Harvey vs Legora: A Buying Guide for Law Firm Leadership

Three people in business attire reviewing and signing a document in an office
Photo: Vitaly Gariev via Unsplash

American legal AI company Harvey is expanding in Europe. In an interview with Sifted, Harvey’s VP of EMEA Jorge Bestard said the company plans to double its regional headcount this year, open new offices and actively pursue acquisitions, and that Europe is expected to drive 35 percent of Harvey’s global growth (Sifted, summarized in Swedish by Breakit, which is behind a paywall). Legora, a Swedish company in the same market, sells into many of the same accounts. For a Swedish law firm or in-house legal team already evaluating Harvey and Legora, or about to start, the useful question is not who is gaining ground on whom, but which vendor answers a buyer’s questions in writing.

This guide does not name a winner. Neither vendor publishes price levels, and neither has a public pricing page. They do differ in what they say publicly about the pricing model itself. Legora announced on 23 June 2026 that it is moving to consumption-based pricing for its most capable product, Agent Pro, where “you only pay for the work Agent Pro delivers”, while the standard Legora Agent “is available to our customers at no additional cost” (Legora, Introducing consumption-based pricing). Harvey publishes no pricing model, but does publish ROI calculators for law firms and in-house teams. What follows is a comparison built from each vendor’s own public pages, organized around the questions a managing partner, general counsel or legal ops lead needs answered before signing anything.

Two companies, two starting points

Legora is a Swedish company and says on its security page that its technical team is based in Sweden, a point it ties directly to its data protection posture. The same page also states that Legora “has both EU-based and US-based technical work forces” (Legora, Security). Harvey is a US company, backed by Sequoia and Andreessen Horowitz among others, according to Breakit’s reporting, and has been expanding its European footprint through new hires and offices, including a London team that CEO Winston Weinberg says has grown to 75+ employees alongside expansion into Spain and Germany (Harvey, company blog).

Both companies raised large funding rounds in March this year, and both are now selling into overlapping accounts. On the closest thing to a like-for-like measure, each vendor’s own count of customer organizations, Legora says it is “trusted by 800+ leading law firms and in-house legal teams globally” (Legora, Customers), while Harvey’s homepage gives 2,400+ law firms and in-house legal teams, alongside 200,000+ professionals and 70+ countries (Harvey, homepage). Harvey additionally reports 75+ AmLaw 100 firms among its clients, a US-specific measure Legora publishes no equivalent for. None of these numbers are audited and the two companies may well count differently, so read them as marketing claims rather than market share. Some names appear on both vendors’ public customer pages, Dentons among them, a reminder that firms often pilot more than one platform rather than choosing exclusively.

What each platform does

Legora organizes its offering around the Legora aOS, which it describes as a single connected system for legal work, with named modules on top: Agent for end-to-end agentic legal work, Tabular Review for turning large sets of contracts into a queryable grid (its signature feature for due diligence and portfolio review), Workflows for orchestrating multi-step work, an Editor, Legal Research with source citations, Monitors for regulatory tracking, and a Portal, Lists, Word and Outlook add-ins and a mobile app for delivery and day-to-day use (Legora, Product).

Harvey’s platform menu lists a similar set of building blocks under different names: Agents for executing complex legal work end to end, Vault for bulk cross-document review, which Harvey says can hold up to 100,000 documents per vault (Harvey, Vault), Knowledge for legal, regulatory and tax research, Shared Spaces for working across organizations, Command Center for analytics and adoption benchmarking, Contract Intelligence for negotiation support, Harvey Mobile, and an Ecosystem of integrations and add-ins (Harvey, homepage; Harvey, Ecosystem). Vault and Tabular Review target the same bulk-document use case; Harvey Agents and Legora Agent both aim at end-to-end drafting and review. Buyers evaluating the two should ask for a side-by-side demo on the same document set rather than assume the marketing names map cleanly onto each other.

Sweden and Nordic coverage: the question that decides it

Three different things get blurred in legal AI marketing: the language of the user interface, the language of the documents a tool can process, and the tool’s actual knowledge of a jurisdiction’s law. They are not the same, and neither vendor’s current public pages spell out all three clearly.

Both vendors do name Swedish primary law sources on their own pages. Harvey’s product blog lists Sweden among its covered jurisdictions, with “Swedish legislation and case law” drawn from Regeringskansliets rättsdatabaser and Sveriges Domstolar (Harvey, Expanding global data coverage). Two caveats belong with that. Sweden appears there as existing coverage, not as part of the eight new national sources the post announces, and the post is dated July 2025, so both its source list and the customer figures in it are a year old. Ask Harvey to confirm what is covered today.

Legora names its sources on its Legal Research page, which lists Sveriges domstolar for Sweden alongside Lovdata for Norway, Retsinformation for Denmark and Finland’s national legal information service, plus EDGAR, EUR-Lex and a set of commercial publishers (Legora, Legal Research). That page carries no date, so it is no more verifiably current than Harvey’s blog post. Legora’s separate supported-countries page is a different thing again: it lists where the service can be bought and used commercially, nearly the whole world with caveats for China and for parts of Ukraine, and says nothing about which law the product is grounded in (Legora, Supported countries). Neither vendor’s list tells a buyer how deep the Swedish material goes or how often it is refreshed.

Both vendors also point to Nordic references. Legora’s customer page names Mannheimer Swartling, Lindahl, BAHR, Borenius and Gorrissen Federspiel among others (Legora, Customers). Harvey’s customer page names Setterwalls in Sweden, Thommessen in Norway and Bruun & Hjejle in Denmark, and carries a published customer story about Vinge, which Harvey describes as “one of the leading Nordic law firms” with offices in Stockholm, Gothenburg, Malmö and Brussels (Harvey, Customers; Harvey, Vinge customer story). A logo grid is not a reference check, so ask for a firm you can actually call.

Neither company’s marketing pages state outright which languages the working interface itself is available in beyond English. For a Swedish buyer, that gap matters more than any feature list: ask both vendors, in writing, exactly which Swedish legal sources ground their research answers today, how current those sources are kept, and whether the interface and output can be produced in Swedish or only translated into it after the fact.

Security and regulatory compliance: read past the badge row

Both vendors list a broadly similar set of certifications. Legora states it is “fully certified with ISO 27001” and holds ISO 42001 for AI governance, and says it meets SOC 2 requirements (Legora, Security). Harvey cites “annual SOC 2 Type II and ISO 27001 audits” plus ISO 27701 and ISO 42001, and references alignment with GDPR and CCPA (Harvey, Security). Read the GDPR and CCPA entries carefully, whichever vendor lists them, because neither is a certification anyone can be audited and certified against. Both companies still place them in a badge row, and Legora goes a step further by listing GDPR under the heading “Certified” in the footer of every page on its site. Ask for the current audit report rather than the logo.

On data residency, Harvey says customers can keep everything in-region, “EU or Switzerland, US, or Australia”, hosted on Microsoft Azure, and publishes a subprocessor list naming Microsoft, OpenAI, Google Cloud, Amazon Web Services, Anthropic and ElevenLabs, last updated in April 2026 (Harvey, Security; Harvey, Subprocessor list). Legora offers EU/EEA, US and Asia-Pacific processing options and publishes a longer EU-region sub-processor table, updated in July 2026, naming Microsoft Ireland, AWS EMEA in Luxembourg, Google Cloud EMEA in Dublin, OpenAI Ireland, DeepL in Cologne, Intercom, Linkup Technologies in France and turbopuffer Inc. of Ottawa for hosting (Legora, EU pre-approved sub-processors). Note that both lists include US-headquartered AI providers and that Legora’s EU table includes a Canadian hosting entity, so “EU processing” is a claim about where data sits, not about who owns the company processing it.

Both companies state that customer data is not used to train their underlying models by default. Harvey says it “contractually guarantees through our Platform Agreement” that “we don’t use inputs, outputs, or uploaded documents to train underlying models”, and describes enforcement of a firm’s existing ethical walls inside the product (Harvey, Security). Legora says “Legora will not use your data to train or fine tune any AI models”, and publishes more encryption detail than Harvey does, naming AES-256 at rest and TLS 1.2 or higher in transit, with a bring-your-own-key option (Legora, Security). For a Swedish law firm, the practical follow-up is the data processing agreement itself, not the security page: ask which specific sub-processors will touch client files, in which country, and get that confirmed in the signed DPA rather than the marketing copy.

A procurement checklist for firm leadership

  • Ask each vendor to confirm, in writing, which sources their Swedish and Nordic legal content is drawn from today, and how it is kept current, not just whether the jurisdiction is “covered.”
  • Ask how you will be billed and what triggers the bill: per seat, per consumption or a mix, what the base contract includes, what is metered separately, and which spending controls you get.
  • Get the current audit reports (SOC 2 Type II, ISO 27001) rather than relying on the certification logos on the website; certificates expire and audits are point-in-time.
  • Confirm the specific data processing region and named sub-processors in the DPA, not the general security page, especially if client confidentiality rules require EU-only processing.
  • Get the no-training-on-customer-data commitment written into the contract, since both vendors currently state this as policy but policies can change.
  • Test both platforms on your own real (anonymized) documents and workflows rather than a vendor demo set, and involve the associates and paralegals who will use the tool daily, not only the partners evaluating it.
  • Ask for reference clients in the same practice area and, where possible, the same jurisdiction, since a strong reference in US litigation says little about Swedish contract review.
  • Clarify exit terms: what happens to stored documents and any custom playbooks or configurations if the firm switches vendors later.

Both vendors are expanding quickly, which makes any comparison built on their public pages a snapshot rather than a verdict. The underlying advice is not new: enterprise legal AI is sold on relationship and configuration as much as on features, and the vendor that answers the jurisdiction, pricing and data-residency questions in writing, rather than in a sales deck, is the one giving a law firm’s leadership something it can act on.

Last fact-checked: 30 July 2026. Last updated: 29 August 2026