Flank vs Ruli: how they compare in 2026
Flank and Ruli both sell AI to enterprise in house legal teams for high volume contract review, drafting and business questions. Ruli sits in the top two bands on twelve of fifteen axes and Flank on eleven of fifteen, identical on nine. Flank's lead is supervision of agents that act. The legal team sets approval thresholds by matter type, counterparty and risk, reviews flagged work in a queue that shows the agent's reasoning, and its AI management system holds ISO 42001 certification. Its data processing agreement names OpenAI, Anthropic, Google and Azure, with a dedicated tenant in the customer's chosen region. Ruli's lead is in what its answers rest on and what its terms say about them. Research answers cite primary sources across US, EU and UK law, and its terms state that outputs are not legal advice. Its terms also keep customer data out of training unless the customer opts in, and then only with identifiers removed. Flank publishes no customer agreement, so its liability position cannot be read.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The agents are the product. Every function the home page sells, intake and routing, drafting, redlining, negotiation rounds, question answering and the Flank Record contract estate, is described as agent execution against the customer's templates and playbooks, and the vendor's own framing distinguishes itself from assistants and Word plug-ins on exactly that ground: tools make lawyers faster, Flank delivers the outcome. Remove the models and there is no workflow system, document repository or template library left to sell; Flank Record is itself maintained by agents rather than being a CLM the agents sit on. The company's origin as Legal OS is recorded in the privacy policy as the legal entity name only, and nothing on the current estate describes a pre-model product surviving underneath.
The models are the product. Research answers, memo drafting, playbook generation, clause-by-clause redlining in Word and Google Docs, issue spotting, extraction across hundreds of contracts and regulatory monitoring filtered to the company's risk profile are all model work. Without them, what remains is storage for playbooks and documents. Verified 22 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted without measurement. The FAQ answers the question whether output can be trusted with a yes and then describes the mechanism, that every agent is trained by the customer's team on its own knowledge and preferences and that every interaction can be tracked for accuracy and improvement, and the home page says every output is grounded in how the team actually works rather than in generic legal reasoning. No accuracy figure, test set, error rate or evaluation is published anywhere located. Two limbs of the band do not apply to this product and are not held against it: the agents draft and review contracts against customer templates and playbooks rather than retrieving primary law, so grounding to primary authority and citation status checking are not functions the product performs. What the band does ask of a contract agent, a measured statement of how often its redlines or drafts are wrong, is not published. Home page, FAQ, use cases page and the vendor's insights hub checked 6 September 2026.
Answers cite their sources and the limits are stated. The Assistant page says every research result includes citations so users can verify accuracy, with primary source citations across US, EU and UK federal and state law and the team's own knowledge base, and the Word extension's Assistant answers with citations. The Platform Terms of Service, last modified 2 February 2026, warn that outputs may be incomplete, inaccurate or outdated and may not reflect the most current law. No accuracy figures, test set or error rate are published. Verified 22 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
All four limbs are published on the home page and its FAQ. Modes: the legal team chooses which tasks agents handle and whether a given class runs unattended or lands in review, and the vendor states plainly that complex or high-risk requests are escalated while everything else is handled. Constraints: approval thresholds are set by matter type, counterparty and risk, alongside escalation rules and risk tolerances, and agents request approval when the rules require it. Review surface: supervised requests land in a supervision queue with flagged items and the agent's reasoning, where a lawyer approves, adjusts or escalates, and the customer chooses who sits behind the queue. Route back: every decision, edit and negotiation point is logged, corrections feed back into the agent so that Tuesday's fix improves Wednesday's output, and the FAQ states the customer's team retains final authority for outcomes. The threshold at which the system acts alone is therefore a customer setting rather than a vendor default, and the vendor says so. Home page, product FAQ and use cases page read 6 September 2026.
Review is placed on the user in writing, with real surfaces to do it. The Platform Terms make the user solely responsible for reviewing outputs and require independent judgement; in Word and Google Docs, playbook edits arrive as tracked changes to accept or reject, and every flagged issue carries a pass, partial or fail status so the reviewer can prioritise. No threshold, categorical limit on use without review, or account of what happens after a wrong output is published. Verified 22 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers without figures, and figures without named customers, which is the B shape exactly. Simmons & Simmons is named with a quote attributed to a partner, Lucy Shurwood, stating that agents autonomously handle drafting, review and negotiation of NDAs, DPAs, service agreements and IMAs and are live for the firm's teams and clients, linked to the firm's own partnership announcement; Perk is named with a quote attributed by first name only. Axel Springer, Financial Times, Bolt, DeepL and Accor appear as logos with no attached statement. The figures sit elsewhere and unattributed: the use cases page states five minutes of legal time instead of forty-five on an NDA and a sixty per cent cut in outside counsel spend from keeping routine work in-house, with no customer, date or method attached to either. Nothing joins a named customer to a measured change. Home page, use cases page and the Simmons & Simmons partnership link checked 6 September 2026.
Named customers, with results stated as testimony rather than measured. The customers page carries stories from Sequoia, MasterClass, Newsweek, Kandji, Groq, Matic, Worksport and Slingshot Aerospace, with named legal leaders quoted. The figures in them are self-reported: a general counsel's estimate of 25 to 30 hours saved a month, a claim that MasterClass's lean team now covers twice the function, and a goal, not a result, that 75 per cent of Sequoia's reviewed contracts will run through the redlining tool. The stories carry no dates and no method. Verified 22 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Four of the five limbs are met in writing a buyer can read before signing, and the fifth is absent. No training on client data is stated on the home page and the security page. Segregation is documented at the level an in-house buyer requires: a dedicated tenant for every customer, on GCP or Azure, in the customer's chosen region, with role-based access and single sign-on. The position on third-party model providers is explicit and unusually complete, with OpenAI, Anthropic, Google Cloud and Azure OpenAI named in the DPA's sub-processor clause with executed standard contractual clauses recorded against three of them, and the security page stating zero data retention clauses with all LLM providers. Retention and deletion are stated in the DPA, deletion on termination and on instruction, though no retention period is given anywhere. What is missing is the limb this axis exists for: nothing on any surface addresses privilege or work product handling directly, for a product that drafts and negotiates on the customer's behalf. Under the standing reading of this band that limb is required for A and a strong confidentiality regime does not stand in for it. Home page, security page, trust centre, DPA and product privacy policy read 6 September 2026.
The published agreement carries real commitments. The Platform Terms state that Ruli does not use customer data to train its models by default, that training on de-identified data happens only if the customer opts in, and that customer data is never shared with third-party AI providers for training; customers keep ownership of their data; and the confidentiality clause permits disclosure required by law only with notice where legally permitted. The home page promises strict isolation of each customer's data, and the Privacy Notice, last updated 12 August 2026, describes Ruli as the processor of enterprise workspace content. Nothing addresses privilege or work product, or separation between matters within a customer. Verified 22 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
The intended audience is clear and the advice line is not drawn. The estate addresses enterprise in-house legal teams throughout and describes the agents as working like paralegals under the team's supervision, and the FAQ states that the customer's team retains final authority for outcomes and that agents absorb repeatable work rather than replacing lawyers. Those are statements about supervision. What is absent is any position on advice versus tooling for the surface where it matters most: the agents answer recurring legal and compliance questions directly to HR, procurement and other business teams through email and chat, and nothing located tells those users that an agent's answer is not legal advice or is subject to lawyer review, nor names any jurisdiction limit, although the insights hub describes agents applying jurisdiction-specific clauses. No terms of service or acceptable use policy is published in which a disclaimer could sit. Home page, FAQ, use cases, insights hub, DPA and both privacy policies checked 6 September 2026; no ethics or disclaimer page exists in the site inventory.
A product-scoped disclaimer with a review duty attached. The Platform Terms state that the services and outputs are for general guidance and workflow assistance, do not constitute legal advice or professional counsel, and create no attorney-client or fiduciary relationship, and they require users to review outputs and use independent judgement. The terms also admit individual consumer accounts, including users aged 13 to 17 with a parent's consent, without saying how the product's legal output should be treated for people who are not lawyers. No ethics obligations or jurisdiction limits are named. Verified 22 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A published, independently audited governance framework short of testing results or a named owner, which is the B band and the same position the index records for Corlytics and Ontra. The trust centre carries an ISO 42001 certification with certificate number AIMS-LE-103025 and an A-LIGN badge, stated to cover the organisation and described as an artificial intelligence management system governing legal, safety and fairness considerations in the development and deployment of the AI features. A document titled How Flank uses LLMs FAQ, described as covering data handling, prompt-injection controls, training assurances and ethical usage guidelines, exists on the trust centre behind an access request and was not requested. No accountable owner is named, no pre-release testing regime is described, and nothing is published about uneven output across contract types, counterparties or business users. Trust centre and security page read 6 September 2026.
Checked the home page, the product and customer pages, the Platform Terms, the Privacy Notice and the Security Policy on 22 September 2026. No AI governance framework, accountable owner, testing before release or bias finding was located. The Platform Terms warn that AI systems may produce unpredictable or biased results, which is a disclaimer rather than a governance position. Verified 22 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Four of the five limbs are published with the specificity the A band asks for, and retention is the one that falls short. Deletion: the DPA commits to secure deletion after termination absent a retention obligation, to correction or deletion on the customer's instruction, and to surrender or deletion on request. Access control: least-privilege access to customer data, restricted production access, unique IDs and periodic access reviews are listed as live controls on the Secureframe-monitored trust centre, with encryption at rest and in transit. Sub-processors: six named in DPA clause 9.3 with locations and, for Azure OpenAI, eight named regions, with written notice before any change and a two-week objection window. Incident practice: DPA clause 10 commits to written notification within 24 hours of a personal data breach with the categories, approximate numbers and mitigation described. Retention: the product privacy policy of 17 March 2026 states data is kept only as long as necessary and names no period, and its own update banner claims that revision added specific data retention periods, which the document does not contain. The home page's zero data retention claim is resolved by the security page as zero-retention clauses with the LLM providers, not a statement about Flank's own storage, and Flank Record is retention by design. DPA, product privacy policy, security page and trust centre read 6 September 2026.
Most of the ground is published in reviewable form. The Platform Terms say most data is deleted within 30 days of a user deleting it and backups within 90 days; the Security Policy describes AWS hosting with all databases in the United States, encryption at rest and in transit, least-privilege access with quarterly access reviews, single sign-on and two-factor authentication where available, and a subprocessor table naming AWS, DocuSign, Google, Microsoft Azure, OpenAI, Pinecone and others with their locations. The incident limb is thin: a single statement of a process with escalation, mitigation and communication, no commitment to notify customers of a breach, and the Security Policy was last updated on 13 March 2025. Verified 22 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Nothing published on who bears the loss when an agent's draft, redline or negotiation position is wrong. The principal customer agreement, which the DPA refers to as the Agreement between the Customer and Flank, is not published on any surface, and the site footer's legal set is the DPA, an Impressum and two privacy policies; no terms of service, master subscription agreement or acceptable use policy exists in the page inventory. The DPA itself carries no indemnity, liability cap, warranty on output or insurance position, its obligations running to data protection alone. The trust centre lists cyber insurance as a procured control, which concerns the vendor's own loss rather than any recourse a customer can invoke. The exposure is concrete for this product, since agents send finished NDAs and negotiated positions to counterparties under the customer's supervision rules, and nothing states whether Flank stands behind an agent acting within the thresholds the customer set. Home page, footer inventory, DPA, both privacy policies and trust centre checked 6 September 2026; the unpublished principal agreement is the rebuttal route.
Liability is handled only by standard clauses that leave the risk of output with the customer. The Platform Terms provide the services and outputs as is, without warranties, cap Ruli's total liability at the greater of $100 or the fees paid in the preceding 12 months, and require the customer to indemnify Ruli, with no indemnity running the other way. Disputes go to individual arbitration under Texas law. Verified 22 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Named integrations with the delivery mechanism described, short of what each connection moves. The home page names Outlook, Teams, Slack, Jira, Salesforce and CLMs generically, and states that requests arrive through the customer's existing Outlook inbox or intranet portal and that agents work where the business already works without custom integration projects; the FAQ adds custom URLs and the legal systems the customer already uses, and says many deployments start without bespoke integrations with deeper connections following. Flank Record captures executed contracts at signature, which implies a signature-tool connection that is not named. The email channel is described well enough to understand, since the agent reads the inbox, identifies the request and replies with the draft attached. No documentation, help centre or developer index was located describing what syncs with a CLM or Salesforce, in which direction, or what a customer must configure; the Implementation page in the product navigation was not opened. Home page, FAQ and use cases page checked 6 September 2026.
Real integrations with some depth described. The extension works inside Microsoft Word, listed on Microsoft Marketplace, and Google Docs, applying playbook edits as tracked changes and generating issues lists in place; the Privacy Notice describes a Google Workspace integration with scoped access to files; and DocuSign appears among the subprocessors. No integration with a document management, matter or contract lifecycle system is named, and no integration documentation is published. Verified 22 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Tenancy, region and the processing location as distinct from storage are all published. The security page states that customer data is contained within the customer's chosen region in a dedicated tenant on GCP or Azure, and the home page repeats dedicated regional tenants for every customer. DPA clause 8.1 forbids the processor and its sub-processors from transferring or processing personal data outside the EEA and UK without the controller's prior written consent, with the transfer mechanism to be identified and any change notified. Clause 9.3 separates hosting from model processing explicitly: Google Cloud Platform is listed as EU for hosting and global for LLMs, MongoDB as EU, and Azure OpenAI services with eight named regions, Amsterdam, Canada East, East US 2, Japan East, France Central, Sweden Central, Switzerland North and UK South, with OpenAI and Anthropic in the USA under executed standard contractual clauses. That is the where-processing-happens limb stated in terms. No tiers are published, so the what-changes-between-tiers limb has nothing to bite on and is not held against the record. Security page, home page and DPA read 6 September 2026.
Cloud, in one stated region. The Security Policy says all services are hosted on Amazon Web Services with all databases in the United States, the Privacy Notice says personal information is hosted in the United States, the home page describes each customer's data as kept separate, and the subprocessor table places the AI model provider in the United States. No residency option, private deployment or tenancy choice is offered. Verified 22 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real and stated, and the evidence sits behind a request whose access tier the portal does not state. The Secureframe-hosted trust centre at trust.flank.ai renders fully and carries SOC 2 Type 2, ISO 42001 with certificate number AIMS-LE-103025 and an A-LIGN badge, GDPR and CCPA, together with a live control monitor listing an annual third-party penetration test, encryption at rest, cyber insurance and vendor SOC 2 reviews. The SOC 2 Type 2 report and the ISO 42001 certificate are each behind a Request button, and a Request all documents control covers the set; nothing on the page states whether the request fulfils on an email address or an NDA click-through or routes to a sales conversation, and no request was submitted. No SOC 2 coverage period, scope or auditor is stated on the open page. Under the standing rule for an unstated access tier the lower tier is graded and this note says why: a named standard with a route to the report, short of dates, scope and evidence reachable without asking. Trust centre and security page read 6 September 2026.
A named attestation without a report route. The home page and Security Policy state that Ruli is SOC 2 Type 2 certified, with independently audited controls for security, availability and confidentiality. No auditor, report period or scope is given, no trust centre is published, and no way to obtain the report is described. Verified 22 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Providers, locations and change notice are all published; the models themselves are not named, which holds this at the top of B. DPA clause 9.3 names OpenAI and Anthropic as LLM providers in the USA under executed standard contractual clauses, Google Cloud Platform as global for LLMs, and Microsoft Azure OpenAI services across eight named regions; the trust centre repeats the same six sub-processors with Anthropic, OpenAI, Google Cloud and Azure each marked LLMs. Clause 9.2 commits to written notice with a reasonable period before any sub-processor is added or replaced, with a two-week objection window, and clause 12.4 adds notification by publication where the DPA is updated. The security page states zero data retention clauses with all LLM providers. What no surface states is which model from each provider runs which task, and under the standing reading of this band naming the provider does not satisfy the separate limb that the models underneath are named. DPA, trust centre and security page read 6 September 2026.
The provider is named. The Security Policy's subprocessor table lists OpenAI for AI models through the OpenAI API platform, located in the United States, alongside Microsoft Azure. The specific models and versions are not named, and no commitment to notify customers when the models change is published. Verified 22 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level. No pricing page appears in the navigation or the footer, the FAQ does not address cost, and the only commercial call to action on the estate is a fifteen-minute demo booking. Nothing states the unit of charge, whether the product is priced per agent, per request, per seat or per workflow, and no tier names or feature splits are published from which the shape could be inferred. Home page, FAQ, use cases page, product navigation and footer checked 6 September 2026; the vendor's insights hub was searched and carries buyer guidance on pricing models generally without stating Flank's own.
Checked the home page, the product pages, the Platform Terms and the Microsoft Marketplace listing on 22 September 2026. No price, tier or unit of charge is published; the terms mention monthly and annual plans and trials in general terms, and the Marketplace listing says a paid subscription is required and points to a demo. Verified 22 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment and work type are described with substance, and the boundaries are left open. The buyer is stated as enterprise in-house legal, with the security page adding enterprises, banks and governments, and the customer list showing large corporates, a media group, a bank-adjacent fintech and one law firm, Simmons & Simmons, deploying agents for its own teams and clients. The work covered is stated concretely: NDAs, DPAs, service agreements, IMAs, statements of work, MSA redlines, procurement reviews, infosec questionnaires, employment questions from HR and legal FAQs from the business, with the FAQ naming NDAs and low-risk vendor documents as the usual first use case before expansion into sales and procurement playbooks. What is not stated is where the product stops: no practice area, contract type, jurisdiction or firm size is named as unsupported, and the escalation of complex or high-risk requests describes a control rather than a coverage limit. Home page, FAQ, use cases and security page checked 6 September 2026.
The buyer and the work are clear: in-house legal teams from fast-growing technology companies to the Fortune 500, handling regulatory research, employment and privacy questions, contract review and redlining, due diligence and regulatory monitoring across US, EU and UK law. The Microsoft Marketplace listing also names law firms and individual legal professionals, and the terms allow consumer accounts, without saying how the product differs for them. What it does not cover is not stated. Verified 22 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Public material states that customer data is never used for training, on the home page and the security page, and no matching term was located in the published agreement. The DPA, last updated March 2026, confines processing to the customer's documented instructions and prohibits staff from processing beyond them, which excludes training as a matter of construction but never names it; the product privacy policy's only improvement basis is anonymized usage data under legitimate interests, which is telemetry rather than customer content.
The principal customer agreement the DPA refers to is not published, so a buyer cannot see whether the marketing commitment appears in it. A How Flank uses LLMs FAQ described as carrying training assurances sits on the trust center behind an access request and was not requested. Surfaces checked 6 September 2026.
The Platform Terms of Service, last modified 2 February 2026, exclude customer data from training by default. If a customer opts in through an express mechanism, Ruli may train on de-identified data only; the customer can opt out at any time, though training already done cannot be reversed, and customer data is never shared with third-party AI providers for training. Ruli may also use de-identified, aggregated analytics to improve the service.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is acknowledged with no stated period. The product privacy policy of 17 March 2026 states data is retained only as long as necessary for its purposes or as required by law and then deleted or anonymized, with earlier deletion available on request under the DPA; the DPA commits to deletion after termination and on instruction. The home page's zero data retention claim is clarified on the security page as zero data retention clauses with all LLM providers, which is a provider-layer commitment rather than a statement of Flank's own retention, and Flank Record keeps an always-current record of every executed contract by design.
The privacy policy's own update banner states the March 2026 revision added specific data retention periods, and section 7 of that document contains none. Surfaces checked 6 September 2026.
Users can delete content or their account, after which the Platform Terms say most data is deleted within 30 days and backups are typically removed within 90 days, with some information kept for legal compliance, disputes and enforcement. A setting that retains nothing is not described.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains and documents its own separation model at the tenant level, which is the level an in-house buyer requires: the security page states customer data is contained in a dedicated tenant on GCP or Azure in the customer's chosen region, the home page lists role-based access, single sign-on with all major identity providers and audit logs as included controls, and the trust center's live monitor lists least-privilege access to customer data.
The customer keeps the role model aligned. Nothing addresses matter-level walls within a tenant, which the product's in-house buyer does not ordinarily need and which a law firm deploying it, as Simmons & Simmons does, would. Surfaces checked 6 September 2026.
Checked the home page, the product pages, the Platform Terms, the Privacy Notice and the Security Policy on 22 September 2026. Each customer's data is described as kept separate from other customers', but nothing addresses walls or permissions between matters or users within a customer.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
The published DPA commits to notice in two places. Clause 12.1 requires Flank to inform the customer without undue delay if personal data is endangered by seizure or attachment or by other measures of third parties, and clause 3.1 requires it to inform the customer before any processing that national or European law obliges it to perform outside the customer's instructions, insofar as legally permissible. No transparency report is published.
The product privacy policy runs the other way, stating only that data may be disclosed in response to valid requests from public authorities with no mention of notice, and under the standing rule the agreement governs over the policy. Surfaces checked 6 September 2026.
The confidentiality clause of the Platform Terms allows confidential information to be disclosed when required by law only with notice where the law permits. The Privacy Notice adds that information may be disclosed to comply with valid legal process.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies a legal corpus behind the product's answers, and the product is not built on one: agents draft, review and answer against the customer's own templates, playbooks and policies, which the home page describes as grounding every output in how the team works rather than in generic legal reasoning. No primary law source, license or update cadence is published. Home page, FAQ, product pages and insights hub checked 6 September 2026.
The research corpus is described by jurisdiction: US, EU and UK federal and state laws and regulations, with rest-of-world trusted sources cited and primary source citations. No database, publisher or license behind that coverage is named.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history, and the product does not retrieve or cite primary law; its output is contract drafts, redlines, negotiation positions and answers to business teams from the customer's own material. Recorded as the honest value for a product with no citator function. Surfaces checked 6 September 2026.
Research results include citations so the user can verify them, and the Platform Terms warn that outputs may not reflect the most current law and require independent judgment. No citator or check for whether cited authority remains good law is described; the Monitor feature tracks regulatory change for the company rather than checking cited authority.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
An explicit path for not completing a request is described in public materials: the home page states that agents apply the customer's escalation rules, approval thresholds and risk tolerances and flag anything outside bounds, that complex or high-risk requests are escalated rather than handled, and that supervised requests land in a review queue with the flagged items and the agent's reasoning. The FAQ adds that agents request approval when rules require it.
The behavior is described rather than demonstrated, since no published evaluation or product recording shows the escalation firing, and nothing states what the agent does when the customer's playbook gives it no answer as distinct from when a rule tells it to stop. Surfaces checked 6 September 2026.
Checked the home page, the product pages and the Platform Terms on 22 September 2026. Flagged contract issues carry a pass, partial or fail status, but no confidence indicator or path in which the Assistant declines a question it cannot answer is described.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record naming Flank or Legal OS GmbH was located as of 6 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on the product name and the corporate name, together with a general search for court findings naming the product. This is a statement about the public record and not a finding about the product; the product drafts contracts rather than court filings, so the exposure this signal tracks is remote for it.
Searched the AI Hallucination Cases database maintained by Damien Charlotin on 22 September 2026 for Ruli; the cases returned matched only on words such as ruling, and none names the product. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance. The estate makes no reference to any ethics opinion, bar rule or professional responsibility framework in any jurisdiction, and the vendor's professional-responsibility positioning is confined to statements that the customer's team retains final authority and that agents do not replace lawyers. The company is German and its named customers span the UK, Germany and the wider EU, so the reference points would differ from the ABA opinion this index uses as a baseline, but none of any jurisdiction is named. Home page, FAQ, insights hub, DPA and privacy policies checked 6 September 2026.
The Platform Terms state that the services and outputs do not constitute legal advice or professional counsel and create no attorney-client relationship, and tell users to consult qualified professionals as appropriate. No bar or ethics opinion is named on any surface read.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Time and cost claims are published and nothing addresses the bill. The use cases page states five minutes of legal time instead of forty-five on an NDA and a sixty percent cut in outside counsel spend from keeping routine work in-house, and the home page's proposition is that routine work leaves the desk and does not come back. No per-matter record of AI-assisted work framed for fee purposes is described, although every agent action is logged, and no guidance on fee or disclosure treatment is published.
The primary buyer is an in-house team that bills no client, so the question lands obliquely there, but a law firm is a named customer: Simmons & Simmons states that agents are live and delivering for its teams and its clients, which places the product inside a lawyer-to-client fee relationship for that deployment, and nothing published addresses how that firm's clients are told or charged. Surfaces checked 6 September 2026.
The product is built for in-house legal teams, whose work bills no client, and its savings claims are aimed at the buyer's own spend: a general counsel's estimate of 25 to 30 hours saved a month and a customer story on replacing outside counsel for research. The Microsoft Marketplace listing also names law firms as users, and nothing addresses how a firm would bill or disclose work done with the product.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current sub-processor and model provider list is published and the client-facing disclosure material is a published DPA, which together meet the top value. DPA clause 9.3 names Google Cloud Platform, MongoDB, Mailgun, Azure OpenAI services with eight regions, OpenAI and Anthropic, with executed standard contractual clauses recorded against three and a two-week objection window on changes; the trust center repeats the same six with each LLM provider marked as such.
The DPA is published in full without an agreement in place and is drafted to be forwarded, and the security page adds that zero data retention clauses are in place with all LLM providers. A firm can therefore tell a client which model providers see its content and on what transfer basis without a bespoke negotiation. Surfaces checked 6 September 2026.
The Security Policy publishes a subprocessor table with each provider's service and data center location, including Amazon Web Services for hosting, OpenAI for AI models, Microsoft Azure, Google Workspace, DocuSign and Pinecone. No client-facing disclosure pack on AI use is published.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of a disclosure record are available and no document-level export is described. The home page states that every decision, edit and negotiation point is logged and that the supervision queue shows flagged items with the agent's reasoning, and the FAQ says every interaction can be tracked; that is a per-matter record of what the agent did and what a human approved. Nothing states that the record can be exported per document, and it does not cover the model used, since the models are not named anywhere on the estate. Court disclosure is remote for a contract agent and the vendor does not address it. Surfaces checked 6 September 2026.
Checked the home page, the product pages and the Platform Terms on 22 September 2026. No record of AI involvement in a document, export of that record or disclosure guidance is described.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Commercial Transparency
Which one fits
Choose Flank if
- You want agents to finish routine work under rules you set. Flank's agents draft NDAs and statements of work, redline vendor paper, run negotiation rounds and answer business questions, with approval thresholds set by matter type, counterparty and risk, and complex or high risk requests escalated.
- Your business sends legal requests by email and chat. Flank takes requests through Outlook, Teams, Slack and an intranet portal, so business users never open a new tool, and Flank Record captures executed contracts at signature for plain language queries.
- You need data residency and a published processor list. Flank runs each customer in a dedicated tenant on Google Cloud or Azure in a chosen region, and its data processing agreement names each model provider with its processing location, 24 hour breach notice and two weeks to object to a new subprocessor.
Choose Ruli if
- You want research answers you can check. Ruli's Assistant answers questions across US, EU and UK laws and regulations and your own playbooks and policies, with citations to the primary sources, and drafts memos from them.
- You review contracts in Word or Google Docs. Ruli's extension checks agreements against your playbooks, marks each issue pass, partial or fail, and applies preferred or fallback language as tracked changes, while Tabular Review extracts clauses across hundreds of contracts.
- You want the training position and the advice line in the terms. Ruli's platform terms exclude customer data from training by default, allow training only on data with identifiers removed if the customer opts in, and state that outputs are not legal advice.
In summary
Flank
Flank, from Legal OS GmbH of Berlin, deploys supervised AI agents that take over high volume work for enterprise in house legal teams: triaging business requests, drafting NDAs and statements of work from the team's templates, redlining vendor paper against its playbook, running negotiation rounds and answering recurring questions, through Outlook, Teams, Slack and an intranet portal. The AI Legal Index grades it in the top two bands on eleven of fifteen capability axes, with A grades on AI centrality, autonomy and oversight, and deployment. It holds ISO 42001 and SOC 2 Type 2 and names Simmons & Simmons, Axel Springer and the Financial Times among customers. As of 6 September 2026 the index located no published customer agreement, accuracy measure or price.
Ruli
Ruli, from Ruli, Inc. of Austin, Texas, is an AI legal platform for in house legal teams. Its Assistant answers research questions across US, EU and UK law and the team's own playbooks with citations and drafts memos, a Word and Google Docs extension reviews and redlines contracts against playbooks, Tabular Review extracts terms across large contract sets, and Monitor tracks regulatory change. The AI Legal Index grades it in the top two bands on twelve of fifteen capability axes, with an A on AI centrality. Its terms exclude customer data from training by default and state that outputs are not legal advice, and it names Sequoia, MasterClass and Newsweek among customers. As of 22 September 2026 the index located no AI governance position or price.
Questions buyers ask
Flank vs Ruli: which is better for an in house legal team?
The grid barely separates them: Ruli sits in the top two bands on twelve of fifteen AI Legal Index capability axes and Flank on eleven of fifteen, identical on nine. Flank publishes a fuller control structure for agents that act on their own, plus ISO 42001 and regional tenancy. Ruli publishes cited research across three legal systems and clearer terms on advice and training. Teams wanting agents to complete work end to end have more to read from Flank.
How does Flank keep its agents under control?
The legal team chooses which tasks agents handle, sets approval thresholds by matter type, counterparty and risk, and reviews supervised work in a queue that shows flagged items with the agent's reasoning. Complex or high risk requests are escalated rather than completed. Every decision, edit and negotiation point is logged, and corrections feed back into the agent. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Does Ruli train AI on customer data?
Not by default. Ruli's platform terms, last modified 2 February 2026, state that customer data is not used to train its models unless the customer opts in, and then only with identifiers removed, that training already done cannot be reversed after an opt out, and that customer data is never shared with third party AI providers for training. Flank states on its website that it never trains on customer data. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Which AI models do Flank and Ruli use?
Flank's data processing agreement names OpenAI and Anthropic in the United States, Google Cloud, and Microsoft Azure OpenAI across eight named regions, with written notice and a two week objection window before any change. Ruli's security policy names OpenAI through its API platform in the United States. Neither names the specific models behind each task. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What do Flank and Ruli both leave unpublished?
The price and any measure of accuracy. Neither publishes a price, tier or unit of charge, and neither publishes an error rate or evaluation for its drafting, redlining or answers. Neither addresses privilege or work product for the material its AI handles, and neither names bar or regulator guidance on AI. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Three readings to weigh. Flank's agents answer legal and compliance questions directly to business teams, and nothing published tells those users the answers are not legal advice. Ruli's terms cap its liability at the greater of $100 or a year's fees and run the only indemnity from the customer to Ruli; that is a published term. Flank's principal customer agreement is not published, and its privacy policy's claim to add retention periods is not borne out in the text. Flank was verified on 6 September 2026 and Ruli on 22 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.