Docusign CLM vs Ironclad: how they compare in 2026

D
Docusign CLM profile
I
Ironclad profile
Last verifiedOctober 8, 2026

Docusign CLM and Ironclad are both enterprise contract lifecycle platforms sold to legal, procurement and sales teams, with AI review and extraction built in, and both connect to Salesforce and Coupa. The difference is in what each puts in writing. Docusign publishes the documents behind CLM: a service schedule with retention terms and pricing units, a master services agreement that keeps confidentiality breaches outside the liability cap, an AI attachment, and a subprocessor list that ties Azure OpenAI, Azure AI Document Intelligence and Google to each CLM feature. Its government editions are authorized under FedRAMP, GovRAMP and DoD Impact Level 4. Ironclad publishes more about how its AI works: AI Playbooks tie each redline to a clause, and Jurist runs named agents for drafting, review, research and intake. On training they differ by default. Docusign's AI terms allow training on anonymized CLM data unless the customer opts out, while Ironclad trains its own models only where the customer opts in. Neither publishes a price.

At a glance

Category
Docusign CLMContract Review & Drafting
IroncladContract Review & Drafting
Founded
Docusign CLMNot published
Ironclad2014
Headquarters
Docusign CLMSan Francisco, California, United States
IroncladSan Francisco, California, United States
Last verified
Docusign CLMOct 8, 2026
IroncladAug 29, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Docusign CLM
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

Docusign CLM is a workflow and document system at its core: generation from templates, a clause library, a drag and drop workflow designer with more than 100 preconfigured steps for generation, review, approval, signature and storage, and a repository with reporting. That system dates from SpringCM, which Docusign agreed to buy in 2018, before generative AI was part of it. AI now drives several core functions. More than 100 pretrained models extract and report on contract data points and legal topics. AI-Assisted Review flags nonstandard clauses and suggests redlines against a playbook. Generative features summarize agreements, draft clauses on request and answer questions about the repository. Docusign brands the engine Iris and describes it as trained on decades of contract data. Workflows can start from analytics, risk scores and contract content, so extraction feeds routing as well as search.

Ironclad
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models drive a core capability, layered on a product that would work without them as a workflow system. Ironclad's intake, no code Workflow Designer, approvals, routing, signature, repository, analytics and integrations all predate and stand without generative AI, and the vendor sells that workflow layer as its foundation. What the models drive is real and central: AI Playbooks, with each play tied to a clause, do the redlining, and Jurist runs a named family of agents for drafting, editing, review, research, intake and redlining under a Manager Agent, with Conversational Search over the repository. This is an established product with a substantial AI layer rather than one built on AI from the start.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Docusign CLM
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Docusign describes Iris as delivering accurate, secure and trusted agreement intelligence. Its AI Trust page says AI outputs have been tested for accuracy, and that diverse datasets and checks are used to correct skewed outputs before release. No figure, error rate, test set or evaluation method is published for CLM extraction, AI-Assisted Review or agreement summaries. The quantified claims on the review product are time savings, such as 72 to 80 percent saved on contract reviews, with no stated baseline. Section 6.2 of the AI Attachment for Docusign Services, version 8 July 2026, says that given the probabilistic nature of machine learning the AI may produce output that is incorrect, and places review for accuracy on the customer. The product works from the customer's own contracts and clause library rather than from law, and nothing published describes how a summary or an answer links back to the clause it came from.

Ironclad
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is asserted, and the grounding behind it is not documented. Vendor material claims precise redlining, advanced AI, and proprietary legal AI models trained on legal terminology with prompts engineered for legal work. The AI Playbooks give real structure: each play is tied to a clause, and the system proposes varying degrees of revision to match preferred terms with minimal change, so output is anchored to a standard the customer wrote and a reviewer can check. No accuracy figure, hallucination rate, test set, evaluation, or description of the retrieval method or how output links to a source a user can open is published.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Docusign CLM
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Section 6.2 of the AI Attachment makes the customer responsible for reviewing and evaluating AI output, including through human review, for accuracy and suitability. The AI Trust page says the customer has the final say to approve outputs. In the product, AI-Assisted Review suggests edits and flags risky language for a reviewer to accept or reject, and CLM workflows send agreements with nonstandard terms to review under conditional rules the customer sets. Every action sits in an audit trail of who did what and when, with version control across drafts. Workflows can also be triggered automatically by analytics, risk scores and contract content. Nothing published sets out what an AI step may do without a person, at what confidence an extraction is held for review, or what happens after an AI output is found to be wrong.

Ironclad
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

A written commitment that the models work alongside a supervising human, with real and specific review surfaces, short of published thresholds. The vendor states human in the loop governance ensures every agent works transparently, is auditable and controllable, and says plainly that the customer is in charge, with governed and auditable AI review frameworks the customer can review, override and continuously govern across teams and contract types. The control surface is administrative as well as rhetorical: playbook permissions let administrators configure which users and groups may view, create and edit playbooks, and a Manager Agent routes tasks across the agent family so orchestration is visible. Vendor material states the agents automate repetitive lower risk work while strategic negotiation and nuanced risk assessment stay with the lawyer, which is a stated allocation. Not located: the threshold at which an agent stops or escalates, and what the vendor commits to when an output is wrong.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Docusign CLM
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

The CLM page carries four named customer stories, each with figures and a named, titled speaker. T-Mobile Wholesale cut agreement time by 44 percent without adding headcount, with 1.8 times faster cycle time on high value agreements, quoted by Janet Sutherland, Senior Manager of Sales Enablement. Genuine Parts Company runs more than ten use cases across five departments, quoted by Keith McCarraher, Special Projects Manager. Vestwell reports agreement packages built in 5 minutes instead of 75 and 70 percent fewer drop offs, quoted by its COO, Jon Mark. iCIMS reports that 78 percent of its agreements need no legal involvement, quoted by Courtney Dutter, Deputy General Counsel. The page also states a 449 percent return on investment, an 85 percent reduction in errors and 2,200 enterprise CLM customers, without naming the study or the customers behind those figures. No story gives a deployment date or a measurement method.

Ironclad
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Real deployment evidence with substance, short of dated attribution and method. A named customer carries a figure: NEXT Insurance is published as giving legal operations 50 percent of its time back with Jurist. Attributed customer quotes carry before and after numbers, including a first pass redline moving from 30 minutes to a couple of hours down to a solid first draft in minutes, and an MNDA review or custom order form clause drafting moving from an hour to a day down to minutes or seconds. A customer stories section is published. Not located: a dated case study with a stated method a reader could assess, and the identity of the speakers behind several of the quoted figures.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Docusign CLM
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Under the Docusign Master Services Agreement, version 14 November 2022, Customer Data stays owned by the customer (3.1), confidential information may be used only for the purpose given and protected with at least reasonable care (11.1), and liability for a breach of confidentiality sits outside the twelve month fee cap (10.2). The AI Attachment treats AI output as Customer Confidential Information. Training is the other side of it. Section 4.1 of the AI Attachment grants Docusign a perpetual license to use CLM customer data and AI output, once anonymized and aggregated, to train models, and section 4.2 lets the customer switch that off going forward with a toggle in the product. Section 4.3 of the MSA separately lets Docusign use deidentified usage data, including for training. Within a customer account, CLM folder security limits who sees which contracts. Privilege and work product are not addressed in the agreements or on the product pages.

Ironclad
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Substantive published commitments, and the vendor addresses its own training use directly, not only its providers'. External LLM providers are held to strict terms against training and for zero data retention. Any customer data used to train Ironclad's own models is anonymized and aggregated first, and output generated for other customers by models trained on a customer's data will never include that customer's data. Training data is stated to be covered by the same security standards as the rest of the platform. Certification covers the privacy trust category under SOC 2 and includes ISO 27701 for privacy information management. Two gaps remain. Attorney client privilege and work product handling are not addressed directly in located material, and separation between customers, users or matters is not documented on the pages checked.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Docusign CLM
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

Section 6.2 of the AI Attachment states that neither Docusign, the AI Services nor AI output provide the customer with legal advice, that suitability for any purpose is at the customer's sole discretion, and that the customer reviews output for accuracy, including through human review. The statement sits in the contract that governs CLM's AI features rather than in a site footer. CLM is sold to sales, procurement, human resources and customer experience teams as well as legal, and AI-Assisted Review proposes redlines and drafts clauses for any of those users. Nothing published addresses who in a customer reviews an AI redline before it reaches a counterparty, how the product supports a lawyer's competence and supervision duties, or any limit by jurisdiction.

Ironclad
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

The intended audience is broad by design and no position on the advice line is published. Dedicated pages address legal operations and general counsel alongside procurement and IT, and vendor material describes the platform as serving business teams that touch contracts, with the AI proposing redlines and drafting negotiation ready revisions for those users. Searched the site, the product and persona pages, the security page and the support documentation via search and located no statement on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits. The human in the loop governance language is a control statement rather than a professional responsibility position, and the two are not the same thing.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Docusign CLM
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

Docusign publishes AI Trust and AI Innovation Principles pages for Iris, the engine behind CLM's AI features. The AI Trust page lists encryption in transit and at rest, consent based training on aggregated and anonymized data, diverse datasets and checks to correct skewed outputs before deployment, content filtering for harmful outputs, and adoption of frameworks such as the NIST AI framework. Section 6.1 of the AI Attachment adds a warranty that, to Docusign's knowledge, it holds sufficient permissions for the data used to train its own models, defined as customer data authorized for that use, publicly available data and licensed data. No person, committee or team is named as accountable for model behavior, no ISO/IEC 42001 certification appears, and no test results are published, including on whether output differs across contract types, languages or regions. The AI Trust page says broader AI Trust capabilities are available through sales.

Ironclad
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

A published governance framework with real substance, short of testing results, a named owner and any bias disclosure. The vendor describes a mechanism rather than a principles page. It offers governed and auditable AI review frameworks and human in the loop governance, stated as making every agent transparent, auditable and controllable. Customers can review, override and continuously govern agent behavior across teams and contract types, and administrators set permissions for who may view, create and edit the playbooks that drive AI behavior. A chief technology officer is publicly named as owning the AI roadmap. Not located: an AI management certification such as ISO 42001, published testing results before release, a named owner accountable for model governance as distinct from the technology function, and anything on uneven output across matter types, parties or populations.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Docusign CLM
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

The Service Schedule for Docusign CLM, version 15 September 2025, stores documents for the subscription term or until the customer deletes them, and lets an account administrator set a different retention and deletion schedule (3.1). Retrieval is free during the term and available for 90 days after it through professional services, after which Docusign may delete the account and its documents (3.2). The Data Protection Attachment, version 4 September 2024, commits to notice of a data breach without undue delay, with its nature, likely consequences and the measures taken, and to deletion of personal data on request. Docusign's subprocessor list, last updated 18 September 2026, has its own CLM section naming each hosting and AI supplier with locations, with updates through an RSS feed and objections by email. Agreement contents are encrypted at rest, and folder security controls access inside an account. Section 4.1 of the AI Attachment lets Docusign keep training data derived from customer content after termination with no duty to delete it, and nothing states what Microsoft or Google keep from prompts.

Ironclad
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Substantive published policy covering most of the ground. Certification breadth is the strongest element and is stated precisely. Routine audits produce third party SOC 1 and SOC 2 Type II reports certified against security, availability, confidentiality and privacy, alongside ISO 27001, 27701, 27017 and 27018, a dedicated GDPR program, and Trusted Cloud Provider status as a Cloud Security Alliance member. Data centers run on public cloud providers that the vendor says are themselves certified under SOC 2, ISO 27001 and PCI DSS, across multiple regions. Zero data retention is enforced at the external model layer. Not located: a stated retention period or deletion control for customer contracts and prompts in Ironclad's own systems, a named subprocessor list, and an incident or breach notification practice.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Docusign CLM
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

The Master Services Agreement, version 14 November 2022, warrants that the services perform substantially as documented, with repair, replacement, or termination and a prorated refund as the remedy (8.1). Docusign indemnifies the customer against third party claims arising from its breach of confidentiality and from intellectual property infringement (9.1). Liability is capped at fees paid for the service in the twelve months before the first event, with no cap on indemnity obligations, confidentiality breaches, gross negligence or willful misconduct (10.2). The AI Attachment narrows this for AI. Section 6.2 disclaims all warranties on AI output, says Docusign is not liable for output to the extent it includes customer data, and removes the indemnity where a claim arises from the customer's data, its own modifications or output it knew to infringe. Nothing in the agreements covers loss from an extraction or redline that is wrong, and no insurance is published.

Ironclad
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

No published indemnity, liability cap, carve out, warranty on output or insurance position is published, and no customer agreement or master services agreement is published as published on the property.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Docusign CLM
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Docusign names CLM integrations with Salesforce, for generating documents and running workflows across Salesforce Customer 360; SAP Ariba, for creating supplier agreements, ingesting third party paper and tracking workflow tasks from Ariba; and Coupa, with contracts created or updated in either system. Slack carries review notifications and actions, comments sync between Microsoft Word, Google Docs and CLM, AI-Assisted Review runs inside Word, and Docusign eSignature is built in. The CLM API in the Docusign Developer Center offers object, task and content APIs for Salesforce and custom applications, and Docusign Monitor, sold as an extra on top of CLM, reports CLM event activity, including through Splunk. Docusign University runs courses on building custom CLM integrations. No document management system used by law firms, such as iManage or NetDocuments, is named, and the product pages do not say which fields move in which direction for each connector.

Ironclad
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Real integrations exist and are documented, and the vendor treats them as a primary differentiator. Named specifically: Salesforce, described by the vendor as the number one Salesforce integration in the market, and Coupa, with a dedicated integrations page and a stated claim of the deepest integrations in the market. The workflow layer is itself integration: teams create, manage and collaborate on contracts from inside the systems they already use rather than switching into the CLM. Orientation is toward enterprise commercial systems rather than legal document management, which fits a CLM buyer. Not located: legal specific document management connectors such as iManage or NetDocuments, and per integration documentation describing what moves in which direction and what an administrator configures.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Docusign CLM
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

Docusign's subprocessor list places CLM hosting with Equinix in the Netherlands, the United Kingdom and the United States, Switch in the United States, and Microsoft Azure in the United States, Australia, Canada, the European Union and Japan, each by where the service is provisioned. AI processing is listed separately. Azure AI services for review, summaries and extraction run in the United States, Canada, the European Union, Australia and Japan, and Google processing for the CLM Analyzer service runs in Belgium, Canada, Germany, Switzerland, the United Kingdom and the United States. Government editions are separate deployments. The CLM Service Schedule keeps government customer data inside Docusign's FedRAMP Moderate boundary unless a connector exports it (5.2), and the DoD Impact Level 4 edition requires a connection to NIPRnet through a boundary cloud access point (5.3). Nothing describes the tenancy model for commercial customers, and no on premises option is offered.

Ironclad
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Residency is offered without the processing location being addressed. The vendor says it uses multiple data center regions from its cloud providers specifically to meet data residency requirements, a real published residency position. The cloud providers are described only as public cloud vendors and are not named. No available regions are listed, no customer selectable region is stated, no tenancy model is given, and nothing separates where processing happens from where data is stored.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Docusign CLM
AA on Security Certifications and Trust CenterCurrent independent attestation with named scope, reachable without a sales call: a trust center carrying reports, dates and the standards actually covered.

Docusign's certifications page lists ISO/IEC 27001:2022 certification enterprise wide, ISO/IEC 27017:2015 and 27018:2019, annual SOC 1 Type II and SOC 2 Type II audits of all production operations including data centers, and PCI DSS 4.0. Three authorizations name CLM directly: FedRAMP agency authorization, GovRAMP authorization and a Defense Information Systems Agency Impact Level 4 provisional authorization. Reports and certificates are available in the Docusign Trust Portal, and the annual CSA STAR CAIQ is public on the CSA registry. Docusign also completes the Shared Assessments SIG, S&P Global KY3P and ProcessUnity assessments each year, and USDM assesses its 21 CFR Part 11 module annually. C5 Type II covers the eSignature product only, so it does not extend to CLM.

Ironclad
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Certification is real and stated with correct scope language, short of accessible evidence. The vendor names SOC 1 and SOC 2 Type II reports from routine third party audits and names the trust categories certified: security, availability, confidentiality and privacy. ISO 27001, 27701, 27017 and 27018 are all named, along with Trusted Cloud Provider status from the Cloud Security Alliance. The vendor says its underlying cloud providers are themselves SOC 2, ISO 27001 and PCI DSS certified. What is not published is a route to the evidence: no audit coverage period, report date or named auditing firm, and no trust portal or published request flow for the reports.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Docusign CLM
AA on Model Supply Chain DisclosureThe models underneath are named, their providers identified, where they run is stated, and the vendor commits to notifying customers when any of that changes.

The CLM section of Docusign's subprocessor list, last updated 18 September 2026, names the AI suppliers feature by feature. Microsoft's Azure OpenAI Service runs AI-Assisted Review in CLM, CLM+ and the AI Extension for CLM, and agreement summaries in the AI Extension and CLM+. Azure AI Document Intelligence runs AI extraction in CLM Essentials, CLM and the AI Extension. Google processes the CLM Analyzer service. DocuSmart Inc., trading as Lexion and wholly owned by Docusign, runs the legacy version of AI-Assisted Review for select US customers. Each entry gives the countries where it is provisioned. Updates are posted to an RSS feed customers can subscribe to, and a customer may object to a new subprocessor by email on grounds set in Docusign's Processor Policy. No model name or version is given for any provider, and section 6.1 of the AI Attachment disclaims responsibility for the data third party providers used to train their own models.

Ironclad
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The vendor refers to models without identifying what sits underneath. It acknowledges two layers and distinguishes them clearly: proprietary legal AI models built by Ironclad with prompts engineered for legal work, and external LLM providers bound by terms against training and for zero data retention. That tells a buyer the shape of the chain and the terms binding it, but not who is in it. No named external model provider, statement of where models run, subprocessor list or commitment to notify customers of supply chain changes is published.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Docusign CLM
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

Docusign publishes no CLM price. Every call to action on the CLM page, Get Started included, goes to Contact Sales, and the site's plans and pricing links lead to eSignature and IAM plans, none of which includes CLM. The Service Schedule for Docusign CLM publishes the charging structure. CLM is a prepaid subscription measured by a seat allowance, a document count or both, depending on the edition (4). Extra seats are charged pro rata at list price for the rest of the term, and documents over the count are charged per document at list price, invoiced monthly in arrears (4.3). Seats can be reassigned between people without penalty, and documents exported and then deleted during the term still count. Retrieval after the term ends is a paid professional services engagement. Editions named across Docusign's documents include CLM Essentials, CLM, CLM+ and the AI Extension for CLM, alongside government and DoD Impact Level 4 editions.

Ironclad
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing page is published on the property, no rate is published, no unit of charge is stated and no tier structure appears. Every commercial path located terminates in a demo request. No free trial or self serve entry point is published. Consistent with third party coverage describing implementation cost as dependent on the scope of the CLM deployment rather than on a published rate.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Docusign CLM
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Docusign sells CLM to legal, sales, procurement, human resources and customer experience teams, and its named stories come from wholesale telecom, auto parts distribution, retirement plan administration and recruiting software. Government use is documented through CLM Government Products authorized under FedRAMP and GovRAMP and a DoD Impact Level 4 edition. Docusign says 2,200 enterprises use CLM for contract management, and integrations with SAP Ariba and Coupa point at procurement as well as sales contracting. Coverage is framed by department and industry rather than by contract type or area of law. Nothing published names a minimum customer size, a law firm use, or contract types the AI handles poorly. Docusign's IAM plans page states AI extraction in English, French and German, and the CLM pages give no language list.

Ironclad
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Segment coverage is described with substance, short of the boundaries. Four buyer personas have their own published positioning: legal operations, general counsel, procurement and IT, and the vendor also addresses business teams beyond legal that handle contracts. Enterprise and global business teams are the stated target, and at least one industry, manufacturing, has dedicated positioning around leakage and contract performance. Practice scope is clear and consistent: contracting end to end from intake to after signature, with no claim to litigation or research capability. Not located: a statement of which organization sizes or contract types the platform is not built for, and a full list of industries or practice areas.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Docusign CLM
Opt out

Section 4.1 of the AI Attachment for Docusign Services, version 8 July 2026, grants Docusign a perpetual license to use customer data and AI output, after anonymizing and aggregating it, to train models and improve its services generally. The attachment's applicability table says customers on a Master Services Agreement consent to that training for Docusign CLM. Section 4.2 lets the customer opt out at any time with a toggle in the product, on a going forward basis, and Docusign keeps the training data created before the opt out with no duty to delete it.

The AI Trust page describes the same program as consent based. Customers whose subscription began before 8 July 2026 are pointed to earlier versions of the terms.

Ironclad
Opt in

Training is opt in, and the vendor argues for it openly. Customers may opt into letting Ironclad train its own models on their contracting data. Any customer data used this way is anonymized and aggregated first, output generated for other customers by models trained on that data will never include the contributing customer's data, and the vendor says the customer stays in control with data kept confidential. Separately, strict terms against training and for zero data retention are enforced with external LLM providers, so the third party layer is barred while the vendor's own layer is permitted with consent.

Training happens only where the customer has enabled it. Not located as of 29 Aug 2026: where the opt in is exercised, whether it sits in the agreement or a product setting, and whether it can be withdrawn.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Docusign CLM
Customer controlled, no zero option

Section 3.1 of the Service Schedule for Docusign CLM, version 15 September 2025, keeps each stored document, including the customer data in it, for the subscription term or until the customer deletes it, and lets the account administrator set a different retention and deletion schedule. After the term, documents can be retrieved for 90 days through professional services, and Docusign may then delete them (3.2). The schedule covers stored documents rather than prompts as such.

AI output is Customer Confidential Information under the AI Attachment, which also lets Docusign keep anonymized training data derived from content with no duty to delete it. What the Azure and Google model services keep from a prompt is not stated.

Ironclad
Disclosed without a period

Retention is answered at the external model layer and unaddressed for the platform itself. The vendor states it enforces zero data retention with external LLM providers, so prompts and completions are not persisted by those providers. Searched the security page, the platform pages, the article library and the support documentation via search on 29 Aug 2026 and located no retention period for contracts, prompts or outputs held in Ironclad's own repository, no customer control over that window, and no deletion commitment.

That gap is material here because the product is a system of record designed to hold every executed agreement indefinitely, so the retention question is the core of what the customer is buying.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Docusign CLM
Own model, documented

CLM has its own permission model built on folders. A Docusign employee's guide on the Docusign Community sets out six levels, from No Access, the default for all content, through View, View and Create, View and Edit, and View, Edit and Delete, to full control with Set Access. Security can be set for a user, a permission profile or a user group, and folders inherit their parent's security unless set explicitly. CLM administrators can see all content whatever the folder settings.

The CLM page adds granular permissions controls and an audit trail of who did what and when. Nothing published says how AI review, summaries or search apply folder permissions when they run.

Ironclad
Own model, documented

The product maintains its own documented permission model rather than inheriting one from a document management system. Published support documentation states that administrators can configure Ironclad users and groups to permit or restrict which users may view, create and edit AI Playbooks, so the standards driving AI behavior are themselves access controlled, and the workflow layer routes and assigns contracts across named reviewers.

That is a documented internal permission model. What was not located as of 29 Aug 2026 is segregation of the contract repository itself between users or matters, any ethical wall concept, and any legal document management integration whose permissions retrieval could inherit at query time. Noted for context: the buyer here is an in house or business team rather than a firm carrying conflicts obligations, so the question reads differently than it would for a firm facing product.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Docusign CLM
Notice committed

Section 11.2 of the Master Services Agreement, version 14 November 2022, requires prompt written notice before a compelled disclosure of confidential information, unless legal process forbids it, and cooperation in seeking a protective order. The Data Protection Attachment adds prompt notice of any government request about personal data. Docusign's law enforcement page says it notifies customers when their data is subject to disclosure, withholds notice only under a signed nondisclosure order or a statute that bars it, and cannot decrypt agreement contents at rest.

Docusign prepares an annual transparency report on requests and makes it available to data protection authorities on request; it is not published. Section 2(d) of the CLM Service Schedule says Docusign is not responsible for producing customer documents to any third party.

Ironclad
Not addressed

Searched the security page, the site navigation, the article library and the support documentation via search on 29 Aug 2026. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. No published customer agreement or data processing agreement was located on the property either, so the search covered the public pages rather than the contract documents.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Docusign CLM
Sources named, basis unstated

CLM works from the customer's own contracts, templates and clause library, and does not retrieve case law or legislation. For the models behind it, Docusign describes Iris as trained on decades of contract data. Section 6.1 of the AI Attachment names the classes of training data for Docusign's own models, customer data authorized for training, publicly available data and data licensed from third parties, and warrants that to its knowledge Docusign holds sufficient permissions for them. It names no specific source or license and excludes the data third party providers used for their own models.

Ironclad
Not addressed

No primary law corpus is identified because the product does not hold one. Retrieval runs against the customer's own contract repository and their own AI Playbooks, and the vendor's proprietary models are described as trained on legal terminology and contract management architecture with legal engineered prompts, plus, where customers opt in, anonymized and aggregated customer contracting data. That last element is the closest thing to a vendor corpus and its provenance is disclosed in principle, being customer contributed under consent, though no scale figure, license basis or update cadence is published for it. Searched the site, the Ironclad AI page and the article library on 29 Aug 2026.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Docusign CLM
Not addressed

Docusign CLM manages a customer's own agreements and does not cite case law or legislation, so a citator is not part of the product. Nothing on the CLM page, the AI-Assisted Review page or the AI Trust page addresses checking authority for later history. The nearest question for this product is whether extracted terms and clause library positions stay current when an agreement is amended or a policy changes, and nothing published describes how CLM detects that.

Ironclad
Not addressed

Searched the site, the product pages and the support documentation via search on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator license was located. Noted for context: this is a contract lifecycle platform grounded in the customer's own playbooks and repository, with no case law research surface, so a citator is outside its design entirely.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Docusign CLM
Not addressed

No path for declining to answer is documented for CLM's AI features, and no confidence or grounding score is published for extraction, review or summaries. Section 6.2 of the AI Attachment warns that AI output may be incorrect or otherwise undesirable and makes the customer responsible for reviewing it, and the AI Trust page describes content filtering for harmful outputs. Neither says what AI-Assisted Review or the question and answer feature does when a playbook or the repository does not cover what is asked, or how a doubtful extraction is marked before it feeds a report, a renewal alert or a workflow rule.

Ironclad
Not addressed

Searched the site, the Ironclad AI and Jurist pages, the agent launch material and the support documentation via search on 29 Aug 2026. No published material describes what the product does when it cannot ground an answer, and no explicit no answer path or confidence signal exposed to the user was located. The Review Agent is documented as identifying missing clauses and compliance gaps, which is flagging what is absent from a contract rather than the system declining to answer, and the two were not conflated.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

Docusign CLM
None located

The AI Hallucination Cases database maintained by Damien Charlotin, which records court decisions worldwide that address hallucinated AI content and the tool involved where known, has no entry naming Docusign, Docusign CLM, Iris, SpringCM or Lexion, in the tool field or anywhere in the case text. This is a statement about the public record rather than a finding about the product, and it covers fabricated content only. CLM manages commercial agreements rather than producing court filings, so its output does not ordinarily reach a brief.

Ironclad
None located

No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one.

This is a statement about the public record on the date shown and not a clearance. Note that this is a contract lifecycle product with no case law research surface, so its output is very unlikely to reach a court filing as cited authority.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Docusign CLM
Generic reference

Section 6.2 of the AI Attachment for Docusign Services, which governs CLM's AI features, states that neither Docusign, the AI Services nor AI output provide the customer with legal advice, and makes the customer responsible for reviewing output for accuracy and suitability, including through human review. No bar opinion, ethics rule or professional conduct guidance is named on the CLM page, the AI-Assisted Review page, the AI Trust page or in the agreements.

Docusign's compliance work covers data, security and sector regimes, including ISO, SOC, PCI DSS, FedRAMP, GovRAMP, DoD Impact Level 4, HIPAA and 21 CFR Part 11, which bind Docusign as a provider rather than a lawyer using the product.

Ironclad
Not addressed

Searched the site, the article library, the persona pages and the community and resources sections via search on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512 and state bar guidance. The vendor publishes substantial material on AI governance, auditability and human in the loop control, which addresses how its own system is controlled rather than the professional responsibility obligations its legal buyers are bound by.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Docusign CLM
Outside the fee relationship

CLM is bought by enterprise legal, sales, procurement, human resources and customer experience teams to run their own contracting, and the named customers are companies such as T-Mobile Wholesale, Genuine Parts Company, Vestwell and iCIMS rather than law firms. No client bill sits in the loop. Docusign's claims are aimed at the buyer's own cost and time: an 83 percent boost in speed and efficiency, a 449 percent return on investment, a 90 percent cut in time to generate a sales contract and 72 to 80 percent saved on contract reviews. Nothing published addresses fee treatment of AI assisted work for a firm that bills a client.

Ironclad
Savings claims only

Savings are claimed and quantified, with nothing published on the client's side. Published figures include a named customer recovering 50 percent of legal operations time, first pass redlines dropping from up to a couple of hours to minutes, and MNDA review dropping from up to a day to minutes or seconds, with framing about scaling review without adding headcount. Searched the site, the product pages, the article library and the support documentation on 29 Aug 2026.

No per matter record of work done with AI for fee purposes and no guidance on billing, fees or client disclosure was located. The buyer is an in house or business team that does not bill a client by the hour, so the question applies differently here.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Docusign CLM
Disclosure pack published

Docusign's subprocessor list, last updated 18 September 2026, is published as a web page and a download with a separate section for CLM. It names each hosting supplier and each AI supplier against the feature it powers, with countries and a contact address, and changes go to an RSS feed with an email objection route. The Data Protection Attachment, the AI Attachment, the Master Services Agreement and the CLM Service Schedule are all published without a login, and the certifications page and the public CSA STAR CAIQ cover security.

A customer answering its own client's questions about AI vendors can forward these documents and name every model provider that touches CLM content.

Ironclad
Not addressed

Substantial certification material is published openly and can be reached without a sales conversation. It covers SOC 1 and SOC 2 Type II with the trust categories named, ISO 27001, 27701, 27017 and 27018, a GDPR program and Cloud Security Alliance Trusted Cloud Provider status. What a client's AI clause asks for was not located as of 29 Aug 2026. There is no subprocessor list, no statement of which model providers see customer content, no published data processing agreement, and no consent or notification pack for clients.

The vendor says its external LLM providers are bound by terms against training and for zero data retention without naming them, which describes the terms rather than disclosing the chain.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Docusign CLM
Partial record

CLM keeps an audit trail of who did what and when and detailed version control across drafts, so the history of a contract can be reconstructed. Nothing published says whether an AI-Assisted Review suggestion, an AI drafted clause or an AI extraction is marked as machine generated in that history, or whether the audit trail records which model produced it. No export built for disclosing AI involvement, and no disclosure template, is published.

CLM output is a contract, a report or an obligation record rather than a court filing, so the likely audience for such a record is a counterparty, an auditor or a regulator.

Ironclad
Partial record

Some elements of a record are available, and the auditability language is specific. The vendor publishes governed and auditable AI review frameworks with human review, saying customers get transparent, auditable AI behavior they can review, override and continuously govern across teams and contract types. The workflow layer records routing, assignment and approvals for each contract. Two elements are missing. No export per document covering the model used, sources retrieved and human verification was located, and no model is named in published material, so the model used could not be stated.

This is a contracting platform rather than a litigation product, so a court order on AI disclosure is unlikely to reach its output.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Signals neither addresses in public material
  • Good Law Verification
  • Refusal and Uncertainty Behavior

Which one fits

Choose Docusign CLM if

  • You want the contract terms before the demo. Docusign publishes the CLM service schedule, the master services agreement, the data protection attachment and the AI attachment, including retention of documents for the term with a 90 day retrieval window afterward. The master services agreement keeps confidentiality breaches outside the liability cap.
  • A client or regulator asks which AI providers touch your contracts. Docusign's subprocessor list names Azure OpenAI for AI-Assisted Review and summaries, Azure AI Document Intelligence for extraction and Google for the Analyzer service, each with the countries it runs in. Changes go to an RSS feed with an email objection route.
  • You need contract management for government or defense work. Docusign CLM has government editions inside its FedRAMP Moderate boundary and a DoD Impact Level 4 edition, and the FedRAMP, GovRAMP and Impact Level 4 authorizations name CLM. Docusign also publishes its CSA STAR CAIQ and runs annual SOC 1 and SOC 2 Type II audits.

Choose Ironclad if

  • You want agents across the whole contract. Ironclad's Jurist runs Manager, Drafting, Editing, Review, Research, Intake and Redlining agents, with Conversational Search over the repository. AI Playbooks tie each redline to a clause, and administrators control who may view, create and edit the playbooks.
  • You want training to be off unless you choose it. Ironclad trains its own models on customer data only where the customer opts in, anonymizes and aggregates it first, and holds external model providers to no training and zero data retention. Output generated for other customers never includes the contributing customer's data.
  • Your privacy team wants an ISO 27701 certificate. Ironclad names ISO 27701 for privacy information management alongside ISO 27001, 27017 and 27018, and SOC 2 Type II reports that include the privacy category. It says its public cloud providers are certified under SOC 2, ISO 27001 and PCI DSS.

In summary

Docusign CLM

Docusign CLM is Docusign's enterprise contract lifecycle product, covering generation from templates and Salesforce data, a clause library, workflows built from more than 100 preconfigured steps, negotiation, eSignature and a repository with obligation reporting. Its AI, branded Iris, reviews agreements against playbooks, extracts data points with more than 100 pretrained models and summarizes agreements. According to the AI Legal Index, its most detailed published material is its paperwork and supply chain: a CLM service schedule with retention terms, government authorizations that name CLM, and a subprocessor list that ties each AI supplier to a CLM feature. Its AI attachment licenses training on anonymized customer data unless the customer opts out, and no price or accuracy measure is published.

Source: AI Legal Index, 2026

Ironclad

Ironclad is an enterprise contract lifecycle management platform covering intake, contract creation, no code workflow automation, approvals, negotiation, signature, repository and analytics, sold to legal, legal operations, procurement, sales and IT teams. AI Playbooks drive redlining with each play tied to a clause, and Jurist runs named agents for drafting, editing, review, research, intake and redlining. According to the AI Legal Index, Ironclad sets out its training terms: its own models train on customer data only where the customer opts in, after anonymization and aggregation, and external model providers are bound against training and to zero data retention. It publishes no customer agreement, subprocessor list or price.

Source: AI Legal Index, 2026

Questions buyers ask

Docusign CLM vs Ironclad: which is better for enterprise contract management?

Docusign CLM suits an enterprise that wants published agreements, a named AI supply chain and government editions. Ironclad suits one that wants agents across drafting, review and intake and training kept off unless it opts in. Both connect to Salesforce and Coupa, and neither publishes a price. Docusign's agreements set out retention, a 90 day retrieval window and AI terms, while Ironclad sets out its certifications and training terms on its own pages. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Do Docusign CLM and Ironclad train AI on customer contracts?

Docusign's AI attachment licenses training on anonymized, aggregated CLM customer data unless the customer opts out with a toggle in the product, and Docusign keeps training data created before an opt out; its AI Trust page describes the program as consent based. Ironclad trains its own models only where the customer opts in, binds its external model providers against training, and says output for other customers never includes a contributing customer's data. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Which AI models do Docusign CLM and Ironclad use?

Docusign names Microsoft's Azure OpenAI Service, Azure AI Document Intelligence and Google against specific CLM features, without model versions, and lists the countries where each runs, with an RSS feed for changes. Its AI Attachment disclaims responsibility for the data those providers used to train their own models. Ironclad describes proprietary legal AI models plus external model providers it does not name. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Is pricing published for Docusign CLM or Ironclad?

No figure is published for either. Docusign's CLM service schedule sets out the charging units, a seat allowance and a document count, charges extra seats at list price for the rest of the term, invoices extra documents monthly, and makes retrieval after the term a paid professional services engagement. Ironclad publishes no unit or tier structure. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

What do Docusign CLM and Ironclad both leave unpublished?

Neither publishes a price, an accuracy measure for AI review or extraction, a model version, or anything on legal privilege and work product. Docusign publishes its customer agreements and its subprocessor list, while Ironclad publishes neither, so its liability terms, indemnities and data processing commitments are not public. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Disclosure

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything on it comes from public material on the dates shown. How the index grades.

This page covers Docusign CLM, which runs under its own service schedule, not Docusign Agreement Manager. Docusign's AI attachment, version 8 July 2026, treats CLM customers on a master services agreement as consenting to training on anonymized, aggregated data unless they opt out, and customers who subscribed earlier are pointed to earlier terms. Ironclad publishes no customer agreement and names no external model provider. Neither vendor reviewed this page.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
October 8, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746