Checkbox vs Josef: how they compare in 2026
Checkbox and Josef are direct substitutes, two no code platforms that let an in house team build self service legal tools for the rest of the business, and the grid does not separate them: both sit in the top two bands on eight of fifteen axes. What breaks the tie is which half of the product each has written down. Checkbox publishes the plumbing. Its data processing addendum names every subprocessor individually with a description of what each one does, including OpenAI for the generative features where a customer switches them on, sets retention at the licence term plus thirty days, requires deletion with certification, and its master agreement lifts privacy and intellectual property claims above the ordinary fee cap. Josef publishes the behaviour. Josef Q is documented as a closed domain system answering only from uploaded content, showing the page, paragraph and clause each answer came from, with a moderation layer over every answer and source and a published stop rule: outside the corpus, it says it does not know.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The product is a workflow and intake system with AI applied to two steps inside it. Checkbox began as a no-code automation platform, which is what the 2022 Gartner Digital Markets recognition was for, and the architecture is still a request pipeline: capture, triage, matter management, automation, reporting. Checkbox AI is described as generative AI to streamline intake and workflow automation, with AI-powered triage routing on matter type, expertise, capacity and business unit, and a separate AI legal chatbot answering routine questions. Those are real shipped capabilities and they accelerate steps that already existed. Remove the models and the platform still captures requests from email, Slack, Teams, Jira and Salesforce, still manages matters, still runs no-code workflows for NDAs and approvals, and still reports on cycle time and workload. The subprocessor list confirms the shape: generative AI is supplied by a third party and enabled only where the customer switches the optional features on, so the AI is a layer a buyer elects rather than the thing being bought.
Josef sells three products: Josef Q for AI question and answer, contract automation, and workflow automation. Only the first is model-driven. The contract and workflow modules are template and rules automation that predate the AI layer, and they are what the L’Oréal case study’s 66% turnaround figure actually rests on. Josef Q is not peripheral — it has its own login at q.joseflegal.com, four dedicated product pages and its own named customers at adidas, Bupa and Cityblock Health — but remove it and a working no-code document and workflow platform remains. That is the B band precisely: the models are the engine of a core capability layered on a product that would still function without them. Pages read 1 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Nothing published addresses accuracy for a product whose AI answers legal questions and routes legal work. The AI legal chatbot is marketed as providing instant legal help and response, and AI triage decides which lawyer receives which matter, so both a wrong answer and a wrong routing decision have consequences the buyer would want measured. No accuracy rate, benchmark, test set, evaluation, error mode or confidence measure was located on the home page, the security page, the legal set or the platform navigation, read on 1 September 2026. Nor is there a grounding description: nothing states what the chatbot answers from, whether responses are restricted to a customer's own policy and FAQ content or draw on the underlying model's general knowledge, and no citation or source-linking behaviour is described. The one adjacent published fact sits in the subprocessor annex rather than in any product material, which is that generative AI functionality is supplied by OpenAI. Checkbox AI's own product page was not opened, so this grade is rebuttable on that surface.
Grounding is real and specifically documented. The AI controls page states Josef Q is a closed-domain system answering only from uploaded content, and the source list shows the exact page, paragraph and clause an answer drew on, so a reader can open and check the support. A document pre-processing engine is described as scanning and optimising uploaded content before indexing. No measured accuracy figure and no test set is published anywhere, which is what holds this at B. Two limbs of the higher bands do not apply to this product class: Josef Q retrieves the customer’s own policies rather than primary law, so grounding to primary authority and citation-status checking are not capabilities it claims. Against that, the audit trail page carries an unqualified “No hallucinations!” claim, which is marketing running ahead of the mechanism. It does not drop the grade to D because it sits alongside a described architectural control and a published refusal path rather than standing alone. Read 1 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
What the automation does is described clearly and what constrains it is not. The published account of the pipeline is specific: requests are automatically captured across channels, triaged and routed by AI on matter type, lawyer expertise, capacity and business unit, matters are maintained automatically, and self-service workflows resolve routine requests without a lawyer touching them. The design intent is stated plainly, that legal teams stay focused on work that matters while the system handles the rest. What is absent is the control structure around it. Nothing describes a review point where a lawyer confirms or overrides an AI routing decision, no confidence threshold or escalation path is published for a request the system cannot classify, and nothing states what happens when a matter is routed wrongly or when the chatbot answers a question it should have escalated. Approvals exist as a workflow feature the customer configures, which places a human in the process by design rather than describing an oversight mechanism over model output.
The control structure is published in unusual detail for this lane. The AI controls page documents human-in-the-loop moderation over every answer, source addition and removal in a Moderation tab, a Tuning Lab for tone, length and spelling convention, and Smart and Follow-up Suggestions that shape what end users ask. The stop rule is published and specific: outside the uploaded corpus the tool answers “Sorry, I don’t know.” The audit trail page adds that all user questions and generated answers are tracked and stored. What is missing for A is the route back to human judgement — no escalation path from an unanswered question to a lawyer was located on any product page read on 1 September 2026 — and no thresholds or distinct autonomy modes are published. B rather than A on the absent escalation route, not on the review surfaces, which are the strongest part of this record.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
The attribution is the best in this pull and the measurement is thin. Six named individuals are quoted with title, employer, legal team size and organisation size: Jeannine Moran, Director of Legal Operations at Hitachi Digital, describing a single front door serving 40-plus countries across a 60-plus legal team and 16,000-plus employees; Janene Asgeirsson, Chief Legal Officer at Analog Devices; Richard Conway, Deputy General Counsel and Corporate Secretary at Coca-Cola Europacific Partners, on a 180-plus legal team; Jim Gray, VP and Head of Global Legal Operations at SAP, on a 400-plus legal team across 100,000-plus employees; Linh Duong, Senior Legal Counsel at Align Technology; and Sam Bailey, Senior Legal Counsel at Air New Zealand. A headline outcome figure is published for Woolworths Group, a reduction in matter volume of up to 80 per cent, and a further story covers NDA automation at Xero. Behind them sits a logo set including BMW, PepsiCo, Telefonica, Allianz, Deloitte, PwC, Danone and Telstra. **What holds it below the top band is measurement and dating**: the quotations are qualitative, the team and employee figures size the customer rather than the change, only one outcome number was located, and no case study carries a visible date. None of the case studies was opened on 1 September 2026.
Attribution and figures are both present, which is more than most of this pull manages. The L’Oréal case study names Candy Welsh, Legal Counsel, and reports a 66% drop in contract turnaround, one contract moving from over an hour to 20 minutes, 100-plus such contracts a year, and roughly two weeks of work saved annually. Further named deployments carry named officers: Katherine Roseveare, General Counsel at adidas, across 65,000-plus people; Claire Nuske, Head of Legal Operations at Bupa, with 40-plus self-service tools; Wendy Chow, General Counsel at Cityblock Health; Sheila Dusseau, Head of Global Legal Operations at Ferring Pharmaceuticals. What keeps this at B is that no case study read on 1 September 2026 carries a date, and the 66% figure is given with no statement of how it was measured or over what period, so a reader can assess neither the method nor the currency.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The contractual position is complete and readable in advance, and the training question is answered only by implication. What a buyer can read before signing: a published data processing addendum incorporating the EU standard contractual clauses in the controller-to-processor module, with Checkbox named as processor and the customer as controller; processing restricted to documented instructions and to the specified purpose; onward disclosure to a third party permitted only on documented instructions; personnel access granted only to the extent strictly necessary and bound by confidentiality; and deletion or return of all personal data at the customer's choice at the end of processing, with certification of deletion. Retention is stated with a period rather than a criterion, at the duration of the licence plus thirty days unless earlier deletion is requested in writing. The master services agreement reinforces it commercially by carving data protection and privacy obligations out of the ordinary liability cap. Two gaps keep this off the top band. **No express statement was located that customer content is not used to train models** — the SCC purpose limitation constrains it without naming it — and privilege and work product are never mentioned despite the product holding legal matters for in-house teams.
No customer agreement is published. The home page, security page, FAQ, website terms and privacy policy were read on 1 September 2026 and a clause-language search was run; the only two published instruments are website terms and conditions and a privacy policy dated 15 February 2024, and that policy states it applies to Josef as a controller rather than to customer content held as a processor. What is published is real but general: the FAQ states customers retain full ownership of their data and Josef acts as custodian, and the security page states AES-256 at rest and TLS 1.3 in transit with Josef-held server-side keys. Nothing addresses training on customer content, tenant separation, or privilege and work product treatment. The in-house band amendment does not rescue this, because for an in-house buyer the requirement is tenant-level separation and no separation of any kind is documented. C rather than D because the ownership and encryption commitments are published and readable before signing; C rather than B because the commitments that decide this axis cannot be read in advance at all.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Nothing located addresses the line between an information tool and legal advice, on a product that markets an AI legal chatbot as providing instant legal help and response to business users who are not lawyers. That framing is what makes the gap material: the chatbot and the self-service workflows are explicitly designed so that employees across the business resolve legal questions without reaching a lawyer, which is precisely the situation where a published position on what the tool is and is not would matter. No statement was located that outputs are not legal advice, that no professional relationship arises, or that answers should be confirmed with counsel, and no jurisdiction limit or supervision statement appears. Searched the home page, the security and trust page, the privacy policy, the legal index and the data processing addendum on 1 September 2026. **The master services agreement was recovered only in part through the R8 ladder and the acceptable use policy and EULA were not opened**, so a disclaimer may sit in one of them and this grade is rebuttable on those three documents.
The only disclaimer located is scoped to the wrong thing. The website terms and conditions state that content on the Josef website is provided for information purposes only, which addresses the marketing site rather than the output of a tool answering policy questions for employees. Meanwhile the product is described in advice terms: the Josef Q demo panel offers to provide scalable guidance and advice, and the FAQ describes legal aid organisations and boutique firms using Josef to deliver client-facing onboarding, wills and guidance tools to members of the public. No jurisdiction limit, no statement of who may rely on an answer, and no consumer-facing disclosure requirement were located on any page read on 1 September 2026, and ABA Formal Opinion 512 is not mentioned. C rather than D because a disclaimer does exist in the terms; C rather than B because it does not reach the product, and the client-facing uses the vendor advertises are exactly where the advice line bites hardest.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Nothing published addresses governance of the AI in the product. There is no responsible-AI page, AI policy, ethics statement, governance committee, named accountable owner for model behaviour, pre-release testing regime or bias evaluation anywhere on the property, and the site navigation and footer were read in full on 1 September 2026 across platform, solutions, resources, partners and company sections. What does exist is information security governance, which is a different subject and is credited on the stewardship and certification rows rather than counted here: an information security management system with named policy domains, thirteen individually listed security policies in the DPA annex, and a Chief Information and Security Officer named as the contact for the data importer. The distinction matters because AI routing decides which lawyer receives which matter and the chatbot answers questions for non-lawyers, so uneven performance across request types or business units is a live question that nothing published addresses.
No governance position located. The home page, the three product pages, the AI controls page, the audit trail page, the security page, the FAQ, the website terms and the privacy policy were all read on 1 September 2026. There is no responsible AI page, no named internal owner, no pre-release testing regime, and no ISO 42001 or equivalent. Nothing addresses whether answer quality varies across topics, document types or populations. The moderation and review controls are real but they are an oversight mechanism already graded on Autonomy, and the band excludes security controls as a different subject, so neither can be spent here. The chief executive’s published article on context engineering is a design argument, not a governance disclosure.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Every limb is published, specific and current, and the subprocessor limb is the strongest in the pull. **Retention carries a period**: personal data is retained for the duration of the licence agreement until thirty days following termination, unless the customer requests earlier deletion in writing. **Deletion is contractual and certified**: at the end of processing Checkbox must, at the customer's choice, delete all personal data and certify that it has done so, or return it and delete existing copies. **Subprocessors are named individually with address, contact and a description of what each does**: Amazon Web Services for hosting and storage, Datadog for application and infrastructure logs, SendGrid for workflow email with automatic deletion after delivery, and OpenAI for generative AI functionality where the customer enables the optional features. Changes require fifteen days' advance written notice with an objection right. **Incident practice is specified**: notification without undue delay after becoming aware, with a contact point, the nature of the breach, categories and approximate numbers of data subjects and records, likely consequences and measures taken. Access is limited to personnel for whom it is strictly necessary and bound by confidentiality. Encryption at rest and in transit is stated, backed by thirteen named policies including a Cryptographic Standard, Data Destruction Standard and Security Incident Response Plan, and by annual third-party penetration testing.
Access control is documented and the rest is not. The security page states AES-256 encryption at rest, TLS 1.3 in transit, Josef-held server-side encryption keys and regular access audits, alongside OWASP and ASD secure coding frameworks, automated vulnerability scanning and annual third-party penetration testing. What happens to uploaded documents and prompts afterwards is not addressed: the privacy policy retains service data for the duration of the business relationship and an unstated period after, deletion is described only as securely deleting or anonymising once no legitimate business need remains, and no incident practice is published anywhere. The subprocessor list is not published — the privacy policy says it can be provided on request, and no self-service portal or instant-download route was located on 1 September 2026, so under the three-tier rule it earns no credit. C rather than B because two of the five elements the band names are absent outright and two more are stated without a period or a mechanism.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
The allocation is published, mutual and better than the corpus norm on one specific point, short of the top band on scope. The general cap is the familiar one, each party's aggregate liability limited to the amount actually paid in the twelve months immediately preceding the date the liability arose. **What lifts it is the super-cap**: that limitation expressly does not apply to infringement or misappropriation of intellectual property rights, to data protection and privacy obligations, or to the indemnification obligations, for which liability instead runs to a stated multiple of the ordinary cap. A vendor voluntarily exposing itself above the fee cap for a privacy failure is uncommon in this corpus. Checkbox indemnifies the customer against third-party claims that the software or services infringe intellectual property rights, and **may not settle on terms imposing a non-monetary obligation on the customer or requiring an admission of fault without the customer's prior written consent**, which is a protection most vendors omit. The customer indemnity is reciprocally narrowed, carved back to the extent a claim results from Checkbox's own negligence or breach. What is missing is anything AI-specific: no warranty on output, no insurance position located, and the agreement was recovered only in part through the R8 ladder.
Nothing published on who bears the loss when an answer is wrong. The only liability clause located sits in the website terms and conditions and excludes liability arising from use of the Josef website, limited where it cannot be excluded to resupply of the relevant services or information. That is a website clause, not a position on product output. No master subscription agreement, customer agreement, service level agreement, warranty or indemnity was found. The escalation ladder was run on 1 September 2026: the footer was checked across six rendering pages and offers only the website terms, the privacy policy and a cookie notice, and a search on customer-agreement clause language returned no Josef instrument. This is an established absence rather than a retrieval failure, so it is graded rather than left unwritten under R7.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations, named individually, with the direction of travel described for each. Slack and Microsoft Teams turn messages into complete matters, so a request raised in chat becomes a tracked item without the requester leaving the channel. Gmail and Outlook automate email capture and matter tracking. Salesforce automates contract generation and approvals, which is the sales-to-legal handoff that usually breaks. Ironclad syncs contract requests and tracking, which matters because it positions Checkbox alongside a CLM rather than against one, and the company markets the pairing directly. Jira is named as a further intake channel. A technology and integration partners page exists alongside a referral and services partner programme. What keeps this below the top band is depth rather than breadth: no API reference, developer documentation or connector specification was located, nothing describes field-level mapping or what happens when a synced record conflicts, and no statement covers systems that are not supported. The integrations pages themselves were not opened on 1 September 2026.
Thirteen integrations are named and grouped by function, and the direction of travel is described: policies sync in from SharePoint and Confluence, data is pulled from Airtable and Google Sheets, and captured information is pushed out to Slack, Teams, SharePoint and Salesforce. The legal systems are what matter in this lane and they are present — HighQ, Xakia, Dazychain and Actionstep are all named. The Xakia entry goes furthest, describing Josef bots launched from Xakia’s internal client portal so that requests stay managed within Xakia. Two integrations carry linked walkthroughs, for Actionstep and Xakia. B rather than A because no documentation an implementer could use was located: no developer index, no field mapping, and no statement of what a firm must configure, with the integrations page answering any unlisted case by inviting a conversation with the team. Read 1 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Residency is offered as a customer choice and the rest of the model is partial. The privacy policy states that Checkbox primarily stores data **in the data centre region that the customer requests**, which is a selectable residency rather than a disclosed default, and is a stronger position than most vendors in this corpus publish. It is qualified in the same passage: data may sometimes be disclosed to third parties in other locations for the listed purposes, and those locations may not have equivalent data protection laws, with transfers performed in accordance with applicable law. The subprocessor annex identifies Amazon Web Services as the hosting and storage provider, so the infrastructure is named rather than implied, and the standard contractual clauses govern transfers with the Irish Data Protection Commission as competent supervisory authority. What is absent is the tenancy model, with nothing stating whether customers share infrastructure or receive a separate environment, no enumeration of the regions actually available, and no statement of what changes between deployment tiers.
The security page and the FAQ both state data residency options in the US, Europe, the UK and Australia, a four-region commitment stated consistently in two places. The tenancy model is never stated: nothing published says whether customers sit in shared or separate instances. Processing location is not addressed as distinct from storage, and there is a tension a buyer should read before signing. While the security page offers regional residency, the privacy policy tells users their personal information may be transferred and processed outside their country including in the United States, relying on standard data protection clauses for EEA and UK transfers. The two are not necessarily inconsistent, since the privacy policy governs Josef as controller rather than the platform tenancy, but no document read on 1 September 2026 reconciles them. B on the second limb of the band: residency is offered without the processing location being addressed.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Four standards are claimed with audit language and none of the confirming detail is public. Checkbox states it has been externally audited and completed a **SOC 2 Type II examination**, holds **ISO/IEC 27001:2022 certification**, and is compliant with **ISO/IEC 27017:2015** and **ISO/IEC 27018:2019**, the last of these being the cloud personal-data standard and a sensible one for this product. The DPA repeats all four, which puts the claim in a contractual document rather than only in marketing. Supporting practice is described in more depth than most: an information security management system covering network security, information handling, access control, incident response, backups, change management, risk management, vulnerability and patch management and vendor risk, plus individually listed controls including network intrusion detection, micro-segmented firewalls, hardened standard operating environment images and monitoring of all administrative access. What holds it below the top band is access and specificity. No auditor, certificate date, examination period or scope statement appears anywhere. A trust portal exists at trust.checkbox.ai and **was not opened**, while the route the page itself offers is a contact form to request policies, penetration tests and SOC 2 reports, so under the gated tiers the lower reading applies until the portal's own access flow is seen.
SOC 2 Type II is stated on the security page, the FAQ and the home page, and the privacy policy states SOC 2 Type I and II. Annual third-party penetration testing is stated, as is GDPR compliance and ISO certification of the underlying server infrastructure. Absent is everything that would let a buyer check any of it: no auditor is named, no scope or coverage period is given, no report or summary is offered by any route, and no trust centre exists — no Vanta, SafeBase or equivalent portal was located on 1 September 2026, including through the footer and navigation of pages that render. B rather than C because the standard is named in prose rather than appearing only as a badge image; B rather than A because there is no access flow to the evidence at all, not even a gated one.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
**The first record in this pull to name a third-party model provider.** Annex III of the published data processing addendum lists OpenAI, LLC, with its address and privacy contact, and describes what it does in terms that answer the question this axis asks: OpenAI is used to provide generative artificial intelligence services for AI-based functionality in Checkbox **where the customer enables such optional features**. That single entry tells a buyer whose model is involved, that the AI is opt-in rather than always-on, and that the provider sits inside the processor chain with the same fifteen-day change-notice and objection rights as any other subprocessor. It also sits alongside the infrastructure entry for Amazon Web Services, so a reader can distinguish where workloads run from whose model reads the content, which is the distinction most vendors collapse. What is missing is the layer below: no model or model family is named, no version or change-notification commitment specific to the model is published, and nothing describes what data is sent to the provider, for how long it is retained there, or whether a zero-retention arrangement applies.
Josef acknowledges a large language model underneath and never says whose. The chief executive’s published position is that an LLM alone cannot be trusted and needs context engineering, and the audit trail page refers to GenAI engineering, but no model, no model provider and no inference location is named on any page read on 1 September 2026. Hosting region and ISO-certified infrastructure are published, but a hosting location answers where the software runs rather than whose model sees client content, and cannot be spent on this axis. There is no commitment to notify customers if the underlying model changes. The only route to the supply chain is the subprocessor list the privacy policy says is available on request.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. The site navigation and footer were read in full on 1 September 2026 across platform, solutions, why-Checkbox, resources, partners and company sections and contain no pricing page. Every commercial route is a demo booking, a guided product tour or a contact-sales form. No rate, band, tier name, package structure or per-seat, per-request or per-matter unit was located, and nothing states what implementation or onboarding adds, which is material for a platform whose value depends on configuring workflows to a particular legal function. The published agreements set out billing mechanics without price: fees are defined by reference to a Checkbox Licence Order, and the data processing addendum ties both the retention period and the execution of the addendum itself to that order. Two audience pages exist for growing and enterprise legal teams, which segments the market without pricing it.
No pricing information at any level. There is no pricing page: the navigation and footer were checked on 1 September 2026 across the home page, the Josef Q and integrations pages, the security page, the AI controls page and the FAQ, and none carries a pricing entry. Every commercial path is a demo booking or a contact form. No tier names, no packaging structure, no unit of charge and no figure are published, so a buyer cannot learn what is being charged for, let alone how much. D rather than C because C requires the shape to be visible with only the number withheld, and here neither the shape nor the number is published.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
The buyer is identified with precision and the boundaries of the product are left open. Checkbox is unambiguous about who it is for, addressing in-house legal teams throughout and publishing separate pages for growing and for enterprise legal teams plus an in-house legal roles page, and the customer evidence bears the positioning out with legal teams ranging from 60 to 400 lawyers at organisations from 10,000 to 100,000 employees. Practice coverage is expressed as request types rather than practice areas, spanning NDA automation, contract lifecycle steps, legal policy and FAQ handling, and general intake, which suits a front-door product. What is thin is everything about limits. No industry or sector segmentation is published despite a customer base spanning banking, pharmaceuticals, retail, aviation, technology and professional services. Nothing states a minimum viable team size, a request volume the product is designed for, or matter types it does not handle, and no jurisdictional scope is given for a platform sold to multinationals. The claim that it suits both growing and enterprise teams is made without describing what differs between them.
Coverage is set out by segment with named customers in each, which is unusually concrete. The FAQ and the customer navigation name five segments — in-house legal, global law firms, boutique and NewLaw firms, legal aid organisations and community legal centres, and law schools — each with its own page and named users: L’Oréal and Bumble in-house, Orrick and Herbert Smith Freehills among firms, Hive Legal and Polaris Lawyers in NewLaw, Housing Court Answers and Everyday Justice in legal aid, and Cornell, NYU and the University of Pennsylvania in education. Document types are named too — NDAs, MSAs, employment agreements, powers of attorney and client onboarding forms — with Q&A use cases grouped under commercial, privacy and data, legal operations and HR. B rather than A because the limits are not stated: the FAQ’s position is that anything repeatable can be automated, government use is not addressed, and no page says where the product stops. Read 1 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No express statement was located that customer content is not used to train or improve models, and the surrounding contractual position constrains it without naming it. The published data processing addendum incorporates the EU standard contractual clauses in the controller-to-processor module, under which Checkbox may process personal data only on documented instructions from the customer and only for the specific purpose of the transfer, stated as providing the software licence. Onward disclosure to any third party requires documented instructions. Training on customer content for Checkbox's own benefit would sit outside that purpose, so the clauses cut against it, and a reader has to reason to that conclusion rather than read it. The subprocessor annex confirms that generative AI functionality is supplied by OpenAI where the customer enables optional features, and says nothing about whether prompts or outputs passed to that provider are retained or used for training there. **Searched the DPA in full, the privacy policy, the security page and the recovered portions of the master services agreement on 1 September 2026.**
No located term or policy addresses whether customer content is used to train models. The website terms, the privacy policy of 15 February 2024, the security page, the FAQ and the Josef Q product and AI controls pages were checked on 1 September 2026, and no customer agreement is published anywhere on the site. The FAQ states that customers retain full ownership of their data and that Josef acts as custodian, which is an ownership statement rather than a training commitment, and Josef Q answering only from uploaded content describes the retrieval corpus rather than model training.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
A fixed retention period is published for customer personal data, which is rarer in this corpus than the value name suggests. Annex I.B of the data processing addendum states that personal data is retained for the duration of the licence agreement until thirty days following termination, unless a written request for earlier deletion is made. The standard contractual clauses add the mechanism: at the end of processing Checkbox must, at the customer's choice, delete all personal data processed on the customer's behalf and certify the deletion, or return it and delete existing copies. One subprocessor carries a tighter and separately stated rule, with SendGrid described as holding workflow email data that is deleted automatically after delivery. What is not separated out is AI specifically: nothing states a distinct retention or zero-retention position for prompts submitted to, or outputs returned by, the generative AI features, either in Checkbox's own systems or at the model provider.
Retention is acknowledged without a period. The privacy policy of 15 February 2024 states Josef retains service data for the duration of the business relationship and a period afterwards for analysis, historical and archiving purposes, deleting or anonymising it once no ongoing legitimate business need remains. No period is stated and no customer control is offered. The audit trail page separately states that all user questions and generated answers are tracked and stored by Josef Q, so prompts and outputs plainly persist, but no document read on 1 September 2026 says for how long.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Access control is committed contractually and segregation between customers or matters is not described. The standard contractual clauses require Checkbox to grant its personnel access to personal data only to the extent strictly necessary for implementing, managing and monitoring the contract, and to ensure those authorised are bound by confidentiality, which governs the vendor's own people. The security page adds an Information Classification Policy and monitoring of all administrative access. None of that addresses separation inside the platform, which is the live question for this product: intake routes matters to particular lawyers by expertise and business unit, and self-service tools expose legal content to employees across the business, so who can see which matter is a permission question the customer will need answered. Nothing published describes a tenancy model, a role or permission structure for customer users, or walls between business units sharing one instance.
No located public material addresses ethical walls, matter-level segregation or tenant separation. The security page, privacy policy, FAQ, website terms and the Josef Q product and AI controls pages were checked on 1 September 2026. Access is described at the level of encryption and access auditing rather than who can see which content. Permissions are implied at tool level, since a builder selects which sources each tool draws on, but nothing published describes how separation between users, teams or matters is enforced at query time.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
A full notice commitment is published, and it goes considerably further than notice, because Clause 15 of the standard contractual clauses is incorporated in the data processing addendum. Checkbox must promptly notify the customer, and where possible the data subject, on receiving a legally binding request from a public authority for disclosure, including judicial authorities, with the notification to state what data was requested, which authority requested it, the legal basis and the response given. Where notification is prohibited, Checkbox must use best efforts to obtain a waiver of the prohibition and document those efforts. It must also **review the legality of the request and challenge it** where there are reasonable grounds to consider it unlawful, pursue appeals, seek interim measures suspending the request, withhold disclosure until required under procedural rules, and provide the minimum information permissible. **What holds this below the top value is the reporting limb**: Clause 15.1(c) obliges periodic information on requests received to the customer where permissible, but no public transparency report was located.
The privacy policy addresses compelled disclosure and commits to nothing on notice. It states that information is provided to comply with the law, giving a search warrant, subpoena or court order as the examples, and separately that Josef discloses where required to enforcement agencies, government agencies and regulatory bodies. No commitment to notify the customer, and no carve-out for where notice is lawfully permitted, was located on 1 September 2026. The policy does state that Josef has received zero government requests for information since it was founded, which is a transparency statement rather than a published transparency report.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No legal corpus is maintained and the row is recorded rather than skipped. Checkbox does not retrieve or publish primary law; it captures, routes and tracks a customer's own legal requests and automates workflows over the customer's own templates, policies and documents. The content the AI works across is therefore supplied by the customer rather than licensed by the vendor, which makes the provenance question narrower here than for a research or regulatory product. It does not disappear entirely: the AI legal chatbot is marketed as providing instant legal help, and nothing published states what it answers from, so a buyer cannot tell whether responses are confined to their own uploaded policy and FAQ content or draw on the underlying model's general knowledge. Searched the home page, the platform navigation, the security page and the published legal set on 1 September 2026.
The product does not retrieve primary law, so there is no legal corpus to source. Josef Q answers from the policies, playbooks and templates a customer uploads, which the vendor states explicitly in contrast to the open internet. No public material identifies any primary law source, licence basis or update cadence, checked 1 September 2026. Recorded as not addressed because the question does not arise for this product class, rather than because the vendor declined to answer it.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No citator applies and the row is recorded rather than skipped. The platform returns a routed matter, a generated document or an answer drawn from a customer's own material, not a legal authority whose subsequent history a user would need to verify. There is no regulatory or case-law corpus behind it and therefore no currency mechanism to describe. The nearest analogue is template currency, since the workflow automation generates NDAs and other documents from customer-maintained templates, and responsibility for keeping those current sits with the customer rather than with Checkbox; nothing published addresses version control or review prompts for ageing templates. Searched the home page, the platform and solutions navigation and the published legal set on 1 September 2026.
No citator, and none would apply. Josef Q returns answers from customer-uploaded policy and playbook content rather than case law or legislation, so there is no authority whose subsequent history could be checked. Nothing on the product, AI controls or audit trail pages addresses currency of the source content beyond letting an administrator add, update or remove documents in the Moderation tab. Checked 1 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Nothing located describes what the system does when it cannot answer or classify, which matters here in two distinct places. The AI legal chatbot is marketed to business users as providing instant legal help and response, so what it does with a question outside its scope determines whether a non-lawyer receives a wrong answer or is routed to a lawyer. And AI triage assigns matters on type, expertise, capacity and business unit, so what happens to a request it cannot categorise determines whether that request is queued for human review or misrouted silently. No confidence score, abstention path, fallback rule, escalation trigger or coverage indicator is published for either. Searched the home page, the security page, the platform navigation and the published legal set on 1 September 2026; the Checkbox AI and AI legal chatbot product pages were not opened and are where such a description would sit.
Josef publishes an explicit no-answer path. The AI controls page states that Josef Q is a closed-domain system answering only from content the customer uploads, and that where it does not know the answer it says so in those words. The behaviour is presented as a property of the closed domain rather than a prompt instruction. Recorded as documented rather than demonstrable because no published evaluation or observable test of the behaviour was located on 1 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name. No court order, opinion or disciplinary record naming Checkbox was located. This is a statement about the public record rather than a finding about the product. The failure mode fits poorly, since the output is a routed matter, a generated document from a customer template, or a chatbot answer consumed inside a company rather than a citation filed with a court; the analogous exposure would be a wrong answer given to a business user who acted on it without a lawyer seeing it, which would surface as a commercial dispute rather than in a sanctions docket.
No court order, opinion or disciplinary record naming this product has been located. The AI Hallucination Cases database maintained by Damien Charlotin was searched on 1 September 2026 on both the product name and the company name, Josef Legal Pty Ltd, alongside general sanctions coverage, and nothing naming the product was found. The database held roughly 1,668 cases as of July 2026, so this is a statement about the public record rather than a finding about the product. Josef Q does not generate citations to legal authority.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No engagement with professional responsibility or ethics guidance was located anywhere. Nothing references ABA Formal Opinion 512, any state bar opinion, guidance from the Law Council of Australia or a state law society, or any regulator statement on AI use in legal work, and no general acknowledgement appears that a lawyer's professional obligations survive use of the platform. The absence is more pointed than for a pure workflow tool because of how the product is positioned: the AI legal chatbot is sold as giving instant legal help to business users, and self-service tools are sold on resolving requests without a lawyer, so the platform is explicitly designed to put legal answers in front of people who are not lawyers. Searched the home page, the security and trust page, the privacy policy, the legal index, the data processing addendum and the recovered portions of the master services agreement on 1 September 2026.
No located public material engages with bar or ethics guidance. ABA Formal Opinion 512 is not mentioned, no state bar or law society opinion is named, and no ethics or professional responsibility page exists. Checked across the home page, the three product pages, the AI controls and audit trail pages, the FAQ, the security page, the website terms and the privacy policy on 1 September 2026. The vendor sells to law firms and to legal aid organisations delivering client-facing tools, which is where that guidance binds the buyer.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Efficiency claims are central and no billing or disclosure treatment exists. The marketing is built on demand and cycle-time reduction, with the headline customer figure a reduction in matter volume of up to 80 per cent at Woolworths Group, and a quoted chief legal officer arguing that expensive professionals should not be answering FAQs or negotiating low-value contracts. Dashboards report cycle times and workload distribution, which is the raw material a legal function would use to demonstrate its own cost of service. The buyer is an in-house team rather than a firm billing a client, so the fee-disclosure question lands obliquely and is not absent, since matter records showing which work was handled by automation rather than by a lawyer would be exactly what an internal chargeback or shared-service model needs. Nothing published addresses that, and no record framed for disclosure of AI-assisted work is described.
Time savings are published and the billing consequence is not addressed. The L’Oréal case study reports a 66% reduction in contract turnaround, a contract moving from over an hour to 20 minutes, and roughly two weeks of work saved a year. No public material addresses how AI-assisted work should be recorded or disclosed on a bill. The question is attenuated for the primary buyer, an in-house team that does not bill clients, but Josef also sells to law firms and NewLaw practices building client-facing tools, where it does arise. Checked 1 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
**The strongest instance of this signal in the pull, and the first where the model side is actually answered.** Annex III of the published data processing addendum names four subprocessors individually with address, contact details and a description of the processing each performs: Amazon Web Services for hosting and storage, Datadog for application and infrastructure logging, SendGrid for workflow email, and **OpenAI for generative artificial intelligence services where the customer enables the optional features**. Under the coverage test that satisfies both limbs, since infrastructure and model provider are separately identified and the AI surface is covered rather than partially disclosed. The forwardable material sits alongside it and is openly published: the DPA itself with the EU standard contractual clauses completed, the master services agreement, the service level agreement and the acceptable use policy, with fifteen days' advance notice of subprocessor changes and an objection right. What holds it below the top value is the absence of a client-facing disclosure pack assembled for the purpose, and that no model or version is named beneath the provider.
The material exists behind a request. The privacy policy states that a list of third-party subprocessors can be provided on request, and no published list was located on 1 September 2026. No model provider is named anywhere on the site, so a firm could not tell its client whose model sees the client’s content without first contacting Josef. No trust centre, disclosure pack or client-facing consent material was found. The request route is an email contact rather than a self-service portal, so it does not reach the middle tier.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
A detailed activity record exists and nothing identifies the machine's contribution to it. Matter management is marketed on giving a view across all matters with linked documents, emails, tasks, approvals and conversations, request tracking follows the status of work, and dashboards report demand, cycle time and workload distribution, so a legal function can reconstruct what happened to a request, who handled it and when. The data processing addendum adds contractual events logging as a technical measure. That is a real audit trail for an internal or regulatory account of the function's work. What it does not do is separate machine from human: nothing states that the record marks which matters were triaged or routed by AI rather than assigned by a person, which documents were generated by automation, or which answers came from the chatbot, so a user could not produce an AI-use disclosure from it without reconstructing that distinction themselves.
Some elements of a record exist without a document-level export. The audit trail page states that all user questions and generated answers are tracked and stored by Josef Q, and the AI controls page states the source list shows the exact page, paragraph and clause an answer drew on, so what was asked, what was answered and what it relied on are all captured. No model is identified, no human verification step is recorded against an individual answer, and no export of a per-document disclosure record is described. Checked 1 September 2026. The product produces internal guidance rather than court filings, so this is an operational audit trail rather than a filing-oriented one.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- AI Governance and Bias Disclosure
- Commercial Transparency
- Ethical Walls and Matter Segregation
- Primary Law Corpus Provenance
- Good Law Verification
- Bar Guidance Alignment
Which one fits
Choose Checkbox if
- You need to tell your privacy team exactly who touches the data. Checkbox's published data processing addendum names each subprocessor individually with its address and what it does, covering Amazon Web Services for hosting, Datadog for logs, SendGrid for workflow email deleted after delivery, and OpenAI for generative functionality where the customer switches the optional features on, with fifteen days notice and an objection right on any change.
- You want more than the fee cap behind a privacy failure. Checkbox's master agreement caps each party at the amount paid in the preceding twelve months and then lifts that cap for intellectual property, for data protection and privacy obligations and for the indemnities, and it bars the vendor from settling a claim on terms imposing a non monetary obligation or an admission of fault on the customer without written consent.
- Requests arrive wherever the business already works. Checkbox captures them from email, Slack, Microsoft Teams, Jira, Salesforce and web forms, triages and routes automatically on matter type, required expertise, team capacity and business unit, and syncs contract requests with Ironclad, with named legal operations leaders at SAP, Coca-Cola Europacific Partners and Hitachi Digital describing teams of 60 to 400 lawyers running on it.
Choose Josef if
- You want the tool to answer only from what you gave it. Josef Q is documented as a closed domain system answering solely from uploaded content, with a source list showing the exact page, paragraph and clause an answer drew on so a reader can open the support, and a published stop rule: where the answer is not in the corpus it says it does not know rather than filling the gap.
- The legal team should be able to correct what the tool tells people. Josef publishes a moderation layer covering every answer, source addition and removal, a Tuning Lab controlling tone, length and spelling convention, suggestion features shaping what end users ask, and an audit trail storing all questions and generated answers.
- Your tools have to reach the systems legal already runs. Josef names thirteen integrations grouped by direction, pulling policies from SharePoint and Confluence and data from Airtable and Google Sheets, pushing captured information to Slack, Teams, SharePoint and Salesforce, and connecting to HighQ, Xakia, Dazychain and Actionstep, with Xakia described as launching Josef bots from its own internal client portal so requests stay managed there.
In summary
Checkbox
Checkbox is a legal service hub for in house teams built around a single front door, capturing requests from email, Slack, Microsoft Teams, Jira, Salesforce and web forms, triaging and routing them on matter type, expertise, capacity and business unit, then managing matters with no code workflow automation and self service tools for routine work. The AI Legal Index grades it in the top two bands on eight of fifteen capability axes, with an A on AI safety and data stewardship: it publishes a subprocessor annex naming each provider individually including OpenAI for optional generative features, a retention period, deletion with certification and specified breach notification contents. As of 1 September 2026 the index located no accuracy measurement, no AI governance position and no published price.
Josef
Josef is a no code platform where in house legal and compliance teams build self service tools for the rest of the business, covering AI question and answer drawn from the team's own policies and playbooks, contract and document generation, and workflows for intake and approvals. The AI Legal Index grades it in the top two bands on eight of fifteen capability axes. Josef Q is documented as a closed domain system answering only from uploaded content, showing the page, paragraph and clause behind each answer, saying it does not know where the corpus does not support one, and giving the legal team a moderation layer over every answer and source. As of 1 September 2026 the index located no customer agreement, no liability position and no published price.
Questions buyers ask
Checkbox vs Josef: which is better for a legal service hub?
The AI Legal Index places both in the top two bands on eight of fifteen capability axes, so the grid does not separate them. What breaks the tie is which half of the product each has written down. Checkbox publishes the plumbing, with named subprocessors, a retention period, certified deletion and a liability cap that lifts for privacy claims. Josef publishes the behaviour, documenting what the AI answers from, what it shows as its source and what it does when it does not know.
Does either name the AI provider?
Checkbox does. Annex III of its published data processing addendum names OpenAI, with an address and privacy contact, and states that it supplies generative AI functionality where the customer enables the optional features, so a buyer learns whose model is involved and that the AI is opt in rather than always on. On Josef the chief executive writes publicly about the limits of a large language model without naming one, and no model, provider or inference location was located on any page. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What happens when the tool does not know?
Josef publishes the answer: Josef Q is closed domain, answers only from uploaded content, and where the content does not support an answer it says it does not know, with every answer and source reviewable and editable by the legal team through a moderation tab. On Checkbox nothing published describes what the AI chatbot answers from, whether responses are restricted to the customer's own policy content, or what happens to a question it cannot classify. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What can you read before signing?
On Checkbox, a master services agreement and a data processing addendum incorporating the EU standard contractual clauses, with the subprocessor annex, a stated retention period of the licence term plus thirty days, deletion with certification, and breach notification contents specified. On Josef, website terms and conditions and a privacy policy dated 15 February 2024, which the policy itself states applies to Josef as a controller rather than to customer content held as a processor. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What do Checkbox and Josef both leave unpublished?
Neither publishes a price, a tier structure or a unit of charge. Neither publishes an AI governance position: no accountable owner, no pre release testing regime and nothing on whether answer quality holds evenly across topics or business units. Neither publishes an accuracy measurement. And neither states that output is not legal advice, which matters because both are sold so that employees outside the legal team resolve legal questions without reaching a lawyer. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Each record leaves out what the other supplies. On Checkbox, no express statement was located that customer content is not used to train models: the standard contractual clauses constrain processing to documented instructions, which limits it without naming it, and nothing addresses privilege or work product. Its acceptable use policy and end user licence agreement were not opened, so a disclaimer may sit in one of them. On Josef, no customer agreement is published at all, so no liability position, warranty, indemnity or training commitment is readable before signing, and the only liability clause located is scoped to the Josef website rather than to product output. Its audit trail page also carries an unqualified claim of no hallucinations, which sits alongside a genuinely described architectural control rather than standing in place of one. Both records were verified on 1 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.