August vs Vesence: how they compare in 2026
These two are not usually evaluated against each other. August is a Delaware company selling a legal AI workspace into firms in the United States, the United Kingdom, Australia and India, and Vesence is Swedish, processes exclusively in the EU and sells to Nordic firms and other professional services businesses. What putting them on the same grid shows is worth the page: two small and recent vendors both sit in the top two bands on thirteen of fifteen axes, the highest count among the twelve general legal assistants the index grades, ahead of four better known platforms that sit at twelve. They get there the same way. Both publish their contracts. Between them they publish a platform agreement, a security addendum, data processing agreements, dated subprocessor lists, an AI policy and law enforcement guidelines, with liability caps, indemnities and training prohibitions all readable before signing. Neither publishes an accuracy measurement, and neither publishes a figure for what it costs.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Every named capability on the product pages is model driven: an Assistant that answers across a document, a folder, email or the web; Tabular Review, which turns thousands of contracts into a comparison grid; clause drafting and rewriting inside Word; and Agents that chain research, analysis and drafting into multi step workflows. There is no underlying document management or practice management system that would survive the models being removed, because the systems of record here belong to someone else: Word, Outlook, SharePoint and SOS are integrations into the firm's existing stack rather than August's own conventional product. The company positions itself as 'Configurable Legal AI' in its own footer and describes co developing workflows on a firm's precedent and drafting standards. Verified 2 September 2026.
There is no conventional product underneath. The four Office add-ins have no non-model function at all: what they do is draft, redline, reformat, cross-check and quality-check, and each of those is model work. The web workspace holds files, chats and drafts in a project, but it exists to give the agent context rather than to be a document management system, and the vendor describes the whole thing as one agent across five products. The systems of record stay where they are, in Word, Outlook, Excel, PowerPoint and the firm's own files. Annex 1 to the data processing agreement puts it plainly from the other direction, describing the processing as machine learning algorithms processing collected text to generate responses and insights. Remove the models and nothing remains to sell. Verified 2 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
The AI Policy of January 2026 states that August runs 'testing protocols for accuracy and reliability verification before and after deployment' and conducts regular audits of AI system performance, but publishes no figure, no test set and no evaluation a reader can assess. Grounding is claimed in product terms rather than described: SharePoint documents 'become available for citation, analysis, and drafting', and the Assistant answers from documents, folders and the web, but no retrieval method is published and the product does not ground to primary authority. Both the Terms of Service at 1.5 and the AI Policy at section 5 state that output is AI generated and may contain errors, misstatements or be incomplete, which is a real limitation statement rather than a bare claim not to hallucinate, so the D limb does not fire. Accuracy asserted without measurement is what places this at C. Verified 2 September 2026.
Accuracy is addressed candidly and never measured. Clause 3.6 of the general terms states that due to the inherent probabilistic nature of artificial intelligence the services may occasionally produce inaccurate output or suggestions, and that this does not constitute a Defect. Putting a hallucination acknowledgement in the operative agreement rather than a disclaimer footer is rare in this pull, and it is the opposite of the bare no-hallucination claim the D limb is written for, so D does not fire. What is absent is any measurement. No accuracy figure, test set, benchmark or published evaluation appears anywhere. The product-side answer is checking rather than grounding: a one-click check described as reviewing hundreds of errors across documents and inboxes, and cross-checking spreadsheet data against source documents. Neither is a described retrieval method, and the product does not ground to primary authority, so the B limbs do not bite. Verified 2 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Review surfaces are real and specific. In Word, August 'applies changes you can accept or reject in Word's review mode', and the drafting surface shows a Preview step before generation. The AI Policy commits in writing to communicating how AI generated output should be reviewed and verified and to 'the importance of human oversight in legal work', and the Terms of Service at 1.5 place the product on the tool side of the advice line. What is missing is the threshold at which the system acts alone. The product ships Agents running two step workflows and an Outlook capability described as 'Draft and send replies', and nothing published states what an agent may complete unattended or what happens after it is wrong. That unstated threshold is the limb the B band names as commonly absent. Verified 2 September 2026.
The review surface is the strongest located in this pull and the threshold is missing. Every edit an agent makes lands as a tracked change across Word, Excel, PowerPoint and Outlook, with accept and reject controls, so the human checkpoint is the native review mode of the application the work already lives in rather than a bespoke approval screen. The obligation to use it is contractual, not aspirational: clause 4.2 requires the customer to assess the accuracy and quality of both input and output for its intended use, including conducting human reviews, and clause 10.5 repeats it. What is not published is what the agent does unattended. Nothing states which steps complete without a human, what an agent does when uncertain, or what happens after it is wrong, and the Outlook capability is described as drafting rather than sending without the boundary being stated. That unstated threshold is what the B band names. Verified 2 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Eight named customer stories are published, each on its own page: Hughes Hubbard, described as an Am Law 150 firm deploying August across legal and business teams; Hicksons in Australia; Harrison Drury; Mission Australia; White Summers; ELP in India; HDRB&B; and Dunning Vallejo & MacDonald, a twenty lawyer firm. One carries a figure, Hicksons at 90 per cent faster document review, and a partner at that firm is quoted by name and title. What holds this below A is measurement: the customer index carries no dates and no basis for the 90 per cent figure, and no method a reader could assess is published alongside it. The individual case study pages were not opened, so this note credits only what the index page itself states. Verified 2 September 2026.
Four law firms are named with their own case studies: Cederquist, Snellman, Andulf and Kanter, all Nordic, covering M&A, fund formation and full-service practice. One carries a figure attached to a named individual, with Maja Wettergren, Managing Partner at Cederquist, quoted as reaching 90 per cent weekly usage across the firm. Several case studies are dated, with the Snellman piece carrying 25 June 2026. That is dated, attributed deployment evidence, which is more than most records manage. It stops short of A on measurement. The one figure is an adoption rate rather than an outcome, so it reports how many lawyers opened the product rather than what changed in the work, and no method or basis is given for it. The individual case studies were not opened this pass, so this note credits only the customer index and home page. Verified 2 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Three of the five things the top band asks for are in the agreement. Section 11.8 of the Terms of Service prohibits training on Content and Customer Data and extends that prohibition to subprocessors other than cloud storage providers, which are also barred from retaining the material for human review, which settles the third party model provider position. Section 7.4 deletes remaining Content within 30 days of termination and clause 6 of the Data Processing Addendum requires return or deletion on the customer's reasonable request. Two limbs fail. Nothing published addresses attorney client privilege or work product treatment on any surface read. Nothing published documents matter level segregation for a product sold to law firms: the home page commits that no client document trains a model reachable outside the firm, which is a firm level boundary, and the SharePoint integration states that August 'gains access to your entire SharePoint repository', which is the shape a firm's ethical walls exist to prevent. Silence on segregation is exactly what the B band names. Verified 2 September 2026.
Three of the five limbs are met, two in the agreement itself. Clause 7.1 provides that Vesence will not use Customer Data to train AI models and will not permit its subcontractors to do so, which settles training contractually rather than by policy. Retention and deletion are set out in Annex 1 to the data processing agreement in unusual detail, with instantaneous processing and no storage by default. The position on third party model providers is the most complete in this pull: named inference entities per route, Microsoft Modified Abuse Monitoring approval waiving prompt and completion storage on all production Azure OpenAI accounts, and OpenAI routing constrained to zero data retention endpoints. Two limbs fail. Segregation is stated at tenant level, that all customer data is logically isolated per tenant, and this vendor sells to law firms, where the band asks for matter level walls; nothing addresses separation between matters or teams inside one firm. And nothing anywhere addresses privilege or work product treatment directly, which the top band requires as its own limb. Verified 2 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The advice line is stated twice and in the agreement itself, not only in a footer: Terms of Service 1.5 and AI Policy section 5 both say the Service is a research tool and its output is not legal advice. The AI Policy reaches part of the supervision and competence dimension by committing to communicate the capabilities and limitations of the systems, how output should be reviewed and verified, and the importance of human oversight. The audience is unambiguous: the product is sold to law firms and in house teams, and there is no consumer facing surface, so the consumer disclosure limb of the top band does not apply to this product class. What is absent is any statement of jurisdiction limits, and no bar or ethics opinion is engaged anywhere. Silence on jurisdiction limits is the B band's own example. Verified 2 September 2026.
The advice line is stated in the operative agreement and stated fully. Clause 10.5 provides that output and any materials made available through the services are not to be viewed as professional advice of any kind, listing legal, tax, accounting, financial and investment advice by name, that Vesence is not an advisory firm, that it does not know the full context in which output will be used, and that it does not bear responsibility for decisions, actions, omissions or reliance based on it. Clause 4.2 adds the customer's obligation to conduct human reviews, which reaches the supervision dimension that most records in this pull leave untouched. Two things hold it at B. No jurisdiction limits are stated anywhere, and no bar or ethics guidance is engaged: the vendor is Swedish and engages the EU Artificial Intelligence Act at clause 3.2 instead, which binds the supplier rather than the lawyers using it. Verified 2 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
The AI Policy of January 2026 is a real framework rather than a principles page. It commits to the EU Artificial Intelligence Act, Regulation (EU) 2024/1689, by name; requires AI literacy training for all employees involved in AI development, deployment and operations; and lists internal AI governance policies, testing protocols before and after deployment, change management for regulatory adherence on update, and regular audits of AI system performance and safety. Clause 7.5 of the Data Processing Addendum adds a commitment to review compliance with new AI specific legislation and negotiate amendments. What is absent is both of the things the top band asks for beyond a framework: no individual or function inside the vendor is named as accountable, and no testing result is published, including nothing on uneven output across matter types or populations. Verified 2 September 2026.
One real governance commitment exists and it sits in the contract rather than on a page. Clause 3.2 of the general terms requires the services to be provided in accordance with laws and regulations including but not limited to the EU Artificial Intelligence Act, which is a named instrument the customer can enforce, and it is materially more than a principles page. Everything the top bands ask for beyond that is absent. No governance framework is published, no individual or function is named as accountable for model behaviour, no pre-release testing regime is described, no certification such as ISO 42001 is claimed, and nothing at all is published about uneven output across matter types, counterparties or populations. The third party audits named on the security page are security assessments, which the axis treats as a different subject. Checked the home page, security page, general terms, data processing agreement, subprocessor list and about page on 2 September 2026. Verified 2 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
All five elements are published and specific enough to hold the vendor to. Retention and deletion: Terms of Service 7.4 deletes remaining Content within 30 days of termination, Data Processing Addendum clause 6 requires return or deletion on reasonable request, and Security Addendum section 9 retains system audit records for a minimum of one year and a maximum of ten. Access control: unique IDs, multi factor authentication and least privilege, personnel barred from accessing Customer Data except to support the Service or comply with law, access to systems holding Customer Data removed within 1 day of separation and all systems within 3 days, quarterly privilege reviews and background checks. Subprocessors: a dated list naming Microsoft, OpenAI, Google Cloud Platform and Amazon Web Services with processing regions, plus 30 days advance notice of additions under Data Processing Addendum 3.2 and a 15 day objection right at 3.3. Incident practice: notification without undue delay and within 48 hours of becoming aware, one year log preservation, and independent forensic specialists engaged at August's expense. The one gap is that no default in term retention window for prompts and outputs is published, which is recorded on the retention signal. Verified 2 September 2026.
All five elements are published, current and specific. Retention is set out in Annex 1 to the data processing agreement: processing is instantaneous and no personal data is stored by default, with the sole exceptions of prompts inside customer-created agents, retained until the customer deletes them, and an optional Cloud agents feature, off unless the customer switches it on, which persists conversations and files until deleted or deactivated. Deletion runs on customer instruction at clause 9.3, with copies destroyed unless law requires retention. Access control covers Microsoft Entra ID with token-based authentication, role-based access with least privilege, enforced multi-factor authentication, audit logging and automated session management, with customer-side administrator control of users at clause 4.5. The subprocessor list is dated 20 May 2026 and names each legal entity, its headquarters, role, processing regions and whether it is required or optional. Incident practice is set out at clause 5 of the DPA: notice without undue delay, root cause investigation, description of the breach and affected data, and coordination on public statements and regulator notices. The one thing not published on a public page is a fixed breach notification deadline in hours. Verified 2 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A buyer can read the whole allocation of loss before signing, with figures. Section 8.1 gives a third party intellectual property indemnity for use in accordance with the Terms and Documentation, with the carve outs stated: no obligation where the claim is attributable to materials not provided by August, or where output results from input the customer knew or should have known was likely to lead to infringement. Section 10.2 sets a liability cap at the greater of twelve months of fees or 250,000 dollars, and 10.3 raises it to the greater of twice twelve months of fees or 500,000 dollars for data breach claims under the Security Addendum or Data Processing Addendum and for confidentiality breaches by either party. Section 9.2 warrants conformity with the Documentation, workmanlike delivery, non infringement to August's knowledge and legal compliance, and 11.11 commits to insurance from carriers rated A.M. Best A minus, VI or better. What the vendor does not stand behind is output accuracy: the Service is provided as is under 9.3 and the indemnity is confined to infringement. That is a narrow position, published specifically, which is what the band rewards. Verified 2 September 2026.
A buyer can read the whole allocation of loss before signing, with figures. Clause 10.2 caps each party's total aggregate liability per contract year at fifty per cent of the subscription fees invoiced in that year and excludes indirect damages; clause 10.3 lifts the cap for intent and gross negligence; clause 10.4 lists six named exclusions; and clause 10.6 sets claim windows of three months from awareness and six months from occurrence. Clause 11.1 gives an intellectual property infringement indemnity running from Vesence to the customer, with the remedies at 11.2 set out in order, procure a licence, replace, amend, or terminate and refund prepaid fees, and 11.3 makes it the sole and exclusive remedy. Warranties are real: clause 3.2 promises professional and workmanlike provision in accordance with law including the EU AI Act, and clause 6.3 warrants non-infringement to the best of Vesence's knowledge. What the vendor does not stand behind is output, and it says so specifically: clause 3.6 provides that occasional inaccurate output is not a Defect. The fifty per cent cap is materially lower than the annual-fees norm and is recorded here because a buyer should price it. Verified 2 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The integrations page describes what moves, in which direction, and what the firm connects. SOS, the practice management system, is bidirectional and says so: August syncs matters, contacts and case data in, workflows run on live matters, and 'Completed reviews, summaries, and outputs sync back to SOS'. SharePoint is inbound after a one time account connection, with selected documents becoming available for citation, analysis and drafting on the same footing as uploads. Word is in place rather than sync, chatting with the open document and generating edits as tracked changes in review mode, with firm playbooks applied. Outlook covers search across the mailbox, thread summarisation and reply drafting. The limitation worth naming is that all of this lives on a marketing page: no developer index, help centre or implementer documentation exists anywhere in the site navigation, footer or legal hub, and iManage and NetDocuments, the two document management systems most large firms run, are not among the named connections. Verified 2 September 2026.
The product lives inside the drafting environment rather than connecting to it, and each surface has its own page describing what it does: tracked-change generation and template filling in Word, house-style drafting and inbox-wide error checking in Outlook, spreadsheet review and cross-checking against source documents in Excel, and slide quality checks and firm formatting in PowerPoint, with distribution through Microsoft AppSource and a mobile continuation of the same workspace. That is real depth in the four applications a professional services firm actually drafts in. What is absent is the rest of the stack a law firm runs. No document management integration is named, and iManage and NetDocuments do not appear anywhere, which matters more here than for an in-house product because the firm's matter files live in a DMS. No API, developer documentation or implementation guide was located, and nothing describes what synchronises or what a firm must configure beyond installing the add-ins. Verified 2 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Section 2 of the Security Addendum states that customer data and content reside in data centres matching the geographic region specified in the order form, and that a customer may request storage in a separate specific region, which August will use commercially reasonable efforts to accommodate where its cloud providers support it. The subprocessor list names the regions in play: United States, European Union, Switzerland and Australia. The home page advertises hosting in the region of the buyer's choice and EU and US options. Two things are absent. The tenancy model is never stated, so a buyer cannot tell whether the deployment is multi tenant, single tenant or private, and the per firm subdomain shown in product imagery is not described as a separation boundary anywhere. Processing location is not addressed as distinct from storage location, since section 2 speaks only to where data reside. Residency offered without the processing location addressed is the B band's second limb. Verified 2 September 2026.
Residency is published to a level of specificity nothing else in this pull approaches, and processing is separated from storage throughout. The subprocessor list gives regions per route: Sweden Central as the primary Azure region, West Europe for Static Web Apps, EU Azure OpenAI regions or DataZone deployments where Azure inference is used, and eu-central-1 in Frankfurt for the AWS Bedrock route. Annex 1 to the data processing agreement states that processing is performed exclusively within the EU and EEA, and the security page repeats it. The tenancy position is stated too, that all customer data is logically isolated per tenant, alongside a Zero Trust architecture and redundant infrastructure with automatic failover and point-in-time recovery. The subprocessor page even addresses which deployment types should not be used for EU traffic. The limitation a buyer should weigh is the flip side of that precision: there is one region policy and no non-EU option, so a customer with a data localisation requirement outside Europe is not served. That is a restriction on availability, disclosed, rather than an absence of disclosure. Verified 2 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Section 1 of the Security Addendum states that August's information security management system undergoes annual assessment by independent third party auditors and that the company maintains SOC 2 Type II and ISO 27001, with a commitment to adopt an equivalent recognised framework if either is discontinued. Section 4 adds annual third party penetration testing and web application assessment against OWASP. Section 10 gives customers, at no cost, access to SOC 2 Type II reports, penetration test summaries and ISO 27001 certifications, plus up to 100 security questions a year. What the top band asks for is not there: no auditor is named, no coverage period or report date is published, and the report route in section 10 runs to contracted customers rather than to a prospect. A trust centre exists at trust.august.law, named in Terms of Service 12.5 as where the Business Associate Addendum sits, but it refused automated access on 2 September 2026; that is a retrieval limit on this side rather than a gap on the vendor's, and its contents are neither graded against August nor credited to it. Verified 2 September 2026.
SOC 2 Type II is claimed with its scope named, described as independently audited controls for security, availability and confidentiality, which is more than the bare standard name most records offer. Regular third-party security audits and vulnerability assessments are stated, and the security page invites IT and compliance teams to ask for the report. What the top band asks for is missing on every remaining count. No auditor is named, no coverage period or report date is published, no penetration test summary is offered, and there is no trust centre or portal of any kind, so the route to the report is an email to support and its tier could not be established from what the page states. Clause 6 of the data processing agreement adds a contractual audit right, allowing the customer or its mandated third-party auditor to inspect, which is a real entitlement for a signed customer rather than accessible evidence for a prospect. Verified 2 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The subprocessor list of January 2026 names four AI providers under its own heading for model providers and infrastructure, Microsoft, OpenAI, Google Cloud Platform and Amazon Web Services, each with its processing regions, and Data Processing Addendum 3.2 commits to 30 days advance notice before any new subprocessor begins processing, with a 15 day objection right. That is providers, location and change notification, three of the four things the top band asks for. The models themselves are not named. The closest the site comes is a home page line describing August as model agnostic across Anthropic, private OpenAI endpoints and Llama, which is a mix of two providers and one model family rather than a model list, and it sits awkwardly against the subprocessor list, where Anthropic does not appear at all. Three further subprocessors that touch content are identified only by function, as web browsing, knowledge source and email subprocessors. Verified 2 September 2026.
This is the most complete supply chain disclosure located in the pull. The models are named on the product pages, including GPT-5.6 Sol, GPT-5.6 Terra, GPT-5.5, Opus 5, Opus 4.8 and Gemini 3.7 Flash. The providers are named as legal entities rather than brands on a dated subprocessor list: Microsoft Ireland Operations Limited, Amazon Web Services EMEA SARL and OpenAI Ireland Ltd, each with headquarters, role and status. Where they run is given per route, from Sweden Central to Frankfurt. The routing itself is explained, so a reader can see that Claude models reached through Bedrock make AWS the subprocessor while OpenAI models reached through Azure make Microsoft the subprocessor, and the customer chooses which provider routes are enabled. Change is committed at clause 7.2 of the DPA: the list is updated before any new subprocessor is authorised, with a ten business day objection right at 7.3. Two limitations belong on the record. Notification is pull rather than push, since the DPA asks the customer to monitor the page with a URL tracking service. And the home page states that Vesence switches to a better model as soon as it ships, so model version changes within an authorised provider are not notified. Verified 2 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Checked the home page, the full navigation and footer, the legal hub and its fourteen documents, the integrations page and the customers page on 2 September 2026. No pricing page appears anywhere in the site's own navigation or footer, and no figure, unit of charge or tier structure is published on any page that loads. The routes offered a buyer are Book a Demo and a self serve sign in at app.august.law, alongside a seven day free trial named in the home page metadata and an offer to build a live workflow free within a week. A pricing page at august.law/start-now remains in search engine indexes carrying tier names, a feature split and a monthly figure, but it returned a 404 on both the www and non www forms of the URL on 2 September 2026, so nothing on it could be confirmed against a loading first party surface. The only other figures located are in January 2026 trade press, and they disagree with the indexed page, so neither is written here. Verified 2 September 2026.
The unit and the structure are published without the figure. Clause 5.1 puts subscription fees in an Order Form; clause 5.4 caps annual indexation at five per cent; clause 5.2 allows fee changes only in proportion to documented changes in third party costs such as Microsoft Azure; clause 12.1.3 sets twelve month automatic renewals terminable on sixty days notice; clause 12.1.2 gives a right to exit within the first three months of the initial term; and section 13 provides that a Pilot is free of charge unless the Order Form says otherwise. The usage-based unit is named rather than gestured at, with Annex 1 to the DPA describing Vesence Credits and consumption tracked at user, matter and day level. A free trial is offered from the home page. What is absent is everything above that: no pricing page, no tier names, no feature splits and no figure anywhere, and the structure sits in the agreement rather than on a commercial surface. Verified 2 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described with substance on both dimensions. Seven practice areas are named on the home page with a time saved figure attached to each: Corporate and M&A, Litigation, Disputes, Real Estate, Capital Markets, Regulatory and ESG, and Healthcare. Segment reach is evidenced by the customer roster rather than only claimed, running from a twenty lawyer firm through midsize firms such as Hicksons and Harrison Drury to the Am Law 150, and including in house teams at Mission Australia, Outside GC and DevRev. Geography is specific: the About section names expansion into England, Australia, Colombia, the Middle East and India, and dedicated India and Australia pages exist. What is left open is the boundary. Nothing states which practice areas or firm types the product is not built for, and the founding story's emphasis on midsize firms sits unreconciled with an Am Law 150 firmwide deployment. Verified 2 September 2026.
Practice coverage is documented better than by any other record in this pull. Seven areas each have their own page describing what the product does there: corporate, banking and finance, fund formation, dispute resolution, compliance, family law and business support, with the corporate page describing diligence across a data room and keeping defined terms and cross-references consistent from term sheet to signing. What is left open is the boundary and the segment. No firm size band is named, nothing distinguishes what the product supports for a large firm from a small one, and no jurisdiction is stated even though the named customers are Nordic and the agreement is governed by Swedish law with Stockholm arbitration. The buyer is also deliberately broader than legal: the vendor addresses law firms, banks, investment funds and enterprises together and describes itself as made for professional services, so a reader cannot tell where legal-specific capability ends and general document work begins. Nothing states what the product does not support. Verified 2 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The prohibition sits in the agreement at clause 11.8 rather than on a policy page, and it extends to subprocessors: all but cloud storage providers are barred from training on the material and from retaining it for human review. Section 3 of the AI Policy repeats the commitment. Two adjacent permissions are disclosed and neither reaches Content or Customer Data: clause 11.7 allows Usage Data, expressly defined to exclude Content and Customer Data, to be used for service development, and clause 3.4 allows free use of Feedback but bars any use that could identify the customer, its users, its Customer Data or its Content.
The prohibition is in the operative agreement at clause 7.1 and extends outward in the same sentence, which adds that Vesence will not permit its subcontractors to train on Customer Data either. It carries one proviso, unless explicitly agreed in writing, which is a variation clause rather than a product setting: nothing describes a configuration in which training is switched on. Annex 1 to the data processing agreement confirms the prohibition applies to the optional Cloud agents feature as well. Two adjacent permissions are disclosed and neither reaches content. Clause 7.2 allows Vesence to collect and disclose quantitative data derived from use of the services, described as statistics about which features were used, in anonymous and aggregated form. That clause names feature usage rather than machine learning, so it does not qualify the prohibition.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Clause 6 of the Data Processing Addendum gives the customer a standing contractual right to require return or deletion at any time, not only at termination, and Terms of Service 7.4 deletes remaining Customer Data and Content within 30 days of termination unless the customer instructs otherwise. Control therefore runs by contractual instruction rather than by a product setting. No default in term retention window for prompts and outputs is published anywhere, and no zero retention option is stated as available. Separately, Security Addendum section 9 retains system audit records for a minimum of one year and a maximum of ten, which covers system activity logging rather than prompt and output content.
Zero retention is the default rather than an option the customer has to find. Annex 1 to the data processing agreement states that each processing is instantaneous and no personal data is stored, and the security page adds that documents are processed in memory and never persisted beyond the session. Persistence exists but the customer switches it on: prompts inside customer-created agents are retained until the customer deletes them, and a Cloud agents feature stores conversations and uploaded files between sessions, described expressly as optional and not activated by default. Where a customer does enable it, retention runs until the customer deletes the data, deactivates Cloud agents, stops using the service or requests removal, with storage in Vesence's Azure environment under the same no-training and tenant isolation terms. Usage data for Vesence Credits, where usage-based pricing is enabled, is retained for the term or until the customer asks for deletion.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Checked the home page, the Assistant, Tabular Review and integrations product pages, the Terms of Service, Security Addendum, Data Processing Addendum and Privacy Policy on 2 September 2026. No located material addresses ethical walls or segregation of one matter from another. The nearest statements point the other way: the home page commits that no client document trains a model anyone outside the firm can access, which draws the boundary at the firm rather than the matter, and the SharePoint integration states that August gains access to the firm's entire SharePoint repository once connected, without describing whether retrieval enforces the source system's per user access model at query time. Security Addendum section 4 constrains August personnel access but says nothing about separation between the firm's own users.
Vesence operates its own permission model rather than inheriting one, and documents it at the level of the tenant. The security page states logical isolation per tenant alongside role-based access control on least-privilege principles, Microsoft Entra ID token-based authentication, enforced multi-factor authentication and a Zero Trust architecture verifying every request. Clause 4.5 of the general terms puts user administration in the customer's hands, giving nominated personnel administrative privileges to manage users and access logging, which is the alignment burden this value describes. The gap matters for this buyer in particular. Vesence sells to law firms, where the question is whether one matter team can reach another's material, and nothing published addresses separation between matters, teams or users inside a single tenant. Tenant isolation answers the question between customers, not within one.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
August publishes a dedicated Law Enforcement Guidelines page committing to notice unless legally prohibited, and where a gag order applies it states it will request a waiver, document that request in writing, and notify the customer as soon as the restriction expires. It also directs requestors to the customer first where legally possible, states it does not volunteer data to government agencies, and limits foreign government responses to MLAT, letters rogatory and CLOUD Act channels. Terms of Service 11.6 gives advance notice of legally required disclosure where permissible, and Data Processing Addendum 4.1 repeats the commitment. Section 5.3 says records of requests received and responses are maintained, but no transparency report was located, which is why this is not the top value.
Clause 4.1(a) of the data processing agreement commits Vesence to notice before it acts. Where EU or member state law requires processing without the customer's instructions, Vesence undertakes to inform the customer of that requirement prior to processing, with the single exception of a legal prohibition on giving that information on important grounds of public interest. Notice before rather than after is a stronger formulation than most. It is not the top value because no transparency report was located: nothing published records how many requests have been received or how they were answered. Clause 8.3(e) of the general terms separately carves legally compelled disclosure out of the confidentiality obligation without addressing notice, and the two provisions read together are what the record rests on.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Section 3 of the AI Policy states that August secures the necessary rights and licences for datasets integrated into the Service and monitors third party compliance when collecting such information, but it identifies no source. Checked the home page, the Assistant, Tabular Review and integrations pages, the AI Policy and the subprocessor list on 2 September 2026; no primary law corpus, publisher or jurisdiction coverage statement was located. The product's material is chiefly the firm's own documents plus SharePoint, email and web content rather than a published body of primary law, so the coverage risk this signal tracks does not arise in its usual form. The subprocessor list carries an unnamed knowledge source subprocessor for knowledge sources and URL searching, so a third party sits behind that retrieval and is not identified.
Checked the home page, the five platform pages, the practice area pages, the security page, the general terms and the data processing agreement on 2 September 2026. No public material identifies a corpus and none is claimed. Annex 1 to the DPA describes the material as the text the user provides, being documents, agreements, questions, answers and conversations, so the product works on the firm's own files and the counterparty documents in front of it rather than on a published body of primary law. The coverage and title risks this signal tracks do not arise in that shape.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Checked the home page, the Assistant, Tabular Review and integrations product pages and the AI Policy on 2 September 2026. No located material addresses subsequent history, treatment flags or citator coverage. The product does not claim to retrieve primary law and its named retrieval targets are uploaded documents, SharePoint, Outlook and the web, so no good law check is offered and none is asserted. The honest reading is that the question is not addressed rather than that a check exists in some weaker form.
Checked the home page, the five platform pages, the practice area pages and the general terms on 2 September 2026. No public material addresses subsequent history, treatment flags or citator coverage, and none is claimed. The product drafts and checks documents rather than retrieving authority, so no good law check is offered; the dispute resolution practice page describes searching and structuring case material supplied by the firm rather than researching reported decisions. The honest value is that the question is not addressed rather than that a weaker form of checking exists.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Checked the AI Policy, the Terms of Service, the home page and the product pages on 2 September 2026. Section 5 of the AI Policy commits to communicating the capabilities and limitations of the systems, and Terms of Service 1.5 states that output is AI generated and may contain errors, misstatements or be incomplete. Neither describes what the product does when it cannot ground an answer. No abstention or no answer path is documented, and no confidence or grounding score is exposed in any published material, so the weaker values are false of this record as well.
Checked the home page, the five platform pages, the security page, the general terms and the data processing agreement on 2 September 2026. Nothing describes what the product does when it cannot ground an answer. Clause 3.6 of the general terms comes closer than most vendors manage by acknowledging that the services may occasionally produce inaccurate output because of the probabilistic nature of artificial intelligence, but that is a disclosure that errors occur rather than an account of abstention. No no-answer path is documented and no confidence or grounding score is exposed, so the weaker values are false of this record as well. The one-click check feature reviews output for errors after generation, which is correction rather than refusal.
Fabricated Citation Record
Does a public court record exist involving output from this product?
Searched the AI Hallucination Cases database maintained by Damien Charlotin, and reporting on it, on 2 September 2026 on both the product name August and the corporate name Credicle Corporation. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product, and the search is weaker than usual because August is a common word that appears in case names, dates and party names throughout the corpus.
Searched the AI Hallucination Cases database maintained by Damien Charlotin, and reporting drawing on it, on 2 September 2026 on the product and corporate name Vesence and Vesence AB. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product. Two things bound it: the vendor is Swedish with a Nordic customer base, and the database is heavily weighted to United States filings, so a European product is less likely to surface even where an incident occurred; and the product drafts and reviews documents rather than retrieving authority, so the fabricated citation exposure is structurally lower than for a research tool.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Checked the home page, the AI Policy, the Terms of Service and Platform Agreement, the Security Addendum, Data Processing Addendum, Privacy Policy, Law Enforcement Guidelines and subprocessor list, and the product, integrations and customers pages on 2 September 2026, and ran a domain scoped search for engagement with bar or ethics guidance. No located material names ABA Formal Opinion 512 or any state bar opinion. The AI Policy does engage a named instrument, the EU Artificial Intelligence Act, Regulation (EU) 2024/1689, but that is legislation binding the vendor rather than ethics guidance binding its buyers, which is what this signal asks about.
Checked the home page, platform and practice area pages, security page, general terms, data processing agreement, subprocessor list and about page on 2 September 2026. No public material engages with ABA Formal Opinion 512, any state bar opinion, or any national bar or law society guidance in the Nordic markets where the named customers sit. The vendor does engage a named instrument, committing at clause 3.2 of the general terms to provide the services in accordance with the EU Artificial Intelligence Act, but that regulates the supplier rather than the professional obligations of the lawyers using the product, which is what this signal records.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The home page publishes a time saved figure for each of seven practice areas, from two hours in Capital Markets to seven in Disputes, and the customer material claims 90 per cent faster document review at one named firm. Nothing located addresses what happens to the invoice when that compression occurs. The home page metadata names invoicing among the tasks the product automates, but no material shows that the invoicing feature records or distinguishes AI assisted work on a per matter basis, so no audit record of AI assisted work was established. Checked the home page, product and integrations pages, the customers page and the AI Policy on 2 September 2026.
A per matter record of AI assisted work exists and is described in the agreement rather than inferred. Annex 1 to the data processing agreement states that where usage-based pricing is enabled, Vesence Credit consumption data is collected at user, matter and day level in order to display that consumption to the customer through the services. Credits are consumed by AI work, so a firm running usage-based pricing can see which matters the AI worked on, by whom and when, which is the record this signal asks for. Two limits keep it off the top value. The record exists only where usage-based pricing is enabled rather than for every customer, and no fee guidance of any kind is published: nothing addresses how AI assisted time should be billed to a client, disclosed, or reconciled against an hourly rate.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
All three artifacts a firm needs are published and reachable without an agreement. The subprocessor list of January 2026 names the AI providers as AI providers rather than as infrastructure, Microsoft, OpenAI, Google Cloud Platform and Amazon Web Services, each with processing regions. The Data Processing Addendum is published in full and its clause 3.2 commits to 30 days advance notice of new subprocessors with a 15 day objection right, which is the forwardable client facing instrument. Alongside it sit an ungated AI Policy, Security Addendum and Law Enforcement Guidelines, all of which a firm can hand to a client. The limitation worth naming is that three subprocessors that touch content are identified only by function, as web browsing, knowledge source and email subprocessors, so a firm answering a client cannot name them.
All three artifacts are published and reachable without an agreement. The subprocessor list, dated 20 May 2026, names each legal entity with its headquarters, role, processing regions and required or optional status, and it separates the core hosting subprocessor from the AI inference providers, so a firm can tell a client exactly which entities may see its content and where. The model provider position is set out route by route, including that Anthropic is not listed separately where Claude is reached through Bedrock and why. The data processing agreement is published in full and is drafted to be forwarded, with clause 7.2 committing to update the list before authorising any new subprocessor and clause 7.3 giving a ten business day objection right. One practical limitation belongs on the record: notification is pull rather than push, since clause 7.2 asks the customer to monitor the page using a URL tracking service.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Checked the home page, the Assistant, Tabular Review and integrations product pages, the AI Policy, the Terms of Service and the Security Addendum on 2 September 2026. No located material addresses judicial standing orders on AI disclosure, verification certification, or exporting a record of which model produced which passage and who checked it. The Word integration produces tracked changes a lawyer accepts or rejects, which is a review artifact rather than a disclosure record, and the audit logging at Security Addendum section 9 covers information system activity for security investigation rather than document level model use.
Checked the home page, the five platform pages, the practice area pages, the security page, the general terms and the data processing agreement on 2 September 2026. Nothing addresses judicial standing orders, AI use disclosure or verification certification, and no exportable per document record of model used, sources retrieved and human verification is described. The product does leave an unusually good trail in the document itself, since every agent edit lands as a tracked change that a person accepted or rejected, and Vesence Credit consumption is recorded per matter where usage-based pricing is on. Neither records which model produced which passage, so neither answers the question this signal asks.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- Primary Law Corpus Provenance
- Good Law Verification
- Refusal and Uncertainty Behaviour
- Bar Guidance Alignment
- Court Disclosure Support
Which one fits
Choose August if
- Your firm runs SOS and wants the work to come back. August documents the practice management integration as bidirectional, syncing matters, contacts and case data in so workflows run on live matters, with completed reviews, summaries and outputs syncing back, alongside SharePoint as an inbound source and tracked change generation inside Word's review mode.
- You want recourse stated with figures. August's terms give an intellectual property indemnity with the carve outs named, cap liability at the greater of twelve months of fees or 250,000 dollars, raise that to the greater of twice twelve months of fees or 500,000 dollars for data breach and confidentiality claims, warrant conformity with the documentation, and commit to insurance from carriers rated A.M. Best A minus, VI or better.
- You want to know what happens when a government asks. August publishes law enforcement guidelines committing to notify customers unless legally prohibited, to request a waiver where a gag order applies and document that request in writing, to notify once the restriction expires, to direct requestors to the customer first where legally possible, and to answer foreign government requests only through mutual legal assistance channels.
Choose Vesence if
- Your processing has to stay in Europe and you want the region named per route. Vesence states processing exclusively within the EU and EEA and publishes the regions individually: Sweden Central as the primary Azure region, West Europe for static web apps, EU Azure OpenAI or DataZone deployments for Azure inference, and eu-central-1 in Frankfurt for the AWS Bedrock route.
- You want to know which model, not just whose. Vesence names the models on its product pages, including GPT-5.6 Sol, Opus 5 and Gemini 3.7 Flash, names the providers as legal entities on a dated subprocessor list covering Microsoft Ireland, Amazon Web Services EMEA and OpenAI Ireland, explains which route makes which entity the subprocessor, and lets the customer choose which provider routes are enabled.
- You would rather nothing persisted at all. Vesence's data processing annex states that each processing is instantaneous with no personal data stored, and the security page adds that documents are processed in memory and never persisted beyond the session, with persistence arriving only where the customer creates agents or switches on the optional Cloud agents feature.
In summary
August
August is a legal AI workspace for law firms, built around an assistant that answers across documents, folders, email and the web, a tabular review grid for large document sets, and configurable agents that chain research, analysis and drafting, working inside Microsoft Word, Outlook and SharePoint and connecting to the SOS practice management system. The AI Legal Index grades it in the top two bands on thirteen of fifteen capability axes, with A grades on AI centrality, AI safety and data stewardship, AI liability and recourse and integration depth. It publishes its platform agreement, security addendum, data processing addendum, subprocessor list, AI policy and law enforcement guidelines in full. As of 2 September 2026 the index located no accuracy measurement and no confirmable published price.
Vesence
Vesence is an agentic AI platform for law firms and other professional services businesses, built to run inside Microsoft Office rather than alongside it, with the same agent working across Word, Outlook, Excel and PowerPoint and in a web workspace, and every edit landing as a tracked change the user accepts or rejects. The AI Legal Index grades it in the top two bands on thirteen of fifteen capability axes, with A grades on AI centrality, AI safety and data stewardship, AI liability and recourse, deployment and data residency and model supply chain disclosure. Processing runs exclusively in the EU, and the models themselves are named. As of 2 September 2026 the index located no accuracy measurement and no published figure for what it costs.
Questions buyers ask
Are August and Vesence alternatives to each other?
Rarely. August is a Delaware company selling into firms in the United States, the United Kingdom, Australia and India, and Vesence is Swedish, processes exclusively in the EU and sells to Nordic firms and other professional services businesses. They occupy the same product class, an agent working inside Microsoft Office, without competing for the same shortlist. The comparison is worth reading because both are graded on the same fifteen axes, and what that shows is that two small recent vendors publish more than most of the platforms they are measured against. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Do either train on client documents?
Neither does, and in both cases the prohibition is contractual rather than a policy statement. Clause 11.8 of August's terms bars training on content and customer data and extends that bar to subprocessors other than cloud storage providers, which are also barred from retaining material for human review. Clause 7.1 of Vesence's terms states that it will not use customer data to train AI models and will not permit its subcontractors to do so, with a proviso for anything explicitly agreed in writing. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Which one names the models rather than the providers?
Vesence. It names GPT-5.6 Sol, Opus 5 and Gemini 3.7 Flash among the models on its product pages, and separately names the providers as legal entities with their processing regions and explains which routing makes which entity the subprocessor. August names four AI providers on its subprocessor list, being Microsoft, OpenAI, Google Cloud Platform and Amazon Web Services, with processing regions, and does not name the models; a home page line describing it as model agnostic across Anthropic, private OpenAI endpoints and Llama sits alongside a subprocessor list where Anthropic does not appear. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What happens if a government asks for your data?
Both commit to notice, by different routes. August publishes dedicated law enforcement guidelines promising notification unless legally prohibited, a documented waiver request where a gag order applies, and notification once the restriction lifts. Vesence's data processing agreement commits at clause 4.1(a) to inform the customer before processing where law requires it to act without instructions, subject only to a prohibition on important grounds of public interest. Neither publishes a transparency report. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What do August and Vesence both leave unpublished?
Neither publishes an accuracy measurement: no figure, test set or evaluation appears on either record. Neither names a bar or ethics authority, including ABA Formal Opinion 512. Neither documents what the product does when it cannot ground an answer. Neither publishes a rate. And neither addresses separation between matters inside a firm, which matters because both sell to law firms: August draws its boundary at the firm and Vesence at the tenant, and neither describes walls within one. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Two things belong on this page. Neither vendor stands behind the accuracy of its output and both say so plainly: August provides the service as is under section 9.3 and confines its indemnity to infringement, and clause 3.6 of Vesence's terms provides that occasionally inaccurate output does not constitute a defect. Vesence's liability cap is also materially lower than the norm, at fifty per cent of the subscription fees invoiced in the contract year, against August's floor of 250,000 dollars, and a buyer should price that difference. Two limits on this reading: August's trust centre refused automated access, and its pricing page returned a 404 on both URL forms, so no figure could be confirmed from a first party surface. Both records were verified on 2 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.