

Everlaw
By Everlaw
The typical implementation process for Everlaw:
Database setup is initiated by naming the project and assigning a default timezone.
Training resources (Knowledge Base, Training Center, live sessions) are available at no extra cost.
Required permissions (Upload, Full Document, or Partial Project Document Management) must be granted before upload.
Everlaw processes uploaded data to prepare it for review, supporting a wide range of file types and formats.
Users can begin document review and configure project settings as soon as data is processed.
Everlaw can be extensively customized to fit specific business needs across a wide range of features and workflows. Here are key data points that highlight its customization capabilities:
Custom Codes and Coding Sheets:
Project administrators can create custom codes (tags) and coding sheets tailored to the needs of each case, allowing reviewers to apply relevant tags to documents and streamline review processes.
Results Table and Review Window Customization:
Users can customize the results table by configuring displayed information, reordering columns, and setting sorting preferences.
The review window layout can be modified by adding or removing tabs and toolbar icons, and multiple custom layouts can be saved and shared across users or set as project defaults.
User Groups and Project Permissions:
Administrators can create custom user groups with specific permission sets, ensuring that each team member has the appropriate level of access and functionality for their role.
Assignments and Workflows:
Everlaw allows administrators to create assignment groups, assign documents to specific reviewers, and track progress, enabling tailored review workflows for responsiveness, privilege, QA, and more.
Metadata and Field Management:
Users can manage and customize metadata fields, create aliases for metadata (e.g., combining “From” and “Author” into a single “Creator” field), and set editable metadata for flexible data handling.
Attachment Grouping:
Administrators can define which metadata fields are used for attachment grouping, ensuring that related documents (like emails and their attachments) are logically grouped during review and analysis.
API and Automation:
Everlaw’s API allows for custom integrations, automated data uploads, custom analytics reporting, and the extraction of project administration information, supporting advanced automation and technical workflows.
Homepage and Layout Customization:
The platform supports customization of the homescreen layout and upload/processing settings, including deduplication, OCR, imaging options, and document clustering scope.
Search and Analytics Customization:
Search parameters, results table metadata fields, predictive coding model settings, and analytics can be tailored to fit specific cases or business requirements.
People Profiles and Storybuilder:
Users can create fully customizable profiles for individuals involved in a case, including photos, job information, and notes, and use Storybuilder to organize documents into narratives for case preparation.
Production and Export Settings:
Export and production settings can be customized, including redaction stamp configuration and exhibit bundle setup, to meet specific production requirements.
Single Sign-On (SSO) and Security:
Everlaw provides a suite of training and support options tailored for new users, ensuring a smooth onboarding experience and ongoing mastery of the platform:
Onboarding Support:
Everlaw offers fully inclusive onboarding services for each new case, including data ingestion consultation, kickoff calls with the Customer Success team, platform migration assistance, initial database creation, and interactive live training sessions.
Training Center and Resources:
The Everlaw Training Center features a wide array of free resources, such as how-to videos, downloadable guides, quick start tutorials, and deep dive sessions on specific features and workflows.
Live and virtual training sessions are available regularly, covering everything from introductory navigation to advanced features and AI-powered tools.
Knowledge Base:
An extensive Knowledge Base provides step-by-step instructions, best practices, and troubleshooting guides for all aspects of the platform.
24/7 Support:
Technical support is available via phone, email, online ticketing, and in-platform messaging.
Phone support is available 24 hours a day, Monday through Friday, and on a limited basis on weekends.
Web chat and email support are available daily during extended hours.
Community and Certification:
The Everlaw Ediscovery Community enables users to share insights, access member-exclusive events, and learn from peers.
The Everlaw Product Certification Program offers role-based certifications to help users and organizations maximize their expertise.
Custom and Onsite Training:
Everlaw’s User Education team develops tailored training modules, conducts workshops, and provides onsite training for clients who require hands-on guidance.
Ongoing Support:
After onboarding, Everlaw’s Customer Success team continues to provide support and guidance throughout the life of the contract at no additional charge.
Everlaw implements a set of security measures to protect sensitive data throughout its platform. Key security measures include:
All customer data is encrypted both in transit and at rest. Everlaw uses hybrid encryption techniques, combining software-based encryption, AWS hosting solutions, and self-encrypting drives to align with NIST Special Publication 800-53 standards.
The platform supports multi-factor authentication (MFA), single sign-on (SSO) via SAML 2.0, and granular user management to ensure only authorized users can access specific data.
Role-based security and least privilege principles are enforced, with access to production environments and administrative interfaces strictly controlled and logged.
Everlaw performs regular proactive intrusion detection, vulnerability scanning, penetration testing, and continuous monitoring of its codebase and infrastructure to identify and address potential issues before they become threats.
All user and system activity is logged and audit trails are maintained for at least 12 months, enabling accountability and forensic analysis.
Everlaw has a formal incident management process, including an on-call response team, to address security incidents following recognized standards such as ISO/IEC 27035:
All changes to the platform are documented, reviewed, and approved by a Configuration Change Review Group, with urgent changes subject to security impact analysis.
The platform employs an ongoing vulnerability management program, with regular internal and independent external vulnerability scanning and remediation processes.
Everlaw is SOC 2 Type II certified, ensuring stringent standards for data security and privacy.
The platform complies with relevant data protection frameworks and regulations, including GDPR and data privacy frameworks for international data transfers.
Everlaw leverages secure cloud infrastructure and maintains strict access controls for employees, with privileged access requiring formal review and approval.
Everlaw’s policy on data ownership and portability is clearly outlined in its contracts and privacy documentation:
Data Ownership:
Everlaw customers retain full ownership and intellectual property rights over their data (referred to as “Customer Data” or “Case Materials” in agreements). Everlaw does not claim any ownership rights to customer data uploaded or processed through the platform.
Everlaw is granted a limited, non-exclusive, royalty-free license to use customer data only as necessary to provide, maintain, and improve its services.
Data Portability:
Everlaw supports robust data export capabilities, allowing customers to download their data from the platform in various formats for further use or migration to other systems.
Data migration processes are designed to be efficient and secure, with Everlaw providing support for transferring data from other platforms or physical media, ensuring customers can move their data as needed.
For users in the European Economic Area (EEA), UK, or Switzerland, Everlaw complies with data transfer mechanisms such as Standard Contractual Clauses (SCCs) and the Data Privacy Framework to facilitate lawful data portability and transfers.
Customer Control:
Customers can manage access, permissions, and data within their accounts, and are responsible for obtaining necessary consents for data processing and transfer.
Everlaw’s terms for scaling up or down as organizational needs change are designed for flexibility, transparency, and ease of use:
Everlaw does not require long-term contracts or impose lock-in periods. Organizations are free to adjust their usage or switch providers at any time without penalties.
Pricing is straightforward and predictable, typically based on a monthly per-gigabyte fee. There are no setup, user, training, technical support, export, or production fees. Adding or removing users or data does not trigger additional charges beyond the standard usage fee.
The platform is built on cloud-native technology (AWS), enabling it to instantly scale up or down to accommodate unlimited users, cases, and documents, with no practical limits on data storage or processing per matter.
Everlaw dynamically allocates computing resources as needed, ensuring consistent performance and fast load times regardless of data volume or user count.
Organizations can create, suspend, or delete projects as needed. Admins can quickly add or remove users and adjust permissions to match evolving team structures.
Organizations can promote or demote documents between staging and active review environments to optimize costs. Promoting documents to active review incurs the standard higher rate, while demoting them reduces costs accordingly.
Everlaw’s intuitive interface and self-service features mean scaling up or down does not require significant IT involvement or infrastructure changes.
Terms and conditions for contract renewal and cancellation for Everlaw, drawn from its official documentation and agreements:
The agreement is effective for the duration specified in the Order Form or until terminated according to the terms.
Unless a party provides written notice of non-renewal at least 30 days before the end of the current term, Order Forms automatically renew for:
12-month periods for annual or multi-year subscriptions, or
successive terms of 1 month for monthly subscriptions.
Either party may terminate the agreement if the other party:
Is in material breach and fails to cure that breach within 30 days after receipt of written notice, or
Ceases business operations or becomes subject to insolvency proceedings that are not dismissed within 90 days.
Everlaw may temporarily suspend access to the service if:
Customer’s use disrupts or creates a security risk,
Customer is using the service in violation of law or the agreement, or
Customer fails to pay fees owed (overdue for more than 14 days after the invoice due date in some contracts).
Suspension will be to the minimum extent and for the shortest duration required to resolve the cause.
Effect of Termination:
If the agreement or an Order Form terminates or expires:
All rights and access to the service (including access to case materials) will terminate,
Everlaw will send a final invoice for any payment obligations under that Order Form.
Survival of Certain Provisions:
Key sections such as Fees and Billing, Intellectual Property Rights & Restrictions, Data Protection, Confidentiality, Representations and Warranties, Indemnification, Limitation of Liability, Governing Law and Dispute Resolution, and Miscellaneous will survive the end of the agreement.
Customer Data Handling:
Upon termination or expiry, Everlaw will return or delete all customer data at the customer’s request. Admins can also delete data, with or without exporting .
Once deleted, all data associated with a project is permanently removed.
For unpaid subscriptions, Everlaw may terminate the subscription at any time, exclude or remove users, delete or suspend case materials, or limit storage usage.
Everlaw may increase or add new fees for existing services by giving 30 days’ written notice.
The customer (or reseller) is responsible for managing authorized users, permissions, and access to databases and projects.
Everlaw meets a robust and set of compliance standards, ensuring high levels of security, privacy, and regulatory adherence for its users:
Everlaw is certified to the ISO 27001 standard, which validates its information security management system and ensures secure management of data centers and operations.
This certification confirms Everlaw’s adherence to cloud-specific information security controls and best practices for cloud service providers.
Everlaw meets this standard, which focuses on the protection of personally identifiable information (PII) in public cloud environments.
Everlaw is SOC 2 Type 2 certified in security, availability, confidentiality, and privacy, providing independent assurance of its control environment.
The SOC 3 report is publicly available and offers a high-level overview of Everlaw’s controls related to security, availability, confidentiality, and privacy.
Everlaw complies with the Health Insurance Portability and Accountability Act (HIPAA), including undergoing independent audits and offering business associate agreements (BAAs) to covered entities.
Everlaw has achieved FedRAMP Moderate Authorization, meeting rigorous NIST 800-53 Revision 5 security requirements for federal agencies.
Everlaw aligns with StateRAMP standards, supporting state and local government requirements by meeting NIST 800-53 Revision 5 controls.
Everlaw is Cyber Essentials Plus certified, a UK government-backed scheme that demonstrates effective operational security and protection against common cyber threats.