Icertis vs Miramis: how they compare in 2026
Icertis and Miramis both sell enterprise contract lifecycle management built around AI agents, Icertis through its Vera agents across authoring, obligations and analytics, and Miramis through PLAI, which reviews each incoming redline against the company's playbook and tells business teams what they can accept. Miramis sits in the top two bands on thirteen of fifteen axes and Icertis on seven of fifteen, level on six. The widest difference is what each agreement says about customer contracts and AI. Miramis's terms bar using customer data to train any foundational model, and its data processing agreement names OpenAI and Google Vertex AI as its model providers with processing in the EU, commits to breach notice within eight hours and lets customers object to a new subprocessor. Icertis's agreement lets it use customer data to maintain, develop and improve its service, and it names no model provider. Icertis's counterweight is enterprise depth: single or multi tenant deployment in an Azure data center the customer picks, a separate FedRAMP cloud, and a published insurance schedule including $5 million of technology errors and omissions cover. Both publish a complete liability position.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
MEMBERSHIP: the AI bar is cleared. The brief flagged this vendor for a check on whether the AI is real, and it is: Icertis Copilots, a contract intelligence engine extracting clauses, obligations and risk, and a Vera agent layer shipped across Engage, Operate and Analyze in 2026, with the vendor stating agents act autonomously within boundaries the customer sets. That is shipped capability rather than an AI roadmap. GRADE: the models are the engine of a core capability layered on a product that would function without them. The platform covers authoring, negotiation, approval, execution, obligation management and analytics, and it existed and sold as Icertis Contract Management before the AI positioning; the rename to Contract Intelligence marks the layer being added rather than the product being rebuilt. Third B in a row on this axis, and the first of the four flagged legacy platform names to be tested.
The models are the engine of a core capability layered on a product that would still function without them as a contract workflow system. PLAI reviews redlines against the playbook, extracts metadata into the repository, answers portfolio questions and generates dashboards, and the vendor describes it as built into every workflow rather than bolted on. Remove it and templates, self-serve drafting with CRM data, approval routing on a Delegation of Authority, native eIDAS e-signing, the repository and renewal alerts remain, which is a working CLM; terms section 2.1.1 describes the service as an AI contract lifecycle management platform and the definitions treat Miramis AI as a feature of it. The AI-native label is the vendor's positioning; the structure is a CLM with a model layer. Home page, terms and rebrand announcement read 6 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted without measurement and without a described grounding method. Vendor material describes a contract intelligence engine that extracts clauses, obligations and risk and turns them into queryable data, and an enterprise wide intelligence layer that understands business and industry context, all of which is capability description rather than accuracy evidence. Searched the vendor site, the research and blog sections, the platform pages and the published State of Contracting material on 29 Aug 2026 and located no accuracy figure, no hallucination rate, no test set, no evaluation and no description of how output grounds to a source the reader can open. Worth recording alongside this, from a third party source rather than the vendor: a Gartner Peer Insights reviewer states their organisation has not been impressed with the Discovery tool AI. That is a single unverified customer view, is not treated as evidence for the grade, and is noted only because this axis exists to weigh published accuracy claims against what buyers can check.
Accuracy is acknowledged as imperfect and nothing is measured. Terms section 5.2.1 states that, given the probabilistic nature of the technology, output may be inaccurate, incomplete or misrepresent people, places or facts, and section 5.2.2 disclaims any warranty on the accuracy or correctness of output; the acceptable use policy requires the customer to review outputs before use. No accuracy figure, test set or evaluation is published. The primary-authority limbs of this band do not apply and are not held against the record: PLAI grounds its review in the customer's own playbook, templates and Delegation of Authority rather than in primary law, and citation checking is not a function it performs. What the band does ask of a contract agent, some measure of how often its redline assessments are wrong, is not published. Home page, terms, acceptable use policy and help centre read 6 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A real published commitment with a stated control concept, short of the mechanism. The vendor's own framing is specific and unusually well chosen: agents act autonomously within boundaries you set, so you can move fast and safely, and the platform is described as human first alongside AI native. That states both that the system acts alone and that the customer defines the limit, which is more than an assertion of human in the loop. The vendor's own published research reports that 44 percent of contracting leaders lack sufficient trust in AI's autonomous capabilities, so it is engaging with the question rather than avoiding it. Not located as of 29 Aug 2026: how a boundary is configured, what an agent does when it reaches one, what review surface a human gets, and what the vendor commits to when an output is wrong.
What runs alone, what constrains it, and how legal checks it are all published. Modes: business teams in sales, HR and procurement handle contracts autonomously within guardrails legal defines, drafting from pre-approved templates and negotiating in-platform, while PLAI reviews each incoming redline and states what can be accepted, what must change and what needs escalation; metadata extraction and approval routing run automatically. Constraints: legal sets the rules once, which templates, which terms are non-negotiable and who approves what, and the Delegation of Authority determines approvers and signatories on every contract. Review surface: flagged redlines with suggested alternative wording, automated approval routing before signature, and a complete audit trail on every action. Route back: anything outside the playbook escalates to legal, and the acceptable use policy and terms section 2.3.2 prohibit using the AI as the sole basis for any decision affecting legal rights without prior human review. Home page, FAQ, terms and acceptable use policy read 6 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Unattributed testimonials and scale claims stand in for deployment evidence. Customer quotes are published but the customers are anonymised by revenue band rather than named, including an IT services customer with more than $30 billion in annual revenue and a healthcare and biotech customer with more than $1 billion. Scale is claimed at 30 percent of the Fortune 100 across 90 plus countries and millions of contracts. Third party recognition is real and quantified: named a Customers' Choice vendor in the 2025 Gartner Peer Insights Voice of the Customer report for CLM, with 93 percent of customers recommending the platform across 84 ratings. That is measured satisfaction rather than a deployment outcome. Searched the vendor site, the customer and research sections and the news index on 29 Aug 2026 and located no named customer paired with figures, a date and an assessable method.
A named customer with a figure, short of a date or method. BabyBjörn's general counsel, David Grünbaum, is quoted that the company improved efficiency six times by streamlining legal flows with Miramis and that each department now handles its own standardised legal tasks; no date, baseline or method accompanies the figure. Six further general counsels or heads of legal are named with attributed quotes and no figures: Strömma, Svea Solar, Cambio, Eton, Treyd, PortmanDentex, Secret Escapes and Almedia. The home page's own figures, cycle time falling from 21 days to three to five, are unattributed, and its animated counters for time from draft to execution, hours saved and cost saving render without values. The customer stories page was not opened. Home page read 6 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Confidentiality is asserted in general terms and the current documentation was not reachable. The clearest located statement of data handling is that the platform stores agreements on a GDPR compliant cloud infrastructure with all data encrypted at rest and in transit under a permission based management approach, which appears in a company news item from 2017. That the most specific confidentiality statement locatable dates from nearly a decade ago is itself the finding. Searched the vendor site, the platform and company sections, the news index and three separate targeted searches for a trust centre or security page on 29 Aug 2026 without reaching one. Not located: any statement on whether customer content may be used to train models, any treatment of attorney client privilege or work product, any segregation model between customers or users, and any retention or deletion terms. See the build log note on this record's evidence floor.
Four of the five limbs are in the published agreement and the privilege limb is absent. No training: terms section 6.2.5 provides that no customer data will be used, directly or indirectly, to train any foundational AI model, with the word foundational carried as a qualifier. Segregation at the level an in-house buyer requires: role-based permissions down to document level and SSO are stated on the help centre and home page, and customer data is defined as confidential information under section 6.1. Retention and deletion: DPA section 16 requires destruction or return on termination and destruction within twelve months in any case. Third-party model providers: section 6.2.4 states that input goes to and output comes from third-party LLM providers under their terms, section 8.3 deems them sub-processors, and Schedule 1 names OpenAI and Google Cloud Vertex AI with EU or EEA residency. Nothing on any surface addresses privilege or work product handling, for a product whose users include a legal team negotiating on the company's behalf; under the standing reading that limb is required for A. Terms, DPA, help centre and home page read 6 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
The audience is broad by design and no position on the advice line was located. The platform is sold across legal, procurement, sales, finance and HR, handling NDAs, service agreements and HR paperwork alongside commercial contracts, and the AI drafts, redlines and negotiates for those users. Searched the vendor site, the platform and solutions pages, the company section and the research library on 29 Aug 2026 and located no statement on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits despite operation in more than 90 countries. The human first framing is a design posture rather than a professional responsibility position.
A real position on advice versus tooling is published, short of the supervision and competence dimension framed for a lawyer and of jurisdiction limits. Terms section 5.2.2 states that Miramis provides self-serve technology, is not a law firm or a substitute for a lawyer and gives no legal advice; section 2.3.2 bars using the services in any way that would constitute or substitute for legal advice, the practice of law or automated decision-making about persons; the acceptable use policy of 11 February 2026 repeats both and requires human review before any decision affecting legal rights. That matters here because the product is sold for business users to handle contracts without legal expertise, and the terms say so plainly. What is not addressed is how the product supports a supervising lawyer's duties beyond the guardrail architecture, and no jurisdiction limit is named except the e-signature caveat in section 2.5.2 that local law may impose requirements the platform does not meet. Terms and acceptable use policy read 6 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Responsible AI principles are published without a mechanism a buyer could audit. The vendor positions itself as AI native and human first, states that agents operate within customer set boundaries, and publishes annual research engaging seriously with buyer concerns about AI, reporting that 55 percent of contracting leaders cite data output quality as a significant concern and 44 percent lack sufficient trust in autonomous AI. Engaging publicly with the trust deficit in your own category is a real editorial position. But searched the vendor site, the research library, the company section and three targeted searches on 29 Aug 2026 and located no published AI governance framework, no AI management certification such as ISO 42001, no named owner of model governance, no pre release testing regime, and nothing on uneven output across matter types, parties or populations.
Responsible-use statements without a mechanism, a testing regime or an accountable owner. The acceptable use policy carries AI usage rules, human review before rights-affecting decisions, and terms section 5.2.1 acknowledges probabilistic limits and states that Miramis continually strives to improve accuracy, reliability and safety. No governance framework, ISO 42001 or equivalent certification, pre-release testing description, or statement about uneven output across contract types or business teams is published, and no AI principles page exists in the site inventory. Security controls are graded elsewhere. Terms, acceptable use policy, home page and help centre checked 6 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
AMENDED 6 September 2026 under R94 on a newly located agreement; the pull-1 C recorded stewardship at the level of general assurance. Substantive published policy now covers most of the ground. Retention and deletion: section 4.5 returns Subscriber Data on request at no fee and permits destruction if not requested within five days of termination. Access control: strict role-based access, identity-provider authentication with multi-factor support, audit logs of all user actions, encryption at rest and in transit, Azure network security groups and threat monitoring, per Exhibit B. Sub-processors: a List of Standard Sub-Processors is published on the foundation page, with the version located dated June 2023. Incident practice: Exhibit B commits to notify the Subscriber of any breach resulting in loss or unauthorised disclosure of Subscriber Data, under a documented incident process. Section 6.1 bars sale of personal data and combination with other sources. The gap is that section 5.2 permits use of Subscriber Data to develop and improve the SaaS. SaaS Subscription and Services Agreement read 6 September 2026.
Retention, deletion, access control, sub-processors and incident practice are all published, current and specific enough to hold the vendor to, in the terms and the DPA appended to them. Retention and deletion: DPA section 16 requires destruction or return of personal data on termination and destruction within twelve months regardless; terms section 2.3.4 requires reasonable prior notice before Miramis deletes customer data for breach. Access control: Schedule 2 lists access-level controls, access logging, VPC, two-factor authentication and password management, and the home page and help centre add SSO and document-level role permissions. Sub-processors: Schedule 1 lists nine by name, service and data residency, all EU or EEA, including AWS, Azure, OpenAI, Google Cloud Vertex AI, Signicat, Idura, Auth0 and Twilio SendGrid, with a 30-day objection window on additions under DPA section 7. Incident practice: DPA section 5.1 commits to written breach notice within eight hours of discovery with the circumstances, categories, consequences, measures and a contact. The help centre adds that data sent through the AI integrations is not stored at the provider. Terms of service version 2.2 of 18 February 2026 and its DPA read in full 6 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
AMENDED 6 September 2026 under R94 on a newly located agreement; the original D of the pull-1 build recorded an absence that the SaaS Subscription and Services Agreement now fills. What the vendor stands behind is published and specific, including insurance. Section 9.1 gives a defence and indemnity for third-party intellectual property claims, for claims by Icertis subcontractors or personnel, and for gross negligence causing injury or property damage, with the Subscriber Data exclusion stated; section 10.1 excludes consequential loss and section 10.2 caps each party at amounts received by Icertis in the preceding twelve months; section 8.2 warrants non-infringement, professional performance and material conformity to documentation with a correction remedy and a termination right; section 10.4 commits Icertis to maintain commercial general liability cover of one million dollars per occurrence and two million aggregate, technology errors and omissions including cyber liability of five million dollars, umbrella cover of five million dollars and employer's liability, from an A-minus rated carrier for the term and one year after, with a certificate on request. AI output carries no separate warranty and the AI Acceptable Use Policy on the foundation page was not opened. SaaS Subscription and Services Agreement read in full 6 September 2026.
What the vendor stands behind is published and specific, including that on wrong output it stands behind nothing, which a buyer can read before signing. Terms section 5.4 gives a vendor indemnity against third-party IP infringement claims arising from use of the services, with its exclusions listed in 5.4.2 and the remedies in 5.4.3 including a refund of prepaid fees on termination. Section 5.3 caps each party's liability at fees paid in the preceding twelve months, excludes indirect loss, and carves out fraud, wilful misconduct and gross negligence; section 5.3.4 sets a twelve-month claims window. Section 5.1.1 warrants that the services conform to specification and are performed professionally, with the remedy in 5.1.2. Section 5.2.2 then states that Miramis bears no legal responsibility and gives no warranty for the accuracy, correctness or fitness of output, and section 5.5 has the customer indemnify Miramis for claims arising from input and use of output. DPA section 13.3 adds an indemnity for processing against instructions. No insurance is stated. The allocation is complete and the terms are the self-serve agreement; order forms prevail on conflict. Terms read in full 6 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integration is claimed at platform level without documentation an implementer could use. The vendor describes an enterprise wide contract intelligence layer connecting agreements, data and systems, and Microsoft Azure hosting with Microsoft as a strategic partner is stated, which implies but does not document connection into the Microsoft estate. Searched the vendor site, the platform pages and the company section on 29 Aug 2026 and located no integrations page, no named connector for ERP, CRM, document management or e signature, and no description of what any integration moves or what an administrator configures. For an enterprise platform whose competitive set is named as including SAP Ariba and DocuSign CLM, and which sells into procurement and finance, that absence on the pages reached is notable.
Real integrations, documented, with depth described for some. Salesforce and HubSpot are described as pulling deal data directly into contract drafts, the Word add-in as keeping redlines synced with the platform, and DocuSign as a supported alternative to native e-signing; Teams, Slack, SharePoint and Google Drive are named on the home page without a description of what moves. A WebAPI is offered for custom connections and public developer documentation exists, still hosted at the pocketlaw-api domain, and a May 2026 release named Miramis Connect exposes the platform to external AI agents. The integrations page and the developer documentation were not opened, so what a firm must configure is not recorded. No document management or matter management system is named. Home page, FAQ and content hub index read 6 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
AMENDED 6 September 2026 under R94 on a newly located agreement; the pull-1 C recorded cloud delivery with neither tenancy nor region established. Deployment options are published with tenancy, region and processing location. Exhibit B of the SaaS Subscription and Services Agreement states the platform is hosted on Microsoft Azure and that the particular Azure data centre may be selected by the Subscriber at the outset of the subscription, with production backups on geo-replicated Azure storage; Exhibit A-2 distinguishes single-tenant subscribers, who schedule their own upgrades and receive wider version support, from multi-tenant subscribers on the automatic upgrade calendar, which establishes that both tenancy models are offered; a FedRAMP government community cloud is listed separately. Model-provider inference location is not stated. SaaS Subscription and Services Agreement, Exhibits A-2 and B, read 6 September 2026.
Residency and processing location are stated and the tenancy model is not. DPA Schedule 1 gives EU or EEA data residency for every sub-processor including both model providers, DPA section 12 states processing is primarily within the EU or EEA with adequacy, standard contractual clauses or equivalent safeguards for anything outside, and the help centre states EU data residency is available. That places both storage and model processing in the region. Nothing states whether customers share infrastructure or receive a dedicated tenant, no region outside the EU is offered, and nothing describes what changes between plans. Terms, DPA, help centre and home page read 6 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
AMENDED 6 September 2026 under R94 on a newly located agreement; the pull-1 C recorded no certification with scope on the surfaces read. Certifications are real and stated in the agreement, short of a report reachable without asking. Exhibit B of the SaaS Subscription and Services Agreement states that Icertis is ISO 27001, ISO 27017 and ISO 27018 certified, holds SOC 2 Type 1 and Type 2 certifications and complies with ITAR, manages risk under the ISO 27001 framework, commissions regular third-party vulnerability assessments and penetration testing, encrypts data at rest with AES-256 and supports customer-managed keys in Azure Key Vault; a Trust Center is linked from the site. No auditor, coverage period or self-serve report route is stated in the agreement, and the Trust Center was not opened. SaaS Subscription and Services Agreement, Exhibit B, read 6 September 2026.
Certification is real, stated, and unusually warranted in the contract, short of accessible evidence. Terms section 6.2.6 states that Miramis is ISO 27001 and SOC 2 Type II certified and shall maintain the certification or an equivalent throughout the term, which is a contractual commitment no other record in this pull carries; the home page and help centre repeat both and add regular penetration testing. No auditor, coverage period, scope or route to the report is published, no trust centre exists, and the Security page and Security Policy in the site inventory were not opened. The control detail in DPA Schedule 2 is a list of headings rather than a description. Terms, DPA, home page and help centre read 6 September 2026; the two security pages are the rebuttal route.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The vendor refers to AI capability without identifying what sits underneath, though the chain is partly inferable. Microsoft is named as a strategic partner and Azure as the platform, and a Microsoft published customer story records Icertis monitoring Azure OpenAI deployments, which indicates Azure OpenAI is in the stack. That is a partner disclosure rather than a vendor one, and the distinction matters: naming a hosting partnership is not naming which models serve which task. Searched the vendor site, the platform and research pages and the company section on 29 Aug 2026 and located no named model provider stated by Icertis, no statement of where models run, no subprocessor list, and no commitment to notify customers when the supply chain changes.
Providers, location and change notice are published; the models are identified only as a family. DPA Schedule 1 names OpenAI and Google Cloud Vertex AI as the AI sub-processors with EU or EEA residency, terms section 8.3 deems the model provider a sub-processor, and DPA section 7 requires written details and a 30-day objection window before any sub-processor is added. The definition of Miramis AI names OpenAI's GPT models as an example, which is a model family rather than a named model, and nothing states which model runs which function. Under the standing reading the separate limb that the models are named is not met by the provider list alone. Terms and DPA read 6 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Checked the vendor site navigation, the platform and solutions pages, the company section and the research library on 29 Aug 2026. No pricing page was located, no rate is published, no unit of charge is stated and no tier structure appears. Every commercial path located terminates in a demo or contact request. No free trial or self serve entry point was located, and no third party pricing figure was located either.
The unit and structure are stated in the agreement without the figure, and the pricing page could not be retrieved. Terms section 2.2.3 licenses per individual user, section 4.1 sets twelve-month initial and renewal terms with 90 days' notice to terminate, section 3.1.2 gives 120 days' notice of price changes, section 3.2 sets 30-day invoice terms and 20 per cent late interest, and section 4.4 provides for free trial accounts; section 3.1.1 refers to standard subscription plans offered from time to time. A pricing page exists in the navigation and footer at /pricing; it did not surface in search and could not be fetched on 6 September 2026, which is a limit on this reading rather than a finding. A third-party review states published pricing was withdrawn at the February 2026 rebrand, and aggregator listings carry pre-rebrand tiers; neither is evidence and neither is credited. Terms read in full 6 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is described with substance, short of the boundaries. The buyer is stated clearly as the large enterprise, with 30 percent of the Fortune 100 claimed across 90 plus countries and multiple languages, and the platform explicitly spans buy side and sell side agreements rather than one direction. Industry breakouts are published in the vendor's own research covering public sector, healthcare and life sciences, and banking and insurance among others. Functional coverage spans legal, procurement, sales, finance and HR. Not located as of 29 Aug 2026: any statement of which organisation sizes, contract types or practice areas the platform is not built for. Third party reviews state that small and most mid market businesses will find it more platform than they need, which is exactly the boundary statement the vendor does not make itself.
Segment and work type are described with substance; the boundaries are partly stated. The buyer is enterprise in-house legal, with solutions pages for legal, sales, HR, procurement, finance and IT, industries named as banking and financial services, manufacturing, retail and technology, and a mid-market to enterprise positioning in the vendor's own comparison pages. Coverage is European by design: Swedish and UK entities, eIDAS e-signing with BankID and MitID, EU residency, and a DORA clause for regulated customers. Limits stated: e-signature validity may not meet enhanced local requirements and some documents cannot be signed electronically. Not stated: any practice area or contract type the platform does not handle, and any position on use outside Europe. Home page, terms and solutions navigation read 6 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
AMENDED 6 September 2026 under R94 on a newly located agreement; the pull-1 value was silent because no agreement had been read. The published agreement permits use of customer content to develop and improve the service. Section 5.2 of the SaaS Subscription and Services Agreement grants Icertis a license to use Subscriber Data to provide the SaaS and states that Icertis may use Subscriber Data to maintain, develop and improve the SaaS, including creating industry-relevant analysis, on condition that the data is not shared with third parties and the Subscriber remains anonymous; Subscriber Data is defined to include the output of processing.
The clause does not name model training, but for an AI-native platform a right to use customer content to develop and improve the service is the shape the index treats as permitted training under the R43 Unity ELM precedent for anonymized improvement carve-outs. An Artificial Intelligence Acceptable Use Policy is listed on the foundation page as an addendum to the agreement and was not opened; it is the rebuttal route if it narrows this right. Surfaces checked 6 September 2026.
The commitment is in the agreement. Terms of service section 6.2.5, version 2.2 of 18 February 2026, provides that no customer data will be used, directly or indirectly, to train any foundational artificial intelligence models. The word foundational is a qualifier: it bars training of foundation models and does not in terms address fine-tuning or any non-foundational model of the vendor's own, and terms section 7.3.4 separately permits usage data, defined to exclude customer content, to be used to develop and improve the services.
The home page and help center state more broadly that data is never used to train or fine-tune any AI models and that this is contractually prohibited across all sub-processor agreements, which describes the vendor's contracts with its model providers rather than a term the customer holds. Surfaces checked 6 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
AMENDED 6 September 2026 under R94 on a newly located agreement; the pull-1 value was not-addressed. A specific period is published and the customer cannot change it. Section 4.5 provides that on written request Icertis returns Subscriber Data in its then-current format at no fee, and that if not requested within five days of termination Icertis may destroy it; Subscriber Data includes the output of processing. Nothing states a shorter or configurable window for AI prompts and outputs during the term. Surfaces checked 6 September 2026.
The customer controls deletion by contractual instruction and no zero-retention setting is stated. DPA section 16 requires destruction or return of personal data at the customer's election on termination, with destruction within twelve months in any case, and DPA section 3.3 confines processing to the customer's written instructions; the help center states that data passed through the AI integrations is not stored at the provider and not linked to any account.
Nothing states how long prompts to PLAI or its outputs are retained inside the platform during the term, and the repository retains executed contracts by design. Surfaces checked 6 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
AMENDED 6 September 2026 under R94 on a newly located agreement; the pull-1 value was claimed-undocumented. The product maintains its own permission model and the agreement documents it at the level of a description: Exhibit B states strict role-based access control with authorization implemented through the platform's own features, identity-provider authentication, and audit logs capturing every user action with date and time, and section 2.4 places responsibility for determining access privileges on the Subscriber; single-tenant deployment is available.
Nothing describes how the Vera agents respect those permissions across a contract portfolio. Surfaces checked 6 September 2026.
The product maintains its own permission model and documents it at the level of a description. The help center states that role-based permissions control access down to document level, the home page lists advanced permissions and SSO with SAML, and the terms require an individual license per user. That is tenant and document level separation, which is what an in-house buyer requires; nothing describes how PLAI's retrieval respects those permissions when answering questions across the portfolio, and no document management system's access model is inherited because none is integrated. Surfaces checked 6 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
AMENDED 6 September 2026 under R94 on a newly located agreement; the pull-1 value was not-addressed because no agreement had been read. The published agreement commits to notice. Section 7.2 permits disclosure of confidential information as required by law, regulation or court order, provided that unless legally prohibited the receiving party gives the disclosing party prompt written notice before the disclosure and reasonable assistance in limiting it or obtaining a protective order; confidential information is defined broadly and Exhibit B states that Subscriber data is treated as confidential. No transparency report is published. Surfaces checked 6 September 2026.
The published agreement commits to notice. Terms section 6.2.3 permits disclosure of confidential information, which includes customer data, when compelled by law or a binding order, and requires the receiving party, to the extent not prevented by law, to give the disclosing party notice of the proceeding and the compelled disclosure and to cooperate in seeking confidential treatment. DPA section 9.1 adds that the processor will inform the controller without undue delay of any contact from authorities, courts or regulators concerning the personal data it processes. No transparency report is published. Surfaces checked 6 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No primary law corpus is identified because the product does not appear to hold one. Retrieval runs against the customer's own contract repository, templates and clause library, so the corpus is the customer's own agreements and its provenance is theirs. Searched the vendor site, the platform pages and the research library on 29 Aug 2026 and located no vendor supplied legal corpus, no license basis and no update cadence.
Noted for a reader: this is the same architectural shape as Definely and Ironclad, where the absence on this signal describes the product design rather than a disclosure failure.
No located public material identifies a legal corpus behind the product's answers, and the product is not built on one: PLAI reviews contracts against the customer's own playbook, templates and Delegation of Authority and answers questions about the customer's own repository. No primary law source, license or update cadence is published. Home page, FAQ, terms and help center checked 6 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Searched the vendor site, the platform pages and the research library on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator license was located. Noted for context: this is a contract lifecycle platform grounded in the customer's own agreements with no case law research surface, so a citator is outside its design entirely.
No located public material addresses whether authority is checked for subsequent history, and the product does not retrieve or cite primary law; its output is redline assessments, drafts from templates, extracted metadata and answers about the customer's contracts. Recorded as the honest value for a product with no citator function. Surfaces checked 6 September 2026.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
Searched the vendor site, the platform pages, the research library and the 2026 event coverage on 29 Aug 2026. No published material describes what the product does when it cannot ground an answer, and no explicit no answer path or confidence signal exposed to the user was located. The vendor's boundaries language describes limits a customer sets on what an agent may do, which is a permission concept rather than a statement about what the system does when it does not know.
An explicit path for not completing a request is described in public materials: the home page and FAQ state that PLAI reviews every incoming redline against the playbook and flags what can be accepted, what needs to change and what needs legal escalation, and that anything outside the guardrails legal defines is routed to legal rather than handled. The behavior is described rather than demonstrated, and nothing states what PLAI does when the playbook gives it no answer as distinct from when a rule tells it to escalate. Surfaces checked 6 September 2026.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one.
This is a statement about the public record on the date shown and not a clearance. Note that this is a contract lifecycle platform with no case law research surface, so its output is very unlikely to reach a court filing as cited authority.
No court order, opinion or disciplinary record naming Miramis, Pocketlaw or Miramis Technologies AB was located as of 6 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on both names together with a general search for court findings; results returned sanctions involving general-purpose chatbots, none of which is this product. This is a statement about the public record, not a finding about the product; a contract management tool that cites no authority carries a remote exposure on this signal.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Searched the vendor site, the research library including the State of Contracting reports, the blog and the news index on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512 and state bar guidance. The vendor publishes substantial annual research on AI adoption and trust in contracting, which surveys practitioner sentiment rather than engaging with the professional responsibility rules its legal buyers are bound by.
No located public material engages with bar or ethics guidance. The terms and acceptable use policy address the advice line and require human review, but neither names an ethics opinion, bar rule or professional responsibility framework in any jurisdiction; the company is Swedish with a UK subsidiary, so the reference points would differ from the ABA opinion this index uses as a baseline, and none of any jurisdiction is named. Home page, terms, acceptable use policy and help center checked 6 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Vendor material is framed around business outcomes rather than hours: growing revenue, controlling costs, mitigating risk and ensuring compliance, with published claims about drafting faster and executing with greater precision. Searched the vendor site, the platform pages, the research library and the news index on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment.
Noted for context: the buyer is a corporate legal, procurement or finance function rather than a firm billing a client by the hour, so this signal reads differently for this segment, and the savings framing here is enterprise cost rather than billable time.
The buyer is an in-house legal department that bills no client, so the product sits outside a lawyer-to-client fee relationship. Savings claims are published and kept here: contract cycle time from 21 days to three to five, a six-times efficiency improvement attributed to BabyBjörn's general counsel, and hours-saved counters on the home page. Nothing addresses how AI-assisted work is recorded or disclosed on any bill, and no per-matter record of AI involvement is described, although every action carries an audit trail. No law firm is a named buyer segment. Surfaces checked 6 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
AMENDED 6 September 2026 under R94 on a newly located agreement page; the pull-1 value was not-addressed. A sub-processor list is published on the foundation page alongside the agreement, a Data Protection Addendum with standard contractual clauses, EU Data Act terms and an AI Acceptable Use Policy; the list version located is dated June 2023 and was not opened, so whether it names the model providers behind the Vera features is not established, which is why the row sits at this value rather than the top one. Surfaces checked 6 September 2026.
A current sub-processor and model provider list is published together with client-facing disclosure material, in the form of a DPA appended to the public terms. Schedule 1 lists nine sub-processors by name, service, personal data processed and residency, with OpenAI and Google Cloud Vertex AI identified as the AI providers and every entry marked EU or EEA; DPA section 7 gives a 30-day objection window on additions and section 7.3 offers extracts of the sub-processor agreements on request.
The DPA is published without an agreement in place and is drafted as an appendix to be executed, so a firm's client could be given it directly. Surfaces checked 6 September 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Searched the vendor site, the platform pages and the research library on 29 Aug 2026. Third party review material refers to standardized workflows and access controls, and the platform tracks obligations and approvals per contract, so a workflow trail plausibly exists, but no vendor material describes an export covering model used, sources retrieved and human verification together, and no model is named by the vendor so the model used could not be stated.
Noted for context: this is a contracting platform rather than a litigation product, so a judicial AI disclosure order is unlikely to reach its output.
Some elements of a disclosure record are available and no document-level export is described. The home page states that approval routing and e-signing carry a complete audit trail on every action, that PLAI's redline review flags changes with reasoning, and that version history is kept in the negotiation workspace; that is a per-contract record of what the agent flagged and what a human approved. Nothing states that a record of the model used, the sources retrieved and the human verification can be exported per document, and the models are identified only as a family.
Court disclosure is remote for a contract management tool and the vendor does not address it. Surfaces checked 6 September 2026.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Primary Law Corpus Provenance
- Good Law Verification
- Bar Guidance Alignment
Which one fits
Choose Icertis if
- You need to choose tenancy and data center. Icertis's agreement offers single tenant subscribers their own upgrade schedule alongside a multi tenant option, lets the customer pick the Azure data center at the outset, keeps geo replicated backups, and lists a separate FedRAMP government community cloud.
- You want insurance standing behind the contract. Icertis commits to general liability cover of $1 million per occurrence, technology errors and omissions including cyber liability of $5 million and umbrella cover of $5 million for the term and a year after, alongside an intellectual property indemnity and a twelve month fee cap.
- Your contracts span buy side and sell side across many countries. Icertis says it serves 30 percent of the Fortune 100 in more than 90 countries, covers procurement, sales, legal, finance and HR agreements, and holds ISO 27001, 27017 and 27018 with SOC 2 Type 1 and Type 2.
Choose Miramis if
- You want sales, HR and procurement to handle routine contracts within rules legal sets. Miramis lets legal fix templates, non negotiable terms and a delegation of authority once, and its PLAI agent reviews every incoming redline and says what can be accepted, what must change and what goes to legal.
- Your data must stay in Europe. Miramis's data processing agreement lists nine subprocessors, including OpenAI and Google Vertex AI, all with EU or EEA residency, gives 30 days to object to a new one, and commits to written breach notice within eight hours of discovery; signing is eIDAS compliant with BankID and MitID.
- You want the training bar and certifications written into the contract. Miramis's terms state that no customer data will be used to train any foundational AI model, and warrant that it will keep ISO 27001 and SOC 2 Type II certification, or an equivalent, for the whole term.
In summary
Icertis
Icertis, founded in 2009 and based in Bellevue, Washington, sells Icertis Contract Intelligence, an enterprise contract lifecycle platform for buy side and sell side agreements covering authoring, negotiation, approval, execution, obligations, risk and analytics, with Copilots, a contract intelligence engine and, since 2026, Vera agents that act within boundaries the customer sets. It runs on Microsoft Azure. The AI Legal Index grades it in the top two bands on seven of fifteen capability axes, with A grades on liability and on deployment, where its agreement offers single or multi tenant hosting in a chosen Azure data center. It states 30 percent of the Fortune 100 as customers. As of 29 August 2026 the index located no named customer outcome, named model provider or price.
Miramis
Miramis, from Miramis Technologies AB of Stockholm with a London subsidiary, traded as Pocketlaw until February 2026 and now sells an enterprise contract lifecycle platform built around its AI agent, PLAI. Business teams draft from approved templates with CRM data and negotiate within guardrails legal sets, while PLAI reviews redlines against the playbook, extracts metadata and answers questions across the repository; signing is built in. The AI Legal Index grades it in the top two bands on thirteen of fifteen capability axes, with A grades on autonomy and oversight, data stewardship and liability. Its terms bar training foundational models on customer data and name OpenAI and Google Vertex AI with EU residency. As of 6 September 2026 the index located no published price figure and no accuracy measurement.
Questions buyers ask
Icertis vs Miramis: which is better for enterprise contract management?
On published evidence Miramis sits in the top two bands on thirteen of fifteen AI Legal Index capability axes and Icertis on seven of fifteen, mostly because Miramis publishes its model providers, a training bar, European data residency and named customer counsel. Icertis publishes stronger deployment choices, including single tenant hosting and a FedRAMP cloud, and an insurance schedule. Large multinationals that need US government hosting have more to read from Icertis.
Does Icertis use customer contracts to improve its AI?
Its agreement allows it. Section 5.2 of Icertis's subscription agreement lets it use subscriber data, which includes output, to maintain, develop and improve its service, including industry analysis, provided the data is not shared with third parties and the customer stays anonymous. The clause does not name model training. An AI acceptable use policy is listed beside the agreement and may narrow this. Miramis's terms bar training foundational models on customer data. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
Where does Miramis process data?
In the EU or EEA. Miramis's data processing agreement lists nine subprocessors, including AWS, Azure, OpenAI and Google Vertex AI, each marked with EU or EEA residency, and states that processing takes place primarily there, with standard contractual clauses for anything outside. Its help center says data passed to the AI providers is not stored there. Icertis lets a customer pick its Azure data center. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
What was Miramis called before its rename?
Miramis Technologies AB traded as Pocketlaw from its founding until 11 February 2026, when it renamed to mark a move from a self serve legal platform for startups to enterprise contract lifecycle management. Its developer documentation is still hosted on a Pocketlaw domain, and a third party review reports that published pricing was withdrawn at the rebrand. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
What do Icertis and Miramis both leave unpublished?
How accurate their agents are and how they are governed. Neither publishes an accuracy figure, test set or evaluation, and neither describes an AI governance framework, an accountable owner or testing before release. Neither states which specific model runs which function, addresses privilege or work product, or names bar guidance on AI. Neither publishes a price figure. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
Three readings to weigh. Icertis's agreement grants it the right to use customer data, including AI output, to develop and improve its service while keeping the customer anonymous; that is a published term, and its AI acceptable use policy, not read here, may narrow it. Miramis's training bar is worded for foundational models and does not address fine tuning or its own models. Miramis traded as Pocketlaw until 11 February 2026, and its pricing page could not be retrieved. Icertis was verified on 29 August 2026 and Miramis on 6 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.