HighQ vs Lupl: how they compare in 2026

H
HighQ profile
L
Lupl profile
Last verifiedOctober 9, 2026

HighQ and Lupl both give law firms and legal departments a shared place to run matters with clients and colleagues. Both belong to larger groups, HighQ to Thomson Reuters and Lupl to Elevate since August 2026. Lupl is built around tasks, with matters broken into tasks with owners and deadlines, templates, workflow automations and list, calendar and board views. It connects to Microsoft Teams, Outlook and the firm's document management system. Its assistant drafts summaries, reports and client updates, and its agents act as matter members under a named human supervisor. HighQ is built around sites, files and portals, with virtual data rooms, iSheets, document automation and dashboards. Its HighQ AI engine classifies documents and extracts clauses, and CoCounsel licenses add document review on GPT 4.1, a client facing question panel and drafting in Word. Both run generative AI calls in the United States with no retention at the model provider, and both commit to breach notice within 72 hours. HighQ's UK government listing prices it at £199 per user a month, while Lupl quotes per user.

At a glance

Category
HighQLegal Ops & Spend
LuplLegal Ops & Spend
Founded
HighQNot published
LuplNot published
Headquarters
HighQToronto, Ontario, Canada
LuplNot published
Last verified
HighQOct 9, 2026
LuplOct 9, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

HighQ
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

HighQ is a collaboration and work management platform with AI layered on. The HighQ AI engine in the AI Hub classifies documents by type or language and extracts fields such as parties, dates, consideration and renewal terms. It also pulls clauses on governing law, jurisdiction, assignment, change of control, force majeure, indemnification and limitation of liability, with no per document cost for low volumes. Generative features arrived with CoCounsel in October 2025, through Document Insights, a prompt library and Self service Q&A, followed by CoCounsel Drafting, each needing CoCounsel licenses or a paid add on. Document Insights is limited to the Premium tier. The AI Hub also connects Kira and Thomson Reuters Document Intelligence for customers with their own accounts. Portals, data rooms, file sharing, iSheets, workflow, document automation, project management and dashboards all run without AI.

Lupl
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

Lupl is task and matter management first. Its features page describes matters broken into tasks with assignments and deadlines in list, calendar and board views. Templates, forms, workflow automations, dashboards, matter budgets and an audit trail complete it, and none of that depends on a model. AI sits on top in two forms. The assistant generates summaries, reports and drafts for client updates from natural language. Agents act as matter members that respond to events, propose actions and complete work within boundaries the firm sets, with use cases for intake and triage, document automation and email handling. Agents can be assigned or mentioned in comments, added to workflows or embedded in playbooks, and work in parallel with the team. Firms build agents in natural language, defining instructions, knowledge, skills and guardrails, and agents reach other systems through APIs or MCP. Elevate's release calls Lupl AI native and says it works natively with Claude, Harvey and Copilot. Without the AI, a firm still has the matter plan, task list and workflows it bought Lupl for.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

HighQ
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Answers trace to the customer's own files. Document Insights writes answers into iSheet columns and stores the detailed text CoCounsel returns behind each answer, with references to the passage in the file. Yes or no extraction fields record whether a field exists in the document, and clause fields point the user to the original text. Self service Q&A draws only on the documents in the top level folder an administrator selects. No accuracy figure, error rate or evaluation accompanies HighQ AI or CoCounsel inside HighQ, and HighQ AI supports English and German only. The Thomson Reuters General Terms say the services are not warranted free of inaccuracies or errors.

Lupl
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Lupl's AI works from the matter it sits in. Agents are matter members that see the matter's structure, tasks, documents and prior decisions, so users do not paste background into prompts. The assistant uses natural language to generate summaries, reports and drafts for client updates, and agents extract details from emails and client instructions and generate drafts through the firm's document automation service. Agents tell users when work is ready for review, and supervisors approve, revise or override it. Lupl does not say whether a summary or draft links back to the tasks, documents or notes it came from, and gives no accuracy figure. The terms disclaim any representation or guarantee regarding results and provide the service as is. The trust center lists an AI overview and AI feature documents among materials available on request.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

HighQ
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

HighQ AI runs automatically when files land in folders set up for it, or a content administrator sends a file or assigns a template to an engine. Classifiers are trained from the customer's own folder mapping, with at least 50 new files recommended, can be rolled back to earlier versions, and the system administrator is told to review the list of models. Document Insights runs only when a user selects files and prompts, up to ten prompts at a time, and stores the text behind each answer, with no approval step before output is used. Self service Q&A gives clients and other external users AI answers through a proxy user, limited to an administrator's database and to the single CoCounsel skill that answers from it. Questions unrelated to the database get a no relevant information found reply. The Thomson Reuters AI Usage Policy bars legal advice or decisions from AI output unless a licensed professional or someone with the right credentials reviews them. The General Terms make the customer solely responsible for review.

Lupl
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Lupl's agents act inside matters under named human supervision. Every agent has a human supervisor who remains accountable and can review outputs, approve actions or override decisions at any point, and all agent activity is logged for audit. Agents respond to events, propose actions and complete work within boundaries the firm sets, and notify users when work is ready for review. In the document automation use case an agent extracts data from client instructions, generates drafts and assigns them to a person for review. Firms define each agent's instructions, knowledge, skills and guardrails in natural language. Lupl does not list what an agent may never do without approval, such as closing tasks or messaging a client, or what happens when an agent acts wrongly. The firm's own workflow automations are rule based.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

HighQ
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Best Best & Krieger's case study, dated May 2026, reports sites created in a day instead of three to six months. Decisions on requests for proposals take two to three hours instead of three days. The Pascua Yaqui Tribe's January 2026 case study describes an attorney general's office serving 20,000 tribal members that automates about 100 contract types a year in HighQ. Geldards' January 2026 case study carries no figures. Bird & Bird, Dillon Eustace and HelloFresh appear in testimonials without figures. Thomson Reuters said in October 2025 that HighQ has more than one million users, and at its 2019 acquisition HighQ served more than 400 customers, including more than half of the Global 100. None of the figures is tied to an AI feature, and no method is given.

Lupl
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Lupl names law firm customers and development partners without figures for what changed. Its home page shows logos for CMS, Cooley, Rajah & Tann Asia, Dykema, Gorrissen Federspiel, Vieira de Almeida, Wilkinson and Withers under a line saying more than 10,000 lawyers at firms worldwide trust Lupl. Elevate's acquisition release of 19 August 2026 says Lupl was developed with input from CMS, Cooley and Rajah & Tann Asia. Its trust center groups customers under AmLaw 10, UK 50, AmLaw 100 and AmLaw 200 labels. The site has no dated case study, and no time saved, matters managed or adoption figure is tied to a named firm. The calculator on the quote page models savings rather than reporting a customer result. The 10,000 lawyer figure is not dated or broken down.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

HighQ
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Section 3 of the HighQ Product Specific Terms, version 1.6 of July 2026, says the customer exclusively owns its content. Thomson Reuters shall not use that content for any purpose other than performing its obligations. The Legal AI Product Specific Terms of January 2026 bar Thomson Reuters from developing, training or fine tuning generative or foundational models with user prompts, user content or outputs unless agreed separately in writing. The General Terms, lower in the order of precedence, license Thomson Reuters to use input to perform and improve its services. Customers who subscribe to bring your own key hold encryption keys Thomson Reuters cannot access. Inside HighQ, access runs through site groups and folder permissions. CoCounsel databases created from HighQ files are not permissioned the same way and keep copies until the customer deletes them. The terms give privilege, work product and ethical walls no separate treatment.

Lupl
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Lupl's terms bind each party to protect the other's confidential information and require prompt written notice, where legally permissible, before a disclosure the law or a court requires. The customer owns its content and grants Lupl a fully paid, royalty free, perpetual, irrevocable, worldwide, non exclusive and fully sublicensable license. The license lets Lupl use, distribute and publicly display that content to operate and provide the services to the customer and other registered users, and the terms say Lupl does not review customer content. Lupl may use personal data in aggregated or anonymized form to improve its services. Annex III of the data processing addendum notes that data sent to OpenAI for Lupl's AI features is not retained or used to train the model. Users choose the level at which the services restrict access to their content, and agents are matter members that see the matter's documents. Lupl's trust center lists an AI Training Data and Bias document among materials available on request. The terms treat customer content as confidential without separate treatment of privilege or work product.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

HighQ
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

Section 7 of the Thomson Reuters General Terms states that Thomson Reuters is not providing legal advice. It makes the customer solely responsible for the preparation, content, accuracy and review of its work and for decisions made in reliance on the services. The AI Usage Policy of January 2026 bars using AI output for legal advice or decisions unless a licensed professional or someone with the right credentials reviews it. It also bars presenting output as solely human generated. The HighQ terms limit external users to collaborating on services the customer provides to its clients. Self service Q&A puts AI answers in front of clients, and its help pages say nothing about verification or about who answers for those responses. Jurisdiction limits are unstated.

Lupl
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

Lupl's terms say nothing in the Lupl materials constitutes or shall be construed as legal or other professional advice, and they disclaim any guarantee regarding results. The users are lawyers and legal staff at law firms and legal departments. Agents work under a human supervisor who remains accountable and can review outputs, approve actions or override decisions at any point, and agents tell users when work is ready for review. The assistant drafts client updates, real time matter dashboards can be shared with clients and stakeholders, and people outside the firm can be invited at no charge. Lupl's terms and product pages do not address a lawyer's duty to review an AI drafted update before a client sees it. Which jurisdictions' practice the templates and workflows assume is not stated, and the terms are governed by Virginia law.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

HighQ
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

Thomson Reuters' eight data and AI ethics principles include fair treatment of people and human involvement in AI use. Its AI security governance whitepaper, last reviewed December 2025, names a Responsible AI and Data Trust team, an Ethics Advisory Committee and a Model Ethics Committee. It requires business AI models to be registered in a central compliance hub and describes a model risk assessment process. An ISO/IEC 42001 certificate issued by MSECB, valid from August 2026 to March 2028, covers CoCounsel Essentials, including the Core and Drafting skills HighQ calls. It does not name HighQ or the HighQ AI engine. There is no bias test method, testing result or named individual owner.

Lupl
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

Lupl's trust center lists an AI overview, AI feature documentation and a document titled AI Training Data and Bias among the materials a visitor can request through its access process. The agents page sets out how agents are governed in use. Each agent has a human supervisor who remains accountable, supervisors can approve, revise or override agent work, all agent activity is logged, and firms define each agent's guardrails. The open pages have no responsible AI statement, named owner of AI governance, description of testing before release or finding about uneven output. The terms say nothing about AI beyond a general disclaimer of results and the data processing addendum's note on OpenAI training. Elevate's acquisition release calls Lupl AI native without describing controls.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

HighQ
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Thomson Reuters' Data Security Addendum commits to notify a breach without undue delay and within 72 hours. It also commits to destroy data securely on termination and confirm it on request, apart from backup and archival copies kept in the normal course of business. The HighQ terms give 30 days after termination to remove content. The HighQ hosting and security whitepaper of February 2021 keeps database backups on a rolling 30 day basis, with data in backups for a further 30 days after a contract ends. All user and administrator actions are logged, and audit logs are kept at least 12 months. The HighQ subprocessor list, dated June 2020, names only data center operators and predates the move to Azure. Files sent to CoCounsel stay in CoCounsel databases until the customer deletes them.

Lupl
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Lupl's terms attach a data processing addendum with standard contractual clauses, under which the customer is controller and Lupl processor. It commits Lupl to notify the customer of a personal data breach without undue delay and in any event within 72 hours, with details of the breach. Annex III lists subprocessors as at 1 September 2025 with each one's activity and location. They include Microsoft as cloud provider in the EU and the United States, OpenAI for Lupl's AI features in the United States, Expel for security operations, Fireflies.ai for transcription and Twilio for email and WhatsApp. Lupl gives at least five working days' notice of a subprocessor change. At the end of the services Lupl disposes of protected data under the agreement, without a stated period. The home page says data is encrypted in transit and at rest and describes regular penetration testing, access reviews and independent audits. How long matter data is kept during the subscription is not stated.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

HighQ
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

The Thomson Reuters General Terms, version 5.0 of November 2023, which the HighQ terms incorporate, cap liability at the amount payable for the service in the prior 12 months. In the first year the cap is 12 times the average monthly charge. They exclude indirect, incidental, punitive, special and consequential damages and loss of data or profits. Fraud, willful misconduct, intellectual property infringement, the indemnities and payment sit outside the cap. Thomson Reuters defends the customer against third party intellectual property claims about its services, excluding third party portions and combinations. It warrants that properly licensed services materially conform to the documentation, with repair or replacement as the remedy, and otherwise provides them as is. No indemnity covers AI output, the HighQ terms give no warranty on the API, and no insurance is described. Updated General Terms are dated September and October 2026.

Lupl
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

Lupl's terms, with Elevate Services, Inc. as the contracting party since August 2026, Virginia law and arbitration under American Arbitration Association rules, handle liability through a standard limitation clause. Lupl's liability is capped at the fees paid in the twelve months before the claim, with exclusions for gross negligence, intentional misconduct, death and personal injury. The services are provided as is, with no representation, warranty or guarantee regarding results. The indemnity runs from the customer to Lupl, for losses arising from the customer's content, its use of the platform and breaches of the terms. The terms add that Lupl has no responsibility for the deletion or accuracy of content and that customers set the level of access to it. Lupl gives no intellectual property indemnity, insurance statement or remedy for a wrong AI drafted update or an agent's action, so that risk stays with the firm.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

HighQ
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

HighQ connects to SharePoint, eDoc, iManage and NetDocuments for document management, to SeeUnity, and to Kira, Leverton and Eigen for AI extraction. It also connects to Microsoft 365 through an Office add in, Outlook, Google Workspace, DocuSign, Adobe Sign, Workshare, Seclore, Active Directory, SAML single sign on and a SQL database connector. A HighQ app for Microsoft Teams uploads and shares files and sites from Teams, and HighQ Drive syncs files to desktops and mobile devices. CoCounsel Drafting opens HighQ documents in Word and syncs changes back with version control and an audit trail. Premium customers get a read only MCP server for assistants such as Claude, ChatGPT Enterprise, Cursor and Copilot Studio, and the APIs include system level audit logs. The connectors page does not describe what each document management integration moves or in which direction.

Lupl
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Lupl calls itself a bring your own system platform. Every plan includes integrations with Slack, WhatsApp, DocuSign, Litera Compare and the firm's document management system, with automatic saving to it, plus sign in with Google, Microsoft or Apple. The features page brings Teams, Outlook and the document management system into one place and creates matters and tracks time and billing through APIs with the firm's practice management system. Agents connect to other systems through APIs or MCP, and the agents page shows one saving documents to iManage. Elevate's acquisition release says Lupl works natively with Claude, Harvey and Copilot. Lupl names no practice management system, does not describe what each connection moves or what a firm configures, and offers no public API reference for developers.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

HighQ
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

HighQ is moving to a single tenant setup on Microsoft Azure, in migrations that began in 2024 and are due to finish by the fourth quarter of 2026, with no added hosting charge. The Azure regions are not named. The February 2021 hosting whitepaper offered hosting in the United Kingdom, the United Arab Emirates, Jersey and Guernsey, Canada, the United States, Germany and Australia. Data stayed inside the chosen jurisdiction for backup and disaster recovery. For CoCounsel features, users pick the CoCounsel account in the same region as their HighQ system. The CoCounsel Essentials page says model calls to OpenAI GPT and Google Gemini are processed in the United States, with regional hosting in the United Kingdom, Australia and Canada. The MCP server works only on instances already moved to Azure, and Azure uploads are capped at 4GB per request.

Lupl
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Lupl runs on Microsoft Azure. Annex III of its data processing addendum lists Microsoft as cloud provider in the EU and the United States. It lists OpenAI, which runs Lupl's AI features, in the United States, so the AI processing location is stated apart from storage. Providers such as Pendo, Zendesk and Zoho carry EU or United States locations. The addendum incorporates standard contractual clauses for transfers, and the trust center lists the EU and United States Data Privacy Framework among its commitments. Setup usually takes about a day. The pages do not say whether a customer chooses its region, whether infrastructure is shared, or whether single tenant or private deployment is offered. Lupl's named firms span the United States, Europe and Asia, through CMS, Cooley and Rajah & Tann Asia. Users reach Lupl on the web and through iOS, Android and desktop apps.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

HighQ
AA on Security Certifications and Trust CenterCurrent independent attestation with named scope, reachable without a sales call: a trust center carrying reports, dates and the standards actually covered.

Thomson Reuters' ISO/IEC 27001 certificate, issued by MSECB and valid from March 2026 to October 2028, lists HighQ in scope at its London and Sydney sites. HighQ's listing on the UK government G-Cloud marketplace adds a CSA STAR Level 1 self assessment. The Thomson Reuters trust center offers SOC reports and bridge letters through product profiles, and downloading them requires an account. The Azure migration FAQ points to a cloud hosting and security whitepaper on Whistic that also requires a login. The February 2021 hosting whitepaper says a CREST accredited firm runs penetration tests at every major release.

Lupl
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Lupl's trust center shows SOC 2 Type 2 and ISO/IEC 27001:2022 and announces completed SOC 2 Type II and ISO 27001 audits for 2025. A visitor asks for the SOC 2 report, a penetration test report, application penetration testing, product architecture and network and data flow diagrams through a Get access button. The trust center also lists GDPR, CCPA and the EU and United States Data Privacy Framework among its commitments. Lupl's home page describes access reviews and continuous monitoring, and calls the product certified under SOC 2 Type I and II and aligned with ISO 27001 standards, wording that differs from the trust center's certification. The open pages give no auditor or certification body, audit period, scope or certificate date. The terms add Expel, a security operations center provider, among Lupl's subprocessors.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

HighQ
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Document Insights' review skill has run on GPT 4.1 since the third quarter of 2026, replacing GPT 4o, according to HighQ's release notes. The CoCounsel Essentials page says CoCounsel's calls to OpenAI GPT and Google Gemini run in the United States through zero retention API calls, and HighQ's generative features run CoCounsel skills. The Legal AI Product Specific Terms say services may be powered by third party AI models. The HighQ AI engine is described only as an engine developed for classification, and Kira and Thomson Reuters Document Intelligence connect through the customer's own accounts. Model changes surface in release notes, with no commitment to notify customers before a model or provider changes.

Lupl
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Lupl names OpenAI as the provider behind its AI features. Annex III of the data processing addendum lists OpenAI for Lupl's AI features with processing in the United States. It notes that data is not retained or used to train the model, and the trust center's subprocessor list also names OpenAI. Annex III adds Fireflies.ai for transcription. Lupl gives at least five working days' notice of subprocessor changes, which covers a new or replaced model provider. The models used, and whether agents run on the same provider, are not stated. Agents connect to other systems a firm chooses through APIs and MCP, such as iManage or a document automation service. Elevate's acquisition release says Lupl works natively with Claude, Harvey and Copilot, tools a firm licenses itself rather than part of Lupl's own supply chain.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

HighQ
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

Thomson Reuters' own product pages carry no HighQ price. Its HighQ listing on the UK government's G-Cloud 14 marketplace, with documents dated April 2024, prices HighQ at £199 per user a month, and a second listing for HighQ document automation carries the same price. HighQ AI has no per document cost for low volumes. Self service Q&A is a paid add on, and Document Insights needs the Premium tier plus CoCounsel Core licenses, which can also come through Westlaw or Practical Law subscriptions. CoCounsel Drafting needs a CoCounsel license. Azure Maps, Power BI and Meeting Planner panels became Premium add ons in the third quarter of 2026. The terms set user numbers by type in the order form, across core internal, basic internal and external users, and no implementation fee is stated.

Lupl
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

Lupl's quote page says pricing is based on the number of users at an organization and is given as a custom quotation. Every plan includes document sharing and comparison, custom matter templates, real time dashboards, cross organization collaboration and automatic saving to the firm's document management system. Plans also include the Lupl Pins browser extension and integrations with Slack, WhatsApp, DocuSign and Litera Compare. There are no setup costs, storage is unlimited, inviting people outside the organization is free, and Lupl says there are no extras. Setup usually takes about a day, and Lupl will set up a structured trial around a firm's use cases. A return on investment calculator shows 90 hours a year saved at its default settings. Lupl gives no plan names or prices and does not say whether agents cost extra.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

HighQ
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

HighQ's product page lists law firms first, corporate legal departments second and government third. The UK site has a page for corporate legal departments covering contract management, intake and self service, document, matter, vendor and knowledge management, and team collaboration. Case studies come from law firms and a tribal government legal department. The interface runs in 11 languages, from English, German and French to Japanese, Simplified Chinese and Brazilian Portuguese, while HighQ AI supports English and German only. External users are limited by contract to collaboration on services the customer provides to its clients. Publisher, HighQ's publishing product, was retired in July 2025. Team size and practice area limits are unstated.

Lupl
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Lupl serves law firms, from global firms to boutiques, and legal teams and departments. Its home page shows logos for CMS, Cooley, Rajah & Tann Asia, Dykema, Gorrissen Federspiel, Vieira de Almeida, Wilkinson and Withers under a line saying more than 10,000 lawyers trust Lupl. Its trust center groups customers under AmLaw 10, UK 50, AmLaw 100 and AmLaw 200 labels and describes the product as a task management and workflow automation tool for the legal industry. Elevate's release of 19 August 2026 says Lupl was developed with input from CMS, Cooley and Rajah & Tann Asia and places it beside Elevate's ELM and ELMA products for law departments and law firms. People outside the organization can be invited at no charge, and matter dashboards keep clients and stakeholders informed. Lupl's navigation also lists services beside the software. The practice areas and matter types its templates support, and the languages and jurisdictions it is built for, are not described.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

HighQ
Never, in the contract

The Legal AI Product Specific Terms of January 2026 bar Thomson Reuters from developing, training or fine tuning any generative or foundational model with user prompts, user content or outputs unless agreed separately in writing. Section 3 of the HighQ Product Specific Terms, version 1.6 of July 2026, says Thomson Reuters shall not use customer content for any purpose other than performing its obligations. The General Terms license Thomson Reuters to use input to perform and improve its services, and sit below both documents in the HighQ order of precedence. HighQ AI document classifiers are trained by the customer from its own folders inside its HighQ instance.

Lupl
Never, in the contract

Annex III of the data processing addendum attached to Lupl's terms lists OpenAI as the provider of Lupl's AI features, with processing in the United States. It notes that data is not retained or used to train the model. The terms grant Lupl a perpetual, irrevocable, sublicensable license to customer content for operating and providing the services. They allow use of personal data in aggregated or anonymized form to improve the services, without mentioning training. Lupl's trust center lists an AI Training Data and Bias document behind an access request.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

HighQ
Customer controlled, no zero option

Files analyzed with Document Insights are copied into CoCounsel databases and are not removed automatically. The customer deletes them with an unlink and delete option, and a database goes automatically only when its link to a site is removed. Self service Q&A gained chat history management in the first quarter of 2026. Answers written into iSheet columns stay in HighQ as ordinary data. The CoCounsel Essentials page says calls to its language model providers use zero retention, and HighQ states no retention period for prompts or output. Backups roll over every 30 days.

Lupl
Disclosed without a period

Lupl's data processing addendum notes that data sent to OpenAI for Lupl's AI features is not retained. At the end of the services Lupl disposes of protected data under the agreement, without a stated period. How long Lupl keeps matter data, prompts and AI outputs during the subscription is not stated. Storage is unlimited on every plan, and the audit trail records activity across users and matters.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

HighQ
Own model, documented

HighQ keeps its own permission model, documented in its help pages. Access is granted by site group or individual user, folder permissions inherit from the parent folder unless an administrator breaks inheritance, and users with no group on a site see none of its content. Groups can mix members from different organizations. CoCounsel databases built from HighQ files are not permissioned the same way as HighQ sites, while the MCP server respects site and folder permissions.

There is no ethical wall or information barrier feature. External users are limited by contract to collaboration on services the customer provides to its clients. Customers who subscribe to bring your own key hold encryption keys Thomson Reuters cannot access.

Lupl
Claimed, not documented

Lupl's terms say certain services let a user specify the level at which they restrict access to content, and make the user responsible for applying the right level. No public material describes walls between matters or teams. Agents are full matter members that see a matter's structure, tasks, documents and prior decisions, and people outside the organization can be invited to collaborate at no charge. The data processing addendum notes that integrated applications such as a document management system may process protected data under their own terms.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

HighQ
Notice committed

Section 6 of the Thomson Reuters General Terms says a court or agency order for disclosure is promptly notified to the customer unless notice is prohibited. The data processing addendum refers regulator requests to the customer where permissible, and the Data Security Addendum says Thomson Reuters will try to notify the customer promptly of government correspondence about data security. There is no transparency report.

HighQ data stays in the hosting jurisdiction the customer chooses, while CoCounsel processes model calls in the United States. The Data Security Addendum commits to notify a breach within 72 hours.

Lupl
Notice committed

Lupl's terms require the receiving party, where legally permissible, to notify the other promptly in writing before a disclosure required by law or by a court or similar body. The receiving party also cooperates if the other seeks a protective order. The data processing addendum commits Lupl, where practicable and lawful, to notify the customer before a disclosure the law requires. Lupl issues no transparency report on government or court requests.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

HighQ
Sources named, basis unstated

HighQ's AI works on the customer's own files. HighQ AI classifies and extracts from documents in AI enabled folders, Document Insights reviews files a user selects, and Self service Q&A answers from documents an administrator places in its database. The features page says due diligence workflows are informed by Practical Law expertise, Thomson Reuters' own content. No license or update basis is stated for that content, and the training data of the models behind CoCounsel is undescribed.

HighQ AI classifiers are trained by the customer from its own folder mapping and can be rolled back to earlier versions.

Lupl
Not addressed

Lupl's AI works on the firm's own matters, tasks, documents and decisions, and firms give agents knowledge and skills when they build them. No primary law collection sits behind the product. Agents that look up companies or draft through a firm's document automation service draw on those outside systems, which the firm chooses.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

HighQ
Not addressed

HighQ's AI reviews, extracts from and answers questions about the customer's own documents and does not cite case law or legislation, so a citator sits outside the product. Thomson Reuters' citator sits in Westlaw, a separate product, and no HighQ page connects it to HighQ output. How a client facing answer drawn from an outdated document in a Self service Q&A database is flagged is undescribed.

Lupl
Not addressed

Lupl manages matter plans, tasks and client updates and does not cite legal authority, so a citator sits outside the product. Agents work from a matter's documents and prior decisions, and checking any authority those documents rely on stays with the lawyers on the matter.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

HighQ
Documented

Self service Q&A answers questions unrelated to its database with a no relevant information found reply, and draws only on the top level folder an administrator sets, with a recommended capacity of about 100GB. Document Insights stores the passage behind each answer with a reference to its place in the file. HighQ AI yes or no fields record whether a field exists in the document. No confidence indicator is shown, and what Document Insights does when a file holds no answer is undescribed. HighQ AI supports English and German only.

Lupl
Not addressed

Lupl describes no path for the assistant or agents when they lack the information to answer or act. Agents notify users when work is ready for review, and supervisors approve, revise or override it, which puts work in front of a person after the agent has acted rather than describing an abstention step. No confidence indicator is described.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

HighQ
None located

The AI Hallucination Cases database maintained by Damien Charlotin, which records court decisions worldwide that address hallucinated AI content and the tool involved where known, has no entry naming HighQ. HighQ's AI classifies, extracts from and summarizes documents in collaboration sites and portals, and its output is not court filings. Its generative features run CoCounsel skills, which carry their own record.

Lupl
None located

The AI Hallucination Cases database maintained by Damien Charlotin, which records court decisions worldwide that address hallucinated AI content and the tool involved where known, has no entry naming Lupl. Lupl manages matters, tasks and client updates rather than producing court filings.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

HighQ
Generic reference

The Thomson Reuters AI Usage Policy bars using AI output for legal advice or decisions unless a professional with the right license or qualifications reviews it. The General Terms state that Thomson Reuters is not providing legal advice and leave review and reliance with the customer. No bar opinion, ethics rule or professional conduct guidance is named on the HighQ pages or in its terms, including for answers Self service Q&A gives to a firm's clients. The AI Usage Policy also bars presenting AI output as solely human generated.

Lupl
Generic reference

Lupl's terms say nothing in the Lupl materials constitutes or shall be construed as legal or other professional advice, and the agents page says every agent has a human supervisor who remains accountable. No bar opinion, such as ABA Formal Opinion 512, or professional conduct rule is named, including for AI drafted updates sent to clients.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

HighQ
Savings claims only

HighQ's lead buyers are law firms, which bill clients for the work done in client portals and on matters. Its case study for Best Best & Krieger reports sites created in a day instead of three to six months and proposal decisions in hours instead of three days. A September 2026 Thomson Reuters blog says the CoCounsel drafting integration can cut up to 30 percent of drafting and review time. How AI assisted work done in HighQ is recorded or treated on a client bill goes unaddressed. Self service Q&A is a paid add on, and Document Insights needs the Premium tier plus CoCounsel Core licenses.

Lupl
Savings claims only

Lupl's quote page has a return on investment calculator that takes the number of legal professionals and a blended billing rate. It estimates the hours and value saved, 90 hours a year at its default settings. Lupl sits inside law firms' work for clients and tracks time and billing through practice management integrations. Lupl says nothing about how AI assisted work or AI drafted client updates are billed or disclosed to clients.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

HighQ
On request only

HighQ's subprocessor list is dated June 2020, names only data center operators and is no longer linked from Thomson Reuters' current subprocessor index. The data processing and data security addenda are readable without an agreement. Current security material, SOC reports and bridge letters sit in product profiles on the Thomson Reuters trust center, which require an account. The CoCounsel Essentials page names OpenAI GPT and Google Gemini as model providers, and HighQ's release notes name GPT 4.1 for Document Insights.

Thomson Reuters' ISO 27001 certificate, issued by MSECB and valid to October 2028, lists HighQ in scope at its London and Sydney sites.

Lupl
Subprocessors listed

Annex III of Lupl's data processing addendum lists subprocessors as at 1 September 2025 with each one's activity and location. It names OpenAI in the United States for Lupl's AI features and notes that data is not retained or used to train the model. Lupl's trust center publishes a shorter current list naming OpenAI, DocuSign, Auth0 by Okta, Airtable and Microsoft. Lupl gives at least five working days' notice of subprocessor changes.

An AI overview, AI feature documents and the AI Training Data and Bias document sit behind the trust center's access request, and no material is written for a firm to pass to its clients.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

HighQ
Partial record

HighQ logs all user and administrator actions and keeps audit logs for at least 12 months. System level audit log APIs arrived in 2026, and since the second quarter administrators can query users, sites, logins and content through the MCP server in plain language. All AI related API activity is logged for the MCP server. CoCounsel reports record who uploaded files, which skill was requested and who asked questions, and Self service Q&A answers download as Word documents.

CoCounsel Drafting keeps version control and an audit trail when changes sync back. Document Insights answers stay in iSheet columns with their source text alongside. There is no record of the model used for an output and no disclosure template.

Lupl
Partial record

Lupl logs every agent action for audit, and its reporting keeps an audit trail of activity across all users and matters. Supervisors approve, revise or override agent work. The record covers actions in the matter rather than a per document record of the model used and the sources behind a drafted update, and no export for court use is described. Lupl manages matter work rather than producing filings, though its drafts for client updates can describe a matter's status.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Signals neither addresses in public material
  • Good Law Verification

Which one fits

Choose HighQ if

  • You run client portals and data rooms. HighQ provides client portals, virtual data rooms, file sharing, iSheets, legal project management, document automation and dashboards, with connections to iManage, NetDocuments, SharePoint and eDoc. A HighQ app for Microsoft Teams shares files and sites from Teams, and Premium customers get a read only MCP server for assistants such as Claude and ChatGPT Enterprise.
  • You want AI answers available to clients. Self service Q&A, a paid add on, gives clients and other external users answers drawn only from the folder an administrator chooses. It answers off topic questions with a no relevant information found reply, keeps chat history and lets answers be downloaded as Word documents.
  • You want security documents tied to the product. Thomson Reuters' ISO 27001 certificate, issued by MSECB and valid to October 2028, lists HighQ in scope at its London and Sydney sites. An ISO/IEC 42001 certificate covers CoCounsel Essentials, whose skills HighQ's generative features call, and HighQ keeps audit logs of user and administrator actions for at least 12 months.

Choose Lupl if

  • You run matters as task plans. Lupl breaks matters into tasks with assignments and deadlines in list, calendar and board views, with templates, forms, workflow automations, matter budgets and an audit trail. Its assistant generates summaries, reports and drafts for client updates, and people outside the firm join matters at no charge.
  • You live in Microsoft Teams and Outlook. Lupl brings Teams, Outlook and the firm's document management system into one place, saves to that system automatically and integrates with Slack, WhatsApp, DocuSign and Litera Compare. It creates matters and tracks time through APIs with practice management systems, and Elevate's acquisition release says it works natively with Claude, Harvey and Copilot.
  • You want agents working inside matters. Lupl's agents are matter members that triage email, extract instructions from clients and draft documents through the firm's document automation service. Each agent has a human supervisor who can approve, revise or override its work, all agent activity is logged, and firms define each agent's instructions, knowledge, skills and guardrails in natural language.

In summary

HighQ

HighQ is Thomson Reuters' collaboration and legal work management platform for law firms, corporate legal departments and government teams, running client portals, virtual data rooms, file sharing, iSheets, workflow and document automation and dashboards. The HighQ AI engine classifies documents and extracts clauses in English and German. With CoCounsel licenses, Document Insights reviews and summarizes HighQ files, Self service Q&A answers clients from documents an administrator chooses, and CoCounsel Drafting opens HighQ documents in Word. Thomson Reuters' AI terms bar training generative models on customer prompts, content or outputs.

Source: AI Legal Index, 2026

Lupl

Lupl, owned by Elevate since August 2026, is a legal work management platform for law firms and legal departments. Teams break matters into tasks with owners and deadlines, run templates, forms and workflow automations, and view status in list, calendar and board views, on the web and in mobile and desktop apps. It connects to Microsoft Teams, Outlook and the firm's document management system. Its assistant generates summaries, reports and client updates, and agents act as matter members under a human supervisor. AI runs on OpenAI in the United States, and pricing is quoted per user.

Source: AI Legal Index, 2026

Questions buyers ask

HighQ vs Lupl: which suits a law firm?

Lupl suits a firm that wants matters run as task plans inside Microsoft Teams and Outlook, with an assistant that drafts client updates and supervised agents inside workflows. Elevate says CMS, Cooley and Rajah & Tann Asia helped develop it. HighQ suits a firm that runs client portals, data rooms and document automation and wants AI classification and clause extraction at no per document cost for low volumes. CoCounsel licenses add AI document review and a client facing question panel. From the AI Legal Index, based on each vendor's own published materials as of October 9, 2026. No vendor pays for placement.

Which AI models does each use?

HighQ's release notes say Document Insights' review skill has run on GPT 4.1 since the third quarter of 2026, replacing GPT 4o. Thomson Reuters' CoCounsel Essentials page says CoCounsel calls OpenAI GPT and Google Gemini in the United States with zero retention, while the HighQ AI engine handles classification and extraction. Lupl's data processing addendum lists OpenAI, processing in the United States, behind its AI features, without naming the models or saying whether agents use the same provider. From the AI Legal Index, based on each vendor's own published materials as of October 9, 2026. No vendor pays for placement.

Do HighQ and Lupl train AI on customer data?

Thomson Reuters' Legal AI terms bar training generative or foundational models on user prompts, content or outputs unless agreed in writing, and HighQ's terms limit use of customer content to performing the service. HighQ document classifiers are trained by the customer from its own folders. Lupl's subprocessor annex says data sent to OpenAI is not retained or used to train the model, and its terms grant Lupl a perpetual, irrevocable license to customer content for operating the services. From the AI Legal Index, based on each vendor's own published materials as of October 9, 2026. No vendor pays for placement.

How do they share security reports?

HighQ's ISO 27001 certificate is openly published with HighQ named in scope, and SOC reports and bridge letters sit in Thomson Reuters' trust center behind an account. Lupl's trust center lists SOC 2 Type 2 and ISO 27001:2022 and offers the SOC 2 report, penetration test reports and architecture and data flow diagrams on request. Its open pages name no auditor or audit period. From the AI Legal Index, based on each vendor's own published materials as of October 9, 2026. No vendor pays for placement.

What do HighQ and Lupl both leave unpublished?

Neither publishes an accuracy measure or test results for its AI, and neither offers an indemnity covering AI output. Neither names bar guidance on AI, including for AI answers or updates that reach a firm's clients. Neither has an ethical wall or information barrier feature, and neither shows a confidence indicator on AI output or issues a transparency report on government requests. From the AI Legal Index, based on each vendor's own published materials as of October 9, 2026. No vendor pays for placement.

Disclosure

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything on it comes from public material on the dates shown. How the index grades.

HighQ's generative features need CoCounsel licenses, Document Insights needs the Premium tier, and the HighQ AI engine supports English and German only. Lupl's trust center lists SOC 2 Type 2 and ISO 27001:2022, while its home page describes the product as aligned with ISO 27001. Lupl's terms grant a perpetual license to customer content for operating the services, and its subprocessor annex says data sent to OpenAI is not retained or used for training. Neither vendor reviewed this page.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
October 9, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746