Grella
Grella is a legal matter workspace for law firms. It turns the files of a single matter into source-linked facts, dated chronologies, cited answers and drafted work product, then flags whatever needs rechecking when new evidence lands.
What is Grella?
Grella is what its makers call a Legal Matter Workspace: a single place where a law firm keeps the file of a matter and the work built on top of it. The premise stated on the site is that facts, documents, drafts and changes normally end up scattered across different tools, so the record and the work drift apart. Grella's answer is to keep them attached.
Documents are uploaded into a matter, then processed through OCR, extraction, chunking, embedding and search. From that material the product builds a matter dashboard holding a summary, the key parties, the live issues with their status, an assessment, typed case weaknesses such as contradictions, evidence gaps, thin support and staleness, and the team's file notes. Every fact it surfaces carries a link back to the page it came from, and to the exact sentence where the file supports it.
On that base sit four working surfaces. Chronologies assemble a master timeline from dated facts and let the team cut focused timelines for one person, one issue or one period, each entry openable at its source. Cited answers take a plain-language question about the matter and return an answer with citations beside each supported point, so a reader can open the underlying document before relying on it. Work products turn that analysis into drafts that stay with the matter, carrying contributors, review status and export controls; the site illustrates memos, partner briefings, evidence matrices, chronology summaries, conference questions, critical-path analyses and interview outlines. Change review watches the record: when a document arrives or a passage disappears, it flags the facts, chronologies and work product that may now be wrong, giving the reason, the affected target and the evidence context.
Access is layered — signed-in user, right firm, assigned matters, permitted role — and key work-product actions are logged. Third-party AI clients such as ChatGPT and Codex can be connected over the Model Context Protocol within existing permissions. Throughout, the vendor is explicit that Grella flags change but never rewrites legal work on its own: the lawyer decides.
What it does
- Pull the documents of one matter into a single workspace and index them
- Extract facts and link each one to the exact page, and to the sentence when the file allows it
- Answer plain-language questions about the matter with citations you can open
- Build a master chronology from dated facts, plus focused timelines by person, issue or event
- Draft work product from the current record and keep it attached to the matter
- Flag the facts, chronologies and work product affected when evidence is added or removed
- Record who created, edited, exported, deleted, opened or restored each work product
When to use Grella / When not to
A quick filter to help you decide if Grella is the right fit.
When to use Grella
- Litigation teams working through document-heavy disputes where the record keeps growing
- Partners and associates who need every fact and citation traceable to a page before they rely on it
- Paralegals and legal assistants who build and maintain chronologies from source documents
- Firms that draft memos, briefings and evidence matrices straight from the matter record
- Legal teams that must know which earlier work is affected when new evidence arrives
When not to use Grella
- Individuals looking for personal legal help, since the terms state the service is not designed for consumer use
- Anyone expecting legal advice or an opinion, which the vendor explicitly refuses to provide
- Firms that need practice management, billing or matter administration rather than work on the record itself
- Teams whose main need is researching case law and statutes, which Grella does not do
- Organisations that require SOC 2 or ISO 27001 certification before onboarding a supplier
How to use Grella
A typical end-to-end flow, from setup to results.
- Ask for a guided demo through the contact form, which runs on a demonstration matter so no real client files are needed to evaluate
- Sign in at app.grella.ai; no software is installed and authentication comes before any access to a matter
- Have an administrator set up the organisation, invite users and assign roles and matter permissions
- Create a matter and upload its documents, which are processed for OCR, extraction and search
- Open the matter dashboard to read the summary, parties, issues, assessment, weaknesses and notes drawn from the file
- Check the source-linked facts, opening the page and sentence behind any one of them
- Ask questions in plain language and read the answers with their citations, opening documents before relying on them
- Build the master chronology and cut focused timelines by person, issue or event
- Draft work product from the current record, track review status and contributors, then export when it is ready
- Return to the review queue whenever new evidence lands, and confirm, reject or mark reviewed each flagged item
Pros & Cons
Pros
- Every fact, answer and drafted passage keeps a path back to its source page, which makes the work checkable rather than merely plausible
- Chronologies are assembled from dated facts already tied to documents, instead of being retyped by hand
- Change review names what a new or withdrawn document affects, so stale work is caught rather than reused unnoticed
- The tool flags and suggests but does not rewrite legal work product; the lawyer confirms or rejects
- Drafting happens inside the matter, so analysis does not have to be copied into another tool and lose its context
- Access is limited by firm, matter and role, and work-product actions are logged
- The vendor is unusually candid about what it has not yet achieved, which makes a security review easier to scope
Cons
- No public pricing at all: no rates, no tiers, no pricing page, so every evaluation starts with a sales conversation
- No certification is claimed, and the vendor states that independent security validation is not yet complete
- No application-level field or column encryption is claimed for stored legal content
- Logging is admittedly partial, since not every file access or search is recorded
- No data processing agreement is published and no named list of subprocessors exists; both must be requested
- Retention is described only in principle, with no figure in days, months or years anywhere
- Very young product, with a domain registered in July 2025 and legal documents dated September 2026
Pricing & Plans
No pricing is published. The site has no pricing page, the route returns an error and is absent from the sitemap, and no amount appears anywhere in the collected pages. The terms state that fees, billing terms, usage limits and renewal terms may be set out in an order form, an invoice, a checkout flow, a written agreement or a plan description, and that payment is handled by a third-party processor. Trials, pilots and early access are mentioned only as something Grella may offer, with no free trial announced as available and no permanent free plan described. Prospective customers must contact the vendor, and a guided demo on a demonstration matter is the stated entry point.
Data, GDPR & hosting
A consolidated view of how Grella handles your data.
GDPR overview
The site never uses the words GDPR or General Data Protection Regulation, in the privacy policy or anywhere else, so no compliance claim is made and none is denied. The stated framework is Australian: Grella is operated from Australia and complaints are directed to the Office of the Australian Information Commissioner. The policy does acknowledge Europe, listing the EDPB directory of national supervisory authorities as a route for EU users, and it grants the usual set of rights on request: access, correction, deletion, objection and restriction, portability, marketing opt-out and the right to lodge a complaint, with a target response of thirty days. Content may reach providers in the United States and in EU member states, but no transfer mechanism is named. No Article 27 representative, no data protection officer and no published data processing agreement exist. Requests go to security@grella.ai.
Who owns the data?
Clients keep ownership of their matter content. The terms state that, as between the parties, the customer retains ownership of documents, files, prompts, queries, messages, outputs and generated work product, and that Grella claims none of it. The customer grants Grella a limited licence to host, process, transmit, display, copy, format, index and analyse that content, but only as needed to provide, secure, support, maintain and improve the service for that organisation, comply with the law and enforce the agreement. Grella states it does not sell customer content. Organisation administrators may request export or deletion, subject to legal, billing, backup, security and operational limits.
Reuse rights
The customer keeps full control of its own material: it may use, export and reuse anything it uploads or produces in Grella without asking the vendor, and organisation administrators can request an export at any time. Grella's own use of that content is bounded by the terms: hosting, processing, indexing and analysis to run the service for that organisation, plus support, security and legal compliance. The vendor states in both the privacy policy and the terms that it does not use customer content to train a Grella-owned foundation model or to build a model for another customer. Third-party AI, OCR, embedding and reranking providers do process document text, queries and outputs to deliver the features, and the vendor notes that provider retention, model-use and location terms vary by provider and by configuration. Customers remain responsible for the rights they hold over what they upload and for the decisions they take on the outputs.
Data retention & training
Hosting summary
Grella states that it is operated from Australia, and that is the jurisdiction its documents point to: complaints go to the Office of the Australian Information Commissioner, the terms are governed by the law of New South Wales, and liability is expressed in Australian dollars. Data itself is held in Grella's systems and in systems run for it by hosting, database, storage, identity, analytics, communications and product providers. The privacy policy says personal information and customer content are likely to be disclosed to providers in the United States and in member states of the European Union, covering hosting, identity, analytics, AI, document processing and communications. No data centre, cloud region or named provider appears anywhere, and the vendor states that provider routes and subprocessors may change, directing firms with data-location requirements to ask for current details before use. HTTPS protects public web and API traffic; no application-level field or column encryption is claimed for stored legal content.
Things to keep in mind
Risks and trade-offs to weigh before adopting Grella.
- The no-training commitment covers Grella's own models; third-party AI providers' retention and model-use terms vary by provider and configuration, and none is named publicly
- The security FAQ answers the training question by pointing to a security review rather than repeating the firm commitment made in the privacy policy, which is a softer position on the page most buyers read first
- Confidential and privileged client material is at stake, and the vendor itself says its privileged-data readiness work is unfinished and independent validation incomplete
- Citations create a strong impression of verification; the terms warn that outputs may be incomplete, inaccurate or outdated, so an unopened citation is reassurance without evidence
- Leaning on generated summaries and chronologies can erode a team's own grip on a file, precisely where professional judgement is owed to the client
- Connecting a third-party AI client over MCP sends matter data to a provider governed by its own terms, and disconnecting does not recall what it already kept
- Liability is capped at the greater of twelve months of fees or AUD 1,000, with exclusive jurisdiction in New South Wales, Australia, which is a low ceiling for a tool holding matter files
Setup & Integrations
Technical difficulty
Low. Grella is a web application with nothing to install: users sign in at app.grella.ai, and authentication precedes any access to a matter. The main setup work is administrative rather than technical, an administrator creating the organisation, inviting users and assigning roles and matter permissions before documents are uploaded. Evaluation starts with a guided demo on a demonstration matter, so a team can judge the product before configuring anything. The only optional technical step is connecting a third-party AI client over the Model Context Protocol. No integrations are required and no public API documentation exists.
Deployment
Integrations
Behind Grella
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What kind of legal work is Grella built for?
Can I verify an answer Grella gives me?
What happens when new evidence arrives in a matter?
How much does Grella cost?
Does Grella train AI models on our matter files?
Is Grella SOC 2 or ISO 27001 certified?
Who can see our matters inside the platform?
Does Grella comply with the GDPR?
Can Grella connect to other AI tools?
Can we try Grella before uploading real client files?
Should you pick Grella?
Grella is a narrow product done deliberately: one workspace for one document-complex legal matter, built so that nothing produced inside it loses its path back to the page it came from. That discipline is its real argument. Facts carry a page and often a sentence, chronologies are assembled from those dated facts rather than retyped, answers arrive with citations meant to be opened, and drafts stay attached to the record they were built on. The change-review layer completes the idea by naming what a new or withdrawn document may have invalidated, without touching the legal work itself. For a litigation team that has watched a chronology quietly go stale, that is a specific and recognisable benefit.
The reservations are equally specific, and the vendor states most of them itself. There is no certification, independent security validation is not finished, application-level encryption of stored legal content is not claimed, logging is partial by admission, and the work on privileged-data readiness is still in progress. No data processing agreement is published, no subprocessor is named, retention is described without a single figure, and the GDPR is never mentioned. Nothing about pricing is public either, so any evaluation begins with a sales conversation.
The candour is worth something: a firm reading the security and privacy pages knows exactly which questions to put on the table. But the product is young, the company publishes no address, no registered entity and no named principals, and it tells prospective customers in writing to complete their own security review before using it for confidential or privileged client material. That is sound advice to follow literally. The guided demo on a demonstration matter, which requires no real files, is the sensible way to judge whether the approach fits before any of that is settled.
- Choosing a selection results in a full page refresh.
- Opens in a new window.