Icertis vs Sirion: how they compare in 2026

I
Icertis profile
S
Sirion profile
Last verifiedOctober 8, 2026

Built for large global companies, Icertis and Sirion both handle procurement and sales contracts, and each now runs an agent layer, Vera at Icertis and agentOS at Sirion. Both publish their customer terms, and both keep some right to use customer data to improve their software. Icertis may use it to develop the service, provided the customer stays anonymous and nothing is shared with third parties. Sirion lets its systems process customer data to inform machine learning. Both cap liability at a year of fees and indemnify intellectual property claims. Icertis adds named insurance, including $5 million of technology errors and omissions cover, and lets the subscriber pick its Azure data center. Both document their ERP connections. Sirion's nine connectors are set out by direction, and Icertis lists prebuilt adapters for SAP Ariba, S/4HANA, Dynamics 365, Workday and Salesforce. Sirion keeps each customer in its own application instance and says its AI answers carry clause level citations. Neither says which models power its own AI features, or describes in any depth how its agents are kept in check.

At a glance

Category
IcertisContract Review & Drafting
SirionContract Review & Drafting
Founded
Icertis2009
Sirion2012
Headquarters
IcertisBellevue, Washington, United States
SirionLehi, Utah, United States
Last verified
IcertisOct 8, 2026
SirionOct 8, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Icertis
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

Icertis offers Icertis Copilots, a contract intelligence engine that extracts clauses, obligations and risk, and Vera, an agent layer released across Engage, Operate and Analyze in 2026. The vendor says Vera acts autonomously within boundaries the customer sets. These sit on a contract platform for authoring, negotiation, approval, execution, obligation management and analytics, which runs without the models and was sold as Icertis Contract Management before the AI positioning. The rename to Contract Intelligence added an AI layer to that platform rather than rebuilding it.

Sirion
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

Sirion's contract lifecycle platform came before its AI, and the company has traded since 2012. The product is organized as Store, Create and Manage, covering repository, drafting, approval, negotiation, obligation tracking and performance management. Without the agents and agentOS, a working enterprise CLM remains, and Gartner classifies it as one. The models drive the capability Sirion now sells on top of it. Agents are described as extracting and normalizing contracts, assembling first drafts from a playbook, proposing redlines on the other side's paper and monitoring obligations. Customers can also build and deploy their own agents in agentOS.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Icertis
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Icertis describes a contract intelligence engine that extracts clauses, obligations and risk and turns them into queryable data, and an intelligence layer across the enterprise that it says understands business and industry context. It publishes no accuracy figure, hallucination rate, test set or evaluation, and does not describe how an output links back to a source the user can open. One Gartner Peer Insights reviewer says their organization has not been impressed with the Discovery tool AI.

Sirion
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

A specific grounding claim runs through Sirion's material. Answers are described as carrying citations linked to the customer's own data, and vendor material states that every AI generated response includes citations linked to exact sources, with citation and justification at clause level. Five percentage figures are published prominently, and each measures speed or coverage rather than correctness. They are 90 percent faster centralization, 85 percent faster insights, up to 90 percent faster time to contract, 99 percent on time obligation compliance and 70 percent faster agentic automation. The home page and the trust center, with its AI ethics, compliance and security sections, give no accuracy figure, error or hallucination rate, test set or published evaluation. They do not say what the system does when the customer's contract set does not support an answer.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Icertis
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Icertis says its agents act autonomously within boundaries the customer sets, so the customer can move fast and safely, and describes the platform as human first alongside AI native. In that design the agents act on their own and the customer defines where they stop. The vendor's own research reports that 44 percent of contracting leaders lack sufficient trust in AI's autonomous capabilities. Its product pages do not say how a boundary is configured or what an agent does when it reaches one. Nor do they say what review screen a person gets, or what the vendor commits to when an output is wrong.

Sirion
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Agents are said to sense intent, reason over enterprise data and act autonomously. They draft and propose redlines, monitor obligations, surface gaps, alert owners and drive follow through. Sirion's one published statement on oversight is that the user stays in control for strategic exceptions. Its published material does not say what an agent completes without a human, the point at which it stops and escalates, where review happens, or what happens after an output is wrong. Customers can build, test and deploy agents in agentOS, which suggests guardrails can be configured, though no control structure is documented.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Icertis
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Icertis publishes customer quotes that identify the customer by industry and revenue band rather than by name. Among them are an IT services company with more than $30 billion in annual revenue and a healthcare and biotech company with more than $1 billion. It says 30 percent of the Fortune 100 are customers, across more than 90 countries and millions of contracts. Gartner named Icertis a Customers' Choice in the 2025 Peer Insights Voice of the Customer report for CLM, with 93 percent of customers recommending the platform across 84 ratings. No published case study pairs a named customer with measured results.

Sirion
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Three customer representatives speak on the record with their roles and employers. Edzard Janssen is Chief Procurement Officer at RBI. Reinhard Plaza-Bartsch is Head of Digital Supply Chain and Operations at Vodafone. Angella Dikmic is Manager of IT Vendor Management at GTAA. All three quotes are qualitative, and all three people work in procurement or vendor management rather than legal. The five percentage claims name no customer and read as product capabilities, so named customers and published figures are never paired. About 25 enterprise logos appear, including Citi, GE, Coca-Cola, Chevron, PayPal, Bayer, Rolls-Royce, Aramco, Yamaha, DP World and Zalando. Customers are in more than 70 countries, with more than $450 billion of contract value under management. Sirion also publishes a case study library.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Icertis
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

The SaaS Subscription and Services Agreement sets out role based access control, identity provider authentication, audit logs of every user action, encryption at rest and in transit, and a single tenant option. Section 4.5 returns Subscriber Data on request and permits destruction if it is not requested within five days of termination. Section 5.2 lets Icertis use Subscriber Data, including output, to maintain, develop and improve the service, provided the data is not shared with third parties and the Subscriber stays anonymous. The agreement does not address attorney client privilege or work product, or say how the Vera agents respect user permissions. A 2017 company news item describes storage on GDPR compliant cloud infrastructure with encryption at rest and in transit. Icertis also links a Trust Center from its site.

Sirion
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Vendor library articles say customer data stays within the customer environment and is not used to train external language models. Clause 4.2 of the SaaS Terms, version 6, modified 26 August 2026, says otherwise. It reserves a right for Sirion to have its automated systems review and process Customer Data to generally inform machine learning capabilities in the services. None of the published agreements offers an opt out, and the agreement, not the library articles, is what binds. The rest of the confidentiality framework is published and can be read before signing. The data processing addendum stores and processes all customer data in a Sirion application instance specific to the customer. It sets Article 32 technical and organizational measures, with AES-256 at rest and TLS 1.2 in transit. It imposes need to know and least privilege access with automatic logout, requires deletion within 30 days of termination, and commits to notifying the customer of a confirmed security incident within 72 hours. Section 5 of the SaaS Terms adds mutual confidentiality, with a duty to give prior notice of any authority or court demand so the other party can object. The published agreements and trust center do not address privilege or work product.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Icertis
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

Icertis sells the platform across legal, procurement, sales, finance and HR, where it handles NDAs, service agreements and HR paperwork alongside commercial contracts. Its AI drafts, redlines and negotiates for all of those users. The product pages, company section and research library take no position on where a tool ends and legal advice begins, and say nothing about competence or supervision duties. They set no jurisdiction limits, although Icertis operates in more than 90 countries. The human first framing describes how the product is designed rather than a position on professional responsibility.

Sirion
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

The platform is sold to procurement, sales and finance teams as well as in house legal, all working on the same contracts. The three customer referees Sirion features are procurement and vendor management leaders, not lawyers. The home page, the trust center index with its AI ethics, compliance and security sections, and the terms and policies index say nothing on where tooling ends and legal advice begins. There is no statement that Sirion does not give legal advice, no professional responsibility or ethics page, no named bar or ethics guidance, including ABA Formal Opinion 512, and no jurisdiction limits.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Icertis
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

Icertis calls itself AI native and human first, says its agents operate within boundaries the customer sets, and publishes annual research on buyer concerns about AI. That research reports that 55 percent of contracting leaders cite data output quality as a significant concern and 44 percent lack sufficient trust in autonomous AI. The product pages and research library describe no AI governance framework, no AI management certification such as ISO 42001, no named owner of model governance and no testing before release. They say nothing about uneven output across matter types, parties or populations.

Sirion
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

The trust center has a section titled Artificial Intelligence Ethics and Governance, last modified 16 December 2025, and its whole content is three sentences. They say Sirion has set up an AI Governance Program called S-AIGP, which monitors and ensures compliance with the EU AI Act 2024/1689 and other AI regulations as they emerge. Readers are told to contact their Sirion Account Executive for more. Sirion publishes nothing on who owns model behavior, what is tested before release, how the program works, or bias and uneven output.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Icertis
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Section 4.5 of the agreement returns Subscriber Data on request at no fee and permits destruction if it is not requested within five days of termination. Exhibit B sets out strict role based access, identity provider authentication with multifactor support, audit logs of all user actions, encryption at rest and in transit, Azure network security groups and threat monitoring. It also commits Icertis to notify the Subscriber of any breach resulting in loss or unauthorized disclosure of Subscriber Data, under a documented incident process. Section 6.1 bars sale of personal data and its combination with other sources, while section 5.2 permits use of Subscriber Data to develop and improve the SaaS. A List of Standard Sub-Processors, in a version dated June 2023, is published on the foundation page.

Sirion
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

The data processing addendum, version 3, modified 2 July 2026, covers retention, access, subprocessors, incidents and encryption. Appendix B sets the retention period by the controller's contractual direction. Clause 8.1 requires deletion or return of all Customer Personal Data, including copies, within 30 days of termination. Any retention the law requires is limited to that purpose and stays under the agreement's protections, and the SaaS Terms add automatic deletion after 30 days as a backstop. Access runs on a need to know and least privilege basis, with automatic logout on inactivity. Subprocessors are named in a list published at its own URL. Sirion gives notice and an objection right for any addition or replacement, imposes equivalent terms on each, and is liable for their breaches. Clause 4.3 commits Sirion to notify the customer within 72 hours of establishing material impact from a confirmed Security Incident, and Appendix B says 48 to 72 hours, with updates until resolved. The definition expressly excludes unsuccessful attempts such as failed logins and denial of service attempts. Encryption is AES-256 at rest and TLS 1.2 in transit.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Icertis
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

Section 9.1 of the agreement gives a defense and indemnity for third party intellectual property claims, for claims by Icertis subcontractors or personnel, and for gross negligence causing injury or property damage. It states an exclusion for Subscriber Data. Section 10.1 excludes consequential loss, and section 10.2 caps each party at the amounts Icertis received in the preceding twelve months. Section 8.2 warrants noninfringement, professional performance and material conformity to the documentation, with a correction remedy and a termination right. Section 10.4 commits Icertis to carry commercial general liability cover of $1 million per occurrence and $2 million in aggregate. It adds technology errors and omissions cover including cyber liability of $5 million, umbrella cover of $5 million and employer's liability. The cover comes from a carrier rated A minus, runs for the term and one year after, and a certificate is available on request. The agreement gives AI output no separate warranty. An AI Acceptable Use Policy sits on the foundation page as an addendum to the agreement.

Sirion
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

Sirion publishes its SaaS terms and a separate end user agreement, so both can be read before signing. Clause 7.1 commits Sirion to indemnify and defend the customer against third party claims that use of the services infringes intellectual property. Clause 7.2 sets four exclusions, namely combination with materials Sirion did not provide, unapproved changes, unauthorized use, and use inconsistent with the documentation. Clause 7.3 gives the remedies of securing the right to continue, replacing or modifying the services, or terminating with a pro rata refund of prepaid fees, as Sirion's sole and exclusive liability. Clause 7.4 has the customer indemnify Sirion over customer data. Clause 8.1 caps each party's total liability, across the whole term, at the fees paid for the subscription in the twelve months before the first event giving rise to a claim. Clause 8.2 excludes lost profits, lost or damaged data and consequential loss, and under clause 8.3 the cap does not apply to fees owed, breach of confidentiality or the indemnities. Clause 6.2 warrants that the services perform materially in line with the documentation, with a pro rata refund if Sirion cannot correct a nonconformity reported within ten days. Separate Sirion AI Services terms extend the intellectual property indemnity to the AI features, but exclude claims that come from the customer failing to review or validate output. Section 5.1 of those terms disclaims any warranty that output is accurate or free from hallucinations. No insurance position is published.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Icertis
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Icertis publishes a Native Integrations page with prebuilt adapters for SAP, Microsoft, Salesforce, Workday, Adobe Sign and DocuSign, each described by what it moves. The SAP Ariba adapter syncs procurement contracts, line items and suppliers, and the SAP S/4HANA adapter brings buy side supplier master data into the platform. For ERP and finance, adapters for Microsoft Dynamics 365 Finance and Operations and for Workday Financials sync procurement contracts, suppliers and financial data. The Salesforce CRM and CPQ adapter creates contracts from accounts, opportunities and quotes, with two way sync of deal and pricing data, and a Dynamics 365 Sales adapter keeps contract and sales data in step. The Adobe Sign and DocuSign adapters return signed agreements and audit trails to the platform. Microsoft Teams, Microsoft 365 for the web and Outlook connections cover collaboration, and SAM.gov and federal clause adapters serve public sector work. Licensed public APIs and connections to OpenAI, Claude, Microsoft Copilot and SAP Joule agents round out the list. The page does not describe setup or what an administrator configures, and it names no document management or identity connector. The platform runs on Microsoft Azure, with Microsoft as a strategic partner, and its named competitors include SAP Ariba and DocuSign CLM.

Sirion
AA on Practice Systems Integration DepthDocumented, verifiable integrations into the systems legal work already lives in, with the depth described: what syncs, in which direction, and what a firm must configure.

Nine named connectors are documented, each with its direction of travel, in the Non-Native Integrations article in Sirion University, last updated 24 February 2026. Four SAP Ariba accelerators cover procurement, bids, awards and contract workspaces. An executed contract request in Sirion creates a purchase requisition in Ariba, and the resulting purchase order is written back. Ariba sourcing events and RFPs become Contract Draft Requests on set triggers, one per bidding supplier with line items mapped, and supplier redlines move into Sirion for legal review. Awarded RFx events create a draft request with awarded line items synced. Contracts finalized in Sirion copy into Ariba Contract Workspaces with metadata, documents, line items and status. Three more connectors cover supplier master data from Ariba, SAP S/4HANA Business Partners on scheduled transfers, and Oracle ERP with logging, error handling and sync status. The Microsoft Dynamics connector runs both ways in auto or manual mode. The article describes configuration through triggers, modes and scheduling rather than as a full guide, and the wider Sirion University catalog needs a login. Sirion's public pages do not document the Word add in or the Salesforce connector to this depth. No document management connector such as iManage or NetDocuments appears on them.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Icertis
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

Exhibit B of the SaaS Subscription and Services Agreement states that the platform is hosted on Microsoft Azure and that the Subscriber may select the Azure data center at the outset of the subscription. Production backups sit on geo replicated Azure storage. Exhibit A-2 distinguishes single tenant subscribers, who schedule their own upgrades and receive wider version support, from multitenant subscribers on the automatic upgrade calendar, so both tenancy models are offered. A FedRAMP government community cloud is listed separately. The agreement does not say where model inference runs.

Sirion
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Sirion's application is SaaS hosted by a cloud provider, according to the data processing addendum, and all customer data is stored and processed in a Sirion application instance specific to that customer. That isolation commitment sits in a contract rather than in marketing. Four underlying providers appear in the trust center, namely AWS, Azure, Oracle and IBM, which suggests customer choice without offering it as an option. Sirion's published documents make no residency commitment and give no region list or jurisdiction option. Nothing separates where processing happens from where data is stored. A Sirion library article describes the platform's multitenant scalability, which sits awkwardly beside the addendum's customer specific instance, and nothing published reconciles the two.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Icertis
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Exhibit B of the SaaS Subscription and Services Agreement states that Icertis is ISO 27001, ISO 27017 and ISO 27018 certified, holds SOC 2 Type 1 and Type 2 certifications and complies with ITAR. It manages risk under the ISO 27001 framework, commissions regular third party vulnerability assessments and penetration testing, encrypts data at rest with AES-256 and supports customer managed keys in Azure Key Vault. The agreement names no auditor, coverage period or self serve route to the reports. Icertis links a Trust Center from its site.

Sirion
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Appendix B of the data processing addendum names ISO 27001 as a held certification and describes the review process around it. Under clause 7.1, unless agreed otherwise, Sirion will give a copy of its latest security attestation report on the customer's written request, no more than once a year. Clause 7.2 adds a customer audit right, with scope, timing and controls agreed in advance and a reasonable fee. Appendix B also says Sirion reviews its cloud providers' SOC 1, SOC 2 and ISO 27001 reports as part of a shared responsibility model. That is oversight of the infrastructure rather than an attestation over the application. The report route is open to existing customers, so a prospective customer cannot get the report before signing. The addendum names no auditor, coverage period or scope statement for the ISO certificate. Sirion's trust center states ISO 27001:2022 certification. Its SOC 1 Type II and SOC 2 Type II sections explain what those reports cover, and its security page attributes SOC 1 and SOC 2 to the cloud providers Sirion runs on.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Icertis
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

Icertis names Microsoft as a strategic partner and Azure as its platform, and a Microsoft published customer story records Icertis monitoring Azure OpenAI deployments, which places Azure OpenAI in the stack. Its integrations page lists interoperability with OpenAI, Claude (Anthropic), Microsoft Copilot and SAP Joule agents. Neither source says which models power the Copilots, the contract intelligence engine or Vera, or which model serves which task. The agreement and product pages do not say where models run or commit to notifying customers when the model supply chain changes. A List of Standard Sub-Processors, dated June 2023, sits on the foundation page.

Sirion
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

An approach built on multiple models sits behind Sirion's AI, combining small purpose built models trained on enterprise contracts with large language models. Sirion presents that as the differentiator against generic models retrofitted for legal use. It names no large language model provider and identifies no model or version. It gives no processing location for the model layer as distinct from the cloud infrastructure. Nothing commits Sirion to notifying customers when any of it changes.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Icertis
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Icertis publishes no pricing page, rate, unit of charge or tier structure. Every commercial path on its site ends in a demo or contact request, and there is no free trial or self serve entry point. No third party pricing figure is published either.

Sirion
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing is published at any level, including the unit of charge. Sirion's site has no pricing page, no tier structure, no unit per seat, per contract or per agent, no volume banding and no statement of what implementation adds. Every call to action is a demo request. No published figure lets a prospective customer estimate cost before a sales process, even though Sirion publishes its SaaS terms, end user agreement and data processing addendum in full.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Icertis
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Icertis sells to large enterprises, says 30 percent of the Fortune 100 are customers across more than 90 countries and multiple languages, and covers buy side and sell side agreements rather than one direction. The vendor's own research publishes industry breakouts for public sector, healthcare and life sciences, and banking and insurance, among others. Functional coverage spans legal, procurement, sales, finance and HR. Icertis does not say which organization sizes, contract types or practice areas the platform is not built for. Third party reviews say small and most mid market businesses will find it more platform than they need.

Sirion
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Eight industries have their own pages. Financial services is split into procurement and into capital markets and credit. Insurance has a separate solution for triaging underwriting submissions. The others are automotive, IT services, healthcare, pharmaceuticals and life sciences, telecom, and oil and gas. Five departments have their own pages, covering in house legal, legal operations, procurement, sales and finance. Customers are in more than 70 countries, and the site is in English, German and French. Sirion does not say where the product stops. It excludes no contract or matter types, does not address law firms, government or public sector use, and describes coverage by industry and department rather than area of law.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Icertis
Permitted, in the contract

Section 5.2 of the SaaS Subscription and Services Agreement licenses Icertis to use Subscriber Data to provide the SaaS. It also lets Icertis use Subscriber Data to maintain, develop and improve the SaaS, including creating industry relevant analysis, provided the data is not shared with third parties and the Subscriber stays anonymous. Subscriber Data is defined to include the output of processing. The clause does not name model training. An Artificial Intelligence Acceptable Use Policy is listed on the foundation page as an addendum to the agreement.

Sirion
Permitted, in the contract

Library material from Sirion states that customer data stays within the customer environment and is not used to train external language models. Its SaaS Terms, version 6, modified 26 August 2026, reserve the opposite at clause 4.2. Sirion may direct its automated systems to review and process Customer Data to generally inform machine learning capabilities in the Subscription Services. The same clause covers generating aggregated and anonymized industry analytics, with a commitment not to publicly identify the customer or disclose Customer Data to third parties.

The agreement governs over a policy page, so the reservation is what binds the customer. It operates on Customer Data itself rather than on deidentified or aggregated derivatives, which gives it a broader reach than clauses limited to aggregate data. It says generally inform rather than train, so the words leave open whether it authorizes model training in the ordinary sense. The SaaS Terms, the end user agreement and the data processing addendum offer no opt out, consent step, configuration setting or exclusion route.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Icertis
Disclosed fixed window

Under section 4.5 of the agreement, Icertis returns Subscriber Data on written request in its then current format at no fee. It may destroy the data if no request arrives within five days of termination. Subscriber Data includes the output of processing. The agreement sets no shorter or configurable window for AI prompts and outputs during the term.

Sirion
Customer controlled, no zero option

The published data processing addendum says the retention period is set by contractual obligations as the controller directs. After termination, personal data is typically kept for 30 days. The window is therefore under customer instruction, with a stated default, in a contract rather than a policy page. The provision covers personal data rather than prompts and generated outputs specifically, and no zero retention setting is offered.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Icertis
Own model, documented

Exhibit B of the agreement describes the product's own permission model. It sets out strict role based access control, with authorization implemented through the platform's own features, identity provider authentication, and audit logs capturing every user action with date and time. Section 2.4 makes the Subscriber responsible for determining access privileges, and single tenant deployment is available. The agreement does not describe how the Vera agents respect those permissions across a contract portfolio.

Sirion
Own model, documented

Separation between customers is set out in the data processing addendum rather than in marketing. All customer data is stated to be stored and processed in a Sirion application instance specific to the customer, within the cloud service. A shared responsibility model applies, in which Sirion secures the software, the customer data and the related access, and the cloud provider secures the underlying facility. Vendor library articles describe role based access control with granular permissions.

Sirion's published material does not describe how access is enforced between teams inside a customer, where legal, procurement, sales and finance share the platform. A Sirion library article also describes the platform's multitenant scalability, and nothing published reconciles that with the addendum's customer specific instance. The buyer is an in house department, so separation between customer tenants is what applies here.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Icertis
Notice committed

Section 7.2 of the agreement permits disclosure of confidential information as required by law, regulation or court order. Unless legally prohibited, the receiving party must give the disclosing party prompt written notice before the disclosure and reasonable assistance in limiting it or obtaining a protective order. Confidential information is defined broadly, and Exhibit B states that Subscriber data is treated as confidential. Icertis publishes no transparency report.

Sirion
Notice committed

Section 5.3 of the SaaS Terms, version 6, modified 26 August 2026, holds the notice commitment. A party receiving a demand from an authority or court for the other party's Confidential Information may comply only after satisfying itself the demand is lawful. It must give as much prior notice as possible, where possible, so the other party can object, and mark the material as the other party's Confidential Information.

The duty is mutual and covers customer material. Confidential Information includes information that should reasonably be understood as confidential, and the AI Module clause at 1.8(b) confirms this by bringing Customer Data back into that definition. The notice duty is limited by the words where possible, not by a legal prohibition. The data processing addendum does not address third party demands. The terms pages, the addendum and the trust center give no transparency report or count of demands.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Icertis
Not addressed

Icertis identifies no primary law corpus, and the product does not appear to hold one. Retrieval runs against the customer's own contract repository, templates and clause library, so the source material is the customer's own agreements and its provenance is theirs. The product pages and research library name no vendor supplied legal corpus, license basis or update cadence, which reflects a product built on the customer's own contracts.

Sirion
Sources named, basis unstated

The working corpus is the customer's own contract set. Answers are described as carrying citations linked to the customer's own data, and agents extract and normalize contracts from sources the customer nominates. Sirion separately states that its purpose built models are trained on millions of enterprise contracts. That describes a second corpus by its makeup, but Sirion names no source, states no license or rights basis, and does not say whose contracts those are.

The product does not retrieve primary law, so the usual questions of jurisdiction and coverage do not arise. No update cadence is published.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Icertis
Not addressed

Icertis is a contract lifecycle platform grounded in the customer's own agreements, with no case law research feature, so a citator falls outside its design. Its product pages and research library say nothing about whether authority carries a treatment signal or whether the product tracks subsequent history, and they name no commercial citator license.

Sirion
Not addressed

The platform manages contracts, obligations and supplier performance rather than retrieving case law or legislation, so a citator is not part of what it sells. The home page, the trust center index with its AI ethics, compliance and security sections, and the terms and policies index do not address whether legal authority is reviewed for subsequent history. They describe no citator, treatment signal or currency check.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Icertis
Not addressed

The product pages and research library do not describe what Icertis does when it cannot ground an answer, and mention no explicit no answer path or confidence signal shown to the user. The boundaries the vendor describes are limits a customer sets on what an agent may do. They are a permission concept, not a statement of what the system does when it does not know.

Sirion
Not addressed

Agents that sense intent, reason over enterprise data and act autonomously are central to Sirion's material, along with answers delivered with citations. The home page and the trust center, with its AI ethics, compliance and security sections, do not say what happens when the customer's contract set does not support a response. They document no explicit no answer or abstention path and no confidence or grounding score.

Sirion's statement that users stay in control for strategic exceptions describes escalation rather than how the model behaves under uncertainty.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

Icertis
None located

The AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known, records no court order, opinion or disciplinary record naming Icertis. Published 2026 sanctions summaries and secondary sanctions trackers do not name it either. Icertis is a contract lifecycle platform with no case law research feature, so its output is very unlikely to reach a court filing as cited authority.

Sirion
None located

The AI Hallucination Cases database, maintained by Damien Charlotin, tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known. It records no court order, opinion or disciplinary record naming Sirion or SirionLabs, its former company name. Published 2026 sanctions trackers and trade press summaries do not name it either. The platform runs enterprise contracting and supplier governance rather than producing court filings.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Icertis
Not addressed

Icertis publishes substantial annual research on AI adoption and trust in contracting, including the State of Contracting reports, and that research surveys practitioner sentiment. Neither the research library nor the blog, the news index or the product pages engages with a named ethics opinion or bar guidance, including ABA Formal Opinion 512 and state bar guidance. None of it addresses the professional responsibility rules that bind the vendor's legal buyers.

Sirion
Not addressed

Sirion's compliance material is oriented to regulation and security frameworks, covering ISO 27001, SOC 1, SOC 2 and the EU AI Act. None of it addresses the professional conduct obligations binding the lawyers who use the product. The home page, the trust center index with its AI ethics, compliance and security sections, and the terms and policies index do not engage with any bar or ethics guidance. That includes ABA Formal Opinion 512 and any state bar or Law Society material.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Icertis
Savings claims only

Icertis frames its material around business outcomes rather than hours, such as growing revenue, controlling costs, reducing risk and ensuring compliance, and it claims faster drafting and more precise execution. Its product pages and research library describe no per matter record of work done with AI for fee purposes and give no guidance on billing, fees or client disclosure. The buyer is a corporate legal, procurement or finance function rather than a firm billing a client by the hour, so the savings are enterprise cost rather than billable time.

Sirion
Savings claims only

Public materials are built around speed and automation gains. They cite 90 percent faster contract centralization, 85 percent faster insights, up to 90 percent faster time to contract and 70 percent faster agentic automation. A customer reports as much as a 50 percent rise in tasks automated. The home page, the trust center and the terms and policies index offer no record of AI assisted work by matter for fee purposes, and no guidance on billing, fee or disclosure treatment.

The buyer is an in house function rather than a firm billing a client, so fee disclosure here comes down to internal cost and outside counsel spend, and the published material addresses neither.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Icertis
Subprocessors listed

Icertis publishes a subprocessor list on its foundation page alongside the agreement, a Data Protection Addendum with standard contractual clauses, EU Data Act terms and an AI Acceptable Use Policy. The list on that page is dated June 2023.

Sirion
Subprocessors listed

Appendix D publishes a Sub-Processor List, stated to be regularly updated, at a named URL that can be reached without a sales conversation. Clause 5.4 commits Sirion to notify the customer of updates and give an opportunity to object to additions or replacements. Clause 5.6 requires equivalent data protection terms on every subprocessor and keeps Sirion liable for their breaches. Sirion publishes no disclosure pack for a firm answering a client's AI clause, and no consent or notification material for clients.

Its published material names no model provider. The trust center's AI ethics page routes AI governance detail to a Sirion Account Executive.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Icertis
Not addressed

Icertis tracks obligations and approvals per contract, and third party reviews refer to standardized workflows and access controls, so a workflow trail plausibly exists. The product pages and research library describe no export that covers the model used, the sources retrieved and human verification together. Icertis names no model behind its features, so such a record could not state the model used. It is a contracting platform rather than a litigation product, so a judicial AI disclosure order is unlikely to reach its output.

Sirion
Partial record

Answers are said to carry citations linked to the customer's own data. Vendor material says every AI response includes citations to exact sources, with citation and justification at clause level. Audit trails are said to record system activity, user actions and data changes. Together these cover the sources retrieved and part of what was done, as a side effect of the product's design. Sirion identifies no model, so its material does not show which system produced a passage, and it describes no export built for court disclosure or AI use certification. The product serves enterprise contracting rather than litigation, so court standing orders are not its usual setting.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • Commercial Transparency
Signals neither addresses in public material
  • Good Law Verification
  • Refusal and Uncertainty Behavior
  • Bar Guidance Alignment

Which one fits

Choose Icertis if

  • You need to choose the data center. Icertis lets the subscriber select its Azure data center when the subscription starts. It offers single tenant and multi tenant hosting and lists a FedRAMP government cloud.
  • You want insurance behind the contract. Icertis commits to $5 million of technology errors and omissions cover, including cyber liability, from an A minus rated carrier. It also caps each party at a year of fees and indemnifies intellectual property claims.
  • You want customer satisfaction measured by an outside party. Icertis was a 2025 Gartner Peer Insights Customers' Choice for contract lifecycle management. In that report 93 percent of 84 reviewers recommended it.

Choose Sirion if

  • Your contracts start from Ariba sourcing events or run on Oracle ERP. Sirion's Ariba accelerators turn sourcing events into contract requests and copy finished contracts back into Ariba. Further connectors cover SAP S/4HANA, Oracle ERP and Microsoft Dynamics, each documented by direction.
  • You want answers you can trace. Sirion says every AI response carries citations to exact sources in the customer's own contracts. It says each citation points to a clause and comes with a justification.
  • You want incident and isolation terms in the addendum. Sirion keeps each customer's data in its own application instance and notifies a confirmed incident within 72 hours of establishing material impact. Customers can request its latest attestation report once a year.

In summary

Icertis

Icertis Contract Intelligence is an enterprise contract lifecycle platform for buy side and sell side agreements, with 30 percent of the Fortune 100 claimed as customers across more than 90 countries. Copilots and an extraction engine pull out clauses, obligations and risk, and the Vera agents reached the platform in 2026. According to the AI Legal Index, Icertis puts its commitments in its published agreement. It sets a cap of a year of fees, an intellectual property indemnity and named insurance cover, and lets the subscriber pick the Azure data center. Section 5.2 lets Icertis use customer data to develop the service, provided the customer stays anonymous and nothing is shared with third parties. Its integrations page lists prebuilt adapters for SAP, Microsoft, Salesforce and Workday systems. Icertis does not say which models power its own AI features, and no price is published.

Source: AI Legal Index, 2026

Sirion

Sirion is an enterprise contract lifecycle platform with three product lines. Store handles extraction and search, Create handles drafting and negotiation, and Manage tracks obligations and performance. Its agentOS layer lets customers build agents that run across enterprise systems. Customers include Citi, GE, Coca-Cola and Chevron in more than 70 countries. According to the AI Legal Index, Sirion documents its ERP connections closely, from SAP Ariba to Microsoft Dynamics, by direction of travel. Its data processing addendum keeps each customer in its own application instance and commits to notice within 72 hours of establishing a confirmed incident's material impact. Clause 4.2 of its terms lets its systems process customer data to inform machine learning.

Source: AI Legal Index, 2026

Questions buyers ask

Icertis vs Sirion: which is better for enterprise contract management?

Both connect to SAP and Microsoft systems. Sirion fits contracting that starts from Ariba sourcing events or runs on Oracle ERP, with each connection documented by direction and what Sirion describes as clause level citations on AI answers. Icertis fits an enterprise that wants hosting choice, a FedRAMP option, Salesforce and Workday adapters and named insurance behind its contract. Both handle procurement and sales contracts at global scale. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Do Icertis and Sirion use customer contracts to train AI?

Both agreements leave room for it. Icertis may use customer data to maintain, develop and improve its service, provided the customer stays anonymous and nothing is shared with third parties. Sirion may have its automated systems process customer data to generally inform machine learning, with no opt out. Neither clause uses the word train, and neither agreement names the models. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

How do Icertis and Sirion control their AI agents?

Icertis says Vera agents act on their own within boundaries the customer sets, without saying how a boundary is configured. Sirion says agents act autonomously, with the user in control for strategic exceptions. Its AI governance page names a governance program and sends readers to an account executive for detail. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Where are Icertis and Sirion hosted?

Icertis runs on Microsoft Azure, with the data center chosen by the subscriber at the start. It offers single tenant and multi tenant hosting and a FedRAMP government cloud. Sirion keeps each customer in its own application instance and names AWS, Azure, Oracle and IBM as providers, but names no region. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

What do Icertis and Sirion both leave unpublished?

Neither publishes a price or unit of charge, an accuracy or hallucination measure, or the models behind its AI in its agreement. Neither agreement addresses attorney client privilege. Neither says in its agreement or product pages where its agents stop short of legal advice, though both sell to procurement, sales and finance teams as well as lawyers. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Disclosure

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything on it comes from public material on the dates shown. How the index grades.

Both agreements allow some use of customer data beyond running the service, worded differently. Section 5.2 of Icertis's agreement allows use to maintain, develop and improve the service, provided the customer stays anonymous and nothing is shared with third parties, and does not mention training. An AI Acceptable Use Policy and a subprocessor list sit beside the agreement, and Icertis links a Trust Center from its site. Clause 4.2 of Sirion's terms lets its systems process customer data to generally inform machine learning, with no opt out, though its library material says data does not train external models. Sirion's separate AI Services terms disclaim any warranty that AI output is accurate. Neither vendor reviewed this page.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
October 8, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746