Definely vs Ivo: how they compare in 2026
Definely and Ivo both apply AI to contract review for transactional lawyers, and the grid does not separate them: both sit in the top two bands on nine of fifteen axes. What breaks the tie is which kind of evidence each publishes. Definely publishes credentials. It holds ISO/IEC 42001 for AI management certified by Prescient Security, with an AI System Register carrying impact assessments and defined ownership per system, ISO/IEC 27001:2022 recertified on 4 February 2026 with zero nonconformities, SOC 2 Type 2 recertified on 28 October 2025, and a 2026 penetration test summarised publicly against the previous year's findings. Ivo publishes measurement. Its benchmarking study scored its redlines blind against a practising Am Law 25 Special Counsel and against Claude for Word across nineteen real contracts, judged by three attorneys on five named criteria, with every participant's redlines and playbooks released for download and its own weakest area named. Neither publishes a price.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The first non A on this axis in the index, and it is the vendor's own positioning rather than a harsh reading. The models are the engine of a core capability layered on a product that functions without them. Definely was founded in 2017 and shipped its first product in September 2020, before modern generative AI, and the vendor states that being built natively in Word before that wave is a structural advantage. Read, Proof and the navigation and proofreading layer are deterministic parsing of document structure, definitions and cross references, and would function unchanged with no model behind them. Vault is clause level indexing with semantic search. Enhance and Cascade are the generative and agentic layer. The vendor describes its own approach as AI layered on top of tools that help lawyers complete concrete tasks, states the combination as rules based logic plus machine learning plus RAG based generative AI, and says explicitly that its advantage is not more AI but where and how AI is applied. Its Claude connector is described as rules based and deterministic, returning identical results on identical input.
Ivo is a review and analysis engine rather than a system of record, and that distinction is what carries the grade. Ivo Intelligence connects to contracts wherever they already live rather than becoming the place they are stored, so the repository belongs to the customer and what Ivo adds is extraction, benchmarking and plain-language querying. Ivo Review generates playbook-backed redlines applied in Word or Google Docs; Playbook Builder derives positions from the customer's own executed agreements; Ivo Assistant compares documents, researches regulation and reports on changes in the law. Every one of those is model work. Remove the models and there is no product left, only a connection to files the customer already had. Verified 2 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real and documented with the method described, short of published accuracy figures. The retrieval architecture is stated: clause level document indexing and chunking, RAG based models, an agentic architecture using multiple agents, and analysis scoped to the active contract and related documents rather than portfolio wide. Output grounds to the document a reader already has open, with definitions and cross references surfaced as links in the provision being read, which is verification by construction. The Claude connector is documented as deterministic and reproducible, and as returning exactly what the tools return rather than improvising, which is a real published claim about grounding behaviour. An AI architecture diagram and an AI security whitepaper are published through the trust centre behind a request. Not located as of 29 Aug 2026: any accuracy figure, hallucination rate, test set or evaluation. The published performance claim is a speed figure, 40 to 70 percent faster contract review.
Ivo publishes the most rigorous accuracy evidence located anywhere in this pull. Its benchmarking study scored output from Ivo, Claude for Word running Opus 4.6, and a practising Special Counsel at an Am Law 25 firm with eight years of experience, across nineteen real anonymised contracts spanning NDAs, MSAs, DPAs and other commercial types. Three attorneys with Am Law 100 or in-house technology experience scored every output blind on a 1 to 10 scale across five named criteria. Results are given as means: Ivo 4.52, the human attorney 4.56, Claude for Word 3.50, with review times of 2m45s, roughly 32 minutes and 4m52s per document. Failure modes are named rather than hidden: the study identifies Formatting Retention as a weak area for Ivo and publishes the worked example where it scores 5 against the attorney's 10. All participants' redlines and all playbooks used are published as downloadable files, which is reproducibility almost nobody offers. Grounding is real on the product side too, with Playbook Builder citing each position back to the agreement it came from. Three qualifications belong on the record. The study was run by Ivo, which the methodology states plainly while the page headline calls it an independent evaluation; the independence sits in the blind judging panel, not the sponsorship. The methodology says three judges while one FAQ answer says five. And the absolute scores are low on their own scale, with the human baseline at 4.56 out of 10, so the headline finding is comparability rather than excellence. Verified 2 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A real written commitment that the models work alongside a supervising lawyer, with review surfaces, short of the full control structure. The vendor states its principle directly: AI is layered on top of tools that help lawyers complete concrete tasks rather than replacing legal judgment, and its stated automation target is roughly 80 percent of manual review work so the lawyer's expertise goes to the critical 20 percent. Human oversight is inside the scope of its ISO 42001 certification, which is externally audited rather than asserted. The Word delivery model means suggestions arrive in a document the lawyer accepts or rejects. Not located as of 29 Aug 2026: the threshold at which an agent stops, what Enhance or Cascade decide unaided, and what the vendor commits to when an output is wrong.
The supervision requirement is contractual, which is rare. Clause 14 of the Terms has the customer represent and warrant that its use of the Services will be under the direct supervision of a qualified lawyer representing the customer. The review surface is the native one: redlines are applied in Microsoft Word or Google Docs where a person accepts or rejects them, and the product is framed as telling a reviewer what to accept, push or fall back on rather than deciding. What is not published is the boundary. Ivo Assistant is described as able to autonomously access playbooks, the contract repository, the Web and company context to inform its responses, and nothing states what it may complete without a human, what triggers escalation, or what happens after it is wrong. Autonomous retrieval is disclosed; autonomous action is neither disclosed nor bounded. Verified 2 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Real deployment evidence with substance, short of attributed figures. Named customers are published in two places: the trust centre names organisations that have completed security review including Allen and Overy, Slaughter and May, Dentons, Shoosmiths, Shepherd and Wedderburn, Deloitte, Liberty Global, Diageo, Asian Development Bank and Barclays, and vendor material names JP Morgan, BT Group, P and O Cruises, Ericsson, KPMG, Samsung and IKEA. Scale is stated at more than 150 enterprise customers and more than 40,000 active users across 30 plus countries, with 30 percent of revenue from the US. A customer stories section is published. Not located as of 29 Aug 2026: a dated case study tying figures to a named customer with a method a reader can assess. The 40 to 70 percent speed figure is a product claim rather than a customer result.
The customer roster is the strongest in this pull: Meta, Uber, IBM, Atlassian, Canva, DoorDash, Intel, Reddit, Coinbase, Pinterest, Mitsubishi, AVEVA, Whataburger, CDW and Strava are all named on the home page. Three carry dedicated case studies with named individuals speaking on the record, including Suhayb Ahmed, Head of Commercial Legal at Canva, and Carla Michel, Director and Senior Counsel at CDW. That is attribution rather than a logo strip. What holds it below A is measurement. No deployment figure is attached to any named customer on the surfaces read, and no dates appear; the individual case studies were not opened this pass. The one quantified claim located, a 75 per cent saving in contract review time on the Review product page, is unattributed to any customer. The benchmarking study is measured evidence but of accuracy rather than of production deployment, and it is credited on the citation accuracy axis rather than counted twice here. Verified 2 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Confidentiality is asserted through a substantial control framework while the commitment this axis turns on was not located. Real and published through the trust centre: a data processing agreement, an access control policy, a data erasure entry, data protection and audit logging under product security, multi factor authentication, data subject request handling and a named data privacy officer. Local architecture diagrams for Read, Proof and Vault are published on request, which speaks to how much processing stays on the user's machine. But searched the site, the trust centre index, the privacy policy and the terms of use on 29 Aug 2026, and ran a targeted search for a training commitment, and located no statement of whether customer content may be used to train models, no statement of what the model providers may retain, and no treatment of attorney client privilege or work product. Segregation between users or matters was not located either. For a vendor whose customers are Magic Circle firms handling counterparty documents, the training question is the one a buyer asks first, and the answer sits behind the trust centre gate rather than on the page.
For a product that ingests the commercial contracts of Meta, Uber and IBM, very little a buyer can read before signing addresses how that material is handled. The no-training commitment is a single marketing sentence on the home page with no matching term anywhere in the published Terms. Nothing published addresses segregation between users, matters or tenants. Nothing identifies what the underlying model providers may retain, and the Terms name no model provider at all. Retention and deletion are partly addressed, with Customer Content deleted within 60 days of request following termination under clause 6.4.2. Against that sits clause 14, in which the customer waives, to the fullest extent, any right or claim of malpractice, privilege or provision of legal advice or existence of an attorney-client relationship in relation to Ivo. Privilege is therefore addressed in the agreement, but as something the customer gives up rather than something the vendor protects. A general confidentiality article at clause 19 exists and is standard mutual drafting. Assertion in general terms, with the substantive commitments living in an unpublished Services Agreement, is the C band. Verified 2 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The audience is unambiguous and narrow, large law firms including Magic Circle and Am Law firms plus corporate legal departments, with no consumer or non lawyer surface anywhere on the property, which is cleaner than most of this index. The vendor states its AI does not replace legal judgment. Searched the site, the published terms of use, the privacy policy and the trust centre on 29 Aug 2026 and located no position on the advice line, no treatment of competence or supervision duties, and no statement of jurisdiction limits despite operating in more than 30 countries. Recorded at C because the position is inferable from the product's shape rather than published.
Clause 14 of the Terms is headed No Legal Advice and does more than disclaim. It states that the Service does not provide legal advice and is not a substitute for professional legal advice, that Ivo does not guarantee the accuracy, completeness or timeliness of legal materials provided, and that no attorney-client or other special relationship arises, including during implementation or training. It then goes further than any other record in this pull by requiring the customer to represent and warrant that its use of the Services will be under the direct supervision of a qualified lawyer, which reaches the supervision and competence dimension the top band asks for. Two limbs fail. No jurisdiction limits are stated anywhere. And no bar or ethics guidance is engaged: ABA Formal Opinion 512 and state bar opinions appear nowhere, so the supervision requirement is the vendor's own construction rather than engagement with the rules its buyers are bound by. Verified 2 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
The strongest AI governance disclosure on the index and the first A on this axis. Definely holds ISO/IEC 42001:2023 certification for AI management systems, audited by a named accredited certification body, Prescient Security, with the trust centre publishing what the certification covers rather than only the badge: the full AI lifecycle from design through deployment, monitoring and improvement; a formal AI System Register with each in scope AI system carrying impact assessments, defined ownership and continuous monitoring of performance and risk; explicit coverage of data protection, fairness, transparency, human oversight and risk assessment; internal AI adoption governed under the same controls as the AI in the products; and ongoing management reviews, internal audits and risk processes rather than a point in time check. Defined ownership per AI system is the named owner element this axis asks for. The vendor also published its intent to pursue the certification before achieving it, naming its assessor and its continuous monitoring tooling, so the claim was checkable in advance. Not located: published testing results, and any disclosure of measured output differences across matter types, parties or populations, though fairness is inside the audited scope.
Nothing published addresses governance over model behaviour. No responsible AI page exists, no governance framework, no certification such as ISO 42001, no individual or function named as accountable, no account of what is tested before a release ships, and nothing whatsoever on uneven output across contract types, counterparties or populations. The benchmarking study is a published test with results, but it is a competitive evaluation of output quality rather than a governance regime, and it is credited on the citation accuracy axis rather than counted twice. SOC 2 and ISO 27001 are security attestations, which this axis treats as a different subject. Checked the home page, the three product pages, the benchmark study, the Terms, the privacy policy and the customer pages on 2 September 2026. One retrieval limit is recorded rather than held against the vendor: the Vanta-hosted trust centre at trust.ivo.ai renders client side and returned no body, so nothing in it is graded or credited. Verified 2 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy covering most of the ground, through an unusually complete trust centre. Published as named entries: access monitoring, data backups, data erasure, access log management, data access controls, logging, audit logging, multi factor authentication, firewall and web application firewall, separate production environment, a documented incident reporting process, business continuity and disaster recovery plans with a stated recovery time objective of 24 to 48 hours, supply chain risk management, vulnerability and patch management, responsible disclosure, and a software development lifecycle policy. A 2026 independent penetration test is summarised publicly with its findings. Not located as of 29 Aug 2026: a stated retention period for customer documents, a named subprocessor list, and a statement of what the model providers retain. Deletion is addressed as a data erasure entry without a published period.
One element is published with real precision and the rest are thin or absent. The precise one is unusual and worth naming: the privacy policy states that where a customer submits a thumbs-down rating or similar negative feedback, the associated contract or document may be temporarily stored and is retained for 14 days from submission before automatic deletion or de-identification. Beyond that, general retention is stated only as being for as long as Ivo has a business or operational purpose, and deletion runs to 60 days after a request following termination. Access control appears only as the customer assigning roles and permissions to Authorized Users. No subprocessor list is readable: the privacy policy points to trust.ivo.ai for it, and that trust centre is Vanta-hosted and returned no body on 2 September 2026, which is recorded as a retrieval limit rather than graded. No incident or breach notification practice was located on any surface. Two of the five elements this axis names are missing from the readable record entirely. Verified 2 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Liability is addressed only through published terms carrying a standard structure. Terms of use and a privacy policy are published openly and a data processing agreement is available through the trust centre, so a buyer can read the framework before entering a sales process, which keeps this above a pure absence. Searched those documents, the trust centre index and the site on 29 Aug 2026 and located no indemnity running to the customer for third party claims arising from output, no warranty on output, no stated liability cap figure and no insurance position.
The published position is complete, specific, and allocates almost everything to the customer. Clause 9.1 caps Ivo's cumulative liability at one hundred US dollars, stating that the existence of more than one claim will not enlarge the limit, and excludes indirect, consequential and punitive damages. Clause 10.1 runs an indemnity from the customer to Ivo and none runs the other way. Clause 10.2 goes further, with the customer releasing and forever discharging Ivo from every past, present and future claim relating to the Site or Services, coupled with an express waiver of California Civil Code section 1542 protection for unknown claims. Clause 8 disclaims all warranties including accuracy and fitness, and clause 14 adds the waiver of malpractice and privilege claims. No insurance commitment appears. This is B rather than A because nothing here is a recourse a buyer can invoke when output is wrong, and B rather than C because a full warranty, disclaimer, indemnity, release and limitation structure is published rather than a bare limitation clause. Two qualifications: the Terms were last updated 20 November 2024, and they contemplate a separate Services Agreement, not published, which is where an enterprise buyer's actual allocation would sit. Verified 2 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations exist and are documented, short of implementer level depth. The product is a native Microsoft Word add in rather than a connector alongside Word, which is the deepest possible placement for transactional drafting, and the vendor treats that as its structural differentiator. Document management integration is named specifically to iManage and NetDocuments, with Vault indexing a connected repository at clause and definition level and surfacing whether a clause is frequently used or marked gold standard. An official Model Context Protocol connector is published in the Anthropic Claude marketplace with its seven exposed tools enumerated, its authentication route described, and an enterprise deployment path for IT teams, which is a documented integration into a second environment. An installation guide and network diagram are published through the trust centre. Not located as of 29 Aug 2026: documentation of what each document management integration moves, in which direction, and what an administrator must configure.
The integrations are real and named across the surfaces where contract work happens: a Microsoft Word add-in, Google Docs, and connection to contract repositories wherever they are held, with the privacy policy naming Slack, Google Docs and Teams as example third-party services a customer may connect and describing email and messaging connection in terms of what actually moves, since it states that where a company connects its email or messaging service Ivo may receive communications and attachments for processing. That last passage is a genuine description of direction and payload. What is missing is the rest. No integrations page exists on the site, no developer documentation or API reference was located, no document management system such as iManage or NetDocuments is named, and nothing states what a customer configures or what synchronises back. Named connections without a systematic description of what they move is the B band. Verified 2 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery is implied and neither the region nor the tenancy model is stated. Amazon Web Services is named as the infrastructure provider in the trust centre and a separate production environment is listed, and local architecture diagrams for Read, Proof and Vault are published on request, which implies meaningful local processing but does not state it as a residency position. Searched the site, the trust centre index and the published policies on 29 Aug 2026 and located no available regions, no customer selectable residency, no tenancy model, and no statement of where processing happens as distinct from where data is stored. For a UK vendor serving Magic Circle firms and operating across 30 plus countries, a published residency option would be expected.
Cloud delivery is evident and neither limb this axis asks for is stated. No region or residency option is published anywhere, and the privacy policy points away from one, saying the business is operated from the United States, Canada and other jurisdictions and that personal information may be transferred to, processed and stored in the United States and other jurisdictions whose data protection laws may differ from the reader's own. Transfers out of Europe rely on standard contractual clauses, which is a lawful basis rather than a residency commitment. No tenancy model is stated: nothing describes the platform as multi-tenant, single-tenant or privately deployed, and no hosting provider is named on any readable surface. Under the co-equal limbs rule either tenancy or region would clear this band and neither is present. Verified 2 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The most complete certification disclosure on the index. Named, dated and attributed: ISO/IEC 27001:2022 recertified in February 2026 by the British Assessment Bureau, now Amtivo, a UKAS accredited body, with the audit dated 4 February 2026 and concluding with zero major and zero minor nonconformities; SOC 2 Type 2 recertified 28 October 2025 under AICPA SSAE 18 standards with the auditor named as Prescient Security; ISO/IEC 42001:2023 certified by Prescient Security; plus Cyber Essentials and a GDPR programme. A 2026 independent penetration test is not only stated but summarised: scope covering web applications, APIs, client side integrations and external network infrastructure, benchmarked against OWASP Top Ten, concluding low overall risk exposure with no critical, high or medium severity findings, and explicitly compared against the prior year's results which did include medium severity findings. Publishing a year over year comparison that names your own previous weaknesses is rare. A SafeBase trust centre carries the SOC 2 report, pen test report, architecture diagrams, privacy and security whitepaper and the policy set behind a self serve access request, which under the three tier test is a request flow rather than a sales gate.
SOC 2 and ISO 27001 are both claimed on the home page, described as certification to protect contract data with proven security controls and as covering comprehensive information security management, alongside stated GDPR and CCPA compliance. Certification is therefore real and stated. Everything the top band asks for beyond the standard name is absent from readable surfaces: no auditor, no coverage period, no report date, no scope statement, and no penetration test summary. A trust centre exists at trust.ivo.ai and the privacy policy directs readers there for subprocessor information and for compliance with audit standards and security frameworks, but it is Vanta-hosted, rendered client side and returned no body on 2 September 2026, so neither its contents nor its access tier could be established. That is a retrieval limit and is not graded against the vendor; equally nothing in it is credited. Verified 2 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The vendor refers to its architecture without identifying what sits underneath. Published: an agentic architecture using multiple AI agents, RAG based models, clause level indexing, AWS as infrastructure, supply chain risk management as a trust centre entry, and an AI architecture diagram and AI security whitepaper available through the trust centre on request. An Anthropic relationship is documented but it is a distribution partnership placing a Definely connector inside Claude, not a statement that Anthropic models power Definely's own products, and the two must not be conflated. Searched the site, the LLM information page, the trust centre index and the product pages on 29 Aug 2026 and located no named model provider for the product itself, no statement of where models run, no subprocessor list, and no commitment to notify customers when the supply chain changes.
Ivo refers to its own engine as proprietary and never identifies what sits underneath. The home page describes a proprietary AI engine that discovers insights and maps relationships; the privacy policy confirms that artificial intelligence service providers exist, listing artificial intelligence among the services that vendors assist with and noting that some third-party services such as artificial intelligence systems and cloud service providers supply information back. Not one model or provider is named on any readable surface, nothing states where inference runs, and no change notification commitment exists. The subprocessor list is not published on the site: the privacy policy states that information about subprocessors is made available at trust.ivo.ai, and that trust centre returned no body on 2 September 2026. Referring to proprietary models without identifying what sits underneath is the C band exactly. Verified 2 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Checked the site navigation, the five product pages, the solutions pages, the trust centre and the footer on 29 Aug 2026. No pricing page exists on the property, no rate is published, no unit of charge is stated and no tier structure appears. Every commercial path terminates in a demo booking. No free trial or self serve entry point was located, and no third party pricing figure was located either. Note that the vendor publishes a buyer's guide comparing drafting software that discusses competitors' pricing models in general terms without stating its own.
No pricing information is published at any level, including the unit of charge. Checked the home page, the full navigation and footer, the three product pages, the benchmark study, the Terms, the privacy policy and the customer pages on 2 September 2026. No pricing page exists in the navigation, and the only commercial route offered is Request Demo. Clause 5.1 of the Terms says only that fees are as set out in the Services Agreement, in US dollars, non-refundable, and changeable on thirty days notice at renewal, which describes payment mechanics rather than what is charged for. The nearest thing to a structure is a passing description in the California disclosures of the business model as subscriptions-as-a-service, which is a characterisation in a privacy notice rather than a pricing statement: no seat, volume or consumption unit, no term, no tier and no figure appears anywhere. Verified 2 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Who the product is for is documented precisely, and unusually the vendor also publishes who it is not for. The ideal customer profile is stated explicitly: large law firms including Magic Circle, Am Law 100 and Am Law 200, corporate legal departments at major enterprises, and lawyers working on complex high risk transactional work in M and A, banking, insurance and complex commercial agreements. Use cases are enumerated at task level from multi document contract suite analysis through issues list extraction. The boundary is published in the vendor's own guidance: it states it should not be described as a general purpose legal AI platform or a CLM system, that it is optimised for complex high risk contracts rather than high volume low complexity documents, and that its focus is the active contract and related documents rather than portfolio wide analysis. Publishing an explicit not built for statement is rare on this index and is exactly what the A band asks for when it asks for the limits to be stated.
Who the product is for is clear and evidenced rather than claimed. The buyer is the in-house legal department at large enterprises, and the named roster bears out the scale and breadth, running across technology, semiconductors, payments, food service, industrials and retail distribution. Coverage is described by document type rather than practice area, and the benchmark study is specific about it, naming NDAs, MSAs, DPAs and other commercial agreements across six commercial types. What is left open is the boundary in both directions. Nothing states a company size floor, no jurisdiction or geography is named anywhere despite a roster spanning several, and nothing states which agreement types or legal work the product does not support. Law firms are outside the intended market but are never addressed as such. Verified 2 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Searched the site, the LLM information page, the published terms of use, the privacy policy and the trust centre index on 29 Aug 2026, and ran a separate targeted search for a training statement. No located term or policy addresses whether customer content may be used to train models, either way. The vendor publishes an AI security whitepaper and an AI architecture diagram through its trust centre behind an access request, so the answer may exist there, but it is not on any open page. Recorded as silent under the rule that a value is never inferred from the absence of a contradiction. Notable given the vendor holds ISO 42001 certification covering data protection across the AI lifecycle, which suggests the position exists internally and is simply not published openly.
The commitment is a single line in the security block of the home page. No matching term appears in the published Terms, which were checked in full: clause 7.2 grants Ivo the right to use Customer Content to provide the Services, and clause 2.6 allows free use of Feedback, which is defined at clause 21.9 to exclude Customer Content. A buyer should read one countervailing passage alongside the promise. The privacy policy, under Developing and Improving Our Business, states that Ivo may develop or improve Services by analysing how you use features, the documentation you submit, or information associated with your transactions, and separately reserves the right to use de-identified or aggregated information for any purpose. Neither passage names models or training, so on the test of whether the clause names the thing it does not displace the no-training statement, but improving an AI service by analysing submitted documents sits close enough to it that the tension belongs on the record rather than in a footnote.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is acknowledged in public material with no stated period. The trust centre publishes data erasure, data backups and backup protection as named entries under data security, and publishes a recovery time objective of 24 to 48 hours, so deletion and backup practice are addressed as topics. Searched the trust centre index, the privacy policy, the terms of use and the site on 29 Aug 2026 and located no retention period for documents, prompts or outputs, no customer control over that window, and no statement of what the model providers retain. The underlying documents sit behind a trust centre access request.
The general position is open-ended, with no period stated and no customer control over the window. One narrow pathway is specified with unusual precision and deserves recording because it is the only number Ivo publishes: where a user submits a thumbs-down rating or similar negative feedback, the associated contract or document may be temporarily stored and is retained for 14 days from submission, after which it is automatically deleted or de-identified unless law requires otherwise. Separately, clause 6.4.2 of the Terms provides that on request following termination Ivo will delete Customer Content within 60 days, which is a deletion window rather than a retention setting. The privacy policy also states that Ivo's own retention obligations may in some cases prevent deletion after a request. Nothing published addresses how long prompts, outputs or uploaded contracts persist in the ordinary course.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Searched the site, the Vault product page, the LLM information page and the trust centre index on 29 Aug 2026. The product integrates with iManage and NetDocuments and indexes a connected repository at clause and definition level, which is exactly the configuration where permission inheritance matters most, and trade coverage of a product demonstration records the question of how firms enable document management search without surfacing inappropriate documents being discussed. No vendor material was located stating whether Vault retrieval enforces the source system access model at query time per user, or how ethical walls are handled. Access control policy, access monitoring and data access entries exist in the trust centre behind an access request. Recorded as not addressed because the question is unanswered on open material despite being central to this product's design.
Checked the home page, the three product pages, the Terms, the privacy policy and the benchmark study on 2 September 2026. Nothing addresses walls, matter separation, or whether retrieval respects the access model of the systems Ivo connects to. The nearest material is in the privacy policy, which notes that a customer's company can assign different roles to Authorized Users carrying different capabilities and permissions, and that information about a user's use of the Services may be disclosed to other Authorized Users including their manager. That describes role assignment within a customer account rather than segregation of one matter or counterparty from another. The question has weight here because Ivo Intelligence connects across a company's contract repositories and answers questions spanning thousands of agreements at once.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Searched the published terms of use, the privacy policy and the trust centre index on 29 Aug 2026. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. The trust centre publishes data subject request handling, which addresses individual privacy rights rather than third party demands for customer data.
Clause 17 of the Terms is headed Legal Process and commits to notice where permitted. It states that Ivo may respond to and comply with any legal order received relating to the account or use of the Services, including subpoenas, warrants or liens, that it is not responsible for losses the customer incurs from that response, and that where permitted it will give reasonable notice that such an order was received. The commitment is qualified by permission rather than by discretion, which is what separates this from the weaker values. It is not the top value because no transparency report was located: nothing published records how many requests have been received or how they were handled. The privacy policy addresses compelled disclosure separately, under security, fraud detection and compelled disclosure, without repeating the notice commitment.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
This vendor inverts the usual shape of this signal, and the inversion is the finding. There is no vendor supplied legal corpus at all: Vault indexes the customer's own connected document management system and clause library, so the provenance of the retrieval corpus is the customer's own precedent and the rights basis is the customer's own. That is published clearly and is a real architectural position rather than an omission. Recorded at the weakest value because the signal asks where the law in the product comes from and no primary law corpus is identified, no licence basis is stated and no update cadence is published, but a reader should weigh that against a product that deliberately holds no legal corpus of its own.
One source is named and the rest are not. The Review product page states that Ivo can retrieve case law and statutes with citations from trusted legal databases without leaving the document, and the company's own machine-readable description names SEC EDGAR filings and statutory databases as the authoritative external sources searched. EDGAR is therefore identified; the case law and statutory databases that would matter most for the regulatory research Ivo advertises are described only as trusted or authoritative. No licence or rights basis is stated for any source, and no update cadence is published. The product's primary material remains the customer's own executed contracts and playbooks, with Playbook Builder citing each position back to the agreement it came from, so the corpus question bites less here than for a research product, but it does bite: Ivo Assistant claims to track changes in the law and to research a regulation in depth.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Searched the site, the five product pages, the LLM information page and the guides index on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is a transactional drafting and proofreading product operating on the contract in front of the lawyer, with no case law research surface, so a citator is outside its design entirely.
Checked the home page, the three product pages, the benchmark study and the Terms on 2 September 2026. No public material addresses subsequent history, treatment flags or whether retrieved authority is still good law. This matters more for Ivo than for most contract tools because it does claim to retrieve case law and statutes with citations and to report on changes in the law, and it describes those citations as verified, which speaks to whether an authority exists rather than whether it still stands. Nothing published states how currency is checked or what happens when a cited authority has been superseded.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
The vendor documents a determinism commitment rather than an abstention path, and the distinction is worth preserving. Published for the Claude connector: it is rules based and deterministic, running the same analysis on the same document produces identical results every time, and the calling model reports back exactly what the tools return rather than guessing or improvising. That is a real published statement about not fabricating, and it is stronger than most on this index. It is not, however, a statement of what the product does when it cannot ground an answer, which is what this signal asks. Searched the site, the product pages and the guides index on 29 Aug 2026 and located no explicit no answer path and no confidence signal exposed to the user.
Checked the home page, the three product pages, the benchmark study, the Terms and the privacy policy on 2 September 2026. Nothing describes what the product does when it cannot ground an answer. No abstention path is documented and no confidence or grounding score is exposed. The benchmark study measures the quality of output produced but says nothing about output withheld, and its Issue Spotting criterion asks whether the author over-spotted issues, which touches false positives rather than abstention. A thumbs-down feedback mechanism exists, per the privacy policy, which is a route for a user to report a bad answer after the fact rather than a behaviour of the system.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note that this is a transactional drafting and proofreading product with no case law research surface, so its output is very unlikely to reach a court filing as cited authority, and note that the database is weighted toward US filings while this vendor is UK founded.
Searched the AI Hallucination Cases database maintained by Damien Charlotin, and reporting drawing on it, on 2 September 2026 on both the product name Ivo and the corporate name Ivo AI, Inc. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product. The search is weaker than usual because Ivo is a short common word and a personal name, which limits a name-based query, and the product is sold to in-house departments for contract work rather than to litigators for filing, so the exposure is structurally lower than for a research tool.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Searched the site, the blogs and guides indexes, the LLM information page and the trust centre on 29 Aug 2026. No engagement with any named ethics opinion or professional guidance was located, including ABA Formal Opinion 512, US state bar guidance, and Solicitors Regulation Authority or Law Society guidance given the company's London base. The vendor publishes substantial material on drafting risk, proofreading failure rates and AI governance, and holds an AI management certification, all of which address quality and governance rather than the professional responsibility rules its buyers are bound by.
Checked the home page, the three product pages, the benchmark study, the Terms, the privacy policy and the customer pages on 2 September 2026. No public material engages with ABA Formal Opinion 512, any state bar opinion, or any other named ethics guidance. Ivo does address professional responsibility ground in substance at clause 14 of the Terms, requiring that use of the Services be under the direct supervision of a qualified lawyer, which is a stronger practical position than most vendors take, but it is the vendor's own construction rather than engagement with the guidance its buyers are bound by, which is what this signal records.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Savings are claimed with nothing published on the client's side of the equation. Published figures include 40 to 70 percent faster contract review, an automation target of roughly 80 percent of manual review work, and a cited figure that lawyers spend around 10 hours a week ensuring document quality. Searched the site, the blogs and guides indexes and the product pages on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment. The primary buyer here is a large law firm billing clients by the hour, so the question applies squarely.
Time savings are claimed and, unusually, measured. The Review product page claims a 75 per cent saving in contract review time, and the benchmarking study puts precise figures behind the compression: an average of 2 minutes 45 seconds for Ivo against roughly 32 minutes per document for a practising Special Counsel, or about 10 hours of attorney time for the full set. Nothing published addresses what happens to the bill when that compression occurs, and no per matter record of AI assisted work was located. The direction this signal assumes is also inverted, since Ivo's buyer is the in-house department that receives bills rather than the firm that issues them, so the saving lands on internal capacity and outside counsel spend.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The material a firm would forward to its own client is more complete here than anywhere else on this index, though the specific artifact this signal names is missing. Available through a self serve trust centre request: a SOC 2 report, a 2026 penetration test report with its findings summarised publicly, ISO 27001:2022 and ISO 42001:2023 certification documentation with named auditors and dates, a data processing agreement, a privacy and security whitepaper, an AI security whitepaper, an AI architecture diagram, network and local architecture diagrams, and a full policy set. Not located as of 29 Aug 2026: a subprocessor list, any statement of which model providers see customer content, and any client facing consent or notification pack assembled as such. Recorded at the subprocessor value as the closest published fit, on the strength of the certification and audit material rather than a subprocessor list, which does not exist.
The material exists and is reachable only by asking. The privacy policy states that additional information about the subprocessors used to support delivery of the Services is made available at trust.ivo.ai, and that the trust centre carries information about compliance with relevant audit standards and security frameworks. That is more than nothing published, so the bottom value is false of this record. It is not a published list either: the trust centre is Vanta-hosted, rendered client side, and returned no body on 2 September 2026, so neither its contents nor its access tier could be established, and no subprocessor or model provider is named on any readable surface. The privacy policy confirms that artificial intelligence providers are among the service providers engaged without identifying any of them.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of a record are available. Audit logging is published as a named product security feature in the trust centre, and the Claude connector produces exportable outputs in HTML, DOCX and table formats including a full drafting issues report and a reference report mapping cross references, which are inspectable artifacts a reviewer could retain. Determinism means an analysis can be re run and reproduced, which is a form of verifiability. Two elements are missing: no per document export covering model used, sources retrieved and human verification together was located, and no model is identified anywhere in published material. Noted for context: this is a transactional drafting product, so a judicial AI disclosure order is unlikely to reach its output.
Checked the home page, the three product pages, the benchmark study, the Terms and the privacy policy on 2 September 2026. Nothing addresses judicial standing orders, AI use disclosure or verification certification, and no exportable per document record of model used, sources retrieved and human verification is described. Playbook Builder does cite each drafted position back to the agreement it came from, which is a provenance trail within the customer's own corpus rather than a record of model use, and redlines land as tracked changes a person accepts. Neither records which model produced which passage. The product class is relevant: this is sold to in-house departments for contracting rather than for filing, so the disclosure obligation would usually fall on outside counsel.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- Commercial Transparency
- Ethical Walls and Matter Segregation
- Good Law Verification
- Refusal and Uncertainty Behaviour
- Bar Guidance Alignment
Which one fits
Choose Definely if
- Your security review wants the certificate, the auditor and the date. Definely publishes ISO/IEC 27001:2022 recertified on 4 February 2026 by the British Assessment Bureau, now Amtivo, with zero major and zero minor nonconformities, SOC 2 Type 2 recertified on 28 October 2025 with Prescient Security named as auditor, and a 2026 penetration test summarised publicly and compared against the previous year's findings.
- You want the AI itself inside an audited management system. Definely holds ISO/IEC 42001:2023 for AI management, certified by Prescient Security, and publishes what the certification covers: the full AI lifecycle, a formal AI System Register with impact assessments and defined ownership for each in scope system, and continuous monitoring rather than a point in time check.
- You want a vendor that says what it is not for. Definely publishes its own boundary, stating that it should not be described as a general purpose legal AI platform or a contract lifecycle system, that it is optimised for complex high risk contracts rather than high volume low complexity documents, and that its focus is the active contract and related documents rather than portfolio wide analysis.
Choose Ivo if
- You want output measured rather than asserted. Ivo publishes a benchmarking study scoring its redlines blind against a practising Am Law 25 Special Counsel and Claude for Word across nineteen real contracts, judged by three attorneys on five named criteria, with every participant's redlines and every playbook published for download and its own weakest area, formatting retention, named and shown.
- You want the supervision expectation written into the contract. Clause 14 of Ivo's Terms states that the service does not provide legal advice and creates no attorney client relationship, and requires the customer to represent and warrant that its use will be under the direct supervision of a qualified lawyer representing the customer.
- You are not replacing your contract repository. Ivo Intelligence connects to contracts wherever they are already stored, extracts data for plain language querying, shows an agreement and its amendments as a single timeline and flags deviations from standard positions, and named individuals at Canva and CDW speak on the record about it alongside a roster including Meta, Uber, IBM and Atlassian.
In summary
Definely
Definely is a Microsoft Word native suite for drafting, navigating and reviewing complex high value contracts, sold to large law firms and corporate legal departments, spanning Read for definitions and cross references, Proof for automated proofreading, Vault for clause level precedent search against a connected document management system, Enhance for AI analysis and Cascade for knock on effects across related contracts. The AI Legal Index grades it in the top two bands on nine of fifteen capability axes, with A grades on AI governance, security certifications and practice coverage. It holds ISO/IEC 42001 for AI management with a formal AI System Register and defined ownership per system. As of 29 August 2026 the index located no accuracy figure, no named model provider, no training statement on any open page and no pricing at any level.
Ivo
Ivo is an AI contract review platform for in house legal teams at large enterprises, checking agreements against a company's own playbooks and executed contracts and applying redlines in Microsoft Word or Google Docs, with a Playbook Builder that cites each position back to the agreement it came from and an intelligence layer that connects to contracts wherever they are stored. The AI Legal Index grades it in the top two bands on nine of fifteen capability axes, with A grades on AI centrality and citation accuracy, the latter resting on a published benchmarking study that scored its output blind against a practising Am Law 25 Special Counsel and released the underlying redlines and playbooks. As of 2 September 2026 the index located no named model provider, no governance material and no published price.
Questions buyers ask
Definely vs Ivo: which is better for contract review?
The AI Legal Index places both in the top two bands on nine of fifteen capability axes, so the grid does not separate them. What breaks the tie is the kind of evidence each publishes. Definely publishes credentials, including three certifications with named auditors and dates and a penetration test summarised in public. Ivo publishes measurement, including a blind scored comparison of its redlines against a practising attorney with the underlying files released. A buyer who has to satisfy procurement and one who has to satisfy a sceptical partner will not reach the same answer.
Has either published an accuracy measurement?
Ivo has. Its benchmarking study scored output from Ivo, from Claude for Word and from a practising Am Law 25 Special Counsel across nineteen real contracts, blind judged by three attorneys on five criteria, reporting means of 4.52 for Ivo and 4.56 for the attorney, with review times of 2 minutes 45 seconds against roughly 32 minutes. Ivo ran the study itself. On Definely the index located no accuracy figure, only a claim of 40 to 70 per cent faster contract review. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Do either say whether they train on customer contracts?
Ivo states on its home page that it never trains AI models on customer data. Its privacy policy separately states that Ivo may develop or improve services by analysing how features are used and the documentation submitted, and reserves the right to use de identified or aggregated information for any purpose; neither passage names models or training. On Definely no statement was located either way on any open page, so the index records it as silent rather than as a commitment. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Which one publishes its security certifications with dates and auditors?
Definely. It names three certifications with their auditors and dates, publishes a penetration test summary that includes a comparison against the prior year's medium severity findings, and runs a trust centre carrying the SOC 2 report, the penetration test report, architecture diagrams and its policy set behind a self serve access request. Ivo claims SOC 2 and ISO 27001 on its home page, and its trust centre renders client side and returned no readable content, so no auditor, scope or coverage period could be established. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What do Definely and Ivo both leave unpublished?
Neither publishes a price, a tier structure or a unit of charge. Neither names a model or a provider behind its AI, so neither could tell a client whose system reads its contracts. Neither describes segregation between users or matters, which matters for products indexing a firm's or a company's whole document set. Neither names a bar or ethics authority, including ABA Formal Opinion 512. And neither states a hosting region or a tenancy model. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Two things to read carefully. Ivo's accuracy study was run by Ivo, so the independence sits in the blind judging panel of three attorneys rather than in the sponsorship, the methodology states three judges while one FAQ answer says five, and the absolute scores are low on the study's own scale, with the human attorney baseline at 4.56 out of 10, so the finding is comparability rather than excellence. On Definely, the index records the training question as silent rather than as a commitment: no statement about whether customer content trains models appears on any open page, and the AI security whitepaper that would answer it sits behind a trust centre access request. Definely was verified on 29 August 2026 and Ivo on 2 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.