Ironclad vs Leah: how they compare in 2026
Two enterprise contract platforms with agents on top, sold to legal, procurement and business teams. Ironclad runs each agreement through a workflow designer and redlines with AI Playbooks, while its Jurist agents draft, review and research. Leah stretches further, putting agents to work on procurement and finance tasks under a governance loop the customer configures. Both publish their contract terms, and the terms look alike. Each caps liability at a year of fees and triples the cap for breaches of its data and security terms. Each names its model providers, Anthropic and OpenAI among them, with thirty days' notice before a new subprocessor. The differences sit in the detail. Ironclad also indemnifies customer data breaches it causes, hosts in the US or the EU, and offers its SOC reports through a security portal. Leah's uptime terms let a customer leave after repeated misses, where Ironclad pays service credits. On training, Ironclad's AI Addendum makes it opt in, set in the admin console. Leah says customer contracts never train models, on its web pages rather than in its terms.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Intake, the no code Workflow Designer, approvals, routing, signature, the repository, analytics and integrations all predate generative AI and work without it. Ironclad sells that workflow layer as its foundation. The models drive central parts of the contract work on top of it. AI Playbooks, with each play tied to a clause, do the redlining. Jurist runs a named family of agents for drafting, editing, review, research, intake and redlining under a Manager Agent, with Conversational Search over the repository. The AI layer sits on an established product rather than one built on AI from the start.
Leah sells AI agents and an orchestration layer that sit on top of a contract lifecycle platform, and that platform works without them. The vendor describes it the other way round. It says other vendors bolted AI onto systems built for manual workflows, while Leah was designed from scratch with orchestration as the foundation. ContractPod Technologies has sold contract lifecycle management since 2012. Leah launched in March 2023 as an AI services hub within that platform, went standalone in May 2023, and Leah Intelligence followed in October 2024. Without the agents, the product is still a working CLM with guided intake, approval routing, DocuSign and Adobe Sign execution and a contract repository. That CLM has its own market and its own Gartner category placement. The orchestration layer on top is model driven.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Ironclad claims precise redlining, advanced AI, and proprietary legal AI models trained on legal terminology with prompts engineered for legal work. AI Playbooks tie each play to a clause. The system proposes varying degrees of revision to match preferred terms with minimal change, so its output follows a standard the customer wrote and a reviewer can check it against that standard. Ironclad publishes no accuracy figure, hallucination rate, test set or evaluation. It does not describe its retrieval method or how output links to a source a user can open. Its AI Addendum says AI output may be incorrect or inaccurate, and Ironclad does not warrant that output will be accurate, complete or error free.
Leah returns to accuracy repeatedly in its materials, and the AI governance page says every action is measured against benchmarks for accuracy, bias and outcome. Neither that page nor the home page publishes a result from that measurement. They give no accuracy figure, no error or hallucination rate, no description of any benchmark or test set and no published evaluation. The product material describes a legal helpdesk that answers contract questions with sources attached, so a user can in principle check an answer against its source. Neither page says what the system does when the customer's own contracts do not support a position.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Human in the loop governance, Ironclad states, ensures every agent works transparently and is auditable and controllable. The vendor says plainly that the customer is in charge. Customers get governed and auditable AI review frameworks they can review, override and continuously govern across teams and contract types. The controls are administrative as well. Playbook permissions let administrators configure which users and groups may view, create and edit playbooks. A Manager Agent routes tasks across the agent family, so the orchestration is visible. The vendor says the agents automate repetitive lower risk work, while strategic negotiation and nuanced risk assessment stay with the lawyer. The AI Addendum makes the customer responsible for reviewing and validating output before using it, and says the AI products are not a substitute for human oversight. Ironclad does not publish the threshold at which an agent stops or escalates.
Leah's dedicated AI governance page sets out a three stage control loop. In the first stage, policy in, the customer defines which agents may act, on which data, within which thresholds and where escalation is required. Those policies are held as configuration rather than code. In the second, execution governed, every agent action runs through those policies in real time. Approvals, escalations and rejections are applied automatically, and the orchestrator enforces guardrails at each step. In the third, audit out, every decision is logged with the rationale, what the agent did, why, under which policy, on what data and to what outcome. The records are described as tamper resistant and immutable. The loop sets the thresholds, the review points and the route back to human judgment. Leah's home page puts the position in one line, that the workflow runs itself while the judgment stays human. The page does not say what happens after an output is found to be wrong. Default modes are not described, because the customer configures the guardrails rather than receiving them preset.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
According to Ironclad, Jurist gave legal operations at NEXT Insurance 50 percent of its time back. Customer quotes carry before and after numbers. In one, a first pass redline that took 30 minutes to a couple of hours becomes a solid first draft in minutes. In another, an MNDA review or custom order form clause drafting goes from an hour to a day down to minutes or seconds. Several of the quoted figures do not name the person speaking. Ironclad publishes a customer stories section, though no dated case study that states its method.
Leah publishes qualitative quotes from four named people. Noelle Perkins is EVP and Chief Legal Officer at Cushman and Wakefield, and Lidia Kamleh is Chief Legal Officer at Dubai Future Foundation. Frances Bain-Cumberbatch is Chief Legal and External Affairs Officer at Ansa McAL, and Zillia Knight is Senior Legal Officer at Terumo Europe. Three results are published with the customer unnamed. A major American logistics company cut contract review time by 91 percent. A global manufacturer protected more than $18 million of revenue, and an American retail REIT tracked more than $2 million of savings. About 54 enterprise logos appear, including Philips, MUFG, Sandoz, Pernod Ricard, Alaska Airlines and Wood PLC. PwC and KPMG appear among them. PwC entered a commercial alliance in March 2024, and Epiq resells Leah in its Service Cloud. Integreon is quoted as an early adopter that resells it, and Pinsent Masons adopted it for managed legal services in July 2025. Partners and customers are shown together without distinction, and the Chief Product Officer of Execo, another services partner, is among the testimonials.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Under its AI Addendum, Ironclad trains its own models on Customer Data, Input and Output only if the customer opts in through the AI Training Settings in the admin console. A later opt out stops new training from that date. Before any such use, Ironclad de identifies, anonymizes and aggregates the data, and it commits to measures so that output generated for other customers does not include that customer's data. The addendum separately lets Ironclad use Input and Output to evaluate the performance and accuracy of the service, whether or not the customer opts in. The external LLM providers, listed as AI subprocessors, are barred from training their own models on Customer Data, with zero data retention enabled where available. Section 5 of the Enterprise Services Agreement treats Customer Data as confidential information. Its SOC 2 certification covers the privacy trust category, and it holds ISO 27701 for privacy information management. The published terms do not address attorney client privilege or work product handling, and Ironclad does not document separation between customers, users or matters.
Leah says customer contract data is never used to train models. The AI governance page treats data leaking into models the customer does not own as a failure it engineered out. It says zero data retention is the only acceptable answer, and that Leah enforces zero retention with OpenAI and Anthropic so they process data but never store it. Encryption is AES-256 at rest and TLS in transit, with keys in Azure Key Vault, rotated and reachable only through controlled service accounts. Role based access control is said to apply at every layer, and single tenant deployment is offered for customers with strict isolation needs. Leah sells to Fortune 500 legal departments, and none of this material addresses privilege or work product.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
Dedicated pages address legal operations and general counsel alongside procurement and IT. Ironclad describes the platform as serving business teams that touch contracts, with the AI proposing redlines and drafting negotiation ready revisions for those users, so the intended audience is broad by design. Section 2.3 of the AI Addendum states that Ironclad is not a legal advisor to the customer and that using the AI products creates no attorney client relationship. It tells the customer to consult its own counsel on legal, regulatory or compliance matters. A separate AI Disclaimer says AI output does not constitute legal or professional advice, and that a licensed professional should be consulted before anyone acts on it. Neither document addresses competence or supervision duties or sets jurisdiction limits. The human in the loop governance language describes how the system is controlled, which is a different thing from a professional responsibility position.
Leah publishes nothing on the line between a tool and legal advice. Its site carries no disclaimer of any kind and no ethics or professional responsibility page, and it names no bar or ethics guidance, including ABA Formal Opinion 512. The platform is sold to run legal work end to end across legal, procurement and finance teams. In the vendor's own framing, agents carry out commercial work in several steps without routing every decision through a person.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
The governance model rests on governed and auditable AI review frameworks and human in the loop governance, which Ironclad says make every agent transparent, auditable and controllable. Customers can review, override and continuously govern agent behavior across teams and contract types. Administrators set permissions for who may view, create and edit the playbooks that drive AI behavior. The vendor presents these as working controls rather than a principles page. A chief technology officer is publicly named as owning the AI roadmap, and Ironclad's security portal lists an AI Security and Governance document available on request. Ironclad publishes no AI management certification such as ISO 42001 and no testing results before release. Its published material names no owner accountable for model governance apart from the technology function, and says nothing about uneven output across matter types, parties or populations.
A dedicated AI governance page names six failure modes the vendor says it engineered out. They include black box decisions that cannot be defended to a regulator or board, and compliance frameworks retrofitted after the fact. Against them the page sets three pillars and a loop of policy, execution and audit. Each action is logged with its rationale and governing policy, in records described as tamper resistant and immutable. The page also says every action is measured against benchmarks for accuracy, bias and outcome, and that accountability is structural rather than aspirational. It names no person or role accountable for model behavior and describes no testing before release. It gives no benchmark method or schedule and discloses no bias measurement result.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Routine audits produce third party SOC 1 and SOC 2 Type II reports certified against security, availability, confidentiality and privacy. Ironclad also holds ISO 27001, 27701, 27017 and 27018, runs a dedicated GDPR program, and has Trusted Cloud Provider status as a Cloud Security Alliance member. Its Data Processing Addendum, version 3.10 effective 5 March 2026, says Ironclad keeps Customer Personal Data only as needed to perform the services. It destroys all copies within 90 days of termination, with a certificate of deletion on request. Section 6(b) commits to notice of a security incident within 48 hours. A subprocessor list at ironcladapp.com/subprocessors names Google Cloud Platform for hosting and Anthropic, OpenAI and Extend as AI providers. The addendum gives 30 days' email notice and an objection right before a new one is added. Ironclad's AI material says zero data retention is enforced at the external model layer, and the AI Addendum commits to enabling it where available. Its data centers run across multiple regions on public cloud providers that the vendor says are themselves certified under SOC 2, ISO 27001 and PCI DSS.
The AI governance page describes TLS in transit and AES-256 at rest. Encryption keys are managed in Azure Key Vault, rotated regularly and reachable only through tightly controlled service accounts. The page also lists multifactor authentication, secure API gateways, network segmentation, real time monitoring and a documented incident response plan. Audit logs are described as comprehensive, tamper resistant and immutable. For outside assurance, the vendor says an independent Managed Security Service Provider audits it every year and that it is penetration tested regularly.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Version 2.2 of the Enterprise Services Agreement, effective 1 July 2026, is published in Ironclad's Legal Center. Section 9.b caps each party's liability at the fees paid in the twelve months before the event giving rise to it. Section 9.d raises the cap to three times that amount for Special Claims. These are breaches of the customer data, information security or confidentiality terms that lead to unauthorized disclosure and misuse of Customer Data, and amounts due under the Data Indemnity. Gross negligence, intentional misconduct and the IP Indemnity are uncapped under section 9.c, and section 9.a excludes consequential loss. Section 8.a gives a defense and indemnity against third party intellectual property claims and against claims arising from unauthorized disclosure of Customer Data caused by Ironclad's breach. Section 6.a warrants that the services materially conform to the agreement and order form and comply with applicable law. Ironclad has 30 days to fix a nonconformity, after which the customer may terminate for a pro rata refund. Exhibit A targets 99.7 percent uptime, with service credits of 1 to 3 percent of the annual fee as the sole remedy. Section 6.b leaves the customer solely responsible for results, including AI output, and neither the agreement nor the AI Addendum indemnifies AI output. The agreement contains no insurance commitment.
Section 16.5 of the Master Terms and Annexes sets a General Cap equal to fees paid or payable in the twelve months before the first incident. An Enhanced Cap of three times that applies to breaches of its security or data protection terms, meaning the security clause and the data processing addendum. Indemnities, intellectual property claims, breach of confidentiality and anything that cannot legally be limited are uncapped. Section 17.1 gives the customer an indemnity against third party intellectual property claims. Section 8.2 warrants that the service will perform materially as documented, with a thirty day fix period under 8.3 and termination with a refund if the fix fails. Annex A publishes uptime tiers of 99.00, 99.5 and 99.9 percent by support plan. A tier missed in three consecutive months, or in four months out of six, allows termination with a refund. Three limits apply. Breaches of confidentiality involving Customer Data fall outside the uncapped claim, so they stay capped and rise to the Enhanced Cap only where the security or data protection terms are also breached. The agreement gives no indemnity for AI output, such as inaccurate output, hallucination or training data provenance. Section 9.2 bars the customer from submitting Sensitive Data, including GDPR Article 9 categories, and the provider disclaims liability for it. These terms are version 3.0c. Version 4.0, dated 4 January 2026, changes only the trading name, according to the vendor.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Ironclad names Salesforce and Coupa specifically, and calls its Salesforce connector the number one Salesforce integration in the market. It has a dedicated integrations page and claims the deepest integrations in the market, treating integration as a primary differentiator. Teams create, manage and collaborate on contracts from inside the systems they already use rather than switching into the CLM. The integrations lean toward enterprise commercial systems rather than legal document management. Ironclad's published integrations include no legal document management connector such as iManage or NetDocuments. It does not document, per integration, what moves in which direction or what an administrator configures.
Leah names its integrations and describes each by function. They cover ERP platforms including SAP and NetSuite, procurement systems including Coupa, financial systems, identity providers including Okta, and existing contract lifecycle tools. DocuSign and Adobe Sign are built in for signing, and a Microsoft Word add in handles redlining. The vendor also describes how the integrations work. It says Leah connects and executes rather than copying data passively, and carries out work across connected systems through the orchestration layer. Leah has a dedicated integrations page, but publishes nothing on what syncs in which direction or what a customer must configure. No document management integration such as iManage or NetDocuments appears, which fits a product built for in house teams rather than law firms.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
To meet data residency requirements, Ironclad says it uses multiple data center regions from its cloud providers. Its subprocessor list shows two CLM regions, the United States and an EU datacenter, both hosted on Google Cloud Platform, with Anthropic and OpenAI processing AI requests in the EU for EU hosted customers. Clickwrap runs on Amazon Web Services in the United States. Ironclad does not state a tenancy model or say what changes between plans.
The standard deployment is shared. Single tenant deployment is available for customers with strict isolation requirements. The vendor also offers what it calls a dedicated zero trust private environment in Azure OpenAI Studio, described as fully isolating data from all other customers. Leah runs on Azure, with keys held in Azure Key Vault. On data residency the vendor says only that it supports the residency and regulatory needs typical of large multinational enterprises. It names no region or jurisdiction and describes no customer choice.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
SOC 1 and SOC 2 Type II reports come from routine third party audits, and Ironclad names the trust categories certified as security, availability, confidentiality and privacy. Its security portal, run on SafeBase, lists SOC 1, SOC 2, ISO/IEC 27001 with its statement of applicability, 27017, 27018, 27701, CSA STAR, HIPAA, GDPR and CCPA. Reports, a penetration test report, a CAIQ and cyber insurance documentation are available there on request. Ironclad also holds Trusted Cloud Provider status from the Cloud Security Alliance, and says its underlying cloud providers are themselves SOC 2, ISO 27001 and PCI DSS certified. The portal shows no auditing firm, audit coverage period or report date.
The AI governance page claims SOC 1 Type I and II, SOC 2 Type I and II, GDPR compliance, CCPA compliance, HIPAA readiness and ISO 27001 alignment. The home page FAQ, on the same site, says only that Leah is SOC 2 Type II certified, so the two pages disagree on what is held. For ISO 27001 and HIPAA the governance page says aligned and ready rather than certified. The auditor is described only as an independent Managed Security Service Provider, a category rather than a named firm. No coverage period, report date or audit scope is given. Penetration testing is said to be regular, with no partner named and no summary published. Leah has no trust center or portal, so there is no published route to request a report.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Two layers of models sit behind Ironclad's AI. One is proprietary legal AI models that Ironclad built, with prompts engineered for legal work. The other is external LLM providers, which its subprocessor list names as Anthropic and OpenAI, alongside Extend for AI processing and Google Cloud Platform for cloud and AI infrastructure. They run in the United States and, for EU hosted customers, in the EU. The Data Processing Addendum gives 30 days' email notice and an objection right before a new subprocessor is added. The AI Addendum bars AI subprocessors from training on Customer Data and commits to zero data retention with them where available. Ironclad does not say which model or version serves which feature.
The DPA Setup Page lists four model providers against Leah Functionality, each noted as storing or retaining no customer data and each with named jurisdictions. Anthropic PBC is listed for the USA, Japan, and the EU or UK, and OpenAI LLC for the USA, Japan, and the EU or Switzerland. Cohere Inc. is listed for Canada, the USA, the EU or UK, and Japan. Google AI/ML with Google Cloud is listed for the USA, Japan, and the EU, Switzerland or UK. Microsoft Azure Services is listed for hosting and translation, and the private deployment option runs in Azure OpenAI Studio. DPA clause 4.3 requires any new subprocessor to be added to the published list with at least thirty days' notice before it processes customer personal data. Clause 4.4 gives a thirty day objection right on reasonable data protection grounds. If the objection is not resolved, the affected order can be terminated with a refund of prepaid unused fees. No model or version is named for any provider. The platform is described as choosing among several language models for each task and letting customers extend or customize models. Nothing published shows which provider handled a given piece of work.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
There is no pricing page on Ironclad's site, and it publishes no rate, unit of charge or tier structure. Every commercial path on the site ends in a demo request, and there is no free trial or self serve entry point. Its AI usage policy, version 1.1, bills overages on AI Credits at Ironclad's then current list price without publishing that price. Third party coverage describes implementation cost as depending on the scope of the CLM deployment rather than on a published rate.
Leah publishes no pricing at any level, including the unit of charge. The primary navigation covers platform, solutions, resources and company, and neither it nor the footer sitemap has a pricing page. There is no tier structure, no unit per seat, contract or agent, no volume banding and no indication of what implementation adds. Every call to action across the site is to request a demo. An implementation FAQ says timelines vary with scope and integrations and that a detailed plan is built during evaluation. It says nothing about cost. No published page gives a view of price before a sales process.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Four buyer personas have their own published positioning, namely legal operations, general counsel, procurement and IT. Ironclad also addresses business teams beyond legal that handle contracts. The stated target is enterprise and global business teams. At least one industry, manufacturing, has dedicated positioning around leakage and contract performance. The practice scope is contracting end to end, from intake to after signature, with no claim to litigation or research capability. Ironclad does not say which organization sizes or contract types the platform is not built for, and publishes no full list of industries or practice areas.
Leah publishes dedicated industry pages for CPG and manufacturing, energy and utilities, financial services, healthcare, and pharma and medical devices. It describes its customers as Fortune 500 enterprises in regulated industries. By function it publishes pages for legal leadership, legal operations, sales and revenue, procurement, and finance. The pages carry distinct propositions written for the General Counsel, the contract operations team, the Chief Procurement Officer and the finance leader. The customer roster spans banking, airlines, pharmaceuticals, consumer goods and engineering. No published page says which practice areas, contract types or matters the platform does not support, and none addresses smaller organizations. Law firms appear only indirectly, through managed service partners, rather than as a served segment.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Section 1.1 of the AI Addendum, version 2.1 effective 20 April 2026, lets the customer enable AI Training Settings in the admin console. Only then may Ironclad use Customer Data, Input and Output to train and improve its own AI models and products. Section 1.2 requires that data to be de identified, anonymized and aggregated first, and output generated for other customers must not include it. Section 1.3 lets the customer opt out later, which stops new training but does not unwind training already under way.
Section 2.1 separately lets Ironclad use Input and Output to evaluate the performance and accuracy of the services, whether or not the customer opts in. Section 3.1 bars AI subprocessors, the external LLM providers, from training their own models on Customer Data. The vendor makes the case for opting in openly, and says the customer stays in control and the data stays confidential.
Leah's security FAQ, on its home page, says customer contract data is never used to train models. The AI governance page treats data leaking into models the customer does not own as a failure it engineered out. It says zero data retention is enforced so that OpenAI and Anthropic process data but never store it. No term in the Master Terms and Annexes v3.0c names training, model training, machine learning or model improvement for customer content, either way.
Two clauses come close. Clause 5.1 limits the provider's use of Customer Data to providing and maintaining the Cloud Service, Support and Professional Services. Clause 5.4 allows use of Usage Data, the provider's technical logs, data and learnings about the customer's use, to run, improve and support the service. Usage Data excludes Customer Data, so the improvement right covers telemetry, not content. Together the clauses fit a ban on training without stating one.
They leave open whether model improvement counts as maintaining the service. The commitment rests on the published policy, not a contract term. Version 4.0 of January 2026 changes only the trading name, according to the vendor.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Section 8(b) of the Data Processing Addendum, version 3.10 effective 5 March 2026, requires Ironclad to destroy all copies of Customer Personal Data, including archival copies, within 90 days of the agreement ending. On request it returns the data within 30 days and issues a certificate of deletion within 30 days. Section 7.c of the Enterprise Services Agreement gives a 28 day courtesy period after termination for exporting the repository.
During the term the addendum says Ironclad keeps the data only as needed to perform the services, and the AI Addendum sets no separate period for prompts and outputs. Ironclad says it enforces zero data retention with its external LLM providers, and the AI Addendum commits to enabling it where available. The product is a system of record built to hold every executed agreement for as long as the customer keeps it.
Section 14.4 allows export during the subscription and deletion of Customer Data within sixty days of a request after termination. That is subject to standard backup or record retention policies and legal requirements, and the customer cannot change the period. The data processing addendum adds secure deletion to industry standards at clause 8.2, with a certificate of deletion on request. Schedule 1 commits to export in CSV or a similar format within thirty calendar days and to physical destruction of media by a recognized provider.
Prompts and outputs have no separate window. The agreement treats Customer Data as one class, defined at section 23 as any data, content or materials the customer submits, so prompts and outputs follow that regime. Usage Data sits outside it. Section 5.4 lets the provider collect Usage Data, meaning its technical logs, data and learnings about the customer's use, excluding Customer Data. The provider may use it to run, improve and support the service and for other lawful purposes such as benchmarking.
It may disclose Usage Data externally only if deidentified and aggregated across customers. No deletion duty applies to Usage Data, and section 14.5 makes 5.4 survive termination.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product keeps its own documented permission model rather than inheriting one from a document management system. Support documentation states that administrators can configure Ironclad users and groups to permit or restrict which users may view, create and edit AI Playbooks. The standards that drive AI behavior are therefore themselves access controlled. The workflow layer routes and assigns contracts across named reviewers.
Ironclad's published material does not describe segregation of the contract repository itself between users or matters, or any ethical wall concept. It names no legal document management integration whose permissions retrieval could inherit at query time. The buyer is an in house or business team rather than a firm carrying conflicts obligations, so the question applies differently than it would for a product sold to law firms.
Leah describes separation at the customer level, through deployment options. The vendor states that single tenant deployment is available for customers with strict data isolation requirements. It says a dedicated zero trust private environment within Azure OpenAI Studio ensures complete isolation from all other customers. Role based access control is stated to be enforced at every layer. That wording makes isolation a deployment option rather than the default, and nothing published describes how customers are separated in the standard shared deployment.
Legal, procurement, finance and shared services teams work in the same system, and nothing published addresses boundaries between them inside a customer.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Section 3(i) of the Data Processing Addendum commits Ironclad to notify the customer promptly of any government or law enforcement request to access or seize Customer Personal Data, unless the law or a binding request prohibits it. Ironclad must also help the customer contest the request. Section 5.c of the Enterprise Services Agreement lets either party disclose confidential information, which includes Customer Data, under a court or government order.
Where the law permits, it must first give reasonable notice so the other party can contest the order. Ironclad publishes no transparency report.
Section 19, headed Required Disclosures, lets the recipient disclose Confidential Information where the law requires. Where the law permits, the recipient must give advance notice and reasonable cooperation, at the discloser's expense, to obtain confidential treatment. The clause expressly covers Confidential Information including Customer Data. Section 23 confirms that the customer's Confidential Information includes Customer Data, so customer material sits inside the notice duty.
The duty is mutual and binds whichever party receives the demand. Section 14.5 makes section 19 survive termination. Leah publishes no transparency report, so there is no public count of demands received or of how they were answered. These terms are version 3.0c. Version 4.0 of January 2026 changes only the trading name, according to the vendor.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No primary law corpus sits behind the product. Retrieval runs against the customer's own contract repository and AI Playbooks. Ironclad describes its proprietary models as trained on legal terminology and contract management architecture, with prompts engineered for legal work. Where customers opt in, the models also train on anonymized and aggregated customer contracting data. That contributed data is the closest thing to a vendor corpus, and Ironclad states its source, which is customers contributing under consent. The site, the Ironclad AI page and the article library give no scale figure, license basis or update cadence for it.
Leah works on the customer's own material. The vendor states that Leah operates against the customer's policies and playbooks and gains intelligence from the customer's unstructured data and business rules. It answers contract questions from the customer's repository with sources attached. The vendor also refers to Leah operating against established legal precedents, but names no source, jurisdiction, database or rights basis for them.
The product manages a customer's contracts rather than retrieving primary law. No provenance statement backs the precedent reference, and no update cadence is published for anything.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
A contract lifecycle platform grounded in the customer's own playbooks and repository, Ironclad has no case law research surface, so a citator falls outside its design. Its site, product pages and support documentation do not address whether authority carries a treatment signal or whether subsequent history is reviewed. They name no commercial citator license.
Leah describes no citator, treatment signal or currency check, and does not say whether legal authority is reviewed for later history. The platform manages contracts, obligations and procurement workflows rather than retrieving case law, so a citator is not part of what it sells. The vendor does refer to Leah operating against established legal precedents, without identifying any source. That is the one place the product invokes primary authority, and no verification step is described for it.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
The Review Agent is documented as identifying missing clauses and compliance gaps. That flags what is absent from a contract, which is different from the system declining to answer. The site, the Ironclad AI and Jurist pages, the agent launch material and the support documentation do not describe what the product does when it cannot ground an answer. They show no explicit no answer path and no confidence signal for the user.
The home page and the AI governance page describe no explicit path for Leah to decline to answer or abstain, and no confidence or grounding rating. The governance loop does produce rejections. Approvals, escalations and rejections are applied automatically according to the customer's rules. Those are policy outcomes set by configured guardrails, not the model declining because it cannot ground a response. Neither page says what Leah does when the customer's own contract set or playbook does not cover the question in front of it.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
The AI Hallucination Cases database, maintained by Damien Charlotin, tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. It records no court order, opinion or disciplinary record naming Ironclad. Published 2026 sanctions summaries and secondary sanctions trackers do not name it either. Ironclad is a contract lifecycle product with no case law research surface, so its output is very unlikely to reach a court filing as cited authority.
The AI Hallucination Cases database maintained by Damien Charlotin tracks decisions worldwide where a court addressed hallucinated AI content, and records the tool implicated where known. It records no court order, opinion or disciplinary record naming Leah or the former company name ContractPodAi. Published 2026 sanctions trackers and trade press summaries name neither. The platform runs commercial contracting and procurement work rather than producing court filings, so its output does not ordinarily reach a brief.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Ironclad publishes substantial material on AI governance, auditability and human in the loop control, which covers how its own system is controlled. Its AI Addendum and AI Disclaimer say AI output is not legal advice and that a licensed professional should be consulted. Neither those documents nor its site, article library, persona pages and resources sections engage with any named ethics opinion or bar guidance, including ABA Formal Opinion 512 and state bar guidance. None of it addresses the professional responsibility obligations its legal buyers are bound by.
Leah publishes nothing that engages with bar or ethics guidance. That includes ABA Formal Opinion 512, state bar guidance in the United States, and Solicitors Regulation Authority or Law Society material. The company is headquartered in London and sells into legal departments across North America, Europe, Asia and Australia. Its published compliance material covers regulation and security frameworks, namely GDPR, CCPA, HIPAA, SOC and ISO. None of it addresses the professional conduct obligations that bind the lawyers using the product.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Ironclad's savings claims come with figures. A named customer, NEXT Insurance, recovered 50 percent of legal operations time. First pass redlines drop from up to a couple of hours to minutes, and MNDA review drops from up to a day to minutes or seconds. The vendor frames this as scaling review without adding headcount. Its site, product pages, article library and support documentation offer no per matter record of work done with AI for fee purposes, and no guidance on billing, fees or client disclosure.
The buyer is an in house or business team that does not bill a client by the hour, so fee disclosure applies differently here.
Leah frames its public materials around cost and time removed, quantified at portfolio level. It cites a 91 percent cut in contract review time, more than $18 million of revenue protected and more than $2 million of tracked savings. Its headline figures are more than $125 billion of commercial value managed and more than $10 billion of ROI impact delivered. No per matter record of AI assisted work for fee purposes is described, and no guidance on billing, fee or client disclosure treatment is published.
The vendor describes an immutable audit log of every action, which could in principle support such a record, but does not present it for that purpose. Leah sells to in house functions rather than firms billing clients, so the costs in play are internal cost and outside counsel spend. Its materials address neither.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
Ironclad's subprocessor list at ironcladapp.com/subprocessors names Anthropic, OpenAI and Extend as AI providers and Google Cloud Platform for cloud and AI infrastructure, by region, for the United States and the EU datacenter. The Data Processing Addendum and AI Addendum are published in its Legal Center and can be read without an agreement in place. The addendum gives 30 days' email notice and an objection right before a new subprocessor is added.
Certification material covers SOC 1 and SOC 2 Type II with the trust categories named, ISO 27001, 27701, 27017 and 27018, a GDPR program and Cloud Security Alliance Trusted Cloud Provider status. Ironclad publishes no consent or notification pack written for a client's outside counsel guidelines.
The data processing agreement is Annex B of the Master Terms and Annexes v3.0c. The DPA Setup Page lists every subprocessor with its purpose, location and the product it serves. The list names ABBYY OCR SDK, Anthropic PBC, Cohere Inc., DocuSign or Adobe, Google AI/ML and Google Cloud, Jitterbit, Microsoft Azure Services, OpenAI LLC, QlikTech, Sendgrid, ZOHO, Zuva and four ContractPod group entities. Anthropic, OpenAI, Cohere and Google AI/ML are each listed against Leah Functionality as model providers, noted as storing or retaining no Customer Data, with named jurisdictions.
The DPA itself is the Bonterms DPA, published openly in the same PDF and ready to forward. It incorporates EU Standard Contractual Clauses Modules 2 and 3 and the UK International Data Transfer Addendum. It sets out processing details in Schedule 1 and fixes a 48 hour notice period for security incidents. Clause 4.3 commits to listing any new subprocessor and giving at least 30 days' notice before it processes anything.
Clause 4.4 gives an objection right, with termination and a refund if the objection is not resolved. Version 4.0 of January 2026 changes only the trading name, according to the vendor.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
The workflow layer records routing, assignment and approvals for each contract. Ironclad publishes governed and auditable AI review frameworks with human review. It says customers get transparent, auditable AI behavior they can review, override and continuously govern across teams and contract types. Ironclad describes no export per document covering the model used, sources retrieved and human verification. Its subprocessor list names the AI providers, Anthropic, OpenAI and Extend, but nothing shows which model produced a given output.
Ironclad is a contracting platform rather than a litigation product, so a court order on AI disclosure is unlikely to reach its output.
The audit stage of Leah's published governance loop logs every decision. Each entry records what the agent did, why, under which policy, with what data and with what outcome. The records are described as tamper resistant, immutable and ready for any audit. That gives the action, the rule, the inputs and the result for each action. The published description of the log does not include the model. The platform chooses among several language models for each task and identifies no model or version, so the log does not show which system produced a given passage.
No export built for court disclosure or AI use certification is described. The audit framing is regulatory and internal rather than judicial.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Commercial Transparency
- Good Law Verification
- Refusal and Uncertainty Behavior
- Bar Guidance Alignment
Which one fits
Choose Ironclad if
- Your security and privacy teams want specifics. Ironclad offers SOC 1 and SOC 2 Type II reports covering security, availability, confidentiality and privacy through its security portal, alongside four ISO standards. Its subprocessor list shows hosting in the US or the EU.
- You want a named customer result. NEXT Insurance is published as getting 50 percent of its legal operations time back with Jurist. Attributed quotes put first pass redlines at minutes instead of hours.
- Your contracts start in Salesforce. Ironclad calls its Salesforce integration the number one in the market and names Coupa alongside it, so teams work contracts inside those systems. In September 2026 it added a plugin for searching the repository from ChatGPT.
Choose Leah if
- You want a way out if uptime slips. Leah publishes uptime of up to 99.9 percent by support plan, with termination and a refund if it is missed three months running or in four months of six. Its master terms add an intellectual property indemnity.
- You want model choice and an isolated option. Leah names Anthropic, OpenAI, Cohere and Google, each with its jurisdictions, and picks among them for each task. A private environment in Azure OpenAI Studio isolates one customer's data from all others.
- You want agents held to rules you write. Customers set which agents may act, on which data and where escalation is required. Every action is logged with what the agent did, why and under which policy.
In summary
Ironclad
Ironclad sells contract lifecycle management to enterprise legal, procurement and sales teams. Each agreement moves from intake and drafting through approvals and signature into a searchable repository, built on a no code workflow designer. AI Playbooks drive redlining, and Jurist runs named agents for drafting, review and research. According to the AI Legal Index, Ironclad publishes its Enterprise Services Agreement, Data Processing Addendum and AI Addendum in a public Legal Center. Its subprocessor list names Anthropic, OpenAI and Extend as AI providers, with hosting on Google Cloud in the US or the EU. It names SOC 1 and SOC 2 Type II reports and ISO 27001, 27701, 27017 and 27018. No price is published.
Leah
Leah, formerly ContractPodAi, is an agentic platform for legal, procurement and finance work at large enterprises. Under the agents sits a contract lifecycle product with playbook review in Microsoft Word, approval routing, built in signing and an obligation repository. The AI Legal Index records a published governance model. The customer sets which agents may act, on which data and where they must escalate, and every action is logged with its rationale. Leah's master terms publish liability caps and an intellectual property indemnity. Its data processing pages name Anthropic, OpenAI, Cohere and Google as model providers. No price or accuracy figure is published.
Questions buyers ask
Ironclad vs Leah: which is better for enterprise contract management?
It depends on what the team needs. Ironclad has named certifications with a portal for the reports, a named customer result, Salesforce and Coupa integration, and US or EU hosting. Leah has agents that reach into procurement and finance under a logged governance loop, connected to SAP, NetSuite and Coupa. Both publish their contract terms and name their model providers. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
Do Ironclad and Leah train AI on customer contracts?
Ironclad's AI Addendum makes training opt in. Only customers who enable AI Training Settings in the admin console have their data used to train Ironclad's own models, after it is anonymized and aggregated. Outside providers may not train on customer data. Leah says customer contract data is never used to train models and that OpenAI and Anthropic keep none of it. That promise sits on its web pages rather than in its terms. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
Which AI models do Ironclad and Leah use?
Leah names four providers, Anthropic, OpenAI, Cohere and Google, with the jurisdictions where each runs. Microsoft Azure hosts the platform, and a private Azure OpenAI environment is available. Ironclad's subprocessor list names Anthropic, OpenAI and Extend, on Google Cloud in the US or the EU, alongside its own legal models. Neither names a model version. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
What happens if something goes wrong with Ironclad or Leah?
Both publish their remedies. Each caps liability at a year of fees, triples the cap for breaches of its data and security terms, and indemnifies intellectual property claims. Ironclad also indemnifies claims from customer data leaks it causes. Both let a customer end the contract with a refund if a defect is not fixed within thirty days. Leah also allows an exit after repeated uptime misses, where Ironclad pays service credits. Neither indemnifies AI output. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
What do Ironclad and Leah both leave unpublished?
Neither publishes a price, or even the unit it charges by. Neither publishes an accuracy or hallucination measure, or any position on attorney client privilege. Neither engages with bar guidance such as ABA Formal Opinion 512, though both sell to business teams well beyond the legal department. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything on it comes from public material on the dates shown. How the index grades.
Two points cut both ways. Leah's promise that customer contracts never train models sits on its home page and governance page, not in its master terms. Those terms limit use of customer data to running the service without naming training. Ironclad's AI Addendum lets it use prompts and outputs to evaluate the accuracy of its service even for customers who do not opt in. An opt out does not unwind training already done. Leah's certification claims also differ between two of its own pages, and no auditor is named. Neither vendor reviewed this page.