Clio vs MyCase: how they compare in 2026
Clio and MyCase are the two practice platforms a small or midsize firm shortlists, and they are the two strongest records in their category: Clio sits in the top two bands on fourteen of fifteen axes, MyCase on thirteen. Both take an A on professional responsibility posture, and both put that treatment in the agreement rather than in a footer. They separate on two things. Clio publishes the model layer, with a subprocessor list last modified 20 August 2026 naming AWS Bedrock, Anthropic, OpenAI, Google Vertex AI and Microsoft Azure Foundry against the products each serves and a data location for each, alongside a SOC 2 Type II report whose coverage period is stated. MyCase publishes the price and the training term: every tier carries a rate at both billing frequencies, and its agreement states that customer content is not used to train or fine tune any large language model, whether its own or a third party's. Clio's agreement permits de identified, aggregated content and output to be used to improve its AI services.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
An eighteen-year-old practice platform with an AI workspace built on top, and the vendor frames it that way itself: the marketing line is that the 18-year foundation now powers the legal AI. Clio Manage, Grow, Draft and Accounting are conventional software, and the entry tier is sold on practice management rather than models. Clio Work is genuinely AI-native and is sold as a separate product with its own trial, and Grow AI and Manage AI sit inside the older modules. Remove the models and the system 400,000 professionals run their firms on still works. B on the band. Pages read 1 September 2026.
MyCase is a fifteen-year-old practice management system with an AI layer bolted in, and the vendor is candid about which is which. Cases, contacts, calendars, documents, time entry, invoicing, trust accounting and the client portal are conventional software and make up the whole of the Basic tier, which includes no AI at all. 8am IQ appears at Pro (Writing and Document Assistants) and Advanced (adding Case and Discovery Assistants), priced into the tier rather than sold separately. Remove the models and the product a firm runs its practice on is untouched. B on the band: the models are the engine of a core capability layered on a product that would plainly still function without them. Pages read 1 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real and doubly sourced, and no accuracy figure was located. The pricing page states the AI is grounded in the firm's matters and cites its sources; the home page describes it working from matters, clients, filings, communications and financial data combined with over a billion legal documents across 100-plus countries, which is the vLex library Clio acquired in June 2025. That is a described retrieval method over identifiable corpora, and the subprocessor list corroborates the architecture by naming a vector database provider. What holds it at B is the absence of published measurement, and the Terms cut against any implied one: clause 14.2 states Themis does not review Output for accuracy or completeness and that Output may be incomplete or inaccurate, and clause 17.2 says the same of the legal Materials, disclaiming accuracy, completeness and currentness. Clio publishes an accuracy resource at /resources/ai-for-lawyers/ai-accuracy-legal/ which was not opened and is the rebuttal route toward A.
Grounding is real, documented and mechanically described. Case Assistant answers questions across a case's documents, notes, calendar events, invoices, transactions, tasks, case fields, portal messages, SMS and call logs, and the vendor states every answer includes a source you can trace back and verify before you act. The retrieval method is set out in the Terms: documents and data for a case are converted into a vector database format by an embedding process performed case by case, then retrieved by the LLM. The vendor also states it runs proprietary evaluation metrics to measure and monitor accuracy and hallucination detection, and constrains the surface by supporting only pre-configured prompts customised per task. What holds this at B is that none of that measurement is published: the metrics are proprietary, no figure, test set or error rate appears anywhere, and the Terms acknowledge output may contain errors, omissions or inaccuracies with no warranty of accuracy. The evaluation regime itself is graded on AI Governance rather than spent twice.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A blanket review commitment stated in marketing and made binding in the contract, without the finer structure the top band asks for. The pricing page says the firm reviews and approves everything before it reaches a client or the court, which is the right commitment for the highest-stakes outputs. Terms clause 14.2 converts that into an obligation running the other way: the subscriber agrees to use AI Services and Output only with human oversight, and is responsible for reviewing Output for accuracy, completeness, appropriateness and compliance with legal, regulatory and professional requirements before disclosing or using it. Clause 14.4 leaves the subscriber in full control of how AI Services are implemented, configured and presented. B rather than A because no modes are described, no thresholds are published, and nothing sets out what the product does on its own versus what it waits to be asked.
Nothing runs unattended, and the vendor says so directly: data is never stored or analysed passively and is only processed when a user asks a question. Control sits at two levels. Firm level, availability of 8am IQ is governed by a firm-wide AI setting managed by the account owner, and disabling it removes access for every authorised user; the Terms make the firm responsible for configuring that setting in line with its own policies and professional obligations. User level, 8am IQ honours existing permissions so a user cannot reach through it anything they could not already open. Review is built into the output through source citations, and the Terms require human review, stating output may not be relied on as a substitute for professional judgment. B rather than A because no thresholds are published and there is no described escalation path; the product is a user-invoked query tool rather than an agent, so the route-back-to-human limb of the band does not really engage.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
One named firm with a figure and a period, against portfolio numbers with no method. King Law is named on the home page with a 275% increase in revenue over four years, attributed to visibility and tooling across the firm. Named individuals appear with their firms: Angela Lennon at Koenig | Dunne, Danielle Harvey-Jacob at Harvey-Jacob Law. Platform figures are 400,000-plus legal professionals, 130-plus countries and 300-plus integrations. Nothing is dated, no method is described for the King Law figure, and the 4.7 from 12,000-plus reviews is directory material excluded under the ground rules along with the vendor's own comparison page. B: real deployment evidence with substance, short of the dating and method the top band requires.
A named firm with a figure, and portfolio metrics with an unusually candid method. Vi Nanthaveth of Nanthaveth & Associates, PLLC is on record describing a move from meeting three or four people a day to fifteen. The headline metrics carry a real methodology footnote rather than a bare number: the 64 hours of billable time recovered per year is attributed to an analysis of anonymised MyCase customer data covering firms using the Smart Time Finder feature, averaging 5.3 hours a month, and the ROI calculator's revenue figure is stated to be built from that same figure plus the user's own inputs, with the whole thing labelled an estimate and not a guarantee. Publishing the derivation of a marketing number is rare. B rather than A because nothing is dated, the remaining testimonials are first-name-only and read as review-site extracts, and the 37% caseload figure carries no stated basis.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive on every limb but the one the band names last. Terms clause 4.2 binds Themis and its third-party vendors and hosting partners to hold Content in strict confidence and not use or disclose it outside the agreement. Clause 21.3 goes further than most: only Themis, with strict business reasons, may access and transfer Content, and only to provide the Service, with reasonable efforts to notify the subscriber before doing so. Clause 14.6 states use of AI Services grants no right to use confidential information to train generalised LLMs. The security page states AI data is encrypted and processed in the customer's region, that AI tools process in real time without storing or reusing, and that outputs are generated only for the authorised user requesting them. What is missing for A is express treatment of privilege and work product, absent for a platform holding the entire matter file, and any documented segregation between matters within a firm.
One limb short of the top band, and the limb it clears best is the one most vendors miss. Training is answered in the agreement, not on a marketing page: Part III states 8am does not use Customer Content or IQ Content to train or fine-tune any large language model or other generative AI model, whether its own or a third party's, and that the substantive content of inputs and outputs is never used to update model weights. Retention is specific: the LLMs used to provide 8am IQ may retain IQ Content for up to thirty days, and case data in the vector database is deleted automatically after thirty days of inactivity. Segregation is documented and inherited rather than reinvented, with 8am IQ unable to reach any record the user cannot already access, and the vendor states safeguards prevent exposure between customers. What is missing for A is express treatment of privilege and work product, which is nowhere addressed for a system indexing a firm's whole case file. Also worth a buyer's eye: Part III states an authorised user's Case Assistant chat history cannot be deleted.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Every limb is covered and all of it is contractual. What it is not is stated at the top of the Terms in bold: Themis is not a law firm and does not provide legal advice, through the Service or otherwise, with clause 12.1 adding that provision of the Services, Output or Materials creates no attorney-client relationship. Who may use it is scoped: the Service is intended only for use by legal professionals and those working under their supervision, with a named exception for academic access participants. Competence and supervision are addressed directly in clause 14.2, which requires human oversight and makes the subscriber responsible for reviewing Output against professional organisation requirements and applicable fiduciary rules. Jurisdiction limits are named three ways: the Service is intended for North America with separate EMEA terms, Materials are limited to the country associated with the account, and clause 2.16 warns that Themis runs one code-base for all jurisdictions and the subscriber must configure and verify settings for its own. The client-facing limb is met by clause 14.4, which requires the firm to give its end-users disclosures covering the use of AI, the nature and limitations of AI-generated responses, and any human oversight processes.
The most complete treatment of this axis located in the pull, and all of it sits in the agreement rather than a footer. The vendor states plainly what it is not: Part I says 8am does not provide legal or accounting advice and is not engaged in the practice of law, and Part III says 8am IQ does not provide legal, accounting or other professional advice and that output may not be relied on as a substitute for professional judgment or human review. Who may use it is scoped and that scope is jurisdictional: the Platform is stated to be intended for legal, accounting and other client-based professionals located in the United States and Canada. The competence and supervision dimension is addressed rather than assumed — using 8am IQ to engage in the unauthorized practice of law, or to offer legal advice without a qualified person reviewing the information, is an express prohibited activity; the customer is made responsible for using the Platform in compliance with the rules of professional conduct applicable to its profession; and the firm-wide AI setting gives an account owner the switch to enforce that. The disclaimer also recommends consulting qualified counsel on compliance obligations. The consumer-facing-disclosure limb does not engage, since 8am IQ is an internal tool for firm staff rather than a client-facing agent.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Principles are published, the mechanism behind them is not. A dedicated AI Principles page sets out five commitments, attributed to Chief Technology Officer Jonathan Watson, covering AI as collaborator, transparency of AI actions, high-quality data, relentless refinement and uncompromising security. Bias appears once, as a claim that diverse top-tier data minimises it, rather than as anything measured or found. Nothing names an individual or committee accountable for the AI, describes what is tested before a feature ships, or discloses a single evaluation result. The one auditable trace of a testing function is indirect and sits elsewhere: the subprocessor list names Braintrust Data as an AI analytics, evaluation and testing provider across five products. That is evidence a pipeline exists, not a published regime a buyer could examine. C on the band's own words.
A published framework with real substance and no results behind it. There is a dedicated 8am IQ Usage Policy incorporated by reference into the Agreement, which is a governance artifact rather than a marketing page, alongside a published statement of principles for building AI in legal technology. The mechanism is described: proprietary evaluation metrics to measure and monitor accuracy and hallucination detection, task-specific pre-configured prompts to raise the likelihood of accurate responses, and a stated commitment to continued testing. Governance also has a control surface in the firm-wide AI setting. What is absent is everything the A band adds: no individual or committee is named as accountable for the AI, no pre-release testing regime is described in terms a buyer could audit, no evaluation result is disclosed, and nothing addresses uneven output across matter types, practice areas or populations. B.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
One limb short of a full set, and the limbs it clears are clearer than anything else in this pull. Incident practice is contractual and specific: clause 5.5 requires Themis to report any event it reasonably believes represents unauthorised access to, disclosure of, use of or damage to Content within 72 hours, with clause 5.6 setting out cooperation, investigation and mitigation duties. Deletion is stated with a period: 90 days to retrieve Content after termination, after which all Content is irrevocably deleted, with escrowed data held six months under a separate escrow agreement the customer controls. Subprocessors are published in full and dated. Access control is covered by clause 21.3, limiting Themis access to strict business reasons with advance notice. Encryption, geo-redundancy and at least annual third-party penetration testing are stated. The gap is retention during the term: no period is published for AI inputs and outputs, and clause 14.6 permits de-identified aggregated Content and Output to be kept for quality improvement without limit.
Substantive across most of the ground, with the subprocessor list the notable hole. Retention is stated with a number rather than a gesture — thirty days at the LLM layer, thirty days of inactivity before embedded case data is automatically deleted and the embedding re-run on next use. Encryption is specified as 128-bit SSL in transit and 256-bit AES at rest. Access control is documented through per-user permission inheritance. A security and privacy whitepaper is published at an ungated link, and a trust centre exists at trust.8am.com. Incident practice is addressed in the Terms, though asymmetrically: the customer must report a data incident within twenty-four hours to a named security address, and 8am reserves the sole right to determine whether and how notice is given to individuals or regulators. Not located: any subprocessor list, and any statement of where data is hosted. B on the band's own named exception.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A real and unusually two-sided position that stops short of the output itself. Clause 11.1 excludes liability generally but carves out breaches of confidentiality, security and managed backup, so those obligations remain live. Clause 11.2 caps liability at the total paid in the six months before the claim arose, and expressly disapplies that cap to the indemnity. Clause 13.2 gives the subscriber a genuine indemnity on two grounds: third-party intellectual property claims against the Service, and, more unusually, claims arising from a violation by Themis of its own confidentiality or security obligations. Carve-outs are itemised in 13.3. What keeps this at B is that none of it reaches AI output. Clause 13.2(a) expressly excludes Output from the IP indemnity, clause 14.2 provides Output as is with no representations, and clause 12.2 disclaims any warranty as to results. No insurance position is published.
Specific, readable and pointed entirely one way. The Terms cap total cumulative liability at the net fees earned by 8am during the three months immediately preceding the event giving rise to the claim, which is the shortest cap located in this pull, and exclude all indirect, incidental, special, consequential and punitive damages. The Platform is provided as is and with all faults, with an express refusal to warrant that information, data or AI output will be accurate, complete, reliable or compliant with applicable law. Part III adds a dedicated AI carve-out: 8am will not be liable for any damages arising out of errors or inaccuracies in output or reliance on it. The only indemnity runs from the customer to 8am, and claims must be brought within one year. There is no indemnity to the customer, no warranty on output and no insurance position. C: liability addressed only through a limitation clause that disclaims the exposure the product creates.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Breadth is stated and documented, depth is not. Clio publishes 300-plus integrations through an app directory, runs a developer hub and partner programme, and the Terms treat API access as a governed feature in clause 3.9, setting out that API use is bound by the agreement, that excessive use may lead to suspension with a reasonable attempt to warn first, and that access may be modified or discontinued. Third-party services are addressed squarely in clause 18, which states they are not Services under the agreement, carry no warranties, indemnities or service commitments from Themis, and may be replaced, disabled or restricted at any time without notice. That is honest about where the boundary sits. B rather than A because no page read on 1 September 2026 describes what any specific integration moves, in which direction, or what a firm must configure; the app directory was not opened and is the rebuttal route.
Real integrations, named partners and public developer documentation, short of described depth. The pricing matrix states 70-plus integrations at the Pro tier and an Open API at Advanced, and names the connected tools in the feature comparison: Google, Outlook, Microsoft Office, QuickBooks, Zapier, LawToolBox for court rules calendaring and Smith.ai. Payments run through LawPay within the same platform, and Desktop Drive provides two-way file sync between a user's desktop and MyCase. A public developer site at developers.8am.com carries a quickstart guide and API reference, which is documentation an implementer can actually use. B rather than A because what each integration moves, in which direction, and what a firm must configure is not described on any page read on 1 September 2026; the dedicated integrations page was not opened and is the rebuttal route.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The most detailed residency disclosure located in this pull, held off the top band by one absence. Regions are published and real: hosting options in the European Union, Australia, the United States and Canada, five regional site variants, a separate EMEA instance at eu.app.clio.com with its own terms, and separate North American and EMEA agreements. Processing is distinguished from storage rather than conflated: the security page states all data used by the AI is encrypted and processed in the customer's own region, naming US, Canada, EMEA and APAC, and the subprocessor list gives a data location for every provider individually, including each AI processor. Infrastructure is named by provider and product. What is absent is the tenancy model, which is stated nowhere, and any statement of whether residency options vary by plan, which is what the top band asks for alongside the regions.
Cloud delivery is evident and neither dimension is published. No tenancy model is stated anywhere, and no data residency region is offered or named. The closest thing to a location statement is a market scope rather than a hosting one: the Terms say the Platform is intended for professionals located in the United States and Canada. Nothing distinguishes where data is processed from where it is stored, and no hosting provider is identified on any surface read on 1 September 2026, though the Terms do refer generically to failures of cloud hosting providers in the force majeure clause. The trust centre at trust.8am.com was not opened and is the rebuttal route. C on the band's words.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The only attestation in this pull that states its coverage period. The trust centre at trust.clio.com announces that the 2025 SOC 2 Type II report has been issued for the period 1 June 2024 to 31 May 2025, and the security page states Clio completes annual SOC 2 Type II and SOC 1 Type II examinations with both reports available through that trust centre. The route to the report is not only a portal but a contractual right: clause 5.4(d) obliges Themis to provide a SOC 2 or SOC 3 report, or a comparable description of security measures, within thirty days of a subscriber request. At least annual third-party penetration testing is stated, and Clio's own help centre names Deloitte as the independent auditor, albeit for the earlier Type I engagement. Weaknesses a buyer should still note: the trust services criteria are not enumerated, the auditor for the current Type II is not named, the penetration testing firm is described only as a leading cybersecurity firm, and clause 5.4(d) requires entering an agreement with the report's third-party provider.
Certification is stated and a trust centre exists, without the particulars that would let a buyer test it. 8am states it is SOC 2 Type II certified on the 8am IQ page, links that claim to the AICPA, operates a trust centre at trust.8am.com linked from the footer of both mycase.com and 8am.com, and publishes a security and privacy whitepaper at an open Google Drive link with no form, NDA or sales conversation in the way — an ungated artifact, which is more than most of this pull offers. The Terms also commit to complying with PCI-DSS for payment processing. What is missing is the attestation detail: no auditor is named, no trust services criteria or scope are given, and no coverage period or report date appears on any readable surface. The trust centre itself was not opened on 1 September 2026, so whether reports are downloadable there was not established and nothing is graded against the vendor for it.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
By a distance the best evidence on this axis in the pull, and still short of the top band on two limbs. The subprocessor list, last modified 20 August 2026, carries a dedicated AI Service Providers table naming five AI processors with the products each serves and the data location for each: AWS Bedrock, Anthropic, OpenAI, Google Vertex AI and Microsoft Azure Foundry, spanning Clio Manage, Grow, Draft, Work, Vincent AI and Clio Operate. It also names Turbopuffer as the vector database and Braintrust Data for AI analytics, evaluation and testing, and Vapi for the Grow voice agent. A buyer can therefore answer whose model sees their content, per product, and where it runs. Two things keep it at B. The specific models are never named, only the providers. And no change-notification commitment was located on the page; the Themis Data Protection Addendum, cited as the clause under which the list is published, was not opened and is the rebuttal route toward A.
The architecture is described in real detail and the providers are never named. The Terms state 8am IQ is enabled via large language models, describe the pipeline — case documents and data converted by an embedding process into a vector database format for retrieval by the LLM, performed case by case — and go further than most by stating what the model layer does with the data: the LLMs used to provide 8am IQ may retain IQ Content for up to thirty days, and that data will not be used to train any LLM. That is a genuine statement about what the underlying provider may retain. But no model and no provider is identified anywhere. Claude appears in the Terms only to be excluded, in a clause stating that third-party services including Claude are not 8am AI-powered features and are governed by the customer's own agreement with them. No subprocessor list and no change-notification commitment was located. B on the band's second limb, architecture described without the providers.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Part of the range is priced and the rest is a conversation. The pricing page publishes a starting figure of $49 USD per user per month and names four tiers, Starter, Core, Signature and Elite, with the feature split described tier by tier and a bundle saving of over 15% advertised. Above the entry tier a buyer is routed to a custom quote, and large firms to a bespoke process. The Terms make clear that the published number is not the whole cost: clause 9.5 refers to setup fees, implementation charges and Metered Features fees as separate non-refundable items, and clause 9.6 gives purchasers of setup or professional services a sixty-day window to start them or lose them. None of those amounts is published. B on the band's first limb, real pricing published for part of the range with the upper tiers withheld. Note the tier names have changed generation again and third-party trackers still report the previous set.
A buyer can price this firm-wide without speaking to anyone, which is what the band asks and what almost nothing else in this pull delivers. All three tiers carry published rates at both billing frequencies: Basic $50 annual or $60 monthly, Pro $100 or $120, Advanced $130 or $150, all USD per user per month, with the annual saving stated per plan. The unit is explicit and the FAQ repeats that the rate depends on the number of active firm users. A full feature comparison shows exactly what each tier buys, including which AI assistants sit at which level. Implementation is addressed head-on rather than left as an unknown: guided implementation, training sessions and support are stated to carry no additional cost, and the FAQ confirms no long-term contract and no setup fee. Add-ons are priced too — MyCase Accounting at $39 per user per month, LawPay at no monthly fee — and even the AI overage carries a rate, at $30 for an additional 5,000 Discovery Assistant pages against an allowance of 5,000 pages per user per month pooled across the firm. A ten-day trial runs without a card.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
The widest published coverage in the pull, with the limits drawn jurisdictionally rather than functionally. Sixteen practice areas carry their own pages, from bankruptcy and criminal to intellectual property and real estate, and the segmentation runs across four firm sizes from solo to enterprise and Big Law, plus seven role-specific pages. Both buyer types the band asks about are addressed by name: in-house counsel and government law each have a page. Real limits are stated, though they concern where rather than what: the Terms scope the Service to North America with separate EMEA terms, restrict Materials to the country associated with the account, and warn in clause 2.16 that a single code-base serves all jurisdictions so the subscriber must configure and verify settings itself. B rather than A because the in-house, government and firm-size pages were not opened on 1 September 2026, and nothing states which practice types the product handles poorly.
Segment and practice coverage are described with substance and the boundaries are only half drawn. Six practice areas carry their own pages — criminal defence, family, immigration, bankruptcy, personal injury, and trust and estate — with a further index behind them, and the product is positioned throughout at small and mid-sized firms. One real limit is stated and it is jurisdictional: the Terms scope the Platform to legal, accounting and other client-based professionals located in the United States and Canada, and a separate clause addresses use by the US Government. Practice-specific depth is evidenced in the feature set, with conflict check tracking, statute-of-limitations deadlines, trust-by-case balances and court rules calendaring. B rather than A because no firm-size segmentation is published in the way the band contemplates, in-house and government legal departments are not addressed as buyers, and nothing states which practice types the product handles poorly.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The agreement permits a qualified form of training and the marketing says the opposite. Terms clause 14.6 lets Themis de-identify and aggregate the Content submitted to, and Output received from, AI Services and use it to improve and ensure the quality of those services, and clause 2.15 adds perpetual aggregate anonymised reporting on usage and content trends. The same clause withholds any right to use confidential information to train generalised LLMs, so the permission is bounded rather than open. The qualifier that matters to a buyer is that it runs on de-identified and aggregated material, not identifiable client content. Against that, the pricing FAQ states a firm's data is never used for AI training or any other external purpose. Where marketing and the agreement disagree the agreement governs, and it is recorded here.
The commitment sits in the published agreement rather than on a marketing page, and it covers both directions. Part III of the Terms states 8am does not use Customer Content or IQ Content to train or fine-tune any large language model or other generative AI model, whether developed by 8am or a third party, and that the substantive content of inputs and outputs is never used to update model weights or incorporated into training data. It expressly carves the improvement activity out of training: inputs, outputs and usage data may be used to monitor and improve accuracy, safety and performance, including aggregated human and automated review, and the Terms state those activities do not involve training or fine-tuning. Part I separately retains a perpetual licence over aggregated and anonymised Customer Content excluding personal information for internal product development. Notably the agreement is more protective than the marketing FAQ, which describes the commitment only as covering third-party models.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
End-of-life is specific, the live term is not. Clause 10.7 gives the subscriber no less than ninety days after cancellation or termination to retrieve Content, after which all Content is irrevocably deleted from the Service, with escrowed data held a further six months under a separate escrow agreement the customer arranges directly. What is not published is any period for AI inputs and outputs while the subscription is running, and clause 14.6 permits de-identified aggregated Content and Output to be retained for quality improvement with no stated limit. The security page states AI tools process data in real time and do not store or reuse it, which points toward minimal model-layer retention but is a marketing statement rather than a term.
A specific period is published at two layers and the customer cannot change either. The Terms state the LLMs used to provide 8am IQ may retain IQ Content for up to thirty days, and that case data held in the vector database is retained for up to thirty days following the last activity on a case, after which the embedded data is automatically deleted and the embedding re-run on next use. Against that, the Terms also state each authorised user has an individual Case Assistant chat history which cannot be deleted and is retained under the Privacy Policy, so the prompt record itself persists on terms the firm does not control. Recorded as a disclosed fixed window on that basis.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Per-user scoping is asserted without published enforcement detail. The security page states sensitive client information never leaves Clio's secure environment and that outputs are generated only for the authorised user requesting them. The Terms establish an administrator role able to designate users and deactivate access, but describe no matter-level partitioning, no conflict wall mechanism, and nothing about how retrieval is bounded when the AI reaches across a firm's matters, clients, filings and communications. Worth noting for comparison that the separately indexed Vincent AI record describes inheriting a firm's existing permissions and ethical walls when run inside Clio Operate; nothing equivalent was located for Clio's own products on any page read on 1 September 2026.
Retrieval enforces the platform's own access model at query time, per user, and the vendor documents it in two places. The 8am IQ page states that 8am enforces user permissions so 8am IQ can only access data a user already has rights to view, and that 8am IQ honours existing permissions such that a user cannot use it for any item within MyCase they cannot already access, linking to the user-permissions help article. MyCase is itself the system of record, so the source system whose access model is inherited is the practice management platform rather than a separate document store. The same page states safeguards prevent a customer's confidential data being exposed to another 8am customer. Nothing separately addresses conflict walls erected for a specific matter.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Notice is committed in the agreement and the process is published separately. Clause 7.2 provides that where Themis is legally required to disclose confidential information in a way the agreement otherwise prohibits, it will give the subscriber prompt written notice, to the extent permitted by law, before disclosing, so the subscriber may seek a protective order or other relief, and will then furnish only the portion legally compelled. Clause 7.1 states the primary duty is to protect Content to the extent the law allows. Clause 7.3 adds something few vendors publish: Themis will only accept legal requests for production of Content through the procedures set out at clio.com/legal-service, a dedicated public page for service of legal process. No transparency report was located on 1 September 2026, which is what keeps this below the top tier.
Part I of the Terms provides that where a party is required by law or by order of a court, regulatory authority or other governmental body to disclose the other's Confidential Information, the receiving party will give prompt notice to the disclosing party, to the extent permitted by applicable law, to allow it to seek a protective order or other appropriate remedy. The obligation is mutual and appears in the published customer agreement. A related clause runs the other way and is worth a buyer noting: where 8am must respond to a subpoena or other compulsory process relating to the customer's account, the customer agrees on request to compensate 8am for staff time at a rate 8am sets and to reimburse related costs. Recorded at the committed tier because no transparency report was located on 1 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The corpus is identifiable and the rights basis is described only in the abstract. Clause 17.2 states Themis may make available primary and secondary legal materials such as case law, legislation and articles, described as licensed or publicly available legal content, with additional third-party terms possibly applying. The source behind it is traceable through Clio's own disclosures rather than a provenance statement: the subprocessor list names Vlex Library and Clio Library as products and lists vLex entities and Fastcase, Inc. among Clio affiliates, and the home page puts the corpus at over a billion legal documents across 100-plus countries. What is absent is which licence covers which jurisdiction, any named publisher, and any update cadence. Clause 17.2 runs the other way on currency, expressly disclaiming that Materials are reviewed for accuracy, completeness or currentness, and clause 17.5 reserves the right to add, modify or remove Materials at any time without notice.
The product does not retrieve primary law, so there is no legal corpus to source. 8am IQ operates only on the firm's own case record: documents, notes, calendar events, invoices, transactions, tasks, case fields, portal messages, SMS and call logs, converted into a per-case vector database. No public material identifies any statutory or case law source, licence basis or update cadence, checked across the MyCase home and pricing pages, the 8am IQ page and the full Terms of Service on 1 September 2026. Recorded as not addressed because the question does not arise for this product class.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material describes a citator or subsequent-history check in Clio's own products. The Terms cut the other way: clause 17.2 states Themis does not review the Materials for accuracy, completeness or currentness and provides them as is, which is the opposite of a good-law guarantee, and clause 17.5 permits Materials to be added, modified or removed without notice. Checked across the home page, pricing page, AI Principles page, security page, subprocessor list and the full North American Terms of Service on 1 September 2026. Note for the reader that the separately indexed Vincent AI record does describe a Cert citator; that capability is graded on that record and is not credited here.
No citator, and none would apply. 8am IQ answers questions about a firm's own matters and extracts details from the firm's own documents; it does not retrieve or cite legal authority whose subsequent history could be checked. The citations it produces point back to the customer's own case records. Nothing on any surface read on 1 September 2026 addresses primary legal authority.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material describes what the product does when it cannot ground an answer. The published position places the burden entirely on the reader instead: clause 14.2 states Themis does not review Output for accuracy or completeness, that Output may be incomplete or inaccurate, and that the subscriber must review it before disclosing or using it. No confidence signal, no abstention path and no described no-answer behaviour was found across the home page, pricing page, AI Principles page, security page or the Terms on 1 September 2026. The Clio Work product page and the published accuracy resource were not opened and are the rebuttal route.
No located public material addresses what the product does when it cannot ground an answer. The vendor describes mitigation rather than abstention: proprietary evaluation metrics to measure and monitor accuracy and hallucination detection, and task-specific pre-configured prompts to increase the likelihood of an accurate response. It also states plainly that output may still be misleading or inaccurate and recommends the user review everything before relying on it, which places the check on the reader rather than describing a no-answer path in the product. No confidence signal and no documented abstention behaviour was found across the 8am IQ page, the MyCase pages and the Terms on 1 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming any Clio product has been located. The AI Hallucination Cases database maintained by Damien Charlotin was searched on 1 September 2026 across Clio, Clio Work and Clio Duo alongside general sanctions coverage, and nothing naming a Clio product as the tool involved was found. Clio itself publishes extensive material on the sanctions record, including analysis of the Morgan and Morgan matter, where the tool involved was that firm's own in-house platform rather than a Clio product. This is a statement about the public record rather than a finding about the product.
No court order, opinion or disciplinary record naming this product has been located. The AI Hallucination Cases database maintained by Damien Charlotin was searched on 1 September 2026 on both the product name and the AI brand 8am IQ, alongside general sanctions coverage, and nothing naming the product was found. This is a statement about the public record rather than a finding about the product. 8am IQ cites the firm's own case records rather than legal authority, so the failure mode this signal tracks is not one the product exhibits.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Professional responsibility is engaged repeatedly and no specific guidance is named. Clause 14.2 makes the subscriber responsible for reviewing Output to ensure compliance with legal, regulatory and professional organization requirements and applicable fiduciary rules, and clause 14.4 enumerates the disclosures a firm must give its own end-users about AI use, limitations and human oversight, which is closer to operationalising a professional obligation than most vendors get. Clio also publishes a substantial body of writing on sanctions, the duty of competence and verification practice. But ABA Formal Opinion 512 is not named on any surface read on 1 September 2026, and no state bar opinion is cited; the 100-plus bar association partnerships are commercial relationships rather than engagement with guidance.
Professional responsibility is referenced in general terms without any named guidance. The Terms require the customer to use the Platform in compliance with the rules of professional conduct applicable to its profession, make configuration of the firm-wide AI setting the firm's responsibility in line with applicable professional or ethical obligations, and prohibit using 8am IQ to engage in the unauthorized practice of law. The vendor publishes a blog piece framed around bar associations weighing in on AI compliance, and states partnership with more than 130 bar associations including the American Bar Association and several state bars, but those are commercial relationships rather than engagement with guidance. ABA Formal Opinion 512 is not named and no state bar opinion is cited on any surface read on 1 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Efficiency and revenue claims are published and the treatment of AI-assisted work on a bill is not. King Law's 275% revenue growth is the headline, and the platform is itself a billing and time-capture system. One clause does address passing a technology cost to a client, and it is worth noting for precision rather than credit: clause 17.3 states the cost of Purchased Materials may be recovered from a client as a disbursement or similar. That is research cost recovery, not a position on how time compressed by AI should be recorded or disclosed, which is the question this signal asks. No audit record identifying which work product was AI-assisted is described. Checked 1 September 2026.
Time and revenue savings are published prominently and the billing consequence of AI-assisted work is not addressed. The vendor claims 64 hours of billable time recovered per year, 37% more cases with the same team, and runs an ROI calculator projecting annual revenue increase from a firm's own inputs. The product captures billable time in detail through Smart Time Finder and produces invoices, but nothing identifies which work was AI-assisted or offers guidance on how that should be recorded or disclosed on a client bill. Notable because this is a billing product whose AI explicitly compresses document review and drafting. Checked 1 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A firm could answer a client's AI questionnaire from published material alone. The subprocessor list, last modified 20 August 2026 and reachable without a form or agreement, names every infrastructure, AI, feature and payment provider, maps each to the products it serves, and gives a data location for each, including a dedicated AI Service Providers table naming five model processors. Alongside it Clio publishes the Data Protection Addendum, the service level commitments exhibit, the AI Principles page, a public trust centre and a dedicated legal process page at clio.com/legal-service. Together that is a forwardable pack covering who processes client content, where, and on what contractual basis. The specific models are not named, which is the one thing a demanding client questionnaire might still ask for.
Some client-facing material is published and the artifact that matters most is not. A security and privacy whitepaper is available at an ungated link with no form or NDA, a trust centre operates at trust.8am.com, and the Terms and the 8am IQ Usage Policy are both public and contain the no-training commitment a firm would need to forward. But no subprocessor list was located anywhere, and no model provider is named, so a firm could not tell a client whose model processes its content without asking. The trust centre was not opened on 1 September 2026 and may hold a subprocessor list; nothing is graded against the vendor for that.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
The pieces of a record exist and none is assembled for disclosure. Output is stated to carry citations traceable to source, the subprocessor list would let a firm identify which providers could have processed a given product's content, and the review-and-approve commitment describes a human step. But nothing identifies which model produced a specific output, no verification event is recorded against a document, and no export is offered or described for the purpose of answering a court. Clause 14.4 pushes the disclosure obligation onto the firm, requiring it to tell its end-users about AI use and human oversight, without giving it an artifact to do so from. Checked 1 September 2026.
Some elements of a record exist without a disclosure-oriented export. Case Assistant answers carry citations traced back to the underlying case records, each authorised user has an individual chat history that is retained and cannot be deleted, and the Terms state responses may be copied, saved or exported. Together that means what was asked, what was answered and what it drew on is recoverable per user. What is missing is the rest: no model is identified against any output, no human verification step is recorded, and nothing frames any of it as a disclosure record for a court. Checked 1 September 2026.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- Good Law Verification
- Refusal and Uncertainty Behaviour
Which one fits
Choose Clio if
- A client asks whose AI sees its matter. Clio's subprocessor list, last modified 20 August 2026 and reachable without a form, names AWS Bedrock, Anthropic, OpenAI, Google Vertex AI and Microsoft Azure Foundry as AI processors, maps each to the products it serves and gives a data location for each, alongside a published data protection addendum and a dedicated legal process page.
- Your security review wants a report with a period on it. Clio's trust centre states that the SOC 2 Type II report covers 1 June 2024 to 31 May 2025, annual SOC 2 Type II and SOC 1 Type II examinations are stated, and clause 5.4(d) of the terms obliges Clio to provide a SOC 2 or SOC 3 report within thirty days of a request.
- Your data has to stay in your region. Clio publishes hosting in the European Union, Australia, the United States and Canada, states that data used by the AI is encrypted and processed in the customer's own region, commits in clause 5.5 to report unauthorised access within 72 hours, and gives ninety days after termination to retrieve content before deletion.
Choose MyCase if
- You want to price the firm without a sales call. MyCase publishes every tier at both billing frequencies, Basic at $50 annual or $60 monthly, Pro at $100 or $120 and Advanced at $130 or $150 per user per month, states that guided implementation, training and support carry no extra cost and that there is no setup fee, and prices the AI overage at $30 for an additional 5,000 Discovery Assistant pages.
- You want the training question closed in the contract. Part III of the MyCase terms states that 8am does not use customer content or IQ content to train or fine tune any large language model, whether its own or a third party's, and that inputs and outputs are never used to update model weights, with model layer retention stated at up to thirty days.
- Your permission model has to hold when the AI reads. MyCase states that 8am IQ can only reach data a user already has rights to view, so retrieval enforces the firm's existing permissions at query time, and a firm wide AI setting held by the account owner switches the assistants off for every user at once.
In summary
Clio
Clio is a legal practice platform for firms of every size, built around Clio Manage for matters, billing and trust accounting, Clio Grow for intake, Clio Draft for document automation and Clio Work as its AI workspace, with the vLex library of more than a billion legal documents behind the research side. The AI Legal Index grades it in the top two bands on fourteen of fifteen capability axes, with A grades on professional responsibility posture and on security certifications, the latter resting on a SOC 2 Type II report whose coverage period of 1 June 2024 to 31 May 2025 is stated on its trust centre. Its subprocessor list names five AI providers against the products each serves with a data location for each. As of 1 September 2026 the index located no named models and no published accuracy measurement.
MyCase
MyCase is legal practice management software for small and mid sized firms, holding cases, contacts, documents, calendars, time entry, billing and trust accounting in one place, with 8am IQ as an embedded AI layer covering case questions, OCR of scanned discovery, document extraction and client writing. The AI Legal Index grades it in the top two bands on thirteen of fifteen capability axes, with A grades on professional responsibility posture and on commercial transparency: all three tiers carry published rates at both billing frequencies, implementation and support are stated to cost nothing extra, and the AI page overage is priced. Its agreement states that customer content is not used to train or fine tune any large language model. As of 1 September 2026 the index located no named model provider and no published hosting region.
Questions buyers ask
Clio vs MyCase: which is better for a small law firm?
The AI Legal Index places Clio in the top two bands on fourteen of fifteen capability axes and MyCase on thirteen, the two strongest records in their category, so this is close. Clio publishes more about the model layer, data residency and its attestations. MyCase publishes every rate and a contractual term stating that customer content is not used to train or fine tune any model. Both take an A on professional responsibility, and both put that treatment in the agreement rather than in a footer.
Does Clio train its AI on client data?
Two documents speak to this and the AI Legal Index records the agreement. Clio's pricing FAQ states that a firm's data is never used for AI training or any other external purpose. Clause 14.6 of the terms permits Themis to de identify and aggregate the content submitted to, and output received from, its AI services and use it to improve and ensure the quality of those services, while withholding any right to use confidential information to train generalised models. The agreement is the document that governs the relationship, so the index records the value from it.
How much does MyCase cost?
MyCase publishes every rate. Basic is $50 per user per month billed annually or $60 monthly, Pro is $100 or $120, and Advanced is $130 or $150, with a full feature comparison showing which AI assistants sit at which tier. Guided implementation, training sessions and support are stated to carry no additional cost, there is no setup fee or long term contract, and a ten day trial runs without a card. MyCase Accounting is $39 per user per month. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
Which one tells you whose AI models see your client data?
Clio. Its subprocessor list names AWS Bedrock, Anthropic, OpenAI, Google Vertex AI and Microsoft Azure Foundry as the AI processors behind named products, with a data location for each, and separately names its vector database and evaluation providers. MyCase's terms describe the architecture, including a per case vector database and a stated thirty day retention limit at the model layer, and name no provider at all. Neither names the specific models underneath the providers. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
What do Clio and MyCase both leave unpublished?
Neither publishes an accuracy measurement: no benchmark, test set or error rate for their assistants was located on either record. Neither names the specific models behind its AI. Neither addresses attorney client privilege or work product expressly, which is notable for two systems that index a firm's whole matter file. Neither describes what the AI does when it cannot ground an answer. And neither addresses how time compressed by AI should be recorded or disclosed on a client bill. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
Two things here are worth reading closely, and both are contractual. Clio's clause 14.6 permits it to de identify and aggregate the content submitted to, and output received from, its AI services and use that material to improve and ensure the quality of those services, while withholding any right to use confidential information to train generalised models. MyCase's Part III states that customer content is not used to train or fine tune any model, and its Part I separately retains a perpetual licence over aggregated, anonymised content excluding personal information for internal product development. The useful comparison here is therefore between two published agreements rather than between disclosure and silence. One limit: MyCase's trust centre at trust.8am.com was not opened during research. Both records were verified on 1 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.