Codes Health
Codes Health retrieves and reviews medical records for plaintiff personal injury and mass tort firms. A firm submits a client's treatment history and Codes Health takes the request from there: validating the authorisation before it goes out, locating the care sites, submitting to each provider in that facility's required format, and chasing every request daily until the records arrive. The company describes an agentic retrieval system that combines automated work with human intervention, drawing on electronic claims networks, custodian integrations and its own provider network, with coverage stated across all fifty states and an average turnaround of one to two weeks. Throughout, the firm sees request status in real time, with updates for every fax and call made on its behalf. What comes back is not a stack of PDFs. The platform produces medical chronologies in treatment order, encounter and bill summaries grouped by visit, and extracted case insights covering diagnoses, breaches in care and future expenses, with the vendor stating that AI insights are verified by humans before delivery. A missing-record detection feature flags gaps in the treatment history before a demand package is finalised. Firms work in a web application with single sign-on, role-based permissions and an audit trail on every action. Codes Health publishes an exclusive partnership with Filevine that puts requesting, receiving and reviewing records inside Filevine itself, and says high-volume firms can integrate with other CRM and case management systems. Pricing is a flat fee quoted on enquiry, with follow-ups, re-requests caused by provider issues and AI chronologies stated to be included at no extra charge. Codes Health, Inc. is independent and based in Brooklyn, New York.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of the core capabilities and sit on a workflow system that would still function without them. Four AI functions are described in present tense on current pages: an agentic retrieval system, error-checking that reviews an authorisation for misspellings, missing dates of service and absent signatures before submission, missing-record detection that flags gaps in the treatment history, and generated medical chronologies, encounter and bill summaries and extracted case insights. Underneath that sits a request-tracking platform with per-request status, visibility into every fax and call, and a provider network. The vendor's own framing is what keeps this off the top band and it is stated plainly rather than inferred: retrieval runs on a mixture of AI and human intervention, insights are verified by humans, and the headline operational measure is a turnaround time. Remove the models and a firm would still receive a tracked, chased retrieval service, which is what the band above forbids. Checked 4 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is claimed and accuracy is asserted, and nothing is measured. The product is described as grounded in the firm's specific case context and tailored to the practice, with chronologies drawn from the client's own retrieved records, so the output has a real source; but no retrieval method is described, no output is shown citing a record a reader can open, and there is no accuracy figure, test set, evaluation or failure-mode statement anywhere on the estate. The assurance offered in place of measurement is human review: insights are stated to be verified by humans, and every batch is stated to be verified for completeness before it reaches the firm. The published figures are operational rather than accuracy claims, running to 80 per cent less manual review, 2.5x faster retrieval, 50 per cent more case capacity and 1.7x larger settlements, none attributed or dated. The band below does not fit, because its words require that nothing be published on accuracy or grounding, and both are addressed here without being evidenced. That matters on a product whose extracted insights include breaches in care. Searched the home page, the Filevine page, the state guides, the FAQ, the Terms of Use, the Privacy Policy and the Disclosure Policy on 4 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Real review surfaces are published and the threshold at which the system runs alone is not. Three concrete controls exist and each names when it happens: AI insights are verified by humans, every batch is verified for completeness before it reaches the firm's desk, and the firm has real-time request status with updates for every fax and call plus a full audit trail on every action. The limitation worth naming is whose oversight it is. The humans in the loop are the vendor's, not the buyer's: nothing describes what a lawyer at the firm should check on receipt, what the review point is for a chronology or an extracted insight, or what happens when one is wrong. Against the review claims sit daily automated follow-up workflows that plainly run unattended and a customer account stating the case manager did not lift a finger, and no published material reconciles the two by stating where the automated boundary sits. That unstated threshold is the limb this band names as commonly absent, and the two claims together are the evidence for it rather than an argument against it. No abstention behaviour and no confidence signal is described.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers and published figures both exist and are never joined to each other. Three testimonials carry full attribution with role and firm: Charles Brown, Managing Partner at Daly & Black P.C.; Kelman Harrel, Partner at Louis Law Firm; and Skinner Louis, Managing Attorney at Louis Law Firm, whose account is operationally specific, describing a matter needing records and bills from nine to ten providers with each request tracked independently so an issue on one did not block the others. Six further customer logos appear unattributed. Separately the site publishes 80 per cent less manual review, 2.5x faster retrieval, 50 per cent more case capacity and 1.7x larger case settlements, and a state guide adds an average turnaround of 3 to 5 days attributed to the company's own operational data. None of those figures is tied to any named firm, none carries a date, and the two named-firm accounts carry no numbers. A fourth quotation is attributed to Sarah Miller, Shareholder at a national mass tort and litigation firm, with the firm unnamed. The turnaround figures also disagree with each other: the home page states one to two weeks and the state guides state 3 to 5 days.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive and specific commitments, published where a buyer can read them before signing, and none of them contractual. The security section states that data is never used to train the vendor's models, that all AI processing is scoped to the firm's own cases, that there is no data sharing between clients, that PHI is encrypted end to end with AES-256 at rest and TLS 1.2 or above in transit, that role-based permissions restrict who sees case data with a full audit trail on every action, and that Business Associate Agreements are executed with all relevant vendors. That answers training use and separation between customers, which is more than the band below describes. Two things hold it here. No privilege or work product treatment appears anywhere, and that limb is required rather than satisfied by a strong confidentiality regime. And the finding a buyer should see is that the two legal instruments the company publishes both scope themselves away from the product: the Terms of Use govern the marketing site, which it defines as a place for current and prospective customers to access information about the services, and the Privacy Policy states it applies to Personal Data collected from Users of that site. Neither reaches a claimant's medical records. No customer agreement or BAA is published, so every commitment above rests on a product page.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Nothing published addresses the advice line, on a product whose own headline describes it as a nurse, paralegal and assistant all in one. There is no statement that Codes Health is not a law firm, no disclaimer that it does not provide legal advice, no description of what the product is and is not, no jurisdiction limit, and nothing on how a firm should supervise the output or maintain competence over it. The Terms of Use disclaim warranties and describe permitted use of the website, and one clause reads oddly against a business product by restricting the site to personal and non-commercial use; none of it speaks to legal work. The absence bites harder than it would elsewhere because of what the product emits: medical chronologies and extracted case insights covering diagnoses, breaches in care and future expenses, which are inputs to a demand package rather than a filing cabinet. The band above does not fit, since it describes a boilerplate disclaimer sitting in the terms, and no such disclaimer exists here. Searched the home page, the Filevine page, the Use Cases page, the FAQ, the state guides, the Terms of Use, the Privacy Policy and the Disclosure Policy on 4 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
No governance position of any kind was located. There is no responsible AI page, no principles statement, no management system, no named person or function accountable for model behaviour, no pre-release testing regime, and nothing at all on uneven output across matter types, injury types or populations. The navigation and footer were inventoried across the full estate on 4 September 2026 and the only policy documents published are the Terms of Use, the Privacy Policy and a Responsible Disclosure Policy, none of which addresses how the models are governed. The nearest statement is the AI data policy block, which commits that data is not used to train the models and that processing is scoped to the customer's own cases; that is a confidentiality commitment and it is credited on the privilege row rather than counted twice here. The gap is pointed on a product that extracts clinical findings from records belonging to injured claimants and flags which of them matter to a case.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Access control is published in real detail, retention and deletion are absent entirely, and the usual route to a better grade is closed by the vendor's own drafting. What is published: AES-256 at rest, TLS 1.2 or above in transit, PHI encrypted end to end, single sign-on, role-based permissions restricting case data to authorised users, a full audit trail on every action, regular third-party penetration testing, 24/7 monitoring and alerting, an incident response plan, and multi-region redundancy with a 99.9 per cent uptime SLA. The Responsible Disclosure Policy adds a real published process with committed timelines, acknowledging a vulnerability report within seven business days and triaging within ten, with a safe-harbour authorisation and named exclusions, and its scope clause expressly reaches subdomains, services and applications rather than stopping at the website. What is absent is the rest of the set. No retention period is stated for retrieved records, chronologies or prompts; no deletion or return-of-data commitment for case material exists; no subprocessor is named anywhere, only an assertion that BAAs are executed with all relevant vendors; and no cloud provider is identified. The band's usual shape does not describe this record and the note says so rather than smoothing it: this is not a generic privacy policy stretched over the product, it is a privacy policy whose first line states it applies solely to information collected by the website, so nothing published governs client data in normal operation.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Nothing published addresses who bears the loss when the product is wrong. The Terms of Use do contain a full allocation of loss, and it is recorded here so a reader who finds it sees it was weighed: the service is provided as is with all warranties disclaimed, liability for consequential damages is excluded and capped in any event at 100 dollars, indemnity runs one way from the user to the vendor, claims must be brought within two years, and Delaware law governs. Every one of those provisions is scoped to use of the website. The instrument defines the Site as the place customers access information about the services, so none of it reaches a missed record, an inaccurate chronology or a wrongly extracted case insight, and crediting it as a product liability position would misdescribe what a buyer is actually reading. No customer agreement, service level commitment on accuracy, indemnity, warranty on output or insurance position was located on any surface. The band above does not fit, because its words require a limitation clause that disclaims the exposure the product creates, and this clause does not reach the product at all. Searched the Terms of Use, the Privacy Policy, the Disclosure Policy, the home page, the Filevine page and the FAQ on 4 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
One named integration described at workflow level, with no depth behind it. Codes Health publishes an exclusive partnership with Filevine and a dedicated page for it, stating that record retrieval is integrated directly into the case system so a firm can request, receive and review records inside Filevine, described as a custom Filevine partner workflow. That is a named connection with a stated function rather than a logo, which is what lifts it off the band below. Two further connection classes are named without being specified: direct connections to major claims clearinghouses and payors, and custodian integrations alongside electronic claims networks, none of which identifies a counterparty. A state guide adds that high-volume firms can integrate directly with CRM platforms and case management software, without naming one. What is missing is everything an implementer would need: no statement of what syncs, in which direction, on what trigger, or what a firm must configure; no integrations page, no developer documentation and no API. One limit belongs on the record. The FAQ carries the question of whether the product works with a firm's existing case management system, and the answers on that page did not render for retrieval, so the question was located and its answer was not.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery is implied and neither limb is stated for the product. The security section says the platform is hosted with enterprise-grade infrastructure and carries multi-region redundancy with a 99.9 per cent uptime SLA, which is a resilience statement rather than a residency one: it says copies exist across regions without naming a region or offering a buyer a choice. No cloud provider is identified anywhere. Tenancy is untouched, with nothing stating whether the platform is single or multi-tenant and no dedicated or isolated option described. The one residency sentence on the estate is in the Privacy Policy, stating that data collected through the site is stored on secure servers in the United States and that third parties may not transfer it outside the United States, and it is not credited here because that policy applies by its own terms to website Personal Data rather than to claimant records. Where the AI processing happens is a separate silence, since no model provider is named at all. The record is a customer application at a published subdomain with its own login, so delivery is not in doubt; the tenancy and the region are.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
A compliance claim displayed as a credential, with no scope, no date and no report. HIPAA compliance is presented in the home page hero as one of three headline stats, reading fully compliant, and repeated in the security section. HIPAA is a statutory obligation a covered entity or business associate self-attests to, not an independent attestation, and no assessor, assessment date or scope accompanies it. Regular third-party penetration testing is claimed and names no testing firm, no date, no scope and no summary. No SOC 2 of either type, no ISO certification, no HITRUST and no named auditor appears anywhere, and there is no trust centre or portal on the estate. The only route offered is the line that full compliance documentation is available on request, with no self-service mechanism and no form, only a general contact address, so it earns no credit as an access flow. The band below does not fit, because it requires that no independent attestation be located at all and the site does present a compliance credential; what is missing is everything that would let a buyer test it. Nothing is machine-blocked here: the estate rendered in full and this is an absence rather than a retrieval limit.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The vendor refers to its models repeatedly and identifies nothing underneath them. The estate speaks of an agentic retrieval system, medical-grade AI, and the first legal grade AI for medical records, and the AI data policy refers to our models, which asserts models the company controls without saying whose they are or what they are. No model, no version, no provider, no hosting arrangement and no processing location is named on any page, and no commitment to notify customers if any of that changes was located. The nearest thing to supply chain disclosure is the statement that Business Associate Agreements are executed with all relevant vendors, which concedes that third parties touch protected health information while naming none of them. This is the middle band rather than the floor because the vendor does describe an architecture and does claim models of its own; a buyer simply cannot learn from any published source whose model reads a claimant's medical file.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The charging model is published clearly and repeatedly, and no figure appears anywhere. There is no pricing page in the navigation. Across the state guides the vendor states flat-fee pricing charged per request rather than metered by volume, with no per-page markups, no charge for follow-ups or status checks, no charge for re-requests caused by provider issues, and AI-generated chronologies included in the service rather than priced separately, closing with an instruction to contact the company for current pricing. That is a unit of charge and a clear inclusion boundary, which is why the floor band does not fit: something real is published about how a buyer would be charged. What is absent is the number, and everything around it: no rate, no band, no minimum, no term, no volume tier and no implementation cost. The material is also inconsistent about its own strongest claim, with one state guide calling the pricing transparent while the same section directs the reader to a sales conversation to learn it. A buyer can describe the shape of the invoice before contacting the company and cannot estimate it.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
The buyer is stated without ambiguity and the boundary is left open. Every surface names plaintiff law firms, with personal injury and mass tort practice named throughout and the workflow described in that idiom: pre-litigation, demand packages, settlement negotiation, case intake and acceptance decisions. Jurisdictional coverage is documented in unusual depth for a vendor this size, with retrieval claimed in all fifty states and individual state and city guides setting out facility-level submission requirements, statutory response windows and fee schedules for named hospital systems, which is a substantive coverage statement rather than a claim of breadth. Firm size is addressed only loosely, through references to high-volume firms qualifying for custom integrations. What is not stated is where the product stops: defence firms, insurers, in-house departments and government are never addressed, no practice area is identified as unsuitable, and no matter type is excluded. A separate surface addresses healthcare providers about their own intake process, which is a second audience the coverage material does not reconcile with the plaintiff-firm framing.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
A public policy or trust page states no training on customer content, with no matching term located in the published agreement.
A clear commitment on a product page, with no agreement published that could carry it. The security section states that customer data is never used to train the vendor's models, that all AI processing is scoped to the customer's own cases, and that there is no data sharing between clients; the same block appears on the Filevine partnership page. The agreement search that this value requires was run: the only instrument published is the Terms of Use, which by its own definition governs the marketing website rather than the service, and it contains no training, machine learning, de-identification or aggregate use clause of any kind. Two limits belong on the record. The Privacy Policy reserves the right for the vendor and its business partners to continue using de-identified data indefinitely, but that policy applies by its own first line to Personal Data collected from website Users, and the reservation does not name training or machine learning, so it is recorded rather than treated as a permission over client records. And nothing published states what any third-party model provider may do with content, because no provider is named.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
No located public material states how long anything the product handles is kept. Nothing addresses retention of retrieved medical records, generated chronologies, encounter summaries, extracted case insights or the prompts behind them, and no deletion or return-of-data commitment for case material exists on any surface. The one retention passage on the estate is in the Privacy Policy, which states that Personal Data is retained only as necessary and lists the factors bearing on the period without naming one; it is not recorded as the answer here because that policy states in its opening line that it applies solely to information collected by the website. The adjacent disclosures do not reach the question either: multi-region redundancy and a 99.9 per cent uptime SLA describe availability, and the audit trail records actions rather than how long their subjects persist. Searched the home page, the Filevine page, the Use Cases page, the FAQ, the state guides, the Terms of Use, the Privacy Policy and the Disclosure Policy on 4 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Segregation is asserted in public materials with no published detail on how it is enforced.
Separation is asserted in specific terms and no published detail says how it is enforced. Three statements bear on it, all in the security section: there is no data sharing between clients, all AI processing is scoped to the customer's own cases, and role-based permissions ensure only authorised users access case data, with a full audit trail on every action. That is an assertion about both customer-level separation and in-firm access. What is absent is the mechanism. Nothing states whether the platform is single or multi-tenant, no permission model is documented, no matter-level walls inside a firm's own workspace are described, and there is no administrator documentation, security whitepaper or trust portal where a buyer could test any of it. The distinction matters for the buyer segment here, since a plaintiff firm running screened matters would need matter-level treatment and only tenant-level separation is claimed.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.
Disclosure to authorities is addressed and customer notice is addressed nowhere. The Privacy Policy carries a Government and Law Enforcement Authorities provision under which the company may share data to comply with legal processes or enforceable governmental requests or as otherwise required by law, and lists responding to lawful requests from public and government authorities, including cooperation with judicial proceedings and court orders, among its processing purposes. No commitment to notify, no reservation of discretion over notifying, and no transparency report appears anywhere on the estate. The nearest statement runs to consent rather than notice and is self-limiting, saying prior consent will be sought before disclosure to a third party only where required by law. One scope limit is material and is recorded rather than resolved: this provision sits in a policy that applies by its own terms to Personal Data collected from website Users, so nothing published addresses what happens when a claimant's medical records held in the platform are demanded by process.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
No located material identifies a corpus, and the question does not bite on this product class. Codes Health does not retrieve or present primary law; the material its models work on is the customer's own client's medical and billing records, obtained under a HIPAA authorisation from named providers, so there is no case law database, statutory source, publisher or licensed reference set behind an answer. The value is the honest absence rather than a finding against the vendor. Searched the home page, the Filevine page, the Use Cases page, the FAQ and the three published policies on 4 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Nothing addresses checking authority for subsequent history, and the product does not surface primary law to a user. Its outputs are chronologies, encounter and bill summaries and extracted case insights drawn from medical records. One adjacent practice is worth recording so a reader sees it was considered: the vendor publishes state and city guides that cite primary authority extensively, naming provisions such as 45 CFR 164.524, NRS 629.061, Tenn. Code sections 63-2-101 and 68-11-304, RCW 70.02.080 and D.C. Official Code section 3-1210.12. That is published marketing guidance rather than product output, no verification or currency check is described for any of it, and it is not credited here. Searched the home page, the Use Cases page, the FAQ, the state guides and the three published policies on 4 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
No located material describes what the system does when it cannot ground an output. There is no abstention path, no no-answer state, no confidence or grounding score shown to a user, and no description of behaviour where a record is illegible, contradictory or incomplete. One feature comes close in name and answers a different question: missing-record detection flags gaps in the treatment history, which is the product reporting an absence in the source material rather than an absence of confidence in its own output, and it is recorded here rather than credited. The published assurance in this territory is human verification before delivery, which is an oversight control rather than an uncertainty behaviour and is graded on the autonomy row. Searched the home page, the Filevine page, the Use Cases page, the FAQ and the three published policies on 4 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
The AI Hallucination Cases database maintained by Damien Charlotin was searched on 4 September 2026 on the product name Codes Health and on the corporate name Codes Health, Inc. No court order, opinion or disciplinary record naming the product or the company was located. This records the state of the public record on that date and is not a finding about the product.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No located material engages with bar or ethics guidance at any level. No bar association, rule of professional conduct, ethics opinion or jurisdiction-specific guidance for lawyers is named or referred to in general terms, and nothing addresses a firm's professional obligations when using the product. The regulatory material the vendor does publish is extensive but sits in a different field: HIPAA, state medical record access statutes and provider fee schedules govern how records may be obtained, not how a lawyer may use the tool that obtains them. No statement that the company is not a law firm and no advice disclaimer exists to anchor even a generic reference. Searched the home page, the Filevine page, the Use Cases page, the FAQ, the state guides, the Terms of Use, the Privacy Policy and the Disclosure Policy on 4 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Time and money claims are published throughout and nothing addresses what a client is told. The estate carries 80 per cent less manual review, 50 per cent more case capacity, 1.7x larger settlements, an account of time saved being redirected to client service, and repeated cost arguments that do-it-yourself retrieval costs more than it appears once staff time, resubmissions and missed records are counted. None of it reaches the question. No per-matter record of AI-assisted work is described as available to a firm, no guidance on fee or disclosure treatment is published, and nothing addresses how the cost of the service or the compression of preparation time should be handled with the client. The direction of the question is unusual on this record and is recorded rather than smoothed: the buyers are contingency-fee plaintiff firms, for whom this is a case expense advanced and later recovered from a settlement, so the live disclosure question is what a client is charged and told about an AI-assisted service, and the vendor's flat-fee, all-inclusive structure is published without any accompanying position on that.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The material exists behind a sales conversation or an executed agreement.
A stated request route and nothing published that would let a firm answer its client. The security section states that Business Associate Agreements are executed with all relevant vendors and that full compliance documentation is available on request, which is the route; there is no self-service portal, no form and no named document set, so what that documentation contains was not established. What is published falls short of the artifacts this signal names. No subprocessor list exists, no cloud provider is identified, and no model provider is named anywhere, so a firm cannot tell a client whose model processes its clients' protected health information. There is also no data processing addendum and no consent or notification pack a firm could forward. The forwardable material that does exist is the security section's own commitments on training, case-scoped processing, separation between clients and encryption, which is useful to a firm and is not the provider disclosure a client AI clause asks for.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located public material addresses court disclosure or verification certification.
No located material addresses producing a record of AI-assisted work for a tribunal or a client. Two published features are adjacent and neither does this job, so both are recorded. The platform provides a full audit trail on every action together with real-time request status and visibility into every fax and call made on a firm's behalf, which is a strong provenance trail for how a record was obtained and says nothing about which output a model generated. And insights are stated to be verified by humans, with no artifact evidencing that verification per document. No export of model usage, no attribution of a chronology or an extracted insight to a model or version, and no disclosure template or guidance was located. The gap is worth naming because the product's outputs travel into demand packages and, where a matter does not settle, into filings. Searched the home page, the Filevine page, the Use Cases page, the FAQ and the three published policies on 4 September 2026.