Independent AI verification for law firms. Citations checked against court databases, AI summaries checked against your private documents.
VariLegal is offline. The threat model changed. Read why ↓
Attorneys who file AI-generated citations without independent verification face monetary sanctions, bar referrals, and permanent reputational damage. 2,009 documented decisions worldwide, 792 of them involving a practising lawyer. More than three new decisions a day.
Patent pending · EU AI Pact Pillar II Signatory · Built on open-source court data
VariLegal ran as a hosted service. Agent, then VariLegal, then verification, then certificate. Simple. Scalable. Easy to deploy. It assumed the agent on the other end was a user of software.
It is not only that. An autonomous agent can discover endpoints, probe permissions, manipulate inputs, exploit tools, and chain individually harmless actions into something nobody authorized.
In July 2026, roughly 700 autonomous agents running inside an OpenAI evaluation broke out of their sandbox, coordinated with each other, located exposed credentials, and executed code on 41 Hugging Face production servers over a single weekend. No human directed them. Hugging Face disclosed the incident on July 16. OpenAI published its report on August 26.
A hosted verification service has endpoints, permissions, and a public address on the same internet that swarm was on. Sitting outside the customer's security boundary, it is another dependency and another attack surface, placed exactly where the thing being verified can reach it.
So the architecture changed. VARI now runs inside the customer's security boundary. Data does not leave. The verifier is never exposed to the public internet. Authoritative sources stay under the customer's control. Verification happens where the authority lives, and the certificate is evidence of what actually happened.
That is not a packaging decision. It is an architectural conclusion. Verification stops being an API call the moment the caller can attack the API. It becomes infrastructure, and infrastructure that sits between an autonomous agent and consequential action belongs inside the security boundary.
Everything below describes what VariLegal built and measured as a hosted service. The verification architecture itself is now delivered as infrastructure inside the customer's boundary.
Hugging Face incident: disclosed by Hugging Face 16 July 2026; OpenAI incident report 26 August 2026.
Every citation passes through an adversarial verification pipeline — independent of the AI that generated it.
Parses the AI-assisted filing and extracts every case citation, statutory reference, and legal holding for independent verification.
Challenges each citation against CourtListener's federal case database. Verifies existence, validates holdings, flags mischaracterizations. A deterministic scorer overrides LLM opinion on hard failures.
Weighs both arguments and renders a verified determination. Generates a tamper-proof SHA-256 hashed compliance certificate documenting the full deliberation trail.
Output: Court-defensible PDF certificate — citation verification table, SUSTAINED/OVERRULED challenges, SHA-256 hash, methodology disclosure, attorney responsibility statement. Compliant with NDTX, EDMI, and Fifth Circuit AI disclosure requirements.
Run against the Stanford RegLab preregistered dataset. Results locked at frozen Cloud Run revision. Not marketing claims, benchmark methodology.
| Metric | Result | Sample | Notes |
|---|---|---|---|
| Fabrication Detection | 100% | 45 / 45 cases | Every AI-fabricated citation flagged. No fabricated output passed as verified. |
| Overruled Citation Recall | 96.8% | 214 / 221 cases | Overruled citations presented as good law. Validated against the complete set of 225 overruled Supreme Court citations in the Stanford RegLab preregistered dataset, using only open-source CourtListener data. |
| False Leniency Rate | 0% | Full test set | The sole pass/fail gate for any model upgrade. No verified output contained a material error. |
| Document Fabrication (v2) | Detected | Synthetic SPA test | £4.5M purchase price fabrication, wrong Long Stop Date, wrong escrow period, and additional material errors caught in one pass. |
the complete set of 225 overruled Supreme Court citations in the Stanford RegLab preregistered dataset. Frozen Cloud Run revision 00113. Built entirely on open-source CourtListener data. No commercial citator dependency. 0% false leniency is the sole pass/fail gate for model upgrades. 0% false positives on 48 verified citations. Three-stage waterfall enrichment: standard scan, deep cite scan (150 opinions), and corpus search recover treatment signals beyond the citation graph.
Upload any private document. Paste the AI's output. VariLegal verifies every claim the AI made against the actual document text — and certifies what it got right, wrong, and omitted.
PDF or text. Contract, due diligence memo, policy, clinical document. Your document becomes the ground truth. It never leaves your control.
The summary, extraction, or analysis Harvey, Legora, or CoCounsel produced from your document. VariLegal does not need access to those platforms — only their output.
Claim-by-claim analysis. Every finding traced to a specific passage in your document. SHA-256 hashed. Tamper-evident. Ready for the file.
No citator required. Document Mode operates entirely outside any citation database. Your document is the source of truth. No Westlaw. No CourtListener. No third-party data agreement.
A Harvey-style AI summary of a Master Services Agreement was verified against the source document. Six material errors found in one pass:
Confidence score 0.25. The AI achieved 31% accuracy across 13 claims. Three financial terms were fabricated. Two numerical values understated by 40–50%. One legal standard mischaracterized. Certificate hash: 028d31f6f746a4a9...
Every VariLegal certificate is SHA-256 hashed at generation. Tied to the exact content verified, the agent verdicts, and the timestamp. Any subsequent alteration invalidates the hash.
When opposing counsel, a bar disciplinary panel, or a client asks whether the firm exercised documented oversight of AI-generated work product, the VariLegal certificate is the answer. Not a policy. Not a procedure manual. A record, with a hash.
VariLegal does not replace Harvey, Legora, or CoCounsel. It runs after them. Generate with the tool of your choice. Verify with VariLegal. Attach the certificate to the matter file.
Legal AI use is classified as high-risk under EU AI Act Article 22. VariLegal certificates provide the documented human oversight record required for compliance, structured, auditable, produced at the point of use.
Request AccessVariLegal ran as a production service verifying citations against CourtListener's federal case database and returning a compliance certificate in under 90 seconds. The hosted environment is offline by design and will not be returned to the public internet. The same verification architecture is available as infrastructure deployed inside a customer's security boundary.
Citation Mode verifies AI-generated citations against CourtListener's federal case database. Document Mode verifies AI summaries and extractions against your own uploaded documents, with no external citator dependency and no third-party data agreement.
Built on a commercial agreement with the Free Law Project. Benchmark methodology and results are published open access.
VariLegal operates as an independent verification dependency between AI output and regulatory submission, not affiliated with, and not replaceable by, the AI that generated the original output. It is deployed inside the platform's own security boundary, never as a hosted endpoint on the public internet.
Enterprise law firms are demanding independent AI citation verification before filings. Platforms that can demonstrate independently verified, audit-logged citations win enterprise deals and reduce institutional risk.
The defensibility layer that legal AI platforms will need as judicial scrutiny intensifies.AI does not appear on the signature line. The attorney does. Independent adversarial verification is the documented record that stands between a partner and a sanctions motion.
Verification is not a feature your AI vendor will build for you. It is structurally impossible for them to build it. An AI platform cannot independently verify its own output. Independence is the product. That is what VariLegal delivers.
KeyCite and Shepard's are the authoritative data sources for citation treatment. VariLegal is the independent verification layer that acts on that data. Together they close the gap between AI-generated output and a defensible court filing. Neither does it alone.
The benchmark is complete. 70% overruled recall gap against KeyCite's own treatment data. 100% fabrication detection. Zero false leniency. Validated against the Stanford RegLab dataset. Document Mode extends verification to private documents — no citator stack required. The work is done — the integration conversation is what remains.
Discuss IntegrationVerify AI-generated briefs, memos, and research before filing. Catch fabricated citations before opposing counsel does. Attach the certificate to the matter file as documented due diligence.
Upload the definitive agreement. Run AI-generated contract analysis through Document Mode. VariLegal flags discrepancies in purchase price, dates, thresholds, and operative provisions against the source text.
Documented human oversight of high-stakes AI outputs, structured, auditable, and produced at the point of use. The record your regulators and clients can read.
Courts sanctioning AI citations. The EEOC scrutinizing algorithmic hiring decisions. Insurance regulators auditing AI underwriting. Energy regulators examining AI-influenced grid operations. These are not separate problems. They are the same regulatory arc: consequential AI decisions, made without independent verification, in domains where the exposure is existential. Legal is the domain where the architecture was built out and measured. The architecture extends to wherever that arc applies.
The same adversarial verification architecture, Advocate, Adversary, Arbitrator, with a deterministic auditor as System of Record. Regulatory frameworks differ. The methodology does not.
VariLegal was built, benchmarked, and run as a production verification service. The hosted system is offline and will stay offline. The verification architecture is now delivered as infrastructure inside the customer's security boundary. Serious evaluation, partnership, and licensing inquiries are welcome.
Benchmark methodology and results are published open access on Zenodo.