Conga CLM vs Leah: how they compare in 2026

C
Conga CLM profile
L
Leah profile
Last verifiedOctober 8, 2026

AI runs across the whole contract workflow in both products, AiMe at Conga and agents under Leah Maestro at Leah, and both publish their oversight in detail. Conga's oversight lives partly in its contract. Its Artificial Intelligence Addendum says AI output must never be the only basis for a decision with legal or financial impact. In the product, AiMe shows its reasoning and a confidence score beside every suggestion. Leah's oversight lives in its governance design, where the customer sets agent permissions and escalation and every action is logged against its policy. On loss they split. Leah publishes liability caps with figures, while Conga's AI terms disclaim liability for AI output. Both name their model providers. Conga ties Azure OpenAI, Google Cloud Vision, Amazon Textract and Zuva to specific jobs, and Leah lists Anthropic, OpenAI, Cohere and Google. On training, Conga lets customer data train only a model for that customer's own tenant, while Leah says customer contracts never train models. Conga's native Salesforce edition suits a Salesforce shop, and Leah's integrations lean toward SAP and NetSuite.

At a glance

Category
Conga CLMContract Review & Drafting
LeahContract Review & Drafting
Founded
Conga CLM2006
Leah2012
Headquarters
Conga CLMBroomfield, Colorado, United States
LeahLondon, United Kingdom
Last verified
Conga CLMOct 8, 2026
LeahOct 8, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Conga CLM
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AiMe is described as a shared AI layer running across the whole commercial suite. It connects workflow data across CPQ, CLM, price optimization and document automation and suggests next steps, rather than being the CLM itself. Underneath sits a full contract lifecycle platform that long predates it, with template and clause library generation, approval routing, negotiation, electronic signature through Conga Sign, a searchable repository, obligation and renewal tracking, and reporting. The models drive core features on top of that platform. Without AiMe a working CLM remains, as the edition built on Salesforce was for years. Recent releases push AI further in. The June 2026 release is described as enhanced by AI throughout, and bulk import and extraction is presented as the way contracts enter the system. The March 2026 AiMe release adds agents that act inside quoting and contracting workflows. Conga still sells and prices the platform as a contract system with intelligence on top.

Leah
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

Leah sells AI agents and an orchestration layer that sit on top of a contract lifecycle platform, and that platform works without them. The vendor describes it the other way round. It says other vendors bolted AI onto systems built for manual workflows, while Leah was designed from scratch with orchestration as the foundation. ContractPod Technologies has sold contract lifecycle management since 2012. Leah launched in March 2023 as an AI services hub within that platform, went standalone in May 2023, and Leah Intelligence followed in October 2024. Without the agents, the product is still a working CLM with guided intake, approval routing, DocuSign and Adobe Sign execution and a contract repository. That CLM has its own market and its own Gartner category placement. The orchestration layer on top is model driven.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Conga CLM
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Conga's trust center names each part of the AI pipeline. Google Cloud Vision handles optical character recognition, Amazon Textract table detection, Zuva provision extraction and Azure OpenAI language processing. Output is grounded in the customer's own repository, playbook and clause library, and extraction needs no model training by the customer. AiMe shows how every recommendation is generated, with the reasoning visible and confidence scores wherever it makes a suggestion. The Artificial Intelligence Addendum addresses accuracy only through a disclaimer. It states that outputs may be inaccurate, incomplete or misleading and disclaims any warranty of accuracy or completeness. Conga publishes no accuracy figure, test set, error rate or benchmark result. It says third party models are benchmarked before release, and publishes no results. The product cites no legal authority, so grounding in authority and citator checks do not apply.

Leah
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Leah returns to accuracy repeatedly in its materials, and the AI governance page says every action is measured against benchmarks for accuracy, bias and outcome. Neither that page nor the home page publishes a result from that measurement. They give no accuracy figure, no error or hallucination rate, no description of any benchmark or test set and no published evaluation. The product material describes a legal helpdesk that answers contract questions with sources attached, so a user can in principle check an answer against its source. Neither page says what the system does when the customer's own contracts do not support a position.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Conga CLM
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a lawyer checks it are all published: modes, thresholds, review surfaces, and the route a matter takes back to human judgment. A categorical limit on a named mode or tier, stating what its output may not be used for, meets the threshold limb without a number.

Conga states that AiMe never acts autonomously on high stakes decisions. Three mechanisms constrain it, agent guardrails, approval thresholds and human in the loop confirmation, and each can be built into a workflow. AiMe shows how every recommendation is generated and the reasoning behind AI driven actions. Confidence scores appear wherever it makes a suggestion, users accept or reject redlines, and every action and approval is kept in an audit trail. Much of the oversight model is written into the contract. The Artificial Intelligence Addendum makes the customer solely responsible for evaluating and validating outputs. It says the customer must not rely on AI outputs as the sole basis for any decision with legal, financial, regulatory or other material impact. It also requires human review and independent judgment, and puts authorizing and supervising agent actions on the customer. The guardrails and thresholds are described as configurable rather than as defaults, and the same document states that Conga does not monitor or review AI generated outputs.

Leah
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a lawyer checks it are all published: modes, thresholds, review surfaces, and the route a matter takes back to human judgment. A categorical limit on a named mode or tier, stating what its output may not be used for, meets the threshold limb without a number.

Leah's dedicated AI governance page sets out a three stage control loop. In the first stage, policy in, the customer defines which agents may act, on which data, within which thresholds and where escalation is required. Those policies are held as configuration rather than code. In the second, execution governed, every agent action runs through those policies in real time. Approvals, escalations and rejections are applied automatically, and the orchestrator enforces guardrails at each step. In the third, audit out, every decision is logged with the rationale, what the agent did, why, under which policy, on what data and to what outcome. The records are described as tamper resistant and immutable. The loop sets the thresholds, the review points and the route back to human judgment. Leah's home page puts the position in one line, that the workflow runs itself while the judgment stays human. The page does not say what happens after an output is found to be wrong. Default modes are not described, because the customer configures the guardrails rather than receiving them preset.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Conga CLM
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Conga's customer story library carries dated, named accounts. The one about Conga CLM describes Cotality, formerly CoreLogic, improving its client service with Conga CLM, and is dated 5 September 2024. It carries no figure. Two other dated stories, DigiKey on price management and Kalixia at 160 times faster document generation, concern other Conga products. Customer logos on the product and pricing pages include Southwest Airlines, LinkedIn, AXA, Peloton, Cotality, T-Mobile, Adobe, Box and Kraft Heinz. The figures Conga publishes sit apart from any named customer. A 9 percent revenue increase appears beside the logo strip with no stated basis, and the features page claims 50 percent less review time with AI. Three headline counters on the product page display as zeros. Conga also cites G2 Leader recognition across five grids.

Leah
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Leah publishes qualitative quotes from four named people. Noelle Perkins is EVP and Chief Legal Officer at Cushman and Wakefield, and Lidia Kamleh is Chief Legal Officer at Dubai Future Foundation. Frances Bain-Cumberbatch is Chief Legal and External Affairs Officer at Ansa McAL, and Zillia Knight is Senior Legal Officer at Terumo Europe. Three results are published with the customer unnamed. A major American logistics company cut contract review time by 91 percent. A global manufacturer protected more than $18 million of revenue, and an American retail REIT tracked more than $2 million of savings. About 54 enterprise logos appear, including Philips, MUFG, Sandoz, Pernod Ricard, Alaska Airlines and Wood PLC. PwC and KPMG appear among them. PwC entered a commercial alliance in March 2024, and Epiq resells Leah in its Service Cloud. Integreon is quoted as an early adopter that resells it, and Pinsent Masons adopted it for managed legal services in July 2025. Partners and customers are shown together without distinction, and the Chief Product Officer of Execo, another services partner, is among the testimonials.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Conga CLM
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Under the Artificial Intelligence Addendum, Conga will not use AI Inputs or AI Outputs to train or improve any model beyond a limited license to provide, maintain or improve the Services for that customer. Customer Data will not train global or foundational models serving multiple customers, and no third party may use Customer Data or AI Output to train, fine tune, validate, test or develop any model. Tenants are logically separated with dedicated encryption keys. The Data Processing Addendum limits retention to the time absolutely necessary and requires return and deletion at the customer's election after the agreement ends. Prompts, completions, embeddings and training data sent to Azure OpenAI are not available to OpenAI and are not used to improve OpenAI, Microsoft or third party products. Each document processing provider works under a zero retention arrangement. Conga sells the product to legal departments to hold their agreements, and its addenda, trust center and product pages do not address attorney client privilege or work product. Conga's Master Services Agreement is a separate document.

Leah
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Leah says customer contract data is never used to train models. The AI governance page treats data leaking into models the customer does not own as a failure it engineered out. It says zero data retention is the only acceptable answer, and that Leah enforces zero retention with OpenAI and Anthropic so they process data but never store it. Encryption is AES-256 at rest and TLS in transit, with keys in Azure Key Vault, rotated and reachable only through controlled service accounts. Role based access control is said to apply at every layer, and single tenant deployment is offered for customers with strict isolation needs. Leah sells to Fortune 500 legal departments, and none of this material addresses privilege or work product.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Conga CLM
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

Conga's position on advice versus tooling sits in the Artificial Intelligence Addendum. The Addendum states that AI generated outputs may be inaccurate, incomplete or misleading, disclaims any warranty of fitness, and makes the customer solely responsible for validating outputs before use. It says the customer must not rely on AI outputs as the sole basis for any decision with legal, financial, regulatory or other material impact, and that human review and independent judgment should be exercised. It applies the same rule to agents, making the customer responsible for deciding whether agent actions are appropriate and for authorizing and supervising them. The function pages name the audience, and the marketing does not describe the product in advice terms. The published materials do not address how a supervising lawyer meets competence or oversight duties over AI drafted contract language. They do not say which buyer groups may use which capability, and state no jurisdictional limit. The product is marketed to sales and procurement users who generate contract positions in the same tenant as legal.

Leah
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Leah publishes nothing on the line between a tool and legal advice. Its site carries no disclaimer of any kind and no ethics or professional responsibility page, and it names no bar or ethics guidance, including ABA Formal Opinion 512. The platform is sold to run legal work end to end across legal, procurement and finance teams. In the vendor's own framing, agents carry out commercial work in several steps without routing every decision through a person.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Conga CLM
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

Conga's AI governance framework sits in the Artificial Intelligence Addendum rather than on a principles page. The Addendum records a cross functional AI Governance Committee responsible for oversight of AI within the Services. The committee focuses on risk management, accountability and compliance, and periodically reviews AI risks, controls and mitigations. Conga commits to internal policies on responsible AI covering oversight of training data, bias mitigation and human interpretability, to staff training, and to full cooperation with a customer's own AI impact assessments. Governance is tied to the NIST AI Risk Management Framework and its four functions, Govern, Map, Measure and Manage. The vendor classifies its products as minimal or limited risk AI systems under the EU AI Act. It states that third party models are tested, audited for bias and benchmarked before release, with rollback to any prior model version within hours. Conga publishes no results from that testing, whether a bias audit finding, an evaluation output, a model card or a statement about uneven performance across contract types.

Leah
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

A dedicated AI governance page names six failure modes the vendor says it engineered out. They include black box decisions that cannot be defended to a regulator or board, and compliance frameworks retrofitted after the fact. Against them the page sets three pillars and a loop of policy, execution and audit. Each action is logged with its rationale and governing policy, in records described as tamper resistant and immutable. The page also says every action is measured against benchmarks for accuracy, bias and outcome, and that accountability is structural rather than aspirational. It names no person or role accountable for model behavior and describes no testing before release. It gives no benchmark method or schedule and discloses no bias measurement result.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Conga CLM
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

The Data Processing Addendum says retention of personal data should generally not be required and is limited to the time absolutely necessary to perform the Services. Daily backups are kept for thirty days, and each third party document processing provider works under a stated zero retention arrangement. Data is returned or deleted at the customer's election within a reasonable period after the agreement ends, and the CCPA attachment requires prompt compliance with deletion requests. Access control is documented control by control. It includes role based authorization, least privilege, quarterly access reviews, multifactor authentication, encryption at rest, TLS of 256 bits or stronger in transit, and per tenant encryption keys. Conga publishes its subprocessor list, gives fifteen days' notice before adding a new one, grants a right to object with termination and refund, and stays liable for subprocessors' acts. Incident notice comes within 48 hours of Conga becoming aware, backed by a documented response plan with root cause analysis and a 24/7 security team. All of these terms are published and can be read before signing.

Leah
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

The AI governance page describes TLS in transit and AES-256 at rest. Encryption keys are managed in Azure Key Vault, rotated regularly and reachable only through tightly controlled service accounts. The page also lists multifactor authentication, secure API gateways, network segmentation, real time monitoring and a documented incident response plan. Audit logs are described as comprehensive, tamper resistant and immutable. For outside assurance, the vendor says an independent Managed Security Service Provider audits it every year and that it is penetration tested regularly.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Conga CLM
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

The Artificial Intelligence Addendum states that Conga makes no warranty, express or implied, on the accuracy, completeness, noninfringement or fitness for purpose of AI generated output. The customer is solely responsible for evaluating and validating that output. To the maximum extent permitted by law, Conga is not liable for any losses, damages or claims arising from the customer's use of or reliance on AI output or on actions by agentic AI features. That includes third party claims. One allocation runs the other way. The Data Processing Addendum makes Conga liable for its subprocessors' acts and omissions as if it had performed the services itself, and much of the AI pipeline sits with those third parties. The addenda do not state a general liability cap, an indemnity scope or an insurance position. Conga's Master Services Agreement is a separate document.

Leah
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

Section 16.5 of the Master Terms and Annexes sets a General Cap equal to fees paid or payable in the twelve months before the first incident. An Enhanced Cap of three times that applies to breaches of its security or data protection terms, meaning the security clause and the data processing addendum. Indemnities, intellectual property claims, breach of confidentiality and anything that cannot legally be limited are uncapped. Section 17.1 gives the customer an indemnity against third party intellectual property claims. Section 8.2 warrants that the service will perform materially as documented, with a thirty day fix period under 8.3 and termination with a refund if the fix fails. Annex A publishes uptime tiers of 99.00, 99.5 and 99.9 percent by support plan. A tier missed in three consecutive months, or in four months out of six, allows termination with a refund. Three limits apply. Breaches of confidentiality involving Customer Data fall outside the uncapped claim, so they stay capped and rise to the Enhanced Cap only where the security or data protection terms are also breached. The agreement gives no indemnity for AI output, such as inaccurate output, hallucination or training data provenance. Section 9.2 bars the customer from submitting Sensitive Data, including GDPR Article 9 categories, and the provider disclaims liability for it. These terms are version 3.0c. Version 4.0, dated 4 January 2026, changes only the trading name, according to the vendor.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Conga CLM
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Several of Conga CLM's integrations are structural. One edition runs natively on Salesforce and is listed on the Salesforce AppExchange. Authoring and review run inside Microsoft Word and Google Docs, and Microsoft Dynamics is named on the product page. The vendor states that the platform edition connects to any CRM, ERP or procurement system. Within Conga's own products, pricing, terms and configurations flow from CPQ into a contract. Documents are generated through Composer and signed through Conga Sign, and price optimization feeds contract pricing. Conga publishes a documentation site at documentation.conga.com, a developer hub at developer.conga.com and an integrations page. The product pages show no field mapping or sync direction, and the claim of connecting to any CRM or ERP describes reach without saying what data moves.

Leah
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Leah names its integrations and describes each by function. They cover ERP platforms including SAP and NetSuite, procurement systems including Coupa, financial systems, identity providers including Okta, and existing contract lifecycle tools. DocuSign and Adobe Sign are built in for signing, and a Microsoft Word add in handles redlining. The vendor also describes how the integrations work. It says Leah connects and executes rather than copying data passively, and carries out work across connected systems through the orchestration layer. Leah has a dedicated integrations page, but publishes nothing on what syncs in which direction or what a customer must configure. No document management integration such as iManage or NetDocuments appears, which fits a product built for in house teams rather than law firms.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Conga CLM
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Conga publishes two delivery forms. One is the original application built on Salesforce. The other is a software as a service edition on the Conga Advantage Platform that gives buyers a CLM interface independent of Salesforce. The Data Processing Addendum treats them differently. It states that Conga does not back up customer data for services hosted on Salesforce and sets no recovery point objective for them. Elsewhere it keeps daily backups for thirty days, with a one hour recovery point objective and a twenty four hour recovery time objective. Infrastructure is named as Salesforce, Amazon Web Services and Azure, with data on servers managed by Salesforce and AWS. Tenants are logically separated with dedicated encryption keys. Availability is described as spanning the United States, the European Union and Asia Pacific with residency options included, which names continents rather than regions. Conga publishes no region list, does not say how a tenant's region is chosen, and does not distinguish processing location from storage. Content reaches Azure OpenAI, Google Cloud Vision, Amazon Textract and Zuva, and no published page states where that processing runs.

Leah
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

The standard deployment is shared. Single tenant deployment is available for customers with strict isolation requirements. The vendor also offers what it calls a dedicated zero trust private environment in Azure OpenAI Studio, described as fully isolating data from all other customers. Leah runs on Azure, with keys held in Azure Key Vault. On data residency the vendor says only that it supports the residency and regulatory needs typical of large multinational enterprises. It names no region or jurisdiction and describes no customer choice.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Conga CLM
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Conga's trust center is ungated, linked from the site navigation, and names each standard. SOC 2 Type II is stated to cover the full platform and is audited annually. The trust center also lists ISO 27001, ISO 27701 as its privacy extension, PCI DSS, HIPAA Security with annual audits, GDPR and CCPA. It adds alignment to the NIST AI Risk Management Framework and certification under the EU-U.S. Data Privacy Framework. That certification can be verified independently, because the Data Processing Addendum points to the public Department of Commerce list. The security program behind the standards is documented. It includes annual third party penetration testing, application vulnerability assessment twice a year, continuous automated threat hunting and code analysis before release. It also covers a patching service level by severity, background checks, annual security training and a vulnerability disclosure program. No auditor, report period, observation window or certificate number is published for any standard, and the trust center holds no report. The Data Processing Addendum makes reports available on a customer's request under confidentiality, so a prospective buyer cannot read the audit scope before signing.

Leah
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

The AI governance page claims SOC 1 Type I and II, SOC 2 Type I and II, GDPR compliance, CCPA compliance, HIPAA readiness and ISO 27001 alignment. The home page FAQ, on the same site, says only that Leah is SOC 2 Type II certified, so the two pages disagree on what is held. For ISO 27001 and HIPAA the governance page says aligned and ready rather than certified. The auditor is described only as an independent Managed Security Service Provider, a category rather than a named firm. No coverage period, report date or audit scope is given. Penetration testing is said to be regular, with no partner named and no summary published. Leah has no trust center or portal, so there is no published route to request a report.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Conga CLM
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Generative features run on Microsoft Azure OpenAI. The document processing agents also use Google Cloud Vision for optical character recognition, Amazon Textract for table detection and Zuva for provision extraction, each under a stated zero retention arrangement. The Azure OpenAI Service is described as fully controlled by Microsoft, hosted in Microsoft's own Azure environment and not interacting with any system operated by OpenAI. Prompts, completions, embeddings and training data are tokenized in transit, are not available to OpenAI, and are not used to improve OpenAI, Microsoft or third party models. Change notice is contractual. The AI providers are subprocessors, and the Data Processing Addendum gives fifteen days' notice before a new one is appointed, with its name, location and activity. It also gives a right to object, and termination with a refund if no workaround exists. No specific model is named. The Addendum refers to Azure OpenAI GPT, which is a family rather than a version, and nothing states which model writes a summary or a redline or when that changes.

Leah
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

The DPA Setup Page lists four model providers against Leah Functionality, each noted as storing or retaining no customer data and each with named jurisdictions. Anthropic PBC is listed for the USA, Japan, and the EU or UK, and OpenAI LLC for the USA, Japan, and the EU or Switzerland. Cohere Inc. is listed for Canada, the USA, the EU or UK, and Japan. Google AI/ML with Google Cloud is listed for the USA, Japan, and the EU, Switzerland or UK. Microsoft Azure Services is listed for hosting and translation, and the private deployment option runs in Azure OpenAI Studio. DPA clause 4.3 requires any new subprocessor to be added to the published list with at least thirty days' notice before it processes customer personal data. Clause 4.4 gives a thirty day objection right on reasonable data protection grounds. If the objection is not resolved, the affected order can be terminated with a refund of prepaid unused fees. No model or version is named for any provider. The platform is described as choosing among several language models for each task and letting customers extend or customize models. Nothing published shows which provider handled a given piece of work.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Conga CLM
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Conga's pricing page is linked from the main navigation and carries no price, band, term, tier table, unit of charge or minimum. It does not say whether the product is licensed per user, per contract or per platform, or what implementation adds. The page holds a heading, a paragraph saying every business is unique and a list of six things the pricing is said to prioritize, one of them Transparency. Below those sit two strips of customer logos and a quote request form. The nearest thing to a tier is a line on the platform page inviting buyers to add CLM Advanced features such as a clause library, version control and redlining. That line names an upgrade, not a price. The pricing and platform pages state no payment terms, renewal terms, price increase caps or termination rights. Conga's Master Services Agreement is a separate document.

Leah
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Leah publishes no pricing at any level, including the unit of charge. The primary navigation covers platform, solutions, resources and company, and neither it nor the footer sitemap has a pricing page. There is no tier structure, no unit per seat, contract or agent, no volume banding and no indication of what implementation adds. Every call to action across the site is to request a demo. An implementation FAQ says timelines vary with scope and integrations and that a detailed plan is built during evaluation. It says nothing about cost. No published page gives a view of price before a sales process.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Conga CLM
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

The site has a navigation tier for seven named functions, Legal, Procurement, Sales, Finance, IT, Business Operations and Pricing, each with its own page. The CLM material gives legal, sales and procurement different task lists. Legal gets workflow, authoring, AI review and redlining, compliance and risk management. Procurement gets obligation management, AI extracted terms and pricing. Sales gets generation, AI assisted negotiation and renewals. Seven industry pages cover technology, financial services, healthcare, life sciences, manufacturing, transport and logistics, and distribution. Named customers span airlines, insurance, media, retail and property data. No practice area inside a legal department is named as supported or unsupported, and nothing states what the product is not for. The pages do not say which capabilities a user who is not a lawyer can reach in a shared tenant. They give no jurisdiction or language coverage statement, although the product is localized into German and French.

Leah
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Leah publishes dedicated industry pages for CPG and manufacturing, energy and utilities, financial services, healthcare, and pharma and medical devices. It describes its customers as Fortune 500 enterprises in regulated industries. By function it publishes pages for legal leadership, legal operations, sales and revenue, procurement, and finance. The pages carry distinct propositions written for the General Counsel, the contract operations team, the Chief Procurement Officer and the finance leader. The customer roster spans banking, airlines, pharmaceuticals, consumer goods and engineering. No published page says which practice areas, contract types or matters the platform does not support, and none addresses smaller organizations. Law firms appear only indirectly, through managed service partners, rather than as a served segment.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Conga CLM
Permitted, in the contract

The Artificial Intelligence Addendum expressly permits training on customer content, within written limits. Section (c) says Conga will not use Customer Data to train global or foundational models that serve multiple customers. Any training on Customer Data is limited to models specific to the customer's instance or tenant. Training therefore happens on the customer's own data, into a model only that customer uses, and neither the Addendum nor the trust center describes an opt out.

Conga does not use Customer Data to train third party foundational models, naming Azure OpenAI GPT as the example. Section (d) says Conga will not let any third party use Customer Data or AI Output to train, fine tune, validate, test or otherwise develop any AI model. Section (b) says that, beyond a limited license to provide, maintain or improve the Services for that customer, Conga will not use AI Inputs or AI Outputs to train or improve any model.

The trust center adds that models trained on one customer's data are never used for another. One carve out is reserved. Service Attributes, defined as anonymized and aggregated usage information, may be used to train and refine models and are stated not to be Customer Data.

Leah
Never, in policy only

Leah's security FAQ, on its home page, says customer contract data is never used to train models. The AI governance page treats data leaking into models the customer does not own as a failure it engineered out. It says zero data retention is enforced so that OpenAI and Anthropic process data but never store it. No term in the Master Terms and Annexes v3.0c names training, model training, machine learning or model improvement for customer content, either way.

Two clauses come close. Clause 5.1 limits the provider's use of Customer Data to providing and maintaining the Cloud Service, Support and Professional Services. Clause 5.4 allows use of Usage Data, the provider's technical logs, data and learnings about the customer's use, to run, improve and support the service. Usage Data excludes Customer Data, so the improvement right covers telemetry, not content. Together the clauses fit a ban on training without stating one.

They leave open whether model improvement counts as maintaining the service. The commitment rests on the published policy, not a contract term. Version 4.0 of January 2026 changes only the trading name, according to the vendor.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Conga CLM
Customer controlled, no zero option

The Data Processing Addendum lets the customer control retention by contractual instruction. Attachment A sets the default. Retention of personal data should generally not be required, and any retention is limited to the time absolutely necessary to perform the Services. Section 9.6 requires return and deletion at the customer's election within a reasonable period after the agreement ends, with the customer deleting within the Services and Conga helping where it cannot.

The CCPA attachment adds a duty to follow any customer deletion instruction promptly. Daily backups are kept for thirty days, except for services hosted on Salesforce, which Conga does not back up. At the model layer, Conga states a zero retention policy with each third party document processing provider. Documents sent to Azure OpenAI, Google Cloud Vision, Amazon Textract and Zuva are therefore processed in real time and not stored. No zero retention setting is offered to the customer inside the Services.

Leah
Disclosed fixed window

Section 14.4 allows export during the subscription and deletion of Customer Data within sixty days of a request after termination. That is subject to standard backup or record retention policies and legal requirements, and the customer cannot change the period. The data processing addendum adds secure deletion to industry standards at clause 8.2, with a certificate of deletion on request. Schedule 1 commits to export in CSV or a similar format within thirty calendar days and to physical destruction of media by a recognized provider.

Prompts and outputs have no separate window. The agreement treats Customer Data as one class, defined at section 23 as any data, content or materials the customer submits, so prompts and outputs follow that regime. Usage Data sits outside it. Section 5.4 lets the provider collect Usage Data, meaning its technical logs, data and learnings about the customer's use, excluding Customer Data. The provider may use it to run, improve and support the service and for other lawful purposes such as benchmarking.

It may disclose Usage Data externally only if deidentified and aggregated across customers. No deletion duty applies to Usage Data, and section 14.5 makes 5.4 survive termination.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Conga CLM
Own model, documented

Conga CLM has its own documented permission model, which the customer administers. Between customers, separation is built into the architecture. Tenant environments are logically separated, each with its own encryption keys, and models trained on one customer's data are never used for another customer's recommendations or scores. Inside a tenant, the Data Processing Addendum's security attachment documents role based authorization, least privilege, quarterly access reviews, multifactor authentication and the customer's ability to limit access to authorized personnel.

Conga's trust center states that rules based access controls, audit logs and admin tools help the customer configure and manage AiMe, which leaves the alignment work with the customer. The product does not apply an outside document management system's access model at query time. The addenda and trust center do not address segregation between matters or business units inside one tenant. The platform is sold to legal, procurement, sales, finance and IT in the same instance, and the assistant answers questions across the whole contract repository.

Leah
Claimed, not documented

Leah describes separation at the customer level, through deployment options. The vendor states that single tenant deployment is available for customers with strict data isolation requirements. It says a dedicated zero trust private environment within Azure OpenAI Studio ensures complete isolation from all other customers. Role based access control is stated to be enforced at every layer. That wording makes isolation a deployment option rather than the default, and nothing published describes how customers are separated in the standard shared deployment.

Legal, procurement, finance and shared services teams work in the same system, and nothing published addresses boundaries between them inside a customer.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Conga CLM
Notice committed

Section 4 of the Data Processing Addendum's security attachment is headed Disclosure by Law. If Conga is required by law to disclose customer data, it will notify the customer as soon as practical where the law permits. It will also take all steps to give the customer an opportunity to prevent or limit the disclosure, an obligation to help and not only to inform. The CCPA attachment adds a slightly stronger commitment for personal information.

For a legally required disclosure unrelated to the contracted business purpose, Conga must first tell the customer and give it a chance to object or challenge the requirement, unless the law prohibits notice. Conga will also redirect a misdirected data subject request to the customer and will not respond without the customer's prior written consent unless legally required. Conga publishes no transparency report, aggregate count of demands or reporting cadence.

Leah
Notice committed

Section 19, headed Required Disclosures, lets the recipient disclose Confidential Information where the law requires. Where the law permits, the recipient must give advance notice and reasonable cooperation, at the discloser's expense, to obtain confidential treatment. The clause expressly covers Confidential Information including Customer Data. Section 23 confirms that the customer's Confidential Information includes Customer Data, so customer material sits inside the notice duty.

The duty is mutual and binds whichever party receives the demand. Section 14.5 makes section 19 survive termination. Leah publishes no transparency report, so there is no public count of demands received or of how they were answered. These terms are version 3.0c. Version 4.0 of January 2026 changes only the trading name, according to the vendor.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Conga CLM
Sources named, basis unstated

Conga CLM works from the customer's own material. That means contracts imported in bulk, including third party, legacy and acquired agreements, plus the customer's clause library, negotiation playbook and approved templates. The vendor states that precise models are built from the customer's own documents without the customer having to train them. The generative layer is named too. Azure OpenAI handles language processing, with Google Cloud Vision, Amazon Textract and Zuva for optical character recognition, table detection and provision extraction.

Conga states no rights basis for any of these sources and does not describe what the underlying foundation models were trained on. Zuva's extraction models are trained on contract collections rather than on the customer's documents, and they are named without any account of what sits behind them. On the customer's side, the Artificial Intelligence Addendum leaves the customer with all right, title and interest in its AI Inputs and AI Outputs and grants Conga only a limited license.

Leah
Sources named, basis unstated

Leah works on the customer's own material. The vendor states that Leah operates against the customer's policies and playbooks and gains intelligence from the customer's unstructured data and business rules. It answers contract questions from the customer's repository with sources attached. The vendor also refers to Leah operating against established legal precedents, but names no source, jurisdiction, database or rights basis for them.

The product manages a customer's contracts rather than retrieving primary law. No provenance statement backs the precedent reference, and no update cadence is published for anything.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Conga CLM
Not addressed

The product cites no cases, statutes or regulations, so checking authority for later history does not arise in its usual form. It works on the customer's own agreements, comparing drafts to a negotiation playbook, matching against an approved clause library, extracting obligations and dates, summarizing, and answering questions about the repository. Nothing it produces is a statement about the law that a lawyer would check for later treatment.

The nearest point is obligation and renewal tracking, where the question is whether a contractual date or duty is still live, and alerts and dashboards handle that. Conga's product pages, feature pages, trust center and both published addenda do not address checking authority for subsequent history.

Leah
Not addressed

Leah describes no citator, treatment signal or currency check, and does not say whether legal authority is reviewed for later history. The platform manages contracts, obligations and procurement workflows rather than retrieving case law, so a citator is not part of what it sells. The vendor does refer to Leah operating against established legal precedents, without identifying any source. That is the one place the product invokes primary authority, and no verification step is described for it.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Conga CLM
Confidence signal only

Conga commits that AiMe shows how every recommendation is generated, that users see the reasoning behind AI driven actions, and that confidence scores appear wherever AiMe makes a suggestion. That gives a reviewer a signal for each suggestion. Conga does not describe what the system does when it cannot ground an answer. It publishes no statement that the system declines and no marking of an unsupported extraction. Nor does it say what happens when a clause cannot be matched to the playbook or a question cannot be answered from the repository.

No evaluation of any such behavior is published. The Artificial Intelligence Addendum allocates the consequences instead. It says outputs may be inaccurate, incomplete or misleading, makes the customer solely responsible for validating them, and states that Conga does not monitor or review AI generated outputs. The product page mentions guardrails without saying what they do.

Leah
Not addressed

The home page and the AI governance page describe no explicit path for Leah to decline to answer or abstain, and no confidence or grounding rating. The governance loop does produce rejections. Approvals, escalations and rejections are applied automatically according to the customer's rules. Those are policy outcomes set by configured guardrails, not the model declining because it cannot ground a response. Neither page says what Leah does when the customer's own contract set or playbook does not cover the question in front of it.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

Conga CLM
None located

The AI Hallucination Cases database maintained by Damien Charlotin tracks decisions worldwide where a court addressed hallucinated AI content, and records the tool implicated where known. It records no court order, opinion or disciplinary record naming Conga CLM or Conga. Two independent sanctions trackers of decisions on AI generated fabricated citations do not name them either. Conga CLM works on contracts and cites no legal authority, so its output does not ordinarily reach a court filing.

Leah
None located

The AI Hallucination Cases database maintained by Damien Charlotin tracks decisions worldwide where a court addressed hallucinated AI content, and records the tool implicated where known. It records no court order, opinion or disciplinary record naming Leah or the former company name ContractPodAi. Published 2026 sanctions trackers and trade press summaries name neither. The platform runs commercial contracting and procurement work rather than producing court filings, so its output does not ordinarily reach a brief.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Conga CLM
Not addressed

Conga's published materials name no bar or ethics guidance. ABA Formal Opinion 512 does not appear, no state guidance on generative AI in legal practice is referenced, and nothing maps a capability to a jurisdiction's rules of professional conduct. Conga does cite outside frameworks, but none of them is professional responsibility guidance. The Artificial Intelligence Addendum ties governance to the NIST AI Risk Management Framework, and the trust center classifies the products as minimal or limited risk AI systems under the EU AI Act.

Both are addressed to the vendor as an AI provider. The nearest thing to a professional responsibility statement is the Addendum's requirement that the customer not rely on AI outputs as the sole basis for a decision with legal impact. It also requires the customer to exercise independent judgment. It names no guidance.

Leah
Not addressed

Leah publishes nothing that engages with bar or ethics guidance. That includes ABA Formal Opinion 512, state bar guidance in the United States, and Solicitors Regulation Authority or Law Society material. The company is headquartered in London and sells into legal departments across North America, Europe, Asia and Australia. Its published compliance material covers regulation and security frameworks, namely GDPR, CCPA, HIPAA, SOC and ISO. None of it addresses the professional conduct obligations that bind the lawyers using the product.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Conga CLM
Outside the fee relationship

The product does not touch a fee between a lawyer and a client, because the teams that buy it bill no client for the work. The named audiences are in house functions, legal, procurement, sales, finance, IT and business operations, each with its own page. The named customers are corporate, among them an airline, an insurer, a property data business, a consumer fitness company and a professional network. Nothing is addressed to a law firm billing a client.

Conga's efficiency claims include a 9 percent revenue increase, 50 percent less review time with AI, faster deal cycles and lower supplier costs. All of them concern the buyer's own cost, cycle time or revenue, and none reaches a client bill. The platform also runs quoting, pricing and billing, but that is the customer billing its own customers rather than a lawyer billing a client. Conga publishes nothing on disclosure of AI use or AI cost in any fee context.

Leah
Savings claims only

Leah frames its public materials around cost and time removed, quantified at portfolio level. It cites a 91 percent cut in contract review time, more than $18 million of revenue protected and more than $2 million of tracked savings. Its headline figures are more than $125 billion of commercial value managed and more than $10 billion of ROI impact delivered. No per matter record of AI assisted work for fee purposes is described, and no guidance on billing, fee or client disclosure treatment is published.

The vendor describes an immutable audit log of every action, which could in principle support such a record, but does not present it for that purpose. Leah sells to in house functions rather than firms billing clients, so the costs in play are internal cost and outside counsel spend. Its materials address neither.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Conga CLM
Disclosure pack published

The documents a company would forward to answer a counterparty's AI clause are published and ungated. Conga's trust center names Google Cloud Vision for optical character recognition, Amazon Textract for table detection, Zuva for provision extraction and Azure OpenAI for language processing. It states a zero retention arrangement with each and explains what Azure OpenAI does and does not do with prompts and completions.

A subprocessor list is published at conga.com/privacy/subprocessors-and-subcontractors. The Data Processing Addendum applies Clause 9(a) Option 2 of the Standard Contractual Clauses to that list, with fifteen days' notice, a right to object and termination with a refund. Two documents a client can read are published in full. One is the Data Processing Addendum, with the SCCs and the UK and Swiss adaptations. The other is a separate Artificial Intelligence Addendum written for a customer's counsel.

Leah
Subprocessors listed

The data processing agreement is Annex B of the Master Terms and Annexes v3.0c. The DPA Setup Page lists every subprocessor with its purpose, location and the product it serves. The list names ABBYY OCR SDK, Anthropic PBC, Cohere Inc., DocuSign or Adobe, Google AI/ML and Google Cloud, Jitterbit, Microsoft Azure Services, OpenAI LLC, QlikTech, Sendgrid, ZOHO, Zuva and four ContractPod group entities. Anthropic, OpenAI, Cohere and Google AI/ML are each listed against Leah Functionality as model providers, noted as storing or retaining no Customer Data, with named jurisdictions.

The DPA itself is the Bonterms DPA, published openly in the same PDF and ready to forward. It incorporates EU Standard Contractual Clauses Modules 2 and 3 and the UK International Data Transfer Addendum. It sets out processing details in Schedule 1 and fixes a 48 hour notice period for security incidents. Clause 4.3 commits to listing any new subprocessor and giving at least 30 days' notice before it processes anything.

Clause 4.4 gives an objection right, with termination and a refund if the objection is not resolved. Version 4.0 of January 2026 changes only the trading name, according to the vendor.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Conga CLM
Partial record

The platform keeps a complete audit trail of every action, approval and signature across the contract lifecycle, which the vendor describes as supporting legal or internal reviews. It also keeps version control, tracked edits and inline comments. AiMe shows how every recommendation is generated and the reasoning behind AI driven actions, and confidence scores accompany each suggestion, so the basis of a proposed clause is visible at review.

No report or extract is described as identifying which model produced a passage, and the model is not named beyond a family. Conga describes no document level export, no marking of machine generated text against human edited text in a form a party could give a court, and no disclosure template, certification form or court guidance.

Leah
Partial record

The audit stage of Leah's published governance loop logs every decision. Each entry records what the agent did, why, under which policy, with what data and with what outcome. The records are described as tamper resistant, immutable and ready for any audit. That gives the action, the rule, the inputs and the result for each action. The published description of the log does not include the model. The platform chooses among several language models for each task and identifies no model or version, so the log does not show which system produced a given passage.

No export built for court disclosure or AI use certification is described. The audit framing is regulatory and internal rather than judicial.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • Commercial Transparency
Signals neither addresses in public material
  • Good Law Verification
  • Bar Guidance Alignment

Which one fits

Choose Conga CLM if

  • You run sales and contracting on Salesforce. Conga CLM has an edition built natively on Salesforce and listed on the AppExchange. Pricing, terms and configurations flow into the contract from Conga's quoting product.
  • You want reviewers to see why the AI suggested something. AiMe shows how each recommendation was generated and the reasoning behind it, with a confidence score on every suggestion. Every action and approval lands in an audit trail.
  • Your privacy team wants certificates and a listing it can check. Conga states SOC 2 Type II across the full platform, ISO 27001 and 27701, and annual HIPAA Security audits. Its Data Privacy Framework certification can be checked on the public Department of Commerce list.

Choose Leah if

  • You want the loss terms in figures. Leah caps liability at a year of fees and triples that for breaches of its security or data protection terms, leaving indemnities uncapped. Conga's AI terms, by contrast, disclaim liability for AI output.
  • Your systems of record are SAP, NetSuite or Coupa. Leah names those integrations alongside Okta for identity. It builds in DocuSign and Adobe Sign for signing and redlines inside Microsoft Word.
  • You want no training on your contracts at all. Leah says customer contract data is never used to train models. Conga permits training into a model specific to the customer's own tenant.

In summary

Conga CLM

Conga CLM is the contract product in Conga's commercial operations suite. It comes as the original application built on Salesforce, or as an edition on the Conga Advantage Platform that Conga says works beside any CRM or ERP. It runs requests, generation from clause libraries, negotiation in Word or Google Docs, approvals, signature and renewal tracking. According to the AI Legal Index, Conga's case rests on AI terms written into its contract. The Artificial Intelligence Addendum keeps any training on customer data inside the customer's own tenant and bars third parties from training on it. It also makes the customer responsible for checking every output. No price or unit of charge is published.

Source: AI Legal Index, 2026

Leah

Leah, formerly ContractPodAi, is ContractPod Technologies' agentic platform for enterprise contracting, legal, procurement and finance teams. Underneath is a contract lifecycle product with intake, playbook review in Microsoft Word, approvals with automatic escalation and an obligation repository. On top sits the Agentic OS, with agents directed by Leah Maestro. The AI Legal Index records a published three stage governance loop of customer policy, governed execution and audit. Leah's master terms publish liability caps, an intellectual property indemnity and uptime tiers. Its data processing pages name Anthropic, OpenAI, Cohere and Google. No price, accuracy figure or privilege position is published.

Source: AI Legal Index, 2026

Questions buyers ask

Conga CLM vs Leah: which is better for enterprise contracting?

The systems you already run decide much of it. Conga CLM fits a team on Salesforce or Conga's quoting product that wants AI suggestions explained with a confidence score. Leah fits a team on SAP, NetSuite or Coupa that wants agents across contracting, procurement and finance under a governance loop it configures. Both publish their oversight in detail. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Do Conga CLM and Leah train AI on customer contracts?

Conga's AI Addendum allows training on customer data only into a model specific to that customer's tenant, and bars third parties from training on it. It reserves anonymized, aggregated usage data for training and refining models, and no opt out is published. Leah says customer contract data is never used to train models. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Which AI providers do Conga CLM and Leah use?

Conga names Azure OpenAI for language, Google Cloud Vision for character recognition, Amazon Textract for tables and Zuva for clause extraction, each under zero retention. Leah names Anthropic, OpenAI, Cohere and Google with their jurisdictions, and Zuva sits on its subprocessor list too. Neither names a model version. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Who is liable when Conga CLM or Leah AI output is wrong?

Under Conga's Artificial Intelligence Addendum, the customer is. Conga disclaims any warranty on AI output and any liability for reliance on it or on agent actions. Leah's master terms cap liability at a year of fees, triple for breaches of its security or data protection terms, but they also give no indemnity for AI output. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

What do Conga CLM and Leah both leave unpublished?

Neither publishes a price, an accuracy or error rate for AI review and extraction, or a named model version. Neither addresses attorney client privilege in its AI terms or product pages. Neither engages with bar guidance such as ABA Formal Opinion 512, though sales and procurement teams use both products alongside lawyers. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Disclosure

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything on it comes from public material on the dates shown. How the index grades.

Conga's general liability cap and indemnities sit in its separate Master Services Agreement, while its AI Addendum disclaims liability for AI output. Conga's training limits are contractual, while Leah's no training promise is a published policy. One detail links the two supply chains, since Zuva appears as a subprocessor for both. Neither vendor reviewed this page.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
October 8, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746