Vannus / Catalog / Legora

Legora

Vannus records that this vendor has not disclosed which model it runs. Every finding below is quoted to the vendor’s own document, or marked not disclosed where the vendor publishes nothing.

Determination
Contracts with Legora AB (Sweden), under a governing law that depends on where the customer is based.
Vannus has not established whether a US parent controls this entity, so US reach is not established either way. The US terms do not name the contracting entity.
legora.com · read 2026-07-29
read from terms of service

Collaborative AI for legal work from Legora AB (registration number 559338-6872), Box 7242, 103 89 Stockholm, Sweden, with its technical team based in Sweden.

AI, legal, enterprise
Model provenance

Uses AI; provider not disclosed. Legora's own aOS page describes an agentic harness over LLMs and its privacy policy refers to transmitting queries to 'our AI model provider', but no first-party prose names a model or vendor; the only first-party naming of OpenAI is an isolated table cell on the EU pre-approved sub-processor page. We checked and found no first-party page naming it, so the criterion is excluded from the grade rather than counted against Legora.

Who controls it
Data jurisdictionEuropean Union · a privacy notice ↗
US corporate controlNot disclosed — the vendor names no contracting entity in its own documents · clause re-checked 17 Sep 2026
Trains on your dataNo — on the vendor's default plan

Training and retention posture varies by plan. What we publish above describes the vendor’s default plan; enterprise, team and API agreements frequently differ, often materially, and a contract can override the published default entirely. Check your own plan and contract before relying on this row.

This is a separate question from the grade above. The grade measures resilience — whether the tool endures and whether you could leave it. This describes who controls the vendor. A tool can score modestly on one and strongly on the other, and many do.

On U.S. CLOUD Act reach specifically: the statute reaches a provider subject to U.S. jurisdiction over data in its possession, custody or control. Corporate control is a strong indicator of that and it is what we can evidence from published documents — but it is not the whole test. A company founded outside the U.S. can still contract through a U.S. entity or run substantial U.S. operations. Treat this as a starting point for your own review, not a legal determination, and take advice on anything that matters.

Signals on file
Data jurisdiction
European Union

The vendor's published or catalog-recorded posture — the concrete facts this grade is built from. A full audit verifies each against the vendor's current documentation.

Compliance the vendor states
ISO 42001ISO 27001SOC 2GDPR

Taken from the vendor’s own published material. Vannus does not hold these reports and has not reviewed their scope or dates — ask the vendor for the current report before relying on any of them.

How this grade is set

Vannus publishes a nine-dimension trust framework — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →

Related tools we grade
Visit Legora ↗ Grade your whole stack →