Blee vs Luthor: how they compare in 2026

B
Blee profile
L
Luthor profile
Last verifiedSeptember 26, 2026

Blee and Luthor both run an AI first pass over marketing content for legal and compliance teams in regulated companies, flagging missing disclosures and unsupported claims against rule sets built with each customer. Blee sits in the top two bands on eleven of fifteen axes and Luthor on eight of fifteen, identical on nine. Blee's lead is how its flags reach a person. Each flag carries its rule, its place on the asset and an explanation checked against the customer's own source of truth, and Blee states that a person always decides. Submissions arrive from Jira, Workfront and Asana, with feedback shown inside Figma and Google Docs. Luthor publishes no position on what its tool is or who decides, and names no connected system. Its counterweight is in its terms, which carry a mutual confidentiality obligation and commit to deleting all customer data within thirty days of termination; Blee's terms have no confidentiality clause. Both describe review decisions tuning their models, although Luthor's security page states that customer data never trains any model.

At a glance

Category
BleeRegulatory & Compliance Counsel
LuthorRegulatory & Compliance Counsel
Founded
BleeNot published
LuthorNot published
Headquarters
BleeNew York, NY, United States
LuthorSan Francisco, CA, United States
Last verified
BleeSep 18, 2026
LuthorSep 20, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Blee
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models drive the capability the vendor leads with, on a review workflow that would run without them, which is the B band. The AI pre-reads every submission and flags regulatory risks, missing disclosures and unsubstantiated claims, and in monitoring scans live sites, social channels and partner content for outdated claims and missing disclosures. Around that sit submission intake, routing to reviewers, approvals and an audit trail of versions and decisions, which function as a review workflow without the models. Verified 18 September 2026.

Luthor
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

The models are the mechanism, not a feature bolted to a workflow tool. Content goes in — text, images, video, audio, SMS, social posts, PDFs and live URLs — and the system classifies it, flags performance claims, guarantees, missing disclosures, testimonials, unsupported assertions, off-brand language and personally identifiable information, then says which rule was hit and what to change. The vendor describes natural language processing for context, machine learning classification and large language models for the written output. The approval routing and the audit trail exist to carry that output rather than the other way round, and the published case for buying is that human review alone cannot enforce every policy at the volume AI-generated content now arrives in. One qualification a buyer should hold: part of the enforcement is plainly rule-based — banned phrases, trigger words, required disclosure lines — and nothing published separates what the rules catch from what the models catch. Read on the home page platform and policy library sections, both solutions pages, the Financial Services page and the 19 June 2026 guide. Verified 20 September 2026.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Blee
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is documented, with each flag tied to the rule and source behind it, short of accuracy figures an outsider can test, which is the B band. The Content Reviews and Financial Services pages say every flag arrives with its rule, its location on the asset and an explanation, and is checked against the customer's source of truth, with a worked example of an APR in an ad compared with the customer's stated rate under Regulation Z; the life sciences page shows each claim beside the exact supporting passage from the customer's approved references. The rule sets are built by the vendor's legal engineers from named regulations and the customer's guidelines. The FAQs say Blee typically reaches 85 to 95 per cent flagging accuracy against 50 to 60 per cent for a general-purpose model, with no test set, sample or definition of accuracy, and no failure modes are named. Flagged for sampling. Verified 18 September 2026.

Luthor
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is asserted repeatedly and measured nowhere. The PCM Encore case study of 28 October 2025 puts review accuracy at 64% before and up to 96% after, described as accuracy with zero critical defects; the Regional Bank study of 8 December 2025 reports 86% of advertising issues self-corrected by the field and licensing errors near zero. Neither gives a sample, a period, a method, or a definition of what a correct review is, and nothing anywhere addresses the failure that matters most in a product like this, which is the violation the system does not flag. A 98.4% detection rate and a 99.2% figure sit inside product mockups on the home and Legal & Compliance pages next to invented assets, so they describe the interface rather than a result. What is real is the grounding: every review shows what was flagged, which rule applied and the reasoning behind it, and the bank study shows that explanation reaching the person who has to fix the ad. A figure an outsider could test is what this row is short of. Verified 20 September 2026.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Blee
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a lawyer checks it are all published: modes, thresholds, review surfaces, and the route a matter takes back to human judgment. A categorical limit on a named mode or tier, stating what its output may not be used for, meets the threshold limb without a number.

A categorical limit on the AI is published for the step that matters, with the review surfaces and the route to a human described, which meets the A band under R124(2). The consumer brands FAQ answers whether a person still approves or the AI decides with 'A person always decides': Blee runs the first pass and approval stays with legal, regulatory and brand reviewers, and the life sciences FAQ says the same of medical, legal and regulatory reviewers. The Content Reviews page sets out the route: an AI first pass, marketing fixing the clear-cut issues it flags, routing to the right reviewer, each flag shown with its rule, its location on the asset and an explanation, and the reviewer's approval clearing the asset to publish, with every decision logged; in life sciences each claim is shown beside the supporting passage from the approved references. Nothing states a confidence threshold, and monitoring flags are routed to the person responsible without a stated review step. Flagged for sampling. Verified 18 September 2026.

Luthor
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

The review point is described and it sits with people, short of a full control structure. The AI runs the first pass; assets come back approved, needing review or escalated, and each review carries provenance showing what was flagged, which rule applied and the reasoning. The Regional Bank study of 8 December 2025 describes the tightest version in production: the field could fix findings and re-upload until an ad passed, and only compliance could override a finding. Role-based permissions, multi-factor authentication and single sign-on are published, and every action is logged. Two things hold this where it is. The override rule and the risk thresholds that drive escalation are the customer's own configuration — escalation criteria and risk thresholds are listed among the things a customer encodes — rather than a limit the vendor places on its own product. And nothing published says what the system does at the point it cannot tell, or what happens after a review turns out to be wrong. An auto-approve control appears in a product mockup on the Marketing Teams page and is described nowhere in text. Verified 20 September 2026.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Blee
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

A named, dated deployment with figures but no method, which is the B band. The May 2025 Rocket Mortgage case study reports initial review time falling from 72 to 24 hours, 14 hours a week saved against about 50 hours a week of manual review before, and review done with a third of the previous staff time, without saying how these were measured. Attributed testimonials come from NerdWallet's Chief Legal Officer, Marqeta's marketing compliance officer, Betterment's and Greenlight's chief compliance officers and a Rocket Mortgage analyst, and further case studies announce partnerships with Betterment, NerdWallet and Public. The 65 per cent review-time reduction in the funding release is not tied to a customer. Verified 18 September 2026.

Luthor
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Two dated deployments are published with figures, and the figures do not entirely agree with each other. PCM Encore, an employee-owned fiduciary wealth manager in Bellevue with more than $1.2 billion under management and over 50 client families, is named and its Chief Compliance Officer is quoted: weekly reviews up from 6, accuracy from 64% to up to 96%, median turnaround from three business days to roughly four hours, live in three days (28 October 2025). A regional mortgage lender, unnamed, reports reviews 82% faster, 86% of issues corrected by the field before compliance saw them, NMLS and licensing errors near zero, and more than 60 custom rules built (8 December 2025). Neither states a method or a measurement window. The bank study headlines 82% faster and its own text says about 70 per cent; PCM Encore's weekly figure reads 45 on one page and 46 on another; the same customer quote appears in two wordings across the site. Three further logos and two anonymous testimonials carry no figures. Verified 20 September 2026.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Blee
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Specific published commitments on how AI providers handle customer content, short of contractual confidentiality or a privilege position, which holds this at the bottom of the B band. The security page states that enterprise agreements with third-party AI providers ensure zero retention and no training on customer data, that data sits in a segregated database on AWS, and that access is set per user or role with SSO and SAML. These are policy statements: the Terms of Service contain no confidentiality clause protecting customer content, the Financial Services FAQ says the model tunes to each firm's risk posture from its team's decisions, and privilege and work product are not addressed. Flagged for sampling. Verified 18 September 2026.

Luthor
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Real written commitments, with the confidences peculiar to legal work left unaddressed. The Terms of 07.11.25 carry a mutual confidentiality obligation with reasonable care and the ordinary exceptions, leave the customer owning its data outright, and commit to deleting all customer data within thirty days of termination. The security page adds AES-256 at rest and TLS 1.2+ in transit with keys held in a rotating key management service, per-organisation isolation with data never co-mingled across customers, access confined to authorised users within the account, and a statement that submitted content is not retained by model providers. Three things keep this short of the top. Privilege and work product are never mentioned, on an estate that sells to legal teams. No model provider is named, so the retention commitment made on their behalf cannot be checked against anyone. And the training position lives on a policy page while the Terms grant a licence to use customer data to provide and improve the Services. Verified 20 September 2026.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Blee
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

A real position on what the tool is and who decides, short of an advice-line statement or supervision guidance, which is the B band. The consumer brands and life sciences FAQs say a person always decides, that approval stays with the customer's legal, regulatory and brand (or medical) reviewers, and that the system supports their judgement and does not replace it. What is missing: no surface says flags are not legal advice, although the AI explains the reason for each flag to marketing staff so they can fix straightforward issues before legal or compliance reviews the asset, and nothing addresses how reviewing lawyers should supervise that first pass or which jurisdictions' rules are covered only on request. The Terms of Service disclaim warranties generally. Flagged for sampling. Verified 18 September 2026.

Luthor
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Nothing published addresses the advice line, on a product whose whole function is telling people what a regulation requires. The Regional Bank study of 8 December 2025 sets out the shape: a loan officer or a marketer uploads an ad and the system returns pass or fail, the rule that was hit and what to change — Regulation Z trigger terms and the disclosures they require, the loan officer's and company NMLS identifiers, state licence lines, the Equal Housing legend, wording in builder co-marketing that could imply a referral arrangement. The home page shows the same thing, calling a return guarantee a FINRA 2210 problem and offering the disclosure to add. No statement that this is not legal advice appears anywhere, including the Terms of 07.11.25, which disclaim warranties and outcomes and say nothing about advice. Nothing addresses the competence or supervision of the lawyer or compliance officer who owns the judgement, and no jurisdiction limit is named. Checked the home page, both solutions pages, the Financial Services page, the security page, the Terms, the Privacy Policy and both case studies on 20 September 2026. Verified 20 September 2026.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Blee
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

A customer-facing configuration process is described without a governance mechanism, which is the C band. The vendor says its legal engineers build each customer's rules from regulations, internal guidelines and risk tolerance, that the model tunes to the customer's decisions, and that each flag is explained. No accountable owner, pre-release testing regime or disclosure of uneven performance across content types, languages or media is published. Verified 18 September 2026.

Luthor
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

No governance position is published about this vendor's own models. There is no statement of who inside Luthor owns model behaviour, nothing on what is tested before a change ships, and nothing on whether output differs across content types, channels, or the populations an advertisement reaches. The estate publishes a good deal of governance material aimed the other way: guides telling regulated firms how to govern AI agents used in marketing review, test the AI, define reviewer authority, require a rationale for overrides, monitor drift and preserve evidence. That is advice to buyers about their own programmes, not a commitment about the product they would be buying. The one mechanism on the product side is the provenance carried on every review, which shows a reader what was flagged and why; that is an output explanation rather than governance over the model, and it is recorded on the oversight row. Read across the home page, the security page, both solutions pages and the resources library. Verified 20 September 2026.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Blee
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Most of the ground is covered in published policy, short of a readable subprocessor list or a retention period for content, which is the B band. The security page states AES-256 encryption at rest, TLS in transit, a segregated database on AWS, zero-retention agreements with AI providers, least-privilege access by user or role, WORM storage meeting SEC and FINRA requirements where needed, and regular third-party penetration testing. The Privacy Policy commits to notify a personal data breach within 15 days and to delete personal information within 60 days of a request. How long Blee keeps submitted content and review records is not stated, and the list of third-party service providers in the Terms and Privacy Policy is an image that could not be read. Verified 18 September 2026.

Luthor
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Most of the ground is covered in published detail, with one clear gap. The security page states AES-256 at rest and TLS 1.2+ in transit with automatic key rotation, per-organisation data isolation, role-based access with multi-factor authentication and single sign-on through OAuth or SAML, immutable audit logs of who did what and when retained to the SEC's 17a-4 requirements, automated vulnerability scanning, DDoS protection and continuous monitoring, and a documented incident response plan with severity levels, escalation paths and notification of affected customers within regulatory timeframes. Processing and storage are stated to be in the United States. The Terms commit to deleting all customer data within thirty days of termination. The gap is the subprocessor list: none is published, and the vendor's own trust centre records zero subprocessors and zero documents. Nothing states how long submitted content is held during the term. Verified 20 September 2026.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Blee
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

Liability is addressed only by standard limitation, which is the C band. The Terms of Service disclaim all warranties including accuracy and reliability, exclude indirect and consequential damages, cap liability at one times the payments received, require the customer to indemnify Blee with no indemnity running the other way, and send disputes to individual arbitration with a class waiver and a one-year limit on claims. Nothing addresses a missed flag or an incorrect one. A signed Master Services Agreement supersedes these terms and is not published. Verified 18 September 2026.

Luthor
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

The published position is a standard limitation clause, and it disclaims the exposure this product creates. Section 6 of the Terms of 07.11.25 provides the services as is, disclaims all warranties including fitness for a particular purpose, states that no particular outcome is guaranteed, excludes indirect, incidental, special, consequential and exemplary damages including lost revenue and goodwill, and caps total liability at the fees paid in the preceding twelve months. Carve-outs run the vendor's way and the customer's alike: personal injury or death, fraudulent misrepresentation, intellectual property infringement and anything that cannot be limited by law. No indemnity of any kind is offered to the customer, and nothing addresses the loss a buyer actually fears here, which is an advertisement that cleared review, went to the public, and drew a regulator. Warranty of effort is offered instead: commercially reasonable efforts to minimise errors and interruptions. Verified 20 September 2026.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Blee
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Named connections with what they carry described, short of documentation, which is the B band. The industry pages say submissions arrive from Jira, Workfront, Wrike, WorkZone, Asana, Monday.com or the customer's own portal through APIs and webhooks, and that feedback appears inside Google Docs, Microsoft 365, Adobe Creative Cloud and Figma; partners and franchisees submit in their own spaces. The integrations pages list project management tools (Jira, Asana, Monday.com, Airtable, Notion, Workfront, Wrike), design and document tools (Figma, Adobe, Frame.io, Google Workspace, Microsoft Office), storage (Google Drive, Dropbox, OneDrive) and channels (Slack, Teams, Chrome and the major social networks) as logos. Integration documentation is offered in a meeting rather than published. Verified 18 September 2026.

Luthor
DD on Practice Systems Integration DepthNo integration into practice systems located, or the product stands alone and requires work to move to it.

No integration into the systems legal and compliance work already lives in is named anywhere on the estate. What is published is ingestion by format and channel — text, images, video, audio, SMS, social posts, PDFs, email drafts, rate sheets and live web pages — and monitoring of published content after it goes out. The Regional Bank study describes the position it replaced rather than one it connects to: reviews that had been running through email chains, Asana tasks, shared drives and design folders moved into Luthor's own upload and vault. No document management, matter management, marketing automation, social publishing or archiving system is named as a connection, no directional sync is described, and no developer or integration documentation is published. Immutable retention to the SEC's 17a-4 standard is offered inside the product rather than through an archiving partner. Read on the home page, both solutions pages, the Financial Services page and the two case studies. Verified 20 September 2026.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Blee
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

The hosting model and region are stated, without the AI processing location, which is the B band. The security page says data is stored in a segregated database built on AWS, and the Privacy Policy says Blee's servers or hosting partners are in the United States, with EU transfers under Standard Contractual Clauses. Where the third-party AI providers process content, and whether other regions are offered, is not stated. Verified 18 September 2026.

Luthor
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Both halves are stated plainly, and neither is offered as a choice. Tenancy: each organisation's data sits in a siloed environment, isolated from other customers and never co-mingled, with access limited to authorised users inside the account. Region: the security page says the platform runs on SOC 2 certified cloud infrastructure in the United States and that all processing happens in controlled environments with network isolation and continuous monitoring, so storage and processing are answered together rather than left apart. What is not published is any option. No single-tenant, private or on-premises deployment is described, no second region is offered, no cloud provider is named, and nothing says what changes between tiers, because no tiers are published. For a buyer with data outside the United States, the international transfer clause in the Privacy Policy points to standard contractual clauses and nothing further. Verified 20 September 2026.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Blee
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

A named attestation without scope, date or a published route to the report, which is the B band. The security page and site footer state SOC 2 Type 2 compliance and regular third-party penetration testing, and the page offers to walk buyers through security practices and share documentation in a meeting. No auditor, period, scope or trust centre is published. Verified 18 September 2026.

Luthor
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

The vendor names a standard, and its two surfaces name different levels of it. Four product pages carry a SOC 2 Type II Compliant badge with a line that the company is independently audited and certified on a continuous basis, alongside GDPR compliance, SEC 17a-4 readiness and regular third-party penetration testing; the security FAQ says the SOC 2 Type II report goes to customers and prospective customers under an NDA, requested through the trust centre. The trust centre at trust.inc/luthor, linked from those same pages and read on 20 September 2026, records SOC 2 Type 1, two frameworks, and zero policies, zero subprocessors and zero documents behind a request-access button. Both are the vendor's own, both are recorded here with their surface and date. What a buyer can reach is a named standard at a stable address and a route to ask for the report. What is not published anywhere is the audit period, the scope of the examination or the auditor, and nothing on the portal is shown to be obtainable. Verified 20 September 2026.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Blee
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The vendor refers to third-party AI providers and customer-specific agents without identifying the models, which is the C band. The security page says enterprise agreements with third-party AI providers bar training and retention and that Blee builds AI agents specifically for each customer, and the Financial Services page contrasts Blee's tuned model with a general-purpose one. No model or provider is named: the LLM integration category lists Claude, ChatGPT, Gemini and Cursor as tools Blee reviews content from, not as the models it runs on, and the list of third-party service providers in the Terms is an image that could not be read. Nothing commits to notice of model changes. Verified 18 September 2026.

Luthor
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The vendor commits on behalf of model providers it never names. The security page states that submitted content is not retained by model providers or used for training, and describes model provenance among the layers it protects, but no provider, model or version appears anywhere on the estate, and nothing says where inference runs beyond the statement that processing happens on US cloud infrastructure. The architecture is described only in categories: natural language processing for context, machine learning classification, and large language models generating the written output. No subprocessor list is published and the trust centre records none, so the chain cannot be reconstructed from another surface either. Nothing commits to telling customers when a model or provider changes. For a buyer in a regulated industry the practical effect is that the zero-retention promise cannot be checked against the party who would have to keep it. Verified 20 September 2026.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Blee
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing information is published at any level, which is the D band. The Terms of Service say access carries a yearly subscription fee, which is a billing period rather than a unit of charge, and every product and industry page leads to a meeting or demo request. No tiers, units or rates are published. Verified 18 September 2026.

Luthor
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Nothing about cost is published, including the unit being charged. There is no pricing page and no pricing link in the footer; every route ends at a demo request, and the demo page offers help with pricing and plans without naming a plan. The ROI calculator models savings against what it calls the Luthor investment and says only that the investment varies by review volume, policy coverage, workflow complexity and implementation scope, which names the things that move the price and neither a rate nor a unit. The Terms of 07.11.25 refer to fees payable under an applicable Subscription Form for a subscription term, which fixes a billing period rather than a unit of charge, and the liability cap is expressed as the fees of the preceding twelve months without saying what those fees buy. No tier names, no feature splits, no implementation figure, and nothing on what an enterprise agreement adds. Verified 20 September 2026.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Blee
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Segments and the regulatory frameworks covered are described with substance, short of stated limits, which is the B band. The vendor serves legal, compliance, risk and brand teams alongside marketing and operations, and its five industry pages name the rule sets it ships: for financial services UDAP and UDAAP, Regulation Z, Regulation DD, FDIC and NCUA advertising rules, FINRA Rule 2210, the SEC Marketing Rule and Regulation Best Interest; for insurance the NAIC model rules and all 50 states' advertising requirements, FCA financial promotions and Consumer Duty rules and ASIC guidance; for life sciences FDA promotional rules, the ABPI/PMCPA code and national codes in Germany, France, Italy, Spain and Singapore; for consumer brands FTC, NAD, ASA, FDA labelling rules and Proposition 65; for travel drip-pricing rules, the EU Package Travel Directive and ADA accessibility claims. Every page invites buyers whose regulation or market is missing to ask, saying it is covered or will be built, so no limit is stated. Verified 18 September 2026.

Luthor
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Who this is for is described with real substance, and where it stops is not. Two buyer pages name the users: legal and compliance teams who review, and the marketing teams whose work they submit. Four industry pages name the segments: asset managers, registered investment advisers and broker-dealers; banks and credit unions; mortgage and consumer lenders; and consumer-regulated industries including food, pharmaceuticals, alcohol and tobacco. The subject matter is equally specific — the SEC Marketing Rule, FINRA 2210, ADV Part 2, Regulation Z, NMLS and state licensing, RESPA, UDAAP and FTC advertising rules — and the named customers sit in three of the four segments. What is absent is the boundary. Nothing says which regimes are not covered, nothing describes the position of a law firm reviewing its own advertising, and the claim that rules can be configured for any regulatory framework is made without an example of one built outside the published list. Verified 20 September 2026.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Blee
Permitted, in policy only

Public material says the customer's own review decisions tune the model, with no matching term in the published agreement. The Financial Services FAQ says the model tunes to each firm's risk posture from its team's decisions, and the security page says each customer's AI agents improve with every comment and review. The same page says enterprise agreements bar Blee's third-party AI providers from training on customer data.

The Terms of Service say nothing on training, and whether one customer's decisions inform another customer's agents is not stated.

Luthor
Permitted, in policy only

The estate says two different things and the more specific one describes training. The security FAQ answers the question flatly: customer data is never used to train, fine-tune or improve any AI model, and submitted content is not retained by model providers or used for training. The PCM Encore case study of 28 October 2025 describes the opposite behavior in that firm's deployment, a continuous-learning loop that captured every human override with the model re-training nightly and precision improving week over week.

A described behavior carries further than a general assertion, so this records the training as it is described. Two limits on how far that goes: nothing suggests one customer's overrides reach another customer's model, and cross-customer use is not stated either way. The Terms of 07.11.25 never mention training and grant a license to use customer data to provide and improve the Services, so the contract settles nothing here.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Blee
Disclosed without a period

Retention is acknowledged without a period. The platform keeps every draft, flag, version and approval as a system of record, with WORM storage available for SEC and FINRA requirements, and the security page says AI providers retain nothing under zero-retention agreements. No period for Blee's own retention of submitted content or review records is stated; the Privacy Policy covers only deletion of personal information within 60 days of a request.

Luthor
Disclosed without a period

Retention is addressed at both ends and left open in the middle. At the model provider, the commitment is zero: submitted content is not retained there. At the end of the relationship, the Terms of 07.11.25 commit to deleting all customer data within thirty days of termination, subject to retention laws. Between those two points nothing states how long Luthor itself holds submitted content, review output or the drafts that failed, and no setting is offered to a customer who wants a shorter window.

The product pulls the other way by design: audit logs are immutable and retained to the SEC's 17a-4 requirements, and one customer's deployment keeps an archive of approved assets for state examinations. A buyer who needs a defined retention period for content held during the term will not find one published.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Blee
Own model, documented

The product keeps its own permission model and describes how it separates users. Partners, franchisees and agencies work in their own spaces with their own permissions and see their own submissions and feedback but never the customer's internal comments; each partner, product and market can carry its own rule set so one partner's requirements never apply to another's content; and access is set per user or role with SSO and SAML.

Luthor
Own model, documented

Separation is documented at the organization level and configurable within it. Each organization's data sits in its own siloed environment, is never co-mingled with another customer's, and is reachable only by authorized users inside that account. Inside the account the controls are described rather than claimed: role-based permissions, multi-factor authentication, single sign-on through OAuth or SAML, and an audit log of every action with who did it and what changed.

One customer's deployment shows what that buys in practice — the field could submit and correct but only compliance could override a finding, and the archive produced for a state examiner carried the approved assets without internal comments or rejected drafts. What is not addressed, because the product is not built around matters, is any wall between one piece of work and another inside the same organization.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Blee
Notice committed

Notice is committed, within a limited scope. The Privacy Policy's EU Standard Contractual Clauses section commits Blee to notify the data exporter promptly of a legally binding law-enforcement request for personal data unless prohibited. Its general disclosure clause says Blee will disclose personal information to comply with a court order, law or legal process, including government or regulatory requests, with no notice commitment, and neither provision addresses customer content as distinct from personal data.

Luthor
Notice committed

A notice commitment exists and its scope is narrower than it first looks. Section 4 of the Terms of 07.11.25 lets either party disclose the other's confidential information where law or regulation requires it, provided notice is given where that is legally permissible. That is a real commitment, it is mutual, and it sits in the agreement rather than a policy page. It attaches to confidential information under that clause, and the Privacy Policy of 08.31.26 takes a different line for personal information, listing disclosure to authorities in response to legal requirements with no notice attached to it.

Nothing published describes what happens operationally when a demand arrives — no named contact, no stated practice of challenging or narrowing a request, no commitment to a timeframe — and no transparency report is published.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Blee
Sources named, basis unstated

The regulatory sources behind the shipped rule sets are named, without a stated basis or update cadence. The industry pages name the rules each set covers, among them UDAP and UDAAP, Regulation Z, FINRA Rule 2210, the SEC Marketing Rule, the NAIC model rules, FDA promotional rules, the ABPI/PMCPA code and FTC advertising rules, and credentials are checked against BrokerCheck and CFP Verify. The pages say the rule sets are kept current as rules change without saying how or how often.

Luthor
Sources named, basis unstated

The rules the system checks against are named; where the rule content comes from is not. Published coverage runs to the SEC Marketing Rule, FINRA Rule 2210, ADV Part 2, Regulation Z, NMLS and state licensing lines, RESPA, UDAAP, FTC truth-in-advertising, GDPR, CCPA and CPRA, CAN-SPAM and TCPA, alongside FCA for firms that need it. The other half of the corpus is the customer's own: policies, past decisions, brand guidelines, approved claims, product specifications and historical claims, plus a knowledge base the system checks assertions against.

Nothing states who writes the regulatory rule content, how it is kept current as rules change, or on what basis any licensed source is used; the vendor's policy and legal engineers are described as building rule sets with each customer. One customer built more than sixty custom rules of its own.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Blee
Not addressed

Searched the Terms, Privacy Policy, home, Content Reviews, Security, Integrations and all five industry pages on 18 September 2026. The product flags marketing content against rules and does not cite case law, so no subsequent-history check arises and none is described.

Luthor
Not addressed

This product cites no authority a reader could check, so there is nothing for a treatment signal to sit on. Flags name the rule behind them — a return guarantee against FINRA 2210, a trigger term against Regulation Z — but the output is a finding and a fix rather than a citation to primary text, and no linked source accompanies it. The nearest question, whether the rule the system applied is still the current one, is answered on the customer's side: rules can be added, updated or overridden as regulations change, and the vendor publishes regulatory updates on its blog.

Nothing published describes how the shipped rule content is maintained against amendments, who reviews it, or how a customer would learn that a rule it relies on has moved.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Blee
Not addressed

Searched the same surfaces on 18 September 2026. Flags are prioritized by the customer's frameworks and carry a risk level, and each is traced to a rule and location, but no confidence score, abstention path or behavior when the AI cannot decide is described.

Luthor
Confidence signal only

Uncertainty is expressed as a risk level, and nothing describes what happens when the system cannot tell. Assets come back banded — low, moderate or high risk — and routed accordingly: pre-cleared, needing review, or escalated, with one industry page illustrating the split as roughly three quarters pre-cleared, a fifth flagged and the remainder escalated. Risk thresholds and escalation criteria are among the things a customer encodes, so where the bands fall is the customer's decision rather than the vendor's. What is missing is any statement that the system says so when it has no basis for a judgment: no published behavior for a claim it cannot substantiate, no abstention, and no description of what a reviewer sees when confidence is low as distinct from when risk is high. The two are not the same and only the second is described.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

Blee
None located

Searched the AI Hallucination Cases database maintained by Damien Charlotin and trade press reporting on 18 September 2026 for court records addressing fabricated or hallucinated content in output from Blee. None located. This signal does not record litigation history of any other kind.

Luthor
None located

No record was located of this product's output being found fabricated or inaccurate in a proceeding, a regulatory action or a published account. Searches on 20 September 2026 across the vendor's estate, press coverage and directory profiles returned nothing of the kind. The exposure this product carries is a different one from the fabricated-citation problem in litigation tools: it does not draft legal assertions or cite authority, and the harm a buyer should worry about is a violation the review missed rather than a source it invented. Nothing published describes such a miss, and no customer account of one was found.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Blee
Not addressed

Searched the same surfaces on 18 September 2026. The vendor names the advertising and marketing regulations its rule sets apply, which are the subject matter of the review, but no ethics opinion, court AI order or rule, or judicial or bar guidance on AI.

Luthor
Not addressed

No rule of professional conduct, ethics opinion or bar guidance is named anywhere on the estate, and professional responsibility is not referred to in general terms either. The regulation this vendor engages with in depth binds the firm advertising rather than the practitioner reviewing: the SEC Marketing Rule, FINRA 2210, Regulation Z, NMLS licensing, RESPA, UDAAP and FTC advertising rules. Nothing addresses the duties of the lawyer or compliance officer who owns the judgment the product informs, and the Terms of 07.11.25 carry no statement that no legal advice is given and no professional relationship is created.

The closest material sits in buyer-facing guides about governing AI in review workflows, which discuss reviewer authority and override rationale as program design rather than as professional obligation. Checked the home page, both solutions pages, the Financial Services page, the security page, the Terms, the Privacy Policy, the resources library and both case studies.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Blee
Outside the fee relationship

The product is bought by in-house legal, compliance and brand teams reviewing their own company's marketing, where no client is billed for the work. Savings are claimed for the buyer's own cost, including Rocket Mortgage's initial review time falling from 72 to 24 hours and review times cut by up to 65 percent in the funding release.

Luthor
Outside the fee relationship

This product sits outside the relationship between a lawyer and a paying client. Its buyers are in-house legal and compliance functions and the marketing teams they review, its work never reaches a client bill, and no fee is charged onward for anything it produces. The published economic case is internal: reviewer hours redirected from first-pass checks to edge cases, approvals arriving in minutes rather than days, and a calculator that models year-one savings against a firm's current manual review baseline.

The cost of the tool itself is not published in any form. Nothing here bears on how a fee is disclosed to a client, because no client fee is in the path.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Blee
Not recorded
Luthor
On request only

The diligence materials exist behind a request and almost nothing is published. The trust center linked from the product pages carries a request-access button and a security questionnaire, and the security FAQ says the SOC 2 report goes to customers and prospective customers under an NDA. Read on 20 September 2026, that trust center records zero policies, zero subprocessors and zero documents, and it states SOC 2 Type 1 where the product pages state Type II.

So a buyer working through an outside counsel guideline checklist can obtain the pack by asking and can verify none of it in advance: no subprocessor list, no named model provider, no penetration test summary, no audit period or scope. What is published without asking is the security page's control description and the confidentiality, deletion and terms.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Blee
Partial record

Part of a verification record exists, short of a document-level AI disclosure record. The audit trail logs each asset's flags, versions and approvals, and the Financial Services page says it is searchable when an examiner asks. Nothing records which model produced a flag.

Luthor
Partial record

The record this product produces is built for an examiner rather than a court, and read through that reader it is real but partial. Every review carries provenance showing what was flagged, which rules applied and the reasoning behind each decision; rule hits, edits and approvals are timestamped and described as exportable for regulators; audit logs are immutable and retained to the SEC's 17a-4 requirements. One customer's deployment shows the export in use: a state-specific set of approved advertisements produced in minutes for a state examination, carrying date, submitter, channel and states of distribution, and excluding internal comments and rejected drafts.

What is not published is any description of the export as a disclosure of AI involvement — no statement of which output the model produced as against the human edit, no format, and nothing addressed to a tribunal. No court sits in this product's path.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • Commercial Transparency
Signals neither addresses in public material
  • Good Law Verification
  • Bar Guidance Alignment

Which one fits

Choose Blee if

  • You want each flag explained to the person fixing it. Blee shows every flag with its rule, its location on the asset and an explanation, checked against your source of truth, such as an APR in an ad compared with your stated rate under Regulation Z.
  • Your creative work runs through project and design tools. Blee takes submissions from Jira, Workfront, Wrike, Asana and Monday.com through APIs and webhooks, and shows feedback inside Google Docs, Microsoft 365, Adobe Creative Cloud and Figma.
  • You review content beyond financial services. Blee ships rule sets for financial services, insurance, life sciences, consumer brands and travel, including FINRA Rule 2210, the NAIC model rules, FDA promotional rules and the EU Package Travel Directive, and also monitors live sites and partner content.

Choose Luthor if

  • You want the confidentiality and deletion promises in the contract. Luthor's terms carry a mutual confidentiality obligation, leave the customer owning its data, and commit to deleting all customer data within thirty days of termination.
  • Your examiners expect records kept to SEC standards. Luthor keeps immutable audit logs of rule hits, edits and approvals retained to SEC Rule 17a-4 requirements, and one customer produced a state specific set of approved ads for an examination in minutes.
  • You run a mortgage or wealth management marketing program. Luthor publishes rule coverage for the SEC Marketing Rule, FINRA Rule 2210, Regulation Z, NMLS and state licensing lines and RESPA, with dated case studies from a named wealth manager and a regional mortgage lender.

In summary

Blee

Blee, from Blee, Inc. of New York, is an AI marketing compliance platform for legal, compliance and risk teams that review marketing, product and sales content. Its Content Reviews product runs an AI first pass over anything from tweets to long videos and Figma mockups, flags regulatory risks, missing disclosures and unsubstantiated claims against rule sets built with each customer, and routes each asset to a reviewer; Content Monitoring scans live sites and partner content. The AI Legal Index grades it in the top two bands on eleven of fifteen capability axes, with an A on autonomy and oversight. It names Rocket Mortgage, NerdWallet and Betterment among customers and states SOC 2 Type 2. As of 18 September 2026 the index located no named model provider or price.

Source: AI Legal Index, 2026

Luthor

Luthor, from Luthor, Inc. of San Francisco, is an enterprise marketing compliance platform for legal and compliance teams in regulated companies and the marketing teams they review. Content from text to video, SMS and live URLs is reviewed by AI against customer configured rule sets covering the SEC Marketing Rule, FINRA Rule 2210, Regulation Z, RESPA and FTC advertising rules, with provenance on every review and timestamped records for examiners. The AI Legal Index grades it in the top two bands on eight of fifteen capability axes, with an A on AI centrality. It publishes dated case studies from a wealth manager and a regional mortgage lender and processes in the United States. As of 20 September 2026 the index located no named model provider, integration or price.

Source: AI Legal Index, 2026

Questions buyers ask

Blee vs Luthor: which is better for marketing compliance review?

Blee sits in the top two bands on eleven of fifteen AI Legal Index capability axes and Luthor on eight of fifteen, identical on nine. Blee publishes more on how flags are explained, who decides and which tools it connects to, and covers more industries. Luthor's terms carry stronger confidentiality and deletion commitments. Teams in financial services will find detailed rule coverage from both.

Does a person approve content reviewed by Blee?

Yes, by Blee's own statement. Its FAQs say a person always decides: Blee runs the first pass and approval stays with legal, regulatory and brand reviewers, and in life sciences with medical, legal and regulatory reviewers. Each flag shows its rule, location and explanation, and every decision is logged. Monitoring flags are routed without a stated review step. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

Do Blee and Luthor train AI on customer content?

Both describe customer review decisions shaping their models. Blee says its model tunes to each firm's risk posture from its team's decisions, and its AI providers are barred from training. Luthor's security page says customer data never trains any model, while its PCM Encore case study describes a model retrained nightly on reviewers' overrides. Neither published agreement addresses training. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

Which regulations do Blee and Luthor cover?

Both cover the SEC Marketing Rule, FINRA Rule 2210, Regulation Z and UDAAP. Blee also ships rule sets for insurance, life sciences, consumer brands and travel, including FDA promotional rules and the EU Package Travel Directive. Luthor lists NMLS and state licensing lines and RESPA for lenders, and lets customers configure rules of their own. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

What do Blee and Luthor both leave unpublished?

The model and the price. Neither names the AI model or provider it runs on, so their promises that providers keep nothing cannot be checked against a named party. Neither publishes a price or unit of charge, and neither states what its AI does when it cannot decide whether content breaks a rule. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

Disclosure

Three readings to weigh. The outside counsel guideline readiness signal has not been recorded for Blee; that is a gap in the record, not a finding about the vendor. Luthor's product pages state SOC 2 Type II while its trust center, read on 20 September 2026, records SOC 2 Type 1. Blee's accuracy figure of 85 to 95 percent and Luthor's case study figures come without a stated method. Blee was verified on 18 September 2026 and Luthor on 20 September 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 24, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746