T
Trustible
Trustible is an Arlington, Virginia company selling an AI governance platform organised around four stages: intake, where every AI use case, model, agent and vendor is captured and routed by risk; risk and impact management, where systems are scored and assessments orchestrated; monitoring of internal performance and external risk signals with alerts that trigger governance actions; and compliance, where governance activity is turned into audit-ready evidence. Its distinctive architecture is a control library rather than a set of per-regulation checklists: Trustible's policy and regulatory experts read each framework in full, normalise its obligations into Controls, and map each Control to every article and clause it satisfies across more than fifteen frameworks, so satisfying a control once updates compliance posture everywhere it applies. Supported frameworks span the EU AI Act, Colorado's AI Act, the Connecticut bill, NYDFS guidance, the NAIC model bulletin, OMB M-25-21, ISO/IEC 42001, the NIST AI Risk Management Framework, and Singapore, Australian and South Korean instruments, with designations such as High Risk, Provider, Deployer and GPAI determining which controls apply to a given system. Model-driven work sits on top of that library: an assistant answers natural-language questions about the AI inventory, agents parse third-party documents such as a vendor's data processing agreement and map their contents to named controls, analyse vendor risk signals, and verify through AI-assisted analysis whether a customer's own policy text addresses a control's guiding questions. The company is an AI-native Public Benefit Corporation, holds a third consecutive SOC 2 Type II certification, hosts its AI tools on Microsoft Azure and states that it does not train them on customer personal information. Named customers include Leidos, Nuix, Ashoka, Guardian Life, Boston Scientific, Molson Coors, Olympus, Korn Ferry and Evertec. The customer agreement is negotiated individually rather than published.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Models do real work on top of a system of record that would function without them, and the vendor is unusually explicit about which half is which. The model half is genuine: the homepage shows a live governance feed in which a vendor's data processing agreement is parsed and mapped to seven ISO 42001 controls, a model provider's API is analysed and twelve risk signals surfaced, and an assistant answers natural-language questions about the AI inventory, returning named high-risk use cases with their regulatory designations. The methodology page adds that policy controls are satisfied by verifying, through AI-assisted analysis, that a customer's policy text addresses a control's guiding questions. The other half is not models and the vendor says so: the risk and regulatory intelligence layer is curated by its own policy experts and applied through what it calls a rules-based engine, framework mappings are built by experts reading each framework in full, and designations determine applicable controls by rule. Strip the models out and the inventory, the control library, the mappings, the routing and the evidence trail remain, which is the product most of this lane sells. Homepage and methodology page read 7 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted in numbers and measured in none of them. The site publishes framework readiness percentages, a documented count of controls a parsed agreement maps to, twelve risk signals surfaced from a vendor review, and headline claims of ten times faster intake and documentation time cut from twelve hours to two. None carries a method, a test set or an error rate. Nothing published states how often the AI-assisted analysis of a customer's policy reaches the right conclusion about whether a control is satisfied, what happens when it does not, or whether a person checks before the control is marked met. Where grounding does exist it is for the record rather than for the model's judgment: the compliance surface states that evidence is assembled from real governance activity rather than reconstructed, logged with field-level precision and timestamped to the use case, with per-article gap analysis, so a reader can trace a compliance claim to the activity behind it. Several limbs of this band do not bite and are named rather than penalised, since the outputs are control mappings and risk scores rather than legal assertions citing authority. Homepage, methodology and compliance pages read 7 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The vendor publishes how much runs without a person, which most records on this axis do not, and stops short of the threshold. What is published: agentic workflows do the heavy lifting while human experts keep the customer in control; the governance agent automates tasks with context and rules while preserving human judgment where it matters; structured intake routes every use case by risk automatically; low-risk AI moves through in minutes; and the dashboard states that seventy-two per cent of use cases are auto-approved with an average review time of 1.8 days. Publishing the auto-approval rate is a real disclosure of the boundary rather than a claim about oversight. The review surfaces are named alongside: a task queue with review types and statuses, reviews routed to the right stakeholders, and an agentic activity feed showing what was triaged, analysed, parsed and reassessed with timestamps. What is missing is the limb this band names as commonly absent: nothing defines what counts as low risk, no threshold or criterion is published for the auto-approval path, and nothing states what happens when a use case was auto-approved and should not have been. Homepage and platform description read 7 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers with named people in named roles, and figures that float free of them. Three customer stories are published with attributed quotations: Leidos, where a VP of AI Strategy and Governance says the platform turbocharged use case throughput across a programme spanning forty countries; Nuix, where the General Counsel says AI governance became an operational reality that is evidence based; and Ashoka, where a Vice President for Global Integrity describes a small team doing work of a much larger one. The wider roster names Guardian Life, Boston Scientific, Molson Coors, Olympus, Korn Ferry, Evertec, Kroll, Databricks and Google. The figures are separate from the names and carry no method: ten times faster intake, four times more use cases approved, sixty per cent reduction in cycle times, seventy-two per cent auto-approved, 1.8 days average review, and documentation time cut from twelve hours to two. A third-party account of a Leidos proof of concept describes intake compressed from weeks to hours or minutes and is described rather than credited. Homepage, SOC 2 announcement and case study listings read 7 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Confidentiality is asserted in general terms and no commitment a buyer could read before signing was located. The customer agreement is not published: the terms of service state that services are provided under separate agreements negotiated individually with each customer, so there is no published confidentiality clause, no statement of who at the vendor may access customer content, and no segregation position. What does exist is narrower than this axis needs and is credited where it belongs rather than here: the privacy policy commits that the AI tools are not trained on Personal Information and do not retain Personal Information uploaded into them, and the SOC 2 Type II covers data and privacy controls among its five areas. Both are expressed as to Personal Information rather than to the governance content a customer loads, which for this product is use case descriptions, vendor contracts, policy text and completed assessments. Nothing addresses segregation between customers, nothing states what the model host may retain, and the security section of the privacy policy is expressly hedged, promising reasonable efforts and no guarantees. Terms of service, privacy policy and SOC 2 announcement read 7 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
A boilerplate disclaimer sits in the website terms while the product produces regulatory characterisations, and nothing addresses where its output stops and a legal judgement begins. The characterisations are specific and consequential: designations of High Risk, Provider, Deployer and GPAI determine which EU AI Act obligations attach to a customer's system, per-article gap analysis reports where a programme falls short of named articles, and the assistant will tell a user which of its use cases qualify as high-risk AI systems under the Act. Those are legal conclusions in substance. Nothing published states that they are not legal advice, that counsel remains responsible for the classification, or what jurisdictional limits apply to the framework content. The only disclaimer language located is in the website terms of service, which govern the site rather than the platform, and the customer agreement that might address it is not published. Same grade and reasoning as the comparable records in this lane. Homepage, methodology page and terms of service read 7 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A principle is published and no mechanism stands behind it, which is worth stating precisely because of what this company sells. The principle is explicit: in its own SOC 2 announcement the chief executive says governance is the product, so the company holds itself to the same standard it asks its customers to meet, and it is constituted as a Public Benefit Corporation. Tested against the published record, the claim holds on security and not on AI. On security there is a third consecutive SOC 2 Type II with five named audit areas. On its own AI there is nothing comparable: nobody is named as accountable for the governance agent's behaviour, no evaluation before release is described, no result from any such evaluation is published, no bias or reliability disclosure exists for the AI-assisted policy analysis that decides whether a control is met, and the company claims no ISO 42001 certification of its own while selling ISO 42001 readiness to others. It does publish model ratings for third-party generative systems at a separate site, which is a product capability rather than governance of itself. The trust centre could not be read on this channel and is the rebuttal route. SOC 2 announcement, homepage and methodology page read 7 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy across most of the ground, short of incident practice and access control. What is published: a third consecutive SOC 2 Type II certification whose five audit areas are named, including data and privacy controls, tested for operating effectiveness over a period rather than design at a point in time; four subprocessors identified by name in the privacy policy, being Amazon Web Services, Microsoft Azure, Cloudflare and PostHog; hosting stated to be in the United States with Standard Contractual Clauses for European transfers; a retention approach that commits to deleting or de-identifying personal information when it is no longer necessary, with the criteria for setting the period described; and an explicit statement that the AI tools do not retain Personal Information uploaded into them. Two limbs are missing and one is hedged: no incident or breach notification practice is published anywhere, no access control or personnel restriction is described, and the security section promises reasonable efforts with an express disclaimer that no guarantee is given. The trust centre states it carries a controls breakdown and a hosting FAQ, and returned no body on this channel, which is recorded as a retrieval limit rather than an absence. Privacy policy and SOC 2 announcement read 7 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Nothing published states who bears the loss when the product is wrong, and the vendor says why. The terms of service of 3 October 2025 govern the website and state that the services are provided under separate agreements negotiated on an individual basis with each customer. So there is no published indemnity, no liability cap, no warranty, no service level commitment, no exclusive remedy and no insurance statement, and none was located on any other surface. This is recorded as a disclosure choice rather than an accusation: the vendor discloses that the agreement exists and is negotiated privately, which is more than the two records in this lane that publish website terms and leave a reader to infer the rest. The exposure a buyer cannot price is worth naming on a product of this kind: the platform produces the regulatory classifications and evidence packages an organisation would rely on in front of a regulator, and nothing published says what the vendor stands behind if a classification or an evidence package is wrong. Terms of service and all located surfaces checked 7 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
An integration surface is described and no integrations are named. The platform plainly ingests from outside itself: the governance feed shows a third-party data processing agreement parsed and mapped to controls and a model provider's API analysed for risk signals, the implementation plan commits to connecting the customer's systems in the first thirty days, and the product is positioned as a system of record that vendor and model reviews feed into. What is absent is any named connector, any statement of what moves in which direction, and any documentation an implementer could work from. No integration list, no API or SDK documentation and no partner directory was located on the surfaces read. Two things are recorded so the grade is read correctly: a third-party assessment describes the platform as operating on metadata rather than in the data path, which is described and not credited; and the two site pages most likely to carry an integration list, the platform overview and the agentic governance feature page, both returned 404 despite appearing in the site's own navigation on every page, which is a site fault rather than a limit of this channel. Homepage, methodology page and navigation checked 7 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
One region is stated and the deployment model is not. The privacy policy says the services are hosted in the United States and are intended for visitors located within the United States, that using them from Europe or elsewhere means transferring personal information to the United States for storage and processing, and that European transfers rely on European Commission or United Kingdom approved Standard Contractual Clauses. It separately states that the AI tools are hosted through Microsoft Azure, and names Amazon Web Services and Microsoft Azure among the subprocessors, so a buyer can establish the country and the cloud providers. Nothing goes further: no region selection, no European or other non-US hosting option, no tenancy model, no single-tenant or self-hosted arrangement, and no statement addressing where processing happens as distinct from where data is stored beyond the transfer mechanism. The trust centre states it contains a FAQ on how customer data is hosted and secured, which is where the rest would sit, and returned no body on this channel. Privacy policy and SOC 2 announcement read, trust centre attempted, 7 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The most substantive certification disclosure in this lane, short of a report a reader can reach. What is published, in the vendor's own announcement of 18 August 2026: a renewed SOC 2 Type II certification, stated to be the third consecutive one, so the controls have held across multiple audit cycles; an explanation of what Type II means, testing whether controls operated effectively over an extended period rather than were designed well at a point in time; and the five areas this cycle's audit examined, being infrastructure security controls, organisational security controls, product security controls, internal security procedures, and data and privacy controls. A trust centre was launched alongside it, stated to carry a compliance overview, a full breakdown of controls by category, a subprocessor list, and a FAQ on how customer data is hosted and secured. What keeps this off the top grade is reachability and specificity: no auditor is named, no report period or date is given, no scope statement identifies the product or entity covered, and the report itself is available on request for customers and prospects conducting vendor due diligence rather than self-serve. The trust centre returned page metadata with no body on this channel, so its contents could not be verified. SOC 2 announcement read in full and trust centre attempted 7 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The supply chain is partly disclosed: a host is named, the models are not. The privacy policy states that the AI tools are hosted through Microsoft Azure, and lists four subprocessors by name, being Amazon Web Services, Microsoft Azure, Cloudflare and PostHog, with hosting stated to be in the United States. That answers where the AI runs and which providers are in the path, which is more than most records in this lane offer. Three things are absent. No model or model family is named, and under the standing rule naming a provider is not naming a model, so the top grade is unavailable. No commitment is given to notify customers when the arrangement changes. And nothing distinguishes which parts of the platform route customer content to the Azure-hosted tools. One arrow is deliberately not crossed: Anthropic and OpenAI appear on the homepage only as the vendors being governed in a demonstration, a Claude API vendor review and an OpenAI data processing agreement being parsed, so they belong to the customer's estate rather than to Trustible's own stack. Privacy policy and homepage read 7 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. There is no pricing page, and none appears in the site navigation, which carries platform, solutions, company and resources sections and ends every path at a demo request. No tier or edition is named, no unit is identified, whether by use case, seat, model, framework or enterprise, no band or range appears, and no minimum or term is stated. The customer agreement that would carry the commercial mechanics is not published, since the terms of service state that services are provided under separately negotiated agreements. The only adjacent commercial fact located is the implementation shape rather than its price: a thirty, sixty and ninety day plan with a named advisor and hands-on enablement, which tells a buyer that professional services are part of the engagement without saying what any of it costs. No VendorPricing row is written. Site navigation, terms of service and homepage checked 7 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described with real substance on the regulatory side and the boundaries are left open. Fifteen frameworks are published individually, each with its jurisdiction and its type stated, and the vendor distinguishes binding regulation from certifiable standard from voluntary framework rather than listing them flat: the EU AI Act, Colorado's AI Act, the Connecticut bill, NYDFS guidance, the NAIC model bulletin, Colorado insurance regulation, OMB M-25-21, the GAO framework, a financial services risk management framework, ISO/IEC 42001, the NIST AI RMF, the Singapore framework, the Australian government standard, the CHAI healthcare guidelines and South Korea's AI Basic Act. Scope within a customer is defined by designations, so High Risk, Provider, Deployer and GPAI determine which controls apply to each system. Four industries have their own surfaces, being financial services, healthcare, insurance and technology, and the customer roster adds defence and nonprofit. The buyer is described as governance teams, with the trust centre stating the platform is built for enterprise AI and legal teams. What is not stated is any limit: no jurisdiction, sector or organisation size is named as out of scope, and no coverage depth is given for frameworks outside the three the site treats in detail. Methodology page, homepage and trust centre metadata read 7 September 2026.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
A public policy or trust page states no training on customer content, with no matching term located in the published agreement.
Public material states that customer content does not train the models, and no agreement is published to match it. Section 6 of the privacy policy, last updated 3 October 2025, is headed How We Use Artificial Intelligence and says the customer may interact with AI while using the services, that the AI tools are hosted through Microsoft Azure, and that Trustible does not train its AI tools with the customer's Personal Information. The value's own text requires that no matching term be located in a published agreement, and the search for one was completed rather than assumed: the terms of service govern the website and state that the services are provided under separate agreements negotiated on an individual basis with each customer, so there is no published contract to check against. Two scope limits travel with the commitment and are recorded rather than smoothed over. It is expressed as to Personal Information, not to customer content generally, and the material this platform holds is largely not personal data: use case descriptions, vendor contracts, policy text and completed assessments. And it is expressed as to the AI tools, leaving the platform's other processing unaddressed; the policy separately reserves use of information to develop new products, services and features. Privacy policy and terms of service read 7 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
A specific retention period is published and the customer cannot change it.
A published position the customer cannot change, and it is the strongest form of one: no retention at all by the AI tools. Section 6 of the privacy policy states that the AI tools do not retain Personal Information uploaded into them. That is a vendor default rather than a customer setting, which is why this sits at the fixed value rather than a configurable one, and no option to vary it is offered. The same two scope limits as on the training row apply and matter more here. The commitment covers Personal Information rather than the governance content that makes up most of what a customer loads, and it covers the AI tools rather than the platform, which is a system of record designed to keep assessments, decisions and evidence indefinitely so they can be produced to an auditor. For the platform's own records the policy gives criteria rather than a period, committing to delete or de-identify personal information when it is no longer necessary and listing the factors that set the period. Privacy policy read in full 7 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses walls or matter level segregation.
No located public material addresses segregation between customers or inside a customer's own tenant. The platform is built around shared visibility rather than compartmentation, routing use cases to reviewers across risk, legal, compliance and business teams and giving leadership a live dashboard view, and nothing published describes whether a reviewer in one business unit can see assessments belonging to another, or how one organisation's inventory, vendor reviews and policy analysis are isolated from another's. No customer agreement is published that would carry a confidentiality or segregation term, and the trust centre that states it holds a controls breakdown returned no body on this channel. Methodology page, homepage, privacy policy and terms of service checked 7 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.
Disclosure to authorities is addressed and customer notice is not. The privacy policy's disclosure section states that Trustible may access, preserve and disclose Personal Information where it believes doing so is required or appropriate to comply with law enforcement requests and legal process such as a court order or subpoena, to respond to requests, or to protect rights, property or safety. It carries no commitment to notify the customer, no reservation of discretion over notice, no undertaking to seek a protective order, and no limit to the portion legally required. The threshold is also broad on its own terms, extending to what the vendor believes appropriate rather than only what is required. No compelled-disclosure clause exists to supplement it, because the customer agreement is not published, and no transparency report or law enforcement guidelines page was located. Privacy policy read in full and terms of service checked 7 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Sources are identified without stating the licence or rights basis.
The sources are named individually and the maintenance is described, with no licence basis stated. Fifteen frameworks are published with their jurisdiction and type, so a buyer can see exactly which instruments the control library derives from, and the derivation itself is unusually well described: policy and regulatory experts read each framework in full, identify every obligation and clause, normalise them into Controls, and map each Control to every article it satisfies. Currency is addressed rather than assumed, with experts stated to monitor framework changes continuously and update mappings so a customer's completed work carries forward, which is more than most records on this signal offer. What is absent is the rights basis. Several of the sources are copyrighted works rather than public law, ISO/IEC 42001 among them, and nothing states the licence under which their requirements are reproduced or normalised into the product. Nothing states when each mapping was last reviewed, or what a customer sees if an assessment was completed against a superseded version. Methodology page read in full 7 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
No located public material addresses whether authority is checked for subsequent history, and the limbs do not bite for this product class. The outputs are control mappings, designations, risk scores and evidence packages rather than citations to case law, so there is no reported decision whose treatment a user would need to check. The analogue that does bite, whether the framework mappings track amendments to the instruments they encode, is addressed on this record and is credited on the corpus provenance row rather than counted twice here: the vendor describes continuous monitoring of framework changes by its own experts, with mappings updated as regulations and standards evolve. What is still missing there, and worth naming once, is any statement of when a given mapping was last reviewed. Methodology page and homepage checked 7 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
No located public material describes what the assistant or the governance agent does when it cannot reach a supported answer. The published material addresses authority rather than uncertainty: agents automate tasks with context and rules while preserving human judgment where it matters, and low-risk work is auto-approved while higher-risk work routes to reviewers. Those describe who decides what, not what the system does when the evidence is thin. Nothing states whether the assistant declines a question it cannot ground in the inventory, whether the AI-assisted policy analysis reports that it could not determine whether a control is satisfied rather than guessing, or whether any confidence or coverage signal is exposed to the reviewer. That matters on this product because the analysis decides whether a control is marked met, and a control marked met on a wrong reading becomes evidence produced to an auditor. Homepage, methodology page and privacy policy checked 7 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
No court order, opinion or disciplinary record naming Trustible or Trible AI was located as of 7 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on the company name alongside a general search of the sanctions coverage; the decisions naming specific tools name general-purpose chatbots and legal research products. This is a statement about the public record, not a finding about the product. Exposure is structurally remote for a platform whose outputs are internal governance artefacts rather than filings, with the qualification that those artefacts are built to be produced to regulators and auditors, an audience that carries its own accuracy expectations even though it is not a court.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No located public material engages with bar or ethics guidance, or with lawyers' professional obligations in general terms. Trustible engages regulation in more depth than most records in this lane, publishing fifteen frameworks with their obligations normalised into controls, and it addresses legal teams as a buyer, with its trust centre describing the platform as built for enterprise AI and legal teams and a General Counsel appearing as a named customer voice. All of that concerns the obligations of the organisations that buy the product. Nothing names an ethics opinion, a bar association guidance document or a regulator's guidance on lawyers' use of AI, and nothing addresses the position of in-house counsel who signs off a regulatory classification the platform generated. The lower value was tested before this one was taken: a generic reference would require some engagement with professional responsibility as such, and none was located. Methodology page, homepage, privacy policy and terms of service checked 7 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.
The product does not touch a fee between a lawyer and a client. Trustible is licensed by an enterprise to govern its own AI estate, and the users it names are governance leads and cross-functional reviewers drawn from risk, legal, compliance and business teams, all internal functions that bill no client for the work. The efficiency claims on the site, ten times faster intake and sixty per cent shorter cycle times, are aimed at the buyer's own throughput, which the value text records as not making the row a savings claim. Nothing addresses billing, fee or disclosure treatment because there is no client invoice for it to address, and no fee terms of any kind were located in any event, since the customer agreement is negotiated individually and not published. Homepage, methodology page and terms of service checked 7 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
A current subprocessor list is published and the forwardable pack around it is thin. The privacy policy names four subprocessors, being Amazon Web Services, Microsoft Azure, Cloudflare and PostHog, and separately states that the AI tools are hosted through Microsoft Azure, which is more than a bare infrastructure list because it identifies where the AI processing happens. Hosting is stated to be in the United States, with Standard Contractual Clauses relied on for European transfers. What is missing is the material a firm would actually forward and the answer a client's AI clause turns on. No data processing agreement was located on any surface. No customer agreement is published, since the terms of service state that services are provided under individually negotiated agreements, so the confidentiality, security and liability terms a questionnaire asks about cannot be sent in advance. And no model provider or model is named, only the host, so a customer cannot say whose model reads the vendor contracts and policy text that the platform parses. The trust centre states that it carries a subprocessor list and a hosting FAQ and returned no body on this channel; it is the rebuttal route. Privacy policy read in full, terms of service checked, trust centre attempted, 7 September 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Some elements of a record exist, built for a regulator rather than a court, and none of them records the model's own work. What the platform produces is substantial and well described: every governance action, including intake decisions, risk and impact assessments, approval records, periodic reviews and policy sign-offs, is logged with field-level precision and timestamped to the use case record, assembled as work happens rather than reconstructed, with exportable evidence packages available on demand and per-article gap analysis recalculated as the programme changes. An organisation could show an auditor who decided what and when. What is absent is the limb this signal asks for. Nothing published offers a per-item record of which model or agent produced a given output, what it read, and what a person verified before the result was accepted, which matters because the platform's AI-assisted analysis can mark a control satisfied. Nothing addresses a court's standing order on AI use, and no certification or template a filer could attach is offered. The distinction is that the record is of the customer's governance decisions, not of the model's part in reaching them. Compliance surface, homepage and methodology page checked 7 September 2026.