Brightflag

AI powered enterprise legal management platform for in house legal departments, covering legal spend management and e-billing, matter management, vendor management and analytics. The core capability is AI invoice review: the system reads, codes and categorises every line of every invoice narrative, and takes a legal team's outside counsel billing guidelines and translates them into rules the AI checks each invoice against, flagging both guideline breaches and departures from general billing best practice without requiring the outside firm's involvement in the review. Surrounding capabilities include controlled approval workflows with complete audit trails, real time budget tracking at overall, practice area and matter level, AI built vendor profiles feeding panel management and RFPs, rate benchmarking, and Ask Brightflag, a conversational interface over the platform's data and workflows. Holds ISO/IEC 42001 certification for AI management systems alongside SOC 1 Type 2, SOC 2 Type 2 and ISO/IEC 27001. Hosted on AWS.

Vendor siteDublin, IrelandFounded 2014
Last verifiedAugust 29, 2026

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The models are the product and the surrounding platform was built out around them. The core capability is language analysis reading, coding and categorising every line of every invoice narrative, and the vendor's own positioning is that this eliminates the manual configuration and outside firm involvement that conventional e-billing requires. The company was founded on that capability rather than adding it to an existing billing system, and its published framing is that it goes beyond AI invoice review to deliver a governed e-billing platform, which puts the AI first and the workflow second. Distinguished from the enterprise platforms graded B on this axis, where a workflow system predates and stands without the model layer.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Grounding is real and structurally verifiable, short of published measurement. The method is described concretely: the vendor takes a legal team's own outside counsel billing guidelines and translates them into rules the AI checks each invoice against, so every flag traces to a specific guideline and a specific invoice line the reviewer can open. That is grounding by construction rather than by claim, and the reviewer holds both sides of the comparison. Invoice Summaries and a redesigned review experience are published as making in depth review easier. Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026 and located no accuracy figure, no false positive or false negative rate for flagging, no test set, no evaluation methodology and no independent benchmark participation. Third party review material notes AI driven invoice analysis may require manual review in complex cases, which is an unverified customer observation and was not treated as evidence.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

A real published commitment with documented control surfaces, short of thresholds. The oversight structure is the product's own architecture: the AI reviews and flags, and a controlled approval process with complete audit trails determines what is actually paid, so a human decision sits between the model's output and any financial consequence. That is a genuine and auditable checkpoint rather than an assertion of human in the loop. Ask Brightflag adds a conversational interface described as accessible to every person in the legal department, which widens who interacts with the AI. Not located as of 29 Aug 2026: any threshold at which a flag is escalated or auto applied, whether any reduction can be applied without human approval, and what the vendor commits to when a flag is wrong. The last matters commercially here, because a wrong flag reduces a law firm's payment.

Source: Vendor Published
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Segment claims stand where deployment evidence would go. The vendor states its customers range from high growth companies to global enterprises with complex multi jurisdictional operations, and third party material describes immediate return on investment from automated invoice review, which is a vendor claim relayed rather than measured. Searched the vendor site, the FAQ, the press releases and the review platforms on 29 Aug 2026 and located no named customer paired with figures and a date, and no case study with an assessable method. Worth recording as a genuine absence rather than a research gap: the Gartner Peer Insights listing for this product carries no reviews at all, which is unusual for an established platform and means the independent evidence base other records here draw on is not available for this one.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

CORRECTED 29 Aug 2026 during the trust portal sweep. Previously graded C because confidentiality rested on certification and general controls with the specific limbs unlocated. The vendor publishes a security page not reached in the original pass, and it is detailed. Published: AES-256 encryption at rest with keys managed in AWS Key Management Service; minimum TLS 1.2 in transit; single sign on via SAML with the identity providers named individually as ADFS, Azure Active Directory, Google, Okta, OneLogin and Ping Identity; SCIM support for user provisioning, permission management and de-provisioning, which matters because de-provisioning is how access actually ends when a lawyer leaves a matter or a firm; OAuth authentication on the API; out of the box user roles and access permissions with a detailed breakdown published in the help centre; optional restriction of access to specified IP ranges; and a continuous vulnerability scanning and patching programme. SOC 1 Type 2 and SOC 2 Type 2 are prepared annually across all five AICPA trust categories including Confidentiality and Privacy, which is broader scope than most records here. A data retention and deletion section is published on the same page, though its content was not captured in this pass. Held at B rather than A because the training question is still unanswered: no statement was located on whether customer content, which here means invoice narratives describing legal work, may be used to train or improve models. Privilege and work product are also not addressed directly.

Source: Vendor Published
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

The audience is corporate rather than lawyer facing in the advisory sense and no position is published. Users are in house legal departments, legal operations and their finance counterparts, and Ask Brightflag is explicitly described as accessible to every person in the legal department, so non lawyers operate the AI by design. The product analyses billing rather than giving legal advice, so the advice line question arises less sharply than for a research or drafting tool. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no published position on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits despite serving customers with complex multi jurisdictional operations where billing rules and professional conduct rules differ.

Source: Vendor Published
AA on AI Governance and Bias DisclosureGovernance is documented and owned: who inside the vendor is accountable, what is tested before release, and what has been found and disclosed about uneven output across matter types or populations.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Fourth A on this axis, earned on an accredited AI management certification. The vendor states it is certified in ISO/IEC 42001 and describes it correctly as the first globally recognised standard for artificial intelligence management systems, which is the governance artifact this axis asks for: an externally audited management system covering the AI lifecycle rather than a principles page. It sits alongside SOC 1 Type 2, SOC 2 Type 2 and ISO 27001, so the AI standard is one part of a substantial assurance posture rather than a lone badge. Recorded honestly as the thinnest of the four A grades on this axis: searched the vendor site, the FAQ, the press releases and third party material on 29 Aug 2026 and located no certifying body, no certification date, no published scope for what the 42001 certification covers, no named owner of model governance, no pre release testing results, and nothing on uneven output across matter types, firms or practice areas. Compare Definely, which publishes its AI System Register and per system ownership, and Workday, which names its certifier and date. The certification is the artifact here; the evidence around it is not.

Source: Vendor Published
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Substantive published assurance covering most of the ground, weighted toward certification rather than described controls. Published: SOC 2 Type 2 and SOC 1 Type 2, both stated as achieved without exceptions, ISO 27001, ISO 42001, GDPR, CCPA and CPRA compliance, AWS as the hosting partner, and a completed Cloud Security Alliance Consensus Assessment Initiative Questionnaire available on request, which is a substantive standardised control disclosure most vendors here do not offer. Third party material describes encryption and user based access controls. Not located as of 29 Aug 2026: a stated retention period or deletion control for invoices, narratives or model outputs, a named subprocessor list, and an incident or breach notification practice. The SOC 1 scope covering invoice approval, accruals management and financial reporting is a genuine control assurance over the money path and is credited here.

Source: Vendor Published
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer terms of service was located on the surfaces reached. Recorded as a pure absence. The shape is distinctive for this product: the AI's output directly reduces payments to third parties, so a wrong flag has an immediate financial effect on a law firm that is not the vendor's customer and has no contractual relationship with the vendor at all. Nothing published addresses either side of that, and it is a recourse question no other record on this index raises in the same form.

Source: Operator Verified
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Integration is claimed at category level without named connectors. The vendor states the platform can be implemented into existing processes with minimal setup, which it attributes to the language analysis removing the need to configure rules manually, and third party material refers to integrations particularly in collaboration and business intelligence. An e-billing platform necessarily exchanges data with accounts payable, enterprise resource planning and law firm billing systems, and handles standard billing formats, but none of that was located as documented on the surfaces reached. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no integrations index page, no named connector, no API documentation, and no statement of which billing format standards are supported. For a product whose data must flow to finance systems, that absence is notable.

Source: Vendor Published
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Cloud delivery and the hosting partner are stated and residency is not addressed. AWS is named as the hosting partner, which the vendor frames as providing security and performance. Searched the vendor site, the FAQ, the press releases and third party material on 29 Aug 2026 and located no named regions, no customer selectable residency, no tenancy model, and no statement of where processing happens as distinct from where data is stored. The absence is more consequential than for most records here: the vendor is headquartered in Ireland, sells to enterprises with complex multi jurisdictional operations, and states GDPR compliance, so where invoice narratives describing legal work are processed and stored is a question its own customer base would be expected to ask.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

CORRECTED 29 Aug 2026 during the trust portal sweep; grade held at B and the currency finding is now firmer. The vendor's security page, not reached in the original pass, states the certification set and scopes it precisely: externally validated through ISO 27001:2013, SOC 1 and SOC 2, with annual AICPA System and Organization Controls reports prepared across all five trust categories, SOC 1 Type 2 covering controls relevant to financial reporting and SOC 2 Type 2 covering Security, Availability, Processing Integrity, Confidentiality and Privacy. Naming all five categories rather than the usual three is more precise than almost any record on this index. A Cloud Security Alliance CAIQ is available with the reports on request. A separate trust centre exists for the vendor's Workspace product at a stable URL, stating annual audits by an independent CPA firm, first SOC 2 audit in February 2021, and reports available by request through the service portal. Why the grade holds at B rather than rising. The evidence route for the main platform is still a request to the team rather than a self serve portal. No coverage period, report date or auditing firm was located for the main platform. And the currency question is now stronger rather than weaker: the ISO 27001:2013 reference appears on the vendor's own current security page, not only in an FAQ, and that revision was withdrawn and superseded by ISO/IEC 27001:2022, whose transition deadline has passed. A vendor stating a withdrawn revision on its live security page is a finding worth recording plainly, and it remains rebuttable by a current certificate.

Source: Vendor Published
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No model, provider, hosting location for model processing, or subprocessor was located, and no commitment to notify customers of supply chain changes. AWS is named as the hosting partner for the platform, which is infrastructure rather than a model supply chain disclosure and was not treated as one. The gap covers both layers of this product's AI: the language analysis that codes invoice narratives, whose nature is not described beyond being language analysis technology, and Ask Brightflag, a conversational interface whose underlying model is not identified anywhere located. A buyer cannot determine from published material which company, if any, processes their invoice narratives.

Source: Operator Verified
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Checked the vendor site, the FAQ and the press releases on 29 Aug 2026. No pricing page was located, no rate is published, no unit of charge is stated and no tier structure appears on the surfaces reached. Third party sources state pricing is not publicly available and requires a custom quote, structured on subscription and varying with organisation size and the volume of legal spend managed, which confirms the absence and identifies the unit of charge without the vendor publishing it. Worth recording plainly because of what this product is: a platform sold on delivering visibility and transparency into legal spend, which does not publish what it costs. That is not a grading factor beyond the D, but it is the sharpest instance of the pattern on this index.

Source: Operator Verified
CC on Firm and Practice CoverageCoverage is claimed broadly, for all firms or all practice areas, without evidence that the breadth is real.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Segment coverage is described in general terms with the detail not reached. The vendor states its customers are corporate legal departments across industries and range from high growth companies to global enterprises with complex multi jurisdictional operations, and identifies the buying roles as in house legal, legal operations and their finance counterparts. Its FAQ begins an enumeration of the industries served but that list was not captured in this pass and is not credited. Practice scope is clear and consistently stated as outside counsel spend, matters, vendors, budgets and reporting, with no claim to advisory or drafting capability. Not located as of 29 Aug 2026: an enumerated industry or practice area list, organisation size segmentation, jurisdictional coverage, and any statement of what the platform is not built for. Flagged as rebuttable in one step by reading the FAQ industry list.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Terms silent

No located term or policy addresses the question either way.

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No located material states whether customer content may be used to train models, either way. Recorded as silent under the rule that a value is never inferred from the absence of a contradiction, and specifically not inferred from the ISO 42001 certification, which evidences that an AI management system exists rather than what its training position is. The question carries unusual weight for this product. The material at issue is invoice narratives describing legal work across many companies and many law firms, and the vendor's own benchmarking and vendor profiling features depend on cross customer comparison, so a buyer would reasonably want to know what is pooled, in what form, and for whose benefit. Nothing located addresses it.

Source: Operator VerifiedAs of Aug 29, 2026

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Not addressed

No located public material states how long prompts and outputs are retained.

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No public material states how long invoices, narratives, AI generated flags, summaries or Ask Brightflag conversations are retained, whether a customer controls the window, or whether deletion is available. The platform is a system of record for spend and matter history and its analytics, forecasting and rate benchmarking features depend on multi year retention, so long retention is inherent to the value proposition and no published terms govern it.

Source: Operator VerifiedAs of Aug 29, 2026

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Own model, documented

The product maintains its own permission model, documented, requiring the firm to keep it aligned.

CORRECTED 29 Aug 2026 during the trust portal sweep. Previously recorded as not addressed on the finding that no vendor material described segregation and that third party references to access controls were assertions relayed rather than a documented model. The vendor's security page, not reached in the original pass, documents the model. Published: out of the box user roles and access permissions with a detailed breakdown available in the help centre, so the roles are enumerated somewhere a customer can read rather than merely asserted; single sign on via SAML with named identity providers; SCIM support for provisioning, permission management and de-provisioning; OAuth on the API; and optional restriction of access to specified IP ranges. That is the product's own permission model, described at mechanism level. Recorded at own model documented rather than the positive value for two reasons. No material states that the AI layer respects those permissions at query time, which matters because Ask Brightflag is described as a conversational interface accessible to every person in the legal department and the underlying data includes invoice narratives describing sensitive matters. And no document management integration was located whose access model could be inherited. Conflicts and ethical walls are not named as such.

Source: Operator VerifiedAs of Aug 29, 2026

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Not addressed

No located term or policy addresses third party requests for customer data.

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026, and no published customer agreement or data processing agreement was reached. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. The exposure is worth naming: a structured record of what every outside law firm did on every matter for a company would be an attractive target for a discovery request or regulatory demand, and nothing published addresses what the vendor would do on receiving one.

Source: Operator VerifiedAs of Aug 29, 2026
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Not addressed

No located public material identifies the corpus behind the product’s answers.

No primary law corpus is identified because the product does not hold one, and the relevant provenance question is a different one that is also unanswered. Invoice review runs against the customer's own invoices and their own billing guidelines, so that corpus is theirs. But the vendor also publishes rate benchmarking and AI built vendor profiles applied to panel management and RFPs, and benchmarking necessarily rests on a comparative dataset drawn from somewhere. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no statement of what the benchmarking corpus comprises, whose data it contains, whether it is aggregated or anonymised, or on what basis it was assembled. Recorded as not addressed on that specific question rather than as inapplicable.

Source: Operator VerifiedAs of Aug 29, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

Searched the vendor site, the FAQ and the press releases on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is a legal spend and matter management platform whose corpus is invoices and billing guidelines rather than case law, so a citator is outside its design entirely.

Source: Operator VerifiedAs of Aug 29, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No published material describes what the product does when it cannot confidently code a line or assess a narrative against a guideline, and no explicit no answer path or confidence signal exposed to the user was located. Third party review material observes that AI driven invoice analysis may require manual review in complex cases, which suggests some routing to human judgement occurs in practice, but it is an unverified customer observation rather than a published behaviour and was not treated as one. For a product that codes every line of every invoice, how it handles an ambiguous narrative is a live question and is unaddressed.

Source: Operator VerifiedAs of Aug 29, 2026

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note the product does not generate citations or court facing text at all: its output is invoice flags and spend analysis, so the failure mode this database catalogues does not arise here, and a wrong output would surface as a billing dispute rather than a sanction.

Source: Operator VerifiedAs of Aug 29, 2026Evidence
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512. The absence is more pointed here than for most records, because the professional rules governing legal billing are directly the subject matter of the product: what a lawyer may bill for, what constitutes a reasonable fee, and how work is described to a client are conduct rules, and this platform automates the assessment of exactly that. It engages with the customer's own outside counsel guidelines, which are contractual instruments, and not with the professional standards that sit behind them.

Source: Operator VerifiedAs of Aug 29, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Audit record only

A usable record of AI assisted work exists with no published fee guidance.

Second record on this index to reach a value above savings claims, and the only one where fee assessment is the entire product. The platform generates a per matter and per invoice record of what the AI flagged, what a reviewer approved and what was ultimately paid, held in controlled approval workflows with complete audit trails, so a legal department has a durable account of how each fee decision was reached and on what basis. That is the artifact this signal looks for, produced as the core function rather than as a by product. Two limits keep it short of the positive value and both matter. First, the record concerns the law firm's billed work rather than any AI assisted work performed by the vendor itself. Second, and more consequential for this index: outside counsel guidelines increasingly address whether and how AI assisted work may be billed, and searched the vendor site, the FAQ and the press releases on 29 Aug 2026 without locating any statement that the AI checks for AI related billing entries or supports a guideline term about them. A product that translates billing guidelines into automated checks, in a market where those guidelines are being rewritten around AI, publishes nothing about that.

Source: Vendor Publishedcontrolled approval processes, complete audit trailsAs of Aug 29, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

On request only

The material exists behind a sales conversation or an executed agreement.

Diligence material exists and reaching it runs through a conversation. The vendor states that security and compliance reports, including a completed Cloud Security Alliance Consensus Assessment Initiative Questionnaire, are available by contacting the team directly, and names SOC 1 Type 2, SOC 2 Type 2, ISO 27001 and ISO 42001 alongside GDPR, CCPA and CPRA compliance. A completed CAIQ is a substantial standardised control disclosure and few vendors on this index offer one. Searched the vendor site, the FAQ and the press releases on 29 Aug 2026 and located no subprocessor list, no statement naming which model providers see customer content, no published data processing agreement, and no client facing consent or notification pack. Recorded at on request on the strength of the stated report route.

Source: Vendor PublishedAs of Aug 29, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Not addressed

No located public material addresses court disclosure or verification certification.

Searched the vendor site, the FAQ, the press releases and third party review material on 29 Aug 2026. No per document record covering model used, sources retrieved and human verification was located, and no model is identified in published material so the model used could not be stated. Complete audit trails exist over the approval workflow, which record who approved what and when rather than what the AI did and on what basis, and the two were not conflated. Noted for context: this is a spend management platform whose output is invoice flags and financial analysis rather than legal work product, so a judicial AI disclosure order is unlikely to reach it. The nearer analogue would be a fee dispute or a challenge to billing judgements, where the approval audit trail would be the relevant record and does exist.

Source: Operator VerifiedAs of Aug 29, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 31 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
August 29, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746