Case Status vs Quilia: how they compare in 2026
Case Status and Quilia both give a firm's clients an app that shows where their case stands, sitting on top of the firm's case management system. Quilia sits in the top two bands on twelve of fifteen axes and Case Status on six of fifteen, identical on five. Quilia's lead is the checks around its AI. Nothing its AI extracts from a client's records reaches the case file until the client confirms it, and a confirmation can be undone for ten minutes. Its client agreement states that the app gives no legal advice. Its terms let it process customer data with machine learning for the benefit of all its customers, and promise only that it does not train public models. Case Status's counterweight is an audit a buyer can name. It states a SOC 2 Type II examination by Modern Assurance covering all five trust services criteria, completed in July 2024, where Quilia cites only its hosts' certifications. It also names Pond Lehocky, with close to 15,000 clients on the app.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The product was a client portal before it was an AI product and the portal still stands on its own. Real-time case status, the branded passwordless app, secure messaging, document upload, stage videos and NPS-driven review prompts are all conventional software, and the CMS sync that feeds them is an integration rather than a model. On top of that sits a named set of model-driven features the vendor sells individually: Agentic AI Translation, Agentic AI Case Summary, Agentic AI Response and Prioritization, an AI Triage Agent, AI Automation Agents and Client Sentiment Tracking. That is the B band: the models power a core capability layered on a product that would still function without them as a communication and status system. Pages read 1 September 2026.
The models are the engine of the thing the firm is actually buying, on a product that would still stand without them. Strip the AI out and Quilia is a competent client app: a mobile file where an injured client logs visits and pain scores, uploads records and photographs, signs documents and messages the firm, syncing both ways with the case management system. What the AI adds is the part the firm cannot staff. It reads each upload, extracts the provider, dates, parties, location, treatment details and injury descriptions, classifies images, files everything chronologically, and asks the client to confirm what it found before it lands on the case. It tracks treatment against what is on file and surfaces gaps. An AI case assistant called ℚ, which reads a client their own file and records their spoken answers, is described by the vendor as rolling out rather than generally available. Read on the artificial intelligence, document management and HIPAA pages and in the privacy policy of 6 September 2026. Verified 20 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Nothing published on accuracy or grounding for a system that drafts and translates messages sent to represented clients. The home page, the security commitment page, the Terms of Use and its Limitation on Liability subpage and the privacy notice were read on 1 September 2026; no accuracy figure, no evaluation, no test set, no error rate and no description of how a drafted reply is grounded in the case record was located. The exposure is specific rather than theoretical: Agentic AI Translation renders a firm's message into another language for a client who by definition cannot check it against the original, and Agentic AI Case Summary condenses a matter for a lay reader. D rather than C because C requires accuracy to at least be asserted or grounding to be claimed, and neither was found; the individual AI feature pages were not opened and are the rebuttal route.
No accuracy figure is published, and the checking mechanism is unusually concrete. Nothing the AI extracts reaches the case file on its own: it presents what it found to the client, the client confirms it, and the confirmation carries a receipt that can be undone for ten minutes. The source of every structured item is therefore the document the client uploaded and the client's own confirmation of it, which is as close as this shape gets to grounding a reader can follow. The vendor also describes a pre-release test: every change to how the assistant writes is replayed against the exact inputs real cases produced, each message is graded on a fixed rubric, including whether it is specific to that client's file and whether it crossed any of the published limits, and the grader is run against itself to measure its own noise. That is a method described without its results. No error rate, no sample, nothing on what a wrong extraction costs if the client confirms it anyway. Verified 20 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A review point is published and the rest of the control structure is not. The home page states that Case Status uses case context to suggest responses that staff can review and send in seconds, which places a human between the model and the client on the drafting path, and the Agentic AI Response and Prioritization feature is described as ranking messages by urgency for staff rather than acting on them. Against that, the product also markets AI Automation Agents and a claim that up to 80% of routine client communication is handled automatically, which implies messages reaching clients without a per-message review, and nothing published reconciles the two or says which categories run unattended. No threshold, no escalation route and no statement of what happens after a wrong message is sent were located on 1 September 2026. B on the strength of the stated review-before-send point, held there by the unexplained automation claim.
The controls are published in more detail than most, and the feature carrying the strongest of them is not yet generally available. On the live product the structure is clear: extracted data is proposed, not written, the client confirms each item, the confirmation can be undone, and everything lands in the firm's case management system where the legal team works. The AI case assistant ℚ adds categorical limits, stated as product constraints rather than model instructions: it does not discuss fault, liability, insurance, bills or liens; it never says what the firm is doing or intends to do; it never puts a date on anything not already in the record; the firm's phase label is withheld from the model entirely so it cannot leak one; and it never tells a client their case has ended, in any wording. Asked what a case is worth it declines, explains why no tool can answer, and gives the client the firm's number. Those would carry this row higher, but the vendor describes ℚ as rolling out to firms rather than in general use, and an announced control is not an operating one. Worth re-reading when ℚ is generally available. Verified 20 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
One named firm with a dated figure, and everything else anonymised. Pond Lehocky is named on the home page with close to 15,000 active clients using the app across its workers compensation and social security disability departments, and a before-and-after review metric with a stated window: 4.6 with 417 reviews before, 4.8 with more than 3,000 reviews within 24 months. Shawn Lehocky, Chief Executive Officer at Pond Lehocky Giordano, appears on record. The three growth case studies are deliberately unattributed, identified only by practice and city: an SSD firm in Charleston WV doubling caseload in a year, a PI firm in Chicago at 40% year-over-year growth, a large PI firm in Kansas City with a 35% increase in case velocity. Firm count is internally inconsistent, 600-plus in the page header and more than 500 in the body. B: real deployment evidence with substance, short of full attribution. G2 ratings, badges and review quotes were excluded as directory material.
Named firms and a survey figure, never joined to each other. Five law firms are named with the people who spoke for them: Brian Riley and Liz Lasslett of Kurtz Riley Law Group, Brandon Hewitt of Michigan Auto Law, Monica of Bay Injury Law, and Dean Tingey of Tingey Injury Law Firm, whose account is the most specific, that the product found treatment gaps the firm had been leaving money on. Separately the vendor publishes that 82% of clients would recommend their attorney because of Quilia, from 568 clients surveyed, and says plainly that this is a survey rather than a selected quote. The sample size is given; the date, the question wording, who was asked and how they were selected are not. None of the named firms is attached to a figure for what changed, and no dated case study exists on the estate. Client testimonials on the same page are user satisfaction, not deployment evidence. Verified 20 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Confidentiality is asserted in general terms while the instrument that would carry it is absent. The security commitment page describes multiple layers of encryption, least-privilege development, mandatory two-factor authentication, background checks and ongoing security training, and the GDPR section states plainly that Case Status acts as a data processor for law firms. But no law firm customer agreement is published anywhere: the only agreement on the site is End User Terms of Use binding the firm's clients. Nothing addresses training on client content, matter or tenant segregation, or privilege and work product, which matters here because the platform carries attorney-client communications by its own description. The privacy notice also grants the app access to contacts, microphone, calendar, reminders, SMS messages and continuous geolocation, a permission scope wider than a case-status app needs, and nothing published explains why. C.
Strong written commitments, and one published sentence that sits badly against the product. The Terms of 22 May 2026 carry mutual confidentiality surviving three years, with trade secrets protected for as long as they qualify, and a compelled-disclosure clause requiring prior written notice and assistance in seeking a protective order. The customer owns its data. Three separate documents say customer data is not used to train AI models. Row-level security confines a client to their own case and a firm to its own data, a Business Associate Agreement is available on request, and the servers are in the United States. Against that: the AI disclosure of 27 December 2025 tells users they are responsible for ensuring that what they put into the app does not contain confidential, sensitive or privileged information, on a product whose purpose is collecting medical records; privilege and work product are named only in the clause disclaiming responsibility for third-party AI assistants a firm connects; and the Terms assign all rights in Resultant Data to the vendor. Verified 20 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
Nothing published on the advice line for a product that generates and translates messages to represented clients. This is the category where that matters most, because the reader is a claimant who cannot judge whether what arrives is legal advice. No disclaimer of any kind, no statement that AI-generated or AI-translated content is not legal advice, no requirement that a firm disclose AI involvement to its client, and no reference to ABA Formal Opinion 512 or any state bar guidance was located across the home page, security commitment page, privacy notice, the Terms of Use and its Limitation on Liability subpage on 1 September 2026. The End User Terms do address the reader as a client, and they use that space to disclaim liability rather than to explain what the technology does. The individual AI feature pages were not opened and are the rebuttal route.
The advice line is drawn where it matters most, on the surface a non-lawyer actually sees. The End User License Agreement of 10 March 2026, which the injured client accepts before using the app, states that the user shall not rely on any part of the app or its output as legal advice and shall not represent to anyone that it is, that the app does not provide legal advice and creates no attorney-client relationship, and that the user should consult a qualified attorney. The same agreement says the app is prone to error and that output should be reviewed before use. The product draws the line again in its own behaviour: the case assistant does not discuss fault, liability, insurance or liens, never states a case value or a range, and hands the client the firm's phone number instead. The Terms put professional responsibility obligations and the rules of professional conduct on the firm where it connects an outside AI assistant. What is missing is jurisdiction: the product is sold across the United States and nothing names a state limit or addresses the firm's supervision duty over what the assistant says to its clients. Verified 20 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
No governance position located. There is no responsible AI page, no named accountable owner for the AI, no pre-release testing regime and no ISO 42001 or equivalent across every surface read on 1 September 2026. The security commitment page names a Chief Technology Officer, Charles Lane, and the privacy notice names a Data Protection Officer, Andy Seavers, but both are framed around information security and privacy rather than model governance. Nothing addresses whether sentiment scoring, urgency ranking or translation quality behaves evenly across languages or client populations, which is the live question for a product whose clients include immigration and workers compensation claimants communicating in languages the firm may not read. Security certifications are a different subject under this band and are graded on Security Certifications.
A real testing regime is published, with no owner and no findings attached to it. The vendor describes what happens before a change to how its case assistant writes can ship: the exact inputs real cases produced are replayed against the new wording, every resulting message is graded on a fixed rubric covering whether it is specific to that client's file, whether each sentence stands on its own read cold, and whether it crossed any of the published limits, and the grader itself is run against itself so its own noise is measured and a small gain is not mistaken for a real one. Published behavioural limits sit alongside it. That is more than a principles page and it is auditable in shape. What is absent is who inside the company owns it, what the replays have found, and anything at all on whether output differs across client populations, languages or injury types, on a product whose users are often in pain, unfamiliar with the process, and served in more than one language through automatic translation. Verified 20 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
A generic privacy notice plus a narrative security page, with the operative details missing or blank. What is published: multiple layers of encryption, least privilege, mandatory two-factor authentication, password and lockout policies, employee background checks, ongoing security training, AWS hosting, and continuous compliance monitoring through Secureframe. What is not: no subprocessor list of any kind, no incident or breach notification practice, and no retention period. The retention section is the specific finding, and it is unusual enough to name. Under the heading on how long information is kept, the privacy notice of 17 July 2025 reads that no purpose in the notice will require keeping personal information for longer than, and the sentence simply ends. The number is missing from the published document. Deletion is committed to once no legitimate business need remains, with an exception preserved for backup archives. C.
Access, infrastructure and incident practice are covered in detail; the end of the data's life is not. Published: dual-layer encryption, AES-256 at the database and AES-256-GCM at the application layer for integration credentials and session data, TLS 1.3 in transit, enforced multi-factor authentication, row-level security at the database, role-based permissions, audit trails of every upload, view and download, automated daily backups with point-in-time recovery, tested restores and stated recovery objectives, and an incident response procedure run by a named team composition of security, legal and technical staff, with supervisory notification inside 72 hours and notification of affected users. Infrastructure subprocessors are named: Supabase for database and authentication, Vercel for the portal and API, Expo for the mobile app, Stripe for payments, PostHog and Sentry in the product. The gaps are retention and deletion: no period is stated for case content, deletion follows an account termination request with exceptions, and the AI providers are named nowhere. Verified 20 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A published allocation that is total, uncapped, and pointed at the wrong party. The Limitation on Liability subpage excludes liability for damages of any kind under any legal theory arising from use or inability to use the service, direct or indirect, whether in negligence or contract and even if foreseeable, expressly naming personal injury, pain and suffering, emotional distress, loss of data and loss of goodwill among the excluded categories. There is no cap, because there is no fee: these are End User Terms binding the law firm's client, not the firm. That the excluded heads of damage are personal injury, pain and suffering and emotional distress, in a product sold into personal injury, workers compensation, disability and mass tort practice, is worth a buyer reading twice. No firm-facing agreement, indemnity, warranty on output or insurance position is published. C rather than D because a specific and readable allocation exists; C rather than B because nothing runs toward either the firm or its client.
Liability is handled by limitation and disclaimer, and the exposure the product creates is pushed outward. The Terms of 22 May 2026 cap the vendor's total liability at the fees paid in the single month before the event for customers paying monthly, or twelve months for annual payers, exclude consequential and indirect damages both ways, apply the caps to negligence and even where remedies fail of their essential purpose, and provide the services as is with all implied warranties disclaimed. No indemnity runs to the customer. The client-facing agreement asks the injured user to agree not to hold the vendor liable for any loss arising from reliance on app output. Where a firm connects an outside AI assistant, the Terms put errors, omissions and hallucinations on the firm. What does exist is a service level: 95% availability measured yearly, with credits as the sole remedy, capped at 5% of fees and claimable only within 24 hours. That answers downtime, not a wrong extraction on a case file. Verified 20 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The integration set is the strongest part of the product proposition and is named in full. Thirteen case management platforms are listed with individual integration pages: Clio, Litify, MyCase, Neos by Assembly, Filevine, CASEpeer, SmartAdvocate, SmokeBall, PracticePanther, CoCounselor, Meruscase, Docketwise and Salesforce. Eight of those are systems this index already covers, which tells a buyer the product genuinely sits in the plaintiff and small-firm stack rather than beside it. The positioning is explicit and useful: Case Status describes itself as the communication layer living inside the case management platform, with staff working where they always have and everything syncing automatically, and one published customer account describes it running inside Litify in a frame. B rather than A because what syncs, in which direction and what a firm must configure is not described on any page read on 1 September 2026; the individual integration pages were not opened and are the rebuttal route.
This is the strongest part of the record, and it is documented rather than listed. Named integrations with the systems personal injury work already lives in: Clio, Filevine, MyCase, CasePeer, SmartAdvocate, Litify, Neos, Smokeball, Salesforce, CasePacer, FileMaker and Neostella, each with its own page. The direction is stated: two-way sync, with documents, treatment updates, confirmed extractions and client messages flowing into the firm's case file and matter data flowing back, and the firm invites a client with one click from inside its own system. What moves is scoped: the vendor describes API-only integration in which it stores no protected health information from the external system and syncs case metadata, with integration credentials encrypted before storage. Configuration is described too, including who does it and how long it takes, with guides published and custom routes through Zapier and an API. A Model Context Protocol connection lets a firm point its own AI tools at its Quilia case data. Verified 20 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery is named and neither dimension a buyer needs is stated. The security commitment page states that Case Status runs on Amazon Web Services and describes the reasoning as scale and redundancy rather than as a tenancy architecture. The privacy notice states that servers are located in the United States and that information from users outside the US will be transferred to and processed there, which fixes a default location but is not a residency offering. No tenancy model is published, no region option is offered, and processing location is not distinguished from storage. For a product whose stated practice areas include immigration, and whose users therefore include clients outside the United States, the absence of any region choice is worth noting. C on the band's words: cloud delivery is evident and neither the tenancy model nor a selectable region is stated.
Both questions are answered and neither is a choice. Tenancy: a shared platform with separation enforced in the database itself through row-level security, so a client sees only their own case, a firm only its own data, and administrators only what their role allows. Residency: the privacy policy of 6 September 2026 states that the servers are in the United States, and the vendor names the providers that hold the data, Supabase for the database, Vercel for the portal and API functions, Expo for the mobile app, with daily backups held in geographically distributed storage for redundancy. What is not published is any option or any detail beyond that. No single-tenant or private deployment, no region selection, nothing distinguishing where processing happens from where data rests, and no statement of where the AI providers process what is sent to them, since those providers are not named. Verified 20 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The best attestation particulars located in this pull, with no way to obtain the report. The security commitment page names the auditor, Modern Assurance, describes it as an independent third-party accounting and auditing firm, states the scope as all five trust services criteria by name (security, confidentiality, availability, privacy and processing integrity), and gives completion dates for both audits: SOC 2 Type I in September 2023 and SOC 2 Type II in July 2024. HIPAA compliance is claimed on the basis that legal practices serve clients who are also patients, and Secureframe is named for continuous monitoring. Two things hold this at B. There is no trust centre or portal and no stated route by which a buyer could request any report, so the evidence is described rather than accessible. And the most recent attestation stated is now over two years old, with the commitment to ongoing audits expressed as intention rather than as a published subsequent report.
No independent attestation of this vendor was located, and the vendor does not claim one. What it publishes, accurately, is that its infrastructure providers hold SOC 2 certification: Supabase, Vercel and Expo are named as SOC 2 certified cloud providers. That is its hosts' attestation, not its own, and the distinction is the vendor's own wording rather than a reading imposed on it. HIPAA compliance is asserted directly and in detail, with a Business Associate Agreement offered on request, but HIPAA compliance is a legal obligation the vendor states of itself rather than an audit anyone else performed. No SOC 2 or ISO report for Quilia, no penetration test summary, no trust centre, no audit period or scope, and nothing obtainable by a buyer without asking. Checked the HIPAA and security page, the detailed HIPAA documentation link, the terms, the privacy policy, the AI disclosure and the full footer on 20 September 2026. Verified 20 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Nothing published about the model supply chain a customer inherits. The product markets six separately named AI capabilities and an entire Data and Agentic AI solution page, and across every surface read on 1 September 2026 no model, no model provider, no inference location and no change-notification commitment appears. There is no subprocessor list of any kind on the site, which is the ordinary route to this disclosure and which several vendors in this pull publish openly. AWS is named on the security commitment page but hosting answers where the software runs rather than whose model reads client messages, and cannot be spent here. D rather than C because C requires the vendor at least to refer to the models underneath in some form, and no reference to a model layer was located at all.
The commitments about AI providers are specific and the providers themselves are never named. The AI disclosure of 27 December 2025 says the vendor may work with various AI providers and models, selected against its security, privacy and performance standards, that any provider must meet its requirements, and that specific retention periods and handling practices vary by provider and will be disclosed. The privacy policy adds that data is not shared with AI providers for their own purposes and that AI processing is scoped to the case. None of that is checkable, because no model, version or provider appears anywhere on the estate, nothing says where inference runs, and the promise to disclose per-provider practices is written in the future tense. By contrast the vendor names its infrastructure providers plainly, which shows the omission is a choice rather than an oversight. Nothing commits to telling customers when a model or provider changes. Verified 20 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information at any level. There is no pricing page: the navigation, the footer and the resource menus were checked on 1 September 2026 across the home page, the security commitment page, the terms index, the Limitation on Liability subpage and the privacy notice, and none carries a pricing entry. No tier names, no packaging structure, no unit of charge and no figure are published, and every commercial route is a demo booking, a tour or a calendar link. D rather than C because C requires the shape to be visible with only the number withheld, and here neither is. Under the pricing-row rule there is no published structure, so no VendorPricing row was written.
The shape of the bill is published in the agreement; the numbers are not. The Terms of 22 May 2026 set out the structure clearly: fees are stated in an order form, capacity is sold as a case tier with a limit on the number of cases, and exceeding it triggers case overage fees and excess user fees, with the vendor entitled to refuse the overage instead. Payment runs monthly or annually, the distinction matters enough that the liability cap differs between them, fees can be changed on 30 days' notice at the end of a term, late balances carry 1.5% a month, cancellation takes effect 30 days before the next renewal with access continuing to the end of the period, and unused subscription time is refundable pro rata. The Terms also record that the fee may be billed on to the client as a hard cost recoverable at settlement. What no buyer can learn without a demo is any rate, any tier size, or what implementation adds. Verified 20 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Practice coverage is unusually specific and firm segmentation is not. Eight practice areas each have their own page with copy describing the work: personal injury, workers compensation, immigration, employment, disability, mass tort, estate planning and criminal. That is a real statement of where the product is aimed, and it is coherent, since all eight are high-volume matters where a client waits a long time with little news. What is missing is the other half of the band: no firm-size segmentation, no in-house or government position, and no statement of where the product stops. The customer evidence points at plaintiff-side and claimant-side firms of varying size but the vendor never says so directly. B rather than A because the limits are not stated.
The practice boundary is stated plainly, which is rare, and the firm boundary is not stated at all. The vendor says it is built for personal injury and workers' compensation first, that the underlying approach of collecting client information and structuring it into the case file applies to other case types, that it expands on firm demand, and that a firm in another practice area should ask where it fits today. That is a limit a buyer can act on rather than a claim of universal coverage. Within personal injury the coverage is specific: motor vehicle, treatment-heavy claims with multiple providers, builder and provider documentation, e-signature, intake checklists and multi-case clients. What is absent is any statement of firm size or type. The named reference firms are small and mid-size plaintiff practices, there is nothing on high-volume or mass tort inventories beyond an integration with systems that serve them, and in-house and government use is not addressed, which is consistent with the product but left unsaid. Verified 20 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses whether client content is used to train models. The privacy notice of 17 July 2025 was read in full and does not mention artificial intelligence, models or training anywhere. The home page, the Data and Agentic AI solution listing, the security commitment page, the Terms of Use and its Limitation on Liability subpage were also checked on 1 September 2026. No law firm customer agreement is published.
The Terms of Use are split across roughly two dozen subpages, of which a Contribution License subpage exists and could not be retrieved; that is the rebuttal route and nothing is graded against the vendor for it.
The policy pages say never; the contract says something narrower. Three published surfaces carry the flat statement: the AI disclosure of 27 December 2025 says customer data is not used to train AI models and is not exposed to public models or shared with third parties for training; the privacy policy of 6 September 2026 repeats it and adds that AI processing is initiated by the legal team and scoped to the case; the AI product page answers the same question the same way.
The Terms of 22 May 2026 commit to less. Section 2.8 permits the vendor to process customer data with machine learning and AI for the benefit of all of its customers, and its promise is that it does not train public models or inappropriately disclose customer data for such purposes, which leaves a model of its own untouched by that sentence. Section 16.1 also assigns all rights in Resultant Data to the vendor. A firm that needs never rather than not publicly should ask for it in the order form.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is acknowledged and the period is missing from the published document. The privacy notice of 17 July 2025 commits to keeping personal information only as long as necessary for the stated purposes unless a longer period is required or permitted by law, and then states that no purpose in the notice will require keeping it for longer than, with the sentence ending there and no figure supplied. Deletion or anonymization is committed to once no legitimate business need remains, with information in backup archives isolated from further processing until deletion is possible. Nothing separately addresses retention of client messages, AI-drafted replies or translations.
Retention is addressed and never given a period. The AI disclosure says data processed by the AI is governed by the privacy policy and that personal information is kept while the account is active; the privacy policy says information is kept as long as necessary for the stated purposes, and that when there is no ongoing need it is deleted or anonymized, or isolated from further processing where it sits in backup archives.
Deletion follows a request to terminate an account, with material retained where needed for fraud, investigations, enforcement or law. For the AI specifically, what is said is that processed data is stored under the same access controls as other case data. What a firm cannot learn is how long the text sent to an AI provider is held by that provider, since no provider is named, whether extraction inputs and outputs are kept separately from the case file, or what happens to a client's data when the matter closes rather than when the account does. No customer-set window exists.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses ethical walls, matter-level segregation or tenant separation. The security commitment page describes least-privilege development practice, two-factor authentication and employee access discipline, which are internal controls on Case Status staff rather than a segregation model between a firm's matters or between firms on the platform. One published customer account describes co-counsel and branding features, implying some access partitioning, but no document describes how any boundary is defined or enforced. Checked across the home page, security commitment page, privacy notice and Terms of Use on 1 September 2026.
Separation is enforced where it is hardest to bypass, and the vendor says where. Row-level security operates at the database itself: a client reaches only their own case, a firm only its own data, and administrators only what their role permits. Role-based permissions govern which members of a legal team can open which documents, audit trails record every upload, view and download, and integration credentials for the firm's case management system are encrypted before storage.
Two details go further than most: the client app is built around the client's own file rather than the firm's, so a client never holds a view across matters, and case delegates, the family members or helpers a client can add, are a named and bounded role rather than a shared login. What is not described is any wall between matters inside one firm, which matters where a firm acts for two clients in the same collision.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
The privacy notice addresses compelled disclosure under a Legal Obligations heading covering applicable law, governmental requests, judicial proceedings, court orders, subpoenas and national security or law enforcement requirements. A separate Vital Interests limb reaches further, permitting disclosure where Case Status believes it necessary to investigate suspected policy violations or fraud, to address safety threats, or to use the information as evidence in litigation it is itself involved in.
No commitment to notify the customer or the client, and no carve-out for notice where lawfully permitted, was located on 1 September 2026, and no transparency report is published.
The commitment is in the agreement and it goes further than notice. Section 15.4 of the Terms of 22 May 2026 requires the party compelled by law to disclose confidential information to notify the other in writing promptly and before disclosing, so that the other can seek a protective order or waive its rights, to give reasonable assistance in opposing the disclosure, and to disclose only the portion legally required.
It is mutual and it is not qualified by cost beyond who pays for the opposition. Two limits a firm should hold. The clause attaches to confidential information under Section 15, not expressly to every item of case data, and the privacy policy describes disclosure to comply with a court order, subpoena or law enforcement request without attaching any notice to it. The Terms also allow suspension of the service on receipt of a governmental demand. No transparency report is published.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The product does not retrieve primary law, so there is no legal corpus to source. Case Status draws on the firm's own case record synced from its case management system, plus the message history between firm and client, to generate summaries, translations, urgency rankings and suggested replies. No public material identifies any statutory or case law source, license basis or update cadence, checked across the home page, solution and security pages, privacy notice and Terms of Use on 1 September 2026. Recorded as not addressed because the question does not arise for this product class.
There is no legal corpus here to have provenance. The material this product works on is the client's own: the police report, the medical records and bills, the photographs, the appointments and pain scores they enter. No case law, statute or secondary source is drawn on, licensed or named, and the estate's legal glossary and state rules pages are consumer explainers rather than anything the product reads. What stands in the place of provenance is per-item: the AI proposes what it extracted, the client confirms it before it reaches the case file, and the confirmation carries a receipt that can be undone for ten minutes, so each structured fact traces to a document the client supplied and an act of confirmation.
That is recorded as the accuracy mechanism on the capability row rather than counted twice here. Nothing addresses what the underlying models were trained on.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No citator, and none would apply. The product summarizes case progress and drafts client-facing messages rather than citing legal authority whose subsequent history could be checked. Nothing on the home page or the AI feature listings addresses legal authority at all. Checked 1 September 2026.
Nothing in this product cites legal authority, so there is nothing for a treatment signal to check. The output is structured case facts, treatment timelines and messages to a client, not propositions of law with citations behind them. The vendor draws that line itself in what its case assistant will not do: it does not discuss fault, liability, insurance, bills or liens, and it never puts a date on anything not already in the record.
The estate does publish a legal glossary and state-by-state rules pages, which are written for injured clients reading about their own situation rather than for a lawyer relying on them, and no currency or verification practice is described for them.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer or is uncertain. The AI features are described as suggesting responses, summarizing a case, translating a message and ranking urgency, and in each case the published description assumes an output is produced; no confidence signal, no fallback to manual handling and no abstention path is documented. Checked across the home page, the Data and Agentic AI listing, the security commitment page, the privacy notice and the Terms of Use on 1 September 2026. The individual AI feature pages were not opened and are the rebuttal route.
The refusals are written down, in detail, as product limits rather than model instructions. The case assistant does not discuss fault, liability, insurance, bills or liens; it never states what the firm is doing or intends to do; it never puts a date on anything that is not already in the record; the firm's internal phase label is held out of everything the model is shown, so it cannot repeat one it was never given; and labels meaning a case has ended are blocked outright.
Asked what a case is worth it does not deflect to ask your firm: it says no tool can put a fair number on a case because too much of what decides it is not on the file yet, names treatment, coverage and what the attorney finds, and gives the client the office number, never a range or an example figure. What holds this short of demonstrable is that the behavior is described rather than shown, and the assistant carrying it is described by the vendor as rolling out.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record naming this product has been located. The AI Hallucination Cases database maintained by Damien Charlotin was searched on 1 September 2026 on the product name alongside general sanctions coverage, and nothing naming the product was found. This is a statement about the public record rather than a finding about the product. Case Status generates client communications rather than citations to legal authority, so the failure mode this signal tracks is not one the product exhibits.
No record was located of this product's output being found fabricated or inaccurate in a proceeding, a regulatory action or a published account. Searches on 20 September 2026 across the vendor's estate, press and directory profiles returned nothing of the kind. The shape of the risk here is different from a drafting or research tool: the product asserts no law and cites no authority, and the failure a firm should watch for is a mis-extracted provider, date or diagnosis reaching a case file after a client in pain confirmed it without reading closely. Nothing published describes such an error, and no account of one was found.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance. ABA Formal Opinion 512 is not named and no state bar opinion appears across the home page, security commitment page, privacy notice, Terms of Use or Limitation on Liability subpage, checked 1 September 2026. The gap is worth naming because the product operates in the area bar guidance speaks to most directly for this category: communication with represented clients, solicitation of reviews and referrals, and the firm's supervisory duty over messages sent in its name.
Professional responsibility is engaged in general terms, and no rule, opinion or bar is named. The client-facing license agreement of 10 March 2026 states that the app does not provide legal advice and creates no attorney-client relationship, that the user must not rely on its output as legal advice or represent to anyone that it is, and that they should consult a qualified attorney. The Terms of 22 May 2026 go further in one place: where a firm connects an outside AI assistant, the firm is made responsible for deciding whether that operator's practices satisfy attorney-client privilege, the work-product doctrine, HIPAA and the applicable rules of professional conduct, and for ensuring its use complies with professional responsibility obligations.
That is the duty referred to as such, without a rule of professional conduct, an ethics opinion or any bar guidance behind it, and nothing engages the guidance on generative AI, supervision or communication with clients.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time and capacity savings, including that up to 80% of routine client communication is handled automatically and that firms doubled caseload or grew 40% year over year without proportional staff increases, without addressing how AI-assisted work should be recorded or disclosed on a bill. No audit record of which client communications were AI-drafted or AI-translated is described. The question is attenuated for the contingency-fee practices the product mainly serves, where the fee does not turn on hours, but it is not absent, since the same firms bill costs and handle fee petitions in workers compensation and disability matters. Checked 1 September 2026.
The vendor's own agreement contemplates the client paying for this. Section 12.3 of the Terms of 22 May 2026 states that the fees for the services may be billed to the client as a hard cost, recoverable at settlement, which in a contingency practice means the cost of the software can come out of the injured person's recovery rather than the firm's overhead. Nothing published addresses what follows from that: no guidance on disclosing the charge in the fee agreement, nothing on how a per-case charge is allocated where a client has several matters or a matter has several clients, and no position on whether a cost recovered at settlement should be disclosed to the client at the point it is incurred.
The fee itself is not published at any level. The firm-facing case for the product is that better treatment documentation raises case value, which is an argument about the client's recovery rather than about the fee.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client-side disclosure obligation. No subprocessor list is published anywhere on the site, no model provider is named, and no trust center, disclosure pack or client-facing consent material exists. The security commitment page describes the SOC 2 audits and names the auditor but offers no artifact a firm could forward. Checked across the home page, security commitment page, privacy notice, Terms of Use and Limitation on Liability subpage on 1 September 2026. Notable because the platform holds attorney-client communications by its own description.
A buyer can name most of the third parties holding the data from published pages, and not the ones processing it with AI. Named: Supabase for the database and authentication, Vercel for the web portal and API functions, Expo for the mobile app, Stripe for payment data, PostHog for product analytics in the app, portal and browser extension, Sentry for error monitoring, and the analytics and advertising tags used on the marketing site.
A Business Associate Agreement is offered on request, a data processing agreement is promised where the law requires one, breach notification runs to supervisory authorities within 72 hours, and the incident response procedure is described. The gap is the one that matters most on this signal: the AI disclosure says only that the vendor may work with various AI providers and that per-provider retention and handling will be disclosed, in the future tense, so the providers seeing case content cannot be named from anything published.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located public material addresses court disclosure or AI-use certification. Nothing describes an exportable record identifying which messages were AI-drafted or AI-translated, which model produced them, or who reviewed them before sending. Checked across the home page, the Data and Agentic AI listing, the security commitment page, the privacy notice and the Terms of Use on 1 September 2026. The product generates client correspondence rather than court filings, so a standing order would rarely reach it directly, though the same record would answer a firm's own supervisory question about what was sent in its name.
A record of what the machine did exists inside the product and is never described as something a firm could produce. Each structured fact on a case file was proposed by the AI, shown to the client, confirmed by them and receipted, with a ten-minute window to undo, so per item there is a trail of a machine proposal and a human confirmation. Audit trails record every upload, view and download, and confirmed data flows into the firm's case management system by the same path as everything else.
What is absent is any export, format or guidance addressed to disclosure: nothing says the confirmation trail can be produced, nothing distinguishes an AI-extracted field from one the client typed once it has landed in the case file, and nothing addresses a court or an opponent asking how a treatment timeline was assembled. On a product built for litigation, that is the gap worth naming.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Primary Law Corpus Provenance
- Good Law Verification
Which one fits
Choose Case Status if
- Your procurement team wants a named auditor and a stated scope. Case Status states SOC 2 Type I in September 2023 and Type II in July 2024 by Modern Assurance, covering security, confidentiality, availability, privacy and processing integrity, with Secureframe named for continuous monitoring.
- Your clients speak languages your staff do not. Case Status sells automatic translation of client messages alongside case summaries, response drafting ranked by urgency, and sentiment tracking, with drafted replies presented for staff to review before sending.
- Your firm runs one of thirteen named case systems. Case Status lists integrations with Clio, Litify, MyCase, Neos, Filevine, CASEpeer, SmartAdvocate, Smokeball, PracticePanther, CoCounselor, Meruscase, Docketwise and Salesforce, and works as a communication layer inside them.
Choose Quilia if
- You want AI extraction checked by the client before it reaches the case. Quilia reads uploaded police reports, medical records, bills and photographs, extracts providers, dates, parties and treatment details, and asks the client to confirm each item, with a receipt that can be undone for ten minutes.
- You want the sync documented, not just the logo. Quilia describes two way sync with Clio, Filevine, MyCase, CasePeer, SmartAdvocate, Litify, Neos, Smokeball and Salesforce, states what moves in each direction and who configures it, and offers Zapier, an API and a Model Context Protocol connection.
- You want the advice line drawn where your client reads it. Quilia's client agreement states that the app gives no legal advice and creates no attorney client relationship, and its case assistant, which the vendor describes as rolling out, will not discuss fault, liability, insurance, liens or case value.
In summary
Case Status
Case Status, from Case Status, Inc. of North Charleston, South Carolina, is a client communication layer that sits on a law firm's existing case management system, giving clients a branded app reached by text without a password, with case stage updates, secure messaging, document upload and short videos for each stage. Its AI features, sold individually, translate client messages, summarize cases, draft replies ranked by urgency and track sentiment. The AI Legal Index grades it in the top two bands on six of fifteen capability axes. It names Modern Assurance as auditor of a SOC 2 Type II examination and integrates with thirteen named case systems. As of 1 September 2026 the index located no firm agreement, model provider, accuracy measure or price.
Quilia
Quilia, from Record System, Inc. of Las Vegas, is a client app for personal injury and workers' compensation firms in which an injured client logs treatment visits, pain scores and photographs, uploads records and bills, signs documents and messages the firm. Its AI extracts providers, dates, parties and treatment details from what arrives, asks the client to confirm each item, and flags gaps in treatment. The AI Legal Index grades it in the top two bands on twelve of fifteen capability axes, with an A on integration depth, where it documents two way sync with Clio, Filevine, Litify and others. Its client agreement states the app gives no legal advice. As of 20 September 2026 the index located no independent security attestation of its own, named AI provider or price.
Questions buyers ask
Case Status vs Quilia: which is better for a personal injury firm?
On published evidence Quilia sits in the top two bands on twelve of fifteen AI Legal Index capability axes and Case Status on six of fifteen, identical on five, mostly because Quilia publishes how its AI is checked, tested and limited. Case Status holds a SOC 2 Type II examination by a named auditor and names a large firm with results. Firms with a strict security review have more to read from Case Status.
Does Quilia train AI on client data?
Quilia's AI disclosure and privacy policy state that customer data is not used to train AI models. Its terms of 22 May 2026 are narrower: section 2.8 lets it process customer data with machine learning and AI for the benefit of all its customers and promises that it does not train public models. Case Status publishes no position on training either way. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What security certifications do Case Status and Quilia hold?
Case Status states SOC 2 Type I in September 2023 and Type II in July 2024, audited by Modern Assurance across all five trust services criteria, with no route published to obtain the report. Quilia holds no attestation of its own; it states that its infrastructure providers, Supabase, Vercel and Expo, are SOC 2 certified, and offers a business associate agreement on request. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
How much do Case Status and Quilia cost?
Neither publishes a figure. Case Status publishes no tier, unit or price, and every route leads to a demo. Quilia's terms set out the structure: capacity sold as a case tier with overage fees, monthly or annual payment, 30 days' notice of fee changes, and a clause allowing the fee to be billed to the client as a hard cost recovered at settlement. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What do Case Status and Quilia both leave unpublished?
Which AI providers read client messages and records, and how long anything is kept. Neither names a model or AI provider, and neither states a retention period for client content or AI output. Neither addresses whether its AI performs evenly across languages and client populations, names bar guidance on AI, or offers an export showing which messages or facts its AI produced. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Three readings to weigh. Quilia's terms let it process customer data with machine learning for the benefit of all its customers, promising only that it does not train public models, and let its fee be billed to the client as a cost recovered at settlement; both are published terms. Case Status publishes no agreement for firms, and its client terms exclude liability for personal injury and emotional distress. Its privacy notice states a retention limit with the figure missing from the sentence. Case Status was verified on 1 September 2026 and Quilia on 20 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.