B
BlackBoiler
BlackBoiler is AI contract review software that applies a legal team's own negotiation standards to incoming contracts as first-pass tracked changes inside Microsoft Word. Rather than proposing clause language from a general model, it turns material the organisation already has — prior redlines, approved language, fallback positions and written playbook guidance — into executable playbook logic, then marks up a new agreement against it and returns the result as tracked changes and comments in the document the reviewer already has open.
The lawyer decides what to accept, change, reject, escalate or negotiate, and the vendor states plainly that playbook coverage may be incomplete and that unusual provisions will need a fresh legal decision. The company has worked on automated contract editing since before the current wave of legal AI and holds eleven US patents covering document revision, playbook-driven markup and clause handling, with further applications pending in the United States, Canada and Europe; it is a National Science Foundation SBIR award recipient and a Virginia Innovation Partnership Corporation portfolio company.
In June 2026 it launched Veris, adding a conversational generative layer inside the Word add-in for building playbooks in plain language, revising or removing provisions, and interrogating a clause against the standards already guiding review, together with a validation step that checks a proposed edit against the intended outcome before it reaches the lawyer. Buyers are in-house legal teams, law firms and contract managers handling recurring agreement types such as NDAs, service agreements and subcontracts, with a dedicated offering for construction and AEC contracting.
BlackBoiler sells through published Starter and Pro subscription tiers with a seven-day trial and self-serve card payment, and a scoped Enterprise tier adding unlimited documents, SSO, API access, playbook build support and negotiated commercial terms and service levels. It states that it is SOC 2 Type II certified, with the report available to prospective customers through a security review, and it is hosted on Amazon Web Services.
Its Access Services Agreement is published, leaves ownership of contract data with the customer, and bars use of that data to train third-party foundation models unless the customer authorises it.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Remove the models and nothing remains to sell. The product is an automated contract editing engine: it converts an organisation's prior redlines, approved language and written guidance into executable playbook logic, applies that logic to a new agreement, and returns tracked changes and comments in Microsoft Word. There is no repository, workflow or signature product underneath it that would still function without the models.
The June 2026 Veris release adds a generative, conversational layer for playbook building and clause interrogation on top of the patented deterministic editing engine, so the platform now carries both a rules-driven and a generative component and both are the product rather than a layer on it. Eleven US patents are stated to cover document revision, playbook-driven markup and clause handling. Checked 8 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real, documented and unusually traceable, but no accuracy figure is published. The vendor describes a four-stage chain in its own words: evidence (the customer's prior redlines, approved language and guidance), logic (how those materials become executable rules), checking (a stated judge validator assessing whether a proposed change aligns with the intended outcome, plus statistical similarity checks), and output (tracked edits and comments returned for lawyer review).
The earlier ContextAI capability surfaces, for each redline, the playbook rule that prompted it and prior examples of the same edit inside the organisation, which is a provenance trail a reviewer can open for every proposed change. Failure modes are named plainly rather than implied: the vendor states that playbook coverage may be incomplete, that contract language may depart from prior examples, and that unusual provisions may require a lawyer to make a fresh decision.
R15 governs the limbs that do not bite: this product cites no legal authority and has no citator, so the primary-authority and citation-status limbs are inapplicable rather than failed, and the grounding limb is read against the customer's own approved language, which is what the output is actually grounded in and which is surfaced to the reviewer. A is unavailable because no measured accuracy figure and no test set are published anywhere. Checked 8 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
All four A limbs are published, and the commitment sits in the customer agreement rather than in marketing alone. What the system runs alone: the first-pass markup, producing tracked changes and comments. What constrains it: the customer's approved playbook positions, with rules reviewed and approved by the customer before use. The review surface: Microsoft Word track changes, in the document the reviewer already has open.
The route back to human judgement: the reviewer decides what to accept, change, reject, escalate or negotiate, and the vendor states that new risks, exceptions and negotiation decisions are left to the appropriate reviewer. The threshold at which the system stops is structural and stated rather than numeric, which is what most records in this lane leave unstated: nothing is applied to the agreement without the reviewer accepting it, because the output is a proposal in tracked changes.
Clause 3(b) of the Access Services Agreement carries the same position contractually, stating that use of the Services is not a substitute for and shall not take the place of review and analysis by a qualified lawyer. Unlike the Case Status record under R37 there is no marketing claim anywhere that the system handles review autonomously, so no contradiction reveals a missing limb. Checked 8 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
The C band describes this record in its own words: unattributed testimonials and logo-level customer claims stand in for evidence. Four testimonials are published, attributed only to a first name and surname initial or to a verified user, in the shape review-platform content takes, and none carries an organisation or a figure. The customer base is described at category level, as AmLaw 25 law firms and Fortune 1000 organisations with several customers in construction, but no customer is named anywhere on the estate and no case study, deployment figure or before-and-after measurement is published.
Awards and research funding were considered and are not counted as deployment evidence: a 2021 AI Breakthrough award, a National Science Foundation SBIR award and Virginia Innovation Partnership Corporation portfolio status are recognition and capital, not evidence of production use. One structural point belongs in the note rather than the grade, because it may explain the absence rather than excuse it: clause 12(c) of the Access Services Agreement is a mutual no-publicity provision under which neither party may issue any public statement mentioning the other without prior written approval, so named references would require a per-customer waiver. The grade records what is locatable, not a judgement about why. Checked 8 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments across most of the ground, held at B by the limb R33 makes mandatory. What is published and readable before signing: customer ownership of all contract data under clause 7(b); a contractual bar on training third-party foundation models absent customer authorisation; a purpose limitation confining use of customer data to configuring, improving, supporting and operating that customer's own use of the service; a statement that customer data is not used to train models shared with other customers; customer-specific isolation with dedicated instances available on enterprise deployments; access limited to authorised personnel with access controls and logging; encryption in transit and at rest; and a mutual confidentiality regime running five years with trade secret protection surviving indefinitely.
Two limbs are missing and both are required for A. Privilege and work product are not addressed anywhere, expressly or by implication, which under R33 is dispositive on its own and is the limb this axis exists to test. And the position on what a third-party model provider may retain cannot be stated because no model provider is identified anywhere on the estate, so a buyer cannot establish whose model touches its contract text or what that provider's retention terms are. Checked 8 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
A real position on advice versus tooling is published, and it sits in the customer agreement rather than only in a website disclaimer, which is stronger than the C band's boilerplate-in-the-terms pattern. Clause 3(b) of the Access Services Agreement, headed Review of Outputs and No Legal Advice, states that use of the Services is not a substitute for and shall not take the place of review and analysis by a qualified lawyer.
The supervision and competence dimension is addressed rather than omitted: the vendor sells expressly to contract managers and procurement staff who are not lawyers, and answers the question directly, stating that a lawyer reviews the redline before anything moves forward and handles exceptions, new risks and negotiation decisions. The marketing does not describe the product in advice terms anywhere; it consistently describes a first pass returned to a lawyer.
A is unavailable because jurisdiction limits are named nowhere: no statement identifies which jurisdictions the product is appropriate for, and the only geographic restriction located is a website terms provision limiting site use to United States residents, which governs the website rather than the service. Checked 8 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
No governance position is published for a system whose output is proposed contract language. Nothing identifies who inside the vendor is accountable for AI governance, no pre-release testing regime is described, no evaluation results are disclosed, and nothing addresses uneven output across contract types, counterparties or drafting conventions. There is no responsible AI page, no principles statement, no model card, no AI policy and no certification such as ISO 42001, and no third-party governance assessment is referenced.
The C band was tested and does not fit: C describes principles published without a mechanism, and here there are no published principles at all. The one candidate consideration is recorded and rejected on the no-double-spend rule: the vendor does describe validation machinery, a judge validator assessing alignment to intended outcome and statistical similarity checks. That is product quality control on individual outputs, it is spent on Citation Accuracy and on Autonomy where it answers those axes directly, and it is not a governance position about how the vendor builds, tests and is accountable for its models. The grade records what is locatable on this axis as of the date. Checked 8 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy covering most of the ground, short of the full set in exactly the two ways the B band names. Published and specific: retention is addressed, with customer data retained for the duration of the customer relationship unless otherwise agreed; deletion is available at contract end or earlier on customer request; access control is described concretely across two documents, with access limited to authorised personnel who need it, access controls and logging, and infrastructure access secured by VPN, secure tokens and IP whitelists issued only to approved employees; encryption is stated as AES256 at rest and TLS in transit; backups are confirmed and stated to be encrypted; and clause 7(b) confirms the customer owns its data and that the vendor will not sell it.
Two elements are absent and both are the B band's named shortfalls. No subprocessor list is published anywhere, so a buyer cannot enumerate who touches its data; only Amazon Web Services for hosting and Stripe for payment processing are individually named. And no incident or breach notification practice is published on any surface. One disclosed detail is recorded because it is the kind of candour this index credits under R65 rather than penalises: the vendor states that individual client files may in some instances be temporarily downloaded onto an employee's encrypted hard drive for testing. Retention carries no stated period, which is graded on the retention signal rather than here. Checked 8 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A real published position on liability, complete on three of the four A limbs, held at B on what a buyer can actually invoke when the output is wrong. Published and specific in the Access Services Agreement: indemnity scope, at clause 9(a), covering third-party claims that the Services infringe or misappropriate US intellectual property rights, with the vendor controlling defence and holding modify, replace or terminate options; carve-outs at clause 9(a)(iii) for use in unauthorised combination, customer modifications, Customer Data and Third-Party Products; and a cap at clause 10 limiting aggregate liability to amounts paid in the twelve months preceding the claim, with named exceptions for confidentiality breach, IP infringement, customer payment obligations and breach of the use restrictions.
What is not available is anything a buyer can invoke when the AI output itself is wrong, and the agreement says so rather than leaving it ambiguous. The IP indemnity does not reach output quality; clause 8 disclaims all warranties express, implied and statutory; clause 3(b) defines the risks of relying on any edit, redline, comment, summary, suggestion or analysis as Customer's Assumed Risks; and clause 9(b)(ii) requires the customer to indemnify the vendor against third-party claims arising from those assumed risks.
No insurance is referenced. Under R65 this is disclosure of an adverse allocation rather than a gap between marketing and agreement, and it is written as the vendor telling the buyer where it stands: nothing contradicts it, and the record is graded consistently with Juro, whose published exclusion of AI output from the indemnity earned the same grade. Checked 8 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
One integration exists, it is into the system this work actually lives in, and its depth is described well; the rest of the practice stack is named without documentation. The Microsoft Word add-in is the delivery surface rather than a connector, and what it does is set out concretely: the review runs inside Word without moving to a separate environment, the playbook is selected in the document, and the output returns as native tracked changes and comments for the reviewer to accept, change or reject.
For a contract redlining product that is the integration that matters most, and it is the reason the product fits a reviewer's existing workflow rather than requiring migration. Beyond it the picture thins. SSO and API access are named as enterprise entitlements with no description of what the API exposes or what a firm must configure. No document management or contract lifecycle management platform is named anywhere as an integration partner: the vendor positions itself explicitly as sitting alongside a CLM at the point the CLM leaves open, and describes handing back to the customer's existing process, but no named connection to any CLM, DMS or e-signature system is published.
A requires documented integrations plural into the systems legal work lives in, with sync direction and configuration described, and that is not available here. Checked 8 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Tenancy is stated and region is not, which under R38 clears C because tenancy and region are co-equal limbs and publishing either one lifts the grade off that floor. Published on tenancy: customer-specific isolation measures are used to keep customer data separate, enterprise deployments may include dedicated customer instances and customer-specific data separation controls, and data is described as held in a silo accessible only to the client and necessary vendor staff.
Published on infrastructure: the service runs on Amazon Web Services, with production, staging and development infrastructure all stated to be in AWS. What is absent is any region at all. No AWS region is named, no choice of region is offered, no European or other non-US option is described, and processing location is nowhere distinguished from storage location, which matters for a product marketed to law firms and to a construction and AEC sector that contracts internationally.
The vendor also states expressly that it does not publish detailed architecture or infrastructure detail publicly, so this is a disclosure decision rather than a retrieval limit and it is recorded as such. This record sits in the band gap R38 logged and left unfixed: a vendor publishing tenancy alone fits neither B nor C cleanly, and B is taken because C's words, that neither the tenancy model nor the region is stated, are false here. Checked 8 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
A real named certification without scope or date, and no way to obtain the report without a sales conversation, which is the B band precisely. The vendor states on two separate surfaces that it is SOC 2 Type II certified. What is not published: the auditor is not named, the audit period or report date is not stated, the scope of the assessment is not described, and no other certification or attestation is claimed anywhere, with no ISO 27001, HIPAA attestation or public penetration test summary located.
Access to the report is sales gated and therefore earns no credit under R5: the report is available to qualified prospective customers on request through the sales or security review process, and the vendor states that additional security materials and completed security questionnaires are reserved for enterprise evaluations while standard team and individual subscribers are directed to the public page. C was tested and does not fit: C describes badges with no scope, no date and no report available, whereas here a specific standard is named and a substantive self-published Security and Trust page sits behind it, carrying a seventeen-question security FAQ covering hosting, encryption, isolation, access, retention, deletion, backups and authentication.
That page is a genuine trust surface, self-published rather than a hosted portal, but it carries no reports, dates or covered standards, so A is unavailable. Checked 8 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The vendor refers to generative AI throughout and identifies nothing that sits underneath it, which is the C band in its own words. No model is named, no model provider is named, and no architecture is described beyond the four-stage evidence, logic, checking and output framing. The gap is sharpened rather than softened by the agreement, which concedes the category while naming no participant: clause 7(b) permits processing Customer Data using third-party infrastructure, technology and artificial intelligence services, and separately bars training third-party foundation models absent customer authorisation, so the vendor's own contract establishes that third-party models are in the supply chain a customer inherits while no surface identifies which.
The Third-Party Products definition offers only a generic example. Two named third parties were considered and neither reaches this axis. Amazon Web Services is infrastructure, and under R29 test 1 naming a cloud host says where a model runs rather than whose model it is; Stripe is a payment processor and touches no contract content, being expressly routed outside the Word add-in and the conversational interface. D was tested and does not fit, because D requires nothing published about the model supply chain and the agreement does address the category and constrain it.
Change notification is not reached: with no models or providers named, notification would be the fourth limb of an A the record cannot approach. Checked 8 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Real pricing is published for part of the range with the enterprise tier withheld, which is the B band verbatim. Published: three named tiers, Starter, Pro and Enterprise; a monthly and annual billing toggle stating that annual billing saves 17 per cent; a seven-day trial with an express statement that a credit card is required and that the selected subscription begins when the trial ends unless cancelled; and an itemised account of what Enterprise adds over the fixed plans, covering unlimited documents, users and teams scaled to the organisation, SSO, API access, playbook build and maintenance support, guided onboarding, a dedicated success manager and the option of custom contract terms and service level commitments.
Enterprise is stated not to be published as a rate, with the reasons given as contract volume, users and teams, playbooks and agreement types in scope, and security, deployment and support commitments. The agreement adds commercial terms most of this lane leaves unpublished: fees payable in US dollars, 1.5 per cent monthly interest on late payment, suspension after ten days, automatic renewal for successive terms equal to the initial term, and thirty days notice of non-renewal.
The purchase path is self-serve, with card and wallet payment accepted. One retrieval limit belongs here and is not graded against the vendor: the Starter and Pro figures render client-side and the plan cards returned a loading state, so the figures themselves were not read, and the vendor's own June 2026 launch PDF confirms the tiers exist without publishing rates. A is unavailable on what was established rather than on what is absent. Checked 8 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment and practice coverage is described with substance, with the boundaries left open. Three buyer segments are set out separately, each with its own stated position rather than a shared line: in-house legal teams reviewing the same agreement types at volume, law firms applying set positions across client matters, and contract managers applying standards the legal team has already defined. One vertical has a dedicated page and product framing, construction and AEC contracting, and it is supported by the vendor's category-level claim of several construction customers.
Agreement types are named rather than implied: NDAs, service agreements and subcontract agreements are identified as the recurring types the product is built for, with more complex contracts stated to be within scope subject to playbook coverage. The product's own limit is stated honestly, that usefulness depends on playbook coverage, the language and context of the agreement, and lawyer review, which is more than most records in this lane publish about where they stop working.
A is unavailable on two limbs. Practice areas are not addressed as such, since coverage is organised by agreement type and industry rather than by practice; and government use is nowhere described, the only government-adjacent material being a US Government Rights clause in the agreement, which is a contract term about licence rights rather than a statement of coverage and is not counted here. Checked 8 September 2026.
4 public documents
The public pages on file for BlackBoiler, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.
-
blackboiler.com5 signals
Primary Law Corpus Provenance, Good Law Verification, Refusal and Uncertainty Behaviour and 2 more
Read Sep 8, 2026
-
blackboiler.com/security3 signals
Prompt and Output Retention, Ethical Walls and Matter Segregation, Outside Counsel Guideline Readiness
Read Sep 8, 2026
-
blackboiler.com/service-terms3 signals
Client Data in Training, Third Party Request and Subpoena Notice, Bar Guidance Alignment
Read Sep 8, 2026
-
blackboiler.com/pricing1 signal
Billing and Fee Posture
Read Sep 8, 2026
No published figure
- BlackBoiler sells three plans. Starter and Pro are fixed subscriptions bought self-serve with a card, and Enterprise is scoped and quoted. Paying annually saves 17 per cent. A seven-day trial runs on your own recurring agreement, requires a credit card, and rolls into the plan you picked unless you cancel before it ends. Enterprise is where unlimited documents, SSO, API access, playbook build support, guided onboarding, a dedicated success manager and negotiated contract and service level terms sit.
Published tier structure with figures on the fixed plans and the enterprise tier withheld. Three named plans: Starter, Pro and Enterprise. A monthly and annual billing toggle is published with annual billing stated to save 17 per cent. Enterprise is expressly not published as a rate, and the vendor names the factors that set it: total contract volume, number of users and teams, playbooks and agreement types in scope, and the security, deployment and support commitments required.
What Enterprise adds over the fixed plans is itemised rather than gestured at, covering unlimited documents, users and teams scaled to the organisation, SSO, API access, dedicated playbook build and maintenance help, guided onboarding, a dedicated success manager, and the option of custom contract terms and service level commitments in place of a fixed plan. Trial terms are published in full: seven days, run against the buyer's own recurring agreement, credit card required, and the selected subscription begins when the trial ends unless cancelled beforehand.
The vendor publishes unusually direct checkout guidance, telling the buyer to verify the selected plan, the price, the billing frequency, the trial end date and the first payment date before confirming. The purchase path is self-serve, with Visa, American Express, Apple Pay and Google Pay accepted and payments routed to Stripe. The Access Services Agreement adds the commercial mechanics: fees payable in US dollars without offset or deduction, 1.5 per cent monthly interest on late payment, recovery of collection costs, suspension of access after ten days past due, automatic renewal for successive terms equal to the initial term, and thirty days' written notice to prevent renewal, with no refund on termination.
Taxes are excluded and payable by the customer. One retrieval limit, recorded as such and not graded against the vendor: the Starter and Pro figures render client-side and the plan cards returned a loading state on fetch, so the rates themselves were not read first-party. The vendor's own launch release of 11 June 2026 confirms the Starter and Pro tiers were introduced alongside Veris but publishes no figures. A named trade publication reported both rates at launch; that is not a first-party source, nothing here is graded on it, and it is named only so a later reader knows it was seen and set aside rather than missed. entryPriceUsd is null because no figure was established first-party, not because none is published.
Surfaces read on 8 September 2026: the pricing page and its FAQ, the launch press release PDF, the home page footer payment methods, and the Access Services Agreement in full.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Training occurs only where the customer has affirmatively enabled it.
The published Access Services Agreement, last modified 31 August 2026, was located and read in full before this value was written. Clause 7(b) sets the default at no training and makes customer authorisation the gate, which is opt-in rather than a flat contractual bar. contractual-never was tested and declined because it would assert something the clause does not say: the express prohibition names third-party foundation models specifically, and it carries a carve-out for customer authorisation or an applicable Order.
The same clause purpose-limits every other use, permitting the vendor to use and retain customer data including edits, redlines, playbook positions, rules, prompts, workflows and configurations to configure, improve, support and operate that customer's own use of the service, and confirming the customer owns the data and that the vendor will not sell it. That purpose limitation is what keeps the public claims and the agreement aligned rather than in tension, so this is not a marketing-versus-agreement divergence and is not written as one: the security page states that customer data is not used to train models shared with other customers and that customer data remains dedicated to that customer's use, and the homepage states that contracts, playbooks, redlines and negotiation positions are not used to train models or to improve the product for other companies.
The aggregated statistics provision at clause 2(f) was tested against the R28 rule that the clause must name the thing and does not reach this signal: it operates on anonymised statistical and performance information, is expressly barred from identifying the customer or disclosing confidential information, and names neither machine learning nor training. One gap belongs in the record: the express bar covers third-party foundation models, and no clause prohibits the vendor training its own models, which is addressed by the purpose limitation rather than by prohibition.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is acknowledged in public materials with no stated period.
Retention is addressed directly on a first-party surface and no period is stated anywhere, which is this value exactly. The security page states that data is retained for the duration of the customer relationship unless otherwise agreed, that it may be deleted at contract end or earlier on customer request, and that deletion requests are processed subject to applicable legal, security, backup and operational requirements.
Clause 7(b) of the agreement separately permits the vendor to use and retain customer data to configure, improve, support and operate that customer's own use of the service, again without a period. Two higher values were tested and neither is true. disclosed-fixed requires a stated window and none exists. customer-configurable requires the customer to control retention, and what is available is a request the vendor processes in accordance with its own operational practices rather than a setting the customer operates, so the words would be false.
The qualifier attached to deletion is recorded because it materially affects what a buyer can rely on: legal, security, backup and operational requirements are unbounded on their face and no maximum is given for how long backup copies persist after a deletion request. Termination is asymmetric in the agreement, which is worth naming: clause 11(c) requires the customer to delete or destroy the vendor's property and certify it in writing, and imposes no matching obligation on the vendor to delete customer data.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Segregation is asserted in public materials with no published detail on how it is enforced.
Segregation is asserted on first-party surfaces with no published detail on how it is enforced, which is this value. What is claimed: customer-specific isolation measures keep customer data separate, enterprise deployments may include dedicated customer instances and customer-specific data separation controls, access is limited to authorised users and required vendor personnel with access controls and logging, and the data handling page describes a silo accessible only to the client and necessary staff, with infrastructure access secured by VPN, secure tokens and IP whitelists. separate-model-documented was tested and declined because it requires a documented permission model, and no permission model is published: the vendor states expressly that it does not publish detailed architecture diagrams or infrastructure detail on its public website, and offers further material only inside an enterprise security review, so the enforcement mechanism cannot be read before signing.
The question bites on this record rather than being inapplicable, because law firms are one of three named buyer segments and the product ingests counterparty agreements across client matters. Two things are absent at the level a firm would need. Nothing addresses matter-level walls or segregation between users or matters inside a single customer tenant, the claims all operating at tenant level between customers. And inherits-dms-acl is not reached at all, since the product takes documents in Microsoft Word rather than retrieving from a document management system, so there is no source system access model for retrieval to enforce.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Terms commit to notice where lawfully permitted. No transparency report located.
The agreement commits to notice before compelled disclosure, and adds a protective-order opportunity, which places this row among the stronger ones in the lane. Section 6 of the Access Services Agreement permits disclosure of confidential information to the limited extent required to comply with an order of a court or other governmental body, or as otherwise necessary to comply with applicable law, and conditions that permission on the disclosing party first giving written notice and the opportunity to obtain a protective order.
The commitment is mutual and it is a condition on the disclosure right rather than a discretionary statement of practice, so discretionary and disclosure-without-notice are both false of this record. notice-and-report was tested and declined: no transparency report, law enforcement request report or equivalent periodic disclosure is published on any surface, and nothing states how many requests have been received. The evidence sits in the confidentiality section of the master agreement rather than in a data processing addendum or privacy policy, consistent with the pattern established across earlier pulls, and no separate DPA was located on the estate.
One limit is recorded rather than graded: the commitment attaches to confidential information as defined in section 6, and the agreement does not separately address requests directed at customer data as such, though customer data submitted under the agreement would ordinarily fall inside that definition.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
No located public material identifies a legal corpus behind the product's output, because the product carries none. It operates on the customer's own material, taking prior redlines, approved language, fallback positions and written playbook guidance and converting them into executable rules applied to the agreement under review, and it neither retrieves nor cites legal authority. The value records what is locatable on this signal and is not an accusation of vendor silence: there is no third-party corpus to name, licence or date.
This matches how the contract-review-and-drafting lane already grades the same shape, where records whose material is the customer's own paper sit at this value while records identifying an actual legal corpus take named-no-licence. A higher value was considered and declined. The vendor does identify what sits behind its output, the customer's own contract material, and clause 7(b) of the agreement does state the rights basis, giving the customer ownership and the vendor a non-exclusive royalty-free licence to use that data only as necessary to provide the service.
Crediting named-and-licensed on that basis would assert that the vendor names primary law sources and their licence footing, which is false of this product, and would credit a limb that does not apply rather than simply declining to penalise it.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
No located public material addresses whether authority is checked for subsequent history, because the product cites no authority. It proposes contract language against the customer's own approved positions and returns tracked changes in Microsoft Word; it does not retrieve cases or statutes, does not present citations, and has no citator function to describe. The value records an absence of located material on this question rather than a defect in the product, and it is the value every comparable record in this lane carries for the same reason.
What the product does check is recorded here so a later reader sees the distinction was understood rather than missed: the vendor describes a judge validator assessing whether a proposed edit aligns with the intended outcome, together with statistical similarity checks against the customer's prior examples, before the edit reaches the lawyer. That is verification of a proposed contract edit against the customer's own standards, not verification of legal authority against subsequent history, and it is graded on the citation accuracy axis where it answers the question directly.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
The vendor describes refusal or abstention behaviour in public materials.
The vendor describes abstention behaviour in public materials, which is this value. Asked directly what the limitations of AI contract review are, it answers that the tool does not remove the need for human review or legal judgement, that playbook coverage may be incomplete, that contract language may depart from prior examples, and that unusual provisions may require a lawyer to make a fresh decision. The routing that follows is stated rather than implied: the output is treated as a first pass, and new risks, exceptions and negotiation decisions are left to the appropriate reviewer, so material the playbook does not cover is passed through to the lawyer rather than guessed at.
The vendor also states that different contract language may call for a different edit and that the resulting markup remains subject to lawyer judgement. In the earlier ContextAI presentation a flag marks a rule where an edit may be needed and the user should review, which is an explicit signal of unresolved cases. documented-and-demonstrable was tested and declined: it requires the behaviour to be observable in the product or in published evaluation, and while a seven-day self-serve trial would let a buyer observe it, no published evaluation, benchmark or worked example of the abstention path exists on any surface, and a trial a reader must run themselves is not published evidence. No confidence or grounding score is exposed, so confidence-scoring-only is false.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.
No matter naming this vendor or its product was located. Searches were run on both the company name, BlackBoiler, and the product name, Veris, against the AI Hallucination Cases database maintained by Damien Charlotin and against general search, on 8 September 2026. Nothing returned any filing, sanction, order or judicial finding involving either name. The value records the state of the search on the date rather than a claim that no such matter could exist.
Two things are worth recording for a later reader. The product does not generate legal citations at all, proposing contract language against the customer's own approved positions rather than retrieving or citing authority, so the failure mode this signal tracks is structurally unlikely to arise from its output. And the vendor publishes an express statement that its output is a first pass requiring lawyer review, which is the practice this signal exists to encourage.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Public materials refer to professional responsibility in general terms without naming guidance.
Public materials refer to professional responsibility in general terms without naming any guidance, which is this value. The reference is real rather than decorative and it sits in the customer agreement: clause 3(b) states that use of the service is not a substitute for and shall not take the place of review and analysis by a qualified lawyer, and the public FAQ addresses the competence and supervision question directly, stating that non-lawyers can apply standards the organisation has defined but that a lawyer reviews the redline before anything moves forward and handles exceptions, new risks and negotiation decisions.
What is absent is engagement with any named authority. No bar ethics opinion is cited, no state or national bar guidance is discussed, no regulator is named, and nothing maps the product against the professional conduct rules its buyers are bound by in any jurisdiction. named-guidance requires engagement with at least one named ethics opinion and nothing on the estate reaches that. The signal measures engagement with AI-specific professional guidance, and a competent-review requirement in an agreement, while genuine, addresses the advice line rather than the ethics guidance a firm must satisfy.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure, and the product sits inside a fee relationship between a lawyer and a client where those savings would change the bill.
Efficiency and cost savings are the frame, and nothing addresses what happens to the bill when the work compresses. The vendor invites a buyer to weigh its subscription against how contract review is handled today, naming internal reviewer time, repeated manual markup, outside counsel spend and available capacity as the comparison factors, and its wider material rests on the claim that the repeatable first pass is taken on by the software so that time is saved.
That is a savings claim addressed to the buyer's own cost base. What the signal asks is whether the vendor addresses what happens to the bill when a task that took six hours takes one, and nothing does. There is no per-matter record of AI-assisted work, no artefact a firm could put in front of a client, and no guidance on fee or disclosure treatment where AI has compressed billable time. audit-record and audit-record-and-guidance both require a per-matter record of AI-assisted work and neither is available.
The direction of sale is worth naming: the buyer here may be an in-house team, a law firm or a contract manager, and where the buyer is an in-house team the compression accrues to the client directly rather than passing through an invoice, so the question the signal asks does not arise in the same form. Where the buyer is a law firm applying set positions across client matters it does arise, and it is unaddressed.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
A firm could not get this vendor through a client's AI clause without a bespoke negotiation, because the central artefact does not exist. No subprocessor list is published anywhere on the estate, and no statement identifies which model providers see client content. That absence is not incidental here: the vendor's own agreement concedes at clause 7(b) that customer data may be processed using third-party artificial intelligence services and separately restricts training of third-party foundation models, so third parties are in the chain and none is named.
Two named third parties were tested against the coverage rules and neither satisfies the signal. Amazon Web Services is infrastructure, and under the established test naming a cloud host says where a model runs rather than whose model it is, so infrastructure alone never satisfies this signal. Stripe is a payment processor, expressly routed outside the Word add-in and the conversational interface and touching no contract content.
No forwardable client-facing disclosure material exists either: no data processing addendum was located, no AI disclosure pack, no consent or notification template, and no subprocessor change notification commitment. on-request was tested and declined because it asserts the material exists behind a sales conversation or an executed agreement, and nothing on the estate indicates a subprocessor list or model provider statement exists in any form.
What is available through the security review process is described as security materials and questionnaire responses, which is a different artefact answering a different question.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located public material addresses court disclosure or verification certification.
No located public material addresses court disclosure or verification certification. Nothing on the estate discusses judicial standing orders on AI use, no disclosure template or guidance is published, and no export produces a per-document record of the kind such an order would require. The value records what is locatable rather than a defect: the product is transactional, applying negotiation standards to commercial agreements before signature, and its output is a redline on a contract rather than a filing put before a court, so the question a standing order asks does not arise in the ordinary course of its use.
One element that would form part of such a record does exist inside the product and is noted so a later reader sees it was weighed. The vendor states that each proposed edit is traceable to the playbook rule that produced it and to prior examples of the same edit within the organisation, which is a provenance trail for the output. partial-record was tested and declined because that trail is a review aid inside the document rather than an available record of model used, sources retrieved and human verification, and because nothing published describes it as serving a disclosure purpose or shows it being produced as a record.