Brightflag vs SimpleLegal: how they compare in 2026
Brightflag and SimpleLegal both review outside counsel invoices with machine learning and both sell to the same budget line. Brightflag sits in the top two bands on seven of fifteen axes, SimpleLegal on five, and Brightflag's lead is assurance. It holds ISO/IEC 42001 for AI management systems alongside SOC 1 Type 2, SOC 2 Type 2 prepared across all five trust categories and ISO 27001, and its security page names controls rather than gesturing at them, with AES-256 at rest under AWS key management, minimum TLS 1.2 in transit, six named single sign on providers and SCIM provisioning so access ends when a person leaves. SimpleLegal answers on scale and on candour about fit. Its owner states more than 550 corporate legal departments and 5.2 billion dollars of annual legal spend processed as at May 2026, and positions the product explicitly against the enterprise tier platform in the same portfolio, so a prospect is told which of the two is meant for them.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the product and the surrounding platform was built out around them. The core capability is language analysis reading, coding and categorising every line of every invoice narrative, and the vendor's own positioning is that this eliminates the manual configuration and outside firm involvement that conventional e-billing requires. The company was founded on that capability rather than adding it to an existing billing system, and its published framing is that it goes beyond AI invoice review to deliver a governed e-billing platform, which puts the AI first and the workflow second. Distinguished from the enterprise platforms graded B on this axis, where a workflow system predates and stands without the model layer.
MEMBERSHIP: the AI bar is cleared on a named, shipped product. InvoiceAI is described in detail by the owner: machine learning models trained on millions of legal invoice charges, finding issues conventional billing rules miss including non working travel, block billing, vague descriptions, improperly billed administrative tasks, improper coding and wrong staff class, integrated with existing rules engines and continuing to learn from corrections. Real capability, not a roadmap. GRADE: the models are the engine of a core capability layered on a platform that would function without them. E-billing, matter intake and management, vendor management, budgets, accruals, reporting and the CounselGO portal all stand without any model, and the platform sold on exactly that from 2013 until the AI layer arrived in 2021. Recorded as a discrepancy rather than resolved: the owner's current marketing describes the product as AI native, which does not fit a platform that operated for eight years before its AI capability was introduced, and the grade follows the product history rather than the adjective.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real and structurally verifiable, short of published measurement. The method is described concretely: the vendor takes a legal team's own outside counsel billing guidelines and translates them into rules the AI checks each invoice against, so every flag traces to a specific guideline and a specific invoice line the reviewer can open. That is grounding by construction rather than by claim, and the reviewer holds both sides of the comparison. Invoice Summaries and a redesigned review experience are published as making in depth review easier. Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026 and located no accuracy figure, no false positive or false negative rate for flagging, no test set, no evaluation methodology and no independent benchmark participation. Third party review material notes AI driven invoice analysis may require manual review in complex cases, which is an unverified customer observation and was not treated as evidence.
Grounding is real and the method is described with unusual specificity for this category, short of published measurement. The owner states InvoiceAI analyses historical and real time invoices, uses machine learning trained on millions of legal invoice charges, and integrates findings with existing rules engines so that machine learning and deterministic rules operate together rather than one replacing the other. The issue types it detects are enumerated rather than left general, which tells a buyer what the model is actually looking for. Every flag attaches to a specific invoice line the reviewer can open against their own billing guidelines, so verification is structural. Searched the product pages, the owner's InvoiceAI material and press coverage on 29 Aug 2026 and located no accuracy figure, no false positive rate, no test set, no evaluation methodology and no independent benchmark. The published figures are savings rather than accuracy: an average of six figures identified in travel related billed time across customers, which measures what was found rather than what was missed or wrongly flagged.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A real published commitment with documented control surfaces, short of thresholds. The oversight structure is the product's own architecture: the AI reviews and flags, and a controlled approval process with complete audit trails determines what is actually paid, so a human decision sits between the model's output and any financial consequence. That is a genuine and auditable checkpoint rather than an assertion of human in the loop. Ask Brightflag adds a conversational interface described as accessible to every person in the legal department, which widens who interacts with the AI. Not located as of 29 Aug 2026: any threshold at which a flag is escalated or auto applied, whether any reduction can be applied without human approval, and what the vendor commits to when a flag is wrong. The last matters commercially here, because a wrong flag reduces a law firm's payment.
A real published commitment with a documented feedback loop, short of thresholds. The owner describes InvoiceAI as handling the first pass review of incoming bills and setting up a framework that continuously learns as invoice corrections are refined in the system, which places the human at the correction point and makes their corrections the training signal. That is an oversight loop described as a mechanism rather than asserted as a principle, and it is more concrete than most records here manage. Approval workflows sit between a flag and any payment decision. Not located as of 29 Aug 2026: any threshold at which a flag is applied automatically versus routed for review, whether any reduction can take effect without human approval, and what the vendor commits to when a flag is wrong. The last matters because a wrong flag reduces a law firm's payment.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Segment claims stand where deployment evidence would go. The vendor states its customers range from high growth companies to global enterprises with complex multi jurisdictional operations, and third party material describes immediate return on investment from automated invoice review, which is a vendor claim relayed rather than measured. Searched the vendor site, the FAQ, the press releases and the review platforms on 29 Aug 2026 and located no named customer paired with figures and a date, and no case study with an assessable method. Worth recording as a genuine absence rather than a research gap: the Gartner Peer Insights listing for this product carries no reviews at all, which is unusual for an established platform and means the independent evidence base other records here draw on is not available for this one.
Quantified figures without named customers. Scale is stated precisely by the owner and dated: more than 550 corporate legal departments and $5.2bn in annual legal spend processed as at May 2026, and processing volume is a meaningful proxy for production use in this category because it measures work actually flowing through the system rather than seats sold. Outcome figures exist but are unattributed: a published customer quote states 10 percent savings identified in legal spend, and the owner reported an average of six figures in travel related billed time identified across customers. Independent review presence exists on multiple platforms. Searched the product pages, the owner's material and the review platforms on 29 Aug 2026 and located no named customer paired with figures and a date, and no case study with an assessable method.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
CORRECTED 29 Aug 2026 during the trust portal sweep. Previously graded C because confidentiality rested on certification and general controls with the specific limbs unlocated. The vendor publishes a security page not reached in the original pass, and it is detailed. Published: AES-256 encryption at rest with keys managed in AWS Key Management Service; minimum TLS 1.2 in transit; single sign on via SAML with the identity providers named individually as ADFS, Azure Active Directory, Google, Okta, OneLogin and Ping Identity; SCIM support for user provisioning, permission management and de-provisioning, which matters because de-provisioning is how access actually ends when a lawyer leaves a matter or a firm; OAuth authentication on the API; out of the box user roles and access permissions with a detailed breakdown published in the help centre; optional restriction of access to specified IP ranges; and a continuous vulnerability scanning and patching programme. SOC 1 Type 2 and SOC 2 Type 2 are prepared annually across all five AICPA trust categories including Confidentiality and Privacy, which is broader scope than most records here. A data retention and deletion section is published on the same page, though its content was not captured in this pass. Held at B rather than A because the training question is still unanswered: no statement was located on whether customer content, which here means invoice narratives describing legal work, may be used to train or improve models. Privilege and work product are also not addressed directly.
EVIDENCE FLOOR: see the build log warning on this record. Searched the product pages, the owner's InvoiceAI material, press coverage and three separate targeted searches for a trust centre, security page or certification listing on 29 Aug 2026 without reaching one. Nothing was located on how client confidences are handled: no statement on whether customer content may be used to train models, no retention or deletion terms, no segregation model, no treatment of privilege or work product. The question is sharper here than the absence alone suggests, because the owner's own description of InvoiceAI states the models are trained on millions of legal invoice charges and continue to learn from customer corrections, so training on customer derived data is the stated design and nothing published says whose data, whether it is pooled across customers, or whether a customer can decline. Invoice narratives describe what lawyers did on matters, which is privileged material. Rebuttable with one link and flagged as the highest priority recheck on this record.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The audience is corporate rather than lawyer facing in the advisory sense and no position is published. Users are in house legal departments, legal operations and their finance counterparts, and Ask Brightflag is explicitly described as accessible to every person in the legal department, so non lawyers operate the AI by design. The product analyses billing rather than giving legal advice, so the advice line question arises less sharply than for a research or drafting tool. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no published position on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits despite serving customers with complex multi jurisdictional operations where billing rules and professional conduct rules differ.
The audience is corporate and the position is unstated. Users are in house legal departments, legal operations and finance counterparts, with outside counsel interacting through the CounselGO portal, and the product analyses billing rather than giving legal advice, so the advice line question arises less sharply than for a research or drafting tool. Searched the product pages, the owner's material and press coverage on 29 Aug 2026 and located no published position on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits. Recorded at C because the position is inferable from what the product is rather than published.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Fourth A on this axis, earned on an accredited AI management certification. The vendor states it is certified in ISO/IEC 42001 and describes it correctly as the first globally recognised standard for artificial intelligence management systems, which is the governance artifact this axis asks for: an externally audited management system covering the AI lifecycle rather than a principles page. It sits alongside SOC 1 Type 2, SOC 2 Type 2 and ISO 27001, so the AI standard is one part of a substantial assurance posture rather than a lone badge. Recorded honestly as the thinnest of the four A grades on this axis: searched the vendor site, the FAQ, the press releases and third party material on 29 Aug 2026 and located no certifying body, no certification date, no published scope for what the 42001 certification covers, no named owner of model governance, no pre release testing results, and nothing on uneven output across matter types, firms or practice areas. Compare Definely, which publishes its AI System Register and per system ownership, and Workday, which names its certifier and date. The certification is the artifact here; the evidence around it is not.
EVIDENCE FLOOR: see the build log warning on this record. Searched the product pages, the owner's InvoiceAI material, press coverage and three targeted searches on 29 Aug 2026. No published AI governance framework, AI principles document, AI management certification, named owner of model governance, pre release testing regime or bias disclosure was located. The gap has a specific edge worth stating: InvoiceAI classifies whether billed work was appropriate, including judgements about whether work was performed by the correct staff class, and a model trained on historical invoice data will have learned historical staffing patterns. Nothing published addresses whether its judgements differ across firms, practice areas, staffing models or timekeeper seniority. Rebuttable with one link.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published assurance covering most of the ground, weighted toward certification rather than described controls. Published: SOC 2 Type 2 and SOC 1 Type 2, both stated as achieved without exceptions, ISO 27001, ISO 42001, GDPR, CCPA and CPRA compliance, AWS as the hosting partner, and a completed Cloud Security Alliance Consensus Assessment Initiative Questionnaire available on request, which is a substantive standardised control disclosure most vendors here do not offer. Third party material describes encryption and user based access controls. Not located as of 29 Aug 2026: a stated retention period or deletion control for invoices, narratives or model outputs, a named subprocessor list, and an incident or breach notification practice. The SOC 1 scope covering invoice approval, accruals management and financial reporting is a genuine control assurance over the money path and is credited here.
CORRECTED 29 Aug 2026 during the trust portal sweep. Previously graded D on the finding that three targeted searches reached no trust centre or security page. That finding was wrong: a trust centre exists at trust.onit.com on the Vanta platform with a dedicated controls section, publishing the owner's security practices and reachable without a sales conversation. The premise of the earlier note is withdrawn. What is now established: a published security posture exists at owner level with a controls disclosure and a self serve route to it. What is still not established, and why this is C rather than higher: the trust centre renders client side and its control detail was not retrieved in this pass, so no specific control is confirmed for this product. Searched the product pages, the owner's material and press coverage on 29 Aug 2026 and located no stated retention period, no deletion control, no encryption statement for this product, no hosting disclosure, no named subprocessor list and no incident or breach notification practice. The related concern recorded elsewhere on this record still stands and is sharpened by the gap: the owner states its invoice review models are trained on millions of legal invoice charges and continue to learn from customer corrections, so what is retained and for how long is a live question that the located material does not answer. Rebuttable in one step by reading the trust centre controls.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer terms of service was located on the surfaces reached. Recorded as a pure absence. The shape is distinctive for this product: the AI's output directly reduces payments to third parties, so a wrong flag has an immediate financial effect on a law firm that is not the vendor's customer and has no contractual relationship with the vendor at all. Nothing published addresses either side of that, and it is a recourse question no other record on this index raises in the same form.
Searched the product pages, the owner's material, press coverage and third party review material on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer terms of service was located on the surfaces reached. Recorded as a pure absence. The shape matches Brightflag and is worth restating as a category observation rather than a vendor one: in legal spend management the AI's output reduces payments to a law firm that is not the vendor's customer and has no contractual relationship with the vendor, so the party bearing the direct financial consequence of a wrong output has no recourse route at all. Neither record in this category addresses it.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integration is claimed at category level without named connectors. The vendor states the platform can be implemented into existing processes with minimal setup, which it attributes to the language analysis removing the need to configure rules manually, and third party material refers to integrations particularly in collaboration and business intelligence. An e-billing platform necessarily exchanges data with accounts payable, enterprise resource planning and law firm billing systems, and handles standard billing formats, but none of that was located as documented on the surfaces reached. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no integrations index page, no named connector, no API documentation, and no statement of which billing format standards are supported. For a product whose data must flow to finance systems, that absence is notable.
Integration is claimed as a differentiator with categories named rather than connectors. The vendor states seamless integration with enterprise resource planning and finance systems ensures real time visibility into spend and performance, and third party material describes support for multiple systems and platforms. CounselGO is a real named component, though it is a vendor portal the product ships rather than an integration into a third party system. For an e-billing platform the finance system connection is the integration that matters most, and naming it as a category is a genuine positioning claim. Searched the product pages, the owner's material and third party review material on 29 Aug 2026 and located no integrations index page, no named connector, no API documentation, and no statement of which billing format standards are supported.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery and the hosting partner are stated and residency is not addressed. AWS is named as the hosting partner, which the vendor frames as providing security and performance. Searched the vendor site, the FAQ, the press releases and third party material on 29 Aug 2026 and located no named regions, no customer selectable residency, no tenancy model, and no statement of where processing happens as distinct from where data is stored. The absence is more consequential than for most records here: the vendor is headquartered in Ireland, sells to enterprises with complex multi jurisdictional operations, and states GDPR compliance, so where invoice narratives describing legal work are processed and stored is a question its own customer base would be expected to ask.
EVIDENCE FLOOR: see the build log warning on this record. Searched the product pages, the owner's material, press coverage and three targeted searches on 29 Aug 2026. Nothing was located on the deployment model: no hosting provider, no named regions, no customer selectable residency, no tenancy model, and no statement of where processing happens. The product is evidently cloud delivered, which is inference from how it is sold and earns nothing on this axis. Rebuttable with one link.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
CORRECTED 29 Aug 2026 during the trust portal sweep; grade held at B and the currency finding is now firmer. The vendor's security page, not reached in the original pass, states the certification set and scopes it precisely: externally validated through ISO 27001:2013, SOC 1 and SOC 2, with annual AICPA System and Organization Controls reports prepared across all five trust categories, SOC 1 Type 2 covering controls relevant to financial reporting and SOC 2 Type 2 covering Security, Availability, Processing Integrity, Confidentiality and Privacy. Naming all five categories rather than the usual three is more precise than almost any record on this index. A Cloud Security Alliance CAIQ is available with the reports on request. A separate trust centre exists for the vendor's Workspace product at a stable URL, stating annual audits by an independent CPA firm, first SOC 2 audit in February 2021, and reports available by request through the service portal. Why the grade holds at B rather than rising. The evidence route for the main platform is still a request to the team rather than a self serve portal. No coverage period, report date or auditing firm was located for the main platform. And the currency question is now stronger rather than weaker: the ISO 27001:2013 reference appears on the vendor's own current security page, not only in an FAQ, and that revision was withdrawn and superseded by ISO/IEC 27001:2022, whose transition deadline has passed. A vendor stating a withdrawn revision on its live security page is a finding worth recording plainly, and it remains rebuttable by a current certificate.
CORRECTED 29 Aug 2026 during the trust portal sweep. Previously graded D on the finding that no trust centre, security page or certification listing existed after three targeted searches. That finding was wrong. A trust centre does exist at trust.onit.com, operated by the owner on the Vanta platform, with a dedicated controls section and a stated commitment to protecting customer data through published practices and transparency. It is reachable without a sales conversation, which under the three tier test is a self serve route rather than a gate. That alone lifts this off a pure absence. The owner also publishes SOC 2 Type 2 attestation for at least one other product in its portfolio, a virtual data room, alongside AWS hosting, permission based user roles, two factor authentication and encryption, which evidences that the owner holds product level certifications and publishes them. Why the grade is C rather than higher. The trust centre renders its content client side and its certification list was not retrieved in this pass, so no certification is confirmed as covering this product specifically. No coverage period, audit scope, report date or auditing firm was located for this product. The SOC 2 located belongs to a sibling product and was not read across. Rebuttable in one step by retrieving the trust centre's compliance list, which remains the highest value check on this record.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No model, provider, hosting location for model processing, or subprocessor was located, and no commitment to notify customers of supply chain changes. AWS is named as the hosting partner for the platform, which is infrastructure rather than a model supply chain disclosure and was not treated as one. The gap covers both layers of this product's AI: the language analysis that codes invoice narratives, whose nature is not described beyond being language analysis technology, and Ask Brightflag, a conversational interface whose underlying model is not identified anywhere located. A buyer cannot determine from published material which company, if any, processes their invoice narratives.
The vendor's own model layer is described and nothing beneath it is identified. Published: InvoiceAI as proprietary machine learning trained on millions of legal invoice charges, working alongside existing rules engines, and developed by the owner rather than licensed in, which tells a buyer the invoice review capability is not a thin wrapper on a third party model. The owner separately built or acquired several other AI products, so an in house model capability is evidenced. Searched the product pages, the owner's material and press coverage on 29 Aug 2026 and located no named foundation model or provider, no statement of where models run, no subprocessor list, and no commitment to notify customers when the supply chain changes. Note the currency question flagged elsewhere on this record: the detailed AI description dates from 2021 and current product pages describe AI capability without naming InvoiceAI, so what powers the product today is not confirmed.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Checked the vendor site, the FAQ and the press releases on 29 Aug 2026. No pricing page was located, no rate is published, no unit of charge is stated and no tier structure appears on the surfaces reached. Third party sources state pricing is not publicly available and requires a custom quote, structured on subscription and varying with organisation size and the volume of legal spend managed, which confirms the absence and identifies the unit of charge without the vendor publishing it. Worth recording plainly because of what this product is: a platform sold on delivering visibility and transparency into legal spend, which does not publish what it costs. That is not a grading factor beyond the D, but it is the sharpest instance of the pattern on this index.
Checked the product pages, the owner's material and third party review material on 29 Aug 2026. No pricing page was located, no rate is published, no unit of charge is stated and no tier structure appears. Third party sources confirm the absence directly, one stating there is no public pricing as at May 2026 and another that plans are customisable and require a personalised quote. Every commercial path located terminates in a demo or quote request. Same pattern as the other record in this category, and the same irony applies: a platform sold on delivering visibility and control over legal spend does not publish what it costs.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is described in general terms with the detail not reached. The vendor states its customers are corporate legal departments across industries and range from high growth companies to global enterprises with complex multi jurisdictional operations, and identifies the buying roles as in house legal, legal operations and their finance counterparts. Its FAQ begins an enumeration of the industries served but that list was not captured in this pass and is not credited. Practice scope is clear and consistently stated as outside counsel spend, matters, vendors, budgets and reporting, with no claim to advisory or drafting capability. Not located as of 29 Aug 2026: an enumerated industry or practice area list, organisation size segmentation, jurisdictional coverage, and any statement of what the platform is not built for. Flagged as rebuttable in one step by reading the FAQ industry list.
Segment coverage is described with substance and, unusually, the boundary is published by the owner rather than inferred. The buyer is stated as in house legal teams needing matter management, e-billing and spend visibility without full enterprise implementation complexity, and the owner positions this product explicitly against its own enterprise tier platform, so a prospect is told which of the two is meant for their situation. That is a vendor stating what its product is not for, which few records here do. Scale is quantified at more than 550 corporate legal departments. Practice scope is clear and consistent as spend, matters, vendors and reporting, with no claim to advisory or drafting capability. Not located as of 29 Aug 2026: an enumerated industry list, organisation size bands stated numerically, jurisdictional coverage, and any language support statement.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No located material states whether customer content may be used to train models, either way. Recorded as silent under the rule that a value is never inferred from the absence of a contradiction, and specifically not inferred from the ISO 42001 certification, which evidences that an AI management system exists rather than what its training position is. The question carries unusual weight for this product. The material at issue is invoice narratives describing legal work across many companies and many law firms, and the vendor's own benchmarking and vendor profiling features depend on cross customer comparison, so a buyer would reasonably want to know what is pooled, in what form, and for whose benefit. Nothing located addresses it.
Training on customer derived data is the stated design and no policy governing it was located. The owner publishes that InvoiceAI has been trained on millions of legal invoice charges, that it analyses historical invoices to train its models, and that it continuously learns as invoice corrections are refined in the system. So the product improves from customer invoice data and customer review decisions by design. What was not located, after searching the product pages, the owner's material, press coverage and three targeted searches on 29 Aug 2026, is any statement of whose invoices those are, whether learning is confined to a single customer's tenant or pooled across customers, whether the data is aggregated or anonymised first, or whether a customer can decline. Recorded as silent because no policy statement exists in either direction, and the description of the mechanism is not a commitment about the boundary. This is the most consequential unanswered question on the record.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No public material states how long invoices, narratives, AI generated flags, summaries or Ask Brightflag conversations are retained, whether a customer controls the window, or whether deletion is available. The platform is a system of record for spend and matter history and its analytics, forecasting and rate benchmarking features depend on multi year retention, so long retention is inherent to the value proposition and no published terms govern it.
Searched the product pages, the owner's material, press coverage and three targeted searches for a security or trust page on 29 Aug 2026. No public material states how long invoices, narratives, AI flags or review decisions are retained, whether a customer controls the window, or whether deletion is available. The platform is a system of record for spend and matter history whose reporting, accrual and forecasting features depend on multi year data, so long retention is inherent to the product and no published terms govern it.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
CORRECTED 29 Aug 2026 during the trust portal sweep. Previously recorded as not addressed on the finding that no vendor material described segregation and that third party references to access controls were assertions relayed rather than a documented model. The vendor's security page, not reached in the original pass, documents the model. Published: out of the box user roles and access permissions with a detailed breakdown available in the help centre, so the roles are enumerated somewhere a customer can read rather than merely asserted; single sign on via SAML with named identity providers; SCIM support for provisioning, permission management and de-provisioning; OAuth on the API; and optional restriction of access to specified IP ranges. That is the product's own permission model, described at mechanism level. Recorded at own model documented rather than the positive value for two reasons. No material states that the AI layer respects those permissions at query time, which matters because Ask Brightflag is described as a conversational interface accessible to every person in the legal department and the underlying data includes invoice narratives describing sensitive matters. And no document management integration was located whose access model could be inherited. Conflicts and ethical walls are not named as such.
Searched the product pages, the owner's material, press coverage and three targeted searches on 29 Aug 2026. No vendor material addresses segregation between users, teams or matters. The question has real weight for this product because CounselGO gives outside counsel their own access into the system, so multiple law firms interact with the same platform on behalf of the same client, and nothing published describes what each firm can see or how their access is bounded. No document management integration was located whose permissions could be inherited.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026, and no published customer agreement or data processing agreement was reached. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. The exposure is worth naming: a structured record of what every outside law firm did on every matter for a company would be an attractive target for a discovery request or regulatory demand, and nothing published addresses what the vendor would do on receiving one.
Searched the product pages, the owner's material, press coverage and three targeted searches on 29 Aug 2026, and no published customer agreement or data processing agreement was reached. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. Worth naming the exposure: a structured record of what every outside firm did on every matter, across 550 legal departments and $5.2bn of annual spend, is a substantial target for discovery or regulatory demand, and nothing published addresses the vendor's response.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No primary law corpus is identified because the product does not hold one, and the relevant provenance question is a different one that is also unanswered. Invoice review runs against the customer's own invoices and their own billing guidelines, so that corpus is theirs. But the vendor also publishes rate benchmarking and AI built vendor profiles applied to panel management and RFPs, and benchmarking necessarily rests on a comparative dataset drawn from somewhere. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no statement of what the benchmarking corpus comprises, whose data it contains, whether it is aggregated or anonymised, or on what basis it was assembled. Recorded as not addressed on that specific question rather than as inapplicable.
No primary law corpus is identified because the product does not hold one, and the relevant provenance question concerns the training corpus instead. Invoice review runs against the customer's own invoices and billing guidelines, so that material is theirs. But the owner states InvoiceAI was trained on millions of legal invoice charges, which is a substantial corpus assembled from somewhere, and searched the product pages, the owner's material and press coverage on 29 Aug 2026 without locating whose charges they were, on what basis they were used, whether consent was obtained, or how the training set is maintained. Recorded as not addressed on that specific question rather than as inapplicable, on the same reasoning applied to the pre trained model libraries in the ediscovery category.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Searched the vendor site, the FAQ and the press releases on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is a legal spend and matter management platform whose corpus is invoices and billing guidelines rather than case law, so a citator is outside its design entirely.
Searched the product pages, the owner's material and press coverage on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is a legal spend and matter management platform whose corpus is invoices and billing guidelines rather than case law, so a citator is outside its design entirely, consistent with the other record in this category.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No published material describes what the product does when it cannot confidently code a line or assess a narrative against a guideline, and no explicit no answer path or confidence signal exposed to the user was located. Third party review material observes that AI driven invoice analysis may require manual review in complex cases, which suggests some routing to human judgement occurs in practice, but it is an unverified customer observation rather than a published behaviour and was not treated as one. For a product that codes every line of every invoice, how it handles an ambiguous narrative is a live question and is unaddressed.
Searched the product pages, the owner's material, press coverage and third party review material on 29 Aug 2026. No published material describes what the product does when it cannot confidently assess a line or a narrative, and no explicit no answer path or confidence signal exposed to the user was located. The owner's framing runs in the opposite direction, presenting the value as reducing the number of warnings a reviewer must parse and finding issues between the billing rules, which is about surfacing more signal rather than about declining to judge. For a model that classifies every line of every invoice, how it handles genuine ambiguity is a live question and is unaddressed.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note the product does not generate citations or court facing text at all: its output is invoice flags and spend analysis, so the failure mode this database catalogues does not arise here, and a wrong output would surface as a billing dispute rather than a sanction.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note the product does not generate citations or court facing text: its output is invoice flags and spend analysis, so the failure mode this database catalogues does not arise, and a wrong output would surface as a billing dispute rather than a sanction.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512. The absence is more pointed here than for most records, because the professional rules governing legal billing are directly the subject matter of the product: what a lawyer may bill for, what constitutes a reasonable fee, and how work is described to a client are conduct rules, and this platform automates the assessment of exactly that. It engages with the customer's own outside counsel guidelines, which are contractual instruments, and not with the professional standards that sit behind them.
Searched the product pages, the owner's material, the owner's blog and press coverage on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512. As with the other record in this category the absence is pointed, because the professional rules on legal billing are directly the subject matter: what may be billed, what constitutes a reasonable fee, and how work is described to a client are conduct questions, and this platform automates judgements about exactly those, including whether work was performed by an appropriate staff class. It engages with the customer's outside counsel guidelines, which are contractual, and not with the professional standards behind them.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Second record on this index to reach a value above savings claims, and the only one where fee assessment is the entire product. The platform generates a per matter and per invoice record of what the AI flagged, what a reviewer approved and what was ultimately paid, held in controlled approval workflows with complete audit trails, so a legal department has a durable account of how each fee decision was reached and on what basis. That is the artifact this signal looks for, produced as the core function rather than as a by product. Two limits keep it short of the positive value and both matter. First, the record concerns the law firm's billed work rather than any AI assisted work performed by the vendor itself. Second, and more consequential for this index: outside counsel guidelines increasingly address whether and how AI assisted work may be billed, and searched the vendor site, the FAQ and the press releases on 29 Aug 2026 without locating any statement that the AI checks for AI related billing entries or supports a guideline term about them. A product that translates billing guidelines into automated checks, in a market where those guidelines are being rewritten around AI, publishes nothing about that.
Third record on this index to reach a value above savings claims, and like the other in this category fee assessment is the product rather than a side effect. The platform produces a per invoice and per matter record of what the AI flagged, what the reviewer decided and what was approved for payment, held within configurable approval workflows, so a legal department retains a durable account of how each fee decision was reached. The owner also states the resulting information can be used to guide outside counsel on the customer's billing expectations, which turns the record into a forward looking instrument as well as an audit one. Two limits keep it short of the positive value. The record concerns the law firm's billed work rather than AI assisted work performed by the vendor. And searched the product pages, the owner's material and press coverage on 29 Aug 2026 without locating any statement that the AI checks for AI related billing entries, which is now a live term in outside counsel guidelines and which neither record in this category addresses.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
Diligence material exists and reaching it runs through a conversation. The vendor states that security and compliance reports, including a completed Cloud Security Alliance Consensus Assessment Initiative Questionnaire, are available by contacting the team directly, and names SOC 1 Type 2, SOC 2 Type 2, ISO 27001 and ISO 42001 alongside GDPR, CCPA and CPRA compliance. A completed CAIQ is a substantial standardised control disclosure and few vendors on this index offer one. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no subprocessor list, no statement naming which model providers see customer content, no published data processing agreement, and no client facing consent or notification pack. Recorded at on request on the strength of the stated report route.
Searched the product pages, the owner's material, press coverage and three separate targeted searches for a trust centre, security page or certification listing on 29 Aug 2026 without reaching one. No subprocessor list, no statement naming which model providers see customer content, no published data processing agreement, no named certification and no client facing consent or notification material was located. A firm bound by a client AI clause could not assemble a response from anything located. Recorded as an absence on the surfaces reached and flagged with the evidence floor warning on this record, since a vendor of this scale is unlikely to have no such material.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No per document record covering model used, sources retrieved and human verification was located, and no model is identified in published material so the model used could not be stated. Complete audit trails exist over the approval workflow, which record who approved what and when rather than what the AI did and on what basis, and the two were not conflated. Noted for context: this is a spend management platform whose output is invoice flags and financial analysis rather than legal work product, so a judicial AI disclosure order is unlikely to reach it. The nearer analogue would be a fee dispute or a challenge to billing judgements, where the approval audit trail would be the relevant record and does exist.
Searched the product pages, the owner's material and press coverage on 29 Aug 2026. No per document record covering model used, sources retrieved and human verification was located, and no model is identified in current published material so the model used could not be stated. Configurable approval workflows record who approved what, which is a decision trail over the payment process rather than a record of what the AI did and on what basis, and the two were not conflated. Noted for context: this is a spend management platform whose output is invoice flags and financial analysis rather than legal work product, so a judicial AI disclosure order is unlikely to reach it, and the nearer analogue is a fee dispute where the approval trail would be the relevant record.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- AI Liability and Recourse
- Commercial Transparency
- Prompt and Output Retention
- Third Party Request and Subpoena Notice
- Primary Law Corpus Provenance
- Good Law Verification
- Refusal and Uncertainty Behaviour
- Bar Guidance Alignment
- Court Disclosure Support
Which one fits
Choose Brightflag if
- You want the review to run off your own guidelines rather than a generic rule set. Brightflag reads, codes and categorises every line of every invoice narrative, and translates a legal team's outside counsel billing guidelines into rules the AI checks each invoice against, flagging both guideline breaches and departures from general billing practice without requiring the outside firm's involvement, with a controlled approval workflow and full audit trail sitting between a flag and a payment.
- Your assurance review covers the AI as well as the platform. Brightflag holds ISO/IEC 42001 for AI management systems alongside SOC 1 Type 2, SOC 2 Type 2 and ISO 27001, with the SOC reports prepared annually across all five AICPA trust categories, being security, availability, processing integrity, confidentiality and privacy, which is broader scope than most vendors state.
- You want named controls, not adjectives. Brightflag publishes AES-256 encryption at rest with keys in AWS Key Management Service, minimum TLS 1.2 in transit, single sign on through six named identity providers including Okta, Azure Active Directory and Ping, SCIM provisioning so access is removed when a person leaves, optional restriction to specified IP ranges, and a Cloud Security Alliance questionnaire available with the reports on request.
Choose SimpleLegal if
- You want volume evidence rather than a logo wall. SimpleLegal's owner states more than 550 corporate legal departments and 5.2 billion dollars of annual legal spend processed as at May 2026, which measures work flowing through the system rather than seats sold, alongside a published customer figure of 10 per cent of legal spend identified in savings.
- You want to know what the model is actually looking for. InvoiceAI is described by issue type rather than in general terms, covering non working travel, block billing, vague or insufficient descriptions, improperly billed administrative tasks, improper invoice coding and work performed by the wrong staff class, with findings integrated into the existing rules engine so machine learning and deterministic rules run together, and the models continuing to learn as invoice corrections are made.
- You do not want an enterprise implementation. SimpleLegal is positioned by its owner for in house teams needing matter management, e billing and spend visibility without full enterprise complexity, and explicitly against the enterprise tier platform in the same portfolio, so a prospect is told which of the two is meant for their situation, with CounselGO as the portal outside counsel work through.
In summary
Brightflag
Brightflag is an AI powered enterprise legal management platform for in house legal departments, covering legal spend and e billing, matter management, vendor management and analytics, built around AI invoice review that reads, codes and categorises every line of every invoice narrative and checks it against the department's own outside counsel billing guidelines. The AI Legal Index grades it in the top two bands on seven of fifteen capability axes, with A grades on AI centrality and AI governance: it holds ISO/IEC 42001 for AI management systems alongside SOC 1 Type 2, SOC 2 Type 2 across all five trust categories and ISO 27001. As of 29 August 2026 the index located no liability position, no named model provider, no retention period and no published price.
SimpleLegal
SimpleLegal is a midmarket enterprise legal management platform for in house legal teams covering e billing and invoice review, matter management and intake, vendor management, budgets, accruals and reporting, with CounselGO as the portal outside counsel collaborate through and InvoiceAI as the machine learning layer trained on millions of legal invoice charges. The AI Legal Index grades it in the top two bands on five of fifteen capability axes. Its owner states more than 550 corporate legal departments and 5.2 billion dollars of annual legal spend processed as at May 2026, and positions the product explicitly against its own enterprise tier platform. As of 29 August 2026 the index located no liability position, no retention or training terms and no published price.
Questions buyers ask
Brightflag vs SimpleLegal: which is better for legal spend management?
The AI Legal Index places Brightflag in the top two bands on seven of fifteen capability axes and SimpleLegal on five. Brightflag's lead is assurance: an AI management certification, SOC reports across all five trust categories, and a security page that names its controls. SimpleLegal answers on scale, with 5.2 billion dollars of annual spend processed, and on fit, since its owner states plainly which of its two platforms suits which buyer.
Which one publishes an AI certification?
Brightflag does. It states certification to ISO/IEC 42001, the international standard for AI management systems, which covers governance of the AI lifecycle rather than information security alone, and it sits alongside SOC 1 Type 2, SOC 2 Type 2 and ISO 27001. No certifying body, certification date or scope statement for the 42001 was located. On SimpleLegal no AI governance framework, principles document, certification or named owner of model governance was located as of 29 August 2026. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What does the AI actually check?
Both check invoices against the department's own billing guidelines and both make the flag traceable to a line a reviewer can open. Brightflag translates the guidelines themselves into rules the AI applies, so the comparison sits between the invoice and the customer's own document. SimpleLegal enumerates the issue types its models detect, including non working travel, block billing, vague descriptions and work by the wrong staff class, and runs them alongside the existing rules engine rather than in place of it. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Do either publish how often the AI is wrong?
Neither publishes a figure. No accuracy rate, false positive rate, false negative rate, test set or evaluation appears on either record, and the numbers both publish measure savings found rather than errors made, including an average of six figures in travel related billed time identified across SimpleLegal's customers. On a product whose output reduces a payment, the false positive rate is the number a buyer most needs and neither vendor states it. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What do Brightflag and SimpleLegal both leave unpublished?
Neither publishes a price, a tier structure or a unit of charge, which is worth noting on platforms sold to deliver visibility into legal spend. Neither names the model or the provider behind its invoice analysis. Neither states a retention period or deletion control for invoices, narratives or model outputs. Neither states a hosting region or a tenancy model. And neither publishes an indemnity, cap or warranty of any kind. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
One gap is shared and it is structural to this category. Neither vendor publishes a liability position, so nothing states what happens when a flag is wrong, and the party that bears the direct financial consequence is the law firm whose invoice is reduced, which is not the vendor's customer and has no contractual relationship with it at all. On SimpleLegal, the owner states that the models are trained on millions of legal invoice charges and continue to learn from customer corrections, so training on customer derived material is the stated design, and nothing published states whose data, whether learning is pooled across customers, or whether a customer can decline. Several absences on that record are limits on this reading rather than findings: the owner's trust centre renders client side and its control and certification list could not be retrieved. Both records were verified on 29 August 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.