August
August is a legal AI workspace for law firms, built around an assistant that answers questions across documents, folders, email and the web, a tabular review surface that turns large document sets into a comparison grid, and configurable agents that chain research, analysis and drafting steps into repeatable workflows. It works inside Microsoft Word, Outlook and SharePoint, generating edits as tracked changes a lawyer accepts or rejects in Word's review mode, and connects to the SOS practice management system to pull matters into workflows and sync completed work back. The company publishes its platform agreement, security addendum, data processing addendum, subprocessor list, AI policy and law enforcement guidelines in full, including stated liability caps and a contractual prohibition on training models with customer content. Named customers run from a twenty-lawyer firm to the Am Law 150 firm Hughes Hubbard, with deployments in the United States, the United Kingdom, Australia and India. August is operated by Credicle Corporation, a Delaware corporation.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Every named capability on the product pages is model driven: an Assistant that answers across a document, a folder, email or the web; Tabular Review, which turns thousands of contracts into a comparison grid; clause drafting and rewriting inside Word; and Agents that chain research, analysis and drafting into multi step workflows. There is no underlying document management or practice management system that would survive the models being removed, because the systems of record here belong to someone else: Word, Outlook, SharePoint and SOS are integrations into the firm's existing stack rather than August's own conventional product. The company positions itself as 'Configurable Legal AI' in its own footer and describes co developing workflows on a firm's precedent and drafting standards. Verified 2 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
The AI Policy of January 2026 states that August runs 'testing protocols for accuracy and reliability verification before and after deployment' and conducts regular audits of AI system performance, but publishes no figure, no test set and no evaluation a reader can assess. Grounding is claimed in product terms rather than described: SharePoint documents 'become available for citation, analysis, and drafting', and the Assistant answers from documents, folders and the web, but no retrieval method is published and the product does not ground to primary authority. Both the Terms of Service at 1.5 and the AI Policy at section 5 state that output is AI generated and may contain errors, misstatements or be incomplete, which is a real limitation statement rather than a bare claim not to hallucinate, so the D limb does not fire. Accuracy asserted without measurement is what places this at C. Verified 2 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Review surfaces are real and specific. In Word, August 'applies changes you can accept or reject in Word's review mode', and the drafting surface shows a Preview step before generation. The AI Policy commits in writing to communicating how AI generated output should be reviewed and verified and to 'the importance of human oversight in legal work', and the Terms of Service at 1.5 place the product on the tool side of the advice line. What is missing is the threshold at which the system acts alone. The product ships Agents running two step workflows and an Outlook capability described as 'Draft and send replies', and nothing published states what an agent may complete unattended or what happens after it is wrong. That unstated threshold is the limb the B band names as commonly absent. Verified 2 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Eight named customer stories are published, each on its own page: Hughes Hubbard, described as an Am Law 150 firm deploying August across legal and business teams; Hicksons in Australia; Harrison Drury; Mission Australia; White Summers; ELP in India; HDRB&B; and Dunning Vallejo & MacDonald, a twenty lawyer firm. One carries a figure, Hicksons at 90 per cent faster document review, and a partner at that firm is quoted by name and title. What holds this below A is measurement: the customer index carries no dates and no basis for the 90 per cent figure, and no method a reader could assess is published alongside it. The individual case study pages were not opened, so this note credits only what the index page itself states. Verified 2 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Three of the five things the top band asks for are in the agreement. Section 11.8 of the Terms of Service prohibits training on Content and Customer Data and extends that prohibition to subprocessors other than cloud storage providers, which are also barred from retaining the material for human review, which settles the third party model provider position. Section 7.4 deletes remaining Content within 30 days of termination and clause 6 of the Data Processing Addendum requires return or deletion on the customer's reasonable request. Two limbs fail. Nothing published addresses attorney client privilege or work product treatment on any surface read. Nothing published documents matter level segregation for a product sold to law firms: the home page commits that no client document trains a model reachable outside the firm, which is a firm level boundary, and the SharePoint integration states that August 'gains access to your entire SharePoint repository', which is the shape a firm's ethical walls exist to prevent. Silence on segregation is exactly what the B band names. Verified 2 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The advice line is stated twice and in the agreement itself, not only in a footer: Terms of Service 1.5 and AI Policy section 5 both say the Service is a research tool and its output is not legal advice. The AI Policy reaches part of the supervision and competence dimension by committing to communicate the capabilities and limitations of the systems, how output should be reviewed and verified, and the importance of human oversight. The audience is unambiguous: the product is sold to law firms and in house teams, and there is no consumer facing surface, so the consumer disclosure limb of the top band does not apply to this product class. What is absent is any statement of jurisdiction limits, and no bar or ethics opinion is engaged anywhere. Silence on jurisdiction limits is the B band's own example. Verified 2 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
The AI Policy of January 2026 is a real framework rather than a principles page. It commits to the EU Artificial Intelligence Act, Regulation (EU) 2024/1689, by name; requires AI literacy training for all employees involved in AI development, deployment and operations; and lists internal AI governance policies, testing protocols before and after deployment, change management for regulatory adherence on update, and regular audits of AI system performance and safety. Clause 7.5 of the Data Processing Addendum adds a commitment to review compliance with new AI specific legislation and negotiate amendments. What is absent is both of the things the top band asks for beyond a framework: no individual or function inside the vendor is named as accountable, and no testing result is published, including nothing on uneven output across matter types or populations. Verified 2 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
All five elements are published and specific enough to hold the vendor to. Retention and deletion: Terms of Service 7.4 deletes remaining Content within 30 days of termination, Data Processing Addendum clause 6 requires return or deletion on reasonable request, and Security Addendum section 9 retains system audit records for a minimum of one year and a maximum of ten. Access control: unique IDs, multi factor authentication and least privilege, personnel barred from accessing Customer Data except to support the Service or comply with law, access to systems holding Customer Data removed within 1 day of separation and all systems within 3 days, quarterly privilege reviews and background checks. Subprocessors: a dated list naming Microsoft, OpenAI, Google Cloud Platform and Amazon Web Services with processing regions, plus 30 days advance notice of additions under Data Processing Addendum 3.2 and a 15 day objection right at 3.3. Incident practice: notification without undue delay and within 48 hours of becoming aware, one year log preservation, and independent forensic specialists engaged at August's expense. The one gap is that no default in term retention window for prompts and outputs is published, which is recorded on the retention signal. Verified 2 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A buyer can read the whole allocation of loss before signing, with figures. Section 8.1 gives a third party intellectual property indemnity for use in accordance with the Terms and Documentation, with the carve outs stated: no obligation where the claim is attributable to materials not provided by August, or where output results from input the customer knew or should have known was likely to lead to infringement. Section 10.2 sets a liability cap at the greater of twelve months of fees or 250,000 dollars, and 10.3 raises it to the greater of twice twelve months of fees or 500,000 dollars for data breach claims under the Security Addendum or Data Processing Addendum and for confidentiality breaches by either party. Section 9.2 warrants conformity with the Documentation, workmanlike delivery, non infringement to August's knowledge and legal compliance, and 11.11 commits to insurance from carriers rated A.M. Best A minus, VI or better. What the vendor does not stand behind is output accuracy: the Service is provided as is under 9.3 and the indemnity is confined to infringement. That is a narrow position, published specifically, which is what the band rewards. Verified 2 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The integrations page describes what moves, in which direction, and what the firm connects. SOS, the practice management system, is bidirectional and says so: August syncs matters, contacts and case data in, workflows run on live matters, and 'Completed reviews, summaries, and outputs sync back to SOS'. SharePoint is inbound after a one time account connection, with selected documents becoming available for citation, analysis and drafting on the same footing as uploads. Word is in place rather than sync, chatting with the open document and generating edits as tracked changes in review mode, with firm playbooks applied. Outlook covers search across the mailbox, thread summarisation and reply drafting. The limitation worth naming is that all of this lives on a marketing page: no developer index, help centre or implementer documentation exists anywhere in the site navigation, footer or legal hub, and iManage and NetDocuments, the two document management systems most large firms run, are not among the named connections. Verified 2 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Section 2 of the Security Addendum states that customer data and content reside in data centres matching the geographic region specified in the order form, and that a customer may request storage in a separate specific region, which August will use commercially reasonable efforts to accommodate where its cloud providers support it. The subprocessor list names the regions in play: United States, European Union, Switzerland and Australia. The home page advertises hosting in the region of the buyer's choice and EU and US options. Two things are absent. The tenancy model is never stated, so a buyer cannot tell whether the deployment is multi tenant, single tenant or private, and the per firm subdomain shown in product imagery is not described as a separation boundary anywhere. Processing location is not addressed as distinct from storage location, since section 2 speaks only to where data reside. Residency offered without the processing location addressed is the B band's second limb. Verified 2 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Section 1 of the Security Addendum states that August's information security management system undergoes annual assessment by independent third party auditors and that the company maintains SOC 2 Type II and ISO 27001, with a commitment to adopt an equivalent recognised framework if either is discontinued. Section 4 adds annual third party penetration testing and web application assessment against OWASP. Section 10 gives customers, at no cost, access to SOC 2 Type II reports, penetration test summaries and ISO 27001 certifications, plus up to 100 security questions a year. What the top band asks for is not there: no auditor is named, no coverage period or report date is published, and the report route in section 10 runs to contracted customers rather than to a prospect. A trust centre exists at trust.august.law, named in Terms of Service 12.5 as where the Business Associate Addendum sits, but it refused automated access on 2 September 2026; that is a retrieval limit on this side rather than a gap on the vendor's, and its contents are neither graded against August nor credited to it. Verified 2 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The subprocessor list of January 2026 names four AI providers under its own heading for model providers and infrastructure, Microsoft, OpenAI, Google Cloud Platform and Amazon Web Services, each with its processing regions, and Data Processing Addendum 3.2 commits to 30 days advance notice before any new subprocessor begins processing, with a 15 day objection right. That is providers, location and change notification, three of the four things the top band asks for. The models themselves are not named. The closest the site comes is a home page line describing August as model agnostic across Anthropic, private OpenAI endpoints and Llama, which is a mix of two providers and one model family rather than a model list, and it sits awkwardly against the subprocessor list, where Anthropic does not appear at all. Three further subprocessors that touch content are identified only by function, as web browsing, knowledge source and email subprocessors. Verified 2 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Checked the home page, the full navigation and footer, the legal hub and its fourteen documents, the integrations page and the customers page on 2 September 2026. No pricing page appears anywhere in the site's own navigation or footer, and no figure, unit of charge or tier structure is published on any page that loads. The routes offered a buyer are Book a Demo and a self serve sign in at app.august.law, alongside a seven day free trial named in the home page metadata and an offer to build a live workflow free within a week. A pricing page at august.law/start-now remains in search engine indexes carrying tier names, a feature split and a monthly figure, but it returned a 404 on both the www and non www forms of the URL on 2 September 2026, so nothing on it could be confirmed against a loading first party surface. The only other figures located are in January 2026 trade press, and they disagree with the indexed page, so neither is written here. Verified 2 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described with substance on both dimensions. Seven practice areas are named on the home page with a time saved figure attached to each: Corporate and M&A, Litigation, Disputes, Real Estate, Capital Markets, Regulatory and ESG, and Healthcare. Segment reach is evidenced by the customer roster rather than only claimed, running from a twenty lawyer firm through midsize firms such as Hicksons and Harrison Drury to the Am Law 150, and including in house teams at Mission Australia, Outside GC and DevRev. Geography is specific: the About section names expansion into England, Australia, Colombia, the Middle East and India, and dedicated India and Australia pages exist. What is left open is the boundary. Nothing states which practice areas or firm types the product is not built for, and the founding story's emphasis on midsize firms sits unreconciled with an Am Law 150 firmwide deployment. Verified 2 September 2026.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The published terms prohibit training on customer content. Not a policy page, the agreement.
The prohibition sits in the agreement at clause 11.8 rather than on a policy page, and it extends to subprocessors: all but cloud storage providers are barred from training on the material and from retaining it for human review. Section 3 of the AI Policy repeats the commitment. Two adjacent permissions are disclosed and neither reaches Content or Customer Data: clause 11.7 allows Usage Data, expressly defined to exclude Content and Customer Data, to be used for service development, and clause 3.4 allows free use of Feedback but bars any use that could identify the customer, its users, its Customer Data or its Content.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
The customer controls the retention window, by product configuration or by contractual instruction, but zero retention is not stated as available.
Clause 6 of the Data Processing Addendum gives the customer a standing contractual right to require return or deletion at any time, not only at termination, and Terms of Service 7.4 deletes remaining Customer Data and Content within 30 days of termination unless the customer instructs otherwise. Control therefore runs by contractual instruction rather than by a product setting. No default in term retention window for prompts and outputs is published anywhere, and no zero retention option is stated as available. Separately, Security Addendum section 9 retains system audit records for a minimum of one year and a maximum of ten, which covers system activity logging rather than prompt and output content.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses walls or matter level segregation.
Checked the home page, the Assistant, Tabular Review and integrations product pages, the Terms of Service, Security Addendum, Data Processing Addendum and Privacy Policy on 2 September 2026. No located material addresses ethical walls or segregation of one matter from another. The nearest statements point the other way: the home page commits that no client document trains a model anyone outside the firm can access, which draws the boundary at the firm rather than the matter, and the SharePoint integration states that August gains access to the firm's entire SharePoint repository once connected, without describing whether retrieval enforces the source system's per user access model at query time. Security Addendum section 4 constrains August personnel access but says nothing about separation between the firm's own users.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Terms commit to notice where lawfully permitted. No transparency report located.
August publishes a dedicated Law Enforcement Guidelines page committing to notice unless legally prohibited, and where a gag order applies it states it will request a waiver, document that request in writing, and notify the customer as soon as the restriction expires. It also directs requestors to the customer first where legally possible, states it does not volunteer data to government agencies, and limits foreign government responses to MLAT, letters rogatory and CLOUD Act channels. Terms of Service 11.6 gives advance notice of legally required disclosure where permissible, and Data Processing Addendum 4.1 repeats the commitment. Section 5.3 says records of requests received and responses are maintained, but no transparency report was located, which is why this is not the top value.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
Section 3 of the AI Policy states that August secures the necessary rights and licences for datasets integrated into the Service and monitors third party compliance when collecting such information, but it identifies no source. Checked the home page, the Assistant, Tabular Review and integrations pages, the AI Policy and the subprocessor list on 2 September 2026; no primary law corpus, publisher or jurisdiction coverage statement was located. The product's material is chiefly the firm's own documents plus SharePoint, email and web content rather than a published body of primary law, so the coverage risk this signal tracks does not arise in its usual form. The subprocessor list carries an unnamed knowledge source subprocessor for knowledge sources and URL searching, so a third party sits behind that retrieval and is not identified.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Checked the home page, the Assistant, Tabular Review and integrations product pages and the AI Policy on 2 September 2026. No located material addresses subsequent history, treatment flags or citator coverage. The product does not claim to retrieve primary law and its named retrieval targets are uploaded documents, SharePoint, Outlook and the web, so no good law check is offered and none is asserted. The honest reading is that the question is not addressed rather than that a check exists in some weaker form.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Checked the AI Policy, the Terms of Service, the home page and the product pages on 2 September 2026. Section 5 of the AI Policy commits to communicating the capabilities and limitations of the systems, and Terms of Service 1.5 states that output is AI generated and may contain errors, misstatements or be incomplete. Neither describes what the product does when it cannot ground an answer. No abstention or no answer path is documented, and no confidence or grounding score is exposed in any published material, so the weaker values are false of this record as well.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
Searched the AI Hallucination Cases database maintained by Damien Charlotin, and reporting on it, on 2 September 2026 on both the product name August and the corporate name Credicle Corporation. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product, and the search is weaker than usual because August is a common word that appears in case names, dates and party names throughout the corpus.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
Checked the home page, the AI Policy, the Terms of Service and Platform Agreement, the Security Addendum, Data Processing Addendum, Privacy Policy, Law Enforcement Guidelines and subprocessor list, and the product, integrations and customers pages on 2 September 2026, and ran a domain scoped search for engagement with bar or ethics guidance. No located material names ABA Formal Opinion 512 or any state bar opinion. The AI Policy does engage a named instrument, the EU Artificial Intelligence Act, Regulation (EU) 2024/1689, but that is legislation binding the vendor rather than ethics guidance binding its buyers, which is what this signal asks about.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
The home page publishes a time saved figure for each of seven practice areas, from two hours in Capital Markets to seven in Disputes, and the customer material claims 90 per cent faster document review at one named firm. Nothing located addresses what happens to the invoice when that compression occurs. The home page metadata names invoicing among the tasks the product automates, but no material shows that the invoicing feature records or distinguishes AI assisted work on a per matter basis, so no audit record of AI assisted work was established. Checked the home page, product and integrations pages, the customers page and the AI Policy on 2 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A subprocessor and model provider list plus client facing disclosure material is published or available without an agreement in place.
All three artifacts a firm needs are published and reachable without an agreement. The subprocessor list of January 2026 names the AI providers as AI providers rather than as infrastructure, Microsoft, OpenAI, Google Cloud Platform and Amazon Web Services, each with processing regions. The Data Processing Addendum is published in full and its clause 3.2 commits to 30 days advance notice of new subprocessors with a 15 day objection right, which is the forwardable client facing instrument. Alongside it sit an ungated AI Policy, Security Addendum and Law Enforcement Guidelines, all of which a firm can hand to a client. The limitation worth naming is that three subprocessors that touch content are identified only by function, as web browsing, knowledge source and email subprocessors, so a firm answering a client cannot name them.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located public material addresses court disclosure or verification certification.
Checked the home page, the Assistant, Tabular Review and integrations product pages, the AI Policy, the Terms of Service and the Security Addendum on 2 September 2026. No located material addresses judicial standing orders on AI disclosure, verification certification, or exporting a record of which model produced which passage and who checked it. The Word integration produces tracked changes a lawyer accepts or rejects, which is a review artifact rather than a disclosure record, and the audit logging at Security Addendum section 9 covers information system activity for security investigation rather than document level model use.