Docusign Agreement Manager vs Pramata: how they compare in 2026

D
Docusign Agreement Manager profile
P
Pramata profile
Last verifiedSeptember 25, 2026

Docusign Agreement Manager and Pramata both turn a company's signed contracts into structured, searchable data. Agreement Manager is the repository in Docusign's agreement platform; Pramata sells contract intelligence to enterprise legal, procurement and finance teams. Agreement Manager sits in the top two bands on fourteen of fifteen axes and Pramata on seven of fifteen. Docusign names each AI supplier against the feature it powers, including Azure OpenAI and Google Gemini, lists the regions each runs in, and announces changes through a subscribable feed. Its certifications carry stated scope and can be checked on public registries, and its terms commit to notice before any compelled disclosure. Its terms also include consent to train on customer data, which customers can switch off in settings. For Pramata, no customer agreement, security page or model provider was located. Pramata's counterweight is how it checks its own extractions. Its TrueCheck compares each extracted attribute against a human built key and a second AI layer, shows a per attribute accuracy score, and sends low confidence results to a person.

At a glance

Category
Docusign Agreement ManagerContract Review & Drafting
PramataContract Review & Drafting
Founded
Docusign Agreement ManagerNot published
PramataNot published
Headquarters
Docusign Agreement ManagerSan Francisco, California, United States
PramataSan Francisco, California, United States
Last verified
Docusign Agreement ManagerSep 13, 2026
PramataSep 6, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Docusign Agreement Manager
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models are the engine of a core capability layered on a product that would function without them as a document system, which is the B band. What the AI does here is substantial and named. Docusign Iris drives AI-powered data extractions including custom extractions defined by the customer, AI-generated worksheets for portfolio analysis, and agents that analyse agreements, follow the customer's policies and work across connected tools. The company describes the current release as the next evolution of Iris, with agents that transform how agreements are managed. What keeps it off A is that the product underneath is a repository. Remove the models and Agreement Manager still consolidates executed agreements into a single searchable store, still runs permissions and audit tracking, still tracks renewals and obligations against dates, and still reports. The extraction layer converts documents into structured data faster than manual entry did, which is a large improvement to a system that existed before it and not the reason the system exists. The product's own positioning supports that reading: it is sold as the manage phase of a lifecycle whose other phases are preparation, signature and workflow, and it is included in selected IAM plans rather than sold as an AI product in its own right. Recorded for the history: the capability came in with the May 2024 acquisition of Lexion, whose entity DocuSmart Inc. still appears as a named subprocessor for extraction, and the product was itself called Docusign Navigator until the rename to Agreement Manager. Verified 13 September 2026.

Pramata
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

The machine learning is the mechanism the buyer pays for. The product is the extraction of structured contract data from portfolios by the Contract AI Engine, validated by AI TrueCheck, with AI Negotiator, agents and a design studio built on it; the vendor positions itself against traditional CLMs precisely as the intelligence layer rather than the repository and workflow. Remove the models and there is a repository of documents without the data the customer is buying. TrueCheck release, product listing text and AI Negotiator release read 6 September 2026.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Docusign Agreement Manager
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is real and documented and no measured accuracy is published, which is the B band. The grounding claim is specific to what this product does: the AI reads the customer's own executed agreements rather than a legal corpus, and agent output is described as traceable to cited sources, so a user can follow an extracted provision or an agent's answer back to the agreement it came from. Around that sit two published quality mechanisms that are more than assertion. The AI Trust page states that diverse datasets and thorough checks are used to correct skewed outputs and ensure quality before model deployment, which is a pre-release testing statement, and that content filtering is applied for harmful outputs. The subprocessor list independently corroborates part of it by naming Google's Model Armor as an AI security and content moderation service in the IAM stack, which is an unusually concrete disclosure of a safety control. What is absent is measurement. The AI Trust page states that customers can trust that AI outputs have been tested for accuracy, and no figure, error rate, test set, evaluation or third-party validation is published anywhere for extraction precision, agent answers or worksheets. Third-party write-ups cite a 15 per cent precision advantage over general-purpose models on extraction; that is not published first-party and is not credited. R15 governs the citator and primary-authority limbs, which do not apply to a product that cites the customer's own contracts rather than law. Verified 13 September 2026.

Pramata
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

A measured accuracy figure and a documented validation method are published, short of a described test set. The vendor states ninety-nine per cent plus verifiable data accuracy, and the TrueCheck release describes how it is measured in production: a human-curated key from a representative set of documents, the AI extraction, and a separate AI validation layer, with a per-attribute accuracy score shown where the three align and lower-confidence results routed to a person. A vendor-authored October 2025 article describes structured output schemas, mandatory step-by-step reasoning logs and context-window monitoring as hallucination controls. The test set behind the headline figure and its date are not published, and the primary-authority limbs do not apply to a contract-data tool. TrueCheck release and Artificial Lawyer article read 6 September 2026.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Docusign Agreement Manager
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

A written commitment that the models work alongside the customer with a real review surface, short of the full control structure, which is the B band. The commitment is explicit and sits on the vendor's own AI Trust page: the customer has the final say to approve outputs, so they meet the customer's standards. Around it, agents are described as following the customer's policies and returning answers traceable to cited sources, and the product publishes access controls and built-in activity tracking that would let an administrator see what was done. Those are genuine oversight materials rather than a slogan. What the A band asks for is not published. No mode distinction is described between what an agent may do unattended and what requires approval, no confidence threshold, no statement of when an agent stops or escalates, and nothing on what happens after the system is wrong. That gap matters more on this record than on most in the lane, because the direction of travel is expressly toward autonomy: the company markets agents that do not just find data but take action, delegated complex tasks working across the customer's other tools, and an agentic layer launched at its 2026 user conference. R124(2) was applied and no qualifying constraint was found: the final-say-on-outputs statement is a general assurance of human review, which R124(2) holds does not substitute for the threshold limb, and nothing attaches a stated boundary to a named agent or tier saying what that tier's output may not be used for. Verified 13 September 2026.

Pramata
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

The modes, the review surface and a confidence-based routing rule are published, short of the full control structure. AI TrueCheck runs extraction and validation automatically, shows a high-confidence score where the stages agree, and brings in a human where the AI has lower confidence, which is a stated route for oversight; AI Negotiator presents red, yellow and green risk flags against playbooks for the negotiator to act on; the design studio lets legal configure playbooks and agents. What is not published is the numeric threshold at which a result is treated as validated without a person, or a stated route back after a wrong extraction beyond the audit trail. TrueCheck release and AI Negotiator release read 6 September 2026.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Docusign Agreement Manager
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Real deployment evidence with substance, short of the dating and method the A band requires, which is the B band. The evidence is joined in a way this corpus rarely sees: four customer stories are published on the product page itself, each naming the organisation, attaching figures, and quoting a named individual with their title. Catchafire reports approximately 77 per cent less time spent processing agreements and a doubling of contracting capacity across sales and legal, quoted by its Deputy Director of Revenue Operations. Greater Philadelphia YMCA reports 99 per cent of agreement requests entering through a single digital intake process and 50 per cent less time on initial agreement reviews, quoted by its Senior Vice President of Information Technology. Kindsight reports a sales cycle one week shorter and two to three days saved by its IT team, quoted by its Director of IT. The Law Offices of Mark T. Hurt, a law firm, is quoted by its Chief of Staff. So named customers and figures are attached to each other rather than floating separately, which is the failure mode on most records. Two limbs of the A band are missing. Nothing is dated: no story states when the deployment happened or over what period the figures were measured. And no method is stated for any figure, so a reader cannot assess what 77 per cent less time was measured against or how. The individual story pages were not opened; under R25 they corroborate a grade that already stands on the product page, and they are what would move this row. Company scale is published separately at 1.9 million customers. Verified 13 September 2026.

Pramata
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Named customers without figures, and figures without a named customer. The vendor's releases name McKesson, ICE, AbbVie and Callaway Golf as customers of twenty years' standing with no measured outcome, and state ten times faster contract analysis, a two hundred per cent adoption rate and a fifty per cent reduction in time on contract tasks, unattributed. Nothing joins a named customer to a figure. TrueCheck release, AI Negotiator release and listing text read 6 September 2026.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Docusign Agreement Manager
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Substantive published commitments on confidentiality, short of the full picture on training and silent on privilege, which is the B band. What is committed is contractual rather than promotional. The published Terms define Customer Data as data uploaded to the Docusign Services and deem it the customer's Confidential Information, which pulls it inside a mutual confidentiality regime requiring use solely for the purpose provided, disclosure only on a need-to-know basis to parties under equivalent obligations, and protection using no less than reasonable care. Where disclosure is compelled by law the receiving party must give prompt written notice before disclosing unless legally prohibited, and must assist in obtaining a protective order where reasonably available. The position on third party model providers is the strongest limb and is answered better here than anywhere else in this corpus: the subprocessor list names Microsoft Azure OpenAI Service, Azure AI Document Intelligence, Google Gemini, Model Armor and DocuSmart, each against the specific feature it powers. Encryption in transit and at rest is stated on the AI Trust page. Two limbs fail. Training on customer data is not excluded but permitted on a consent that the Terms describe as something to opt out of, which is graded on the training row and is the reason this axis cannot reach A. And privilege and work product are not addressed anywhere located, on a repository built to hold a company's executed agreements and, in at least one published customer story, a law firm's matter workflow. Retention and deletion for AI inputs were not established; the AI Attachment governing them was not opened. Verified 13 September 2026.

Pramata
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Confidentiality is addressed at the level of general assurance on the surfaces read. The vendor states hosting on Amazon Web Services with SOC 2 Type II, ISO 27001, HIPAA and GDPR compliance; no customer agreement, DPA, security page or trust centre was located, so no statement on training use, retention, deletion, segregation, third-party model providers or privilege was read. Those documents, if published on pramata.com, are the rebuttal route. Releases and listing text read 6 September 2026.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Docusign Agreement Manager
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Nothing published on the advice line was located for a product that produces legal work and is expressly sold to people who are not lawyers, which is the D band including its own parenthetical. The parenthetical is the point of this grade and is why R15 does not rescue it. Docusign IAM is marketed by department, with dedicated pages for Sales, Customer Experience, Human Resources, Procurement and Legal, and the published customer stories are led by revenue operations and IT rather than by counsel. What the AI does for those buyers is legal work by any ordinary description: extracting governing law, indemnification clauses and liability caps; flagging high-risk clauses and recommending alignment to a company standard; and, through agents and the adjacent AI-Assisted Review, redlining and reviewing contracts. Nothing published states what the product is and is not, whether its output constitutes legal advice, whether a lawyer should review an agent's redline before it goes to a counterparty, or who inside a customer is expected to be accountable for it. No competence or supervision statement was located and no jurisdiction limit is named for the AI. Recorded and expressly not credited, because each answers a different question: the Terms disclaim warranties and provide the service as is, which is a liability position and is graded there; the Legality Guide is a jurisdiction-by-jurisdiction resource on the legal validity of electronic signatures, not on AI output; and the restriction barring customers from using outputs to train competing systems protects the vendor rather than the customer's professional position. Verified 13 September 2026.

Pramata
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

No advice line or supervision statement was located. The product is sold to enterprise legal, procurement and finance teams and AI Negotiator is positioned as accelerating negotiation for those users; no surface read states that outputs are not legal advice, who should rely on them, or how the product supports a supervising lawyer's duties, and no customer agreement was located. Releases and listing text read 6 September 2026.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Docusign Agreement Manager
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

A published governance framework with real substance, short of testing results and a named owner, which is the B band. The substance is genuine and sits on surfaces built for it: Iris carries its own sub-navigation including an AI Innovation Principles page and an AI Trust page, which is more governance real estate than any other record in this pull. The AI Trust page publishes four capabilities with mechanisms attached rather than adjectives: encryption in transit and at rest; customer control over whether data is used for AI or ML training, with a consent that can be managed and, where given, aggregation and anonymisation before use; the use of diverse datasets and thorough checks to correct skewed outputs and ensure quality before model deployment, plus content filtering for harmful outputs; and a compliant storage and compute platform for data labelling and AI training, described as extensible so the company can adapt to evolving global standards, with the NIST AI framework named. Naming an external framework and describing pre-deployment testing puts this comfortably above a principles page. Two A limbs are missing. No accountable owner is identified: no individual, committee or function inside Docusign is named as responsible for model behaviour. And nothing is disclosed about what the testing has found, so the correction of skewed outputs is asserted as a practice with no results attached and no statement of whether output is uneven across agreement types, languages or regions. One access limit is recorded under R5: the page states that broader AI Trust capabilities require contacting a sales representative, so the published set is a summary. The AI Innovation Principles page was not opened and is what would move this row. Verified 13 September 2026.

Pramata
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

A published account of mechanisms with real substance, short of test results or a named owner. The vendor's October 2025 article describes patent-pending controls against hallucination, a Relationship Object Model that constrains outputs to predefined schemas, a requirement that the model document its reasoning step by step, context-window overflow monitoring with user alerts, and states fifteen or more such measures; the TrueCheck release adds a production validation layer with audit trails. No responsible AI framework, ISO 42001 or equivalent, published test results, bias findings or accountable owner was located. Artificial Lawyer article and TrueCheck release read 6 September 2026.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Docusign Agreement Manager
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Substantive published policy covering most of the ground, short of the full set on retention, which is the B band. Subprocessors are the strongest limb by a wide margin and are dealt with on the Model Supply Chain row as well: a dated list, last updated 11 August 2026, published as a web page and a downloadable document, itemised per Docusign Service so a buyer reads only the IAM section, naming entity, country, the exact feature each supplier powers and a contact address, and extending to eighteen named Docusign group entities and their locations. Change management around it is real rather than nominal: updates are published to an RSS feed customers can subscribe to, the Data Protection Attachment commits to that mechanism, and customers may object to a new subprocessor by email on stated grounds. Access control and incident practice are both addressed: the Terms provide for prompt written notice before compelled disclosure and for suspension notice, and the Trust Center carries incident reporting, security alert and system status pages. Encryption in transit and at rest is stated for Iris specifically. What is not established is retention. No retention period or deletion commitment for prompts, extracted provisions or agent outputs was located, and the AI Attachment that would govern it was not opened. Recorded because it cuts the other way and a buyer should weigh it: the Terms reserve Usage Data to Docusign, including insights derived from operation of the services, for purposes including benchmarking, analytics and product development, with disclosure de-identified and aggregated. Verified 13 September 2026.

Pramata
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

Some of the ground is covered and the rest was not located. The vendor states AWS hosting with SOC 2 Type II, ISO 27001, HIPAA and GDPR compliance and audit trails on AI outputs; no retention period, deletion commitment, sub-processor list or incident-notification practice was located, and no customer agreement, DPA or security page surfaced in search. Those are the rebuttal route. Releases and listing text read 6 September 2026.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Docusign Agreement Manager
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

A real published position on liability, short of the full picture, which is the B band. The position is published in full and is unambiguous, which is more than most records manage, but it runs almost entirely one way. Warranties are disclaimed: the service and any information supplied are provided as is and as available, with all implied warranties of merchantability, fitness for purpose, quality, accuracy and title expressly excluded, and no warranty that the service will be error-free or meet the customer's requirements. Liability is capped twice over: total liability for any cause of action arising out of the Docusign Services will not exceed the total paid for the service giving rise to the claim in the twelve months preceding the first event, or 100 dollars, whichever is greater, with the same cap restated for the services section and a flat 100 dollar cap during a free trial. Direct as well as consequential damages are disclaimed. Indemnification runs from the customer to Docusign, covering use of the service, breach of the Terms and the substance of documents uploaded. So a buyer can read the allocation before signing and it is a published, specific and heavily vendor-favourable one. What is missing is anything running the other way on the AI. No vendor indemnity for AI output appears in these Terms; the only vendor indemnity located is an intellectual property indemnity in the supplemental terms for Australian consumers and small businesses. No insurance is addressed, no service level accompanies the liability position here, and nothing addresses who bears the loss when an extraction is wrong or an agent acts on a mis-read obligation. Enterprise customers contract on a separate Master Services Agreement, which is published in archive form and was not opened. Verified 13 September 2026.

Pramata
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

No liability position was located on the surfaces that could be read. No terms of service, subscription agreement or licence surfaced in search, the releases describe capabilities without any warranty, indemnity, cap or insurance position, and the pramata.com footer was not inventoried, so whether an agreement exists is not established. This records what is locatable on the date and not a finding that no position exists; any published agreement is the rebuttal route. Releases read 6 September 2026.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Docusign Agreement Manager
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Real integrations exist and are documented, short of the depth the A band describes, which is the B band. The breadth is not in doubt and is unusual in this corpus: the company publishes an App Center for partner and ISV applications, advertises more than 1,000 pre-built integrations, runs a public Developer Center, and lists pre-built MCP connections as a filterable integration category, which is a route into agentic tooling that almost nothing else in this pull offers. On the product page, integrations and data sharing is a named feature, described as connecting agreement data to existing tools via integrations, APIs and pre-built connectors so agreements are actionable without switching platforms, and a separate feature promises to extend agreement data across vetted tools and AI ecosystems while enforcing governance and security controls. Docusign Connect provides webhook events on envelope state changes. What the A band requires is depth described: what syncs, in which direction, and what a firm must configure. That was not established from the surfaces read. No individual practice management, document management or matter management system is named as supported on the product page, no direction of flow is described for any named connection, and no configuration prerequisite is stated. The Developer Center and the App Center listings were not opened; under R25 they corroborate a grade that stands on the product page and the published integration count, and they are precisely what would move this row to A. Verified 13 September 2026.

Pramata
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Real integrations with depth described for some. AI Negotiator runs inside Microsoft Word, analysing incoming agreements against playbooks and prior negotiations; the platform exposes contract intelligence through Model Context Protocol connectivity and an extension to Anthropic's Claude Cowork legal plugin, described as bringing commercial relationship context into that interface; a partnership with Gotransverse connects contract data to billing; the design studio is described as connecting to existing systems. Document management and matter system integrations are not named with what syncs in which direction, and no integration documentation was opened. Releases read 6 September 2026.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Docusign Agreement Manager
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Cloud delivery with region genuinely answered and tenancy not described, which under R38 is B because tenancy and region are co-equal limbs and publishing either clears C. Region is answered with more precision than a residency page alone would give, because the subprocessor list carries it per supplier and per service: Azure cloud hosting for IAM is provisioned in the United States, Australia, Canada, the European Union and Japan; Azure AI Services for IAM in the United States, Canada, the European Union, Australia and Japan; and Google Cloud Vertex AI for IAM in those regions plus Switzerland. The list also states that applicability depends on data centre location, with EU-provisioned accounts using EU infrastructure subprocessors, and the trust estate states that customer documents are encrypted and stored in the data centre region of the account that sends them. A dedicated data residency page exists. Binding Corporate Rules approved by EU data protection authorities as both processor and controller, plus the EU Standard Contractual Clauses at Modules 2 and 3, give the cross-border position a contractual basis rather than a marketing one. What is absent is tenancy. Nothing describes whether a customer's agreements sit in a shared or isolated environment, no separation model is published, and no single-tenant, private or on-premises option is offered or refused. Nothing states where inference runs relative to where documents are stored, which is the live question given AI processing is provisioned region by region and separately from hosting. Verified 13 September 2026.

Pramata
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Cloud delivery on a named provider is stated and neither tenancy nor region is addressed. The vendor describes a cloud repository hosted on Amazon Web Services; no region, residency option or tenancy model is stated on the surfaces read, and no security page was located. Listing text read 6 September 2026.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Docusign Agreement Manager
AA on Security Certifications and Trust CenterCurrent independent attestation with named scope, reachable without a sales call: a trust center carrying reports, dates and the standards actually covered.

Current independent attestation with named scope, reachable without a sales call, which is the A band met on every limb. The trust centre is a genuine estate rather than a page, with sections for Legal, Alerts, Compliance, Privacy, Security, System Status and a Trust Portal through which certifications and assessments are accessed. The standards are enumerated with versions and years rather than as logos: ISO 27001:2022, ISO 27017:2015 and ISO 27018:2019; PCI DSS version 4.0, with the company listed as a service provider on the Visa Global Registry; SOC 1 Type II and SOC 2 Type II against the AICPA Trust Services Criteria, with annual audits stated to cover all aspects of production operations including data centres; C5 Type II under the German BSI; Australian IRAP at PROTECTED level; DoD IL4 provisional authorisation; APEC Privacy Recognition for Processor; Binding Corporate Rules approved as both processor and controller; and Government of Canada Protected-B. Scope is stated per certification, which is what makes this an A rather than a long list, and it is stated precisely enough to cut both ways: FedRAMP Agency authorisation and GovRAMP authorisation both name Docusign Federal covering eSignature and IAM, so this product sits inside those scopes, while C5 is scoped to the eSignature product and DoD IL4 to eSignature and CLM, so this product does not sit inside those. Independent verification is reachable without a sales conversation through public registries: the FedRAMP marketplace, the Visa registry, the EU Trusted List via ANSSI, the APEC certificate directory, and the CSA STAR registry, where the annual CAIQ is stated to be publicly accessible for viewing and download. Third-party risk assessments are completed annually under S&P Global KY3P, ProcessUnity and the Shared Assessments SIG. Verified 13 September 2026.

Pramata
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

Standards are stated in vendor-supplied listing text without an attestation on a vendor page that could be read. SOC 2 Type II, ISO 27001, HIPAA and GDPR compliance are stated in the product description the vendor supplies to directories; no auditor, coverage period, certificate or report route was located, and no security page or trust centre on pramata.com surfaced in search. Under the standing rule that directory listings are not evidence of capability, the stated standards are recorded without credit and the vendor's own security page, if any, is the rebuttal route to B. Listing text read 6 September 2026.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Docusign Agreement Manager
AA on Model Supply Chain DisclosureThe models underneath are named, their providers identified, where they run is stated, and the vendor commits to notifying customers when any of that changes.

The models are named, their providers identified, where they run is stated, and the vendor commits to notifying customers when any of it changes. All four A limbs are met, and this is the most complete model supply chain disclosure located in this corpus. The disclosure lives in the subprocessor list, dated 11 August 2026, which is itemised per Docusign Service so the IAM section can be read on its own, and which carries a heading for Artificial Intelligence Suppliers. Under it, three entries, each mapped to the specific feature it powers rather than listed generically. Microsoft Corporation, Azure AI Services: Azure OpenAI Service for AI extractions in Agreement Manager, AI agents, and AI-Assisted Review for IAM; Azure AI Document Intelligence for AI extractions in Agreement Manager and Agreement Desk AI agents. Google LLC, Google Cloud Platform Vertex AI: Google Gemini for AI extractions in Agreement Manager, Model Armor as an AI security and content moderation service, and Gemini global endpoints for AI-assisted web form creation. DocuSmart Inc. trading as Lexion, a wholly owned Docusign subsidiary, for AI extractions in Agreement Manager, with its own subprocessor page linked. Each entry states the countries of service provisioning and a contact address. Change notification is committed and operational rather than promised: updates are published to an RSS feed customers can subscribe to, the Data Protection Attachment records that mechanism at clause 7.2, and customers may object to a new subprocessor on stated grounds. What is not published, and is named so the A is read for what it is: no model version is given for any of the three, so a buyer knows which provider and which service but not which release, and nothing states what any provider may retain. Verified 13 September 2026.

Pramata
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The vendor describes its architecture without identifying what sits underneath. The releases describe a proprietary Contract AI Engine, generative AI extraction with an AI validation layer, and structured-output and reasoning-log controls, and the Claude Cowork extension identifies an interface rather than a supplier; no model, provider, inference location or change-notification commitment is named on the surfaces read. Releases and article read 6 September 2026.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Docusign Agreement Manager
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

Real pricing is published for part of the range with the enterprise tiers withheld, which is the B band. The commercial mechanics are published in unusual detail in the Terms and a buyer can read them before committing: subscription plans with entitlement units, automatic renewal unless cancelled at least five business days before the term ends, overage fees billed monthly in arrears at the per-unit rate in the plan, promotional codes applying only to the initial term with renewals at the undiscounted price, payments non-refundable subject to a good-faith consideration of refund requests made within the first thirty days of an annual term, thirty days' advance notice of fee changes, late payment interest at 1.5 per cent monthly, and taxes payable in addition. The Terms also state that subscription plans may be generally published on the website, and self-serve plans and pricing pages exist for both eSignature and IAM. What holds this off A is that the rate card itself was not read and the product's own position is mixed. Agreement Manager is not sold on its own: the page states it is included in select IAM plans, and offers Explore IAM Plans alongside Contact Sales, so what a buyer pays for this capability depends on which plan carries it and that mapping was not established. The IAM plans and pricing page at the ecommerce subdomain was not opened, and it is what would move this row to A. Recorded so the grade is read correctly: this is a limit on what was established, not a finding that the vendor withholds the number, and nothing suggests the page is gated. Verified 13 September 2026.

Pramata
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing information was located at any level. The releases and listing text describe an enterprise platform without a unit of charge, tier or figure, and no pricing page surfaced in search; the pramata.com footer was not inventoried, so the absence of a pricing page is not established by inventory and this row is rebuttable on one. Releases and listing text read 6 September 2026.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Docusign Agreement Manager
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Segment coverage is described with real substance and the boundaries are left open, which is the B band. The description is unusually systematic. Buyer segments are addressed department by department with a dedicated page each, covering Legal alongside Sales, Customer Experience, Human Resources and Procurement, plus an IAM Core page and a separate enterprise page. Industry coverage is addressed the same way, with pages for financial services, insurance, real estate, government, healthcare and life sciences, and the regulatory posture behind several of them is evidenced rather than claimed: FedRAMP and GovRAMP authorisations naming IAM support the government segment, 21 CFR Part 11 with an annual independent USDM assessment supports life sciences, and HIPAA support is stated. Scale is published at 1.9 million customers. Legal buyers are addressed directly, with published material on agentic contract workflows for in-house legal teams and a law firm among the named customer stories. What is left open is the boundary in both directions. Nothing states which agreement types or practice areas the extraction models handle well or badly, and the AI is documented elsewhere as English-first for some extraction paths without that limit being stated on the product surface. Nothing identifies a customer size floor or a segment out of scope. And the record should be read knowing legal is one buyer among five here rather than the buyer, which is a real difference from the specialist contract tools in this lane and is not a criticism of the product. Verified 13 September 2026.

Pramata
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Segment and coverage are described with substance; the boundaries are left open. The buyer is enterprise legal, procurement, finance and operations teams at large companies, with Fortune 500 users named in the Claude Cowork release and customers across healthcare, financial exchanges, pharmaceuticals and consumer goods; coverage spans the contract lifecycle from repository through negotiation to obligation management, with a named tariff-risk agent. No contract type, jurisdiction or company size is named as unsupported, and no law firm use is described. Releases read 6 September 2026.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Docusign Agreement Manager
Opt out

Training is on by default with a published mechanism to switch it off, which is this value, and the value turns on a conflict between two of the vendor's own surfaces that R37 resolves. The marketing surface reads as consent-first. The AI Trust page states that data is only used for AI or ML training with the customer's consent, that the customer has the flexibility to manage that consent, and that where consent is given the data is aggregated and anonymized before use.

Read alone, that is an opt-in. The agreement reads the other way. Clause 4.3 of the Sites and Services Terms provides that services using AI are subject to the AI Attachment for Docusign Services, which may include consent to use Customer Data to improve Docusign Services and AI Services, including without limitation to train artificial intelligence algorithms and machine learning models, and then tells the reader how to opt out of that consent by reference to the AI Data Controls Settings guidance.

Consent that arrives with the contract and is removed by a setting is an opt-out, whatever the marketing calls it. R37 rule 1 governs where marketing and the agreement conflict and the agreement wins, which is the same shape as Clio at R43. Two things belong on the record. The control is real and named, not theoretical, and the aggregation and anonymization qualifier is a genuine mitigation. And the AI Attachment itself, which is the instrument that would settle the scope, is published and was not opened; R43(1) is therefore run but not discharged and a reading could move this row in either direction.

Pramata
Terms silent

No located public material addresses whether customer contracts train models, and no customer agreement, DPA or security page surfaced in search. The TrueCheck release describes a human-curated key built from a representative set of the customer's documents for validation, which is calibration within the customer's engagement rather than a training statement. Any published agreement or security page on pramata.com is the rebuttal route in either direction. Surfaces checked 6 September 2026.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Docusign Agreement Manager
Not addressed

No located public material states how long prompts, extracted provisions or agent outputs are kept, which is the floor, and the note records precisely why that verdict sits alongside an otherwise strong data estate. What is published concerns protection rather than duration: data is encrypted in transit and at rest when Iris is used, and where a customer has consented to training use the material is aggregated and anonymized first.

Neither is a retention statement. On the contract side the Terms address the end of the relationship in general terms and route personal data handling to the privacy notice and the Data Protection Attachment, and the effect-of-termination clause deals with accrued liabilities and license termination rather than with the disposal of uploaded content. Nothing states a period, a deletion trigger, or an export or return obligation for the AI material specifically, and nothing states what any of the three named model providers may retain of a prompt or a document sent to them.

The instrument that would answer this is identified and published, and it was not opened: the AI Attachment for Docusign Services is linked from clause 4.3 of the Terms and governs AI Services. That is named here rather than left implicit, because it is the single document that would move this row, and because it also carries the training question graded separately. Recorded and not credited as retention: the Terms reserve Usage Data, meaning diagnostic and usage-derived insights, to Docusign indefinitely for benchmarking and product development, which is a different object from the content this signal covers.

Pramata
Not addressed

No located public material addresses how long contracts, extracted data or AI outputs are retained. The releases describe audit trails without a retention period, and no agreement or privacy notice for the product was located. Surfaces checked 6 September 2026.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Docusign Agreement Manager
Own model, documented

A permission model is described as a product capability rather than asserted as a security posture, which is this value. Access controls and audit features are one of the six named features of the product, and the description is functional: the right users are enabled to reach the right agreements through flexible permissions, and built-in activity tracking keeps the account audit-ready. A separate feature statement extends the same idea outward, describing agreement data being made available across vetted tools and AI ecosystems while governance and security controls are enforced, which indicates the permission model travels with the data rather than stopping at the interface.

A screenshot on the product page shows an interface for selecting a level of agreement access for others, so the control is exposed to administrators rather than being configured by the vendor. On the vendor's own side the Terms restrict disclosure of Customer Confidential Information to a need-to-know basis among parties under equivalent obligations. What is not published is the model itself. No roles or permission levels are enumerated, nothing describes how a grant is made, reviewed or revoked, and nothing states whether an account administrator can read agreements they were not granted.

Nothing addresses walls between matters or clients as a legal concept, which is the framing a law firm would need and which matters here because a law firm appears among the published customer stories, though the product's center of gravity is a company's own agreement portfolio rather than client matters.

Pramata
Not addressed

No located public material describes segregation between customers or within a customer's portfolio. The releases describe a cloud repository and role-agnostic access to contract intelligence across legal, finance and operations, and no permission model or tenancy description was located. Surfaces checked 6 September 2026.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Docusign Agreement Manager
Notice committed

The agreement commits to notice before compelled disclosure and adds an assistance obligation, which is this value. Clause 5.3 of the published Terms provides that a party required by law to disclose the other's Confidential Information will give prompt written notice before making the disclosure, unless prohibited from doing so by the legal or administrative process, and will assist the other party in obtaining, where reasonably available, an order protecting that information from public disclosure.

Customer Data is expressly deemed the customer's Confidential Information at clause 4.7.1, so the protection reaches uploaded agreements rather than only account records. Notice before rather than after, coupled with a duty to help obtain a protective order, is materially stronger than the discretionary formulations that dominate this signal. It is not the top value because no reporting obligation accompanies it: no transparency report is published and nothing commits to periodic disclosure of demand volumes.

One qualification is recorded rather than left for a reader to find, because it pulls against the clause above. A separate access and disclosure provision at clause 4.7.2.1 reserves a broader discretion, allowing Docusign to access, preserve or share information where it believes in good faith that doing so is reasonably necessary to investigate or act on possible illegal activity or to comply with legal process, and in situations involving threats to physical safety or violations of its terms, with sharing contemplated to law enforcement, government agencies and courts. That provision carries no notice commitment of its own.

Pramata
Not addressed

No located public material addresses whether the customer is told when its data is demanded by a third party. No customer agreement or DPA was located. Surfaces checked 6 September 2026.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Docusign Agreement Manager
Not addressed

No located public material identifies a source corpus, and R15 governs the weight, so the note sets out the position rather than leaving it to inference. This product answers from no body of law. The AI reads the customer's own executed agreements, extracting parties, dates, financial terms, renewal conditions and governing law from documents the customer uploaded, and the vendor's own framing is that the models are grounded in the customer's legal language, counterparty history and policies.

There is therefore no licensed legal corpus whose provenance this signal would ordinarily test, and the vendor is not withholding something its product class implies. What is genuinely unaddressed, and why the value is recorded rather than treated as inapplicable, is the provenance of the training material behind the extraction models. Nothing states what the models were trained on. The question is not academic here: the vendor operates a consent-based program under which customer agreements may be used for training after aggregation and anonymization, so at least part of the training corpus is other customers' contracts, and nothing published describes the scope of that pool, how consent is recorded across it, or whether a customer that has opted out nonetheless benefits from models trained on those that did not.

Nothing addresses licensing of any third-party corpus behind the named model providers. The surfaces read on the date shown were the product page, the Iris overview, the AI Trust page, the Terms, the subprocessor list and the certifications page.

Pramata
Not addressed

No located public material identifies a legal corpus behind the product's output, and the product is not built on one: it extracts data from the customer's own executed contracts and negotiation history, citing no law. Releases checked 6 September 2026.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Docusign Agreement Manager
Not addressed

No located public material addresses whether authority is checked for subsequent history, and on this product the question does not arise. Nothing in Agreement Manager cites law. The repository holds a company's executed agreements and the AI extracts provisions from them, reports across the portfolio and tracks obligations and renewals; the only citation that occurs is internal, the traceability of an agent's answer back to the clause in the customer's own contract that supports it.

No proposition about the state of the law is produced whose treatment a lawyer would verify in a citator. R15 governs and the limb is recorded as inapplicable rather than failed. One adjacency is named so it is not mistaken for the thing, because it is the closest this product comes to a currency question: extracted provisions such as governing law and renewal terms go stale when an agreement is amended or superseded, and nothing published describes how the repository detects that a later document changes an earlier extraction, or what happens to an obligation the system is tracking when the underlying clause is renegotiated.

That is a data currency question rather than a good-law question and it is not graded here. The surfaces read on the date shown were the product page, the Iris overview and AI Trust pages, the Terms, the subprocessor list and the trust center certifications page.

Pramata
Not addressed

No located public material addresses whether authority is checked for subsequent history, and the product does not retrieve or cite primary law; its output is structured contract data, risk flags and negotiation guidance. Recorded as the honest value for a product without a citator function. Surfaces checked 6 September 2026.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Docusign Agreement Manager
Not addressed

No located public material describes what the system does when it cannot produce a reliable answer. What the vendor publishes addresses the rate of bad output and the customer's ability to catch it, not the system's behavior at the moment of uncertainty. On rate: diverse datasets and thorough checks are stated to correct skewed outputs and ensure quality before model deployment, and content filtering is applied for harmful outputs, with the subprocessor list independently naming Google's Model Armor as an AI security and content moderation service in the IAM stack.

On catching it: the customer has the final say to approve outputs, and agent answers are described as traceable to cited sources. Neither says what happens when an extraction is doubtful. Nothing states that the system declines to extract a provision it cannot locate confidently, marks a low-confidence extraction for review, reports that a requested term is absent rather than returning a nearest match, or behaves differently when an agent cannot complete a delegated task.

That gap has weight on this product because of what the output feeds: extracted provisions populate reports, obligation tracking and renewal alerts, so a silently wrong extraction becomes a missed renewal or an untracked obligation rather than a visibly wrong answer a reader would question. Nothing published indicates which way the system errs. The surfaces read on the date shown were the product page, the Iris overview, the AI Trust page, the Terms, the subprocessor list and the certifications page.

Pramata
Documented

An explicit path for low-confidence output is described: the TrueCheck release states that where the three validation stages do not align a human-in-the-loop component provides oversight, and the vendor's October 2025 article states the system alerts users when context utilization approaches thresholds that might impact reliability. The behavior is described rather than demonstrated, and the confidence threshold itself is not published. TrueCheck release and article checked 6 September 2026.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

Docusign Agreement Manager
None located

Searched on 13 September 2026 against the company name, the product name, the AI engine name and the acquired brand, across reporting and trackers covering decisions on AI-generated fabricated citations in the United States and elsewhere. None located. No decision, sanction or disciplinary referral names Docusign, Agreement Manager, Iris or Lexion. Context is recorded because the field searched is now large rather than empty, so the absence was tested against something: reported instances include a first published California appellate opinion imposing a 10,000 dollar sanction and a State Bar referral for briefs replete with fabricated citations, a federal sanction of three litigators from a national firm over five fabricated citations, a show-cause order requiring patent counsel to identify which AI platform produced nonexistent quotations, a Delaware Chancery letter ruling on fictitious citations and hallucinated legal propositions, and an Oregon Court of Appeals notice warning that fabricated authority is grounds for striking a filing and imposing sanctions.

General-purpose assistants rather than agreement platforms are what those accounts describe. Under R119 this signal records fabricated legal citations in filings and nothing else, so no other proceeding involving this vendor would appear here. One point of product context: this product does not generate citations to legal authority, extracting provisions from the customer's own agreements instead, so the exposure this signal tracks is structurally low.

Pramata
None located

No court order, opinion or disciplinary record naming Pramata was located as of 6 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on the name together with a general search for court findings; results returned the vendor's own article on hallucination controls and sanctions involving general-purpose chatbots, none of which is a court record naming this product. This is a statement about the public record, not a finding about the product; a contract-data tool that cites no authority carries a remote exposure on this signal.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Docusign Agreement Manager
Not addressed

No located public material engages with bar or ethics guidance, in general terms or otherwise. No bar opinion is cited, no rule of professional conduct of any jurisdiction is named, and nothing maps the AI or the agents to the obligations of a lawyer who relies on their output. Nor is professional responsibility engaged generically: no statement was located requiring customers to use the product consistently with their professional obligations, and the Terms restrict use by reference to the vendor's own acceptable use rather than to the customer's duties.

The regulatory engagement that does exist is extensive and runs entirely to data, security and sectoral regimes rather than to conduct: ISO, SOC, PCI DSS, FedRAMP, GovRAMP, DoD IL4, IRAP, C5, HIPAA, 21 CFR Part 11 and the NIST AI framework. Those bind the vendor as a processor, not the customer as a lawyer. The gap is worth naming precisely rather than generally, because of who buys this product. Docusign publishes dedicated material on agentic contract workflows for in-house legal teams and sells IAM to legal departments alongside sales, procurement and HR, so agents that review, redline and draft agreements are being placed in the hands of both lawyers and non-lawyers inside the same customer.

Guidance on where the professional line sits in that arrangement is exactly what a general counsel would want and none is referenced. The eSignature Legality Guide is recorded and not credited: it addresses the legal validity of electronic signatures by jurisdiction, not the use of AI.

Pramata
Not addressed

No located public material names an ethics opinion, bar rule or professional responsibility framework. The vendor's general counsel has spoken publicly on generative AI in contracting, which is commentary rather than guidance alignment. Releases checked 6 September 2026.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Docusign Agreement Manager
Not addressed

Nothing published addresses what happens to the bill when AI-assisted work takes an hour instead of six, which is the floor. The product's center of gravity is the in-house side of the relationship, where there is no client bill: the buyer is a company's legal, procurement, sales or HR function managing its own agreement portfolio, and the published efficiency claims are framed as internal productivity, being an 81 percent faster contract turnaround, a 75 percent productivity boost and legal teams saving 37 percent more time on review and risk evaluation.

Those measure the customer's own time rather than time billed onward. The value is not outside-fee-relationship, however, because the product is also sold to law firms and one appears among the published customer stories, so some buyers will use it on client matters and pass the time or the cost on. For those buyers nothing is published: no per-matter record of AI-assisted work is described, nothing marks an extraction or an agent output as machine-generated for the purposes of a bill or a fee note, and no guidance on fee or disclosure treatment appears anywhere.

Recorded and expressly not credited under R21 and R24, because subscription cost is a different object from AI-assisted work: the Terms publish entitlement units, overage fees billed monthly in arrears and per-unit overage rates, which would let a customer attribute platform cost to a period, and say nothing about a client's invoice. All the higher values being false, this is a gap and the summary carries it.

Pramata
Outside the fee relationship

The buyer is an enterprise legal, procurement or finance function that bills no client, so the product sits outside a lawyer-to-client fee relationship. The published savings framing is operational, fifty percent less time on contract tasks and ten times faster analysis; nothing addresses how AI-assisted work is recorded or disclosed on any bill, and no law firm is a named buyer segment. Releases checked 6 September 2026.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Docusign Agreement Manager
Disclosure pack published

All three artifacts exist, are published and are forwardable, which is this value and the strongest instance of it located in this corpus. The subprocessor list is current and dated 11 August 2026, published both as a web page and as a downloadable document, and itemized per Docusign Service so a firm reads only the IAM section rather than filtering an undifferentiated list. The model provider statement is not merely present but mapped feature by feature under an Artificial Intelligence Suppliers heading: Microsoft Azure OpenAI Service for extractions, agents and AI-assisted review; Azure AI Document Intelligence for extractions and Agreement Desk agents; Google Gemini for extractions, with Model Armor for AI security and content moderation; and DocuSmart trading as Lexion for extractions.

Each carries the countries of service provisioning and a contact address. The third limb, client-facing material a firm can forward, is satisfied in the form R29's IPRally condition specifies: a published Data Protection Attachment which at clause 7.2 incorporates the subprocessor list by reference and describes the notification mechanism, sitting alongside Binding Corporate Rules approved by EU data protection authorities as both processor and controller and the EU Standard Contractual Clauses at Modules 2 and 3.

So a firm answering a client's AI clause can forward a signed-form data instrument, name every model provider touching the client's agreements, say which feature each powers and in which region, and point to an RSS notification feed and an email objection route for changes. Nothing in the set is gated.

Pramata
Not addressed

No sub-processor list, model provider list or forwardable disclosure material was located. The vendor describes a proprietary engine and an interface to Anthropic's Claude Cowork without naming the models behind its own extraction, and no DPA, trust center or security page surfaced in search. Surfaces checked 6 September 2026.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Docusign Agreement Manager
Not addressed

No located public material addresses disclosure of AI involvement in legal work, which is the floor, and the note distinguishes that from the traceability the product genuinely provides. Two features come close and neither is a disclosure instrument. Agents are described as returning answers traceable to cited sources, so a user can see which clause in which agreement supports a given answer; that is provenance for the input, not a record that a machine produced the output.

And built-in activity tracking is published as an audit feature, described as keeping the account audit-ready, which is an access and administration log rather than a record of what the AI did. Neither is presented as something a customer could produce to a third party, and nothing states that either survives export or identifies AI involvement on the face of an extracted provision, a report or an agent-drafted document.

What is absent is everything the higher values describe: no per-matter or per-query record of AI use a customer could produce, no export designed to evidence machine involvement, no certification template, and no guidance on when or how AI assistance should be disclosed. The exposure is real but indirect for this product class: its output is a report, an obligation record or a redline rather than a filing, so the likely forum is a counterparty, an auditor or a regulator rather than a court, and nothing published would let a customer show afterwards which terms in its own agreement record were machine-extracted rather than human-entered.

Pramata
Partial record

Some elements of a verification record are available and no export for a court is described. AI TrueCheck gives each extracted attribute an accuracy score and an audit trail showing whether the human key, the extraction and the validation layer agreed, and the reasoning-log control records the model's step-by-step process; that is a per-attribute record of validation. Nothing states that the record can be exported for a court, and the product's outputs are contract data rather than filings. TrueCheck release and article checked 6 September 2026.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Signals neither addresses in public material
  • Prompt and Output Retention
  • Primary Law Corpus Provenance
  • Good Law Verification
  • Bar Guidance Alignment

Which one fits

Choose Docusign Agreement Manager if

  • You need to tell a client exactly which AI touches its agreements. Docusign's subprocessor list names Azure OpenAI, Azure AI Document Intelligence, Google Gemini with Model Armor, and DocuSmart, maps each to the feature it powers and the regions it runs in, and announces changes through an RSS feed.
  • Your security review wants attestations it can verify itself. Docusign publishes ISO 27001:2022, SOC 1 and SOC 2 Type II, PCI DSS 4.0 and FedRAMP authorization naming IAM, with scope stated per certification and public registry routes to check them.
  • Your agreements already pass through Docusign. Agreement Manager sits in the same platform as eSignature and contract lifecycle management, extracts parties, dates, renewal terms and governing law, tracks renewals and obligations, and names customers such as Catchafire and the Greater Philadelphia YMCA with reported figures.

Choose Pramata if

  • You need to know how accurate each extracted term is. Pramata's AI TrueCheck checks every attribute against a human curated key and a separate AI validation layer, shows a real time accuracy score and audit trail, and routes lower confidence results to a person.
  • You negotiate in Word against your history with a counterparty. Pramata's AI Negotiator flags incoming terms red, yellow or green against your playbook and compares them with your past negotiations with that counterparty.
  • You want contract data inside the AI tools your team already uses. Pramata exposes its contract intelligence through Model Context Protocol connectivity and an extension to Anthropic's Claude Cowork legal plugin, and its design studio lets legal configure playbooks and agents without IT.

In summary

Docusign Agreement Manager

Docusign Agreement Manager is the repository in Docusign's Intelligent Agreement Management platform, from Docusign, Inc. of San Francisco, built on its 2024 acquisition of Lexion. It consolidates executed agreements and uses Docusign Iris to extract parties, dates, financial terms, renewals and governing law, with reports, renewal and obligation tracking, permissions and agents that cite their sources. The AI Legal Index grades it in the top two bands on fourteen of fifteen capability axes, with A grades on security certifications and model supply chain disclosure. It names each AI supplier by feature and region. As of 13 September 2026 the index located no advice line statement, no retention period for AI material and no standalone price.

Source: AI Legal Index, 2026

Pramata

Pramata, headquartered in San Francisco and operating for about twenty years, is an AI contract intelligence platform for enterprise legal, procurement and finance teams that extracts terms, obligations and relationships from executed agreements into a structured repository, validates them through AI TrueCheck, and supports negotiation in Word through AI Negotiator. The AI Legal Index grades it in the top two bands on seven of fifteen capability axes, with an A on AI centrality. It publishes a three stage validation method with per attribute accuracy scores and names McKesson, ICE and AbbVie among its customers. As of 6 September 2026 the index located no customer agreement, security page, model provider or price.

Source: AI Legal Index, 2026

Questions buyers ask

Docusign Agreement Manager vs Pramata: which is better for contract data?

On published evidence Docusign Agreement Manager sits in the top two bands on fourteen of fifteen AI Legal Index capability axes and Pramata on seven of fifteen, mostly because Docusign publishes its AI suppliers, certifications and contract terms. Pramata publishes more about how it validates each extraction, including accuracy scores and human review of uncertain results. Buyers already on Docusign have more to read there.

Which AI models does Docusign Agreement Manager use?

Docusign's subprocessor list, dated 11 August 2026, names Microsoft Azure OpenAI Service and Azure AI Document Intelligence, Google Gemini with Model Armor on Vertex AI, and DocuSmart, its Lexion subsidiary, each mapped to the feature it powers and the countries where it runs. Changes are announced through an RSS feed with an objection route. No model versions are given. Pramata names no model provider. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

Does Docusign train AI on customer agreements?

Its terms route AI services through an AI attachment that may include consent to use customer data to improve its services, including training models, and tell customers how to opt out through AI data control settings. Its AI trust page says data used with consent is aggregated and anonymized first. Pramata publishes no position on training either way. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

How does Pramata check its extraction accuracy?

Pramata's AI TrueCheck, launched in March 2026 for all customers, compares each extracted attribute against a human curated key built from representative documents and a separate AI validation layer, and shows a real time accuracy score with an audit trail. Where the stages disagree, a person reviews the result. Pramata states 99 percent or better accuracy but publishes no test set behind it. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

What do Docusign Agreement Manager and Pramata both leave unpublished?

Any retention period for AI inputs and outputs, and any statement on legal advice. Neither states how long extracted data or AI outputs are kept, and neither says whether its output is legal advice or who should review it, although both are used by business teams alongside lawyers. Neither names bar guidance on AI or describes an export recording what the AI produced. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

Disclosure

Three readings to weigh. Docusign's terms route AI use through an AI attachment that can include consent to train on customer data, switched off through a setting; the attachment itself was not read. Its IAM rate card was not read either, so no figure for Agreement Manager is stated here. For Pramata no customer agreement, security page or pricing page was located on the surfaces searched, so its low grades record what could be read. Its 99 percent accuracy figure has no published test set. Docusign Agreement Manager was verified on 13 September 2026 and Pramata on 6 September 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 24, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746