B
BigHand

BigHand sells operational and financial software to law firms, and has done so for more than thirty years, reporting more than 810,000 users across 3,300 firms including 81 per cent of the AmLaw 200, 82 per cent of the top 200 United Kingdom firms and 96 per cent of the top 50 firms in Asia-Pacific. The catalogue runs to sixteen products in three groups. People productivity covers Workflow Management, which routes support tasks and gives firms visibility of demand, capacity and cost; Resource Management, for allocating lawyers to matters with skills, availability and career tracking; digital dictation and speech recognition; and Impact Analytics.

Document and business productivity covers Document Creation with template and clause automation in Microsoft Word, Metadata Management for cleansing metadata and checking email recipients, formatting and styling, document stamping, content redaction and a pitching and proposals tool. Financial productivity covers Business Intelligence dashboards, Matter Pricing, Budgeting and Forecasting, Partner Performance, PrebillManager for reviewing time narratives and rates before invoices go out, and AlertManager.

The artificial intelligence sits in two places. Impact Analytics, acquired as Digitory Legal, uses machine learning to convert inconsistent timecard narratives into structured phase and task-level data that informs pricing accuracy, staffing fairness and billing quality, and produces dashboards on financial, data quality and diversity metrics. AI Email Routing shipped in the Workflow Management Spring Update in 2026.

In August 2026 BigHand acquired Ayora, a legal AI pricing and data enrichment business incubated in Mishcon de Reya's MDR Lab, with the first integrated capabilities stated to be expected later in the year. Products are packaged in Standard, Plus and Advanced tiers with optional add-ons. BigHand Limited is registered in London, with BigHand Inc in Chicago serving North America.

Vendor siteLondon, United Kingdom
Last verifiedSeptember 12, 2026
Compare with other vendors

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Artificial intelligence is present, real and peripheral to a sixteen-product estate, which is the C band, and the vendor says so itself more plainly than most. The AI that ships is two features. BigHand Impact Analytics, formerly Digitory Legal, uses machine learning to analyse and re-encode timecard data, converting inconsistent narratives into structured phase and task-level information that feeds pricing, staffing and billing quality.

AI Email Routing arrived in the Workflow Management Spring Update 2026. Everything else in the catalogue is rules-based or analytical: workflow and task allocation, resource forecasting, digital dictation and speech recognition, document creation, formatting, stamping, metadata cleansing, recipient checking, redaction, pitching, business intelligence dashboards, matter pricing, budgeting, partner performance, prebill review and alerting.

Remove the AI and fourteen of sixteen products are untouched. The vendor's own positioning statement is the clearest evidence and is quoted in the note because it cuts against the grain of this market: the market is selling AI, BigHand is building the intelligence AI needs to be useful. Recorded and expressly not credited under the ground rules on future tense: the Predict section describing the acquired Ayora technology is written entirely in the future, the next chapter, the next development stage, and what the company will predict, with integrated capabilities stated to be expected later in the year. Verified 12 September 2026.

Source: Vendor Published
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Reliability is asserted without measurement and no grounding method is described, which is the C band, and R15 governs the weight. This product cites no legal authority: the AI reads a firm's own timecards and routes its own email, so the limbs on primary sources, openable citations and citator status do not bite and the record is not penalised for them. What does bite is that the output is quantitative and reaches a client.

Impact Analytics re-encodes narrative time entries into phase and task codes, and those codes and narratives are what a client sees on a bill and what a firm relies on to price the next matter. The vendor's language around that is confident and unevidenced: reliable pricing insights, dependable data, award-winning AI-enabled timecard analysis, and a promise of clean timecard narratives. No accuracy figure, error rate, test set, confusion matrix or evaluation is published for the re-coding, and nothing describes what happens when the model codes an entry wrongly.

Recorded and expressly not credited, because they measure a different thing: the outcome figures published across the estate, a 20 per cent increase in realisation on a multimillion-dollar engagement and a 23 per cent average reduction in write-offs, are commercial results rather than accuracy measurements, and neither is dated or attributed. No hallucination disclosure of any kind was located on any surface read. Verified 12 September 2026.

Source: Vendor Published
DD on Autonomy and Oversight ModelNo oversight structure is published for a system that drafts, advises, or acts on a client matter.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Nothing published on how the models are supervised was located, which is the D band, and the note sets out why that reads as a real gap here rather than an inapplicable limb. Two of this vendor's AI features act rather than advise. Workflow Management is described as automatically routing work to the right resource, and AI Email Routing shipped in 2026 as an enhancement to that routing. Impact Analytics re-encodes timecard data, which is a change to the firm's own records rather than a suggestion about them.

For none of these does any surface state whether a person reviews the output before it takes effect, whether a re-coded time entry can be inspected or reversed, what happens when a routing decision is wrong, or where a human sits in the loop at all. No published statement of human oversight, no review surface, no threshold, no confidence signal and no escalation path was located. The absence is not explained by the product class: R15 would excuse the limbs about legal advice and filings, and it does, but supervision of automated action on a firm's own billing records and work allocation is squarely within what this axis measures.

One adjacent statement is recorded and not credited because it addresses the vendor's own internal use rather than the product: the privacy policy states that the vendor does not use personal information to profile or enable automated decision-making about individuals. Verified 12 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Named customers at the top of the market and outcome figures are both published, and they are never joined, which is the B band in its own terms. The naming is extensive and specific, a client wall carrying DLA Piper, Dentons, Allen and Overy, Norton Rose Fulbright, Ashurst, CMS, Pinsent Masons, Clyde and Co, Lewis Brisbois, Fox Rothschild, Husch Blackwell, Foley and Lardner, Baker Donelson, Allens and Schillings, supported by penetration figures that are the most precise in this lane: 81 per cent of the AmLaw 200, 82 per cent of the top 200 United Kingdom firms, 96 per cent of the top 50 Asia-Pacific firms, 3,300 firms and more than 810,000 users.

Four case studies are published by name, covering Womble Bond Dickinson on resource management, FordHarrison on business intelligence, Charles Russell Speechlys on workflow and Otten Johnson on document creation. Outcome figures are published per product: a 20 per cent increase in realisation on a multimillion-dollar engagement, a 23 per cent average reduction in write-offs within twelve months, a 28 per cent reduction in the billing and collections lifecycle, 81 hours saved per fee earner per year, four hours per user per week, and around three weeks from time entry to bill.

What A requires is these two halves joined, and they are not: no figure is attributed to a named firm, none is dated, and no basis or method is stated for any of them. The case studies were not opened; under R25 they corroborate a grade already resting on the client wall and are what would move this row. Verified 12 September 2026.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Substantive published commitments on confidentiality and on the use of customer content, failing the limb R33 makes decisive. The commitments are real and, unusually for a record of this kind, they sit in an instrument that expressly covers the products rather than only the website. The privacy policy defines Customer Data as the data input during use of the products, acknowledges it may contain personal or sensitive personal information about the customer's own clients, states that it is processed only at the customer's direction, and commits that the vendor does not use it other than to provide the products.

That is a purpose limitation on client material and it is graded on the training signal as well as recorded here. Around it: a certified information security management system, access to personal information recorded and controlled, contractors and sub-contractors held to the same administrative, physical and technical standards, and certification to ISO 27701, which is the privacy information management standard rather than a general security one.

The limb that fails is privilege and work product, and it fails completely: neither privilege, professional secrecy nor legal confidentiality is addressed on any surface read, on a platform that holds timecard narratives describing what lawyers did on named matters. Two further gaps: no retention period is published for customer data, and nothing describes segregation between matters or between clients within a firm's tenant. Verified 12 September 2026.

Source: Vendor Published
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Nothing published on professional responsibility was located, and R15 requires naming which limbs bite before the grade is read as heavier than it is. The advice-line limb barely applies. This is operational and financial software for law firm business services: workflow routing, resource allocation, dictation, document production, metadata cleansing, billing review and management reporting. Nothing it produces is advice to a client, and the audience is unambiguous, being the firm's support, finance, pricing and operations functions.

What is absent, and what the grade records, is any statement connecting the output to the obligations of the lawyers whose names sit on the work. Two places where it would bite are named rather than passed over. Impact Analytics re-encodes the narrative of a time entry, and a time entry narrative is a representation to a client about work performed which a lawyer certifies when the bill goes out. PrebillManager surfaces issues in time recording, narratives and rates before invoices reach clients, which is the same territory approached from the other side.

Nothing published addresses whether a lawyer must review a machine-altered narrative before it is billed, and no disclaimer of any kind appears on any surface read. There is no published customer agreement in which such a position might otherwise sit; the only terms published are website terms of use. Verified 12 September 2026.

Source: Vendor Published
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Nothing published on AI governance was located, which is the D band, and on this vendor the bias half of the axis is the sharper omission. No responsible AI principles page, no AI policy, no acceptable use position, no accountable owner, no statement about how models are built, evaluated or monitored, and no disclosure of any testing or its results appears anywhere on the surfaces read. The bias gap is not theoretical and is stated plainly because the product is built around it.

BigHand Impact Analytics is marketed on its ability to surface implicit bias in how work is allocated, to identify quantitative and qualitative diversity data for every activity within a matter, to award career scores, and to support equity partnership pathways, with a published claim of a 14 per cent increase in career-advancing work attributable to diverse attorneys. That is a machine learning system whose output feeds decisions about which lawyers get which work and who advances.

Nothing published addresses whether the model that re-codes and classifies that activity is itself even across the people being classified, what it was trained on, or how a firm would audit it. A vendor selling bias detection publishes nothing about bias in the detector. One adjacent statement is recorded and not credited: the privacy policy states the vendor does not use personal information to profile individuals, which governs the vendor's own conduct rather than the product's. Verified 12 September 2026.

Source: Vendor Published
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Substantive published policy covering most of the ground, missing the named subprocessor list and a stated incident practice, which is the B band and its two named examples. What is published is a genuine assurance programme rather than a paragraph. A formal information security management system is stated to be formally managed, controlled, independently audited and certified to ISO 27001 and Cyber Essentials Plus. Compliance is claimed against an unusually specific set for a legal vendor: GDPR with an ICO registration number published, HIPAA, DCB0129 for NHS clinical risk management, and the Data Security and Protection Toolkit, which together indicate the estate handles health data as well as legal.

Controls listed include trained personnel, physical security at facilities, network and technical protection, access to personal information recorded and controlled, systems and practices audited and reviewed, and contractors and service providers held to the same administrative, physical and technical standards. Use of customer data is purpose-limited to providing the products. What is missing is the two things the band names.

No subprocessor is identified: the policy lists categories only, service providers providing technology and infrastructure support, professional advisors and group members, without naming any. And no incident notification commitment to customers was located, no breach notification window and no incident response description. Retention is stated without a period. Verified 12 September 2026.

Source: Vendor Published
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Nothing published on who bears the loss when the system is wrong was located, which is the D band. There is no customer agreement on the estate. The footer's legal inventory is a trust centre link, a modern slavery statement, a cookie policy, a privacy policy and a page headed Terms, and that last document is website terms of use rather than a software licence. This is worth stating precisely because the page presents itself otherwise: its own meta description offers terms of use for the website and software including limitations of liability, and the body delivers only website terms, covering intellectual property in the site, trade marks, linking, viruses and a disclaimer of accuracy for site content.

It contains no warranty for the products, no service level, no liability cap, no indemnity and no data terms, and its liability provisions are expressly about use of the website. So a buyer evaluating a platform that re-codes its billing data, routes its work and generates its management reporting cannot read, before entering a sales process, what the vendor stands behind. Nothing on insurance was located. The exposure is concrete: a mis-coded time entry reaches a client's invoice, and a mis-routed email reaches the wrong recipient, both of which this estate's own products exist to prevent. Verified 12 September 2026.

Source: Vendor Published
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Integrations are claimed and the host applications are named, without a documented catalogue or any configuration detail, which is the C band. What is published sits mostly inside the packaging tables rather than on an integrations page, because no integrations page exists in the navigation, which is itself a page-inventory finding. From those tables: Microsoft Word integration and document management system integration in Document Creation; Microsoft Office and DMS integration in Metadata Management; CRM and DMS integration plus marketing document automation across Word, PowerPoint and Excel in Pitching and Proposals; export to Microsoft Excel in Matter Pricing; and integration between Document Creation and BigHand Workflow or Dictation as a purchasable add-on.

Two extensibility items are named as add-ons in Workflow Management, an SDK and a Service Provider Gateway, and an Outsource Module. So a buyer learns that the products live inside Microsoft Office and connect to document and client relationship systems. What is absent is everything the higher bands ask for. Not one document management or CRM product is named, so a firm cannot tell whether its own system is supported; no direction of flow is described for any connection; no configuration or prerequisite is stated; and no public API reference, developer portal or connector register was located, the SDK appearing as a line item on a pricing table rather than as documentation. Verified 12 September 2026.

Source: Vendor Published
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Cloud delivery is implied rather than described and neither the tenancy model nor the region is published, which is the C band. Delivery is not seriously in doubt: products are named as cloud offerings, Matter Pricing Cloud appears by that name in the vendor's own acquisition announcement, and the estate is sold as subscription software with a customer support portal and a login. But nothing states where any of it runs.

No data centre, country, region or cloud provider is named on any surface read. No residency option is offered or refused, which is a live question for a vendor operating three regional estates in the United Kingdom, the United States and Asia-Pacific and reporting clients in all three. No tenancy model is described, so a buyer cannot learn whether a firm's data sits in a shared or isolated environment, and nothing distinguishes storage from processing.

The closest thing to a residency statement is a single line in the privacy policy of the United States entity, that personal information will only be transferred outside North America for the purposes described elsewhere in that policy, which implies North American processing for North American customers without stating it as a commitment or addressing the other two regions. On-premises deployment is not addressed either way, which matters because several products in this estate, including metadata management installed across more than 800 sites, have historically been desktop-installed. Verified 12 September 2026.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Certification is real, current and named across an unusually wide set, and the evidence behind it could not be reached, which is the B band. The claims are specific and appear in two places. The trust centre states a certified information security and privacy management system audited to ISO 27001, ISO 27701, SOC 2 Type 2 and Cyber Essentials, and publishes an Information Commissioner's Office registration number, which is a verifiable regulator record rather than a self-assertion.

The privacy policy adds Cyber Essentials Plus, HIPAA, DCB0129 for NHS clinical risk management and the Data Security and Protection Toolkit. The footer badges carry a further standard, ISO 14001 for environmental management certified by BSI, and, more usefully for this axis, they name the auditor for the information security certifications as A-LIGN, which is a limb most records in this corpus never supply. What is missing is the evidence itself.

The trust centre is Vanta-hosted and returned page metadata with no body to this index's fetcher on the date shown, which is a documented persistent limit of this instrument rather than a fault of the site, so the access flow could not be graded under R5 and the lower tier is taken with the reason stated. No report period, observation window, certificate number or issue date was located on any readable surface, and nothing indicates whether the SOC 2 report is downloadable, gated behind a click-through, or released only after a sales conversation. Verified 12 September 2026.

Source: Vendor Published
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Nothing published about the models was located, which is the D band, and the silence is complete rather than partial. Across every surface read the AI is described only by what it does: AI-enabled timecard analysis, machine learning used to analyse and re-encode timecard information, AI Email Routing, and AI used to turn unstructured timecard data into pricing accuracy. No model is named, no version is given, no provider is identified, nothing states whether the models are built in-house or licensed, nothing says where inference runs, and no commitment to notify customers of a change was located.

There is no subprocessor list anywhere that would answer the question by another route, the privacy policy naming only categories of recipient. So a buyer cannot establish whether its timecard narratives, which describe work done on named client matters, are processed by a model the vendor built or by a third-party service. One adjacent fact is recorded and expressly not credited, because it is a future capability rather than a current disclosure: the acquired Ayora technology is described in third-party coverage as using large language models, and the vendor's own material places its integration in the future, so it discloses nothing about what processes customer data today. Verified 12 September 2026.

Source: Vendor Published
CC on Commercial TransparencyPricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Some pricing information is published but not enough to plan, specifically a tier list without figures, which is the C band. The estate carries a dedicated Pricing and Packaging page and it is more substantial than the label on most such pages: seven product families are broken into named tiers with feature matrices setting out what each tier includes. Workflow Management runs Standard, Plus and Advanced across fourteen features with four named optional add-ons including speech recognition, an outsource module, a service provider gateway and an SDK.

Resource Management runs two tiers across sixteen features. Document Creation runs three tiers, Metadata Management two, Matter Pricing three, Business Intelligence three, and Pitching and Proposals a single tier. A buyer can therefore establish exactly what a tier upgrade buys, which is real and gradeable information. What is absent is everything a buyer would need to budget. No figure appears anywhere for any tier, and, more fundamentally, no unit of charge is published: nothing states whether the products are licensed per user, per fee earner, per site, per module or per firm, so a buyer cannot even scale an estimate.

Every call to action on the page routes to a Get Pricing form. No term, minimum, uplift provision or renewal mechanic is published, and no agreement is published in which they might appear. Under R17 the pricing evidence lifts this axis off D, so a VendorPricing row is owed and written with no figure. Verified 12 September 2026.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Coverage is documented with real substance and evidenced by market penetration, short of the stated limits the A band asks for. Who this is for is unambiguous and demonstrated rather than asserted: law firms, and the published penetration figures are the most precise in this lane, 81 per cent of the AmLaw 200, 82 per cent of the top 200 United Kingdom firms, 96 per cent of the top 50 Asia-Pacific firms, 3,300 firms and more than 810,000 users.

The vendor states it serves from the Magic Circle to boutique practices, which addresses the size range at both ends. Geographic reach is evidenced by three regional estates for the United Kingdom, United States and Asia-Pacific rather than claimed. Functional coverage is enumerated product by product across sixteen products in three named groups, and the buyer roles are addressed throughout, being support services, resourcing leads, finance, pricing, billing and partnership management.

In-house legal is addressed on a surface of its own, Impact Analytics carrying a dedicated corporate legal page aimed at optimising outside counsel spend. R15 applies to the practice-area limb and the note says so: this is business-of-law infrastructure whose function does not vary by whether the firm does patent litigation or private client. What holds it off A is that no limit is stated. Nothing identifies a firm size floor, no segment is named as out of scope, government use is neither claimed nor excluded, and nothing states which of the sixteen products are available in which of the three regions. Verified 12 September 2026.

Source: Vendor Published
Sources on file

4 public documents

The public pages on file for BigHand, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.

Pricing

No published figure

  • BigHand publishes what is in each package but not what any of it costs.
  • The Pricing and Packaging page is genuinely useful as far as it goes. Seven product families are broken into named tiers, mostly Standard, Plus and Advanced, with a table for each showing which features you get at which level. Workflow Management, for example, gives you real-time workflow, mobile access and voice task submission at Standard, adds forms, deadline management and process reporting at Plus, and adds timesheets and utilisation reporting at Advanced, with speech recognition, an outsourcing module, a service provider gateway and an SDK all available as paid add-ons on any tier.
  • What you will not find is a number. There is no price for any tier, and, more awkwardly, no statement of how you are charged at all. Nothing says whether you pay per user, per fee earner, per office or per product, so you cannot even estimate. Every button on the page leads to a form asking you to request pricing.
  • There is also no customer contract published anywhere, so the commercial terms behind the packages, the length of the deal, what happens at renewal and whether prices can rise, are all things you will only see once you are in a sales conversation.

Published tier structure across seven product families with no figure and no unit of charge. Workflow Management is offered in Standard, Plus and Advanced, with Standard covering real-time workflow, mobile access, voice task submission and workflow administration; Plus adding form task submission, a form designer, email task submission, task retention and search, deadline management and process reporting; and Advanced adding timesheets and utilisation reporting.

Four optional add-ons are named as available in any tier: speech recognition, an outsource module, a service provider gateway and an SDK. Resource Management is offered in Standard and Plus, Standard covering skills and career tracking, assisted forecasting, a lawyer dashboard, a forecast calendar, scheduling by workbook and matter, automated forecast reminders and reporting, and Plus adding resource manager and partner dashboards, an opportunities board, resource request management, candidate shortlists and selection, role assignment, an advanced reporting suite and matter management.

Document Creation runs three tiers from template management and Microsoft Word and document management system integration at Standard, through formatting, styling and document ID stamping at Plus, to a content and clause bank, front-end profiling and cross-referencing at Advanced, with integration to BigHand Workflow or Dictation as an add-on. Metadata Management runs two tiers, Standard covering Microsoft Office and document management system integration and cleansing of Office, PDF, open document, audio, video and image files, and Plus adding prompts on reply and external send plus single and batch redaction.

Matter Pricing runs three tiers from single-currency budgets and actuals tracking to multi-currency, portfolio arrangements and advanced pricing tools. Business Intelligence runs three tiers differentiated by the number of visualisation dashboards on top of a data warehouse and self-service cube. Pitching and Proposals is a single Standard tier covering opportunity tracking, experience and case study management, CV and biography management, CRM and document management system integration, marketing document automation across Word, PowerPoint and Excel, directories submissions, content management and marketing reports.

No figure, band, minimum, term or renewal provision is published for any tier, no unit of charge is stated, and each product routes to a Get Pricing request form.

Confidentiality and data terms: No business associate agreement is offered as a signable instrument, and no customer agreement of any kind is published, but this vendor is unusual in claiming HIPAA compliance directly and it is recorded here rather than dismissed. The privacy policy states that the group is GDPR compliant with a published Information Commissioner's Office registration number, HIPAA compliant, DCB0129 compliant for NHS clinical risk management, and meets the requirements of the Data Security and Protection Toolkit, which is the assurance regime for organisations handling English health and care data. The trust centre describes protecting customer data including sensitive legal and medical information. That combination of legal and health assurance is rare in this corpus and is consistent with an estate whose dictation and workflow products are sold beyond law firms. What is absent is the instrument: nothing published is signable, no business associate agreement, data processing addendum or processor terms exist on the estate, and the underlying certifications sit behind a trust centre that returned no readable body to this index's fetcher. Certifications claimed are ISO 27001, ISO 27701, SOC 2 Type 2, Cyber Essentials and Cyber Essentials Plus, with A-LIGN named as auditor in the published badges and ISO 14001 certified by BSI.

Note: Tier structure and feature contents read directly from the vendor's own Pricing and Packaging page on 12 September 2026, which publishes named tiers and feature matrices for seven product families: Workflow Management in three tiers with four named add-ons, Resource Management in two, Document Creation in three, Metadata Management in two, Matter Pricing in three, Business Intelligence in three, and Pitching and Proposals in one. entryPriceUsd is null because no figure is published anywhere on the estate, and entryPriceDisplay is empty per R10 and R19, which reserve the display field for a figure or nothing. Currency is not set because no charging currency is stated. The row is written under R17 rather than R10: the published structure lifted Commercial Transparency above D, and the mechanical test is that where pricing evidence lifts the axis off the floor a row is owed even though no figure exists. The absence that matters most is recorded in pricingBasis and repeated here because it is unusual: not only is there no figure, there is no unit of charge, so nothing states whether the products are licensed per user, per fee earner, per site, per module or per firm, and a buyer cannot scale even a rough estimate from what is published. Every call to action on the packaging page routes to a Get Pricing form. No customer agreement is published, so no term, renewal, uplift or minimum commitment could be read either.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Purpose limited, in the contract

The customer agreement or data processing addendum contractually limits use of Customer Data to providing the contracted service, and no surface names training either way. The limit is bound, which a policy page is not, but it is not an express training prohibition. If any surface names training in either direction, one of the other values is true and this one is not.

Customer content is confined to service provision by a published purpose limitation, and no training prohibition is stated in those words, which is this value. The limitation is express and it sits in an instrument that expressly reaches the products rather than only the website: the privacy policy states that it covers the vendor's website, tools, solutions, products and services including any AI tools it utilises. Within it, Customer Data is defined as the data input during use of the products, acknowledged as potentially containing personal or sensitive personal information about the customer's own clients, and governed by two statements, that it is processed only at the direction of customers when they upload it, and that the vendor does not use it other than to provide the products to its customers.

That confines use to delivery and would exclude model training as a matter of construction. What it does not do is say so. No sentence anywhere states that customer content is not used to train, refine or improve models, and no separate AI or trust statement was located that does. R43(1) was run: there is no published customer agreement on the estate in which a contractual term could sit, only website terms of use, so the contractual values are unavailable rather than declined.

Two qualifications belong on the record. The same policy reserves broad use and disclosure of Customer Data for a defined set of Business Purposes, and it separately notes collection of non-personal derived information including usage information and aggregate statistics to develop and support the products.

Source: Vendor PublishedWe do not use it other than to provide our Products to our CustomersAs of Sep 12, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Disclosed without a period

Retention is acknowledged in public materials with no stated period.

Retention is addressed and no period is stated, which is this value. The privacy policy has a retention section and it does three things: commits to keeping personal information only as long as necessary for the purposes described, notes that certain information must be kept for certain periods to meet legal and regulatory obligations, and states that the vendor minimises what it retains and de-identifies it. It then puts the specifics behind a request, inviting the reader to ask about the periods by contacting the data protection manager.

That is a real position without a number, which is the distinction this value draws. Nothing narrows it for the AI. No separate window is published for the material this signal is about, and on this product that material is unusual and worth naming: Impact Analytics ingests and re-encodes timecard narratives, so what the model has processed is not a discardable prompt but a modified record inside the firm's own billing history, and nothing states how long the original, the re-coded version or any intermediate working is kept.

Deletion is addressed only as an individual right rather than as a customer-level commitment on termination, and no return or export obligation was located. There is no published customer agreement in which any of this could be pinned down.

Source: Vendor PublishedWe only keep Personal Information for as long as necessary for the purposes for which we use itAs of Sep 12, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Claimed, not documented

Segregation is asserted in public materials with no published detail on how it is enforced.

Access control is claimed and no permission model is described, which is this value. The claim appears in the privacy policy's security section as one of six assurances, that access to personal information is recorded and controlled, alongside trained personnel, physical security, network protection, audit and review, and contractors held to the same standards. Product-level fragments appear in the packaging tables rather than in any documentation: Resource Management lists role assignment, user reporting and candidate shortlists, Workflow Management lists workflow administration, and Metadata Management lists self-service administration.

None of that describes a permission model. Nothing published sets out roles, groups, or how a firm restricts who sees what, and there is no security or administration documentation on the estate in which it might sit; the trust centre that would ordinarily carry it returned no readable body. The question has a specific edge on this product and it is recorded rather than left implicit. Timecard narratives describe work done on named client matters, and Impact Analytics aggregates them into firm-wide dashboards on cost, staffing and diversity.

Nothing published states whether those dashboards respect matter-level or client-level confidentiality restrictions, or whether a partner viewing a diversity dashboard can see activity on matters they are walled off from.

Source: Vendor PublishedAccess to Personal Information is recorded and controlledAs of Sep 12, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Disclosure addressed, notice absent

Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.

Compelled disclosure is addressed squarely and customer notice is absent, which is this value. The privacy policy reserves the right to use or disclose any Customer Data, expressly including personal information, as needed to comply with any law, regulation or legal request, to protect the integrity of the products, to cooperate in any law enforcement investigation or an investigation on a public safety matter, to protect or defend the legal rights or property of the vendor, its group members, its customers or any other party, or in an emergency to protect health and safety.

Those are grouped and defined as Business Purposes. The reservation is unusually broad on two counts worth naming: it extends to Customer Data rather than only to the vendor's own records, and the trigger includes a legal request rather than only a binding order, which is a lower threshold than most records in this corpus set. One mitigation is published and is recorded because it is real: the vendor commits to limit use or disclosure to what is necessary for the objective, including de-identifying or anonymising the customer data as practicable.

What appears nowhere is notice. Nothing states that the customer would be told a demand had been received, given an opportunity to object or to seek a protective order, or informed afterwards. No transparency report was located.

Source: Vendor PublishedWe reserve the right to use or disclose any Customer Data (including Personal Information) as needed to comply with any law, regulation or legal requestAs of Sep 12, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Not addressed

No located public material identifies the corpus behind the product’s answers.

No located public material identifies any source corpus, and R15 governs the weight, so the note states the position rather than leaving it to inference. This product answers from no body of law. The AI reads the customer's own timecard data and routes the customer's own email, so there is no legal corpus whose provenance or licensing this signal would ordinarily test and the vendor is not withholding something its product class implies.

What is genuinely unaddressed, and why the value is recorded rather than treated as inapplicable, is the training material behind the models. Nothing states what the timecard classifier was trained on. The question is not academic on this product: a model that re-encodes narrative time entries into phase and task codes has to have learned that mapping from somewhere, and the obvious candidate is timecard data from other law firms.

Nothing published says whether the models were trained on customer data, on synthetic or licensed data, or on an industry corpus, and nothing states whether one firm's coded history informs the model another firm uses. The purpose limitation graded on the training row points against pooling but does not answer the provenance question. The surfaces read on the date shown were the Impact Analytics product pages, the home page, the packaging page, the privacy policy, the terms and the trust centre metadata.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

No located public material addresses whether authority is checked for subsequent history, and on this product the question does not arise. Nothing in the estate cites law. The sixteen products cover workflow routing, resource forecasting, dictation, document production and formatting, metadata cleansing, redaction, pitching, business intelligence, matter pricing, budgeting, partner performance, prebill review and alerting, and none produces a proposition about the state of the law whose treatment a lawyer would verify.

R15 governs and the limb is recorded as inapplicable rather than failed. One adjacency is named so it is not mistaken for the thing: Document Creation maintains template and clause bank automation, so the currency of a firm's own precedent library is a real question on this estate, but that is the customer's content management rather than the vendor checking legal authority, and nothing published describes any staleness mechanism for it either.

The surfaces read on the date shown were the home page with the full solution navigation, the packaging page setting out every product's feature set, the Impact Analytics pages, the privacy policy and the terms.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

No located public material describes what the system does when it cannot produce a reliable answer. The surfaces where it would appear were read on the date shown: the home page, the Impact Analytics product and corporate pages, the packaging tables, the Workflow Management spring release notice, the privacy policy and the terms. None states that any AI feature declines, flags low confidence, marks an uncertain classification for review, or escalates an ambiguous input to a person.

The published account is uniformly confident, describing AI that converts complex, inconsistent and often dirty billing data into reliable insight, and email routing that sends work to the right resource. The gap matters more here than the product class might suggest, and the note says why. A timecard classifier working on inconsistent narratives will encounter entries it cannot code with confidence, and what it does then determines whether a firm's billing data is improved or quietly corrupted: an entry coded wrongly and silently is worse than one flagged as unclassifiable.

Nothing published indicates which way the system errs, whether a confidence score attaches to a re-coded entry, or whether low-confidence codings are surfaced for human review before they enter the billing record.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

None located

No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.

Searched on 12 September 2026, on the company name and on the AI product name, against published trackers and coverage of decisions on AI-generated fabricated citations, including coverage of the Damien Charlotin AI Hallucination Cases database and reporting on the 2025 and 2026 sanctions decisions in the United States federal and state courts. None located. Under R119 this signal records fabricated citations and nothing else, so it is not a litigation history and no other proceeding involving the vendor would appear here.

One point of context is recorded because it bears on how the absence should be read: the exposure this signal tracks arises where a product generates legal authority for filing, and nothing in this estate does. The analogous failure for this vendor would be a mis-coded or machine-altered time entry narrative reaching a client's invoice, which no tracker records and which would surface, if at all, as a billing dispute or a client audit rather than as a sanctions order.

Source: Bar Guidance or Court RecordAs of Sep 12, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No located public material engages with bar or ethics guidance, in general terms or otherwise. No bar opinion is cited anywhere on the estate, no professional conduct rule of any jurisdiction is named, and nothing maps a product or an AI feature to the obligations of the lawyers whose work it processes. Nor is professional responsibility engaged generically: there is no requirement that customers use the products consistently with their professional obligations, which is the clause that would ordinarily sit in a customer agreement, and no customer agreement is published.

The regulatory engagement that does exist runs to data and security regimes rather than conduct, the vendor citing GDPR with an ICO registration, HIPAA, the NHS clinical risk management standard DCB0129 and the Data Security and Protection Toolkit. Those bind the vendor as a processor, not the customer as a lawyer. The gap has a specific edge that is recorded rather than passed over. Billing conduct is among the most closely regulated areas of professional responsibility in every jurisdiction this vendor sells into, and this estate re-codes time entry narratives, reviews prebills and prices matters.

Guidance on what a lawyer may do when software alters the description of work billed to a client is exactly the material a firm would want, and none is referenced.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure, and the product sits inside a fee relationship between a lawyer and a client where those savings would change the bill.

Savings claims are published, the product sits inside a lawyer-to-client fee relationship at the closest range in this corpus, and nothing addresses billing disclosure, which is this value. The savings claims are quantified and published throughout: 81 hours saved per fee earner per year, four hours per user per week, around three weeks from time entry to bill, a 28 per cent reduction in the billing and collections lifecycle, a 23 per cent average reduction in write-offs and a 20 per cent increase in realisation.

The proximity to the bill is the point. Impact Analytics uses machine learning to re-encode the narrative and coding of time entries; PrebillManager surfaces issues in time recording, narratives and rates before invoices reach clients; Matter Pricing sets what the client is quoted. So a model touches the description of work that a client is charged for. Nothing published addresses the consequence. No per-matter record of AI-assisted work is described, nothing states that a re-coded entry is identified as machine-altered in the firm's records or on the invoice, and no guidance on fee or disclosure treatment appears anywhere.

R124(1) governs the temptation to grade this higher: a pipeline that touches time entries is not by itself a record of AI-assisted work, and attribution rather than capture is the limb. The commercial framing points the other way, toward realisation and recovery rather than disclosure.

Source: Vendor Publishedclean timecard narratives to inform future resource plans, accurate billing, tracking, and reportingAs of Sep 12, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Not addressed

No located public material supports a client side disclosure obligation.

None of the three artifacts this signal looks for was located, which is the floor, and the note distinguishes what is absent from what could not be read. No subprocessor list exists on any readable surface: the privacy policy names categories only, service providers providing technology and infrastructure support, professional advisors and group members, and no individual processor is identified anywhere. No model provider statement exists at all, the AI being described only by function, so a firm asked which third party processes its timecard narratives could not answer.

No forwardable client-facing disclosure pack was located, and no data processing addendum is published. The distinction worth recording is that a trust centre exists at a published address and returned page metadata with no body to this index's fetcher, which is a documented persistent limit of that platform rather than a fault of the site; its own description mentions security and privacy certifications and ESG policies rather than subprocessor or model disclosure, but the underlying documents could not be inspected and it is named here as what would move this row.

The value is not on-request, because nothing indicates that an OCG-shaped pack exists behind any request process; it is recorded as unaddressed on the readable estate.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Not addressed

No located public material addresses court disclosure or verification certification.

No located public material addresses disclosure of AI involvement in legal work, and on this product the relevant forum is a client or a fee assessor rather than a court, which the note states rather than forcing the signal. Nothing this estate produces is filed. The AI re-encodes timecard data and routes email, and the wider suite produces internal management reporting, documents and invoices, so the certification regimes now attaching to court filings in several jurisdictions do not reach this output.

Within the narrower frame the position is a complete absence. Nothing identifies a time entry whose narrative or coding a model altered, nothing distinguishes an original entry from a re-coded one in any published description, no audit or provenance trail for the AI's changes is described, and no export, template or certification designed to evidence machine involvement was located. The realistic route to a tribunal is indirect and specific, and it is recorded because it is the version of this question that actually bites here: a bill assessed by a court or a client's audit turns on what the timekeeper recorded, and if a model rewrote that narrative, nothing published would let the firm establish afterwards which words were the lawyer's own.

Source: Vendor PublishedAs of Sep 12, 2026Evidence
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 13, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746