Conga CLM vs Docusign CLM: how they compare in 2026

C
Conga CLM profile
D
Docusign CLM profile
Last verifiedOctober 8, 2026

Each of these is the contract product inside a larger commercial suite, Conga's built around quoting and pricing and Docusign's around electronic signature. Both serve sales and procurement teams as well as legal, name their AI suppliers by function and connect deeply to Salesforce. Their AI terms differ on training. Conga keeps any training on customer data inside a model for the customer's own tenant and bars third parties from training on it. Docusign licenses training on anonymized CLM data across customers unless the customer opts out. Conga shows more of its reasoning in the product. AiMe explains how each suggestion was made and puts a confidence score beside it. Conga's terms add that AI output must never be the only basis for a legal decision. Docusign publishes more of the paperwork around the AI. Its hosting countries, government authorizations naming CLM, charging units and master services agreement are all public, and four customer stories carry figures. Both AI addenda disclaim warranties on AI output.

At a glance

Category
Conga CLMContract Review & Drafting
Docusign CLMContract Review & Drafting
Founded
Conga CLM2006
Docusign CLMNot published
Headquarters
Conga CLMBroomfield, Colorado, United States
Docusign CLMSan Francisco, California, United States
Last verified
Conga CLMOct 8, 2026
Docusign CLMOct 8, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Conga CLM
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AiMe is described as a shared AI layer running across the whole commercial suite. It connects workflow data across CPQ, CLM, price optimization and document automation and suggests next steps, rather than being the CLM itself. Underneath sits a full contract lifecycle platform that long predates it, with template and clause library generation, approval routing, negotiation, electronic signature through Conga Sign, a searchable repository, obligation and renewal tracking, and reporting. The models drive core features on top of that platform. Without AiMe a working CLM remains, as the edition built on Salesforce was for years. Recent releases push AI further in. The June 2026 release is described as enhanced by AI throughout, and bulk import and extraction is presented as the way contracts enter the system. The March 2026 AiMe release adds agents that act inside quoting and contracting workflows. Conga still sells and prices the platform as a contract system with intelligence on top.

Docusign CLM
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The core of CLM is a workflow and document system. It generates contracts from templates, keeps a clause library, and stores agreements in a repository with reporting. A drag and drop workflow designer offers more than 100 preconfigured steps for generation, review, approval, signature and storage. That system dates from SpringCM, which Docusign agreed to buy in 2018, before generative AI was part of it. AI now drives several core functions. More than 100 pretrained models extract and report on contract data points and legal topics. AI-Assisted Review flags nonstandard clauses and suggests redlines against a playbook. Generative features summarize agreements, draft clauses on request and answer questions about the repository. Docusign brands the engine Iris and describes it as trained on decades of contract data. Workflows can start from analytics, risk scores and contract content, so extracted data drives routing as well as lookups in the repository.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Conga CLM
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Conga's trust center names each part of the AI pipeline. Google Cloud Vision handles optical character recognition, Amazon Textract table detection, Zuva provision extraction and Azure OpenAI language processing. Output is grounded in the customer's own repository, playbook and clause library, and extraction needs no model training by the customer. AiMe shows how every recommendation is generated, with the reasoning visible and confidence scores wherever it makes a suggestion. The Artificial Intelligence Addendum addresses accuracy only through a disclaimer. It states that outputs may be inaccurate, incomplete or misleading and disclaims any warranty of accuracy or completeness. Conga publishes no accuracy figure, test set, error rate or benchmark result. It says third party models are benchmarked before release, and publishes no results. The product cites no legal authority, so grounding in authority and citator checks do not apply.

Docusign CLM
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Docusign describes Iris as delivering accurate, secure and trusted agreement intelligence. Its AI Trust page says AI outputs have been tested for accuracy, and that diverse datasets and checks correct skewed outputs before release. Docusign publishes no figure, error rate, test set or evaluation method for CLM extraction, AI-Assisted Review or agreement summaries. The numbers it gives for the review product are time savings, such as 72 to 80 percent saved on contract reviews, with no stated baseline. Section 6.2 of the AI Attachment for Docusign Services, version 8 July 2026, warns that the AI may produce incorrect output, given the probabilistic nature of machine learning. The same section places review for accuracy on the customer. CLM works from the customer's own contracts and clause library rather than from law. Docusign does not describe how a summary or an answer links back to the clause it came from.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Conga CLM
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a lawyer checks it are all published: modes, thresholds, review surfaces, and the route a matter takes back to human judgment. A categorical limit on a named mode or tier, stating what its output may not be used for, meets the threshold limb without a number.

Conga states that AiMe never acts autonomously on high stakes decisions. Three mechanisms constrain it, agent guardrails, approval thresholds and human in the loop confirmation, and each can be built into a workflow. AiMe shows how every recommendation is generated and the reasoning behind AI driven actions. Confidence scores appear wherever it makes a suggestion, users accept or reject redlines, and every action and approval is kept in an audit trail. Much of the oversight model is written into the contract. The Artificial Intelligence Addendum makes the customer solely responsible for evaluating and validating outputs. It says the customer must not rely on AI outputs as the sole basis for any decision with legal, financial, regulatory or other material impact. It also requires human review and independent judgment, and puts authorizing and supervising agent actions on the customer. The guardrails and thresholds are described as configurable rather than as defaults, and the same document states that Conga does not monitor or review AI generated outputs.

Docusign CLM
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

AI-Assisted Review suggests edits and flags risky language for a reviewer to accept or reject. CLM workflows send agreements with nonstandard terms to review under conditional rules the customer sets, and they can also be triggered automatically by analytics, risk scores and contract content. Every action sits in an audit trail of who did what and when, with version control across drafts. Section 6.2 of the AI Attachment makes the customer responsible for reviewing and evaluating AI output for accuracy and suitability, including through human review. The AI Trust page says the customer has the final say to approve outputs. Docusign does not set out what an AI step may do without a person, at what confidence an extraction is held for review, or what happens after an AI output is found to be wrong.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Conga CLM
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Conga's customer story library carries dated, named accounts. The one about Conga CLM describes Cotality, formerly CoreLogic, improving its client service with Conga CLM, and is dated 5 September 2024. It carries no figure. Two other dated stories, DigiKey on price management and Kalixia at 160 times faster document generation, concern other Conga products. Customer logos on the product and pricing pages include Southwest Airlines, LinkedIn, AXA, Peloton, Cotality, T-Mobile, Adobe, Box and Kraft Heinz. The figures Conga publishes sit apart from any named customer. A 9 percent revenue increase appears beside the logo strip with no stated basis, and the features page claims 50 percent less review time with AI. Three headline counters on the product page display as zeros. Conga also cites G2 Leader recognition across five grids.

Docusign CLM
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

The CLM page carries four customer stories, each naming the customer, giving figures and quoting a named, titled speaker. T-Mobile Wholesale cut agreement time by 44 percent without adding headcount, with 1.8 times faster cycle time on high value agreements, says Janet Sutherland, Senior Manager of Sales Enablement. Genuine Parts Company runs more than ten use cases across five departments, quoted by Keith McCarraher, Special Projects Manager. Vestwell reports agreement packages built in 5 minutes instead of 75 and 70 percent fewer drop offs, quoted by its COO, Jon Mark. At iCIMS, 78 percent of the company's agreements need no legal involvement, according to Courtney Dutter, Deputy General Counsel. The page also states a 449 percent return on investment, an 85 percent reduction in errors and 2,200 enterprise CLM customers, without naming the study or the customers behind those figures. No story gives a deployment date or a measurement method.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Conga CLM
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Under the Artificial Intelligence Addendum, Conga will not use AI Inputs or AI Outputs to train or improve any model beyond a limited license to provide, maintain or improve the Services for that customer. Customer Data will not train global or foundational models serving multiple customers, and no third party may use Customer Data or AI Output to train, fine tune, validate, test or develop any model. Tenants are logically separated with dedicated encryption keys. The Data Processing Addendum limits retention to the time absolutely necessary and requires return and deletion at the customer's election after the agreement ends. Prompts, completions, embeddings and training data sent to Azure OpenAI are not available to OpenAI and are not used to improve OpenAI, Microsoft or third party products. Each document processing provider works under a zero retention arrangement. Conga sells the product to legal departments to hold their agreements, and its addenda, trust center and product pages do not address attorney client privilege or work product. Conga's Master Services Agreement is a separate document.

Docusign CLM
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

The Docusign Master Services Agreement, version 14 November 2022, keeps Customer Data owned by the customer (3.1). Confidential information may be used only for the purpose given and must be protected with at least reasonable care (11.1). Liability for a breach of confidentiality sits outside the twelve month fee cap (10.2). The AI Attachment treats AI output as Customer Confidential Information. Section 4.1 of the AI Attachment grants Docusign a perpetual license to use CLM customer data and AI output, once anonymized and aggregated, to train models. Section 4.2 lets the customer switch that off going forward with a toggle in the product. Section 4.3 of the MSA separately lets Docusign use deidentified usage data, including for training. Within a customer account, CLM folder security limits who sees which contracts. The agreements and the product pages do not address privilege or work product.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Conga CLM
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

Conga's position on advice versus tooling sits in the Artificial Intelligence Addendum. The Addendum states that AI generated outputs may be inaccurate, incomplete or misleading, disclaims any warranty of fitness, and makes the customer solely responsible for validating outputs before use. It says the customer must not rely on AI outputs as the sole basis for any decision with legal, financial, regulatory or other material impact, and that human review and independent judgment should be exercised. It applies the same rule to agents, making the customer responsible for deciding whether agent actions are appropriate and for authorizing and supervising them. The function pages name the audience, and the marketing does not describe the product in advice terms. The published materials do not address how a supervising lawyer meets competence or oversight duties over AI drafted contract language. They do not say which buyer groups may use which capability, and state no jurisdictional limit. The product is marketed to sales and procurement users who generate contract positions in the same tenant as legal.

Docusign CLM
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

Section 6.2 of the AI Attachment, the contract that governs CLM's AI features, states that neither Docusign, the AI Services nor AI output provide the customer with legal advice. The same section leaves suitability for any purpose to the customer's sole discretion and has the customer review output for accuracy, including through human review. CLM is sold to sales, procurement, human resources and customer experience teams as well as legal. AI-Assisted Review proposes redlines and drafts clauses for any of those users. Docusign does not say who in a customer reviews an AI redline before it reaches a counterparty, how the product supports a lawyer's competence and supervision duties, or whether any limit applies by jurisdiction.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Conga CLM
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

Conga's AI governance framework sits in the Artificial Intelligence Addendum rather than on a principles page. The Addendum records a cross functional AI Governance Committee responsible for oversight of AI within the Services. The committee focuses on risk management, accountability and compliance, and periodically reviews AI risks, controls and mitigations. Conga commits to internal policies on responsible AI covering oversight of training data, bias mitigation and human interpretability, to staff training, and to full cooperation with a customer's own AI impact assessments. Governance is tied to the NIST AI Risk Management Framework and its four functions, Govern, Map, Measure and Manage. The vendor classifies its products as minimal or limited risk AI systems under the EU AI Act. It states that third party models are tested, audited for bias and benchmarked before release, with rollback to any prior model version within hours. Conga publishes no results from that testing, whether a bias audit finding, an evaluation output, a model card or a statement about uneven performance across contract types.

Docusign CLM
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

Docusign publishes AI Trust and AI Innovation Principles pages for Iris, the engine behind CLM's AI features. The AI Trust page lists encryption in transit and at rest, consent based training on aggregated and anonymized data, and content filtering for harmful outputs. It also describes diverse datasets and checks that correct skewed outputs before deployment, and adoption of frameworks such as the NIST AI framework. Section 6.1 of the AI Attachment warrants that, to Docusign's knowledge, it holds sufficient permissions for the data used to train its own models. That data is defined as customer data authorized for that use, publicly available data and licensed data. Docusign names no person, committee or team as accountable for model behavior and lists no ISO/IEC 42001 certification. It publishes no test results, including on whether output differs across contract types, languages or regions. The AI Trust page says broader AI Trust capabilities are available through sales.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Conga CLM
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

The Data Processing Addendum says retention of personal data should generally not be required and is limited to the time absolutely necessary to perform the Services. Daily backups are kept for thirty days, and each third party document processing provider works under a stated zero retention arrangement. Data is returned or deleted at the customer's election within a reasonable period after the agreement ends, and the CCPA attachment requires prompt compliance with deletion requests. Access control is documented control by control. It includes role based authorization, least privilege, quarterly access reviews, multifactor authentication, encryption at rest, TLS of 256 bits or stronger in transit, and per tenant encryption keys. Conga publishes its subprocessor list, gives fifteen days' notice before adding a new one, grants a right to object with termination and refund, and stays liable for subprocessors' acts. Incident notice comes within 48 hours of Conga becoming aware, backed by a documented response plan with root cause analysis and a 24/7 security team. All of these terms are published and can be read before signing.

Docusign CLM
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

Under section 3.1 of the Service Schedule for Docusign CLM, version 15 September 2025, documents are stored for the subscription term or until the customer deletes them. An account administrator can set a different retention and deletion schedule. Retrieval is free during the term and available for 90 days after it through professional services, after which Docusign may delete the account and its documents (3.2). The Data Protection Attachment, version 4 September 2024, commits to notice of a data breach without undue delay, giving its nature, likely consequences and the measures taken. It also commits to deletion of personal data on request. Docusign's subprocessor list, last updated 18 September 2026, has its own CLM section naming each hosting and AI supplier with locations. Updates go out through an RSS feed, and objections go by email. Agreement contents are encrypted at rest, and folder security controls access inside an account. Section 4.1 of the AI Attachment lets Docusign keep training data derived from customer content after termination, with no duty to delete it. Docusign does not state what Microsoft or Google keep from prompts.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Conga CLM
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

The Artificial Intelligence Addendum states that Conga makes no warranty, express or implied, on the accuracy, completeness, noninfringement or fitness for purpose of AI generated output. The customer is solely responsible for evaluating and validating that output. To the maximum extent permitted by law, Conga is not liable for any losses, damages or claims arising from the customer's use of or reliance on AI output or on actions by agentic AI features. That includes third party claims. One allocation runs the other way. The Data Processing Addendum makes Conga liable for its subprocessors' acts and omissions as if it had performed the services itself, and much of the AI pipeline sits with those third parties. The addenda do not state a general liability cap, an indemnity scope or an insurance position. Conga's Master Services Agreement is a separate document.

Docusign CLM
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

The Master Services Agreement, version 14 November 2022, warrants that the services perform substantially as documented (8.1). The remedy is repair, replacement, or termination and a prorated refund. Docusign indemnifies the customer against third party claims arising from its breach of confidentiality and from intellectual property infringement (9.1). Liability is capped at fees paid for the service in the twelve months before the first event (10.2). The cap does not apply to indemnity obligations, confidentiality breaches, gross negligence or willful misconduct. The AI Attachment narrows these terms for AI. Section 6.2 disclaims all warranties on AI output and says Docusign is not liable for output to the extent it includes customer data. It also removes the indemnity where a claim arises from the customer's data, its own modifications or output it knew to infringe. The agreements do not cover loss from a wrong extraction or redline, and Docusign publishes nothing on insurance.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Conga CLM
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Several of Conga CLM's integrations are structural. One edition runs natively on Salesforce and is listed on the Salesforce AppExchange. Authoring and review run inside Microsoft Word and Google Docs, and Microsoft Dynamics is named on the product page. The vendor states that the platform edition connects to any CRM, ERP or procurement system. Within Conga's own products, pricing, terms and configurations flow from CPQ into a contract. Documents are generated through Composer and signed through Conga Sign, and price optimization feeds contract pricing. Conga publishes a documentation site at documentation.conga.com, a developer hub at developer.conga.com and an integrations page. The product pages show no field mapping or sync direction, and the claim of connecting to any CRM or ERP describes reach without saying what data moves.

Docusign CLM
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Docusign's Salesforce integration for CLM generates documents and runs workflows across Salesforce Customer 360. With SAP Ariba, users create supplier agreements, ingest third party paper and track workflow tasks from Ariba. The Coupa integration lets contracts be created or updated in either system. Slack carries review notifications and actions, and comments sync between Microsoft Word, Google Docs and CLM. AI-Assisted Review runs inside Word, and Docusign eSignature is built in. The CLM API in the Docusign Developer Center offers object, task and content APIs for Salesforce and custom applications. Docusign Monitor, sold as an extra on top of CLM, reports CLM event activity, including through Splunk. Docusign University runs courses on building custom CLM integrations. The named integrations include no document management system used by law firms, such as iManage or NetDocuments. The product pages do not say which fields move in which direction for each connector.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Conga CLM
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Conga publishes two delivery forms. One is the original application built on Salesforce. The other is a software as a service edition on the Conga Advantage Platform that gives buyers a CLM interface independent of Salesforce. The Data Processing Addendum treats them differently. It states that Conga does not back up customer data for services hosted on Salesforce and sets no recovery point objective for them. Elsewhere it keeps daily backups for thirty days, with a one hour recovery point objective and a twenty four hour recovery time objective. Infrastructure is named as Salesforce, Amazon Web Services and Azure, with data on servers managed by Salesforce and AWS. Tenants are logically separated with dedicated encryption keys. Availability is described as spanning the United States, the European Union and Asia Pacific with residency options included, which names continents rather than regions. Conga publishes no region list, does not say how a tenant's region is chosen, and does not distinguish processing location from storage. Content reaches Azure OpenAI, Google Cloud Vision, Amazon Textract and Zuva, and no published page states where that processing runs.

Docusign CLM
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

Docusign's subprocessor list names CLM's hosting suppliers and places each by where the service is provisioned. The hosts are Equinix in the Netherlands, the United Kingdom and the United States, Switch in the United States, and Microsoft Azure in the United States, Australia, Canada, the European Union and Japan. AI processing is listed separately. Azure AI services for review, summaries and extraction run in the United States, Canada, the European Union, Australia and Japan. Google processing for the CLM Analyzer service runs in Belgium, Canada, Germany, Switzerland, the United Kingdom and the United States. Government editions are separate deployments. The CLM Service Schedule keeps government customer data inside Docusign's FedRAMP Moderate boundary unless a connector exports it (5.2). The DoD Impact Level 4 edition requires a connection to NIPRnet through a boundary cloud access point (5.3). Docusign does not describe the tenancy model for commercial customers and offers no on premises option.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Conga CLM
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Conga's trust center is ungated, linked from the site navigation, and names each standard. SOC 2 Type II is stated to cover the full platform and is audited annually. The trust center also lists ISO 27001, ISO 27701 as its privacy extension, PCI DSS, HIPAA Security with annual audits, GDPR and CCPA. It adds alignment to the NIST AI Risk Management Framework and certification under the EU-U.S. Data Privacy Framework. That certification can be verified independently, because the Data Processing Addendum points to the public Department of Commerce list. The security program behind the standards is documented. It includes annual third party penetration testing, application vulnerability assessment twice a year, continuous automated threat hunting and code analysis before release. It also covers a patching service level by severity, background checks, annual security training and a vulnerability disclosure program. No auditor, report period, observation window or certificate number is published for any standard, and the trust center holds no report. The Data Processing Addendum makes reports available on a customer's request under confidentiality, so a prospective buyer cannot read the audit scope before signing.

Docusign CLM
AA on Security Certifications and Trust CenterCurrent independent attestation with named scope, reachable without a sales call: a trust center carrying reports, dates and the standards actually covered.

The certifications page Docusign publishes lists ISO/IEC 27001:2022 certification enterprise wide, ISO/IEC 27017:2015 and 27018:2019, and PCI DSS 4.0. Annual SOC 1 Type II and SOC 2 Type II audits cover all production operations, including data centers. FedRAMP agency authorization, GovRAMP authorization and a Defense Information Systems Agency Impact Level 4 provisional authorization each name CLM directly. Reports and certificates are available in the Docusign Trust Portal, and the annual CSA STAR CAIQ is public on the CSA registry. Docusign also completes the Shared Assessments SIG, S&P Global KY3P and ProcessUnity assessments each year. USDM assesses its 21 CFR Part 11 module annually. C5 Type II covers the eSignature product only and does not extend to CLM.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Conga CLM
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Generative features run on Microsoft Azure OpenAI. The document processing agents also use Google Cloud Vision for optical character recognition, Amazon Textract for table detection and Zuva for provision extraction, each under a stated zero retention arrangement. The Azure OpenAI Service is described as fully controlled by Microsoft, hosted in Microsoft's own Azure environment and not interacting with any system operated by OpenAI. Prompts, completions, embeddings and training data are tokenized in transit, are not available to OpenAI, and are not used to improve OpenAI, Microsoft or third party models. Change notice is contractual. The AI providers are subprocessors, and the Data Processing Addendum gives fifteen days' notice before a new one is appointed, with its name, location and activity. It also gives a right to object, and termination with a refund if no workaround exists. No specific model is named. The Addendum refers to Azure OpenAI GPT, which is a family rather than a version, and nothing states which model writes a summary or a redline or when that changes.

Docusign CLM
AA on Model Supply Chain DisclosureThe models underneath are named, their providers identified, where they run is stated, and the vendor commits to notifying customers when any of that changes.

The CLM section of Docusign's subprocessor list, last updated 18 September 2026, names the AI suppliers feature by feature. Microsoft's Azure OpenAI Service runs AI-Assisted Review in CLM, CLM+ and the AI Extension for CLM, and agreement summaries in the AI Extension and CLM+. Azure AI Document Intelligence runs AI extraction in CLM Essentials, CLM and the AI Extension. Google processes the CLM Analyzer service. DocuSmart Inc., trading as Lexion and wholly owned by Docusign, runs the legacy version of AI-Assisted Review for select US customers. Each entry gives the countries where it is provisioned. Updates are posted to an RSS feed customers can subscribe to. A customer may object to a new subprocessor by email on grounds set in Docusign's Processor Policy. The list gives no model name or version for any provider. Section 6.1 of the AI Attachment disclaims responsibility for the data third party providers used to train their own models.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Conga CLM
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Conga's pricing page is linked from the main navigation and carries no price, band, term, tier table, unit of charge or minimum. It does not say whether the product is licensed per user, per contract or per platform, or what implementation adds. The page holds a heading, a paragraph saying every business is unique and a list of six things the pricing is said to prioritize, one of them Transparency. Below those sit two strips of customer logos and a quote request form. The nearest thing to a tier is a line on the platform page inviting buyers to add CLM Advanced features such as a clause library, version control and redlining. That line names an upgrade, not a price. The pricing and platform pages state no payment terms, renewal terms, price increase caps or termination rights. Conga's Master Services Agreement is a separate document.

Docusign CLM
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

A CLM subscription is prepaid and measured by a seat allowance, a document count or both, depending on the edition (4). The Service Schedule for Docusign CLM publishes that charging structure, but Docusign publishes no CLM price. Every call to action on the CLM page, Get Started included, goes to Contact Sales. The site's plans and pricing links lead to eSignature and IAM plans, none of which includes CLM. Under section 4.3, extra seats are charged pro rata at list price for the rest of the term. Documents over the count are charged per document at list price and invoiced monthly in arrears. Seats can be reassigned between people without penalty, and documents exported and then deleted during the term still count. Retrieval after the term ends is a paid professional services engagement. Editions named across Docusign's documents include CLM Essentials, CLM, CLM+ and the AI Extension for CLM, alongside government and DoD Impact Level 4 editions.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Conga CLM
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

The site has a navigation tier for seven named functions, Legal, Procurement, Sales, Finance, IT, Business Operations and Pricing, each with its own page. The CLM material gives legal, sales and procurement different task lists. Legal gets workflow, authoring, AI review and redlining, compliance and risk management. Procurement gets obligation management, AI extracted terms and pricing. Sales gets generation, AI assisted negotiation and renewals. Seven industry pages cover technology, financial services, healthcare, life sciences, manufacturing, transport and logistics, and distribution. Named customers span airlines, insurance, media, retail and property data. No practice area inside a legal department is named as supported or unsupported, and nothing states what the product is not for. The pages do not say which capabilities a user who is not a lawyer can reach in a shared tenant. They give no jurisdiction or language coverage statement, although the product is localized into German and French.

Docusign CLM
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

CLM is sold to legal, sales, procurement, human resources and customer experience teams. Its named customer stories come from wholesale telecom, auto parts distribution, retirement plan administration and recruiting software. Government use runs through CLM Government Products, authorized under FedRAMP and GovRAMP, and a DoD Impact Level 4 edition. Docusign says 2,200 enterprises use CLM for contract management. Its integrations with SAP Ariba and Coupa point at procurement as well as sales contracting. Docusign frames coverage by department and industry rather than by contract type or area of law. It names no minimum customer size, no law firm use, and no contract types the AI handles poorly. The IAM plans page states AI extraction in English, French and German, and the CLM pages give no language list.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Conga CLM
Permitted, in the contract

The Artificial Intelligence Addendum expressly permits training on customer content, within written limits. Section (c) says Conga will not use Customer Data to train global or foundational models that serve multiple customers. Any training on Customer Data is limited to models specific to the customer's instance or tenant. Training therefore happens on the customer's own data, into a model only that customer uses, and neither the Addendum nor the trust center describes an opt out.

Conga does not use Customer Data to train third party foundational models, naming Azure OpenAI GPT as the example. Section (d) says Conga will not let any third party use Customer Data or AI Output to train, fine tune, validate, test or otherwise develop any AI model. Section (b) says that, beyond a limited license to provide, maintain or improve the Services for that customer, Conga will not use AI Inputs or AI Outputs to train or improve any model.

The trust center adds that models trained on one customer's data are never used for another. One carve out is reserved. Service Attributes, defined as anonymized and aggregated usage information, may be used to train and refine models and are stated not to be Customer Data.

Docusign CLM
Opt out

Section 4.1 of the AI Attachment for Docusign Services, version 8 July 2026, grants Docusign a perpetual license to use customer data and AI output to train models and improve its services generally. The data and output are anonymized and aggregated first. The attachment's applicability table says customers on a Master Services Agreement consent to that training for Docusign CLM. Section 4.2 lets the customer opt out at any time with a toggle in the product, on a going forward basis.

Docusign keeps the training data created before the opt out, with no duty to delete it. The AI Trust page describes the same program as consent based. Customers whose subscription began before 8 July 2026 are pointed to earlier versions of the terms.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Conga CLM
Customer controlled, no zero option

The Data Processing Addendum lets the customer control retention by contractual instruction. Attachment A sets the default. Retention of personal data should generally not be required, and any retention is limited to the time absolutely necessary to perform the Services. Section 9.6 requires return and deletion at the customer's election within a reasonable period after the agreement ends, with the customer deleting within the Services and Conga helping where it cannot.

The CCPA attachment adds a duty to follow any customer deletion instruction promptly. Daily backups are kept for thirty days, except for services hosted on Salesforce, which Conga does not back up. At the model layer, Conga states a zero retention policy with each third party document processing provider. Documents sent to Azure OpenAI, Google Cloud Vision, Amazon Textract and Zuva are therefore processed in real time and not stored. No zero retention setting is offered to the customer inside the Services.

Docusign CLM
Customer controlled, no zero option

Section 3.1 of the Service Schedule for Docusign CLM, version 15 September 2025, keeps each stored document, including the customer data in it, for the subscription term or until the customer deletes it. The account administrator can set a different retention and deletion schedule. After the term, documents can be retrieved for 90 days through professional services, and Docusign may then delete them (3.2). The schedule covers stored documents rather than prompts as such.

AI output is Customer Confidential Information under the AI Attachment. The same attachment lets Docusign keep anonymized training data derived from content, with no duty to delete it. Docusign does not state what the Azure and Google model services keep from a prompt.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Conga CLM
Own model, documented

Conga CLM has its own documented permission model, which the customer administers. Between customers, separation is built into the architecture. Tenant environments are logically separated, each with its own encryption keys, and models trained on one customer's data are never used for another customer's recommendations or scores. Inside a tenant, the Data Processing Addendum's security attachment documents role based authorization, least privilege, quarterly access reviews, multifactor authentication and the customer's ability to limit access to authorized personnel.

Conga's trust center states that rules based access controls, audit logs and admin tools help the customer configure and manage AiMe, which leaves the alignment work with the customer. The product does not apply an outside document management system's access model at query time. The addenda and trust center do not address segregation between matters or business units inside one tenant. The platform is sold to legal, procurement, sales, finance and IT in the same instance, and the assistant answers questions across the whole contract repository.

Docusign CLM
Own model, documented

CLM has its own permission model built on folders. A Docusign employee's guide on the Docusign Community sets out six levels. They run from No Access, the default for all content, through View, View and Create, View and Edit, and View, Edit and Delete, to full control with Set Access. Security can be set for a user, a permission profile or a user group. Folders inherit their parent's security unless it is set explicitly.

CLM administrators can see all content whatever the folder settings. The CLM page adds granular permissions controls and an audit trail of who did what and when. Docusign does not say how AI review, summaries or repository lookups apply folder permissions when they run.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Conga CLM
Notice committed

Section 4 of the Data Processing Addendum's security attachment is headed Disclosure by Law. If Conga is required by law to disclose customer data, it will notify the customer as soon as practical where the law permits. It will also take all steps to give the customer an opportunity to prevent or limit the disclosure, an obligation to help and not only to inform. The CCPA attachment adds a slightly stronger commitment for personal information.

For a legally required disclosure unrelated to the contracted business purpose, Conga must first tell the customer and give it a chance to object or challenge the requirement, unless the law prohibits notice. Conga will also redirect a misdirected data subject request to the customer and will not respond without the customer's prior written consent unless legally required. Conga publishes no transparency report, aggregate count of demands or reporting cadence.

Docusign CLM
Notice committed

Section 11.2 of the Master Services Agreement, version 14 November 2022, requires prompt written notice before a compelled disclosure of confidential information, unless legal process forbids it. It also requires cooperation in seeking a protective order. The Data Protection Attachment adds prompt notice of any government request about personal data. Docusign's law enforcement page says the company notifies customers when their data is subject to disclosure and withholds notice only under a signed nondisclosure order or a statute that bars it.

The page adds that Docusign cannot decrypt agreement contents at rest. Docusign prepares an annual transparency report on requests and makes it available to data protection authorities on request. The report is not published. Section 2(d) of the CLM Service Schedule says Docusign is not responsible for producing customer documents to any third party.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Conga CLM
Sources named, basis unstated

Conga CLM works from the customer's own material. That means contracts imported in bulk, including third party, legacy and acquired agreements, plus the customer's clause library, negotiation playbook and approved templates. The vendor states that precise models are built from the customer's own documents without the customer having to train them. The generative layer is named too. Azure OpenAI handles language processing, with Google Cloud Vision, Amazon Textract and Zuva for optical character recognition, table detection and provision extraction.

Conga states no rights basis for any of these sources and does not describe what the underlying foundation models were trained on. Zuva's extraction models are trained on contract collections rather than on the customer's documents, and they are named without any account of what sits behind them. On the customer's side, the Artificial Intelligence Addendum leaves the customer with all right, title and interest in its AI Inputs and AI Outputs and grants Conga only a limited license.

Docusign CLM
Sources named, basis unstated

CLM works from the customer's own contracts, templates and clause library, and does not retrieve case law or legislation. Docusign describes Iris, the engine behind it, as trained on decades of contract data. Section 6.1 of the AI Attachment lists the training data for Docusign's own models as customer data authorized for training, publicly available data and data licensed from third parties. Docusign warrants that to its knowledge it holds sufficient permissions for them.

The section names no specific source or license, and it excludes the data third party providers used for their own models.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Conga CLM
Not addressed

The product cites no cases, statutes or regulations, so checking authority for later history does not arise in its usual form. It works on the customer's own agreements, comparing drafts to a negotiation playbook, matching against an approved clause library, extracting obligations and dates, summarizing, and answering questions about the repository. Nothing it produces is a statement about the law that a lawyer would check for later treatment.

The nearest point is obligation and renewal tracking, where the question is whether a contractual date or duty is still live, and alerts and dashboards handle that. Conga's product pages, feature pages, trust center and both published addenda do not address checking authority for subsequent history.

Docusign CLM
Not addressed

Docusign CLM manages a customer's own agreements and does not cite case law or legislation, so a citator is not part of the product. The CLM page, the AI-Assisted Review page and the AI Trust page do not address checking authority for later history. Docusign does not describe how CLM detects when an amendment or a policy change leaves extracted terms or clause library positions out of date.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Conga CLM
Confidence signal only

Conga commits that AiMe shows how every recommendation is generated, that users see the reasoning behind AI driven actions, and that confidence scores appear wherever AiMe makes a suggestion. That gives a reviewer a signal for each suggestion. Conga does not describe what the system does when it cannot ground an answer. It publishes no statement that the system declines and no marking of an unsupported extraction. Nor does it say what happens when a clause cannot be matched to the playbook or a question cannot be answered from the repository.

No evaluation of any such behavior is published. The Artificial Intelligence Addendum allocates the consequences instead. It says outputs may be inaccurate, incomplete or misleading, makes the customer solely responsible for validating them, and states that Conga does not monitor or review AI generated outputs. The product page mentions guardrails without saying what they do.

Docusign CLM
Not addressed

Section 6.2 of the AI Attachment warns that AI output may be incorrect or otherwise undesirable and makes the customer responsible for reviewing it. The AI Trust page describes content filtering for harmful outputs. Neither document says what AI-Assisted Review or the question and answer feature does when a playbook or the repository does not cover what is asked. Nor do they say how a doubtful extraction is marked before it feeds a report, a renewal alert or a workflow rule.

Docusign documents no path for CLM's AI features to decline an answer and publishes no confidence or grounding scores for extraction, review or summaries.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

Conga CLM
None located

The AI Hallucination Cases database maintained by Damien Charlotin tracks decisions worldwide where a court addressed hallucinated AI content, and records the tool implicated where known. It records no court order, opinion or disciplinary record naming Conga CLM or Conga. Two independent sanctions trackers of decisions on AI generated fabricated citations do not name them either. Conga CLM works on contracts and cites no legal authority, so its output does not ordinarily reach a court filing.

Docusign CLM
None located

The AI Hallucination Cases database maintained by Damien Charlotin tracks court decisions worldwide that address hallucinated AI content and records the tool involved where known. It has no entry naming Docusign, Docusign CLM, Iris, SpringCM or Lexion, in the tool field or anywhere in the case text. CLM manages commercial agreements rather than producing court filings, so its output does not ordinarily reach a brief.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Conga CLM
Not addressed

Conga's published materials name no bar or ethics guidance. ABA Formal Opinion 512 does not appear, no state guidance on generative AI in legal practice is referenced, and nothing maps a capability to a jurisdiction's rules of professional conduct. Conga does cite outside frameworks, but none of them is professional responsibility guidance. The Artificial Intelligence Addendum ties governance to the NIST AI Risk Management Framework, and the trust center classifies the products as minimal or limited risk AI systems under the EU AI Act.

Both are addressed to the vendor as an AI provider. The nearest thing to a professional responsibility statement is the Addendum's requirement that the customer not rely on AI outputs as the sole basis for a decision with legal impact. It also requires the customer to exercise independent judgment. It names no guidance.

Docusign CLM
Generic reference

Section 6.2 of the AI Attachment for Docusign Services, which governs CLM's AI features, states that neither Docusign, the AI Services nor AI output provide the customer with legal advice. It makes the customer responsible for reviewing output for accuracy and suitability, including through human review. The CLM page, the AI-Assisted Review page, the AI Trust page and the agreements name no bar opinion, ethics rule or professional conduct guidance.

Docusign's compliance work covers data, security and sector regimes, including ISO, SOC, PCI DSS, FedRAMP, GovRAMP, DoD Impact Level 4, HIPAA and 21 CFR Part 11. Those regimes bind Docusign as a provider rather than a lawyer using the product.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Conga CLM
Outside the fee relationship

The product does not touch a fee between a lawyer and a client, because the teams that buy it bill no client for the work. The named audiences are in house functions, legal, procurement, sales, finance, IT and business operations, each with its own page. The named customers are corporate, among them an airline, an insurer, a property data business, a consumer fitness company and a professional network. Nothing is addressed to a law firm billing a client.

Conga's efficiency claims include a 9 percent revenue increase, 50 percent less review time with AI, faster deal cycles and lower supplier costs. All of them concern the buyer's own cost, cycle time or revenue, and none reaches a client bill. The platform also runs quoting, pricing and billing, but that is the customer billing its own customers rather than a lawyer billing a client. Conga publishes nothing on disclosure of AI use or AI cost in any fee context.

Docusign CLM
Outside the fee relationship

Enterprise legal, sales, procurement, human resources and customer experience teams buy CLM to run their own contracting. The named customers are companies such as T-Mobile Wholesale, Genuine Parts Company, Vestwell and iCIMS rather than law firms, so no client bill sits in the loop. Docusign claims an 83 percent boost in speed and efficiency and a 449 percent return on investment. It also claims a 90 percent cut in time to generate a sales contract and 72 to 80 percent saved on contract reviews.

All of these concern the customer's own cost and time. Docusign publishes nothing on fee treatment of AI assisted work for a firm that bills a client.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Conga CLM
Disclosure pack published

The documents a company would forward to answer a counterparty's AI clause are published and ungated. Conga's trust center names Google Cloud Vision for optical character recognition, Amazon Textract for table detection, Zuva for provision extraction and Azure OpenAI for language processing. It states a zero retention arrangement with each and explains what Azure OpenAI does and does not do with prompts and completions.

A subprocessor list is published at conga.com/privacy/subprocessors-and-subcontractors. The Data Processing Addendum applies Clause 9(a) Option 2 of the Standard Contractual Clauses to that list, with fifteen days' notice, a right to object and termination with a refund. Two documents a client can read are published in full. One is the Data Processing Addendum, with the SCCs and the UK and Swiss adaptations. The other is a separate Artificial Intelligence Addendum written for a customer's counsel.

Docusign CLM
Disclosure pack published

Docusign's subprocessor list, last updated 18 September 2026, is published as a web page and a download, with a separate section for CLM. It names each hosting supplier and each AI supplier against the feature it powers, with countries and a contact address. Changes go to an RSS feed, with an email route for objections. The Data Protection Attachment, the AI Attachment, the Master Services Agreement and the CLM Service Schedule are all published without a login.

The certifications page and the public CSA STAR CAIQ cover security. Together these documents name every model provider that touches CLM content, and a customer can forward them when its own clients ask about AI vendors.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Conga CLM
Partial record

The platform keeps a complete audit trail of every action, approval and signature across the contract lifecycle, which the vendor describes as supporting legal or internal reviews. It also keeps version control, tracked edits and inline comments. AiMe shows how every recommendation is generated and the reasoning behind AI driven actions, and confidence scores accompany each suggestion, so the basis of a proposed clause is visible at review.

No report or extract is described as identifying which model produced a passage, and the model is not named beyond a family. Conga describes no document level export, no marking of machine generated text against human edited text in a form a party could give a court, and no disclosure template, certification form or court guidance.

Docusign CLM
Partial record

CLM keeps an audit trail of who did what and when, and detailed version control across drafts, so the history of a contract can be reconstructed. Docusign does not say whether an AI-Assisted Review suggestion, an AI drafted clause or an AI extraction is marked as machine generated in that history. Nor does it say whether the audit trail records which model produced it. It publishes no export built for disclosing AI involvement and no disclosure template.

CLM output is a contract, a report or an obligation record rather than a court filing. A record of AI involvement would most likely go to a counterparty, an auditor or a regulator.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Signals neither addresses in public material
  • Good Law Verification

Which one fits

Choose Conga CLM if

  • You want training kept inside your own tenant. Conga's Artificial Intelligence Addendum limits any training on customer data to a model for the customer's own instance. It bars Conga and any third party from using customer data or AI output to train other models.
  • You run quoting and contracting together. Conga CLM takes pricing, terms and configurations from Conga's quoting product, generates documents through Composer and signs through Conga Sign. One edition runs natively on Salesforce.
  • You want each AI suggestion explained. AiMe shows how a recommendation was generated, the reasoning behind it and a confidence score. Conga states that AiMe never acts on its own on high stakes decisions.

Choose Docusign CLM if

  • You work with government or defense agencies. Docusign's FedRAMP, GovRAMP and DoD Impact Level 4 authorizations name CLM. Its government editions keep data inside the FedRAMP Moderate boundary unless a connector exports it.
  • You want to know the charging units before negotiating. Docusign's service schedule sets subscriptions by seat allowance, document count or both. Overages are billed at list price, and retrieval after the term is a paid service.
  • You want customer results with numbers. In Docusign's customer stories, T-Mobile Wholesale reports cutting agreement time by 44 percent, and Vestwell builds agreement packages in 5 minutes instead of 75. iCIMS reports that 78 percent of its agreements need no legal involvement.

In summary

Conga CLM

Conga CLM is Conga's contract lifecycle product, sold as an application built on Salesforce or as an edition on the Conga Advantage Platform that Conga says works beside any CRM or ERP. It runs contract requests, generation from approved clause libraries, negotiation in Word or Google Docs, approval and renewal tracking. Pricing and terms flow in from Conga's quoting product. According to the AI Legal Index, Conga writes its AI position into its contract. Its Artificial Intelligence Addendum keeps any training on customer data inside the customer's own tenant, and AiMe shows the reasoning and a confidence score for each suggestion. Azure OpenAI, Google Cloud Vision, Amazon Textract and Zuva are named by function. No price is published.

Source: AI Legal Index, 2026

Docusign CLM

Docusign CLM is Docusign's enterprise contract lifecycle product, descended from SpringCM and now part of its Intelligent Agreement Management platform. It assembles agreements from templates and Salesforce data, routes them through configurable workflows and signs them through Docusign eSignature. Its Iris AI handles review, extraction and summaries. According to the AI Legal Index, Docusign CLM publishes its paperwork in depth, from a service schedule with charging units to a master services agreement. Hosting countries are named for each provider, and FedRAMP, GovRAMP and DoD Impact Level 4 authorizations name the product. Its AI terms allow training on anonymized customer data unless the customer opts out. No price figure is published.

Source: AI Legal Index, 2026

Questions buyers ask

Conga CLM vs Docusign CLM: which is better?

If you quote in Conga or run on Salesforce and want AI suggestions explained with a confidence score, Conga CLM fits. Its AI terms keep training on your data inside your tenant. If you need government authorizations, published hosting countries and charging units, and customer stories with figures, Docusign CLM publishes them. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Do Conga CLM and Docusign CLM train AI on customer contracts?

Conga allows training on customer data only into a model for that customer's tenant, and bars third parties from training on it. Docusign licenses training on anonymized, aggregated CLM data across customers unless the customer opts out with a toggle. It keeps data gathered before an opt out. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Which AI providers do Conga CLM and Docusign CLM use?

Conga names Azure OpenAI for language, Google Cloud Vision for character recognition, Amazon Textract for tables and Zuva for clause extraction. Docusign names Azure OpenAI for review and summaries, Azure AI Document Intelligence for extraction and Google for its Analyzer service, with countries. Neither names a model version. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Do Conga CLM and Docusign CLM say AI output is not legal advice?

Docusign's AI Attachment states that neither Docusign nor its AI output provides legal advice, and puts review on the customer. Conga's Artificial Intelligence Addendum says output must never be the only basis for a decision with legal, financial or regulatory impact, and requires human review. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

What do Conga CLM and Docusign CLM both leave unpublished?

Neither publishes a price figure, an accuracy or error rate for extraction and review, or a model version. Neither addresses attorney client privilege in its AI terms or product pages. Neither stands behind AI output, since both AI addenda disclaim warranties on it and leave review to the customer. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Disclosure

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything on it comes from public material on the dates shown. How the index grades.

Conga's general liability cap and indemnities sit in its separate Master Services Agreement, and Docusign's sit in its published master services agreement. Docusign's training license applies to CLM customers on a master services agreement unless they opt out, and Docusign keeps training data created before an opt out. Conga reserves the right to use anonymized, aggregated usage data, which it calls Service Attributes, to train and refine models. Neither vendor reviewed this page.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
October 8, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746