BigHand vs Foundation AI: how they compare in 2026
BigHand and Foundation AI both run law firm operations but are not usually weighed against each other. BigHand sells work routing, resourcing and financial software to large firms; Foundation AI files every document a high volume firm receives, and one grid shows them as near mirror images. Foundation AI sits in the top two bands on six of fifteen axes and BigHand on five of fifteen, identical on three. Foundation AI publishes how its AI works and where a person checks it. Each field it extracts carries a calibrated confidence score, uncertain results go to a reviewer, and on matter matching it states that it does not guess. It publishes nothing on how it handles the medical records and pleadings it reads. BigHand is the reverse. Its privacy policy limits customer data to providing the products, and it names ISO 27001, ISO 27701 and SOC 2 Type 2, audited by A-LIGN. Yet it names no model and describes no human review of AI that recodes time entries. Neither publishes a customer agreement.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Artificial intelligence is present, real and peripheral to a sixteen-product estate, which is the C band, and the vendor says so itself more plainly than most. The AI that ships is two features. BigHand Impact Analytics, formerly Digitory Legal, uses machine learning to analyse and re-encode timecard data, converting inconsistent narratives into structured phase and task-level information that feeds pricing, staffing and billing quality. AI Email Routing arrived in the Workflow Management Spring Update 2026. Everything else in the catalogue is rules-based or analytical: workflow and task allocation, resource forecasting, digital dictation and speech recognition, document creation, formatting, stamping, metadata cleansing, recipient checking, redaction, pitching, business intelligence dashboards, matter pricing, budgeting, partner performance, prebill review and alerting. Remove the AI and fourteen of sixteen products are untouched. The vendor's own positioning statement is the clearest evidence and is quoted in the note because it cuts against the grain of this market: the market is selling AI, BigHand is building the intelligence AI needs to be useful. Recorded and expressly not credited under the ground rules on future tense: the Predict section describing the acquired Ayora technology is written entirely in the future, the next chapter, the next development stage, and what the company will predict, with integrated capabilities stated to be expected later in the year. Verified 12 September 2026.
Take the models out and what is left is a mailroom. The platform's published architecture is the product: fine-tuned language models, retrieval, vector search, business logic, jurisdiction-specific taxonomies and deterministic guardrails evaluating each document from several angles, with the results reconciled and calibrated into a confidence score for every field. Classification, matter matching and extraction are all model work, and the vendor argues the point directly, saying general-purpose models look impressive in demos and fail silently in production because categories overlap, taxonomies are hierarchical and a wrong model sounds as confident as a right one. Verified 20 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Reliability is asserted without measurement and no grounding method is described, which is the C band, and R15 governs the weight. This product cites no legal authority: the AI reads a firm's own timecards and routes its own email, so the limbs on primary sources, openable citations and citator status do not bite and the record is not penalised for them. What does bite is that the output is quantitative and reaches a client. Impact Analytics re-encodes narrative time entries into phase and task codes, and those codes and narratives are what a client sees on a bill and what a firm relies on to price the next matter. The vendor's language around that is confident and unevidenced: reliable pricing insights, dependable data, award-winning AI-enabled timecard analysis, and a promise of clean timecard narratives. No accuracy figure, error rate, test set, confusion matrix or evaluation is published for the re-coding, and nothing describes what happens when the model codes an entry wrongly. Recorded and expressly not credited, because they measure a different thing: the outcome figures published across the estate, a 20 per cent increase in realisation on a multimillion-dollar engagement and a 23 per cent average reduction in write-offs, are commercial results rather than accuracy measurements, and neither is dated or attributed. No hallucination disclosure of any kind was located on any surface read. Verified 12 September 2026.
For an extraction product the question is whether a value traces back to the document and whether the system knows when it is unsure, and both are addressed with real method. Every classification, match and extraction is evaluated against calibrated confidence thresholds, results from several analytical routes are reconciled, and the confidence attaches per field rather than per document. Matching is described the same way, using names, dates, addresses and claim and policy numbers through custom models, retrieval and guardrails. What is not published is a number: no accuracy, precision or error rate from the vendor, no test set and no evaluation an outsider could check. The only figures are customer-reported, such as the 98 per cent accuracy quoted in the Stockwell Harris story. Verified 20 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Nothing published on how the models are supervised was located, which is the D band, and the note sets out why that reads as a real gap here rather than an inapplicable limb. Two of this vendor's AI features act rather than advise. Workflow Management is described as automatically routing work to the right resource, and AI Email Routing shipped in 2026 as an enhancement to that routing. Impact Analytics re-encodes timecard data, which is a change to the firm's own records rather than a suggestion about them. For none of these does any surface state whether a person reviews the output before it takes effect, whether a re-coded time entry can be inspected or reversed, what happens when a routing decision is wrong, or where a human sits in the loop at all. No published statement of human oversight, no review surface, no threshold, no confidence signal and no escalation path was located. The absence is not explained by the product class: R15 would excuse the limbs about legal advice and filings, and it does, but supervision of automated action on a firm's own billing records and work allocation is squarely within what this axis measures. One adjacent statement is recorded and not credited because it addresses the vendor's own internal use rather than the product: the privacy policy states that the vendor does not use personal information to profile or enable automated decision-making about individuals. Verified 12 September 2026.
What runs alone, what stops it and how a person checks it are all published together. Confident results move straight through; anything below the calibrated threshold is held and surfaced in the review interface with the uncertainty highlighted, and on matter matching the vendor states plainly that when confidence is low it does not guess but offers the most likely matches for a person to confirm. The escalation route is described at the organisational level too, with most firms centralising review in an operations team rather than spreading it across case managers. Execution is bounded by firm-defined rules for routing, tasking, deadlines and escalation, and every action is tracked. The vendor's own summary is that the platform does not remove humans from the process, it removes the wrong work from humans. Verified 20 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers at the top of the market and outcome figures are both published, and they are never joined, which is the B band in its own terms. The naming is extensive and specific, a client wall carrying DLA Piper, Dentons, Allen and Overy, Norton Rose Fulbright, Ashurst, CMS, Pinsent Masons, Clyde and Co, Lewis Brisbois, Fox Rothschild, Husch Blackwell, Foley and Lardner, Baker Donelson, Allens and Schillings, supported by penetration figures that are the most precise in this lane: 81 per cent of the AmLaw 200, 82 per cent of the top 200 United Kingdom firms, 96 per cent of the top 50 Asia-Pacific firms, 3,300 firms and more than 810,000 users. Four case studies are published by name, covering Womble Bond Dickinson on resource management, FordHarrison on business intelligence, Charles Russell Speechlys on workflow and Otten Johnson on document creation. Outcome figures are published per product: a 20 per cent increase in realisation on a multimillion-dollar engagement, a 23 per cent average reduction in write-offs within twelve months, a 28 per cent reduction in the billing and collections lifecycle, 81 hours saved per fee earner per year, four hours per user per week, and around three weeks from time entry to bill. What A requires is these two halves joined, and they are not: no figure is attributed to a named firm, none is dated, and no basis or method is stated for any of them. The case studies were not opened; under R25 they corroborate a grade already resting on the client wall and are what would move this row. Verified 12 September 2026.
Named firms, named people, described deployments and figures, at a stated scale. Seven customer stories run on the homepage with the customer, the individual and their title attached to each outcome: Nyman Turkish at more than 12 times the document processing productivity, Miller Dawson Sigal & Ward down from five or six hours a day to fifteen minutes, Acumen Law from about 120 hours a week to roughly five, Stockwell Harris at five times faster with 8,000 dollars a week saved and 400,000 dollars of temporary staff spend avoided. The Floyd Skeren study, read in full, sets out the firm's prior process across ten offices, the system it integrates with, the staffing change and the results, 350 per cent more document processing efficiency and 81 per cent fewer non-billable hours, with a downloadable version. Around forty firm logos appear across the platform and integration pages, and the vendor states seven years of operations, hundreds of firms and millions of documents a month. What no story gives is the measurement method behind the percentages. Verified 20 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments on confidentiality and on the use of customer content, failing the limb R33 makes decisive. The commitments are real and, unusually for a record of this kind, they sit in an instrument that expressly covers the products rather than only the website. The privacy policy defines Customer Data as the data input during use of the products, acknowledges it may contain personal or sensitive personal information about the customer's own clients, states that it is processed only at the customer's direction, and commits that the vendor does not use it other than to provide the products. That is a purpose limitation on client material and it is graded on the training signal as well as recorded here. Around it: a certified information security management system, access to personal information recorded and controlled, contractors and sub-contractors held to the same administrative, physical and technical standards, and certification to ISO 27701, which is the privacy information management standard rather than a general security one. The limb that fails is privilege and work product, and it fails completely: neither privilege, professional secrecy nor legal confidentiality is addressed on any surface read, on a platform that holds timecard narratives describing what lawyers did on named matters. Two further gaps: no retention period is published for customer data, and nothing describes segregation between matters or between clients within a firm's tenant. Verified 12 September 2026.
This product takes in every document that reaches a firm, medical records, liens, pleadings, demand letters and client correspondence, and nothing published says what happens to them. There is no customer agreement on the estate: the Terms and Conditions govern the website and the Privacy Policy covers website visitors and their contact details by its own terms. No statement was located on whether firm documents train or improve the models, how long they are held, whether they are segregated between firms, or what happens to them when a customer leaves. The one adjacent claim, made in a feature block on a case study page, is that the company is SOC 2 Type 2 certified and HIPAA compliant. Checked the homepage, the platform page, the Filevine integration page, a full case study, the terms and the privacy policy on 20 September 2026. Verified 20 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
Nothing published on professional responsibility was located, and R15 requires naming which limbs bite before the grade is read as heavier than it is. The advice-line limb barely applies. This is operational and financial software for law firm business services: workflow routing, resource allocation, dictation, document production, metadata cleansing, billing review and management reporting. Nothing it produces is advice to a client, and the audience is unambiguous, being the firm's support, finance, pricing and operations functions. What is absent, and what the grade records, is any statement connecting the output to the obligations of the lawyers whose names sit on the work. Two places where it would bite are named rather than passed over. Impact Analytics re-encodes the narrative of a time entry, and a time entry narrative is a representation to a client about work performed which a lawyer certifies when the bill goes out. PrebillManager surfaces issues in time recording, narratives and rates before invoices reach clients, which is the same territory approached from the other side. Nothing published addresses whether a lawyer must review a machine-altered narrative before it is billed, and no disclaimer of any kind appears on any surface read. There is no published customer agreement in which such a position might otherwise sit; the only terms published are website terms of use. Verified 12 September 2026.
Nothing published addresses the professional dimension of the work. The product makes decisions that bear directly on a lawyer's duties, classifying a pleading, matching a document to a matter, deciding who is alerted to a time-sensitive notice, and the estate frames the risk in operational terms, missed deadlines, misfiled documents and missed liens, without ever addressing supervision, competence or what the firm remains responsible for. There is no statement that the output is not legal advice, no description of what a reviewer is expected to check, and no guidance on the firm's responsibility when a document is routed to the wrong person. Checked the homepage, the platform page, the Filevine integration page, a full case study, the terms and the privacy policy on 20 September 2026. Verified 20 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Nothing published on AI governance was located, which is the D band, and on this vendor the bias half of the axis is the sharper omission. No responsible AI principles page, no AI policy, no acceptable use position, no accountable owner, no statement about how models are built, evaluated or monitored, and no disclosure of any testing or its results appears anywhere on the surfaces read. The bias gap is not theoretical and is stated plainly because the product is built around it. BigHand Impact Analytics is marketed on its ability to surface implicit bias in how work is allocated, to identify quantitative and qualitative diversity data for every activity within a matter, to award career scores, and to support equity partnership pathways, with a published claim of a 14 per cent increase in career-advancing work attributable to diverse attorneys. That is a machine learning system whose output feeds decisions about which lawyers get which work and who advances. Nothing published addresses whether the model that re-codes and classifies that activity is itself even across the people being classified, what it was trained on, or how a firm would audit it. A vendor selling bias detection publishes nothing about bias in the detector. One adjacent statement is recorded and not credited: the privacy policy states the vendor does not use personal information to profile individuals, which governs the vendor's own conduct rather than the product's. Verified 12 September 2026.
The approach is published in detail and the governance around it is not. The platform page explains how model behaviour is controlled, several analytical routes reconciled against each other, deterministic guardrails, jurisdiction-specific taxonomies, calibrated confidence thresholds and human validation of low-confidence results, which is more architectural transparency than most vendors offer. Nobody is named as accountable for model behaviour, nothing describes what is tested before a model or taxonomy change ships, no evaluation results are published, and nothing addresses whether accuracy falls unevenly across document types, practice areas, languages or handwriting quality. Verified 20 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy covering most of the ground, missing the named subprocessor list and a stated incident practice, which is the B band and its two named examples. What is published is a genuine assurance programme rather than a paragraph. A formal information security management system is stated to be formally managed, controlled, independently audited and certified to ISO 27001 and Cyber Essentials Plus. Compliance is claimed against an unusually specific set for a legal vendor: GDPR with an ICO registration number published, HIPAA, DCB0129 for NHS clinical risk management, and the Data Security and Protection Toolkit, which together indicate the estate handles health data as well as legal. Controls listed include trained personnel, physical security at facilities, network and technical protection, access to personal information recorded and controlled, systems and practices audited and reviewed, and contractors and service providers held to the same administrative, physical and technical standards. Use of customer data is purpose-limited to providing the products. What is missing is the two things the band names. No subprocessor is identified: the policy lists categories only, service providers providing technology and infrastructure support, professional advisors and group members, without naming any. And no incident notification commitment to customers was located, no breach notification window and no incident response description. Retention is stated without a period. Verified 12 September 2026.
Nothing published covers the handling of the documents the platform processes. No retention period, no deletion commitment, no encryption statement, no access control description, no subprocessor list and no incident practice was located; there is no security or trust page on the estate, and the privacy policy addresses website visitors, saying only that reasonable administrative, physical and technical controls are adopted and that the company is GDPR compliant. The certification claim on a case study page is the closest thing to a statement. Checked the homepage, the platform page, the Filevine integration page, a full case study, the terms and the privacy policy on 20 September 2026. Verified 20 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Nothing published on who bears the loss when the system is wrong was located, which is the D band. There is no customer agreement on the estate. The footer's legal inventory is a trust centre link, a modern slavery statement, a cookie policy, a privacy policy and a page headed Terms, and that last document is website terms of use rather than a software licence. This is worth stating precisely because the page presents itself otherwise: its own meta description offers terms of use for the website and software including limitations of liability, and the body delivers only website terms, covering intellectual property in the site, trade marks, linking, viruses and a disclaimer of accuracy for site content. It contains no warranty for the products, no service level, no liability cap, no indemnity and no data terms, and its liability provisions are expressly about use of the website. So a buyer evaluating a platform that re-codes its billing data, routes its work and generates its management reporting cannot read, before entering a sales process, what the vendor stands behind. Nothing on insurance was located. The exposure is concrete: a mis-coded time entry reaches a client's invoice, and a mis-routed email reaches the wrong recipient, both of which this estate's own products exist to prevent. Verified 12 September 2026.
Nothing published says who bears the loss when a document is misfiled or an alert never fires. The Terms and Conditions cover the website: they disclaim warranties, exclude consequential damages, cap liability at whatever the user paid to access the site, and require the user to indemnify Foundation AI. No customer agreement, service level commitment, accuracy warranty or indemnity for the product was located, which leaves the risk the vendor's own marketing names, missed deadlines and missed liens, allocated nowhere on the published record. Checked the terms, the privacy policy, the homepage, the platform page and a full case study on 20 September 2026. Verified 20 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integrations are claimed and the host applications are named, without a documented catalogue or any configuration detail, which is the C band. What is published sits mostly inside the packaging tables rather than on an integrations page, because no integrations page exists in the navigation, which is itself a page-inventory finding. From those tables: Microsoft Word integration and document management system integration in Document Creation; Microsoft Office and DMS integration in Metadata Management; CRM and DMS integration plus marketing document automation across Word, PowerPoint and Excel in Pitching and Proposals; export to Microsoft Excel in Matter Pricing; and integration between Document Creation and BigHand Workflow or Dictation as a purchasable add-on. Two extensibility items are named as add-ons in Workflow Management, an SDK and a Service Provider Gateway, and an Outsource Module. So a buyer learns that the products live inside Microsoft Office and connect to document and client relationship systems. What is absent is everything the higher bands ask for. Not one document management or CRM product is named, so a firm cannot tell whether its own system is supported; no direction of flow is described for any connection; no configuration or prerequisite is stated; and no public API reference, developer portal or connector register was located, the SDK appearing as a line item on a pricing table rather than as documentation. Verified 12 September 2026.
Integration is the point of the product and it is documented per system. CASEpeer, Clio, Filevine, Litify, SmartAdvocate and Smokeball each have their own page; the Filevine page describes what actually moves, matching documents against parties, case numbers, claim numbers and dates held in Filevine, filing into matter folders, alerting the people the firm nominates, and writing extracted fields such as parties, senders, treating providers and dates back into Filevine to drive calendaring. Elsewhere the platform tags the originating message in Outlook or Gmail, matches Salesforce objects and Filevine collections, and feeds Domo and Power BI. What is missing is the engineering detail: no API or developer reference, nothing on authentication, sync direction or failure handling, and no named certification in any partner marketplace. Verified 20 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery is implied rather than described and neither the tenancy model nor the region is published, which is the C band. Delivery is not seriously in doubt: products are named as cloud offerings, Matter Pricing Cloud appears by that name in the vendor's own acquisition announcement, and the estate is sold as subscription software with a customer support portal and a login. But nothing states where any of it runs. No data centre, country, region or cloud provider is named on any surface read. No residency option is offered or refused, which is a live question for a vendor operating three regional estates in the United Kingdom, the United States and Asia-Pacific and reporting clients in all three. No tenancy model is described, so a buyer cannot learn whether a firm's data sits in a shared or isolated environment, and nothing distinguishes storage from processing. The closest thing to a residency statement is a single line in the privacy policy of the United States entity, that personal information will only be transferred outside North America for the purposes described elsewhere in that policy, which implies North American processing for North American customers without stating it as a commitment or addressing the other two regions. On-premises deployment is not addressed either way, which matters because several products in this estate, including metadata management installed across more than 800 sites, have historically been desktop-installed. Verified 12 September 2026.
Nothing published states how or where the platform runs. No hosting provider, region, tenancy model or residency option appears anywhere, and the only deployment language found is a claim on a case study page that the software integrates with existing hardware and core systems. For a platform that ingests a firm's entire inbound document stream, including medical records, a buyer has nothing to evaluate. Checked the homepage, the platform page, the Filevine integration page, a full case study, the terms and the privacy policy on 20 September 2026. Verified 20 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real, current and named across an unusually wide set, and the evidence behind it could not be reached, which is the B band. The claims are specific and appear in two places. The trust centre states a certified information security and privacy management system audited to ISO 27001, ISO 27701, SOC 2 Type 2 and Cyber Essentials, and publishes an Information Commissioner's Office registration number, which is a verifiable regulator record rather than a self-assertion. The privacy policy adds Cyber Essentials Plus, HIPAA, DCB0129 for NHS clinical risk management and the Data Security and Protection Toolkit. The footer badges carry a further standard, ISO 14001 for environmental management certified by BSI, and, more usefully for this axis, they name the auditor for the information security certifications as A-LIGN, which is a limb most records in this corpus never supply. What is missing is the evidence itself. The trust centre is Vanta-hosted and returned page metadata with no body to this index's fetcher on the date shown, which is a documented persistent limit of this instrument rather than a fault of the site, so the access flow could not be graded under R5 and the lower tier is taken with the reason stated. No report period, observation window, certificate number or issue date was located on any readable surface, and nothing indicates whether the SOC 2 report is downloadable, gated behind a click-through, or released only after a sales conversation. Verified 12 September 2026.
The certification is claimed, and only just. A footer badge links to the AICPA's general SOC page on every page of the site, and a feature block on a case study page states that Foundation AI is SOC 2 Type 2 certified and HIPAA compliant. There is no security page, no trust centre, no auditor named, no report period or scope, and no route to request the report; the HIPAA claim, which matters for a product handling medical records in injury and workers' compensation matters, appears only in that one block. Checked the homepage, the platform page, the integration page, a full case study, the terms and the privacy policy on 20 September 2026. Verified 20 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Nothing published about the models was located, which is the D band, and the silence is complete rather than partial. Across every surface read the AI is described only by what it does: AI-enabled timecard analysis, machine learning used to analyse and re-encode timecard information, AI Email Routing, and AI used to turn unstructured timecard data into pricing accuracy. No model is named, no version is given, no provider is identified, nothing states whether the models are built in-house or licensed, nothing says where inference runs, and no commitment to notify customers of a change was located. There is no subprocessor list anywhere that would answer the question by another route, the privacy policy naming only categories of recipient. So a buyer cannot establish whether its timecard narratives, which describe work done on named client matters, are processed by a model the vendor built or by a third-party service. One adjacent fact is recorded and expressly not credited, because it is a future capability rather than a current disclosure: the acquired Ayora technology is described in third-party coverage as using large language models, and the vendor's own material places its integration in the future, so it discloses nothing about what processes customer data today. Verified 12 September 2026.
The architecture is described and the models are anonymous. The platform page names the components, fine-tuned large language models, retrieval, vector search, custom models, deterministic guardrails and proprietary methods, which tells a buyer more about the shape of the system than most vendors do, while identifying no model, version or provider and saying nothing about where inference runs. The vendor's argument that general-purpose models fail in production implies models of its own, and no commitment to notify customers when they change was located. Verified 20 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Some pricing information is published but not enough to plan, specifically a tier list without figures, which is the C band. The estate carries a dedicated Pricing and Packaging page and it is more substantial than the label on most such pages: seven product families are broken into named tiers with feature matrices setting out what each tier includes. Workflow Management runs Standard, Plus and Advanced across fourteen features with four named optional add-ons including speech recognition, an outsource module, a service provider gateway and an SDK. Resource Management runs two tiers across sixteen features. Document Creation runs three tiers, Metadata Management two, Matter Pricing three, Business Intelligence three, and Pitching and Proposals a single tier. A buyer can therefore establish exactly what a tier upgrade buys, which is real and gradeable information. What is absent is everything a buyer would need to budget. No figure appears anywhere for any tier, and, more fundamentally, no unit of charge is published: nothing states whether the products are licensed per user, per fee earner, per site, per module or per firm, so a buyer cannot even scale an estimate. Every call to action on the page routes to a Get Pricing form. No term, minimum, uplift provision or renewal mechanic is published, and no agreement is published in which they might appear. Under R17 the pricing evidence lifts this axis off D, so a VendorPricing row is owed and written with no figure. Verified 12 September 2026.
No pricing information is published at any level, including the unit of charge, which matters here because the natural units, documents, pages or mailboxes, would tell a firm a great deal. Checked the homepage, the platform page, the six integration pages linked from it, the customer stories index, a full case study, the about page, the terms and the privacy policy on 20 September 2026: there is no pricing page, no tier, no rate and no trial, and every route ends at a demo booking or a call. Verified 20 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is documented with real substance and evidenced by market penetration, short of the stated limits the A band asks for. Who this is for is unambiguous and demonstrated rather than asserted: law firms, and the published penetration figures are the most precise in this lane, 81 per cent of the AmLaw 200, 82 per cent of the top 200 United Kingdom firms, 96 per cent of the top 50 Asia-Pacific firms, 3,300 firms and more than 810,000 users. The vendor states it serves from the Magic Circle to boutique practices, which addresses the size range at both ends. Geographic reach is evidenced by three regional estates for the United Kingdom, United States and Asia-Pacific rather than claimed. Functional coverage is enumerated product by product across sixteen products in three named groups, and the buyer roles are addressed throughout, being support services, resourcing leads, finance, pricing, billing and partnership management. In-house legal is addressed on a surface of its own, Impact Analytics carrying a dedicated corporate legal page aimed at optimising outside counsel spend. R15 applies to the practice-area limb and the note says so: this is business-of-law infrastructure whose function does not vary by whether the firm does patent litigation or private client. What holds it off A is that no limit is stated. Nothing identifies a firm size floor, no segment is named as out of scope, government use is neither claimed nor excluded, and nothing states which of the sixteen products are available in which of the three regions. Verified 12 September 2026.
The coverage is stated concretely by practice and by document type. The vendor publishes models, taxonomies and workflows for personal injury, workers' compensation, SSDI, VA, property claims, bankruptcy and immigration, and names the document classes it is trained to recognise, correspondence, discovery demands, pleadings, medical reports and event notices, with a separate Claims Operations product for insurers. The customer roster matches the claim, dominated by injury, workers' compensation and insurance defence firms from solo practices to Morgan & Morgan. What is not published is the boundary: no statement of which practice areas, document types or firm sizes the platform handles poorly, and nothing on jurisdictions outside the United States. Verified 20 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Customer content is confined to service provision by a published purpose limitation, and no training prohibition is stated in those words, which is this value. The limitation is express and it sits in an instrument that expressly reaches the products rather than only the website: the privacy policy states that it covers the vendor's website, tools, solutions, products and services including any AI tools it utilizes. Within it, Customer Data is defined as the data input during use of the products, acknowledged as potentially containing personal or sensitive personal information about the customer's own clients, and governed by two statements, that it is processed only at the direction of customers when they upload it, and that the vendor does not use it other than to provide the products to its customers.
That confines use to delivery and would exclude model training as a matter of construction. What it does not do is say so. No sentence anywhere states that customer content is not used to train, refine or improve models, and no separate AI or trust statement was located that does. R43(1) was run: there is no published customer agreement on the estate in which a contractual term could sit, only website terms of use, so the contractual values are unavailable rather than declined.
Two qualifications belong on the record. The same policy reserves broad use and disclosure of Customer Data for a defined set of Business Purposes, and it separately notes collection of non-personal derived information including usage information and aggregate statistics to develop and support the products.
No position either way was located. There is no customer agreement on the estate; the Terms and Conditions govern the website and the Privacy Policy covers website visitors. The platform description says the models are fine-tuned and that the system learns from validation, without saying whose documents that learning uses. Checked the homepage, the platform page, the Filevine integration page, a full case study, the terms and the privacy policy on 20 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is addressed and no period is stated, which is this value. The privacy policy has a retention section and it does three things: commits to keeping personal information only as long as necessary for the purposes described, notes that certain information must be kept for certain periods to meet legal and regulatory obligations, and states that the vendor minimizes what it retains and de-identifies it. It then puts the specifics behind a request, inviting the reader to ask about the periods by contacting the data protection manager.
That is a real position without a number, which is the distinction this value draws. Nothing narrows it for the AI. No separate window is published for the material this signal is about, and on this product that material is unusual and worth naming: Impact Analytics ingests and re-encodes timecard narratives, so what the model has processed is not a discardable prompt but a modified record inside the firm's own billing history, and nothing states how long the original, the re-coded version or any intermediate working is kept.
Deletion is addressed only as an individual right rather than as a customer-level commitment on termination, and no return or export obligation was located. There is no published customer agreement in which any of this could be pinned down.
Checked the same pages on 20 September 2026. Nothing states how long the platform keeps the documents it processes, the extracted data or the tracking record of every action taken, and no deletion commitment on termination was located. The privacy policy's retention paragraph addresses personal information collected through the website.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Access control is claimed and no permission model is described, which is this value. The claim appears in the privacy policy's security section as one of six assurances, that access to personal information is recorded and controlled, alongside trained personnel, physical security, network protection, audit and review, and contractors held to the same standards. Product-level fragments appear in the packaging tables rather than in any documentation: Resource Management lists role assignment, user reporting and candidate shortlists, Workflow Management lists workflow administration, and Metadata Management lists self-service administration.
None of that describes a permission model. Nothing published sets out roles, groups, or how a firm restricts who sees what, and there is no security or administration documentation on the estate in which it might sit; the trust center that would ordinarily carry it returned no readable body. The question has a specific edge on this product and it is recorded rather than left implicit. Timecard narratives describe work done on named client matters, and Impact Analytics aggregates them into firm-wide dashboards on cost, staffing and diversity.
Nothing published states whether those dashboards respect matter-level or client-level confidentiality restrictions, or whether a partner viewing a diversity dashboard can see activity on matters they are walled off from.
The platform routes documents by role and matches them to matters, contacts, providers and staff roles, so it plainly holds a view of who should see what, but nothing published describes a permission model, whether it inherits the practice management system's access controls, or how a matter walled off inside a firm is kept out of the wrong queue.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Compelled disclosure is addressed squarely and customer notice is absent, which is this value. The privacy policy reserves the right to use or disclose any Customer Data, expressly including personal information, as needed to comply with any law, regulation or legal request, to protect the integrity of the products, to cooperate in any law enforcement investigation or an investigation on a public safety matter, to protect or defend the legal rights or property of the vendor, its group members, its customers or any other party, or in an emergency to protect health and safety.
Those are grouped and defined as Business Purposes. The reservation is unusually broad on two counts worth naming: it extends to Customer Data rather than only to the vendor's own records, and the trigger includes a legal request rather than only a binding order, which is a lower threshold than most records in this corpus set. One mitigation is published and is recorded because it is real: the vendor commits to limit use or disclosure to what is necessary for the objective, including de-identifying or anonymizing the customer data as practicable.
What appears nowhere is notice. Nothing states that the customer would be told a demand had been received, given an opportunity to object or to seek a protective order, or informed afterwards. No transparency report was located.
Nothing addresses what happens if a customer's documents are subpoenaed from Foundation AI. The only disclosure clause located sits in the website terms and concerns material submitted through the site, which the vendor may disclose to comply with legal obligations or governmental requests, without notice or attribution; it does not reach the documents the platform processes for a firm.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies any source corpus, and R15 governs the weight, so the note states the position rather than leaving it to inference. This product answers from no body of law. The AI reads the customer's own timecard data and routes the customer's own email, so there is no legal corpus whose provenance or licensing this signal would ordinarily test and the vendor is not withholding something its product class implies.
What is genuinely unaddressed, and why the value is recorded rather than treated as inapplicable, is the training material behind the models. Nothing states what the timecard classifier was trained on. The question is not academic on this product: a model that re-encodes narrative time entries into phase and task codes has to have learned that mapping from somewhere, and the obvious candidate is timecard data from other law firms.
Nothing published says whether the models were trained on customer data, on synthetic or licensed data, or on an industry corpus, and nothing states whether one firm's coded history informs the model another firm uses. The purpose limitation graded on the training row points against pooling but does not answer the provenance question. The surfaces read on the date shown were the Impact Analytics product pages, the home page, the packaging page, the privacy policy, the terms and the trust center metadata.
Checked the homepage, the platform page, the Filevine integration page and a full case study on 20 September 2026. The platform works on the customer's own inbound documents against the vendor's jurisdiction-specific taxonomies; no external legal corpus is involved, and the taxonomies' sourcing is described only as seven years of document operations practice.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history, and on this product the question does not arise. Nothing in the estate cites law. The sixteen products cover workflow routing, resource forecasting, dictation, document production and formatting, metadata cleansing, redaction, pitching, business intelligence, matter pricing, budgeting, partner performance, prebill review and alerting, and none produces a proposition about the state of the law whose treatment a lawyer would verify.
R15 governs and the limb is recorded as inapplicable rather than failed. One adjacency is named so it is not mistaken for the thing: Document Creation maintains template and clause bank automation, so the currency of a firm's own precedent library is a real question on this estate, but that is the customer's content management rather than the vendor checking legal authority, and nothing published describes any staleness mechanism for it either.
The surfaces read on the date shown were the home page with the full solution navigation, the packaging page setting out every product's feature set, the Impact Analytics pages, the privacy policy and the terms.
Checked the same pages on 20 September 2026. The product classifies and files documents rather than citing legal authority, so no subsequent-history check arises and none is described.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
No located public material describes what the system does when it cannot produce a reliable answer. The surfaces where it would appear were read on the date shown: the home page, the Impact Analytics product and corporate pages, the packaging tables, the Workflow Management spring release notice, the privacy policy and the terms. None states that any AI feature declines, flags low confidence, marks an uncertain classification for review, or escalates an ambiguous input to a person.
The published account is uniformly confident, describing AI that converts complex, inconsistent and often dirty billing data into reliable insight, and email routing that sends work to the right resource. The gap matters more here than the product class might suggest, and the note says why. A timecard classifier working on inconsistent narratives will encounter entries it cannot code with confidence, and what it does then determines whether a firm's billing data is improved or quietly corrupted: an entry coded wrongly and silently is worse than one flagged as unclassifiable.
Nothing published indicates which way the system errs, whether a confidence score attaches to a re-coded entry, or whether low-confidence codings are surfaced for human review before they enter the billing record.
The abstention path is described plainly and it is the center of the product's design. Every match, classification and extraction is scored against calibrated confidence thresholds; confident results pass straight through and the rest are held, with the uncertainty highlighted in the review interface for a person to resolve. On matter matching the vendor states that when confidence is low the system does not guess, and instead surfaces the most likely matches for the team to confirm. What would lift this further is a published evaluation or an observable demonstration of that behavior.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
Searched on 12 September 2026, on the company name and on the AI product name, against published trackers and coverage of decisions on AI-generated fabricated citations, including coverage of the Damien Charlotin AI Hallucination Cases database and reporting on the 2025 and 2026 sanctions decisions in the United States federal and state courts. None located. Under R119 this signal records fabricated citations and nothing else, so it is not a litigation history and no other proceeding involving the vendor would appear here.
One point of context is recorded because it bears on how the absence should be read: the exposure this signal tracks arises where a product generates legal authority for filing, and nothing in this estate does. The analogous failure for this vendor would be a mis-coded or machine-altered time entry narrative reaching a client's invoice, which no tracker records and which would surface, if at all, as a billing dispute or a client audit rather than as a sanctions order.
Searched the AI Hallucination Cases database maintained by Damien Charlotin on 20 September 2026 on the name Foundation AI. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product, which files documents rather than drafting filings.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance, in general terms or otherwise. No bar opinion is cited anywhere on the estate, no professional conduct rule of any jurisdiction is named, and nothing maps a product or an AI feature to the obligations of the lawyers whose work it processes. Nor is professional responsibility engaged generically: there is no requirement that customers use the products consistently with their professional obligations, which is the clause that would ordinarily sit in a customer agreement, and no customer agreement is published.
The regulatory engagement that does exist runs to data and security regimes rather than conduct, the vendor citing GDPR with an ICO registration, HIPAA, the NHS clinical risk management standard DCB0129 and the Data Security and Protection Toolkit. Those bind the vendor as a processor, not the customer as a lawyer. The gap has a specific edge that is recorded rather than passed over. Billing conduct is among the most closely regulated areas of professional responsibility in every jurisdiction this vendor sells into, and this estate re-codes time entry narratives, reviews prebills and prices matters.
Guidance on what a lawyer may do when software alters the description of work billed to a client is exactly the material a firm would want, and none is referenced.
Checked the homepage, the platform page, the Filevine integration page, a full case study, the terms and the privacy policy on 20 September 2026. Nothing engages a lawyer's professional duties. The risks the vendor names, missed deadlines, misfiled documents and missed liens, are framed as operational and financial, and no rule of professional conduct, ethics opinion or bar guidance is mentioned.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Savings claims are published, the product sits inside a lawyer-to-client fee relationship at the closest range in this corpus, and nothing addresses billing disclosure, which is this value. The savings claims are quantified and published throughout: 81 hours saved per fee earner per year, four hours per user per week, around three weeks from time entry to bill, a 28 percent reduction in the billing and collections lifecycle, a 23 percent average reduction in write-offs and a 20 percent increase in realization.
The proximity to the bill is the point. Impact Analytics uses machine learning to re-encode the narrative and coding of time entries; PrebillManager surfaces issues in time recording, narratives and rates before invoices reach clients; Matter Pricing sets what the client is quoted. So a model touches the description of work that a client is charged for. Nothing published addresses the consequence. No per-matter record of AI-assisted work is described, nothing states that a re-coded entry is identified as machine-altered in the firm's records or on the invoice, and no guidance on fee or disclosure treatment appears anywhere.
R124(1) governs the temptation to grade this higher: a pipeline that touches time entries is not by itself a record of AI-assisted work, and attribution rather than capture is the limb. The commercial framing points the other way, toward realization and recovery rather than disclosure.
The published case is about the firm's own economics rather than the client's bill: an 81 percent reduction in non-billable hours, staff redeployed to billable work, and a partner quoted on reducing non-billable hours while increasing billable ones. The work the platform replaces is overhead a firm generally cannot bill, and nothing published addresses whether the platform cost is passed through to clients as a case expense.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
None of the three artifacts this signal looks for was located, which is the floor, and the note distinguishes what is absent from what could not be read. No subprocessor list exists on any readable surface: the privacy policy names categories only, service providers providing technology and infrastructure support, professional advisors and group members, and no individual processor is identified anywhere. No model provider statement exists at all, the AI being described only by function, so a firm asked which third party processes its timecard narratives could not answer.
No forwardable client-facing disclosure pack was located, and no data processing addendum is published. The distinction worth recording is that a trust center exists at a published address and returned page metadata with no body to this index's fetcher, which is a documented persistent limit of that platform rather than a fault of the site; its own description mentions security and privacy certifications and ESG policies rather than subprocessor or model disclosure, but the underlying documents could not be inspected and it is named here as what would move this row.
The value is not on-request, because nothing indicates that an OCG-shaped pack exists behind any request process; it is recorded as unaddressed on the readable estate.
Checked the homepage, the platform page, the Filevine integration page, a full case study, the terms and the privacy policy on 20 September 2026. No subprocessor list, model provider list or client-facing disclosure material was located, and there is no trust page or request route, so a firm asked by an insurer client what technology reads its claim documents would have nothing published to hand over.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located public material addresses disclosure of AI involvement in legal work, and on this product the relevant forum is a client or a fee assessor rather than a court, which the note states rather than forcing the signal. Nothing this estate produces is filed. The AI re-encodes timecard data and routes email, and the wider suite produces internal management reporting, documents and invoices, so the certification regimes now attaching to court filings in several jurisdictions do not reach this output.
Within the narrower frame the position is a complete absence. Nothing identifies a time entry whose narrative or coding a model altered, nothing distinguishes an original entry from a re-coded one in any published description, no audit or provenance trail for the AI's changes is described, and no export, template or certification designed to evidence machine involvement was located. The realistic route to a tribunal is indirect and specific, and it is recorded because it is the version of this question that actually bites here: a bill assessed by a court or a client's audit turns on what the timekeeper recorded, and if a model rewrote that narrative, nothing published would let the firm establish afterwards which words were the lawyer's own.
A real processing record exists, built for firm oversight rather than for a court. The platform tracks each document and every action taken within it, from capture, matching, classification and validation through filing, routing, task creation and delivery, with per-field confidence scores, built-in dashboards, custom reports and feeds into Domo and Power BI. What is not recorded is which model produced a determination, so the record shows what happened and who confirmed it rather than what the AI did.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- UPL and Professional Responsibility Posture
- AI Liability and Recourse
- Primary Law Corpus Provenance
- Good Law Verification
- Bar Guidance Alignment
- Outside Counsel Guideline Readiness
Which one fits
Choose BigHand if
- You need to route support work and see demand, capacity and cost. BigHand Workflow Management routes tasks to the right resource, added AI email routing in 2026, and comes in Standard, Plus and Advanced tiers with published feature lists for each.
- Your security review wants privacy certification as well as security. BigHand names ISO 27001, ISO 27701 and SOC 2 Type 2 with A-LIGN as auditor, Cyber Essentials Plus and an ICO registration number, and its privacy policy states that customer data is used only to provide the products.
- You want inconsistent timecards turned into pricing data. BigHand Impact Analytics uses machine learning to convert time entry narratives into structured phase and task data for pricing, staffing and billing quality, and BigHand reports 81 percent of the AmLaw 200 among its customers.
Choose Foundation AI if
- Your firm receives thousands of documents by post, fax, portal and email. Foundation AI captures each one, reads it, matches it to a matter, names and files it to your convention, and routes and tasks it, tracking every step.
- You want uncertain results sent to a person rather than guessed. Foundation AI scores every field against calibrated confidence thresholds, passes confident results straight through, and holds the rest in a review screen with the uncertainty highlighted.
- You run a personal injury, workers' compensation or disability practice on a common case system. Foundation AI publishes integrations for CASEpeer, Clio, Filevine, Litify, SmartAdvocate and Smokeball, and names firms with results, including Acumen Law cutting about 120 hours a week of document work to roughly five.
In summary
BigHand
BigHand, from BigHand Limited of London with BigHand Inc in Chicago, sells operational and financial software to law firms across sixteen products: workflow management and task routing, resource management, dictation and speech recognition, document creation, metadata management, business intelligence, matter pricing, budgeting and prebill review. Its AI sits in Impact Analytics, which turns timecard narratives into structured phase and task data, and in AI email routing. The AI Legal Index grades it in the top two bands on five of fifteen capability axes. It reports 81 percent of the AmLaw 200 as customers and names ISO 27001, ISO 27701 and SOC 2 Type 2. As of 12 September 2026 the index located no customer agreement, named model or price figure.
Foundation AI
Foundation AI, from Foundation Inc. of Irvine, California, runs the document operations of high volume law firms: everything arriving by post, fax, portal or email is captured, read, matched to a matter, named, filed, routed and tasked, with every step tracked, and extracted data drives calendaring and damages records. Its customers are mostly personal injury, workers' compensation, disability and insurance defense firms. The AI Legal Index grades it in the top two bands on six of fifteen capability axes, with A grades on AI centrality, autonomy and oversight, and outcome evidence. It publishes per field confidence scoring with escalation to a reviewer. As of 20 September 2026 the index located no customer agreement, data handling terms, named model or price.
Questions buyers ask
Are BigHand and Foundation AI the same kind of product?
No. BigHand sells workflow, resourcing, document and financial software mostly to large law firms, with AI in timecard analytics and email routing. Foundation AI processes the whole inbound document stream of high volume injury and claims firms. On the AI Legal Index Foundation AI sits in the top two bands on six of fifteen capability axes and BigHand on five of fifteen.
How does Foundation AI handle documents it is unsure about?
It scores every classification, match and extracted field against calibrated confidence thresholds. Confident results pass straight through, and the rest are held in a review interface with the uncertainty highlighted. On matter matching the vendor states that when confidence is low it does not guess, and offers the most likely matches for a person to confirm. No accuracy rate or test set is published. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Does BigHand use customer data to train its AI?
BigHand's privacy policy, which covers its products and AI tools, states that customer data is processed only at the customer's direction and not used other than to provide the products. That confines use without stating in words that no training occurs. Foundation AI publishes no position either way, and says its fine tuned models learn from validation without saying whose documents that uses. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What does BigHand publish about security?
BigHand names ISO 27001, ISO 27701, SOC 2 Type 2 and Cyber Essentials Plus, with A-LIGN as auditor, publishes an ICO registration number, and claims HIPAA and NHS data security compliance. Its trust center could not be read by this index, so no report period or access route is established. Foundation AI claims SOC 2 Type 2 and HIPAA compliance on one case study page. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What do BigHand and Foundation AI both leave unpublished?
The contract and the model. Neither publishes a customer agreement, so neither states a warranty, liability cap or indemnity for its products, and neither names the model or provider behind its AI. Neither states where data is hosted, publishes a price figure, or addresses a lawyer's supervision duties over AI that files documents or recodes time entries. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Three readings to weigh. Neither vendor publishes a customer agreement; both publish website terms only, so neither page can state what either stands behind when a document is misfiled or a time entry is miscoded. Foundation AI's SOC 2 Type 2 and HIPAA claims appear on one case study page with no auditor or scope. BigHand's trust center could not be read by this index, so its attestation details rest on its badges and privacy policy. BigHand was verified on 12 September 2026 and Foundation AI on 20 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.