R
Red Oak Compliance

Red Oak is a financial services compliance platform from Red Oak Compliance Solutions of Austin, Texas, sold to broker-dealers, registered investment advisers, banks and insurers. Its core is a configurable, books-and-records compliant workflow engine for advertising and marketing review: firms build their own review workflows with a rules engine, parallel reviews, user-defined questions, document and video annotations, document stamping, full audit trails and SEC 17a-4 write-once retention, and file directly with FINRA through an AREF integration that also retrieves and stores comment letters.

Around that sit disclosure management with a central disclosure library, deterministic disclosure intelligence rules, registration and licensing management, and a supervision suite covering internet supervision of advisers' online presence, social media pre-approval and archiving, and third-party website monitoring. A distribution platform pushes approved content out to advisers. The AI Review module is the machine limb: large language models with prompts engineered to the firm's own policies and procedures give marketers compliance feedback before formal submission, with customers able to bring their own model.

Red Oak also sells compliance consulting and an outsourced chief compliance officer service alongside the software. In July 2026 it combined with MirrorWeb, with the combined company operating under the Red Oak name.

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The models are one module on a workflow platform that sells perfectly well without them, and the vendor says so in its own words. What Red Oak leads with is the most configurable books-and-records compliant workflow engine: unlimited review workflows, a rules engine, parallel reviews, user-defined questions, annotations, document stamping, audit trails and write-once retention. Around it sit disclosure management, registration and licensing management, internet and social media supervision, website monitoring and a distribution platform, none of which is described as model-driven; disclosure intelligence is explicitly deterministic rules.

AI Review is presented as an addition to that engine, with the vendor framing it as using AI without compromising compliance workflows and pairing the module with the engine so a buyer is not sacrificing compliance functionality for the sake of AI. Strip the module out and the platform, which has served this market since well before it, remains. Verified 20 September 2026.

Source: Vendor Published
DD on Citation Accuracy and Hallucination DisclosureNothing published on accuracy or grounding for a product that produces legal assertions, or a bare claim that the system does not hallucinate.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

No accuracy or grounding disclosure was located for the AI module at all. The product gives marketers compliance feedback on advertising copy before it reaches a reviewer, which is a judgement about whether content meets a firm's policies and the rules behind them, and nothing published says how reliable that judgement is. There is no accuracy figure, no error rate, no description of what grounds the feedback beyond prompts engineered to the firm's policies and procedures, no statement that the output should be verified, and no hallucination or limitation disclosure anywhere on the module page or elsewhere on the estate.

The published numbers measure throughput instead: 35 per cent faster approvals, 70 per cent fewer compliance touchpoints and a 54 per cent reduction in AI review time. No customer agreement is published in which an accuracy position might otherwise sit. Checked the AI Review page, the advertising review page, the solutions pages, the privacy notice and the website disclosure. Verified 20 September 2026.

Source: Vendor Published
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

The machine is placed before the human rather than beside or instead of them, and nothing states what weight its output may carry. The described flow is clear enough: marketers receive instant compliance insights so they can correct errors before submission, and the formal review by the compliance team then runs through the workflow engine as it always did, with parallel reviews, audit trails and document stamping behind it.

That placement is a real design decision and the vendor makes a point of it, saying AI improves the existing process rather than breaking it. What is absent is any statement of the constraint. Nothing says the AI's feedback is advisory, nothing describes a threshold or an escalation, nothing addresses whether a reviewer may rely on a clean AI pass, and no published agreement carries an obligation to check output before relying on it. Verified 20 September 2026.

Source: Vendor Published
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Scale is claimed convincingly, testimonials are plentiful, and almost nothing is attributable. The estate publishes more than 1,800 client firms, partnership with over half of the top 20 asset managers, an 84 NPS score, over 99.9 per cent uptime and average help ticket resolution under an hour. Twelve client stories are published and two carry a name and firm: Stephen D. Tally, Chief Operating Officer at Leo Wealth, and Matthew Dorn, President at Dorn and Co. Wealth Management.

The other ten identify the speaker by role and firm type only, such as a chief compliance officer at a broker-dealer, RIA and investment bank. None of the twelve mentions the AI module. The outcome figures, 35 per cent faster approvals, 70 per cent fewer touchpoints and a 54 per cent reduction in AI review time, appear without a period, a sample, a baseline or a method, and none is attached to a named firm. Verified 20 September 2026.

Source: Vendor Published
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Confidentiality is asserted through product properties rather than commitments, and the one privacy document on the estate addresses the wrong subject. The product pages promise data ownership, saying a firm's data stays secure, accessible and under its control, and the platform is built to SEC 17a-4 write-once standards with full audit trails and document stamping. But no customer agreement is published anywhere, so there is no confidentiality clause, no need-to-know restriction, no return or destruction obligation and no compelled-disclosure notice a buyer could read before signing.

The published privacy notice is a financial-institution notice written as though Red Oak were an adviser holding clients' nonpublic personal information, describing brokerage accounts, balances and transactions and an opt-out from sharing with non-affiliated third parties. It says nothing about the marketing material, adviser communications or model prompts the platform actually holds. Verified 20 September 2026.

Source: Vendor Published
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

A real disclosure exists, it is better than boilerplate, and it does not reach the AI. The website disclosure states plainly that Red Oak Compliance Solutions is not a law firm, attorney or CPA firm and does not provide legal services or tax advice; that information on the site should not be relied on as a substitute for legal, tax or accounting advice from a qualified professional; that a firm should retain a compliance professional or attorney for guidance on its own situation; and that securities regulations for advisers vary by state and federal government so the material is general and not specific to any location.

It adds that no relationship arises without a written engagement, and that no outcome with regulators is guaranteed. What it does not do is address the product: nothing states whether AI Review's feedback is advice, whether it must be checked, or who is accountable when a piece clears the machine and fails at examination. The same company also sells an outsourced chief compliance officer service. Verified 20 September 2026.

Source: Vendor Published
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Nothing published addresses governance of the model at all. No owner is named, no testing or evaluation is described before a prompt set or model change reaches customers, no principles page exists, and no disclosure addresses whether the module's judgements differ across content types, asset classes, distribution channels or the populations an adviser markets to. The two statements that touch the machine are operational rather than governance: that no time-consuming model training or retraining is required of the customer, and that a firm may bring its own model.

Neither says anything about how Red Oak governs what it ships. The gap is wider here than the grade alone conveys, because the module's prompts are configured per firm by an implementation team and compliance staff can generate further prompts themselves, so the behaviour of the system varies by customer with no published method for validating any of it. Verified 20 September 2026.

Source: Vendor Published
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Retention of the record is engineered and everything else is generic or absent. What is published and real: SEC 17a-4 write-once retention, full audit trails, document stamping and a data ownership claim, all of which speak to keeping the compliance record intact and producible. What is not published is the rest of the axis. No retention period is stated for prompts or AI output, nothing describes deletion, no subprocessor list appears, no incident response or breach notification practice is published, and no encryption or access-control detail is given.

The privacy notice that would normally carry some of this is a financial-institution notice concerned with nonpublic personal information about individuals, offering only that access is restricted to employees who need to know and that physical, electronic and procedural safeguards meeting federal or state standards are maintained. No security page or trust centre exists on the estate. Verified 20 September 2026.

Source: Vendor Published
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

No position on liability for the product is published, because no customer agreement is published. The navigation and footer were run to the bottom and carry only a privacy policy and a website disclosure; there are no terms of service, no master agreement and no order form anywhere on the estate. The only liability language located is in the website disclosure and it addresses the website rather than the platform: information is provided as is without warranty of any kind, the company assumes no responsibility for errors or omissions in the site's content, and under no circumstances and no legal theory will it be liable for damages of any kind arising from an individual's use of the site.

A separate line states that no specific outcome with securities regulators is guaranteed for registration services or consulting work. Nothing addresses indemnity, caps, warranty, service levels or remedy if the AI module clears content that later draws a regulatory finding. Verified 20 September 2026.

Source: Vendor Published
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Named connections, described by what moves through them, into both the regulator and the marketing stack. The FINRA AREF integration automates direct filing with FINRA and the retrieval and storage of comment letters, which the vendor puts at up to thirty minutes saved per filing; that is a connection into the regulatory system this work actually ends at. A Submission API connects advertising review to content creation tools and automates publishing and retirement of approved material in digital asset management systems, with Seismic, Workfront, PowerBI and Tableau named.

A User Management API integrates with HR systems to automate user activation and deactivation, group memberships and visibility settings. An Embedded Annotations API lets content creators see and act on reviewer feedback inside their own tools. A dedicated integrations and APIs page sits in the navigation. What is missing is depth: no developer documentation was located, and no authentication, sync direction or field-level detail is published. Verified 20 September 2026.

Source: Vendor Published
DD on Deployment Model and Data ResidencyNothing published on where the software runs or where client data sits.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Neither question is answered anywhere on the estate. No hosting region, country or cloud provider is stated for the platform, and no residency commitment appears on any product page, in the privacy notice or in the website disclosure. Nothing describes the tenancy model, and no single-tenant, private or on-premise option is offered or referred to. The only geographic statement located sits in the EU and UK privacy notice and concerns personal information rather than the platform, saying that data may be transferred to companies in the United States and to third parties providing email and marketing services, with reasonable steps taken to protect it.

For a vendor whose customers include firms subject to SEC and FINRA books-and-records obligations and whose combined client base is described as global, the absence of any published residency position is the notable part. Checked the navigation, the footer, all solutions pages read and both privacy notices. Verified 20 September 2026.

Source: Vendor Published
DD on Security Certifications and Trust CenterNo independent security attestation located.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

No independent security attestation is named anywhere and no trust centre exists. There is no security page in the navigation or the footer, which carry only a privacy policy and a website disclosure, and no SOC 2, ISO 27001, penetration testing or audit reference appears on any page read. Nothing is offered on request. The strongest security language on the estate is in the financial-institution privacy notice: access restricted to employees who need to know, and physical, electronic and procedural safeguards that comply with applicable federal or state standards.

That is a description of practice, not something a third party has examined. The absence is recorded rather than inferred, the navigation and footer having been run to the bottom. This records what is published, not a finding about the vendor's actual security, and a firm serving this client base may well hold an attestation that it does not publish. Verified 20 September 2026.

Source: Vendor Published
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The architecture is described and no model is identified. The module page states that AI Review leverages advanced large language models and sophisticated prompt engineering specific to the firm's policies and procedures, and adds an unusual option: bring your own large language model, so a customer is not locked into one model or another. That option is genuinely useful disclosure, because it tells a buyer that model choice can be moved under its own control and its own agreements with a provider.

What is not published is any identification: no default provider, no model family or version, nothing on where inference runs, nothing on what a firm gets if it does not bring its own, and no commitment to notify customers when the underlying model changes. A related line, that no time-consuming model training or retraining is required, describes what the customer need not do rather than what the vendor does. Verified 20 September 2026.

Source: Vendor Published
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

No pricing information of any kind is published. There is no pricing page in the navigation or the footer, no tier names, no feature-to-plan split, no unit of charge, no minimum and no implementation figure, and the only route anywhere on the estate is a demo request or a contact form. The commercial statements that do appear are claims rather than prices: unlimited workflows at no extra cost, data ownership without fees, and implementation in as little as four to eight weeks with the customer's own team trained to manage workflows afterwards to cut long-term costs.

Because no customer agreement is published either, none of the surrounding mechanics is visible: nothing states the term, renewal, notice period or what happens on termination. A buyer cannot form any estimate from public material. Verified 20 September 2026.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Five buyer types are named and the regulatory regimes behind them show up in the evidence. The estate addresses broker-dealers, registered investment advisers, banks, insurance and other industries, and puts its reach at more than 1,800 firms globally including over half of the top 20 asset managers. The client stories fill in the range: a hedge fund and RIA, a global investment manager, a global retirement solutions and insurance company, a private lender, a broker-dealer in the Midwest, and a compliance professional supervising in the foreign exchange markets whose account names CFTC and NFA supervision requirements.

Practice coverage is US securities and financial services compliance, with SEC 17a-4, FINRA filing and state and federal adviser regulation named across the product and disclosure pages. What is absent is the boundary: nothing states which regimes or firm types the platform does not serve, and no non-US regulatory coverage is described. Verified 20 September 2026.

Source: Vendor Published
Sources on file

6 public documents

The public pages on file for Red Oak Compliance, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

No agreement published

No customer agreement, terms of service or equivalent contract is published on any surface located, and no policy page states a position on training. Nothing is granted and nothing is withheld, so a client has no term to hold the firm to. Where a policy page does state a position, the row takes the matching policy value instead and the summary records that no agreement exists.

No customer agreement is published, so no training position can be established. The navigation and footer were run to the bottom and carry only a privacy policy and a website disclosure; there are no terms of service, no master agreement and no order form anywhere on the estate, and no security or trust page exists that might carry a data commitment instead. The privacy notice that is published is a financial-institution notice about individuals' nonpublic personal information, brokerage accounts and transactions, and it says nothing about customer content in the platform or about model training in either direction.

One line on the AI module page can be mistaken for an answer and is not one: the statement that no time-consuming model training or retraining is required describes work the customer is spared, not a limit on what the vendor may do with a firm's marketing material or prompts. The bring-your-own-model option is the only lever a buyer has here, and it is a workaround rather than a commitment.

Source: Operator VerifiedAs of Sep 20, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Not addressed

No located public material states how long prompts and outputs are retained.

How long prompts or AI output are kept is not addressed. The platform's retention story is about the compliance record rather than the machine: material moving through advertising review is held to SEC 17a-4 write-once standards with full audit trails and document stamping, which is retention by regulatory design and is recorded on the stewardship row. Nothing published extends that to the AI layer. No period is stated for the prompts a firm's compliance staff configure or generate, for the instant feedback returned to marketers before submission, or for any intermediate content passed to a model.

Nothing describes deletion. Because no customer agreement is published, there is no document in which such a term could sit, and the bring-your-own-model option means retention may in practice depend on an agreement the customer holds with a provider the vendor never names. Checked the AI Review page, the advertising review page, both privacy notices and the website disclosure on 20 September 2026.

Source: Operator VerifiedAs of Sep 20, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Not addressed

No located public material addresses walls or matter level segregation.

Nothing published addresses walls or segregation, between customers or inside one. The nearest material is administrative rather than protective: a User Management API that integrates with HR systems to automate user activation and deactivation, group memberships and visibility settings, and a workflow engine in which firms build their own review paths with parallel reviews and user-defined questions. Visibility settings imply per-user control but no published detail says what they enforce or how.

No statement describes separation between one client firm's content and another's, which matters on a platform holding unpublished marketing material for more than 1,800 competing firms, and nothing addresses separation inside a firm between business lines, affiliated broker-dealer and adviser entities, or distribution partners. No conflicts or screening mechanism appears. Checked the advertising review page, the AI Review page, the solutions overview and the privacy notices on 20 September 2026.

Source: Operator VerifiedAs of Sep 20, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Disclosure addressed, notice absent

Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.

Disclosure is addressed and no notice attaches to it. The published privacy notices state that information may be shared with regulatory authorities including tax authorities, courts and bodies as required by law or requested for internal investigations and reporting, and separately in connection with litigation, investigations, regulatory or governmental enquiries or other legal or regulatory purposes involving the company or its clients.

A further clause permits transfer of personal information as part of a sale, merger, consolidation, change of control or reorganisation, which is live given the combination announced in July 2026. None of it commits to telling the customer that a demand has arrived, to waiting before producing anything, to narrowing the response or to assisting with a protective order. No customer agreement is published in which such a commitment could otherwise sit, and no transparency report exists.

Source: Vendor PublishedAs of Sep 20, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Jurisdictions only

Coverage is described by jurisdiction with no identification of the underlying corpus.

The regimes are named and no corpus behind the judgements is identified. Coverage is described by jurisdiction and regulator across the estate: SEC rules including 17a-4 write-once retention, direct filing with FINRA, state and federal adviser regulation, and in the client evidence CFTC and NFA supervision requirements. What is never identified is what the AI module actually reasons over. The published account is that prompts are engineered to the firm's own policies and procedures, configured by an implementation team, tuned against the firm's previous submissions and extendable by its compliance staff, which makes the customer's own rulebook the working corpus.

No regulatory rule set, filing manual, enforcement record or interpretive source is named as maintained by the vendor, nothing states who updates the rule content when a regulator moves, and no licence or rights basis is stated for anything.

Source: Vendor PublishedAs of Sep 20, 2026Evidence

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

This product cites no authority, so there is nothing for a treatment signal to attach to. AI Review returns compliance feedback on a firm's own marketing copy measured against that firm's own policies; it does not quote a rule, cite a release or reference an enforcement action that a user would need to verify. The currency question that does arise here, whether the policies and prompts a firm configured last year still reflect what the SEC or FINRA requires today, is not addressed either: nothing published describes rule-change monitoring, a prompt refresh cadence or any notice to a firm that the basis of its automated review has moved.

The disclosure management module maintains a central disclosure library with deterministic rules for where a disclosure belongs, which is version control over the firm's own text rather than a check on authority. Checked the compliance solutions pages, the AI Review page and the website disclosure on 20 September 2026.

Source: Operator VerifiedAs of Sep 20, 2026Evidence

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

Nothing published describes what the module does when it cannot judge a piece of content. The described behaviour is uniformly confident: marketers receive instant compliance insights so they can correct errors before submission, and the module is presented as going beyond deterministic rules to harness advanced AI. No confidence score accompanies a flag, no threshold is described below which the system declines to opine, and nothing says what a marketer sees when content falls outside the prompts configured for that firm, which is the ordinary case for a new product type or a novel claim and the one where silent confidence costs most.

Nothing distinguishes a clean pass from an unexamined one. Because the prompts are firm-specific and extendable by the firm's own staff, the boundary of what the module can assess varies by customer and is documented nowhere. Checked the AI Review page, the advertising review page and the solutions overview on 20 September 2026.

Source: Operator VerifiedAs of Sep 20, 2026Evidence

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

None located

No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.

No record was located of this product's output being found fabricated or inaccurate in a proceeding, a regulatory action or a published account. Searches on 20 September 2026 across the vendor's estate, press and directory profiles returned nothing of the kind. The failure that would matter here is not an invented citation, since the module asserts no authority: it would be marketing material that cleared automated review and later drew an SEC or FINRA finding, or a required disclosure the system did not flag as missing. Nothing published describes such a case and no account of one was found.

Source: Operator VerifiedAs of Sep 20, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Generic reference

Public materials refer to professional responsibility in general terms without naming guidance.

Professional duty is engaged squarely and no guidance is named. The website disclosure states that Red Oak Compliance Solutions is not a law firm, attorney or CPA firm and does not provide legal services or tax advice; that information on the site is not a substitute for legal, tax or accounting advice from a qualified professional; that a firm should retain a compliance professional or an attorney for guidance on its own situation; and that no relationship arises from viewing the site or contacting its consultants without a written engagement.

It also notes that adviser regulation varies by state and federal government and that the material is not specific to any location. That is a clearer statement of the advice line than most records in this lane carry. What is absent is any named authority: no rule of professional conduct, no ethics opinion, no bar or regulator guidance on the use of generative AI, and nothing tying the AI module to a compliance officer's own supervisory obligations.

Source: Vendor Publishedis not a law firm, attorney, or CPA firm and does not provide legal services or tax adviceAs of Sep 20, 2026Evidence

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Outside the fee relationship

The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.

No lawyer's fee sits in this product's path. The buyer is the regulated firm itself, licensing the platform for its own compliance and marketing teams, and nothing is billed on to an advisory client. The vendor's own commercial framing is internal efficiency and revenue velocity rather than legal spend: shorter review cycles, 35 per cent faster approvals, 70 per cent fewer compliance touchpoints, unlimited workflows at no extra cost, and advisers getting quicker access to approved content that drives growth.

The one place a fee relationship does appear is the consulting and outsourced chief compliance officer side of the business, where a firm pays Red Oak for compliance work under a written engagement and fee agreement, but that is the vendor's own service rather than a lawyer billing a client, and nothing addresses disclosing machine assistance within it.

Source: Vendor PublishedAs of Sep 20, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Not addressed

No located public material supports a client side disclosure obligation.

A diligence reviewer would find almost nothing to work from. No subprocessor or model provider list is published, no security certification is named, no penetration testing statement appears, no data processing addendum is offered, and no trust centre or security page exists in the navigation or the footer. No customer agreement is published, so there is no confidentiality, data handling or audit-cooperation term to point at.

The published privacy notices are financial-institution and consumer privacy notices concerned with individuals' personal information rather than with the platform's handling of client content, and the only security language in them is that access is restricted to employees who need to know and that safeguards meeting federal or state standards are maintained. The one genuinely useful disclosure for a reviewer is architectural rather than documentary: a customer may bring its own model, which moves that part of the supply chain under its own contracts.

Source: Operator VerifiedAs of Sep 20, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

The record is built for an examiner rather than a court, and it is substantial as a record while saying nothing about the machine. The platform is described as 100 per cent books and records compliant, with SEC 17a-4 write-once retention, full audit trails and document stamping, and the FINRA integration stores comment letters alongside the filings they answer. A published client account describes producing audit reports directly from the system to demonstrate to regulators that required monitoring was performed, with individual findings organised.

So a firm can show what was reviewed, by whom and when. What is absent is the disclosure question itself: nothing distinguishes a flag raised by the AI module from one raised by a human reviewer once both sit in the trail, nothing describes an export addressed to disclosing machine involvement, and no court sits in this product's path. Third record in this pull read through the regulatory analogue.

Source: Vendor PublishedAs of Sep 20, 2026Evidence
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 20, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746