Breach response has changed.
Incidents are larger. Data is messier. Reporting obligations are tighter. And the tolerance for mistakes, missed individuals, duplicate notifications, and inconsistent documentation, has never been lower.
Yet the hardest part of breach response has remained stubbornly manual: turning a chaotic, multi-format data set into defensible, decision-ready outputs including an impacted-individual list, the supporting rationale, and reporting artifacts teams need to move forward confidently.
Today, I’m excited to share that Relativity Data Breach Response is entering a new era. Now powered by generative AI skills that can run within agentic workflows at scale, Relativity aiR for Data Breach Response is generally available.
This release brings Relativity’s AI platform for Legal Data Intelligence to a critical use case where the market has long relied on patchwork tooling and heroics: end-to-end, sensitive data mining and entity linking for notification readiness, inside a single workflow, all within RelativityOne.
Breach Response Needs Holistic Legal Data Intelligence
In breach response, the bottleneck isn’t “finding the documents with PII/PHI,” but in what comes next:
- Extracting personally identifiable information (PII) and protected health information (PHI) across messy data types
- Linking that sensitive data to the right individual
- Deduplicating results across the full population
- Producing a notification-ready, defensible record of what was found and how decisions were made
Historically, the industry has tried to solve this with combinations of e-discovery tools, spreadsheets, scripts, and point solutions. Even when pieces work, the workflow often breaks where it matters most: handoffs, revalidation loops, offline entity lists, and outputs that have to be rebuilt at each stage.
Teams need a connected workflow that turns raw breach data into defensible decisions, at speed, while keeping human judgment at the center.
Introducing aiR for Data Breach Response
aiR encompasses all of our generative AI solutions, each of which is fit-for-purpose and produces defensible results—all within the security of RelativityOne.
aiR for Data Breach Response is our next generation legal data intelligence application that runs in RelativityOne production environments hosted exclusively in Microsoft Azure, ensuring your workflow and outputs are delivered in the most trusted, secure, and governed platform built for high-stakes legal work.
What’s New and What It Unlocks
Now generally available, aiR for Data Breach Response delivers a step-change in the most time-consuming portion of breach response: manual PI mining and linking. In particular, generative AI automatically identifies and links PI/PHI across documents, accelerating both review and quality control (QC) processes. Equally important, the workflow is designed so results carry forward into QC and reporting without rebuilding outputs at each step.
- As the analysis job runs, project leads have visibility into PI/PHI identification, extraction, linking progress, and document errors across the set.
- When the job completes, reviewers focus on QC, validating detections and AI-generated linking, rather than manually linking PI to individuals.
- When normalizer runs, the entity report is generated, and after conflicts and clusters are reviewed you can rerun normalization to update the report for final export.
The result is a faster path to notification readiness with fewer downstream revalidation loops—the workflow is connected end-to-end and outputs are designed to be reviewable and defensible.
AI-powered and Designed for Defensibility
AI should augment your team’s breach response efforts with clarity, control, and speed—never replacing human insights. aiR for Data Breach Response shifts invaluable human effort from repetitive, manual tasks to higher-value quality control and judgment.
In a manual workflow, reviewers spend enormous amounts of time on arduous tasks: combing through documents, identifying sensitive data, and manually associating it to individuals, normalizing the data, then repeating steps as the scope changes. With aiR, AI accelerates this work, identifying and linking sensitive data and deduplicating so experts can spend more of their time where it matters most:
- validating and resolving edge cases
- assessing anomalies and inconsistencies earlier
- confirming defensible outcomes before exports and downstream actions
One customer described the impact this way:
“aiR for Data Breach Response, with the full scale of the RelativityOne platform, transformed our workflow efficiency, saving us significant review time. We were able to deliver faster time to insight with the added leverage of generative AI, and maintain our defensible outcomes for our client, ensuring they navigate breaches with greater confidence.”
Trust and Operational Fit to Match How Breach Responses Run
aiR for Data Breach Response runs as an application within a secure RelativityOne Review workspace, and the data used for analysis never leaves the RelativityOne security boundary. Our platform is hosted on Microsoft Azure, built on Microsoft’s security technology, operational processes, and expertise.
For generative AI capabilities, aiR for Data Breach Response leverages Azure OpenAI, which does not retain document data beyond your organization’s instance and does not use it to train models for Relativity, Microsoft, or third parties. All aiR for Data Breach Response analysis occurs within this Azure-hosted environment,.
Built on the scale of RelativityOne, teams can manage large incident collections in one secure platform without breaking the workflow. Breach data sets are often massive, and in practice, teams don’t need everything collected to produce notification-ready outputs. Most customers bring their broader incident collection into RelativityOne first to securely process and cull to a breach-relevant population, then run aiR for Data Breach Response on that scoped subset. This approach drives PI/PHI detection and entity linking within a connected workflow, without rebuilding results across disconnected systems and introducing risks by importing and exporting data at multiple steps. And because breach data sets often include password-protected files, teams typically handle decryption during processing so content can be evaluated within the workflow rather than skipped.
We also publish operational guardrails and performance guidance for generative AI workflows, including the use of tracked quotas and incremental processing, because predictable execution is foundational to defensibility.
And because breach response is increasingly multi-jurisdictional, scale isn’t only about volume—it’s also about handling global data consistently. Global incidents require global language readiness. The underlying LLM that powers aiR is largely language-agnostic and has been evaluated for use with 83 languages, including support for CJK characters within the aiR for Data Breach Response workflow and its reporting outputs. While we’ve primarily tested on English-language documents, testing with non-English data sets has shown encouraging results (and our team has built some guidance for operating across languages).
Why this Matters for Providers, Counsel, and Insurers
aiR for Data Breach Response is built for the organizations doing the work, and the stakeholders accountable for the outcomes.
- Service providers and incident response firms can execute faster and more consistently with fewer rework cycles, improving throughput without scaling headcount linearly.
- Breach counsel can reach defensible, explainable clarity faster, optimizing speed to advice while keeping judgment and oversight central.
- Cyber insurers benefit when breach execution becomes more predictable and defensible, reducing variance and improving outcome consistency—which we believe leads to protecting overall loss ratios.
And zooming out: the market has needed a connected solution that addresses the end-to-end culling, PI mining, and individual and entity linking workflow, not just one step in isolation. aiR for Data Breach Response brings that workflow together inside a single Legal Data Intelligence platform, with AI-powered acceleration and human-empowered defensibility.
What’s Next
This release is a major milestone, and it’s also a foundation. Our roadmap is focused on continuing to expand capabilities while maintaining the same core principles: AI-powered speed, human-empowered judgment, and defensible outcomes.
If you’re interested in learning more, we’d love to talk to you. Reach out any time to schedule an aiR for Data Breach Response workflow session, and we’ll help you operationalize a repeatable, defensible workflow.
