Antidote vs Legal Decoder: how they compare in 2026
Antidote and Legal Decoder both read the narrative of legal time entries, from opposite sides of the invoice. Antidote helps a law firm rewrite entries to meet each client's guidelines before billing; Legal Decoder analyzes invoices for corporate legal teams, fee examiners and firms. Legal Decoder sits in the top two bands on seven of fifteen axes and Antidote on five of fifteen, identical on four. Legal Decoder publishes how its analysis works. Matter, client and attorney names are replaced with tokens before data reaches its model, a separate engine does the arithmetic, and every flag traces to a line item and rule. It states that its analysis is neither legal advice nor a verdict on counsel's work. Antidote's counterweight is disclosure about its supply chain. Its trust center names Anthropic among its subprocessors, customers choose storage in the EU, the United States or Australia, and it names ISO 27001:2022 and SOC 2 Type 1. Antidote names no customer, and nothing it publishes addresses a fee earner's duty over a narrative its model rewrote.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Remove the models and there is no product. Antidote ships no document system, no workflow engine and no time recording of its own; it is explicitly an overlay on the firm's existing time recording and practice management software. Every function it performs is a model task: extracting billing rules from a client's outside counsel guideline documents and the firm's historical billing data to build Individual Client Standards, analysing time entries continuously through the billing cycle against those standards, and generating a corrected narrative for a fee earner to accept. The vendor's own naming makes the same point, describing the analysis layer as Antidote AI. There is no rules engine or template library underneath that would survive the models being taken away, and no conventional software product the AI is a feature on. Checked 4 September 2026.
The models turn billing prose into data, and a rules engine does the judging. Legal Decoder's own framing is that UTBMS codes tell you what was billed but not what happened, so its technology reads the narrative itself: entries are parsed, categorised, enriched, standardised and then evaluated against more than 45 proprietary compliance flags. Aperture adds a natural language interface on top, and the vendor is explicit that the AI agents decide what data and calculations a question needs while a separate deterministic engine does the arithmetic. Underneath the language work sits an analytics platform of flags, benchmarks and indices that would still run on structured invoice feeds without any model reading prose. Verified 20 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is described at the level of its inputs and accuracy is asserted without measurement. The source material is named and it is unusually concrete for this axis: outside counsel guideline documents, internal firm guidelines and historical billing data, combined into per-client Individual Client Standards against which entries are checked. That is a real account of what the output is grounded in. What is missing is everything testable. No accuracy figure, no test set, no evaluation, no error rate and no description of retrieval method appears on any surface, and nothing addresses what happens when the model misreads a guideline or rewrites a narrative into something the fee earner did not do. Accuracy is instead asserted, with corrected recommendations said to ensure compliance. There is no published statement about hallucination in either direction. Searched the home page, the resources index, the about page, the terms, the privacy notice and the trust centre on 4 September 2026.
The method is described in detail and the performance is not measured. Aperture's published answers show an Analysis Request Breakdown setting out the data used for the response, every figure is computed by a deterministic engine rather than the model, and the underlying flags are documented down to the individual rule, with worked examples in the published bankruptcy retrospective showing which entries triggered which flag and why. What is asserted rather than tested is quality: the site describes the methodology as court-validated and says Legal Decoder is the only invoice review technology accepted at the federal court level, without citing a decision or naming a court, and no accuracy, false-positive or agreement rate for the flags is published. Verified 20 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A human approval step is published as part of the design rather than added as a caveat, and the threshold structure around it is absent. The workflow is stated in terms: Antidote sends suggested fixes directly to email so fee earners can review, approve and move on, and corrections are described as recommendations accepted with one click. Nothing is presented as writing to the billing system unattended, which matters because the output is text that reaches a client invoice. What is not published is the control structure around that review: no statement of what happens to entries nobody approves, no threshold at which the system acts alone, no confidence signal surfaced to the reviewer, and no description of what a supervising partner sees as against a fee earner. The absence of a described escalation path is the limb this band commonly lacks and it is the position here.
The product flags and a person decides, and the review surface is the flag itself. Every flag attaches to an individual line item with the rule that fired, and users drill from an index category to a timekeeper to the entry, so each conclusion can be checked against the billing record behind it. Aperture is described as sticking to observations and suggested next steps by default and producing a specific action plan only when asked, and users hold read-only permissions, so nothing in the analysis can alter the underlying billing data. What is not published is any threshold or confidence level at which a flag fires, or guidance on what a flagged entry may not be used for when it becomes the basis of a fee objection or a write-down. Verified 20 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
No production evidence was located on any first-party surface. There are no named customers, no case studies, no testimonials and no customer logos anywhere on the site: the only logo strip is headed Backed by and carries investors rather than users. The figures the home page does publish are modelled rather than observed, and the vendor says so in a footnote, stating that the 8 to 10 per cent write-off rate, the 30 extra days to payment, the 17 million dollars of tied-up working capital and the 800,000 dollars of partner time are based on a 100-partner firm billing 200 million dollars annually. Disclosing that basis is more honest than most illustrative arithmetic in this corpus and it is recorded as a point in the vendor's favour, but a hypothetical firm is not a deployment. Trade coverage of the January 2026 funding round refers to adoption by firms in the United States, United Kingdom and Australia without naming any of them, and funding coverage is not deployment evidence. Searched the home page, the about page and the resources index on 4 September 2026.
The numbers are real and the customers are not named. The published Allied Nevada Gold retrospective analyses a named Chapter 11 case: over fifty invoices and 2,000 pages covering 10.7 million dollars in fees, 14,755 line items and 135 timekeepers across eight named law firms, with over 21,000 flags and roughly 2.4 million dollars identified as unrealised savings, and firm-by-firm findings set out with percentages. That is a demonstration on public court filings rather than a customer deployment; the firms analysed are the subjects, not the buyers. The other success stories, including an AmLaw 100 firm's risk management programme and the Toys "R" Us fee review, describe the customer only by segment, and the homepage quotes are attributed to roles rather than people. Verified 20 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Confidentiality is asserted in general terms and every specific commitment sits behind an access request or in an unpublished contract. The trust centre states that the commitment to data privacy and security is embedded in every part of the business, and lists a Data Protection Policy, an Information Security Policy and an Encryption Policy, all behind a Get access flow. The published privacy notice expressly excludes the material that matters: it records that users may upload confidential company information when using the services, that such information may include personal data, and that its collection and protection are subject to a separate agreement and are not covered by that policy. Nothing published addresses training on customer content, matter or client segregation, tenancy, or what the named model provider may retain. The gap is sharper than the general case because the content ingested is time entry narratives, which describe what a lawyer did on a matter and are among the most privilege-sensitive text a firm holds, routinely redacted in fee disputes for exactly that reason.
The confidentiality commitments are specific to the one thing this product handles, and they live outside any agreement a buyer can read. Invoice narratives describe matters, clients and strategy, and Aperture's published answers address that directly: identifying fields such as matter, client and attorney names are tokenised before any data reaches the model, so the model sees strings like Matter_ABCDEF, tokens cannot be reverse-engineered, and new identifiers are generated per session rather than held in a persistent vault; results are remapped inside Legal Decoder's own environment. The vendor also states that data is never used to train models and that users hold read-only permissions. Nothing published addresses separation between customers, privilege or work product in the narratives, and both the Terms of Use and the Privacy Policy state that client processing is governed by separate master services and data processing agreements that are not published. Verified 20 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
Two of this band's limbs do not bite and the one that does is unaddressed. The product gives no legal advice and has no consumer-facing surface: the terms restrict access to Law Firm Users authorised by a law firm, require use in a commercial capacity, and state that the services are not intended to be available for personal use, so the advice line and the jurisdiction limb both fall away on the product class. What bites instead is the professional responsibility limb, and it bites hard. Antidote generates the narrative text that describes a lawyer's work and then travels to the client on an invoice, which engages the rules on fee reasonableness and on candour to a client directly. Nothing published addresses it: no rule of professional conduct, no bar or regulator, no ethics guidance, no statement that a fee earner remains responsible for the accuracy of a narrative the model rewrote, and nothing on whether an AI-corrected entry must still reflect the work actually done. The nearest provision runs the other way, with the terms disclaiming any liability for a law firm's delivery of legal services to its clients. Searched the home page, the about page, the resources index, the terms and the privacy notice on 4 September 2026.
The line between analysis and judgement is drawn in the vendor's own words. The published methodology states that the technology neither provides legal advice nor operates as a referendum on the quality of legal services provided or the outcome delivered by outside counsel, which is the relevant disclaimer for a product whose output is used to challenge another lawyer's fees, and the Terms of Use dated 21 January 2026 add that website content is not legal advice and creates no attorney-client relationship. What is missing is the other half: nothing addresses the duty of the person acting on a flag, whether a fee examiner, a general counsel or a billing partner, or what review a flagged entry should get before it becomes an objection or a write-off. Verified 20 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
No governance position was located for a system that rewrites the record of billable work. There is no responsible AI page, no principles statement, no named owner accountable for model behaviour, no pre-release evaluation, no testing regime and nothing at all on bias. The site inventory was established from the navigation and footer across four pages on 4 September 2026 and consists of How it works, Resources, About, Contact, Terms and Conditions, Privacy Notice, Cookie Policy and the trust centre; none of them carries governance material. The trust centre's document set is entirely security governance, being an Acceptable Use Policy, Backup Policy, Data Protection Policy, Encryption Policy and Information Security Policy, and security controls are a different subject from AI governance under the axis definition, so none of it is credited here. The trust centre does carry one candid line about an adjacent gap, recording that an application security monitoring programme is being put together.
How the system works is explained; how it is governed is not. The Aperture material is unusually open about mechanism, setting out that the model plans the analysis and never calculates, that tokenisation happens before processing, and that the underlying data is parsed, categorised, enriched, standardised and evaluated in sequence. Nobody inside Legal Decoder is named as accountable for the flags or the models, nothing describes what is tested before a rule or release ships, no evaluation results are published, and nothing addresses whether flags fall unevenly across practice areas, firm sizes or timekeeper seniority, which matters for a product whose output is used to question individual lawyers' bills. Checked the homepage, the Aperture, Compliance Decoder and Partners pages, the success stories, the Terms of Use and the Privacy Policy on 20 September 2026. Verified 20 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Real material exists around the edges and the published policy does not reach the content the product ingests. What is published is genuine: a retention table giving 180 days from the end of the relationship for identity and account records, 12 months for technical and usage data, and 7 years for enquiry records; an international transfer position resting on UK adequacy regulations or the International Data Transfer Agreement; an ICO registration number, ZB821053, verifiable on a public register; a named subprocessor list covering Amazon Web Services, Anthropic, Google, Linear and WorkOS; and storage in the customer's choice of the EU, US or Australia. What is absent is the set governing customer content, and the privacy notice says so expressly rather than by omission, recording that uploaded confidential company information is subject to a separate agreement and is not covered by that policy. So no retention period, no deletion route and no incident or breach notification commitment applies to time entries, narratives or ingested guideline documents. Encryption and Backup Policies exist on the trust centre behind an access request and were not read.
One question is answered precisely and the rest are not. The Aperture material says the product is not a system of record and does not store, own or act as the repository for billing information, which should remain in the customer's e-billing or matter management system, and that users have read-only access. Beyond that, no retention period for what Legal Decoder does hold, no deletion commitment, no encryption statement, no subprocessor list and no incident practice was located; there is no security or trust page anywhere on the estate, and the Privacy Policy dated 21 January 2026 covers website visitors and marketing only, stating that client processing sits under separate agreements that are not published. Verified 20 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Nothing published allocates loss for the platform, and the published document says so itself. The only loss-allocation language on the site is in the website terms of use, which exclude indirect and consequential loss and loss of profit, revenue, contracts, data and goodwill, preserve liability for death, personal injury and fraudulent misrepresentation, and then state that any liability for losses arising from use of the services is limited as set out in the separate agreement between Antidote and the user's employer. That separate agreement is not published. A cap or exclusion in a website terms of use does not grade the platform, so what remains for a buyer is a pointer to a document they cannot read before signing. No indemnity of any kind, no warranty on output and no cap figure appears anywhere in the clear. One artifact exists and is named rather than credited: the trust centre lists a Cyber Insurance document under Legal, behind the Get access flow, so an insurance position exists but its scope and limits could not be established and crediting it on its title would be inference. It is the cheapest available upgrade on this record.
Nothing published says who bears the loss if a flag is wrong. The Terms of Use dated 21 January 2026 govern the website: they disclaim warranties, exclude indirect and consequential damages and require the user to indemnify Legal Decoder, and they address the website rather than the analysis a customer buys. The Privacy Policy points client processing to master services and data processing agreements which are not published, and no warranty, indemnity, cap or insurance position covering the product was located. For a product whose output is used to reduce another party's fees, nothing addresses the consequences of a mistaken flag. Checked the Terms of Use, the Privacy Policy, the product pages and the Partners page on 20 September 2026. Verified 20 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integration is the product's entire delivery model and not one system is named. The claim is central and repeated: the product works inside existing workflows, promises no workflow disruption, and is described as sitting on top of a firm's existing time recording and practice management software. It is architecturally true, since Antidote reads and corrects entries held elsewhere. But no integrations page exists in the site inventory, and no practice management system, time recording system, eBilling platform or document management system is named on any first-party surface, nor is there an API reference, a connector list or any statement of what syncs in which direction or what a firm must configure. Neither band reads cleanly here and that is worth recording: the band below asserts the product stands alone or no integration is located, which is false of an overlay, while this band contemplates logos or coming-soon markers, and there are none. Graded at the nearer of the two because a real capability is claimed with nothing an implementer could use. Checked 4 September 2026.
No integration into the systems legal billing already runs through was located. Aperture is described as a complementary analytics layer rather than a replacement for an e-billing or enterprise legal management system, and the customer's system is expected to remain the system of record, but nothing names a single one of those systems, describes how invoice data reaches Legal Decoder, or documents an API, file format or connector. There is no integrations page and no developer documentation; the Partners page describes commercial partnerships with alternative legal service providers and consultancies rather than technical connections. Checked the homepage, the Aperture, Compliance Decoder and Partners pages, the success stories, the Terms of Use and the Privacy Policy on 20 September 2026. Verified 20 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Residency is offered as a genuine choice and processing is not addressed separately from storage. The home page states data is stored in-region and names the three options as the European Union, the United States or Australia, which is more than most records in this lane publish, since it is a selectable region rather than a single stated location. Amazon Web Services is identified as the hosting subprocessor on the trust centre, so the infrastructure provider is named. Two limbs are missing. Tenancy is never addressed: nothing states whether the platform is single or multi-tenant, and no dedicated or isolated option is offered. And where processing happens is not stated as distinct from where data is stored, which matters on this record because Anthropic and Google are named subprocessors and no location is given for the inference leg, so a buyer choosing EU storage cannot establish that the model call stays in region.
Nothing published says where the software runs or where invoice data is held. The product is reached through a web portal, and no tenancy model, hosting provider, region or residency option appears anywhere; the Privacy Policy addresses website data and says nothing about where client processing happens. Buyers in this market routinely send an entire outside counsel spend file, which makes the absence a live question for a procurement review. Checked the homepage, the Aperture, Compliance Decoder and Partners pages, the success stories, the Terms of Use and the Privacy Policy on 20 September 2026. Verified 20 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Named certifications and a real trust centre, short of accessible evidence. The SafeBase portal at trust.antidotelegal.com renders in full and carries three compliance entries, GDPR, ISO/IEC 27001:2022 with the standard version named, and SOC 2 Type 1, alongside a document set listing an Antidote Legal Security Summary 2026, a Pentest Report, the certification documents themselves, Cyber Insurance and five policies. The certifications are therefore stated rather than implied, and a route to the underlying reports visibly exists, which is what lifts this above a badge wall. What holds it here is that no report is readable in the clear: every document sits behind a Get access flow whose tier the portal does not state, offering to start a security review, view and download sensitive information or ask for information without saying whether fulfilment is self-serve or runs through a sales conversation, so the lower tier is assumed and that assumption is stated. No auditor is named, no audit period or report date beyond the year appears, and no scope statement is published. One precision worth keeping: the attestation is SOC 2 Type 1, a point-in-time assessment of control design, not Type 2.
No independent security attestation was located. There is no security page and no trust centre on the estate, and no SOC 2, ISO 27001, penetration test or named auditor is mentioned on any page; the only security language is the Privacy Policy's statement that reasonable administrative, technical and physical safeguards are maintained and that no system is completely secure. Checked the homepage, the Aperture, Compliance Decoder and Partners pages, the success stories, the news and blog indexes, the Terms of Use and the Privacy Policy on 20 September 2026. Verified 20 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The provider is named and the rest of the chain is not. The trust centre publishes a subprocessor list in the clear, without an access request, naming Amazon Web Services, Anthropic, Google, Linear and WorkOS. Anthropic being listed identifies whose models process customer content, which is the limb most records in this lane leave blank, and Google appears alongside it though the list does not state whether that entry is infrastructure or a second inference provider. Three limbs fail. No model is named, only the provider, so a buyer cannot establish which model reads a time entry or what version. Where inference runs is not stated, and Amazon Web Services is not counted toward it because naming a cloud host says where the vendor's platform sits rather than whose model reads the content. And no commitment to notify customers when a subprocessor, provider or model changes was located on the portal or elsewhere.
The model is referred to and never identified. The Aperture material describes data being sent to an LLM after tokenisation and says potentially sensitive fields are protected before any data reaches the AI model, which tells a buyer that a third-party model is in use without saying whose. No model, version or provider is named, nothing states where inference runs, and no commitment to notify customers when the model changes was located. The vendor's own distinction, that the model plans and explains while a deterministic engine computes, limits what the unnamed model actually decides. Verified 20 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. The site inventory taken from the navigation and footer on 4 September 2026 contains How it works, Resources, About, Contact, Terms and Conditions, Privacy Notice, Cookie Policy and the trust centre, and there is no pricing page. Every call to action on every page is Book a demo, routing to a contact form. Nothing states whether the product is charged per fee earner, per timekeeper, per entry checked, per matter or as a platform fee; no tier structure, no band, no minimum, no term and no implementation cost appears anywhere. The terms of use refer to placing an order and to a separate agreement with the customer's employer without describing any commercial term. The absence is notable on a product whose own pitch is quantified in pounds and dollars of recovered revenue, since a buyer is given a detailed model of the benefit and nothing at all about the cost. No pricing row is written, which is the correct outcome where the only thing published is an invitation to contact sales.
No price, rate or unit of charge is published. Checked the homepage, the Aperture, Compliance Decoder, Pricing Decoder and Partners pages, the three buyer pages, the success stories, the news and blog indexes, the Terms of Use and the Privacy Policy on 20 September 2026: there is no pricing page, no tier, no per-invoice or per-dollar-reviewed rate and no trial, and every route ends at a scheduled call. Pricing Decoder is a product for pricing legal work, not a statement of what Legal Decoder costs. Verified 20 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
The buyer is claimed broadly and the boundary is drawn only in the contract. Marketing addresses leading law firms and leading global firms without defining either, and the single quantitative indicator of segment is the modelled example of a 100-partner firm billing 200 million dollars a year, which is an illustration rather than a statement of who the product is for. The real boundary sits in the terms, which restrict access to Law Firm Users authorised by a law firm and exclude personal use, so in-house and government legal are outside the product by contract rather than by any published statement of scope. Practice area does not bite on this product class and is named rather than penalised: billing compliance operates on time entries irrespective of the underlying matter type, so the absence of practice pages is not a gap. What is missing is size and geography stated plainly. No firm size range, no minimum timekeeper count and no jurisdictional coverage appears, and the only geographic signal is the choice of data storage regions.
Three buyers are addressed with separate pages and different arguments: corporate legal teams justifying outside counsel spend, law firms defending rates and realisation, and bankruptcy fee examiners reviewing fee applications, with the bankruptcy work documented in detail against the US Trustee Program's 2013 guidelines. The analytical coverage is specific too, with the flag set organised into staffing efficiency, workflow efficiency and billing hygiene and individual rules named. What is not stated is the boundary: nothing says which billing formats, jurisdictions, languages or alternative fee arrangements the analysis handles poorly, or what happens with non-hourly billing. Verified 20 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No public material addresses training on customer content in either direction, and the reason is that the governing document is unpublished by design rather than missing by oversight. The privacy notice, last reviewed 5 June 2026, acknowledges that users upload confidential company information when using the services, that it may include personal data, and that its collection and protection are subject to a separate agreement with Antidote and are not covered by that policy.
The website terms of use contain no training, machine learning or data use clause. The agreement search this value requires was therefore performed and returned a document the vendor states exists and does not publish. The trust center lists a Data Protection Policy and an Acceptable Use Policy behind an access request, either of which may address it. Anthropic is named as a subprocessor, so a model provider is identified, but no statement was located about what that provider may or may not do with customer content.
The Aperture page answers the question directly: data processed through Legal Decoder's analytics engine and Aperture is used solely for the customer's own business purposes and is never used to train models. The commitment sits on a product page; the agreements that govern client processing, named in the Privacy Policy as master services and data processing agreements, are not published.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
A retention table is published and it does not reach the material the product ingests. The privacy notice sets periods for personal data: identity and account records for 180 days from the end of the relationship, marketing data until unsubscribe plus one year, technical and usage data for 12 months, and inquiry and correspondence records for 7 years. Those are specific and dated, and they are recorded here as what does exist.
None of them covers time entries, corrected narratives, ingested outside counsel guideline documents or the historical billing data used to build Individual Client Standards, because the same notice states that uploaded confidential company information is governed by a separate agreement and is not covered by that policy. No retention period, no configurable window, no deletion route and no certification applies to the content on any published surface. A Backup Policy exists on the trust center behind an access request and was not read.
Retention is acknowledged and no period is given. Legal Decoder says Aperture is not a system of record and does not store, own or act as the repository for billing information, which should stay in the customer's e-billing system, and that tokens identifying matters and people are regenerated each session rather than kept in a persistent vault. No retention window for the analysis, the queries or the structured data Legal Decoder does hold is published, and no deletion commitment on termination was located.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located material addresses walls or separation. Nothing states whether the platform is single or multi-tenant, and no role or permission model, matter-level partition or client-level partition is described on any surface. Two adjacent facts exist and neither answers the question: SAML SSO is listed among the security features on the home page and WorkOS is named as a subprocessor, both of which govern authentication into the platform rather than separation inside it.
The question has particular force on this product because Individual Client Standards are built per client from that client's own guidelines and the firm's historical billing for them, so the product holds one client's commercial standards alongside another's within a single firm tenant, and nothing published describes how those are kept apart. Searched the home page, the about page, the terms, the privacy notice and the trust center on 4 September 2026.
Checked the homepage, the Aperture, Compliance Decoder and Partners pages, the success stories, the Terms of Use and the Privacy Policy on 20 September 2026. Users are described as having read-only permissions, which prevents changes to data rather than restricting what they can see. Nothing addresses separation between matters, teams or customers, which matters where one platform holds spend data for multiple clients of the same firm.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Compelled disclosure is addressed and customer notice is not mentioned. The privacy notice lists regulators and law enforcement among the categories of recipient, on the basis that the company is required to disclose by law, court order or regulatory requirement, or to protect the rights, property or safety of Antidote Legal, its customers or others. No advance notice commitment appears, and no discretion over notice is reserved either, so the position never reaches the question of telling the customer.
Two limits belong on the record. The statement sits in a notice that governs personal data of website and account users, and the same document expressly excludes uploaded customer content from its scope, so nothing published addresses what happens if a firm's billing data is demanded. And no transparency report or request statistics were located. The confidentiality section of a master agreement is this signal's usual evidence home and that agreement is not published.
The Privacy Policy dated 21 January 2026 says information may be disclosed to comply with legal obligations or lawful requests and to protect Legal Decoder's rights, and makes no commitment about notifying anyone. It applies to website visitors and marketing only, so nothing published addresses what happens if Legal Decoder is served for a customer's invoice data.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The inputs are named and they are the customer's own documents rather than a licensed corpus. Antidote states that it ingests outside counsel guideline documents, internal firm guidelines and historical billing data to construct Individual Client Standards, so what the model reads is material the firm already holds and supplies. No external corpus is involved: the product does not retrieve primary law, published authority, form libraries or any third-party dataset, and none is named anywhere.
There is consequently no licensing question of the kind this signal was written for, and no jurisdictional coverage statement to record. The honest value is the absence with the reason stated rather than a penalty. Searched the home page, the about page, the resources index, the terms and the privacy notice on 4 September 2026.
Checked the homepage, the Aperture, Compliance Decoder and Partners pages and the success stories on 20 September 2026. The product analyses the customer's own invoices against benchmarks the vendor says are built from tens of billions of dollars in legal fees analyzed; no primary law corpus is involved, and the composition, sourcing or permissions behind the benchmark data are not described.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Nothing on any located surface addresses checking authority for subsequent history, and the product does not retrieve or present legal authority at all. Antidote reads time entries and guideline documents and writes billing narratives; no case, statute or regulation is surfaced to a user at any point in the published workflow. The question does not bite on this product class and the value records the absence rather than a shortcoming. Searched the home page, the about page, the resources index and the legal documents on 4 September 2026.
Checked the same pages on 20 September 2026. The product analyses billing data rather than citing legal authority, so no subsequent-history check arises and none is described.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
No located material describes what the system does when it cannot produce a compliant correction. The published workflow moves from detection straight to a suggested fix delivered by email, with no abstention state, no confidence or certainty signal shown to the reviewer, and no described behavior where a guideline is ambiguous, where two client rules conflict, or where the original entry is too sparse to rewrite faithfully.
That last case is the one that matters most on this product, since a model asked to improve a thin narrative has to choose between leaving it non-compliant and adding detail the fee earner did not record, and nothing published says which it does. Searched the home page, the about page, the resources index, the terms, the privacy notice and the trust center on 4 September 2026.
Checked the homepage, the Aperture page and its published questions and answers, the Compliance Decoder page and the success stories on 20 September 2026. Nothing describes what Aperture does when a question cannot be answered from the data, and no confidence level is attached to a flag or an answer. The related published control is that the model never calculates: an Analysis Request Breakdown shows the data used and a deterministic engine produces the figures.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
The AI Hallucination Cases database maintained by Damien Charlotin was searched on 4 September 2026 on the product name Antidote, the trading name Antidote Legal and the registered company name Team34. No court order, opinion or disciplinary record naming the product or the company was located. This records the state of the public record on that date and is not a finding about the product. The signal also sits at an angle to this product class, since Antidote generates billing narratives rather than legal citations and would not ordinarily produce the kind of output a court sanctions.
Searched the AI Hallucination Cases database maintained by Damien Charlotin on 20 September 2026 on the names Legal Decoder and Aperture. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No bar authority, regulator, conduct rule or ethics opinion is named on any located surface. Nothing in the home page, the about page, the resources index, the terms of use or the privacy notice engages professional regulation, and no jurisdiction-specific guidance is mapped. The absence is more consequential here than on a general productivity tool because the output is the narrative description of billable work that reaches a client, which engages fee-related conduct obligations in every jurisdiction the vendor sells into, and because the company sells across the United Kingdom, United States and Australia, which have different regimes for exactly that question.
The nearest published statement runs the other way, with the terms disclaiming any liability for a law firm's delivery of legal services to its clients.
The published bankruptcy material works through the fee standards its buyers answer to: the six-factor reasonableness of compensation test in section 330 of the Bankruptcy Code and the US Trustee Program's 2013 guidelines for reviewing fee applications in larger Chapter 11 cases, with the vendor mapping each problematic billing practice named in those guidelines to a flag in its own system. That is engagement with named professional standards on fees rather than with an ethics opinion on the use of AI, and no bar opinion is named anywhere on the estate.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Quantified savings and recovery claims are published and nothing addresses disclosure of AI involvement in the bill. The figures are prominent and modeled on a stated hypothetical of a 100-partner firm billing 200 million dollars: 8 to 10 percent of fees written off, 30 extra days to payment, roughly 17 million dollars of working capital tied up monthly, and 800,000 dollars of partner time at 8 to 10 hours per partner per month.
The stated benefits are increased realization, reduced lock-up and partner time freed. None of it reaches this signal's question. No per-matter record of AI-assisted work is described as available, no guidance on fee or disclosure treatment is published, and nothing states whether a time entry whose narrative the model rewrote is flagged as such to the firm or to the client. The direction is also worth recording plainly: this product exists to recover fees that would otherwise be written off, so its effect on the bill is upward, which is the inverse of the compression this signal was written to catch.
The fee record is the product. Legal Decoder exists to examine what was billed and whether it was reasonable, for corporate legal teams paying outside counsel, for fee examiners reviewing Chapter 11 applications, and for firms testing their own invoices before a client does. The published output is an account of billing behavior at line-item level rather than a byproduct of AI-assisted lawyering, and both sides of the invoice are addressed on their own pages.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor list is published in the clear and the forwardable pack is not. The trust center presents subprocessors without an access request, naming Amazon Web Services, Anthropic, Google, Linear and WorkOS, so a firm can tell its client which providers touch its data and, because Anthropic is on that list, can answer the model provider question specifically rather than by naming infrastructure. That satisfies the register limb.
The third limb fails: no data processing addendum is published, no consent or notification pack exists, and the Antidote Legal Security Summary 2026, the Pentest Report and the Data Protection Policy all sit behind the trust center's access flow, so there is no artifact drafted to be forwarded to a client. Worth recording as an edge rather than a defect: this vendor's entire product is helping firms comply with their clients' outside counsel guidelines, and its own readiness on the same question sits mid-tier.
The Privacy Policy states that client processing is governed by separate master services and data processing agreements, so the material exists but only for a customer who is already in a contract. No subprocessor list, model provider list or client-facing disclosure pack is published, and there is no trust page or self-serve route to request one.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located material addresses producing a record of AI involvement for a court, a client or an auditor. The product necessarily knows which entries it flagged and which corrections were accepted, since the workflow runs on review and approval, but nothing published says that history is retained, exportable or available to the firm, and no audit trail, log or export is described on any surface. This has practical bite beyond the usual case: billing narratives are disclosable in fee assessments, costs proceedings and client billing audits, and a firm asked whether a narrative was written by its fee earner or generated by a model would need exactly the record that is not described.
Searched the home page, the about page, the resources index, the terms, the privacy notice and the trust center on 4 September 2026.
Some elements of a record are published, built for a fee proceeding rather than for an AI disclosure. Every flag ties to the line item and rule that produced it, Aperture shows an Analysis Request Breakdown of the data behind each answer, and responses export to PDF, Word or CSV with the underlying data included. Nothing records which model was involved in producing an answer or who reviewed it before it was used.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- AI Liability and Recourse
- Commercial Transparency
- Ethical Walls and Matter Segregation
- Primary Law Corpus Provenance
- Good Law Verification
- Refusal and Uncertainty Behavior
Which one fits
Choose Antidote if
- You want time entries fixed to each client's guidelines before the bill goes out. Antidote builds a standard for each client from its outside counsel guidelines, your internal rules and your billing history, checks entries through the billing cycle, and emails fee earners a revised narrative to approve in one click.
- You need data stored in a region you choose. Antidote lets customers store data in the European Union, the United States or Australia, on Amazon Web Services, and names its subprocessors in its trust center without an access request.
- Your client's AI clause asks whose model reads your data. Antidote's trust center names Anthropic, Google, Amazon Web Services, Linear and WorkOS as subprocessors and lists ISO 27001:2022 and SOC 2 Type 1, with a security summary and penetration test report behind an access request.
Choose Legal Decoder if
- You pay outside counsel and want to see billing behavior line by line. Legal Decoder parses each narrative and checks it against more than 45 flags for staffing, workflow and billing hygiene, such as block billing, skill mismatches and vague entries, and benchmarks rates with Pricing Decoder.
- You review Chapter 11 fee applications. Legal Decoder maps the problematic billing practices named in the US Trustee Program's 2013 guidelines to its own flags, and publishes a retrospective on the Allied Nevada Gold case covering 14,755 line items and 135 timekeepers across eight firms.
- You want answers you can check without exposing client names to a model. Aperture replaces matter, client and attorney names with tokens regenerated each session, has a separate engine compute every figure, and shows the data behind each answer, with export to PDF, Word or CSV.
In summary
Antidote
Antidote, from Team34 Ltd of London trading as Antidote Legal, is billing compliance software for law firms that sits on top of existing time recording and practice management systems. It builds a standard for each client from that client's outside counsel guidelines, the firm's own rules and its billing history, checks time entries continuously through the billing cycle, and proposes revised narratives that fee earners approve by email. The AI Legal Index grades it in the top two bands on five of fifteen capability axes, with an A on AI centrality. Its trust center names Anthropic among its subprocessors, and customers can store data in the EU, the United States or Australia. As of 4 September 2026 the index located no named customer, published customer agreement or price.
Legal Decoder
Legal Decoder, from Legal Decoder, Inc. of Falls Church, Virginia, analyzes legal invoices for corporate legal departments, law firms and bankruptcy fee examiners, reading each billing narrative and checking it against more than 45 compliance flags covering staffing, workflow and billing hygiene. Compliance Decoder enforces outside counsel guidelines, Pricing Decoder benchmarks rates, and Aperture answers plain language questions over the structured data with a separate engine doing the arithmetic. The AI Legal Index grades it in the top two bands on seven of fifteen capability axes. It tokenizes identifying names before data reaches its model and states that data never trains models. As of 20 September 2026 the index located no security attestation, named model, integration or price.
Questions buyers ask
Antidote vs Legal Decoder: which is better for legal billing compliance?
They work on opposite sides of the invoice. Antidote helps a law firm correct entries before billing; Legal Decoder analyzes invoices for the teams that pay or examine them. On published evidence Legal Decoder sits in the top two bands on seven of fifteen AI Legal Index capability axes and Antidote on five of fifteen. Legal Decoder publishes more on method; Antidote publishes more on its supply chain and security.
Does Antidote rewrite time entry narratives?
It proposes rewrites. Antidote flags entries that breach a client's guidelines or are poorly drafted and generates a revised narrative that a fee earner can accept in one click, with suggestions sent by email. Nothing published describes what it does when an entry is too thin to revise faithfully, or states that an accepted revision is recorded as machine written for the firm or its client. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
How does Legal Decoder protect client names in AI analysis?
Aperture replaces identifying fields such as matter, client and attorney names with tokens before any data reaches the model, generates new tokens each session rather than keeping them in a persistent vault, and maps results back inside Legal Decoder's own environment. The vendor also states that data is never used to train models and that users hold read only permissions. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Which AI model does Antidote use?
Antidote's trust center lists Anthropic among its subprocessors alongside Google, Amazon Web Services, Linear and WorkOS, which identifies a model provider without naming a model or version, or saying where inference runs. It does not state whether Google is infrastructure or a second model provider. Legal Decoder says data is sent to a language model after tokenization and names no model or provider. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What do Antidote and Legal Decoder both leave unpublished?
The contract, the price and any measure of accuracy. Neither publishes the customer agreement that governs client data or states a warranty or liability position for its product, and neither publishes a price or unit of charge. Neither measures how often its flags or revisions are right, and neither describes testing before release or who is accountable for its AI. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Three readings to weigh. Antidote's figures for write offs and partner time are modeled on a hypothetical firm billing 200 million dollars a year, as the vendor states, and it names investors rather than customers. Legal Decoder's Allied Nevada Gold analysis was run on public court filings, so the firms in it are subjects rather than customers. Both vendors place client data terms in agreements that are not published. Antidote was verified on 4 September 2026 and Legal Decoder on 20 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.