Draftwise vs Spellbook: how they compare in 2026
Draftwise and Spellbook both sell AI drafting to transactional lawyers and both live inside Microsoft Word. Spellbook sits in the top two bands on twelve of fifteen axes, Draftwise on six, and the gap is disclosure about the AI itself. Spellbook names the models on its own home page, GPT-5 and Claude Opus, names OpenAI and Anthropic as the providers, states the zero data retention agreements negotiated with each and what they mean technically, names AWS as its cloud with Canada and the United States as processing locations, and publishes a full subprocessor list. On the Draftwise record the index located no model, no provider, no architecture beyond the phrase agentic AI, and no subprocessor list. Draftwise answers on the boundary rather than the model, taking an A on deployment for a private cloud in the customer's choice of AWS, Azure or GCP where the firm's own IT holds the encryption keys and no data leaves the VPC by default, alongside on premise installation.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the product and there is no conventional system underneath, because the system of record belongs to the customer. Draftwise connects to the firm's existing document management system and the machine learning is what turns that corpus into work: the product page describes agentic AI that performs deep research across the DMS, interprets redlines and comments, understands version history and edits entire documents, analyses millions of documents in real time to select relevant precedent, builds playbooks automatically from existing precedent and guidance rather than by hand, and auto-curates contract collections in the background with no setup. The Legal Ontology platform announced August 2026 is a structured intelligence layer over the same material. Remove the models and what remains is the firm's own DMS, which Draftwise does not sell.
The models are the product. Review, Draft, Ask, Compare and the Associate agent are all generative capabilities delivered through a Word add in that exists to carry them. The company pivoted its whole business to generative AI in 2022, rebranding from Rally to Spellbook. Remove the models and there is no product, only an empty add in.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted repeatedly and measured nowhere. The claims are confident and unquantified: lawyer-quality edits described as precise and accurate, drafting delivered with total confidence, and the Legal Ontology page headed with answers you can trust. Searched the home page, the product page, the FAQ, the terms of service and the privacy policy on 31 Aug 2026 and located no accuracy figure, no hallucination rate, no benchmark, no described test set and no published evaluation of any kind. What does support the output is provenance rather than measurement: drafting is grounded in the firm's own precedent, which a lawyer can open in their own DMS, and negotiation positions are checked against EDGAR filings, a named public corpus. No retrieval method is described, no citation mechanism is documented, and nothing addresses what the system does when the precedent does not support a position.
Grounding is real and documented with the method described, short of published figures. The vendor states its architecture explicitly and unusually: it does not fine tune, it connects general purpose models to proprietary market data and requires them to fetch and cite rather than rely on learned patterns, on the stated reasoning that putting documents into a model's long term memory encourages hallucination. Compare benchmarks a clause against a stated corpus of more than 2,300 contract types and explains why differences matter, and Ask is published as producing answers with citations. The vendor also publishes educational material on hallucination risk aimed at its own users. Not located as of 29 Aug 2026: any accuracy figure, hallucination rate, test set or evaluation for its own product. Worth noting the CEO has publicly questioned third party benchmarking studies of legal AI tools while the company publishes no measurement of its own.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Autonomy is claimed prominently and no oversight mechanism is published. The product is described as a personal drafting agent that drafts, reads, redlines, researches and reasons like the buyer's best team member, as agentic AI built to draft, and as editing entire documents in minutes, with collections curated in the background requiring no setup and no maintenance. The one real review surface is implicit rather than described: the product operates as a Microsoft Word add-in, so redlines land in a document a lawyer opens, and the vendor says they are easy to review and negotiation-ready. Searched the home page, the product page, the FAQ, the terms and the privacy policy on 31 Aug 2026 and located no statement of what the system does unattended, no threshold at which it stops, no described approval or review point, and nothing on what happens after an output is wrong.
A real written commitment that the models work alongside a supervising lawyer, with a genuine review surface, short of the full control structure. Associate is described as the first AI agent that can work through multi document legal matters with your oversight, which states the oversight position in the product's own headline claim. The delivery model is itself the review mechanism: output arrives as tracked redlines inside a Word document the lawyer accepts or rejects clause by clause, which is a more concrete control point than most of this market publishes. Not located as of 29 Aug 2026: what the agent decides on its own within a matter, the threshold at which it stops, and what happens after an output is wrong.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
An unusually deep roster of named customers speaking on the record, with no figures attached. Attributed quotes come from Vedika Mehera, Director of Orrick Labs, and Wendy Butler Curtis, Chief Innovation Officer at Orrick; Naveen Pai, Chief Knowledge Officer, and Joe Green, Chief Innovation Officer, both at Gunderson Dettmer; Oliver Neasham, Managing Associate at Mishcon de Reya; Cameron Reeves, Partner at Mayne Wetherell; and Franck Sekri, Partner at Sekri Valentin Zerrouk. Zac Padgett, a partner at Orrick, describes a specific task in detail, reviewing comparable deal documents and surfacing a market-standard percentage during the closing hours of a deal. A 14-logo strip adds Katten, McGuireWoods, Womble, Chapman, Maddocks, Borenius and Bronstein Zilberberg, and dedicated case study pages exist for Orrick, Gunderson Dettmer and Mishcon de Reya. What is missing is measurement: every quote is qualitative, no figure of any kind is attached to any customer on the pages read, and no deployment date or method appears. The case study pages were not opened on 31 Aug 2026, so the figures and dates limb is rebuttable.
Real deployment evidence with substance, short of the full A bar. Multiple named customer stories are published with individually attributed detail, including Dropbox with a named associate general counsel on video, Panasonic on saving three weeks building an RFP process, KMSC Law with a named partner, Alturas Capital Partners, Elevare Law and Westaway with a named managing partner. The logo wall names large enterprises including eBay, Fender, Crocs, Franklin Templeton, Hapag Lloyd, Valentino and DirecTV, and the vendor states more than 4,500 legal teams across 80 plus countries. Figures appear but attach loosely: a named partner states Spellbook helps him bill an extra hour a day, and Panasonic's three weeks is a stated saving. Not located as of 29 Aug 2026: a dated case study carrying figures with a method a reader can assess.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Strong architecture, strong assertions, and nothing a buyer can hold the vendor to. The assertions are specific: the FAQ states that the firm retains complete control of its data and that Draftwise will not share or disclose any data or firm intellectual property in any form, including trained intelligence or aggregates, which is an unusually explicit formulation. The architecture backs it, since private cloud and on-premise deployments leave encryption keys and audit control with the firm's own IT and no data leaves the VPC by default. Three things hold this at C. The only agreement published on the property is a website terms of use, last updated 11 August 2025 and scoped to the Site, so there is no customer agreement a buyer can read before signing; its clause 8 instead permits Draftwise to access, store, process and use information provided, and clause 9 makes Submissions non-confidential and Draftwise's sole property. The no-training statement is qualified on its face to public models, which leaves the vendor's own models unaddressed on a product built to learn a firm's positions. And privilege and work product are not addressed anywhere on any surface read on 31 Aug 2026, on a product whose corpus is a law firm's client matter files.
Substantive published commitments, short of the full picture. Zero data retention agreements are stated as negotiated with both named model providers, OpenAI and Anthropic, with the mechanism described precisely: customer data in requests and responses is not persisted and exists only in memory to process a request. That is a stronger and more specific statement than most of this market publishes. Encryption, SSO through Microsoft Entra with enforced MFA, and audit controls are stated. Two gaps hold this off an A. Attorney client privilege and work product handling is not addressed directly in located material. Segregation between users or matters inside a customer is not documented, and for a firm facing product the applicable standard under the amended band is matter level walls.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Nothing published on the advice line. Searched the home page, the product page, the FAQ, the terms of service, the privacy policy and the trust centre landing page on 31 Aug 2026. No statement that Draftwise is not a law firm and does not provide legal advice was located, no professional responsibility or ethics page exists, no bar or ethics guidance is named including ABA Formal Opinion 512, and nothing addresses a lawyer's competence or supervision duties when using the tool. The website terms of use disclaim warranties and accuracy in general commercial language but say nothing about legal advice. The buyer here is a lawyer rather than a consumer, which lowers the unauthorized practice exposure relative to a public-facing product, but the axis asks what the vendor has published about the line between tooling and advice, and the answer is nothing.
The audience is unambiguous, transactional lawyers at firms and in house teams, with a signup form that asks a prospect to confirm they are a legal professional and offers no path for non lawyers. The vendor publishes educational material engaging with a lawyer's duty of competence and the obligation to verify AI output. What was not located, after checking the site, the solutions pages, the published terms of service and the learning hub on 29 Aug 2026, is a published position on the advice line, on supervision duties as distinct from competence, or on jurisdiction limits, despite the product being sold in more than 80 countries.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
No governance position for model behaviour was located. Searched the home page, the product page, the FAQ, the terms of service, the privacy policy and the trust centre landing page on 31 Aug 2026. Nothing names an internal owner accountable for model behaviour, describes what is tested before release, publishes a responsible AI framework, or discloses anything about uneven output across matter types, counterparties or practice areas. The home page carries a tab labelled Ethics, which is the closest thing on the property, and its content is a single confidentiality claim that customer data never trains public models. Confidentiality is a different subject from governance over model behaviour and does not carry here. The published Information Security Policy and the security certifications likewise address information security rather than AI governance.
A published governance framework with real substance and independent validation, short of testing results or a named owner. The vendor commissioned and publishes an independent legal opinion from CMS Law on its classification under the EU AI Act, states it was assessed as low risk, and makes the full opinion letter downloadable from its trust portal along with the controls implemented for that classification. Commissioning an outside law firm to classify your own AI system and then publishing the letter is a governance artifact rather than a principles page, and no other vendor on this index has published one. Not located as of 29 Aug 2026: a named internal owner of model governance, published pre release testing results for model behaviour, or any disclosure about uneven output across matter types, parties or populations.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published material with two specific gaps. Draftwise publishes an Information Security Policy and a Data Retention Policy as separate documents alongside the privacy policy, which is more than most of this market offers openly. The FAQ gives real operational detail rather than assurances: AES-256 at rest and HTTPS over TLS 1.2 or 1.3 in transit, audit logging through AWS CloudWatch collected in near real time with rules-based and composite alerting and anomaly detection on containers and applications, and logs retained for up to two years. Draftwise Inc. is certified under the EU-U.S. Data Privacy Framework with the UK Extension and the Swiss-U.S. framework, with JAMS named as the independent recourse mechanism and FTC enforcement jurisdiction acknowledged. Against that, no named subprocessor list exists anywhere; the privacy policy lists categories of recipient only. No incident response or breach notification practice was located on any surface. And the privacy policy's own section headed how long data is stored contains the text of the following section on changes to the policy instead of a retention answer, so the document that should answer retention does not. The separate Data Retention Policy was not opened on 31 Aug 2026, so that last point is rebuttable.
Substantive published policy covering most of the ground, short of the full set. Published and specific: zero data retention at the model layer with both providers named and the mechanism described, a complete third party subprocessor list with processing locations in the trust portal, AWS named as primary cloud provider, storage and processing locations stated as Canada and the US, access control through Microsoft Entra so a customer enforces its own authentication and MFA policy, breach notification addressed through implemented HIPAA Breach Notification rule controls with signed business associate agreements downloadable, and a published vulnerability disclosure policy. What holds this off an A is deletion, which the A band requires alongside the rest: searched the security page and FAQ, the published terms of service, the privacy policy and the trust portal entry point on 29 Aug 2026 and located no stated retention period for the vendor's own storage of documents, prompts and outputs, no customer control over that window, and no deletion commitment. This record's own prompt-and-output-retention signal row records the same gap.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Liability is addressed only through a limitation clause, and the clause governs the website rather than the product. The document published as Terms of Service, last updated 11 August 2025, is a website terms of use: it is expressly made concerning access to and use of the Site. Within it, clause 17 disclaims all warranties including any representation about accuracy or completeness, clause 18 excludes liability for direct, indirect, consequential, exemplary, incidental, special and punitive damages arising from use of the Site with no cap stated, clause 19 requires the user to indemnify Draftwise, and clause 20 disclaims all liability for loss or corruption of transmitted data. No indemnity running to the customer, no warranty on output and no insurance position was located. No master subscription agreement or product terms were located anywhere on the property, so the enterprise buyer's actual allocation of loss is negotiated rather than published. This is a C rather than a D because a limitation of liability is published and readable in advance, and clause 17 extends its disclaimer to the services as well as the Site.
Liability is addressed only through published terms a buyer can read in advance, without a position on the exposure the product creates. Terms of service, a privacy policy and a refund policy are all published openly, which is more than several vendors on this index manage, and the refund policy is an unusual published commercial commitment. But searched those documents, the security page and the trust portal entry point on 29 Aug 2026 and located no indemnity running to the customer for third party claims arising from output, no warranty on output, no stated liability cap figure and no insurance position. The vendor will sign a business associate agreement for protected health information, which is a regulatory undertaking rather than recourse for wrong output.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations into the systems that matter for this buyer, named but not documented. The product page names iManage and NetDocuments alongside Microsoft Word, EDGAR and a Microsoft Partner mark, which is the right set for a product sold to transactional law firms, and the function is described rather than merely asserted: Draftwise connects to the firm's complete deal history including documents, clauses and tags, performs deep research on the DMS, follows version history, and auto-curates contract collections from the moment the DMS is connected. The privacy policy confirms the product operates as an installable Microsoft Word add-in. What is absent is depth an implementer could use: no integrations page, no statement of what syncs in which direction, no description of what a firm must configure, and no developer or API reference index was located on 31 Aug 2026. One detail on that page is worth a buyer's notice: one logo in the integrations strip is an unreplaced placeholder, published with the filename and alt text reading simply Something.
Real integrations exist and are documented, short of depth. The product is delivered as a Microsoft Word add in and also runs in Google Docs, which is the deepest possible integration into the surface where transactional drafting actually happens rather than a connector alongside it. A dedicated integrations page is published, and the ACM product describes contracts arriving from email, Slack and Salesforce. Authentication integrates with Microsoft Entra. Not located as of 29 Aug 2026: legal specific document management connectors such as iManage or NetDocuments, and per integration documentation describing what moves in which direction and what an administrator configures.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The most complete deployment disclosure read in this pull, published openly on the FAQ rather than held for a security questionnaire. Three routes are described with the trade-offs spelled out. A private cloud dedicated to the firm in the customer's choice of AWS, Azure or GCP, where the firm's own IT maintains encryption keys and audit control, Draftwise retains only limited access to support the deployment, no data leaves the VPC by default, and network access can be restricted to the firm's IP subnets. Deployment into the firm's existing cloud infrastructure through a helm chart and private image registry, VM images or Linux binaries, administered either by Draftwise or self-serviced by firm IT. Or an on-premise install, again with limited vendor access for upgrades and support. The privacy policy adds that products are typically deployed behind the customer's firewall on servers the customer's IT department manages, and that Draftwise consequently processes minimal information in its own systems. Residency follows from the customer's choice of provider and estate rather than from a vendor region list. One tension a buyer should resolve: if no data leaves the VPC by default, where the language models run relative to that boundary is not explained anywhere, and no model provider is named.
Deployment model is stated clearly with partial residency detail. The vendor publishes that AWS is the primary cloud provider and that customer data is stored and processed in data centres in Canada and the US, with a full list of subprocessors and their locations in the trust portal. That is a real residency statement naming both jurisdictions. What is missing is customer choice and tenancy: no selectable region, no single tenant or private deployment option, and no statement of the tenancy model was located as of 29 Aug 2026. For a vendor selling into more than 80 countries, the absence of an EU or UK processing option is a live buyer question the site does not address.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certifications are claimed, a trust centre exists, and the property contradicts itself on what is actually held. The home page states that Draftwise is SOC 2 Type II and ISO 27001 certified and GDPR compliant. The FAQ, on the same property, states that Draftwise has been certified for Cyber Security Essentials Plus, a UK cybersecurity standard, and is SOC 2 compliant. Those are three separate discrepancies: ISO 27001 appears on one page and not the other, Cyber Essentials Plus appears on the other and not the first, and compliant is not the same claim as certified. A Vanta-hosted trust centre at security.draftwise.com is linked openly from the footer and is credited here as reachable, since its body renders client side and could not be read by the index, which is a retrieval limit on this side rather than a gap on the vendor's. What could not be established from any readable surface on 31 Aug 2026 is the substance: no auditor is named, no coverage period or report date is given, no audit scope is described, and although the FAQ asserts routine security evaluation it names no penetration testing partner and publishes no summary. Further encryption and audit questions are directed to a sales address.
Certification is real and stated with an open route to the evidence, short of published scope. SOC 2 Type II and HIPAA are both named, and the badges on the home page link directly to named, dated resources in the trust portal rather than sitting as decorative images, which is a materially better pattern than most of this market and is why this is not a C. The trust portal is at a stable URL and carries downloadable documents including business associate agreements and the EU AI Act opinion letter. Under the three tier test this is a self serve request flow rather than a sales gate. What was not located as of 29 Aug 2026 is the audit coverage period, the scope, or the name of the auditing firm.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Nothing published about the model supply chain a customer inherits. Searched the home page, the product page, the Legal Ontology summary, the FAQ, the terms of service and the privacy policy on 31 Aug 2026. No model provider is named, no model or version is identified, no architecture is described beyond the phrase agentic AI built to draft, no subprocessor list exists, and there is no commitment to notify customers when any of it changes. The only reference to underlying models anywhere is the confidentiality claim that customer data never trains public models, which acknowledges that third-party models exist without saying whose are used, where they run, or what they see. That gap is sharper here than it would be elsewhere, because the deployment story turns on data not leaving the firm's own VPC, and a buyer cannot reconcile that with an unnamed external model provider. The FAQ names AWS, Azure and GCP as cloud partners, which is infrastructure rather than model supply.
The models underneath are named, their providers identified, where they run is stated, and the commercial terms binding them are disclosed. The vendor names GPT-5 and Claude Opus as the models powering the product on its own home page, names OpenAI and Anthropic as the providers, states the zero data retention agreements negotiated with each and what that means technically, names AWS as the primary cloud provider, states processing locations as Canada and the US, and publishes a complete third party subprocessor list at a stable trust portal URL. Naming the specific model versions in marketing copy is rare and is what a customer inheriting the dependency actually needs. Short of the very top only in that no explicit commitment to notify customers before the model supply chain changes was located, though the subprocessor list is the mechanism through which such a change would surface.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. Searched the main navigation, the footer, the home page, the product page, the FAQ, the terms of service and the privacy policy on 31 Aug 2026. There is no pricing page, no tier structure, no per-seat or per-matter unit, no indication of what implementation adds, and every call to action across the property is to book a demo. The website terms of use confirm only that fees may apply and that payment is accepted by credit, wire or ACH in US dollars, with prices subject to change at the vendor's discretion, which is payment mechanics rather than a published rate. Nothing was located that would let a prospective buyer form any view of cost before entering a sales process.
Pricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not. The pricing page publishes two named tiers, Law Firms and In House Teams, itemises what each includes, states that pricing is structured around the number of team members on a licence, and confirms a 7 day free trial with extended trials available for larger organisations. Free access for academic institutions is published. So a buyer learns the unit of charge and the packaging without a sales call. No figure appears at any tier, and the only route to one is a demo booking. Checked the pricing page, the home page and the footer on 29 Aug 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is documented with real precision and the boundaries are never stated. The property segments by firm size with dedicated Big Law and Mid Law pages, and by in-house vertical with six named pages: advertising technology, defense technology framed around FAR and DFARS alongside commercial work, investment funds, life sciences and pharmaceuticals, real estate, and SaaS. The customer roster evidences that breadth rather than merely claiming it, spanning US firms including Orrick, Gunderson Dettmer, Katten, McGuireWoods, Womble and Chapman, and non-US firms including Mishcon de Reya in the UK, Maddocks in Australia, Borenius in Finland, Mayne Wetherell in New Zealand, Sekri Valentin Zerrouk in France and Bronstein Zilberberg in Brazil. Government use is touched only indirectly, through a US Government Rights clause in the website terms addressing FAR and DFARS acquisition and through the defence vertical. What is absent is any statement of where the product stops: no practice areas are excluded, no contract types are named as unsupported, and nothing addresses litigation or any non-transactional work despite the product being explicitly built for transactional practice.
Segment and practice coverage is described with substance, short of the boundaries. Two buyer segments carry dedicated pages, law firms and in house legal, and six industries have their own: energy, healthcare, financial services, technology, manufacturing, and retail and consumer goods. Firm size is addressed in the trial form from 1 to 10 through 200 plus, and the vendor states more than 4,500 teams across 80 plus countries. Practice focus is stated clearly and repeatedly as transactional and commercial legal work rather than claimed broadly, which is a real self limit. Short of an A because litigation appears as an option in the signup form while nothing on the site describes litigation support, and because no statement of which practice areas or firm sizes the product is not built for was located.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The home page states that customer data never trains public models and adds that this is not in the vendor's code, and the FAQ states that the firm retains complete control of its data and that Draftwise will not share or disclose any data or firm intellectual property in any form, including trained intelligence or aggregates. Read as published, the commitment is to non-disclosure and to keeping data out of public models; neither formulation addresses training the vendor's own or a firm-specific model, on a product whose stated design learns a firm's positions from its precedent. No training term was located in any published agreement, because the only agreement published on the property is a website terms of use scoped to the Site, whose clause 8 instead permits Draftwise to access, store, process and use information provided.
The vendor states plainly that zero data retention means its model providers never learn from, train on or store customer data, and the security FAQ describes the mechanism: agreements negotiated with OpenAI and Anthropic under which customer data in requests and responses is not persisted and exists only in memory to process a request. The commitment as located covers the model providers specifically and sits on a public security page and pricing page rather than in a term of the published customer agreement, which was searched on 29 Aug 2026. No separate statement was located as to whether the vendor itself trains on customer content, as distinct from its providers.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is acknowledged without a period for customer documents or prompts. The only retention figure located anywhere is for audit and monitoring logs, which the FAQ states are kept for up to two years through AWS CloudWatch. The privacy policy carries a heading asking how long data is stored, but the text beneath it is the text of the following section on changes to the policy, so the document does not answer its own question. A separate Data Retention Policy is published and linked from the FAQ; it was not opened on 31 Aug 2026, so this value is rebuttable on that document. In private cloud and on-premise deployments the customer's own IT holds the data and the keys, which may make retention a customer decision in practice, but no retention control or configurable window is described in vendor material.
At the model provider layer the answer is specific and zero: data in requests and responses is not persisted and exists only in memory. That is a real published retention position for the part of the pipeline buyers ask about most. What was not located as of 29 Aug 2026, after checking the security page, the published terms of service, the privacy policy and the trust portal entry point, is any statement of how long the vendor itself retains prompts, documents and outputs in its own systems, whether a customer controls that window, or whether deletion is available. Recorded at the middle value because retention is acknowledged and answered for one layer without a period for the other.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Segregation is asserted through the source system rather than through a separate permission model: the home page security card states that Draftwise mirrors the customer's document management system permissions. The claim is more substantiated here than the wording alone suggests, because iManage and NetDocuments are both named as integrations on the product page and the product is described as performing deep research on the DMS and auto-curating collections from it. What is not published is how the mirroring is enforced: no documentation was located on 31 Aug 2026 describing whether the source access model is applied per user at query time or synchronised on a schedule, how matter-level walls propagate, or what happens when firm permissions change. The buyer here includes large transactional law firms, so matter-level walls rather than tenant separation are the relevant test.
Searched the security page, the integrations page, the published terms of service and the trust portal entry point on 29 Aug 2026. No vendor material addresses ethical walls or segregation between users or matters. Authentication runs through Microsoft Entra, so a firm enforces its own identity policy at sign in, but that governs who can open the add in rather than what the product may retrieve per user. No legal document management integration was located whose permissions retrieval could inherit at query time. For a product sold to law firms this is the applicable standard and it is not addressed.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
The privacy policy addresses compelled disclosure directly under a heading on disclosure to public authorities, stating that Draftwise may be required to disclose personal data in response to lawful requests including to meet national security or law enforcement requirements, and committing, where permitted by law, to limit such disclosure to what is legally required. That is a minimisation commitment and it is the only obligation the vendor takes on itself. Nothing in the privacy policy, the website terms of use or the FAQ commits Draftwise to notifying the customer that a request has been received, and no transparency report was located on 31 Aug 2026, so whether the firm hears about it remains at the vendor's discretion.
Searched the published terms of service, the privacy policy, the security page and FAQ, and the trust portal entry point on 29 Aug 2026. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. This records a search across the published documents that did not surface the clause rather than a reading of every document end to end.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The corpus is identified because it largely belongs to the customer. Drafting and research run over the firm's own complete deal history, connected through its document management system, with iManage and NetDocuments named as the systems Draftwise reads. The one external source named is EDGAR, the US Securities and Exchange Commission filing system, used to benchmark negotiated positions against market. No licence or rights basis is stated for the EDGAR material and no update cadence or lag is published for either source. The product does not retrieve primary law, so questions of case law and statutory provenance do not arise in the usual form here.
The corpus here is contract market data rather than primary law, which is the right shape for a transactional product and reads differently against a signal written for case law. Coverage is quantified: Compare benchmarks a clause against a stated more than 2,300 contract types and thousands of similar agreements, and the vendor describes the architecture as fetching from proprietary market data sources and citing them. What is not published is where that market data comes from, on what rights basis it was assembled, or how current it is. Searched the Compare feature page, the clause index, the state of contracts report page and the security pages on 29 Aug 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Searched the home page, the product page, the FAQ, the terms of service and the privacy policy on 31 Aug 2026. Nothing addresses whether authority is checked for subsequent history, and no citator, treatment signal or currency check was located. The product drafts and negotiates contracts from a firm's own precedent and does not retrieve case law or legislation, so a citator is not part of what it sells. The nearest analogue is the EDGAR benchmarking feature, which tests whether a negotiating position is market-standard against filed agreements rather than whether any authority remains good law.
Searched the site, the Ask and Compare feature pages, the learning hub and the help centre entry point on 29 Aug 2026. No material was located addressing whether authority returned carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is a transactional contract product whose grounding corpus is contract market data rather than case law, so a citator is largely outside its design. The absence is recorded as found, and a reader should weigh it against what the product is for.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Searched the home page, the product page, the Legal Ontology summary, the FAQ, the terms of service and the privacy policy on 31 Aug 2026. No explicit no-answer or abstention path is documented, no confidence or grounding score was located, and nothing states what the product does when the firm's precedent does not support a requested position. Published material runs the other way, describing drafting delivered with total confidence and answers the buyer can trust, without describing the behaviour behind either phrase.
Searched the site, the feature pages, the learning hub and the help centre entry point on 29 Aug 2026. No published material describes what the product does when it cannot ground an answer, and no explicit no answer path or confidence signal exposed to the user was located. The vendor publishes a clear architectural position that models should fetch and cite rather than rely on learned patterns, which is about how an answer is grounded rather than what happens when nothing supports one.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, searched on both spellings of the product name and on the company name Draftwise Inc., alongside 2026 sanctions trackers and trade press summaries. This is a statement about the public record on the date shown rather than a clearance, and it is bounded by what that database covers. The product drafts and negotiates transactional documents rather than producing court filings, so its output does not ordinarily take the form of citations in a brief.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note that this vendor publishes its own editorial content about AI hallucination sanctions, which surfaces in searches for its name and is not a record about the product. Note also that the product is transactional rather than litigation facing, so its output is less likely to reach a court filing in the first place.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Searched the home page, the product page, the FAQ, the terms of service, the privacy policy and the trust centre landing page on 31 Aug 2026. No engagement with any bar or ethics guidance was located, including ABA Formal Opinion 512, US state bar guidance, and Solicitors Regulation Authority or Law Society material despite UK, Australian, New Zealand, French, Finnish and Brazilian firms appearing on the customer roster. No professional responsibility page exists and no ethics opinion is named anywhere. The tab labelled Ethics on the home page carries a confidentiality claim about training rather than any reference to professional obligations.
Public materials refer to professional responsibility in general terms without naming guidance. The vendor publishes substantial educational content on hallucination risk that engages with a lawyer's duty of competence and candour to the court and the obligation to verify AI output, and it is named exclusive AI partner of the Canadian Bar Association, which is a relationship with a bar association rather than engagement with its guidance. Searched the site, the learning hub, the blog and the guides and reports index on 29 Aug 2026 and located no engagement with a named ethics opinion, including ABA Formal Opinion 512, any state bar guidance, or any Canadian law society guidance.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials are framed around time saved and lawyer productivity. A named partner describes reducing time spent on preparation, another describes surfacing a market-standard figure within minutes during the closing hours of a deal, the product page describes editing entire documents in minutes, and a case study is titled around improving attorney productivity. Searched the home page, the product page, the FAQ, the terms of service and the privacy policy on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee purposes and no published guidance on billing, fee or client disclosure treatment. The buyer here is frequently a law firm billing a client, which is the setting where this question bites hardest, and nothing addresses it.
Savings are claimed with nothing published on the client's side of the equation, and unusually the framing runs the other way. A published customer quote from a named partner states the product probably helps him bill an extra hour a day, and the pricing page is headed on boosting profitability, alongside a published return on investment calculator and repeated ten times faster drafting claims. Searched the site, the pricing page, the customer stories and the learning hub on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment. A published claim about billing more hours, in a market where ethics guidance is direct that a lawyer bills for time actually spent, is the sharpest version of this signal on the index so far.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
Two policy documents are published openly and linked from the FAQ, an Information Security Policy and a Data Retention Policy, which is more than most of this market puts on the open web. What a firm would need to satisfy a client AI clause is not there. No subprocessor list was located anywhere; the privacy policy names categories of recipient such as cloud hosting, payment, analytics and professional advisers rather than entities. No model provider is identified at all, so a firm cannot tell its client which providers see matter content. No client-facing consent or notification material was located. A Vanta trust centre is linked from the footer and is the plausible home for the missing artifacts, but its contents render client side and could not be read on 31 Aug 2026, and the FAQ routes further encryption and audit questions to a sales address.
A firm can assemble most of what a client AI clause asks for without a sales conversation. Published through a trust portal at a stable URL: a complete third party subprocessor list with processing locations, named model providers with the zero data retention terms binding them, a dated SOC 2 Type II resource, a HIPAA resource, signed business associate agreements from vendors handling protected health information, and an independent EU AI Act classification opinion from CMS Law. Short of the top value because the material is a self serve portal rather than a client facing consent or notification pack the firm could forward as assembled, and no such pack was located as of 29 Aug 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Searched the home page, the product page, the FAQ, the terms of service and the privacy policy on 31 Aug 2026 and located nothing addressing court disclosure, AI-use certification or the production of a verification record. Audit logging exists but is infrastructure monitoring rather than a work record: the FAQ describes AWS CloudWatch collecting resource, application and service logs with alerting and anomaly detection, retained up to two years, which is operational telemetry and not a per document account of which model produced which passage and who checked it. No model is identified anywhere on the property, so the model element of any disclosure could not be produced from vendor material in any event.
Searched the site, the feature pages, the security page and the help centre entry point on 29 Aug 2026. The vendor states audit controls exist and Ask is published as returning answers with citations, but no per document export covering model used, sources retrieved and human verification together was located, and no disclosure or certification support material was located. Noted for context: this is a transactional drafting product whose output is contracts rather than court filings, so a judicial AI disclosure order is less likely to reach it. Recorded as found.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- Good Law Verification
- Refusal and Uncertainty Behaviour
- Court Disclosure Support
Which one fits
Choose Draftwise if
- Client mandates mean the work cannot leave your infrastructure. Draftwise publishes three deployment routes: a private cloud dedicated to the firm in its choice of AWS, Azure or GCP where the firm's own IT holds the encryption keys and audit control and no data leaves the VPC by default, installation into the firm's existing cloud through a helm chart, VM images or Linux binaries, or an on premise install.
- Your precedent is the asset, not a generic corpus. Draftwise connects to the firm's document management system, naming iManage and NetDocuments, reads the complete deal history including documents, clauses and tags, generates playbooks automatically from that precedent rather than by hand, and states that it mirrors the document management system's permissions.
- You want references who will speak on the record. Draftwise publishes attributed quotes from named executives at Orrick and Gunderson Dettmer, a managing associate at Mishcon de Reya and partners at Mayne Wetherell and Sekri Valentin Zerrouk, with dedicated case study pages for three of them. None of the quotes carries a figure.
Choose Spellbook if
- A client asks which models see its draft. Spellbook names GPT-5 and Claude Opus on its own home page, names OpenAI and Anthropic as the providers, states the zero data retention agreements negotiated with each and what they mean technically, names AWS as its cloud, gives Canada and the United States as processing locations, and publishes a full subprocessor list in its trust portal.
- You want governance evidence rather than a principles page. Spellbook commissioned an independent legal opinion from CMS Law on its classification under the EU AI Act, publishes the full opinion letter for download alongside the controls implemented for that classification, and links its SOC 2 Type II and HIPAA badges to dated resources in the same portal rather than leaving them as images.
- You want to know how the answer is grounded. Spellbook states its architecture openly: it does not fine tune, it connects general purpose models to proprietary market data and requires them to fetch and cite, on the stated reasoning that putting documents into a model's long term memory encourages hallucination, with Compare benchmarking a clause against more than 2,300 contract types.
In summary
Draftwise
Draftwise is a contract drafting, review and negotiation tool for transactional lawyers that works from a firm's own precedent rather than a generic corpus, connecting to the document management system, reading its complete deal history and operating inside Microsoft Word. The AI Legal Index grades it in the top two bands on six of fifteen capability axes, with A grades on AI centrality and on deployment and data residency: it publishes a private cloud in the customer's choice of AWS, Azure or GCP where the firm's own IT holds the encryption keys and no data leaves the VPC by default, alongside installation into a firm's existing cloud or on premise. As of 31 August 2026 the index located no model or provider named, no subprocessor list, no AI governance material and no pricing at any level.
Spellbook
Spellbook is AI contract review and drafting for transactional lawyers, delivered mainly as a Microsoft Word add in and also working in Google Docs, covering redlining against a firm's standards, drafting from precedent, playbooks, cited answers and clause benchmarking, with an agent for longer multi document matters. The AI Legal Index grades it in the top two bands on twelve of fifteen capability axes, with A grades on AI centrality and on model supply chain disclosure: it names GPT-5 and Claude Opus as the models, OpenAI and Anthropic as the providers, states the zero data retention agreements negotiated with each, names AWS and gives Canada and the United States as processing locations, and publishes a full subprocessor list. As of 29 August 2026 the index located no accuracy measurement, no published rate and no indemnity running to the customer.
Questions buyers ask
Draftwise vs Spellbook: which is better for a transactional practice?
The AI Legal Index places Spellbook in the top two bands on twelve of fifteen capability axes and Draftwise on six, and the gap is disclosure about the AI itself rather than about drafting. Spellbook names its models, providers and processing locations and publishes an independent EU AI Act opinion. Draftwise answers on the boundary instead, publishing private cloud and on premise deployment and reading the firm's own precedent through its document management system.
Which one tells you which AI models it uses?
Spellbook. It names GPT-5 and Claude Opus as the models powering the product, identifies OpenAI and Anthropic as the providers, describes the zero data retention agreements negotiated with each, names AWS as its primary cloud and states Canada and the United States as processing locations, with a full subprocessor list published. On the Draftwise record the index located no model, no provider and no subprocessor list, and the only reference to underlying models is a claim that customer data never trains public models. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
Can either run inside your own cloud?
Draftwise can. It publishes a private cloud dedicated to the firm in the customer's choice of AWS, Azure or GCP, with the firm's IT holding encryption keys and audit control, network access restrictable to the firm's own IP subnets, and no data leaving the VPC by default, alongside deployment into a firm's existing cloud or on premise. Spellbook publishes AWS hosting with data stored and processed in Canada and the United States, and no customer selectable region or single tenant option was located. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
Do they work with iManage or NetDocuments?
Draftwise names both iManage and NetDocuments and describes what it does with them, reading the firm's complete deal history including documents, clauses and tags and auto curating contract collections once the system is connected. On the Spellbook record the index located a Word add in, Google Docs support and an integrations page, and no legal document management connector for iManage or NetDocuments. Neither publishes per integration documentation describing what moves in which direction. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
What do Draftwise and Spellbook both leave unpublished?
Neither publishes an accuracy figure, a hallucination rate or a test set for its own product. Neither publishes an indemnity running to the customer or a warranty on output. Neither names an ethics opinion, including ABA Formal Opinion 512. Neither documents what the product does when the precedent does not support the position requested. And neither publishes a rate at any tier, although Spellbook does publish its tier names and what each includes. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
Two things to read closely. Draftwise's strongest published claim is that in a private cloud deployment no data leaves the firm's own VPC by default, and no model or provider is named anywhere on the property, so a buyer cannot reconcile that boundary against wherever the language model actually runs. Its own pages also differ on certifications, with the home page stating SOC 2 Type II and ISO 27001 certification and the FAQ stating Cyber Security Essentials Plus certification and SOC 2 compliance. On Spellbook, a published customer quote from a named partner states the product helps him bill an extra hour a day, and neither vendor publishes guidance on how AI assisted time should be recorded on a client bill. Draftwise was verified on 31 August 2026 and Spellbook on 29 August 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.