Brightflag vs Legal Tracker: how they compare in 2026

Brightflag profileLegal Tracker profile
Last verifiedSeptember 2, 2026

Brightflag and Legal Tracker sell legal spend management to the same in house budget, one built around its models and one a Thomson Reuters platform carrying an AI tier on top. Brightflag sits in the top two bands on seven of fifteen axes, Legal Tracker on three, and the separation is what each publishes about its own AI and its own controls. Brightflag states ISO/IEC 42001 certification for an AI management system alongside ISO 27001, SOC 1 Type 2 and SOC 2 Type 2 prepared across all five AICPA trust categories, and publishes a security page naming AES-256 encryption, a minimum of TLS 1.2, SAML single sign on with its identity providers listed and SCIM provisioning. On Legal Tracker the index could not establish a certification status for the product itself, and recorded that sibling Thomson Reuters products carry separate certifications that do not transfer to it. Legal Tracker answers on scale, with benchmarking drawn from 1,800 law departments, 120,000 law firms and $230 billion of legal spend.

At a glance

Category
BrightflagLegal Ops & Spend
Legal TrackerLegal Ops & Spend
Founded
Brightflag2014
Legal TrackerNot published
Headquarters
BrightflagDublin, Ireland
Legal TrackerToronto, Ontario, Canada
Last verified
BrightflagAug 29, 2026
Legal TrackerAug 29, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Brightflag
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

The models are the product and the surrounding platform was built out around them. The core capability is language analysis reading, coding and categorising every line of every invoice narrative, and the vendor's own positioning is that this eliminates the manual configuration and outside firm involvement that conventional e-billing requires. The company was founded on that capability rather than adding it to an existing billing system, and its published framing is that it goes beyond AI invoice review to deliver a governed e-billing platform, which puts the AI first and the workflow second. Distinguished from the enterprise platforms graded B on this axis, where a workflow system predates and stands without the model layer.

Legal Tracker
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

A spend and matter management platform with an AI tier sold on top of it. Legal Tracker is electronic billing, matter management, budgeting, rate management and workflow, and every one of those works without a model. The generative AI capability sits in Legal Tracker Advanced as a separate tier, which is the same commercial shape as Onspring's add on module and lands in the same place. Credit where it is due and it distinguishes this record from a bolt on: the vendor states AI powered innovation in the product for more than a decade, and the specific tasks are real and long standing rather than newly announced, being non LEDES to LEDES conversion, duplicate line item detection, excessive timekeeper hour flagging and block billing audit efficiency. That is machine learning doing the actual work of invoice review rather than decorating it. Graded C because the platform is bought for spend control and the AI improves the throughput of one function within it. Compare Brightflag at A in this same category, where the models are the product and the platform was built around them.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Brightflag
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is real and structurally verifiable, short of published measurement. The method is described concretely: the vendor takes a legal team's own outside counsel billing guidelines and translates them into rules the AI checks each invoice against, so every flag traces to a specific guideline and a specific invoice line the reviewer can open. That is grounding by construction rather than by claim, and the reviewer holds both sides of the comparison. Invoice Summaries and a redesigned review experience are published as making in depth review easier. Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026 and located no accuracy figure, no false positive or false negative rate for flagging, no test set, no evaluation methodology and no independent benchmark participation. Third party review material notes AI driven invoice analysis may require manual review in complex cases, which is an unverified customer observation and was not treated as evidence.

Legal Tracker
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Detection claims are specific and nothing measured is published. The vendor names discrete, checkable tasks: duplicate line item detection, excessive timekeeper hour flagging, block billing audit, LEDES conversion, and a plain language question interface over spend data. These are classification and extraction problems with objectively correct answers, which makes them unusually measurable compared with most AI in this index. No figure of any kind is published: no precision or recall on duplicate detection, no false positive rate on guideline violations, no accuracy measure on LEDES conversion, no evaluation of the natural language query interface, and no statement of what the system does when an invoice narrative is ambiguous. The asymmetry matters commercially: a false positive costs a firm an argument with its client, a false negative costs the department money silently, and neither rate is disclosed. Checked the Legal Tracker and Legal Tracker Advanced product pages, the features page, the UK product page and the Thomson Reuters blog material on 29 Aug 2026.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Brightflag
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

A real published commitment with documented control surfaces, short of thresholds. The oversight structure is the product's own architecture: the AI reviews and flags, and a controlled approval process with complete audit trails determines what is actually paid, so a human decision sits between the model's output and any financial consequence. That is a genuine and auditable checkpoint rather than an assertion of human in the loop. Ask Brightflag adds a conversational interface described as accessible to every person in the legal department, which widens who interacts with the AI. Not located as of 29 Aug 2026: any threshold at which a flag is escalated or auto applied, whether any reduction can be applied without human approval, and what the vendor commits to when a flag is wrong. The last matters commercially here, because a wrong flag reduces a law firm's payment.

Legal Tracker
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Oversight is built into the workflow and never described as a model. The product's structure places a human at the decision point by design: AI flags anomalies and guideline breaches, and a reviewer approves, adjusts or rejects the invoice through an approval workflow with data driven rules for task automation. That is genuine human control over the consequential act, which here is payment. What is not published: whether any adjustment can auto apply without review, what the data driven automation rules can be configured to do unattended, whether a flag carries a confidence indication, and what happens to invoices the system does not flag at all, which is the silent path and the one that matters. Checked the product pages, the Advanced features page and the UK product page on 29 Aug 2026.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Brightflag
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Segment claims stand where deployment evidence would go. The vendor states its customers range from high growth companies to global enterprises with complex multi jurisdictional operations, and third party material describes immediate return on investment from automated invoice review, which is a vendor claim relayed rather than measured. Searched the vendor site, the FAQ, the press releases and the review platforms on 29 Aug 2026 and located no named customer paired with figures and a date, and no case study with an assessable method. Worth recording as a genuine absence rather than a research gap: the Gartner Peer Insights listing for this product carries no reviews at all, which is unusual for an established platform and means the independent evidence base other records here draw on is not available for this one.

Legal Tracker
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

The largest published adoption figures on this index and one properly named customer. Stated: 164 of the Fortune 500 and 343 of the Fortune 1000 use the product, with benchmarking drawing on aggregated data from 1,800 law departments and 120,000 law firms covering $230 billion in legal spend. Those are specific, falsifiable numbers rather than market leader language. Named customer with independent validation: Legal Tracker Advanced was named an ACC Value Champion in 2022 jointly with Volkswagen Group of America, which is an Association of Corporate Counsel award to a named department rather than a vendor case study. Further independent placement on G2 and Gartner Peer Insights with published customer commentary. Held at B rather than A because no outcome measure is published: no savings figure, no invoice reduction rate, no realised ROI with a baseline and period, and the adoption counts establish penetration rather than result. The $230 billion figure describes the size of the benchmarking asset, not what customers achieved with it.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Brightflag
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

CORRECTED 29 Aug 2026 during the trust portal sweep. Previously graded C because confidentiality rested on certification and general controls with the specific limbs unlocated. The vendor publishes a security page not reached in the original pass, and it is detailed. Published: AES-256 encryption at rest with keys managed in AWS Key Management Service; minimum TLS 1.2 in transit; single sign on via SAML with the identity providers named individually as ADFS, Azure Active Directory, Google, Okta, OneLogin and Ping Identity; SCIM support for user provisioning, permission management and de-provisioning, which matters because de-provisioning is how access actually ends when a lawyer leaves a matter or a firm; OAuth authentication on the API; out of the box user roles and access permissions with a detailed breakdown published in the help centre; optional restriction of access to specified IP ranges; and a continuous vulnerability scanning and patching programme. SOC 1 Type 2 and SOC 2 Type 2 are prepared annually across all five AICPA trust categories including Confidentiality and Privacy, which is broader scope than most records here. A data retention and deletion section is published on the same page, though its content was not captured in this pass. Held at B rather than A because the training question is still unanswered: no statement was located on whether customer content, which here means invoice narratives describing legal work, may be used to train or improve models. Privilege and work product are also not addressed directly.

Legal Tracker
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

A product specific security document exists and the privilege question this product raises more sharply than most is unaddressed. Legal invoice narratives routinely describe the substance of legal work, so an e-billing platform holds a running account of what outside counsel did on a matter and why, which is privileged or work product material flowing from firm to vendor as a matter of routine operation. Nothing located addresses that: no treatment of privilege in invoice narratives, no statement on whether narrative text is segregated from the spend data used for benchmarking, and no position on what a department's own privilege posture should be when narratives leave its control. Credited at C rather than lower because Thomson Reuters publishes a Legal Tracker specific data security and certification guide, which is a product level document rather than a corporate assurance, and because AI processes narrative text for block billing analysis, so the vendor plainly handles it deliberately. Checked the product pages, the Legal Tracker data security guide reference, the UK product page and the corporate AI Principles on 29 Aug 2026.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Brightflag
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

The audience is corporate rather than lawyer facing in the advisory sense and no position is published. Users are in house legal departments, legal operations and their finance counterparts, and Ask Brightflag is explicitly described as accessible to every person in the legal department, so non lawyers operate the AI by design. The product analyses billing rather than giving legal advice, so the advice line question arises less sharply than for a research or drafting tool. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no published position on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits despite serving customers with complex multi jurisdictional operations where billing rules and professional conduct rules differ.

Legal Tracker
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Not located, and largely peripheral to this product. Legal Tracker does not produce legal analysis or advice, so the unauthorised practice question does not arise in the form it takes for a research or drafting tool. The adjacent professional question that does arise is left unaddressed: the platform evaluates law firms, attorneys and judges through data driven profiles and performance indicators, and enforces billing guidelines against outside counsel, and nothing published addresses the professional dimension of a machine assessing an attorney's billing conduct or a judge's record. Checked the product pages, the Advanced features page and the corporate material on 29 Aug 2026.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Brightflag
AA on AI Governance and Bias DisclosureGovernance is documented and owned: who inside the vendor is accountable, what is tested before release, and what has been found and disclosed about uneven output across matter types or populations.

Fourth A on this axis, earned on an accredited AI management certification. The vendor states it is certified in ISO/IEC 42001 and describes it correctly as the first globally recognised standard for artificial intelligence management systems, which is the governance artifact this axis asks for: an externally audited management system covering the AI lifecycle rather than a principles page. It sits alongside SOC 1 Type 2, SOC 2 Type 2 and ISO 27001, so the AI standard is one part of a substantial assurance posture rather than a lone badge. Recorded honestly as the thinnest of the four A grades on this axis: searched the vendor site, the FAQ, the press releases and third party material on 29 Aug 2026 and located no certifying body, no certification date, no published scope for what the 42001 certification covers, no named owner of model governance, no pre release testing results, and nothing on uneven output across matter types, firms or practice areas. Compare Definely, which publishes its AI System Register and per system ownership, and Workday, which names its certifier and date. The certification is the artifact here; the evidence around it is not.

Legal Tracker
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

A named, published and enumerated corporate framework, applied above the product. The Thomson Reuters AI Principles are public and specific: that use of data and AI is informed by the Thomson Reuters Trust Principles, that the company will prioritise security and privacy throughout design, development and deployment, that it will strive to maintain meaningful human involvement and treat people fairly, that products should be reliable and consistent and empower socially responsible decisions, and that it will seek partners with similar ethical approaches. Publishing a fairness commitment matters more than usual for this product specifically, because the system evaluates timekeepers and firms and flags individual billing behaviour, so a systematic tendency would fall on named professionals. Held at B because nothing behind the principles is published for this product: no model card, no bias or fairness testing on flagging behaviour, no evaluation, no accuracy monitoring, no named governance body and no ISO 42001. The commitment is corporate; the evidence is absent at the product level.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Brightflag
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Substantive published assurance covering most of the ground, weighted toward certification rather than described controls. Published: SOC 2 Type 2 and SOC 1 Type 2, both stated as achieved without exceptions, ISO 27001, ISO 42001, GDPR, CCPA and CPRA compliance, AWS as the hosting partner, and a completed Cloud Security Alliance Consensus Assessment Initiative Questionnaire available on request, which is a substantive standardised control disclosure most vendors here do not offer. Third party material describes encryption and user based access controls. Not located as of 29 Aug 2026: a stated retention period or deletion control for invoices, narratives or model outputs, a named subprocessor list, and an incident or breach notification practice. The SOC 1 scope covering invoice approval, accruals management and financial reporting is a genuine control assurance over the money path and is credited here.

Legal Tracker
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

Corporate commitments exist and no product level position on AI data handling was located. The AI Principles state prioritisation of security and privacy across the AI lifecycle, and a Legal Tracker specific data security guide is published, which together are more than an assurance in marketing copy. What was not located for this product: any statement on whether invoice narratives, matter data or spend records are used to train or improve models, any retention position for AI processed content, and any description of how customer data is separated from the aggregated benchmarking pool. That last question is unusually pointed here, because the benchmarking asset is built from customer spend data and is sold back as a feature, so the boundary between a customer's data and the shared corpus is a live commercial question the published material does not draw. Checked the product pages, the Advanced features page, the Legal Tracker data security guide reference and the corporate AI Principles on 29 Aug 2026.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Brightflag
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer terms of service was located on the surfaces reached. Recorded as a pure absence. The shape is distinctive for this product: the AI's output directly reduces payments to third parties, so a wrong flag has an immediate financial effect on a law firm that is not the vendor's customer and has no contractual relationship with the vendor at all. Nothing published addresses either side of that, and it is a recourse question no other record on this index raises in the same form.

Legal Tracker
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

No published position located. Nothing was found on liability for AI output, warranty, service levels or remedy where an invoice is wrongly flagged, a legitimate charge is rejected, or a duplicate goes undetected. The consequence path is direct and financial in both directions: a false flag creates a dispute with outside counsel, and a missed duplicate is money paid that should not have been. Enterprise agreements govern this and are not public, and no public terms page for the product was located in this pass, so this is recorded as an absence across the surfaces checked, being the product pages, the Advanced features page, the UK product page and the corporate material on 29 Aug 2026.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Brightflag
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

Integration is claimed at category level without named connectors. The vendor states the platform can be implemented into existing processes with minimal setup, which it attributes to the language analysis removing the need to configure rules manually, and third party material refers to integrations particularly in collaboration and business intelligence. An e-billing platform necessarily exchanges data with accounts payable, enterprise resource planning and law firm billing systems, and handles standard billing formats, but none of that was located as documented on the surfaces reached. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no integrations index page, no named connector, no API documentation, and no statement of which billing format standards are supported. For a product whose data must flow to finance systems, that absence is notable.

Legal Tracker
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

Two integrations are named and the ones a legal operations buyer would ask about are not. Named: Microsoft Outlook and Microsoft Teams, described as seamless integration with essential enterprise platforms, plus in platform communication with outside counsel. What is absent from located material: no accounts payable, ERP or finance system integration despite this being a spend platform whose output is payment, no document management system, no matter or contract system connector, and no API documentation. For a product whose core workflow ends in an approved invoice moving to finance, the finance integration story is the one a buyer needs and it is not published. Checked the product pages, the Advanced features page and the UK product page on 29 Aug 2026.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Brightflag
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Cloud delivery and the hosting partner are stated and residency is not addressed. AWS is named as the hosting partner, which the vendor frames as providing security and performance. Searched the vendor site, the FAQ, the press releases and third party material on 29 Aug 2026 and located no named regions, no customer selectable residency, no tenancy model, and no statement of where processing happens as distinct from where data is stored. The absence is more consequential than for most records here: the vendor is headquartered in Ireland, sells to enterprises with complex multi jurisdictional operations, and states GDPR compliance, so where invoice narratives describing legal work are processed and stored is a question its own customer base would be expected to ask.

Legal Tracker
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Residency options are described, and the description comes from third party material rather than from the vendor pages read. An independent software directory states that secure data residency options provide flexible storage while upholding compliance and security, and the product is sold globally with multi currency and multi language support, which implies regional handling. No vendor page located in this pass names a hosting provider, enumerates regions, states a residency commitment, or describes single tenant options. Source basis recorded as Third Party Estimated on that footing rather than credited as vendor disclosure. Correction candidate: the published Legal Tracker data security and certification guide is the document most likely to state residency directly and was identified but not read in full in this pass.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Brightflag
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

CORRECTED 29 Aug 2026 during the trust portal sweep; grade held at B and the currency finding is now firmer. The vendor's security page, not reached in the original pass, states the certification set and scopes it precisely: externally validated through ISO 27001:2013, SOC 1 and SOC 2, with annual AICPA System and Organization Controls reports prepared across all five trust categories, SOC 1 Type 2 covering controls relevant to financial reporting and SOC 2 Type 2 covering Security, Availability, Processing Integrity, Confidentiality and Privacy. Naming all five categories rather than the usual three is more precise than almost any record on this index. A Cloud Security Alliance CAIQ is available with the reports on request. A separate trust centre exists for the vendor's Workspace product at a stable URL, stating annual audits by an independent CPA firm, first SOC 2 audit in February 2021, and reports available by request through the service portal. Why the grade holds at B rather than rising. The evidence route for the main platform is still a request to the team rather than a self serve portal. No coverage period, report date or auditing firm was located for the main platform. And the currency question is now stronger rather than weaker: the ISO 27001:2013 reference appears on the vendor's own current security page, not only in an FAQ, and that revision was withdrawn and superseded by ISO/IEC 27001:2022, whose transition deadline has passed. A vendor stating a withdrawn revision on its live security page is a finding worth recording plainly, and it remains rebuttable by a current certificate.

Legal Tracker
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

A product specific security document exists and no certification status for this product was established, and the reason that matters is recorded here as a warning. Thomson Reuters publishes a Legal Tracker specific data security and certification quick reference guide, which is better than a corporate page and indicates the topic is addressed at product level. The guide was identified but not read in full in this pass, and no certification status for Legal Tracker itself was confirmed from any source. THE HAZARD, stated explicitly: sibling Thomson Reuters products carry distinct and separately stated certifications. Case Center is ISO 27001 certified on its own certifications page. The Thomson Reuters Europe trust centre material describes ISO 27701 certification in the context of ONESOURCE Pagero, an e-invoicing product. CoCounsel publishes its own security posture. None of those transfers to Legal Tracker, and treating a corporate parent's certification estate as a per product credential is the domain hazard this pull has already hit four times in a different form. Held at C on what is actually established: a product level security document is published, its contents are unverified, and no certification is confirmed. Correction candidate in both directions.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Brightflag
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No model, provider, hosting location for model processing, or subprocessor was located, and no commitment to notify customers of supply chain changes. AWS is named as the hosting partner for the platform, which is infrastructure rather than a model supply chain disclosure and was not treated as one. The gap covers both layers of this product's AI: the language analysis that codes invoice narratives, whose nature is not described beyond being language analysis technology, and Ask Brightflag, a conversational interface whose underlying model is not identified anywhere located. A buyer cannot determine from published material which company, if any, processes their invoice narratives.

Legal Tracker
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

Nothing located. No foundation model provider, model family or version is named, no subprocessor list was found, and no distinction is drawn between the machine learning models the vendor states have been in the product for over a decade and the generative AI and advanced multilanguage models described in the Advanced tier. The corporate AI Principles include a commitment to partner with organisations sharing similar ethical approaches, which acknowledges that partners exist and names none of them. Checked the product pages, the Advanced features page, the corporate AI Principles and the blog material on 29 Aug 2026.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Brightflag
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Checked the vendor site, the FAQ and the press releases on 29 Aug 2026. No pricing page was located, no rate is published, no unit of charge is stated and no tier structure appears on the surfaces reached. Third party sources state pricing is not publicly available and requires a custom quote, structured on subscription and varying with organisation size and the volume of legal spend managed, which confirms the absence and identifies the unit of charge without the vendor publishing it. Worth recording plainly because of what this product is: a platform sold on delivering visibility and transparency into legal spend, which does not publish what it costs. That is not a grading factor beyond the D, but it is the sharpest instance of the pattern on this index.

Legal Tracker
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing at any level. No price, no range, no unit of charge, and no indication of the difference in cost between Legal Tracker and Legal Tracker Advanced, which is the specific question a buyer faces here since the AI capability sits in the upper tier. Every route is a contact or demo request. The irony is on the record and worth stating: this is a product sold to bring transparency to legal spend, and its own cost is not published at any level of abstraction. Checked the product pages, the Advanced page, the features page and independent directory listings on 29 Aug 2026.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Brightflag
CC on Firm and Practice CoverageCoverage is claimed broadly, for all firms or all practice areas, without evidence that the breadth is real.

Segment coverage is described in general terms with the detail not reached. The vendor states its customers are corporate legal departments across industries and range from high growth companies to global enterprises with complex multi jurisdictional operations, and identifies the buying roles as in house legal, legal operations and their finance counterparts. Its FAQ begins an enumeration of the industries served but that list was not captured in this pass and is not credited. Practice scope is clear and consistently stated as outside counsel spend, matters, vendors, budgets and reporting, with no claim to advisory or drafting capability. Not located as of 29 Aug 2026: an enumerated industry or practice area list, organisation size segmentation, jurisdictional coverage, and any statement of what the platform is not built for. Flagged as rebuttable in one step by reading the FAQ industry list.

Legal Tracker
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Coverage is quantified with real specificity on the dimension that matters for this category, which is the reach of the benchmarking corpus rather than jurisdictions of law. Stated: aggregated data from 1,800 law departments and 120,000 law firms worldwide, a library of $230 billion in legal spend, with segmentation by industry, spend, department, company size, work type, metro area, classification and law firm performance by substantive law. Global operation is supported by multi currency handling, language packs and management of laws and currencies across regions. Rate increase history is analysable by individual timekeeper and firm using compound annual growth rate. Held at B rather than A because the corpus is described rather than characterised: no statement of geographic distribution, no indication of how current the aggregated data is or how often it refreshes, and nothing on whether coverage in a given jurisdiction or practice area is deep enough for a benchmark to be meaningful, which is the question a department comparing itself actually needs answered.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Brightflag
Terms silent

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No located material states whether customer content may be used to train models, either way. Recorded as silent under the rule that a value is never inferred from the absence of a contradiction, and specifically not inferred from the ISO 42001 certification, which evidences that an AI management system exists rather than what its training position is. The question carries unusual weight for this product. The material at issue is invoice narratives describing legal work across many companies and many law firms, and the vendor's own benchmarking and vendor profiling features depend on cross customer comparison, so a buyer would reasonably want to know what is pooled, in what form, and for whose benefit. Nothing located addresses it.

Legal Tracker
Terms silent

Silent for this product, and the quote shows precisely why. That commitment is published by Thomson Reuters for CoCounsel Legal, a different product on this index with its own record. It is quoted here to document what was found and deliberately not credited, because a no training commitment made for one product in a large portfolio is not a commitment for another, and transferring it would manufacture a contractual position Legal Tracker has never stated. Nothing located addresses whether Legal Tracker invoice narratives, matter data or spend records are used to train or improve models. The question has commercial weight beyond the usual: the benchmarking asset covering $230 billion in spend is built from aggregated customer data and sold back as a product feature, so this vendor demonstrably does reuse customer data for a purpose beyond the individual customer, and the boundary between that and model training is not drawn anywhere public. Checked the product pages, the Advanced features page, the UK product page and the corporate AI Principles on 29 Aug 2026.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Brightflag
Not addressed

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No public material states how long invoices, narratives, AI generated flags, summaries or Ask Brightflag conversations are retained, whether a customer controls the window, or whether deletion is available. The platform is a system of record for spend and matter history and its analytics, forecasting and rate benchmarking features depend on multi year retention, so long retention is inherent to the value proposition and no published terms govern it.

Legal Tracker
Not addressed

Not addressed. No retention period is published for AI processed invoice content, natural language queries against spend data, or generated insights, and nothing indicates whether retention is configurable. The platform retains invoices, matter records and spend history by design as a system of record, which is retention as a product function and a different question from how long the AI layer holds what it processes. Neither is quantified. Checked the product pages, the Advanced features page and the UK product page on 29 Aug 2026. Correction candidate: the published Legal Tracker data security guide was not read in full.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Brightflag
Own model, documented

CORRECTED 29 Aug 2026 during the trust portal sweep. Previously recorded as not addressed on the finding that no vendor material described segregation and that third party references to access controls were assertions relayed rather than a documented model. The vendor's security page, not reached in the original pass, documents the model. Published: out of the box user roles and access permissions with a detailed breakdown available in the help centre, so the roles are enumerated somewhere a customer can read rather than merely asserted; single sign on via SAML with named identity providers; SCIM support for provisioning, permission management and de-provisioning; OAuth on the API; and optional restriction of access to specified IP ranges. That is the product's own permission model, described at mechanism level. Recorded at own model documented rather than the positive value for two reasons. No material states that the AI layer respects those permissions at query time, which matters because Ask Brightflag is described as a conversational interface accessible to every person in the legal department and the underlying data includes invoice narratives describing sensitive matters. And no document management integration was located whose access model could be inherited. Conflicts and ethical walls are not named as such.

Legal Tracker
Not addressed

Not addressed. No permission model, matter level access restriction or segregation description was located. The structural question specific to this product is unanswered: multiple outside firms bill into a single department's instance and collaborate within it, so a firm's invoice narratives describing its work on a matter sit in a platform other firms also use, and nothing published describes what walls exist between them or between matters within the department. No document management system integration exists to inherit permissions from. Checked the product pages, the Advanced features page and the UK product page on 29 Aug 2026.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Brightflag
Not addressed

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026, and no published customer agreement or data processing agreement was reached. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. The exposure is worth naming: a structured record of what every outside law firm did on every matter for a company would be an attractive target for a discovery request or regulatory demand, and nothing published addresses what the vendor would do on receiving one.

Legal Tracker
Not addressed

Not addressed for this product. A process is described elsewhere in the Thomson Reuters estate, in trust centre material covering ONESOURCE Pagero, stating that processes exist to manage and validate third party data access requests including informing the customer in accordance with applicable law, audited under ISO 27701. That is a different product with a different certification and it is recorded here as located and not transferred. No notice commitment, process description or transparency report specific to Legal Tracker was found. Checked the product pages, the corporate material and the trust centre material on 29 Aug 2026.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Brightflag
Not addressed

No primary law corpus is identified because the product does not hold one, and the relevant provenance question is a different one that is also unanswered. Invoice review runs against the customer's own invoices and their own billing guidelines, so that corpus is theirs. But the vendor also publishes rate benchmarking and AI built vendor profiles applied to panel management and RFPs, and benchmarking necessarily rests on a comparative dataset drawn from somewhere. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no statement of what the benchmarking corpus comprises, whose data it contains, whether it is aggregated or anonymised, or on what basis it was assembled. Recorded as not addressed on that specific question rather than as inapplicable.

Legal Tracker
Sources named, basis unstated

Named without a licence basis, and the corpus here is customer contributed rather than public law. The benchmarking data is described precisely: aggregated data from 1,800 law departments and 120,000 law firms worldwide covering $230 billion in legal spend, segmentable by industry, department size, work type, metro area and firm performance by substantive law. Naming the composition and scale of the corpus that specifically is genuine provenance disclosure and better than most records manage. What is absent is the basis on which it exists: nothing states the contractual or consent footing on which customer spend data enters the aggregate, whether contribution is a condition of use, whether a customer can opt out and still buy the product, or how data is de-identified before it is pooled. There is no primary law corpus in this product, so the signal is recorded against the corpus that does the work.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Brightflag
Not addressed

Searched the vendor site, the FAQ and the press releases on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is a legal spend and matter management platform whose corpus is invoices and billing guidelines rather than case law, so a citator is outside its design entirely.

Legal Tracker
Not addressed

Not addressed, and inapplicable on the facts. Legal Tracker manages spend and matters and produces no legal analysis or citation to authority, so there is nothing for a citator to check. Recorded as a scope fact rather than omitted, so a reader comparing this record against a legal research product does not read an empty row as a disclosure failure. Consistent with the treatment of this row on TrialView and Exterro. Checked the product pages and the Advanced features page on 29 Aug 2026.

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Brightflag
Not addressed

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No published material describes what the product does when it cannot confidently code a line or assess a narrative against a guideline, and no explicit no answer path or confidence signal exposed to the user was located. Third party review material observes that AI driven invoice analysis may require manual review in complex cases, which suggests some routing to human judgement occurs in practice, but it is an unverified customer observation rather than a published behaviour and was not treated as one. For a product that codes every line of every invoice, how it handles an ambiguous narrative is a live question and is unaddressed.

Legal Tracker
Not addressed

Not addressed. The product includes a plain language question interface over spend data and AI that flags billing anomalies, and nothing published describes what either does under uncertainty: whether an ambiguous invoice narrative is surfaced for human attention or silently passed, whether a flag carries a confidence level, or whether the query interface will state that it cannot answer rather than returning a number. For a system whose output feeds payment decisions and benchmark comparisons, a confidently wrong answer and an abstention have very different consequences and neither behaviour is documented. Checked the product pages, the Advanced features page and the UK product page on 29 Aug 2026.

Fabricated Citation Record

Does a public court record exist involving output from this product?

Brightflag
None located

No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note the product does not generate citations or court facing text at all: its output is invoice flags and spend analysis, so the failure mode this database catalogues does not arise here, and a wrong output would surface as a billing dispute rather than a sanction.

Legal Tracker
None located

None located, with the instrument named and a transfer refused. General web searches combining the vendor and product names with court, order, sanction and billing dispute terms returned nothing on 29 Aug 2026, and no named docket database or court record tracker was searched. Recorded explicitly for the next reader: the Stanford RegLab and HAI study measuring hallucination rates applies to Westlaw AI-Assisted Research and Ask Practical Law AI, not to Legal Tracker, and it does not transfer to this record on the strength of a shared corporate parent. The product generates no citations to legal authority, so the classic failure mode does not arise. Recorded as a statement about what this search found, not as a clearance.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Brightflag
Not addressed

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512. The absence is more pointed here than for most records, because the professional rules governing legal billing are directly the subject matter of the product: what a lawyer may bill for, what constitutes a reasonable fee, and how work is described to a client are conduct rules, and this platform automates the assessment of exactly that. It engages with the customer's own outside counsel guidelines, which are contractual instruments, and not with the professional standards that sit behind them.

Legal Tracker
Not addressed

Not addressed. No named ethics opinion, no ABA Formal Opinion 512, no state bar guidance and no engagement with professional conduct rules was located for this product. The adjacent professional territory the product occupies is billing conduct, where guidance on reasonable fees and billing practices exists in every jurisdiction, and the platform enforces billing guidelines and flags timekeeper behaviour without engaging any of it. Checked the product pages, the Advanced features page, the UK product page and the Thomson Reuters blog and institute material on 29 Aug 2026.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Brightflag
Audit record only

Second record on this index to reach a value above savings claims, and the only one where fee assessment is the entire product. The platform generates a per matter and per invoice record of what the AI flagged, what a reviewer approved and what was ultimately paid, held in controlled approval workflows with complete audit trails, so a legal department has a durable account of how each fee decision was reached and on what basis. That is the artifact this signal looks for, produced as the core function rather than as a by product. Two limits keep it short of the positive value and both matter. First, the record concerns the law firm's billed work rather than any AI assisted work performed by the vendor itself. Second, and more consequential for this index: outside counsel guidelines increasingly address whether and how AI assisted work may be billed, and searched the vendor site, the FAQ and the press releases on 29 Aug 2026 without locating any statement that the AI checks for AI related billing entries or supports a guideline term about them. A product that translates billing guidelines into automated checks, in a market where those guidelines are being rewritten around AI, publishes nothing about that.

Legal Tracker
Audit record only

Audit record, and the strongest position on this signal located in the pull, because billing is the product rather than a side effect of it. The platform produces exactly what this signal asks about: an auditable record of what outside counsel billed, which line items were flagged and why, which were adjusted or rejected, and by whom, held against enforced billing guidelines with approval workflow and full spend history. A department can evidence its review of a bill in a way no other record on this index supports. Held at audit record rather than the top value because the guidance limb is missing: nothing published addresses how AI assisted time should itself be billed or disclosed, and no position is taken on what a firm using AI should record on an invoice, which is the live question in this category and the one a spend platform is best placed to answer.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Brightflag
On request only

Diligence material exists and reaching it runs through a conversation. The vendor states that security and compliance reports, including a completed Cloud Security Alliance Consensus Assessment Initiative Questionnaire, are available by contacting the team directly, and names SOC 1 Type 2, SOC 2 Type 2, ISO 27001 and ISO 42001 alongside GDPR, CCPA and CPRA compliance. A completed CAIQ is a substantial standardised control disclosure and few vendors on this index offer one. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no subprocessor list, no statement naming which model providers see customer content, no published data processing agreement, and no client facing consent or notification pack. Recorded at on request on the strength of the stated report route.

Legal Tracker
Not addressed

Not addressed, which is the sharpest irony on this record. This product exists to operationalise outside counsel guidelines, enforcing a department's billing rules against the firms it instructs, and the vendor publishes no equivalent disclosure pack about itself. No subprocessor list, no named model provider, no data processing agreement, no trust centre for this product and no self serve documentation request route were located. The published Legal Tracker data security and certification guide is the closest thing and its contents were not verified in this pass. Checked the product pages, the Advanced features page, the UK product page and the corporate material on 29 Aug 2026.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Brightflag
Not addressed

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No per document record covering model used, sources retrieved and human verification was located, and no model is identified in published material so the model used could not be stated. Complete audit trails exist over the approval workflow, which record who approved what and when rather than what the AI did and on what basis, and the two were not conflated. Noted for context: this is a spend management platform whose output is invoice flags and financial analysis rather than legal work product, so a judicial AI disclosure order is unlikely to reach it. The nearer analogue would be a fee dispute or a challenge to billing judgements, where the approval audit trail would be the relevant record and does exist.

Legal Tracker
Not addressed

Not addressed, and close to inapplicable in the form this signal usually takes. Legal Tracker does not produce legal work product that would be filed, so the model used, sources retrieved and human verification export a judicial standing order asks for has no natural object here. The platform does hold a strong internal audit trail of invoice review decisions, and that is recorded on the billing signal where it belongs rather than double counted here. Recorded as a scope fact: the row is empty because the product does not generate output that reaches a court, not because the vendor declined to document it. Checked the product pages and the Advanced features page on 29 Aug 2026.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • AI Liability and Recourse
  • Model Supply Chain Disclosure
  • Commercial Transparency
Signals neither addresses in public material
  • Prompt and Output Retention
  • Third Party Request and Subpoena Notice
  • Good Law Verification
  • Refusal and Uncertainty Behaviour
  • Bar Guidance Alignment
  • Court Disclosure Support

Which one fits

Choose Brightflag if

  • You want the AI itself inside an audited management system. Brightflag states ISO/IEC 42001 certification for AI management alongside ISO 27001, SOC 1 Type 2 and SOC 2 Type 2, with the SOC 2 prepared across all five AICPA trust categories, which is more precise scope than almost any record in this index publishes.
  • You need every flag to trace back to something you wrote. Brightflag takes a department's own outside counsel billing guidelines and translates them into rules the AI checks each invoice line against, so a reviewer can open both the guideline and the line, and a controlled approval workflow with audit trails decides what is actually paid.
  • Your security review starts with identity. Brightflag publishes AES-256 encryption at rest with keys in AWS Key Management Service, a minimum of TLS 1.2 in transit, SAML single sign on with ADFS, Azure Active Directory, Google, Okta, OneLogin and Ping Identity named individually, SCIM provisioning and de-provisioning, OAuth on the API and optional IP range restriction.

Choose Legal Tracker if

  • You want to know whether your rates are normal. Legal Tracker benchmarks against aggregated data described as 1,800 law departments, 120,000 law firms and a library of $230 billion in legal spend, segmentable by industry, department size, work type and metro area, with rate increase history analysed by timekeeper and firm using compound annual growth rate.
  • You want evidence the platform survives at scale. Thomson Reuters states adoption by 164 of the Fortune 500 and 343 of the Fortune 1000, and Legal Tracker Advanced was named an Association of Corporate Counsel Value Champion in 2022 jointly with Volkswagen Group of America, which is an award to a named department rather than a vendor case study.
  • Your department bills in several currencies across regions. Legal Tracker handles multi currency conversion, ships language packs, and manages laws and currencies across regions, with Microsoft Outlook and Microsoft Teams named as integrations and outside counsel collaborating inside the platform.

In summary

Brightflag

Brightflag is an AI powered legal spend and matter management platform for in house legal departments, built around invoice review that reads, codes and categorises every line of every invoice narrative and checks it against the department's own outside counsel billing guidelines. The AI Legal Index grades it in the top two bands on seven of fifteen capability axes, with A grades on AI centrality and on AI governance, the latter resting on stated ISO/IEC 42001 certification for an AI management system alongside ISO 27001, SOC 1 Type 2 and SOC 2 Type 2. As of 29 August 2026 the index located no named customer paired with figures, no model or provider named, no liability position and no published price.

Source: AI Legal Index, 2026

Legal Tracker

Legal Tracker is Thomson Reuters' legal spend and matter management platform for corporate legal departments, sold in a standard tier and an Advanced tier carrying the generative AI capability, with AI invoice review covering LEDES conversion, duplicate line detection, excessive timekeeper hours and block billing analysis. The AI Legal Index grades it in the top two bands on three of fifteen capability axes, with a B on operational evidence: benchmarking draws on aggregated data described as 1,800 law departments, 120,000 law firms and $230 billion in legal spend, and the vendor states adoption by 164 of the Fortune 500. As of 29 August 2026 the index could not establish a certification status for the product itself, and located no model named, no liability position and no published price.

Source: AI Legal Index, 2026

Questions buyers ask

Brightflag vs Legal Tracker: which is better for legal spend management?

The AI Legal Index places Brightflag in the top two bands on seven of fifteen capability axes and Legal Tracker on three, and the gap is what each publishes about its own AI and controls rather than what either can do. Brightflag publishes an AI management certification, a detailed security page and a grounded review method. Legal Tracker publishes scale, including a benchmarking corpus covering $230 billion in legal spend and adoption across the Fortune 500.

Does Brightflag publish an AI certification?

Brightflag states ISO/IEC 42001 certification, the standard for artificial intelligence management systems, alongside ISO 27001, SOC 1 Type 2 and SOC 2 Type 2. It is the artifact this index grades on that axis, and the evidence around it is thin: no certifying body, certification date or published scope statement for what the AI certification covers was located, and no owner of model governance is named. Legal Tracker publishes corporate AI Principles rather than a certification. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.

What does Legal Tracker's benchmarking data cover?

Thomson Reuters describes it as aggregated data from 1,800 law departments and 120,000 law firms worldwide, covering a library of $230 billion in legal spend, segmentable by industry, spend, department size, company size, work type, metro area and law firm performance by substantive law. What is not published is how current that aggregate is, how often it refreshes, or the basis on which customer spend data enters it. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.

Does either vendor say whether invoice narratives train its models?

Neither. The AI Legal Index records both as silent, meaning no commitment was located in either direction. The question has weight on both records because both reuse customer data beyond the individual customer: Brightflag publishes rate benchmarking and AI built vendor profiles, and Legal Tracker builds its benchmarking library from aggregated customer spend. Neither draws a published boundary between that reuse and model training.

What do Brightflag and Legal Tracker both leave unpublished?

Neither publishes a price, a rate or a unit of charge, which is worth noting for two products sold on bringing transparency to legal spend. Neither publishes a liability position, a warranty on output or an insurance position. Neither names a model or a provider. Neither states a retention period. And neither addresses how AI assisted work should itself be billed or disclosed on an invoice, which is the live question in this category and the one a spend platform is best placed to answer. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.

Disclosure

Two things belong on the record. Brightflag's own security page states ISO 27001:2013, a revision that has been withdrawn and superseded by ISO/IEC 27001:2022 with its transition deadline passed, and no current certificate was located; that is what the live page says rather than a conclusion about what Brightflag holds. On Legal Tracker, Thomson Reuters publishes a product specific data security and certification guide that was identified but not read during research, so the security, residency and retention grades on that record are rebuttable in either direction. Neither vendor states whether invoice narratives are used to train models. Both records were verified on 29 August 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 2, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746