Docusign CLM vs SpotDraft: how they compare in 2026

D
Docusign CLM profile
S
SpotDraft profile
Last verifiedOctober 8, 2026

Both are contract lifecycle platforms with AI review and extraction, so the choice turns on scale and on what each puts in writing. Docusign CLM is the enterprise system that began as SpringCM, sold by department to legal, sales, procurement, HR and customer experience teams, with government editions authorized under FedRAMP, GovRAMP and DoD Impact Level 4. Its paperwork is published in full: a CLM service schedule, a master services agreement, a data protection attachment and an AI attachment, plus a subprocessor list that ties Azure OpenAI, Azure AI Document Intelligence and Google to each CLM feature. SpotDraft is built for in house legal teams in the mid market. It runs on Google Cloud in the Netherlands, keeps personal data in a region the customer picks across the US, the EU, India and the Middle East, gives each contract its own encryption key, and names the California State Bar's AI guidance and ABA Formal Opinion 512. Docusign's AI terms let it train on CLM customer data unless the customer switches that off; SpotDraft publishes nothing on training. Neither publishes a price or an accuracy measure for its AI.

At a glance

Category
Docusign CLMContract Review & Drafting
SpotDraftContract Review & Drafting
Founded
Docusign CLMNot published
SpotDraftNot published
Headquarters
Docusign CLMSan Francisco, California, United States
SpotDraftNot published
Last verified
Docusign CLMOct 8, 2026
SpotDraftAug 31, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Docusign CLM
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

Docusign CLM is a workflow and document system at its core: generation from templates, a clause library, a drag and drop workflow designer with more than 100 preconfigured steps for generation, review, approval, signature and storage, and a repository with reporting. That system dates from SpringCM, which Docusign agreed to buy in 2018, before generative AI was part of it. AI now drives several core functions. More than 100 pretrained models extract and report on contract data points and legal topics. AI-Assisted Review flags nonstandard clauses and suggests redlines against a playbook. Generative features summarize agreements, draft clauses on request and answer questions about the repository. Docusign brands the engine Iris and describes it as trained on decades of contract data. Workflows can start from analytics, risk scores and contract content, so extraction feeds routing as well as search.

SpotDraft
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

SpotDraft is a full contract lifecycle system first: templates, conditional workflows and approvals, a shared editor, built in eSignature meeting ESIGN, eIDAS and ECA, a repository, reporting and analytics. Without SpotDraft AI, VerifAI, Intake and Sidebar, a working CLM with signature and workflow remains, with its own market. The AI covers review inside Word, automatic extraction of more than a thousand metadata types, and agents that track regulatory change. SpotDraft now calls itself context aware, AI native CLM, but the platform predates that framing.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Docusign CLM
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Docusign describes Iris as delivering accurate, secure and trusted agreement intelligence. Its AI Trust page says AI outputs have been tested for accuracy, and that diverse datasets and checks are used to correct skewed outputs before release. No figure, error rate, test set or evaluation method is published for CLM extraction, AI-Assisted Review or agreement summaries. The quantified claims on the review product are time savings, such as 72 to 80 percent saved on contract reviews, with no stated baseline. Section 6.2 of the AI Attachment for Docusign Services, version 8 July 2026, says that given the probabilistic nature of machine learning the AI may produce output that is incorrect, and places review for accuracy on the customer. The product works from the customer's own contracts and clause library rather than from law, and nothing published describes how a summary or an answer links back to the clause it came from.

SpotDraft
DD on Citation Accuracy and Hallucination DisclosureNothing published on accuracy or grounding for a product that produces legal assertions, or a bare claim that the system does not hallucinate.

SpotDraft publishes nothing on accuracy or grounding. There is no accuracy figure, error or hallucination rate, benchmark, test set or evaluation on the home, pricing or security pages. Nothing describes how AI output is grounded in the customer's documents or whether a user can trace a statement back to its source. The figures SpotDraft publishes measure speed and cost: contracts reviewed 15 times faster with VerifAI, closings twice as fast, 65 percent lower cost and 70 percent less review time. The nearest thing to an accuracy claim is that the AI works in the customer's own context and follows its rules, which describes setup, not correctness.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Docusign CLM
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Section 6.2 of the AI Attachment makes the customer responsible for reviewing and evaluating AI output, including through human review, for accuracy and suitability. The AI Trust page says the customer has the final say to approve outputs. In the product, AI-Assisted Review suggests edits and flags risky language for a reviewer to accept or reject, and CLM workflows send agreements with nonstandard terms to review under conditional rules the customer sets. Every action sits in an audit trail of who did what and when, with version control across drafts. Workflows can also be triggered automatically by analytics, risk scores and contract content. Nothing published sets out what an AI step may do without a person, at what confidence an extraction is held for review, or what happens after an AI output is found to be wrong.

SpotDraft
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

SpotDraft's approval routing is conditional, with thresholds shown, for example approvals going to the Head of Finance below a deal value and to the CFO and CEO above it. Audit logs trace changes at contract level by both the customer and the counterparty, every draft keeps its version history, and permissions are scoped by contract type, entity and department. Nothing describes control over the AI itself: what SpotDraft AI, VerifAI or the Sidebar agents do unattended, when a person must review model output, what agents can change without approval, or what happens when an output is wrong. Saying the AI follows the customer's rules implies limits without describing any.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Docusign CLM
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

The CLM page carries four named customer stories, each with figures and a named, titled speaker. T-Mobile Wholesale cut agreement time by 44 percent without adding headcount, with 1.8 times faster cycle time on high value agreements, quoted by Janet Sutherland, Senior Manager of Sales Enablement. Genuine Parts Company runs more than ten use cases across five departments, quoted by Keith McCarraher, Special Projects Manager. Vestwell reports agreement packages built in 5 minutes instead of 75 and 70 percent fewer drop offs, quoted by its COO, Jon Mark. iCIMS reports that 78 percent of its agreements need no legal involvement, quoted by Courtney Dutter, Deputy General Counsel. The page also states a 449 percent return on investment, an 85 percent reduction in errors and 2,200 enterprise CLM customers, without naming the study or the customers behind those figures. No story gives a deployment date or a measurement method.

SpotDraft
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

SpotDraft names in house lawyers with roles and employers: Anna Claveria Brannan, Deputy General Counsel at IPSY; Susan Koenig, formerly Senior Legal Operations Manager at Abnormal Security; Micah Nessan, formerly General Counsel at Guideline; Reason Abajuo, VP of Legal and Corporate Affairs at Chaberton Energy; Lizzy Gagan, Senior Legal Counsel at Beamery; Arzu Hasanova, Legal Counsel at Circularise; Aditi Kapoor, Director of Legal at Gameskraft; and Natasha Wilson, Head of Legal at SUN Mobility. Every quote is qualitative. The quantified claims carry no customer at all: two times faster closings, 65 percent lower cost, 70 percent less review time, and contracts reviewed 15 times faster. Two of the referees are identified as former employees of the companies named.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Docusign CLM
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Under the Docusign Master Services Agreement, version 14 November 2022, Customer Data stays owned by the customer (3.1), confidential information may be used only for the purpose given and protected with at least reasonable care (11.1), and liability for a breach of confidentiality sits outside the twelve month fee cap (10.2). The AI Attachment treats AI output as Customer Confidential Information. Training is the other side of it. Section 4.1 of the AI Attachment grants Docusign a perpetual license to use CLM customer data and AI output, once anonymized and aggregated, to train models, and section 4.2 lets the customer switch that off going forward with a toggle in the product. Section 4.3 of the MSA separately lets Docusign use deidentified usage data, including for training. Within a customer account, CLM folder security limits who sees which contracts. Privilege and work product are not addressed in the agreements or on the product pages.

SpotDraft
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

SpotDraft's security page says customer data is logically separated within shared, multitenant infrastructure. Each contract has its own encryption key in HashiCorp Vault backed by Google Cloud KMS, with AES-256 at rest and FIPS 140 certified encryption. Data is classified as public, company confidential, customer confidential or personal, and access follows least privilege with unique IDs. Third party vendors handling scoped data must follow confidentiality, audit and incident response rules. Nothing published says whether customer contracts are used to train any model, by SpotDraft or a model provider, and no retention period for prompts or outputs is published. Privilege and work product are not addressed.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Docusign CLM
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

Section 6.2 of the AI Attachment states that neither Docusign, the AI Services nor AI output provide the customer with legal advice, that suitability for any purpose is at the customer's sole discretion, and that the customer reviews output for accuracy, including through human review. The statement sits in the contract that governs CLM's AI features rather than in a site footer. CLM is sold to sales, procurement, human resources and customer experience teams as well as legal, and AI-Assisted Review proposes redlines and drafts clauses for any of those users. Nothing published addresses who in a customer reviews an AI redline before it reaches a counterparty, how the product supports a lawyer's competence and supervision duties, or any limit by jurisdiction.

SpotDraft
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

SpotDraft's home page says its AI features are designed with attention to the California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law, November 2023. It also names the American Bar Association's Formal Opinion 512 on generative AI, July 2024. Both are named with their issuer and date, on the home page rather than in a policy. Nothing addresses a lawyer's own competence and supervision duties or any limit on use by jurisdiction. The claim is attention to principles, not a mapping of product behavior to specific duties, so which principle each control meets is not shown.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Docusign CLM
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

Docusign publishes AI Trust and AI Innovation Principles pages for Iris, the engine behind CLM's AI features. The AI Trust page lists encryption in transit and at rest, consent based training on aggregated and anonymized data, diverse datasets and checks to correct skewed outputs before deployment, content filtering for harmful outputs, and adoption of frameworks such as the NIST AI framework. Section 6.1 of the AI Attachment adds a warranty that, to Docusign's knowledge, it holds sufficient permissions for the data used to train its own models, defined as customer data authorized for that use, publicly available data and licensed data. No person, committee or team is named as accountable for model behavior, no ISO/IEC 42001 certification appears, and no test results are published, including on whether output differs across contract types, languages or regions. The AI Trust page says broader AI Trust capabilities are available through sales.

SpotDraft
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

SpotDraft's security page describes a formal risk governance policy approved by management that defines an Enterprise Risk Management program. Periodic operational risk assessments feed management reports, with each risk rated, assigned an owner and tracked to treatment or acceptance. Privacy risk is assessed through vendor due diligence, and an information security team led by the Chief Technology Officer oversees the process. None of it covers model behavior. Nothing describes testing before an AI release, there is no responsible AI framework, and nothing addresses bias or uneven output across contract types, counterparties or populations.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Docusign CLM
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

The Service Schedule for Docusign CLM, version 15 September 2025, stores documents for the subscription term or until the customer deletes them, and lets an account administrator set a different retention and deletion schedule (3.1). Retrieval is free during the term and available for 90 days after it through professional services, after which Docusign may delete the account and its documents (3.2). The Data Protection Attachment, version 4 September 2024, commits to notice of a data breach without undue delay, with its nature, likely consequences and the measures taken, and to deletion of personal data on request. Docusign's subprocessor list, last updated 18 September 2026, has its own CLM section naming each hosting and AI supplier with locations, with updates through an RSS feed and objections by email. Agreement contents are encrypted at rest, and folder security controls access inside an account. Section 4.1 of the AI Attachment lets Docusign keep training data derived from customer content after termination with no duty to delete it, and nothing states what Microsoft or Google keep from prompts.

SpotDraft
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

SpotDraft's security page, last updated 17 October 2025, describes FIPS 140 certified encryption, AES-256 at rest, and a unique key per contract held in HashiCorp Vault backed by Google Cloud KMS. Primary and backup servers run on Google Cloud Platform in the Netherlands. Data is classified into four sensitivity tiers, and access follows least privilege, with unique IDs and enforced password rules. There is a documented business continuity and disaster recovery program, automated patching, ongoing tracking of known vulnerabilities in third party packages, regular threat modeling, independent penetration testers, and routine code analysis and vulnerability scans. A set incident response process is stated and refined through regular exercises. No subprocessor is named, though the page says fourth parties such as backup providers and subcontractors have no access to scoped systems or data, and no retention period for customer content is published.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Docusign CLM
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

The Master Services Agreement, version 14 November 2022, warrants that the services perform substantially as documented, with repair, replacement, or termination and a prorated refund as the remedy (8.1). Docusign indemnifies the customer against third party claims arising from its breach of confidentiality and from intellectual property infringement (9.1). Liability is capped at fees paid for the service in the twelve months before the first event, with no cap on indemnity obligations, confidentiality breaches, gross negligence or willful misconduct (10.2). The AI Attachment narrows this for AI. Section 6.2 disclaims all warranties on AI output, says Docusign is not liable for output to the extent it includes customer data, and removes the indemnity where a claim arises from the customer's data, its own modifications or output it knew to infringe. Nothing in the agreements covers loss from an extraction or redline that is wrong, and no insurance is published.

SpotDraft
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

The SpotDraft Terms of Use on its Legal Hub at legal.spotdraft.com, version 2.3, last updated 21 February 2024, are published with five prior versions downloadable from the same page. Clause 8.3 caps SpotDraft's total liability, in contract or tort, at one hundred Indian rupees, roughly one US dollar. Clause 8.2 excludes consequential, indirect and special damages, including loss of data and profits. Clauses 5.2 and 5.3 disclaim fitness for purpose and error free or uninterrupted use, and expressly waive the warranty of noninfringement. Clause 9 is an indemnity from the customer to SpotDraft only, and the document contains no vendor indemnity. Clause 5.5 disclaims liability for consequences of using the Platform, and 5.4 says SpotDraft gives no legal advice. Indian law governs, with exclusive jurisdiction in the courts at Bangalore. The contracting entity is Draftspotting Technologies Private Limited, with affiliates including Draftspotting Inc. These are the Terms of Use reached from the signup path. Clause 11.8 contemplates added terms for other services, so an enterprise customer may sign a negotiated master agreement that is not published.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Docusign CLM
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Docusign names CLM integrations with Salesforce, for generating documents and running workflows across Salesforce Customer 360; SAP Ariba, for creating supplier agreements, ingesting third party paper and tracking workflow tasks from Ariba; and Coupa, with contracts created or updated in either system. Slack carries review notifications and actions, comments sync between Microsoft Word, Google Docs and CLM, AI-Assisted Review runs inside Word, and Docusign eSignature is built in. The CLM API in the Docusign Developer Center offers object, task and content APIs for Salesforce and custom applications, and Docusign Monitor, sold as an extra on top of CLM, reports CLM event activity, including through Splunk. Docusign University runs courses on building custom CLM integrations. No document management system used by law firms, such as iManage or NetDocuments, is named, and the product pages do not say which fields move in which direction for each connector.

SpotDraft
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

SpotDraft states more than 30 integrations and gives each its own page, with Salesforce, HubSpot, Slack, Microsoft Word for desktop, Google Drive, DocuSign, Greenhouse, Google Forms, Jira and Zapier all linked directly from the pricing page. VerifAI runs review inside Microsoft Word, negotiation and redlining are described as working in Word, Slack or SpotDraft itself, and one named customer credits the Word desktop editor with driving adoption. Single sign on covers Office 365, Google Workspace, Okta, Active Directory and custom SAML with zero touch provisioning. No document management integration such as iManage or NetDocuments appears, consistent with an in house rather than law firm product.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Docusign CLM
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

Docusign's subprocessor list places CLM hosting with Equinix in the Netherlands, the United Kingdom and the United States, Switch in the United States, and Microsoft Azure in the United States, Australia, Canada, the European Union and Japan, each by where the service is provisioned. AI processing is listed separately. Azure AI services for review, summaries and extraction run in the United States, Canada, the European Union, Australia and Japan, and Google processing for the CLM Analyzer service runs in Belgium, Canada, Germany, Switzerland, the United Kingdom and the United States. Government editions are separate deployments. The CLM Service Schedule keeps government customer data inside Docusign's FedRAMP Moderate boundary unless a connector exports it (5.2), and the DoD Impact Level 4 edition requires a connection to NIPRnet through a boundary cloud access point (5.3). Nothing describes the tenancy model for commercial customers, and no on premises option is offered.

SpotDraft
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

SpotDraft's customer data is logically separated within shared, multitenant infrastructure. Residency is a customer choice with a clear limit: personal data is stored in selected regions covering the US, EU, India and the Middle East, and is not sent outside them. Primary and backup servers are on Google Cloud Platform in the Netherlands, and Google Cloud Platform runs processing throughout. Encryption keys are held per contract in HashiCorp Vault backed by Google Cloud KMS, which shows where keys are held as well as where data rests. Which region applies by default, and whether contract content follows the same rule as personal data, are not stated; the regional commitment is written for personal data.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Docusign CLM
AA on Security Certifications and Trust CenterCurrent independent attestation with named scope, reachable without a sales call: a trust center carrying reports, dates and the standards actually covered.

Docusign's certifications page lists ISO/IEC 27001:2022 certification enterprise wide, ISO/IEC 27017:2015 and 27018:2019, annual SOC 1 Type II and SOC 2 Type II audits of all production operations including data centers, and PCI DSS 4.0. Three authorizations name CLM directly: FedRAMP agency authorization, GovRAMP authorization and a Defense Information Systems Agency Impact Level 4 provisional authorization. Reports and certificates are available in the Docusign Trust Portal, and the annual CSA STAR CAIQ is public on the CSA registry. Docusign also completes the Shared Assessments SIG, S&P Global KY3P and ProcessUnity assessments each year, and USDM assesses its 21 CFR Part 11 module annually. C5 Type II covers the eSignature product only, so it does not extend to CLM.

SpotDraft
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

Four compliance marks appear on SpotDraft's home, pricing and security pages: ISO, GDPR, HIPAA and AICPA SOC 2. SpotDraft's home page lists them as ISO 27001, SOC 2 Type II, GDPR and HIPAA. The footer on every page says SpotDraft is ISO/IEC 27001:2013 certified, but 27001:2013 was replaced by the 2022 revision, so the site claims a current certification while naming a retired version. A separate trust center at trustcenter.spotdraft.com is linked. No auditor, coverage period or report date for the SOC 2, or scope, is published outside the trust center. Independent penetration testers are said to be used, but none is named and no summary is published.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Docusign CLM
AA on Model Supply Chain DisclosureThe models underneath are named, their providers identified, where they run is stated, and the vendor commits to notifying customers when any of that changes.

The CLM section of Docusign's subprocessor list, last updated 18 September 2026, names the AI suppliers feature by feature. Microsoft's Azure OpenAI Service runs AI-Assisted Review in CLM, CLM+ and the AI Extension for CLM, and agreement summaries in the AI Extension and CLM+. Azure AI Document Intelligence runs AI extraction in CLM Essentials, CLM and the AI Extension. Google processes the CLM Analyzer service. DocuSmart Inc., trading as Lexion and wholly owned by Docusign, runs the legacy version of AI-Assisted Review for select US customers. Each entry gives the countries where it is provisioned. Updates are posted to an RSS feed customers can subscribe to, and a customer may object to a new subprocessor by email on grounds set in Docusign's Processor Policy. No model name or version is given for any provider, and section 6.1 of the AI Attachment disclaims responsibility for the data third party providers used to train their own models.

SpotDraft
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

SpotDraft publishes nothing about the AI models a customer relies on. No model provider, model or version is named. The only description is that the AI is built into SpotDraft and works in the customer's own context. There is no subprocessor list and no commitment to notify customers of changes. The security page is otherwise detailed, naming HashiCorp Vault, Google Cloud KMS, JAMF, FileVault and BitLocker among its tools.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Docusign CLM
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

Docusign publishes no CLM price. Every call to action on the CLM page, Get Started included, goes to Contact Sales, and the site's plans and pricing links lead to eSignature and IAM plans, none of which includes CLM. The Service Schedule for Docusign CLM publishes the charging structure. CLM is a prepaid subscription measured by a seat allowance, a document count or both, depending on the edition (4). Extra seats are charged pro rata at list price for the rest of the term, and documents over the count are charged per document at list price, invoiced monthly in arrears (4.3). Seats can be reassigned between people without penalty, and documents exported and then deleted during the term still count. Retrieval after the term ends is a paid professional services engagement. Editions named across Docusign's documents include CLM Essentials, CLM, CLM+ and the AI Extension for CLM, alongside government and DoD Impact Level 4 editions.

SpotDraft
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

SpotDraft's pricing page says plans are priced either by users or by contract volume, framed as avoiding wasted spend. It also covers implementation: in house implementation is always included, covering workflow and integration setup and migration of old contracts, with no extra fees and no outsourcing. Every customer gets a dedicated customer success manager and support around the clock at no extra cost. A six week implementation timeline is published, week by week. No number appears: no rate, floor or currency, and every call to action is Get Pricing or a demo request.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Docusign CLM
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Docusign sells CLM to legal, sales, procurement, human resources and customer experience teams, and its named stories come from wholesale telecom, auto parts distribution, retirement plan administration and recruiting software. Government use is documented through CLM Government Products authorized under FedRAMP and GovRAMP and a DoD Impact Level 4 edition. Docusign says 2,200 enterprises use CLM for contract management, and integrations with SAP Ariba and Coupa point at procurement as well as sales contracting. Coverage is framed by department and industry rather than by contract type or area of law. Nothing published names a minimum customer size, a law firm use, or contract types the AI handles poorly. Docusign's IAM plans page states AI extraction in English, French and German, and the CLM pages give no language list.

SpotDraft
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

SpotDraft gives five buying teams dedicated pages: legal, sales, finance, HR and procurement, with legal as the owner and the others as self serve users. Five industries have their own pages: SaaS, HR tech, edtech, healthtech and fintech. Its home page names its audience as high performing in house legal teams. No law firm segment is addressed, nothing covers government or public sector use, and no contract types or matters are named as unsupported. Coverage is described by industry and internal function rather than by area of law.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Docusign CLM
Opt out

Section 4.1 of the AI Attachment for Docusign Services, version 8 July 2026, grants Docusign a perpetual license to use customer data and AI output, after anonymizing and aggregating it, to train models and improve its services generally. The attachment's applicability table says customers on a Master Services Agreement consent to that training for Docusign CLM. Section 4.2 lets the customer opt out at any time with a toggle in the product, on a going forward basis, and Docusign keeps the training data created before the opt out with no duty to delete it.

The AI Trust page describes the same program as consent based. Customers whose subscription began before 8 July 2026 are pointed to earlier versions of the terms.

SpotDraft
Terms silent

Nothing on SpotDraft's home, pricing or security pages, including the security page's data security, infrastructure security, product security and risk governance sections and its five question FAQ, addresses whether customer contracts, prompts or outputs are used to train any model, by SpotDraft or by an underlying model provider. The nearest statements are that the AI is embedded in SpotDraft, operates in a context specific to the customer and follows the customer's rules, and that the platform is risk free AI on the customer's terms, none of which is a commitment about training.

No model provider is named. The trust center was not available to read, so the silence is an absence on the published pages with a retrieval limit on the trust center.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Docusign CLM
Customer controlled, no zero option

Section 3.1 of the Service Schedule for Docusign CLM, version 15 September 2025, keeps each stored document, including the customer data in it, for the subscription term or until the customer deletes it, and lets the account administrator set a different retention and deletion schedule. After the term, documents can be retrieved for 90 days through professional services, and Docusign may then delete them (3.2). The schedule covers stored documents rather than prompts as such.

AI output is Customer Confidential Information under the AI Attachment, which also lets Docusign keep anonymized training data derived from content with no duty to delete it. What the Azure and Google model services keep from a prompt is not stated.

SpotDraft
Not addressed

No retention period for contracts, prompts or generated outputs is published on SpotDraft's home, pricing or security pages. Retention appears only as a heading within the security page's data handling practices, where data classification and retention are named together and the text describes classification into public, company confidential, customer confidential and personal tiers without stating how long anything is kept.

Secure data disposal is listed among the data center measures without a period attached. No retention setting the customer can configure is described.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Docusign CLM
Own model, documented

CLM has its own permission model built on folders. A Docusign employee's guide on the Docusign Community sets out six levels, from No Access, the default for all content, through View, View and Create, View and Edit, and View, Edit and Delete, to full control with Set Access. Security can be set for a user, a permission profile or a user group, and folders inherit their parent's security unless set explicitly. CLM administrators can see all content whatever the folder settings.

The CLM page adds granular permissions controls and an audit trail of who did what and when. Nothing published says how AI review, summaries or search apply folder permissions when they run.

SpotDraft
Own model, documented

Separation is documented at two levels. Between customers, SpotDraft's security page states that customer data is logically separated within a secure multitenant infrastructure, and adds that each contract is protected with a unique encryption key held in HashiCorp Vault backed by Google Cloud KMS, a finer control than isolation at tenant level alone. Within a customer, roles and permissions are described as fully customizable and scoped by contract type, organizational entity and department, with permissions at contract level ensuring documents are visible only to authorized personnel without manual sharing.

How retrieval and the AI features apply those permissions at query time is not published, so whether a model answering a question respects the same boundaries is not stated. The buyer is an in house department, so separation at tenant and entity level is the relevant test.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Docusign CLM
Notice committed

Section 11.2 of the Master Services Agreement, version 14 November 2022, requires prompt written notice before a compelled disclosure of confidential information, unless legal process forbids it, and cooperation in seeking a protective order. The Data Protection Attachment adds prompt notice of any government request about personal data. Docusign's law enforcement page says it notifies customers when their data is subject to disclosure, withholds notice only under a signed nondisclosure order or a statute that bars it, and cannot decrypt agreement contents at rest.

Docusign prepares an annual transparency report on requests and makes it available to data protection authorities on request; it is not published. Section 2(d) of the CLM Service Schedule says Docusign is not responsible for producing customer documents to any third party.

SpotDraft
Not addressed

Nothing on SpotDraft's home, pricing or security pages addresses what happens if a third party, law enforcement agency or court requests customer data, and no commitment to notify the customer is published. No transparency report exists. The security page states that third party vendors handling scoped data are bound by confidentiality, audit and incident response protocols, and that fourth parties such as backup providers and subcontractors have no access to scoped systems or data, but neither addresses compelled disclosure.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Docusign CLM
Sources named, basis unstated

CLM works from the customer's own contracts, templates and clause library, and does not retrieve case law or legislation. For the models behind it, Docusign describes Iris as trained on decades of contract data. Section 6.1 of the AI Attachment names the classes of training data for Docusign's own models, customer data authorized for training, publicly available data and data licensed from third parties, and warrants that to its knowledge Docusign holds sufficient permissions for them. It names no specific source or license and excludes the data third party providers used for their own models.

SpotDraft
Sources named, basis unstated

The working corpus is the customer's own contract set and is identified as such: SpotDraft's repository is described as centralizing all of a customer's contracts and automatically pulling over a thousand types of contract metadata using AI, and the AI is described as operating in a context specific to the customer and following the customer's rules. No external legal corpus is claimed and the product does not retrieve primary law, so the usual jurisdiction and coverage questions do not arise. No training corpus for the models themselves is described, no source is named and no license or rights basis is given.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Docusign CLM
Not addressed

Docusign CLM manages a customer's own agreements and does not cite case law or legislation, so a citator is not part of the product. Nothing on the CLM page, the AI-Assisted Review page or the AI Trust page addresses checking authority for later history. The nearest question for this product is whether extracted terms and clause library positions stay current when an agreement is amended or a policy changes, and nothing published describes how CLM detects that.

SpotDraft
Not addressed

Nothing on SpotDraft's home, pricing or security pages addresses whether legal authority is checked for later history, and no citator, treatment signal or currency check is published. The platform manages a customer's own contracts rather than retrieving case law or legislation, so a citator is not part of what it sells. Sidebar is described as helping users stay ahead of regulatory change with AI agents, which concerns the currency of regulation rather than the standing of cited authority, and no source or verification method is published for it.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Docusign CLM
Not addressed

No path for declining to answer is documented for CLM's AI features, and no confidence or grounding score is published for extraction, review or summaries. Section 6.2 of the AI Attachment warns that AI output may be incorrect or otherwise undesirable and makes the customer responsible for reviewing it, and the AI Trust page describes content filtering for harmful outputs. Neither says what AI-Assisted Review or the question and answer feature does when a playbook or the repository does not cover what is asked, or how a doubtful extraction is marked before it feeds a report, a renewal alert or a workflow rule.

SpotDraft
Not addressed

No path for declining to answer is documented on SpotDraft's home, pricing or security pages, no confidence or grounding score is published, and nothing states what the product does when the customer's contract set or playbook does not cover the question put to it. Published material addresses configuration rather than uncertainty, describing AI that operates in the customer's context and follows the customer's rules.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

Docusign CLM
None located

The AI Hallucination Cases database maintained by Damien Charlotin, which records court decisions worldwide that address hallucinated AI content and the tool involved where known, has no entry naming Docusign, Docusign CLM, Iris, SpringCM or Lexion, in the tool field or anywhere in the case text. This is a statement about the public record rather than a finding about the product, and it covers fabricated content only. CLM manages commercial agreements rather than producing court filings, so its output does not ordinarily reach a brief.

SpotDraft
None located

The AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, together with 2026 sanctions trackers and trade press summaries, records no court order, opinion or disciplinary record naming SpotDraft. This is a statement about the public record rather than a clearance, bounded by what that database covers.

The product manages commercial contracts for in house teams rather than producing court filings, so its output does not ordinarily reach a brief.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Docusign CLM
Generic reference

Section 6.2 of the AI Attachment for Docusign Services, which governs CLM's AI features, states that neither Docusign, the AI Services nor AI output provide the customer with legal advice, and makes the customer responsible for reviewing output for accuracy and suitability, including through human review. No bar opinion, ethics rule or professional conduct guidance is named on the CLM page, the AI-Assisted Review page, the AI Trust page or in the agreements.

Docusign's compliance work covers data, security and sector regimes, including ISO, SOC, PCI DSS, FedRAMP, GovRAMP, DoD Impact Level 4, HIPAA and 21 CFR Part 11, which bind Docusign as a provider rather than a lawyer using the product.

SpotDraft
Named guidance addressed

SpotDraft's home page names two ethics guidance documents from two jurisdictions. One is the California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law, dated November 2023. The other is the American Bar Association's Formal Opinion 512 on generative AI, dated July 2024. Both are given with issuer and date. SpotDraft says its AI features are designed with attention to the principles in each, for responsible and secure use across contracting workflows.

What is published is a statement of attention to principles, not a mapping of which duty each product control meets, and no other jurisdiction's guidance is addressed.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Docusign CLM
Outside the fee relationship

CLM is bought by enterprise legal, sales, procurement, human resources and customer experience teams to run their own contracting, and the named customers are companies such as T-Mobile Wholesale, Genuine Parts Company, Vestwell and iCIMS rather than law firms. No client bill sits in the loop. Docusign's claims are aimed at the buyer's own cost and time: an 83 percent boost in speed and efficiency, a 449 percent return on investment, a 90 percent cut in time to generate a sales contract and 72 to 80 percent saved on contract reviews. Nothing published addresses fee treatment of AI assisted work for a firm that bills a client.

SpotDraft
Savings claims only

SpotDraft's public materials are framed around speed and cost removed: two times faster closings, 65 percent lower cost, 70 percent less review time, and contracts reviewed 15 times faster with VerifAI. No record of AI assisted work for each matter intended for fee purposes, and no guidance on billing, fee or disclosure treatment, is published on the home, pricing or security pages. The contract level audit logging SpotDraft describes, which traces changes by both the creator and the counterparty and retains every version, could support such a record, but nothing presents it for that purpose.

The buyer is an in house department rather than a firm billing a client, so the question lands on internal cost, and it is not addressed.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Docusign CLM
Disclosure pack published

Docusign's subprocessor list, last updated 18 September 2026, is published as a web page and a download with a separate section for CLM. It names each hosting supplier and each AI supplier against the feature it powers, with countries and a contact address, and changes go to an RSS feed with an email objection route. The Data Protection Attachment, the AI Attachment, the Master Services Agreement and the CLM Service Schedule are all published without a login, and the certifications page and the public CSA STAR CAIQ cover security.

A customer answering its own client's questions about AI vendors can forward these documents and name every model provider that touches CLM content.

SpotDraft
On request only

No subprocessor list is published and no model provider is named on SpotDraft's home, pricing or security pages, so which third parties see contract content is not stated. No consent or notification material for clients is published. Assurances about third parties stand in for identifying them: vendors handling scoped data are said to be bound by confidentiality, audit and incident response protocols, and fourth parties such as backup providers and subcontractors are stated to have no access to scoped systems or data.

A trust center is linked at trustcenter.spotdraft.com, and a request route for security documentation appears on the security page.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Docusign CLM
Partial record

CLM keeps an audit trail of who did what and when and detailed version control across drafts, so the history of a contract can be reconstructed. Nothing published says whether an AI-Assisted Review suggestion, an AI drafted clause or an AI extraction is marked as machine generated in that history, or whether the audit trail records which model produced it. No export built for disclosing AI involvement, and no disclosure template, is published.

CLM output is a contract, a report or an obligation record rather than a court filing, so the likely audience for such a record is a counterparty, an auditor or a regulator.

SpotDraft
Partial record

SpotDraft's security page says audit logging traces user actions at contract level. It captures signing and creation events and the trail of changes by both the creator and the counterparty, and every version of a contract is kept, which covers what changed, by whom and when. No model is named, so which system produced a passage cannot be established, and nothing in the log, as described, separates an AI change from a human one. No export built for a court disclosure or AI use certification is published.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Signals neither addresses in public material
  • Good Law Verification
  • Refusal and Uncertainty Behavior

Which one fits

Choose Docusign CLM if

  • You need contract management for government or defense work. Docusign CLM's government editions keep customer data inside Docusign's FedRAMP Moderate boundary, a DoD Impact Level 4 edition runs over NIPRnet, and the FedRAMP, GovRAMP and Impact Level 4 authorizations all name CLM. Docusign's certifications page adds ISO 27001, SOC 1 and SOC 2 Type II audits of all production operations and PCI DSS 4.0.
  • A client or regulator asks which AI providers touch your contracts. Docusign's subprocessor list has its own CLM section naming Azure OpenAI for AI-Assisted Review and agreement summaries, Azure AI Document Intelligence for extraction and Google for the Analyzer service, each with the countries it runs in, and changes go to an RSS feed with an email objection route.
  • Sales, procurement and legal all need to work in one system. Docusign CLM generates contracts from Salesforce data, creates supplier agreements from SAP Ariba, keeps contracts in sync with Coupa, and routes them through workflows built from more than 100 preconfigured steps. Comments sync between Word, Google Docs and CLM, and Slack carries review notifications.

Choose SpotDraft if

  • Your data has to stay in a region you choose. SpotDraft stores personal data in the customer's selected region across the US, the EU, India and the Middle East, runs on Google Cloud in the Netherlands, and gives each contract its own encryption key held in HashiCorp Vault backed by Google Cloud KMS.
  • Your general counsel wants the ethics guidance named. SpotDraft says its AI features are designed with attention to the California State Bar's practical guidance on generative AI of November 2023 and to ABA Formal Opinion 512 of July 2024. Its Terms of Use also state that SpotDraft gives no legal advice.
  • You want implementation inside the price. SpotDraft includes workflow and integration setup and migration of old contracts at no extra fee, publishes a six week rollout plan, and lets the customer choose pricing by users or by contract volume. Every customer also gets a dedicated customer success manager and support around the clock.

In summary

Docusign CLM

Docusign CLM is Docusign's enterprise contract lifecycle product, covering generation from templates and Salesforce data, a clause library, workflows built from more than 100 preconfigured steps, negotiation, eSignature and a repository with obligation reporting. Its AI, branded Iris, reviews agreements against playbooks, extracts data points with more than 100 pretrained models and summarizes agreements. According to the AI Legal Index, its most detailed published material is its paperwork and supply chain: a CLM service schedule with retention terms, government authorizations that name CLM, and a subprocessor list that ties each AI supplier to a CLM feature. Its AI attachment licenses training on anonymized customer data unless the customer opts out, and no price or accuracy measure is published.

Source: AI Legal Index, 2026

SpotDraft

SpotDraft is a contract lifecycle platform for in house legal teams, covering creation from templates, conditional approval workflows, negotiation and redlining in Word, Slack or the browser, and built in eSignature. Its repository extracts more than a thousand metadata types, VerifAI reviews contracts in Word, and Sidebar agents answer questions and track regulatory change. According to the AI Legal Index, SpotDraft's clearest published positions are on residency and professional guidance: personal data stays in a customer selected region across the US, the EU, India and the Middle East, each contract has its own encryption key, and its AI features cite the California State Bar's guidance and ABA Formal Opinion 512. It names no model provider and publishes no training position or price.

Source: AI Legal Index, 2026

Questions buyers ask

Docusign CLM vs SpotDraft: which is better for an in house legal team?

SpotDraft is built for in house legal teams in the mid market, with legal as the owner and sales, finance, HR and procurement as self serve users, implementation included and personal data held in a region the customer picks. Docusign CLM is an enterprise system sold to several departments at once, with procurement connectors for SAP Ariba and Coupa, government editions and a full set of published agreements. Neither publishes a price. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Does Docusign CLM train AI on customer contracts?

Its AI attachment, version 8 July 2026, licenses Docusign to use CLM customer data and AI output, once anonymized and aggregated, to train models, and lets the customer opt out going forward with a toggle in the product. Training data created before an opt out is kept. Customers whose subscription began before 8 July 2026 are pointed to earlier versions of the terms. SpotDraft publishes no position on training, by SpotDraft or by a model provider. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Which AI models do Docusign CLM and SpotDraft use?

Docusign names its AI suppliers for CLM: Microsoft's Azure OpenAI Service for AI-Assisted Review and summaries, Azure AI Document Intelligence for extraction, Google for the Analyzer service, and its own Lexion unit for a legacy version of review, without model versions. Each entry lists the countries where it runs. SpotDraft names no model or provider, publishes no subprocessor list and describes its AI as built into the product. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

What do Docusign CLM's and SpotDraft's agreements say about liability?

Docusign's Master Services Agreement caps liability at fees paid in the twelve months before the first event, keeps indemnities, confidentiality breaches, gross negligence and willful misconduct outside the cap, and indemnifies the customer against confidentiality and infringement claims. Its AI Attachment disclaims warranties on AI output. SpotDraft's published Terms of Use cap its liability at one hundred Indian rupees and contain no vendor indemnity, and an enterprise customer may sign a master agreement that is not published. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

What do Docusign CLM and SpotDraft both leave unpublished?

Neither publishes an accuracy measure for AI review or extraction, neither publishes a price, and neither addresses legal privilege or work product. Both keep audit trails of changes, and neither marks AI generated text in a record a customer could export. Neither publishes a confidence score for AI output or says what its AI does when a playbook or the repository does not cover a question. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Disclosure

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything on it comes from public material on the dates shown. How the index grades.

Docusign CLM and Docusign Agreement Manager are separate products from the same company, and this page covers CLM, which runs under its own service schedule. Docusign's AI attachment applies to CLM customers on a master services agreement and treats them as consenting to training on anonymized, aggregated data unless they switch it off, and customers who subscribed before 8 July 2026 are pointed to earlier terms. SpotDraft's published Terms of Use, version 2.3 of 21 February 2024, cap its liability at one hundred Indian rupees and contemplate further terms for other services, so an enterprise customer may sign a master agreement that is not published. Neither vendor reviewed this page.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
October 8, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746