Luminance AI Vendor Risk Profile
Cambridge-founded legal AI platform for contract review, negotiation, and compliance. SOC 2 Type II + ISO 27001 + GDPR. Used by 25% of the world's largest law firms across 600+ customers in 70 countries (AMD, BBC Studios, DHL among them). $75M Series C in 2026 (Point72, Forestay, RPS, Schroders) brought total funding past $115M.
Risk overview
Risk score: 40/100
Risk tier: Elevated
Safety rating: 60/100 (higher is better)
Lower risk scores indicate lower assessed risk.
Last verified: May 18, 2026 Fresh
Risk dimensions
| Dimension | Risk score |
|---|---|
| Data Handling | 72/100 |
| IP Exposure | 16/100 |
| Jurisdiction | 8/100 |
| Security | 34/100 |
| Regulatory Compliance | 60/100 |
| Transparency | 60/100 |
| Business Stability | 25/100 |
| Dependency Chain | 40/100 |
| Agent Governance | Not assessed |
Analyst summary
Rating: Recommended
Luminance is the most credentialed of the dedicated legal-AI platforms operating from the UK. SOC 2 Type II, ISO 27001, GDPR, hosted on Azure with multi-region data residency, no training on customer data. 600+ customers across 70 countries including a quarter of the world's largest law firms. The $75M Series C in 2026 (Point72-led) and $115M+ cumulative funding place it on stable financial footing, and the UK-incorporation gives EU buyers post-Brexit data adequacy without the US CLOUD Act exposure that Harvey carries.
Bottom line: Strongest non-US legal AI vendor on the market. Compliance posture, customer roster, and jurisdiction profile make Luminance a defensible default for EU/UK legal teams; US buyers without HIPAA or FedRAMP requirements should also short-list it alongside Harvey and CoCounsel.
Strengths
- SOC 2 Type II and ISO 27001 — full enterprise security baseline
- GDPR compliant; UK-incorporation provides post-Brexit data adequacy with the EU
- Customer documents explicitly excluded from training
- Multi-region data residency (UK / US / EU / AU) including hosted Azure tenancy
- 600+ customers in 70 countries; 25% of world's largest law firms — broad enterprise validation
- Public DPA and subprocessor list; indemnification offered
Concerns
- No HIPAA BAA — not appropriate for processing PHI
- No FedRAMP authorization — not currently appropriate for US federal legal workloads
- ISO 42001 not yet pursued
- Proprietary model corpus details limited; provenance specifics not fully disclosed
- Five-Eyes-aligned jurisdiction may matter for buyers concerned about UK Investigatory Powers Act exposure
Best for
- Mid-market and enterprise legal teams across the UK and EU with multi-jurisdiction operations
- Procurement and corporate-counsel functions needing contract-review automation with mature compliance posture
- Buyers who want a non-US alternative to Harvey or CoCounsel
Avoid if
- You require a HIPAA BAA or healthcare-data workload
- Your procurement requires FedRAMP authorization
- You need a vendor with ISO 42001 AI-management-system certification today
Citations
- Data Handling — Trains On User Data
- Security Compliance — Iso 27001
- Security Compliance — Soc2 Type2
- Vendors — Funding Total Usd
- Vendors — Description