EvenUp vs Filevine: how they compare in 2026

EvenUp profileFilevine profile
Last verifiedSeptember 3, 2026

EvenUp and Filevine both produce the document that opens a personal injury negotiation, and they sit at different scales. EvenUp does one practice area and nothing else, turning police reports, medical records, bills and photographs into chronologies, demand packages and case valuations. Filevine runs the whole practice and layers a dozen AI products on top, stating that its customers draft around 100,000 demand letters a month. Filevine sits in the top two bands on twelve of fifteen axes and EvenUp on seven, and the difference is largely contractual. Filevine publishes an indemnity, a liability cap set at the greater of twelve months of fees or 200,000 dollars, carve outs reaching a security breach affecting subscriber data, an insurance commitment with a stated carrier rating floor, and a 99 per cent uptime commitment with a published credit table. EvenUp publishes no customer agreement, and its strength lies elsewhere: a SOC 2 Type 2 examination across four trust criteria recertified in April 2026, alongside an independent HIPAA attestation.

At a glance

Category
EvenUpPlaintiff & Claims AI
FilevinePlaintiff & Claims AI
Founded
EvenUp2019
Filevine2014
Headquarters
EvenUpSan Francisco, California, United States
FilevineSalt Lake City, Utah, United States
Last verified
EvenUpAug 29, 2026
FilevineAug 31, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

EvenUp
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

The models are the entire product and the company was built around a proprietary dataset to feed them. Piai is named as EvenUp's own AI engine and the vendor's central technical claim is that it is trained on a large personal injury specific dataset rather than adapted from a general model, which is the same shape as Jhana.ai: build the corpus first, then the models, then the interface. Every deliverable is model output. Medical chronologies are generated from raw records with treatment timelines and ICD extraction, demand letters are generated end to end, case valuations are derived from a settlement repository, and analytics sit on top of the extracted data. Remove the models and nothing remains but a document store the firm already had. Independent review material reaches the same conclusion from outside, describing it as a vertical drafting engine trained on injury cases rather than a general legal assistant. Fourth A on this axis in the pull, after Reveal, Jhana.ai and Descrybe.

Filevine
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The AI portfolio is the widest in this pull and the platform beneath it is a complete practice management system. Twelve or more distinct AI products are named and separately marketed: MedChron for medical chronologies, DemandsAI for demand letters, Depo CoPilot for live deposition assistance, Depo Summaries, AIFields, AI Doc Review, AI Data Mapping, ValidationAI, ImmigrationAI, Leads AI, Ask LOIS, LOIS for Word and the LOIS Console. AI has its own top-level navigation entry and its own free tier. Several of those are the engine of a capability a firm actually buys, most obviously the medical chronology and the demand letter, which are the two most labour-intensive documents in a personal injury practice. What sits underneath is the business Filevine sold before any of it: matter management, document management and assembly, intake and lead conversion, billing and time-keeping, e-signature, analytics and deadline generation. Strip the models out and every one of those remains and the firm keeps running. The commercial structure confirms the reading, with the AI products sold as packages and extensions on top of a core platform rather than as the platform itself.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

EvenUp
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is structural and visible in the deliverable, and no measured figure is published by the vendor. Medical chronologies carry citations back to source documents so a reviewer can verify any entry against the underlying record, which is the correct architecture when the output is a factual account of someone's treatment. Demand packages cite comparable verdicts drawn from the settlement repository, so the valuation argument is traceable to named prior outcomes rather than asserted, and a Thomson Reuters and Westlaw integration supports legal citation. Held at B on two gaps. Two accuracy figures circulate in third party material and neither was located in vendor material with methodology attached: that chronologies capture over 90 percent of relevant medical information on first pass, and that demands are 69 percent more likely to reach policy limits. Both are the kind of number this axis exists to test and neither is published with a sample, baseline or definition, so neither is credited. And nothing states what the system does when a record is illegible, contradictory or missing, which in medical record work is the common case rather than the edge case.

Filevine
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is claimed consistently across products and no measurement is published anywhere. The pricing page describes Ask LOIS as returning grounded, traceable answers, LOIS for Word as producing source-linked recommendations, AI Drafting as delivering fact-level accuracy and human-verified output, and Depo Summaries as carrying page and line references, and the free LOIS Explore tier is described as drafting content with every result cited to source. A legal research capability with an opinion reader sits alongside it, so a user can open the authority rather than take the citation on trust. The failure modes are named in the agreement rather than in a footnote, and that is rare: output may be incomplete, may contain factual or legal errors or omissions, may reflect biases present in training data, and substantially similar inputs may produce different output. What is absent is any number. Searched the AI features page, the pricing page and the subscription agreement on 31 Aug 2026 and located no accuracy figure, no test set, no evaluation and no error rate, set against a marketing claim on AIFields inviting buyers to stop struggling with AI hallucinations. One hedge belongs in the record: MedChron's verifiable output is described as pointing back to source documents when applicable, which is not the same as always. The individual product pages were not opened.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

EvenUp
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Oversight is sold as a product tier, which makes it inspectable rather than aspirational. Demands are offered across tiers running from instant AI generation through Express Demands to an expert reviewed tier where an in house team quality checks the document before delivery, and independent material notes the human quality assurance step adds turnaround time, which is the honest trade off made visible in the pricing structure. Output is consistently positioned as a draft with attorney review required. Held at B because the mechanics are not published: no statement of what the in house reviewers check or against what standard, no description of what distinguishes the tiers beyond speed, no confidence indication on generated content, and no account of what happens in the instant tier where no human sits between generation and the attorney's inbox. Same shape as Mitratech Managed Bill Review, where a documented human layer exists for customers who buy it and the unattended path is undescribed.

Filevine
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

The review obligation is written into the contract and it is specific about the act required. Section 3.2 of the subscription agreement makes the subscriber solely responsible for reviewing, verifying and determining whether and how to use any output, and then names what that means: independently confirming citations and legal conclusions before relying on output or sharing it with any third party, including a client or a judicial body. Few vendors name the court as the audience. It is reinforced by an AI Acceptable Use Policy incorporated into the agreement and governing permitted and prohibited uses of AI-enabled features, by a product page describing AI drafting as producing human-verified output, and by outputs described as structured for human review with hyperlinks into the underlying material. What is not published, checked across the AI features page, the pricing page and the full agreement on 31 Aug 2026: no abstention behaviour, no confidence or uncertainty indicator surfaced to the user, no threshold at which a feature declines, and no route to report or correct a wrong output. The agreement discloses non-determinism, that similar inputs may produce different output, which is honest and is a warning rather than a control. The AI Acceptable Use Policy was not opened and is the rebuttal route.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

EvenUp
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Outcome claims are specific, named firms appear, and the strongest source available flags the whole class as vendor supplied. Reported: Lundy Law increasing output from about 30 to about 110 monthly demand packages after adopting AI tooling without adding staff, and J. Chrisp Law reclaiming 80 hours per case in paralegal time. Those are named firms with quantified operational change, which is better evidence than most of this index carries. The vendor level claim that demands are 69 percent more likely to reach policy limits is the most consequential figure attached to this product because it speaks to case outcome rather than throughput, and it carries no methodology, comparison group or sample. The independent guide reporting these figures states plainly that most such benchmarks come from vendor marketing and that results depend on case complexity and record volume. Held at B and recorded as Third Party Estimated on that footing: the adoption story is credible and consistently reported, and none of it was located as a vendor published case study with methodology on 29 Aug 2026.

Filevine
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Volume claims stand where customer outcomes should be, on the surfaces read. What is published: approximately 100,000 demand letters drafted by Filevine customers every month, a claim to host the largest and most accurate repository of personal injury case management data in the world, and a case study headline naming an individual, a shareholder said to have brought 125 active cases under control and recovered his evenings. The agreement carries a customer reference clause permitting Filevine to use a subscriber's name and logo, with a withdrawal right, which tells a buyer the logos are consented to rather than assumed. What was not established is any measured outcome attributable to a named organisation: the case study headline gives a person and a caseload figure without naming the firm, and no other quantified result was located on the pages read. This is the weakest-evidenced row on this record and the limit is worth naming precisely: a dedicated customers and case studies library exists at a public URL and was not opened on 31 Aug 2026, and it is the obvious home for named, quantified deployments. Anyone revisiting this record should open it first.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

EvenUp
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

The strongest confidentiality evidence in this category and the first record on the index where a health specific credential is the load bearing one. This product ingests complete medical records, billing statements and treatment histories for injured claimants, so the confidential material is not only the client's legal matter but a third party's protected health information. Against that: an independently assessed HIPAA compliance attestation validating implemented safeguards for PHI, and a SOC 2 Type 2 examination whose named scope includes confidentiality and privacy as well as security and availability. The vendor also states it supports customers handling sensitive information through contractual, technical, organisational and compliance measures, which acknowledges the business associate relationship a plaintiff firm needs. Held at B rather than A because nothing addresses legal professional privilege or attorney work product specifically: a demand package is work product, the case strategy embedded in a valuation is privileged, and the published posture speaks to health data protection and general security without reaching the legal dimension at all.

Filevine
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Substantive published commitments on confidentiality and training use, in the agreement, short of matter-level segregation. The training position is the most carefully drafted in this pull: Filevine engages third-party AI providers under written agreements prohibiting them from using subscriber data to train or improve their models, and under which they do not retain subscriber data beyond the applicable request, with a single named exception for temporary retention for abuse-monitoring or trust-and-safety purposes. Naming that exception rather than leaving it implicit is the mark of a drafter who expected the clause to be read. Ownership is stated clearly, with the subscriber owning its data including output generated from it, and subscriber data defined as confidential information under a mutual confidentiality clause surviving seven years, with trade secrets protected indefinitely. A separate clause commits Filevine not to reduce its confidentiality or security commitments mid-term without written consent. Tenant separation is addressed obliquely, in a provision stating that other subscribers' queries and output are not the subscriber's data. What is missing is the matter-level question: nothing describes a wall between two matters inside one firm, which for a plaintiff practice running adverse cases is the live issue. The Security Addendum and Data Protection Agreement are published and were not opened.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

EvenUp
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Not located in vendor material. The product generates the demand letter a firm sends to an insurer, which is an advocacy document making legal and valuation arguments on a client's behalf, and it generates the case valuation that shapes settlement advice. Independent material states consistently that output is a draft requiring attorney review, and that framing was not located as a vendor published position. Nothing addresses the supervising attorney's duty over machine drafted advocacy, the professional responsibility of relying on a machine generated valuation when advising a client whether to settle, or any bar guidance. The gap matters more here than on a research tool because the output goes out under the firm's name to an adverse party. Checked the product and blog material, the trust centre summary and the site navigation on 29 Aug 2026.

Filevine
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

The most complete advice-line clause located in this pull, and no engagement with the authorities behind it. The agreement states that Filevine is not a law firm or provider of legal advice and that use of output does not create an attorney-client relationship, repeats in the disclaimer that Filevine is not a law firm and does not provide legal advice, and then goes further than any comparable clause by specifying the professional act required: the subscriber must independently confirm citations and legal conclusions before relying on output or sharing it with any third party, including a client or a judicial body. That names the duty, the object of the duty and the audience, which is the competence and supervision dimension most vendors omit. An AI Acceptable Use Policy is incorporated into the agreement and controls permitted and prohibited uses of AI features. What holds this below the top band: no bar or ethics authority is named anywhere located, including ABA Formal Opinion 512, and no jurisdictional limit on the product's output is stated, which matters for a platform serving immigration, criminal defence and prosecution work across every state. The AI Acceptable Use Policy was not opened on 31 Aug 2026 and is the rebuttal route.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

EvenUp
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

Nothing published about how the models are governed or evaluated. No AI policy, no model card, no bias or fairness testing, no evaluation methodology or result, no accuracy monitoring, no drift statement, no named governance body and no ISO 42001. The untested risk on this product is specific and serious: case valuation is generated from a settlement repository of past outcomes, and historical personal injury settlements carry the demographic and geographic patterns of who was compensated well and who was not. A valuation engine trained on that history can reproduce those patterns for a new claimant while presenting the result as a data backed figure, and nothing published indicates whether that has ever been examined. Checked the product material, the blog including the compliance announcements, the trust centre summary and the site navigation on 29 Aug 2026.

Filevine
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

The first vendor in this pull to address bias at all, and it does so twice. Six AI principles are published and named: Fairness, stated as fighting against the threat of bias in its legal AI tools so the technology works for all legal professionals and their clients; Reliability and safety; Privacy and security; Inclusiveness, framed around building tools across practice areas and fostering equity in the profession; Transparency, committing to explain how the AI works in understandable language; and Accountability, committing to take full responsibility for the impact of the technology. More importantly the point is repeated where it binds, with the agreement disclosing that output may reflect biases present in training data, which is a contractual acknowledgement rather than a marketing sentiment. Governance has real apparatus around it: an AI Acceptable Use Policy incorporated into the agreement, a commitment to maintain a list of permitted models for use in AI-enabled features, and a clause preventing Filevine from reducing confidentiality or security commitments mid-term without consent. Named roles exist in a Head Legal Futurist and a Legal Futurist. What is absent is testing: no pre-release evaluation regime is described, no result of any kind is published, no bias audit or fairness measurement appears, and the Fairness principle is a single sentence. Owner accountability is implied by role rather than assigned.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

EvenUp
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

Handling is credentialed and the training question is unanswered. The HIPAA attestation and the SOC 2 Type 2 privacy and confidentiality scope establish that safeguards over protected health information have been independently assessed, which is real stewardship evidence and more than most of this index carries. What was not located is any statement on whether medical records, demand drafts, case files or settlement outcomes submitted by firms are used to train or improve Piai, how long client content is retained, or whether a firm can require deletion. The question is unavoidable for this vendor rather than incidental: its central technical claim is a proprietary model trained on a large personal injury specific dataset, and nothing published states where that dataset came from or whether customer matters continue to feed it. A credential covering how data is protected is not a statement about what it is used for. Checked the trust centre summary, the compliance announcements, the product material and the site navigation on 29 Aug 2026.

Filevine
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

The Data Protection Agreement, last updated 14 Jan 2026 and read in full, closes the two gaps that held this row down. All five elements this axis asks for are now published and specific. Retention: personal information is retained for the duration of performance of the Services, and on termination or expiry Filevine will destroy it or return it if the subscriber so directs in writing. Deletion: where law compels retention Filevine must notify the subscriber in writing with the documents involved, the legal basis, and a specific timeline for destruction once the requirement ends, and it commits to certify in writing that destruction is complete within thirty days of completing it. Access control: access is limited to employees who require it and to the parts they strictly require, under confidentiality commitments, with privacy training and background checks where lawful. Subprocessors: each is engaged under a written agreement with obligations not less protective than the DPA, the current list sits in Annex C, a subscribe-by-email mechanism gives notice of new ones, the subscriber may object within ten business days on reasonable grounds, and Filevine is liable for a subprocessor's acts as if it had performed them itself. Incident practice: Filevine will notify the subscriber promptly and without undue delay on becoming aware of a security breach, describing the categories of information affected, the approximate number of data subjects, the steps taken to investigate and remedy, and a named contact, with phased disclosure permitted and Filevine bearing the reasonable costs. One softness rather than a gap: the notification duty is expressed as promptness rather than a fixed number of hours. The Security Addendum was not opened.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

EvenUp
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

No published position located. Nothing was found on liability for AI output, warranty, service levels or remedy. The exposure profile is unusually concrete here: a missed injury, a misread treatment date or an omitted provider in a generated chronology flows straight into a demand letter and can understate a claim, and an understated demand that settles is a loss the claimant never learns about. A generated valuation that anchors a firm low has the same shape. No published vendor position addresses any of it, and the risk sits with the firm and ultimately the injured claimant. Checked the product material, the blog, the trust centre summary and the site navigation on 29 Aug 2026. Enterprise agreements govern this and are not public.

Filevine
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

The first A on this axis in the pull, and it is earned on four separate limbs rather than one strong clause. Indemnity: Filevine will defend the subscriber against third-party claims that the services infringe a United States patent or copyright or misappropriate a trade secret, and will indemnify for damages, costs and fees awarded or agreed, with named remedies of procuring the right to continue, modifying the services, or terminating and refunding. Cap: total liability is limited to the greater of the fees paid in the twelve months before the claim or two hundred thousand dollars, which is a floor rather than a ceiling for smaller subscribers and is the highest published floor located in this pull. Carve-outs: the cap expressly reaches claims arising from a security breach affecting subscriber data caused by breach of the Security Addendum or the DPA and from breach of confidentiality obligations, gross negligence and intentional misconduct sit outside the limitation where law prohibits limiting them, and the infringement indemnity sits outside the cap entirely. Insurance: the agreement commits Filevine to maintain industry-standard insurance from carriers rated A minus, VI or better by A.M. Best, which is a stated quality floor and the only insurance commitment located in any agreement in this pull. Alongside those sit an affirmative warranty that the services will substantially conform to documentation, not knowingly infringe and comply with applicable law, and a 99.0 per cent uptime commitment with a published three-tier credit table. Output itself carries no warranty and is carved out of the indemnity, which the note records so the picture is complete.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

EvenUp
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

One substantive integration is named and the connections this buyer needs most are not. Named: Thomson Reuters and Westlaw integration supporting legal citation inside generated demand packages, which is a real and unusual integration for a plaintiff side drafting tool and gives the citation layer an established source. What was not located: any named case management system integration, which for a personal injury firm is the connection that matters, since the practice runs on a case management platform holding intake, treatment tracking and deadlines. No API or export documentation was located either, and nothing describes how records get in or how a finished demand returns to the matter file. Independent comparison material in this category treats case management integration as a primary evaluation criterion, which makes its absence from located vendor material notable. Checked the product material, the trust centre summary and the site navigation on 29 Aug 2026.

Filevine
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Real integrations exist and are named, with the depth left to a page that was not opened. The most substantive is LOIS for Word, which puts drafting and standards-enforced redlining inside Microsoft Word with source-linked recommendations, so the AI reaches the application where the document is actually written rather than requiring a trip to a separate system. Microsoft 365 integration is reported, DataBridge is published as a package extension giving secure real-time access to Filevine data, Vinesign has a public API for embedding e-signature into other workflows, and the platform advertises native and partner integrations as a purchasable extension. The agreement confirms API access is granted and makes the subscriber responsible for activity through it. Deposition scheduling includes court reporter booking and automated Zoom link generation, which is an operational integration into how the work is actually run. What is not established is what any of these move, in which direction, or what a firm must configure: the dedicated integrations and API page was not opened on 31 Aug 2026, and no developer documentation, endpoint list or connector catalogue was read. Nothing was located for iManage, NetDocuments or e-billing.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

EvenUp
DD on Deployment Model and Data ResidencyNothing published on where the software runs or where client data sits.

Nothing located. No hosting provider is named, no region or data residency commitment is published, and no single tenant or dedicated instance option is described. For a platform holding protected health information for injured claimants, the location and tenancy of that data is a question a firm's own compliance review would ask directly, and the HIPAA attestation establishes that safeguards were assessed without stating where the data sits. Checked the product material, the trust centre summary, the compliance announcements and the site navigation on 29 Aug 2026. Correction candidate: the Trust Center operates a request access route which was not entered in this pass and is the surface most likely to hold residency detail.

Filevine
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed.

Reading the Data Protection Agreement supplied the processing location and the cross-border framework that were missing. Delivery is cloud, hosted on Amazon Web Services, which the vendor names on both the case management page and the pricing FAQ, and separate United States and Canadian login domains imply a distinct Canadian instance. The DPA adds what the marketing did not. Annex A identifies the data importer as Filevine, Inc. at 1260 Stringham Avenue, Suite 600, Salt Lake City, Utah, so a European or British subscriber can see which entity in which jurisdiction receives its data, and a Data Protection Officer is named as the contact point. Cross-border transfers are governed rather than assumed: the European Commission's Standard Contractual Clauses and the UK Information Commissioner's international data transfer addendum are both incorporated, with the operative provisions completed, the docking clause disapplied, and competent supervisory authorities enumerated for EU member states, the United Kingdom via the ICO, and Switzerland via the Federal Data Protection and Information Commissioner, with the CNIL as the default. Government access requests are to be notified to the subscriber only, not the data subject. What is still not published is the residency choice itself: no list of available regions or data centre locations, no option a subscriber can select, no tenancy model, and no statement distinguishing where data is stored from where model inference runs, which matters because third-party AI providers process subscriber data. The Security Addendum was not opened.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

EvenUp
AA on Security Certifications and Trust CenterCurrent independent attestation with named scope, reachable without a sales call: a trust center carrying reports, dates and the standards actually covered.

Scope, currency and a self serve route, which is the combination this axis rewards. A dedicated Trust Center operates at trust.evenuplaw.com describing security, privacy and compliance practices and offering a request access route to available documentation, which under the three tier test is a request flow rather than a sales gate. The attestation is named with its scope stated: a SOC 2 Type 2 examination covering security, availability, confidentiality and privacy, four of the five Trust Services Criteria and materially broader than a security only scope. Currency is addressed and dated, with recertification announced April 2026 rather than an undated claim. Alongside it a HIPAA compliance assessment and attestation, independently conducted, which is the credential this product actually needs given it processes protected health information, and the vendor correctly explains that HIPAA has no formal certification and that what exists is a third party attestation, which is an accurate distinction most vendors blur. Held short of a perfect record on one point: the auditing firm is not named for either the SOC 2 or the HIPAA assessment. Consistent with Lexis+ AI at A on scope, currency and portal, and below Exterro, whose FedRAMP status is verifiable in a public registry without any request at all.

Filevine
AA on Security Certifications and Trust CenterCurrent independent attestation with named scope, reachable without a sales call: a trust center carrying reports, dates and the standards actually covered.

Reading the Data Protection Agreement moved this row. The certification claim was always broad, covering SOC 2 Type II, SOC 3, HIPAA, CJIS, HITECH and GDPR, with a structured security page reached from the platform navigation under governance and risk, industry compliance, access and identity security, and data protection. What was missing was any way for a buyer to get behind it, and the DPA supplies that contractually. Filevine commits to retain an independent third party at least once per year to audit its data processing practices and its information technology and information security controls for the facilities, infrastructure and systems used to process personal information, which is a stated scope and a stated cadence. On the subscriber's written request it will make the relevant audit reports available for review, subject to confidentiality, which is a route to the report rather than a promise of one. It commits to address any issues or exceptions raised in those audits through a management corrective action plan. If it has not conducted an audit in the past year, or declines to share the reports, the subscriber acquires a direct audit right on 21 days' notice, extending to records, systems, facilities and meetings with relevant personnel. And separately it agrees to respond in writing to a subscriber security questionnaire once a year, within six weeks of receipt. What is still absent is the paperwork a buyer would ideally see without asking: no auditor is named, no report date or coverage period is published, and the certification claims themselves carry no scope statement. The security page and Security Addendum were not opened.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

EvenUp
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

Nothing located. Piai is named and claimed as proprietary, trained on a personal injury specific dataset, and that is a statement about ownership rather than about supply chain. No foundation model provider is named, nothing states whether third party models sit underneath Piai or process any part of the pipeline, no subprocessor list was located, and the Thomson Reuters and Westlaw integration establishes at least one external data relationship without any accompanying disclosure of what flows to it. For a product handling protected health information, the identity of every party in the processing chain is a question a firm's HIPAA business associate review asks directly and it cannot be answered from public material. Checked the product material, the compliance announcements, the trust centre summary and the site navigation on 29 Aug 2026.

Filevine
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The agreement confirms third-party models are in the stack and never says whose. Section 3.1 states that AI-enabled features use artificial intelligence including models provided by third-party AI providers, and section 4.3 commits Filevine to maintaining a list of permitted models for use in those features. A commitment to maintain a list is not a commitment to publish one, and no model, provider or version was located on any page read on 31 Aug 2026. One tension belongs on the record: the AI principles page states that Filevine's AI is proprietary, while the agreement describes models provided by third-party AI providers, and nothing published reconciles the two. What is disclosed instead is the contractual treatment of those providers, which is strong on its own terms, prohibiting them from training on subscriber data and from retaining it beyond the applicable request except temporarily for abuse monitoring. No change-notification commitment specific to models was located, though the general update clause requires thirty days' notice for material changes and bars reduction of security or confidentiality commitments mid-term. A Subprocessors page is published at a public URL and was not opened; it is the most likely place a provider is named and could move this grade.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

EvenUp
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing published at any level. Independent review material describes the model as case based rather than seat based, which is a meaningful structural fact for a plaintiff firm because cost then scales with caseload rather than headcount, and notes that the platform only earns its keep at sufficient injury volume. None of that comes from the vendor: no price, no range, no per case figure, no tier structure and no indication of what a demand package costs. Every route is a sales conversation and an annual contract. The absence is heavier in this category than most, because contingency fee firms carry case costs themselves and a per case charge is a direct deduction from a claimant's eventual recovery. Checked the product material, the pricing navigation and independent review material on 29 Aug 2026.

Filevine
CC on Commercial TransparencyPricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not.

The shape of the purchase is published in unusual detail and no figure appears anywhere. The pricing page sets out the full modular structure: a LOIS tier with seven named components, and four platform packages covering Matters, Intake, Depositions and Signatures, each broken into named features, plus five Matters extensions for analytics, deadline management, a client portal, data access and integrations. A buyer can therefore see exactly what is bought separately, which is the practical question in a modular product. A genuinely free tier is published with its limits stated, LOIS Explore, requiring no credit card, offering document upload and questioning, AI drafting with results cited to source, legal research and the opinion reader, and expressly excluding the case management connection. The agreement adds real commercial mechanics: interest at the lesser of 1.5 per cent per month on amounts more than ten days overdue, suspension rights at ten days, a ten-day window to dispute a charge or waive it, usage telemetry with retroactive invoicing at list rates if entitlements are exceeded, and non-refundable fees outside a warranty or breach termination. One cost disclosure is unusual and creditable: implementation, configuration and data migration are stated not to be provided by Filevine at all but by separate certified Implementation Providers under their own agreements and fees. What is nowhere published is a number, at any tier, and every route to one is a demo or a custom quote.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

EvenUp
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Depth in one practice area, stated plainly, with the boundary acknowledged rather than obscured. The vendor is explicit that it builds for plaintiff side personal injury and nothing else, and independent review confirms it is not a general legal assistant. Within that scope the coverage is genuinely deep: police reports, medical records, billing statements, photographs and intake notes as inputs, demand letters, chronologies, case valuations, negotiation preparation and caseload analytics as outputs, and a settlement repository supporting jurisdictional comparables. Single practice specialisation is a design decision rather than a coverage failure and is credited as such. Held at B rather than A because the corpus behind the differentiator is not characterised: no statement of how many verdicts or settlements the repository holds, which jurisdictions it covers, what date range, how often it updates, or whether coverage is deep enough in a given venue for a comparable to carry weight, which is exactly what an attorney relying on that citation in negotiation needs to know.

Filevine
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

The most extensively documented segment coverage in this pull, and no boundary anywhere. Seventeen dedicated segment pages are published across four dimensions. By practice area: personal injury, family law, mass torts, immigration, insurance defence, criminal defence and estate planning. By government tier: prosecutors, public defenders, states and municipalities, attorneys general, and federal agencies, which is the widest public-sector treatment located in the pull and is reinforced in the agreement by clauses addressing sovereign immunity, anti-indemnification statutes, constitutional limits on multi-year obligations, and FAR and DFARS commercial software designations. By corporate use: in-house counsel. By firm size: solo, small, mid-size and big law, each with its own page. Product coverage is equally specific, with ImmigrationAI stated to handle documents in 170 languages and Timely generating court deadlines for any jurisdiction in the country. What is absent is any statement of limits: no practice area, matter type, jurisdiction or scale is identified as unsupported, and the deadline claim of any jurisdiction in the country is asserted without a coverage table behind it. The individual segment pages were not opened on 31 Aug 2026.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

EvenUp
Terms silent

Silent. The quoted phrase is the stated scope of the SOC 2 Type 2 examination and it is the strongest data protection evidence on this record, but an examination of controls is not a statement of purpose: it establishes that safeguards over customer content were assessed, not what that content is used for. No statement was located in either direction on whether medical records, demand drafts, case files or settlement outcomes submitted by firms are used to train or improve Piai. The silence is conspicuous rather than ordinary here, because the vendor's central technical claim is a proprietary model trained on a large personal injury specific dataset and nothing published states where that dataset came from or whether customer matters continue to feed it. Recorded as silent, not as a negative commitment. Correction candidate: the Trust Center request access route was not entered in this pass. Checked the compliance announcements, the trust centre summary, the product material and the site navigation on 29 Aug 2026.

Filevine
Never, in the contract

A contractual prohibition, drafted with its exception named rather than left implicit. The subscription agreement, last updated 12 August 2026, states that Filevine engages third-party AI providers under written agreements prohibiting them from using subscriber data to train or improve their models, and under which those providers do not retain subscriber data beyond the applicable request, except for temporary retention solely for abuse-monitoring or trust-and-safety purposes. The same section commits Filevine to maintain a list of permitted models consistent with that undertaking. One carve-out sits alongside it and a buyer should read the two together: a separate clause permits Filevine to use subscriber data in de-identified, aggregated form to improve and enhance the services and for development, diagnostic and corrective purposes across its other technologies, subject to a commitment that anonymised data cannot reasonably identify anyone and that Filevine will not attempt re-identification. Checked the agreement, the AI features page and the pricing page on 31 Aug 2026.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

EvenUp
Not addressed

Not addressed. No retention period is published for uploaded medical records, generated chronologies, demand drafts or case valuations, and nothing indicates whether a firm can require deletion at matter close. Retention has a statutory dimension on this product that it does not have elsewhere on the index: the content is protected health information belonging to a third party claimant, and HIPAA safeguards address how it is protected rather than how long a business associate keeps it. Nothing published closes that. Checked the trust centre summary, the compliance announcements, the product material and the site navigation on 29 Aug 2026.

Filevine
Disclosed fixed window

Retention is now stated contractually across the data lifecycle, with a certification deadline attached to the end of it. The Data Protection Agreement, updated 14 Jan 2026 and read in full, gives the period as the duration of performance of the Services, and provides that on termination or expiry Filevine will destroy personal information or return it where the subscriber directs in writing. Where a law or regulator compels Filevine to keep something it would otherwise destroy, it must notify the subscriber in writing identifying the material, the legal basis, and a specific timeline for destruction once the requirement lapses. It then commits to certify in writing that destruction is complete within thirty days of completing it, which converts a promise into a checkable event. Two qualifications keep this short of a fixed customer-facing period. The commitments run to personal information as defined in the DPA rather than to prompts and generated output as a class, and nothing published addresses whether an AI conversation thread is retained separately or for how long. And the Subscription Agreement routes retention, return and destruction of data generally to the Security Addendum, which is published and was not opened on 31 Aug 2026.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

EvenUp
Not addressed

Not addressed. No permission model, matter level access restriction or tenant segregation description was located. The question has an unusual edge on this product: the settlement repository is a shared benchmarking asset drawn from past outcomes, and nothing published describes the boundary between one firm's case data and the pooled comparables sold to every other firm, including opposing firms working the same venues. A plaintiff firm's settlement history is competitively sensitive as well as confidential. No document management system integration exists to inherit permissions from. Checked the product material, the trust centre summary and the site navigation on 29 Aug 2026.

Filevine
Not addressed

Nothing published describes a wall between matters. Searched the AI features page, the pricing page, the case management page and the full subscription agreement on 31 Aug 2026 and located no ethical wall concept, no matter-level permission model, and no statement that a user can be restricted to particular cases or that AI features respect such a restriction. Tenant separation is addressed once and obliquely, in a clause stating that queries submitted by and output generated for other subscribers are not the subscriber's data, which draws a line between customers rather than inside one. Account-level control exists, with each authorised user required to hold unique credentials that may not be shared and the subscriber responsible for its users' compliance. The question is live for this buyer base: a plaintiff firm running adverse matters, or a public defender office and a prosecutor's office both named as target segments, would need to know whether one matter's material can surface in another's AI output. The Security Addendum is published and was not opened, and is the rebuttal route.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

EvenUp
Not addressed

Not addressed. No government or law enforcement request clause, no commitment to notify a customer before producing their data, and no transparency report were located. The stakes are higher than the usual case because the vendor holds protected health information and unfiled demand material for claimants in active disputes, and a subpoena to the vendor rather than the firm would reach work product the firm would otherwise resist producing. Checked the trust centre summary, the compliance announcements and the site navigation on 29 Aug 2026.

Filevine
Notice committed

Two instruments address this and the Data Protection Agreement is the stronger of them. The Subscription Agreement permits disclosure of confidential information where required by law, court order or other government order, conditioned on advance notice to the disclosing party where legally permitted. The DPA, read in full on 31 Aug 2026, goes further on personal information: where a law requires Filevine to process or disclose it, Filevine will first inform the subscriber of the legal requirement and give the subscriber an opportunity to object or challenge it, unless the law prohibits such notice, and any disclosure is limited to the minimum necessary to accomplish its purpose. An opportunity to object and a minimisation duty are materially better than notice alone. The Standard Contractual Clauses appendix adds that on a government access request Filevine will notify the subscriber only and not the data subject, leaving the subscriber to decide what its own client is told. Two carve-outs a buyer should read: the opportunity to object is qualified where it would prejudice Filevine or expose it to liability for non-disclosure, and the DPA route governs personal information rather than every document in a matter. No transparency report or disclosure statistics were located, and nothing commits Filevine to seek a protective order of its own motion.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

EvenUp
Sources named, basis unstated

Named without a licence basis, and the named corpus is the product's differentiator. The Settlement Repository is described as a database of past settlements used for benchmarking and case valuation, and comparable verdicts from it are cited directly inside demand packages, so the corpus is not background infrastructure but the substance of the argument sent to an insurer. What is absent is everything a practitioner relying on that citation would check: no count of verdicts or settlements held, no jurisdictional coverage, no date range, no update frequency, and no statement of the basis on which the outcomes were obtained, whether public court records, customer contributed results, or licensed data. Piai is separately claimed as trained on a large personal injury specific dataset whose provenance is also unstated. Two corpora, both central, neither sourced.

Filevine
Not addressed

This question does arise for this product and nothing answers it. Most of what Filevine's AI reads is the customer's own case file, where provenance is not in issue, but the pricing page states that the free LOIS Explore tier gives access to legal research and an opinion reader, which means the platform retrieves primary law from a corpus Filevine has assembled or licensed from someone. Searched the AI features page, the pricing page, the case management page and the full subscription agreement on 31 Aug 2026 and located nothing identifying that corpus: no source, no supplier, no jurisdictions covered, no licence or public-domain basis, and no update cadence. For a research capability offered free to anyone who signs up, and used to produce drafts that the same agreement expects to be filed after citation checking, the absence of any statement about where the law comes from is the finding. The LOIS product pages were not opened and are the rebuttal route.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

EvenUp
Not addressed

Not addressed. The product does cite legal authority, through a Thomson Reuters and Westlaw integration supporting citation inside demand packages, so unlike TrialView or Exterro this signal is applicable rather than a scope fact. Nothing published indicates whether cited authority is checked for current treatment, whether an overruled or superseded case would be flagged before it reaches a demand letter, or whether the Westlaw integration includes KeyCite treatment data or only citation retrieval. Comparable verdicts drawn from the settlement repository are outcomes rather than authority and carry no treatment question, but the legal citations in a demand do. Checked the product material, the integration references and the site navigation on 29 Aug 2026.

Filevine
Not addressed

A legal research capability is published and no currency check is claimed for it. The pricing page states that LOIS Explore provides access to legal research and an opinion reader, and the drafting products are described as citing every result to source, so the product does retrieve and cite authority. Searched the AI features page, the pricing page and the full subscription agreement on 31 Aug 2026 and located no citator, no treatment signal, no subsequent-history check and no statement about whether cited authority remains good law. The agreement puts that burden squarely on the user, requiring independent confirmation of citations and legal conclusions before output is relied on or shared, which is an allocation of responsibility rather than a product capability. One adjacent signal is recorded rather than credited: a published webinar is titled around checking the cite, seeing the reasoning and reading the opinion, which suggests the vendor is thinking about verification workflow, and it was not opened.

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

EvenUp
Not addressed

Not addressed. Nothing published describes an explicit no answer path, abstention behaviour or confidence signal. The gap is specific to medical record work: records arrive illegible, contradictory, incomplete or out of order as a matter of routine, and nothing states whether the system flags a gap in the treatment timeline, marks a low confidence extraction, or silently produces a clean looking chronology from an incomplete file. Independent material notes that missed items and misinterpretations occur in complex cases with extensive treatment histories, which confirms the failure mode exists without the vendor describing how it is surfaced. A chronology that looks complete and is not is the most dangerous output this product can produce. Checked the product material, the trust centre summary and the site navigation on 29 Aug 2026.

Filevine
Not addressed

The limitations are disclosed unusually frankly and the behaviour is not described. The subscription agreement states that AI-generated output may be incomplete, may contain factual or legal errors or omissions, may reflect biases present in training data, or may otherwise be unreliable, and that substantially similar inputs may produce different output. Disclosing non-determinism in a customer agreement is rare and is recorded as a point in the vendor's favour. What none of it does is describe what the system does when it is unsure. Searched the AI features page, the pricing page and the full agreement on 31 Aug 2026 and located no abstention path, no confidence or grounding indicator surfaced to the user, no threshold at which a feature declines to answer, and no statement of behaviour where the case file does not support the question asked. The AI Acceptable Use Policy is incorporated into the agreement and published, and was not opened; it governs permitted and prohibited uses and is the rebuttal route.

Fabricated Citation Record

Does a public court record exist involving output from this product?

EvenUp
None located

None located, with the instrument named. General web searches combining the vendor and product names with court, order, sanction, fabricated citation and demand letter terms returned nothing on 29 Aug 2026, and no named docket database or court record tracker was searched. Recorded as a statement about what this search found and not as a clearance. Worth flagging the exposure shape for a later pass with a proper docket instrument: this product generates documents citing both legal authority and comparable verdicts, sent to adverse parties, so both a fabricated case and a fabricated or misdescribed comparable would be discoverable in the record if either had occurred.

Filevine
None located

No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known and which stood at roughly 1,994 identified decisions when checked, together with several independent 2026 sanctions trackers and practitioner guides, searched on the company name and the product names. This is a statement about the public record on the date shown rather than a clearance. The exposure is more direct here than for most vendors in this pull, because the platform drafts demand letters, motions and other documents intended to be filed or served and offers legal research with an opinion reader, so a fabricated citation could in principle originate inside the product rather than elsewhere. The agreement anticipates exactly this, requiring the subscriber to confirm citations independently before sharing output with a client or a judicial body.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

EvenUp
Not addressed

Not addressed. No named ethics opinion, no ABA Formal Opinion 512, no state bar guidance and no engagement with professional conduct rules was located. The relevance is direct rather than theoretical: the product drafts the advocacy document a firm sends under its own name and generates the valuation informing settlement advice to a client, both of which sit squarely inside the competence and supervision duties bar guidance on AI addresses. Checked the product material, the blog, the trust centre summary and the site navigation on 29 Aug 2026.

Filevine
Not addressed

The duties are described accurately and no authority is cited for them. Searched the AI features page, the pricing page, the case management page and the full subscription agreement on 31 Aug 2026 and located nothing naming ABA Formal Opinion 512, any state bar guidance on generative artificial intelligence, or any court standing order. What the agreement does instead is state the substance: Filevine is not a law firm, use of output creates no attorney-client relationship, and the subscriber must independently confirm citations and legal conclusions before relying on output or sharing it with a client or a judicial body. That tracks the competence, confidentiality and candour duties those authorities describe without pointing a risk committee at a single source. Two published items were not opened and are the rebuttal route: the AI Acceptable Use Policy, which is incorporated into the agreement and governs prohibited uses, and a webinar and blog series on AI risk and verification, either of which may engage named guidance.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

EvenUp
Not addressed

Not addressed, and the omission carries more weight in this category than any other on the index. Personal injury work is contingency fee work: the firm advances case costs and recovers them from the claimant's settlement, so a per case charge for AI generated demand packages is money that comes out of an injured person's recovery. Nothing published addresses whether the platform's per case cost is treated as a case expense or firm overhead, how it should be disclosed to a client, or what record a firm could produce showing what portion of a demand was machine generated. Reported time savings of 80 hours per case describe the firm's side of the equation only. Checked the product material, the pricing navigation and independent review material on 29 Aug 2026.

Filevine
Savings claims only

Savings are quantified and the client's side of the bill is not addressed. The published claims are specific by the standards of this pull: AIFields is said to reduce costs by over 75 per cent, demand letters are said to take 15 minutes or less, DemandsAI is offered on affordable per-case fees with no charges based on complexity or number of edits, and the AI features page argues that reduced workload translates to cost savings a firm can pass on to clients. Searched that page, the pricing page and the full subscription agreement on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee purposes and no guidance on billing, fee or client disclosure treatment where AI-generated work informs what a client is charged. The platform includes billing and time-keeping as a core module, so the mechanism to record it exists, and nothing published connects the two. The gap is sharpest on the demand letter, which in a contingency practice is priced into the recovery rather than billed hourly.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

EvenUp
On request only

On request, through a real route with the credential this buyer actually needs. The Trust Center at trust.evenuplaw.com offers a request access path to available documentation, and behind it sit a SOC 2 Type 2 examination scoped to security, availability, confidentiality and privacy, recertified April 2026, and a HIPAA compliance attestation. For a plaintiff firm that must satisfy itself about a business associate handling claimant protected health information, that is the pack the diligence actually calls for and there is a defined place to request it. Held at on request rather than higher because nothing is published open: no subprocessor list, no named model provider, no downloadable summary and no business associate agreement template were located outside the gate, and the gate itself was not entered in this pass so the contents are unverified.

Filevine
Disclosure pack published

The strongest position on this signal in the pull, and it is now verified rather than inferred. The Data Protection Agreement was read in full on 31 Aug 2026 and answers what a client's outside counsel guidelines actually ask. Subprocessors: engaged only under written agreements with obligations not less protective than the DPA, the current list published at a live URL reached from Annex C, a subscribe-by-email mechanism for notice of new ones, a ten business day objection window on reasonable grounds, and a right to terminate the affected Services with a refund of prepaid fees and no penalty if Filevine cannot work around an objection. Audit: an independent third party audits Filevine's data processing and information security controls at least annually, the reports are available on the subscriber's written request, a direct audit right on 21 days' notice arises if that fails, and Filevine will answer a written security questionnaire once a year within six weeks. Transfers: Standard Contractual Clauses and the UK addendum incorporated, supervisory authorities named, a Data Protection Officer identified. Breach: prompt notice with stated content. Around the DPA sit four further published instruments incorporated into the subscription agreement, including a Security Addendum and an AI Acceptable Use Policy. Two limits: the subprocessor list page itself did not retrieve on 31 Aug 2026, so the names remain unverified, and the Security Addendum and AI policy were not opened.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

EvenUp
Partial record

Partial record, strong on the source trail and silent on the machine's own involvement. Medical chronologies carry citations back to source documents so any entry can be verified against the underlying record, and demand packages cite comparable verdicts from the settlement repository, so a firm can show what a factual assertion or a valuation argument rests on. That is the sources retrieved limb answered properly. The other two limbs are absent: nothing indicates that output records which model generated it, and no human verification record is captured, including for the expert reviewed tier where an in house team demonstrably does check the document before delivery and no artifact of that check appears to reach the customer. A demand package is a pre litigation document, so the forum here is a claim file or a subsequent suit rather than a standing order, and the same question applies in either.

Filevine
Partial record

The obligation is stated and the record that would discharge it is not described. The agreement is explicit about the duty, requiring the subscriber to independently confirm citations and legal conclusions before relying on output or sharing it with any third party including a judicial body, which is the clearest published statement in this pull that output may end up in front of a court. Product-side support for that duty is real in part: drafting output is described as cited to source, LOIS for Word gives source-linked recommendations, deposition summaries carry page and line references, and a legal research opinion reader lets a user open the authority. What is missing is the record itself. Searched the AI features page, the pricing page and the full agreement on 31 Aug 2026 and located no model identification or versioning, so which system produced a passage cannot be established; no log of AI invocations or of what a user accepted or edited; and no export, certification template or guidance for a court's standing order on AI use. The AI Acceptable Use Policy was not opened and is the rebuttal route.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.

Signals neither addresses in public material
  • Ethical Walls and Matter Segregation
  • Good Law Verification
  • Refusal and Uncertainty Behaviour
  • Bar Guidance Alignment

Which one fits

Choose EvenUp if

  • You want a vendor that does one thing. EvenUp builds only for plaintiff side personal injury, turning police reports, medical records, billing statements, photographs and intake notes into medical chronologies with treatment timelines and ICD extraction, demand packages, and case valuations drawn from a settlement repository, with comparable verdicts cited inside the demand itself and a Thomson Reuters and Westlaw integration supporting legal citation.
  • You want to choose how much human review the demand gets. Demands are sold in tiers running from instant AI generation through Express Demands to an expert reviewed tier where an in house team quality checks the document before delivery, so the oversight level is a purchasing decision rather than an assumption, and chronologies carry citations back to source documents so an entry can be checked against the record.
  • Your compliance review wants current credentials for health information. EvenUp publishes a SOC 2 Type 2 examination covering security, availability, confidentiality and privacy, recertified and announced in April 2026, alongside an independently conducted HIPAA compliance assessment and attestation, through a trust centre offering a request route to the documentation.

Choose Filevine if

  • You want recourse written down. Filevine's subscription agreement gives an infringement indemnity with named remedies, caps liability at the greater of twelve months of fees or 200,000 dollars, lifts that cap for a security breach affecting subscriber data and for breach of confidentiality, commits to maintaining insurance from carriers rated A minus, VI or better by A.M. Best, and publishes a 99 per cent uptime commitment with a three tier service credit table.
  • Your data protection officer will read the addendum. Filevine's data processing agreement sets retention to the term of the services with destruction or return on termination, requires written certification of destruction within thirty days, lists subprocessors in an annex with email notice of additions and a ten business day objection right, requires breach notification describing the categories affected and the steps taken, and commits to an annual independent audit whose reports the subscriber may request, with a direct audit right if they are not provided.
  • The AI has to reach the whole practice. Filevine publishes a dozen AI products including MedChron for clinical chronologies, DemandsAI, Depo CoPilot transcribing depositions live, Depo Summaries with page and line references and LOIS for Word for drafting and redlining inside Word, alongside seventeen segment pages spanning practice areas, firm sizes, in house teams and public sector buyers from prosecutors and public defenders to attorneys general and federal agencies.

In summary

EvenUp

EvenUp is a vertical AI platform built exclusively for plaintiff side personal injury firms, turning police reports, medical records, billing statements, photographs and intake notes into medical chronologies, demand packages and case valuations, with comparable verdicts from its settlement repository cited inside the demand and demands offered across tiers from instant generation to an expert reviewed option. The AI Legal Index grades it in the top two bands on seven of fifteen capability axes, with A grades on AI centrality and security certifications: its SOC 2 Type 2 covers four trust criteria and was recertified in April 2026, alongside a HIPAA attestation. As of 29 August 2026 the index located no customer agreement, no liability position, no named model provider and no published price.

Source: AI Legal Index, 2026

Filevine

Filevine is a case management platform for contingency and volume practices covering the matter lifecycle from lead capture through settlement, with an unusually broad AI layer spanning clinical chronologies, demand assembly, live deposition transcription and summaries, drafting and redlining inside Word, document review and data mapping into case fields. The AI Legal Index grades it in the top two bands on twelve of fifteen capability axes, with A grades on data stewardship, liability and recourse, and security certifications: its agreement carries an indemnity, a cap floored at 200,000 dollars, an insurance commitment and uptime credits, and its data processing agreement covers retention, subprocessor objection and breach notification. As of 31 August 2026 the index located no named model and no published price.

Source: AI Legal Index, 2026

Questions buyers ask

EvenUp vs Filevine: which is better for a personal injury firm?

The AI Legal Index places Filevine in the top two bands on twelve of fifteen capability axes and EvenUp on seven, and most of that gap is contractual. Filevine publishes an indemnity, a cap with a stated floor, an insurance commitment and a data processing agreement. EvenUp publishes no agreement and answers instead on credentials and on depth in a single practice area, with a dated SOC 2 recertification and a HIPAA attestation.

What can you read before signing?

On Filevine, a subscription agreement, a data processing agreement, a security addendum and an AI acceptable use policy, covering indemnity, caps and carve outs, uptime credits, insurance, retention and destruction, subprocessor notice and objection, breach notification and audit rights. On EvenUp, a trust centre offering documentation on request and no published customer agreement, so the allocation of risk is negotiated rather than read. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Who checks the demand before it goes out?

EvenUp sells the answer as a tier, with an expert reviewed option where its own team quality checks the demand before delivery and an instant tier where nobody does. Filevine puts the duty on the subscriber in the contract, requiring independent confirmation of citations and legal conclusions before relying on output or sharing it with any third party including a client or a judicial body, which names the audience most vendors leave out. Neither publishes what its reviewers check or against what standard. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

What happens to the medical records?

EvenUp publishes an independently conducted HIPAA compliance assessment and attestation covering safeguards for protected health information, and correctly notes that HIPAA has no formal certification. Filevine states HIPAA and CJIS compliance among a broader set including SOC 2 Type II and SOC 3, and its data processing agreement governs retention, destruction and subprocessors. Neither states whether medical records or generated chronologies are used to train or improve models, though Filevine bars its third party providers from doing so. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

What do EvenUp and Filevine both leave unpublished?

Neither publishes a price or a unit of charge, so a firm cannot tell what a demand package costs, which matters in contingency practice because case costs are advanced against a claimant's recovery. Neither names the model behind the drafting. And neither publishes an accuracy measurement: EvenUp's chronology and valuation figures circulate without methodology, and Filevine publishes grounding claims across a dozen products with no test set or error rate behind any of them. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Disclosure

Filevine's agreement discloses two things about its AI that most vendors leave unsaid: that output may reflect biases present in training data, and that substantially similar inputs may produce different output. Its AI principles page separately describes its AI as proprietary while the agreement describes models provided by third party AI providers, and nothing published reconciles the two. On EvenUp, no customer agreement was located, so no liability position, warranty, service level or training commitment is readable before signing, and its central technical claim is a proprietary engine trained on a large personal injury dataset with nothing published stating where that dataset came from or whether customer matters continue to feed it. Its case valuations are generated from a repository of past settlements, and no evaluation of that valuation output is published. EvenUp was verified on 29 August 2026 and Filevine on 31 August 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 2, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746