Docusign CLM vs Leah: how they compare in 2026
Docusign CLM and Leah run the same lifecycle, from drafting to repository, and Leah even signs through Docusign. They part on what the AI is for. Docusign CLM puts its Iris AI inside a workflow system. It reviews against playbooks, extracts data points and summarizes agreements, and a person accepts or rejects each suggestion. Leah puts agents to work across contracting, procurement and finance under a governance loop the customer configures, logging every action. Docusign publishes more of the paperwork around the AI. Its subprocessor list ties Azure OpenAI and Google to specific features, with countries. Its FedRAMP, GovRAMP and DoD Impact Level 4 authorizations name the product, and its AI terms say output is not legal advice. Leah names its model providers too, but not by feature, and names no hosting region. On training they differ by default. Docusign trains on anonymized customer data unless the customer opts out, while Leah says customer contracts never train models. Docusign also publishes how it charges, by seats and documents.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The core of CLM is a workflow and document system. It generates contracts from templates, keeps a clause library, and stores agreements in a repository with reporting. A drag and drop workflow designer offers more than 100 preconfigured steps for generation, review, approval, signature and storage. That system dates from SpringCM, which Docusign agreed to buy in 2018, before generative AI was part of it. AI now drives several core functions. More than 100 pretrained models extract and report on contract data points and legal topics. AI-Assisted Review flags nonstandard clauses and suggests redlines against a playbook. Generative features summarize agreements, draft clauses on request and answer questions about the repository. Docusign brands the engine Iris and describes it as trained on decades of contract data. Workflows can start from analytics, risk scores and contract content, so extracted data drives routing as well as lookups in the repository.
Leah sells AI agents and an orchestration layer that sit on top of a contract lifecycle platform, and that platform works without them. The vendor describes it the other way round. It says other vendors bolted AI onto systems built for manual workflows, while Leah was designed from scratch with orchestration as the foundation. ContractPod Technologies has sold contract lifecycle management since 2012. Leah launched in March 2023 as an AI services hub within that platform, went standalone in May 2023, and Leah Intelligence followed in October 2024. Without the agents, the product is still a working CLM with guided intake, approval routing, DocuSign and Adobe Sign execution and a contract repository. That CLM has its own market and its own Gartner category placement. The orchestration layer on top is model driven.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Docusign describes Iris as delivering accurate, secure and trusted agreement intelligence. Its AI Trust page says AI outputs have been tested for accuracy, and that diverse datasets and checks correct skewed outputs before release. Docusign publishes no figure, error rate, test set or evaluation method for CLM extraction, AI-Assisted Review or agreement summaries. The numbers it gives for the review product are time savings, such as 72 to 80 percent saved on contract reviews, with no stated baseline. Section 6.2 of the AI Attachment for Docusign Services, version 8 July 2026, warns that the AI may produce incorrect output, given the probabilistic nature of machine learning. The same section places review for accuracy on the customer. CLM works from the customer's own contracts and clause library rather than from law. Docusign does not describe how a summary or an answer links back to the clause it came from.
Leah returns to accuracy repeatedly in its materials, and the AI governance page says every action is measured against benchmarks for accuracy, bias and outcome. Neither that page nor the home page publishes a result from that measurement. They give no accuracy figure, no error or hallucination rate, no description of any benchmark or test set and no published evaluation. The product material describes a legal helpdesk that answers contract questions with sources attached, so a user can in principle check an answer against its source. Neither page says what the system does when the customer's own contracts do not support a position.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
AI-Assisted Review suggests edits and flags risky language for a reviewer to accept or reject. CLM workflows send agreements with nonstandard terms to review under conditional rules the customer sets, and they can also be triggered automatically by analytics, risk scores and contract content. Every action sits in an audit trail of who did what and when, with version control across drafts. Section 6.2 of the AI Attachment makes the customer responsible for reviewing and evaluating AI output for accuracy and suitability, including through human review. The AI Trust page says the customer has the final say to approve outputs. Docusign does not set out what an AI step may do without a person, at what confidence an extraction is held for review, or what happens after an AI output is found to be wrong.
Leah's dedicated AI governance page sets out a three stage control loop. In the first stage, policy in, the customer defines which agents may act, on which data, within which thresholds and where escalation is required. Those policies are held as configuration rather than code. In the second, execution governed, every agent action runs through those policies in real time. Approvals, escalations and rejections are applied automatically, and the orchestrator enforces guardrails at each step. In the third, audit out, every decision is logged with the rationale, what the agent did, why, under which policy, on what data and to what outcome. The records are described as tamper resistant and immutable. The loop sets the thresholds, the review points and the route back to human judgment. Leah's home page puts the position in one line, that the workflow runs itself while the judgment stays human. The page does not say what happens after an output is found to be wrong. Default modes are not described, because the customer configures the guardrails rather than receiving them preset.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
The CLM page carries four customer stories, each naming the customer, giving figures and quoting a named, titled speaker. T-Mobile Wholesale cut agreement time by 44 percent without adding headcount, with 1.8 times faster cycle time on high value agreements, says Janet Sutherland, Senior Manager of Sales Enablement. Genuine Parts Company runs more than ten use cases across five departments, quoted by Keith McCarraher, Special Projects Manager. Vestwell reports agreement packages built in 5 minutes instead of 75 and 70 percent fewer drop offs, quoted by its COO, Jon Mark. At iCIMS, 78 percent of the company's agreements need no legal involvement, according to Courtney Dutter, Deputy General Counsel. The page also states a 449 percent return on investment, an 85 percent reduction in errors and 2,200 enterprise CLM customers, without naming the study or the customers behind those figures. No story gives a deployment date or a measurement method.
Leah publishes qualitative quotes from four named people. Noelle Perkins is EVP and Chief Legal Officer at Cushman and Wakefield, and Lidia Kamleh is Chief Legal Officer at Dubai Future Foundation. Frances Bain-Cumberbatch is Chief Legal and External Affairs Officer at Ansa McAL, and Zillia Knight is Senior Legal Officer at Terumo Europe. Three results are published with the customer unnamed. A major American logistics company cut contract review time by 91 percent. A global manufacturer protected more than $18 million of revenue, and an American retail REIT tracked more than $2 million of savings. About 54 enterprise logos appear, including Philips, MUFG, Sandoz, Pernod Ricard, Alaska Airlines and Wood PLC. PwC and KPMG appear among them. PwC entered a commercial alliance in March 2024, and Epiq resells Leah in its Service Cloud. Integreon is quoted as an early adopter that resells it, and Pinsent Masons adopted it for managed legal services in July 2025. Partners and customers are shown together without distinction, and the Chief Product Officer of Execo, another services partner, is among the testimonials.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The Docusign Master Services Agreement, version 14 November 2022, keeps Customer Data owned by the customer (3.1). Confidential information may be used only for the purpose given and must be protected with at least reasonable care (11.1). Liability for a breach of confidentiality sits outside the twelve month fee cap (10.2). The AI Attachment treats AI output as Customer Confidential Information. Section 4.1 of the AI Attachment grants Docusign a perpetual license to use CLM customer data and AI output, once anonymized and aggregated, to train models. Section 4.2 lets the customer switch that off going forward with a toggle in the product. Section 4.3 of the MSA separately lets Docusign use deidentified usage data, including for training. Within a customer account, CLM folder security limits who sees which contracts. The agreements and the product pages do not address privilege or work product.
Leah says customer contract data is never used to train models. The AI governance page treats data leaking into models the customer does not own as a failure it engineered out. It says zero data retention is the only acceptable answer, and that Leah enforces zero retention with OpenAI and Anthropic so they process data but never store it. Encryption is AES-256 at rest and TLS in transit, with keys in Azure Key Vault, rotated and reachable only through controlled service accounts. Role based access control is said to apply at every layer, and single tenant deployment is offered for customers with strict isolation needs. Leah sells to Fortune 500 legal departments, and none of this material addresses privilege or work product.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
Section 6.2 of the AI Attachment, the contract that governs CLM's AI features, states that neither Docusign, the AI Services nor AI output provide the customer with legal advice. The same section leaves suitability for any purpose to the customer's sole discretion and has the customer review output for accuracy, including through human review. CLM is sold to sales, procurement, human resources and customer experience teams as well as legal. AI-Assisted Review proposes redlines and drafts clauses for any of those users. Docusign does not say who in a customer reviews an AI redline before it reaches a counterparty, how the product supports a lawyer's competence and supervision duties, or whether any limit applies by jurisdiction.
Leah publishes nothing on the line between a tool and legal advice. Its site carries no disclaimer of any kind and no ethics or professional responsibility page, and it names no bar or ethics guidance, including ABA Formal Opinion 512. The platform is sold to run legal work end to end across legal, procurement and finance teams. In the vendor's own framing, agents carry out commercial work in several steps without routing every decision through a person.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Docusign publishes AI Trust and AI Innovation Principles pages for Iris, the engine behind CLM's AI features. The AI Trust page lists encryption in transit and at rest, consent based training on aggregated and anonymized data, and content filtering for harmful outputs. It also describes diverse datasets and checks that correct skewed outputs before deployment, and adoption of frameworks such as the NIST AI framework. Section 6.1 of the AI Attachment warrants that, to Docusign's knowledge, it holds sufficient permissions for the data used to train its own models. That data is defined as customer data authorized for that use, publicly available data and licensed data. Docusign names no person, committee or team as accountable for model behavior and lists no ISO/IEC 42001 certification. It publishes no test results, including on whether output differs across contract types, languages or regions. The AI Trust page says broader AI Trust capabilities are available through sales.
A dedicated AI governance page names six failure modes the vendor says it engineered out. They include black box decisions that cannot be defended to a regulator or board, and compliance frameworks retrofitted after the fact. Against them the page sets three pillars and a loop of policy, execution and audit. Each action is logged with its rationale and governing policy, in records described as tamper resistant and immutable. The page also says every action is measured against benchmarks for accuracy, bias and outcome, and that accountability is structural rather than aspirational. It names no person or role accountable for model behavior and describes no testing before release. It gives no benchmark method or schedule and discloses no bias measurement result.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Under section 3.1 of the Service Schedule for Docusign CLM, version 15 September 2025, documents are stored for the subscription term or until the customer deletes them. An account administrator can set a different retention and deletion schedule. Retrieval is free during the term and available for 90 days after it through professional services, after which Docusign may delete the account and its documents (3.2). The Data Protection Attachment, version 4 September 2024, commits to notice of a data breach without undue delay, giving its nature, likely consequences and the measures taken. It also commits to deletion of personal data on request. Docusign's subprocessor list, last updated 18 September 2026, has its own CLM section naming each hosting and AI supplier with locations. Updates go out through an RSS feed, and objections go by email. Agreement contents are encrypted at rest, and folder security controls access inside an account. Section 4.1 of the AI Attachment lets Docusign keep training data derived from customer content after termination, with no duty to delete it. Docusign does not state what Microsoft or Google keep from prompts.
The AI governance page describes TLS in transit and AES-256 at rest. Encryption keys are managed in Azure Key Vault, rotated regularly and reachable only through tightly controlled service accounts. The page also lists multifactor authentication, secure API gateways, network segmentation, real time monitoring and a documented incident response plan. Audit logs are described as comprehensive, tamper resistant and immutable. For outside assurance, the vendor says an independent Managed Security Service Provider audits it every year and that it is penetration tested regularly.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
The Master Services Agreement, version 14 November 2022, warrants that the services perform substantially as documented (8.1). The remedy is repair, replacement, or termination and a prorated refund. Docusign indemnifies the customer against third party claims arising from its breach of confidentiality and from intellectual property infringement (9.1). Liability is capped at fees paid for the service in the twelve months before the first event (10.2). The cap does not apply to indemnity obligations, confidentiality breaches, gross negligence or willful misconduct. The AI Attachment narrows these terms for AI. Section 6.2 disclaims all warranties on AI output and says Docusign is not liable for output to the extent it includes customer data. It also removes the indemnity where a claim arises from the customer's data, its own modifications or output it knew to infringe. The agreements do not cover loss from a wrong extraction or redline, and Docusign publishes nothing on insurance.
Section 16.5 of the Master Terms and Annexes sets a General Cap equal to fees paid or payable in the twelve months before the first incident. An Enhanced Cap of three times that applies to breaches of its security or data protection terms, meaning the security clause and the data processing addendum. Indemnities, intellectual property claims, breach of confidentiality and anything that cannot legally be limited are uncapped. Section 17.1 gives the customer an indemnity against third party intellectual property claims. Section 8.2 warrants that the service will perform materially as documented, with a thirty day fix period under 8.3 and termination with a refund if the fix fails. Annex A publishes uptime tiers of 99.00, 99.5 and 99.9 percent by support plan. A tier missed in three consecutive months, or in four months out of six, allows termination with a refund. Three limits apply. Breaches of confidentiality involving Customer Data fall outside the uncapped claim, so they stay capped and rise to the Enhanced Cap only where the security or data protection terms are also breached. The agreement gives no indemnity for AI output, such as inaccurate output, hallucination or training data provenance. Section 9.2 bars the customer from submitting Sensitive Data, including GDPR Article 9 categories, and the provider disclaims liability for it. These terms are version 3.0c. Version 4.0, dated 4 January 2026, changes only the trading name, according to the vendor.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Docusign's Salesforce integration for CLM generates documents and runs workflows across Salesforce Customer 360. With SAP Ariba, users create supplier agreements, ingest third party paper and track workflow tasks from Ariba. The Coupa integration lets contracts be created or updated in either system. Slack carries review notifications and actions, and comments sync between Microsoft Word, Google Docs and CLM. AI-Assisted Review runs inside Word, and Docusign eSignature is built in. The CLM API in the Docusign Developer Center offers object, task and content APIs for Salesforce and custom applications. Docusign Monitor, sold as an extra on top of CLM, reports CLM event activity, including through Splunk. Docusign University runs courses on building custom CLM integrations. The named integrations include no document management system used by law firms, such as iManage or NetDocuments. The product pages do not say which fields move in which direction for each connector.
Leah names its integrations and describes each by function. They cover ERP platforms including SAP and NetSuite, procurement systems including Coupa, financial systems, identity providers including Okta, and existing contract lifecycle tools. DocuSign and Adobe Sign are built in for signing, and a Microsoft Word add in handles redlining. The vendor also describes how the integrations work. It says Leah connects and executes rather than copying data passively, and carries out work across connected systems through the orchestration layer. Leah has a dedicated integrations page, but publishes nothing on what syncs in which direction or what a customer must configure. No document management integration such as iManage or NetDocuments appears, which fits a product built for in house teams rather than law firms.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Docusign's subprocessor list names CLM's hosting suppliers and places each by where the service is provisioned. The hosts are Equinix in the Netherlands, the United Kingdom and the United States, Switch in the United States, and Microsoft Azure in the United States, Australia, Canada, the European Union and Japan. AI processing is listed separately. Azure AI services for review, summaries and extraction run in the United States, Canada, the European Union, Australia and Japan. Google processing for the CLM Analyzer service runs in Belgium, Canada, Germany, Switzerland, the United Kingdom and the United States. Government editions are separate deployments. The CLM Service Schedule keeps government customer data inside Docusign's FedRAMP Moderate boundary unless a connector exports it (5.2). The DoD Impact Level 4 edition requires a connection to NIPRnet through a boundary cloud access point (5.3). Docusign does not describe the tenancy model for commercial customers and offers no on premises option.
The standard deployment is shared. Single tenant deployment is available for customers with strict isolation requirements. The vendor also offers what it calls a dedicated zero trust private environment in Azure OpenAI Studio, described as fully isolating data from all other customers. Leah runs on Azure, with keys held in Azure Key Vault. On data residency the vendor says only that it supports the residency and regulatory needs typical of large multinational enterprises. It names no region or jurisdiction and describes no customer choice.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The certifications page Docusign publishes lists ISO/IEC 27001:2022 certification enterprise wide, ISO/IEC 27017:2015 and 27018:2019, and PCI DSS 4.0. Annual SOC 1 Type II and SOC 2 Type II audits cover all production operations, including data centers. FedRAMP agency authorization, GovRAMP authorization and a Defense Information Systems Agency Impact Level 4 provisional authorization each name CLM directly. Reports and certificates are available in the Docusign Trust Portal, and the annual CSA STAR CAIQ is public on the CSA registry. Docusign also completes the Shared Assessments SIG, S&P Global KY3P and ProcessUnity assessments each year. USDM assesses its 21 CFR Part 11 module annually. C5 Type II covers the eSignature product only and does not extend to CLM.
The AI governance page claims SOC 1 Type I and II, SOC 2 Type I and II, GDPR compliance, CCPA compliance, HIPAA readiness and ISO 27001 alignment. The home page FAQ, on the same site, says only that Leah is SOC 2 Type II certified, so the two pages disagree on what is held. For ISO 27001 and HIPAA the governance page says aligned and ready rather than certified. The auditor is described only as an independent Managed Security Service Provider, a category rather than a named firm. No coverage period, report date or audit scope is given. Penetration testing is said to be regular, with no partner named and no summary published. Leah has no trust center or portal, so there is no published route to request a report.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The CLM section of Docusign's subprocessor list, last updated 18 September 2026, names the AI suppliers feature by feature. Microsoft's Azure OpenAI Service runs AI-Assisted Review in CLM, CLM+ and the AI Extension for CLM, and agreement summaries in the AI Extension and CLM+. Azure AI Document Intelligence runs AI extraction in CLM Essentials, CLM and the AI Extension. Google processes the CLM Analyzer service. DocuSmart Inc., trading as Lexion and wholly owned by Docusign, runs the legacy version of AI-Assisted Review for select US customers. Each entry gives the countries where it is provisioned. Updates are posted to an RSS feed customers can subscribe to. A customer may object to a new subprocessor by email on grounds set in Docusign's Processor Policy. The list gives no model name or version for any provider. Section 6.1 of the AI Attachment disclaims responsibility for the data third party providers used to train their own models.
The DPA Setup Page lists four model providers against Leah Functionality, each noted as storing or retaining no customer data and each with named jurisdictions. Anthropic PBC is listed for the USA, Japan, and the EU or UK, and OpenAI LLC for the USA, Japan, and the EU or Switzerland. Cohere Inc. is listed for Canada, the USA, the EU or UK, and Japan. Google AI/ML with Google Cloud is listed for the USA, Japan, and the EU, Switzerland or UK. Microsoft Azure Services is listed for hosting and translation, and the private deployment option runs in Azure OpenAI Studio. DPA clause 4.3 requires any new subprocessor to be added to the published list with at least thirty days' notice before it processes customer personal data. Clause 4.4 gives a thirty day objection right on reasonable data protection grounds. If the objection is not resolved, the affected order can be terminated with a refund of prepaid unused fees. No model or version is named for any provider. The platform is described as choosing among several language models for each task and letting customers extend or customize models. Nothing published shows which provider handled a given piece of work.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
A CLM subscription is prepaid and measured by a seat allowance, a document count or both, depending on the edition (4). The Service Schedule for Docusign CLM publishes that charging structure, but Docusign publishes no CLM price. Every call to action on the CLM page, Get Started included, goes to Contact Sales. The site's plans and pricing links lead to eSignature and IAM plans, none of which includes CLM. Under section 4.3, extra seats are charged pro rata at list price for the rest of the term. Documents over the count are charged per document at list price and invoiced monthly in arrears. Seats can be reassigned between people without penalty, and documents exported and then deleted during the term still count. Retrieval after the term ends is a paid professional services engagement. Editions named across Docusign's documents include CLM Essentials, CLM, CLM+ and the AI Extension for CLM, alongside government and DoD Impact Level 4 editions.
Leah publishes no pricing at any level, including the unit of charge. The primary navigation covers platform, solutions, resources and company, and neither it nor the footer sitemap has a pricing page. There is no tier structure, no unit per seat, contract or agent, no volume banding and no indication of what implementation adds. Every call to action across the site is to request a demo. An implementation FAQ says timelines vary with scope and integrations and that a detailed plan is built during evaluation. It says nothing about cost. No published page gives a view of price before a sales process.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
CLM is sold to legal, sales, procurement, human resources and customer experience teams. Its named customer stories come from wholesale telecom, auto parts distribution, retirement plan administration and recruiting software. Government use runs through CLM Government Products, authorized under FedRAMP and GovRAMP, and a DoD Impact Level 4 edition. Docusign says 2,200 enterprises use CLM for contract management. Its integrations with SAP Ariba and Coupa point at procurement as well as sales contracting. Docusign frames coverage by department and industry rather than by contract type or area of law. It names no minimum customer size, no law firm use, and no contract types the AI handles poorly. The IAM plans page states AI extraction in English, French and German, and the CLM pages give no language list.
Leah publishes dedicated industry pages for CPG and manufacturing, energy and utilities, financial services, healthcare, and pharma and medical devices. It describes its customers as Fortune 500 enterprises in regulated industries. By function it publishes pages for legal leadership, legal operations, sales and revenue, procurement, and finance. The pages carry distinct propositions written for the General Counsel, the contract operations team, the Chief Procurement Officer and the finance leader. The customer roster spans banking, airlines, pharmaceuticals, consumer goods and engineering. No published page says which practice areas, contract types or matters the platform does not support, and none addresses smaller organizations. Law firms appear only indirectly, through managed service partners, rather than as a served segment.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Section 4.1 of the AI Attachment for Docusign Services, version 8 July 2026, grants Docusign a perpetual license to use customer data and AI output to train models and improve its services generally. The data and output are anonymized and aggregated first. The attachment's applicability table says customers on a Master Services Agreement consent to that training for Docusign CLM. Section 4.2 lets the customer opt out at any time with a toggle in the product, on a going forward basis.
Docusign keeps the training data created before the opt out, with no duty to delete it. The AI Trust page describes the same program as consent based. Customers whose subscription began before 8 July 2026 are pointed to earlier versions of the terms.
Leah's security FAQ, on its home page, says customer contract data is never used to train models. The AI governance page treats data leaking into models the customer does not own as a failure it engineered out. It says zero data retention is enforced so that OpenAI and Anthropic process data but never store it. No term in the Master Terms and Annexes v3.0c names training, model training, machine learning or model improvement for customer content, either way.
Two clauses come close. Clause 5.1 limits the provider's use of Customer Data to providing and maintaining the Cloud Service, Support and Professional Services. Clause 5.4 allows use of Usage Data, the provider's technical logs, data and learnings about the customer's use, to run, improve and support the service. Usage Data excludes Customer Data, so the improvement right covers telemetry, not content. Together the clauses fit a ban on training without stating one.
They leave open whether model improvement counts as maintaining the service. The commitment rests on the published policy, not a contract term. Version 4.0 of January 2026 changes only the trading name, according to the vendor.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Section 3.1 of the Service Schedule for Docusign CLM, version 15 September 2025, keeps each stored document, including the customer data in it, for the subscription term or until the customer deletes it. The account administrator can set a different retention and deletion schedule. After the term, documents can be retrieved for 90 days through professional services, and Docusign may then delete them (3.2). The schedule covers stored documents rather than prompts as such.
AI output is Customer Confidential Information under the AI Attachment. The same attachment lets Docusign keep anonymized training data derived from content, with no duty to delete it. Docusign does not state what the Azure and Google model services keep from a prompt.
Section 14.4 allows export during the subscription and deletion of Customer Data within sixty days of a request after termination. That is subject to standard backup or record retention policies and legal requirements, and the customer cannot change the period. The data processing addendum adds secure deletion to industry standards at clause 8.2, with a certificate of deletion on request. Schedule 1 commits to export in CSV or a similar format within thirty calendar days and to physical destruction of media by a recognized provider.
Prompts and outputs have no separate window. The agreement treats Customer Data as one class, defined at section 23 as any data, content or materials the customer submits, so prompts and outputs follow that regime. Usage Data sits outside it. Section 5.4 lets the provider collect Usage Data, meaning its technical logs, data and learnings about the customer's use, excluding Customer Data. The provider may use it to run, improve and support the service and for other lawful purposes such as benchmarking.
It may disclose Usage Data externally only if deidentified and aggregated across customers. No deletion duty applies to Usage Data, and section 14.5 makes 5.4 survive termination.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
CLM has its own permission model built on folders. A Docusign employee's guide on the Docusign Community sets out six levels. They run from No Access, the default for all content, through View, View and Create, View and Edit, and View, Edit and Delete, to full control with Set Access. Security can be set for a user, a permission profile or a user group. Folders inherit their parent's security unless it is set explicitly.
CLM administrators can see all content whatever the folder settings. The CLM page adds granular permissions controls and an audit trail of who did what and when. Docusign does not say how AI review, summaries or repository lookups apply folder permissions when they run.
Leah describes separation at the customer level, through deployment options. The vendor states that single tenant deployment is available for customers with strict data isolation requirements. It says a dedicated zero trust private environment within Azure OpenAI Studio ensures complete isolation from all other customers. Role based access control is stated to be enforced at every layer. That wording makes isolation a deployment option rather than the default, and nothing published describes how customers are separated in the standard shared deployment.
Legal, procurement, finance and shared services teams work in the same system, and nothing published addresses boundaries between them inside a customer.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Section 11.2 of the Master Services Agreement, version 14 November 2022, requires prompt written notice before a compelled disclosure of confidential information, unless legal process forbids it. It also requires cooperation in seeking a protective order. The Data Protection Attachment adds prompt notice of any government request about personal data. Docusign's law enforcement page says the company notifies customers when their data is subject to disclosure and withholds notice only under a signed nondisclosure order or a statute that bars it.
The page adds that Docusign cannot decrypt agreement contents at rest. Docusign prepares an annual transparency report on requests and makes it available to data protection authorities on request. The report is not published. Section 2(d) of the CLM Service Schedule says Docusign is not responsible for producing customer documents to any third party.
Section 19, headed Required Disclosures, lets the recipient disclose Confidential Information where the law requires. Where the law permits, the recipient must give advance notice and reasonable cooperation, at the discloser's expense, to obtain confidential treatment. The clause expressly covers Confidential Information including Customer Data. Section 23 confirms that the customer's Confidential Information includes Customer Data, so customer material sits inside the notice duty.
The duty is mutual and binds whichever party receives the demand. Section 14.5 makes section 19 survive termination. Leah publishes no transparency report, so there is no public count of demands received or of how they were answered. These terms are version 3.0c. Version 4.0 of January 2026 changes only the trading name, according to the vendor.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
CLM works from the customer's own contracts, templates and clause library, and does not retrieve case law or legislation. Docusign describes Iris, the engine behind it, as trained on decades of contract data. Section 6.1 of the AI Attachment lists the training data for Docusign's own models as customer data authorized for training, publicly available data and data licensed from third parties. Docusign warrants that to its knowledge it holds sufficient permissions for them.
The section names no specific source or license, and it excludes the data third party providers used for their own models.
Leah works on the customer's own material. The vendor states that Leah operates against the customer's policies and playbooks and gains intelligence from the customer's unstructured data and business rules. It answers contract questions from the customer's repository with sources attached. The vendor also refers to Leah operating against established legal precedents, but names no source, jurisdiction, database or rights basis for them.
The product manages a customer's contracts rather than retrieving primary law. No provenance statement backs the precedent reference, and no update cadence is published for anything.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Docusign CLM manages a customer's own agreements and does not cite case law or legislation, so a citator is not part of the product. The CLM page, the AI-Assisted Review page and the AI Trust page do not address checking authority for later history. Docusign does not describe how CLM detects when an amendment or a policy change leaves extracted terms or clause library positions out of date.
Leah describes no citator, treatment signal or currency check, and does not say whether legal authority is reviewed for later history. The platform manages contracts, obligations and procurement workflows rather than retrieving case law, so a citator is not part of what it sells. The vendor does refer to Leah operating against established legal precedents, without identifying any source. That is the one place the product invokes primary authority, and no verification step is described for it.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
Section 6.2 of the AI Attachment warns that AI output may be incorrect or otherwise undesirable and makes the customer responsible for reviewing it. The AI Trust page describes content filtering for harmful outputs. Neither document says what AI-Assisted Review or the question and answer feature does when a playbook or the repository does not cover what is asked. Nor do they say how a doubtful extraction is marked before it feeds a report, a renewal alert or a workflow rule.
Docusign documents no path for CLM's AI features to decline an answer and publishes no confidence or grounding scores for extraction, review or summaries.
The home page and the AI governance page describe no explicit path for Leah to decline to answer or abstain, and no confidence or grounding rating. The governance loop does produce rejections. Approvals, escalations and rejections are applied automatically according to the customer's rules. Those are policy outcomes set by configured guardrails, not the model declining because it cannot ground a response. Neither page says what Leah does when the customer's own contract set or playbook does not cover the question in front of it.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
The AI Hallucination Cases database maintained by Damien Charlotin tracks court decisions worldwide that address hallucinated AI content and records the tool involved where known. It has no entry naming Docusign, Docusign CLM, Iris, SpringCM or Lexion, in the tool field or anywhere in the case text. CLM manages commercial agreements rather than producing court filings, so its output does not ordinarily reach a brief.
The AI Hallucination Cases database maintained by Damien Charlotin tracks decisions worldwide where a court addressed hallucinated AI content, and records the tool implicated where known. It records no court order, opinion or disciplinary record naming Leah or the former company name ContractPodAi. Published 2026 sanctions trackers and trade press summaries name neither. The platform runs commercial contracting and procurement work rather than producing court filings, so its output does not ordinarily reach a brief.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Section 6.2 of the AI Attachment for Docusign Services, which governs CLM's AI features, states that neither Docusign, the AI Services nor AI output provide the customer with legal advice. It makes the customer responsible for reviewing output for accuracy and suitability, including through human review. The CLM page, the AI-Assisted Review page, the AI Trust page and the agreements name no bar opinion, ethics rule or professional conduct guidance.
Docusign's compliance work covers data, security and sector regimes, including ISO, SOC, PCI DSS, FedRAMP, GovRAMP, DoD Impact Level 4, HIPAA and 21 CFR Part 11. Those regimes bind Docusign as a provider rather than a lawyer using the product.
Leah publishes nothing that engages with bar or ethics guidance. That includes ABA Formal Opinion 512, state bar guidance in the United States, and Solicitors Regulation Authority or Law Society material. The company is headquartered in London and sells into legal departments across North America, Europe, Asia and Australia. Its published compliance material covers regulation and security frameworks, namely GDPR, CCPA, HIPAA, SOC and ISO. None of it addresses the professional conduct obligations that bind the lawyers using the product.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Enterprise legal, sales, procurement, human resources and customer experience teams buy CLM to run their own contracting. The named customers are companies such as T-Mobile Wholesale, Genuine Parts Company, Vestwell and iCIMS rather than law firms, so no client bill sits in the loop. Docusign claims an 83 percent boost in speed and efficiency and a 449 percent return on investment. It also claims a 90 percent cut in time to generate a sales contract and 72 to 80 percent saved on contract reviews.
All of these concern the customer's own cost and time. Docusign publishes nothing on fee treatment of AI assisted work for a firm that bills a client.
Leah frames its public materials around cost and time removed, quantified at portfolio level. It cites a 91 percent cut in contract review time, more than $18 million of revenue protected and more than $2 million of tracked savings. Its headline figures are more than $125 billion of commercial value managed and more than $10 billion of ROI impact delivered. No per matter record of AI assisted work for fee purposes is described, and no guidance on billing, fee or client disclosure treatment is published.
The vendor describes an immutable audit log of every action, which could in principle support such a record, but does not present it for that purpose. Leah sells to in house functions rather than firms billing clients, so the costs in play are internal cost and outside counsel spend. Its materials address neither.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
Docusign's subprocessor list, last updated 18 September 2026, is published as a web page and a download, with a separate section for CLM. It names each hosting supplier and each AI supplier against the feature it powers, with countries and a contact address. Changes go to an RSS feed, with an email route for objections. The Data Protection Attachment, the AI Attachment, the Master Services Agreement and the CLM Service Schedule are all published without a login.
The certifications page and the public CSA STAR CAIQ cover security. Together these documents name every model provider that touches CLM content, and a customer can forward them when its own clients ask about AI vendors.
The data processing agreement is Annex B of the Master Terms and Annexes v3.0c. The DPA Setup Page lists every subprocessor with its purpose, location and the product it serves. The list names ABBYY OCR SDK, Anthropic PBC, Cohere Inc., DocuSign or Adobe, Google AI/ML and Google Cloud, Jitterbit, Microsoft Azure Services, OpenAI LLC, QlikTech, Sendgrid, ZOHO, Zuva and four ContractPod group entities. Anthropic, OpenAI, Cohere and Google AI/ML are each listed against Leah Functionality as model providers, noted as storing or retaining no Customer Data, with named jurisdictions.
The DPA itself is the Bonterms DPA, published openly in the same PDF and ready to forward. It incorporates EU Standard Contractual Clauses Modules 2 and 3 and the UK International Data Transfer Addendum. It sets out processing details in Schedule 1 and fixes a 48 hour notice period for security incidents. Clause 4.3 commits to listing any new subprocessor and giving at least 30 days' notice before it processes anything.
Clause 4.4 gives an objection right, with termination and a refund if the objection is not resolved. Version 4.0 of January 2026 changes only the trading name, according to the vendor.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
CLM keeps an audit trail of who did what and when, and detailed version control across drafts, so the history of a contract can be reconstructed. Docusign does not say whether an AI-Assisted Review suggestion, an AI drafted clause or an AI extraction is marked as machine generated in that history. Nor does it say whether the audit trail records which model produced it. It publishes no export built for disclosing AI involvement and no disclosure template.
CLM output is a contract, a report or an obligation record rather than a court filing. A record of AI involvement would most likely go to a counterparty, an auditor or a regulator.
The audit stage of Leah's published governance loop logs every decision. Each entry records what the agent did, why, under which policy, with what data and with what outcome. The records are described as tamper resistant, immutable and ready for any audit. That gives the action, the rule, the inputs and the result for each action. The published description of the log does not include the model. The platform chooses among several language models for each task and identifies no model or version, so the log does not show which system produced a given passage.
No export built for court disclosure or AI use certification is described. The audit framing is regulatory and internal rather than judicial.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Good Law Verification
- Refusal and Uncertainty Behavior
Which one fits
Choose Docusign CLM if
- You need to say where contracts and AI processing sit. Docusign lists CLM hosting by country across Equinix, Switch and Microsoft Azure. It lists separately where its Azure and Google AI services process CLM data.
- You work with government or defense agencies. Docusign's FedRAMP, GovRAMP and DoD Impact Level 4 authorizations name CLM. Its government editions keep data inside the FedRAMP Moderate boundary unless a connector exports it, and reports sit in the Docusign Trust Portal.
- You want customer results with numbers. In Docusign's customer stories, T-Mobile Wholesale reports cutting agreement time by 44 percent, and Vestwell builds agreement packages in 5 minutes instead of 75. iCIMS reports that 78 percent of its agreements need no legal involvement.
Choose Leah if
- You want agents doing work beyond review. Leah's Agentic OS assigns contracting, procurement and finance tasks to agents under the Leah Maestro orchestrator. A no code builder adds new workflows and apps.
- You want training off without having to switch it off. Leah says customer contract data is never used to train models and holds OpenAI and Anthropic to zero retention. Docusign's AI terms license training on anonymized CLM data unless the customer opts out.
- You want each agent decision traceable. Leah logs what each agent did, why, under which policy and with what outcome. Escalation and approval rules are customer configuration rather than code.
In summary
Docusign CLM
Docusign CLM is the contract lifecycle product in Docusign's Intelligent Agreement Management platform, built on SpringCM, which Docusign agreed to buy in 2018. It generates agreements from templates and Salesforce data and routes them through workflows assembled from preconfigured steps, while its Iris AI reviews, extracts and summarizes. According to the AI Legal Index, Docusign CLM publishes the paperwork a security or procurement team asks for. That includes hosting and AI processing countries, a subprocessor list naming the AI supplier behind each feature, and government authorizations that name the product. Its AI terms permit training on anonymized customer data unless the customer opts out. The charging structure is published, but no price.
Leah
Leah, formerly ContractPodAi, is an enterprise platform where agents carry contracting, legal, procurement and finance work. Beneath them is a contract lifecycle product with playbook review in Microsoft Word, approval routing, signing through DocuSign or Adobe Sign, and a repository with renewal alerts. The AI Legal Index records governance as Leah's selling point. The customer configures what agents may do and on which data, and each action is logged with what was done and why. Its master terms set liability caps with figures, and its data processing pages name four model providers. Leah says customer contracts never train models. No price, region or accuracy figure is published.
Questions buyers ask
Docusign CLM vs Leah: which is better for enterprise contract management?
They answer different needs. Docusign CLM is a workflow system with AI review inside it, backed by published agreements, named hosting countries and government authorizations. Leah is an agent platform for contracting, procurement and finance, run under rules the customer configures. Both connect to Coupa and SAP systems. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
Do Docusign CLM and Leah train AI on customer contracts?
Docusign's AI Attachment licenses training on anonymized, aggregated CLM data and output unless the customer turns it off with a toggle in the product. Data gathered before the opt out is kept. Leah says customer contract data is never used to train models, and that OpenAI and Anthropic process it under zero retention. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
Which AI providers do Docusign CLM and Leah use?
Docusign names them feature by feature. Azure OpenAI runs AI review and summaries, Azure AI Document Intelligence runs extraction, and Google runs the Analyzer service, each with its countries. Leah names Anthropic, OpenAI, Cohere and Google for the platform as a whole. Neither names a model version. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
Do Docusign CLM or Leah say their AI is not legal advice?
Docusign does, in its contract. Section 6.2 of its AI Attachment states that neither Docusign nor its AI output gives legal advice, and puts review of output on the customer. Leah publishes no such statement, though it is sold to run legal work end to end. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
What do Docusign CLM and Leah both leave unpublished?
Neither publishes a price figure, an accuracy or error rate for AI review, or a model version. Neither addresses attorney client privilege. Docusign disclaims warranties on AI output, and neither indemnifies it. Docusign at least publishes its charging units, seats and documents, while Leah gives no unit at all. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything on it comes from public material on the dates shown. How the index grades.
Docusign's training license sits in section 4.1 of its AI Attachment of 8 July 2026. It applies to CLM customers on a master services agreement unless they opt out, and Docusign keeps training data created before an opt out. Earlier subscribers are pointed to earlier terms. Leah's no training position is a published policy, not a contract term. The two can also meet in one estate, since Leah builds in DocuSign for signing and lists it among its subprocessors. Neither vendor reviewed this page.