Checkbox
Checkbox is a legal service hub for in-house legal teams, built around the idea of a single front door for legal work. Requests arrive from wherever the business already works, with the platform capturing them from email, Slack, Microsoft Teams, Jira, Salesforce and web forms, then triaging and routing them automatically on matter type, required expertise, team capacity and business unit. From there matters are managed in one place with linked documents, emails, tasks, approvals and conversations, tracked through dashboards covering demand, cycle times and workload distribution so the function can report on itself with numbers rather than anecdote. Alongside intake sits no-code workflow automation for repeatable work such as NDA generation, contract lifecycle steps, policy and FAQ answering and approval chains, plus self-service tools that let the business resolve routine requests without a lawyer and an AI legal chatbot that answers common questions directly. Checkbox AI applies generative AI across intake and workflow automation, and the platform integrates with Ironclad for contract requests as well as with the messaging and CRM systems requests originate in. The company is Checkbox Technology Pty Ltd, based in Sydney with a United States affiliate in Checkbox Software, Inc. It holds SOC 2 Type II attestation and ISO/IEC 27001:2022 certification with ISO/IEC 27017 and 27018 compliance, publishes its master services agreement, data processing addendum, service level agreement and acceptable use policy openly, and names its subprocessors including the provider behind its generative AI features. Customers include SAP, Coca-Cola Europacific Partners, Analog Devices, Hitachi Digital, Air New Zealand and Woolworths Group.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The product is a workflow and intake system with AI applied to two steps inside it. Checkbox began as a no-code automation platform, which is what the 2022 Gartner Digital Markets recognition was for, and the architecture is still a request pipeline: capture, triage, matter management, automation, reporting. Checkbox AI is described as generative AI to streamline intake and workflow automation, with AI-powered triage routing on matter type, expertise, capacity and business unit, and a separate AI legal chatbot answering routine questions. Those are real shipped capabilities and they accelerate steps that already existed. Remove the models and the platform still captures requests from email, Slack, Teams, Jira and Salesforce, still manages matters, still runs no-code workflows for NDAs and approvals, and still reports on cycle time and workload. The subprocessor list confirms the shape: generative AI is supplied by a third party and enabled only where the customer switches the optional features on, so the AI is a layer a buyer elects rather than the thing being bought.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Nothing published addresses accuracy for a product whose AI answers legal questions and routes legal work. The AI legal chatbot is marketed as providing instant legal help and response, and AI triage decides which lawyer receives which matter, so both a wrong answer and a wrong routing decision have consequences the buyer would want measured. No accuracy rate, benchmark, test set, evaluation, error mode or confidence measure was located on the home page, the security page, the legal set or the platform navigation, read on 1 September 2026. Nor is there a grounding description: nothing states what the chatbot answers from, whether responses are restricted to a customer's own policy and FAQ content or draw on the underlying model's general knowledge, and no citation or source-linking behaviour is described. The one adjacent published fact sits in the subprocessor annex rather than in any product material, which is that generative AI functionality is supplied by OpenAI. Checkbox AI's own product page was not opened, so this grade is rebuttable on that surface.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
What the automation does is described clearly and what constrains it is not. The published account of the pipeline is specific: requests are automatically captured across channels, triaged and routed by AI on matter type, lawyer expertise, capacity and business unit, matters are maintained automatically, and self-service workflows resolve routine requests without a lawyer touching them. The design intent is stated plainly, that legal teams stay focused on work that matters while the system handles the rest. What is absent is the control structure around it. Nothing describes a review point where a lawyer confirms or overrides an AI routing decision, no confidence threshold or escalation path is published for a request the system cannot classify, and nothing states what happens when a matter is routed wrongly or when the chatbot answers a question it should have escalated. Approvals exist as a workflow feature the customer configures, which places a human in the process by design rather than describing an oversight mechanism over model output.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
The attribution is the best in this pull and the measurement is thin. Six named individuals are quoted with title, employer, legal team size and organisation size: Jeannine Moran, Director of Legal Operations at Hitachi Digital, describing a single front door serving 40-plus countries across a 60-plus legal team and 16,000-plus employees; Janene Asgeirsson, Chief Legal Officer at Analog Devices; Richard Conway, Deputy General Counsel and Corporate Secretary at Coca-Cola Europacific Partners, on a 180-plus legal team; Jim Gray, VP and Head of Global Legal Operations at SAP, on a 400-plus legal team across 100,000-plus employees; Linh Duong, Senior Legal Counsel at Align Technology; and Sam Bailey, Senior Legal Counsel at Air New Zealand. A headline outcome figure is published for Woolworths Group, a reduction in matter volume of up to 80 per cent, and a further story covers NDA automation at Xero. Behind them sits a logo set including BMW, PepsiCo, Telefonica, Allianz, Deloitte, PwC, Danone and Telstra. **What holds it below the top band is measurement and dating**: the quotations are qualitative, the team and employee figures size the customer rather than the change, only one outcome number was located, and no case study carries a visible date. None of the case studies was opened on 1 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The contractual position is complete and readable in advance, and the training question is answered only by implication. What a buyer can read before signing: a published data processing addendum incorporating the EU standard contractual clauses in the controller-to-processor module, with Checkbox named as processor and the customer as controller; processing restricted to documented instructions and to the specified purpose; onward disclosure to a third party permitted only on documented instructions; personnel access granted only to the extent strictly necessary and bound by confidentiality; and deletion or return of all personal data at the customer's choice at the end of processing, with certification of deletion. Retention is stated with a period rather than a criterion, at the duration of the licence plus thirty days unless earlier deletion is requested in writing. The master services agreement reinforces it commercially by carving data protection and privacy obligations out of the ordinary liability cap. Two gaps keep this off the top band. **No express statement was located that customer content is not used to train models** — the SCC purpose limitation constrains it without naming it — and privilege and work product are never mentioned despite the product holding legal matters for in-house teams.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Nothing located addresses the line between an information tool and legal advice, on a product that markets an AI legal chatbot as providing instant legal help and response to business users who are not lawyers. That framing is what makes the gap material: the chatbot and the self-service workflows are explicitly designed so that employees across the business resolve legal questions without reaching a lawyer, which is precisely the situation where a published position on what the tool is and is not would matter. No statement was located that outputs are not legal advice, that no professional relationship arises, or that answers should be confirmed with counsel, and no jurisdiction limit or supervision statement appears. Searched the home page, the security and trust page, the privacy policy, the legal index and the data processing addendum on 1 September 2026. **The master services agreement was recovered only in part through the R8 ladder and the acceptable use policy and EULA were not opened**, so a disclaimer may sit in one of them and this grade is rebuttable on those three documents.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Nothing published addresses governance of the AI in the product. There is no responsible-AI page, AI policy, ethics statement, governance committee, named accountable owner for model behaviour, pre-release testing regime or bias evaluation anywhere on the property, and the site navigation and footer were read in full on 1 September 2026 across platform, solutions, resources, partners and company sections. What does exist is information security governance, which is a different subject and is credited on the stewardship and certification rows rather than counted here: an information security management system with named policy domains, thirteen individually listed security policies in the DPA annex, and a Chief Information and Security Officer named as the contact for the data importer. The distinction matters because AI routing decides which lawyer receives which matter and the chatbot answers questions for non-lawyers, so uneven performance across request types or business units is a live question that nothing published addresses.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Every limb is published, specific and current, and the subprocessor limb is the strongest in the pull. **Retention carries a period**: personal data is retained for the duration of the licence agreement until thirty days following termination, unless the customer requests earlier deletion in writing. **Deletion is contractual and certified**: at the end of processing Checkbox must, at the customer's choice, delete all personal data and certify that it has done so, or return it and delete existing copies. **Subprocessors are named individually with address, contact and a description of what each does**: Amazon Web Services for hosting and storage, Datadog for application and infrastructure logs, SendGrid for workflow email with automatic deletion after delivery, and OpenAI for generative AI functionality where the customer enables the optional features. Changes require fifteen days' advance written notice with an objection right. **Incident practice is specified**: notification without undue delay after becoming aware, with a contact point, the nature of the breach, categories and approximate numbers of data subjects and records, likely consequences and measures taken. Access is limited to personnel for whom it is strictly necessary and bound by confidentiality. Encryption at rest and in transit is stated, backed by thirteen named policies including a Cryptographic Standard, Data Destruction Standard and Security Incident Response Plan, and by annual third-party penetration testing.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
The allocation is published, mutual and better than the corpus norm on one specific point, short of the top band on scope. The general cap is the familiar one, each party's aggregate liability limited to the amount actually paid in the twelve months immediately preceding the date the liability arose. **What lifts it is the super-cap**: that limitation expressly does not apply to infringement or misappropriation of intellectual property rights, to data protection and privacy obligations, or to the indemnification obligations, for which liability instead runs to a stated multiple of the ordinary cap. A vendor voluntarily exposing itself above the fee cap for a privacy failure is uncommon in this corpus. Checkbox indemnifies the customer against third-party claims that the software or services infringe intellectual property rights, and **may not settle on terms imposing a non-monetary obligation on the customer or requiring an admission of fault without the customer's prior written consent**, which is a protection most vendors omit. The customer indemnity is reciprocally narrowed, carved back to the extent a claim results from Checkbox's own negligence or breach. What is missing is anything AI-specific: no warranty on output, no insurance position located, and the agreement was recovered only in part through the R8 ladder.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations, named individually, with the direction of travel described for each. Slack and Microsoft Teams turn messages into complete matters, so a request raised in chat becomes a tracked item without the requester leaving the channel. Gmail and Outlook automate email capture and matter tracking. Salesforce automates contract generation and approvals, which is the sales-to-legal handoff that usually breaks. Ironclad syncs contract requests and tracking, which matters because it positions Checkbox alongside a CLM rather than against one, and the company markets the pairing directly. Jira is named as a further intake channel. A technology and integration partners page exists alongside a referral and services partner programme. What keeps this below the top band is depth rather than breadth: no API reference, developer documentation or connector specification was located, nothing describes field-level mapping or what happens when a synced record conflicts, and no statement covers systems that are not supported. The integrations pages themselves were not opened on 1 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Residency is offered as a customer choice and the rest of the model is partial. The privacy policy states that Checkbox primarily stores data **in the data centre region that the customer requests**, which is a selectable residency rather than a disclosed default, and is a stronger position than most vendors in this corpus publish. It is qualified in the same passage: data may sometimes be disclosed to third parties in other locations for the listed purposes, and those locations may not have equivalent data protection laws, with transfers performed in accordance with applicable law. The subprocessor annex identifies Amazon Web Services as the hosting and storage provider, so the infrastructure is named rather than implied, and the standard contractual clauses govern transfers with the Irish Data Protection Commission as competent supervisory authority. What is absent is the tenancy model, with nothing stating whether customers share infrastructure or receive a separate environment, no enumeration of the regions actually available, and no statement of what changes between deployment tiers.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Four standards are claimed with audit language and none of the confirming detail is public. Checkbox states it has been externally audited and completed a **SOC 2 Type II examination**, holds **ISO/IEC 27001:2022 certification**, and is compliant with **ISO/IEC 27017:2015** and **ISO/IEC 27018:2019**, the last of these being the cloud personal-data standard and a sensible one for this product. The DPA repeats all four, which puts the claim in a contractual document rather than only in marketing. Supporting practice is described in more depth than most: an information security management system covering network security, information handling, access control, incident response, backups, change management, risk management, vulnerability and patch management and vendor risk, plus individually listed controls including network intrusion detection, micro-segmented firewalls, hardened standard operating environment images and monitoring of all administrative access. What holds it below the top band is access and specificity. No auditor, certificate date, examination period or scope statement appears anywhere. A trust portal exists at trust.checkbox.ai and **was not opened**, while the route the page itself offers is a contact form to request policies, penetration tests and SOC 2 reports, so under the gated tiers the lower reading applies until the portal's own access flow is seen.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
**The first record in this pull to name a third-party model provider.** Annex III of the published data processing addendum lists OpenAI, LLC, with its address and privacy contact, and describes what it does in terms that answer the question this axis asks: OpenAI is used to provide generative artificial intelligence services for AI-based functionality in Checkbox **where the customer enables such optional features**. That single entry tells a buyer whose model is involved, that the AI is opt-in rather than always-on, and that the provider sits inside the processor chain with the same fifteen-day change-notice and objection rights as any other subprocessor. It also sits alongside the infrastructure entry for Amazon Web Services, so a reader can distinguish where workloads run from whose model reads the content, which is the distinction most vendors collapse. What is missing is the layer below: no model or model family is named, no version or change-notification commitment specific to the model is published, and nothing describes what data is sent to the provider, for how long it is retained there, or whether a zero-retention arrangement applies.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. The site navigation and footer were read in full on 1 September 2026 across platform, solutions, why-Checkbox, resources, partners and company sections and contain no pricing page. Every commercial route is a demo booking, a guided product tour or a contact-sales form. No rate, band, tier name, package structure or per-seat, per-request or per-matter unit was located, and nothing states what implementation or onboarding adds, which is material for a platform whose value depends on configuring workflows to a particular legal function. The published agreements set out billing mechanics without price: fees are defined by reference to a Checkbox Licence Order, and the data processing addendum ties both the retention period and the execution of the addendum itself to that order. Two audience pages exist for growing and enterprise legal teams, which segments the market without pricing it.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
The buyer is identified with precision and the boundaries of the product are left open. Checkbox is unambiguous about who it is for, addressing in-house legal teams throughout and publishing separate pages for growing and for enterprise legal teams plus an in-house legal roles page, and the customer evidence bears the positioning out with legal teams ranging from 60 to 400 lawyers at organisations from 10,000 to 100,000 employees. Practice coverage is expressed as request types rather than practice areas, spanning NDA automation, contract lifecycle steps, legal policy and FAQ handling, and general intake, which suits a front-door product. What is thin is everything about limits. No industry or sector segmentation is published despite a customer base spanning banking, pharmaceuticals, retail, aviation, technology and professional services. Nothing states a minimum viable team size, a request volume the product is designed for, or matter types it does not handle, and no jurisdictional scope is given for a platform sold to multinationals. The claim that it suits both growing and enterprise teams is made without describing what differs between them.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way.
No express statement was located that customer content is not used to train or improve models, and the surrounding contractual position constrains it without naming it. The published data processing addendum incorporates the EU standard contractual clauses in the controller-to-processor module, under which Checkbox may process personal data only on documented instructions from the customer and only for the specific purpose of the transfer, stated as providing the software licence. Onward disclosure to any third party requires documented instructions. Training on customer content for Checkbox's own benefit would sit outside that purpose, so the clauses cut against it, and a reader has to reason to that conclusion rather than read it. The subprocessor annex confirms that generative AI functionality is supplied by OpenAI where the customer enables optional features, and says nothing about whether prompts or outputs passed to that provider are retained or used for training there. **Searched the DPA in full, the privacy policy, the security page and the recovered portions of the master services agreement on 1 September 2026.**
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
A specific retention period is published and the customer cannot change it.
A fixed retention period is published for customer personal data, which is rarer in this corpus than the value name suggests. Annex I.B of the data processing addendum states that personal data is retained for the duration of the licence agreement until thirty days following termination, unless a written request for earlier deletion is made. The standard contractual clauses add the mechanism: at the end of processing Checkbox must, at the customer's choice, delete all personal data processed on the customer's behalf and certify the deletion, or return it and delete existing copies. One subprocessor carries a tighter and separately stated rule, with SendGrid described as holding workflow email data that is deleted automatically after delivery. What is not separated out is AI specifically: nothing states a distinct retention or zero-retention position for prompts submitted to, or outputs returned by, the generative AI features, either in Checkbox's own systems or at the model provider.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses walls or matter level segregation.
Access control is committed contractually and segregation between customers or matters is not described. The standard contractual clauses require Checkbox to grant its personnel access to personal data only to the extent strictly necessary for implementing, managing and monitoring the contract, and to ensure those authorised are bound by confidentiality, which governs the vendor's own people. The security page adds an Information Classification Policy and monitoring of all administrative access. None of that addresses separation inside the platform, which is the live question for this product: intake routes matters to particular lawyers by expertise and business unit, and self-service tools expose legal content to employees across the business, so who can see which matter is a permission question the customer will need answered. Nothing published describes a tenancy model, a role or permission structure for customer users, or walls between business units sharing one instance.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Terms commit to notice where lawfully permitted. No transparency report located.
A full notice commitment is published, and it goes considerably further than notice, because Clause 15 of the standard contractual clauses is incorporated in the data processing addendum. Checkbox must promptly notify the customer, and where possible the data subject, on receiving a legally binding request from a public authority for disclosure, including judicial authorities, with the notification to state what data was requested, which authority requested it, the legal basis and the response given. Where notification is prohibited, Checkbox must use best efforts to obtain a waiver of the prohibition and document those efforts. It must also **review the legality of the request and challenge it** where there are reasonable grounds to consider it unlawful, pursue appeals, seek interim measures suspending the request, withhold disclosure until required under procedural rules, and provide the minimum information permissible. **What holds this below the top value is the reporting limb**: Clause 15.1(c) obliges periodic information on requests received to the customer where permissible, but no public transparency report was located.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
No legal corpus is maintained and the row is recorded rather than skipped. Checkbox does not retrieve or publish primary law; it captures, routes and tracks a customer's own legal requests and automates workflows over the customer's own templates, policies and documents. The content the AI works across is therefore supplied by the customer rather than licensed by the vendor, which makes the provenance question narrower here than for a research or regulatory product. It does not disappear entirely: the AI legal chatbot is marketed as providing instant legal help, and nothing published states what it answers from, so a buyer cannot tell whether responses are confined to their own uploaded policy and FAQ content or draw on the underlying model's general knowledge. Searched the home page, the platform navigation, the security page and the published legal set on 1 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
No citator applies and the row is recorded rather than skipped. The platform returns a routed matter, a generated document or an answer drawn from a customer's own material, not a legal authority whose subsequent history a user would need to verify. There is no regulatory or case-law corpus behind it and therefore no currency mechanism to describe. The nearest analogue is template currency, since the workflow automation generates NDAs and other documents from customer-maintained templates, and responsibility for keeping those current sits with the customer rather than with Checkbox; nothing published addresses version control or review prompts for ageing templates. Searched the home page, the platform and solutions navigation and the published legal set on 1 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Nothing located describes what the system does when it cannot answer or classify, which matters here in two distinct places. The AI legal chatbot is marketed to business users as providing instant legal help and response, so what it does with a question outside its scope determines whether a non-lawyer receives a wrong answer or is routed to a lawyer. And AI triage assigns matters on type, expertise, capacity and business unit, so what happens to a request it cannot categorise determines whether that request is queued for human review or misrouted silently. No confidence score, abstention path, fallback rule, escalation trigger or coverage indicator is published for either. Searched the home page, the security page, the platform navigation and the published legal set on 1 September 2026; the Checkbox AI and AI legal chatbot product pages were not opened and are where such a description would sit.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name. No court order, opinion or disciplinary record naming Checkbox was located. This is a statement about the public record rather than a finding about the product. The failure mode fits poorly, since the output is a routed matter, a generated document from a customer template, or a chatbot answer consumed inside a company rather than a citation filed with a court; the analogous exposure would be a wrong answer given to a business user who acted on it without a lawyer seeing it, which would surface as a commercial dispute rather than in a sanctions docket.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No engagement with professional responsibility or ethics guidance was located anywhere. Nothing references ABA Formal Opinion 512, any state bar opinion, guidance from the Law Council of Australia or a state law society, or any regulator statement on AI use in legal work, and no general acknowledgement appears that a lawyer's professional obligations survive use of the platform. The absence is more pointed than for a pure workflow tool because of how the product is positioned: the AI legal chatbot is sold as giving instant legal help to business users, and self-service tools are sold on resolving requests without a lawyer, so the platform is explicitly designed to put legal answers in front of people who are not lawyers. Searched the home page, the security and trust page, the privacy policy, the legal index, the data processing addendum and the recovered portions of the master services agreement on 1 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Efficiency claims are central and no billing or disclosure treatment exists. The marketing is built on demand and cycle-time reduction, with the headline customer figure a reduction in matter volume of up to 80 per cent at Woolworths Group, and a quoted chief legal officer arguing that expensive professionals should not be answering FAQs or negotiating low-value contracts. Dashboards report cycle times and workload distribution, which is the raw material a legal function would use to demonstrate its own cost of service. The buyer is an in-house team rather than a firm billing a client, so the fee-disclosure question lands obliquely and is not absent, since matter records showing which work was handled by automation rather than by a lawyer would be exactly what an internal chargeback or shared-service model needs. Nothing published addresses that, and no record framed for disclosure of AI-assisted work is described.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
**The strongest instance of this signal in the pull, and the first where the model side is actually answered.** Annex III of the published data processing addendum names four subprocessors individually with address, contact details and a description of the processing each performs: Amazon Web Services for hosting and storage, Datadog for application and infrastructure logging, SendGrid for workflow email, and **OpenAI for generative artificial intelligence services where the customer enables the optional features**. Under the coverage test that satisfies both limbs, since infrastructure and model provider are separately identified and the AI surface is covered rather than partially disclosed. The forwardable material sits alongside it and is openly published: the DPA itself with the EU standard contractual clauses completed, the master services agreement, the service level agreement and the acceptable use policy, with fifteen days' advance notice of subprocessor changes and an objection right. What holds it below the top value is the absence of a client-facing disclosure pack assembled for the purpose, and that no model or version is named beneath the provider.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
A detailed activity record exists and nothing identifies the machine's contribution to it. Matter management is marketed on giving a view across all matters with linked documents, emails, tasks, approvals and conversations, request tracking follows the status of work, and dashboards report demand, cycle time and workload distribution, so a legal function can reconstruct what happened to a request, who handled it and when. The data processing addendum adds contractual events logging as a technical measure. That is a real audit trail for an internal or regulatory account of the function's work. What it does not do is separate machine from human: nothing states that the record marks which matters were triaged or routed by AI rather than assigned by a person, which documents were generated by automation, or which answers came from the chatbot, so a user could not produce an AI-use disclosure from it without reconstructing that distinction themselves.