B
BrandShield

BrandShield is an AI-powered brand protection and external cybersecurity platform that detects and removes online threats targeting a company's brand, executives and customers. It monitors marketplaces, websites and domains, social media, paid ads, mobile app stores, the dark web and, through a product launched in 2026, the answers generative AI platforms give about a brand, prompting ChatGPT, Gemini, Perplexity and Grok with brand-specific queries and then acting against the sources those answers cite.

Detection runs on AI.ClusterX, the company's proprietary predictive threat-clustering engine, which reads infrastructure, hosting patterns, content signals and behavioural indicators to decide whether a domain or asset is malicious and how it connects to known threat activity, alongside image-based detection that catches altered logos and product visuals. Enforcement is handled by the company's own team, which coordinates takedowns with platforms, registrars and hosting providers, and the platform is sold in fully managed, self-service and hybrid models so a customer can run incidents itself, hand them to a 24/7 security operations centre, or split the work.

Named solutions cover trademark and IP protection, domain protection, phishing, social media scams, brand and executive impersonation, marketplace protection, rogue apps, counterfeits, paid ad scams, dark web monitoring and AI platforms. The company publishes dedicated pages for twelve industries and for six buying roles including legal counsel, compliance, CISOs and information security. BrandShield Resolve, an entry-level product for domain and phishing protection, is sold through AWS Marketplace. The contracting entity is Brandshield Ltd. of Herzliya, Israel.

Vendor siteHerzliya, Israel
Last verifiedSeptember 12, 2026
Compare with other vendors

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Same shape as the other enforcement vendors in this lane and graded consistently with them. Detection is model work end to end: AI.ClusterX, described on the vendor's own marketplace listing as a proprietary predictive threat-clustering engine reading infrastructure, hosting patterns, content signals and behavioural indicators; image-based detection that catches altered logos and product visuals; AI-powered prioritisation; and a 2026 product that prompts generative AI platforms and analyses their answers.

Remove the models and what remains is still a business: an enforcement desk with a 24/7 security operations centre, named enforcement managers, relationships with registrars, hosts and platforms, and a case and evidence workflow. That substrate is what the analyst-driven vendors in this market sell, so the models are the engine of detection layered on a workflow platform rather than the whole product. Graded from the home page, the vendor's AWS Marketplace listing and product-page text recovered through the search index; the product pages themselves were blocked to this fetcher on 12 September 2026 and are marked unread under R85. Verified 12 September 2026.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

R15 governs: the product cites no legal authority, so the primary-authority grounding and citator limbs do not apply and are neither credited nor penalised. What bites is grounding and measurement. Grounding is described rather than asserted: the marketplace listing sets out what AI.ClusterX actually reads to reach a verdict on a domain or asset, and states that evidence is collected automatically and cases are structured for takedown readiness, so a reviewer sees the material a determination rests on.

What is absent is any measurement of detection correctness. No precision, no recall, no false-positive rate and no test set is published anywhere located. The one figure the vendor does publish, a 98% takedown success rate, measures whether platforms grant removals rather than whether the detections were right, and the distinction matters on a product whose errors fall on third parties. Verified 12 September 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

The mode structure is published more plainly than on most records in this lane, and one limb is still missing. Three delivery models are named and sold as a choice: fully managed, self-service and hybrid, so the customer sets how much the system does alone. The entry product applies automation across detection, investigation and, in the vendor's own words, response if desired, with single-click remediation and unlimited self-managed takedowns, while the listing states the design allows teams to maintain control and oversight.

The route back to a human is named and staffed: a 24/7 security operations centre available to assist, advise or intervene, and named enforcement managers who handle complex premium takedowns directly with registrars and hosts. What is not published is the same limb missing across this class: what happens after a detection is wrong. No remediation, appeal or withdrawal path for a wrongly removed asset was located on any readable surface. Verified 12 September 2026.

Source: Vendor Published
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Logos and unattributed claims stand in for evidence on the readable estate, which is the C band. The home page presents a Trusted by the world's leading companies band whose customer names did not render, four headline counters (verified takedowns per year, phishing takedown success, customer satisfaction, real-time security operations coverage) that rendered as zeros to this fetcher, a 98% phishing takedown success figure with no basis stated, and one testimonial fragment with no name, title or company attached.

Recognition is recorded rather than credited, because analyst and award placement is not deployment evidence: a G2 category leader position, a Cybersecurity Breakthrough Award and a Frost and Sullivan leader listing. **A success-story library exists in the navigation and was blocked to this fetcher on 12 September 2026**, so named-customer material may well exist and could not be reached; the grade reflects the readable estate and is the first row to revisit when the block clears. Verified 12 September 2026.

Source: Vendor Published
DD on Privilege and Confidentiality PostureNothing published on how client confidences are handled by a product built to ingest them.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Nothing was located on how client confidences are handled by a product built to ingest them, which is the D band. The customer sends this platform its trademark portfolio, the assets it is protecting, its enforcement instructions and, on the vendor's own account of the Takedown Service, the documents needed to authorise cease and desist letters in its name. The privacy policy is scoped to the website by its own terms and addresses browsing, registration, cookies and marketing.

The data processing agreement is not published and executes on entry into a Subscription Form, so the data terms cannot be read before subscribing. No confidentiality clause, no segregation statement, no retention or deletion commitment for customer material, and no position on privilege or work product was located on any readable surface or in the portions of the terms of service recovered through the search index. That agreement refused automated fetch on both URL forms on 12 September 2026 and is marked unread as a page under R85; a confidentiality section is likely to exist in it, and it did not surface. The grade records the record as located. Verified 12 September 2026.

Source: Vendor Published
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Nothing published on the advice line for a product that contracts to produce legal work, which is the D band. What the vendor does contract to do is now on the record: the terms of service define the Takedown Service to include cease and desist letters to websites, domain name holders, registrants, hosting providers and registrars, reports to ICANN on whois inaccuracy and DNS abuse, de-indexing requests to search engines, reports to anti-virus and security companies, app store and paid-advertising reports, marketplace and social platform reports, and general assistance concerning those actions.

Sending a cease and desist letter on a customer's behalf is legal work by any ordinary description, and it is performed by a company that is not a law firm. Against that, no statement was located anywhere that BrandShield is not a law firm, that it does not provide legal advice, that no attorney-client relationship arises, or who may use the service, and no jurisdiction limits are named despite enforcement running across registrars and platforms worldwide.

The comparison inside this lane is stark: Red Points publishes all of that in its legal notice. Retrieval limit, recorded so the grade is read correctly: the terms of service refused automated fetch on both URL forms on 12 September 2026 and is marked unread as a page under R85; the clauses above were recovered through the search index, and a disclaimer could sit in a section that did not surface. The grade records the record as located on the date, not a finding that the vendor is silent in a document nobody has read. Verified 12 September 2026.

Source: Vendor Published
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

No governance position was located for a system that decides whether a named third party's domain, listing or profile is malicious and then acts to remove it. The page inventory is established from the vendor's own navigation and footer and contains no trust centre, no security page, no responsible-AI page and no governance page; the footer's legal section holds three items, being the privacy policy, the terms of use and a cookie policy.

Nothing on the readable estate names an accountable owner, describes pre-release testing, publishes evaluation results, or discloses anything about uneven output across sectors, languages or jurisdictions. That last gap is the one that matters here: false positives on this product fall on third-party sellers and site operators rather than on the buyer, and no error rate, appeal statistic or review of who is wrongly flagged is published.

The product and solution pages were blocked to this fetcher, and governance material of this kind is not usually carried there. Verified 12 September 2026.

Source: Vendor Published
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

A generic website privacy policy covers the company without addressing what the platform does with what it holds, which is the C band. The privacy policy, updated July 2026 and read in full, states in terms that it applies solely to information collected by the website and in the course of transactions, and its subject matter is browsing, registration, cookies, third-party ad servers, promotional communications and payment-account information.

None of the five limbs the A band asks for is addressed for platform data: no retention period for detections, evidence or case records; no deletion commitment on termination; no access-control description; no subprocessor list; and no incident or breach notification practice. Two structural facts belong on the record. A data processing agreement exists and, on the agreement's own incorporation language, executes on entry into a Subscription Form rather than being published, so a buyer cannot read the data terms in advance.

And the security commitment on the readable estate is that the company takes precautions and implements data security systems, with an express statement that it does not guarantee its systems are immune. Verified 12 September 2026.

Source: Vendor Published
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Nothing was located on who bears the loss when the system is wrong, which is the D band and which matters more here than on most records. The product's errors do not fall on the buyer. A false positive removes a third party's listing, domain or account, and the vendor contracts to send cease and desist letters and platform reports in the customer's name, so a wrong call exposes the customer to the party on the other end of it.

No liability cap, no indemnity in either direction, no warranty, no insurance position and no remediation or withdrawal process was located on any readable surface. The AWS Marketplace listing publishes a payment term rather than a liability term: fees are non-refundable. The data processing agreement is unpublished. Retrieval limit, recorded so the grade is read correctly: the terms of service refused automated fetch on both URL forms on 12 September 2026 and is marked unread as a page under R85; a limitation of liability clause is near certain to exist in it, and it did not surface through the search index.

The grade records the record as located on the date and would move on a reading of that document. Verified 12 September 2026.

Source: Vendor Published
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

What is published is procurement and channel coverage rather than documented integration, which lands on C. The one integration established is the AWS Marketplace listing: software as a service deployed on AWS, purchasable inside an existing AWS account with billing through the AWS bill, which the vendor presents as removing procurement and deployment friction for security teams already operating there. Everything else described as coverage is monitoring reach rather than integration: marketplaces, social platforms, app stores, domains, paid ads and the dark web are surfaces watched, and registrars and hosting providers are counterparties for enforcement, not systems the customer connects.

No API or developer documentation was located, nothing describes what moves in which direction or what a customer must configure, and no connection to an IP portfolio, docketing, trademark management or document management system was found, which is where an IP counsel's own records sit. The product and solution pages were blocked to this fetcher on 12 September 2026. Verified 12 September 2026.

Source: Vendor Published
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Cloud delivery is stated and neither the tenancy model nor the region is, which is the C band. The AWS Marketplace listing records the product as software as a service deployed on AWS, and the vendor's own announcement frames the listing as letting security teams deploy domain and phishing protection inside their existing AWS environment. Beyond that nothing is published: no statement of whether tenancy is shared or dedicated, no list of available regions, no choice of region, no separation of where data is processed from where it is stored, and no transfer mechanism, which is a live question for a company whose contracting entity is in Israel and whose customers include European and United States enterprises. No data processing agreement is published in which residency terms would ordinarily sit. Verified 12 September 2026.

Source: Vendor Published
DD on Security Certifications and Trust CenterNo independent security attestation located.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

No independent security attestation was located. The page inventory is established from the vendor's own navigation and footer and contains no trust centre and no security page; the footer's legal section carries three items and no certification marks of any kind, which distinguishes this record from the badge-without-scope shape at C. The ladder was run before this absence was written: the footer and full navigation of the page that rendered, and a targeted search for an ISO 27001 or SOC 2 attestation naming this vendor, which returned only aggregator profiles and market-data pages and nothing from the company.

The one assurance statement on the readable estate is in the privacy policy and is a statement of precautions rather than an attestation, and it carries an express caveat that the systems are not absolutely immune to unauthorised access. Verified 12 September 2026.

Source: Vendor Published
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The vendor names its engine and not what sits underneath it, which is the C band, though the architecture description is fuller than most records that land here. AI.ClusterX is named as a proprietary predictive threat-clustering engine and its inputs are described: infrastructure, hosting patterns, content signals and behavioural indicators, used to decide whether an asset is malicious and how it connects to known threat activity.

Image-based detection and AI-powered prioritisation are named as capabilities. What is absent for anything above C: no model is named, no model provider is identified, nothing states where inference runs, and no commitment to notify customers when any of it changes was located. The AWS deployment stated on the marketplace listing is infrastructure and is spent on the deployment axis rather than here, per the ground rules against one fact working two axes. Verified 12 September 2026.

Source: Vendor Published
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Real pricing is published for part of the range, which is B. The vendor's AWS Marketplace listing satisfies all three limbs of the R117(2) test: BrandShield is the seller of record, the listing copy is its own, and the listing carries its own end user licence agreement. It publishes a twelve-month contract at $22,000 for the BrandShield Managed Anti-Phishing Solution, covering unlimited standard takedowns, a capped allowance of managed premium takedowns and 24/7 security operations support, on a single dimension billed by units where the price scales with units committed rather than with threat volume or takedown count.

The refund position is published and absolute: non-refundable. What holds this off A is that the figure prices one entry-level product, BrandShield Resolve, while the two enterprise products, Online Brand Protection and External Cybersecurity, carry no published price, and **the vendor's own site has no pricing page at all** in a navigation and footer inventory that is otherwise unusually detailed. A pricing row is owed under R17 and is written. Verified 12 September 2026.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Coverage is segmented with real precision and the boundaries are left open, which is B. The vendor publishes dedicated pages for twelve industries (pharmaceuticals, financial services, cryptocurrency, fashion and apparel, retail, online gaming, luxury, SME and SMB, manufacturing, sports and entertainment, technology and internet, travel and hospitality, plus an enterprise page), for five use cases, and, unusually for this lane, for six buying roles: founders, legal counsel, compliance teams, IT managers, CISO threat intelligence and information security teams.

Publishing a legal counsel page alongside a CISO page tells a buyer plainly that both are addressed, and it is what clears the membership screen's route A on this record. Segment intent is stated at the product level too: the entry product is positioned for entry-level or lean security teams. What is not stated is where coverage stops, and the industry and role page bodies were blocked to this fetcher on 12 September 2026, so this grade rests on the published taxonomy rather than on what each page says. Verified 12 September 2026.

Source: Vendor Published
Sources on file

4 public documents

The public pages on file for BrandShield, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.

Pricing

$22,000 per yearUSD, as published, never converted

  • The only published price is on BrandShield's AWS Marketplace page: $22,000 a year.
  • That buys the entry-level product, BrandShield Resolve, which watches for fake domains and phishing sites.
  • It includes unlimited ordinary takedowns, a capped number of harder ones handled by hand, and round-the-clock support.
  • The price goes up with the number of units you commit to, not with how many threats are found.
  • The two bigger products have no published price, there is no pricing page on the company's own website, and fees are not refundable.

One figure is published, for one product, on one surface. The vendor's AWS Marketplace listing prices the BrandShield Managed Anti-Phishing Solution, the packaging of BrandShield Resolve, at $22,000 for a twelve-month contract. It is a single contract dimension billed by units: each unit bundles unlimited standard takedowns, a capped allowance of managed premium takedowns worked by named enforcement managers with registrars and hosts, and 24/7 security operations support.

The vendor states that price scales with the number of units committed rather than with detection or takedown volume, that standard takedowns carry no cap, and that raising the premium allowance means adding units. The refund position is published and absolute: non-refundable. Nothing is published for the two enterprise products, Online Brand Protection and External Cybersecurity, and the vendor's own site carries no pricing page, so this figure is the entry product's price rather than a floor across the range.

Separately, the terms of service state that subscriptions auto-renew unless sixty days' written notice is given, which is a commercial term a buyer should read alongside the price; that document was blocked to this fetcher and is recorded from the search index under R85.

Confidentiality and data terms: A data processing agreement exists and is not published: the terms of service state that entry into the agreement or a Subscription Form is treated as execution of the Standard Contractual Clauses as described in the DPA, and no DPA URL exists in the public index. The confidentiality and data terms are therefore readable only after subscribing. The terms of service itself was blocked to this fetcher on 12 September 2026 and is an operator item.

Note: Figure read from the vendor's AWS Marketplace listing on 12 September 2026. All three limbs of the R117(2) test are met: BrandShield is the seller of record, the listing copy is the vendor's own, and the listing carries the vendor's own end user licence agreement. The vendor's own website has no pricing page anywhere in a navigation and footer inventory that is otherwise unusually detailed, so this is the only price published for any BrandShield product. Five competitor comparison pages published by this vendor were excluded outright under the ground rules and no figure from any of them appears here.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Terms silent

A published agreement or policy exists and none of it addresses the question either way, or the document that would answer it could not be read and the summary names the retrieval limit. The summary states which shape the silence takes: an improvement right granted that never names training, or no improvement right granted at all.

An agreement is published and no training position was located in it. Read the retrieval limit first: the terms of service is published at the URL shown and refused automated fetch on both URL forms on 12 September 2026, so it is recorded here from portions recovered through the search index and is marked unread as a page under R85. The portions recovered are substantial and include the formation clause, the definition of the Online Services and Enforcement Services, the Takedown Service scope, the account and login provisions, and the allocation.

In them, Your Data is a defined term, the customer warrants it is entitled to transfer that data and must inform data subjects where required, BrandShield is designated a CCPA Service Provider and the customer a Business, and a data processing agreement executes on entry into a Subscription Form. A Service Provider designation restricts use of California personal information to the business purpose, which is a real constraint and is not a training term.

Nothing in the recovered portions, and nothing on the privacy policy or any other readable surface, states whether customer material may be used to train or improve models. The value records that the published agreement, so far as it could be read, says nothing on the question.

Source: Vendor Publishedform a binding agreement between you and BrandShield Ltd.As of Sep 12, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Not addressed

No located public material states how long prompts and outputs are retained.

No located public material states how long the platform keeps what a customer puts into it or what it generates. The privacy policy, updated July 2026 and read in full, is scoped to the website by its own terms and its deletion provision concerns personally identifiable information submitted through the site, handled by written request with an invitation to inspect the records at the company's Herzliya offices within thirty days.

Nothing addresses the material that matters on this product: the customer's trademark and brand assets, the detection record, evidence collected for takedowns, case history or the seller and domain intelligence built from it. No retention period, no customer control and no deletion commitment on termination was located in the readable estate or in the portions of the terms of service recovered through the search index; that agreement refused automated fetch on 12 September 2026 and is marked unread as a page under R85.

The data processing agreement, which would ordinarily carry a retention schedule, is not published and executes on subscribing.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Not addressed

No located public material addresses walls or matter level segregation.

No located public material addresses segregation between users, brands or matters. The platform plainly contemplates multi-brand and multi-user work: a customer console at a dedicated subdomain, a dashboard presenting everything included in a subscription, three delivery models including self-service, and enforcement staff who act on the customer's behalf. Nothing states whether one brand's detections, evidence or seller intelligence are separated from another's inside an account, whether roles or permissions exist, or how access by the vendor's own security operations and enforcement staff is controlled.

The privacy policy is scoped to the website and carries no product access model, and the page inventory contains no security or trust page in which one would sit. Recorded as of 12 September 2026 on the surfaces named in the build log.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Disclosure addressed, notice absent

Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.

Compelled disclosure is addressed and customer notice is not. The privacy policy, updated July 2026 and read in full, lists four circumstances in which BrandShield may transfer personal information to third parties without obtaining consent, and receipt of a court order instructing it to give details or information to a third party is one of them. The other three are breach of the user's agreements or unlawful acts, any dispute or legal proceeding between the user and BrandShield, and a corporate reorganisation.

No commitment to notify the customer appears anywhere in that document, and none was located on any other readable surface or in the portions of the terms of service recovered through the search index. Two limits belong on the record: the policy is scoped to website-collected information rather than to platform data, and the terms of service refused automated fetch on 12 September 2026 and is marked unread as a page under R85, so a notice commitment could exist in a section that did not surface. On the record as located, disclosure to authorities is contemplated and notice is not promised.

Source: Vendor PublishedIf Brandshield received a court order instructing it to give details or information to a third partyAs of Sep 12, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Not addressed

No located public material identifies the corpus behind the product’s answers.

No primary law corpus is identified because the product does not answer from one. What it reads is described in outline on the vendor's marketplace listing and product material: domain registrations and DNS and hosting attributes, content signals, behavioural indicators, marketplace and social platform listings, mobile app stores, paid ads, dark web sources, and the answers generative AI platforms return to brand-specific prompts.

Against that it matches the customer's own trademarks and brand assets. Nothing published identifies where that detection corpus comes from, how it is acquired or refreshed, or on what basis, and no licensing question is addressed. The value records that the corpus behind the product's determinations is not identified.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

The product cites no legal authority, so nothing located addresses checking subsequent history, and nothing would be expected to. The currency mechanisms it publishes concern threats rather than authority: continuous monitoring, real-time detection and rescreening as new domains, listings and profiles appear. Recorded so the row states the position rather than leaving a reader to infer it from silence.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Documented

The vendor describes refusal or abstention behaviour in public materials.

The vendor describes a hand-off to a person in public materials, short of anything demonstrable. Automation is stated to run across detection, investigation and, in the vendor's words, response if desired, with the design allowing teams to maintain control and oversight; a 24/7 security operations centre is available to assist, advise or intervene when needed; and complex cases are routed to named enforcement managers who work them by hand with registrars and hosting providers.

So the published behaviour where the system is not confident, or the case is hard, is that a human takes it. What is not published is any threshold, any rate at which escalation happens, or any evaluation demonstrating it, and the same estate carries an unmeasured accuracy claim alongside.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

None located

No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.

Searched on 12 September 2026, on both the product name and the company name, against published trackers of AI hallucination decisions including coverage of the Charlotin AI Hallucination Cases database, for court records addressing fabricated or hallucinated legal citations in this product's output. None located. This is a statement about the public record on that one subject as of that date, and this signal does not record enforcement or takedown litigation.

Source: Bar Guidance or Court RecordAs of Sep 12, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No located public material engages with bar or ethics guidance. The vendor publishes a legal counsel role page and sells enforcement work that produces legal notices, and nothing on the readable estate addresses ABA Formal Opinion 512, any state bar opinion on generative AI, or the professional responsibility of the counsel who directs an enforcement programme run on this platform. The terms of service, which is the surface most likely to carry a professional-responsibility statement, was blocked to this fetcher on 12 September 2026 and is an operator item; this row records the absence on the marketing and policy estate, which is where bar-guidance engagement is normally published when it exists at all. Recorded as of 12 September 2026.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Outside the fee relationship

The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.

The product does not touch a fee between a lawyer and a client. It is bought by a brand owner's legal, IP, compliance or security function to enforce that company's own rights, and no client is billed for the work the detection and takedown engine performs. Savings claims are published and aimed at the buyer's own cost rather than at a client invoice: the entry product is presented as saving time, reducing costs and making high-level protection available to businesses of all sizes by automating tasks traditionally handled by threat hunters, and the pricing model is sold on cost predictability, with standard takedowns uncapped so cost does not rise with threat volume. Under the value's own terms those are recorded here and do not make this a savings-claims row.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

On request only

The material exists behind a sales conversation or an executed agreement.

The material a firm would need exists behind an executed agreement rather than in public. The terms of service state that where the Standard Contractual Clauses apply according to the data processing agreement, entry into the agreement or a Subscription Form is itself treated as execution of those clauses as described in the DPA, and that BrandShield is a CCPA Service Provider and the customer a Business. So a DPA exists, and it takes effect on subscribing rather than being published: no URL for it exists in the public index, and the ladder was run for one before this row was written.

No subprocessor list and no model provider statement was located anywhere on the estate, and there is no trust centre or security page in the navigation where either would sit. A firm asked by its client to evidence this vendor under an AI or data clause would have to obtain the pack through the sales process. The terms of service itself was blocked to this fetcher on 12 September 2026 and is read here only through the search index, marked unread under R85.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

Elements of a record exist and they are built for platform enforcement rather than for a court's AI disclosure. The vendor states that evidence is collected automatically and that cases are structured for takedown readiness, with remediation workflows triggered from them, and the console presents case status and enforcement outcomes to the customer. That is a per-case evidence record, assembled by the system, which is more than several products in this corpus produce.

What is absent is the part a certifying lawyer would need: nothing states that the record identifies which model or classifier reached the determination, what it analysed, or which named person reviewed it before the notice was sent, and no disclosure template or court-facing guidance was located.

Source: Vendor PublishedAs of Sep 12, 2026Evidence
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 12, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746