Centerbase vs Clio: how they compare in 2026

C
Centerbase profile
C
Clio profile
Last verifiedSeptember 26, 2026

Centerbase and Clio both sell cloud practice management with billing and trust accounting, but they point their AI at different questions. Centerbase IQ answers a managing partner's questions about the firm's own finances; Clio Work researches and drafts from a firm's matters and the vLex legal library. Clio sits in the top two bands on fourteen of fifteen axes and Centerbase on four of fifteen. The gap is published terms. Clio's agreement commits to breach notice within 72 hours and to deletion after a 90 day retrieval window, and its subprocessor list names five AI providers. Its terms also let Clio use content and output, stripped of identifiers and aggregated, to improve its AI services. For Centerbase no customer agreement was located, so its positions on training, retention and liability are not established. Centerbase's counterweight is how its answers can be checked. Every IQ answer carries the source records behind it, so a figure traces back to the billing entry or matter it came from, and the analysis stays inside the firm's own data.

At a glance

Category
CenterbaseIntake & Client Development
ClioIntake & Client Development
Founded
CenterbaseNot published
Clio2008
Headquarters
CenterbaseDallas, Texas, United States
ClioBritish Columbia, Canada
Last verified
CenterbaseSep 12, 2026
ClioSep 1, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Centerbase
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models are the engine of a core capability layered on a product that would function without them, which is B. Centerbase has sold a practice management, billing and accounting platform to midsize firms for more than a decade, and Centerbase IQ arrived in April 2026 as an intelligence layer on top of it. The vendor's own account of its history makes the sequence explicit: the chief product officer's colleague described the company's first act as building the core system of record, billing, accounting and practice management, and IQ as the layer that reads it. Remove IQ and matter management, timekeeping, billing, collections, trust and general accounting, document management, intake, client portal, workflows and reporting all remain. Recorded on the other side because the positioning is moving quickly: by August 2026 the vendor describes itself as an AI-powered performance platform with AI-driven financial intelligence through its Centerbase IQ layer, and states a strategy to expand proactive insights and deepen agentic AI. **That last is future tense and does not evidence a shipped capability under the ground rules**; it is recorded, not graded. Verified 12 September 2026.

Clio
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

An eighteen-year-old practice platform with an AI workspace built on top, and the vendor frames it that way itself: the marketing line is that the 18-year foundation now powers the legal AI. Clio Manage, Grow, Draft and Accounting are conventional software, and the entry tier is sold on practice management rather than models. Clio Work is genuinely AI-native and is sold as a separate product with its own trial, and Grow AI and Manage AI sit inside the older modules. Remove the models and the system 400,000 professionals run their firms on still works. B on the band. Pages read 1 September 2026.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Centerbase
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is real, documented and verifiable by the reader, short of any published measurement, which is B, and the design is better than the grade alone conveys. The vendor commits that **every Centerbase IQ answer includes the source records behind it**, that users see exactly where the answer came from, and that a firm administrator can trace a figure back to the underlying data. Its chief product officer puts the design intent in terms: they are not asking firm leaders to trust a black box, they are showing both the answer and the source. The corpus is bounded to match, the insights being described as isolated to only the firm's own data, so there is no external material an answer could drift into. One feature of this product class is worth naming because it cuts in the vendor's favour: the cited sources are the firm's own billing entries and matter records, which the reader can open directly, so verification is more available here than on a product citing external authority. What holds it off A is measurement. No accuracy figure, error rate, evaluation or test is published, and nothing describes how a natural language question is translated into a query over the firm's data. R15: the authority and citator limbs do not bite on a product that answers questions about a firm's finances rather than about law. Verified 12 September 2026.

Clio
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is real and doubly sourced, and no accuracy figure was located. The pricing page states the AI is grounded in the firm's matters and cites its sources; the home page describes it working from matters, clients, filings, communications and financial data combined with over a billion legal documents across 100-plus countries, which is the vLex library Clio acquired in June 2025. That is a described retrieval method over identifiable corpora, and the subprocessor list corroborates the architecture by naming a vector database provider. What holds it at B is the absence of published measurement, and the Terms cut against any implied one: clause 14.2 states Themis does not review Output for accuracy or completeness and that Output may be incomplete or inaccurate, and clause 17.2 says the same of the legal Materials, disclaiming accuracy, completeness and currentness. Clio publishes an accuracy resource at /resources/ai-for-lawyers/ai-accuracy-legal/ which was not opened and is the rebuttal route toward A.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Centerbase
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Oversight is implied by the design and not described as a structure, which is C. The autonomy actually shipped is modest and the vendor does not overstate it: Centerbase IQ answers questions put to it and returns visual, sourced answers. It does not act, file, draft or decide, and nothing published claims it does. The traceability design gives a user something to check against, and that is graded on the Citation Accuracy row rather than counted twice here. What is absent is any published structure. Nothing states whether an answer should be verified before it is relied on in a partner meeting, nothing describes what the system does when a question cannot be answered from the data, no confidence indicator is described, and no threshold or escalation route appears. The gap is worth flagging forward rather than only recording, because the vendor has published its intention to **deepen agentic AI to power workflows**, and an intelligence layer that begins to act on billing, collections or matter data is a materially different oversight question from one that answers questions about them. Nothing published yet addresses what would govern that. Verified 12 September 2026.

Clio
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

A blanket review commitment stated in marketing and made binding in the contract, without the finer structure the top band asks for. The pricing page says the firm reviews and approves everything before it reaches a client or the court, which is the right commitment for the highest-stakes outputs. Terms clause 14.2 converts that into an obligation running the other way: the subscriber agrees to use AI Services and Output only with human oversight, and is responsible for reviewing Output for accuracy, completeness, appropriateness and compliance with legal, regulatory and professional requirements before disclosing or using it. Clause 14.4 leaves the subscriber in full control of how AI Services are implemented, configured and presented. B rather than A because no modes are described, no thresholds are published, and nothing sets out what the product does on its own versus what it waits to be asked.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Centerbase
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Third-party coverage and partner endorsements stand in for customer evidence, and no result is quoted with a basis, which is C. No named customer firm was located on any surface read, and no case study, named reference or attributed testimonial appears in the material examined. What the vendor does publish in that space is of a different kind: trade press coverage of the Centerbase IQ launch, a conference debut at the 2026 Association of Legal Administrators Annual Conference with a booth number, a listing in the ALA's own supplier directory, and a run of partnership announcements with NetDocuments, Billables AI and Scan Logic. **Partners are not customers and are recorded rather than credited**, and analyst or directory placement is not deployment evidence. The claims that are made about outcomes are made in the abstract, that firms get greater delivery capacity without added headcount and stronger realisation, with no firm, figure, period or method attached. Named as unopened under the sufficiency discipline and as the route by which this row would move: the vendor's own customer and resource surfaces, and the Centerbase IQ product page at centerbase.com/IQ. Verified 12 September 2026.

Clio
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

One named firm with a figure and a period, against portfolio numbers with no method. King Law is named on the home page with a 275% increase in revenue over four years, attributed to visibility and tooling across the firm. Named individuals appear with their firms: Angela Lennon at Koenig | Dunne, Danielle Harvey-Jacob at Harvey-Jacob Law. Platform figures are 400,000-plus legal professionals, 130-plus countries and 300-plus integrations. Nothing is dated, no method is described for the King Law figure, and the 4.7 from 12,000-plus reviews is directory material excluded under the ground rules along with the vendor's own comparison page. B: real deployment evidence with substance, short of the dating and method the top band requires.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Centerbase
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Confidentiality is addressed through infrastructure security and one real AI scoping statement, short of the data commitments this axis asks for, which is C. The security side is specific and is graded principally on the stewardship row: SHA256 4096-bit RSA encryption in transit, 256-bit AES encryption on backups, enterprise-class firewalls, and a SOC 2 Type II claim. The one statement that speaks directly to the AI is genuinely useful and is credited here: the vendor states that Centerbase IQ's insights are **isolated to only the firm's own data**, which addresses the question a managing partner would ask first about a tool reading the firm's financials. Three of the five limbs are unaddressed on the surfaces read. Nothing states whether customer content is used to train models. No model provider is named, so nothing states what any third party may retain. And privilege and work product are not addressed at all, on a platform holding matter records, document management and the firm's complete billing narrative, where time entries routinely describe privileged work. No customer agreement was located; the legal path publishes a website privacy and security policy for payments. Verified 12 September 2026.

Clio
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Substantive on every limb but the one the band names last. Terms clause 4.2 binds Themis and its third-party vendors and hosting partners to hold Content in strict confidence and not use or disclose it outside the agreement. Clause 21.3 goes further than most: only Themis, with strict business reasons, may access and transfer Content, and only to provide the Service, with reasonable efforts to notify the subscriber before doing so. Clause 14.6 states use of AI Services grants no right to use confidential information to train generalised LLMs. The security page states AI data is encrypted and processed in the customer's region, that AI tools process in real time without storing or reusing, and that outputs are generated only for the authorised user requesting them. What is missing for A is express treatment of privilege and work product, absent for a platform holding the entire matter file, and any documented segregation between matters within a firm.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Centerbase
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Nothing published on professional responsibility was located, which is the D band, and R15 requires saying which limbs bite before the grade is read as heavier than it is. The advice-line limb barely applies. Centerbase IQ answers questions about the firm's own billing, collections, realisation, productivity and deadlines; it does not produce legal work product, advise on a client matter or generate anything that goes to a client or a court, so the question of whether output could be mistaken for legal advice does not arise in its usual form. The audience limb is answered: the product is sold to law firms and the AI is addressed to managing partners and firm administrators. What is genuinely absent, and is what the grade records, is any statement connecting the tool to the professional obligations of the people using it. Nothing addresses the judgement a managing partner exercises when acting on a machine-generated read of realisation or attorney productivity, nothing addresses supervision, and no disclaimer of any kind was located. No customer agreement was located either, and the security page that might have carried adjacent language is machine-refused to this index. Verified 12 September 2026.

Clio
AA on UPL and Professional Responsibility PostureThe vendor states plainly what the product is and is not, who may use it, and how it supports a lawyer’s competence and supervision duties. Jurisdiction limits are named and any consumer facing surface carries a clear disclosure.

Every limb is covered and all of it is contractual. What it is not is stated at the top of the Terms in bold: Themis is not a law firm and does not provide legal advice, through the Service or otherwise, with clause 12.1 adding that provision of the Services, Output or Materials creates no attorney-client relationship. Who may use it is scoped: the Service is intended only for use by legal professionals and those working under their supervision, with a named exception for academic access participants. Competence and supervision are addressed directly in clause 14.2, which requires human oversight and makes the subscriber responsible for reviewing Output against professional organisation requirements and applicable fiduciary rules. Jurisdiction limits are named three ways: the Service is intended for North America with separate EMEA terms, Materials are limited to the country associated with the account, and clause 2.16 warns that Themis runs one code-base for all jurisdictions and the subscriber must configure and verify settings for its own. The client-facing limb is met by clause 14.4, which requires the firm to give its end-users disclosures covering the use of AI, the nature and limitations of AI-generated responses, and any human oversight processes.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Centerbase
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

A principle is published without a mechanism, a testing regime or anything a buyer could audit, which is C. The principle is stated and is more than boilerplate: the chief product officer's position that AI in legal software has to earn trust before it earns adoption, that the company is not asking firm leaders to trust a black box, and that it shows both the answer and the source. Two design commitments sit behind it, source records on every answer and analysis isolated to the firm's own data, and the vendor uses the language of a governed system repeatedly across its platform and integration announcements. That is a coherent stance. None of what the higher bands require appears. No governance framework is named, nobody is identified as accountable for AI decisions, nothing describes what is evaluated before a capability ships, and no testing regime is published. Bias is addressed nowhere, and the shape it would take here is worth naming: a tool that reports attorney productivity, realisation and origination is producing numbers that feed compensation and staffing decisions, and nothing published considers whether those readings are even across practice groups, seniority or working patterns. Verified 12 September 2026.

Clio
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

Principles are published, the mechanism behind them is not. A dedicated AI Principles page sets out five commitments, attributed to Chief Technology Officer Jonathan Watson, covering AI as collaborator, transparency of AI actions, high-quality data, relentless refinement and uncompromising security. Bias appears once, as a claim that diverse top-tier data minimises it, rather than as anything measured or found. Nothing names an individual or committee accountable for the AI, describes what is tested before a feature ships, or discloses a single evaluation result. The one auditable trace of a testing function is indirect and sits elsewhere: the subprocessor list names Braintrust Data as an AI analytics, evaluation and testing provider across five products. That is evidence a pipeline exists, not a published regime a buyer could examine. C on the band's own words.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Centerbase
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

Protection is documented and the data lifecycle is not, which is C. The protection half is specific and unusual in one respect worth recording: Centerbase runs its own infrastructure rather than a hyperscaler, describing the Centerbase Cloud as built on enterprise-class Dell server hardware and firewalls with 24/7 high-availability VMware clusters. Encryption is stated at a level of detail few records match, SHA256 4096-bit RSA from the browser to the data centre and 256-bit AES on all backups of customer data. A SOC 2 Type II position is claimed and is graded on the certifications row. The other half of the axis is absent from every surface read. No retention period is stated for firm data, prompts or generated answers; no deletion right or export-on-termination commitment is published; no subprocessor list exists anywhere and no processor is named; and no breach or incident notification commitment was located. Two retrieval facts belong on the record: the current security page is **machine-refused** to this index by the site's robots file, so its content was recovered only through the search index, and that is a refusal rather than an absence. Verified 12 September 2026.

Clio
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

One limb short of a full set, and the limbs it clears are clearer than anything else in this pull. Incident practice is contractual and specific: clause 5.5 requires Themis to report any event it reasonably believes represents unauthorised access to, disclosure of, use of or damage to Content within 72 hours, with clause 5.6 setting out cooperation, investigation and mitigation duties. Deletion is stated with a period: 90 days to retrieve Content after termination, after which all Content is irrevocably deleted, with escrowed data held six months under a separate escrow agreement the customer controls. Subprocessors are published in full and dated. Access control is covered by clause 21.3, limiting Themis access to strict business reasons with advance notice. Encryption, geo-redundancy and at least annual third-party penetration testing are stated. The gap is retention during the term: no period is published for AI inputs and outputs, and clause 14.6 permits de-identified aggregated Content and Output to be kept for quality improvement without limit.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Centerbase
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

Nothing published on who bears the loss when the system is wrong was located, which is the D band. No warranty, indemnity, liability cap, exclusion, service credit or insurance position appears on any surface read, and no customer agreement or master subscription agreement was located anywhere on the estate; the legal path publishes a privacy and security policy addressed to website and payments use rather than a contract governing the platform. Nothing addresses what happens if Centerbase IQ misreports a collection rate, misstates work in progress ageing or misses a deadline it was asked about, on outputs the vendor itself positions as giving managing partners confidence in the boardroom. The absence is worth stating plainly against what the vendor does commit to: it promises that every answer carries its source records, which is a transparency mechanism that lets a user catch an error, and it makes no commitment at all about the consequences if the user does not. Recorded as a retrieval position rather than a settled one: no agreement was located, the security page is robots-refused to this index, and this row would move on a customer agreement being found and read. Verified 12 September 2026.

Clio
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

A real and unusually two-sided position that stops short of the output itself. Clause 11.1 excludes liability generally but carves out breaches of confidentiality, security and managed backup, so those obligations remain live. Clause 11.2 caps liability at the total paid in the six months before the claim arose, and expressly disapplies that cap to the indemnity. Clause 13.2 gives the subscriber a genuine indemnity on two grounds: third-party intellectual property claims against the Service, and, more unusually, claims arising from a violation by Themis of its own confidentiality or security obligations. Carve-outs are itemised in 13.3. What keeps this at B is that none of it reaches AI output. Clause 13.2(a) expressly excludes Output from the IP indemnity, clause 14.2 provides Output as is with no representations, and clause 12.2 disclaims any warranty as to results. No insurance position is published.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Centerbase
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Real integrations, named, dated and described at the level of what they do, short of the depth an implementer could work from. Three are published as announcements within six months of each other and each is specific. **NetDocuments**, March 2026, described as the first native connection between a practice management platform's matter data and ndMAX document intelligence, so that AI is applied from the moment a matter opens, automating matter workflows and removing manual re-entry. **Billables AI**, April 2026, for automated time capture feeding practice intelligence. **Scan Logic BillSync**, August 2026, bringing e-billing and compliance into the platform. Alongside those sit Outlook, Microsoft Calendar and Microsoft Word synchronisation and online banking reconciliation for trust accounts. That is a coherent integration story aimed squarely at the midsize firm stack. What holds it off A is documentation: no API or developer surface was located, nothing describes which objects synchronise or in which direction, and no configuration or authentication detail is published. One published limit is recorded: a third-party review notes no direct Google Workspace integration. Verified 12 September 2026.

Clio
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Breadth is stated and documented, depth is not. Clio publishes 300-plus integrations through an app directory, runs a developer hub and partner programme, and the Terms treat API access as a governed feature in clause 3.9, setting out that API use is bound by the agreement, that excessive use may lead to suspension with a reasonable attempt to warn first, and that access may be modified or discontinued. Third-party services are addressed squarely in clause 18, which states they are not Services under the agreement, carry no warranties, indemnities or service commitments from Themis, and may be replaced, disabled or restricted at any time without notice. That is honest about where the boundary sits. B rather than A because no page read on 1 September 2026 describes what any specific integration moves, in which direction, or what a firm must configure; the app directory was not opened and is the rebuttal route.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Centerbase
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

The delivery model is described in real architectural detail and neither the region nor the tenancy model is stated, which is C. The deployment description is more concrete than most in this corpus and is distinctive because the vendor is not on a hyperscaler: it describes the Centerbase Cloud as built on industry-standard platforms with server hardware and firewalls that are enterprise-class systems from Dell, running 24/7 high-availability VMware clusters to keep services continuously available, with backups encrypted at 256-bit AES. A firm evaluating this can picture how the service runs. What it cannot learn is where. No data centre location, country or region is named, no residency option is offered or refused, no tenancy model is described and nothing states whether one firm's data is logically or physically separated from another's beyond the AI-scoping statement graded on the privilege row. Nothing distinguishes where firm data is stored from where Centerbase IQ processes it, which matters because the vendor hosts its own infrastructure while the AI layer's own hosting is unstated. The current security page is machine-refused to this index and its content was recovered through the search index. Verified 12 September 2026.

Clio
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

The most detailed residency disclosure located in this pull, held off the top band by one absence. Regions are published and real: hosting options in the European Union, Australia, the United States and Canada, five regional site variants, a separate EMEA instance at eu.app.clio.com with its own terms, and separate North American and EMEA agreements. Processing is distinguished from storage rather than conflated: the security page states all data used by the AI is encrypted and processed in the customer's own region, naming US, Canada, EMEA and APAC, and the subprocessor list gives a data location for every provider individually, including each AI processor. Infrastructure is named by provider and product. What is absent is the tenancy model, which is stated nowhere, and any statement of whether residency options vary by plan, which is what the top band asks for alongside the regions.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Centerbase
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

A certification is claimed with no scope statement a reader can rely on, no date and no report available, which is C, and the reason is a discrepancy on the vendor's own estate rather than mere thinness. **Two live pages disagree.** The current security page states that the Centerbase platform is fully SOC 2 Type II and that the controls protecting firm data are independently tested every year. An older security page, still published, states that the platform is SOC 2 Type 2 compliant **regarding the Security trust services criterion only**, with the remaining four, availability, processing integrity, confidentiality and privacy, to be completed in 2025. Those are materially different claims about the same attestation, and nothing on either page resolves which is current. No auditor is named on either, no report period or observation window is given, no certificate or report is published, and no trust centre exists. Two retrieval facts belong on the record under the ground rules' distinction between absent and machine-refused: the current security page is **robots-refused** to this index, so its text was recovered through the search index rather than by fetch, and that is a refusal about this reader rather than a fault of the site. Verified 12 September 2026.

Clio
AA on Security Certifications and Trust CenterCurrent independent attestation with named scope, reachable without a sales call: a trust center carrying reports, dates and the standards actually covered.

The only attestation in this pull that states its coverage period. The trust centre at trust.clio.com announces that the 2025 SOC 2 Type II report has been issued for the period 1 June 2024 to 31 May 2025, and the security page states Clio completes annual SOC 2 Type II and SOC 1 Type II examinations with both reports available through that trust centre. The route to the report is not only a portal but a contractual right: clause 5.4(d) obliges Themis to provide a SOC 2 or SOC 3 report, or a comparable description of security measures, within thirty days of a subscriber request. At least annual third-party penetration testing is stated, and Clio's own help centre names Deloitte as the independent auditor, albeit for the earlier Type I engagement. Weaknesses a buyer should still note: the trust services criteria are not enumerated, the auditor for the current Type II is not named, the penetration testing firm is described only as a leading cybersecurity firm, and clause 5.4(d) requires entering an agreement with the report's third-party provider.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Centerbase
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The vendor refers to its AI without identifying anything underneath it, which is C. Centerbase IQ is described as an AI-powered natural language decision support capability, an AI intelligence layer, and in the vendor's marketing as the only AI intelligence layer built on a native legal system of record. None of that names a model, a version or a provider, and nothing states where inference happens or commits to notifying a customer when any of it changes. No subprocessor list exists on any surface read. What is disclosed, and credited on other rows rather than here, is the data side: the analysis is isolated to the firm's own data, every answer carries its source records, and firms may add an internal knowledge base of their own standards. Those describe what the model reads, not what the model is. One adjacent disclosure is recorded and expressly not credited to this vendor's own supply chain: the native NetDocuments integration brings **ndMAX** document intelligence into Centerbase workflows, which is a named third-party AI, but it is the partner's product rather than a component of Centerbase IQ. Verified 12 September 2026.

Clio
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

By a distance the best evidence on this axis in the pull, and still short of the top band on two limbs. The subprocessor list, last modified 20 August 2026, carries a dedicated AI Service Providers table naming five AI processors with the products each serves and the data location for each: AWS Bedrock, Anthropic, OpenAI, Google Vertex AI and Microsoft Azure Foundry, spanning Clio Manage, Grow, Draft, Work, Vincent AI and Clio Operate. It also names Turbopuffer as the vector database and Braintrust Data for AI analytics, evaluation and testing, and Vapi for the Grow voice agent. A buyer can therefore answer whose model sees their content, per product, and where it runs. Two things keep it at B. The specific models are never named, only the providers. And no change-notification commitment was located on the page; the Themis Data Protection Addendum, cited as the clause under which the list is published, was not opened and is the rebuttal route toward A.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Centerbase
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing information is published at any level, including the unit of charge, which is the D band. No pricing page was located on the vendor's estate, no rate, band, tier name or minimum appears anywhere on the surfaces read, and nothing states whether the platform is licensed per user, per firm or by module. The published routes are a demonstration request and a contact form, repeated as the call to action across the estate, and the Centerbase IQ announcement itself directs readers to a product page rather than to a price. Under R10's closing discipline a page that only invites a sales conversation is an absence and belongs in this note alone, so no VendorPricing row is written for this record. Two things are recorded rather than credited. A third-party review states plainly that the vendor does not list pricing on its website and advises readers to contact the company for a quote, which corroborates the finding without being the basis for it. And software directories publish estimates in the range of roughly $40 to $110 per user per month; those are directory extrapolations rather than vendor disclosure and are excluded under the ground rules. The vendor does note that a full accounting package carries an additional fee. Verified 12 September 2026.

Clio
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

Part of the range is priced and the rest is a conversation. The pricing page publishes a starting figure of $49 USD per user per month and names four tiers, Starter, Core, Signature and Elite, with the feature split described tier by tier and a bundle saving of over 15% advertised. Above the entry tier a buyer is routed to a custom quote, and large firms to a bespoke process. The Terms make clear that the published number is not the whole cost: clause 9.5 refers to setup fees, implementation charges and Metered Features fees as separate non-refundable items, and clause 9.6 gives purchasers of setup or professional services a sixty-day window to start them or lose them. None of those amounts is published. B on the band's first limb, real pricing published for part of the range with the upper tiers withheld. Note the tier names have changed generation again and third-party trackers still report the previous set.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Centerbase
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

The segment is described with real substance and the boundaries around it are left open, which is B. Who this is for is stated with unusual consistency and is the vendor's whole positioning: **midsize law firms**, repeated across every announcement and product page as purpose-built rather than adapted. The vendor articulates why the segment is distinct rather than merely naming it, describing midsize firms as expected to operate with the strategic visibility of larger firms while running leaner administrative teams, and builds the AI around that gap. Roles are named specifically: managing partners and firm administrators for Centerbase IQ, with attorneys, timekeepers, accounting teams and operations leaders as platform users. Functional coverage is enumerated across matter management, timekeeping, billing, collections, trust and general accounting, document management, intake, CRM, workflows and reporting. What is left open holds it off A. No practice area is named as supported or unsupported, the platform being practice-agnostic without saying so; no firm size is given in numbers, so midsize is left to the reader; no jurisdictional statement appears despite trust accounting rules varying by state; and nothing states what the product is not for. Verified 12 September 2026.

Clio
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

The widest published coverage in the pull, with the limits drawn jurisdictionally rather than functionally. Sixteen practice areas carry their own pages, from bankruptcy and criminal to intellectual property and real estate, and the segmentation runs across four firm sizes from solo to enterprise and Big Law, plus seven role-specific pages. Both buyer types the band asks about are addressed by name: in-house counsel and government law each have a page. Real limits are stated, though they concern where rather than what: the Terms scope the Service to North America with separate EMEA terms, restrict Materials to the country associated with the account, and warn in clause 2.16 that a single code-base serves all jurisdictions so the subscriber must configure and verify settings itself. B rather than A because the in-house, government and firm-size pages were not opened on 1 September 2026, and nothing states which practice types the product handles poorly.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Centerbase
Terms silent

A published policy exists, it does not address training, and the nearest statement is about scope rather than use, which is this value. The statement worth weighing is the chief product officer's, that Centerbase IQ's insights are derived in a very precise approach isolated to only the firm's own data. **That is a boundary on what the model reads, not a commitment about what the vendor does with what it reads**, and the distinction is exactly the one this signal turns on: a tool can answer only from one firm's records and still contribute those records to a training set.

Nothing published resolves it either way. The published privacy and security policy on the legal path addresses information collected through the website and payments rather than platform data, and **no customer agreement or master subscription agreement was located anywhere on the estate**, so R43(1) could not be discharged. The current security page is machine-refused to this index by the site's robots file and its content was recovered through the search index; nothing in what was recovered addresses training. On a reading of a customer agreement the three-way choice under R122(1) is live.

Clio
Permitted, in the contract

The agreement permits a qualified form of training and the marketing says the opposite. Terms clause 14.6 lets Themis de-identify and aggregate the Content submitted to, and Output received from, AI Services and use it to improve and ensure the quality of those services, and clause 2.15 adds perpetual aggregate anonymized reporting on usage and content trends. The same clause withholds any right to use confidential information to train generalized LLMs, so the permission is bounded rather than open.

The qualifier that matters to a buyer is that it runs on de-identified and aggregated material, not identifiable client content. Against that, the pricing FAQ states a firm's data is never used for AI training or any other external purpose. Where marketing and the agreement disagree the agreement governs, and it is recorded here.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Centerbase
Not addressed

No located public material states how long firm data, Centerbase IQ questions or generated answers are retained. The published material addresses protection rather than duration: encryption in transit and on backups, enterprise-class firewalls and high-availability clusters, all of which describe how data is held rather than for how long. Backups are mentioned as encrypted with no retention window stated for the backups themselves.

Nothing addresses deletion, export on termination, or what happens to a firm's records when a subscription ends. The AI layer is not addressed separately at all: nothing states whether the questions a managing partner asks, or the answers and visualizations returned, are retained beyond the session, which matters because those questions can themselves be sensitive, a query about a particular attorney's realization or write-offs being a record of management scrutiny.

The published privacy and security policy on the legal path is scoped to the website and payments. No customer agreement was located, and the current security page is machine-refused to this index.

Clio
Disclosed without a period

End-of-life is specific, the live term is not. Clause 10.7 gives the subscriber no less than ninety days after cancellation or termination to retrieve Content, after which all Content is irrevocably deleted from the Service, with escrowed data held a further six months under a separate escrow agreement the customer arranges directly. What is not published is any period for AI inputs and outputs while the subscription is running, and clause 14.6 permits de-identified aggregated Content and Output to be retained for quality improvement with no stated limit.

The security page states AI tools process data in real time and do not store or reuse it, which points toward minimal model-layer retention but is a marketing statement rather than a term.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Centerbase
Not addressed

No located public material describes a permission model or matter-level segregation. The vendor refers to comprehensive controls for administrators and to a single governed system, and neither is a description of who can see what. Nothing published sets out user roles, access groups, matter-level restrictions, conflict screening, or how a firm would wall one team off from another's files. The question is sharper than usual on this record and the note records why.

Centerbase IQ answers questions across the firm's billing, matter, productivity and origination data, which is precisely the material a firm would ordinarily restrict: origination credit, individual attorney realization and write-offs, and matter economics are not normally visible to everyone. Nothing published states whether IQ answers within the permission scope of the person asking or across the whole firm regardless, and for a tool addressed to managing partners and administrators that is the first configuration question a firm would raise.

Recorded as an absence on the surfaces read, with the product page at centerbase.com/IQ and the machine-refused security page named as where it might be answered.

Clio
Claimed, not documented

Per-user scoping is asserted without published enforcement detail. The security page states sensitive client information never leaves Clio's secure environment and that outputs are generated only for the authorized user requesting them. The Terms establish an administrator role able to designate users and deactivate access, but describe no matter-level partitioning, no conflict wall mechanism, and nothing about how retrieval is bounded when the AI reaches across a firm's matters, clients, filings and communications.

Worth noting for comparison that the separately indexed Vincent AI record describes inheriting a firm's existing permissions and ethical walls when run inside Clio Operate; nothing equivalent was located for Clio's own products on any page read on 1 September 2026.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Centerbase
Not addressed

No located public material addresses what happens when a third party demands customer data. Nothing on the surfaces read refers to subpoenas, warrants, court orders, regulator notices or law enforcement, and no commitment or reservation about notifying the customer appears. No transparency report exists. The published privacy and security policy on the legal path is scoped to information collected through the website and payments rather than to the platform's contents, and no customer agreement was located anywhere on the estate.

The material held makes the question a real one rather than a formality: this platform holds a midsize firm's complete billing narrative, and time entries and matter records describe what lawyers did for which clients and when, which is discoverable-adjacent material that opposing parties, regulators and taxing authorities have reason to seek. A demand served on the platform rather than on the firm would reach the firm's clients' affairs without the firm necessarily knowing.

Nothing published addresses it. The current security page is machine-refused to this index and its recovered content does not reach the question.

Clio
Notice committed

Notice is committed in the agreement and the process is published separately. Clause 7.2 provides that where Themis is legally required to disclose confidential information in a way the agreement otherwise prohibits, it will give the subscriber prompt written notice, to the extent permitted by law, before disclosing, so the subscriber may seek a protective order or other relief, and will then furnish only the portion legally compelled.

Clause 7.1 states the primary duty is to protect Content to the extent the law allows. Clause 7.3 adds something few vendors publish: Themis will only accept legal requests for production of Content through the procedures set out at clio.com/legal-service, a dedicated public page for service of legal process. No transparency report was located on 1 September 2026, which is what keeps this below the top tier.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Centerbase
Sources named, basis unstated

The corpus is identified exactly and nothing behind it is, which is this value. The identification is as precise as this corpus gets: Centerbase IQ reads the billing, financial, matter and productivity data already housed in Centerbase, enumerated as billing, collections, matter economics, realization, work in progress and accounts receivable aging, attorney productivity, origination and docket activity, and the vendor states that the analysis is isolated to only the firm's own data.

A second, firm-authored corpus is described alongside: an internal knowledge base the firm builds within IQ from its own best practices and performance standards, against which answers are benchmarked. So a buyer knows exactly what the model reads, and there is no external legal corpus whose licensing this signal would otherwise test. The rights position on the firm's side is not stated anywhere, no published document addressing what the vendor may do with platform data, and no customer agreement was located.

Nothing states what the underlying models were trained on, and no model or provider is named, which is graded on the Model Supply Chain row.

Clio
Sources named, basis unstated

The corpus is identifiable and the rights basis is described only in the abstract. Clause 17.2 states Themis may make available primary and secondary legal materials such as case law, legislation and articles, described as licensed or publicly available legal content, with additional third-party terms possibly applying. The source behind it is traceable through Clio's own disclosures rather than a provenance statement: the subprocessor list names Vlex Library and Clio Library as products and lists vLex entities and Fastcase, Inc. among Clio affiliates, and the home page puts the corpus at over a billion legal documents across 100-plus countries.

What is absent is which license covers which jurisdiction, any named publisher, and any update cadence. Clause 17.2 runs the other way on currency, expressly disclaiming that Materials are reviewed for accuracy, completeness or currentness, and clause 17.5 reserves the right to add, modify or remove Materials at any time without notice.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Centerbase
Not addressed

No located public material addresses whether authority is checked for subsequent history, and on this product the question does not arise. Centerbase IQ answers questions about the firm's own finances and operations, not about law. It cites no cases, statutes or regulations, and the sources it does cite are the firm's own billing entries and matter records. Nothing it produces is a proposition about the state of the law whose treatment a lawyer would check.

The nearest adjacency worth recording is docket activity, which the vendor lists among the data IQ reads and which includes approaching deadlines: currency there is a matter of whether the firm's own calendar data is up to date rather than whether an authority remains good law, and no staleness or freshness statement is published about it. Recorded so the row states the position plainly rather than leaving a reader to infer it from the product category.

The surfaces read were the Centerbase IQ announcement in full, the partnership announcements, and security content recovered through the search index from a machine-refused page.

Clio
Not addressed

No located public material describes a citator or subsequent-history check in Clio's own products. The Terms cut the other way: clause 17.2 states Themis does not review the Materials for accuracy, completeness or currentness and provides them as is, which is the opposite of a good-law guarantee, and clause 17.5 permits Materials to be added, modified or removed without notice. Checked across the home page, pricing page, AI Principles page, security page, subprocessor list and the full North American Terms of Service on 1 September 2026.

Note for the reader that the separately indexed Vincent AI record does describe a Cert citator; that capability is graded on that record and is not credited here.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Centerbase
Not addressed

No located public material addresses what Centerbase IQ does when it cannot answer. The published description is confident throughout: users ask in natural language and instantly receive visual, citation-backed answers, and the examples given are all cases where the data supports a clean answer, collection rates by practice group, attorneys with work in progress aging beyond sixty days, matters with approaching deadlines.

Nothing describes the other case. No statement says that a question outside the data is declined, that an incomplete answer is flagged, that a confidence indicator accompanies a figure, or that ambiguity in a natural language question is surfaced back to the user rather than resolved silently. What the vendor does publish is adjacent and genuinely useful, that every answer carries its source records so a user can check the basis, and that is graded on the Citation Accuracy row; being able to audit an answer is not the same as being told the system was unsure.

The distinction matters on a tool whose output is quoted in partner meetings, where a confidently wrong realization figure is harder to catch than a refusal.

Clio
Not addressed

No located public material describes what the product does when it cannot ground an answer. The published position places the burden entirely on the reader instead: clause 14.2 states Themis does not review Output for accuracy or completeness, that Output may be incomplete or inaccurate, and that the subscriber must review it before disclosing or using it. No confidence signal, no abstention path and no described no-answer behavior was found across the home page, pricing page, AI Principles page, security page or the Terms on 1 September 2026. The Clio Work product page and the published accuracy resource were not opened and are the rebuttal route.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

Centerbase
None located

Searched on 12 September 2026, on the product name with a legal-software qualifier and on the corporate name, against published trackers of decisions on AI-generated fabricated citations including coverage of the Damien Charlotin AI Hallucination Cases database and two independent sanctions trackers. None located. This is a statement about the public record on that one subject as of the date shown, and under R119 this signal records fabricated citations and nothing else, so it is not a litigation history.

Recorded because it bears on how this signal should be read on this record: the product generates no citations to legal authority at all, its AI having launched in April 2026 and answering questions about a firm's own billing and operational data. The exposure this signal tracks is not the exposure this product presents, and its analogous failure would be a misstated financial or productivity figure relied on in a management decision, which no tracker records and which would surface, if at all, as a commercial dispute rather than a sanctions order.

Clio
None located

No court order, opinion or disciplinary record naming any Clio product has been located. The AI Hallucination Cases database maintained by Damien Charlotin was searched on 1 September 2026 across Clio, Clio Work and Clio Duo alongside general sanctions coverage, and nothing naming a Clio product as the tool involved was found. Clio itself publishes extensive material on the sanctions record, including analysis of the Morgan and Morgan matter, where the tool involved was that firm's own in-house platform rather than a Clio product. This is a statement about the public record rather than a finding about the product.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Centerbase
Not addressed

No located public material engages with bar or ethics guidance. No bar opinion is named, ABA Formal Opinion 512 does not appear, no state guidance on generative AI in legal practice is referenced, and nothing maps the product to a rule of professional conduct. Nor is professional responsibility referred to in general terms on the surfaces read. The vendor's trust argument is made in commercial and technical language rather than professional language: AI has to earn trust before it earns adoption, firm leaders are not asked to trust a black box, they are shown both the answer and the source.

Recorded and expressly not credited, because it is adjacent enough to be mistaken for engagement: the product debuted at the Association of Legal Administrators Annual Conference and is listed in the ALA's supplier directory, which is a trade-body marketing channel rather than any statement of alignment with ethics guidance. The one area where a professional rule plainly touches this product, trust accounting compliance under state rules, is presented as a feature rather than tied to any published authority.

Clio
Generic reference

Professional responsibility is engaged repeatedly and no specific guidance is named. Clause 14.2 makes the subscriber responsible for reviewing Output to ensure compliance with legal, regulatory and professional organization requirements and applicable fiduciary rules, and clause 14.4 enumerates the disclosures a firm must give its own end-users about AI use, limitations and human oversight, which is closer to operationalizing a professional obligation than most vendors get.

Clio also publishes a substantial body of writing on sanctions, the duty of competence and verification practice. But ABA Formal Opinion 512 is not named on any surface read on 1 September 2026, and no state bar opinion is cited; the 100-plus bar association partnerships are commercial relationships rather than engagement with guidance.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Centerbase
Savings claims only

Capacity and realization claims are published and nothing addresses billing disclosure, on a product that is itself the firm's billing system. The claims are explicit in the NetDocuments announcement: greater delivery capacity without added headcount, workflows that make alternative fee arrangements more predictable, and stronger realization and client service. The fee relationship is engaged more directly here than on most records, because Centerbase is where the time is captured, the invoice is built, collections are chased and realization is measured, and the Billables AI partnership adds automated time capture on top.

Nothing published states whether AI-assisted work is identified on a bill, whether a client is told, or how a firm should price work that AI has compressed. One distinction is recorded rather than glossed: Centerbase IQ's own saving is administrative, sparing a managing partner a report request rather than reducing billable work, so the compression claim attaches to the partner integrations rather than to the vendor's own AI. Either way the platform sits inside the fee relationship and the disclosure question is unaddressed.

Clio
Savings claims only

Efficiency and revenue claims are published and the treatment of AI-assisted work on a bill is not. King Law's 275% revenue growth is the headline, and the platform is itself a billing and time-capture system. One clause does address passing a technology cost to a client, and it is worth noting for precision rather than credit: clause 17.3 states the cost of Purchased Materials may be recovered from a client as a disbursement or similar.

That is research cost recovery, not a position on how time compressed by AI should be recorded or disclosed, which is the question this signal asks. No audit record identifying which work product was AI-assisted is described. Checked 1 September 2026.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Centerbase
Not addressed

No located public material supports a client-side disclosure obligation, and none of the three artifacts this signal looks for exists on the surfaces read. There is no subprocessor list anywhere. No model provider is named, so a firm asked which third party processes its data through Centerbase IQ could not answer from anything published. No data processing addendum, security exhibit or forwardable client-facing pack was located, and no trust center exists.

The value is not on-request, because nothing indicates such material sits behind a request process: no security contact, documentation request route or portal is published, and the security page that might have offered one is machine-refused to this index. The gap has a specific edge on this record, because the product's own subject matter is the firm's relationship with its clients: Centerbase handles e-billing and compliance through its Scan Logic integration, and the corporate clients that impose outside counsel guidelines are the same ones now writing AI clauses into them, so a firm running its e-billing here may be asked exactly this question by the client whose invoices flow through it.

Clio
Disclosure pack published

A firm could answer a client's AI questionnaire from published material alone. The subprocessor list, last modified 20 August 2026 and reachable without a form or agreement, names every infrastructure, AI, feature and payment provider, maps each to the products it serves, and gives a data location for each, including a dedicated AI Service Providers table naming five model processors. Alongside it Clio publishes the Data Protection Addendum, the service level commitments exhibit, the AI Principles page, a public trust center and a dedicated legal process page at clio.com/legal-service.

Together that is a forwardable pack covering who processes client content, where, and on what contractual basis. The specific models are not named, which is the one thing a demanding client questionnaire might still ask for.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Centerbase
Not addressed

No located public material addresses disclosure of AI involvement in legal work, and the record the product does produce is a different artifact worth distinguishing. What Centerbase IQ produces is a traceable answer: every answer includes the source records behind it, users see where it came from, and an administrator can trace a figure back to the underlying billing entry or matter. That is a real provenance trail and it is graded on the Citation Accuracy row.

It is a record of how a management figure was derived, not a record of AI involvement in anything that reaches a client, an opponent or a court. Nothing identifies the model, no model is named anywhere, nothing distinguishes machine-generated from human-authored content in any output, and no disclosure template, certification or court-facing guidance was located. The distinction is worth stating rather than forcing the signal: this product does not touch legal work product, so the disclosure exposure it carries is indirect, reaching a court only if a firm's internal analytics became relevant to a fee dispute or a sanctions inquiry into billing.

Clio
Partial record

The pieces of a record exist and none is assembled for disclosure. Output is stated to carry citations traceable to source, the subprocessor list would let a firm identify which providers could have processed a given product's content, and the review-and-approve commitment describes a human step. But nothing identifies which model produced a specific output, no verification event is recorded against a document, and no export is offered or described for the purpose of answering a court.

Clause 14.4 pushes the disclosure obligation onto the firm, requiring it to tell its end-users about AI use and human oversight, without giving it an artifact to do so from. Checked 1 September 2026.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Signals neither addresses in public material
  • Good Law Verification
  • Refusal and Uncertainty Behavior

Which one fits

Choose Centerbase if

  • You want firm leaders to ask the numbers questions themselves. Centerbase IQ answers plain language questions about collection rates by practice group, work in progress aging past sixty days, realization, origination and receivables, and returns a visual answer with the source records behind it.
  • Your firm runs NetDocuments and wants matter data flowing into it. Centerbase publishes a native NetDocuments connection to ndMAX document intelligence from March 2026, Billables AI time capture from April 2026, and Scan Logic BillSync for electronic billing compliance from August 2026.
  • You are a midsize firm and want software built for that size. Centerbase positions its whole platform on midsize firms, names managing partners and firm administrators as the users of its AI, and brings matters, timekeeping, billing, collections, trust and general accounting, intake and reporting into one system.

Choose Clio if

  • You want the professional line drawn in the contract. Clio's terms state in bold that it is not a law firm and gives no legal advice, limit use to legal professionals and those they supervise, and require the firm to tell its own clients about AI use and human oversight.
  • Your client asks who processes its data and where. Clio's subprocessor list, dated 20 August 2026, names AWS Bedrock, Anthropic, OpenAI, Google Vertex AI and Microsoft Azure Foundry with the products each serves and a data location for each, and AI processing stays in the customer's region.
  • Your security review wants a report with a coverage period. Clio announces a SOC 2 Type II report for 1 June 2024 to 31 May 2025 through its trust center, and its terms require it to provide a SOC 2 or SOC 3 report within thirty days of a request.

In summary

Centerbase

Centerbase, from Centerbase, LLC of Dallas, Texas, is a cloud operating platform for midsize law firms that brings matter management, timekeeping, billing and collections, trust and general accounting, document management, intake, a client portal and reporting into one system of record. Its AI, Centerbase IQ, launched in April 2026, answers plain language questions from managing partners and administrators about collections, realization, work in progress and deadlines, with the source records behind every answer. The AI Legal Index grades it in the top two bands on four of fifteen capability axes. It publishes native integrations with NetDocuments and Billables AI. As of 12 September 2026 the index located no customer agreement, no price at any level and no named model provider.

Source: AI Legal Index, 2026

Clio

Clio, operated by Themis Solutions Inc. of British Columbia, is a legal practice platform for firms of every size, built around Clio Manage for matters, time, billing and trust accounting, Clio Grow for intake, Clio Draft for document automation and Clio Work, an AI workspace for research and drafting over the firm's matters and the vLex library, which Clio acquired in June 2025. The AI Legal Index grades it in the top two bands on fourteen of fifteen capability axes, with A grades on professional responsibility and security certifications. It publishes its terms, a dated subprocessor list naming five AI providers, and prices from $49 per user a month. As of 1 September 2026 the index located no published accuracy figure and no AI governance mechanism.

Source: AI Legal Index, 2026

Questions buyers ask

Centerbase vs Clio: which is better for a midsize law firm?

On published evidence Clio sits in the top two bands on fourteen of fifteen AI Legal Index capability axes and Centerbase on four of fifteen, mostly because Clio publishes its agreement, subprocessors, certifications and prices. Centerbase is built only for midsize firms, and its AI answers questions about the firm's own finances with the source records shown. Firms choosing on published terms have far more to read from Clio.

Does Clio train AI on client data?

Its agreement permits a bounded form of it. Clause 14.6 of Clio's terms lets it take content submitted to its AI services and the output returned, strip identifiers, aggregate it and use it to improve those services, and withholds any right to train general language models on confidential information. Centerbase publishes no position on training, and no customer agreement for it was located. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

What does Centerbase IQ do?

Centerbase IQ, launched in April 2026, lets a managing partner or administrator ask plain language questions about the firm's own data, such as collection rates by practice group, work in progress aging past sixty days, realization or approaching deadlines, and returns a visual answer. Every answer carries the source records behind it, and the vendor states the analysis stays within the firm's own data. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

How much do Centerbase and Clio cost?

Clio publishes a starting price of $49 per user a month and names four tiers, Starter, Core, Signature and Elite, with the upper tiers quoted; its terms add setup, implementation and metered fees that are not published. Centerbase publishes no price, tier or unit of charge, and its site routes buyers to a demonstration request. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

What do Centerbase and Clio both leave unpublished?

How their AI is governed and how accurate it is. Neither names who is accountable for its AI, describes testing before a feature ships, or publishes an accuracy figure. Neither documents walls between matters inside a firm for its AI, names bar guidance on AI use, or says how work done with AI is recorded on a client's bill, though both run the firm's billing. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

Disclosure

Three readings to weigh. No customer agreement for Centerbase was located, and its current security page is closed to this index's reader by the site's robots file, so its low grades record what could be reached, not a judgment that its controls are weak. Two live Centerbase security pages describe its SOC 2 Type II scope differently, one covering the security criterion only. Clio's permission to improve its AI with content stripped of identifiers sits beside a bar on training general language models with confidential information; both are published terms. Centerbase was verified on 12 September 2026 and Clio on 1 September 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 24, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746