By Ray Biederman -- Co-Founder, Proteus Discovery Group | Founding Partner, Mattingly Burke Cohen & Biederman | Adjunct Lecturer, Indiana University
Almost every "how to choose an eDiscovery vendor" article you'll find online was written by a vendor. That's the problem. Vendors lead with what they sell -- platforms, features, per-gigabyte rates -- because that's what they want you to compare on. The buyer, meanwhile, is trying to figure out something entirely different: am I going to get sanctioned, embarrassed, or over-billed if I hire this person?
I've spent my career on both sides of this transaction. I practice commercial litigation at MBCB. I co-founded Proteus in 2015 because my partners and I saw a gap in the middle of the market -- sophisticated eDiscovery service designed for the firms and cases that don't have Am Law 100 budgets but still face Am Law 100–style discovery demands. I teach eDiscovery, information governance, and health information protection at Indiana University. I've testified as an expert witness on document production. I've hired vendors, been the vendor, and been the lawyer trying to explain to a judge why the vendor's mistake shouldn't cost my client the case.
So this guide isn't a features checklist. It's what I'd tell a friend who called me and said, "I just got a case with 500 GB of email and I have no idea what to do."
Before you pick a vendor, answer this: what are you actually buying?
There are four distinct things people mean when they say "eDiscovery vendor," and confusing them is the single most common mistake I see:
These are four different price tags, four different risk profiles, and four different vendor rosters. If you don't know which one you're buying, you'll compare apples to oranges and end up with the cheapest apple when what you needed was the ripest orange.
Here is my honest, litigator's shortlist. These are the criteria I use when I'm evaluating a vendor for a client -- including when the client wants my recommendation on Proteus's competitors, which happens more often than you'd think.
A lot of vendors say they're "attorney-led." Ask what that actually means. Is there a practicing litigator on staff who could stand behind you in a Rule 26(f) conference and defend the collection scope? Or is "attorney-led" a founder's law degree from 20 years ago and a marketing tagline?
The reason this matters: eDiscovery is a legal exercise dressed up as a technical one. Every meaningful decision -- what to collect, what to preserve, how to scope search terms, what constitutes a reasonable production, how to log privilege -- is a legal decision with a technical implementation. If the vendor doesn't have current legal judgment in the room, you'll be the one holding the bag when opposing counsel calls a meet-and-confer to challenge your process.
A vendor should be able to walk you through their rate structure in plain English before you sign anything. That means being clear about what's included in the base rates and what triggers additional charges -- hosting, user fees (or the absence of them), processing, review, project management, rush turnaround, after-hours support.
The reality of eDiscovery is that scope changes as a case develops. New custodians appear. Data volumes turn out to be triple what the client estimated. Opposing counsel demands a rolling production. A good vendor won't pretend otherwise by boxing you into a fixed-price quote that either penalizes them or penalizes you the moment reality diverges from the estimate. What you want instead is a rate card you understand and a project manager who tells you before costs move, not after.
Red flag: a vendor whose pricing you can't explain back to a partner or a client without pulling out a calculator. If you don't understand how you'll be billed, you can't budget, and you can't defend the invoice when it lands.
Some vendors are Relativity shops. Some are Everlaw shops. Some are DISCO shops. That's fine -- as long as they'll tell you.
The real question is whether the vendor will honestly say, "For your case, this other platform would be a better fit and we can work in it." At Proteus, we've completed reviews in Relativity, RelativityOne, DISCO, Everlaw, iCONECT, IPRO, Logikcull, Ontrack, NextPoint, Reveal, and even legacy Summation -- because we think the tool should serve the case, not the other way around. That's a rare posture in this industry, and it's the one you should look for.
If a vendor tries to shoehorn every case into their preferred platform because it's what they license, you're paying for their business model, not your case strategy.
SOC 2 Type 1 or Type 2 is table stakes in 2026. If a vendor doesn't have it, they're either too small to have invested in it (fine, ask why and what they do instead) or they've been putting it off (not fine).
Ask about: encryption at rest and in transit, access controls, breach notification procedures, data residency, and what happens to your data when the engagement ends. If the vendor's answer to "when is our data purged and how do we verify it" is a shrug or a marketing brochure, walk away.
For health information, ask about HIPAA specifically. For financial services, ask about GLBA. For anything involving EU data, ask about GDPR compliance and cross-border transfer mechanisms. If the vendor doesn't know what you're talking about, they can't help you.
Ask the salesperson: "Who will manage my matter, day to day?" You want a name, a bio, and ideally a conversation with that person before you sign.
The reason: eDiscovery success is 20% platform, 20% attorney judgment, and 60% project management. A great PM anticipates issues, keeps timelines honest, escalates before problems become emergencies, and communicates in a way that lets you sleep at night. A bad PM makes you the project manager without paying you for the role.
If the vendor won't commit a specific PM to your matter -- or worse, if the PM changes every 60 days -- you're going to spend every case re-explaining your preferences.
Ask for three references of your choosing -- meaning, references you can pick based on matter type, size, and industry, not the three happy clients the vendor pre-approved.
Better yet, ask the vendor for the names of three lawyers who used them and didn't renew. If the vendor can't give you any, they either haven't been in business long enough or they're not being straight with you. Every honest vendor has clients who left -- because of price, fit, staffing changes, or a merger. What matters is how the vendor talks about those departures.
Also worth doing: ask around your local bar. In Indianapolis, the eDiscovery community is small enough that reputations are earned and known. In bigger markets, ACEDS chapters, EDRM working groups, and the litigation section of your state bar are the places to ask.
Litigation happens on litigation's schedule, not the vendor's. Ask: what happens at 9 PM on a Sunday when the production is due Monday at 8 AM and something breaks?
A good vendor has a documented after-hours protocol, a live human answering the phone, and a PM who has your cell number. A weak vendor has a support ticket system and a promise to respond within one business day. The gap between those two answers has cost more than one case.
Here are the things I've watched sink client engagements, in no particular order.
🚩 "We'll figure out pricing as we go."
No, you won't. You'll get a bill three months in that has line items you didn't authorize and can't dispute. The rate structure should be in writing before any data moves -- even if the total scope will legitimately evolve as the case unfolds.
🚩 No communication before the invoice.
eDiscovery scope changes; that's the nature of the work. What shouldn't change is the vendor's obligation to flag material cost movements before they show up on a bill. If the vendor's answer to "how will I know if we're heading over budget" is "you'll see it on the next invoice," that's a problem.
🚩 Salesperson does the technical talking.
The person selling you the service should not be the last technical voice you hear. Before you sign, get on a call with the PM and, ideally, the processing lead.
🚩 No written incident-response plan.
Ask, "What happens if there's a data breach involving my client's information?" If the answer isn't a specific process with specific timeframes and specific notification obligations, you have a problem.
🚩 Overpromising on AI.
Every vendor in 2026 leads with AI. Ask specifically: what model, trained on what data, validated how, defensible in what jurisdictions? If the answers are hand-wavy, the technology probably is too. Judges are getting educated fast, and unsupported AI claims are becoming Rule 11 problems.
🚩 Pressure to sign before you can compare.
"This pricing expires Friday" is a sales tactic, not a business reality. Any vendor worth hiring will let you take your time.
🚩 Vendor lock-in on data export.
Before you sign, ask exactly how you get your data out -- format, timeline, and cost -- if the relationship ends. If the answer is expensive or slow, that's the point. Don't sign until you have a defensible exit plan.
When you get a proposal, look for these four things before you look at anything else.
Everything else -- feature lists, logos, awards -- is noise until you understand those four things.
For a mid-sized commercial matter (say, 50 GB of processed data, three custodians, a modest privilege review), you should expect an all-in cost between roughly $15,000 and $50,000 depending on platform, review model, and rush factors. Larger matters -- regulatory investigations, multi-district litigation, class actions -- routinely run into six and seven figures when all components are included. Anyone who quotes you a single per-gigabyte number and calls it done is either oversimplifying or setting you up for surprise invoices.
A platform (Relativity, Everlaw, DISCO, Logikcull, etc.) is software. It processes, hosts, and lets you review documents. A vendor is a services company that operates the platform on your behalf and provides project management, attorney oversight, technical support, and often the review team. Many law firms and legal departments license a platform but still need a vendor to actually staff and manage the matter. Confusing the two is a common and expensive mistake.
For most small and mid-sized firms, you don't need your own account. If your firm does document review projects only a handful of times a year, buying a Relativity license is overkill -- you'll pay for capacity you never use. Use the vendor's account and let them handle the infrastructure. If you're doing 100+ matters a year and have a dedicated litigation support person, then a firm account may make economic sense.
At a minimum: SOC 2 Type 1 or Type 2 for security, and staff certifications like CEDS (Certified E-Discovery Specialist) for individual practitioners. For platform-specific work, look for Relativity Certified Administrator (RCA), Relativity Certified Sales Pro, or equivalent credentials from Everlaw, DISCO, or whoever they operate in.
Yes, but ask carefully. "We use AI" in 2026 means nothing. What you want to know: which specific tools (technology-assisted review, continuous active learning, generative AI for privilege screening, etc.), how they've been validated, whether opposing counsel or a court has challenged their outputs, and what the vendor's documented protocol is for defending AI-assisted decisions.
Match the term to the matter. For a single case, project-based engagements with no long-term commitment are standard and appropriate. For firms with a steady docket, an annual master services agreement with matter-specific SOWs is usually best. Multi-year commitments make sense only if you've worked with the vendor before and have negotiated meaningful discounts and clean exit terms.
The three biggest: vague pricing that "depends on the case," pressure to sign quickly, and salespeople who won't let you talk to the project management or technical team before you sign. Any of these three should give you pause. All three together should send you elsewhere.
If you take nothing else from this piece, take this. When you're evaluating an eDiscovery vendor, run every conversation through three questions.
Would I stake my client relationship on this vendor's judgment?
If the answer is anything less than yes, keep looking.
Do I understand exactly what I'm going to be billed, and when?
If not, don't sign until you do.
If this engagement goes badly, do I have a clean way out?
If not, negotiate one before you commit.
Everything else -- the demo, the pitch deck, the feature list, the awards -- is secondary. eDiscovery is legal work. Hire the vendor who treats it that way.
Ray Biederman is Co-Founder and CEO of Proteus Discovery Group, a litigator-led eDiscovery firm headquartered in Indianapolis. He is also a founding partner at Mattingly Burke Cohen & Biederman LLP, where he leads commercial litigation, and an adjunct lecturer at Indiana University, teaching eDiscovery, information governance, and health information protection. He has testified as an expert witness on document production and is recognized as a SuperLawyer and Best Lawyer in eDiscovery and commercial litigation.
This article is being provided for informational purposes only and should not be relied on as the provision of legal advice. This document does not create any attorney-client relationship. Each circumstance and factual scenario is unique and your personal experience may differ.
If you're evaluating vendors for a specific matter and would like a candid second opinion -- even if we're not the right fit -- reach out at ray.biederman@proteusdiscovery.com.