Icertis vs Leah: how they compare in 2026

I
Icertis profile
L
Leah profile
Last verifiedOctober 8, 2026

Both are enterprise contract platforms on Microsoft Azure with an agent layer on top, called Vera at Icertis and the Agentic OS at Leah. Icertis leads with its intelligence engine, pulling clauses, obligations and risk out of buy side and sell side agreements. Leah leads with agents that carry procurement and finance work alongside legal. Both publish their customer agreements. Each caps liability at a year of fees and indemnifies intellectual property claims. Icertis adds named insurance, including $5 million of technology errors and omissions cover. Leah triples its cap for breaches of its security or data protection terms and publishes uptime tiers. The sharper split is the AI itself. Leah publishes its control loop, logs every agent action with its rationale, and names four model providers. Icertis says Vera acts within boundaries the customer sets, without saying how a boundary works, and it does not say which models power its own AI features. On training, Icertis's agreement lets it use customer data to improve the service, provided the customer stays anonymous and nothing is shared with third parties. Leah says customer contracts never train models.

At a glance

Category
IcertisContract Review & Drafting
LeahContract Review & Drafting
Founded
Icertis2009
Leah2012
Headquarters
IcertisBellevue, Washington, United States
LeahLondon, United Kingdom
Last verified
IcertisOct 8, 2026
LeahOct 8, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Icertis
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

Icertis offers Icertis Copilots, a contract intelligence engine that extracts clauses, obligations and risk, and Vera, an agent layer released across Engage, Operate and Analyze in 2026. The vendor says Vera acts autonomously within boundaries the customer sets. These sit on a contract platform for authoring, negotiation, approval, execution, obligation management and analytics, which runs without the models and was sold as Icertis Contract Management before the AI positioning. The rename to Contract Intelligence added an AI layer to that platform rather than rebuilding it.

Leah
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

Leah sells AI agents and an orchestration layer that sit on top of a contract lifecycle platform, and that platform works without them. The vendor describes it the other way round. It says other vendors bolted AI onto systems built for manual workflows, while Leah was designed from scratch with orchestration as the foundation. ContractPod Technologies has sold contract lifecycle management since 2012. Leah launched in March 2023 as an AI services hub within that platform, went standalone in May 2023, and Leah Intelligence followed in October 2024. Without the agents, the product is still a working CLM with guided intake, approval routing, DocuSign and Adobe Sign execution and a contract repository. That CLM has its own market and its own Gartner category placement. The orchestration layer on top is model driven.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Icertis
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Icertis describes a contract intelligence engine that extracts clauses, obligations and risk and turns them into queryable data, and an intelligence layer across the enterprise that it says understands business and industry context. It publishes no accuracy figure, hallucination rate, test set or evaluation, and does not describe how an output links back to a source the user can open. One Gartner Peer Insights reviewer says their organization has not been impressed with the Discovery tool AI.

Leah
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Leah returns to accuracy repeatedly in its materials, and the AI governance page says every action is measured against benchmarks for accuracy, bias and outcome. Neither that page nor the home page publishes a result from that measurement. They give no accuracy figure, no error or hallucination rate, no description of any benchmark or test set and no published evaluation. The product material describes a legal helpdesk that answers contract questions with sources attached, so a user can in principle check an answer against its source. Neither page says what the system does when the customer's own contracts do not support a position.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Icertis
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Icertis says its agents act autonomously within boundaries the customer sets, so the customer can move fast and safely, and describes the platform as human first alongside AI native. In that design the agents act on their own and the customer defines where they stop. The vendor's own research reports that 44 percent of contracting leaders lack sufficient trust in AI's autonomous capabilities. Its product pages do not say how a boundary is configured or what an agent does when it reaches one. Nor do they say what review screen a person gets, or what the vendor commits to when an output is wrong.

Leah
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a lawyer checks it are all published: modes, thresholds, review surfaces, and the route a matter takes back to human judgment. A categorical limit on a named mode or tier, stating what its output may not be used for, meets the threshold limb without a number.

Leah's dedicated AI governance page sets out a three stage control loop. In the first stage, policy in, the customer defines which agents may act, on which data, within which thresholds and where escalation is required. Those policies are held as configuration rather than code. In the second, execution governed, every agent action runs through those policies in real time. Approvals, escalations and rejections are applied automatically, and the orchestrator enforces guardrails at each step. In the third, audit out, every decision is logged with the rationale, what the agent did, why, under which policy, on what data and to what outcome. The records are described as tamper resistant and immutable. The loop sets the thresholds, the review points and the route back to human judgment. Leah's home page puts the position in one line, that the workflow runs itself while the judgment stays human. The page does not say what happens after an output is found to be wrong. Default modes are not described, because the customer configures the guardrails rather than receiving them preset.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Icertis
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Icertis publishes customer quotes that identify the customer by industry and revenue band rather than by name. Among them are an IT services company with more than $30 billion in annual revenue and a healthcare and biotech company with more than $1 billion. It says 30 percent of the Fortune 100 are customers, across more than 90 countries and millions of contracts. Gartner named Icertis a Customers' Choice in the 2025 Peer Insights Voice of the Customer report for CLM, with 93 percent of customers recommending the platform across 84 ratings. No published case study pairs a named customer with measured results.

Leah
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Leah publishes qualitative quotes from four named people. Noelle Perkins is EVP and Chief Legal Officer at Cushman and Wakefield, and Lidia Kamleh is Chief Legal Officer at Dubai Future Foundation. Frances Bain-Cumberbatch is Chief Legal and External Affairs Officer at Ansa McAL, and Zillia Knight is Senior Legal Officer at Terumo Europe. Three results are published with the customer unnamed. A major American logistics company cut contract review time by 91 percent. A global manufacturer protected more than $18 million of revenue, and an American retail REIT tracked more than $2 million of savings. About 54 enterprise logos appear, including Philips, MUFG, Sandoz, Pernod Ricard, Alaska Airlines and Wood PLC. PwC and KPMG appear among them. PwC entered a commercial alliance in March 2024, and Epiq resells Leah in its Service Cloud. Integreon is quoted as an early adopter that resells it, and Pinsent Masons adopted it for managed legal services in July 2025. Partners and customers are shown together without distinction, and the Chief Product Officer of Execo, another services partner, is among the testimonials.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Icertis
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

The SaaS Subscription and Services Agreement sets out role based access control, identity provider authentication, audit logs of every user action, encryption at rest and in transit, and a single tenant option. Section 4.5 returns Subscriber Data on request and permits destruction if it is not requested within five days of termination. Section 5.2 lets Icertis use Subscriber Data, including output, to maintain, develop and improve the service, provided the data is not shared with third parties and the Subscriber stays anonymous. The agreement does not address attorney client privilege or work product, or say how the Vera agents respect user permissions. A 2017 company news item describes storage on GDPR compliant cloud infrastructure with encryption at rest and in transit. Icertis also links a Trust Center from its site.

Leah
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Leah says customer contract data is never used to train models. The AI governance page treats data leaking into models the customer does not own as a failure it engineered out. It says zero data retention is the only acceptable answer, and that Leah enforces zero retention with OpenAI and Anthropic so they process data but never store it. Encryption is AES-256 at rest and TLS in transit, with keys in Azure Key Vault, rotated and reachable only through controlled service accounts. Role based access control is said to apply at every layer, and single tenant deployment is offered for customers with strict isolation needs. Leah sells to Fortune 500 legal departments, and none of this material addresses privilege or work product.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Icertis
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

Icertis sells the platform across legal, procurement, sales, finance and HR, where it handles NDAs, service agreements and HR paperwork alongside commercial contracts. Its AI drafts, redlines and negotiates for all of those users. The product pages, company section and research library take no position on where a tool ends and legal advice begins, and say nothing about competence or supervision duties. They set no jurisdiction limits, although Icertis operates in more than 90 countries. The human first framing describes how the product is designed rather than a position on professional responsibility.

Leah
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Leah publishes nothing on the line between a tool and legal advice. Its site carries no disclaimer of any kind and no ethics or professional responsibility page, and it names no bar or ethics guidance, including ABA Formal Opinion 512. The platform is sold to run legal work end to end across legal, procurement and finance teams. In the vendor's own framing, agents carry out commercial work in several steps without routing every decision through a person.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Icertis
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

Icertis calls itself AI native and human first, says its agents operate within boundaries the customer sets, and publishes annual research on buyer concerns about AI. That research reports that 55 percent of contracting leaders cite data output quality as a significant concern and 44 percent lack sufficient trust in autonomous AI. The product pages and research library describe no AI governance framework, no AI management certification such as ISO 42001, no named owner of model governance and no testing before release. They say nothing about uneven output across matter types, parties or populations.

Leah
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

A dedicated AI governance page names six failure modes the vendor says it engineered out. They include black box decisions that cannot be defended to a regulator or board, and compliance frameworks retrofitted after the fact. Against them the page sets three pillars and a loop of policy, execution and audit. Each action is logged with its rationale and governing policy, in records described as tamper resistant and immutable. The page also says every action is measured against benchmarks for accuracy, bias and outcome, and that accountability is structural rather than aspirational. It names no person or role accountable for model behavior and describes no testing before release. It gives no benchmark method or schedule and discloses no bias measurement result.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Icertis
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Section 4.5 of the agreement returns Subscriber Data on request at no fee and permits destruction if it is not requested within five days of termination. Exhibit B sets out strict role based access, identity provider authentication with multifactor support, audit logs of all user actions, encryption at rest and in transit, Azure network security groups and threat monitoring. It also commits Icertis to notify the Subscriber of any breach resulting in loss or unauthorized disclosure of Subscriber Data, under a documented incident process. Section 6.1 bars sale of personal data and its combination with other sources, while section 5.2 permits use of Subscriber Data to develop and improve the SaaS. A List of Standard Sub-Processors, in a version dated June 2023, is published on the foundation page.

Leah
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

The AI governance page describes TLS in transit and AES-256 at rest. Encryption keys are managed in Azure Key Vault, rotated regularly and reachable only through tightly controlled service accounts. The page also lists multifactor authentication, secure API gateways, network segmentation, real time monitoring and a documented incident response plan. Audit logs are described as comprehensive, tamper resistant and immutable. For outside assurance, the vendor says an independent Managed Security Service Provider audits it every year and that it is penetration tested regularly.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Icertis
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

Section 9.1 of the agreement gives a defense and indemnity for third party intellectual property claims, for claims by Icertis subcontractors or personnel, and for gross negligence causing injury or property damage. It states an exclusion for Subscriber Data. Section 10.1 excludes consequential loss, and section 10.2 caps each party at the amounts Icertis received in the preceding twelve months. Section 8.2 warrants noninfringement, professional performance and material conformity to the documentation, with a correction remedy and a termination right. Section 10.4 commits Icertis to carry commercial general liability cover of $1 million per occurrence and $2 million in aggregate. It adds technology errors and omissions cover including cyber liability of $5 million, umbrella cover of $5 million and employer's liability. The cover comes from a carrier rated A minus, runs for the term and one year after, and a certificate is available on request. The agreement gives AI output no separate warranty. An AI Acceptable Use Policy sits on the foundation page as an addendum to the agreement.

Leah
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

Section 16.5 of the Master Terms and Annexes sets a General Cap equal to fees paid or payable in the twelve months before the first incident. An Enhanced Cap of three times that applies to breaches of its security or data protection terms, meaning the security clause and the data processing addendum. Indemnities, intellectual property claims, breach of confidentiality and anything that cannot legally be limited are uncapped. Section 17.1 gives the customer an indemnity against third party intellectual property claims. Section 8.2 warrants that the service will perform materially as documented, with a thirty day fix period under 8.3 and termination with a refund if the fix fails. Annex A publishes uptime tiers of 99.00, 99.5 and 99.9 percent by support plan. A tier missed in three consecutive months, or in four months out of six, allows termination with a refund. Three limits apply. Breaches of confidentiality involving Customer Data fall outside the uncapped claim, so they stay capped and rise to the Enhanced Cap only where the security or data protection terms are also breached. The agreement gives no indemnity for AI output, such as inaccurate output, hallucination or training data provenance. Section 9.2 bars the customer from submitting Sensitive Data, including GDPR Article 9 categories, and the provider disclaims liability for it. These terms are version 3.0c. Version 4.0, dated 4 January 2026, changes only the trading name, according to the vendor.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Icertis
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Icertis publishes a Native Integrations page with prebuilt adapters for SAP, Microsoft, Salesforce, Workday, Adobe Sign and DocuSign, each described by what it moves. The SAP Ariba adapter syncs procurement contracts, line items and suppliers, and the SAP S/4HANA adapter brings buy side supplier master data into the platform. For ERP and finance, adapters for Microsoft Dynamics 365 Finance and Operations and for Workday Financials sync procurement contracts, suppliers and financial data. The Salesforce CRM and CPQ adapter creates contracts from accounts, opportunities and quotes, with two way sync of deal and pricing data, and a Dynamics 365 Sales adapter keeps contract and sales data in step. The Adobe Sign and DocuSign adapters return signed agreements and audit trails to the platform. Microsoft Teams, Microsoft 365 for the web and Outlook connections cover collaboration, and SAM.gov and federal clause adapters serve public sector work. Licensed public APIs and connections to OpenAI, Claude, Microsoft Copilot and SAP Joule agents round out the list. The page does not describe setup or what an administrator configures, and it names no document management or identity connector. The platform runs on Microsoft Azure, with Microsoft as a strategic partner, and its named competitors include SAP Ariba and DocuSign CLM.

Leah
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Leah names its integrations and describes each by function. They cover ERP platforms including SAP and NetSuite, procurement systems including Coupa, financial systems, identity providers including Okta, and existing contract lifecycle tools. DocuSign and Adobe Sign are built in for signing, and a Microsoft Word add in handles redlining. The vendor also describes how the integrations work. It says Leah connects and executes rather than copying data passively, and carries out work across connected systems through the orchestration layer. Leah has a dedicated integrations page, but publishes nothing on what syncs in which direction or what a customer must configure. No document management integration such as iManage or NetDocuments appears, which fits a product built for in house teams rather than law firms.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Icertis
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

Exhibit B of the SaaS Subscription and Services Agreement states that the platform is hosted on Microsoft Azure and that the Subscriber may select the Azure data center at the outset of the subscription. Production backups sit on geo replicated Azure storage. Exhibit A-2 distinguishes single tenant subscribers, who schedule their own upgrades and receive wider version support, from multitenant subscribers on the automatic upgrade calendar, so both tenancy models are offered. A FedRAMP government community cloud is listed separately. The agreement does not say where model inference runs.

Leah
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

The standard deployment is shared. Single tenant deployment is available for customers with strict isolation requirements. The vendor also offers what it calls a dedicated zero trust private environment in Azure OpenAI Studio, described as fully isolating data from all other customers. Leah runs on Azure, with keys held in Azure Key Vault. On data residency the vendor says only that it supports the residency and regulatory needs typical of large multinational enterprises. It names no region or jurisdiction and describes no customer choice.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Icertis
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Exhibit B of the SaaS Subscription and Services Agreement states that Icertis is ISO 27001, ISO 27017 and ISO 27018 certified, holds SOC 2 Type 1 and Type 2 certifications and complies with ITAR. It manages risk under the ISO 27001 framework, commissions regular third party vulnerability assessments and penetration testing, encrypts data at rest with AES-256 and supports customer managed keys in Azure Key Vault. The agreement names no auditor, coverage period or self serve route to the reports. Icertis links a Trust Center from its site.

Leah
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

The AI governance page claims SOC 1 Type I and II, SOC 2 Type I and II, GDPR compliance, CCPA compliance, HIPAA readiness and ISO 27001 alignment. The home page FAQ, on the same site, says only that Leah is SOC 2 Type II certified, so the two pages disagree on what is held. For ISO 27001 and HIPAA the governance page says aligned and ready rather than certified. The auditor is described only as an independent Managed Security Service Provider, a category rather than a named firm. No coverage period, report date or audit scope is given. Penetration testing is said to be regular, with no partner named and no summary published. Leah has no trust center or portal, so there is no published route to request a report.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Icertis
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

Icertis names Microsoft as a strategic partner and Azure as its platform, and a Microsoft published customer story records Icertis monitoring Azure OpenAI deployments, which places Azure OpenAI in the stack. Its integrations page lists interoperability with OpenAI, Claude (Anthropic), Microsoft Copilot and SAP Joule agents. Neither source says which models power the Copilots, the contract intelligence engine or Vera, or which model serves which task. The agreement and product pages do not say where models run or commit to notifying customers when the model supply chain changes. A List of Standard Sub-Processors, dated June 2023, sits on the foundation page.

Leah
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

The DPA Setup Page lists four model providers against Leah Functionality, each noted as storing or retaining no customer data and each with named jurisdictions. Anthropic PBC is listed for the USA, Japan, and the EU or UK, and OpenAI LLC for the USA, Japan, and the EU or Switzerland. Cohere Inc. is listed for Canada, the USA, the EU or UK, and Japan. Google AI/ML with Google Cloud is listed for the USA, Japan, and the EU, Switzerland or UK. Microsoft Azure Services is listed for hosting and translation, and the private deployment option runs in Azure OpenAI Studio. DPA clause 4.3 requires any new subprocessor to be added to the published list with at least thirty days' notice before it processes customer personal data. Clause 4.4 gives a thirty day objection right on reasonable data protection grounds. If the objection is not resolved, the affected order can be terminated with a refund of prepaid unused fees. No model or version is named for any provider. The platform is described as choosing among several language models for each task and letting customers extend or customize models. Nothing published shows which provider handled a given piece of work.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Icertis
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Icertis publishes no pricing page, rate, unit of charge or tier structure. Every commercial path on its site ends in a demo or contact request, and there is no free trial or self serve entry point. No third party pricing figure is published either.

Leah
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Leah publishes no pricing at any level, including the unit of charge. The primary navigation covers platform, solutions, resources and company, and neither it nor the footer sitemap has a pricing page. There is no tier structure, no unit per seat, contract or agent, no volume banding and no indication of what implementation adds. Every call to action across the site is to request a demo. An implementation FAQ says timelines vary with scope and integrations and that a detailed plan is built during evaluation. It says nothing about cost. No published page gives a view of price before a sales process.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Icertis
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Icertis sells to large enterprises, says 30 percent of the Fortune 100 are customers across more than 90 countries and multiple languages, and covers buy side and sell side agreements rather than one direction. The vendor's own research publishes industry breakouts for public sector, healthcare and life sciences, and banking and insurance, among others. Functional coverage spans legal, procurement, sales, finance and HR. Icertis does not say which organization sizes, contract types or practice areas the platform is not built for. Third party reviews say small and most mid market businesses will find it more platform than they need.

Leah
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Leah publishes dedicated industry pages for CPG and manufacturing, energy and utilities, financial services, healthcare, and pharma and medical devices. It describes its customers as Fortune 500 enterprises in regulated industries. By function it publishes pages for legal leadership, legal operations, sales and revenue, procurement, and finance. The pages carry distinct propositions written for the General Counsel, the contract operations team, the Chief Procurement Officer and the finance leader. The customer roster spans banking, airlines, pharmaceuticals, consumer goods and engineering. No published page says which practice areas, contract types or matters the platform does not support, and none addresses smaller organizations. Law firms appear only indirectly, through managed service partners, rather than as a served segment.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Icertis
Permitted, in the contract

Section 5.2 of the SaaS Subscription and Services Agreement licenses Icertis to use Subscriber Data to provide the SaaS. It also lets Icertis use Subscriber Data to maintain, develop and improve the SaaS, including creating industry relevant analysis, provided the data is not shared with third parties and the Subscriber stays anonymous. Subscriber Data is defined to include the output of processing. The clause does not name model training. An Artificial Intelligence Acceptable Use Policy is listed on the foundation page as an addendum to the agreement.

Leah
Never, in policy only

Leah's security FAQ, on its home page, says customer contract data is never used to train models. The AI governance page treats data leaking into models the customer does not own as a failure it engineered out. It says zero data retention is enforced so that OpenAI and Anthropic process data but never store it. No term in the Master Terms and Annexes v3.0c names training, model training, machine learning or model improvement for customer content, either way.

Two clauses come close. Clause 5.1 limits the provider's use of Customer Data to providing and maintaining the Cloud Service, Support and Professional Services. Clause 5.4 allows use of Usage Data, the provider's technical logs, data and learnings about the customer's use, to run, improve and support the service. Usage Data excludes Customer Data, so the improvement right covers telemetry, not content. Together the clauses fit a ban on training without stating one.

They leave open whether model improvement counts as maintaining the service. The commitment rests on the published policy, not a contract term. Version 4.0 of January 2026 changes only the trading name, according to the vendor.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Icertis
Disclosed fixed window

Under section 4.5 of the agreement, Icertis returns Subscriber Data on written request in its then current format at no fee. It may destroy the data if no request arrives within five days of termination. Subscriber Data includes the output of processing. The agreement sets no shorter or configurable window for AI prompts and outputs during the term.

Leah
Disclosed fixed window

Section 14.4 allows export during the subscription and deletion of Customer Data within sixty days of a request after termination. That is subject to standard backup or record retention policies and legal requirements, and the customer cannot change the period. The data processing addendum adds secure deletion to industry standards at clause 8.2, with a certificate of deletion on request. Schedule 1 commits to export in CSV or a similar format within thirty calendar days and to physical destruction of media by a recognized provider.

Prompts and outputs have no separate window. The agreement treats Customer Data as one class, defined at section 23 as any data, content or materials the customer submits, so prompts and outputs follow that regime. Usage Data sits outside it. Section 5.4 lets the provider collect Usage Data, meaning its technical logs, data and learnings about the customer's use, excluding Customer Data. The provider may use it to run, improve and support the service and for other lawful purposes such as benchmarking.

It may disclose Usage Data externally only if deidentified and aggregated across customers. No deletion duty applies to Usage Data, and section 14.5 makes 5.4 survive termination.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Icertis
Own model, documented

Exhibit B of the agreement describes the product's own permission model. It sets out strict role based access control, with authorization implemented through the platform's own features, identity provider authentication, and audit logs capturing every user action with date and time. Section 2.4 makes the Subscriber responsible for determining access privileges, and single tenant deployment is available. The agreement does not describe how the Vera agents respect those permissions across a contract portfolio.

Leah
Claimed, not documented

Leah describes separation at the customer level, through deployment options. The vendor states that single tenant deployment is available for customers with strict data isolation requirements. It says a dedicated zero trust private environment within Azure OpenAI Studio ensures complete isolation from all other customers. Role based access control is stated to be enforced at every layer. That wording makes isolation a deployment option rather than the default, and nothing published describes how customers are separated in the standard shared deployment.

Legal, procurement, finance and shared services teams work in the same system, and nothing published addresses boundaries between them inside a customer.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Icertis
Notice committed

Section 7.2 of the agreement permits disclosure of confidential information as required by law, regulation or court order. Unless legally prohibited, the receiving party must give the disclosing party prompt written notice before the disclosure and reasonable assistance in limiting it or obtaining a protective order. Confidential information is defined broadly, and Exhibit B states that Subscriber data is treated as confidential. Icertis publishes no transparency report.

Leah
Notice committed

Section 19, headed Required Disclosures, lets the recipient disclose Confidential Information where the law requires. Where the law permits, the recipient must give advance notice and reasonable cooperation, at the discloser's expense, to obtain confidential treatment. The clause expressly covers Confidential Information including Customer Data. Section 23 confirms that the customer's Confidential Information includes Customer Data, so customer material sits inside the notice duty.

The duty is mutual and binds whichever party receives the demand. Section 14.5 makes section 19 survive termination. Leah publishes no transparency report, so there is no public count of demands received or of how they were answered. These terms are version 3.0c. Version 4.0 of January 2026 changes only the trading name, according to the vendor.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Icertis
Not addressed

Icertis identifies no primary law corpus, and the product does not appear to hold one. Retrieval runs against the customer's own contract repository, templates and clause library, so the source material is the customer's own agreements and its provenance is theirs. The product pages and research library name no vendor supplied legal corpus, license basis or update cadence, which reflects a product built on the customer's own contracts.

Leah
Sources named, basis unstated

Leah works on the customer's own material. The vendor states that Leah operates against the customer's policies and playbooks and gains intelligence from the customer's unstructured data and business rules. It answers contract questions from the customer's repository with sources attached. The vendor also refers to Leah operating against established legal precedents, but names no source, jurisdiction, database or rights basis for them.

The product manages a customer's contracts rather than retrieving primary law. No provenance statement backs the precedent reference, and no update cadence is published for anything.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Icertis
Not addressed

Icertis is a contract lifecycle platform grounded in the customer's own agreements, with no case law research feature, so a citator falls outside its design. Its product pages and research library say nothing about whether authority carries a treatment signal or whether the product tracks subsequent history, and they name no commercial citator license.

Leah
Not addressed

Leah describes no citator, treatment signal or currency check, and does not say whether legal authority is reviewed for later history. The platform manages contracts, obligations and procurement workflows rather than retrieving case law, so a citator is not part of what it sells. The vendor does refer to Leah operating against established legal precedents, without identifying any source. That is the one place the product invokes primary authority, and no verification step is described for it.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Icertis
Not addressed

The product pages and research library do not describe what Icertis does when it cannot ground an answer, and mention no explicit no answer path or confidence signal shown to the user. The boundaries the vendor describes are limits a customer sets on what an agent may do. They are a permission concept, not a statement of what the system does when it does not know.

Leah
Not addressed

The home page and the AI governance page describe no explicit path for Leah to decline to answer or abstain, and no confidence or grounding rating. The governance loop does produce rejections. Approvals, escalations and rejections are applied automatically according to the customer's rules. Those are policy outcomes set by configured guardrails, not the model declining because it cannot ground a response. Neither page says what Leah does when the customer's own contract set or playbook does not cover the question in front of it.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

Icertis
None located

The AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known, records no court order, opinion or disciplinary record naming Icertis. Published 2026 sanctions summaries and secondary sanctions trackers do not name it either. Icertis is a contract lifecycle platform with no case law research feature, so its output is very unlikely to reach a court filing as cited authority.

Leah
None located

The AI Hallucination Cases database maintained by Damien Charlotin tracks decisions worldwide where a court addressed hallucinated AI content, and records the tool implicated where known. It records no court order, opinion or disciplinary record naming Leah or the former company name ContractPodAi. Published 2026 sanctions trackers and trade press summaries name neither. The platform runs commercial contracting and procurement work rather than producing court filings, so its output does not ordinarily reach a brief.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Icertis
Not addressed

Icertis publishes substantial annual research on AI adoption and trust in contracting, including the State of Contracting reports, and that research surveys practitioner sentiment. Neither the research library nor the blog, the news index or the product pages engages with a named ethics opinion or bar guidance, including ABA Formal Opinion 512 and state bar guidance. None of it addresses the professional responsibility rules that bind the vendor's legal buyers.

Leah
Not addressed

Leah publishes nothing that engages with bar or ethics guidance. That includes ABA Formal Opinion 512, state bar guidance in the United States, and Solicitors Regulation Authority or Law Society material. The company is headquartered in London and sells into legal departments across North America, Europe, Asia and Australia. Its published compliance material covers regulation and security frameworks, namely GDPR, CCPA, HIPAA, SOC and ISO. None of it addresses the professional conduct obligations that bind the lawyers using the product.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Icertis
Savings claims only

Icertis frames its material around business outcomes rather than hours, such as growing revenue, controlling costs, reducing risk and ensuring compliance, and it claims faster drafting and more precise execution. Its product pages and research library describe no per matter record of work done with AI for fee purposes and give no guidance on billing, fees or client disclosure. The buyer is a corporate legal, procurement or finance function rather than a firm billing a client by the hour, so the savings are enterprise cost rather than billable time.

Leah
Savings claims only

Leah frames its public materials around cost and time removed, quantified at portfolio level. It cites a 91 percent cut in contract review time, more than $18 million of revenue protected and more than $2 million of tracked savings. Its headline figures are more than $125 billion of commercial value managed and more than $10 billion of ROI impact delivered. No per matter record of AI assisted work for fee purposes is described, and no guidance on billing, fee or client disclosure treatment is published.

The vendor describes an immutable audit log of every action, which could in principle support such a record, but does not present it for that purpose. Leah sells to in house functions rather than firms billing clients, so the costs in play are internal cost and outside counsel spend. Its materials address neither.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Icertis
Subprocessors listed

Icertis publishes a subprocessor list on its foundation page alongside the agreement, a Data Protection Addendum with standard contractual clauses, EU Data Act terms and an AI Acceptable Use Policy. The list on that page is dated June 2023.

Leah
Subprocessors listed

The data processing agreement is Annex B of the Master Terms and Annexes v3.0c. The DPA Setup Page lists every subprocessor with its purpose, location and the product it serves. The list names ABBYY OCR SDK, Anthropic PBC, Cohere Inc., DocuSign or Adobe, Google AI/ML and Google Cloud, Jitterbit, Microsoft Azure Services, OpenAI LLC, QlikTech, Sendgrid, ZOHO, Zuva and four ContractPod group entities. Anthropic, OpenAI, Cohere and Google AI/ML are each listed against Leah Functionality as model providers, noted as storing or retaining no Customer Data, with named jurisdictions.

The DPA itself is the Bonterms DPA, published openly in the same PDF and ready to forward. It incorporates EU Standard Contractual Clauses Modules 2 and 3 and the UK International Data Transfer Addendum. It sets out processing details in Schedule 1 and fixes a 48 hour notice period for security incidents. Clause 4.3 commits to listing any new subprocessor and giving at least 30 days' notice before it processes anything.

Clause 4.4 gives an objection right, with termination and a refund if the objection is not resolved. Version 4.0 of January 2026 changes only the trading name, according to the vendor.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Icertis
Not addressed

Icertis tracks obligations and approvals per contract, and third party reviews refer to standardized workflows and access controls, so a workflow trail plausibly exists. The product pages and research library describe no export that covers the model used, the sources retrieved and human verification together. Icertis names no model behind its features, so such a record could not state the model used. It is a contracting platform rather than a litigation product, so a judicial AI disclosure order is unlikely to reach its output.

Leah
Partial record

The audit stage of Leah's published governance loop logs every decision. Each entry records what the agent did, why, under which policy, with what data and with what outcome. The records are described as tamper resistant, immutable and ready for any audit. That gives the action, the rule, the inputs and the result for each action. The published description of the log does not include the model. The platform chooses among several language models for each task and identifies no model or version, so the log does not show which system produced a given passage.

No export built for court disclosure or AI use certification is described. The audit framing is regulatory and internal rather than judicial.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • Commercial Transparency
Signals neither addresses in public material
  • Good Law Verification
  • Refusal and Uncertainty Behavior
  • Bar Guidance Alignment

Which one fits

Choose Icertis if

  • You need to choose where your data lives. Icertis lets the subscriber pick its Azure data center when the subscription starts. It offers single tenant and multi tenant hosting and lists a FedRAMP government cloud.
  • Your risk team wants insurance behind the contract. Icertis commits to $5 million of technology errors and omissions cover, including cyber liability, plus general liability and umbrella cover. The cover runs for the term and one year after.
  • Your contracting spans both directions and many countries. Icertis covers buy side and sell side agreements and says its customers span more than 90 countries. It was a Gartner Peer Insights Customers' Choice for 2025, with 93 percent of 84 reviewers recommending it.

Choose Leah if

  • You want to see how agents are controlled before you buy. Leah publishes a loop of customer policy, governed execution and audit. The customer sets permissions, data scope and escalation points, and every action is logged.
  • You need the model providers named. Leah lists Anthropic, OpenAI, Cohere and Google with their jurisdictions. It gives thirty days' notice and an objection right before a new subprocessor touches customer data.
  • Your contract work runs through ERP and procurement systems. Leah names SAP, NetSuite, Coupa and Okta as integrations. Signing runs through DocuSign or Adobe Sign, and redlining happens inside Microsoft Word.

In summary

Icertis

Icertis Contract Intelligence is an enterprise platform for authoring, negotiating, executing and tracking agreements, on both the buying and the selling side. Copilots and an extraction engine pull clauses, obligations and risk out of contracts, and the Vera agents arrived in 2026. According to the AI Legal Index, Icertis's case rests on its published agreement. It gives an intellectual property indemnity, a cap of a year of fees and named insurance cover. The subscriber chooses its Azure data center, and single tenant hosting is offered. Section 5.2 lets Icertis use customer data to improve the service, provided the customer stays anonymous and nothing is shared with third parties. It does not say which models power its own AI features, and no accuracy measure or price is published.

Source: AI Legal Index, 2026

Leah

Leah, formerly ContractPodAi, comes from ContractPod Technologies of London and serves legal, procurement and finance teams at large enterprises. Its contract lifecycle product handles intake, playbook review in Microsoft Word, approvals and an obligation repository. On top, the Agentic OS assigns work to agents under an orchestrator called Leah Maestro. The AI Legal Index records a governance model the customer controls, with escalation rules set in configuration and every agent action logged. Leah's master terms carry tiered liability caps, and its subprocessor list names four model providers. It publishes no price, no accuracy figure and nothing on privilege.

Source: AI Legal Index, 2026

Questions buyers ask

Icertis vs Leah: which is better for large enterprise contracting?

The choice turns on what you need to see before signing. Icertis gives hosting choice, named insurance and a platform it says is used in more than 90 countries. Leah gives a documented agent governance model, named model providers and integrations with SAP, NetSuite and Coupa. Both publish their customer agreements. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Does Icertis or Leah use customer contracts to train AI?

Icertis's agreement lets it use customer data, including output, to maintain and improve the service, provided the customer stays anonymous and nothing is shared with third parties. It does not mention model training. Leah says customer contract data is never used to train models. Its master terms limit customer data to running the service. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

How do Icertis and Leah control what AI agents do?

Icertis says Vera agents act on their own within boundaries the customer sets. It does not describe how a boundary is configured or what happens when an agent reaches one. Leah's customer defines which agents act, on which data and where they escalate, and each action is logged with its rationale and outcome. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Where are Icertis and Leah hosted?

Both run on Microsoft Azure. Icertis lets the subscriber choose the data center at the outset, offers single tenant and multi tenant hosting, and lists a FedRAMP government cloud. Leah offers single tenant deployment and a private Azure OpenAI environment, but names no region. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

What do Icertis and Leah both leave unpublished?

Neither publishes a price or a unit of charge, an accuracy figure, or any position on attorney client privilege in its agreement or product pages. Neither offers a warranty or indemnity specific to AI output. Neither engages with bar guidance such as ABA Formal Opinion 512, though both sell to procurement and finance teams as well as lawyers. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Disclosure

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything on it comes from public material on the dates shown. How the index grades.

Section 5.2 of Icertis's agreement lets it use customer data, including output, to maintain, develop and improve the service while the customer stays anonymous. It does not mention model training. Icertis publishes an AI Acceptable Use Policy as an addendum to the agreement, and a subprocessor list dated June 2023. Leah's promise never to train on customer contracts is a published policy rather than a contract term. Neither vendor reviewed this page.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
October 8, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746