Chamelio vs Leah: how they compare in 2026

Chamelio profileLeah profile
Last verifiedSeptember 3, 2026

These two are not usually evaluated against each other. Chamelio is a recent legal intelligence platform sold exclusively to in house departments, and Leah, formerly ContractPodAi, is an enterprise agentic platform sold to Fortune 500 legal, procurement and finance functions and delivered in part through PwC, Epiq and Pinsent Masons. What putting them on the same grid shows is that size does not predict disclosure: Leah sits in the top two bands on eleven of fifteen axes and Chamelio on ten. Leah publishes the fuller control and recourse position, with a governance loop in which the customer defines which agents may act, on which data and within which thresholds, and a tiered liability cap reaching three times twelve months of fees where the security clause or the data processing addendum is breached. Chamelio publishes the deeper integration documentation and the firmer training term, a clause headed No Third Party LLM Model Training recording that it has opted out of every available training option. Neither publishes a price or an accuracy figure.

At a glance

Category
ChamelioContract Review & Drafting
LeahContract Review & Drafting
Founded
ChamelioNot published
LeahNot published
Headquarters
ChamelioNot published
LeahLondon, United Kingdom
Last verified
ChamelioSep 2, 2026
LeahAug 31, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Chamelio
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models are the engine of the capabilities the buyer is sold on: AI redlining in Word, a playbook generator that derives standards from a team's own precedent, automatic metadata extraction, agentic workflows and an AI agent answering from the department's documents. Underneath them sits a product that would still function without any of it, which the vendor effectively concedes by pitching itself as a replacement for contract lifecycle management systems and shipping a CLM Migrator. Strip the models out and a contract repository, a Vault, custom metadata columns, reminders, intake forms, task and matter tracking, approval routing, DocuSign orchestration and Insights dashboards remain, and that is a CLM. That combination is the B band rather than the A band, where removing the models would leave nothing to sell. Verified 2 September 2026.

Leah
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models are the engine of the capability being sold, layered on a contract lifecycle platform that would function without them. The vendor argues the opposite, stating that other vendors bolted AI onto systems built for manual workflows while Leah was designed from scratch with orchestration as the foundation. The published record does not support that reading. ContractPod Technologies has sold contract lifecycle management since 2012; Leah launched in March 2023 as an AI services hub within that platform, went standalone in May 2023, and Leah Intelligence followed in October 2024. Strip out the agents and what remains is a working CLM with guided intake, approval routing, DocuSign and Adobe Sign execution, and a contract repository, which is a product with its own market and its own Gartner category placement. The orchestration layer is real and is genuinely model-driven, which is why this is a B rather than lower.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Chamelio
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is asserted and never measured. The documentation states that models from leading providers are continuously evaluated and that top performers are automatically deployed for specific tasks, under a heading claiming this will guarantee the most accurate and reliable results, but no benchmark, test set, figure or evaluation is published anywhere on the site or in the documentation. The product page states that every AI answer links back to the source document, which is real grounding for a product whose corpus is the customer's own material, and it is what keeps this off D. It falls short of B because no retrieval method is described and there is no accuracy figure an outsider could test. The published percentages, 89 per cent less review time on the home page and a customer's 90 per cent, measure time saved rather than correctness. Verified 2 September 2026.

Leah
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is asserted repeatedly, and at one point claimed to be benchmarked, without a single figure attached. The AI governance page states that every action is measured against benchmarks for accuracy, bias and outcome, and the product material describes a legal helpdesk that answers contract questions with sources attached, which is a grounding claim a reader could in principle check inside the product. Searched the home page and the AI governance page in full on 31 Aug 2026 and located no accuracy figure, no error or hallucination rate, no description of any benchmark or test set, and no published evaluation. The benchmark claim is the sharpest version of the problem this axis exists to catch: a vendor asserting measurement without publishing the measurement. Nothing addresses what the system does when the customer's own contract set does not support a position.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Chamelio
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

The review surfaces are documented in unusual detail because the API reference exposes the workflow engine. Tasks move through defined steps; an approval step carries eligible approvers and pending variables that can be retrieved; approval or rejection is submitted per task; a running task can be cancelled; and an activity log records comments, approvals and other actions. Redlining lands in Word as suggestions a lawyer works with rather than as applied changes. That is a real route back to human judgement, published rather than asserted. What is absent is the threshold. The vendor describes agentic workflows executing complex multi-step tasks and a customer describes the system handling a first pass and escalating only what needs legal review, but nothing published states which steps run unattended, what triggers an escalation, or what happens after the system is wrong. That missing limb is what the B band names. Verified 2 September 2026.

Leah
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a lawyer checks it are all published: modes, thresholds, review surfaces, and the route a matter takes back to human judgement.

The control structure is published in full and is the thing the vendor sells on. A dedicated AI governance page sets out a three-stage loop. Policy in: the customer defines which agents may act, on which data, within which thresholds, and where escalation is required, with those policies held as configuration rather than code. Execution governed: every agent action runs through those policies in real time, with approvals, escalations and rejections applied automatically and the orchestrator enforcing guardrails at each step. Audit out: every decision is logged with the rationale, what the agent did, why, under which policy, on what data and to what outcome, in records described as tamper-resistant and immutable. That covers the thresholds, the review surfaces and the route back to human judgement, and the home page states the position plainly, that the workflow runs itself while the judgment stays human. What is still missing is what happens after an output is found to be wrong, and default modes are not described because the guardrails are customer-configured rather than shipped.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Chamelio
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Five customers are named with the individual and the title attached: Noa Weyl, General Counsel at Bizzabo; Noa Rosenberg Segalovitz, General Counsel at Lightricks; Aviad Levin, General Counsel at Socure; Maayan Yaakobovich, Senior Legal Counsel at Radware; and Duncan McQueen, Assistant General Counsel at Integrity. Two carry figures attached to the named customer, a reduction in legal review time of 90 per cent at Integrity and a fall in NDA turnaround from 24 hours to under an hour at Lightricks. What holds this below A is that nothing is dated and no measurement basis is given for any figure. A retrieval note belongs here: the home page carries four headline statistics whose values are rendered by script and extracted as zero, so those four numbers were not read and are not relied on. Verified 2 September 2026.

Leah
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Substantial evidence on both halves of the question, never joined together. Named individuals speak on the record with roles and employers: Noelle Perkins, EVP and Chief Legal Officer at Cushman and Wakefield; Lidia Kamleh, Chief Legal Officer at Dubai Future Foundation; Frances Bain-Cumberbatch, Chief Legal and External Affairs Officer at Ansa McAL; and Zillia Knight, Senior Legal Officer at Terumo Europe. Every one of those quotes is qualitative. Separately, three figures are published with the customer anonymised: a 91 per cent cut in contract review time at a major US logistics company, more than 18 million dollars of revenue protected at a global manufacturer, and more than 2 million dollars of tracked savings at a US retail REIT. Roughly 54 enterprise logos appear, including Philips, MUFG, Sandoz, Pernod Ricard, Alaska Airlines and Wood PLC. A buyer should read that logo strip carefully: PwC and KPMG appear in it, and PwC entered a commercial alliance in March 2024, while Epiq resells Leah inside its Service Cloud, Integreon is quoted as an early adopter reselling onward, and Pinsent Masons adopted it for managed legal services in July 2025. Channel partners and customers are presented together without distinction, and a Chief Product Officer of Execo, another services partner, appears in the testimonial carousel.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Chamelio
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Substantive and in more than one place. The Terms of Service carry an express clause headed No Third Party LLM Model Training, stating that Customer Data sent to third party large language models is not used to train them and that Chamelio has opted out of every available training option for each one; the data licence is confined to providing the service; and the documentation extends the commitment to Chamelio's own models. Segregation is addressed at the level this buyer segment requires, which for an in-house department is tenant separation rather than matter walls: the documentation states that each customer's data is processed in isolated environments and describes role-based access control, user groups, legal entities and SCIM provisioning. Two things keep it off A. Nothing published addresses attorney client privilege or work product treatment directly, which the A band requires as its own limb. Retention is stated only as data being kept as long as necessary for service delivery, with no period. Verified 2 September 2026.

Leah
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Specific published commitments on the questions that matter most, with two real gaps. The vendor states that customer contract data is never used to train models, and the AI governance page frames data leaking into models the customer does not own as a failure it engineered out, stating that zero data retention is the only acceptable answer and that it enforces zero retention with OpenAI and Anthropic so that data is processed but never stored by the providers. Encryption is AES-256 at rest and TLS in transit with keys held in Azure Key Vault, rotated and reachable only through controlled service accounts. Role-based access control is stated to be enforced at every layer, and single-tenant deployment is offered for customers with strict isolation requirements. Two gaps. Privilege and work product are not addressed anywhere on the surfaces read on 31 Aug 2026, on a platform sold into Fortune 500 legal departments. And none of it could be checked against an agreement: the legal and privacy pages are linked from every footer but neither could be retrieved, so every commitment recorded here sits on a marketing or governance surface rather than in a contract.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Chamelio
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

The only located position on the advice line is a liability clause: the Terms of Service state that Chamelio has no responsibility or liability for the accuracy of Customer Data or for the customer's usage of, or reliance on, Outputs. That is a disclaimer of reliance rather than a statement of what the product is and is not, and no page states that output is not legal advice. Meanwhile the marketing describes the product in advice terms. The home page carries a customer line, published by the vendor, describing the platform as providing strategic insight like a seasoned attorney, and the feature list includes risk and decision support, liability ranking and legal research. A boilerplate disclaimer in the terms alongside marketing that describes the product in advice terms is the C band exactly. The audience is not ambiguous, which is the other route into C: the product is sold exclusively to in-house legal teams, and there is no consumer facing surface, so that limb of the A band does not apply here. No bar or ethics guidance is engaged. Verified 2 September 2026.

Leah
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Nothing published on the advice line was located. Section 8 places this evidence in footers, disclaimers, terms and any ethics page; three of those four were checked on 31 Aug 2026, across the complete footers of the home page and the AI governance page and the full navigation and footer sitemap covering platform, solutions, resources and company. No disclaimer of any kind appears, there is no ethics or professional responsibility page, no bar or ethics guidance is named including ABA Formal Opinion 512, and no statement was found on the line between a tool and legal advice. The exposure is not trivial: the platform is sold to run legal work end to end across legal, procurement and finance teams, and its own framing is that agents execute multi-step commercial work without routing every decision through a person. The fourth home, the terms page at the site's legal link, could not be retrieved, so this grade is rebuttable on that document alone.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Chamelio
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

There is no responsible AI page, no governance framework, no named owner and no certification such as ISO 42001. What exists sits inside the security documentation under AI Model Security: continuous benchmarking of models from leading providers, automatic deployment of the best performer for a given task, controlled deployment and rollback through model versioning, output filtering and prompt injection safeguards. Those are mechanisms rather than principles, which is why this is not a bare principles page, but they are security and performance controls and the axis is explicit that security controls are a different subject. Nothing at all is published about uneven output across matter types, counterparties or populations, and no testing result of any kind is disclosed. Checked the home page, the security page, the full documentation index and the recoverable portions of the Terms of Service on 2 September 2026. Verified 2 September 2026.

Leah
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

The most substantial governance framework published by any vendor in this pull, short of a named owner and any disclosed result. A dedicated AI governance page names six failure modes the vendor says it engineered out, including black-box decisions that cannot be defended to a regulator or board, and compliance frameworks retrofitted after the fact. Against those it sets three pillars and the policy-execution-audit loop, with per-action logging of rationale and governing policy described as tamper-resistant and immutable, which is a mechanism a buyer could audit rather than a principle. It also makes a claim no other vendor in either pull has made: that every action is measured against benchmarks for accuracy, bias and outcome, with the page stating that accountability is structural rather than aspirational. That is why this is not lower. It is not higher because none of the substance behind the claim is published. No individual or role inside the vendor is named as accountable for model behaviour, no pre-release testing regime is described, no benchmark method or cadence is given, and no result of any bias measurement has been disclosed.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Chamelio
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Most of the ground is covered with specifics. Encryption is stated as TLS 1.3 in transit and AES-256 at rest with key rotation. Access control is detailed: least privilege, regular user access reviews, restricted production access, multi-factor authentication for administrative access, role-based access control, session timeouts, and single sign-on with SCIM provisioning documented per identity provider. Incident practice is a published six stage process from detection through containment and forensic investigation to post-incident review, with a commitment to notify customers of incidents that affect them and a security contact address. Deletion is real and observable in the product, since the API documents document deletion and fires a webhook when a document is permanently deleted. The gap is the one the B band names: no subprocessor list is published. The documentation refers to AI sub-processors and to vendor security evaluations without naming a single one, and retention is stated only as being as long as necessary. Verified 2 September 2026.

Leah
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Substantive published controls with two specific absences. The AI governance page publishes real operational detail: TLS for data in transit and AES-256 at rest, encryption keys managed through Azure Key Vault, rotated regularly and accessible only through strictly controlled service accounts, multi-factor authentication, secure API gateways, network segmentation, real-time monitoring, and a fully documented incident response plan. Audit logs are described as comprehensive, tamper-resistant and immutable. Assurance is external rather than self-asserted: the vendor states it is audited annually by an independent Managed Security Service Provider and penetration tested regularly. What is absent, checked 31 Aug 2026: no subprocessor list of any kind, with OpenAI and Anthropic named as model providers but no other processor identified, and no breach notification practice or timeline anywhere despite the incident response plan being referenced twice. No retention period for customer content was located either, which is recorded separately in the signals.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Chamelio
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

A real published position, read in part. The Terms of Service allocate loss expressly: Chamelio has no responsibility or liability for the accuracy of Customer Data or for the customer's usage of, or reliance on, Outputs, which is a direct disclaimer of the exposure this product creates. Article 10 is a limitation of liability that the parties agree forms an essential basis of the bargain, applies to the maximum extent permissible, and extends to affiliates, licensors and suppliers. Separate articles cover Indemnification at 9 and Warranty Disclaimers at 8.3, both named and both stated to survive termination. What could not be established is their content: the legal hub renders client side and returns no body, and the search index surfaced Articles 1 to 12 in fragments without reaching the indemnity scope, any cap figure or any warranty. This is graded B rather than C because C requires that liability be addressed only through a limitation clause, and that is false of an agreement carrying distinct indemnity and warranty articles. The unread scope is a limit on this reading, not a finding against the vendor. Verified 2 September 2026.

Leah
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

Row completed 2 September 2026 under R26, from the ContractPodAi Master Terms and Annexes v3.0c dated 29 August 2024, read in full. The whole allocation of loss is published with figures and it is tiered, which almost nothing else in this corpus manages. Section 16.5 sets a General Cap of amounts paid or payable in the twelve months before the first incident, then an Enhanced Cap of three times that figure which applies specifically to the provider's breach of the security clause or either party's breach of the data processing addendum. Uncapped Claims are enumerated: indemnification obligations, intellectual property infringement or misappropriation, breach of confidentiality, and anything that cannot be limited by law. Section 17.1 gives the customer a real indemnity, with the provider defending third-party claims that the service infringes intellectual property rights, remedies ordered at 17.5 as procure, replace or modify, or terminate and refund. Section 8.2 warrants that the service will perform materially as documented and that functionality will not materially decrease during a term, with a concrete remedy at 8.3 of correction within a thirty day fix period failing which the customer terminates and is refunded. Annex A adds published uptime tiers of 99.00, 99.5 and 99.9 per cent by support plan, with termination and refund if missed in three consecutive or four of six months. Three limits belong on the record and none is hidden. The uncapped confidentiality limb expressly excludes breaches related to Customer Data, so the confidentiality failure that would matter most to a contract platform is capped rather than uncapped, mitigated only by the Enhanced Cap where the security clause is also breached. There is no AI-specific or output indemnity: nothing addresses inaccurate output, hallucination, or training data provenance, and the indemnity at 17.7 is the exclusive remedy for intellectual property claims. And section 9.2 requires the customer not to submit Sensitive Data, defined to include GDPR Article 9 special categories, government identifiers and financial account numbers, with the provider disclaiming liability for such use, which is a meaningful allocation for a platform used on live matters. Trials and betas carry no warranty, indemnity, service level or support and are capped at one thousand US dollars under section 21. Version note: v3.0c is the version published and readable; the current v4.0 dated 4 January 2026 sits behind a viewer neither the operator nor this reader could render, and the vendor's own change note states the only modification is the update to the new trading name.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Chamelio
AA on Practice Systems Integration DepthDocumented, verifiable integrations into the systems legal work already lives in, with the depth described: what syncs, in which direction, and what a firm must configure.

A real documentation property carries a setup guide per integration, and each states what moves and in which direction. Salesforce: install the Chamelio AI package, generate contracts and sync legal data from Opportunities. DocuSign: signed contracts are captured automatically into the repository. Google Drive and SharePoint: documents import through a native file picker. Slack: legal knowledge, answers and workflow triggers surface in channels. Word: an add-in with its own installation guide delivers review and redlining in the drafting environment. Underneath sits a documented REST API with an OpenAPI specification, covering document upload, search, contract data retrieval, workflow initiation, task approval, signature envelopes and file download, plus thirteen webhook events for document and workflow lifecycle changes. Configuration is documented rather than gestured at, including single sign-on through Entra ID by OIDC and SAML, Okta by OIDC, and SCIM provisioning from both. iManage and NetDocuments are absent, but this product is sold exclusively to in-house departments rather than firms, so those are not the systems this buyer's work lives in. Verified 2 September 2026.

Leah
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Real integrations into enterprise systems, named and functionally described, short of implementer documentation. The named set is the right one for this buyer and unusually broad for the category: ERP platforms including SAP and NetSuite, source-to-pay and procurement systems including Coupa, financial systems, identity providers including Okta, and existing contract lifecycle tools, alongside DocuSign and Adobe Sign built in for execution and a Microsoft Word add-in for redlining. The vendor describes the integration model rather than just listing logos, stating that integration is connect-and-execute, that Leah does not replicate data passively, and that it executes work across connected systems through the orchestration layer, which is a meaningful architectural claim. What was not reached on 31 Aug 2026 is depth: the dedicated integrations page was not opened, and nothing read states what syncs in which direction or what a customer must configure. No document management integration such as iManage or NetDocuments appears, consistent with an in-house rather than law firm product.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Chamelio
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Cloud delivery is clear and the specifics are not. The documentation states hosting on AWS and Google Cloud Platform, describes a multi-cloud strategy for redundancy, and names virtual private cloud isolation, web application firewalls, DDoS protection and network segmentation. On the two things this axis asks for, it stops at the level of an offer. Residency appears as options for specific geographic data storage, with cross-border controls and jurisdiction compliance mentioned, but no region is named anywhere and there is no way for a buyer to learn which regions are available without a sales conversation. No tenancy model is stated: the product is not described as multi-tenant, single-tenant or private anywhere on the site or in the documentation. The isolated processing environment the documentation describes is credited on the confidentiality axis, where it answers the segregation question, and is not counted twice here. Checked the home page, security page and full documentation index on 2 September 2026. Verified 2 September 2026.

Leah
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed.

The tenancy model is addressed directly and the regions are not. Single-tenant deployment is stated to be available for customers with strict data isolation requirements, and beyond that the vendor offers what it calls a dedicated zero-trust private environment within Azure OpenAI Studio, described as ensuring complete data isolation from all other customers, which tells a buyer both that the default is shared and that a separated option exists. The infrastructure is identified as Azure, with encryption keys held in Azure Key Vault. Two things hold this at B, checked 31 Aug 2026. Data residency is addressed only in the abstract, with the vendor saying it supports the residency and regulatory requirements typical of large multinational enterprises and naming no region, no jurisdiction and no customer-selectable option. And nothing states where processing happens as distinct from where data is stored, which matters on a platform that routes work dynamically across multiple model providers.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Chamelio
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

SOC 2 Type 2 is claimed on both the security page and in the documentation, and the documentation goes further than most by enumerating the scope as all five trust services criteria: security, availability, processing integrity, confidentiality and privacy. Third-party penetration testing by independent security firms is stated. What the A band asks for is missing on every count: no auditor is named, no coverage period or report date is published, no penetration test summary is offered, and no route to obtain the report is described. A trust centre exists at trust.chamelio.ai and is linked from the security page, but it renders client side and returned an empty document on 2 September 2026. That is a retrieval limit under the machine refusal rule and is not graded against the vendor; equally, nothing on it is credited, since its contents were not read. Verified 2 September 2026.

Leah
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

A long list of frameworks with no scope, no date, no auditor and no report, and the property contradicts itself on what is held. The AI governance page claims SOC 1 Type I and II, SOC 2 Type I and II, GDPR compliant, CCPA compliant, HIPAA ready and ISO 27001 aligned. The home page FAQ, on the same property, says only that Leah is SOC 2 Type II certified. Credit where it is due: the hedged wording is honest, since the page says aligned and ready rather than certified for ISO 27001 and HIPAA, and most vendors blur exactly that line. But the substance an attestation is judged on is missing entirely. The auditor is identified only as an independent Managed Security Service Provider, which is a category rather than a name; no coverage period or report date is given; no audit scope is described; penetration testing is said to be regular with no partner named and no summary published; and no trust centre or portal exists anywhere on the property, so there is no route to request a report either. Checked 31 Aug 2026.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Chamelio
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

The architecture is described and the providers are not named, which is the B band's second limb precisely. The documentation states that Chamelio uses the best model for each job rather than a single model, that models from leading providers are continuously benchmarked, that top performers are automatically deployed for specific tasks, and that model versioning gives controlled deployment and rollback. The Terms of Service define Third Party LLM as a defined term, state that a data processing agreement has been executed with each one, and record that Chamelio has opted out of their training options. Not one provider is identified anywhere. AWS and Google Cloud Platform are named, but as hosting, which says where things run rather than whose models they are. Nor is there any commitment to notify customers when the underlying models change, and automatic deployment of new top performers means they change without notice. Verified 2 September 2026.

Leah
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Amended 2 September 2026 under R42, after the Master Terms and Annexes v3.0c were read in full. The original note recorded that nothing committed the vendor to notifying customers when the provider set or the models change; that is withdrawn. DPA clause 4.3 requires a new subprocessor to be added to the published list and the customer notified at least thirty days before it processes any customer personal data, and clause 4.4 gives a thirty day objection right on reasonable data protection grounds, with termination of the affected order and a refund of prepaid unused fees if the objection cannot be resolved. The provider set is also larger than first recorded. The DPA Setup Page names four model providers rather than two, each listed against Leah Functionality with a parenthetical that no customer data is stored or retained by that provider and each with named jurisdictions: Anthropic PBC across the USA, Japan and the EU or UK; OpenAI LLC across the USA, Japan and the EU or Switzerland; Cohere Inc. across Canada, the USA, the EU or UK and Japan; and Google AI/ML alongside Google Cloud across the USA, Japan and the EU, Switzerland or UK. Microsoft Azure Services is separately listed for data hosting and translation, and the private deployment option remains identified as Azure OpenAI Studio. The grade does not move, and the limb that holds it is unchanged: no model or version is named for any of the four providers, and naming the house is not naming the model. The architectural disclosure problem also stands and is sharper with four providers than with two. The platform is described as dynamically selecting across multiple advanced language models to match each task to the right model, and as allowing customers to extend or customise models, so which provider handled a given piece of legal work remains unknowable to the buyer from anything published.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Chamelio
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing information is published at any level, including the unit of charge. Two independent page inventories were checked on 2 September 2026 and neither contains a pricing surface: the site's own navigation and footer run to Product, Security, Learn, Company, Careers, Partnership and Contact, and the documentation publishes a complete machine readable index of every page, which covers guides, integrations, API reference and webhooks with nothing on cost. The only commercial route offered is Book a demo. Module names are published, Negotiate and Knowledge Center, but a product structure is not a pricing structure: no tier, no seat or volume unit, no term and no figure appears anywhere. Verified 2 September 2026.

Leah
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing information is published at any level, including the unit of charge. Searched the home page, the AI governance page, the full primary navigation covering platform, solutions, resources and company, and the complete footer sitemap on 31 Aug 2026. There is no pricing page, no tier structure, no per-seat, per-contract or per-agent unit, no volume banding, and no indication of what implementation adds. Every call to action across the property is to request a demo. The closest the vendor comes is an implementation FAQ stating that timelines vary with scope and integrations and that a detailed plan is built during evaluation, which is a statement about effort rather than cost. Nothing published would let a prospective buyer form any view of price before entering a sales process.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Chamelio
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

The buyer boundary is stated more plainly than most records in this index manage. The documentation header reads that the platform is exclusively for in-house legal teams, a dedicated page answers who it is for, and the marketing is consistent with it throughout, so a law firm reading this site learns quickly that it is not the customer. Named customers bear that out, sitting at technology companies including Bizzabo, Lightricks, Socure, Radware, Integrity and Atera. What is missing is the other half of the A band. No practice areas are enumerated: the material describes document types the platform handles, contracts, templates, policies, compliance documents, corporate records and regulatory filings, which is a document taxonomy rather than a statement of practice coverage. No company size band, no jurisdiction and no geography is published first party, and nothing states which legal work the platform does not support. Verified 2 September 2026.

Leah
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Segment coverage is documented precisely across two dimensions and the boundaries are never stated. By industry the vendor publishes dedicated pages for CPG and manufacturing, energy and utilities, financial services, healthcare, and pharma and medical devices, and describes its customers as Fortune 500 enterprises in regulated industries. By function it publishes pages for legal leadership, legal operations, sales and revenue, procurement, and finance, with distinct propositions written for the General Counsel, the contract operations team, the Chief Procurement Officer and the finance leader. The customer roster evidences that spread rather than merely claiming it, spanning banking, airlines, pharmaceuticals, consumer goods and engineering. What is absent is the far edge. No statement identifies which practice areas, contract types or matters the platform does not support, nothing addresses smaller organisations, and law firms appear only indirectly through managed service partners rather than as a served segment. Checked 31 Aug 2026.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Chamelio
Never, in the contract

The prohibition is in the agreement under a clause headed No Third Party LLM Model Training, and it adds that Chamelio has opted out of all available training options for each third party model it uses. The data licence is separately confined to providing the service. The security documentation extends the commitment inward, stating that customer data is not used to train Chamelio's own models or those of its AI sub-processors, which is broader than the home page wording, which promises only that data is never used to train external or public AI models. One carve-out belongs on the record: Chamelio may compile and disclose anonymous aggregated statistics, defined as Derived Data, which it owns along with any products incorporating it. That clause names statistics rather than training and so does not reverse the value, but a buyer should read it. The agreement renders client side and this text was recovered through the search index rather than by loading the page.

Leah
Never, in policy only

The security FAQ on the home page states that customer contract data is never used to train models, and the AI governance page reinforces it, naming data leaking into models the customer does not own as a failure it engineered out and stating that zero data retention is the only acceptable answer, enforced against the named providers so that data is processed but never stored by OpenAI or Anthropic. Amended 2 September 2026. The original summary recorded that no agreement could be retrieved; that is withdrawn, because the Master Terms and Annexes v3.0c have now been read in full. The value does not move, and the reason is worth stating for a reader. No term in the agreement names training, model training, machine learning or model improvement in relation to customer content, either to permit it or to prohibit it. Two clauses bear on it without reaching it. Clause 5.1 confines the provider's access to and use of Customer Data to providing and maintaining the Cloud Service, Support and Professional Services. Clause 5.4 reserves a right to use Usage Data, defined as the provider's technical logs, data and learnings about the customer's use, to operate, improve and support the service, and expressly excludes Customer Data from that definition, so the improvement permission runs to telemetry rather than to content. Read together they are consistent with a prohibition on training without stating one, and whether model improvement falls inside providing and maintaining the service is precisely the question they leave open. The commitment recorded here therefore rests on the published policy statement rather than on a located contractual term. Version note: v3.0c is the version that renders; v4.0 of January 2026 sits behind a viewer that could not be rendered, and the vendor states the only change is the trading name.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Chamelio
Disclosed without a period

Retention is acknowledged in the security documentation under a privacy guarantees heading and no period is given, for prompts, outputs or documents. Deletion exists as a product function rather than a published window: the API documents permanent document deletion and fires a core.document.deleted webhook when it happens, so a customer can remove material, but no retention setting is exposed and no zero retention option is stated as available. The termination and deletion provisions of the Terms of Service could not be read, because the legal hub renders client side and the search index did not surface Article 11 beyond its survival clause.

Leah
Disclosed fixed window

Row completed 2 September 2026 under R26 from the Master Terms and Annexes v3.0c, read in full. A specific period is published and the customer cannot vary it: section 14.4 provides for export during the subscription term and deletion of Customer Data within sixty days of request after termination, subject to a carve-out for standard backup or record retention policies and legal requirements. The data processing addendum tightens it, requiring deletion in accordance with industry-standard secure deletion practices at clause 8.2 with a certificate of deletion on request, and Schedule 1 commits to export in CSV or similar format within thirty calendar days and physical destruction of media by a recognised provider. What is absent is any prompt-specific or output-specific window: the agreement governs Customer Data as a class, defined at section 23 as any data, content or materials the customer submits to its accounts, so prompts and outputs inherit that regime rather than having one of their own. One layer sits outside it and a buyer should see it. Section 5.4 permits the provider to collect Usage Data, defined as its technical logs, data and learnings about the customer's use but expressly excluding Customer Data, and to use it to operate, improve and support the service and for other lawful business purposes including benchmarking and reports, with external disclosure only where de-identified and aggregated across customers. No deletion obligation attaches to Usage Data anywhere in the agreement, and section 14.5 makes 5.4 survive termination.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Chamelio
Own model, documented

Chamelio operates its own permission model rather than inheriting one. Documents arrive from Google Drive and SharePoint through a native file picker into Chamelio's own repository, so the source system's access model does not travel with them and is not enforced at query time. What Chamelio publishes in its place is documented: role-based access control, user groups for organising access across the organisation, legal entities, per-document access customisation, and SCIM provisioning from Entra ID and Okta so that group membership can be kept in step with the identity provider. The documentation also states that each customer's data is processed in isolated environments. The consequence for the buyer is the one this value describes: the permission model has to be maintained in Chamelio and kept aligned with the source systems by hand.

Leah
Claimed, not documented

Separation is asserted at customer level and offered as an architecture rather than a control. The vendor states that single-tenant deployment is available for customers with strict data isolation requirements, and that a dedicated zero-trust private environment within Azure OpenAI Studio ensures complete isolation from all other customers, with role-based access control stated to be enforced at every layer. What that wording also establishes is that isolation is a deployment option rather than the default, and nothing published describes how customers are separated in the standard shared deployment. Nothing addresses boundaries inside a customer either, which matters on a platform where legal, procurement, finance and shared services teams work in the same system. Searched the home page and the AI governance page on 31 Aug 2026; the privacy statement could not be retrieved.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Chamelio
Not addressed

Nothing locatable addresses disclosure to authorities or in response to legal process, and nothing addresses notice to the customer if a demand arrives. The reason is retrieval rather than drafting, and it is stated here so no reader infers that Chamelio has simply not written the term. Terms of service exist and are referred to from the site, but they sit behind a JavaScript-gated hub that returns the page frame and no body. The full escalation ladder was run: both www and non-www forms, the footer and navigation of pages that do render, sitemap and robots paths, and search queries built from distinctive contract language to pull the text out of the search index rather than the page. Two fragments surfaced that way and neither concerns third party requests: one confirming the customer owns all Customer Data and Outputs, and a paired analytics and feedback provision. The operator independently attempted the same retrieval on separate tooling and obtained the same empty frame, which establishes the block as a property of the site rather than of one fetcher. This row is written on the value's own words, which turn on what is located rather than on what the vendor did, and a buyer sitting where this reading sat could not read the term either. Surfaces checked and confirmed on 2 September 2026.

Leah
Notice committed

Row completed 2 September 2026 under R26 from the Master Terms and Annexes v3.0c, read in full. Section 19, headed Required Disclosures, permits the recipient to disclose Confidential Information to the extent required by law and then commits, where law permits, to the quoted advance notice plus reasonable cooperation at the discloser's expense to obtain confidential treatment for the information. Two features make this stronger than it first reads. The clause says Confidential Information including Customer Data in terms, so customer material is inside the notice obligation rather than needing to be argued into it, and section 23 confirms that the customer's Confidential Information includes Customer Data. And the obligation is reciprocal, binding whichever party receives the demand. Section 14.5 makes section 19 survive termination. It is not the top value because no transparency report was located: nothing published records how many demands have been received or how they were answered. Version note: v3.0c is the readable version; the current v4.0 of January 2026 sits behind a viewer that could not be rendered, and the vendor states the only change is the new trading name.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Chamelio
Not addressed

Checked the home page, product page, security page, the complete documentation index and the recoverable portions of the Terms of Service on 2 September 2026. No public material identifies a corpus. The platform's material is chiefly the customer's own contracts, templates, policies and negotiation history, so the coverage risk this signal tracks does not arise in its usual form. It is not entirely absent either: the home page lists legal research among the AI Agent's capabilities, and no source, jurisdiction or licence basis is stated for whatever underlies that feature.

Leah
Sources named, basis unstated

The working corpus is the customer's own material and is identified as such: the vendor states that Leah operates against the customer's policies and playbooks, gains intelligence from the customer's unstructured data and business rules, and answers contract questions from the customer's repository with sources attached. Alongside that it refers to Leah operating against established legal precedents, which names no source, no jurisdiction, no database and no rights basis. The product manages a customer's contracts rather than retrieving primary law, so the usual coverage question does not arise in full, but the precedent reference is unsupported by any provenance statement. No update cadence is published for anything.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Chamelio
Not addressed

Checked the home page, product page and the complete documentation index on 2 September 2026. No public material addresses subsequent history, treatment flags or citator coverage. The platform is built around the customer's own document corpus rather than primary authority, and no citator function is claimed anywhere, so the honest reading is that the question is not addressed rather than that a weaker form of checking exists. The legal research capability named on the home page is not documented further and nothing states whether any authority it surfaces is checked for currency.

Leah
Not addressed

Searched the home page and the AI governance page in full, together with the complete navigation and footer sitemap, on 31 Aug 2026. Nothing addresses whether legal authority is checked for subsequent history, and no citator, treatment signal or currency check was located. The platform manages contracts, obligations and procurement workflows rather than retrieving case law, so a citator is not part of what it sells. Worth recording alongside that: the vendor refers to Leah operating against established legal precedents without identifying any source, so the one place primary authority is invoked carries no verification mechanism.

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Chamelio
Not addressed

Checked the home page, product page, security page and the complete documentation index on 2 September 2026. Nothing describes what the platform does when it cannot ground an answer. No abstention path, no no-answer behaviour and no confidence or grounding score is documented, so the weaker values are false of this record as well. The nearest published statements run the other way: the security documentation claims the model selection approach will guarantee the most accurate and reliable results, and output filtering and prompt injection protection are described, but those are security controls over what the system emits rather than an account of what it does when it does not know.

Leah
Not addressed

Searched the home page and the AI governance page in full on 31 Aug 2026. No explicit no-answer or abstention path is documented and no confidence or grounding score was located. The governance loop does produce rejections, with approvals, escalations and rejections applied automatically according to the customer's rules, but those are policy outcomes decided by configured guardrails rather than the model declining to answer because it cannot ground a response. Nothing published states what Leah does when the customer's own contract set or playbook does not cover the question in front of it.

Fabricated Citation Record

Does a public court record exist involving output from this product?

Chamelio
None located

Searched the AI Hallucination Cases database maintained by Damien Charlotin, and reporting drawing on it, on 2 September 2026 on both the product name Chamelio and the corporate name Innvo AI. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product, and it is worth noting that the platform is sold to in-house departments for contract work rather than to litigators for filing, so the exposure this signal tracks is structurally lower for this product than for a research tool.

Leah
None located

No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, searched on both the current product name and the former company name ContractPodAi, alongside 2026 sanctions trackers and trade press summaries. This is a statement about the public record on the date shown rather than a clearance, and it is bounded by what that database covers. The platform runs commercial contracting and procurement work rather than producing court filings, so its output does not ordinarily reach a brief.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Chamelio
Not addressed

Checked the home page, product page, security page, company page, the complete documentation index and the recoverable portions of the Terms of Service on 2 September 2026. No public material engages with ABA Formal Opinion 512, any state bar opinion, or any other named ethics guidance. Nothing addresses professional responsibility even in general terms, so this is a full absence rather than a generic reference.

Leah
Not addressed

Searched the home page, the AI governance page and the complete navigation and footer sitemap on 31 Aug 2026. No engagement with any bar or ethics guidance was located, including ABA Formal Opinion 512, US state bar guidance, and Solicitors Regulation Authority or Law Society material despite the company being headquartered in London and selling into legal departments across North America, Europe, Asia and Australia. The compliance material published is regulatory and security-framework oriented, covering GDPR, CCPA, HIPAA, SOC and ISO, and none of it addresses the professional conduct obligations that bind the lawyers using the product.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Chamelio
Savings claims only

Savings claims are made plainly and repeatedly: an 89 per cent reduction in review time on the home page, a customer's 90 per cent reduction in legal review time, and NDA turnaround falling from 24 hours to under an hour. Nothing published addresses billing, fee or disclosure treatment, and no per matter record of AI assisted work was located. One edge is worth recording, because it recurs for in-house products. This signal assumes a vendor selling to a firm that bills a client by the hour, and Chamelio's buyer is the in-house department, which is the client rather than the biller. The compression it markets lands on outside counsel spend and internal capacity rather than on an invoice the platform's buyer issues, so the top values could not apply here on any evidence.

Leah
Savings claims only

Public materials are framed around cost and time removed, and quantified at portfolio level: a 91 per cent cut in contract review time, more than 18 million dollars of revenue protected, more than 2 million dollars of tracked savings, and headline figures of more than 125 billion dollars of commercial value managed and more than 10 billion dollars of ROI impact delivered. Searched the home page and the AI governance page on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee purposes and no published guidance on billing, fee or client disclosure treatment. The immutable per-action audit log the vendor describes could in principle support such a record, but nothing presents it for that purpose. The buyer is an in-house function rather than a firm billing a client, so the question lands on internal cost and outside counsel spend, and neither is addressed.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Chamelio
Not addressed

Checked the home page, security page, the complete documentation index and the recoverable portions of the Terms of Service on 2 September 2026. No subprocessor list is published and no model provider is named anywhere. The gap is explicit rather than inferred: the security documentation states that customer data is not used to train the models of Chamelio's AI sub-processors, and the Terms of Service define Third Party LLM and record that a data processing agreement has been executed with each one, so the vendor confirms these parties exist and identifies none of them. AWS and Google Cloud Platform are named, but naming a host says where a model runs rather than whose it is, which does not satisfy this signal. A department asked by a counterparty which providers see its contracts could not answer from anything Chamelio publishes.

Leah
Subprocessors listed

Amended 2 September 2026 under R42. The original summary, written 31 August 2026, recorded that no subprocessor list of any kind existed and that the data processing agreement, if published, sat behind a legal page that could not be retrieved. Both statements are withdrawn: the Master Terms and Annexes v3.0c render in full at the URL above, and the DPA is Annex B of that same document. All three limbs are now met. The DPA Setup Page carries a full subprocessor list with purpose, location and the product each is used in, running to ABBYY OCR SDK, Anthropic PBC, Cohere Inc., DocuSign or Adobe, Google AI/ML and Google Cloud, Jitterbit, Microsoft Azure Services, OpenAI LLC, QlikTech, Sendgrid, ZOHO, Zuva and four ContractPod group entities. The model providers are named directly rather than inferred, with Anthropic, OpenAI, Cohere and Google AI/ML each listed against Leah Functionality, each carrying a parenthetical that no Customer Data is stored or retained by that provider, and each with named jurisdictions. And the forwardable artifact exists in the Bonterms DPA itself, published ungated as part of the same PDF, with EU Standard Contractual Clauses Modules 2 and 3 incorporated, the UK International Data Transfer Addendum for UK transfers, Schedule 1 setting out the processing details a client would ask for, and a Specified Notice Period for security incidents of 48 hours, which is tighter than the 72 hours most of this corpus publishes. Clause 4.3 commits to adding a new subprocessor to the list and notifying at least 30 days before it processes anything, with an objection right at 4.4 and termination with refund if the objection cannot be resolved. The private deployment environment identified on the vendor's AI governance page as Azure OpenAI Studio remains part of the picture. Version note: v3.0c is the version that renders; v4.0 of January 2026 sits behind a viewer that could not be rendered, and the vendor states the only change is the trading name.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Chamelio
Not addressed

Checked the home page, product page, security page and the complete documentation index including the API reference on 2 September 2026. Nothing addresses judicial standing orders, AI use disclosure or verification certification. The platform does emit a task level audit trail: the API retrieves activity log history covering comments, approvals and other actions, and the security documentation states that audit trails are maintained for system access and changes. That records who did what to a task, not which model produced which passage or what it retrieved, so it does not answer the question this signal asks. The product class matters too: this platform is sold to in-house departments for contract and knowledge work rather than for court filing, so the disclosure obligation it tracks would usually fall on outside counsel instead.

Leah
Partial record

The strongest partial record read in this pull, missing one element. The audit stage of the published governance loop logs every decision with what the agent did, why, against which policy, with what data, and what the outcome was, in records the vendor describes as tamper-resistant, immutable and ready for any audit. That covers the action, the governing rule, the inputs and the result at per-action granularity. The missing element is the model: the platform selects dynamically across multiple LLMs per task and no model or version is identified anywhere, so which system produced a given passage cannot be established from the record. No export designed for a court disclosure or AI-use certification was located, and the audit framing throughout is regulatory and internal rather than judicial. Checked 31 Aug 2026.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • Commercial Transparency
Signals neither addresses in public material
  • Good Law Verification
  • Refusal and Uncertainty Behaviour
  • Bar Guidance Alignment

Which one fits

Choose Chamelio if

  • Your department needs the AI where the work already happens. Chamelio publishes a setup guide for each integration stating what moves and in which direction, covering Salesforce, DocuSign, Google Drive, SharePoint, Slack and a Microsoft Word add in, over a documented REST API with an OpenAPI specification and thirteen webhook events, with single sign on through Entra ID and Okta and SCIM provisioning from both.
  • You want the training position in the agreement rather than in marketing. Chamelio's Terms of Service carry a clause headed No Third Party LLM Model Training stating that customer data sent to third party large language models is not used to train them and that Chamelio has opted out of every available training option for each one, and its documentation extends the commitment to Chamelio's own models.
  • You need a permission model you can administer and keep in step with your identity provider. Chamelio documents role based access control, user groups, legal entities and per document access customisation, with SCIM provisioning from Entra ID and Okta so group membership stays aligned, and states that each customer's data is processed in isolated environments.

Choose Leah if

  • You need to define what an agent may do before it does it. Leah publishes a three stage governance loop in which the customer sets which agents may act, on which data, within which thresholds and where escalation is required, those policies are held as configuration rather than code and applied at run time, and every action is logged with its rationale, the governing policy, the data and the outcome.
  • You want the allocation of loss written out with figures. Leah's master terms set a general cap at twelve months of fees, an enhanced cap at three times that figure for breach of the security clause or the data processing addendum, and enumerate uncapped claims covering indemnification, intellectual property, and confidentiality, alongside a customer indemnity, a warranty with a thirty day fix period and published uptime tiers with refund.
  • A counterparty asks which providers see the contract. Leah's data processing addendum publishes a subprocessor list naming Anthropic, OpenAI, Cohere and Google AI/ML against Leah functionality with jurisdictions for each, commits to adding new subprocessors to that list with thirty days notice and an objection right, and sets a forty eight hour security incident notice period.

In summary

Chamelio

Chamelio is a legal intelligence platform sold exclusively to in house legal departments, built around Negotiate, a Microsoft Word add in that reviews and redlines against playbooks it can generate from a team's own precedent, and a Knowledge Center holding contracts, templates and policies as a searchable repository, with agentic workflows chaining intake, review, approval and signature. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes, with an A on practice systems integration depth: each integration carries a setup guide stating what moves and in which direction, over a documented REST API with thirteen webhook events and SCIM provisioning. Its terms carry a clause headed No Third Party LLM Model Training. As of 2 September 2026 the index located no accuracy figure, no named model provider and no published price.

Source: AI Legal Index, 2026

Leah

Leah is an agentic platform for contracting, legal, procurement and finance at large enterprises, formerly known as ContractPodAi, covering guided intake, playbook driven review and redlining in Word, conditional approval routing, execution through DocuSign and Adobe Sign, and a repository with obligation tracking, under a skills based orchestration layer assigning work to domain agents. The AI Legal Index grades it in the top two bands on eleven of fifteen capability axes, with A grades on autonomy and oversight and on AI liability and recourse: the customer defines which agents may act within which thresholds, every action is logged with its governing policy, and the master terms set tiered liability caps with uncapped claims enumerated. As of 31 August 2026 the index located no accuracy figure, no named model version and no published price.

Source: AI Legal Index, 2026

Questions buyers ask

Are Chamelio and Leah alternatives to each other?

Not really, and the page does not pretend otherwise. Chamelio is a recent platform sold exclusively to in house legal departments and positions itself as a replacement for a contract lifecycle system. Leah, formerly ContractPodAi, is an enterprise agentic platform sold to Fortune 500 legal, procurement and finance functions and delivered in part through PwC, Epiq, Integreon and Pinsent Masons. They rarely appear on the same shortlist. What the comparison shows is what the same fifteen axes reveal about two vendors of very different size. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Does Chamelio train its AI on customer contracts?

The prohibition is contractual. A clause headed No Third Party LLM Model Training states that customer data transmitted to third party large language models is not used to train them, and that Chamelio has opted out of all available training options for each model it uses, with the security documentation extending the commitment to Chamelio's own models and those of its AI subprocessors. One carve out belongs alongside it: Chamelio may compile and disclose anonymous aggregated statistics, which it defines as Derived Data and owns. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

What does Leah publish about liability?

More than almost anything else in this index. Leah's master terms set a general liability cap at the amounts paid in the twelve months before the first incident, an enhanced cap at three times that figure for breach of the security clause or the data processing addendum, and list uncapped claims covering indemnification, intellectual property and confidentiality. A customer indemnity, a warranty with a thirty day correction period and published uptime tiers with termination and refund sit alongside. Nothing addresses inaccurate output specifically. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Which one names the AI providers behind the product?

Leah does. Its data processing addendum lists Anthropic, OpenAI, Cohere and Google AI/ML against Leah functionality, each with the jurisdictions involved and a note that no customer data is stored or retained by that provider. Chamelio confirms that third party large language models are used and that a data processing agreement is executed with each, and names none of them. Neither names the specific models or versions, and both select dynamically per task, so which model handled a given piece of work is unknowable from published material on either side. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

What do Chamelio and Leah both leave unpublished?

Neither publishes a price, a tier structure or a unit of charge, so every commercial route on both properties is a demo request. Neither publishes an accuracy figure, hallucination rate or test set, despite both describing benchmarking programmes. Neither names the specific models underneath. Neither names a bar or ethics authority, including ABA Formal Opinion 512. And neither addresses legal professional privilege or work product, which both platforms hold in volume for a legal department. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Disclosure

Two things to weigh. Both vendors assert measurement that neither publishes: Leah states that every agent action is measured against benchmarks for accuracy, bias and outcome, and Chamelio states that models are continuously benchmarked with the best performer deployed per task to guarantee the most accurate results, and no figure, method or cadence appears on either record. Both readings also hit a retrieval limit worth naming. Chamelio's terms render client side and returned no body, so the indemnity scope, cap and warranty could not be read and its third party request row records what could not be located rather than what the vendor wrote. On Leah the version read is v3.0c of the master terms, because the current v4.0 sits behind a viewer that would not render. Chamelio was verified on 2 September 2026 and Leah on 31 August 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 2, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746