Legal AI
Smokeball AI / Archie
Medium riskAI features across the Smokeball practice management suite for small firms (family law, personal injury, conveyancing), including the Archie matter assistant, intake, billing narratives, and communication summaries.
Is Smokeball AI / Archie safe for confidential data?
Smokeball's published claims are reassuring but thin on verifiable detail. The vendor states Archie and other AI features run in a ring-fenced environment under zero-data-retention agreements, that firm data is never used to train AI models or shared outside Smokeball, that each firm's data is logically isolated, and that Archie operates within a single matter and inherits existing matter permissions — genuinely good design choices. What is missing is independent corroboration: Smokeball's ISO 27001 certification is published on its Australian site, no SOC 2 report is publicly referenced for the U.S. business, the LLM providers behind the generative features are not named (an AWS case study indicates AWS-hosted GenAI), and the boundary between Smokeball's long-standing deterministic automation and the newer generative features is not always clear in marketing. Several facts below are marked unknown accordingly; the sensible posture is to enable it under a contract that restates the claims.
Risk by plan
The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.
Vendor-stated no-training across the suite; Archie is a paid add-on scoped to one matter at a time and to users who already have access to that matter.
Data handling
Training on inputs
Smokeball states firm data is never used to train AI models and never shared outside Smokeball, with zero-data-retention agreements covering Archie's underlying providers. The specific model providers are not publicly named; treat the commitment as contractual, not architectural, until confirmed.
Retention
Vendor claims zero data retention by third-party AI providers; retention of prompts and AI outputs within Smokeball itself is not published — confirm in your agreement.
Residency
Smokeball operates U.S., Australian, and UK clouds; its ISO 27001 certification and security policy are published on the Australian site. Confirm which region hosts your firm's data and its AI processing (relevant for PIPEDA if serving Canadian clients).
Compliance
- SOC 2Not verified
- GDPR / DPANot verified
- HIPAA BAANot verified
Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.
New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.
Enterprise controls
- Matter-scoped AI (Archie limited to single-matter context)
- AI access inherits existing matter permissions
- Per-firm logical data isolation
- ISO 27001:2022 certification (published for Smokeball Australia)
- Annual third-party penetration testing (vendor-stated)
Frequently asked questions
Is Smokeball AI secure enough for client matter data?
The published design is sound — single-matter scoping, permission inheritance, per-firm isolation, and vendor-stated zero-retention agreements with AI providers — but almost all of it rests on Smokeball's own statements, with ISO 27001 the main independent attestation and that published for the Australian entity. Before relying on it for sensitive matters, get the no-training and zero-retention claims restated in your contract and ask which region and providers process your data.
Which Smokeball features are generative AI, and does it matter?
It matters for risk review. Smokeball's document automation and time tracking are largely deterministic and carry ordinary cloud-software risk, while Archie, intake generation, AutoTime narratives, and Communicate summaries are generative and can be wrong in fluent ways. Marketing labels both 'Smokeball AI', so review them separately: verify generative outputs (especially billing narratives that go to clients and courts) the way you would any AI draft.
Does adopting Smokeball AI address our firm's wider AI use?
No. A matter assistant inside your practice management system covers in-platform tasks; the quick research question or letter rewrite still tends to go to a personal chatbot account outside any agreement. Small firms in Smokeball's core practice areas handle exceptionally sensitive facts — family and injury matters — so pair the sanctioned assistant with explicit rules and controls for everything else.
Policy changelog
- Initial entry published from Smokeball's published security documentation; independent verification is sparse and several facts are marked unknown.
Sources
- Smokeball AI product page (US)
- Smokeball security policy (Australia, ISO 27001)
- AWS case study on Smokeball's generative AI
This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.
Smokeball AI / Archie is probably already in your organization.
Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.
More AI tool profiles
AI assistant built into Clio Manage, the dominant solo and small-firm practice management platform, answering questions and drafting from the firm's own matter data.
Thomson Reuters' professional AI assistant, delivered inside Westlaw Precision for legal work and as CoCounsel Tax, Audit & Accounting for advisory practices.
Legal AI platform for law firms and in-house teams: research, drafting, document review, and workflow automation built on foundation models.
LexisNexis' generative AI research and drafting assistant, now sold as Lexis+ with Protégé, grounded in the Lexis primary-law and Shepard's citation database.