Billables AI vs Brightflag: how they compare in 2026

Billables AI profileBrightflag profile
Last verifiedSeptember 3, 2026

These two sit on opposite sides of the same invoice. Billables AI writes the time entry inside the firm, watching activity across Outlook, Word, Teams, Google Workspace, Zoom and the browser and inferring what was billable, how long it took, which matter it belongs to and how to describe it. Brightflag reads the invoice that results, on behalf of the department paying it, coding every line of every narrative and checking it against that department's own billing guidelines. Putting the seller's tool and the buyer's tool on one grid is the reason for the page, and they land close, with Billables AI in the top two bands on eight of fifteen axes and Brightflag on seven. They get there differently. Billables AI publishes its agreement, including a commitment to store only metadata and the generated records rather than the underlying emails and documents. Brightflag publishes credentials, holding ISO 42001 for AI management alongside SOC 1 and SOC 2 Type 2 across all five trust categories. Neither names the model reading the work.

At a glance

Category
Billables AILegal Ops & Spend
BrightflagLegal Ops & Spend
Founded
Billables AINot published
Brightflag2014
Headquarters
Billables AISan Francisco, California, United States
BrightflagDublin, Ireland
Last verified
Billables AISep 2, 2026
BrightflagAug 29, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Billables AI
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

Every output is a model output and the comparator is explicit. What the product delivers is a set of inferences: deciding which activity in a stream of email, documents, calls and browsing is billable, calculating a duration without any timer input, matching each piece of work to the right client and matter, reconciling overlapping and multitasked activity, and writing a narrative in the timekeeper's own style. The company describes machine learning models adapting to each user's billing preferences and narrative writing style over time. There is no conventional product beneath it and no content asset. The alternative the vendor names is not other software but manual timekeeping, and a customer on its own page draws the sharper line, contrasting the product with timekeeping applications that merely compile time from screenshots. That is the distinction between capturing pixels and understanding work, and only the second requires a model. Verified 2 September 2026.

Brightflag
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

The models are the product and the surrounding platform was built out around them. The core capability is language analysis reading, coding and categorising every line of every invoice narrative, and the vendor's own positioning is that this eliminates the manual configuration and outside firm involvement that conventional e-billing requires. The company was founded on that capability rather than adding it to an existing billing system, and its published framing is that it goes beyond AI invoice review to deliver a governed e-billing platform, which puts the AI first and the workflow second. Distinguished from the enterprise platforms graded B on this axis, where a workflow system predates and stands without the model layer.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Billables AI
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is asserted, disclaimed in the agreement, and measured nowhere. The published figures are business outcomes rather than accuracy measures: more billable time captured and less time spent on billing describe what a firm gains, not how often the system attributes work to the right matter or writes a narrative that survives review. No figure is published for matching accuracy, duration accuracy or narrative quality, and no evaluation, benchmark or test method is described. Three headline statistics on the home page rendered as zero because they are animated counters that did not execute, so even those could not be read; the labels establish that figures exist and the values could not be retrieved, which is recorded as a limit on this reading. Against the marketing, section 6.3 of the terms of service states plainly that the service is designed to generate output, that such output may not always be accurate, and that the customer agrees to evaluate and review it for accuracy and appropriateness before relying on it. That is candid and it is the operative position. Nothing describes how an entry traces back to the underlying activity that produced it. Verified 2 September 2026.

Brightflag
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is real and structurally verifiable, short of published measurement. The method is described concretely: the vendor takes a legal team's own outside counsel billing guidelines and translates them into rules the AI checks each invoice against, so every flag traces to a specific guideline and a specific invoice line the reviewer can open. That is grounding by construction rather than by claim, and the reviewer holds both sides of the comparison. Invoice Summaries and a redesigned review experience are published as making in depth review easier. Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026 and located no accuracy figure, no false positive or false negative rate for flagging, no test set, no evaluation methodology and no independent benchmark participation. Third party review material notes AI driven invoice analysis may require manual review in complex cases, which is an unverified customer observation and was not treated as evidence.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Billables AI
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

The review gate is real, named as a design principle, and backed by contract. Under a heading of human-guided automation the vendor states that a user's time reports are visible only to that user, and that any billable record can be edited or deleted before it is exported or shared with anyone else. That is an unusual and meaningful boundary: nothing the system infers about a lawyer's day reaches a billing administrator or a partner until the lawyer releases it. Section 6.3 of the terms turns the expectation into an obligation, requiring the customer to evaluate and review output for accuracy and appropriateness before relying on it, which places the duty in the agreement rather than in marketing. What is missing is the shape of the automation on the other side of that gate. Nothing states what the system decides without any prompt, what confidence or threshold governs whether an activity is classified billable at all, what happens to activity it cannot attribute to a matter, or whether bulk approval is available, which matters because a review step that can be cleared in one click is a different control from one exercised entry by entry. Verified 2 September 2026.

Brightflag
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

A real published commitment with documented control surfaces, short of thresholds. The oversight structure is the product's own architecture: the AI reviews and flags, and a controlled approval process with complete audit trails determines what is actually paid, so a human decision sits between the model's output and any financial consequence. That is a genuine and auditable checkpoint rather than an assertion of human in the loop. Ask Brightflag adds a conversational interface described as accessible to every person in the legal department, which widens who interacts with the AI. Not located as of 29 Aug 2026: any threshold at which a flag is escalated or auto applied, whether any reduction can be applied without human approval, and what the vendor commits to when a flag is wrong. The last matters commercially here, because a wrong flag reduces a law firm's payment.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Billables AI
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

This is the strongest evidence base in the pull on this axis and it stops just short of the top band. Eight customers speak on the record with name, title and firm, spanning Tycko & Zavareei, Mohan Groble Scolaro, Pulse Law, Zigler Law Group, Finch & Hammer, Kronenberger Rosenfeld, Corporate Law Partners and Acevedo Belt, which is a mix of managing partners, a COO, office administrators and directors of operations rather than a single flattering role. Three attach a figure to a named person: a managing partner reporting at least ten per cent more time captured, a chief executive reporting thirty per cent, and a founding partner stating he recouped his annual investment in two days. Aggregate claims carry a named and dated basis, footnoted to a 2025 pilot programme, and one statistic is labelled by the vendor itself as unsubstantiated, which is a joke that also signals where the line between measured and asserted sits. What holds this below A is method. No baseline is defined for what counts as more time captured, no sample size or firm count is given for the pilot, and the aggregate figures appear inconsistently across the vendor's own surfaces, as 10 to 30 per cent in one listing and 15 to 30 per cent in another. Verified 2 September 2026.

Brightflag
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Segment claims stand where deployment evidence would go. The vendor states its customers range from high growth companies to global enterprises with complex multi jurisdictional operations, and third party material describes immediate return on investment from automated invoice review, which is a vendor claim relayed rather than measured. Searched the vendor site, the FAQ, the press releases and the review platforms on 29 Aug 2026 and located no named customer paired with figures and a date, and no case study with an assessable method. Worth recording as a genuine absence rather than a research gap: the Gartner Peer Insights listing for this product carries no reviews at all, which is unusual for an established platform and means the independent evidence base other records here draw on is not available for this one.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Billables AI
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Four limbs are met and one of them is answered better than by any comparable record. The product watches a lawyer work inside their email, documents and calls, so the obvious fear is that privileged material is being copied to a vendor, and the agreement addresses it head on rather than reassuring around it. Section 1.9 states that Billables AI stores only metadata regarding user activity and the generated billable records, and that it will not store or retain underlying work product such as documents or emails, a commitment the home page repeats as not storing privileged data. Not holding the material at all is the strongest form this limb can take. Section 1.9 also names data isolation and confirms the customer retains full control of Customer Data with the ability to access, delete and manage it, and section 1.6 confines Billables AI's use of Customer Data to what is necessary to provide the service. Section 4 gives mutual confidentiality with a compelled-disclosure notice commitment. Two things keep this off the top band: no model or AI provider is named anywhere, so a firm cannot say whose model reads the activity stream, and no retention period is stated for the metadata and generated records that are kept. Verified 2 September 2026.

Brightflag
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

CORRECTED 29 Aug 2026 during the trust portal sweep. Previously graded C because confidentiality rested on certification and general controls with the specific limbs unlocated. The vendor publishes a security page not reached in the original pass, and it is detailed. Published: AES-256 encryption at rest with keys managed in AWS Key Management Service; minimum TLS 1.2 in transit; single sign on via SAML with the identity providers named individually as ADFS, Azure Active Directory, Google, Okta, OneLogin and Ping Identity; SCIM support for user provisioning, permission management and de-provisioning, which matters because de-provisioning is how access actually ends when a lawyer leaves a matter or a firm; OAuth authentication on the API; out of the box user roles and access permissions with a detailed breakdown published in the help centre; optional restriction of access to specified IP ranges; and a continuous vulnerability scanning and patching programme. SOC 1 Type 2 and SOC 2 Type 2 are prepared annually across all five AICPA trust categories including Confidentiality and Privacy, which is broader scope than most records here. A data retention and deletion section is published on the same page, though its content was not captured in this pass. Held at B rather than A because the training question is still unanswered: no statement was located on whether customer content, which here means invoice narratives describing legal work, may be used to train or improve models. Privilege and work product are also not addressed directly.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Billables AI
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

One limb of this axis does not bite and the other bites hard and is unaddressed. The product gives no legal advice and generates no legal work product, so the unauthorised practice question is largely inapplicable and its absence is not held against the record. The professional responsibility question is the opposite: billing judgement is a core duty, and this product's central promise is that firms capture ten to thirty per cent more billable time than their previous methods. That raises the reasonableness of fees directly, together with the question of whether time surfaced by inference from an activity stream was properly billable to that client at all, and whether narratives written by a model accurately describe what the lawyer did. Checked the home page, the terms of service in full, the site footer and the solution pages for timekeepers, managing partners and legal administrators on 2 September 2026: nothing engages any of it. No bar rule, ethics opinion or fee-reasonableness principle is named, and no guidance is offered on reviewing machine-surfaced time before billing it. The closest published language is section 6.3's requirement that the customer review output for appropriateness, which gestures at the question without naming it. Verified 2 September 2026.

Brightflag
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

The audience is corporate rather than lawyer facing in the advisory sense and no position is published. Users are in house legal departments, legal operations and their finance counterparts, and Ask Brightflag is explicitly described as accessible to every person in the legal department, so non lawyers operate the AI by design. The product analyses billing rather than giving legal advice, so the advice line question arises less sharply than for a research or drafting tool. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no published position on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits despite serving customers with complex multi jurisdictional operations where billing rules and professional conduct rules differ.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Billables AI
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

No governance material was located on any surface. Checked the home page, the terms of service in full, the privacy and site terms links, the full footer and the three solution pages on 2 September 2026. There is no responsible AI page, no framework or set of principles, no individual or function named as accountable for model behaviour, no account of what is evaluated before a model change ships, and no certification such as ISO 42001. Nothing anywhere addresses uneven output, which is a live question on this product in a specific way: the system classifies which activity is billable and adapts to each user's patterns, so it plausibly performs differently across practice areas, working styles and roles, and a model that learns from a user's history will reinforce whatever that history contains. Nothing states whether the adaptation is evaluated for drift or for systematic over- or under-capture. The only governance-adjacent statement is the contractual requirement at section 6.3 that the customer review output, which places responsibility rather than describing control. Verified 2 September 2026.

Brightflag
AA on AI Governance and Bias DisclosureGovernance is documented and owned: who inside the vendor is accountable, what is tested before release, and what has been found and disclosed about uneven output across matter types or populations.

Fourth A on this axis, earned on an accredited AI management certification. The vendor states it is certified in ISO/IEC 42001 and describes it correctly as the first globally recognised standard for artificial intelligence management systems, which is the governance artifact this axis asks for: an externally audited management system covering the AI lifecycle rather than a principles page. It sits alongside SOC 1 Type 2, SOC 2 Type 2 and ISO 27001, so the AI standard is one part of a substantial assurance posture rather than a lone badge. Recorded honestly as the thinnest of the four A grades on this axis: searched the vendor site, the FAQ, the press releases and third party material on 29 Aug 2026 and located no certifying body, no certification date, no published scope for what the 42001 certification covers, no named owner of model governance, no pre release testing results, and nothing on uneven output across matter types, firms or practice areas. Compare Definely, which publishes its AI System Register and per system ownership, and Workday, which names its certifier and date. The certification is the artifact here; the evidence around it is not.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Billables AI
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

The security position is in the agreement rather than on a marketing page, which is where it counts, and two of five elements are absent. Section 1.9 commits Billables AI to encryption of all data in transit and at rest, strict access controls, routine audits and vulnerability testing, secure coding practices, continuous monitoring and data isolation, and then goes further than most by limiting what is held at all: only metadata regarding user activity and the generated billable records are stored, with underlying work product such as documents and emails expressly not stored or retained. Data minimisation of that kind is stronger protection than any control applied to data a vendor is holding. The home page adds user opt-ins per connected tool, single sign-on to third-party applications and audited access logs, and section 1.9 confirms customer ability to access, delete and manage its data. What is missing is retention and disclosure: no retention period is stated for the metadata and records that are kept, no subprocessor is named anywhere, and no incident or breach notification practice was located. A trust centre is linked from the home page and could not be reached on this pass, recorded as a retrieval limit rather than an absence. Verified 2 September 2026.

Brightflag
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Substantive published assurance covering most of the ground, weighted toward certification rather than described controls. Published: SOC 2 Type 2 and SOC 1 Type 2, both stated as achieved without exceptions, ISO 27001, ISO 42001, GDPR, CCPA and CPRA compliance, AWS as the hosting partner, and a completed Cloud Security Alliance Consensus Assessment Initiative Questionnaire available on request, which is a substantive standardised control disclosure most vendors here do not offer. Third party material describes encryption and user based access controls. Not located as of 29 Aug 2026: a stated retention period or deletion control for invoices, narratives or model outputs, a named subprocessor list, and an incident or breach notification practice. The SOC 1 scope covering invoice approval, accruals management and financial reporting is a genuine control assurance over the money path and is credited here.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Billables AI
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

A complete allocation is published and readable without a sales conversation, which by itself puts this ahead of most records here. Section 7 caps liability at the greater of fees paid in the preceding twelve months or one thousand dollars, and excludes lost profits, business interruption and other indirect damages. Section 5.2 gives the customer an intellectual property infringement indemnity covering United States and Berne Convention rights, with defined exclusions, and section 5.1 runs the reciprocal obligation. Section 6.1 warrants that the service will perform in all material respects the functions described in the documentation for the whole term, which is a functionality warranty rather than a bare as-is disclaimer. Support and uptime commitments are referenced at section 1.10. Three things hold it below the top band. The consequential damages exclusion at section 7 protects Billables AI only and is not mutual. The sole remedy for breach of warranty at section 6.2 is prompt correction, with no refund, service credit or termination right. And no insurance position is stated, while the uptime service level itself lives in a Service Description that is not published. Verified 2 September 2026.

Brightflag
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer terms of service was located on the surfaces reached. Recorded as a pure absence. The shape is distinctive for this product: the AI's output directly reduces payments to third parties, so a wrong flag has an immediate financial effect on a law firm that is not the vendor's customer and has no contractual relationship with the vendor at all. Nothing published addresses either side of that, and it is a recourse question no other record on this index raises in the same form.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Billables AI
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Integration is the product rather than an add-on, and the named systems are the ones lawyers actually work in. First-party material names Microsoft 365 including Outlook and Teams, Google Workspace, Adobe, Zoom and the Chrome and Edge browsers, covering email, calendar, documents, calls and browsing. The connection model is described rather than merely claimed: the customer selects which daily work tools to connect, described as a two-click setup with custom-built integrations, which means capture scope is opted into tool by tool rather than imposed. The direction of flow is stated for the outbound side too, with entries exported or shared only after the timekeeper releases them. Two gaps keep this below A. No practice management or billing system is named on any first-party page read, which matters more here than on most records because a time entry that cannot reach the billing system is unfinished work; third-party sources name several, and third-party sourcing is not credited. And no connector list, API reference or developer documentation was located, with the integrations page not opened on this pass. Verified 2 September 2026.

Brightflag
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

Integration is claimed at category level without named connectors. The vendor states the platform can be implemented into existing processes with minimal setup, which it attributes to the language analysis removing the need to configure rules manually, and third party material refers to integrations particularly in collaboration and business intelligence. An e-billing platform necessarily exchanges data with accounts payable, enterprise resource planning and law firm billing systems, and handles standard billing formats, but none of that was located as documented on the surfaces reached. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no integrations index page, no named connector, no API documentation, and no statement of which billing format standards are supported. For a product whose data must flow to finance systems, that absence is notable.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Billables AI
DD on Deployment Model and Data ResidencyNothing published on where the software runs or where client data sits.

Nothing published addresses where the platform runs or how customers are separated within it. Checked the home page, the terms of service in full, the full footer and the three solution pages on 2 September 2026. No cloud provider is named, no hosting region or country is stated, no residency option is offered, nothing distinguishes processing location from storage location, and no on-premises or customer-cloud path exists. Section 1.9 names data isolation, which is a separation claim rather than a tenancy model, and no mechanism is described. The gap has particular weight on this product because the platform connects into a firm's email and document systems and processes a continuous stream of activity derived from client work, so a firm with residency obligations, or one whose own outside counsel guidelines specify where client-related data may be processed, has nothing published to assess. A trust centre is linked and could not be reached on this pass, which is recorded as a retrieval limit. Verified 2 September 2026.

Brightflag
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Cloud delivery and the hosting partner are stated and residency is not addressed. AWS is named as the hosting partner, which the vendor frames as providing security and performance. Searched the vendor site, the FAQ, the press releases and third party material on 29 Aug 2026 and located no named regions, no customer selectable residency, no tenancy model, and no statement of where processing happens as distinct from where data is stored. The absence is more consequential than for most records here: the vendor is headquartered in Ireland, sells to enterprises with complex multi jurisdictional operations, and states GDPR compliance, so where invoice narratives describing legal work are processed and stored is a question its own customer base would be expected to ask.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Billables AI
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

A trust surface exists, is signposted, and could not be read on this pass. The home page carries a security section headed with a statement that the company is serious about security and links to a trust centre on its own subdomain, so the vendor plainly maintains one. That page could not be retrieved: a direct fetch was refused and a targeted search did not surface it, and both failures are recorded as a limit on this reading rather than as an absence on the vendor's part. What can be established from pages that did render is that no certification is named anywhere on them. Neither SOC 2 nor ISO 27001 nor any other standard appears on the home page, in the terms of service or in the footer, no auditor or report period is published, and no penetration testing programme is described beyond the reference at section 1.9 to routine audits and vulnerability testing. The underlying security commitments are unusually concrete for a company of this size and sit in the agreement rather than on a badge page, which is why this is not the bottom band. Verified 2 September 2026.

Brightflag
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

CORRECTED 29 Aug 2026 during the trust portal sweep; grade held at B and the currency finding is now firmer. The vendor's security page, not reached in the original pass, states the certification set and scopes it precisely: externally validated through ISO 27001:2013, SOC 1 and SOC 2, with annual AICPA System and Organization Controls reports prepared across all five trust categories, SOC 1 Type 2 covering controls relevant to financial reporting and SOC 2 Type 2 covering Security, Availability, Processing Integrity, Confidentiality and Privacy. Naming all five categories rather than the usual three is more precise than almost any record on this index. A Cloud Security Alliance CAIQ is available with the reports on request. A separate trust centre exists for the vendor's Workspace product at a stable URL, stating annual audits by an independent CPA firm, first SOC 2 audit in February 2021, and reports available by request through the service portal. Why the grade holds at B rather than rising. The evidence route for the main platform is still a request to the team rather than a self serve portal. No coverage period, report date or auditing firm was located for the main platform. And the currency question is now stronger rather than weaker: the ISO 27001:2013 reference appears on the vendor's own current security page, not only in an FAQ, and that revision was withdrawn and superseded by ISO/IEC 27001:2022, whose transition deadline has passed. A vendor stating a withdrawn revision on its live security page is a finding worth recording plainly, and it remains rebuttable by a current certificate.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Billables AI
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

Nothing identifies what powers the product. Checked the home page, the terms of service in full, the full footer and the three solution pages on 2 September 2026. No model is named, no version, no provider entity, and nothing states whether any component is built in-house or reached through a third party. Nothing describes where inference runs, what any provider may retain, or whether customers would be told if the model set changed. Section 1.7 of the terms refers to methods, techniques or models in the abstract when permitting use of aggregated de-identified usage data, which names the category without identifying anything within it. No subprocessor list exists in the agreement or anywhere else. The absence is consequential here rather than formal: the system reads a lawyer's email subjects, document activity and calendar to infer what work was done, and a firm cannot tell from anything published whether that stream reaches a third-party model provider or stays inside Billables AI's own systems. Verified 2 September 2026.

Brightflag
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No model, provider, hosting location for model processing, or subprocessor was located, and no commitment to notify customers of supply chain changes. AWS is named as the hosting partner for the platform, which is infrastructure rather than a model supply chain disclosure and was not treated as one. The gap covers both layers of this product's AI: the language analysis that codes invoice narratives, whose nature is not described beyond being language analysis technology, and Ask Brightflag, a conversational interface whose underlying model is not identified anywhere located. A buyer cannot determine from published material which company, if any, processes their invoice narratives.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Billables AI
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

The structure is published in the agreement in real detail, no figure is published anywhere, and the agreement points at a page that does not exist. Section 1.1 of the terms establishes the commercial model: fees sit in a Service Description that also sets out use limitations, specified either in a signed Service Order or, for customers without one, in a Service Description the vendor states it publishes at a named plans page on its own site. Section 2.2 sets monthly invoicing or the frequency stated in the Service Description, with late interest at 1.5 per cent per month, and section 3.1 provides automatic renewal with thirty days notice of non-renewal. Section 1.2 offers trials expressly on an as-is basis without indemnification, support or warranty, which is candid about what a pilot does and does not include. The charging unit is per user. That published structure is what lifts this off the floor. The page the contract names returns a 404. This was re-checked on 2 September 2026 and is an established absence rather than a retrieval limit: no first-party figure is published in any currency on any surface, and third-party sources disagree among themselves, variously quoting 39 to 99 dollars per user per month, 25 to 50, custom pricing by firm size, and no public listing at all, which corroborates the absence rather than supplying a number. A contract directing a customer to a fee page that does not resolve is itself a disclosure gap and is recorded as one.

Brightflag
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Checked the vendor site, the FAQ and the press releases on 29 Aug 2026. No pricing page was located, no rate is published, no unit of charge is stated and no tier structure appears on the surfaces reached. Third party sources state pricing is not publicly available and requires a custom quote, structured on subscription and varying with organisation size and the volume of legal spend managed, which confirms the absence and identifies the unit of charge without the vendor publishing it. Worth recording plainly because of what this product is: a platform sold on delivering visibility and transparency into legal spend, which does not publish what it costs. That is not a grading factor beyond the D, but it is the sharpest instance of the pattern on this index.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Billables AI
CC on Firm and Practice CoverageCoverage is claimed broadly, for all firms or all practice areas, without evidence that the breadth is real.

The buyer is segmented clearly and almost nothing else is bounded. Three dedicated solution pages address timekeepers, managing partners and legal administrators, which is a sensible split because each wants something different from the same data, and the named customer roster bears it out with managing partners, chief executives, office administrators and directors of operations all speaking. The buyer type is stated broadly as lawyers, consultants and professional services providers. Beyond that, coverage is undefined. No jurisdiction is named anywhere, which is less consequential for timekeeping than for substantive legal work but still leaves unstated whether the product handles non-English activity or non-US billing conventions. No practice area is mentioned and no firm size band is given, though the named customers are visibly small and mid-sized firms rather than large ones. Nothing states what the product does not cover, including the obvious limit that work performed away from a connected application cannot be captured at all. Verified 2 September 2026.

Brightflag
CC on Firm and Practice CoverageCoverage is claimed broadly, for all firms or all practice areas, without evidence that the breadth is real.

Segment coverage is described in general terms with the detail not reached. The vendor states its customers are corporate legal departments across industries and range from high growth companies to global enterprises with complex multi jurisdictional operations, and identifies the buying roles as in house legal, legal operations and their finance counterparts. Its FAQ begins an enumeration of the industries served but that list was not captured in this pass and is not credited. Practice scope is clear and consistently stated as outside counsel spend, matters, vendors, budgets and reporting, with no claim to advisory or drafting capability. Not located as of 29 Aug 2026: an enumerated industry or practice area list, organisation size segmentation, jurisdictional coverage, and any statement of what the platform is not built for. Flagged as rebuttable in one step by reading the FAQ industry list.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Billables AI
Terms silent

No clause names training on customer content in either direction, so the value is silent, but the surrounding structure is tighter than that word suggests and belongs on the record. Section 1.6 confines the vendor's use of Customer Data to what is necessary to provide the service. Section 1.7 does name models, permitting use of Usage Data in connection with improvements and enhancements to the service and to any methods, techniques or models, but Usage Data is defined as diagnostic, performance and telemetry data in aggregated de-identified form, which by definition excludes the customer's work content. And section 1.9 removes the material a training clause would otherwise reach, committing that only metadata about activity and the generated billable records are stored and giving the quoted commitment about underlying documents and emails. So the agreement names models for telemetry, purpose-limits customer data, and states that the work product itself is not retained at all. What it does not contain is a statement that customer content is or is not used to train, and no policy page supplies one. This is the fifth record in this pull with that shape.

Brightflag
Terms silent

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No located material states whether customer content may be used to train models, either way. Recorded as silent under the rule that a value is never inferred from the absence of a contradiction, and specifically not inferred from the ISO 42001 certification, which evidences that an AI management system exists rather than what its training position is. The question carries unusual weight for this product. The material at issue is invoice narratives describing legal work across many companies and many law firms, and the vendor's own benchmarking and vendor profiling features depend on cross customer comparison, so a buyer would reasonably want to know what is pooled, in what form, and for whose benefit. Nothing located addresses it.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Billables AI
Disclosed without a period

What is retained is stated with unusual precision and how long is not stated at all. Section 1.9 of the terms limits storage to metadata regarding user activity and the generated billable records, and commits that underlying work product such as documents and emails is not stored or retained, so a reader knows the categories held and the categories excluded. The same section confirms the customer retains full control of Customer Data and the ability to access, delete and manage it, which gives a deletion route on demand. Section 1.6 adds that Customer Data may be irretrievably deleted if the account is terminated, which is a warning rather than a commitment and cuts against a customer needing its historical time records after leaving. No period is stated for anything: nothing says how long activity metadata, generated entries or narratives persist during the term, and no retention setting is described as available. A data processing addendum is referred to at section 1.8 as agreed between the parties and is not published.

Brightflag
Not addressed

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No public material states how long invoices, narratives, AI generated flags, summaries or Ask Brightflag conversations are retained, whether a customer controls the window, or whether deletion is available. The platform is a system of record for spend and matter history and its analytics, forecasting and rate benchmarking features depend on multi year retention, so long retention is inherent to the value proposition and no published terms govern it.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Billables AI
Claimed, not documented

Isolation is asserted in the agreement and on the product pages, and no mechanism is described. Section 1.9 of the terms names data isolation among the security practices followed, and the home page states that customer data is isolated and anonymised. Neither says what is isolated from what, whether the boundary runs between customers, between users within a firm, or between matters. One related control is described concretely and is worth recording even though it answers a different question: the vendor states that a user's time reports are visible only to that user until released, which is a per-timekeeper boundary inside the firm rather than a boundary between firms. The matter-level question this signal asks is not reached. The product attributes activity across a lawyer's whole day to different clients and matters, so whether a conflicted matter's activity can surface to a user who should not see it is a live question, and nothing published addresses it.

Brightflag
Own model, documented

CORRECTED 29 Aug 2026 during the trust portal sweep. Previously recorded as not addressed on the finding that no vendor material described segregation and that third party references to access controls were assertions relayed rather than a documented model. The vendor's security page, not reached in the original pass, documents the model. Published: out of the box user roles and access permissions with a detailed breakdown available in the help centre, so the roles are enumerated somewhere a customer can read rather than merely asserted; single sign on via SAML with named identity providers; SCIM support for provisioning, permission management and de-provisioning; OAuth on the API; and optional restriction of access to specified IP ranges. That is the product's own permission model, described at mechanism level. Recorded at own model documented rather than the positive value for two reasons. No material states that the AI layer respects those permissions at query time, which matters because Ask Brightflag is described as a conversational interface accessible to every person in the legal department and the underlying data includes invoice narratives describing sensitive matters. And no document management integration was located whose access model could be inherited. Conflicts and ethical walls are not named as such.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Billables AI
Notice committed

The commitment sits in the operative agreement and has both halves this value requires. Section 4 of the terms permits disclosure of Confidential Information as required by law or court order, and then conditions it on the quoted terms, so the customer is told and the vendor must actively try to narrow what goes out rather than simply complying. The obligation is mutual and survives termination under section 3.4. Two limits belong on the record. The clause protects Confidential Information, which section 4 defines by marking or by what the recipient reasonably should have known was confidential, rather than protecting Customer Data as a defined category, so the fit with a demand for a firm's time records is left to construction. And the notice is prompt rather than advance, so it does not commit to telling the customer before disclosure occurs, which is the difference between an opportunity to intervene and a notification after the fact.

Brightflag
Not addressed

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026, and no published customer agreement or data processing agreement was reached. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. The exposure is worth naming: a structured record of what every outside law firm did on every matter for a company would be an attractive target for a discovery request or regulatory demand, and nothing published addresses what the vendor would do on receiving one.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Billables AI
Not addressed

Checked the home page, the terms of service in full, the full footer and the three solution pages on 2 September 2026. The vendor ships no corpus and none is claimed. The input to the product is the customer's own activity stream drawn from its connected applications, so there is no licensed database, no published collection and no third-party content behind any output, and the provenance risks this signal tracks do not arise in their usual form. The honest record is that the question is not addressed rather than that a corpus was withheld. One adjacent dependency is undescribed: the system must recognise client and matter identifiers to attribute work, which implies it consumes a client and matter list from somewhere, and nothing published states where that comes from or how it is kept current.

Brightflag
Not addressed

No primary law corpus is identified because the product does not hold one, and the relevant provenance question is a different one that is also unanswered. Invoice review runs against the customer's own invoices and their own billing guidelines, so that corpus is theirs. But the vendor also publishes rate benchmarking and AI built vendor profiles applied to panel management and RFPs, and benchmarking necessarily rests on a comparative dataset drawn from somewhere. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no statement of what the benchmarking corpus comprises, whose data it contains, whether it is aggregated or anonymised, or on what basis it was assembled. Recorded as not addressed on that specific question rather than as inapplicable.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Billables AI
Not addressed

Checked the home page, the terms of service in full, the full footer and the three solution pages on 2 September 2026. The product retrieves no legal authority and cites none, so this signal has nothing to operate on and its absence is not a criticism of the record. The nearest analogous question concerns whether the reference data the system attributes work against stays current, since a time entry assigned to a closed matter or a superseded client code is wrong in a way a citator-like check would catch, and nothing published describes any validation of that kind.

Brightflag
Not addressed

Searched the vendor site, the FAQ and the press releases on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is a legal spend and matter management platform whose corpus is invoices and billing guidelines rather than case law, so a citator is outside its design entirely.

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Billables AI
Not addressed

Checked the home page, the terms of service in full, the full footer and the three solution pages on 2 September 2026. Nothing describes what the system does when it cannot determine an answer, and no confidence indicator is described as shown to the user. The questions this raises are concrete on a timekeeping product: nothing states what happens to activity the system cannot attribute to any client or matter, whether such activity is surfaced as unassigned, silently dropped, or guessed at, and nothing states whether an entry the model is unsure about is flagged differently from one it is confident in. The review gate before export is an oversight control rather than an uncertainty signal, since it gives the user the last word without telling them where the system was least sure and therefore where to look hardest.

Brightflag
Not addressed

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No published material describes what the product does when it cannot confidently code a line or assess a narrative against a guideline, and no explicit no answer path or confidence signal exposed to the user was located. Third party review material observes that AI driven invoice analysis may require manual review in complex cases, which suggests some routing to human judgement occurs in practice, but it is an unverified customer observation rather than a published behaviour and was not treated as one. For a product that codes every line of every invoice, how it handles an ambiguous narrative is a live question and is unaddressed.

Fabricated Citation Record

Does a public court record exist involving output from this product?

Billables AI
None located

Searched the AI Hallucination Cases database maintained by Damien Charlotin, and reporting drawing on it, on 2 September 2026 on the product and corporate name Billables AI and Billables Inc. No court order, opinion or disciplinary record naming the product was located, and a separate search for billing or fee disputes involving the product returned nothing. This is a statement about the public record rather than a finding about the product. The signal fits this product class poorly and the reason is worth stating: the platform generates time entries and billing narratives rather than legal citations, so its characteristic failure is an entry attributed to the wrong matter or a narrative describing work inaccurately. That surfaces as a client fee objection, a write-down at pre-bill review, or in the worst case a fee dispute or disciplinary complaint, and none of those is indexed anywhere comparable to a court sanctions tracker.

Brightflag
None located

No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note the product does not generate citations or court facing text at all: its output is invoice flags and spend analysis, so the failure mode this database catalogues does not arise here, and a wrong output would surface as a billing dispute rather than a sanction.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Billables AI
Not addressed

Checked the home page, the terms of service in full, the full footer and the three solution pages for timekeepers, managing partners and legal administrators on 2 September 2026. No public material engages guidance from any professional body. That absence is more pointed here than on most records, because billing is one of the most heavily regulated things a lawyer does and the relevant guidance is long-established rather than new: nothing names the duty to charge a reasonable fee, the guidance on billing for time actually expended, or any state bar opinion on automated or reconstructed timekeeping. Nor is any newer guidance on generative AI cited in connection with machine-written narratives that will be read by a client as the lawyer's own description of their work. The only related published language is the contractual requirement at section 6.3 that the customer review output for accuracy and appropriateness, which allocates the duty without naming what governs it.

Brightflag
Not addressed

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512. The absence is more pointed here than for most records, because the professional rules governing legal billing are directly the subject matter of the product: what a lawyer may bill for, what constitutes a reasonable fee, and how work is described to a client are conduct rules, and this platform automates the assessment of exactly that. It engages with the customer's own outside counsel guidelines, which are contractual instruments, and not with the professional standards that sit behind them.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Billables AI
Savings claims only

This is the record where the signal's premise inverts most sharply, and the inversion is the finding. The signal exists because AI compresses work that was formerly billed by the hour, and asks whether the vendor gives the firm something disclosable when six hours become one. Billables AI runs the other way: its central published claim is that firms capture ten to thirty per cent more billable time than under their previous methods, alongside a ninety per cent reduction in time spent writing narratives. The bill goes up rather than down. What is published is therefore efficiency and revenue claims with no disclosure treatment attached. Nothing addresses whether a client is told that narratives on their invoice were machine-written, whether entries surfaced by inference rather than contemporaneous recording are identified as such, or how a firm should satisfy itself that newly captured time was properly billable to that client. The product generates a per matter record of time, which is not the same as a record of AI-assisted work, and nothing marks which entries the model produced.

Brightflag
Audit record only

Second record on this index to reach a value above savings claims, and the only one where fee assessment is the entire product. The platform generates a per matter and per invoice record of what the AI flagged, what a reviewer approved and what was ultimately paid, held in controlled approval workflows with complete audit trails, so a legal department has a durable account of how each fee decision was reached and on what basis. That is the artifact this signal looks for, produced as the core function rather than as a by product. Two limits keep it short of the positive value and both matter. First, the record concerns the law firm's billed work rather than any AI assisted work performed by the vendor itself. Second, and more consequential for this index: outside counsel guidelines increasingly address whether and how AI assisted work may be billed, and searched the vendor site, the FAQ and the press releases on 29 Aug 2026 without locating any statement that the AI checks for AI related billing entries or supports a guideline term about them. A product that translates billing guidelines into automated checks, in a market where those guidelines are being rewritten around AI, publishes nothing about that.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Billables AI
On request only

The agreement is public and the AI-specific disclosure material is not. What a firm can forward today is genuine: the terms of service are published in full and contain concrete commitments a client can be shown, including the section 1.9 undertaking that underlying documents and emails are not stored or retained, encryption in transit and at rest, data isolation, and the section 4 confidentiality and compelled-disclosure notice provisions. That is more than many vendors expose without an agreement. What is missing is everything specific to the model layer. No subprocessor list exists in any form, no AI or model provider is named anywhere, and the data processing addendum is referred to at section 1.8 as agreed between the parties rather than published. A trust centre is linked from the home page and could not be reached on this pass, recorded as a retrieval limit. A firm asked by a client which third parties process the activity stream drawn from its matters could not answer from anything published and would have to obtain that by request.

Brightflag
On request only

Diligence material exists and reaching it runs through a conversation. The vendor states that security and compliance reports, including a completed Cloud Security Alliance Consensus Assessment Initiative Questionnaire, are available by contacting the team directly, and names SOC 1 Type 2, SOC 2 Type 2, ISO 27001 and ISO 42001 alongside GDPR, CCPA and CPRA compliance. A completed CAIQ is a substantial standardised control disclosure and few vendors on this index offer one. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no subprocessor list, no statement naming which model providers see customer content, no published data processing agreement, and no client facing consent or notification pack. Recorded at on request on the strength of the stated report route.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Billables AI
Not addressed

Checked the home page, the terms of service in full, the full footer and the three solution pages on 2 September 2026. Nothing addresses disclosure of AI involvement, and no record identifying which entries or narratives a model produced is described as available or exportable. The forum here is not usually a court but a fee audit, a client billing guideline review or a fee dispute, and in each the question is the same: which of these entries did a person write and which did a system infer. The platform holds the answer, since every entry originates as a machine-generated draft that the timekeeper may then edit or delete, so the distinction between accepted-as-generated and materially revised exists inside the product. Nothing states that it is captured, retained or exportable, and no audit trail of edits is described. Time records themselves export to billing systems, but that is the work record rather than a record of how it was produced.

Brightflag
Not addressed

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No per document record covering model used, sources retrieved and human verification was located, and no model is identified in published material so the model used could not be stated. Complete audit trails exist over the approval workflow, which record who approved what and when rather than what the AI did and on what basis, and the two were not conflated. Noted for context: this is a spend management platform whose output is invoice flags and financial analysis rather than legal work product, so a judicial AI disclosure order is unlikely to reach it. The nearer analogue would be a fee dispute or a challenge to billing judgements, where the approval audit trail would be the relevant record and does exist.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • Model Supply Chain Disclosure
Signals neither addresses in public material
  • Primary Law Corpus Provenance
  • Good Law Verification
  • Refusal and Uncertainty Behaviour
  • Bar Guidance Alignment
  • Court Disclosure Support

Which one fits

Choose Billables AI if

  • Nobody at the firm is writing time down. Billables AI connects to the applications work happens in, including Microsoft 365 with Outlook, Teams and Word, Google Workspace, Adobe, Zoom and the Chrome and Edge browsers, separates billable work from everything else, calculates a duration without any start and stop input, matches it to the right client and matter, reconciles overlapping activity and writes the narrative, with each tool connected by the customer rather than switched on for them.
  • The lawyer has to see it before anyone else does. The vendor states that a user's time reports are visible only to that user, who can edit or delete any record before it is exported or shared, and section 6.3 of the terms turns the expectation into an obligation by requiring the customer to evaluate and review output for accuracy and appropriateness before relying on it.
  • You do not want your emails sitting on a vendor's servers. Section 1.9 of the agreement commits Billables AI to store only metadata regarding user activity and the generated billable records, and states that it will not store or retain underlying work product such as documents or emails, which is a stronger protection than any control applied to material a vendor is holding.

Choose Brightflag if

  • The invoices arriving are checked against your own rules or not at all. Brightflag reads, codes and categorises every line of every invoice narrative and translates a department's outside counsel billing guidelines into rules the AI applies, so each flag traces to a specific guideline and a specific line a reviewer can open, with a controlled approval workflow and audit trail between a flag and a payment.
  • Your assurance review covers the AI itself. Brightflag holds ISO/IEC 42001 for AI management systems alongside SOC 1 Type 2, SOC 2 Type 2 and ISO 27001, with the SOC reports prepared annually across all five AICPA trust categories, being security, availability, processing integrity, confidentiality and privacy.
  • You want the controls named rather than described. Brightflag publishes AES-256 at rest with keys in AWS Key Management Service, minimum TLS 1.2 in transit, single sign on through six named identity providers, SCIM provisioning so access ends when a person leaves, optional restriction to specified IP ranges, and a Cloud Security Alliance questionnaire available with the reports on request.

In summary

Billables AI

Billables AI records a lawyer's billable time without the lawyer recording it, connecting to Microsoft 365, Google Workspace, Adobe, Zoom and the browser, separating billable work from everything else, calculating durations without timers, matching work to the right client and matter and writing the narrative in that timekeeper's style. The AI Legal Index grades it in the top two bands on eight of fifteen capability axes, with an A on AI centrality. Its agreement commits it to store only metadata and the generated billable records rather than underlying documents and emails, and time reports are visible only to the timekeeper until released. As of 2 September 2026 the index located no named model provider, no accuracy measurement and no published price.

Source: AI Legal Index, 2026

Brightflag

Brightflag is an AI powered enterprise legal management platform for in house legal departments covering spend and e billing, matter management, vendor management and analytics, built around invoice review that reads, codes and categorises every line of every narrative and checks it against the department's own outside counsel billing guidelines. The AI Legal Index grades it in the top two bands on seven of fifteen capability axes, with A grades on AI centrality and AI governance: it holds ISO/IEC 42001 for AI management systems alongside SOC 1 Type 2, SOC 2 Type 2 across all five trust categories and ISO 27001. As of 29 August 2026 the index located no customer agreement, no named model provider, no retention period and no published price.

Source: AI Legal Index, 2026

Questions buyers ask

Are Billables AI and Brightflag alternatives to each other?

No. They sit on opposite sides of the same invoice. Billables AI creates the time entry inside the law firm, inferring what was billable from the lawyer's own activity. Brightflag reads the invoice that results, on behalf of the department paying it, and checks every line against that department's billing guidelines. The comparison is worth reading because the same fifteen axes apply to both, and putting the seller's tool and the buyer's tool on one grid shows what each side of the transaction has published about the machinery. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

What does each actually infer?

Billables AI infers four things from an activity stream: whether a piece of work was billable, how long it took without any timer, which client and matter it belongs to, and how to describe it in a narrative written in that timekeeper's own style. Brightflag infers what a narrative means, coding and categorising every line, then applies the department's own guidelines to it. Both are judgements about the same underlying work, made at different ends of it. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Who sees the output before it goes anywhere?

On Billables AI, only the timekeeper. Time reports are stated to be visible to that user alone, who can edit or delete any record before it is exported or shared with anyone else. On Brightflag, the flag reaches a reviewer inside the legal department, and a controlled approval workflow with an audit trail sits between the AI's finding and any payment decision, so a human decides what is actually paid. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

What does each publish about what it holds?

Billables AI states that it stores only metadata about user activity and the generated billable records, and that underlying work product such as documents and emails is not stored or retained, which is data minimisation written into the agreement. Brightflag publishes its controls rather than its holdings, naming encryption, key management, access provisioning and de provisioning, and states SOC reports across all five trust categories. Neither publishes a retention period for what it does keep. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

What do Billables AI and Brightflag both leave unpublished?

Neither names a model or a provider, so neither says whose system reads a lawyer's activity stream or a firm's invoice narratives. Neither publishes an accuracy measurement for the inference each is sold on: no matching rate, no false positive rate on flagging, no test set on either record. Neither publishes a price a buyer could budget against. And neither engages any bar rule or ethics opinion on billing. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Disclosure

Neither vendor engages the professional rules that govern what may be billed, which is striking for two products built around the billable hour. Billables AI markets capturing between ten and thirty per cent more billable time than a firm's previous method and publishes nothing on fee reasonableness or on how machine surfaced time should be reviewed before it reaches a client. Brightflag publishes no position on the line between tooling and judgement, on a product whose flags reduce what a firm is paid. Two specifics: the Billables AI agreement directs a customer without a signed order to a plans page for its fees, and that page returned a 404 when rechecked on 2 September 2026, so the contract points at a fee page that does not resolve. On Brightflag, no customer agreement, indemnity, cap or warranty was located at all. Billables AI was verified on 2 September 2026 and Brightflag on 29 August 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 2, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746