Contract Logix vs Gatekeeper: how they compare in 2026

C
Contract Logix profile
G
Gatekeeper profile
Last verifiedSeptember 25, 2026

Contract Logix and Gatekeeper both sell contract lifecycle management to legal, procurement and finance, with AI that extracts terms from signed agreements and reviews drafts against approved language. Gatekeeper sits in the top two bands on eleven of fifteen axes and Contract Logix on eight of fifteen. The difference is what each publishes about its AI before a buyer signs. Gatekeeper's AI terms bar training on customer input by it or any provider, its data processing agreement names Amazon Bedrock and Anthropic among its subprocessors with each one's location, and it lets customers pick one of four AWS hosting regions, commits to breach notice within 72 hours and binds itself by contract to keep ISO 27001. Its terms also require customers to label AI output before publishing it. Contract Logix, owned by LegalSifter since October 2024, keeps its customer agreement unpublished and names no model, attestation or price. Its counterweight is measurement, which is rare: it publishes an extraction accuracy of about 95 percent on standard fields, roughly 99 percent with human validation, and a named customer who went from three days to five minutes on one contract question.

At a glance

Category
Contract LogixContract Review & Drafting
GatekeeperContract Review & Drafting
Founded
Contract LogixNot published
GatekeeperNot published
Headquarters
Contract LogixLowell, Massachusetts, United States
GatekeeperLondon, United Kingdom
Last verified
Contract LogixSep 13, 2026
GatekeeperSep 12, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Contract Logix
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models are the engine of core capabilities layered on a product that would function without them, which is the B band. Two AI capabilities are named, each with its own page and its own place in the lifecycle. The Contract Intelligence Engine is described as the AI extraction layer inside Contract Logix and runs post-execution: AI Contract Analysis detects which key terms and clauses are present in contract language, and AI Data Extraction, branded AIDE, pulls chosen properties into the platform as structured data. The supporting detail is more concrete than most in this lane: 92 pre-built standard fields, customer-defined fields driven by extraction prompts, Custom Data Objects for line-item detail with calculated fields and row-level dates, and portfolio-wide reprocessing against a new configuration without re-loading documents. Contract Logix Review runs pre-signature and delivers first-pass redlines against the organisation's own standards inside Microsoft Word or Google Docs, and the vendor states expressly that the two share a platform but are not stages in a sequence. What keeps this off A is that the product underneath is a full contract lifecycle management platform. Remove the models and the request intake, authoring, negotiation workflow, repository, permissions and automated tracking of obligations, renewals and milestones all remain, and those are what the company sold for years before either AI capability existed. The extraction layer converts what was manual data entry into an automated read of the signed portfolio, which is a large improvement to a system that stands without it. Verified 13 September 2026.

Gatekeeper
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models are the engine of a core capability layered on a product that would function without them, which is B. Gatekeeper has sold vendor and contract lifecycle management since well before the AI arrived, and LuminIQ is described by the vendor as an intelligence layer added to that platform, launched in March 2025 with a first agent for workflow approvals and agents added since. Underneath sits a complete platform that does not depend on it: repository, template and clause authoring, the Kanban workflow engine with mandated approval paths, integrated eSignature compliant with ESIGN, UETA and eIDAS, vendor and employee portals, spend module, risk register and balanced scorecards. The pricing page shows the same structure, listing Gatekeeper Agents and the AI Suite as capabilities within plans whose quota is measured in third-party records rather than in AI usage. What is recorded on the other side is direction rather than present state: the vendor now leads with agentic AI throughout, claims more than fifty agents, and describes them as a digital workforce that reads, reasons and acts. Remove them and the platform still runs the lifecycle, which is what keeps this off A. Verified 12 September 2026.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Contract Logix
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

An accuracy figure is published without the test set or the failure modes, which lands in the B band, and the shape of the disclosure is worth recording because it is rare. The product page states that AIDE delivers approximately 95 per cent or better accuracy on the standard extraction fields, rising to roughly 99 per cent with human validation in the loop. Publishing the delta is the notable part: it tells a buyer that the system is wrong on the order of one field in twenty unaided, which is closer to naming an error rate than anything else located in this lane, and it prices the human review step rather than assuming it away. Three things hold it at B rather than A. The A band asks for measured accuracy with the test set described and the failure modes named, and neither is published: nothing states what corpus the figure was measured on, how many documents or fields, of what type, or in which languages, and no failure mode is named, so a buyer cannot tell whether the missing five per cent is spread evenly or concentrated in particular field types. The qualifiers do real work in the vendor's favour, since approximately and roughly are not figures an outsider can test. And no independent validation of either number exists. R15 governs the remaining limbs and they are recorded as inapplicable rather than counted against the record: the grounding and linked-primary-source limbs do not bite on a system extracting from the customer's own executed contracts, because there is no external authority being cited whose existence could be fabricated. Verified 13 September 2026.

Gatekeeper
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is addressed only by disclaimer and grounding is claimed without a described method, which is C. R15 governs the inapplicable limbs: the product cites no legal authority, so authority grounding and citation-status checking do not bite. What bites is grounding and measurement. The grounding claim is real in outline, the agents working on the customer's own contracts and vendor records inside the platform, generating plain-language summaries from the uploaded agreement, matching clauses against approved language and extracting obligations, and the vendor states that agents explain every decision they make. That explainability claim is the strongest thing here and it is asserted rather than described: nothing published sets out what an explanation contains, what is retrieved, or how a proposed clause is traced back to the source text. Measurement is absent entirely, and the agreement makes the position explicit rather than leaving it implied. AI Terms clause 6.3 states that neither Gatekeeper nor any AI Provider makes any representation or warranty as to the accuracy, availability, suitability, reliability or content of Output, clause 9 excludes all warranties in relation to AI Functionality, and clause 6.6 requires the customer to check and evaluate the accuracy of any Output and not to rely on Gatekeeper to do it. No figure, test set, error rate or benchmark was located. Verified 12 September 2026.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Contract Logix
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

A written commitment that the models work alongside a human reviewer with a real review surface, short of the full control structure, which is the B band. What lifts this above an assurance is that the human step is quantified rather than asserted. The published accuracy claim is expressed as approximately 95 per cent or better unaided rising to roughly 99 per cent with human validation in the loop, so the vendor has priced the review step into its own headline figure and, by implication, told the buyer what happens if the step is skipped. Very few records in this corpus put a number on the difference the human makes. The second AI capability is framed the same way: Review produces first-pass redlines against the organisation's standards, and first-pass is the vendor's own characterisation of what the output is, which sets an expectation that a person completes the work. What the A band requires is not published. No threshold is stated at which the system defers or escalates, no confidence signal is described on an individual extraction, nothing states which fields or clause types the system will not attempt, and nothing describes what happens after an extraction is found to be wrong beyond the general ability to reprocess a portfolio against a new configuration. R124(2) was applied to the first-pass framing and it does not qualify: it describes the maturity of the output rather than attaching a boundary to a named tier stating what that tier's output may not be used for, which is the test that distinguished Verbit. Verified 13 September 2026.

Gatekeeper
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

A written commitment that the models work alongside a human decision-maker, with real review surfaces, short of the threshold at which the system acts alone. The commitment is contractual and specific. AI Terms clause 6.5 states that Output is a suggestion designed to assist and does not replace the need for the customer to use a human being to decide upon its suitability before it is published, used or relied upon. Clause 6.6 requires the customer to check and evaluate accuracy before use. Clause 7.4 goes further and bars the customer from using the AI to make automated decisions that may have a detrimental impact on individual rights without appropriate human supervision. The review surfaces are the workflow engine's own: mandated approval paths and thresholds, an audit trail across the lifecycle, and the vendor's claim that agents explain every decision they make, giving transparency and auditability. R37 rule 2 identifies what is missing. The same estate markets agents as a digital workforce that reads, reasons and acts, autonomously handling contract management and compliance validation, and those claims sit against a human-decides rule with no published boundary between them. No threshold, confidence level or class of work is published at which an agent proceeds or stops, and no mode structure is described. Verified 12 September 2026.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Contract Logix
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Real deployment evidence with substance, short of the attribution and method the A band requires, which is the B band. Scale is published as a figure rather than a gesture: more than 60,000 legal, procurement, finance and sales professionals use the platform, across what the company describes as hundreds of brands. One testimonial does the work that most in this corpus do not, joining a named organisation to a named role and a concrete before-and-after: the Director of Contracts at Soar Technology describes a question that used to take three days being answered in five minutes. That is a named customer, an identified seat and a figure in a single artifact, which is more than the B band's own description of the common failure, being a named customer without figures or figures without the named customer. Three things keep it from A. It is one instance, so the evidence is an example rather than a body. Nothing is dated, so a reader cannot tell when the deployment happened or over what period the improvement was observed. And no method accompanies the figure, so the three-days-to-five-minutes comparison cannot be assessed: nothing states what the question was, what the old process involved, or whether the comparison is like for like. The named accuracy figures on the product page are measurements of the model rather than of a deployment and are graded on the citation accuracy row instead of being counted twice here. Verified 13 September 2026.

Gatekeeper
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Real deployment evidence with substance, held at B on the method limb, and it sits at the top of the band. One account is named, figured and specific: CompSource Mutual Insurance, where the vendor reports a 95 per cent reduction in executive review time per contract, 636 hours saved annually described as the equivalent of 17 weeks of capacity, executives reviewing ten-line AI summaries instead of thirteen-page contracts, and the elimination of back-and-forth between legal, finance and procurement. That is attribution and measurement together, published in a dated January 2026 article. A second carries a figure and a named individual: Krupa Patel, Global Head of Procurement at Funding Circle, on terminating contracts worth $1.3 million. Three further named individuals with titles are quoted without figures, the Legal Operations Manager at BlaBlaCar, a Paralegal at Hakkasan Group and an Associate Corporate Counsel at Cricut, and a customer-story library is published. What holds it off A is the fourth limb: no method or basis is stated for any figure, so a reader cannot assess how 95 per cent or 636 hours was computed. Headline claims elsewhere are unattributed and should be read as marketing, including average vendor cost reduction of $1.3 million in year one, 75 per cent shorter cycle times and 400 hours saved per audit. Verified 12 September 2026.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Contract Logix
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Substantive published commitments on access and data handling, short of the full picture and silent on privilege, which is the B band. What is published is unusually detailed for a vendor with no published customer agreement, and it is operational rather than promotional. The security page describes role-based and feature-based permissions set by the customer's own administrator, a designated System Owner from the customer organisation who invites users and grants access in-application, mandatory email validation of every user, policy-driven passwords with complexity configurable by the customer, and single sign-on via SAML 2.0 against named identity providers. Personnel controls are described in more specificity than anywhere else in this lane, covering background screening and routine privacy, security and regulatory training. Data deletion and archiving is customer-set, with application and service-level controls supporting the customer's own policies and restore restricted to users holding the right role. The privacy policy is materially better drafted than several comparators because it covers privacy practices in connection with the services as well as the websites, so the platform is not carved out. Three limbs fail. Privilege and work product are not addressed anywhere located. No position is published on what any AI model provider may see or retain, because no provider is identified at all. And the substantive contractual commitments sit in an agreement that is not published, the website terms expressly carving out a separately executed customer agreement, so a buyer cannot read the confidentiality terms before entering a sales conversation. Verified 13 September 2026.

Gatekeeper
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Four of the five A limbs are met on published instruments and the fifth is absent, and R33 makes the absent one decisive. Training use is the strongest limb and it is contractual: AI Terms clause 5 states that Input is not used to train or fine-tune any underlying machine learning model, whether proprietary or third-party, and that Gatekeeper prohibits AI Providers from retaining, accessing or using Input or Output to train their models; clause 12 repeats it and adds that no Content is retained by AI Providers beyond the session and no model training, fine-tuning or dataset enhancement is performed. Segregation is documented in the DPA's security schedule, customer data being stored in a way that logically separates it from other customer data, with a unique per-customer encryption key generated using a FIPS 140-2 compliant library and a master key released only through multi-level executive authorisation. Retention and deletion are stated: deletion or return at the customer's choice, all copies removed within 60 days of termination and from backups within a year. The third-party model provider position is explicit, the AI Providers being named sub-processors barred from retention and training. The limb that fails is privilege and work product, which is addressed nowhere. On a platform whose own legal-teams page invites counsel to hold their contracts in it, that silence is the whole distance to A. Verified 12 September 2026.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Contract Logix
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Nothing published on the advice line was located for a product that produces legal work and is sold to people who are not lawyers, which is the D band including its own parenthetical. The parenthetical fits directly. The stated audience is legal, procurement, finance and sales, and the platform carries solution pages by department, role, process and company size, so non-lawyers are an intended and named user group rather than an incidental one. What the AI produces for them is legal work on any ordinary description: Contract Logix Review delivers first-pass redlines against the organisation's standards inside Word or Google Docs, and the Intelligence Engine detects which key terms and clauses are present in an executed contract. Nothing published states whether that output is legal advice, whether a lawyer should review a redline before it reaches a counterparty, what a procurement or finance user may rely on it for, or who inside the customer is accountable when the extraction of a governing law or indemnity clause is wrong. The grade is recorded knowing the vendor addresses legal buyers seriously, which is why it is worth saying that this is not an audience-ambiguity problem. There is a dedicated Legal Department page naming General Counsel, Paralegal and Compliance Officer with a role page each, and a published Corporate Counsel's Guide to contract lifecycle management. The audience is clearly identified; it is the professional line through the middle of it that is unaddressed. No competence or supervision statement and no jurisdiction limit for the AI were located. Verified 13 September 2026.

Gatekeeper
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

A real published position on advice versus tooling, short of full treatment, and with an omission worth naming. The position is contractual: AI Terms clause 6.5 states that Output is a suggestion and does not replace the need for a human being to decide on its suitability, clause 6.6 puts checking and evaluating accuracy on the customer, and clause 6.6 adds an obligation this corpus has not seen before, that prior to publication or distribution of any Output the customer must add a disclosure notice that it was generated by AI tools. Clause 7.1 bars using the AI to mislead anyone that Output is human-generated. Clause 7.4 requires appropriate human supervision for automated decisions affecting individual rights. The omission is the interesting part and is recorded rather than inferred: clause 7 restricts the customer from using the AI to offer tailored financial advice without a qualified person reviewing it, and from providing health advice, and names no equivalent restriction for legal advice, on a platform sold to legal teams for clause review and redlining. No statement that Gatekeeper is not a law firm was located anywhere. What is also missing for A is the supervision and competence dimension, any statement of who may operate which agent, and any jurisdictional limit. Verified 12 September 2026.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Contract Logix
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

Nothing published on AI governance was located, which is the D band. The page inventory was taken from the navigation and footer under R20 and covers the platform pages, the Contract Intelligence Engine, Review, Organize, security and data privacy, hosting on Azure, integrations, the solution pages by industry, department, role, process and company size, the company pages, the news section and the blog. No responsible AI page, AI policy, AI principles statement, acceptable use position or AI governance section exists anywhere in it. No framework is named, whether NIST, ISO 42001 or any other. No accountable owner for model behaviour is identified. No testing regime is described and no evaluation result is disclosed beyond the headline accuracy figures, which measure output quality rather than governance and are graded on the citation accuracy row. Bias is not addressed in any form. The absence is established rather than untested: the vendor publishes a detailed security page, a substantive privacy policy and a product page carrying a quantified accuracy claim, so this is an estate that documents itself carefully and has not extended that habit to how the models are governed. It is worth naming what that means for a buyer on this particular product. The Intelligence Engine's extractions populate the obligation and renewal tracking the platform is bought for, and Review's redlines are applied against the organisation's own standard positions, so uneven model behaviour across contract types, counterparties or languages would propagate silently into the record and nothing published would let a buyer test for it. Verified 13 September 2026.

Gatekeeper
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

Governance is expressed as contractual constraint rather than as a programme, with no mechanism, testing regime or accountable owner published, which is C. The substance that keeps it off D is real and unusually detailed for a terms document: the AI Terms define AI Functionality, bind the AI Providers as sub-processors subject to change notification, prohibit training on Input, and set out thirteen acceptable-use restrictions covering misleading users about machine authorship, unsupervised automated decisions affecting individual rights, activities with high risk of economic harm, unqualified financial advice, health advice, political campaigning and lobbying, and attempts to reverse engineer or replicate the models. That is a published position on what the AI may be used for. None of what the higher bands ask for is present. No responsible AI or AI governance page exists, no framework is named and no certification against one such as ISO 42001 is claimed, nobody inside the vendor is identified as accountable for AI, nothing is published about what is evaluated before an agent ships or how an agent's behaviour is tested, and nothing addresses uneven output across contract types, counterparty drafting or jurisdictions. An Executive Guide to AI Risk Management is published as a marketing download and concerns managing AI as a third-party risk in the reader's own supply chain rather than governance of this vendor's own AI. Verified 12 September 2026.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Contract Logix
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Substantive published policy covering most of the ground, short of the full set on subprocessors and incident practice, which is the B band and both of the gaps it names. Deletion and archiving are addressed with an approach that is genuinely customer-led rather than vendor-stated: application and service-level controls support the customer's own deletion and archiving policies, the customer sets its own requirements for how data should be deleted and archived, and restore is restricted to users holding the appropriate role. Access control is the strongest limb, with role-based and feature-based permissions administered by the customer, a designated System Owner, email validation of every user, configurable password policy and SAML 2.0 single sign-on against Azure Active Directory, ADFS, DUO, Okta and Ping. Personnel security is described in unusual detail, covering background screening and routine privacy, security and regulatory training including HIPAA. Hosting on Microsoft Azure has its own page. Two limbs are missing and they are the two the band anticipates. No subprocessor list exists: the privacy policy refers to service providers and states they may be located outside the United States, without naming one, so a buyer cannot establish who touches its contracts. And no incident practice is published, with no breach notification commitment, no notification window and no description of what a customer would be told or when. Nothing states a retention period for prompts or extraction outputs as distinct from stored contracts. Verified 13 September 2026.

Gatekeeper
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

Retention, deletion, access control, subprocessors and incident practice are all published, current and specific enough to hold the vendor to, which is the A band, and all five rest on the ungated Data Processing Agreement rather than on a marketing page. Retention is bounded in three layers: AI Content is processed transiently and not retained by AI Providers beyond the session under the AI Terms; personal data is retained for the duration of the agreement; and a published data classification scheme drives a retention policy under which deleted records are permanently evicted from active databases. Deletion is specific: delete or return at the customer's choice, all copies removed from systems within 60 days of termination and from backups within one year, with export and permanent erase tools built into the product. Access control is documented in detail: least privilege and need-to-know roles, two-factor VPN for production access, unique per-customer encryption keys from a FIPS 140-2 compliant library with master-key release requiring multiple levels of executive authorisation, AES-256 at rest, TLS in transit, SIEM logging and alerting, and STIG-based configuration management. Subprocessors are named individually with purpose and location in Exhibits C, with 30 days' notice of change, ten business days to object and a right to terminate. Incident practice is contractual: notification without undue delay and in any event within 72 hours of discovering a personal data breach. Verified 12 September 2026.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Contract Logix
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

No published position on liability for AI output was located, which is the D band, and the cause is a choice rather than a retrieval limit. The footer Terms and Conditions are website terms on their face: they govern use of the Site and apply to visitors, users and others who access the Site. Their entire-agreement clause expressly carves out any current mutually executed written agreement between the customer and Contract Logix, which establishes two things at once. A customer agreement exists, so the silence is not because the vendor has nothing; and it is not published, so a buyer cannot read the allocation of risk before entering a sales process. That distinction matters for how this D is read: this is not a vendor that failed to draft the terms, it is one that declines to publish them. Consequently nothing is established on any limb the axis tests. No warranty of any kind attaches to the extraction output, notwithstanding that the vendor publishes an approximately 95 per cent accuracy figure and therefore acknowledges a material error rate. No liability cap is stated. No indemnity in either direction is published. No service level, no uptime commitment and no insurance position were located. Nothing addresses who bears the loss when a mis-extracted renewal date or liability cap propagates into the obligation tracking the platform is bought to run. What the website terms do settle is jurisdiction: Massachusetts law, non-exclusive. R85 does not apply, because nothing was blocked. Verified 13 September 2026.

Gatekeeper
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

Liability for what the AI produces is addressed only by disclaiming it, and here the disclaimer is more complete than most, which is C. AI Terms clause 9 excludes all warranties in relation to AI Functionality and states that no warranty is given for the accuracy, availability, suitability or reliability of Content. Clause 6.4 states that Gatekeeper has no liability or responsibility resulting from the use of or reliance upon any Output, or for any errors or omissions in it. Clause 10.1 extends that to any damages arising in connection with use of, or inability to use, the AI Functionality, regardless of the form of action and expressly including negligence. Clause 11 runs the indemnity the other way, the customer defending Gatekeeper and the AI Providers against third-party claims relating to Content. Two provisions run in the buyer's favour and are recorded rather than credited, because neither answers what happens when the output is wrong: the DPA makes Gatekeeper liable for breaches caused by its sub-processors to the same extent as if it performed their services directly, and the vendor publishes an insurance position, worldwide cover at an A rated standard including cyber cover extended to IT forensics, legal advice, notification costs and credit monitoring. That is breach cover, not output cover. The Master Subscription Agreement's general cap was not read and is named as unestablished on this row. Verified 12 September 2026.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Contract Logix
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Real integrations exist and named connections are documented, short of the depth the A band describes, which is the B band. The strongest evidence is that one of the two AI capabilities runs inside the applications the work already happens in: Contract Logix Review delivers its first-pass redlines inside Microsoft Word or Google Docs, so a negotiator does not leave the drafting surface to use it. That is integration into a system legal work lives in rather than a connector list. Identity integration is documented with named counterparties rather than described generically, single sign-on running over SAML 2.0 against Azure Active Directory, ADFS, DUO, Okta and Ping, which is enough detail for an implementer to know whether their estate is covered. A dedicated Integrations page exists in the platform navigation and hosting on Microsoft Azure has its own page. What the A band asks for and was not established is depth: what each connection moves, in which direction, and what a customer must configure. No practice management, document management, matter management or e-signature system is named as supported on the surfaces read, and no ERP or procurement suite is named, which matters because procurement and finance are two of the four stated buyer groups and those buyers would be integrating with systems of record. The Integrations page itself was not opened; under R25 it corroborates a grade that stands on the Word and Google Docs hosting and the named identity providers, and it is what would move this row. Verified 13 September 2026.

Gatekeeper
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Real integrations, named and documented, short of the depth an implementer could work from, which is B. The named connections are substantial. Gatekeeper is a NetSuite SuiteApp, described as the only Built for NetSuite application for contract and third-party management and as NetSuite Partner of the Year 2024, and the marketplace listing describes sales teams working entirely within Salesforce while legal works in Gatekeeper. Identity integration is specific: SAML 2.0 and OAuth 2.0, Google and Microsoft 365 single sign-on, official partnerships with Okta and OneLogin, and SCIM 2.0 user provisioning on higher plans. A RESTful API into any Gatekeeper data point is published as a plan feature, an integration product called Gatekeeper Interconnect is offered as no-code, Workato appears as an integration sub-processor in the DPA, and a Model Context Protocol connector is listed as a plan feature for connecting LuminIQ to the customer's own tools. Two things hold it off A. What actually syncs, in which direction, and what a customer must configure is described only for the NetSuite path, at the level of vendor, contract and spend data. And the count of supported third-party solutions is inconsistent across the estate, given as over 220 on the platform page and over 4,000 on another, which is recorded rather than resolved. Verified 12 September 2026.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Contract Logix
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Cloud delivery is named without either the tenancy model or the region, which under R38 is the C band because tenancy and region are co-equal limbs and neither is published. What is published is the hosting arrangement: Microsoft Azure-based cloud products, with a dedicated page for it, and the security page describes Azure-supported infrastructure controls. Under ground rules section 3 and R16 that is the infrastructure provider's arrangement rather than a residency commitment, and it is recorded as such rather than credited as one. Naming the hyperscaler tells a buyer whose data centres are involved and nothing about where its own contracts sit. Region is unaddressed. No data centre location, country or region is stated anywhere located, no regional election is offered to customers, and no data residency page exists. The one statement bearing on location runs the other way and is recorded because a buyer with cross-border obligations needs it: the privacy policy states that the company's service providers may be located outside the United States, without naming them or the countries involved. Tenancy is equally unaddressed. Nothing states whether a customer's contract repository sits in a shared or isolated environment, no separation model is described, and no single-tenant, private cloud or on-premises option is offered or refused. Nothing states where the extraction models run relative to where documents are stored. The absences are established rather than untested, the estate carrying a dedicated hosting page and a detailed security page that address neither. Verified 13 September 2026.

Gatekeeper
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

Deployment options and residency are published to a level no other record in this lane reaches, which carries the A band. Four hosting regions are named individually and the customer chooses: the DPA's infrastructure sub-processor table lists Amazon Web Services for data hosting in the USA, Ireland, Australia and Canada, and the enterprise page states that a customer may select any region to support its data sovereignty requirements. A second deployment option is published alongside the shared cloud, a Gatekeeper private cloud for bespoke requirements. Where processing happens is stated as distinct from where data is stored, and stated per processor rather than in the abstract: the group companies that provide support and development are listed individually with their locations, Jersey, the United Kingdom, the United States and Canada, each with its transfer mechanism, EU adequacy for the first two and Standard Contractual Clauses with encryption for the others, and the AI providers carry their own locations, Amazon Bedrock across the same four regions and Anthropic in the United States only. Resilience detail is published too: data stored in triplicate across two data centres with two separate cross connections and stateless applications recreatable in other regions. The one soft limb, recorded rather than hidden: what the private cloud changes relative to the standard tiers is not described. Verified 12 September 2026.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Contract Logix
DD on Security Certifications and Trust CenterNo independent security attestation located.

No independent security attestation was located, which is the D band. No SOC 1, SOC 2, ISO 27001 or equivalent certification is claimed anywhere on the estate, no penetration test summary or third-party assessment is referenced, and there is no trust centre, compliance page or security portal. What exists in place of attestation is a self-description: a detailed security page setting out the vendor's own controls, covering permissions, single sign-on, password policy, employee background screening, training including HIPAA, customer-set deletion and archiving, and Azure-based hosting. Those are the vendor's statements about itself and the axis asks for something a third party has checked. One certification claim exists and is expressly not credited, on the standard pull 7 set for this record. The privacy policy claims certification under the EU-U.S. Data Privacy Framework, the UK Extension and the Swiss-U.S. DPF, names BBB National Programs as the independent recourse mechanism, and acknowledges FTC investigatory jurisdiction. Two things follow. First, the DPF is a self-certification programme administered by the Department of Commerce rather than an independent audit, so even verified it would not answer what this axis asks. Second, it could not be verified: dataprivacyframework.gov is a client-side search application and no participant record was reached, on this pass or in pull 7. Under R85 and rule 6.6 that is a retrieval limit recorded as such, it is not evidence the certification is absent, and nothing adverse is inferred from it. It is simply not credited unverified. Verified 13 September 2026.

Gatekeeper
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Certification is real and stated, short of accessible evidence, which is B. The standards are named and the estate is broad: ISO 27001, ISO 9001, SOC 2 Type II completed and announced in January 2026, and SOC 1 Type 2. One commitment is stronger than a badge and is contractual, appearing in both the Terms of Service and the DPA's security schedule: Gatekeeper shall maintain its ISO 27001 certification, or an equivalent, throughout the term of the agreement, and will not use third-party data centres that do not hold equivalent certification. The DPA sets out the audit regime, an external audit performed at least annually to ISO 27001 standards by independent third-party security professionals at Gatekeeper's expense, alongside a statement elsewhere that all global hosting locations are independently audited quarterly by two security specialist firms. What holds it off A is access to the evidence. The resulting Report is designated Gatekeeper's confidential information and is provided only on written request, no more than once in any twelve months, and subject to the confidentiality terms; no auditor is named, no report period or certificate number is published, and no scope statement accompanies any standard. A Security Center exists at trust.gatekeeperhq.com and is Vanta-hosted; it returned page metadata with no body to this index's fetcher on 12 September 2026, which is a limit on the reader under R20 and not a finding about the vendor. Verified 12 September 2026.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Contract Logix
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

Nothing published about the model supply chain a customer inherits was located, which is the D band. The product pages describe what the AI does in real detail, covering 92 pre-built extraction fields, extraction prompts, Custom Data Objects, portfolio reprocessing and an accuracy figure with a human-validation delta, and say nothing whatever about what performs the work. No model is named, no version is given, no provider is identified, no distinction is drawn between proprietary and third-party models, and no architecture is described beyond the branding of the Intelligence Engine and AIDE. Nothing states whether Review's redlining and the Engine's extraction run on the same models. Recorded and expressly not credited under ground rules section 3 and R16, because it is the obvious candidate for a misread: Microsoft Azure is named as the hosting platform and has its own page, and single sign-on runs against Azure Active Directory among others. Naming the cloud a system runs on is infrastructure disclosure, not model disclosure, and it does not tell a buyer whether an Azure-hosted service, an Azure OpenAI deployment, a third-party API or an in-house model reads its contracts. Nothing addresses what any provider may retain of a document sent for extraction, and no commitment to notify customers of a change is published. The absence is established rather than untested: the vendor publishes a subprocessor-shaped statement in its privacy policy referring to service providers who may sit outside the United States, and names none of them. Verified 13 September 2026.

Gatekeeper
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

The supply chain is partly disclosed and stops one limb short of A, which is B under R34. Providers are identified by name in an ungated contractual document rather than referenced in the abstract: the Data Processing Agreement's sub-processor table names Amazon Bedrock as an AI Provider operating in the USA, Ireland, Australia and Canada, and Anthropic, PBC, described as providing AI language model services powering internal workflow automation, in the United States. Where they run is therefore stated per provider. Change notification is contractual and specific: 30 days' prior notice by email of any change to the sub-processor list, a ten business day window to object, and a right to terminate the affected services if no alternative can be provided. The AI Terms bind the providers further, permitting them to use Input only to create Output and prohibiting retention or training. The limb that fails is the first. No model is named anywhere, and Amazon Bedrock is a hosting service for models rather than a model, so a reader learns the route customer text travels without learning what generates the answer. Two cross-reference defects are recorded rather than resolved: the AI Terms define AI Providers as those set out in clause 3, and clause 3 does not set them out but points to the sub-processor list; and the DPA's Exhibit A refers to a sub-processor list published in Exhibit D, while the document's tables appear at Exhibit C. Verified 12 September 2026.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Contract Logix
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing information is published at any level, including the unit of charge, which is the D band. The page inventory taken from the navigation and footer under R20 carries platform pages, product pages, solution pages by industry, department, role, process and company size, company pages, news and a blog, and a demo request route. There is no pricing page. No rate, band, per-seat figure, minimum commitment, term length or implementation charge appears anywhere on the estate, and the website Terms and Conditions govern use of the site rather than any subscription, with the commercial terms sitting in the separately executed customer agreement that is not published. So a buyer cannot establish even the shape of the commercial model from first-party material: not whether the platform is charged per user, per contract, per seat tier or by volume, and not what implementation adds. Under R10's closing discipline no structure means no row, and a page that only invites a sales conversation is an absence belonging in this note alone, so no VendorPricing row is written for this record. Recorded because it bears on how the D is read and because R41 excludes it from the grade: third-party aggregator listings describe a subscription model varying by user count, contract volume and feature tier, name Submitter, Read-Only and Full-User subscription levels, and state that implementation is charged separately. None of that is first-party, none of it is credited, and one such listing gives the starting price simply as contact vendor, which corroborates that nothing is published rather than that anything was missed. Verified 13 September 2026.

Gatekeeper
CC on Commercial TransparencyPricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not.

Pricing is gated behind a demo while tier names and feature splits are published, so the shape is visible and the number is not, which is the C band in its exact terms. What is published is more than most gated pages carry. Three tiers are named, Pro, Enterprise and Enterprise Plus, and the unit of charge is stated plainly rather than implied: the quota is the number of third parties managed, banded at up to 250, up to 750 and more than 750, with archived third parties excluded from the count. A feature matrix of roughly twenty rows sets out what differs, and several entries are notable for being unlimited on every tier, including users, live and archived contracts, eSignature licences and senders, and Gatekeeper Agents. Where the tiers diverge is published too: two best-practice AI-enabled workflows on the lower tiers against more above, one custom workflow rising to two and then more, and API access, Model Context Protocol connectivity, SCIM provisioning, remote backup and granular sensitive-data controls positioned as higher-tier capabilities. One item carries its own unit, MarketIQ Full being marked usage based. No figure, band, term, minimum or implementation cost appears anywhere, and the only route to a number is a demonstration request. Commercial terms were not read: the Master Subscription Agreement was not opened. Verified 12 September 2026.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Contract Logix
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Segment coverage is described with real substance and the boundaries are left open, which is the B band. The legal buyer is addressed on a dedicated page rather than inferred from a list, which is what settled 5.4 on route A for this record: a Legal Department page opening on the people who run Legal's contracts every day, with three legal seats named and given a page each, being General Counsel, framed around governing the contract portfolio with visibility, control and standard positions, Paralegal, and Compliance Officer, supported by a published Corporate Counsel's Guide to contract lifecycle management. Beyond legal, coverage is organised along four axes at once, with solution pages by industry, by department, by role, by process and by company size. Named industries include healthcare, manufacturing, pharmaceutical, and oil, gas and energy, which is a coherent regulated-and-heavy-industry cluster rather than a scatter. Scale is published at more than 60,000 professionals across hundreds of brands. What is left open is the boundary in both directions. No contract type or agreement family is named as well or poorly handled by the extraction models, and the 92 standard fields are counted without being enumerated or scoped, so a buyer cannot tell whether its own agreement types are covered. No language coverage is stated. No customer size floor or ceiling is given despite company size being a published navigation axis. And the record should be read knowing legal is one of four stated buyer groups alongside procurement, finance and sales, which is a real difference from the specialist tools in this lane. Verified 13 September 2026.

Gatekeeper
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Segment coverage is described with substance and the boundaries are left open, which is B. The buyer groups are named consistently and legal is one of three, addressed on a page of its own at /legal-teams that speaks to counsel directly about clause deviations, missed approvals, policy enforcement and being brought in too late to prevent risk, alongside procurement and finance, with the CFO named as a fourth audience on the AI page. That page answers the seed's concern that this is a procurement product with legal attached. Coverage is also described by task rather than only by audience, through six published use-case pages spanning contract creation and execution, renewals and amendments, vendor onboarding, vendor performance, third-party compliance monitoring and vendor consolidation, each with its own claimed outcome. Named users support the spread across functions, from a Legal Operations Manager and a Paralegal to a Global Head of Procurement. What is left open holds it off A. No practice area within a legal department is identified as supported or unsupported, no industry pages were located, nothing states what the product is not for, and no jurisdictional coverage statement appears despite four hosting regions and group companies on three continents. Verified 12 September 2026.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Contract Logix
Purpose limited, in the contract

Customer content is stated to be used only for delivering the service, with no separate training permission and no training prohibition either, which is this value and the disposition of the item carried into pull 8. The privacy policy is the operative surface and it is better drafted than several comparators in this lane, covering privacy practices in connection with the services as well as the websites, so the platform is not carved out and the commitments reach uploaded contracts rather than only site visitors.

Within it, processing is framed by purpose: personal information is handled for the purposes for which it was collected or subsequently authorized, sensitive information attracts an affirmative opt-in before any disclosure to a third party or any use beyond the original purpose, and onward transfers to service providers carry a continuing responsibility. What is absent is any sentence in either direction about models.

No provision permits customer content to train, fine-tune or improve any model, and no provision prohibits it. So the buyer is left with a purpose limitation that would not obviously admit training, and no express confirmation. Two points bound the value. This is a policy position rather than a contractual one: the website terms carve out a separately executed customer agreement which is not published, so the contractual values on this signal cannot be reached and R43(1) is run but not discharged.

And no model provider is identified anywhere on the estate, so nothing states what any third party may do with a document sent for extraction.

Gatekeeper
Never, in the contract

The published agreement prohibits training on customer content, without qualification and in two places, which is the top value and the first record in pull 8 to reach it. AI Terms clause 5 states that Input is not used to train or fine-tune any underlying machine learning models, whether proprietary or third-party, that Gatekeeper prohibits AI Providers from retaining, accessing or using Input or Output to train their models, that Input and Output are processed transiently and not stored or reused beyond what is required to deliver the Services, and that no Input or Output is used for model improvement, corpus building or similar training-related purposes.

Clause 12 repeats the commitment in its own right: Gatekeeper does not use any Content to train any machine learning models, and no Content is retained by AI Providers beyond the session, with no model training, fine-tuning or dataset enhancement performed. This is an agreement rather than a policy page, published ungated and incorporated into the Master Subscription Agreement, and clause 2 provides that the AI Terms prevail over the main agreement in relation to AI Functionality.

The one boundary a reader should note is what the clauses cover: they govern Input and Output as defined, being data provided to and generated by the AI Functionality, and no separate statement was located about aggregated or anonymized usage data outside that definition.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Contract Logix
Customer controlled, no zero option

Retention is put in the customer's hands rather than fixed by the vendor, which is this value and an uncommon shape in this corpus. The security page states that the platform provides application and service-level controls to support the customer's own data deletion and archiving policies, and that the customer sets its own requirements for how its data should be deleted and archived. Restoration is bounded by the same permission model, only users holding the appropriate role being able to restore data within the application.

So a buyer with a records retention schedule can implement it here rather than accepting a vendor default, which is a genuine answer to the question this signal asks and is stronger than the disclosed-vague position most records in this lane occupy. Three limits are recorded so the value is not read as more than it is. No default is published, so nothing states what happens to data at a customer that configures nothing.

No maximum or backstop is stated, so the controls are described without an outer bound the vendor commits to. And the controls are described for customer data in the repository rather than for the AI material specifically: nothing states whether a prompt, an extraction candidate or an intermediate output is retained separately from the contract it was drawn from, or whether reprocessing a portfolio against a new configuration leaves prior extraction results in place.

No deletion-on-termination commitment was located, which sits in the unpublished customer agreement if it exists at all.

Gatekeeper
Disclosed fixed window

A retention boundary is published and the customer cannot change it, which is this value. For prompts and generated output specifically, the boundary is the session: AI Terms clause 12 states that no Content is retained by AI Providers beyond the session, and clause 5 that Input and Output are processed transiently and not stored or reused beyond what is required to deliver the Services. That second formulation carries a qualifier a reader should see, since what is required to deliver the Services is not itself defined, but the session boundary at the provider layer is stated flatly.

Around it the platform-level periods are published in the Data Processing Agreement and are specific rather than gestural: personal data is retained for the duration of the agreement, all copies are deleted from Gatekeeper's systems within 60 days of the effective date of termination unless a different date is agreed or the law requires storage, and partial data held in backups is deleted within one year. The security schedule adds a data classification scheme driving a retention policy under which a deleted record is permanently evicted from active databases and then rotated out of backups, and states that data no longer required is deleted promptly, locked in the first instance to guard against accidental or malicious deletion.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Contract Logix
Own model, documented

A permission model is documented in enough detail for an administrator to plan against, which is this value. The security page describes two dimensions of control rather than one: role-based and feature-based permissions, created by the customer's own administrator, giving the IT or business group control over what information can be accessed by whom, with multiple user types and the ability to add and remove roles supporting granular control.

The model has a named owner inside the customer organization, a designated System Owner who invites other users and grants access through in-application tools rather than through the vendor. Identity is bounded at the entry point too: every user must be validated by email before use, must then set a policy-driven password whose complexity the customer's administrator configures, and single sign-on is available over SAML 2.0 against Azure Active Directory, ADFS, DUO, Okta and Ping.

Restore rights are tied to the same roles. That is a documented model rather than an assertion of care, which is what separates this value from the one below it. What is not addressed is the legal framing. Nothing describes walls between matters, clients or counterparties as a concept, and nothing states whether a permission boundary can be made invisible rather than merely inaccessible, which is the distinction a conflicts wall turns on.

The product's center of gravity is a company's own contract portfolio rather than client matters, so the gap is less acute here than on a firm-facing tool, and legal is one of four stated buyer groups.

Gatekeeper
Own model, documented

The product maintains its own documented permission model that the customer must administer, which is this value. Separation between customers is documented in the Data Processing Agreement's security schedule rather than asserted in marketing: customer data is stored in a way that logically separates it from other customer data, multi-client capability includes separation of functions and of test from production systems, and each customer holds a unique encryption key generated using a FIPS 140-2 compliant library, with the key itself encrypted under a Gatekeeper master key whose release requires multiple levels of executive authorization and is logged and alerted through a SIEM.

Inside a tenant the model is Gatekeeper's own and is the customer's to run: role and authorization concepts on least privilege and need-to-know are set out in the security schedule, role-based access control groups are a named plan feature with a documented access group matrix in the knowledge base, and SCIM 2.0 provisioning automates joiners and leavers on higher tiers. What is not addressed is segregation between matters or business units within one tenant, which matters on a platform where legal, procurement and finance work the same records and agents answer across the whole contract and vendor estate.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Contract Logix
Not addressed

No located public material addresses what happens when a third party demands customer data. Nothing states whether the vendor would notify the customer of a subpoena, a warrant or a regulatory demand, whether it would give the customer an opportunity to object or to seek relief before producing, or whether it would narrow or challenge a demand. No transparency report is published and no law enforcement guidelines page exists.

The one adjacent provision located concerns a different route and is recorded rather than credited: the privacy policy acknowledges that Contract Logix is subject to the investigatory and enforcement powers of the Federal Trade Commission in connection with its Data Privacy Framework commitments, which is a statement about the vendor's own regulatory exposure and says nothing about notice to a customer whose contracts are demanded.

The absence has weight on this product because of what the repository holds: a company's executed agreements, which are exactly what a litigant, a regulator or a counterparty in a dispute would seek, and a customer that cannot establish the vendor's notice practice cannot plan for that. The value is recorded as the floor rather than as a finding about the vendor's actual conduct, because the instrument that would ordinarily carry a notice clause is the customer agreement, and the website terms expressly carve that agreement out and it is not published.

Surfaces read on the date shown were the privacy policy, the website Terms and Conditions, the security page and the platform pages.

Gatekeeper
Notice committed

Notice is committed in the published agreement where lawfully permitted, and no transparency report exists, which is this value. Data Processing Agreement clause 11.1 is the operative provision: Gatekeeper will notify the customer promptly of any request or complaint regarding the processing of personal data which adversely impacts the customer, unless notification is not permitted under applicable law or a relevant court order.

The carve-out is the ordinary one and the trigger is drawn around adverse impact rather than around compelled disclosure by name, which is a narrower framing than some records in this corpus use and is recorded as such. Two adjacent provisions complete the picture. Clause 8.2 provides that where Gatekeeper receives a request from a data subject it refers the individual back to the customer unless prohibited by law. Clause 11.2 records that Gatekeeper may copy or retain personal data to comply with a legal or regulatory requirement, which tells a customer that data can be held back for legal reasons even where deletion has been instructed.

What is absent is the reporting half: no transparency report, no aggregate figure for demands received and no reporting cadence was located anywhere on the estate.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Contract Logix
Not addressed

No located public material identifies a source corpus, and R15 governs the weight. This product answers from no body of law. The Intelligence Engine reads the customer's own executed contracts, detecting which key terms and clauses are present and pulling chosen properties into the platform as structured data, and Review works against the organization's own standard positions. There is therefore no licensed legal corpus whose provenance this signal would ordinarily test, and the vendor is not withholding something its product class implies.

What is genuinely unaddressed, and why a value is recorded rather than the limb being treated as wholly inapplicable, is the provenance of whatever sits behind the extraction models. The vendor publishes 92 pre-built standard extraction fields and an accuracy figure for them, which implies models trained or tuned on a body of contracts, and nothing states what that body was: whether public filings, licensed corpora, synthetic data, or other customers' agreements.

The last of those is the one a buyer would want excluded and nothing excludes it, which connects this row to the purpose-limited position recorded on the training signal. Nothing addresses licensing of any third-party material, and no model provider is named whose own training corpus could be inquired into. The surfaces read on the date shown were the Intelligence Engine page, the Review page, the security page, the privacy policy and the website terms.

Gatekeeper
Sources named, basis unstated

The working corpus is identified and the rights basis for it is stated, while nothing is said about what the models bring, which is this value. The source of every answer is the customer's own material: contracts, vendor records, risk data and spend imported into the platform, which the agents read, summarize, classify and extract from inside the tenant. The rights basis for that is set out expressly, which is unusual: AI Terms clause 5 provides that the customer or its licensors own Input and retain all ownership of it, warrants that the customer holds all rights, licenses and consents required, and grants Gatekeeper a non-exclusive right to permit itself and its AI Providers to use Input within the AI Functionality for the purpose of generating Output only.

What is not stated is the provenance of anything underneath. The AI Providers are named in the sub-processor list as Amazon Bedrock and Anthropic, and nothing published describes what their models were trained on, under what license, or with what update cadence, and clause 3.3 passes that question through by making use of the AI Functionality subject to each AI Provider's own terms of service without identifying them.

No external legal or contract corpus is claimed, so the product makes no coverage claim this signal would otherwise test.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Contract Logix
Not addressed

No located public material addresses whether authority is checked for subsequent history, and on this product the question does not arise. Nothing in the platform cites law. The AI reads a company's own executed contracts and its own standard positions; no proposition about the state of the law is produced whose treatment a lawyer would verify in a citator, and no case, statute or regulation is cited to the user. R15 governs and the limb is recorded as inapplicable rather than failed.

One adjacency is named so it is not mistaken for the thing, because it is the closest analog this product has to a currency problem. Extracted provisions describe a contract as it stood when it was read, and the platform's value proposition depends on those extractions staying true: obligation and renewal tracking runs off them. Nothing published describes how the system detects that an amendment, side letter or novation has changed a term it already extracted, or what happens to a tracked obligation when the underlying clause is renegotiated.

The vendor does publish the ability to reprocess an entire portfolio against a new configuration without re-loading documents, which addresses changes to the extraction schema rather than changes to the contracts. That is a data currency question and it is not graded here. The surfaces read on the date shown were the Intelligence Engine page, the Review page, the platform pages, the security page and the privacy policy.

Gatekeeper
Not addressed

No located public material addresses whether authority is checked for subsequent history, and on this product class the question does not arise in its usual form. The product cites no cases, statutes or regulations to a reader. Its agents work on the customer's own agreements and vendor records: extracting metadata, summarizing, matching clauses against an approved library and fallback terms, flagging policy breaches, identifying obligations and screening third parties for financial, cyber and sanctions exposure.

Nothing it produces is a statement about the state of the law that a lawyer would need to check for later treatment. The nearest adjacency is the compliance screening, where agents are described as reviewing third parties against SOC 2, DORA and ESG criteria, and where currency means whether an attestation or a risk signal is still valid rather than whether an authority is still good law; nothing published states how those criteria are kept current either, and that is recorded here rather than graded. Product pages, the AI Terms, the Data Processing Agreement and the pricing matrix were read on the date shown.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Contract Logix
Not addressed

No located public material describes what the system does when it cannot produce a reliable answer. The vendor comes closer than most to acknowledging that the situation arises, which is why the adjacency is recorded rather than the row left bare: the published accuracy claim of approximately 95 percent or better on standard fields, rising to roughly 99 percent with human validation in the loop, is an admission that roughly one field in twenty is wrong unaided.

Having conceded the error rate, the vendor says nothing about how the error surfaces. Nothing states that a low-confidence extraction is flagged for review, that a field the model cannot locate is returned as absent rather than as a nearest match, that a confidence score attaches to individual extractions, or that any field type is excluded as unreliable. Nothing describes what Review does when a clause has no counterpart in the organization's standards.

The gap matters because of where the output goes. Extractions populate the obligation and renewal tracking the platform is bought to run, so a silently wrong extraction becomes a missed renewal or an untracked obligation rather than a visibly wrong answer someone would question, and the published human-validation delta implies the review step is the only mechanism catching it. Nothing published indicates which way the system errs when uncertain.

Surfaces read on the date shown were the Intelligence Engine page, the Review page, the platform pages, the security page and the privacy policy.

Gatekeeper
Not addressed

No located public material addresses what the product does when it cannot ground an answer. The nearest published claim is about explanation rather than abstention: the vendor states that Lumin Agents explain every decision they make, giving complete transparency and auditability, and that they read, reason and act on data securely inside the platform. Explanation of a decision taken is not a description of what happens when a decision cannot be taken.

Nothing states that an agent declines, marks an extraction as unsupported, reports that a clause could not be matched to the playbook, escalates rather than answers, or exposes a confidence or grounding score to the reviewer, and no evaluation demonstrating any such behavior was located. The contractual material allocates the consequences instead of describing the behavior: AI Terms clause 6.3 disclaims any warranty as to the accuracy or reliability of Output, clause 6.6 requires the customer to check and evaluate accuracy before use and not to rely on Gatekeeper to do it, and clause 6.5 states that Output is a suggestion that does not replace a human deciding on its suitability.

Recorded as an established absence: the product pages, both published addenda and the plan matrix were read on the date shown.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

Contract Logix
None located

Searched on 13 September 2026 against the company name and both AI product names, across reporting and trackers covering court decisions on AI-generated fabricated citations. None located. No decision, sanction or disciplinary referral names Contract Logix, the Contract Intelligence Engine or Contract Logix Review. This discharges the R3 item carried from pull 7 on this name. Context is recorded so the absence reads as tested rather than assumed, the field now being substantial: reported instances include a Wyoming federal sanction of 5,000 dollars over eight non-existent cases produced by ChatGPT, a 6,000 dollar sanction in Indiana, a 1,500 dollar sanction in the Eastern District of California, a show-cause order requiring patent counsel in Kansas to explain nonexistent quotations and citations, four lawyers sanctioned in Mississippi where both sides filed fabricated authority, and a Kentucky decision treating hallucinated citations as a fraud-on-the-court concern.

General-purpose assistants rather than contract platforms are what those accounts describe. Under R119 this signal records fabricated legal citations in filings and nothing else, so no other proceeding involving this vendor appears here or is implied by this value. One point of product context: neither AI capability generates citations to legal authority, working on the customer's own executed contracts and its own standard positions, so the exposure this signal tracks is structurally low.

Gatekeeper
None located

Searched on 12 September 2026, on both the product name and the company name, against published trackers of decisions on AI-generated fabricated citations including coverage of the Damien Charlotin AI Hallucination Cases database and two independent sanctions trackers, for any court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product. None located. This is a statement about the public record on that one subject as of the date shown, and under R119 this signal records fabricated citations and nothing else, so it is not a litigation history and no other proceeding involving the vendor would appear here.

Note for a future reader that the product name is also a common noun and the name of unrelated software, including an open-source Kubernetes policy controller, so any future search on this name needs the company qualifier to be meaningful.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Contract Logix
Not addressed

No located public material engages with bar or ethics guidance, in general terms or otherwise. No bar opinion is cited, no rule of professional conduct of any jurisdiction is named, and nothing connects either AI capability to the obligations of a lawyer relying on its output. Nor is professional responsibility engaged generically: no statement was located asking customers to use the product consistently with their professional duties.

The gap is worth stating precisely rather than generally, because this vendor addresses legal buyers deliberately. There is a dedicated Legal Department page, three named legal seats each with a page of its own covering General Counsel, Paralegal and Compliance Officer, and a published Corporate Counsel's Guide to contract lifecycle management. So the estate speaks to lawyers directly and at length, and says nothing about the professional line running through a tool that produces first-pass redlines against an organization's standards and extracts governing law and indemnity terms from executed agreements.

The regulatory engagement that does exist runs entirely to data protection rather than conduct, the privacy policy claiming GDPR and CCPA compliance and Data Privacy Framework certification and naming BBB National Programs as its recourse mechanism, and the security page referencing HIPAA training for personnel. Those bind the vendor as a processor, not the customer as a lawyer, and they are recorded here so the absence is not read as an absence of all regulatory awareness.

Gatekeeper
Not addressed

No located public material engages with bar or ethics guidance. No bar opinion is named anywhere on the estate, ABA Formal Opinion 512 does not appear, no state or Law Society guidance on generative AI is referenced, and nothing maps any agent to a jurisdiction's rules of professional conduct. The absence carries more weight on this record than on most, for two reasons drawn from the vendor's own agreement. AI Terms clause 7 shows the vendor is willing to write profession-specific restrictions when it chooses to: it bars using the AI to offer tailored financial advice without a qualified person reviewing the information, and bars health advice outright, and it names neither legal advice nor any professional conduct obligation, on a platform marketed to legal teams for clause review and redlining.

And clause 6.6 imposes an obligation that touches professional conduct directly, requiring the customer to add a disclosure notice that Output was AI-generated before publishing or distributing it, without connecting that requirement to any court rule, bar guidance or candour obligation that would explain it. The related material on the EU AI Act published on the vendor's blog is educational content about the reader's own obligations, not an alignment statement about this product.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Contract Logix
Outside the fee relationship

The vendor sits outside the lawyer-client fee relationship, which is this value. The buyer here is an organization managing its own contracts, and the stated audience is that organization's legal, procurement, finance and sales functions, with solution pages by department, role, process, industry and company size and named legal seats covering General Counsel, Paralegal and Compliance Officer. Those are in-house seats.

There is no client on the other side of the work and therefore no bill on which AI-assisted efficiency could be passed on, discounted or disclosed, so the question this signal asks does not arise in the form it was written for. The value records that structural position rather than a gap in the vendor's disclosure, which is the distinction between this value and the floor. Two qualifications are recorded so the value is not read too broadly.

The corpus has seen in-house-facing platforms bought by law firms for their own back office, and nothing on this estate excludes a firm from being a customer, so a firm using the platform on client matters would find nothing published about marking AI-assisted work for a fee note; that is noted rather than graded, because the product is not sold on that basis. And the efficiency claims that do exist are framed as internal time saved, the published testimonial describing a three-day question answered in five minutes for a Director of Contracts, which measures the customer's own effort rather than time billed onward. Recorded and not credited under R21 and R24.

Gatekeeper
Outside the fee relationship

The product does not touch a fee between a lawyer and a client, because it is bought by teams that bill no client for the work. The named audiences are in-house functions of the buying organization, legal, procurement and finance, with the CFO named as the economic buyer on the AI page, and the whole commercial argument is about the buyer's own cost: vendor spend reduced, unwanted renewals stopped, supplier consolidation, cycle times shortened, audit hours saved.

The named customers reflect that, a Global Head of Procurement, a Legal Operations Manager, a Paralegal and an Associate Corporate Counsel, all inside the organizations that own the contracts. Savings claims are extensive and under this value they are recorded here rather than making the row a savings claim, because none of them reaches a client bill: an average $1.3 million cut in vendor costs in year one, 75 percent shorter contract cycle times, 400 hours saved per audit, and at CompSource Mutual Insurance 636 hours of executive review time saved annually.

Nothing published addresses disclosure of AI use or AI cost in any fee context, and on this side of the relationship nothing needs to.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Contract Logix
Not addressed

None of the three artifacts a firm would need is published, which is the floor. There is no subprocessor list of any kind. The privacy policy refers to service providers and states they may be located outside the United States, and names not one of them, which is the shape R29 distinguishes from a partial list: a category acknowledged without a single entity identified is not a list. There is no model provider statement, because no model or provider is named anywhere on the estate, so a customer cannot tell a client which third party reads its contracts, or indeed whether any third party does.

And there is no forwardable client-facing pack: no data processing addendum, no standard contractual clauses, no consent or notification template, and no security or privacy questionnaire response available for onward transmission. The instrument that would ordinarily carry the first and third of those is the customer agreement, and the website terms expressly carve out a separately executed agreement which is not published, so nothing in this set can be read before entering a sales process.

Recorded and expressly not credited under R29 and ground rules section 3: Microsoft Azure is named as the hosting platform and named identity providers appear for single sign-on, and neither is a subprocessor disclosure for the AI. The Data Privacy Framework claim in the privacy policy is a transfer mechanism rather than a disclosure artifact and is separately unverified.

Gatekeeper
Disclosure pack published

The pack a company would forward to answer a counterparty's AI clause is published and ungated, which is the top value. The subprocessor list is not behind a portal or a request form: it is set out in the Data Processing Agreement itself, at Exhibit C, as three tables naming each processor with its purpose and location, covering infrastructure hosting on Amazon Web Services across four regions, the four Gatekeeper group companies with their transfer mechanisms and supplemental measures, and eighteen other processors from Vanta to Workato.

The model provider limb is met from the same table rather than from marketing: Amazon Bedrock is listed as an AI Provider across four regions and Anthropic, PBC as providing AI language model services powering internal workflow automation in the United States. Client-facing disclosure material is met twice over and both artifacts were read in full: the DPA, which incorporates the EU, UK and Swiss Standard Contractual Clauses and names the competent supervisory authorities, and a standalone set of AI Terms written to be read by a customer's counsel, which prohibits training on Input and binds the AI Providers to it.

Change control is contractual: 30 days' notice of any new processor, ten business days to object, and termination if no workaround exists.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Contract Logix
Not addressed

No located public material addresses disclosure of AI involvement in legal work, which is the floor. Nothing states that an extracted field is marked as machine-generated rather than manually entered, that a redline produced by Review carries any indication of its origin, or that any record of AI involvement survives into an export or a report. No audit trail of AI use is described, no per-contract or per-matter record a customer could produce, no certification template, and no guidance on whether or when AI assistance should be disclosed to a counterparty, an auditor, a regulator or a court.

The exposure is real but indirect for this product class and the note says which way it runs rather than overstating it. The output is a structured data record and a draft redline rather than a filing, so the likely forum is a counterparty in a dispute, an auditor testing the contract register, or a regulator, rather than a judge. What a customer would want in any of those settings is the ability to show which terms in its own contract record were read by a machine and which by a person, particularly given the vendor's own published figure of approximately 95 percent accuracy unaided, and nothing published provides it.

The permission model does support built-in role-based restore and administrator control, which is access governance rather than provenance, and is recorded here so it is not mistaken for an AI audit record. Surfaces read on the date shown were the Intelligence Engine page, the Review page, the security page, the privacy policy and the website terms.

Gatekeeper
Partial record

Some elements of a record exist and no document-level export is described, which is this value, and one element here runs in the opposite direction to the usual finding. Most records in this corpus are silent on whether anyone should be told that output is machine-generated. Gatekeeper makes it a contractual obligation on the customer: AI Terms clause 6.6 requires that, prior to publication or distribution of any Output, the customer must add a disclosure notice that it was generated by AI tools, and clause 7.1 separately bars using the AI to mislead anyone that Output is human-generated.

That is a labeling duty rather than a product capability, and it is imposed rather than supported, which is why it does not lift the row further. The product elements around it are real: the vendor states that agents explain every decision they make with complete transparency and auditability, the workflow engine maintains an audit trail across intake, approval and signature, and system inputs are logged so it can be reviewed retroactively who entered, altered or deleted data.

What is absent is the export. Nothing states that any record identifies which model produced a passage, and no model is named in any event; nothing marks machine-generated text against human-edited text in a portable form; and no disclosure template or court-facing guidance was located.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Signals neither addresses in public material
  • Good Law Verification
  • Refusal and Uncertainty Behavior
  • Bar Guidance Alignment

Which one fits

Choose Contract Logix if

  • You want a stated accuracy for contract extraction. Contract Logix says its AI Data Extraction reaches about 95 percent or better on its 92 standard fields and roughly 99 percent with human validation in the loop, and it can reprocess a whole portfolio against a new field set without reloading documents.
  • You want to set your own deletion and archiving rules. Contract Logix provides controls that support your organization's deletion and archiving policies, restricts restore to users holding the right role, and runs permissions by role and by feature under a system owner you designate.
  • You negotiate in Word or Google Docs. Contract Logix Review delivers first pass redlines against your organization's standard positions inside Word or Google Docs, and its managed Organize service designs the data model and bulk imports legacy contracts.

Choose Gatekeeper if

  • You need to choose where contract and vendor data lives. Gatekeeper hosts on AWS in the United States, Ireland, Australia or Canada at the customer's choice, offers a private cloud, and lists each group company and AI provider with its location and transfer mechanism in its data processing agreement.
  • Your contracts and supplier risk live in separate systems. Gatekeeper treats the supplier and the agreement as one record, with vendor onboarding, third party risk registers, scorecards and spend analysis beside the contract repository, and its LuminIQ agents screen third parties for financial, cyber and sanctions risk.
  • Your counterparty's AI clause needs a forwardable answer. Gatekeeper's standalone AI terms bar training on customer input by it or any provider and keep provider content only for the session, and its data processing agreement gives 30 days' notice of any new subprocessor with a right to object and commits to breach notice within 72 hours.

In summary

Contract Logix

Contract Logix, of Lowell, Massachusetts, owned by LegalSifter since October 2024 and still sold under its own name, is a contract lifecycle platform for legal, procurement, finance and sales covering intake, authoring, negotiation, execution, a repository and obligation tracking. Its Contract Intelligence Engine extracts 92 standard fields and custom fields from signed contracts, and Contract Logix Review redlines drafts inside Word or Google Docs. The AI Legal Index grades it in the top two bands on eight of fifteen capability axes. It publishes an extraction accuracy of about 95 percent, rising to about 99 percent with human validation, and runs on Microsoft Azure. As of 13 September 2026 the index located no published customer agreement, security attestation, named model or price.

Source: AI Legal Index, 2026

Gatekeeper

Gatekeeper, from Gatekeeper Ltd of Jersey with group companies in the United Kingdom, United States and Canada, is a vendor and contract lifecycle platform that keeps the supplier and the agreement in one record, with intake, authoring, approvals, electronic signature, obligations, vendor onboarding and third party risk. Its LuminIQ agents extract, summarize, review clauses and screen suppliers. The AI Legal Index grades it in the top two bands on eleven of fifteen capability axes, with A grades on data stewardship and deployment. It publishes AI terms barring training on customer input, names Amazon Bedrock and Anthropic among its subprocessors, and hosts in four selectable regions. As of 12 September 2026 the index located no price figure, no named model and no accuracy measurement.

Source: AI Legal Index, 2026

Questions buyers ask

Contract Logix vs Gatekeeper: which is better for contract lifecycle management?

On published evidence Gatekeeper sits in the top two bands on eleven of fifteen AI Legal Index capability axes and Contract Logix on eight of fifteen, mostly because Gatekeeper publishes its AI terms, data processing agreement and hosting regions. Contract Logix publishes an extraction accuracy figure that Gatekeeper does not. Teams that manage supplier risk alongside contracts have more to read from Gatekeeper; teams that want a measured extraction rate have a figure from Contract Logix.

How accurate is Contract Logix's AI extraction?

Contract Logix states approximately 95 percent or better accuracy on the 92 standard fields its AI Data Extraction pulls from signed contracts, rising to roughly 99 percent with human validation in the loop. It does not describe the test set, the contract types measured or which fields fail, and no independent check was located. Gatekeeper publishes no accuracy figure and disclaims all warranties on AI output. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

Does Gatekeeper train AI on customer contracts?

No, by contract. Gatekeeper's AI terms state that customer input is not used to train or fine tune any model, proprietary or third party, that its AI providers may not retain or train on input or output, and that nothing is kept by those providers beyond the session. Contract Logix's privacy policy limits use to delivering the service without mentioning training, and its customer agreement is not published. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

Who owns Contract Logix?

LegalSifter acquired Contract Logix on 22 October 2024, as both companies' newsrooms confirm, and announced a unified team and product roadmap. LegalSifter is itself a portfolio company of Carrick Capital Partners. Contract Logix continues to sell under its own name, on its own domain, with its own agreement and purchase path, and LegalSifter is indexed separately. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

What do Contract Logix and Gatekeeper both leave unpublished?

The price and the model. Neither publishes a price figure, and neither names the AI model behind its extraction and review. Neither addresses privilege or work product, walls between business units inside one account, or what its AI does when it cannot find a term. Neither names bar guidance on AI use, although both sell to in house legal teams alongside procurement and finance. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

Disclosure

Three readings to weigh. Gatekeeper's AI terms require the customer to label AI generated output before publishing or distributing it, and restrict use of the AI for financial and health advice while naming no restriction for legal advice. Contract Logix's customer agreement exists but is not published, so its low grades on liability and professional responsibility record what could be read. Its accuracy figures are stated as approximate, with no test set described. Contract Logix was verified on 13 September 2026 and Gatekeeper on 12 September 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 24, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746