Brightflag vs BusyLamp: how they compare in 2026
Brightflag and BusyLamp both sell legal departments a system for receiving and reviewing outside counsel invoices, and both sit inside larger groups, Brightflag under Wolters Kluwer and BusyLamp under Onit. The difference is where the AI works. Brightflag's own model reads and classifies every invoice line, and a rules engine checks it against the department's billing guidelines, with invoice summaries and Ask Brightflag on top. BusyLamp's AI converts incoming invoice PDFs into LEDES files with UTBMS codes, and review against guidelines, budgets and work in progress runs around it. BusyLamp is built for European departments, with VAT, German electronic invoice formats and Germany's statutory fee table, and customers choose hosting in the United Kingdom or Germany. Brightflag hosts data in Ireland, the United States or Australia by customer location, names AI21 Labs and Anthropic for its generative features and offers an intellectual property indemnity on their output. BusyLamp's conversion runs through OpenAI in the United States. Neither lists prices.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Brightflag was founded in 2014 on machine learning that reads legal invoices, and that model sits at the center of the product. A supervised model, refined on labeled invoice text for more than a decade, reads every line item narrative and classifies it by phase of work and activity on an extended UTBMS framework. A rules engine then checks each line against the customer's billing guidelines and flags violations, rate discrepancies and duplicate entries before a reviewer opens the invoice. Generative features sit on top of that core. AI invoice summaries arrive in approval emails, Ask Brightflag answers questions about spend data, spend forecasts predict budget overruns, AI built vendor profiles support panel management and RFPs, and generative AI produces matter summaries. Workflow, budgets, accruals, matter management and reporting surround the AI, and approved invoices flow to accounts payable. Without the classification model, Brightflag would be a conventional electronic billing system.
AI sits at one step of a billing workflow that runs without it. The Smart Invoice Converter reads an invoice PDF and produces a LEDES file with UTBMS codes and timekeepers, using OpenAI in the United States. Since the August 2026 release, client administrators can require law firms to submit LEDES invoices only through the converter. Onit's product update for that month lists a new AI invoice extraction engine and better validation of converted invoices. The December 2025 release let legal teams run the converter themselves on behalf of law firms. A support chatbot from Maven AGI is the other AI component. Review against billing guidelines, approval workflows, budgets, accruals, work in progress, rate approval, RFPs, reporting and the dashboard all run without AI. Onit's AI Studio products, Spend Agent, ReviewAI and Olava, are separate, and Spend Agent works inside OnitX ELM and Unity ELM rather than BusyLamp.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Brightflag's flags trace to evidence a reviewer can open. Each flag ties an invoice line to the billing guideline rule it breaks, and the reviewer sees both on the invoice review page. Brightflag's internal analysts supervise the classification model, reviewing cases where it is not yet confident in its interpretation and feeding corrections back to it. Ask Brightflag answers only from the organization's own spend data, and a filter explainer shows how it interpreted each question, so a user can check that the results match the query. Users report a wrong answer with a thumbs down for Brightflag's team to investigate. The generative AI terms say outputs are produced probabilistically, may not always be accurate and should not be relied on as a sole source of truth. Brightflag's FAQ says LEDES and PDF invoices are processed with equal accuracy, and the figures it publishes are savings and returns from a Forrester study rather than accuracy rates.
The converter extracts billing data rather than making legal assertions, so there are no citations to ground. No accuracy figure or error rate accompanies it. Onit's product page describes AI driven validation that reduces errors and built in checks that cut review effort. The converter extracts, validates and enriches invoice data before a law firm reviews and corrects the LEDES file. Errors on submitted invoices, such as rate, tax or duration breaches, open on an invoice validation screen for the legal team. Section 12.3 of Onit's Subscription and Services Agreement says Onit cannot guarantee that outputs will be 100 percent accurate. It adds that machine generated output may be incomplete, inaccurate or biased.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
In Brightflag the AI reviews and a person, or a rule the customer sets, approves. Invoices route by matter, value or practice area to designated approvers, and approving from an email summary does not bypass workflow rules. Customers can configure automatic approval for invoices that meet set criteria, and the FAQ says most customers auto approve invoices under $5,000 with no guideline violations, which can be about 30 percent of invoices. Invoices that fail set criteria can be rejected automatically. Flagged lines go to the customer's reviewers, and lines the model is not confident about go to Brightflag's own analysts. Approved invoices flow to accounts payable, and approvals sit in an audit trail. The MCP connector is read only, so approvals, edits and rejections happen inside Brightflag. The generative AI terms leave the customer to decide where human review is appropriate and bar using the features to automate decisions with a legal or material impact on an individual.
A person stands between the converter and an approved invoice. Law firm users with the Billing Manager role run the Smart Invoice Converter, which produces LEDES files for review and correction before submission, and client administrators can require that route for every LEDES invoice. Once submitted, invoices pass validation against the customer's rates, taxes and billing guidelines, and errors surface on a validation screen. Approval workflows are scoped by matter criteria with thresholds per currency, and designated releasers handle release, approval and paid status. Section 12.3 of Onit's services agreement makes the customer solely responsible for review of and reliance on AI output, and section 12.7 bars uses that would make the AI high risk under applicable law. Sensitive data needs Onit's prior written approval before it goes into AI features. No confidence signal marks an uncertain line, and what the converter does with a field it cannot read is undescribed.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Brightflag's success stories name the customer and give figures. In the nine months after switching, SMBC's Americas division saved $2.7 million by applying its discount agreements and outside counsel guidelines consistently. It also saved more than 300 labor hours by replacing a Word and email matter opening process with a request form. Lufthansa raised outside counsel guideline compliance by 5 percent in a single quarter and now assigns budgets to more than 80 percent of its matters, up from 20 percent. Syngenta recouped the equivalent of 10 percent of its gross legal spend in the first half of 2021, and Dropbox spends two days less on accruals each month. Each figure is the customer's own account, without a stated method. A Forrester Total Economic Impact study commissioned by Brightflag found a 387 percent return over three years for a composite organization and a 4 percent average saving from billing compliance.
Named customer material for BusyLamp dates from 2021. An Onit blog post of April 2021 quotes Daniel Wate, legal technology analyst at Associated British Foods, on using eBilling.Space to secure volume discounts and consolidate firms. The same post quotes Lynne Kellett, managing legal counsel at EDF UK NNB, whose team implemented it. Neither quote carries a figure. Onit's September 2021 acquisition release said BusyLamp had grown annual recurring revenue by more than 60 percent in twelve months, with customers in automotive, telecommunications and banking. It cited Hyperion Research calling BusyLamp highly innovative and a market leader, and Hyperion's June 2021 report listed it among ten advanced solutions. Today's product page carries an unattributed testimonial from legal counsel at a global financial institution and claims measurable savings without a number. No customer count is given for BusyLamp.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Brightflag's generative AI terms address training for its generative features. Customer data is not transferred to the third party model developers, who cannot and do not use inputs or outputs to train their models, and Brightflag will not fine tune the model instances it operates. Brightflag's own classification model, refined since 2014 on labeled text from actual legal invoices, sits outside those terms, and Brightflag does not name the source of that text. Vendor benchmarking uses data aggregated across Brightflag customers. Data is encrypted at rest with AES 256 under AWS Key Management Service and in transit with TLS 1.2 or higher. Access runs through SAML single sign on, SCIM provisioning and four client roles, from ordinary users who see only their own matters and invoices to administrators, and access can be limited to set IP ranges. Brightflag staff reach customer data only as needed under a role based access policy. Ask Brightflag answers only from the organization's own legal spend data, which its help article presents as keeping that data confidential. The security page and the generative AI terms treat customer data as confidential without separate treatment of privilege or work product.
Onit's Subscription and Services Agreement, last revised 19 August 2026, governs BusyLamp and leaves the customer owning its data as confidential information. Section 12.1 bars third party model providers from using customer input to train their models for the benefit of others, except in deidentified or aggregated form needed to run the service. The same section lets Onit use deidentified, aggregated usage data to improve its AI services, and section 5.2 lets it use customer data, once aggregated and anonymized, for product improvement, analysis and benchmarking. Inside eBilling.Space, administrators, matter scoped project managers and observers hold different rights, and matter fields can be withheld from assigned law firms. Since August 2026 a law firm or lawyer can be blocked globally, and multifactor authentication has been required for all licensed users since February 2026. Privilege, work product and what OpenAI keeps from a conversion go unmentioned, and the tenancy model is unstated.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
Brightflag's generative AI terms state that outputs are not legal, tax or other professional advice or a substitute for it, and may not always be accurate. The customer decides whether outputs suit its use case and where human review is appropriate. The terms bar using the features as a general purpose chatbot, to automate decisions with a legal or material impact on an individual, or for anything that does not directly support the platform's primary functions. Brightflag sells to corporate legal departments, and Ask Brightflag is open only to administrator and overview roles. The billing rules it applies come from the customer's own outside counsel guidelines rather than from Brightflag. The terms set no jurisdiction limits for a product that reviews invoices from firms in many countries.
Section 4.14 of Onit's services agreement states that Onit is not a law firm and does not offer legal advice. Section 12.3 makes the customer solely responsible for review of and reliance on AI output, including obtaining legal or other professional advice as appropriate. BusyLamp's AI converts invoices into billing data and produces no legal analysis. Its buyers are in house legal and legal operations teams, and law firms take part to submit invoices, answer RFPs and correct converted LEDES files. The product carries Germany's statutory RVG fee table, and since May 2026 invoices show which RVG version applies. Jurisdiction limits are unstated, and how the product supports a lawyer's competence and supervision duties is unaddressed.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Brightflag states on its FAQ that it is certified to ISO/IEC 42001, the standard for AI management systems. An article on its site by Michael Dineen, its director of data science, updated in April 2026, says it is among the first legal technology providers to meet the standard. The article says Brightflag has built the standard's principles into its AI product development and internal governance. The FAQ says each AI feature is designed with a confidentiality, privacy and security focused approach. Its security page, which lists ISO 27001, SOC 1 and SOC 2, does not include ISO 42001, and no certifying body, certificate date or scope appears on the open pages. The article lists bias detection and mitigation among the standard's requirements, and Brightflag reports no testing or bias results of its own. The article commits Brightflag to protecting customer data, deploying AI that is transparent, auditable and trustworthy, and improving its AI systems in line with legal and ethical standards. Governance is presented through the certification, without a named owner inside Brightflag.
No AI governance policy covers BusyLamp or Onit's wider product line. There is no responsible AI page, no named owner for model behavior, no description of testing before release and no AI management certification such as ISO/IEC 42001. Section 12 of Onit's services agreement allocates AI risk instead. Output may be incomplete, inaccurate or biased, and uses that would be high risk under applicable law are barred. AI features carry no service levels unless an order says otherwise, and fair use limits let Onit throttle or suspend them. Whether conversion accuracy differs by invoice layout, language or country is unaddressed, although BusyLamp serves law firms across Europe and imports German electronic invoice formats.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Brightflag publishes its security controls and leaves several data handling terms to agreements it signs with each customer. Data retention and deletion are configurable to each customer's requirements, and the privacy notice keeps basic customer account data for six years after a relationship ends. Data is encrypted at rest and in transit, staff access follows a role based access control policy, and the platform is penetration tested by CREST certified testers and scanned for vulnerabilities continuously. Customer data is backed up to AWS data centers as part of business continuity. The privacy notice says all subprocessors, including AI subprocessors, are listed in Brightflag's data processing agreement and in its trust center, which Brightflag opens on request. Brightflag commits to notify customers and regulators of a suspected breach where the law requires it. Customers can track application actions in the product and request fine grained audit logs. Brightflag's 2021 announcement scoped its SOC 1 report to invoice approval and accruals management.
Customers choose hosting in the United Kingdom or Germany, data is encrypted at rest with AES 256, and multifactor authentication has been mandatory for licensed users since February 2026, with authenticator apps added in August. Onit's subprocessor list, updated 17 August 2026, gives BusyLamp its own table of nine processors with purposes and countries. AWS, PlusServer and Hetzner host and back up data, Imperva and Cloudflare protect it, Mailgun and Google Analytics handle email and analytics, Maven AGI runs the support chatbot and OpenAI converts invoices. The data processing addendum, revised 20 April 2026, keeps data for the term of the agreement and defines access rights by duty. It separates test and production systems and keeps an audit trail of data entered, changed or removed. It commits to notify the customer promptly of a security breach, with no number of hours. After termination the customer has 30 days to export, then data is deleted under Onit's retention policy, which is not public, and backup copies may persist.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Brightflag's generative AI terms carry an intellectual property indemnity. If a third party claims an output or a generative feature infringes its rights, Brightflag indemnifies the customer against damages finally awarded by a court, provided Brightflag can defend the claim. The indemnity excludes customer modifications, combination with other technology, customer inputs, known infringement, patented inventions in outputs and trademark use of outputs, and the terms state no cap. Otherwise the features and outputs are provided as is, with accuracy not warranted. Liability caps and exclusions for the platform sit in Brightflag's subscription agreement, which is signed with each customer and not published. The generative AI terms, last updated 6 March 2025, are incorporated into that agreement and take precedence over it for generative features.
Onit's Subscription and Services Agreement, last revised 19 August 2026 and governed by Delaware law, caps liability at the fees paid or payable under the order in the 12 months before the event. Indemnification, payment obligations and liability that law does not allow to be limited sit outside the cap, and consequential, indirect and punitive damages are excluded. Onit defends the customer against intellectual property infringement claims, except where they arise from combinations, customer data, customer designs or use after Onit asks it to stop. It warrants that the services operate substantially as documented. For AI, section 12 provides features and output as is, says Onit cannot guarantee 100 percent accurate output and gives AI features no service level unless an order states one. Liability under the data processing addendum is limited to one times the prior year's fees, and no insurance is described.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Brightflag's integrations page names each connection and what it does. Approved invoices go to Coupa, Workday, NetSuite, Dynamics 365 and other accounts payable systems, with payment statuses returned to Brightflag, and the page also lists SAP Ariba, SAP S/4HANA and Oracle Fusion. The FAQ describes three finance routes, which are email with a cover page, CSV batch files over SFTP on an hourly, daily or weekly schedule, and the API. Integrations with iManage and NetDocuments link matters to document workspaces, and Jira tickets and Xakia intake submissions create matters. Okta and Microsoft Entra handle sign in and user provisioning. Law firms submit LEDES 1998B or LEDES 98BI version 2 files, PDF invoices or global e invoicing XML. An API and an MCP server connect AI tools such as Claude, Microsoft Copilot, ChatGPT and Gemini, and every role and access restriction set in Brightflag applies in the connected tool. The connector is read only, so approvals, edits and rejections stay in Brightflag.
Invoices move as LEDES files with UTBMS codes, and the converter builds them from PDFs for firms that cannot produce LEDES. A December 2024 enhancement called InvoiceConnect added import of XRechnung and ZUGFeRD electronic invoices, and since September 2026 a government invoice number for tax authority cleared invoices appears in exports. Invoices save as PDF or cXML, and reports download to Excel. The product page says BusyLamp connects with accounts payable and ERP systems and on premises single sign on, with OpenAPI integrations for IP, content management, claims and legal hold systems. It names no system and does not describe what moves. Onit's matter management pushes matters into BusyLamp at the click of a button, a feature described in 2023. The services agreement provides APIs as set out in each order, and no public API documentation is available.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Brightflag is cloud software hosted in a multi tenant AWS environment, with data centers in Ireland, the United States and Australia. The data center follows the customer's location and where its data originates, and the privacy notice says a customer can choose to host platform data in the European Economic Area. Websites are hosted in the European Economic Area. Generative features run from Brightflag's own AWS environment, and the terms say data does not leave that environment. The region where generative processing runs for each customer is not stated. Customer data is backed up to AWS data centers for business continuity, a security operations center monitors the infrastructure, and Brightflag publishes a system status page.
Customers choose hosting in the United Kingdom or Germany, with backups in Ireland, under the AWS entry in Onit's subprocessor table. The same table names PlusServer for the German production environment and Hetzner for German backup servers, without explaining how the German setup divides between them and AWS. Invoice conversion runs through OpenAI in the United States, and the support chatbot through Maven AGI in the United States, with no European processing option for either. Transfers out of the EU rely on standard contractual clauses under Belgian law, with a UK addendum, and the data processing addendum names the Belgian Data Protection Authority as supervisor. The tenancy model is unstated, and there is no single tenant or private deployment.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Brightflag's security page lists ISO/IEC 27001:2013 certification and annual SOC 1 Type 2 and SOC 2 Type 2 reports, with SOC 2 covering security, availability, processing integrity, confidentiality and privacy. Its FAQ adds ISO/IEC 42001, which the security page does not list. Encryption keys are managed in AWS Key Management Service. The certificates, independent test reports and security and privacy policies sit in a trust center that Brightflag opens to prospects and customers on request. The open pages give no auditor, report period or certificate date. The security page still cites the 2013 edition of ISO 27001, whose transition period to the 2022 edition ended in October 2025. Penetration tests come from CREST certified testers. Employees take mandatory security and privacy training when they join and during employment, and Brightflag runs regular phishing simulations. It states compliance with GDPR, CCPA and CPRA. Brightflag acts as a data processor for personal data in the platform, and Ireland's Data Protection Commission is its supervisory authority.
Onit's security page says it audits to SSAE 18 SOC 2 Type 2, SOC 1 Type 2 and HIPAA standards, with no auditor, dates or statement that BusyLamp is in scope. BusyLamp's product page cites ISO 27001 and ISO 9001 certified data centers, which describes the hosting providers rather than BusyLamp GmbH. Onit's trust center, built on Vanta, takes requests for its audit reports. The data processing addendum accepts an SSAE 18 report covering the prior twelve months in place of a customer audit. BusyLamp's German data protection officer is K11 Consulting GmbH of Ludwigsburg, named on the product page.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Brightflag's generative AI terms name AI21 Labs' summarization model for invoice summaries and Anthropic's Claude for Ask Brightflag. Both run from Brightflag's AWS environment, data does not leave that environment, and the model developers receive no customer data. The terms say the models may change from time to time and ask customers to check the terms periodically, while Brightflag's promise of notice covers material changes to the terms themselves. The terms, last updated 6 March 2025, list two features, and Brightflag now also markets generative matter summaries, AI built vendor profiles and Ask Brightflag on the invoice review page. Users agree to AI21's Responsible Use Policy and EULA, Anthropic's Usage Policy and Commercial Terms, and AWS's Responsible AI Policy and service terms. Invoice classification runs on Brightflag's own supervised model. No model versions are given.
Onit's subprocessor list names OpenAI, in the United States, as the service that converts BusyLamp invoices into LEDES files, and Maven AGI as the support chatbot. No model name or version is given. Section 12.4 of the services agreement lets Onit improve, replace or deprecate models or prompts without materially reducing core functionality, and no notice attaches to that. Subprocessor changes go out through an email subscription. The services agreement gives customers 15 days to object, while the data processing addendum sets a 10 day notice period for new subprocessors and 30 days' notice to terminate over one.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Brightflag's FAQ sets out how it charges without publishing figures. Customers pay a fixed one time implementation fee and an annual subscription based on their annual outside counsel spend, and quotes are sized to that spend. Upgrades, maintenance, support, ongoing training, additional users or vendors, storage, bandwidth and custom reports carry no extra charge. Average implementation takes six weeks for first time buyers and ten weeks for replacement buyers, according to a Forrester Total Economic Impact study. The same study is the source of the savings figures on Brightflag's pages, including roughly $160,000 a year from billing compliance. Brightflag has no pricing page.
BusyLamp has no public price. Onit has no pricing page, and the product page offers a datasheet and two demo requests, so every route ends in a sales conversation. The services agreement describes how orders work in general terms. Fees are in United States dollars payable within 30 days, usage beyond the order moves the customer to a higher tier, and AI features can carry overage fees at current rates. No BusyLamp rate, unit, tier or implementation cost is stated.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Brightflag sells to corporate legal departments, from high growth companies to global enterprises with complex, multi jurisdictional operations. Its FAQ names technology, financial services, healthcare, manufacturing, energy, consumer goods and education among the industries it serves. Its stories cover SMBC, Lufthansa, Syngenta, Dropbox, Docker, AIB, Ocado and Ironclad. The buyers are in house legal and legal operations teams and their finance counterparts. Brightflag has offices in Dublin, New York and Sydney, hosts data in Ireland, the United States and Australia, and runs tax workflows for North America, Europe and Asia Pacific. The product covers outside counsel spend, matters, vendors, budgets, accruals and reporting. Contract drafting and legal advice sit outside it, and law firms take part only as vendors submitting invoices.
BusyLamp serves European corporate legal departments that manage outside counsel across borders, with VAT, multiple currencies, matter budgets in any currency and an interface in English and German. Law firms use it to submit invoices, answer RFPs and manage their timekeepers' rates, rather than as buyers. German features include the statutory RVG fee table and a government invoice number for tax authority cleared invoices. Onit's 2021 release named automotive, telecommunications and banking customers. Its March 2026 blog groups BusyLamp with Unity ELM, OnitX ELM, SimpleLegal and Legal Files, each still available and supported. Team size and excluded uses are unstated, apart from the services agreement's bar on ITAR controlled data. Support is provided in English under Onit's maintenance terms.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Brightflag's Supplemental Terms of Use for Generative AI Features, last updated 6 March 2025, are incorporated into each customer's subscription agreement and take precedence for generative features. Under them, customer data is not transferred to the third party model developers, who cannot and do not use inputs or outputs to train their models. Brightflag will not use customer data to fine tune the model instances it operates.
The terms cover invoice summaries on AI21 Labs' model and Ask Brightflag on Anthropic's Claude. Brightflag's own classification model, refined since 2014 on labeled text from actual legal invoices, sits outside them, and Brightflag does not name the source of that text. Vendor benchmarking uses data aggregated across Brightflag customers. The terms also bar customers from using the features to build competing products or train competing AI models.
The agreement permits training on derived data. Section 12.1 of Onit's Subscription and Services Agreement, last revised 19 August 2026, bars third party model providers from using customer input to train their models for the benefit of others. The exception is deidentified or aggregated form needed to run the service. The same section lets Onit use deidentified and aggregated usage data to operate and improve its AI services.
Section 5.2 lets Onit use customer data, once aggregated and anonymized so no customer or person can be identified, for product improvement, analysis and benchmarking. No opt out is described. Section 12.7 bars putting sensitive data into AI features without Onit's prior written approval. Onit's product specific terms, revised May 2026, carry no BusyLamp section.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Brightflag's security page says data retention and deletion are configurable to each customer's requirements, and that its retention management keeps records no longer than needed. The privacy notice keeps basic customer account data for six years after a relationship ends, for tax and legal purposes, and profile and support data for the life of the account. The generative AI terms set no separate period for invoice summaries or Ask Brightflag questions and answers, which run inside Brightflag's AWS environment.
Deletion at the end of a contract is governed by the subscription agreement and data processing agreement Brightflag signs with each customer.
Section 12.2 of Onit's services agreement says Onit need not keep or recreate AI output unless a retention feature is provided and switched on. The data processing addendum keeps personal data for the term of the agreement. After termination the customer has 30 days to export, then data is deleted under Onit's retention policy, which is not public, and backup copies may persist. No period applies to invoices sent to OpenAI for conversion or to converted files. Since August 2025 BusyLamp archives work in progress automatically and tracks invoice revisions.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Brightflag keeps its own permission model with four standard client roles. Ordinary users see only matters where they are a participant or internal matter lead, and invoices for those matters or in their approval workflow. Department overview users see only the departments in their profile, overview users see all matters and invoices without admin settings, and administrators see everything and manage configuration. Matter teams control which members can access each matter, and a user without access to a workroom asks the customer's Brightflag administrator to be added.
Email approval works only for invoices at the reviewer's own stage of the approval process. Ask Brightflag is open only to administrator and overview roles, and the MCP connector applies every role, access restriction and data boundary configured in Brightflag. iManage and NetDocuments integrations link matters to document workspaces.
eBilling.Space runs its own permission model, documented in its settings guide. Administrators hold all rights, project managers hold the same rights limited to a specific matter, and observers see matter data without administration rights. Law firm users hold their own roles, and only a billing manager can run the converter. Matter fields can be withheld from assigned law firms, and since August 2026 a law firm or lawyer can be blocked globally from new matters and RFPs, with a firm's block extending to its lawyers. The data processing addendum defines access rights by duty. The tenancy model between customers is unstated.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Brightflag's privacy notice says it may disclose any information to government officials as necessary to comply with laws and orders if compelled. It may answer a request where it believes, in its reasonable discretion, that the request is lawful and disclosure reasonably necessary. It may also disclose personal data to respond to subpoenas, court orders or legal process. The notice states no commitment to tell the customer when that happens.
Brightflag acts as a processor for customer data in the platform, and any notice term would sit in the subscription agreement and data processing agreement it signs with each customer, which stay off its website. Brightflag issues no transparency report.
Section 8.5 of Onit's services agreement commits to reasonable advance notice of a disclosure required by law, where law permits. Section 3 of the data processing addendum commits Onit to notify the customer promptly of a government request for personal data unless data protection law prohibits it. The standard contractual clauses add notice of public authority requests, best efforts to obtain a waiver and periodic aggregate information about requests received.
There is no transparency report. Customer data sits in the United Kingdom or Germany, and invoices sent for conversion go to OpenAI in the United States. The services agreement is governed by Delaware law, and transfers out of the EU rely on standard contractual clauses under Belgian law with a UK addendum.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Brightflag's AI works on the customer's own invoices, matters and billing guidelines, and Ask Brightflag answers only from the organization's own spend data. The vendor management page offers data aggregated across Brightflag customers, while advanced vendor management describes benchmarking and firm performance analysis built entirely from the customer's own invoice history. Brightflag's data science team developed the classification model over ten years on labeled text from actual legal invoices, and its patent covers that model.
The timekeeper rates report draws on Brightflag's database of billions of dollars of analyzed outside counsel spend, broken down by firm size and practice area. Brightflag does not say how that pooled data is anonymized or which customers contribute to it. No primary law collection sits behind the product.
BusyLamp's AI reads the customer's incoming invoices to produce LEDES files with UTBMS codes and timekeepers. It does not retrieve case law or legislation, and UTBMS codes are a billing standard rather than a legal source. InvoiceConnect converts XRechnung and ZUGFeRD electronic invoices, which already carry structured data, with built in validation. Onit's subprocessor list names OpenAI in the United States as the service that performs the conversion, with no model name or version. The training data behind that model is undescribed.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Brightflag reviews invoices against billing guidelines rather than citing case law, so a citator sits outside the product. The rules it applies come from the customer's own outside counsel guidelines, and keeping them current is the legal team's work. Brightflag offers a sample set of outside counsel guidelines as a starting point. Its tax engine checks that the correct tax rates were applied when an invoice is submitted and sends the right tax code to accounts payable.
BusyLamp handles invoices, budgets and spend data and does not cite case law or legislation, so a citator sits outside the product. Billing guidelines are set by each customer and shown to law firms in their own language, with a tab per client. Hourly rates run through an approval workflow with validity periods, and entries off the approved rate are flagged. How a guideline that has gone out of date is flagged is undescribed.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
Brightflag's classification model has a stated route for lines it is unsure of. Brightflag's internal analysts act as expert supervisors, reviewing cases where the model is not yet confident in its interpretation and providing corrective feedback. Ask Brightflag shows how it interpreted each question through a filter explainer, and users report a wrong answer with a thumbs down for Brightflag's team to investigate. Ask Brightflag is open only to administrator and overview roles.
Its help article asks users to confirm that results match the query, such as checking that only rejected invoices appear when they asked for rejected invoices. Brightflag's FAQ says LEDES and PDF invoices are processed with equal accuracy. Customers see flags, summaries and answers without a confidence indicator.
There is no described path for declining a conversion and no confidence indicator on converted invoice lines. The converter extracts, validates and enriches invoice data, and law firms review and correct each LEDES file before submission. What the converter does with a field it cannot read is undescribed. Section 12 of Onit's services agreement says output may be incomplete or inaccurate and leaves review to the customer. Section 12.4 lets Onit change the models or prompts behind AI features without notice.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
The AI Hallucination Cases database maintained by Damien Charlotin, which records court decisions worldwide that address hallucinated AI content and the tool involved where known, has no entry naming Brightflag or Ask Brightflag. Brightflag reviews legal invoices and produces flags, summaries and spend analysis rather than court filings.
The AI Hallucination Cases database maintained by Damien Charlotin, which records court decisions worldwide that address hallucinated AI content and the tool involved where known, has no entry naming BusyLamp, eBilling.Space or the Smart Invoice Converter. BusyLamp converts and manages law firm invoices for legal departments and produces no court filings. Its AI output is LEDES billing data rather than text that cites authority.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Brightflag's material on professional conduct is written for the client paying the bill. Its sample outside counsel guidelines, in a newly updated edition, add a clause giving the legal department visibility into outside counsel's use of AI. Its outside counsel AI strategy guide helps legal teams encourage good use of AI by firms, set guardrails and measure the effect on legal service delivery. The rules Brightflag enforces are the customer's contractual billing guidelines.
None of this material names a bar opinion, such as ABA Formal Opinion 512, or a professional rule on reasonable fees or billing for AI assisted work.
Section 4.14 of Onit's services agreement states that Onit is not a law firm and does not offer legal advice. Section 12.3 makes the customer solely responsible for review and reliance on AI output, including obtaining legal or other professional advice as appropriate. No bar opinion, ethics rule or professional conduct guidance on billing or AI is named. BusyLamp reviews law firm invoices for the paying client, and the fee rules that govern those invoices go unaddressed. Law firms take part to submit invoices, answer RFPs and correct converted LEDES files.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Brightflag is the payer's record of outside counsel fees. Its AI reads and classifies every invoice line, the rules engine flags breaches of the customer's billing guidelines, and reviewers approve, adjust or reject before approved invoices go to accounts payable. Customers can approve invoices automatically when they meet set criteria, such as invoices under $5,000 with no guideline violations. The tax engine itemizes tax jurisdictions, types and rates on each invoice, and each invoice is processed in one currency.
Budgets, accruals and forecasts track spend against plan, and approved invoices go to accounts payable by API, batch file or email. Lufthansa uses the auto reject function so that non compliant invoices no longer reach its in house lawyers. Brightflag's sample outside counsel guidelines include a clause on outside counsel's use of AI, and the guidelines a customer adopts are translated into rules the system checks.
BusyLamp is bought by in house legal departments to receive, convert and review the invoices their outside law firms send, so the record of fees is the product. Invoices arrive as LEDES files with UTBMS codes and timekeepers, are compared with the customer's billing guidelines and approved rates, and are tracked against budgets, accruals and work in progress. Law firms can message the legal team inside eBilling.Space, and work in progress is archived automatically.
Since August 2026 invoices tied to several matters can be processed for more accurate allocation. The product page claims return on investment through automated invoice review and stronger budget control, and measurable savings, without a figure.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
Brightflag's generative AI terms, attached to its help center article, name the model providers a client might ask about. AI21 Labs supplies the invoice summary model and Anthropic's Claude runs Ask Brightflag, both from Brightflag's AWS environment with no data passed to the developers. The privacy notice says every subprocessor, including AI subprocessors, is listed in Brightflag's data processing agreement and in its trust center, which Brightflag opens on request.
Users of the generative features also agree to each provider's acceptable use terms, which the terms list. Certificates, independent test reports and security policies sit in the same trust center.
Onit's subprocessor list, updated 17 August 2026, has a table for BusyLamp that names each processor, its purpose and its country. It includes OpenAI in the United States for converting invoices into LEDES files and Maven AGI for the support chatbot. The data processing addendum and services agreement are readable without an agreement in place, and an email subscription announces subprocessor changes. Customers have 15 days to object under the services agreement, and the addendum accepts an SSAE 18 report covering the prior twelve months in place of a customer audit. Beyond those documents, there is no plain language summary of how the AI uses invoice data.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Brightflag keeps a record of each invoice decision. Flags tie each line to the guideline or rule it breaks, such as a billing rule violation or a rate discrepancy. Approval workflows record each approval, and customers can track application actions in the product and request fine grained audit logs. Brightflag's SOC 1 report, scoped in 2021 to invoice approval and accruals management, tests the controls behind that record.
Each invoice's approval workflow, with its approvers, is visible on the invoice, and email approvals follow the same workflow rules. Ask Brightflag shows how it interpreted each question, and the MCP connector is read only, so outside AI tools cannot change the record. The record covers billing decisions rather than a per document account of which model produced which output. Brightflag's output is invoice flags and spend analysis, which reach a court mainly in a fee dispute.
The data processing addendum requires an audit trail of whether data was entered, changed or removed, and since August 2025 BusyLamp tracks invoice revisions. Invoices save as PDF or cXML, reports download to Excel, and data can be exported in bulk during the 30 day period after termination. Nothing marks which invoice lines the AI converted or records the model used, and there is no disclosure export. BusyLamp's output is billing data rather than court filings.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Primary Law Corpus Provenance
- Good Law Verification
Which one fits
Choose Brightflag if
- You want AI to examine every invoice line. Brightflag classifies each line narrative by phase and activity and checks it against your billing guidelines turned into rules, flagging violations, rate discrepancies and duplicates before a reviewer opens the invoice. Lines the model is unsure of go to Brightflag's own analysts.
- You want the generative models named in the terms. Brightflag's generative AI terms name AI21 Labs for invoice summaries and Anthropic's Claude for Ask Brightflag, run from Brightflag's AWS environment with no data passed to the model developers. They include an intellectual property indemnity on generative output, with no cap stated.
- You want finance systems connected and approvals automated. Approved invoices go to Coupa, Workday, NetSuite, Dynamics 365 and other accounts payable systems, with payment status returned. Customers can auto approve invoices that meet set criteria, such as those under $5,000 with no guideline violations.
Choose BusyLamp if
- Your outside counsel bill across European borders. BusyLamp handles VAT and multiple currencies, carries Germany's statutory RVG fee table, imports XRechnung and ZUGFeRD electronic invoices through InvoiceConnect, and can process invoices tied to several matters. Its interface runs in English and German.
- You need to choose where data lives in Europe. BusyLamp customers pick hosting in the United Kingdom or Germany, with AWS, PlusServer and Hetzner named for hosting and backups. Onit's subprocessor list gives BusyLamp its own dated table of processors and countries, with an email subscription for changes.
- You want the contract terms published before you buy. Onit's Subscription and Services Agreement, data processing addendum and subprocessor list are public. They include a liability cap at 12 months of fees, an intellectual property indemnity, advance notice of compelled disclosure and prompt notice of a government request for personal data.
In summary
Brightflag
Brightflag, founded in Dublin in 2014 and owned by Wolters Kluwer since June 2025, is a legal spend and matter management platform for corporate legal departments. Its core is AI invoice review, in which a supervised model classifies every invoice line and a rules engine checks it against the department's billing guidelines before reviewers approve. Generative features add invoice summaries on an AI21 Labs model and Ask Brightflag on Anthropic's Claude. Brightflag states ISO 27001, SOC 1 Type 2, SOC 2 Type 2 and ISO 42001, and charges an implementation fee plus an annual subscription based on outside counsel spend.
BusyLamp
BusyLamp, owned by Onit since 2021 and run as an independent subsidiary, is an electronic billing and spend management product for European in house legal departments, run in the eBilling.Space application. Law firms submit invoices that are reviewed against billing guidelines and tracked against budgets, accruals and work in progress, with VAT, multiple currencies and Germany's statutory fee table built in. Its Smart Invoice Converter turns invoice PDFs into LEDES files through OpenAI. Onit's services agreement, data processing addendum and subprocessor list govern it, and customers choose hosting in the United Kingdom or Germany.
Questions buyers ask
Brightflag vs BusyLamp: which is better for a European legal department?
BusyLamp is built for European departments, with VAT and currency handling, German electronic invoice formats and fee tables and an English and German interface. Customers choose United Kingdom or German hosting under Onit's published agreements. Brightflag sells to departments across many jurisdictions from Dublin and hosts European data in Ireland. It puts its own AI at the center of invoice review, with named generative models and ISO 42001 certification stated on its FAQ. Neither lists prices. From the AI Legal Index, based on each vendor's own published materials as of October 9, 2026. No vendor pays for placement.
What does the AI do in each product?
Brightflag's AI classifies every invoice line, flags breaches of billing guidelines, writes invoice summaries, predicts budget overruns and builds vendor profiles for panel management. Ask Brightflag answers questions about spend data for administrator and overview users. BusyLamp's AI converts invoice PDFs into LEDES files with UTBMS codes and timekeepers, and the August 2026 release added a new extraction engine and better validation of converted files. A support chatbot from Maven AGI also runs on AI. From the AI Legal Index, based on each vendor's own published materials as of October 9, 2026. No vendor pays for placement.
Do Brightflag and BusyLamp train AI on customer data?
Brightflag's generative AI terms say customer data is not passed to the model developers, who do not train on it, and that Brightflag will not fine tune its model instances on it. Those terms do not cover Brightflag's own classification model, refined since 2014 on labeled invoice text. BusyLamp's governing Onit agreement bars model providers from training on customer input for others, except in deidentified or aggregated form needed to run the service. It lets Onit use aggregated, anonymized data for product improvement. From the AI Legal Index, based on each vendor's own published materials as of October 9, 2026. No vendor pays for placement.
Which models do they use?
Brightflag names AI21 Labs' summarization model for invoice summaries and Anthropic's Claude for Ask Brightflag, run from its AWS environment. Its terms say those models may change from time to time and ask customers to check the terms, and invoice review runs on Brightflag's own supervised model. Onit's subprocessor list names OpenAI, in the United States, for BusyLamp's invoice conversion and Maven AGI for its support chatbot, with no model version. Onit's agreement lets it replace models or prompts without a notice step. From the AI Legal Index, based on each vendor's own published materials as of October 9, 2026. No vendor pays for placement.
What do Brightflag and BusyLamp both leave unpublished?
Neither lists prices or an accuracy rate for its AI, and neither names bar guidance on billing or AI, although outside counsel fees are the subject of both products. Neither commits to notice before a model changes, and neither states how long invoices sent to its models are kept. Brightflag's subscription agreement is not published, and Onit does not publish the retention policy that BusyLamp's deletion terms refer to. From the AI Legal Index, based on each vendor's own published materials as of October 9, 2026. No vendor pays for placement.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything on it comes from public material on the dates shown. How the index grades.
Brightflag's subscription agreement is signed with each customer and not published, while its generative AI terms are attached to its help center. BusyLamp's terms are Onit's, which let Onit use aggregated, anonymized customer data for product improvement and bar third party model providers from training on customer input for others. BusyLamp's invoice conversion runs through OpenAI in the United States. Neither vendor reviewed this page.