Coheso vs Tonkean LegalWorks: how they compare in 2026
Coheso and Tonkean LegalWorks, one of three solutions from Tonkean, both give in house legal teams a front door that takes requests from Slack, Teams or email and answers simple ones with AI. Coheso sits in the top two bands on ten of fifteen axes and Tonkean LegalWorks on nine of fifteen, identical on nine. Coheso's lead is evidence about its answers. Its AI Assist cites the passage in the legal team's own documents behind each answer. A dated Taskrabbit study reports 297 requests in about three and a half months, 86 of them resolved by AI. Tonkean's counterweight is a published contract layer. Its data processing addendum names Azure, OpenAI and Google as AI subprocessors a customer must opt into, requires notice before any new one, and commits to challenge government demands. It publishes its pricing unit and offers dedicated or self hosted deployment. Its customer terms date from May 2019 and cap liability at three months of fees; Coheso publishes no customer agreement at all.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models drive the product's headline capabilities, on top of a workflow system that would still run without them. AI triages each incoming request and decides whether it can be answered from source documents or needs a lawyer, answers business users' questions from the legal team's approved content, generates first drafts from the team's templates, and runs agents that apply the team's playbooks to recurring reviews. Intake forms, routing rules, shared boards, status tracking and dashboards are conventional work management that functions without the models. Verified 22 September 2026.
The models drive a core capability on a product that plainly functions without them. What the AI does is real and named: AI Front Door reads plain-language requests, LegalGPT triages and classifies unstructured inbound requests, and packaged agents handle NDA generation and contract work. But underneath sits a no-code process orchestration platform with forms, rules, approval chains, dashboards and integrations, marketed as 100 per cent no-code and sold to procurement and IT in identical form. The clearest evidence is contractual rather than promotional: the published sub-processor table lists Microsoft Azure for AI LLM engine services, OpenAI for AI/ML powered product features and Google Cloud for OCR, and marks all three opt in. A customer who does not opt in receives an orchestration platform with no model behind it. That is the definition of this band rather than the one above. Checked 4 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Answers are grounded in the customer's own material and cite it. The AI Assist page says business-facing answers draw from the contracts, policies and guidance documents the legal team curates, with citations linking to the source passages, and the ROI page says each response from the legal-side assistant cites every individual assertion with footnotes hyperlinked to the passage relied on. The home page adds a report of which documents the AI leans on most and which questions it cannot yet answer. No accuracy figures, test set or error rate are published. Verified 22 September 2026.
Grounding is described in outline and accuracy is disclaimed rather than measured. The retrieval story is stated: the AI Front Door trawls the data sources the customer has given it access to and generates a document if one does not already exist, and agents draw on connected enterprise systems, so a reader can tell in principle what an output is built from. Nothing beyond that exists. No accuracy figure, no test set, no evaluation, no error rate and no method description appears on any surface, and no output is presented with a traceable citation to the source record it came from. The agreement moves in the opposite direction and does so explicitly: Tonkean does not warrant that the Platform will meet the customer's requirements or expectations, including with respect to any actions or outcomes of use of Tonkean's A.I. Bot. Nothing addresses hallucination in either direction. Searched the LegalWorks page, the security page, the pricing page, the DPA and the customer terms on 4 September 2026; docs.tonkean.com and the AI handbook were not opened.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The control structure is real and set by the customer. Legal teams write response rules defining what the AI can and cannot answer directly, validation workflows route sensitive answers through legal before they reach business users, the AI escalates questions that need a lawyer, and every AI interaction is logged and reviewable by legal. Agents handle repeat requests from the team's playbooks and leave judgement calls and exceptions with the lawyers. What sits outside the customer's own configuration is not published: the vendor states no limit of its own on what the AI may answer unreviewed, no threshold at which it stops, and nothing on what happens after a wrong answer reaches a business user. Verified 22 September 2026.
The division between what runs alone and what reaches a person is published clearly, and the threshold that decides it is the customer's rather than the vendor's. What runs unattended is stated: simple requests such as NDAs and statements of work are auto-handled, urgency is identified on every inbound request, and more complex matters including conflict waivers, intellectual property questions and outside counsel engagements are auto-routed to the right person or practice group. The control structure around it is real, with approval paths and risk tiers mapped to the department's policy, intake forms that adapt by risk level and matter type, and a full audit trail of actions and approvals. What holds this off the top band is that the thresholds are configured by the customer rather than published by the vendor, so a buyer cannot learn from the material what the system will do by default. No confidence signal, no abstention state and no described behaviour where the model misclassifies a request appears anywhere.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named legal departments, dated, with figures a reader can check. The Taskrabbit case study of 30 April 2026 reports that within about three and a half months of launch the legal team logged 297 interactions through Slack, of which 211 were escalated to legal and 86 were resolved by AI, running on eight intake forms, and quotes the company's Principal Counsel on adoption. The Narvar study of 26 November 2025 describes a migration of more than 10,000 contracts with the data extracted for legal, finance and the deal desk, and the M42 study of September 2025 describes CLM templates completed automatically from intake forms. The headline figures on the home page, up to 75 per cent faster responses and more than eight hours saved per attorney each week, carry no customer or method. Verified 22 September 2026.
Substantial evidence exists for the platform and very little of it is legal. The logo wall on the LegalWorks page runs to twenty enterprises including Google, Lenovo, AbbVie, Workday, Cisco and Intuit, but it is headed trusted by enterprises like and is the same strip used across the site rather than a LegalWorks customer list. The headline figures are unattributed and carry no stated basis: 50 per cent cycle time reduction, 99 per cent of customers reporting higher adoption, 30 employee hours saved weekly, 7.7 billion steps automated annually. Of the three attributed quotes, two are procurement rather than legal, from the Head of Global Procurement at Semrush, who supplies the only hard figure at a cycle time of 19 days falling to 10, and the Head of Procurement at Cockroach Labs. The legal quote is from Mary O'Carroll, identified as former President of CLOC and Head of Legal Operations at Google, and speaks to Tonkean generally rather than to LegalWorks. A customer showcase exists and was not opened. On this record the deployment evidence for the legal product is thinner than the page's overall impression suggests.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Specific commitments cover the model provider and little else. The security page says no data is stored with any language model provider used for processing and that data is processed and immediately discarded there, names data residency options in the US, EU and UAE, and describes SAML SSO, IP allow-listing and audit logs; the AI Assist page describes document-level permissions separating business-facing from internal legal content. No customer agreement is published, so none of this can be read as a term, and nothing addresses whether Coheso itself trains on customer content, how privileged material is treated, or how long Coheso keeps documents. The Privacy Notice, last modified 8 December 2025, reserves use of information to improve the Service and to analyse its accuracy. Verified 22 September 2026.
The marketing addresses privilege directly and the agreement excludes the material it would protect, which is the gap this axis exists to surface. The LegalWorks governance section is the strongest privilege language in the pull: an audit trail of all actions and approvals presented as helping preserve attorney-client privilege, comprehensive role-based access control and ethical walls, item-level data retention and legal holds. Against that, the customer terms provide that User Content shall not be deemed information acquired by Tonkean, which removes customer content from the contractual confidentiality obligation entirely and refers it instead to the Security section, where Tonkean states it cannot fully ensure or warrant the absolute security and privacy of User Content or personal information. So the confidentiality commitment a buyer can actually enforce over its matter material is materially thinner than the product page implies. Two provisions point the other way and are recorded: Tonkean shall have no right in the User Content beyond the minimal rights required to facilitate use of the Platform and shall not use it for any other purpose, and the DPA bars Tonkean from deriving rights or benefits from Personal Information. Where marketing and agreement conflict the agreement governs, which is why this sits here rather than higher.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
Checked the home page, the AI Assist, security, ROI and privacy pages and the Taskrabbit case study on 22 September 2026. Nothing states that answers given to business users are not legal advice, who may rely on them, or how the product supports the legal team's professional supervision duties, and no customer terms are published where such a statement would usually sit. The product gives employees who are not lawyers answers to legal and compliance questions; the controls the legal team can set over those answers are real and are described under oversight, but they are product settings rather than a position on the advice line. Verified 22 September 2026.
A boilerplate disclaimer sits in a general agreement while the product is marketed in advice-adjacent terms. The customer terms state that the Service provides ideas, suggestions, analyses and other data for informational purposes only and not as advice, and disclaim responsibility for any information provided by the Service. That is a real sentence but a generic one, drafted for a business management platform rather than for a legal product, and the agreement carrying it was last updated May 2019, before LegalWorks and every agent now sold. Against it the marketing describes agents that handle complex contract analysis and negotiation strategies, and an AI Front Door that answers employees' legal questions directly. The audience limits the exposure and is stated plainly: the buyer is a corporate legal department and the requesters are its own employees, so there is no consumer surface and no unlicensed practice question of the ordinary kind. What is absent is everything above the disclaimer: no rule of professional conduct or bar guidance named, no jurisdiction limit, and nothing on how a legal team supervises an agent that answers a business question without a lawyer seeing it.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Governance is described as something the customer runs, not something Coheso publishes about itself. Response rules, validation workflows, audit trails for every AI interaction and usage analytics give the legal team the means to watch and correct the AI, and a report shows which questions it cannot yet answer. No governance framework, accountable owner, pre-release testing regime or bias finding of the vendor's own is published. Checked the home page, the AI Assist, security and privacy pages on 22 September 2026. Verified 22 September 2026.
No governance position for the vendor's own models was located, on a product whose agents act on matters without a lawyer in the loop for simple requests. There is no responsible AI page, no principles statement, no named owner accountable for model behaviour, no pre-release evaluation or testing regime, and nothing at all on bias, including nothing on whether triage and classification perform evenly across request types, business units or languages. That last gap matters here specifically, because the product's core function is deciding which requests are simple enough to resolve without a lawyer. The security page is thorough and entirely about information security, which the axis definition treats as a different subject and which is graded on the stewardship row rather than counted twice. An AI handbook page exists in the navigation, headed with questions about what an agent is and when one counts as an enterprise agent, and it was not opened; it is named here as the one surface that might carry governance material. Searched the LegalWorks page, the security page, the pricing page and the site navigation on 4 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Most of the ground is covered on published pages. The Privacy Notice names where customer documents and logs are stored, on Amazon Web Services S3 and RDS, and names the other processors, including the Azure OpenAI Service for language model features and Adobe's PDF viewer; the security page adds zero retention at the model provider, SAML SSO, IP allow-listing, audit logs and residency options in the US, EU and UAE; and the trust centre carries a subprocessors section and offers a SOC 2 report and a penetration test report on request. What is missing is a stated retention period, since the notice keeps information for as long as the Service is used and a reasonable time after, and any stated incident or breach notification practice. Verified 22 September 2026.
Almost the whole set is published and one limb is soft. Retention is customer-controlled at unusual granularity, with item-level policies definable down to the field so data is held only as long as a given process needs, and the DPA adds that within 60 days of termination Tonkean will delete or return all Personal Data at the customer's choice and delete existing copies, retaining one copy only where law requires. Access control is described as comprehensive role-based control across data access and process creation, encryption is AES-256 at rest and in transit, and non-repudiation audit logs capture all edits and processed transactions. The sub-processor position is fully published rather than promised, naming each provider, its function and its country. Incident practice exists but is the weak limb: Tonkean commits to notify without undue delay after becoming aware of a Data Incident, with no stated clock, and the same clause bars the customer from publishing anything identifying Tonkean about an incident without prior written approval unless legally compelled, which is worth a buyer's attention.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Checked the home page, the security, AI Assist, ROI and privacy pages and the site footer on 22 September 2026. No customer agreement, terms of service or subscription terms are published, so nothing states who bears the loss when an AI answer or draft is wrong: no indemnity, cap, warranty or remedy was located. The Privacy Notice disclaims liability for disclosure of information through transmission errors, third-party access or causes beyond the company's control, which concerns data security rather than the product's output. Verified 22 September 2026.
Liability is addressed only through a limitation clause, and that clause disclaims the exposure the AI creates by name. The cap is short: aggregate liability may not exceed the consideration actually paid in the three months preceding the cause of the claim, against the twelve months more common in this corpus. Excluded damages are broad, covering loss or corruption of data, lost profits and pure economic loss. There is no indemnity running to the customer at all; the only intellectual property remedy is that Tonkean may at its sole discretion procure a licence, modify the Platform or terminate and refund the post-termination period, with the agreement stating that no other rights or remedies will accrue. The indemnity that does exist runs the other way, from customer to Tonkean. The warranty is repair-or-replace for material errors preventing ordinary use and expressly does not extend to any actions or outcomes of use of Tonkean's A.I. Bot. No insurance position was located. The dating is the sharpest fact: the agreement was last updated May 2019, so the instrument governing a 2026 agentic legal product predates it entirely and mentions AI once, to disclaim it.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Named integrations exist and some of their behaviour is described. Requests are captured from Slack, Microsoft Teams, Gmail and Outlook with their context, and legal's responses sync back to the original thread; documents connect through Google Drive and SharePoint; Docusign and CLM connectors are listed; and the M42 case study describes intake form fields passing to the customer's CLM to generate standard agreements automatically. No integration documentation is published describing what each connector moves, in which direction, or what a team must configure. Verified 22 September 2026.
Real integrations into the systems legal work lives in, named individually, with direction described in outline rather than in depth. The legal-specific connections are the ones that count and they are named: Ironclad for contract lifecycle management, TeamConnect for matter management, SimpleLegal for legal spend, alongside DocuSign and Adobe Sign for execution and SharePoint for documents. The wider set covers Salesforce, ServiceNow, JIRA, Slack, Microsoft Teams, email, Coupa and SAP, and the product's stated architecture is an orchestration layer across them rather than a destination to migrate into. Direction of travel is described at summary level, with contracts syncing from CLM to e-signature, approvals routed through email and chat, data pulled from billing systems and coordination with outside counsel platforms. What is missing for the top band is configuration detail: nothing published on the pages read states what a legal team must set up, what fields map, or what an integration requires. A public integration library and developer documentation both exist and were not opened; they are the cheapest available upgrade on this record.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The residency options are named and the processing location is not. The security page offers data residency in the US, EU and UAE, and the trust centre lists an architecture diagram for each region, available on request. The Privacy Notice says customer documents and logs are stored on Amazon Web Services and that language model features run on the Azure OpenAI Service, without stating which region processes a customer's prompts, and it separately says information collected through the Service is stored and processed in the United States, which the regional options qualify without resolving. The tenancy model is not stated. Verified 22 September 2026.
The tenancy picture is published in full and the region menu is not. Three options are described with what separates them: a Tonkean-managed multi-tenant public cloud on AWS, a single-tenant dedicated cloud not shared with other customers and also managed by Tonkean on AWS, and self-hosting in the customer's own environment on AWS, Azure or Google Cloud. The pricing page states which tier each sits in, with multi-tenant included and dedicated, customer-cloud and on-premises available on the enterprise plan at additional cost, so what changes between tiers is answerable. Processing location is establishable from the DPA rather than the marketing: every sub-processor is listed as United States except Tonkean Israel Ltd., and Schedule 2 incorporates the 2021 Standard Contractual Clauses with UK and Swiss addenda for transfers out of the EEA. What is absent is a published region choice for the managed offering, and no page states where data is stored as distinct from where it is processed.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
A named attestation with a request route. The security page states SOC 2 Type II, with annual independent audits over a full-year observation period, and independent penetration testing of the web application and infrastructure. The trust centre lists a SOC 2 Type II report, a penetration test report and regional architecture diagrams behind an access request, with the privacy policy open to view. The auditor, the report period and the scope are not stated on any page read. Verified 22 September 2026.
Certifications are real, named and scoped, and the evidence behind them is reachable only by customers. The security page states SOC 2 Type 2 compliance, independently audited, in accordance with the AICPA Trust Services Principles and Criteria and named to security, availability and confidentiality, so the scope is published rather than implied. ISO/IEC 27001:2022 is stated as achieved, with the standard version given. A HIPAA compliance page sits alongside them. Three things hold this off the top band. No auditor is named, no audit period or report date is given for either attestation, and access to the reports is expressly limited to existing customers, with the page inviting a customer to ask the team for the latest report. That is narrower than a sales gate: a prospective buyer evaluating the product has no route to the evidence at all, which is the condition the top band exists to distinguish. There is no trust portal, and the badges displayed are the certification marks themselves rather than unsupported logos.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The provider is named: the Privacy Notice says language model features use OpenAI's GPT models hosted on the Azure OpenAI Service, and the security page says no data is stored with any model provider used. The specific models and versions are not named, where the Azure processing runs is not stated, and no commitment to notify customers of a model change is published. Verified 22 September 2026.
The providers are named with their function and location, the change commitment is contractual, and the models themselves are not identified. Schedule 1 of the published DPA lists each sub-processor with a described service and a country: Microsoft Azure for AI LLM engine services, OpenAI, LLC for AI and machine learning powered product features, and Google Cloud Platform for OCR services, all in the United States, each marked opt in, alongside AWS for cloud storage, Elastic.co for the hosting index database, SendGrid for email and Tonkean Israel Ltd. as an affiliate sub-processor. Change notification is not a promise but a term: Tonkean shall notify before authorising any new sub-processor, the customer has seven days to object, and unresolved objection allows termination of the affected services. What fails is model naming. Azure and OpenAI are providers, not models, and no model or version is identified anywhere, so a buyer cannot establish which model reads a legal request. Provider identification and model naming are separate limbs of the top band and only one is met.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Checked the home page, the platform pages, the ROI calculator, the security page, the privacy page and the footer on 22 September 2026. No price, tier, unit of charge or package structure is published; the ROI calculator estimates the value of time saved without stating what the product costs, and every route to a figure is a demo request. Verified 22 September 2026.
The unit and the structure are published with real rigour and no figure appears anywhere. Charging is on Monthly Tracked Users, and the definition is unusually precise rather than gestural: an MTU is a unique person who in a calendar month submits a form, accesses a workspace app, submits or replies to an item in Slack or Teams, sends or replies to a Tonkean email, or engages by clicking a button or updating an item. The vendor states expressly that MTUs are not named seats and are not a count of records processed, that actions per tracked user are unlimited once counted, and that billing rests on the average MTU across the subscription year so that busy months even out. The quote is built from three components, the platform with unlimited workflows and connectors, the MTU volume, and optional deployment and services, and the hosting and support tiers are itemised with what each includes. No price, band, minimum or term is published and every route ends in a scheduled discussion. A buyer can therefore model the shape of the bill precisely and cannot learn what it costs.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
The buyer is stated precisely: in-house legal and compliance teams, across industries the site names, including healthcare, technology, finance, chemicals, cybersecurity, beauty and wellness, and manufacturing. The work covered is clear from the product and case study pages: intake and triage of business requests, NDAs, MSAs, DPAs, vendor and marketing reviews, employment questions, contract generation and contract data migration. What the product does not cover is not stated, and nothing addresses team size or use outside in-house legal. Verified 22 September 2026.
The buyer and the work are described with substance and the edge of the product is left open. The segment is unambiguous: corporate and government in-house legal departments at enterprise scale, with the material addressed separately to three audiences that a legal operations buyer would recognise, being employees raising requests, the legal team itself, and cross-functional stakeholders in procurement, sales and IT. Practice coverage is expressed as the request types the product handles rather than as practice groups, and the list is specific: NDAs, statements of work, contract review, conflict waivers, intellectual property questions, outside counsel engagement, legal mailroom and email triage, and matter intake generally. Company-size evidence is real, with the customer set drawn from Fortune 500 and Fortune 200 enterprises. What is not stated is where the product stops. Nothing addresses law firm use, no minimum department size is given, no jurisdiction or language coverage is published, and no request type is identified as unsuitable for automated handling.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No agreement that governs the product could be read: no customer agreement, terms of service or subscription terms are published. Checked on 22 September 2026, the home page, security page, AI Assist page, ROI page, Privacy Notice and trust center listing state no position on whether Coheso trains on customer content. The security page says no data is stored with any language model provider, which concerns retention at the provider rather than training, and the Privacy Notice reserves use of information to improve the Service and analyze its accuracy without naming training.
The silence here is of the second kind: a published agreement exists and grants no improvement right over customer content at all, rather than granting one that stops short of naming training. Nothing published names training in either direction, and two clauses constrain use tightly without naming it. The customer terms provide that Tonkean shall have no right in the User Content except for the minimal rights required to facilitate use of the Platform, and shall not use the User Content for any other purpose.
The DPA adds that Tonkean shall not have, derive or exercise any rights or benefits regarding Personal Information processed on the customer's behalf and may use it solely for the purposes for which it was provided. Both would exclude training as a matter of construction, and neither says so. Pointing the other way, the DPA lists rendering Personal Data fully anonymous and non-identifiable among the permitted processing purposes, with no statement of what may then be done with the result.
Under the naming test an unnamed clause is not evidence about training in either direction, so the honest value is the absence with the clauses recorded. One further fact belongs on the row: the LLM sub-processors, Microsoft Azure and OpenAI, are marked opt in, so a customer that does not opt in has no model processing its content at all.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
The security page says nothing is stored with any language model provider and that data is processed and immediately discarded there. Coheso itself keeps customer documents and logs on Amazon Web Services and logs every AI interaction for audit, and the Privacy Notice keeps information for as long as the Service is used and a reasonable time after. No retention period is stated for what a user submits to Coheso, and no customer setting to shorten it is described.
Retention is configurable by the customer at a finer grain than most products offer. The security page states that item-level data retention policies let a customer define specific retention lengths down to the field level so that sensitive data is available only as long as each process needs, which puts the period in the customer's hands rather than the vendor's. The DPA supplies the end-of-life position: within 60 days of termination Tonkean will delete or return all Personal Data at the customer's choice and delete existing copies, retaining one copy only where law authorizes or requires it for legal claims.
What is not offered is a stated zero-retention option for prompts and model outputs specifically, and nothing distinguishes the retention of a request record from the retention of the model exchange that resolved it. No default period is published for a customer that configures nothing.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The AI Assist page describes Coheso's own permission model over the knowledge base: document-level access controls keep business-facing and internal legal content separately scoped, and AI responses draw from the knowledge base with that access control applied. The legal team sets and maintains the permissions; nothing published maps them to matters, and no inheritance from a document management system's access model is described.
Ethical walls are named as a product capability and no separation model is described. The LegalWorks governance section lists comprehensive role-based access control and ethical walls together as a single bullet, alongside full audit logs and item-level retention, and the security page describes RBAC in general terms as ensuring every permission from data access through process creation is secured. Neither states how a wall is defined, at what level it operates, whether it applies to matters, clients or business units, who administers it, or what a walled user sees.
Tenant-level separation is a different question and is answered well, with a single-tenant dedicated cloud and a self-hosted option both published, but tenancy separates customers from each other rather than matters within one legal department. Naming a control without describing it is what this value records. Product documentation at docs.tonkean.com was not opened and may describe the mechanism.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
The Privacy Notice, last modified 8 December 2025, lists assisting law enforcement and responding to subpoenas among the uses of information, and says information may be disclosed to comply with law, to cooperate with government or law enforcement officials or private parties, and to respond to claims and legal process. No commitment to notify the customer, and no reservation of a discretion to do so, was located, and no customer agreement is published.
Both limbs are met, and the reporting limb is met more fully than anywhere else located in this pull. On notice, the DPA provides that where processing is required by law or by a court or governmental authority, Tonkean shall inform the customer of the legal requirement before processing unless prohibited on important grounds of public interest. Schedule 2 Part 4 goes considerably further for cross-border transfers: on becoming aware that a government authority seeks access, Tonkean will tell that authority the customer has not authorized disclosure and that demands should be served on the customer instead, will use commercially reasonable legal mechanisms to challenge the demand, and will notify the customer as soon as possible after any emergency access.
On reporting, once in every twelve-month period and on written request Tonkean will inform the customer of the types of binding legal demands for personal data it has received, expressly including national security orders and directives and any process issued under section 702 of the US Foreign Intelligence Surveillance Act. Tonkean also commits to resist bulk surveillance requests. The reporting is on request rather than published, which is the one qualification worth carrying.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Checked the home page, the AI Assist page and the security page on 22 September 2026. The AI answers from the customer's own contracts, policies and guidance documents, and no body of primary law is identified behind its output.
The material the models read is the customer's own, and it is identified as such. Published descriptions state that the AI Front Door trawls the data sources the customer has given it access to, and that agents draw on connected enterprise systems including contract lifecycle management, billing, document stores and chat. No external corpus is involved: the product does not retrieve primary law, published precedent or any licensed third-party dataset, and none is named anywhere.
There is accordingly no licensing question of the kind this signal was written for and no jurisdictional coverage statement to record. Searched the LegalWorks page, the platform navigation, the security page, the pricing page, the DPA and the customer terms on 4 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Checked the home page, the AI Assist page and the security page on 22 September 2026. Answers cite the customer's own documents, and nothing addresses checking legal authority for subsequent history.
Nothing on any located surface addresses checking authority for subsequent history, and the product does not retrieve or present primary law. LegalWorks routes and resolves internal legal requests and generates operational documents such as NDAs and statements of work; no case, statute or regulation is surfaced to a user at any point in the published workflow. The question does not bite on this product class and the value records the honest absence rather than a shortcoming. Searched the LegalWorks page, the security page, the pricing page and the agreements on 4 September 2026.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
The home page says the AI decides for each request whether it can be answered from source documents or needs escalation, and the AI Assist page says it escalates automatically when a question requires legal review, routes answers on topics the legal team has flagged through legal validation first, and reports which questions it cannot yet answer so the team can fill the gap. No published evaluation shows how often it declines or escalates.
A routing rule is published and no uncertainty behavior is described. The product states that it autonomously resolves simple requests and routes more complex ones to the correct workflow, person or practice group, naming conflict waivers, intellectual property and outside counsel engagements as the kind that escalate, and it identifies the urgency of every inbound request. That is a real deferral mechanism, and it is recorded here as what exists, but it sorts by request complexity as configured by the customer rather than by the model's own confidence in its answer.
Nothing describes what happens when the model cannot classify a request, misreads one, or produces a draft it has insufficient grounding for; no confidence score, no abstention state and no no-answer condition is surfaced to the requester or to the legal team. The gap has practical weight because the requester in this product is a business employee rather than a lawyer, so an unflagged wrong answer may never reach legal at all.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
Searched the AI Hallucination Cases database maintained by Damien Charlotin on 22 September 2026 for Coheso, and no recorded case was returned. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product.
The AI Hallucination Cases database maintained by Damien Charlotin was searched on 4 September 2026 on the product name LegalWorks and on the company name Tonkean. No court order, opinion or disciplinary record naming the product or the company was located. This records the state of the public record on that date and is not a finding about the product. The signal also sits at an angle to this product class, since LegalWorks routes internal requests and generates operational documents rather than legal citations, so a fabricated citation is not the failure mode it would ordinarily produce.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Checked the home page, the AI Assist, security, ROI and privacy pages and the Taskrabbit case study on 22 September 2026. No material refers to lawyers' professional or ethical obligations or names any ethics opinion.
No bar authority, regulator, conduct rule or ethics opinion is named on any located surface. Nothing on the LegalWorks page, the security page, the pricing page, the DPA or the customer terms engages professional regulation, and no jurisdiction-specific guidance is mapped. The nearest published language is the customer terms' statement that the Service provides analyses for informational purposes only and not as advice, which is a disclaimer rather than an engagement with any professional standard.
The absence is worth noting against the product's own privilege claim: the LegalWorks page frames its audit trail as helping preserve attorney-client privilege, which is a professional responsibility concept, and no source of that standard is cited anywhere.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The product is bought by in-house legal teams whose work bills no client, so no fee between a lawyer and a client is touched. The savings Coheso claims are aimed at the buyer's own cost: responses up to 75 percent faster, more than eight hours saved per attorney each week, and an ROI calculator estimating hours recovered and reduced outside counsel spend.
Efficiency claims are published and the billing question is not reached, in part because this product sits on the wrong side of it. The claims are prominent and unattributed: a 50 percent reduction in cycle time, 30 employee hours saved each week, and a named legal operations endorsement referring to millions of dollars saved. Nothing addresses what happens to a bill when work compresses, and no per-matter record of AI-assisted work is described as available for that purpose.
The structural point is worth recording as an edge rather than a defect. The buyer here is an in-house legal department, which pays outside counsel rather than billing a client, so the compression this signal was written to catch does not arise in the ordinary way. The product does coordinate outside counsel engagement and pulls data from billing systems, so a partial grip exists, but nothing published connects automated handling of a matter to what the department is billed for it.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The Privacy Notice names the processors that handle customer material, including Amazon Web Services for documents and logs, the Azure OpenAI Service for GPT-based features, Adobe's PDF viewer, Frontegg for user management, and Vercel and Render for analytics, and the trust center carries a subprocessors section beside a SOC 2 report and penetration test report available on request. No client-facing disclosure pack on AI use is published.
All three limbs are met from a single published document. The Data Processing Addendum is public and ungated, and Schedule 1 carries a full sub-processor table naming each provider, the service it performs and its country, including the AI entries specifically: Microsoft Azure for AI LLM engine services, OpenAI, LLC for AI and machine learning powered product features and Google Cloud Platform for OCR, all United States and all marked opt in.
So the model provider question is answerable in the affirmative rather than by naming infrastructure. The forwardable artifact is the DPA itself, drafted to be given to a counterparty and incorporating the 2021 Standard Contractual Clauses with UK and Swiss addenda. Change notification is contractual, at notice before authorizing any new sub-processor with a seven-day objection window and a termination remedy. The direction of this signal inverts on an in-house product, since the buyer is the client rather than the firm, but the artifacts a counterparty would ask for are published and complete.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Every AI interaction is logged with its cited sources and can be reviewed by legal, and responses are logged and searchable. No export of a per-document record covering the model used, the sources and the human check is described, and no disclosure guidance is published.
A substantial record exists and nothing states that it distinguishes model work from human work. The security page describes non-repudiation logs capturing full records of all edits to solutions and enterprise components and all processed transactions in test and production, and the LegalWorks governance section commits to an audit trail of all actions and approvals framed as supporting audit readiness and the preservation of attorney-client privilege.
That is more than most records in this corpus publish and it is why this sits above the floor. What is missing is the AI-specific half. Nothing says the log identifies which requests were resolved autonomously by an agent rather than by a person, no model or version is attributed to a generated document such as an NDA, and no export route for the audit trail is described for a regulator, an auditor or a court. Product documentation was not opened and may describe the log's export format.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Primary Law Corpus Provenance
- Good Law Verification
- Bar Guidance Alignment
Which one fits
Choose Coheso if
- You want business users' questions answered from your own approved material. Coheso's AI Assist answers from the contracts, policies and guidance the legal team curates, cites the source passages, and routes topics the team has flagged through legal validation first.
- You want evidence from a legal team like yours. Coheso's dated Taskrabbit case study reports 297 interactions through Slack in about three and a half months, with 211 escalated to legal and 86 resolved by AI, and its Narvar study describes a migration of more than 10,000 contracts.
- You need to know which model reads requests and where data sits. Coheso names OpenAI GPT models on the Azure OpenAI Service, states that nothing is stored with the model provider, stores documents on Amazon Web Services, and offers data residency in the US, EU or UAE.
Choose Tonkean LegalWorks if
- Your legal work spans Ironclad, TeamConnect, SimpleLegal and DocuSign. LegalWorks orchestrates matters across named systems, syncing contracts from lifecycle management to electronic signature, routing approvals through chat and email, and pulling data from billing and outside counsel platforms.
- You need a dedicated or self hosted deployment. LegalWorks is offered on a shared cloud, a single tenant dedicated cloud, or in your own AWS, Azure or Google Cloud environment, with retention set by your team down to the field level.
- You want the AI supply chain and government demands handled in a published contract. Tonkean's data processing addendum names its AI subprocessors, which a customer must opt into, gives seven days to object to a new one, and commits to challenge government demands and report yearly on those received.
In summary
Coheso
Coheso, from Coheso, Inc. of New York, is an AI front door and work management platform for in house legal and compliance teams. Requests arrive through Slack, Microsoft Teams, Gmail, Outlook or intake forms; AI triages and routes them, AI Assist answers business users from a knowledge base the legal team curates with citations to the source passages, and agents built on the team's playbooks handle recurring reviews and first drafts. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes, with an A on outcome evidence. It names OpenAI models on Azure and offers US, EU or UAE data residency. As of 22 September 2026 the index located no customer agreement, retention period or price.
Tonkean LegalWorks
Tonkean LegalWorks, one of three solutions from Tonkean Inc. of Palo Alto, is matter lifecycle management for in house legal departments that meets employees in Slack, Microsoft Teams, email or a portal. Its AI Front Door answers simple requests and routes the rest into adaptive intake, and packaged agents handle NDAs, contract work, conflict checks and legal mailroom triage, all configured with no code tools. The AI Legal Index grades it in the top two bands on nine of fifteen capability axes. It publishes a data processing addendum naming its AI subprocessors, offers shared, dedicated or self hosted deployment, and prices on monthly tracked users. As of 4 September 2026 the index located no accuracy measure, named model or price figure.
Questions buyers ask
Coheso vs Tonkean LegalWorks: which is better for a legal front door?
The grid barely separates them: Coheso sits in the top two bands on ten of fifteen AI Legal Index capability axes and Tonkean LegalWorks on nine of fifteen, identical on nine. Coheso shows its sources and names legal customers with dated results. LegalWorks publishes deeper contract terms on subprocessors and government demands, more deployment options and its pricing unit. Large enterprises needing self hosting have more to read from Tonkean.
Which AI models do Coheso and Tonkean LegalWorks use?
Coheso's privacy notice names OpenAI GPT models hosted on the Azure OpenAI Service, and its security page says no data is stored with the model provider. Tonkean's data processing addendum names Microsoft Azure for language model services, OpenAI for AI features and Google Cloud for OCR, each marked as something a customer opts into. Neither names a specific model or version. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
How is Tonkean LegalWorks priced?
By monthly tracked users, a published unit: a unique person who in a month submits a form, opens a workspace app, replies in Slack or Teams, answers a Tonkean email or clicks to approve something. Once counted, their use that month is unlimited, and billing rests on the yearly average. No figure is published. Coheso publishes no price, tier or unit. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What does Tonkean do if a government demands customer data?
Its data processing addendum commits Tonkean to tell the customer before complying with a legal requirement unless barred, to tell an authority seeking access that demands should go to the customer, to challenge demands through commercially reasonable legal means, and to report yearly on request the types of demands received, including national security orders. Coheso's privacy notice allows disclosure to respond to subpoenas with no notice commitment. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What do Coheso and Tonkean LegalWorks both leave unpublished?
Any measure of accuracy and any position on professional duties. Neither publishes an error rate or evaluation for its triage and answers, and neither addresses what business employees may rely on without a lawyer or how a legal team supervises AI answers given directly to them. Neither names bar guidance on AI, and neither publishes a price figure. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Three readings to weigh. Tonkean's customer terms were last updated in May 2019, before LegalWorks existed; they cap liability at three months of fees, exclude outcomes of its AI from the warranty, and exclude customer content from the confidentiality clause, while its data processing addendum is more protective. Coheso publishes no customer agreement, so its commitments sit on product and security pages. Tonkean's logo wall and figures cover its whole platform rather than LegalWorks alone. Coheso was verified on 22 September 2026 and Tonkean LegalWorks on 4 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.