Harvey vs Legora: A Buying Guide for Law Firm Leadership

Three people in business attire reviewing and signing a document in an office
Foto: Vitaly Gariev via Unsplash

American legal AI company Harvey is pushing harder into Europe, the market that Swedish rival Legora calls home. In an interview with Sifted, Harvey’s Europe chief Jorge Bestard said the company plans to double its regional headcount this year, open new offices and actively pursue acquisitions, with Europe expected to drive a large share of Harvey’s global growth (Breakit). For a Swedish law firm or in-house legal team already evaluating Harvey and Legora, or about to start, that context matters: a well-funded American challenger is deliberately targeting the ground Legora built its business on.

This guide does not name a winner. Harvey and Legora are both enterprise sales operations that price on request, and both publish security and product claims that change as fast as the market does. What follows is a comparison built strictly from each vendor’s own current pages, organized around the questions a managing partner, general counsel or legal ops lead actually needs answered before signing anything.

Two companies, two starting points

Legora was founded in Stockholm in 2023 and says its technical team is still based in Sweden, a point the company ties directly to its data protection posture (Legora, Security). Harvey is a US company, backed among others by Sequoia and Andreessen Horowitz according to Breakit’s reporting, and has been expanding its European footprint through new hires and offices, including a London team that CEO Winston Weinberg says has grown past 75 people alongside expansion into Spain and Germany (Harvey, company blog).

Both companies raised large funding rounds in the same month this spring, and both are now selling into overlapping accounts. Legora’s own customer page states it works with “800+ leading law firms and in-house legal teams globally” (Legora, Customers). Harvey’s homepage cites more than 70 AmLaw 100 firms among its clients (Harvey, homepage). Some names appear on both vendors’ public customer pages, Dentons among them, a reminder that firms often pilot more than one platform rather than choosing exclusively.

What each platform actually does

Legora organizes its offering into named modules: Legora Agent for end-to-end agentic legal work, Tabular Review for turning large sets of contracts into a queryable grid (its signature feature for due diligence and portfolio review), a Word add-in and Outlook add-in for drafting and email work, Legal Research with source citations, Monitors for regulatory tracking, and a Portal, Lists, Assistant and mobile app for delivery and day-to-day use (Legora, Product).

Harvey’s own product pages describe a similar set of building blocks under different names: Assistant for chat, drafting and document analysis, Vault for bulk cross-document review of up to 10,000 files per project, Knowledge for legal, regulatory and tax research, Workflow Agents for building multi-step processes without code, Contract Intelligence for negotiation support, and add-ins for Word, Outlook and mobile (Harvey, homepage; Harvey, Ecosystem). Vault and Tabular Review target the same bulk-document use case; Assistant and Legora Agent both aim at end-to-end drafting and review. Buyers evaluating the two should ask for a side-by-side demo on the same document set rather than assume the marketing names map cleanly onto each other.

Sweden and Nordic coverage: the question this pitch is actually about

Three different things get blurred in legal AI marketing: the language of the user interface, the language of the documents a tool can process, and the tool’s actual knowledge of a jurisdiction’s law. They are not the same, and neither vendor’s current public pages spell out all three clearly.

Harvey is the more explicit of the two here. Its own product blog names Sweden directly as a covered jurisdiction, alongside Australia, Austria, Finland, Germany, India, the Netherlands, Norway, Singapore, Spain and Switzerland, stating the expansion adds “Swedish legislation and case law” sourced from government legal databases (Harvey, Expanding global data coverage). That is a specific, checkable claim about legal content, not about the interface language.

Legora makes no equivalent public claim. Its product and security pages describe “jurisdiction-aware legal research grounded in real sources” without naming which jurisdictions (Legora, Product), and its dedicated supported-countries page lists where the service can be accessed commercially (essentially the whole world, with a caveat for China) rather than which jurisdictions’ law it has been trained or grounded on (Legora, Supported countries). What Legora does say clearly is that its own technical team sits in Sweden and that the company operates under GDPR as a result (Legora, Security), and its customer page names several Nordic and Swedish-market firms, including Setterwalls, Mannheimer Swartling, Lindahl, BAHR, Borenius and Gorrissen Federspiel (Legora, Customers). Harvey’s own published customer list, by contrast, does not include a Swedish-named firm at the time of writing, though it names other Nordic and European firms such as Thommessen in Norway (Harvey, Customers).

Neither company’s marketing pages state outright which language the working interface itself is available in beyond English. For a Swedish buyer, that gap matters more than any feature list: ask both vendors, in writing, exactly which Swedish legal sources ground their research answers today, how current those sources are kept, and whether the interface and output can be produced in Swedish or only translated into it after the fact.

Security and regulatory compliance: read past the badge row

Both vendors list a broadly similar set of certifications. Legora states it is “fully certified with ISO 27001” and holds ISO 42001 for AI governance, and says it meets SOC 2 requirements (Legora, Security). Harvey cites “annual SOC 2 Type II and ISO 27001 audits” plus ISO 27701 and ISO 42001, and references alignment with GDPR and CCPA (Harvey, Security). Neither GDPR nor CCPA is a certification a vendor can be “certified” against, so read those two specifically as compliance claims, not audited credentials, and ask for the current audit report rather than the logo.

On data residency, Harvey says customers can choose to have data processed in “EU and Switzerland, US, or Australia,” hosted on Microsoft Azure (Harvey, Security). Legora offers EU/EEA, US and Asia-Pacific processing options and names its EU-region sub-processors explicitly, including Microsoft Ireland, AWS EMEA in Luxembourg, Google Cloud EMEA in Dublin and DeepL in Cologne (Legora, EU pre-approved sub-processors). Both companies state that customer data is not used to train their underlying models by default: Harvey says “we don’t use inputs, outputs, or uploaded documents to train underlying models” (Harvey, Security), and Legora says “Legora will not use your data to train or fine tune any AI models” (Legora, Security). Legora additionally publishes specifics on encryption (AES-256 at rest, TLS 1.2 or higher in transit) and offers a bring-your-own-key option (Legora, Security); Harvey’s public security page confirms encryption of data at rest and in transit but without the same level of technical detail (Harvey, Security). For a Swedish advokatbyrå, the practical follow-up is the data processing agreement itself, not the security page: ask which specific sub-processors will touch client files, in which country, and get that confirmed in the signed DPA rather than the marketing copy.

A procurement checklist for firm leadership

  • Ask each vendor to confirm, in writing, which sources their Swedish and Nordic legal content is drawn from today, and how it is kept current, not just whether the jurisdiction is “covered.”
  • Get the current audit reports (SOC 2 Type II, ISO 27001) rather than relying on the certification logos on the website; certificates expire and audits are point in time.
  • Confirm the specific data processing region and named sub-processors in the DPA, not the general security page, especially if client confidentiality rules require EU-only processing.
  • Get the no-training-on-customer-data commitment written into the contract, since both vendors currently state this as policy but policies can change.
  • Test both platforms on your own real (anonymized) documents and workflows rather than a vendor demo set, and involve the associates and paralegals who will use the tool daily, not only the partners evaluating it.
  • Ask for reference clients in the same practice area and, where possible, the same jurisdiction, since a strong reference in US litigation says little about Swedish contract review.
  • Clarify exit terms: what happens to stored documents and any custom playbooks or configurations if the firm switches vendors later.

Harvey’s push into Europe makes this comparison timely, but the underlying advice is not new: enterprise legal AI is sold on relationship and configuration as much as on features, and the vendor that answers the jurisdiction and data-residency questions in writing, rather than in a sales deck, is the one giving a law firm’s leadership something it can actually act on.

Leave a Comment