L
LBOX
LBOX is a Korean legal research and AI platform built on a database of South Korean court judgments, statutes and administrative rules. The company positions the product as a single working environment for lawyers, running from case law and statute search through AI answers to document drafting, and it is available on the web and as a mobile app. The artificial intelligence is delivered as LBOX AI, which the company describes as a legal AI agent: rather than answering a query in one pass, it plans and executes the whole sequence itself, interpreting the question, searching the relevant materials, verifying what it finds and generating the final answer, and the company describes the move to an agent architecture as the most fundamental product change since LBOX AI first launched.
Answers are grounded in the company's own legal data, which it presents as the way it reduces the hallucination risk of general-purpose AI, and cited precedents and statutes are linked so a reader can open the underlying authority. Text entered as a query and files uploaded for analysis are stated to be used only while the answer is being generated and deleted once that purpose is met, and the company states that personal information in queries and uploaded files is not used to train AI models.
Work is organised into projects and folders, and documents a user creates are visible only to that user and to Business plan colleagues given sharing rights. Access to the AI agent is restricted: it is available to members who have completed occupational verification as lawyers, judicial scriveners, labour attorneys, tax accountants, patent attorneys or accountants, to staff of courts, prosecution offices, police and legal research institutions the company recognises, and to employees of other organisations only where a qualified legal professional has approved their use and the work is carried out under that professional's direction, supervision and review.
Plans run from Standard for individuals through Business and Enterprise for firms and legal departments, a Law School plan for students, and a Public plan offered to government and public institutions on an IP-authenticated basis. Alongside the research platform the company operates LBOX Scholar, a publishing arm through which named academics and practitioners write commentaries and practice texts that are surfaced as citation support inside AI answers and for which authors are paid royalties based on actual usage, as well as CaseNote, Lawwave and the consumer-facing L-Find lawyer directory. LBOX Co., Ltd. is based in Gangnam-gu, Seoul, and is led by its founder Lee Jin.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of a core capability on a product that would still function without them, which is the B band exactly, and the vendor's own history makes the boundary unusually easy to see. LBOX began as a judgment database. The AI arrived later as LBOX AI and was then rebuilt: the company's own product announcement describes the shift to an agent architecture as the most fundamental product change since LBOX AI launched, with every step from receiving the question to delivering the final answer now running on an agent, and it claims this as the first legal AI agent in Korea.
The current positioning is AI-first, the platform being sold as the single AI working environment for lawyers covering case law and statute search, AI answers and document drafting. What keeps it off A is the A band's own test: remove the models and there is nothing left to sell. Remove them here and a Korean case law and statute database remains, with search, projects, folders and the instance linking that users single out, and it is that database the company treats as the durable asset, grounding its AI in its own legal data rather than in a general corpus.
The AI is also not universally available within the product, being gated to occupationally verified legal professionals and to supervised staff, so some subscribers hold the platform without holding the agent. Recorded and not credited toward this axis: LCUBE, the Korean legal language model the company released with KAIST at NeurIPS 2022 on a 147,000-judgment corpus, is real and is the company's own, but it is a research artifact and is not what the seed's AI line implies is shipped. Verified 13 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real and documented with linked primary sources, and no measured accuracy is published, which is the B band. The grounding is described as the point of the product rather than as a footnote: answers are generated from the company's own legal data so that the question's intent is understood in context, and the vendor states in terms that this minimises the hallucination that can occur with general-purpose AI.
R40 governs rather than the D limb, because the claim sits alongside architecture rather than in place of it. The verification path is concrete. Cited precedents and statutes are linked and openable from the answer. Where a commentary or practice text from the company's own LBOX Scholar imprint supports an answer, the original text is reachable directly from the AI query so a reader can check the basis of the answer against the source, and authors are shown how often their material is cited by the AI.
That is a closer coupling between answer and authority than most records in this corpus publish. What is absent is measurement. No accuracy figure, error rate, test set or evaluation is published on any first-party surface for the agent, for search or for drafting, and nothing states what proportion of answers carry support. Recorded and expressly not credited because it is not first-party: press coverage reports the company claiming its agentic AI outperformed human candidates on the bar examination and beats general-purpose AI on accuracy, which is a measurement claim made to a newspaper rather than published with a test set the reader can assess.
The A band also asks whether the system states when it found no support, and nothing addresses that. Verified 13 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A written commitment that the models work alongside a supervising lawyer, short of the full control structure, which is the B band, and the commitment here takes an unusual form worth setting out. Rather than describing a review step inside the product, the vendor controls who is permitted to operate the agent at all. Its published eligibility rules limit LBOX AI to members who have completed occupational verification as lawyers, judicial scriveners, labour attorneys, tax accountants, patent attorneys or accountants; to staff of courts, prosecution offices, police and legal research institutions the company recognises as appropriate; to employees of other organisations only where a qualified legal professional has given prior approval and the work is performed under that professional's direction, supervision and review; and to public institutions using the IP-authenticated Public plan.
Verification requires documentary proof by profession. So the supervising-lawyer requirement is not a sentence of marketing but an access control with an enrolment process behind it, and the vendor frames it as continuing work to keep use of legal AI lawful. Against that, the autonomy being supervised is real and broad: the agent plans and executes the entire sequence itself, from interpreting the question through searching and verifying to producing the answer and drafting documents.
What the A band asks for is absent. No mode distinction is published, no confidence threshold, no statement of when the agent stops or escalates, no described review surface between generation and use, and nothing on what happens after the system is wrong. The verification affordance that exists, opening the cited authority, is the user's own diligence rather than a control the vendor operates. Verified 13 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Unattributed testimonials and store metrics stand in for deployment evidence on first-party surfaces, which is the C band. What the vendor publishes itself is thin for a company of this standing. The pricing page carries user quotes attributed only by role, an in-house counsel and unnamed practitioners, with competitor names redacted; under R122(2) a testimonial is named customer evidence only where the customer is named, and none is.
The Google Play listing gives 10,000-plus downloads and a 4.6 rating from 155 reviews, which measures an app rather than a platform. LBOX Scholar names authors, including senior academics and practitioners whose commentaries it publishes, but an author is a supplier rather than a customer and is not credited here. No named law firm, corporation, court or public institution was located on any first-party surface, no case study, and no outcome figure of any kind.
Recorded and expressly not credited, because they are third-party and would breach the first-party floor: press coverage reports the company serving ten of the largest domestic law firms, corporations and major judicial institutions, and an aggregator profile reports some 23,000 lawyers using the service. Aggregator listings are excluded outright as evidence, and the press figures are neither published by the vendor nor attributable to a named customer.
The gap is the interesting part of this record: a vendor with what its own market plainly treats as the leading position publishes almost nothing a buyer could verify about who uses it. Verified 13 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Four of the five A limbs are met and the fifth is not addressed at all, which holds this at B under R33 and makes it the second record in this pull to sit one word short. What is published is strong and specific. On training, the vendor states that personal information in queries and uploaded files is not used to train AI models. On retention and deletion, query text and uploaded files are stated to be used only while the answer is being generated and deleted immediately once the purpose is met, with the privacy policy setting a further ceiling of 30 days at each overseas processor.
On segregation, documents a user creates are visible only to that user and to Business plan colleagues expressly granted sharing rights, and all material is stated to be held encrypted in customer-dedicated storage. On third party model providers, the position is not merely explicit but enumerated: the privacy policy names OpenAI, Anthropic, Google, Amazon and Microsoft as recipients of user input to LBOX AI, with the purpose and the retention period for each.
That last limb is answered more completely here than on any other record in this pull. The limb that fails is privilege and work product, and it fails by absence rather than by weakness. Neither privilege, professional secrecy nor work product is addressed anywhere located, on a platform whose users are verified lawyers uploading case documents for analysis, and nothing states what happens to that material if it is demanded.
Two further limits belong on the record: the no-training sentence is written about personal information within queries and files rather than about the content itself, and the deletion commitment is what closes that gap in practice; and the customer agreement, which would be the natural home for all of this, is published and could not be read by this index. Verified 13 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
A real published position, short of full treatment, which is the B band, and this record is the inverse of the usual shape. The B band anticipates a disclaimer without the supervision and competence dimension. Here the supervision dimension is the strongest thing on the axis and the disclaimer is what could not be found. Who may use the product is stated with more precision than any record in this corpus and is enforced rather than asserted.
The AI agent is available only to members who have completed occupational verification against documentary proof as lawyers, judicial scriveners, labour attorneys, tax accountants, patent attorneys or accountants; to staff of courts, prosecution offices, police and legal research institutes the company recognises; and to employees of other organisations only where a qualified legal professional has approved the use in advance and the work proceeds under that professional's direction, supervision and review.
Public institutions reach it through an IP-authenticated plan. The vendor frames this as ongoing work so that those doing legal work can use legal AI lawfully, which engages the Korean regulation of legal services without naming it. That is the competence and supervision limb, answered operationally. What is missing is the rest of the A band. No statement was located of what the product is and is not, no advice disclaimer on any readable surface, and no jurisdiction limit stated, though the content is Korean law throughout.
The customer agreement, where such a statement would ordinarily sit, is published and unreadable to this index. Recorded so the grade is read correctly: the consumer-facing lawyer directory the company also operates is a separate product and is not this record. Verified 13 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Nothing published on AI governance was located, which is the D band, and the contrast with what this vendor does publish is the finding. On data protection the governance is documented in detail: a named protection officer who is the chief executive, a named handler, a named responsible department, an internal management plan with inspection, a dedicated organisation, regular staff training, and a statutory grievance route.
None of that reaches AI. No responsible AI or ethics statement, no AI policy, no acceptable use position, no accountable owner for model behaviour, no description of what is tested before a model or agent change ships, and no disclosure of evaluation results of any kind was located on any readable surface. Bias is not addressed anywhere. That matters on this product for a specific reason worth naming rather than leaving general: the agent ranks and selects which precedents surface in answer to a legal question, and a systematic tilt in retrieval, toward particular courts, particular periods or particular outcomes, would be invisible to the user and would shape the authority a lawyer relies on.
Nothing published would let a buyer test it. The vendor did publish a benchmark and model of its own with an academic partner in 2022, which shows the capability to evaluate exists internally, and no evaluation of the shipped agent has been published in the four years since. The absence is not explained by retrieval difficulty: the help centre and policy estate are fully readable and carry nothing on this. Verified 13 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Retention, deletion, access control and subprocessors are all published and specific, and no incident practice was located, which is the B band and precisely the second of the two gaps it names. The published material is detailed because Korean data protection law requires it to be, and the record benefits either way. Retention: query text and uploaded files used only during answer generation and deleted immediately afterwards, with a stated ceiling of 30 days at each overseas processor, behavioural logs held until withdrawal, and statutory periods set out instrument by instrument.
Destruction: a stated procedure, electronic records rendered unrecoverable and paper shredded or incinerated, with credential documents destroyed immediately once verification is complete. Access control: access rights management, an access control system, encryption, security software, access logs retained and periodically inspected, plus physical control of server and archive rooms and locked storage, all under an internal management plan with a dedicated organisation and regular training.
Subprocessors: fully enumerated, domestic and overseas, including re-delegated parties, with the company committing to notify without delay through the privacy policy if a processor or the scope of its work changes and to consent to any re-delegation. What is absent is incident practice. No breach notification commitment to customers was located, no notification window, no description of incident response, and nothing states what a subscriber would be told or when. Verified 13 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Nothing published on who bears the loss when the output is wrong could be located, and the note records the reason precisely so the grade is read as the state of the located record rather than as a finding about the vendor's contract. A customer agreement exists and is published. The integrated service terms, the paid service terms and the operating policy are all linked from the vendor's own footer and help centre. The paid service terms and operating policy are hosted on Notion and return the JavaScript shell rather than a body, and the terms page on the main domain sits behind the same bot detection that blocks the rest of the site to this index.
R85 governs: a document that is published and machine-unreadable is a limit on the reader, not an absence by the vendor, and it is never graded as a finding against them. The R8 ladder was run in full, including recovery through the vendor's own Korean document vocabulary, which opened the whole help centre and policy estate but did not surface the operative liability clauses. So what is recorded is that no warranty position, no liability cap, no indemnity and no insurance statement was located on any readable surface.
What was located is commercial rather than liability material and is not credited here: refunds where a paid plan is unused within seven days of payment, or within thirty days on a switch from Standard to Business or Public, no fee reduction where a Business plan's active user count falls mid-term, and a notice-and-objection process for fee changes. The grade would move on a reading of the agreement, and the note says so. Verified 13 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
No integration into the systems legal work already lives in was located, which is the D band, and the product's own shape is part of the explanation. LBOX is built to be the place the work happens rather than a layer over something else: the vendor's own framing is a single AI working environment for lawyers, running search, AI answers and drafting inside its own interface, with projects and folders for organising matters and sharing within a Business plan.
Nothing published describes moving that work anywhere else. No practice management system, document management system, billing system or CRM used by Korean firms is named as supported. No public API reference, developer documentation, connector catalogue or authentication model was located, and there is no integrations page anywhere in the navigation or the help centre, which is a page-inventory finding under R20 rather than an unreachable page.
The only external touchpoints located are a mobile application on iOS and Android, which is the same product on another device rather than an integration, and third-party services in the vendor's own processing chain, being optical character recognition and payments, which are supplier arrangements and are not capabilities offered to a customer. Recorded so the D is read correctly: a firm adopting this platform is adopting a destination, and nothing published tells it how the work leaves. Verified 13 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery with a genuinely detailed answer on where data goes and a partial one on tenancy, which under R38 is B on either limb and is comfortably clear of C on both. Residency is answered with more precision than almost any record in this corpus, because the privacy policy carries a statutory cross-border transfer table naming each recipient, the destination country, the transfer method, what is transferred, the purpose and the retention period.
A buyer can therefore establish that text and files entered into LBOX AI are transmitted to the United States to OpenAI, Anthropic, Google, Amazon and Microsoft, that transfers to Amazon and Microsoft are described as travelling over an encrypted network, and that retention at each is capped at 30 days after the purpose is met except Google at 180 days. The policy also states plainly that refusing the overseas transfer means the service cannot be used, and that the only remedy is to close the account, which is an unusually candid statement of the trade-off.
Tenancy is claimed rather than described: all material is stated to be held encrypted in customer-dedicated storage, and document visibility is limited to the creator and to Business plan colleagues given sharing rights. What is absent is the domestic half of the picture. No data centre, region, cloud provider or hosting arrangement is named for the primary platform, nothing distinguishes storage from processing for Korean-resident data, no residency option or on-premises deployment is offered or refused, and the dedicated-storage claim carries no description of how the separation is implemented. Verified 13 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
No certification held by this vendor and no trust centre were located, which is the D band, and the reason the grade is not higher needs stating because the site invites the opposite reading. The home page tells a buyer that all data is processed on verified infrastructure that has obtained global security certification. Read carefully, that is a statement about the infrastructure provider, not about LBOX. The ground rules and R16 both bite here: a cloud provider's certification is infrastructure rather than the vendor's own attestation, and credit follows scope that a buyer can establish.
No certificate, attestation or audit report of LBOX itself was located under any standard, whether ISO 27001, ISO 27701, SOC 2 or Korea's own ISMS-P, which is the certification a Korean information service provider of this size would ordinarily hold and publish. No auditor is named, no report period or certificate number appears, no penetration test summary exists, and there is no trust centre, security page or compliance page anywhere in the navigation or the help centre.
What is published instead is a description of controls without third-party validation, and it is substantive: administrative, technical and physical measures set out by category, an internal management plan with inspection, a dedicated organisation, regular training, access rights management, an access control system, encryption, security software, access log retention and periodic inspection, and controlled physical access to server and archive rooms.
Statutory compliance with the Personal Information Protection Act is asserted and a protection officer is named, and neither is an independent attestation. Verified 13 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The supply chain is partly disclosed, which is the B band by design under R35, and the part that is disclosed is the most complete provider naming located in this pull. The privacy policy's cross-border transfer table identifies, by legal entity and contact address, every party that receives what a user types into LBOX AI: OpenAI LLC, Anthropic PBC, Google, Amazon and Microsoft, each with the purpose stated as generating the answer to the user's question, and Microsoft additionally for optical character recognition of uploaded files.
Upstage is named as the domestic processor performing the same OCR conversion. Each entry carries a retention period, 30 days after the purpose is met for all but Google, which is 180. Change notification, which R34 counts as a distinct limb and which most records lack entirely, is committed: the vendor undertakes to disclose without delay through the privacy policy any change of processor or of the scope of the work, and states that re-delegation requires its consent and is published.
What holds this off A is the limb R34 makes decisive: providers are identified and the models themselves are not. No model or version is named for any of the five providers, nothing states which provider serves which function or how requests are routed between them, and nothing distinguishes the vendor's own retrieval layer from the frontier models it calls. The company's own LCUBE model, released with an academic partner in 2022, is not described as part of the current stack and is not credited as one.
So a buyer learns exactly whose infrastructure sees its content, and not what is running on it. Verified 13 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Real pricing is published for part of the range with the enterprise tiers withheld, which is the B band in its own words. The structure is fully published and ungated: an individual Standard plan, Business and Enterprise plans for firms and legal departments, a Law School plan for students, and a Public plan offered to government and public institutions on IP authentication, with discounts published for members of bar associations and of the labour attorney and loss adjuster bodies under partnership arrangements.
The unit of charge is clear, being per user per month for Standard, per seat with volume discounting for Business and Enterprise, and institution-wide by IP for Public. The commercial mechanics are published in the operating policy rather than hidden: refund where a paid plan is unused within seven days of payment, or within thirty days on a switch from Standard to Business or Public, expressly no fee reduction or refund where a Business plan's active user count falls during a term, and fee changes announced in advance with an objection window and an opt-in for preferential rates.
Figures exist and are the vendor's own, published in its fee-change notices: a Standard monthly rate moving from 29,900 won to a six-month preferential 39,900 won and then to 69,900 won. Two limits keep it off A and are stated rather than implied. Those figures come from a fee-change notice rather than from a current rate card, so their age goes in the note under the standing rule that age never enters the grade; and the live pricing page, which exists and is ungated, sits behind the bot detection that blocks the whole main domain to this index, so what a buyer sees there today could not be read. Business and Enterprise pricing is quoted rather than published in any event. Verified 13 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is described with real substance and the practice boundaries are left open, which is the B band. Who this is for is set out more precisely than most records manage, and it is set out as an enforced eligibility rule rather than as marketing. Named professional segments are lawyers, judicial scriveners, labour attorneys, tax accountants, patent attorneys and accountants, each with its own verification route.
Institutional segments are named too: courts, prosecution offices, police and legal research institutions, reached through recognition by the vendor, and government and public bodies through an IP-authenticated Public plan the company describes as a social contribution. Law firms and in-house legal departments are addressed through Business and Enterprise plans with an administrator and user distinction, students through a Law School plan with defined eligibility including repeat bar candidates and doctoral students, and non-lawyer staff only under a qualified professional's supervision.
Content coverage is Korean, spanning court precedents, statutes and administrative rules, with the company's own commentary and practice texts layered over it through its Scholar imprint. What is left open is the practice dimension. No practice area is named as supported or unsupported, nothing states which courts or which years the judgment database reaches, and nothing says whether the AI agent covers the whole corpus or only parts of it.
Jurisdiction is Korea throughout and is never stated as a limit, which matters for a buyer with cross-border work. Verified 13 September 2026.
5 public documents
The public pages on file for LBOX, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.
-
lbox.kr5 signals
Client Data in Training, Ethical Walls and Matter Segregation, Good Law Verification and 2 more
Read Sep 13, 2026
-
Prompt and Output Retention, Third Party Request and Subpoena Notice, Outside Counsel Guideline Readiness
Read Sep 13, 2026
-
lbox.kr/scholar1 signal
Primary Law Corpus Provenance
Read Sep 13, 2026
-
lbox.kr/v2/pricing1 signal
Billing and Fee Posture
Read Sep 13, 2026
-
Bar Guidance Alignment
Read Sep 13, 2026
From ₩69,900 per month
- LBOX publishes its plan structure openly, and the individual price is knowable, though you should confirm the current figure on the site.
- There are five plans. Standard is the individual subscription. Business and Enterprise are for firms and legal departments, sold per seat with a volume discount and an administrator who manages who gets access. There is a Law School plan for students, including repeat bar candidates and doctoral students. And there is a Public plan that the company offers to courts, prosecution offices, police and other public institutions, which works on IP address rather than individual logins and which the company describes as a social contribution rather than a commercial tier.
- On price, the company's own fee notices set the Standard rate at 69,900 won a month, having moved up from 29,900 won through a six-month preferential rate of 39,900 won. That figure comes from the vendor's announcement of the change rather than from a current rate card, so treat it as the last published rate and check the pricing page. Business and Enterprise are quoted rather than listed.
- Discounts are published for members of bar associations and of the labour attorney and loss adjuster bodies under partnership arrangements.
- The refund position is clear and worth knowing before you buy. You can get a refund if you have not used a paid plan within seven days of paying, or within thirty days if you switched from Standard to Business or Public. If a Business plan loses users mid-term because people leave, there is expressly no reduction and no refund for the unused seats. Fee changes are announced in advance with a window to object, and the company has previously offered a preferential rate to existing subscribers who accepted a change.
- One thing you cannot do is read the contract. The terms are published in three parts and all three are effectively unreadable to anything but a browser.
Published plan structure with a per-seat unit of charge and a published individual rate; enterprise tiers quoted rather than listed. Five plans: Standard for individual practitioners, Business and Enterprise for law firms and in-house legal departments sold per seat with volume discounting and an administrator and user distinction, a Law School plan with defined student eligibility including repeat bar candidates and doctoral students, and a Public plan offered to government and public institutions on IP authentication rather than per user, described by the vendor as a social contribution.
The individual rate published in the vendor's own fee-change notice is 69,900 won per month, reached from 29,900 won via a six-month preferential rate of 39,900 won, with existing subscribers offered the preferential rate on accepting the change within a stated window. Discounts are published for members of bar associations and of the labour attorney and loss adjuster bodies under partnership arrangements. AI access is not separately metered but is gated by eligibility: the AI agent is available only to occupationally verified legal professionals, to staff of recognised judicial and law enforcement institutions, and to other employees working under a qualified professional's approval and supervision, so a Business plan administrator allocates AI rights rather than purchasing them by volume.
Refund mechanics are published in the operating policy: refund where a paid plan is unused within seven days of payment, or within thirty days on a switch from Standard to Business or Public; expressly no fee reduction or refund where a Business plan's active user count falls during a term. Fee and policy changes are announced in advance with an objection window, silence after a stated period being treated as acceptance.
No term length, minimum commitment or uplift provision was located, and the customer agreement in which they would sit is published and machine-unreadable.
Confidentiality and data terms: No business associate agreement, data processing addendum or separately signable data instrument is published. The data commitments live in the privacy policy and on the product surface rather than in a forwardable contract, and they are unusually detailed because Korean data protection law compels the disclosure: a full processor list including re-delegated parties, a cross-border transfer table naming OpenAI, Anthropic, Google, Amazon and Microsoft as recipients of user input to the AI with purpose and retention for each, immediate deletion of query text and uploaded files once the answer is generated, a 30-day ceiling at each overseas processor except Google at 180 days, a statement that personal information in queries and uploads is not used to train AI models, and a commitment to publish any change of processor without delay. The vendor accepts the statutory roles under the Personal Information Protection Act and names a protection officer, a handler and a responsible department. What is absent is external validation and a signable instrument. No certification held by LBOX itself was located under any standard including Korea's own ISMS-P, no auditor or report period is named, and no trust centre exists; the only certification referred to anywhere is that of the underlying infrastructure provider, which under R16 and the ground rules is infrastructure rather than this vendor's attestation and is not credited. No breach notification commitment to customers was located.
Note: Structure, plan names, discount arrangements and refund mechanics read from the vendor's own pricing page copy and from the operating-policy revision notices published on its help centre, 13 September 2026. entryPriceUsd carries the published numeral 69900 in its native currency, Korean won, following the settled corpus convention confirmed at Manupatra across eleven non-USD rows and logged as parking item 5; no conversion has been applied and none should be inferred. The figure is the Standard monthly rate published by the vendor in its own fee-change notice, which set 29,900 won moving to a six-month preferential 39,900 won and then to 69,900 won. Two qualifications on that figure, recorded so it is not read as more current than it is. It comes from a fee-change announcement rather than from a rate card read today, and the standing rule is that an old first-party source still clears the bar with its age going into the note and the confidence rather than into the grade. And the live pricing page at lbox.kr/v2/pricing exists and is ungated but sits behind the bot detection blocking the whole main domain to this index, so what a buyer sees there today could not be read; that is a limit on this reader under R85 and never a finding against the vendor. Business and Enterprise pricing is quoted per seat with volume discounting rather than published, the Public plan is institution-wide on IP authentication, and a Law School plan exists with defined student eligibility. The customer agreement, which would carry the commercial terms behind the price, is published on the vendor's footer in three parts and is machine-unreadable, two as JavaScript shells and one behind the same bot detection.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
A public policy or trust page states no training on customer content, with no matching term located in the published agreement.
Public material states that customer content is not used to train, with no matching term located in a published agreement, which is this value. The statement sits on the product surface and is direct: personal information in queries and uploaded files is not used for AI model training. Around it the vendor publishes a purpose limitation that does most of the practical work, stating that text entered as a query and files uploaded are used only during the process of generating the answer and are deleted immediately once the collection and use purpose is met, and the privacy policy caps retention at each overseas model provider at 30 days after that purpose is achieved.
Two qualifications belong on the record rather than in the value. The training sentence is written about personal information within queries and files rather than about the content of those files as such, so read strictly it is narrower than a general no-training commitment; what closes that gap is the immediate-deletion commitment, since material deleted on completion is not available as training data. And the value is policy rather than contractual because R43(1) was run and could not be discharged: the integrated terms, the paid service terms and the operating policy are all published and linked from the vendor's own footer, and all three are machine-unreadable to this index, the first behind the site's bot detection and the others as JavaScript shells.
The three-way choice therefore remains live for a later pass in the manner recorded on Anytime AI, and a reading of the agreement could move this row in either direction.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
A specific retention period is published and the customer cannot change it.
A fixed period is published, and it is published twice at two different levels, which is this value. At the product level the vendor states that query text and uploaded files are used only while the answer is being generated and deleted immediately once the collection and use purpose is achieved. At the processor level the privacy policy's cross-border transfer table sets an explicit ceiling for each recipient of that same content: a maximum of 30 days after the purpose is met for OpenAI, Anthropic, Amazon and Microsoft.
The discrepancy inside that table is named rather than averaged away, because a reader who finds it unaided and does not find it here would trust the record less: Google's entry is not 30 days but 180, stated as until the collection purpose is achieved or the retention period of 180 days expires. Nothing explains why one provider holds the same material six times longer than the others. Behavioural and usage data is treated separately and held until the member withdraws, covering search terms entered, search result clicks, AI query submission history, and document creation, saving and download history, collected through named third-party software development kits.
Statutory retention is set out instrument by instrument, including three months for communication confirmation data and five years for contract and payment records. The customer agreement, which would ordinarily carry a return or deletion obligation on termination, is published and unreadable to this index.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
A permission model is described rather than merely claimed, which is this value. The rule is stated at document level and in the vendor's own words: material a user creates is viewable by that user alone, and beyond them only by Business plan members who have been granted sharing rights. That is a default-closed model with an explicit grant, which is the substance of a wall between colleagues inside the same subscribing organisation, and it is the form of segregation a firm actually needs.
Around it sit two supporting statements: all material is held encrypted in customer-dedicated storage, which is a tenant-level separation claim, and work is organised into projects and folders that carry the sharing boundary. The Business and Enterprise plans distinguish administrators from users, and the help centre addresses what happens to a departing employee's projects when a corporate account is closed, which indicates the model is administered rather than notional.
What is not published keeps this off the top of the range. Nothing describes the roles or permission levels available, how a grant is made or revoked, whether an administrator can read a user's projects, or whether any audit record of access exists. Nothing addresses conflicts or matter-level walls as a legal concept rather than as a sharing setting, which is the framing a Korean firm managing a conflict would look for.
And on the vendor's own side, no statement was located limiting which staff may view customer material or requiring that such access be logged.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.
Compelled disclosure is addressed and customer notice is absent, which is this value. The privacy policy states that where a state agency requests provision under the procedure and method prescribed by law, the company may provide personal data to a third party. The trigger is narrower than most in this corpus, being tied to a statutory procedure rather than to any legal request or to protecting the vendor's own interests, and the surrounding third-party provision regime is consent-based and enumerated, listing only the lawyer receiving a consultation request and the payment provider, each with the items provided and the recipient's retention period.
One unusual feature is recorded because it is a real mitigation and is rare: the same clause commits the company, where such a disclosure occurs, to state the fact in the privacy policy itself. That is a published-transparency undertaking rather than a transparency report, and it is more than most vendors offer, but it is a disclosure to the world after the event and not notice to the affected customer. What is absent is the thing this signal names.
Nothing states that the subscriber would be told a demand had been received, given an opportunity to object or to seek relief before production, or informed afterwards, and no transparency report or law enforcement guidelines page exists. The customer agreement, which might carry a notice term, is published and unreadable to this index, so the row records the policy position.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Sources are identified without stating the licence or rights basis.
The sources are identifiable and the licensing basis for the main corpus is not stated, which is this value. What the corpus consists of is clear enough from the vendor's own surfaces: South Korean court judgments across instances, statutes and administrative rules, with the linking between lower and appellate decisions singled out by its own users as the distinguishing feature. The published research the company did with an academic partner describes the same underlying material at scale, a corpus of 147,000 Korean precedents amounting to 259 million tokens.
What is not published is the basis on which the judgment database is held. Nothing states how judgments are obtained, under what statutory access route or agreement, whether any court or government body licenses them, or what the vendor may do with them, which is a live question in Korea where access to written judgments has been a contested policy matter rather than a settled open-data position. One part of the corpus is licensed and is licensed transparently, and it is recorded as the exception rather than allowed to carry the row: LBOX Scholar commissions commentaries, practice texts and articles from named academics and practitioners, publishes them as citation support inside AI answers, and settles royalties with the author on the basis of actual usage, with the author shown how often the AI cited their work.
That is an express licensing arrangement with a named counterparty class and a consideration, and it covers the secondary material rather than the precedents. Verified against the surfaces read on the date shown.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
No located public material addresses whether authority is checked for subsequent history, and the note distinguishes what is genuinely absent from what is adjacent. The adjacent capability is real and is what users praise: the platform links a case across instances, connecting first instance to appellate to Supreme Court, and that linkage is repeatedly named as the reason practitioners prefer it. Cited precedents and statutes are also linked and openable from an AI answer.
But instance linking is case history, not treatment. It tells a reader what happened to this case on appeal; it does not tell them whether the proposition the case stands for has since been overruled, distinguished, doubted or superseded, and no flag, indicator, status or treatment vocabulary of any kind was located. Nothing states whether a judgment surfaced by AI Search or cited in an answer is still good law, and nothing describes any editorial or algorithmic process that would establish it.
The gap is worth naming plainly because of what the product is: an agent that selects and presents precedent to verified lawyers, in a jurisdiction whose courts have begun demanding explanations for citations that turn out not to hold. The surfaces read on the date shown were the product home page, the AI landing page, the Scholar pages, the help centre in full including the release and policy notices, and the mobile listing.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
No located public material describes what the system does when it cannot produce a reliable answer. What the vendor publishes is a claim about the rate of the problem rather than a description of the behaviour: answers are generated from its own legal data so as to minimise the hallucination that can arise with general-purpose AI. That is an architectural argument for fewer bad answers, not a statement of what happens when one is about to be produced.
Nothing states that the agent declines a question outside its corpus, reports that it found no supporting authority, attaches a confidence signal to an answer, marks a low-confidence passage for checking, or escalates rather than answering. The question has particular force on this product because of the architecture the vendor itself describes: the agent plans and executes the whole sequence, deciding what to search, judging what it has found and composing the answer, and the vendor states that it verifies information as part of that loop.
Verification is asserted as a step in the pipeline, and nothing published says what the step does when it fails. The user-side mitigation that exists is real and is recorded without being credited as this signal: cited precedents, statutes and Scholar passages are linked so a lawyer can open the source and check the answer against it, which is the reader's diligence rather than the system's behaviour. The surfaces read on the date shown were the product home page, the AI landing and agent announcement pages, the help centre in full, and the mobile listing.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.
Searched on 13 September 2026 against the company name in Korean and English and against the product name, across Korean legal press reporting on AI-generated fabricated citations and the international trackers. None located. No decision, order or disciplinary finding names LBOX or LBOX AI. Context is recorded because the jurisdiction is now live on this question and a reader should be able to see that the absence was tested against a real body of cases rather than an empty field.
Korean legal press reported in 2026 the first domestic instance of fabricated citations reaching a court, a criminal division finding that five judgments cited in an advocate's written opinion did not exist on the court network, the advocate withdrawing them and then acknowledging under questioning that AI had been used; separate reporting describes a court ordering a party to file an explanation of how a fabricated judgment came to be cited and to produce the originals of every Supreme Court decision relied on, and describes courts and bar bodies weighing what sanctions should follow.
No product is named in any of that reporting, and general-purpose assistants rather than legal platforms are what the accounts describe. Under R119 this signal records fabricated legal citations in filings and nothing else, so no other proceeding involving this vendor would appear here.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Public materials refer to professional responsibility in general terms without naming guidance.
Professional responsibility is engaged in general terms without any authority being named, which is this value, and the engagement here is more operational than most records at this level. The vendor restricts who may use the AI agent by professional qualification, verifying lawyers, judicial scriveners, labour attorneys, tax accountants, patent attorneys and accountants against documentary proof, admitting staff of courts, prosecution offices, police and legal research institutions it recognises, and permitting other employees only under the prior approval and the direction, supervision and review of a qualified legal professional.
It frames that regime as continuing review so that those working in law can use legal AI lawfully, which is an explicit if unnamed reference to the Korean statutory framework governing who may perform legal work. The Korean Bar Association appears on the estate, but only as an identity source: bar membership card registration and issue numbers are collected to verify that a member is a lawyer, and bar association partnership discounts are offered.
That is credential plumbing, not alignment. What is absent is any named authority or guidance. No provision of the Attorney-at-Law Act is cited, no Korean Bar Association opinion, ethics rule or AI guidance is referenced, and no court guidance is mapped to the product, at a moment when Korean courts have begun demanding explanations for citations that do not exist and bar bodies are publicly weighing what sanctions should follow. Nothing connects the agent's output to the verification duty falling on the lawyer who files it.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The product sits inside a lawyer to client fee relationship and no located public material addresses billing, fee or disclosure treatment, with no savings claim published either.
Nothing published addresses what happens to the bill when AI-assisted work takes an hour instead of six, which is the floor, and none of the higher values is true of this record. The product sits inside a lawyer-to-client fee relationship: its buyers are verified practising lawyers and law firms on Business and Enterprise seats, and legal research time in Korea is conventionally either billed or absorbed into a fee. Nothing states which.
No per-matter record of AI-assisted work is described, nothing marks output as machine-generated for the purpose of a bill or a fee note, no guidance on fee or disclosure treatment is published, and no saving is claimed in billable terms. The vendor's efficiency claims are framed as productivity for the practitioner rather than as time removed from a client's invoice, and the one quantified claim located anywhere is a bar-examination accuracy comparison in press coverage, which is about quality rather than cost.
Recorded and expressly not credited under R21 and R24, because subscription cost is a different object from AI-assisted work: the platform publishes per-seat pricing, volume discounts for Business and Enterprise, bar association partnership discounts, and refund mechanics, all of which would let a firm attribute software cost to a matter and none of which addresses the client's bill. All four higher values being false, this is a gap rather than a grading error and the summary carries it.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
A current processor list and a model provider statement are both published and no forwardable client-facing pack sits around them, which is this value under R29's IPRally condition. Two of the three artifacts are present and are the most complete in this pull. The privacy policy enumerates every processor, domestic and overseas, including re-delegated parties: payment and identity providers with their own re-delegates named, Upstage for optical character recognition of uploaded files, and messaging and mailing suppliers.
Separately, and this is what answers a client's AI clause, the cross-border transfer table names by legal entity every recipient of what a user types into LBOX AI, being OpenAI LLC, Anthropic PBC, Google, Amazon and Microsoft, with the destination country, the transfer method, the purpose stated as generating the answer, a contact address for each, and a retention period of 30 days after purpose except Google at 180.
Under R29 that satisfies the model provider limb outright rather than partially, and infrastructure is not doing the work: three of the five are model providers named as such. The vendor also commits to publish any change of processor without delay. The third limb fails. There is no data processing addendum, no consent or notification pack drafted to be forwarded, and no client-facing disclosure artifact of any kind; the disclosure lives in a privacy policy written for the data subject under Korean statute.
R29's condition is explicit that where the list sits outside a DPA and no other forwardable artifact exists, the value drops rather than the top two values collapsing into each other. A firm can nonetheless forward the policy and answer its client precisely, which is more than most records at this value permit.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located public material addresses court disclosure or verification certification.
No located public material addresses disclosure of AI involvement in legal work, which is the floor, and on this record the absence is more pointed than on most because the jurisdiction has begun asking the question directly. Nothing identifies output as machine-generated once it leaves the platform. No audit trail of AI use is described, no per-query or per-matter record a firm could produce, no export designed to evidence what the agent did, no certification template, and no guidance on when or how AI assistance should be disclosed to a court or a client.
The platform records AI query submission history as behavioural telemetry for its own analytics, held until the member withdraws, and nothing indicates that record is available to the subscriber as evidence of its own use. Two adjacent features are recorded and not credited. Cited precedents, statutes and Scholar passages are linked and openable from an answer, which supports verification before filing rather than disclosure after it.
And documents generated in the platform sit in projects with sharing controls, which is storage rather than provenance. The concrete consequence is worth naming: Korean courts have begun ordering parties to explain how a fabricated citation came to be filed and to produce the originals of the authorities relied on, and a lawyer using this agent has nothing published that would let them show afterwards which passages the model produced and which authority it drew on at the time.