CobbleStone Software vs Conga CLM: how they compare in 2026
CobbleStone Software and Conga CLM are both enterprise contract lifecycle suites sold to legal, procurement and sales, each with an AI layer, VISDOM and AiMe, running over a platform that long predates it. Conga CLM sits in the top two bands on thirteen of fifteen axes and CobbleStone on eleven of fifteen, identical on nine. Conga's lead is a published governance and data regime: an AI addendum that records a governance committee anchored to the NIST AI Risk Management Framework, a subprocessor list with fifteen days' notice of changes, breach notice within 48 hours, and each AI provider named by function under a zero retention arrangement. Its addendum also permits training on a customer's data, into models used only for that customer's tenant. CobbleStone's counterweight is price and control over where it runs. It publishes its AI tiers from $3,995 a year by words processed, names OpenAI in its agreement with notice before any change, and sells an installed edition the customer runs on its own servers. Conga publishes no price at all. Both disclaim liability for what their AI produces, and neither publishes an accuracy figure.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of a core capability layered on a product that would still function without them, which is the B band and is the vendor's own description of the architecture. VISDOM is presented as a native intelligence layer inside Contract Insight, using the same data model and clause library, and as something that attaches to an existing workflow rather than being a destination. Underneath it sits a full contract lifecycle management platform that predates the AI by decades: repository, version control, template and clause authoring, workflow automation, alerts, reporting, electronic signature, and separately licensed vendor management, e-procurement, e-sourcing, purchase order, requisition and OFAC modules. Remove VISDOM and a working CLM and procurement suite remains, and the vendor sells the AI as a priced add-on with its own tiers rather than as the platform itself. That is the distinction from the records in this lane that carry A. Recorded on the other side: the 2026 releases push the AI further into the platform, with VISDOM embedded at platform level in the native online editor and described as operating autonomously there, and the vendor's own framing has moved from a feature to an agentic layer. It has not moved far enough to make the platform unsaleable without it. Verified 12 September 2026.
The models are the engine of a core capability layered on a product that would function without them, which is B and is the vendor's own architecture. AiMe is described as a shared AI layer running across the whole commercial suite, connecting workflow data across CPQ, CLM, price optimisation and document automation and suggesting next steps, rather than as the CLM itself. Underneath sits a full contract lifecycle platform that long predates it: template and clause-library generation, approval routing, negotiation, electronic signature through Conga Sign, a searchable repository, obligation and renewal tracking, and reporting. Strip AiMe out and a working CLM remains, which is precisely what the Salesforce-based edition was for years. What is recorded on the other side, because it is moving: the June 2026 platform release is described as AI-enhanced throughout, bulk import and extraction is presented as the way contracts enter the system at all, and the March 2026 AiMe release adds agents that act inside quoting and contracting workflows. The direction is toward the models becoming the product, and the record says so, but the platform is still sold and priced as a contract system with intelligence on top. Verified 12 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted without measurement and grounding is claimed without a described method, which is the C band. The grounding claim is real in the product's own idiom and worth stating: VISDOM works from the customer's own clause library, playbook and repository, using the same data model as the platform, and clause suggestions are described as generated based on precedence, so the output has an identifiable source inside the customer's own material. The accuracy claim is unquantified, the strongest version being an assertion of consistent system-wide accuracy in a February 2026 release announcement. Nothing published gives an accuracy figure, a test set, an error rate, a benchmark or a described retrieval method, and no evaluation of extraction or clause-matching precision was located anywhere on the estate. R40 governs the floor and the D limb does not fire, because the position is not a bare no-hallucination claim: the Master Subscription Agreement disclaims warranties as to the quality, accuracy or validity of information residing on or passing through the system, and section 9.3(b) states that information available from the software may not be complete or accurate and that the customer assumes responsibility for its review and use. The product cites no legal authority, so the authority-grounding and citation-status limbs do not apply under R15 and are not counted against it. Verified 12 September 2026.
Grounding is real and documented, short of any accuracy figure an outsider could test, which is B. R15 governs the inapplicable limbs: the product cites no legal authority, so authority grounding and citation-status checking do not bite and are not counted against it. What does bite is grounding and measurement, and the grounding disclosure is stronger than most in this lane. The pipeline is named component by component on the trust centre: Google Cloud Vision for optical character recognition, Amazon Textract for table detection, Zuva for provision extraction and Azure OpenAI for language processing, which tells a reader how a clause becomes an assertion. Output is grounded in the customer's own repository, playbook and clause library, extraction is described as requiring no model training by the customer, and the vendor states that AiMe surfaces how every recommendation is generated with the reasoning visible to the user and a confidence score shown wherever it makes a suggestion. Accuracy is addressed only as a disclaimer: the Artificial Intelligence Addendum states that outputs may be inaccurate, incomplete or misleading and disclaims all warranty as to accuracy or completeness. No figure, test set, error rate or published benchmark result was located; third-party models are said to be benchmarked before release and no results are published. Verified 12 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A written commitment that the models work alongside a human decision-maker, with real review surfaces, short of the threshold at which the system acts alone. The commitment is unusually strong for this corpus because it is contractual rather than marketing: Master Subscription Agreement section 7.2 prohibits the customer from using any AI Tool as part of an automated decision-making process with legal effects unless the final decision is made by a human being, and from using it to provide advice that would normally be provided by a licensed professional. That is a published constraint on what the system may be allowed to decide, drafted into the instrument that governs the product. The review surfaces are real: tracked edits, inline comments and co-authoring in the native online editor, high-risk clause flagging that triggers auditable reviews, and deviation reporting against the playbook before signature. R37 rule 2 identifies what is missing. The same estate describes AI operating autonomously within the editor, agents that analyse, flag and review without complex user configuration, and an assistant that runs compliance checks, and those cannot all sit alongside a human-decides rule without a stated boundary. No threshold, confidence level or class of work is published at which the system stops and hands back. The note carries both so a reader can weigh them. Verified 12 September 2026.
Modes, constraints, review surfaces and the route back to human judgement are all published, which is the A band, and most of it is contractual rather than marketing. What the system runs alone is stated as a boundary: AiMe never acts autonomously on high-stakes decisions. What constrains it is named as three specific mechanisms, agent guardrails, approval thresholds, and human-in-the-loop confirmation, each of which can be built into a workflow, which is the threshold limb answered in the product's own idiom rather than dodged. The review surfaces are real and are the strongest part: the vendor states that AiMe surfaces how every recommendation is generated, that users see the reasoning behind AI-driven actions, and that a confidence score is shown wherever AiMe makes a suggestion, alongside redlines a user accepts or rejects and a complete audit trail of every action and approval. The route back to human judgement is contractual: the Artificial Intelligence Addendum makes the customer solely responsible for evaluating and validating outputs, states that the customer shall not rely on AI outputs as the sole basis for any decision with legal, financial, regulatory or other material impact, requires appropriate human review and independent judgment, places authorising and supervising agent actions on the customer, and records that the features are intended to support and not replace human decision-making. One limit is recorded rather than credited: the guardrails and thresholds are described as configurable rather than as defaults, and the same document states that Conga does not monitor or review AI-generated outputs. Verified 12 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers without figures, which is the B band's stated shape almost exactly. Fourteen organisations are named in a published case-study library, each with the edition deployed and a one-line account of what changed: El Paso County, Marion County, the County of San Diego Health and Human Services Agency, SUNY Upstate Medical University, Chiesi, Intarcia Therapeutics, Soquel Creek Water District, Regional Water Authority, Brownsville Public Utilities Board, NewFields, Rapattoni Corporation, CentroMotion, Wound Care Advantage and Vertical Screen. The spread across government, healthcare, pharmaceuticals, utilities, manufacturing and software is itself evidence of production use rather than a pilot estate. What is absent is measurement attached to any of those names: not one carries a figure for cycle time, cost or volume on the index page read. The figures the vendor does publish are unattributed and sit at company level, being 95 per cent customer satisfaction according to its most recent survey, more than 5,000 organisations worldwide, a claim that digitised agreement workflows can drive up to 26 per cent efficiency gains, and a 1.8 times revenue velocity figure on the VISDOM page. None states a basis. Analyst placement with Gartner, Forrester, IDC and QKS is recorded rather than credited, since analyst recognition is not deployment evidence. Individual case studies were not opened. Verified 12 September 2026.
A named customer without figures, which is the B band's stated shape. The published customer-story library carries dated, named accounts, and one of the three surfaced on the index page is on this product: Cotality, formerly CoreLogic, described as elevating its client service capabilities with Conga CLM, dated 5 September 2024. The other two dated stories name DigiKey on price management, dated 27 April 2026, and Kalixia at 160 times faster document generation, dated 19 March 2025, and neither is the contracting product, so they are recorded rather than credited here. Around that sit customer logos on the product and pricing pages, Southwest Airlines, LinkedIn, AXA, Peloton, Cotality, T-Mobile, Adobe, Box and Kraft Heinz, which under the C band would stand in for evidence if they were all there was. What keeps the row off A is measurement and attribution together. The CLM story carries no figure. The figures that are published sit apart from any named customer: a 9 per cent revenue increase claimed beside the logo strip with no basis stated, an AI-assisted review claim of 50 per cent less review time on the features page, and three headline counters on the product page that render as zeros. Analyst placement, G2 Leader recognition across five grids with first rankings for enterprise usability and relationships, is recorded and not credited, since analyst placement is not deployment evidence. Verified 12 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments on confidentiality, readable before signing, short of the full picture, which is B. What is published and contractual: Master Subscription Agreement section 8.1 defines Confidential Information to include Customer Data expressly, section 8.2 requires each party to hold it in strict confidence, to use no less than a reasonable degree of care, and not to disclose it except as approved in writing or as legally required, and those obligations survive termination without a time limit. Tenant separation is stated as architecture on the VISDOM page, and the installed edition goes further by putting the whole application on the customer's own server under Exhibit A. The model-provider position is partly explicit and better than most of this corpus: section 7.1 names OpenAI as the AI Processor, states it may act as data subprocessor for information input into an AI Tool, and commits the vendor to reasonable advance notice before changing it. Three A limbs fail. Privilege and work product are addressed nowhere, and R33 makes that limb decisive on its own. There is no contractual prohibition on training: section 8.3 reserves the right to collect and analyse data including information concerning Customer Data and to use it to improve and enhance the Services, and the no-training statements sit on product pages rather than in the agreement. And while the model provider is named, nothing states what OpenAI may retain of what is sent to it. Retention and deletion are not addressed in the agreement at all. Verified 12 September 2026.
Four of the five A limbs are met contractually and one is absent, and R33 makes the absent one decisive. Training use is addressed in the Artificial Intelligence Addendum rather than on a policy page: Conga shall not use AI Inputs or AI Outputs to train or improve any AI or machine learning model beyond the limited licence to provide, maintain or improve the Services for that customer's benefit; Customer Data shall not be used to train global or foundational models serving multiple customers; and no third party may use Customer Data or AI Output to train, fine-tune, validate, test or otherwise develop any model. Segregation at the level an in-house buyer needs is documented: tenant environments are logically separated with dedicated encryption keys per tenant. Retention and deletion are stated in the Data Processing Addendum, which limits retention to the duration absolutely necessary and requires return and deletion at the customer's election after the agreement ends. The position on third-party model providers is explicit and unusually detailed: prompts, completions, embeddings and training data sent to Azure OpenAI are not available to OpenAI, are not used to improve OpenAI models and are not used to improve Microsoft or third-party products, and a zero-retention arrangement is stated with each document-processing provider. The limb that fails is privilege and work product, which is addressed nowhere on any surface read. On a product sold to legal departments to hold their agreements, that silence is the whole distance to A. Verified 12 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
A real published position on advice versus tooling, contractual rather than a website notice, short of the supervision and competence dimension. Two provisions carry it. Master Subscription Agreement section 7.2(ii) bars the customer from using any AI Tool to provide advice that would normally be provided by a licensed professional, naming legal advice expressly, which is a restriction on use rather than a disclaimer of status and is therefore addressed to the risk this axis exists for. Section 9.3(b) adds the status statement plainly, that CobbleStone does not provide legal advice for the customer, alongside an allocation of responsibility for reviewing and using output. Section 7.2(i) reinforces both by requiring a human being to make the final decision wherever an AI Tool feeds a decision with legal effects. C does not fire: this is not boilerplate in the terms contradicted by marketing that speaks in advice terms, and the audience is named rather than left ambiguous. What is missing for A is everything about the lawyer's own duties. Nothing addresses how a supervising lawyer discharges competence or oversight obligations over AI-generated redlines, nothing states which of the four named buyer groups may operate which capability, and no jurisdictional limit is named anywhere. The product is sold to procurement, sales and IT alongside legal, and nothing published addresses what that means for the review of legal positions. Verified 12 September 2026.
A real published position on advice versus tooling, short of the supervision and competence dimension, which is B. The position is contractual and specific rather than a website disclaimer: the Artificial Intelligence Addendum states that AI-generated outputs may be inaccurate, incomplete or misleading, disclaims any warranty of fitness, makes the customer solely responsible for evaluating and validating outputs before use, and then draws the line that matters here, that the customer shall not rely on AI-generated outputs as the sole basis for any decision that may have legal, financial, regulatory or other material impact, and that appropriate human review and independent judgment should be exercised. It extends the same allocation to agentic behaviour, making the customer responsible for determining whether agent actions are appropriate and for authorising and supervising them. C does not fire: the audience is named across published function pages, the marketing does not describe the product in advice terms, and the clause is not boilerplate. What is missing for A is the lawyer's own side. Nothing published addresses how a supervising lawyer discharges competence or oversight duties over AI-drafted contract language, nothing states which of the named buyer groups may use which capability, and no jurisdictional limit appears anywhere. That last gap is sharper than usual on a product marketed to sales and procurement users generating contract positions in the same tenant as legal. Verified 12 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
No governance framework, testing regime or accountable owner is published, which is C. What exists is governance by contract rather than by programme, and it is recorded because it is real: Master Subscription Agreement section 7 is a dedicated Artificial Intelligence article that names the third-party AI Processor, states that CobbleStone is not a data controller of information processed through an AI Tool, places control of what is uploaded with the customer's users, restricts the uses to which AI Tools may be put, and reserves the right to alter or withdraw VISDOM+ on reasonable advance notice. The product pages add a guardrails claim and an inference-only architecture statement. None of that is what the higher bands ask for. There is no responsible AI or AI governance page, no framework and no certification against one such as ISO 42001, no person or function inside the vendor is named as accountable for AI, nothing is published about what is evaluated before a model change ships, and there is no published position on uneven output across contract types, counterparty drafting styles or the seven languages the extraction engine claims to support. The one place a bias question is directly raised by the product, sentiment and negotiating-tone analysis, is described as a capability with no accompanying account of how tone is judged or tested. Verified 12 September 2026.
A published governance framework with real substance, short of testing results, which is B, and it sits at the top of that band. The substance is documented and contractual, not a principles page. The Artificial Intelligence Addendum records a cross-functional AI Governance Committee responsible for oversight of AI within the Services with a focus on risk management, accountability and compliance, which periodically reviews AI-related risks, controls and mitigation measures including data protection, security and appropriate human oversight. It commits Conga to internal policies for the ethical and responsible use of AI covering oversight of training data, bias mitigation and human interpretability, to personnel training on responsible development and deployment, and to full cooperation with a customer's own AI impact assessments and transparency obligations. Governance is anchored to a named external framework, the NIST AI Risk Management Framework, by its four core functions of Govern, Map, Measure and Manage. The vendor also publishes its own regulatory classification, stating that its products qualify as minimal or limited risk AI systems under the EU AI Act, and states that third-party models undergo testing, bias auditing and benchmarking before release with rollback to any prior model version available within hours. What holds it off A is the limb the band names: no results are published. No bias audit finding, evaluation output, model card or statement about uneven performance across contract types or drafting conventions was located anywhere. Verified 12 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy across most of the ground, short of the full set, which is B. Retention and deletion are addressed in the privacy policy rather than left blank: personal information is kept as necessary to fulfil contracts and legal obligations and is retained until deleted by the vendor or as requested by the data owner, with deletion available on request at any time. Access control is documented across several surfaces: encryption at rest and in transit, tenant isolation, named and concurrent user licence models with server session timeouts defined in the agreement, and audit trails across AI chats, contracts and other key areas. The subprocessor limb is partly met in an unusual way, through the agreement rather than a register: section 7.1 names OpenAI as the AI Processor and as a possible data subprocessor, with reasonable advance notice of change, so a customer can identify the third party that sees content sent to an AI Tool. Two gaps hold it at B, and they are the two the band names. There is no subprocessor list, so the hosting, support and infrastructure processors behind the platform are unidentified, with Google Cloud Platform surfacing only as an environment on the attestations page. And no incident practice runs to the customer: the agreement obliges the customer to notify the vendor within 24 hours of a suspected compromise and says nothing about the vendor notifying the customer of a breach. Verified 12 September 2026.
Retention, deletion, access control, subprocessors and incident practice are all published, current and specific enough to hold the vendor to, which is the A band, and every limb rests on a document a buyer can read before signing. Retention: the Data Processing Addendum states that retention of personal data should generally not be required and that any retention is limited to the duration absolutely necessary to perform the Services, with daily backups retained for thirty days, and a zero-retention arrangement stated with each third-party document-processing provider. Deletion: return and deletion at the customer's election within a reasonable period after the agreement ends, with the customer able to delete within the Services and assistance where it cannot, and a prompt-compliance obligation on deletion requests under the CCPA attachment. Access control is documented control by control: role-based authorisation, least privilege, quarterly access reviews, joiner-mover-leaver revocation, VP-level approval for access escalation, multi-factor authentication, managed firewalls, host-based intrusion detection, encryption at rest and TLS at 256-bit or stronger in transit, per-tenant encryption keys, and no customer data on laptops or removable media. Subprocessors: a published list, fifteen days' notice before appointing a new one, a right to object with a termination and refund remedy, flow-down obligations, and Conga liable for subprocessor acts as if performing them itself. Incident practice: notification within 48 hours of becoming aware under the DPA, a documented response plan with root-cause analysis, and a 24/7 security team. Verified 12 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Liability is addressed through a limitation clause that disclaims the exposure the product creates, which is C, and as with the other records graded here today the grade turns on scope rather than on drafting quality. What is published is specific: section 11.1 caps total liability at the licence fees paid in the twelve months before the claim, excludes lost profits and indirect, incidental, consequential, special, exemplary and punitive damages, and makes adjustment, repair or replacement the customer's sole remedy for breach of warranty; section 11.2 preserves liability for death or personal injury caused by negligence, for fraud, and under the indemnity; section 12.6 requires any action to be brought within one year. Section 10.1 is a genuine indemnity but runs only to third-party United States patent, trademark or copyright infringement, and section 10.3 removes it wherever the damages relate to the content of the customer's data. There is more warranty here than most records at this grade carry, section 9.2(b) warranting that the software will materially conform to the documentation with a correct-or-refund remedy inside ninety business days, and that is recorded. It does not reach the question the axis asks. Nothing stands behind wrong AI output: section 9.3(a) disclaims all warranties as to accuracy or validity, section 9.3(b) puts review and use on the customer, and no insurance position or indemnity was located. Verified 12 September 2026.
Liability for what the AI produces is addressed only by disclaiming it, which is the C band, and here the disclaimer is unusually explicit rather than buried in a general limitation. The Artificial Intelligence Addendum states that Conga makes no warranty, express or implied, regarding the accuracy, completeness, non-infringement or fitness for a particular purpose of any AI-generated output, that the customer is solely responsible for evaluating and validating outputs, and then that, to the maximum extent permitted by applicable law, Conga shall not be liable for any losses, damages or claims, including third-party claims, arising from the customer's use of, reliance on, or actions taken based on AI-generated outputs or actions performed by agentic AI capabilities. That is the question this axis asks, answered in the negative and in terms. One genuine allocation runs the other way and is recorded: the Data Processing Addendum makes Conga liable for the acts and omissions of its subprocessors to the same extent as if it had performed the services directly, which matters given how much of the AI pipeline sits with third parties. A limit on this reading is stated plainly: the Master Services Agreement itself was not opened, so the general liability cap, indemnity scope and any insurance position are not established, and a reading of it could move this row. It would have to reverse the Addendum to do so, and the Addendum is the instrument that governs the AI question. Verified 12 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations, named and documented, short of a description of what they move, which is B. Named on the vendor's own surfaces: Microsoft Word and Microsoft Outlook add-ins carrying VISDOM into the drafting and mail surfaces, Salesforce, Microsoft Dynamics 365, Oracle, DocuSign, Adobe Acrobat Sign, Twilio and Unanet on the integration strip, plus an API described as available at the Elite tier for high-volume pipelines. A published support-portal article adds native CLM integrations, connectors to Zapier and Microsoft Power Automate reaching thousands of applications, and a plugin environment for contract lifecycle systems with two described use cases, pushing a Word or PDF file into the platform from a contract record or intake form and round-tripping a prepared redline back without leaving the browser. That round trip is the one place depth is genuinely described. Elsewhere it is not. No field-level mapping, sync direction or configuration requirement is published for the CRM and ERP connections, the connector article notes that new connectors were invite-only and directs the reader to email support, and API documentation is obtained the same way rather than published. A technical wiki exists at wiki.cobblestonesoftware.com and was not opened; under R25 it corroborates rather than carries. Verified 12 September 2026.
Real integrations, named and documented, short of the depth an implementer could work from, which is B. The named connections are substantial and several are structural rather than bolt-on. The product exists in two forms, one of which runs natively on the Salesforce platform and is listed on the Salesforce AppExchange, which is about as deep as a CRM integration gets. Authoring and review run inside Microsoft Word and Google Docs, Microsoft Dynamics is named on the product page, and the vendor states the platform edition connects to any CRM, ERP or procure-to-pay system. Inside Conga's own estate the connections are described functionally: pricing, terms and configurations from CPQ flow automatically into a contract, documents are generated through Composer and signed through Conga Sign, and price optimisation feeds contract pricing. Supporting surfaces exist and are named, a product documentation site at documentation.conga.com and a developer hub at developer.conga.com. What is not established is depth. Neither the integrations page nor the developer hub was opened, no field-level mapping or sync direction is published on the surfaces read, and the recurring claim of connecting to any CRM or ERP describes reach without describing what moves. Under R25 those two surfaces would corroborate and could lift this row; they are named here as published and unread. Verified 12 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Deployment model is stated clearly with partial residency detail, which is B, and the deployment side of this record is stronger than most. Two delivery forms are published and genuinely distinct: a hosted edition, and an Enterprise Installed Edition that the customer runs on its own infrastructure, specified down to the operating system, database, processor, memory and disk in Exhibit A of the agreement, with the customer responsible for backup and firewalling. For the installed edition residency is answered by construction and the agreement addresses it directly, section 2.3 permitting a single production instance located in the United States and its territories or any other country to which the software is legally exported, so the customer chooses where the data sits. Tenant isolation is stated for the hosted side, and the hosting environment is identified as Google Cloud Platform, though only in passing on the attestations page rather than on any product or security surface. What is missing for A: no region menu or list of available regions is published for the hosted edition, nothing distinguishes where processing happens from where data is stored, and the AI path is the sharpest gap, since content sent to the named third-party AI Processor leaves the tenant and no surface states where that processing occurs. Verified 12 September 2026.
Deployment model is stated clearly with partial residency detail, which is B, and the model side is fully answered. Two delivery forms are published and distinguished: the original Salesforce-based application, and a full software-as-a-service edition on the Conga Advantage Platform introduced to give buyers a CLM interface independent of Salesforce. What changes between them is published and material rather than cosmetic, and it is in the agreement: the Data Processing Addendum states that for services hosted on the Salesforce platform Conga does not back up customer data and there is no recovery point objective, against daily backups retained thirty days and a one-hour recovery point objective with a twenty-four hour recovery time objective elsewhere. Infrastructure is named, Salesforce, Amazon Web Services and Azure, with data stored on servers managed by Salesforce and AWS, and tenant environments logically separated with dedicated encryption keys. Residency is where it falls short of A. Availability is described as multi-region across the United States, the European Union and Asia-Pacific with residency options included, which names continents rather than regions; no region list or menu is published, nothing states which region a given tenant lands in or how a buyer chooses, and where processing happens is not distinguished from where data is stored. The AI path is the sharpest instance: content reaches Azure OpenAI, Google Cloud Vision, Amazon Textract and Zuva, and no surface states where any of that runs. Verified 12 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Badges appear with no scope, no date and no report available, which is the C band, and the page is a clear example of it. The Attestations page lists sixteen entries, including SOC 1 Type II, SOC 2 Type II, FISMA, HIPAA, GSA, NIST, CSA, eVerify, TX-RAMP, VPAT, the Data Privacy Framework and CMMC 2.0. Not one carries an auditor, a report period, a certificate number, a scope statement or a downloadable report, and there is no trust portal or request route on the page at all. Several entries do not survive reading. Safe Harbor is listed as a current attestation although that framework was invalidated in 2015. SSAE Type II is listed as if it were a certification, and is illustrated with a CSA STAR logo. ISO appears twice with no standard number, once as a bare entry and once as ISO for the Google Cloud Platform environment, which is Google's attestation rather than this vendor's and does not travel to the product without a scope connector under R16. FedRAMP is listed the same way, as compliance of the GCP environment, while the vendor's own press release on the same site says it has achieved FedRAMP Ready status and is seeking a sponsor, which is a materially different claim. A separate certification strip on the case-studies page names ISO 27001 and GDPR compliance, which the Attestations page does not. Recorded rather than resolved. Verified 12 September 2026.
Certification is real, named and scoped, and the evidence behind it is not reachable without a customer relationship, which is B at the top of the band. A genuine trust centre exists, is ungated and is linked from the site navigation. The standards are named individually rather than displayed as a badge wall: SOC 2 Type II with a stated scope of full platform coverage and audited annually, ISO 27001, ISO 27701 described as the privacy extension to it, PCI DSS, HIPAA Security with annual audits, GDPR, CCPA, alignment to the NIST AI Risk Management Framework, and certification under the EU-US Data Privacy Framework, which is the one item a reader can independently verify because the Data Processing Addendum points to the public Department of Commerce list. The programme behind them is documented: annual third-party penetration testing, biannual application vulnerability assessment, continuous automated threat hunting, static and dynamic code analysis before release, a severity-based patching service level, background checks, annual security training, and a published vulnerability disclosure programme. Two things hold it off A. No auditor is named, no report period, observation window or certificate number is published for any standard, and no report is carried on the trust centre itself. The route to the evidence is the Data Processing Addendum, which makes reports available on the customer's request subject to confidentiality, so a prospective buyer cannot read the scope of what was audited before contracting. Verified 12 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The supply chain is partly disclosed, which is B, and this is the strongest row on the record and among the better disclosures in this lane. Two of the four A limbs are met and both are met in the agreement rather than in marketing. The provider is identified: Master Subscription Agreement section 7.1 states that the AI Processor as of the effective date is OpenAI, defines the AI Processor as the third-party data processor used to provide certain AI features, and states that it may act as data subprocessor for information input into an AI Tool. Change notification is committed in the same clause, the vendor undertaking to change the AI Processor only with reasonable advance notice to the customer. The models are partly named, which is rarer still: the VISDOM pricing page states that VISDOM may use up to GPT-4 and GPT-4o with the vendor reserving the right to adjust model levels. Two things hold it off A. Where the models run is not stated anywhere, which matters because content leaves the tenant to reach them. And the two disclosures contradict each other on notice: the pricing page says the vendor reserves the right to alter the AI without notice, while section 7.1 requires reasonable advance notice. R37 rule 1 governs and the agreement wins, but the contradiction is the finding and belongs on the record. Verified 12 September 2026.
The supply chain is disclosed further than anything else in this lane and stops one limb short of A, which is B under R34. Providers are identified individually and by function, not gestured at: generative features run on Microsoft Azure OpenAI, and the document-processing agents additionally use Google Cloud Vision for optical character recognition, Amazon Textract for table detection and Zuva for provision extraction, each named with what it does and each under a stated zero-data-retention arrangement. Where the models run is stated, which few records manage: the Azure OpenAI Service is described as fully controlled by Microsoft, with Microsoft hosting the models in its own Azure environment and the service not interacting with any system operated by OpenAI, and the consequences are spelt out, that prompts, completions, embeddings and training data are tokenised in transit, are not available to OpenAI, and are not used to improve OpenAI, Microsoft or third-party models. Change notification is contractual and specific: the AI providers are subprocessors, and the Data Processing Addendum gives fifteen days' notice before any new subprocessor is appointed, with the name, location and activity disclosed, a right to object, and termination with a refund if no workaround is available. The limb that fails is the first one. No model is named. The addendum's closest approach is a parenthetical reference to Azure OpenAI GPT, which is a family rather than a version, and no surface states which model generates a summary or a redline or when that changes. Verified 12 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Real pricing is published for part of the range with the rest withheld, which is B, and the published part is the AI. Four VISDOM tiers carry figures and volumes: Basic free with up to 100,000 words a month and no overages, Starter at $3,995 billed annually with 500,000 words a month, Pro at $6,995 with 1,000,000, and Elite at $29,995 with 5,000,000, each shown with a monthly equivalent, above which the buyer is directed to sales. The unit of charge is defined rather than gestured at: words processed in and out per iteration, shared and consumed across all users, not rolling over month to month, with overage invoiced in 750-word increments, and the same unit is written into Master Subscription Agreement section 7.3. Commercial terms sit in the agreement and are specific: payment within thirty days, non-refundable fees, interest at 1.50 per cent monthly, annual increases capped at eight per cent, automatic twelve-month renewal with thirty days' notice not to renew, thirty days' notice to terminate for convenience, a thirty-day evaluation period with a full refund of licence fees, and thirty days' notice for VISDOM+ price changes. What holds it off A is the platform itself. Contract Insight licensing is quoted through a Request Pricing form, no figure or band is published for it, and the licence model is named and concurrent user seats, so a buyer can price the AI precisely and cannot price the thing the AI runs inside. Verified 12 September 2026.
No pricing information is published at any level, including the unit of charge, which is the D band and is the plainest instance of it in this lane. The pricing page exists, is linked from the top-level navigation, and carries no price, no band, no term, no tier table, no feature-by-tier comparison, no unit of charge, no minimum, no statement of whether the product is licensed per user, per contract or per platform, and no indication of what implementation adds. What it does carry is a heading, a paragraph saying that every business is unique and that the vendor provides clear details about product options and associated costs, a list of six things the pricing is said to prioritise, one of which is Transparency, two customer logo strips, and a quote request form. That is a page which invites a sales conversation and nothing else, which R10 identifies as an absence rather than as structure, and it is why no VendorPricing row is written for this record. The nearest thing to a published tier anywhere on the estate is a line on the platform page inviting the buyer to add CLM Advanced features such as a clause library, version control and redlining, which names one upgrade and three features on a product page; it is recorded here for completeness and is not pricing information. Commercial terms are not published either: the Master Services Agreement was not opened, so payment terms, renewal, uplift caps and termination rights are not established from any surface read. Verified 12 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment and practice coverage is described with substance and the boundaries are left open, which is B. Buyer coverage is published as its own navigation tier with four named audiences, Legal, Procurement, Sales and IT, each with a page, and the legal audience is addressed twice, once as a team and once as an industry. Sector coverage is enumerated across seven industry pages, healthcare, government, education, pharmaceuticals and life sciences, energy and utilities, financial services and legal, and the published customer base bears that out across counties, a state university medical centre, water districts, a public utility board and pharmaceutical companies, spanning public and private sector. Product coverage is described edition by edition, with a comparison page setting out what differs between CLM editions and an add-on module list a buyer can read before speaking to anyone. What is left open holds it off A. No practice area inside a legal department is identified as supported or unsupported, the seven languages named for extraction are not tied to any statement about jurisdictional or drafting-convention coverage, nothing states which of the four named audiences may use which AI capability, and there is no published statement of what the product is not for. The only firm-shaped datum located is that the design is aimed at in-house and public-sector contract functions rather than at law firms, and that is inferred from the estate rather than stated. Verified 12 September 2026.
Segment coverage is described with real substance and the boundaries are left open, which is B. Who the product serves is published as its own navigation tier with seven named functions, Legal, Procurement, Sales, Finance, IT, Business Operations and Pricing, each with a page of its own, and the CLM material addresses legal, sales and procurement side by side with a different task list for each: legal gets workflow, authoring, AI reviewing and redlining, contract compliance and risk management, procurement gets obligation management, AI-extracted terms and pricing, and sales gets generation, AI-assisted negotiation and renewals. Industry coverage is enumerated across seven pages, technology, financial services, healthcare, life sciences, manufacturing, transport and logistics, and distribution, and a process tier organises the same estate by contracting stage. The published customer base bears the breadth out across airlines, insurance, media, retail and property data. What is left open holds it off A. No practice area inside a legal department is named as supported or unsupported, no statement of what the product is not for appears anywhere, nothing distinguishes which capabilities are available to a non-lawyer user in a shared tenant, and there is no jurisdictional or language coverage statement despite the product being sold and localised into German and French. Verified 12 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The public statement is a no, the agreement does not carry it, and both of the vendor's own formulations are qualified in ways a buyer should see. The VISDOM page states that proprietary contracts never train public models and answers the direct question with: never, VISDOM uses inference-only architecture for client data, documents are processed and not learned from, and model weights are not updated using non-permitted client content.
The pricing page adds that documents are not used to train global AI models. The qualifiers are the point. Public and global models leave the vendor's own models unaddressed, and non-permitted client content implies a category of permitted client content that is not defined anywhere located. No matching prohibition appears in the Master Subscription Agreement, which was read in full. What the agreement does contain runs the other way: section 8.3 reserves the right to collect and analyze data and other information relating to the provision, use and performance of the Services, including information concerning Customer Data, and to use it to improve and enhance the Services or Licensed Software and for other development purposes, and to disclose it in aggregate or de-identified form.
Following the same reading applied to other records today, that is an improvement right that never names training, so contractual-permitted is not reached under the R28 test. A third fact belongs here: section 7.1 sends content input into an AI Tool to OpenAI as AI Processor, and nothing published states what OpenAI may retain or train on.
Training on customer content is expressly permitted in the published agreement and is fenced more tightly than any other record in this pull, and both halves belong in the reading. The permission is in the Artificial Intelligence Addendum section (c): Conga shall not use Customer Data to train global or foundational models that serve multiple customers, and any model training using Customer Data shall be limited to models specific to the customer's instance or tenant.
So training happens, on the customer's own data, into a model only that customer uses, and no opt-out is located. The fences around it are unusually strong and are contractual, not policy: Conga does not use Customer Data to train third-party foundational models, naming Azure OpenAI GPT as the example; section (d) provides that Conga will not permit any third party to use, directly or indirectly, any Customer Data or AI Output to train, fine-tune, validate, test or otherwise develop any AI system or model; and section (b) states that beyond a limited license to provide, maintain or improve the Services for that customer's benefit, Conga shall not use AI Inputs or AI Outputs to train or improve any AI or machine learning model.
The trust center adds that models trained on one customer's data are never used to score or recommend for another and that model training takes place within the customer's environment. One carve-out is reserved: Service Attributes, defined as anonymized and aggregated usage information, may be used to train and refine models, and are stated not to be Customer Data.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is acknowledged in public material with no period stated, which is this value. The privacy policy addresses it directly: information is kept as necessary to fulfill contracts, interact with users, meet government regulations and support the establishment, exercise or defense of legal claims, is kept only as long as necessary as determined in the applicable governing documents or law, and is retained until deleted by the vendor or as requested by the data owner, with deletion available on request at any time.
That is a real published position and it is more than silence, but no number attaches to it and the governing documents that would set the period are the customer's own order form rather than anything published. Two things narrow it further for the purposes of this signal. The policy is written about personal information across the website and the software rather than about contract documents, prompts and generated output specifically, and the Master Subscription Agreement, read in full, sets no retention period and no deletion or return obligation on termination.
Separately, the product publishes audit trails across AI chats, which establishes that AI interactions are retained without saying for how long. Nothing addresses retention by the third-party AI Processor named in section 7.1.
The customer controls the retention window by contractual instruction and no zero-retention setting is published for the product itself, which is this value. The Data Processing Addendum sets the default at Attachment A: retention of personal data should generally not be required, and where it is retained the period is limited to the duration absolutely necessary to perform the Services. Section 9.6 puts the end state in the customer's hands, requiring return and deletion at the customer's election within a reasonable period after the agreement concludes, with the customer responsible for correcting, blocking or deleting within the Services and Conga assisting where it cannot.
The CCPA attachment adds an obligation to comply promptly with any customer instruction to delete. One specific figure is published and is worth having: daily backups of customer data are retained for thirty days, except for services hosted on the Salesforce platform, which Conga does not back up at all. The strongest retention fact on this record sits at the model layer rather than the product layer and is recorded here rather than credited to the top value: Conga states a zero-data-retention policy with each third-party document-processing provider, so documents sent to Azure OpenAI, Google Cloud Vision, Amazon Textract and Zuva are processed in real time and not stored afterwards. No zero-retention setting is offered to the customer inside the Services.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own documented permission model that the customer has to administer, which is this value rather than the stronger one. Separation between customers is stated architecturally, the VISDOM page asserting complete tenant isolation and the pricing page adding that data stays isolated within the customer's own CobbleStone environment; for the Enterprise Installed Edition the separation is absolute, since the application and database run on the customer's own server under Exhibit A of the agreement.
Inside a deployment the model is the vendor's own. The agreement defines named and concurrent End User license models with server session timeouts, the marketing describes highly robust security options, and section 6.1 places responsibility on the customer to administer the system successfully, which is exactly the alignment burden this value describes. Retrieval is not shown to enforce an external document system's access model at query time, so the top value is not reached.
What is not addressed is segregation between matters or deals inside one deployment: nothing published describes a wall between one business unit's contracts and another's, which matters here because the platform is sold to legal, procurement, sales and IT in the same instance and the AI assistant answers questions across the whole repository.
The product maintains its own documented permission model that the customer must administer, which is this value. Separation between customers is documented as architecture rather than asserted: tenant environments are logically separated with dedicated encryption keys, each tenant holds unique keys, and the training position reinforces it, models trained on one customer's data never being used to score or recommend for another and training taking place within the customer's environment.
Inside a tenant the model is Conga's own and is documented in the Data Processing Addendum's security attachment: role-based authorization, least privilege, quarterly access reviews, multi-factor authentication, and the customer's own ability to limit access to authorized personnel. The trust center states plainly that rules-based access controls, audit logs and admin tools help the customer configure and manage AiMe, which is the alignment burden this value describes, sitting with the buyer.
The product does not enforce an external document management system's access model at query time, so the top value is not reached. What is not addressed is segregation between matters or business units inside one tenant. That is the live question on this product, because the platform is sold to legal, procurement, sales, finance and IT in the same instance and the assistant answers questions across the whole contract repository in natural language.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Compelled disclosure is addressed and customer notice is absent, which is this value precisely. Master Subscription Agreement section 8.2 obliges each party to hold the other's Confidential Information in strict confidence and not to disclose it to any third party except as approved in writing or as legally required, and Customer Data is inside the definition of Confidential Information under section 8.1. So the agreement tells the customer plainly that its data can leave on legal compulsion.
What is absent is any treatment of what happens next. No clause commits the vendor to notify the customer of a subpoena, court order, warrant or law enforcement request, none reserves discretion over whether to notify, none commits to seeking a protective order or to redirecting the authority to the customer, and none sets any period for anything. The privacy policy, recovered through the search index, addresses onward transfers and the Data Privacy Framework and was not located to address notice either.
No transparency report of any kind was found. The distinction from a vendor that says nothing at all is that this one has addressed disclosure and stopped short of notice, which is the state this value was added to record.
Notice is committed in the published agreement and no transparency report exists, which is this value. The commitment is in the Data Processing Addendum's security attachment at section 4, headed Disclosure by Law: if Conga is required by any law to disclose customer data it will, to the extent permitted by applicable law, give the customer prior notice of the obligation as soon as practical after becoming aware, and will take all steps to enable the customer an opportunity to prevent or limit the disclosure.
The second limb is the useful one, because it is an obligation to help rather than merely to inform. The CCPA attachment carries a parallel and slightly stronger commitment for personal information: where a law requires disclosure for a purpose unrelated to the contracted business purpose, Conga must first inform the customer of the legal requirement and give it an opportunity to object or challenge the requirement, unless applicable law prohibits notice.
Two related provisions round out the picture: Conga will redirect a misdirected data subject request to the customer rather than answering it, and will not respond without the customer's prior written consent unless legally required. What is absent is the reporting half. No transparency report, no aggregate figure for demands received, and no reporting cadence was located on any surface.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The sources behind the output are identified and no rights basis is stated for any of them, which is this value. The primary corpus is named and is the customer's own: VISDOM is described as using the same data model and clause library as the platform, drafting clause language based on precedence, matching against the customer's approved clause library and enforcing a playbook the organization defines once, so the material the answers come from is the customer's own repository.
The generative layer is also identified, the agreement naming OpenAI as AI Processor and the pricing page naming GPT-4 and GPT-4o as the model levels that may be used, which tells a reader what general corpus sits behind the language generation even though its contents are not described. The rights basis is stated nowhere. The agreement grants the vendor rights over Customer Data through sections 8.3 and 2.6 but says nothing about the provenance or licensing of anything the models bring with them.
The one place the product reaches outside the customer's own material is the compliance question-and-answer capability, which maps contract language to regulatory frameworks including GDPR and HIPAA obligations, and no source, edition or update cadence is published for those frameworks.
The sources behind the output are identified and no rights basis is stated for any of them, which is this value. The working corpus is the customer's own and is named as such throughout: contracts imported in bulk including third-party, legacy and acquired agreements, the customer's clause library, its negotiation playbook and its approved templates, with the vendor stating that highly precise models are created from the customer's own documents without the customer needing to train them.
The generative layer is identified too, which is more than most records manage: Azure OpenAI provides the language model processing, with Google Cloud Vision, Amazon Textract and Zuva named for optical character recognition, table detection and provision extraction respectively. What is never stated is any rights or licensing basis. Nothing describes what the underlying foundation models were trained on, and Zuva's provision-extraction models, which are trained on contract corpora rather than on the customer's own documents, are named as a component without any account of what sits behind them.
The customer-side basis is the agreement itself, the Artificial Intelligence Addendum leaving the customer with all right, title and interest in its AI Inputs and AI Outputs and granting Conga only a limited license.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history, and on this product class the question largely does not arise. The product cites no cases, statutes or regulations to a reader: it works on the customer's own contracts, matching clauses against a playbook and an approved library, extracting obligations and dates, and drafting replacement language from precedent inside the customer's own estate.
The one capability that touches external law is the compliance question-and-answer feature, which is described as mapping contract language to regulatory frameworks such as GDPR and HIPAA in real time, and nothing published states how those frameworks are kept current, which edition is held, or what happens when a regulation changes. The nearest published currency mechanism is the Horizon Scanning capability advertised on other vendors' terms elsewhere in this corpus and not offered here.
Recorded so the row states the position rather than leaving a reader to infer it. Verified against the product and pricing surfaces on the date shown.
No located public material addresses whether authority is checked for subsequent history, and on this product class the question does not arise in its usual form. The product cites no cases, statutes or regulations to a reader: it works on the customer's own agreements, comparing draft language to a negotiation playbook, matching against an approved clause library, extracting obligations and dates, summarizing, and answering questions about the repository.
Nothing it produces is an assertion about the state of the law that a lawyer would need to check for subsequent treatment. The nearest adjacency is the obligation and renewal tracking, where currency means whether a contractual date or duty is still live rather than whether an authority is still good law, and that is addressed through alerts and dashboards rather than through anything this signal measures. Recorded so the row states the position rather than leaving a reader to infer it from silence. Product, features, trust center and both published addenda were read on the date shown.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer. The nearest thing published is a claim that the assistant is kept on track by guardrails that align with the customer's process and data, which describes a constraint without describing a behavior, and a risk-flagging design in which high-risk clauses are surfaced and auditable reviews triggered, which is detection rather than abstention.
Nothing states that the system declines to answer, marks an answer as unsupported, reports that a clause could not be matched to the playbook, or exposes a confidence or grounding score to the user. The contractual material points the other way rather than filling the gap: section 9.3(b) of the agreement places responsibility for reviewing and using output on the customer, and section 7.2 requires a human to make any final decision with legal effects, both of which allocate the consequences of an ungrounded answer without describing what the system does before one is produced.
Recorded as an established absence: the product pages, the pricing page and its FAQ, and the full agreement were read on the date shown.
A confidence signal is exposed to the user and no explicit abstention path is published, which is this value exactly. The confidence half is stated plainly and is unusual in this corpus: the vendor commits that AiMe surfaces how every recommendation is generated, that users see the reasoning behind AI-driven actions, and that confidence scores are shown wherever AiMe makes a suggestion. That gives a reviewer a per-suggestion signal to work from, which is more than most records offer.
What is absent is the other half. Nothing published describes what the system does when it cannot ground an answer: no statement that it declines, no marking of an unsupported extraction, no account of what happens when a clause cannot be matched to the playbook or a question cannot be answered from the repository, and no published evaluation demonstrating any such behavior. The surrounding material allocates the consequences rather than describing the behavior: the Artificial Intelligence Addendum acknowledges that outputs may be inaccurate, incomplete or misleading, makes the customer solely responsible for validating them, and states that Conga does not monitor or review AI-generated outputs. A guardrails claim appears on the product page without any description of what the guardrails do.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
Searched on 12 September 2026, on both the product name and the company name, against published trackers of decisions on AI-generated fabricated citations including coverage of the Damien Charlotin AI Hallucination Cases database and two independent sanctions trackers, for any court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product. None located. This is a statement about the public record on that one subject as of the date shown, and under R119 this signal records fabricated citations and nothing else, so it is not a litigation history and no other proceeding involving the vendor would appear here.
Searched on 12 September 2026, on both the product name and the company name, against published trackers of decisions on AI-generated fabricated citations including coverage of the Damien Charlotin AI Hallucination Cases database and two independent sanctions trackers, for any court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product. None located. This is a statement about the public record on that one subject as of the date shown, and under R119 this signal records fabricated citations and nothing else, so it is not a litigation history and no other proceeding involving the vendor would appear here.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Professional responsibility is referred to in general terms and no guidance is named. Master Subscription Agreement section 7.2 restricts the customer from using any AI Tool to provide advice that would normally be provided by a licensed professional, naming legal advice expressly, and from using one in automated decision-making with legal effects unless a human makes the final decision. That is a reference to the professional licensing framework rather than a disclaimer of the vendor's own status, and it is addressed to the customer's conduct, which is why this row takes a value at all rather than recording nothing.
It is graded here on that clause and not on the separate statement in section 9.3(b) that the vendor does not provide legal advice, which is a status disclaimer and is graded on the professional responsibility axis. Nothing further is engaged. No bar or ethics opinion is cited anywhere on the estate, ABA Formal Opinion 512 does not appear, no state guidance on generative AI in legal work is referenced, and nothing maps any capability to a jurisdiction's rules of professional conduct.
The absence carries weight on this record because the platform is sold to procurement, sales and IT teams alongside legal and the same AI capabilities are available to all of them.
No located public material engages with bar or ethics guidance. No bar opinion is named anywhere on the estate, ABA Formal Opinion 512 does not appear, no state guidance on generative AI in legal practice is referenced, and nothing maps any capability to a jurisdiction's rules of professional conduct. This record engages external authority more than most, and none of it is professional responsibility guidance: the Artificial Intelligence Addendum anchors governance to the NIST AI Risk Management Framework, and the trust center publishes the vendor's own classification of its products as minimal or limited risk AI systems under the EU AI Act.
Both are AI-regulatory instruments addressed to the vendor as an AI system provider, both are graded on the governance axis, and crediting them again here would work one fact across two rows. The nearest thing to a professional-responsibility statement is the Addendum's requirement that the customer not rely on AI outputs as the sole basis for a decision with legal impact and exercise independent judgment, which is graded on the professional responsibility axis and names no guidance in any event.
The absence is worth stating because the same estate shows the vendor is willing and able to engage named frameworks when it chooses to.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The product does not touch a fee between a lawyer and a client, because it is bought by teams that bill no client for the work. The named audiences are legal, procurement, sales and IT departments inside the buying organization, and the published customer base is weighted toward counties, public utilities, a state university medical center, health and human services agencies and pharmaceutical companies, all of them running their own contracts rather than billing a client for reviewing them.
The vendor's efficiency claims, 26 percent efficiency gains from digitized agreement workflows and 1.8 times revenue velocity, are aimed at the buyer's own cost and cycle time, and under this value they are recorded here rather than making the row a savings claim, because no client bill sits in the loop. Worth noting for a reader working the other way round: the AI is metered and priced in a way that would make pass-through arithmetic possible if anyone wanted it, with words consumed in and out per iteration, shared across all users, and overage billed in 750-word increments.
Nothing published addresses disclosure of AI use or AI cost in any fee or billing context, and nothing needs to on this buyer's side of the relationship.
The product does not touch a fee between a lawyer and a client, because it is bought by teams that bill no client for the work. The named audiences are in-house functions of the buying organization, legal, procurement, sales, finance, IT and business operations, each with its own published page, and the customer base is corporate rather than law-firm: an airline, an insurer, a property data business, a consumer fitness company and a professional network among the named logos.
Nothing in the estate is addressed to a law firm billing a client. Efficiency claims are extensive, a 9 percent revenue increase, a 50 percent reduction in AI-assisted review time, faster deal cycles and reduced supplier costs, and under this value they are recorded here rather than making the row a savings claim, because every one of them is aimed at the buyer's own cost, cycle time or revenue and none reaches a client bill.
Worth noting for a reader coming the other way: because the same platform runs quoting, pricing and billing alongside contracts, the vendor sits close to its customers' own revenue processes, but that is the customer billing its customers rather than a lawyer billing a client, and it is a different object. Nothing published addresses disclosure of AI use or AI cost in any fee context.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A model provider is identified in a published, ungated agreement, which is what this value records. Master Subscription Agreement section 7.1 defines the AI Processor as the third-party data processor used to provide certain artificial intelligence features, names it as OpenAI as of the effective date, states that it may act as data subprocessor for any information input into an AI Tool, and commits the vendor to reasonable advance notice before changing it.
A company asked by its counterparty or its own counsel which third party sees content sent to the AI can therefore answer from the public record, which most records in this corpus cannot. Under R29 that is the substance of the naming limb: a statement about who touches customer content rather than a partnership boast. The top value is not reached because the other two limbs are missing. There is no subprocessor list, so hosting, support and infrastructure processors are unidentified and Google Cloud Platform surfaces only in passing on the attestations page, and no client-facing disclosure pack, consent notice or forwardable annex exists.
The legal hub advertises data processing addenda but its body did not render to this index's fetcher and no DPA was recovered, so nothing is credited to one.
The pack a company would forward to answer a counterparty's AI clause is published and ungated, which is the top value and the first record in this pull to reach it. The model provider statement is the part that usually fails and here it is the strongest: the trust center names the third-party services behind the AI individually and by function, Google Cloud Vision for optical character recognition, Amazon Textract for table detection, Zuva for provision extraction and Azure OpenAI for language model processing, states a zero-data-retention arrangement with each, and explains what Azure OpenAI does and does not do with prompts and completions.
A subprocessor list is published at conga.com/privacy/subprocessors-and-subcontractors, and the Data Processing Addendum executes Clause 9(a) Option 2 of the Standard Contractual Clauses against it with fifteen days' notice, a right to object and a termination-and-refund remedy. Client-facing disclosure material is the third limb and it is met twice over: the Data Processing Addendum itself, published in full with the SCCs, the UK addendum and Swiss adaptations, and a separate Artificial Intelligence Addendum written to be read by a customer's counsel.
Stated for the record: the model provider limb rests on the trust center, which was read in full, and the subprocessor list page itself was not opened, so its publication is evidenced by the addendum rather than by its contents.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of a record exist, short of a document-level export, which is this value. The AI-specific element is the one that counts and it is published in the vendor's own words: audit trails across AI chats, contracts and other key areas, which means interactions with the assistant are logged rather than ephemeral. Around it sit the ordinary evidentiary ingredients of a contract platform: robust document version control, tracked edits and inline comments in the native editor, an approval and workflow history, and deviation reporting showing where a draft departed from the approved playbook.
Together those would let a party show who changed what and when. What is absent is everything that would turn that into a disclosure record about the AI. Nothing states that any export identifies which model produced a passage, and the model level is in any case variable by the vendor's own reservation to adjust between GPT-4 and GPT-4o; nothing marks machine-generated text against human-edited text in an exportable form; and no disclosure template, certification form or court-facing guidance was located anywhere on the estate.
Several elements of a record exist and no document-level export is described, which is this value. The elements are better than most. The platform maintains a complete audit trail of every action, approval and signature across the contract lifecycle, described by the vendor as supporting compliance and offering full transparency for legal or internal reviews, alongside version control, tracked edits and inline comments in the native editor.
The AI-specific element is the one that matters here and it is published: the vendor commits that AiMe surfaces how every recommendation is generated, that users see the reasoning behind AI-driven actions, and that a confidence score accompanies each suggestion, so the basis of a machine-proposed clause is visible at the point of review rather than lost. What is absent is the export and the model identity. Nothing states that any report or extract identifies which model produced a passage, and the model is in any case not named beyond a family; nothing marks machine-generated text against human-edited text in a form a party could hand to a court; and no disclosure template, certification form or court-facing guidance was located anywhere on the estate.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Good Law Verification
Which one fits
Choose CobbleStone Software if
- You need the contract system on your own servers. CobbleStone sells an Enterprise Installed Edition that runs on your own Windows and SQL Server infrastructure, with a single production instance in the United States or any country the software can be exported to, alongside a hosted edition on Google Cloud.
- You want to price the AI before a sales call. CobbleStone publishes VISDOM at no cost up to 100,000 words a month, then $3,995, $6,995 and $29,995 a year for 500,000, one million and five million words, counted in and out and shared across users; the platform license itself is quoted.
- You need the model provider named in the contract. CobbleStone's agreement names OpenAI as its AI processor with advance notice before any change, its pricing page names GPT-4 and GPT-4o, and the agreement bars using its AI for decisions with legal effects unless a person makes the final call.
Choose Conga CLM if
- Your AI risk review wants a governance structure in writing. Conga's AI addendum records a cross functional AI Governance Committee, policies on training data oversight and bias mitigation, and alignment with the NIST AI Risk Management Framework, and its trust center classifies its products under the EU AI Act.
- You need breach notice and subprocessor control on a clock. Conga's data processing addendum commits to notice within 48 hours of a breach, fifteen days' notice before a new subprocessor with a right to object and a refund remedy, per tenant encryption keys, and return or deletion at your election after the contract ends.
- You want suggestions whose reasoning you can see, inside Salesforce. Conga's AiMe shows how each recommendation is generated with a confidence score and states that it never acts autonomously on high stakes decisions, and Conga CLM runs natively on Salesforce or as a standalone platform beside any CRM.
In summary
CobbleStone Software
CobbleStone Software, the trading name of CobbleStone Systems Corp. of Princeton, New Jersey, sells Contract Insight, a contract lifecycle platform in the market since the mid 1990s with modules for vendor management, procurement and sourcing, and a proprietary AI layer, VISDOM, that extracts clauses, checks drafts against a playbook, proposes language and answers questions, with generative features on OpenAI models. The AI Legal Index grades it in the top two bands on eleven of fifteen capability axes. It publishes VISDOM prices by words processed, names OpenAI in its agreement, and offers hosted and customer installed editions. Named users include El Paso County and SUNY Upstate Medical University. As of 12 September 2026 the index located no platform price, no accuracy measurement and no auditable security report.
Conga CLM
Conga CLM is the contract lifecycle product of Conga Corporation of Broomfield, Colorado, sold on Salesforce or as standalone software beside any CRM or ERP, with authoring in Word or Google Docs and links to Conga's quoting, document and billing products. Its AI, AiMe, imports legacy contracts as structured data, checks drafts against a playbook, proposes redlines and answers repository questions, on Azure OpenAI with named document processing providers. The AI Legal Index grades it in the top two bands on thirteen of fifteen capability axes, with A grades on autonomy and oversight and on data stewardship. It publishes an AI addendum and a data processing addendum and names Southwest Airlines and LinkedIn among customers. As of 12 September 2026 the index located no published price or model version.
Questions buyers ask
CobbleStone vs Conga CLM: which is better for enterprise contract management?
On published evidence Conga CLM sits in the top two bands on thirteen of fifteen AI Legal Index capability axes and CobbleStone Software on eleven of fifteen, identical on nine. Conga publishes more on AI governance, data handling and breach notice. CobbleStone publishes AI prices, names its model provider in the contract and offers an edition installed on your own servers. Public sector buyers who need on premises deployment have more to read from CobbleStone.
Does Conga CLM train AI on customer contracts?
On the customer's own data, for that customer only. Conga's AI addendum permits model training using customer data but limits it to models specific to the customer's tenant, bars training global or foundation models that serve multiple customers, and bars any third party from using customer data or outputs to train or develop a model. Anonymized, aggregated usage data may be used to refine models. No opt out was located. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
Does CobbleStone train AI on customer contracts?
CobbleStone's VISDOM page says proprietary contracts never train public models and that client data is processed by inference only, without updating model weights. Its master subscription agreement contains no training prohibition and reserves use of data concerning customer data to improve its services, without naming training. Content sent to its AI tools goes to OpenAI as its named AI processor. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
How much do CobbleStone and Conga CLM cost?
CobbleStone publishes its AI tiers: VISDOM Basic is free up to 100,000 words a month, and paid tiers cost $3,995, $6,995 and $29,995 a year for 500,000, one million and five million words; the Contract Insight platform license is quoted, by named or concurrent user. Conga publishes no price, unit or tier for Conga CLM, and its pricing page leads to a quote form. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
What do CobbleStone and Conga CLM both leave unpublished?
How accurate their AI is and what either stands behind when it is wrong. Neither publishes an accuracy figure, test set or evaluation result, and both disclaim warranties on AI output. Neither addresses privilege or work product, or separation between business units inside one deployment, although both are sold to legal, sales and procurement in the same tenant. Neither names a bar opinion on AI use. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
Three readings to weigh. Conga's AI addendum permits training on a customer's own data into models limited to that customer's tenant, while barring global models and any third party from training on it; that is a published term. CobbleStone's attestations page lists sixteen badges without auditors, dates or reports, including Safe Harbor, a framework invalidated in 2015, and FedRAMP described as compliance while its own release says FedRAMP Ready. Conga's master services agreement was not read, so its general liability cap is not established here. CobbleStone Software and Conga CLM were both verified on 12 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.