Everlaw (Analytics and Business Intelligence)
Everlaw is the world's most advanced cloud-native eDisclosure platform. Its industry-leading speed, processing up to one million documents per hour, combined with powerful EverlawAI Assistant, delivers instant, citation-backed insights. Everlaw allows you to accelerate workflows, slash review time and maintain full control over legal spend.
Features
- EverlawAI Assistant provides instant, citation-backed answers from corpus.
- Automated legal holds, notifications, and tracking slash human error risk.
- Cloud Connectors ingest data directly from M365, Slack, and Zoom.
- Storybuilder enables collaborative narrative building, interviews, and trial preparation.
- Interactive visualisations uncover key document relationships and new insights.
- Simple, colour-coded search interface rapidly runs highly sophisticated queries.
- Automated redactions, including bulk PII redaction on native spreadsheets.
- Instant translation across 109+ foreign languages and automatic audio/video transcoding/transcribing
- Predictive coding models improve accuracy and prioritise efficient document review.
- Detects duplicates, near-duplicates and email threads automatically
Benefits
- Slash document review costs and cut active data by 74%.
- Control legal spend through transparent, predictable pricing.
- Accelerate litigation and internal investigations using advanced AI technology.
- Find key facts quickly, accelerating review processes.
- Achieve compliance with defensible, automated legal hold notification tracking.
- Real-time collaboration across teams builds the strongest case possible.
- Data encrypted in transit and at rest for industry-leading security.
- Gain near-instant insight when a legal matter first arises.
- Simplify complex legal tasks with powerful yet accessible technology.
- Review most file types, including PDFs, CAD files, and Slack.
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 3 8 8 3 3 7 2 2 2 4 8 7 6 5
Contact
ANEXSYS LIMITED
Rob Crowley
Telephone: 07527 384 123
Email: tenders@anexsys.com
About the service
- Service categories
-
- Application Development and Deployment
- Analytics and business intelligence
- Business Intelligence
- Business Intelligence
- Advanced and predictive analytics
- Advanced and predictive analytics
- Business Intelligence
- Analytics and business intelligence
- Application Development and Deployment
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Everlaw maintains a predictable release schedule, operating on a standard four-week cycle for planned maintenance. Maintenance is scheduled by region and has a limited or no negative impact on the service's availability and functionality. When downtime is necessary, it typically lasts less than 30 minutes. Users are alerted to upcoming releases via an in-platform banner and can opt in to receive email notifications.
- System requirements
-
- Windows, MacOS, Linux for desktop/laptop, IOS, iPadOS, Android for mobile
- Minimum resolution is 960 x 700 pixels
- Any currently supported Windows OS running Google Chrome
- Any currently supported Windows OS running Edge v79+ (Chromium-based)
- Any currently supported Windows OS running Firefox
- Any currently supported Mac OS X supporting Safari
- Any currently supported Mac OS X supporting Chrome
- Any currently supported Mac OS X supporting Firefox
User support
- Email or online ticketing support
- Yes
- Support response times
- Our core support hours are Monday to Friday, 08:30 to 18:30. Users can log support requests using our ticketing facility 24/7. Outside of office hours, we typically provide an initial response to support requests within three hours in the evening, with overnight requests actioned the following day. We also offer enhanced support hours covering weekends and bank holidays by prior arrangement.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Anexsys delivers supplier support through a structured system featuring dedicated client teams, clear escalation routes, and measurable Service Level Agreements (SLAs) for response and resolution. Our team will support you from scoping and data collection to the processing, review and production. Our complete onboarding process ensures we understand your needs from the outset. You will have direct access to our security-cleared technical project managers. They all have extensive experience, and a large technical team supports them. Our support team can assist with more complex tasks such as creating layouts, search term reports, applying analytics functionality, and creating productions. We will seek your approval for any additional costs for completing complex tasks. Our Head of Public Sector serves as the primary point of contact and account manager. This role is responsible for client success, managing contract governance, tracking budgets and ensuring clients maximise the services offered. Contract governance and ongoing relationship management are led through the processes of our Strategic Client Solutions (SCS) team. The SCS team provides proactive service management, including biannual reviews, monthly reporting (such as storage usage reports and budget tracking) and making technology recommendations.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Our onboarding process starts with a kick-off meeting where we agree on the ordering and engagement process, key contacts, timelines, design templates and workflows, define security arrangements and agree on milestones. We also analyse existing skills within your team and determine what levels of training will be required. We then arrange online or face-to-face training using dummy data. We support all our training with comprehensive user guide documentation. We also support each new case with its own engagement process. With any new case, a scoping call will be required to determine data sources, sizes, whereabouts, and requirements specific to the case, such as de-duplication and search criteria. We will use previously agreed, bespoke templates to set up your new workspace, applying case-specific adjustments as required. We will also provide further training on the specific workspace at this stage so that reviewers are introduced to their case-specific data and workflows.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- Other
- Other documentation formats
- MP4
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- We discuss the accessibility requirements of your user base with you and agree on bespoke solutions for every contract. Following these discussions, our existing documentation can be adapted or new documentation created, keeping the audience's accessibility needs in mind. The platform natively supports browser-level accessibility features such as high contrast displays and large fonts. This can be supported through user-level configurations, such as implementing dark mode for light sensitivity or changing highlight colour sets for colour-blind users. While the core vendor documentation is in English, we routinely enhance and customise client-specific documentation, including instructions, presentations and videos, translating these to meet the needs of non-native English speakers. For video content, our integration with AWS Transcribe offers automatic subtitling capabilities for audio and video files. Written documentation can be offered in large fonts and/or high-contrast formats to support those with visual impairments. We use multiple media types in our knowledge transfer programmes, so providing users with the ability to choose the medium that is most accessible for them.
- End-of-contract data extraction
- We offer various closure options. We can export the entire database, including all the files and transmit these via sFTP. Data can then be restored in the future if required. Similarly, we can export the documents with the agreed metadata on an encrypted hard drive. Finally, we can delete all data. We also have options for the source data initially supplied for processing. Such source data can be stored for an agreed period, copied and returned, or deleted from our systems. We will only delete the data from our servers once you have confirmed that you can access your archive. We use forensically sound deletion processes, rendering data irretrievable from our systems.
- End-of-contract process
- Our case closure letter, issued in advance, outlines all available options and associated costs clearly. Options such as archiving, exports or extended data storage are priced on a sliding scale based on case size, providing visibility of what is included and what may incur additional charges. Deleting all project data from our systems is free of charge, and once completed, we provide a formal certificate of destruction for your records.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- Description of service interface
- Everlaw is known for its intuitive and user-friendly interface, designed to streamline the complex eDisclosure (aka eDiscovery) process. The layout is clean and modern, facilitating efficient navigation of large datasets. The primary document review window typically displays the document viewer alongside a contextual panel, enabling reviewers to apply codes, notes, and redactions easily. Advanced tools for searching, filtering, and data visualisation are readily accessible, with a strong focus on self-service capabilities. Everlaw's considered design ensures that legal professionals can focus on review and analysis with minimal fuss, enhancing productivity.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Everlaw designs its platform for professionals of all skill levels. It features an intuitive, colour-coded interface that simplifies complex eDisclosure tasks without requiring deep technical expertise. Everlaw targets WCAG 2.1 AA compliance and conducts automated and manual third-party audits against that standard. Examples of accessibility include providing skip links to bypass repeated blocks of content across multiple web pages, preventing changes in context when the focus changes, and identifying the associated form field when errors are detected.
- Accessibility testing
- Everlaw is periodically audited for compliance with Section 508 of the US Rehabilitation Act of 1973, and prioritises any accessibility issues that arise from these audits. Through this process, Everlaw has introduced many new features to its platform. Everlaw provides alternative text labels for images and form fields, enabling screen readers to identify icons, buttons, graphics, and text fields. Users can rely on the text label, not just the image, to understand what action to take or what the graphic means. Evewlaw presents errors as text errors and coloured markings to help users with differing accessibility requirements identify where errors are present. Everlaw also offers a wide variety of keyboard shortcuts, allowing the interface to be navigated equally by keyboard-only or mouse-only (or any combination), supporting its use by users with a wide variety of impairments and integration with a wide variety of third-party devices.
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- The API keys tab of the Organisation Admin dashboard lets you generate secure keys for your organization to connect your programs with Everlaw. Everlaw's API lets your custom programs interface directly with Everlaw to automate processes like custom reporting to provide detailed analytics, billing tracking, and uploading native data. Everlaw's API allows the flexibility to support your automation of complex and unique workflows at scale. Everlaw’s API empowers engineers or technical experts to build programs or scripts that interface with Everlaw. Everlaw’s Search API gives you the ability to build out custom analytics reporting with the same flexibility as Everlaw’s instant visual search. Everlaw’s Upload API lets you build programs to automatically upload native data to Everlaw, letting you automate your data pipeline and integrate your upload process with Everlaw. You can use Everlaw’s API to automatically pull billable size information for projects and databases, including ECA projects. This includes both final and peak sizes. Everlaw’s API also lets you pull project administration information for your organisation like users, latest user activity, user identifiers, permission groups, and some project settings. It also lets you track the most recent activity date for a project or database.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Different customisations are available depending on a user group's permissions, ranging from Organisation Admin, to Database Admin, to Project Admin, to customised granular user project permissions. User permissions can include restricting access to documents, categories/ codes and the whitelisting of locations, together with restriction of translation [and generative AI (GenAI)] features. From Everlaw's Organisation Admin module, an administrator simply needs to click "Add New Database" and provide a name. They may optionally build off of an existing project (case) or template (including codes, layouts, search term reports, production templates, and more). A new project will instantly be created with the desired settings. From there, the project can be further customised to meet the specific needs of that matter. Areas that can be customised include; homescreen layout; upload/ processing settings, including deduplication, OCR and imaging options; document clustering scope; search parameters (including parameters); results table metadata fields displayed; review window layout; assignments (batches) of documents and how these are delivered to reviewers; categories/ codes for tagging documents; redaction stamps; predictive coding model settings; production and other export settings; exhibit bundle configuration. Customisations are carried out in Everlaw's easy to use consumer friendly user interface , with wizard-driven processes for multi-stop customisations.
Scaling
- Independence of resources
- Everlaw is a cloud-native platform built on AWS. Its scalable architecture allows it to automatically and dynamically adjust its processing capacity and resources on demand. By leveraging the power of the cloud, Everlaw can effectively isolate the performance of different activities and users. High-volume tasks, such as data processing or complex searches initiated by one user, are provisioned with dedicated resources, preventing them from negatively affecting the speed and stability experienced by other reviewers concurrently undertaking tasks such as document coding.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The platform provides flexible reporting tailored to your needs, covering everything from high-level project statistics (e.g., data volumes processed and documents in review) to granular metrics (e.g., pages reviewed per hour or decision overturn rates). Reports can be delivered graphically and numerically via dashboards, with bespoke scripts for alerts and user-friendly insights. In addition, our Strategic Client Solutions (SCS) team specialises in creating custom reports and delivering any additional metrics beyond standard offerings, ensuring complete visibility of service usage.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Everlaw, by Everlaw UK Ltd
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- Data export is managed securely and in line with case and user requirements. User permissions strictly govern the ability to download documents, reports, or print content, and case manager approval is required before enabling these features. For large-scale exports, our team can handle these process or end-users can be guided through how to complete these in-house. Exported data can be delivered via Secure FTP for electronic transfer or provided on encrypted physical media, which can be collected or couriered as needed.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Concordance DAT file (standard legal export)
- PDF (Single Page and Multi-Page)
- Natives
- Text files
- Images (JPG, TIFF, PNG, etc)
- Media formats including MP3, MP4 and WAV
- XML
- Image Loadfile (OPT, LFP)
- Loadfile Formats (DII, LST)
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- Concordance DAT file (native, text and metadata files)
- CSV, HTML or TXT loadfiles (native, text and metadata files)
- Standard files such as Word, Excel and PDF
- Raw unstructured data such as PST, AD1 and ZIP files
- OPT files (images)
- Media formats including MP3, MP4 and WAV
- Platform-specific archive formats
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Everlaw’s uptime exceeds 99.95% annually, including scheduled maintenance windows. Everlaw's Recovery Time Objective (RTO) is 2 hours and Everlaw's Recovery Point Objective (RPO) is 4 hours.
- Approach to resilience
- Anexsys is an ISO 27001, ISO 9001 and Cyber Essentials Plus accredited organisation. Our data centres are ISO 27001 and SOC 2 compliant. The processes and security arrangements we have in place (protecting both physical and digital assets) are regularly audited for compliance, internally and externally. We have documented disaster recovery and business continuity procedures. You can view these by request. Everlaw consistently maintains an annual uptime exceeding 99.95%, inclusive of scheduled maintenance. Our business continuity and disaster recovery plans are developed using insights from regular risk assessments, vulnerability scans, and threat analyses, along with third-party and vendor risk evaluations. These plans and our incident response procedures are tested at least once a year, playing a crucial role in refining our continuous risk assessment and management strategies.
- Outage reporting
- The platform is actively monitored, and in the event of an outage or significant downtime, our in-house infrastructure team will be notified, and project managers will, in turn, issue email alerts to you. Email alerts will contain detailed information regarding our plans to address the issue(s), the root cause, and the expected length of the outage.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- Everlaw supports single sign-on (SSO) via the SAML 2.0 protocol, allowing customers to log into Everlaw via their organisation’s existing LDAP or other SSO system. If organisations use SSO, they also have the option to require SSO; requiring SSO will disable Everlaw’s optional password-based login process.
- Access restrictions in management interfaces and support channels
- Access in management interfaces and support channels is controlled by adhering to the Principle of Least Privilege and using Role-Based Access Controls (RBAC). Access is denied by default and granted only when explicitly authorised based on a user’s job function. Permissions are highly granular and flexible, allowing user access to be configured to match the user’s job role. Permissions control which databases and data can be accessed, the ability to import/export data and access to the administrator interface. All actions are immutably logged and fully auditable for accountability. All access granted for troubleshooting is strictly Just-In-Time (JIT) and fully logged.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
- Everlaw supports single sign-on (SSO) via the SAML 2.0 protocol, allowing customers to log into Everlaw via their organisation’s existing LDAP or other SSO system. If organisations use SSO, they also have the option to require SSO; requiring SSO will disable Everlaw’s optional password-based login process.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Software Security Code of Practice
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Anexsys’ policies for handling client data are laid down by our parent, Consilio, and ensure that data and devices are stored securely and protected from unauthorised access while in our possession. We treat all client data as confidential. Our enterprise privacy structures and policies ensure that we meet international, EU and UK privacy regulations. These include the Data Protection Act 2018, the General Data Protection Regulations, the Computer Misuse Act 1990, Part 2 of the Serious Crime Act 2015, the Communications Act 2003, the Regulatory and Investigatory Powers Act 2000, GDPR, HIPAA, ITAR, CCPA, and others. They also include HMG security requirements such as security considerations for protecting OFFICIAL information on a corporate network, the Cloud Security Principles, End User Device security guidance and Browser Security guidance. Compliance with ISO standards ensures that we are committed to meeting your needs and protecting our information and data. Completing regular internal and external audits of our quality and information security management systems is a mechanism to show that we are continually improving and learning.
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- All changes are documented and approved by Everlaw's Configuration Change Review Group (CCRG), which ensures that all modifications meet its strict quality and security standards. Changes with security implications are subject to a Security Impact Analysis. For urgent modifications, Everlaw employs an emergency change management process. Everlaw's change management procedures apply uniformly across the board. Every change is logged, analysed for security implications, and must receive formal approval before implementation. Everlaw comprehensively documents its change management policies and procedures and reviews them annually. In addition, our change management process includes internal and external notification protocols based on the change's impact.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Everlaw has an ongoing vulnerability management programme that utilises a variety of vulnerability scanning tools to assess its internal and external network environments against emerging security threats, including OWASP Top 10 security risks. These tools are carefully configured to match our infrastructure requirements and are updated monthly. Everlaw has an established process to log, prioritise, and remediate discovered vulnerabilities. As described above, in addition to our internal scanning and testing program, Everlaw employs an independent testing team to perform vulnerability scanning and penetration testing on at least an annual basis.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Everlaw has an on-call team to respond to specific alerts. Through vulnerability scanning, the use of intrusion detection and intrusion prevention systems, and by subscribing to industry and government alerts (e.g., US-CERT), we keep a continuous watch on the security of our customers’ data. Everlaw’s monitoring program uses a combination of open-source and commercial tools such as Host Intrusion Detection Software (HIDS). We also leverage security logs generated by AWS firewalls to monitor suspicious activity. Everlaw security and site reliability engineers actively monitor alerts on our system configuration and any anomalies.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Post-quantum cryptography secure
- No
- Incident management approach
- We use well-defined incident response procedures, triggered by security alerts and 24/7 monitoring by a security operations vendor. This includes escalation protocols to management and client notification protocols, especially if client data is compromised. Users report incidents via a dedicated email address for non-urgent issues, or directly via telephone during working hours. For complex issues, Anexsys diagnoses the problem and seeks a permanent solution while developing workarounds. The process for providing an incident report is client-specific and timelines depend on the nature of the incident. We secure data first, then provide transparency on the issue and detailed proposals for remediation.
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- Schellman Compliance LLC
- ISO/IEC 27001 accreditation date
- Monday 6 January 2025
- What the ISO/IEC 27001 doesn’t cover
- All our services are covered by our ISO/IEC 27001 certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- British Assessment Bureau Ltd
- ISO 9001 accreditation date
- Wednesday 13 August 2025
- What the ISO 9001 doesn’t cover
- All our services are covered by our ISO 9001 certification.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 9986e0a6-b241-4960-8f41-12bf072baecc
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- 49743f06-ea2e-449d-a61a-50c1c2a1e8b4
- Other security certifications
- Yes
- Any other security certifications
-
- HITRUST certified (CSF V9.3)
- FedRAMP
- SSAE-16 SOC 1 and SOC 2
- ISO 9001 and ISO 14001
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d