quadrant placements and the fourteen component scores are the author's assessment. An assessment has no source URL, so it cannot be sealed, and it is not. Remaining rows of the feature matrix are sealed as each source is confirmed. Where you see no seal, you are reading an opinion or a claim whose source has not yet been verified, and the document tells you which.
What a seal cannot do. It does not prevent a wrong claim. A fabricated statement with a plausible-looking URL would seal perfectly if nobody opened the URL. What the chain enforces is that no claim ships without a source attached, and that nothing changed after sealing. One assertion in an earlier draft of this document described AT&T as a Fortune 10 company. It is not. That sentence had no source that supported it, so it could not be sealed, so it did not ship. That is the mechanism working, and it is the entire argument of this document applied to itself.
The conventional view
Stated capability against market scale, the shape a procurement committee will recognize. On these axes Marcella is early and narrow, and it is not close. Anyone who draws a chart like this with themselves in the top right corner is selling something. Note the marker: every other vendor belongs to one category, and Marcella is the only entrant plotted in all three at once. The scorecard further down publishes the component scores behind the placement, including the ones that do not flatter.
Our own placement is low, and it belongs there. These axes measure revenue, installed base, support scale, territory and channel maturity. Against companies with thousands of employees and decades of installed base, a young product scores low on all of it. That is the correct result and we are not going to argue with it.
What the axes do not measure is whether the output holds up when someone checks it. That is the subject of the next panel.
The axes that decide a sanctions motion
Verification depth against custody and provenance control. These are the two properties that determine whether an output holds up when a court, a regulator, a disciplinary body or an insurer examines it. The market has not organized itself around them, which is why the corner is occupied by one entrant and no one else.
The verification and custody stack is built. Components are marked Live where they are in service, Built where the code is complete but the capability has not been switched on in production, and Untested where the artifact is produced but has not yet been adjudicated.
Two qualifications are stated deliberately rather than buried. The self-authenticating exhibit credential is generated today; no court has yet ruled on one. Nothing has entered the record. And the device-forensics tier is complete but not yet running against production GPU. Both distinctions are load-bearing. A claim of judicial acceptance that cannot survive a general counsel's first question destroys the credibility of every other row on this page.
Feature breakdown
Capabilities as publicly announced between May and August 2026, stated as of 28 August 2026. Where a vendor announced a capability but has not shipped it generally, the cell reflects the announcement. This market moves quickly and some of these cells will be out of date within a quarter.
| Vendor | Headline move | Orchestration layer |
Own / derived model |
Persistent matter memory |
Drafting layer |
Citation verification |
Customer-tenant deployment |
Exit & portability |
Audit of already- filed documents |
Court-verifiable credential |
Infra / security layer |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Thomson Reuters | CoCounsel Legal GA; "Thomson" in-house LLM | Yes | Yes, open-weight base | Matter-centric | Brief Builder | Post-hoc, KeyCite-grounded | No | Vendor-held | No | No | No |
| LexisNexis | Legal Intelligence Engine harness | Yes, dynamic | Own models + frontier | Context carry-forward | Agentic drafting | Post-hoc, Shepard's-grounded | No | Vendor-held | No | No | No |
| Harvey | Harvey II; Tenet model; AIUC-1 | Yes, agentic | Yes, Kimi K3 base | Yes, core feature | Yes | Model-side | No | Vendor-held | No | No | Ethical walls via partner |
| Clio + vLex | Clio Work; bar member program | Skills infrastructure | Frontier models | Practice data | Clio Draft | Corpus-grounded | No | Vendor-held | No | No | No |
| Filevine | LOIS console; LOIS Explore free tier | Yes, acts on matters | Frontier models | System of record | LOIS for Word | Verified citations claimed | No | Vendor-held | Document analysis only | No | No |
| Legora | Legora aOS agentic operating system | Yes | Frontier models | Workflow context | Editor / Word | Model-side | No | Vendor-held | No | No | No |
| Eve | EveOS; Atlas data layer; Analyst | Yes | Frontier models | Atlas, portable | Demands, discovery | Not a focus | No | Structured, exportable | No | No | No |
| Litera | Firm AI Search via Lito; Foundation 365 | Single agent | Frontier models | Firm experience data | Draft / Lito | Deterministic heritage | No | Vendor-held | No | No | No |
| iManage | Next-gen platform GA; MCP read/write | Via MCP | No | Knowledge + context | Word editing agent | No | Governed, hosted | Export tooling | No | No | Governance controls |
| NetDocuments | Legal context graph; MCP | Via MCP | No | Context graph | Word editing agent | No | Governed, hosted | Export tooling | No | No | Governance controls |
| Anthropic | Claude for Legal: plugins & connectors | Yes, agentic | Frontier owner | Session / project | Claude for Word | No native citator | API / enterprise | No retention by default | No | No | No |
| Relativity / DISCO | Agentic review; AI bundled free | Yes, discovery scope | Frontier models | Matter workspace | No | Out of scope | No | Vendor-held | Review, not integrity | No | No |
| Marcella | Retrieval-first + attestation substrate | MoA orchestration Live | Frontier via own tenant | Matter memory Live | SCDL: conditioning, no training Live | Pre-generation anchoring Live | Runs in customer tenant Live | Never transferred; firm holds keys Live | Forensic audit of filings Live | Produced today No ruling yet | Endpoint, entropy, hardware Live |
Where the architectures actually diverge
The prevailing architecture
Shared by every vendor on the chart above.
- Generate first, then check. A citation is produced by a model and validated afterwards by lookup against an index.
- Verification is probabilistic where it is thorough. A second model invocation judges whether the source supports the proposition, reintroducing the error class the check exists to catch.
- The link between output and the retrieval context is discarded at generation time, so no system can answer whether an authority was actually before it when it drafted the passage.
- Attestation is decoupled from verification. A flagged response can be cleaned and then attested, laundering the event out of the record.
- No measured error rate exists, because outcomes are not recorded as counts. There is no defensible per-tenant fabrication figure.
- Multi-tenant SaaS custody. The vendor holds the data; the firm holds a contract.
- Exit is a feature that has to be built, because custody was transferred in the first place. The strongest position on offer is a vendor that structures the firm's data well enough to be exported and used elsewhere. That is a real improvement, and still an answer to a problem the architecture created.
- Verification is a product feature, so it is only available to paying customers, which means no court can ever require it.
- Drafting is trained or generic. Firm-specific voice is achieved by fine-tuning on the firm's own documents, which reads across every conflict screen, encodes privilege into weights that cannot be audited, and cannot forget a departed attorney. The alternative on offer is a generic drafter that produces prose in nobody's style.
- Every drafting layer generates only into its own product. None will audit a competitor's output.
The Marcella architecture
Design intent. Components marked Spec are not yet shipped.
- The verification substrate is created before generation, not inferred after it. A citation that cannot be anchored cannot be emitted.
- Integrity is deterministic and model-free, using a Merkle root over the canonical corpus, where a single-byte change cascades. Drift is adjudicated separately from nonexistence.
- Render policy is fixed at ingest from the source licence class, never decided at query time, so licensed text cannot leak through a per-query bug.
- The human attestation act is a hard gate. Work product that is not attorney-verified cannot receive an attestation, with no partial and no override.
- Telemetry records counts only, never citation strings or excerpts, producing a measured per-tenant unanchored-citation rate as an empirical error figure.
- Deployment into the firm's own tenant. The data does not move; the compute comes to it.
- Verification of a credential is free and open. Anyone can check one offline, at any time, without an account and without contacting us.
- Drafting without training. Firm-shaped drafts are produced by conditioning a generic model on convergence-gated style derivatives (argument skeleton, clause-position map, citation-authority graph, redline posture) abstracted across a minimum threshold of same-class documents, with the source discarded after extraction. No model is trained on privileged data, so there is no ethical-wall breach, no privilege in weights, and no deletion problem when an attorney departs.
- Attach mode. The same layer will audit the output of any third-party drafter against the firm's own frames and judicial-treatment data, with zero integration into that competitor's generation process. A firm can run a rival platform and still verify it here.
- Attestation on the standard a court already applies. The verification checklist an attorney completes before work product can leave the system is built around the reliability factors courts use to evaluate expert and technical evidence under Daubert: whether the method can be tested, whether it has a known error rate, whether standards govern its operation, and whether it is generally accepted. The system produces a measured error rate precisely because that is one of the factors. This is not a compliance checkbox designed in the abstract. It is built to the test that will actually be applied if the output is ever challenged.
- Attestation-gated export. Output is labelled machine-generated in a non-suppressible state and cannot leave the system until a human completes a full multi-item attestation, recorded as an immutable event. Partial attestation is rejected. Display is permitted before attestation; export is not.
- Drafts are emitted as tracked changes rather than prose, so every machine edit is individually reviewable, acceptable and rejectable.
- There is no exit to build, because there was no transfer. The data sits in the firm's own tenant under the firm's own keys for the entire relationship. Disconnection is revoking access to software, not repatriating an asset. A firm that wants its complete footprint before disconnecting takes a static export of material it already holds.
- The sealed credential outlives the vendor. An exported credential is verifiable by anyone, offline, indefinitely, with no callback to the issuer and no dependency on the issuer continuing to exist. Portable data still requires someone to interpret the exporting vendor's structures; a self-authenticating artifact does not.
- Deploys where the work already happens. Native to the firm's existing productivity suite rather than another destination to log into. A full private-tenant deployment on the customer's own infrastructure completes within a business day.
- An infrastructure and security layer beneath the application that no content or application vendor on this chart operates.
The layer nobody else operates
Every vendor on this map is a content company or an application company. None of them runs an endpoint agent, an entropy plane, or a hardware attestation floor, because none of them is an infrastructure and security operator. This is the comparison that does not appear in any analyst chart, because no analyst covering legal software thinks to draw it.
What legal AI vendors secure
- Application-layer access control, SSO and role permissions.
- Encryption in transit and at rest, on infrastructure they rent.
- Ethical walls and conflict screening, generally inherited from an integration partner rather than enforced natively.
- Tenant separation inside a shared multi-tenant estate.
- Certification against an AI assurance standard, which is a governance artifact rather than a control plane.
- Data residency commitments expressed contractually.
All of it sits above the application. None of it survives a compromise below the application.
What Marcella secures
- Heuristics plane. Adversarial static analysis as a pre-commit CI gate that blocks deploy on critical findings with no override. Content fingerprinting of every ingested corpus document against a native known-bad set, quarantining poisoned corpus before it is ever indexed. Runtime recon detection that removes the system from an attacker's view rather than returning an error.
- Entropy plane. Concentric decoy broadcast across network, session and seed-derivation layers, so an attacker who pierces one ring finds an unbounded field of valid-looking targets at the next. Multi-stream attestation deriving a single seed without which no inference, unlock or signing operation proceeds. A hardware random floor beneath all of it with no software attack path.
- Detection plane. Composite-score quarantine, plus threat intelligence derived from pattern absence and displacement rather than known signatures.
- Endpoint plane. A managed device agent and a behavioral entropy gate where the biometric baseline never leaves the device. Only a hashed entropy contribution does.
- Deployment. Runs inside the customer's own tenant under managed identity with private endpoints and per-tenant key isolation. Derivative-only persistence is enforced on every write, so privileged source content is structurally incapable of entering the record.
- Supply-chain hygiene. Copyleft dependency audit and personally-identifiable-data scanning are hard gates before any binary is packaged. No artifact ships without both passing.
The question no vendor on this map can answer
In a single quarter, two of the largest vendors in legal moved from renting frontier models to post-training their own from open-weight foundations. The economics are compelling and the engineering is legitimate. The procurement consequence has not been priced in.
The durable framing is provenance, not geography. An argument built on where a model was trained ages the moment an equivalent base is published elsewhere, and reads as prejudice to a sophisticated buyer. An argument built on whether a vendor can produce a documented, auditable, attested inventory of its own stack does not age, applies uniformly to every vendor including this one, and is the exact question a court, an auditor, a disciplinary body and an insurer will each arrive at independently.
State the facts. Let the buyer reach the conclusion. That is the register this entire document is written in, and it is the only register that survives contact with opposing counsel.
The component scores, published
Most vendor comparisons show you a position without showing you the arithmetic. This one shows the arithmetic. Below is our own product scored against fourteen criteria written for this document, with the reasoning for each, including the criteria we fail. If you are evaluating us, these are the questions worth asking, and the answers are here before you have to ask them.
The honest one-line read: a finished product at the beginning of its commercial life. The capability is built and running. What has not accumulated yet is the reference list, and a buyer is entitled to weigh that. What a buyer gets in exchange for going early is a roadmap still responsive to them, published pricing, and a verification standard that remains checkable by anyone whether or not this company is in the room.
See it against your own filings. A short paid assessment runs a brief your firm has already filed through the verification layer and returns what it finds. No deployment, no connector, no IT ticket. You supply one document and read the report.
What that buyer gets in exchange is a capability no funded competitor offers, at a stage where the roadmap is still responsive to them, and with an open verification standard that does not strand them if the company does not survive. That last point is not a consolation. A verifiable credential that anyone can check offline, forever, without calling back to the vendor, is the only architecture on this map that degrades gracefully if its author disappears.
Both ends of someone else's pipeline
Every other vendor on this map competes for the same seat: replace what the firm uses today. One position on the board is structurally different: a layer a firm can adopt without displacing anything, which attaches to the front of a rival's pipeline, the back of it, or both.
Upstream: the retrieval and context source
Their agent calls in.
- An open protocol tool surface exposing the same substrate three ways: direct point reads, pre-assembled compound context in a single call, and graph-aware semantic traversal across typed relationships.
- One provenance record per compound invocation, enumerating every node assembled into the response. That is chain of custody over an assembled subgraph rather than element by element.
- Context assembled once and served warm to a second verifying pass, collapsing the cost of a two-model proposer-verifier loop that is otherwise prohibitive at production scale.
- Any protocol-capable client can consume it. Two document management incumbents shipped protocol surfaces in August 2026 with no verification layer behind them.
Downstream: the audit gate
Their output comes back.
- Attach mode ingests the finished output of any third-party drafting or research system and evaluates it against the firm's own derivative style frames and judicial-treatment data.
- Zero integration into the third party's generation process. No API agreement, no partnership, no permission. The firm supplies the document.
- Produces a structured delta report, which terminates at the same attestation gate as native output. It stays machine-generated until a human clears the full checklist, and no export before that.
- Extends to documents already filed, where no prospective control was ever applied.
A firm does not have to choose. This layer runs alongside whatever research or drafting platform is already in place, and it can also run alone. Document management and knowledge platforms are the natural fit, since they hold the firm's content and have recently exposed the protocol surfaces this connects to.
The firm holds the controls, not a vendor. The verification client runs on the firm's side, so no software provider can decide whether the firm's own work gets checked. That is the same rule that governs the attestation layer, for the same reason.
What the map says
Now consider what is happening during those months. Attorneys at the firm are already using AI. They were using it before the evaluation started and they will keep using it while the committee meets, because the work is due regardless. Every one of those months is a month of unverified citations entering draft work product with no attestation, no record of what was checked, and no way to reconstruct afterward what the model actually had in front of it. The exposure does not pause for procurement. It compounds.
That is a present problem, and the conventional purchase does not begin to address it for two or three quarters. A deployment that completes inside a business day, inside the software the firm already runs, is not a marginally faster version of the same purchase. It is the difference between having a plan and having a fix. No announcement this quarter contested that ground.
What else is in the box
The comparison above deliberately holds the ground where the market is empty. It understates the platform, because the verification layer sits on top of an infrastructure stack that a firm acquires in the same deployment. A summary, not a catalog.
Bring one filed brief
The fastest way to evaluate any claim in this document is to test it against work your firm has already produced. Nothing is deployed, no connector is installed, and no IT approval is required. You supply a document and read what comes back.
Book an evaluation
A working session against your own filings, with the verification layer, the drafting layer and the attestation gate running live. We will also walk the security stack for your IT and risk people, who will have questions this document does not answer.
marcellalegal.com/evaluation/
What the session covers
Your filed brief run through the verification layer, with every citation anchored or flagged. The drafting layer conditioned on your firm's own documents. The attestation gate, and the record it produces. Then the security and deployment questions your IT and risk people will raise, answered directly rather than deferred to a follow-up.
Pricing is published. You will not be asked to request a quote.