Agiloft vs Ironclad: how they compare in 2026
Agiloft and Ironclad are enterprise contract lifecycle platforms for legal and procurement teams, and their published terms line up closely. Both make training on customer data opt in by contract. Agiloft's Services Agreement requires explicit written consent, and Ironclad's AI Addendum ties it to a setting in the admin console. Both cap liability at a year of fees, triple the cap for security breaches, and indemnify intellectual property claims and customer data misuse after a breach. Both say their AI gives no legal advice. The differences are in the detail. Agiloft names Microsoft Azure OpenAI as its AI subprocessor and deletes data within thirty days of termination. Ironclad names Anthropic, OpenAI and Extend, allows up to 90 days for deletion, and hosts in the US or the EU. Ironclad also names four ISO certificates, and NEXT Insurance reports getting half its legal operations time back. In the product, Agiloft links each ConvoAI answer to its source passage, while Ironclad's Jurist runs named agents for drafting, review and research.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
AI Trainer, ConvoAI Document Q&A, the GenAI Prompt Lab, generative redlining and Screens are sold as AI Applications on top of Agiloft's contract lifecycle management platform. The platform's workflows, repository, approvals and integrations predate them. The Services Agreement defines AI Applications as functionality made available as part of the subscription and specified in the order. The Supplemental Terms govern them as a separate add on class. The models drive these features, and the CLM itself runs without them.
Intake, the no code Workflow Designer, approvals, routing, signature, the repository, analytics and integrations all predate generative AI and work without it. Ironclad sells that workflow layer as its foundation. The models drive central parts of the contract work on top of it. AI Playbooks, with each play tied to a clause, do the redlining. Jurist runs a named family of agents for drafting, editing, review, research, intake and redlining under a Manager Agent, with Conversational Search over the repository. The AI layer sits on an established product rather than one built on AI from the start.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
ConvoAI Document Q&A ties each answer to the passage in the contract that supports it and lets the user jump to the highlighted text, which the vendor calls white box AI. Section 9.3(c) of the Services Agreement states that AI features exhibit varying degrees of accuracy. The Supplemental Terms require the customer to check output independently. Agiloft publishes no accuracy figure, test set, benchmark or evaluation. The tool reads the customer's own contracts rather than primary law, so questions of legal authority do not arise.
Ironclad claims precise redlining, advanced AI, and proprietary legal AI models trained on legal terminology with prompts engineered for legal work. AI Playbooks tie each play to a clause. The system proposes varying degrees of revision to match preferred terms with minimal change, so its output follows a standard the customer wrote and a reviewer can check it against that standard. Ironclad publishes no accuracy figure, hallucination rate, test set or evaluation. It does not describe its retrieval method or how output links to a source a user can open. Its AI Addendum says AI output may be incorrect or inaccurate, and Ironclad does not warrant that output will be accurate, complete or error free.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Agiloft's AI features are built so that a person reviews what the models produce. Generative redlining proposes insertions and deletions against approved clause language for a negotiator to accept. Agiloft's own product lead describes it as best used where the language differs in substance, not for minor edits. AI Trainer lets a firm decide what the review model looks for, and ConvoAI answers link to the source text so a user can verify them. Section 2.3(c) of the Services Agreement makes the customer solely responsible for evaluating output. Agiloft does not publish a threshold at which any AI Application acts without a person, or a route for correcting a wrong output beyond the customer's own review.
Human in the loop governance, Ironclad states, ensures every agent works transparently and is auditable and controllable. The vendor says plainly that the customer is in charge. Customers get governed and auditable AI review frameworks they can review, override and continuously govern across teams and contract types. The controls are administrative as well. Playbook permissions let administrators configure which users and groups may view, create and edit playbooks. A Manager Agent routes tasks across the agent family, so the orchestration is visible. The vendor says the agents automate repetitive lower risk work, while strategic negotiation and nuanced risk assessment stay with the lawyer. The AI Addendum makes the customer responsible for reviewing and validating output before using it, and says the AI products are not a substitute for human oversight. Ironclad does not publish the threshold at which an agent stops or escalates.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
The vendor states a 99.6 percent implementation success rate without saying how it is measured, and describes its customers as some of the largest companies. The pages carrying these claims name no customer deployment. The site navigation also links a customer stories page and the Pacesetter awards.
According to Ironclad, Jurist gave legal operations at NEXT Insurance 50 percent of its time back. Customer quotes carry before and after numbers. In one, a first pass redline that took 30 minutes to a couple of hours becomes a solid first draft in minutes. In another, an MNDA review or custom order form clause drafting goes from an hour to a day down to minutes or seconds. Several of the quoted figures do not name the person speaking. Ironclad publishes a customer stories section, though no dated case study that states its method.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Section 2.3 of the Services Agreement and section 1 of the Supplemental Terms provide that customer data is not used to train AI Applications or AI Models without the customer's explicit prior written consent. Section 4.3 extends that consent requirement to developing or improving the services at all. The platform is offered single tenant or multitenant by order, and section 2.2 confines Agiloft's use of customer data to providing and maintaining the services. Section 14.3 deletes customer data within thirty days of termination, and section 4.2 allows export at any time. Microsoft Azure OpenAI is named as a subprocessor, and its temporary storage of input and output for abuse monitoring is disclosed. AI service providers are defined as those on the published subprocessor list. The agreement does not address attorney client privilege or work product.
Under its AI Addendum, Ironclad trains its own models on Customer Data, Input and Output only if the customer opts in through the AI Training Settings in the admin console. A later opt out stops new training from that date. Before any such use, Ironclad de identifies, anonymizes and aggregates the data, and it commits to measures so that output generated for other customers does not include that customer's data. The addendum separately lets Ironclad use Input and Output to evaluate the performance and accuracy of the service, whether or not the customer opts in. The external LLM providers, listed as AI subprocessors, are barred from training their own models on Customer Data, with zero data retention enabled where available. Section 5 of the Enterprise Services Agreement treats Customer Data as confidential information. Its SOC 2 certification covers the privacy trust category, and it holds ISO 27701 for privacy information management. The published terms do not address attorney client privilege or work product handling, and Ironclad does not document separation between customers, users or matters.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
Section 9.3(b) of the Services Agreement states that Agiloft is not an attorney or law firm or a substitute for one. It adds that Agiloft does not provide advice, explanation, opinion or recommendation about legal rights, remedies, defenses, options, selection of forms or strategies. Section 9.3(c) and the Supplemental Terms state that AI output may be inaccurate and must be verified independently. The product is sold to legal and procurement teams. Agiloft's published terms do not describe how the product supports a supervising lawyer's duties, and name no jurisdiction limit beyond export control.
Dedicated pages address legal operations and general counsel alongside procurement and IT. Ironclad describes the platform as serving business teams that touch contracts, with the AI proposing redlines and drafting negotiation ready revisions for those users, so the intended audience is broad by design. Section 2.3 of the AI Addendum states that Ironclad is not a legal advisor to the customer and that using the AI products creates no attorney client relationship. It tells the customer to consult its own counsel on legal, regulatory or compliance matters. A separate AI Disclaimer says AI output does not constitute legal or professional advice, and that a licensed professional should be consulted before anyone acts on it. Neither document addresses competence or supervision duties or sets jurisdiction limits. The human in the loop governance language describes how the system is controlled, which is a different thing from a professional responsibility position.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
The vendor markets white box AI that shows its reasoning by linking answers to source text. The Supplemental Terms bind customers to the Microsoft AI Code of Conduct, OpenAI usage policies and the AWS responsible AI policy, and section 3 warrants that insights from usage data are anonymized. Agiloft's terms and product pages set out no responsible AI framework of its own, no ISO 42001 or equivalent standard, no description of testing before release and no statement about uneven output. They name no accountable owner for AI governance. Agiloft also runs a trust portal at trustportal.agiloft.com.
The governance model rests on governed and auditable AI review frameworks and human in the loop governance, which Ironclad says make every agent transparent, auditable and controllable. Customers can review, override and continuously govern agent behavior across teams and contract types. Administrators set permissions for who may view, create and edit the playbooks that drive AI behavior. The vendor presents these as working controls rather than a principles page. A chief technology officer is publicly named as owning the AI roadmap, and Ironclad's security portal lists an AI Security and Governance document available on request. Ironclad publishes no AI management certification such as ISO 42001 and no testing results before release. Its published material names no owner accountable for model governance apart from the technology function, and says nothing about uneven output across matter types, parties or populations.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Section 14.3 of the Services Agreement deletes customer data within thirty days of termination unless law requires longer, and section 4.2 allows export at any time. A subprocessor list is published at a stated URL, and AI service providers are defined by reference to it. Section 16.2 commits to emailed notice of updates to the list. The Supplemental Terms disclose Microsoft's temporary storage of AI content for abuse monitoring. Section 5.1 commits to organizational, physical and technical precautions against access by employees and subcontractors. Agiloft also publishes a security page and a trust portal. Section 5.3 gives the customer a route for reporting incidents, and an incident notification commitment sits in the DPA.
Routine audits produce third party SOC 1 and SOC 2 Type II reports certified against security, availability, confidentiality and privacy. Ironclad also holds ISO 27001, 27701, 27017 and 27018, runs a dedicated GDPR program, and has Trusted Cloud Provider status as a Cloud Security Alliance member. Its Data Processing Addendum, version 3.10 effective 5 March 2026, says Ironclad keeps Customer Personal Data only as needed to perform the services. It destroys all copies within 90 days of termination, with a certificate of deletion on request. Section 6(b) commits to notice of a security incident within 48 hours. A subprocessor list at ironcladapp.com/subprocessors names Google Cloud Platform for hosting and Anthropic, OpenAI and Extend as AI providers. The addendum gives 30 days' email notice and an objection right before a new one is added. Ironclad's AI material says zero data retention is enforced at the external model layer, and the AI Addendum commits to enabling it where available. Its data centers run across multiple regions on public cloud providers that the vendor says are themselves certified under SOC 2, ISO 27001 and PCI DSS.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Section 10.1 of the Services Agreement, version 1.2 of 22 July 2026, gives an indemnity for intellectual property infringement. A second indemnity covers unauthorized disclosure or misuse of customer data resulting from a breach of the data use or security obligations. Section 10.2 sets out exclusions, and the mitigation remedies include a pro rata refund. Section 11 caps each party at twelve months' fees and raises the cap to three times that for breaches of the security, confidentiality and compliance sections. Gross negligence, willful misconduct, fraud and the indemnities sit outside any cap. Section 9.2 warrants material conformity, with a remedy of repair or refund. The Supplemental Terms state that AI output is provided as is and that Agiloft has no liability for any damages arising from use of output. Neither document mentions insurance.
Version 2.2 of the Enterprise Services Agreement, effective 1 July 2026, is published in Ironclad's Legal Center. Section 9.b caps each party's liability at the fees paid in the twelve months before the event giving rise to it. Section 9.d raises the cap to three times that amount for Special Claims. These are breaches of the customer data, information security or confidentiality terms that lead to unauthorized disclosure and misuse of Customer Data, and amounts due under the Data Indemnity. Gross negligence, intentional misconduct and the IP Indemnity are uncapped under section 9.c, and section 9.a excludes consequential loss. Section 8.a gives a defense and indemnity against third party intellectual property claims and against claims arising from unauthorized disclosure of Customer Data caused by Ironclad's breach. Section 6.a warrants that the services materially conform to the agreement and order form and comply with applicable law. Ironclad has 30 days to fix a nonconformity, after which the customer may terminate for a pro rata refund. Exhibit A targets 99.7 percent uptime, with service credits of 1 to 3 percent of the annual fee as the sole remedy. Section 6.b leaves the customer solely responsible for results, including AI output, and neither the agreement nor the AI Addendum indemnifies AI output. The agreement contains no insurance commitment.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The Integration Hub is an embedded integration platform powered by Workato. Agiloft states that the hub connects its platform to hundreds of other systems through connectors and recipes. Public help documentation sits on the Agiloft wiki, and the Services Agreement addresses Third Party Services. The pages describing the hub cover its depth in general terms and do not say what a firm must configure or which systems sync in which direction. Agiloft also publishes an integrations page.
Ironclad names Salesforce and Coupa specifically, and calls its Salesforce connector the number one Salesforce integration in the market. It has a dedicated integrations page and claims the deepest integrations in the market, treating integration as a primary differentiator. Teams create, manage and collaborate on contracts from inside the systems they already use rather than switching into the CLM. The integrations lean toward enterprise commercial systems rather than legal document management. Ironclad's published integrations include no legal document management connector such as iManage or NetDocuments. It does not document, per integration, what moves in which direction or what an administrator configures.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The Services Agreement defines the core platform as available on a single tenant basis, meaning a dedicated cloud environment for one customer, or on a multitenant basis. The order selects between them. An EU Data Act addendum exists for EU customers. The published terms state no region list, hosting provider or processing location for the AI providers. Agiloft also publishes a security page and a trust portal.
To meet data residency requirements, Ironclad says it uses multiple data center regions from its cloud providers. Its subprocessor list shows two CLM regions, the United States and an EU datacenter, both hosted on Google Cloud Platform, with Anthropic and OpenAI processing AI requests in the EU for EU hosted customers. Clickwrap runs on Amazon Web Services in the United States. Ironclad does not state a tenancy model or say what changes between plans.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Section 5.2 of the Services Agreement states that Agiloft has completed audits by an independent auditor of the design and effectiveness of its security controls. Customers may obtain the reports through the trust portal at trustportal.agiloft.com, where they are treated as confidential information. The agreement does not name the audit standard, the auditor or the coverage period, or say whether a prospect can obtain a report without asking.
SOC 1 and SOC 2 Type II reports come from routine third party audits, and Ironclad names the trust categories certified as security, availability, confidentiality and privacy. Its security portal, run on SafeBase, lists SOC 1, SOC 2, ISO/IEC 27001 with its statement of applicability, 27017, 27018, 27701, CSA STAR, HIPAA, GDPR and CCPA. Reports, a penetration test report, a CAIQ and cyber insurance documentation are available there on request. Ironclad also holds Trusted Cloud Provider status from the Cloud Security Alliance, and says its underlying cloud providers are themselves SOC 2, ISO 27001 and PCI DSS certified. The portal shows no auditing firm, audit coverage period or report date.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The Supplemental Terms name Microsoft Azure OpenAI Service as the provider behind certain AI Applications. They disclose that Microsoft temporarily stores input and output for abuse monitoring, with human review of flagged content. The incorporated acceptable use policies are Microsoft's, OpenAI's and AWS's, which identifies the set of providers. AI service providers are defined as those on the published subprocessor list, and section 16.2 commits to emailed notice of changes to that list. The terms name no model and state no inference location.
Two layers of models sit behind Ironclad's AI. One is proprietary legal AI models that Ironclad built, with prompts engineered for legal work. The other is external LLM providers, which its subprocessor list names as Anthropic and OpenAI, alongside Extend for AI processing and Google Cloud Platform for cloud and AI infrastructure. They run in the United States and, for EU hosted customers, in the EU. The Data Processing Addendum gives 30 days' email notice and an objection right before a new subprocessor is added. The AI Addendum bars AI subprocessors from training on Customer Data and commits to zero data retention with them where available. Ironclad does not say which model or version serves which feature.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The Services Agreement prices by order, with use limits by type and number of users and prorated increases during the term. Additional services are priced separately, payment terms are thirty days, and the customer chooses a single tenant or multitenant platform. The agreement states no price figure. Agiloft also links a pricing page from its site navigation.
There is no pricing page on Ironclad's site, and it publishes no rate, unit of charge or tier structure. Every commercial path on the site ends in a demo request, and there is no free trial or self serve entry point. Its AI usage policy, version 1.1, bills overages on AI Credits at Ironclad's then current list price without publishing that price. Third party coverage describes implementation cost as depending on the scope of the CLM deployment rather than on a published rate.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Solution pages address legal and procurement functions and seven industries, and the product is sold to enterprises. The platform is offered single tenant or multitenant, with an EU addendum. The Services Agreement bars use for high risk activities. Agiloft's pages name no contract type or practice area as unsupported and describe no law firm use.
Four buyer personas have their own published positioning, namely legal operations, general counsel, procurement and IT. Ironclad also addresses business teams beyond legal that handle contracts. The stated target is enterprise and global business teams. At least one industry, manufacturing, has dedicated positioning around leakage and contract performance. The practice scope is contracting end to end, from intake to after signature, with no claim to litigation or research capability. Ironclad does not say which organization sizes or contract types the platform is not built for, and publishes no full list of industries or practice areas.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Training on customer data happens only if the customer affirmatively enables it, and the switch is written consent under the agreement. Section 2.3 of the Services Agreement and section 1 of the Supplemental Terms provide that customer data is not used to train AI Applications or AI Models without the customer's explicit prior written consent. Section 4.3 provides that Agiloft does not use customer data to develop or improve the services without the same consent. Usage data, defined to exclude the contents of customer data, may be used to improve the AI Applications.
Section 1.1 of the AI Addendum, version 2.1 effective 20 April 2026, lets the customer enable AI Training Settings in the admin console. Only then may Ironclad use Customer Data, Input and Output to train and improve its own AI models and products. Section 1.2 requires that data to be de identified, anonymized and aggregated first, and output generated for other customers must not include it. Section 1.3 lets the customer opt out later, which stops new training but does not unwind training already under way.
Section 2.1 separately lets Ironclad use Input and Output to evaluate the performance and accuracy of the services, whether or not the customer opts in. Section 3.1 bars AI subprocessors, the external LLM providers, from training their own models on Customer Data. The vendor makes the case for opting in openly, and says the customer stays in control and the data stays confidential.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Section 14.3 of the Services Agreement deletes all customer data, which includes input and output, within thirty days of termination unless law requires longer. Section 4.2 allows export at any time during the term. The Supplemental Terms disclose that Microsoft temporarily stores AI input and output for debugging and abuse monitoring. The terms set no shorter or configurable window for prompts and outputs during the term, and the customer cannot change the published period.
Section 8(b) of the Data Processing Addendum, version 3.10 effective 5 March 2026, requires Ironclad to destroy all copies of Customer Personal Data, including archival copies, within 90 days of the agreement ending. On request it returns the data within 30 days and issues a certificate of deletion within 30 days. Section 7.c of the Enterprise Services Agreement gives a 28 day courtesy period after termination for exporting the repository.
During the term the addendum says Ironclad keeps the data only as needed to perform the services, and the AI Addendum sets no separate period for prompts and outputs. Ironclad says it enforces zero data retention with its external LLM providers, and the AI Addendum commits to enabling it where available. The product is a system of record built to hold every executed agreement for as long as the customer keeps it.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The Services Agreement sets out separation at the tenant level. It defines single tenant as a dedicated cloud environment for one customer and multitenant as an environment that may be shared, with the choice made in the order. Section 2.2 confines Agiloft's use of customer data to providing the services. The agreement does not describe matter level or department level walls within a customer's instance, or how the AI Applications respect user permissions. Agiloft also publishes a security page.
The product keeps its own documented permission model rather than inheriting one from a document management system. Support documentation states that administrators can configure Ironclad users and groups to permit or restrict which users may view, create and edit AI Playbooks. The standards that drive AI behavior are therefore themselves access controlled. The workflow layer routes and assigns contracts across named reviewers.
Ironclad's published material does not describe segregation of the contract repository itself between users or matters, or any ethical wall concept. It names no legal document management integration whose permissions retrieval could inherit at query time. The buyer is an in house or business team rather than a firm carrying conflicts obligations, so the question applies differently than it would for a product sold to law firms.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Section 7.3 of the Services Agreement permits disclosure of confidential information, which includes customer data, to the extent required by law. Where legally permitted, the receiving party must give the disclosing party prompt notice of the compelled disclosure and reasonable assistance should it wish to contest it. Section 5.1 refers to the same clause for compelled access to customer data. Agiloft publishes no transparency report.
Section 3(i) of the Data Processing Addendum commits Ironclad to notify the customer promptly of any government or law enforcement request to access or seize Customer Personal Data, unless the law or a binding request prohibits it. Ironclad must also help the customer contest the request. Section 5.c of the Enterprise Services Agreement lets either party disclose confidential information, which includes Customer Data, under a court or government order.
Where the law permits, it must first give reasonable notice so the other party can contest the order. Ironclad publishes no transparency report.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The product is not built on a legal corpus. ConvoAI answers questions about the customer's own contracts with links to the source passage, AI Trainer learns from the customer's own documents, and generative redlining works from the customer's approved clause language. Agiloft's news releases and terms name no primary law source, license or update cadence.
No primary law corpus sits behind the product. Retrieval runs against the customer's own contract repository and AI Playbooks. Ironclad describes its proprietary models as trained on legal terminology and contract management architecture, with prompts engineered for legal work. Where customers opt in, the models also train on anonymized and aggregated customer contracting data. That contributed data is the closest thing to a vendor corpus, and Ironclad states its source, which is customers contributing under consent. The site, the Ironclad AI page and the article library give no scale figure, license basis or update cadence for it.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
The product does not retrieve or cite primary law. Its output is contract answers, redlines and extracted data, and its published materials do not address checking authority for subsequent history.
A contract lifecycle platform grounded in the customer's own playbooks and repository, Ironclad has no case law research surface, so a citator falls outside its design. Its site, product pages and support documentation do not address whether authority carries a treatment signal or whether subsequent history is reviewed. They name no commercial citator license.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
ConvoAI Document Q&A links each answer to the supporting passage so the user can verify it in the source, which the vendor markets as white box AI. The product documents how a user checks an answer rather than what the model does when it cannot answer. Neither the February 2025 release nor the terms state an abstention path or confidence signal for questions with no supporting passage. The terms require independent checking of every output.
The Review Agent is documented as identifying missing clauses and compliance gaps. That flags what is absent from a contract, which is different from the system declining to answer. The site, the Ironclad AI and Jurist pages, the agent launch material and the support documentation do not describe what the product does when it cannot ground an answer. They show no explicit no answer path and no confidence signal for the user.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
The AI Hallucination Cases database maintained by Damien Charlotin tracks decisions worldwide where a court addressed hallucinated AI content, and records the tool implicated where known. It records no court order, opinion or disciplinary record naming Agiloft, ConvoAI or Astra. Published reports of court findings on AI errors do not name them either. Agiloft is a contract platform that cites no legal authority, so its output does not ordinarily reach a court filing.
The AI Hallucination Cases database, maintained by Damien Charlotin, tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. It records no court order, opinion or disciplinary record naming Ironclad. Published 2026 sanctions summaries and secondary sanctions trackers do not name it either. Ironclad is a contract lifecycle product with no case law research surface, so its output is very unlikely to reach a court filing as cited authority.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Section 9.3(b) of the Services Agreement addresses the line between tooling and legal advice, and the Supplemental Terms incorporate the AI providers' acceptable use policies. Neither the terms nor Agiloft's news releases name an ethics opinion, bar rule or professional responsibility framework, or any bar or regulator guidance on lawyers' use of AI.
Ironclad publishes substantial material on AI governance, auditability and human in the loop control, which covers how its own system is controlled. Its AI Addendum and AI Disclaimer say AI output is not legal advice and that a licensed professional should be consulted. Neither those documents nor its site, article library, persona pages and resources sections engage with any named ethics opinion or bar guidance, including ABA Formal Opinion 512 and state bar guidance. None of it addresses the professional responsibility obligations its legal buyers are bound by.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The product is sold to legal and procurement teams inside companies, which bill no client, so it sits outside a lawyer to client fee relationship. Agiloft frames its savings in cycle time and negotiation loops rather than fees. Its materials do not address how AI assisted work is recorded or disclosed on a bill, and no law firm is a named buyer segment.
Ironclad's savings claims come with figures. A named customer, NEXT Insurance, recovered 50 percent of legal operations time. First pass redlines drop from up to a couple of hours to minutes, and MNDA review drops from up to a day to minutes or seconds. The vendor frames this as scaling review without adding headcount. Its site, product pages, article library and support documentation offer no per matter record of work done with AI for fee purposes, and no guidance on billing, fees or client disclosure.
The buyer is an in house or business team that does not bill a client by the hour, so fee disclosure applies differently here.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
Agiloft publishes a current subprocessor list, and the Services Agreement defines AI service providers as the third party AI providers listed on it at a stated URL. The agreement commits to emailed notice of updates. The Supplemental Terms name Microsoft Azure OpenAI Service, disclose its content handling, and incorporate the Microsoft, OpenAI and AWS policies. The DPA is published. Together the terms give a firm material it could show a client.
Ironclad's subprocessor list at ironcladapp.com/subprocessors names Anthropic, OpenAI and Extend as AI providers and Google Cloud Platform for cloud and AI infrastructure, by region, for the United States and the EU datacenter. The Data Processing Addendum and AI Addendum are published in its Legal Center and can be read without an agreement in place. The addendum gives 30 days' email notice and an objection right before a new subprocessor is added.
Certification material covers SOC 1 and SOC 2 Type II with the trust categories named, ISO 27001, 27701, 27017 and 27018, a GDPR program and Cloud Security Alliance Trusted Cloud Provider status. Ironclad publishes no consent or notification pack written for a client's outside counsel guidelines.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
ConvoAI's source linked answers let a user verify each answer inside the product. Agiloft's news releases and terms do not describe exporting a record of the model used, sources and human verification for a court, or certifying AI assisted work. The product produces no work product meant for court.
The workflow layer records routing, assignment and approvals for each contract. Ironclad publishes governed and auditable AI review frameworks with human review. It says customers get transparent, auditable AI behavior they can review, override and continuously govern across teams and contract types. Ironclad describes no export per document covering the model used, sources retrieved and human verification. Its subprocessor list names the AI providers, Anthropic, OpenAI and Extend, but nothing shows which model produced a given output.
Ironclad is a contracting platform rather than a litigation product, so a court order on AI disclosure is unlikely to reach its output.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Primary Law Corpus Provenance
- Good Law Verification
- Bar Guidance Alignment
Which one fits
Choose Agiloft if
- You want the tightest limit on data use. Agiloft's Services Agreement bars training on customer data, or using it to improve the service at all, without explicit prior written consent. It also states that Agiloft is not a law firm and gives no legal advice.
- You want data gone soon after you leave. Agiloft's Services Agreement deletes customer data within thirty days of termination. It caps each party at a year of fees, triples the cap for security, confidentiality and compliance breaches, and indemnifies misuse of customer data after a breach.
- You want to train review models yourself. AI Trainer lets a team teach the review model what to find using its own documents, without code. ConvoAI links each answer to the highlighted passage it came from.
Choose Ironclad if
- Your data must stay in the EU. Ironclad's subprocessor list shows an EU datacenter on Google Cloud, with Anthropic and OpenAI processing AI requests in the EU for those customers. It names SOC 1 and SOC 2 Type II reports with their trust categories.
- You want a named customer result. Ironclad publishes NEXT Insurance as getting 50 percent of its legal operations time back with Jurist. Attributed before and after figures cover redlining and NDA review.
- Your contracts begin in Salesforce or Coupa. Ironclad calls its Salesforce integration the number one in the market and names Coupa alongside it, so teams work contracts from inside those systems. In September 2026 it added a plugin for searching the repository from ChatGPT.
In summary
Agiloft
Agiloft is an enterprise contract lifecycle platform for legal and procurement teams in industries from financial services and healthcare to manufacturing and energy. Its AI tools include AI Trainer, which trains review models on a customer's own documents without code, and ConvoAI Document Q&A, which links answers to highlighted source text. Generative redlining works from approved clause language. According to the AI Legal Index, Agiloft's commitments sit in its published Services Agreement and Supplemental Terms. Customer data trains no model without explicit written consent, and liability caps are stated. Microsoft Azure OpenAI is named as a subprocessor. The Services Agreement prices per order by type and number of users, and Agiloft links a pricing page from its site.
Ironclad
Ironclad is an enterprise contract lifecycle platform for in house legal, procurement, sales and IT teams. Agreements move from intake through no code workflows, approvals and signature into a searchable repository. AI Playbooks redline against clauses the customer defines, and Jurist directs named agents for drafting, review, research and intake. According to the AI Legal Index, Ironclad publishes its Enterprise Services Agreement, Data Processing Addendum and AI Addendum. It names SOC 1 and SOC 2 Type II reports with their trust categories, and ISO 27001, 27701, 27017 and 27018. Its subprocessor list names Anthropic, OpenAI and Extend as AI providers. It publishes no price.
Questions buyers ask
Agiloft vs Ironclad: which CLM is better for enterprise legal teams?
Agiloft puts tight data limits in its contract, links answers to source passages and lets teams train their own review models. Ironclad leads with named certifications, a named customer result, EU hosting and Salesforce and Coupa integration. Both publish their terms and make training on customer data opt in. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
Do Agiloft and Ironclad train AI on customer contracts?
Only with consent. Agiloft's Services Agreement requires explicit prior written consent before customer data trains any model or improves the service. Ironclad's AI Addendum lets it train its own models only for customers who enable AI Training Settings, on anonymized and aggregated data. It bars its AI subprocessors from training on customer data. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
Which AI models do Agiloft and Ironclad use?
Agiloft's Supplemental Terms name Microsoft Azure OpenAI Service, incorporate the Microsoft, OpenAI and AWS usage policies, and disclose that Microsoft briefly stores input and output for abuse monitoring. Ironclad's subprocessor list names Anthropic, OpenAI and Extend alongside its own legal models, and it commits to zero data retention with them where available. Neither names a model or version. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
Do Agiloft and Ironclad publish their customer contracts?
Both do. Agiloft's Services Agreement, version 1.2 of 22 July 2026, covers liability caps, indemnities, warranties, deletion within thirty days of termination and notice of compelled disclosure. Ironclad's Enterprise Services Agreement, version 2.2 of 1 July 2026, sits in a public Legal Center with its Data Processing Addendum and AI Addendum. It covers the same ground, with deletion within 90 days and 99.7 percent target uptime. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
What do Agiloft and Ironclad both leave unpublished?
Neither publishes an accuracy or hallucination measure, or anything on attorney client privilege in its terms or product pages. Neither engages with bar guidance such as ABA Formal Opinion 512, though both serve procurement teams as well as lawyers. Neither states a price in its terms, and Ironclad has no pricing page, while Agiloft links one from its site. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything on it comes from public material on the dates shown. How the index grades.
Both vendors put training behind the customer's choice, with a difference in reach. Agiloft's consent requirement covers any use of customer data to train models or improve the service. Ironclad's AI Addendum still lets it use prompts and outputs to evaluate the accuracy of its service without an opt in, and an opt out does not unwind training already done. Agiloft's Supplemental Terms supply AI output as is, with no liability for its use, and Ironclad's terms leave the customer responsible for AI output. Agiloft links customer stories and a trust portal from its site. Neither vendor reviewed this page.