BlackBoiler vs LexCheck: how they compare in 2026

B
BlackBoiler profile
L
LexCheck profile
Last verifiedSeptember 25, 2026

BlackBoiler and LexCheck make near identical claims: both apply a team's own negotiation positions to incoming contracts and return proposed redlines inside Microsoft Word. BlackBoiler sits in the top two bands on twelve of fifteen axes and LexCheck on eight of fifteen. The gap is about what happens after the redline. BlackBoiler's agreement says its output does not replace review by a qualified lawyer, and it states where it falls short: playbooks may be incomplete, and unusual clauses need a fresh legal decision. LexCheck publishes no statement that its output is not legal advice, and it markets the tools as easy enough for anyone to finish reviews without outside support. BlackBoiler's terms also bar training third party foundation models on customer data without consent; LexCheck's say nothing about training. LexCheck's counterweight is its contract. It names data centers in Northern Virginia and Oregon, commits to breach notice within 24 hours, and leaves its liability uncapped for security failures. It also names customers, including NetApp and RSM, where BlackBoiler names none.

At a glance

Category
BlackBoilerContract Review & Drafting
LexCheckContract Review & Drafting
Founded
BlackBoilerNot published
LexCheckNot published
Headquarters
BlackBoilerBrambleton, Virginia, United States
LexCheckNew York, New York, United States
Last verified
BlackBoilerSep 8, 2026
LexCheckSep 8, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

BlackBoiler
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

Remove the models and nothing remains to sell. The product is an automated contract editing engine: it converts an organisation's prior redlines, approved language and written guidance into executable playbook logic, applies that logic to a new agreement, and returns tracked changes and comments in Microsoft Word. There is no repository, workflow or signature product underneath it that would still function without the models. The June 2026 Veris release adds a generative, conversational layer for playbook building and clause interrogation on top of the patented deterministic editing engine, so the platform now carries both a rules-driven and a generative component and both are the product rather than a layer on it. Eleven US patents are stated to cover document revision, playbook-driven markup and clause handling. Checked 8 September 2026.

LexCheck
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

Remove the models and nothing remains to sell. The vendor states the systems are built on large language models, and the two capabilities that constitute the product both depend on them: automatic capture of a customer's preferred positions from an uploaded template into a working playbook, and evaluation of an incoming contract against those positions to surface deviations and propose redlines. There is no repository, workflow, approval or signature product underneath that would still function if the models were removed; the self-serve platform exists to review and edit the playbook the models generated. Two named products ship: LexCheck Insights, described as AI-powered contract review software that evaluates every contract and catches deviations in seconds, and LexCheck Copilot. The vendor describes its playbooks as LLM-powered and trained on the most common provisions and ready to use across virtually every contract type. Checked 8 September 2026.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

BlackBoiler
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is real, documented and unusually traceable, but no accuracy figure is published. The vendor describes a four-stage chain in its own words: evidence (the customer's prior redlines, approved language and guidance), logic (how those materials become executable rules), checking (a stated judge validator assessing whether a proposed change aligns with the intended outcome, plus statistical similarity checks), and output (tracked edits and comments returned for lawyer review). The earlier ContextAI capability surfaces, for each redline, the playbook rule that prompted it and prior examples of the same edit inside the organisation, which is a provenance trail a reviewer can open for every proposed change. Failure modes are named plainly rather than implied: the vendor states that playbook coverage may be incomplete, that contract language may depart from prior examples, and that unusual provisions may require a lawyer to make a fresh decision. R15 governs the limbs that do not bite: this product cites no legal authority and has no citator, so the primary-authority and citation-status limbs are inapplicable rather than failed, and the grounding limb is read against the customer's own approved language, which is what the output is actually grounded in and which is surfaced to the reviewer. A is unavailable because no measured accuracy figure and no test set are published anywhere. Checked 8 September 2026.

LexCheck
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is asserted repeatedly and measured nowhere, which is the C band's first limb exactly. The claims located are comparative and unquantified: the vendor states its system's AI is highly accurate and that this lowers risk more than human review, and its blog states that accuracy exceeds attorney counterparts while cutting review time by more than ninety per cent. No accuracy figure attributable to a test is published, no test set is described, no method is set out, and no third-party validation is referenced. Failure modes are named nowhere on the estate: nothing states what the system does with contract language outside the playbook, with unusual provisions, or where a position is ambiguous. What does exist, and what keeps this off the floor, is a described rationale surface: the vendor states that insights are transparent and explain why particular contract language is potentially problematic and requires attention, so a reviewer sees a reason attached to each flagged passage rather than an unexplained mark. R15 governs the limbs that do not bite. This product cites no legal authority, retrieves no cases and has no citator, so the primary-authority, citation-status and no-support limbs are inapplicable rather than failed, and grounding is read against the customer's own playbook positions. B is unavailable because the rationale surface is asserted rather than described: no retrieval or matching method is published, so a buyer cannot tell what the explanation is derived from. Checked 8 September 2026.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

BlackBoiler
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a lawyer checks it are all published: modes, thresholds, review surfaces, and the route a matter takes back to human judgment. A categorical limit on a named mode or tier, stating what its output may not be used for, meets the threshold limb without a number.

All four A limbs are published, and the commitment sits in the customer agreement rather than in marketing alone. What the system runs alone: the first-pass markup, producing tracked changes and comments. What constrains it: the customer's approved playbook positions, with rules reviewed and approved by the customer before use. The review surface: Microsoft Word track changes, in the document the reviewer already has open. The route back to human judgement: the reviewer decides what to accept, change, reject, escalate or negotiate, and the vendor states that new risks, exceptions and negotiation decisions are left to the appropriate reviewer. The threshold at which the system stops is structural and stated rather than numeric, which is what most records in this lane leave unstated: nothing is applied to the agreement without the reviewer accepting it, because the output is a proposal in tracked changes. Clause 3(b) of the Access Services Agreement carries the same position contractually, stating that use of the Services is not a substitute for and shall not take the place of review and analysis by a qualified lawyer. Unlike the Case Status record under R37 there is no marketing claim anywhere that the system handles review autonomously, so no contradiction reveals a missing limb. Checked 8 September 2026.

LexCheck
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Oversight is asserted and one real control is described, but nothing addresses oversight of the output, which is where this axis bites. What is published: the customer reviews and finalises the drafted playbook in a self-serve platform before use, can add fallback positions and adjust language, and the vendor frames this as maintaining control and being able to edit the playbook at any time. That is a genuine described control, but it governs the standard rather than the result. Nothing published states whether a lawyer must review the redlines the system proposes, at what point the system acts alone, what happens when it is wrong, or what route a flagged contract takes back to human judgement. No human-in-the-loop commitment appears on any surface, and no such provision appears in the Terms of Service, which were read in full. Two of the vendor's own statements pull against each other and R37 rule 2 governs the treatment: the platform is presented as keeping the customer in control, while the technology page states the AI is highly accurate and lowers risk more than human review, and the marketing states the tools are easy enough for anyone to use so reviews can be completed without the need for external support. The conflict is not graded as such; what it reveals is that the threshold at which the system's output is relied on without legal review is unstated, and that is the limb missing. B requires a written commitment that the models work alongside a supervising lawyer, and no such commitment is published. Checked 8 September 2026.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

BlackBoiler
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

The C band describes this record in its own words: unattributed testimonials and logo-level customer claims stand in for evidence. Four testimonials are published, attributed only to a first name and surname initial or to a verified user, in the shape review-platform content takes, and none carries an organisation or a figure. The customer base is described at category level, as AmLaw 25 law firms and Fortune 1000 organisations with several customers in construction, but no customer is named anywhere on the estate and no case study, deployment figure or before-and-after measurement is published. Awards and research funding were considered and are not counted as deployment evidence: a 2021 AI Breakthrough award, a National Science Foundation SBIR award and Virginia Innovation Partnership Corporation portfolio status are recognition and capital, not evidence of production use. One structural point belongs in the note rather than the grade, because it may explain the absence rather than excuse it: clause 12(c) of the Access Services Agreement is a mutual no-publicity provision under which neither party may issue any public statement mentioning the other without prior written approval, so named references would require a per-customer waiver. The grade records what is locatable, not a judgement about why. Checked 8 September 2026.

LexCheck
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Real deployment evidence with named customers, short of attributed measurement, which is the B band. Two case studies are published with the customer named and a quotation attributed: NetApp, on contract review, and RSM, whose quoted reviewer calls it the best technology implementation they have witnessed for value and ease of use. A further customer strip names Autodesk, Bio-Rad, DigiCert and NetApp. That is named production use rather than logos alone. What holds it off A is that the figures and the names are never joined. The headline outcome claims are aggregate and unattributed: more than a seventy-five per cent increase in speed to close, contracts signed in as little as one day rather than weeks, and more than a fifty per cent reduction in legal costs per contract review. None is tied to a named customer, dated, or supported by a stated basis or method, so a reader cannot assess how any of them was derived or over what population. Under the R25 triage the two case study pages were named but not opened, because the grade rests on the named customers and attributed quotations visible on the home page rather than on the contents of those pages; had the grade turned on a figure inside them they would have been load-bearing and read. Checked 8 September 2026.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

BlackBoiler
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Substantive published commitments across most of the ground, held at B by the limb R33 makes mandatory. What is published and readable before signing: customer ownership of all contract data under clause 7(b); a contractual bar on training third-party foundation models absent customer authorisation; a purpose limitation confining use of customer data to configuring, improving, supporting and operating that customer's own use of the service; a statement that customer data is not used to train models shared with other customers; customer-specific isolation with dedicated instances available on enterprise deployments; access limited to authorised personnel with access controls and logging; encryption in transit and at rest; and a mutual confidentiality regime running five years with trade secret protection surviving indefinitely. Two limbs are missing and both are required for A. Privilege and work product are not addressed anywhere, expressly or by implication, which under R33 is dispositive on its own and is the limb this axis exists to test. And the position on what a third-party model provider may retain cannot be stated because no model provider is identified anywhere on the estate, so a buyer cannot establish whose model touches its contract text or what that provider's retention terms are. Checked 8 September 2026.

LexCheck
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Substantive commitments a buyer can read before signing, held at B by two absent limbs, one of which R33 makes mandatory. Published and readable: the customer exclusively owns all right, title and interest in Client Data irrespective of whether it is stored or processed in the platform, with assignment of any interest the vendor might be deemed to hold; Client Data is expressly within the definition of the customer's Confidential Information; confidentiality obligations run during the term and thereafter with no expiry; disclosure is restricted to personnel with a need to know; data is stored and processed in the United States with ninety days' notice of any change in processing location; the security page states customer data is only used to provide the service and that the vendor does not look into an account without permission; and encryption is AES-256 at rest and TLS 1.2 or greater in transit. Two limbs are missing. Privilege and work product are not addressed anywhere, expressly or by implication, which under R33 is dispositive on its own. And the position on training use is silent across all three published instruments, so a buyer cannot establish whether contract text reaches a model, while no model provider is named anywhere so what any such provider may retain is equally unestablishable. Segregation between users or matters is also unaddressed, which matters given law firms are a named buyer segment. Checked 8 September 2026.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

BlackBoiler
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

A real position on advice versus tooling is published, and it sits in the customer agreement rather than only in a website disclaimer, which is stronger than the C band's boilerplate-in-the-terms pattern. Clause 3(b) of the Access Services Agreement, headed Review of Outputs and No Legal Advice, states that use of the Services is not a substitute for and shall not take the place of review and analysis by a qualified lawyer. The supervision and competence dimension is addressed rather than omitted: the vendor sells expressly to contract managers and procurement staff who are not lawyers, and answers the question directly, stating that a lawyer reviews the redline before anything moves forward and handles exceptions, new risks and negotiation decisions. The marketing does not describe the product in advice terms anywhere; it consistently describes a first pass returned to a lawyer. A is unavailable because jurisdiction limits are named nowhere: no statement identifies which jurisdictions the product is appropriate for, and the only geographic restriction located is a website terms provision limiting site use to United States residents, which governs the website rather than the service. Checked 8 September 2026.

LexCheck
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Nothing published addresses the advice line for a product that proposes contract language, and the product is expressly sold to people who are not lawyers. The Terms of Service were read in full and contain no statement that the service is not legal advice, no requirement or expectation of lawyer review, and no provision addressing competence or supervision. The privacy policy and the security and technology pages contain nothing on the point either. The intended audience is not ambiguous, which removes the other route to C: the vendor names legal departments, sales departments and procurement departments among those it serves, and states that its tools are easy for anyone to use so a team can complete reviews efficiently without the need for external support. That is marketing addressed to non-lawyers describing the product as a substitute for outside legal help, with no accompanying statement about what the product is and is not. One provision was tested and does not reach this axis: clause 11.3 disclaims warranties including accuracy of results, but a warranty disclaimer allocates risk for defective performance and says nothing about whether output constitutes legal advice or who should review it. Under the no-double-spend rule it is graded on AI Liability and Recourse, where it answers the question directly. The grade records what is locatable on the date. Checked 8 September 2026.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

BlackBoiler
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

No governance position is published for a system whose output is proposed contract language. Nothing identifies who inside the vendor is accountable for AI governance, no pre-release testing regime is described, no evaluation results are disclosed, and nothing addresses uneven output across contract types, counterparties or drafting conventions. There is no responsible AI page, no principles statement, no model card, no AI policy and no certification such as ISO 42001, and no third-party governance assessment is referenced. The C band was tested and does not fit: C describes principles published without a mechanism, and here there are no published principles at all. The one candidate consideration is recorded and rejected on the no-double-spend rule: the vendor does describe validation machinery, a judge validator assessing alignment to intended outcome and statistical similarity checks. That is product quality control on individual outputs, it is spent on Citation Accuracy and on Autonomy where it answers those axes directly, and it is not a governance position about how the vendor builds, tests and is accountable for its models. The grade records what is locatable on this axis as of the date. Checked 8 September 2026.

LexCheck
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

No governance position is published for a system whose output is proposed contract language. Nothing identifies who inside the vendor is accountable for AI governance, no pre-release testing or evaluation regime is described, no results are disclosed, and nothing addresses uneven output across contract types, counterparties, drafting conventions or jurisdictions. There is no responsible AI page, no principles statement, no model card, no AI policy, no certification such as ISO 42001, and no third-party assessment referenced. The C band was tested and does not fit: C describes principles published without a mechanism, and here no principles are published at all. Two items were considered and rejected as belonging to other axes under the no-double-spend rule. The operational security policies described on the security page govern IT assets, disaster recovery and access control and are validated under SOC 2 guidance, which is security governance rather than AI governance and is spent on Security Certifications and on AI Safety. And the accuracy assertions on the technology page are marketing claims about performance, not a testing regime, and are spent on Citation Accuracy. The absence is notable in context, since the vendor's own material makes a comparative claim that its AI is more accurate than human review while publishing nothing that would let anyone test or govern that claim. Checked 8 September 2026.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

BlackBoiler
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Substantive published policy covering most of the ground, short of the full set in exactly the two ways the B band names. Published and specific: retention is addressed, with customer data retained for the duration of the customer relationship unless otherwise agreed; deletion is available at contract end or earlier on customer request; access control is described concretely across two documents, with access limited to authorised personnel who need it, access controls and logging, and infrastructure access secured by VPN, secure tokens and IP whitelists issued only to approved employees; encryption is stated as AES256 at rest and TLS in transit; backups are confirmed and stated to be encrypted; and clause 7(b) confirms the customer owns its data and that the vendor will not sell it. Two elements are absent and both are the B band's named shortfalls. No subprocessor list is published anywhere, so a buyer cannot enumerate who touches its data; only Amazon Web Services for hosting and Stripe for payment processing are individually named. And no incident or breach notification practice is published on any surface. One disclosed detail is recorded because it is the kind of candour this index credits under R65 rather than penalises: the vendor states that individual client files may in some instances be temporarily downloaded onto an employee's encrypted hard drive for testing. Retention carries no stated period, which is graded on the retention signal rather than here. Checked 8 September 2026.

LexCheck
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Substantive published policy covering nearly the whole of the A band, short of it on the single limb the B band names. Published and specific: incident practice is unusually strong, with the Data Processing Addendum committing to written notice without undue delay and in no event longer than twenty-four hours of becoming aware of a Security Incident, including the details the customer needs for its own notification obligations, alongside documented detection and response procedures; the Terms add a broadly defined Security Event, a notification and cooperation obligation, and a customer or regulator right to audit books, systems and log files following an incident. Deletion is specific: all copies of Customer Personal Data including archival copies destroyed within ninety days of termination, return within thirty days on request, secure physical destruction of media, and a Certificate of Deletion supplied within thirty days on request. Access control, encryption at rest and in transit, regular penetration and vulnerability testing, backups with a stated twenty-four hour recovery time and recovery point objective, and an annual audit right exercisable for any reason are all published. The B band's named shortfall is exactly what is absent: no subprocessor list is published. The DPA makes one available on reasonable request with thirty days' notice and an objection right before any new third party is engaged, which is a strong change-control mechanism but is not a published list. Retention of contract content is also addressed only as prescribed intervals, naming no interval. Checked 8 September 2026.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

BlackBoiler
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

A real published position on liability, complete on three of the four A limbs, held at B on what a buyer can actually invoke when the output is wrong. Published and specific in the Access Services Agreement: indemnity scope, at clause 9(a), covering third-party claims that the Services infringe or misappropriate US intellectual property rights, with the vendor controlling defence and holding modify, replace or terminate options; carve-outs at clause 9(a)(iii) for use in unauthorised combination, customer modifications, Customer Data and Third-Party Products; and a cap at clause 10 limiting aggregate liability to amounts paid in the twelve months preceding the claim, with named exceptions for confidentiality breach, IP infringement, customer payment obligations and breach of the use restrictions. What is not available is anything a buyer can invoke when the AI output itself is wrong, and the agreement says so rather than leaving it ambiguous. The IP indemnity does not reach output quality; clause 8 disclaims all warranties express, implied and statutory; clause 3(b) defines the risks of relying on any edit, redline, comment, summary, suggestion or analysis as Customer's Assumed Risks; and clause 9(b)(ii) requires the customer to indemnify the vendor against third-party claims arising from those assumed risks. No insurance is referenced. Under R65 this is disclosure of an adverse allocation rather than a gap between marketing and agreement, and it is written as the vendor telling the buyer where it stands: nothing contradicts it, and the record is graded consistently with Juro, whose published exclusion of AI output from the indemnity earned the same grade. Checked 8 September 2026.

LexCheck
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

All four elements the A band names are published and specific, including the one most vendors in this lane omit entirely. Indemnity scope, at clause 9.1, is broader than the usual intellectual property carve: the vendor indemnifies against losses arising from any Security Event, from any failure to comply with the confidentiality and data security article, and from third-party claims that the platform infringes intellectual property rights, with the vendor controlling defence at its own cost and a licence, replacement or refund path at 9.4. Caps, at clause 10.1, are the charges paid in the preceding twelve months. Carve-outs are specific in both directions: 9.3 excludes unauthorised combination and customer-supplied designs, while 10.3 makes liability entirely uncapped for Security Events, confidentiality and data security failures, indemnification obligations, fraud, wilful misconduct, gross negligence and service level credits. Insurance is a full article rather than a mention: the vendor must maintain primary coverage of at least one million dollars with A-rated carriers, name the customer as an additional insured with equally broad coverage, furnish certificates on request, give thirty days' notice of cancellation or material alteration, and waive subrogation, with the stated intent that the vendor's insurance rather than the customer's responds. Affirmative warranties at 11.1 include that the platform will perform the functions described in the Documentation with a repair-or-replace obligation. A service level of 99.9 per cent availability carries a defined credit and a termination right after three consecutive failures. One limit is named rather than buried, because it is the adverse half of the picture: clause 11.3 disclaims accuracy of results, so the warranty runs to conformity with the Documentation rather than to the correctness of any individual redline, and nothing is invocable for a wrong output as such. Under R65 that is disclosure of an adverse allocation, credited rather than penalised, and it is stated here so a reader weighs the wording rather than the grade. Checked 8 September 2026.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

BlackBoiler
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

One integration exists, it is into the system this work actually lives in, and its depth is described well; the rest of the practice stack is named without documentation. The Microsoft Word add-in is the delivery surface rather than a connector, and what it does is set out concretely: the review runs inside Word without moving to a separate environment, the playbook is selected in the document, and the output returns as native tracked changes and comments for the reviewer to accept, change or reject. For a contract redlining product that is the integration that matters most, and it is the reason the product fits a reviewer's existing workflow rather than requiring migration. Beyond it the picture thins. SSO and API access are named as enterprise entitlements with no description of what the API exposes or what a firm must configure. No document management or contract lifecycle management platform is named anywhere as an integration partner: the vendor positions itself explicitly as sitting alongside a CLM at the point the CLM leaves open, and describes handing back to the customer's existing process, but no named connection to any CLM, DMS or e-signature system is published. A requires documented integrations plural into the systems legal work lives in, with sync direction and configuration described, and that is not available here. Checked 8 September 2026.

LexCheck
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

An integration into the contract stack is claimed and no system is named, which is the C band's substance. The vendor states the platform is built to seamlessly integrate with the customer's contract lifecycle management solution and to optimise the negotiation phase of the lifecycle, but names no CLM platform anywhere on the estate, publishes no integration page, no partner list, no connector documentation and no API reference. Nothing describes what would sync, in which direction, or what an implementer would configure. Microsoft Word is the one named system, and the product does deliver into it, described as keeping work in one place and working in the customer's usual word processing software; the privacy policy separately refers to plug-ins exchanging information with LexCheck. That is a named surface without a description of what actually moves between it and the platform, and the primary workflow described elsewhere is web-based, with the user signing into the platform and uploading a contract. B was tested and declined: it requires real integrations that are documented, and what is published here is one delivery surface asserted without description alongside a category-level integration claim with nothing behind it. A third-party source names two channel partnerships; that is an aggregator listing, excluded outright as evidence, and is recorded only so a later reader knows it was seen and refused rather than missed. Checked 8 September 2026.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

BlackBoiler
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Tenancy is stated and region is not, which under R38 clears C because tenancy and region are co-equal limbs and publishing either one lifts the grade off that floor. Published on tenancy: customer-specific isolation measures are used to keep customer data separate, enterprise deployments may include dedicated customer instances and customer-specific data separation controls, and data is described as held in a silo accessible only to the client and necessary vendor staff. Published on infrastructure: the service runs on Amazon Web Services, with production, staging and development infrastructure all stated to be in AWS. What is absent is any region at all. No AWS region is named, no choice of region is offered, no European or other non-US option is described, and processing location is nowhere distinguished from storage location, which matters for a product marketed to law firms and to a construction and AEC sector that contracts internationally. The vendor also states expressly that it does not publish detailed architecture or infrastructure detail publicly, so this is a disclosure decision rather than a retrieval limit and it is recorded as such. This record sits in the band gap R38 logged and left unfixed: a vendor publishing tenancy alone fits neither B nor C cleanly, and B is taken because C's words, that neither the tenancy model nor the region is stated, are false here. Checked 8 September 2026.

LexCheck
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

Residency is published to a level almost nothing else in this lane reaches, and the distinction the A band asks for is drawn expressly. Regions are named in the agreement rather than gestured at: clause 1.6 identifies the primary data centres as located in Northern Virginia and the secondary in Oregon, and provides that the platform and Client Data may only be hosted at those data centres or others the customer approves. Clause 8.6 addresses processing separately from storage, stating that the platform and services are provided from the United States and that Client Data will be stored and processed in the United States, requiring at least ninety days' advance notice before any change in processing location, and giving the customer a right to terminate without penalty with a pro-rata refund if data is stored in a foreign jurisdiction it has not approved in writing. The Data Processing Addendum reinforces it, committing the vendor to inform the customer in writing of all countries where data is processed or stored and to obtain consent, and recording the United States as the only such country as of the effective date. Hosting is on Amazon Web Services. The tier limb does not bite and is named rather than counted either way under R15: a single cloud deployment model is offered, with no on-premise, private cloud or region-choice variation to describe. One genuine gap is recorded and is the reason this call is flagged: the tenancy model is stated nowhere, so a buyer cannot establish whether the deployment is single or multi-tenant or how separation is achieved. Checked 8 September 2026.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

BlackBoiler
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

A real named certification without scope or date, and no way to obtain the report without a sales conversation, which is the B band precisely. The vendor states on two separate surfaces that it is SOC 2 Type II certified. What is not published: the auditor is not named, the audit period or report date is not stated, the scope of the assessment is not described, and no other certification or attestation is claimed anywhere, with no ISO 27001, HIPAA attestation or public penetration test summary located. Access to the report is sales gated and therefore earns no credit under R5: the report is available to qualified prospective customers on request through the sales or security review process, and the vendor states that additional security materials and completed security questionnaires are reserved for enterprise evaluations while standard team and individual subscribers are directed to the public page. C was tested and does not fit: C describes badges with no scope, no date and no report available, whereas here a specific standard is named and a substantive self-published Security and Trust page sits behind it, carrying a seventeen-question security FAQ covering hosting, encryption, isolation, access, retention, deletion, backups and authentication. That page is a genuine trust surface, self-published rather than a hosted portal, but it carries no reports, dates or covered standards, so A is unavailable. Checked 8 September 2026.

LexCheck
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

A real named certification without scope or date and with no route to the report that avoids a sales conversation, which is the B band precisely. The vendor states it has achieved and maintains SOC 2 Type II accreditation and that its operational security policies are regularly reviewed and validated per its SOC 2 guidance. What is not published: the auditor is not named, no audit period or report date is given, and the scope of the assessment is not described. Access is sales gated and therefore earns no credit under R5, the page directing a reader to contact their Account Executive to obtain the most recent Type II report. A second badge sits under the same Certifications heading and is not a certification: GDPR compliance is described as best practices maintaining strict compliance, which is a self-assertion with no attestation, auditor or scope behind it, and it is recorded as such rather than counted. The security page itself is substantive and self-published rather than a hosted portal, setting out hosting, encryption, data usage, recovery objectives, ownership, operational policies, retention and penetration testing, which is what keeps this above the C band's bare badges. A is unavailable because nothing there carries reports, dates or the standards actually covered, and no self-serve route to evidence exists. Checked 8 September 2026.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

BlackBoiler
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The vendor refers to generative AI throughout and identifies nothing that sits underneath it, which is the C band in its own words. No model is named, no model provider is named, and no architecture is described beyond the four-stage evidence, logic, checking and output framing. The gap is sharpened rather than softened by the agreement, which concedes the category while naming no participant: clause 7(b) permits processing Customer Data using third-party infrastructure, technology and artificial intelligence services, and separately bars training third-party foundation models absent customer authorisation, so the vendor's own contract establishes that third-party models are in the supply chain a customer inherits while no surface identifies which. The Third-Party Products definition offers only a generic example. Two named third parties were considered and neither reaches this axis. Amazon Web Services is infrastructure, and under R29 test 1 naming a cloud host says where a model runs rather than whose model it is; Stripe is a payment processor and touches no contract content, being expressly routed outside the Word add-in and the conversational interface. D was tested and does not fit, because D requires nothing published about the model supply chain and the agreement does address the category and constrain it. Change notification is not reached: with no models or providers named, notification would be the fourth limb of an A the record cannot approach. Checked 8 September 2026.

LexCheck
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The vendor refers to the models generically and identifies nothing underneath them, which is the C band in its own words. What is published is that the systems are built on large language models, that these are ideal for handling large sets of data, and that the playbooks are LLM-powered and trained on the most common provisions. No model is named, no model provider is named, no architecture is described, and nothing states whether the models are the vendor's own or a third party's. The Terms of Service and the Data Processing Addendum were both read in full and neither identifies an artificial intelligence subprocessor; the DPA's third-party mechanism is generic and its list is available only on request. Amazon Web Services is named as the hosting environment and as a subcontractor in the support exclusions, and under R29 test 1 naming a cloud host says where a model runs rather than whose model it is, so that fact is spent on infrastructure and does not reach this axis. D was tested and does not fit, because the vendor does publish that large language models sit behind the product; what it withholds is which. Change notification is not reached: with nothing named, notification would be a fourth limb of an A this record cannot approach. Checked 8 September 2026.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

BlackBoiler
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

Real pricing is published for part of the range with the enterprise tier withheld, which is the B band verbatim. Published: three named tiers, Starter, Pro and Enterprise; a monthly and annual billing toggle stating that annual billing saves 17 per cent; a seven-day trial with an express statement that a credit card is required and that the selected subscription begins when the trial ends unless cancelled; and an itemised account of what Enterprise adds over the fixed plans, covering unlimited documents, users and teams scaled to the organisation, SSO, API access, playbook build and maintenance support, guided onboarding, a dedicated success manager and the option of custom contract terms and service level commitments. Enterprise is stated not to be published as a rate, with the reasons given as contract volume, users and teams, playbooks and agreement types in scope, and security, deployment and support commitments. The agreement adds commercial terms most of this lane leaves unpublished: fees payable in US dollars, 1.5 per cent monthly interest on late payment, suspension after ten days, automatic renewal for successive terms equal to the initial term, and thirty days notice of non-renewal. The purchase path is self-serve, with card and wallet payment accepted. One retrieval limit belongs here and is not graded against the vendor: the Starter and Pro figures render client-side and the plan cards returned a loading state, so the figures themselves were not read, and the vendor's own June 2026 launch PDF confirms the tiers exist without publishing rates. A is unavailable on what was established rather than on what is absent. Checked 8 September 2026.

LexCheck
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing information is published at any level, including the unit of charge. There is no pricing page on the estate, no rate, no band, no tier name, no feature split, no minimum term, no seat minimum and no free or trial tier with stated terms. Every purchase path resolves to a demo or contact request, and the agreement confirms the shape: fees are set entirely in an Order Form executed between the parties, with clause 2.3 leaving the Unit of Measure to be specified per order as named users, concurrent users, devices, locations or transactions. That clause describes what an order may contain rather than telling a buyer what this vendor charges for, so it does not lift the axis. C was tested and does not fit, because C describes pricing gated behind a demo while tier names and feature splits are published, and no tier or feature split is published here at all. Two commercial terms were located and are recorded rather than used to lift the grade, because they govern how a price may change rather than what the product costs: clause 5.3 caps any renewal increase at the lesser of two per cent of the prior year's charges or the rise in the vendor's list prices, which is a genuinely protective term rarely published in this lane, and clause 5.4 sets thirty-day payment with a one per cent monthly late fee and a good-faith dispute process. Clause 5.6 records that a satisfactory credit check is required before a subscription starts. No VendorPricing row is written, per the R10 discipline that a page inviting only a sales conversation is an absence. Checked 8 September 2026.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

BlackBoiler
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Segment and practice coverage is described with substance, with the boundaries left open. Three buyer segments are set out separately, each with its own stated position rather than a shared line: in-house legal teams reviewing the same agreement types at volume, law firms applying set positions across client matters, and contract managers applying standards the legal team has already defined. One vertical has a dedicated page and product framing, construction and AEC contracting, and it is supported by the vendor's category-level claim of several construction customers. Agreement types are named rather than implied: NDAs, service agreements and subcontract agreements are identified as the recurring types the product is built for, with more complex contracts stated to be within scope subject to playbook coverage. The product's own limit is stated honestly, that usefulness depends on playbook coverage, the language and context of the agreement, and lawyer review, which is more than most records in this lane publish about where they stop working. A is unavailable on two limbs. Practice areas are not addressed as such, since coverage is organised by agreement type and industry rather than by practice; and government use is nowhere described, the only government-adjacent material being a US Government Rights clause in the agreement, which is a contract term about licence rights rather than a statement of coverage and is not counted here. Checked 8 September 2026.

LexCheck
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Who the product serves is set out as an explicit list rather than implied, with the boundaries left open. Seven segments are named: legal departments, sales departments, procurement departments, global enterprises, high-growth businesses, private equity firms and law firms. The named customers corroborate breadth across segments rather than clustering in one, spanning technology, professional services and life sciences. Buyer framing is differentiated in the material, with the platform positioned for teams reviewing recurring commercial agreements at volume and for non-specialist users applying positions the legal team has set. What is left open is the coverage boundary. Contract type is addressed only by the claim that the playbooks are ready to use on virtually every contract type, which is a breadth assertion with no supporting enumeration, no list of supported agreement types, and no statement of where the product works less well. Practice areas are not addressed as a dimension at all, coverage being organised by buyer function rather than by practice. Government use is nowhere described. A requires the limits to be stated and they are not; C was tested and does not fit, because coverage here is not a bare claim to serve everyone but a specific and differentiated segment list. Checked 8 September 2026.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

BlackBoiler
Opt in

The published Access Services Agreement, last modified 31 August 2026, was located and read in full before this value was written. Clause 7(b) sets the default at no training and makes customer authorization the gate, which is opt-in rather than a flat contractual bar. contractual-never was tested and declined because it would assert something the clause does not say: the express prohibition names third-party foundation models specifically, and it carries a carve-out for customer authorization or an applicable Order.

The same clause purpose-limits every other use, permitting the vendor to use and retain customer data including edits, redlines, playbook positions, rules, prompts, workflows and configurations to configure, improve, support and operate that customer's own use of the service, and confirming the customer owns the data and that the vendor will not sell it. That purpose limitation is what keeps the public claims and the agreement aligned rather than in tension, so this is not a marketing-versus-agreement divergence and is not written as one: the security page states that customer data is not used to train models shared with other customers and that customer data remains dedicated to that customer's use, and the homepage states that contracts, playbooks, redlines and negotiation positions are not used to train models or to improve the product for other companies.

The aggregated statistics provision at clause 2(f) was tested against the R28 rule that the clause must name the thing and does not reach this signal: it operates on anonymized statistical and performance information, is expressly barred from identifying the customer or disclosing confidential information, and names neither machine learning nor training. One gap belongs in the record: the express bar covers third-party foundation models, and no clause prohibits the vendor training its own models, which is addressed by the purpose limitation rather than by prohibition.

LexCheck
Terms silent

The agreement is published and was read in full, and it says nothing about training. The Terms of Service dated 13 January 2025, the Data Processing Addendum and the privacy policy dated 21 March 2025 were each read end to end, and none contains any provision addressing training, model improvement, machine learning or the use of customer content to develop the product. The value records that silence. no-agreement-published is false because a full agreement is published. policy-never was tested and declined: its words require public material stating that customer content never trains, and no surface makes that statement.

The closest located, quoted here, is a purpose limitation on the security page confining use of customer data to providing the service, alongside a statement that data is not mined or sold for advertising purposes and belongs entirely to the customer. That is a purpose limitation and an advertising carve-out rather than a training position, and a buyer cannot tell from it whether contract text reaches a model. The residuals clause at 6.4 was tested against the rule that a clause must name the thing before it reaches this signal: it lets each party reuse general concepts, techniques and know-how, but it is expressly bounded away from the other party's Confidential Information, which is defined to include all Client Data, and it names neither training nor machine learning, so it does not reach the permissive end.

The context makes the silence pointed rather than incidental, because the vendor states elsewhere that its systems are built on large language models and its playbooks are LLM-powered.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

BlackBoiler
Disclosed without a period

Retention is addressed directly on a first-party surface and no period is stated anywhere, which is this value exactly. The security page states that data is retained for the duration of the customer relationship unless otherwise agreed, that it may be deleted at contract end or earlier on customer request, and that deletion requests are processed subject to applicable legal, security, backup and operational requirements.

Clause 7(b) of the agreement separately permits the vendor to use and retain customer data to configure, improve, support and operate that customer's own use of the service, again without a period. Two higher values were tested and neither is true. disclosed-fixed requires a stated window and none exists. customer-configurable requires the customer to control retention, and what is available is a request the vendor processes in accordance with its own operational practices rather than a setting the customer operates, so the words would be false.

The qualifier attached to deletion is recorded because it materially affects what a buyer can rely on: legal, security, backup and operational requirements are unbounded on their face and no maximum is given for how long backup copies persist after a deletion request. Termination is asymmetric in the agreement, which is worth naming: clause 11(c) requires the customer to delete or destroy the vendor's property and certify it in writing, and imposes no matching obligation on the vendor to delete customer data.

LexCheck
Disclosed without a period

Retention is addressed on more than one surface and no period is stated for the material this product actually processes. A ninety-day figure exists and is real, but its scope has to be read carefully before it is credited. The Data Processing Addendum requires destruction of all copies of Customer Personal Data, including archival copies, within ninety calendar days of termination, return within thirty days on request, and a Certificate of Deletion within thirty days on request.

However the addendum defines Customer Personal Data narrowly as personal data pertaining to the customer's users or employees, and enumerates it as names, titles, positions, employers, contact details, identification data and electronic identifiers such as IP addresses. It does not govern the contract documents, playbooks and outputs the product exists to handle. For those the position is the Terms of Service return-or-destroy-on-request provision at 8.5, which is triggered by a written request rather than by a schedule and carries exceptions for material archived for disaster recovery and material retained under applicable law, and the security page statement quoted here, which commits to deletion at prescribed intervals without naming an interval. disclosed-fixed was declined because no fixed window governs prompts or outputs. customer-configurable was declined because deletion is a request the vendor processes rather than a control the customer operates. The vendor separately commits not to delete data in an account without giving the customer time to export it.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

BlackBoiler
Claimed, not documented

Segregation is asserted on first-party surfaces with no published detail on how it is enforced, which is this value. What is claimed: customer-specific isolation measures keep customer data separate, enterprise deployments may include dedicated customer instances and customer-specific data separation controls, access is limited to authorized users and required vendor personnel with access controls and logging, and the data handling page describes a silo accessible only to the client and necessary staff, with infrastructure access secured by VPN, secure tokens and IP whitelists. separate-model-documented was tested and declined because it requires a documented permission model, and no permission model is published: the vendor states expressly that it does not publish detailed architecture diagrams or infrastructure detail on its public website, and offers further material only inside an enterprise security review, so the enforcement mechanism cannot be read before signing.

The question bites on this record rather than being inapplicable, because law firms are one of three named buyer segments and the product ingests counterparty agreements across client matters. Two things are absent at the level a firm would need. Nothing addresses matter-level walls or segregation between users or matters inside a single customer tenant, the claims all operating at tenant level between customers. And inherits-dms-acl is not reached at all, since the product takes documents in Microsoft Word rather than retrieving from a document management system, so there is no source system access model for retrieval to enforce.

LexCheck
Not addressed

No located public material addresses walls or matter-level segregation. The Terms of Service, the Data Processing Addendum, the privacy policy, the security page and the technology page were all read and none states the tenancy model, describes isolation between customers, addresses separation between users or matters within a customer, or explains how any of it is enforced. The question bites on this record rather than being inapplicable, because law firms are one of seven named buyer segments and the product ingests counterparty agreements that may sit across client matters.

Two provisions were tested and neither reaches this signal. The statement quoted here commits the vendor not to access an account without permission and confines use of customer data to providing the service, which is an access-control and purpose commitment rather than a segregation architecture, and it is graded on Privilege and Confidentiality Posture where it answers the question directly. And the confidentiality article restricts disclosure to personnel with a need to know, which governs vendor staff rather than retrieval boundaries between customers or matters. claimed-undocumented was tested and declined because it requires segregation to be asserted in public materials, and no assertion of segregation was located to be undocumented. inherits-dms-acl is not reached, since the product takes uploaded documents rather than retrieving from a document management system, so there is no source system access model for retrieval to enforce.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

BlackBoiler
Notice committed

The agreement commits to notice before compelled disclosure, and adds a protective-order opportunity, which places this row among the stronger ones in the lane. Section 6 of the Access Services Agreement permits disclosure of confidential information to the limited extent required to comply with an order of a court or other governmental body, or as otherwise necessary to comply with applicable law, and conditions that permission on the disclosing party first giving written notice and the opportunity to obtain a protective order.

The commitment is mutual and it is a condition on the disclosure right rather than a discretionary statement of practice, so discretionary and disclosure-without-notice are both false of this record. notice-and-report was tested and declined: no transparency report, law enforcement request report or equivalent periodic disclosure is published on any surface, and nothing states how many requests have been received. The evidence sits in the confidentiality section of the master agreement rather than in a data processing addendum or privacy policy, consistent with the pattern established across earlier pulls, and no separate DPA was located on the estate.

One limit is recorded rather than graded: the commitment attaches to confidential information as defined in section 6, and the agreement does not separately address requests directed at customer data as such, though customer data submitted under the agreement would ordinarily fall inside that definition.

LexCheck
Notice committed

The agreement commits to advance notice before compelled disclosure and pairs it with a protective-order opportunity. Section 8.3 permits disclosure of the other party's confidential information only pursuant to the order, request or requirement of a court, administrative or regulatory agency or other governmental body, and only where the receiving party gives the notice quoted here. It adds a second protection that most records at this value do not carry: where a protective order is not obtained, the receiving party discloses only the portion of the confidential information that its legal counsel, including internal counsel, advises it is legally required to disclose, and the material disclosed remains confidential as between the parties.

The commitment is mutual and it operates as a condition on the disclosure permission rather than as a statement of practice, so discretionary and disclosure-without-notice are both false of this record. Customer contract content falls inside the protection because Client Data is expressly within the definition of the customer's Confidential Information. Two qualifications are recorded rather than left implicit: the notice obligation applies where the receiving party is legally permitted and it is reasonably practicable, which is standard drafting, and the cost of seeking the protective order falls on the disclosing party. notice-and-report was declined because no transparency report, law enforcement request report or periodic disclosure of any kind is published.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

BlackBoiler
Not addressed

No located public material identifies a legal corpus behind the product's output, because the product carries none. It operates on the customer's own material, taking prior redlines, approved language, fallback positions and written playbook guidance and converting them into executable rules applied to the agreement under review, and it neither retrieves nor cites legal authority. The value records what is locatable on this signal and is not an accusation of vendor silence: there is no third-party corpus to name, license or date.

This matches how the contract-review-and-drafting lane already grades the same shape, where records whose material is the customer's own paper sit at this value while records identifying an actual legal corpus take named-no-licence. A higher value was considered and declined. The vendor does identify what sits behind its output, the customer's own contract material, and clause 7(b) of the agreement does state the rights basis, giving the customer ownership and the vendor a non-exclusive royalty-free license to use that data only as necessary to provide the service.

Crediting named-and-licensed on that basis would assert that the vendor names primary law sources and their license footing, which is false of this product, and would credit a limb that does not apply rather than simply declining to penalize it.

LexCheck
Not addressed

No located public material identifies a corpus behind the product's output. The product carries no legal corpus: it operates on the customer's own uploaded template and the playbook positions extracted from it, and on the contract under review, and it neither retrieves nor cites legal authority. The value records what is locatable rather than alleging vendor silence about something the product has. One statement was located that touches the question and is recorded because it comes closest without answering it.

The technology page states that the LLM-powered playbooks are trained on the most common provisions and are ready to use on virtually every contract type. That asserts the models were developed against a body of contract language, which raises the provenance question directly, but it identifies no source, no jurisdiction, no dataset, no license and no rights basis for whatever that body was, so nothing in it can be credited. named-no-licence was tested and declined on that basis: the most common provisions identifies nothing a reader could examine.

This is also the value the contract-review-and-drafting lane carries for products whose material is the customer's own paper, so the record sits consistently with its comparators rather than being graded on a fresh reading.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

BlackBoiler
Not addressed

No located public material addresses whether authority is checked for subsequent history, because the product cites no authority. It proposes contract language against the customer's own approved positions and returns tracked changes in Microsoft Word; it does not retrieve cases or statutes, does not present citations, and has no citator function to describe. The value records an absence of located material on this question rather than a defect in the product, and it is the value every comparable record in this lane carries for the same reason.

What the product does check is recorded here so a later reader sees the distinction was understood rather than missed: the vendor describes a judge validator assessing whether a proposed edit aligns with the intended outcome, together with statistical similarity checks against the customer's prior examples, before the edit reaches the lawyer. That is verification of a proposed contract edit against the customer's own standards, not verification of legal authority against subsequent history, and it is graded on the citation accuracy axis where it answers the question directly.

LexCheck
Not addressed

No located public material addresses whether authority is checked for subsequent history, because the product cites no authority. It evaluates a commercial contract against positions captured from the customer's own template, surfaces deviations and proposes redlines inside Microsoft Word. It does not retrieve cases or statutes, does not present citations to legal authority, and has no citator function to describe. The value records an absence of located material on this question rather than a defect in a product that was never built to answer it, and it is the value carried across the contract-review-and-drafting lane for the same structural reason.

What the product does check is recorded so a later reader sees the distinction was drawn rather than missed: the vendor states that it evaluates contract language against the customer's preferred positions and explains why flagged language requires attention. That is verification of a commercial provision against a customer standard, not verification of legal authority against subsequent history, and it is graded on the citation accuracy axis where it answers the question directly.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

BlackBoiler
Documented

The vendor describes abstention behavior in public materials, which is this value. Asked directly what the limitations of AI contract review are, it answers that the tool does not remove the need for human review or legal judgment, that playbook coverage may be incomplete, that contract language may depart from prior examples, and that unusual provisions may require a lawyer to make a fresh decision. The routing that follows is stated rather than implied: the output is treated as a first pass, and new risks, exceptions and negotiation decisions are left to the appropriate reviewer, so material the playbook does not cover is passed through to the lawyer rather than guessed at.

The vendor also states that different contract language may call for a different edit and that the resulting markup remains subject to lawyer judgment. In the earlier ContextAI presentation a flag marks a rule where an edit may be needed and the user should review, which is an explicit signal of unresolved cases. documented-and-demonstrable was tested and declined: it requires the behavior to be observable in the product or in published evaluation, and while a seven-day self-serve trial would let a buyer observe it, no published evaluation, benchmark or worked example of the abstention path exists on any surface, and a trial a reader must run themselves is not published evidence. No confidence or grounding score is exposed, so confidence-scoring-only is false.

LexCheck
Not addressed

No located public material addresses what the product does when it cannot ground an output. Nothing on the estate describes an abstention path, states what happens to contract language that falls outside the playbook's coverage, addresses unusual or novel provisions, or explains how a reviewer is told that the system has low confidence in a particular passage. No confidence score, grounding score or uncertainty indicator is described, so confidence-scoring-only is false as well.

The published material runs in the opposite direction and is recorded here because it is the reason the absence matters rather than being merely a gap: the vendor states that its system's AI is highly accurate and that this lowers risk more than human review, that playbooks are ready to use on virtually every contract type, and that reviews can be completed without the need for external support. Those are claims of coverage and reliability made without any accompanying account of where coverage ends.

The nearest thing located to a limit is the invitation to edit the playbook and add fallback positions at any time, which is a mechanism for the customer to extend the standard rather than a description of what the system does when it reaches the edge of one.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

BlackBoiler
None located

No matter naming this vendor or its product was located. Searches were run on both the company name, BlackBoiler, and the product name, Veris, against the AI Hallucination Cases database maintained by Damien Charlotin and against general search, on 8 September 2026. Nothing returned any filing, sanction, order or judicial finding involving either name. The value records the state of the search on the date rather than a claim that no such matter could exist.

Two things are worth recording for a later reader. The product does not generate legal citations at all, proposing contract language against the customer's own approved positions rather than retrieving or citing authority, so the failure mode this signal tracks is structurally unlikely to arise from its output. And the vendor publishes an express statement that its output is a first pass requiring lawyer review, which is the practice this signal exists to encourage.

LexCheck
None located

No matter naming this vendor was located. Searches were run on the company name against the AI Hallucination Cases database maintained by Damien Charlotin and against general search on 8 September 2026, and nothing returned any filing, sanction, order or judicial finding involving LexCheck or its named products. The value records the state of the search on that date rather than a claim that no such matter could exist.

One structural point is recorded for a later reader. The product does not generate legal citations: it proposes contract language against positions captured from the customer's own template and does not retrieve or cite authority, so the failure mode this signal tracks is unlikely to arise from its output in the ordinary course. That structural observation is not a substitute for the search, which was run on the name regardless and returned nothing.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

BlackBoiler
Generic reference

Public materials refer to professional responsibility in general terms without naming any guidance, which is this value. The reference is real rather than decorative and it sits in the customer agreement: clause 3(b) states that use of the service is not a substitute for and shall not take the place of review and analysis by a qualified lawyer, and the public FAQ addresses the competence and supervision question directly, stating that non-lawyers can apply standards the organization has defined but that a lawyer reviews the redline before anything moves forward and handles exceptions, new risks and negotiation decisions.

What is absent is engagement with any named authority. No bar ethics opinion is cited, no state or national bar guidance is discussed, no regulator is named, and nothing maps the product against the professional conduct rules its buyers are bound by in any jurisdiction. named-guidance requires engagement with at least one named ethics opinion and nothing on the estate reaches that. The signal measures engagement with AI-specific professional guidance, and a competent-review requirement in an agreement, while genuine, addresses the advice line rather than the ethics guidance a firm must satisfy.

LexCheck
Not addressed

No located public material engages with bar or ethics guidance. No ethics opinion is cited, no state or national bar guidance is discussed, no regulator is named, and nothing maps the product against the professional conduct rules its buyers are bound by in any jurisdiction. generic-reference was tested and declined, and the distinction is worth stating because it is narrow. That value requires public materials to refer to professional responsibility in general terms, and here there is no such reference at all: the Terms of Service were read in full and contain no statement that the service is not legal advice, no requirement or expectation of lawyer review, and nothing touching competence or supervision, and neither the privacy policy nor any product or security page addresses the subject.

The one clause that might be mistaken for it is the warranty disclaimer at 11.3, which disclaims accuracy of results; that allocates risk for defective performance and engages no professional responsibility question, and it is graded on AI Liability and Recourse. The absence is more pointed here than on a comparable record because the vendor markets the product to sales and procurement teams as usable without the need for external support, which is the setting in which ethics guidance would most matter.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

BlackBoiler
Savings claims only

Efficiency and cost savings are the frame, and nothing addresses what happens to the bill when the work compresses. The vendor invites a buyer to weigh its subscription against how contract review is handled today, naming internal reviewer time, repeated manual markup, outside counsel spend and available capacity as the comparison factors, and its wider material rests on the claim that the repeatable first pass is taken on by the software so that time is saved.

That is a savings claim addressed to the buyer's own cost base. What the signal asks is whether the vendor addresses what happens to the bill when a task that took six hours takes one, and nothing does. There is no per-matter record of AI-assisted work, no artifact a firm could put in front of a client, and no guidance on fee or disclosure treatment where AI has compressed billable time. audit-record and audit-record-and-guidance both require a per-matter record of AI-assisted work and neither is available.

The direction of sale is worth naming: the buyer here may be an in-house team, a law firm or a contract manager, and where the buyer is an in-house team the compression accrues to the client directly rather than passing through an invoice, so the question the signal asks does not arise in the same form. Where the buyer is a law firm applying set positions across client matters it does arise, and it is unaddressed.

LexCheck
Savings claims only

Savings are the frame throughout and nothing addresses what happens to the bill when the work compresses. The published claims are quantified and prominent: more than a fifty percent reduction in legal costs per contract review, more than a seventy-five percent increase in speed to close, contracts signed in as little as one day rather than weeks, and blog material claiming a reduction in review time of more than ninety percent.

Those are savings claims addressed to the buyer's own cost base, which is what this value records. What the signal asks is whether the vendor addresses what happens to the bill when a task that took six hours takes one, and nothing does. There is no per-matter record of AI-assisted work, no artifact a firm could put in front of a client, and no guidance on fee or disclosure treatment where the technology has compressed billable time. audit-record and audit-record-and-guidance both require a per-matter record and neither is available.

The direction of sale is recorded because it shapes how the question lands: the named buyer segments include corporate legal, sales and procurement departments as well as law firms, and where the buyer is an in-house or commercial team the saving accrues to that organization directly rather than passing through an invoice, so the question arises in its full form only for the law firm segment, where it is unaddressed.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

BlackBoiler
Not addressed

A firm could not get this vendor through a client's AI clause without a bespoke negotiation, because the central artifact does not exist. No subprocessor list is published anywhere on the estate, and no statement identifies which model providers see client content. That absence is not incidental here: the vendor's own agreement concedes at clause 7(b) that customer data may be processed using third-party artificial intelligence services and separately restricts training of third-party foundation models, so third parties are in the chain and none is named.

Two named third parties were tested against the coverage rules and neither satisfies the signal. Amazon Web Services is infrastructure, and under the established test naming a cloud host says where a model runs rather than whose model it is, so infrastructure alone never satisfies this signal. Stripe is a payment processor, expressly routed outside the Word add-in and the conversational interface and touching no contract content.

No forwardable client-facing disclosure material exists either: no data processing addendum was located, no AI disclosure pack, no consent or notification template, and no subprocessor change notification commitment. on-request was tested and declined because it asserts the material exists behind a sales conversation or an executed agreement, and nothing on the estate indicates a subprocessor list or model provider statement exists in any form.

What is available through the security review process is described as security materials and questionnaire responses, which is a different artifact answering a different question.

LexCheck
On request only

The material exists behind a request rather than on a page, which is what this value asserts, and unlike many rows at this value that is demonstrable rather than inferred. The published Data Processing Addendum states in terms that a list of third parties processing customer personal data is available on reasonable request, and surrounds it with a change-control mechanism stronger than most published lists carry: notification by email before engaging any new third party, thirty days for the customer to object, a good-faith resolution period, and a right to terminate the affected part of the service with a pro-rata refund if the objection cannot be resolved.

The addendum also commits the vendor to written agreements with third parties imposing compliant data protection terms and to remaining responsible for their performance. Two limbs of the higher values are unavailable. No list is published, so subprocessors-listed is false. And no model provider is named anywhere on the estate, so a firm cannot tell its client whose model sees its contract text; under the coverage test infrastructure alone never satisfies this signal, and Amazon Web Services is named only as the hosting environment.

One limit belongs on the record for a firm relying on this addendum for an EEA client: the transfer mechanism it incorporates is European Commission Decision C(2010)593, the controller-to-processor standard contractual clauses superseded by Decision 2021/914 in 2021, and the addendum separately defines Privacy Shield, invalidated in 2020, without using the term.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

BlackBoiler
Not addressed

No located public material addresses court disclosure or verification certification. Nothing on the estate discusses judicial standing orders on AI use, no disclosure template or guidance is published, and no export produces a per-document record of the kind such an order would require. The value records what is locatable rather than a defect: the product is transactional, applying negotiation standards to commercial agreements before signature, and its output is a redline on a contract rather than a filing put before a court, so the question a standing order asks does not arise in the ordinary course of its use.

One element that would form part of such a record does exist inside the product and is noted so a later reader sees it was weighed. The vendor states that each proposed edit is traceable to the playbook rule that produced it and to prior examples of the same edit within the organization, which is a provenance trail for the output. partial-record was tested and declined because that trail is a review aid inside the document rather than an available record of model used, sources retrieved and human verification, and because nothing published describes it as serving a disclosure purpose or shows it being produced as a record.

LexCheck
Not addressed

No located public material addresses court disclosure or verification certification. Nothing on the estate discusses judicial standing orders on the use of artificial intelligence, no disclosure template or guidance is published, and no export produces a per-document record of the model used, the sources drawn on and the human verification applied. The value records what is locatable rather than a defect: the product is transactional, applying negotiation positions to commercial agreements before signature, and its output is a redline on a contract rather than a document filed with a court, so the question a standing order asks does not arise in the ordinary course of its use. partial-record was tested and declined.

The nearest thing located is the vendor's statement that its insights explain why particular contract language requires attention, which surfaces a rationale alongside each flagged passage; that is a review aid presented inside the workflow rather than an extractable record of model, sources and verification, and nothing published describes it as serving a disclosure purpose or shows it being produced as a record. The audit rights in the addendum were also considered and are a compliance mechanism for the customer's own assurance rather than a disclosure artifact for a court.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • AI Governance and Bias Disclosure
Signals neither addresses in public material
  • Primary Law Corpus Provenance
  • Good Law Verification
  • Court Disclosure Support

Which one fits

Choose BlackBoiler if

  • You want the markup built from your own past redlines. BlackBoiler turns prior redlines, approved language, fallback positions and playbook guidance into executable rules, returns tracked changes and comments in Word, and shows for each edit the playbook rule and earlier examples behind it.
  • You want to try it before a sales call. BlackBoiler sells Starter and Pro plans self serve by card with a seven day trial and 17 percent off annual billing, and quotes an Enterprise tier that adds unlimited documents, SSO, API access and playbook build support.
  • You work in construction or review recurring agreements at volume. BlackBoiler has a dedicated construction and AEC offering, names NDAs, service agreements and subcontracts as the types it is built for, and states that unusual provisions still need a lawyer's fresh decision.

Choose LexCheck if

  • You want data location and breach notice fixed in the contract. LexCheck's terms name its data centers in Northern Virginia and Oregon and require 90 days' notice before any change in processing location, and its data processing addendum commits to breach notice within 24 hours.
  • You want insurance and liability terms behind the service. LexCheck's terms leave liability uncapped for security failures, require insurance naming you as an additional insured, cap renewal increases at two percent, and commit to 99.9 percent availability with service credits.
  • You want a playbook drafted for you from your own template. LexCheck captures your preferred positions automatically from an uploaded template, lets you add fallbacks in a self serve platform, explains why each flagged passage needs attention, and names NetApp and RSM among its customers.

In summary

BlackBoiler

BlackBoiler is AI contract review software from Brambleton, Virginia that applies a legal team's own negotiation standards to incoming contracts as tracked changes and comments inside Microsoft Word. It builds playbook rules from prior redlines and approved language, and its 2026 Veris release adds a conversational layer and a validation step before an edit reaches the lawyer. The AI Legal Index grades it in the top two bands on twelve of fifteen capability axes, with A grades on AI centrality and on autonomy and oversight. Its agreement states that output does not replace review by a qualified lawyer. It holds eleven US patents and states SOC 2 Type II. As of 8 September 2026 the index located no named customer, no named model provider and no accuracy figure.

Source: AI Legal Index, 2026

LexCheck

LexCheck is AI contract review software from New York that applies a company's own negotiation positions to incoming contracts, returning an issues list and proposed redlines inside Microsoft Word. It builds a playbook automatically from an uploaded template, explains why each flagged passage needs attention, and is sold to legal, sales and procurement teams and to law firms. The AI Legal Index grades it in the top two bands on eight of fifteen capability axes, with A grades on AI centrality, liability and deployment. Its terms name US data centers, leave liability uncapped for security failures and require insurance naming the customer. As of 8 September 2026 the index located no training position, no statement that its output is not legal advice and no price.

Source: AI Legal Index, 2026

Questions buyers ask

BlackBoiler vs LexCheck: which is better for contract redlining?

On published evidence BlackBoiler sits in the top two bands on twelve of fifteen AI Legal Index capability axes and LexCheck on eight of fifteen. BlackBoiler publishes more about keeping a lawyer in charge of its redlines and about training. LexCheck publishes stronger contract terms on liability, insurance and data location, and names customers. Legal teams that need the review rule in writing have more to read from BlackBoiler.

Does LexCheck say its redlines need a lawyer's review?

No such statement was located. LexCheck's terms of service contain no statement that the service is not legal advice and no requirement of lawyer review, and its site markets the tools as easy enough for anyone to complete reviews without outside support. It does let customers edit the playbook the system drafts. BlackBoiler's agreement states that its output does not replace review by a qualified lawyer. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

Do BlackBoiler and LexCheck train AI on customer contracts?

BlackBoiler's agreement bars training third party foundation models on customer data unless the customer authorizes it, limits other use to running that customer's own service, and states that customer data is not used for models shared with other customers. LexCheck's terms, addendum and privacy policy say nothing about training; its security page says customer data is only used to provide the service. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

Where do BlackBoiler and LexCheck host data?

LexCheck's terms name its primary data center in Northern Virginia and its secondary in Oregon, both on AWS, state that data is stored and processed in the United States, and require 90 days' notice before processing moves. BlackBoiler runs on AWS with customer specific isolation and dedicated instances on enterprise plans, but names no region. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

What do BlackBoiler and LexCheck both leave unpublished?

The model and the evidence of accuracy. Neither names the language model or provider behind its redlines, and neither publishes an accuracy figure or test set. Neither publishes an AI governance position, a subprocessor list, or a warranty that covers a wrong redline. Neither addresses privilege or work product for the contracts it reads. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

Disclosure

Three readings to weigh. LexCheck's terms disclaim the accuracy of results, so its warranty covers conformity with documentation, not whether a given redline is right. BlackBoiler's agreement puts the risk of relying on any edit on the customer. BlackBoiler's Starter and Pro prices load in the browser and could not be read, and it names no customers, which may reflect a mutual no publicity clause in its agreement. BlackBoiler and LexCheck were both verified on 8 September 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 24, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746