Ironclad vs LinkSquares: how they compare in 2026
Ironclad and LinkSquares both sell contract lifecycle management to in house teams, one at enterprise scale and one pitched at the midmarket. Ironclad sits in the top two bands on ten of fifteen axes, LinkSquares on six. Ironclad publishes more about how its AI is controlled: administrators configure which users and groups may view, create and edit the playbooks that drive AI behaviour, the vendor states that customers can review, override and continuously govern agent behaviour across teams and contract types, and its certification set names SOC 1 and SOC 2 Type II with the trust categories listed alongside ISO 27001, 27701, 27017 and 27018. It is also direct about its own training, offering customers an opt in for training on their contracting data, anonymised and aggregated first. LinkSquares answers on evidence and architecture, naming DraftKings, TIME, ProPharma and Asurion, publishing a case study reporting a 40 per cent cut in outside counsel costs, and rebuilding its AI layer as an agentic architecture in May 2026.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of a core capability, layered on a product that would function without them as a workflow system. Ironclad is a contract lifecycle management platform: intake, no code Workflow Designer, approvals, routing, signature, repository, analytics and integrations all predate and stand without generative AI, and the vendor sells that workflow layer as its foundation. What the models drive is real and central rather than peripheral, which is why this is not a C: AI Playbooks with each play tied to a clause do the redlining, and Jurist runs a named family of agents for drafting, editing, review, research, intake and redlining under a Manager Agent, with Conversational Search over the repository. Second B on this axis after Definely, and for the same structural reason: an established product with a substantial AI layer rather than an AI native one.
A platform that chose to rebuild rather than bolt on, which is the distinction this axis exists to catch. LinkAI launched 5 May 2026 as an AI native agentic architecture replacing the prior approach, and independent review material credits that specifically as rebuilding on an AI native architecture rather than attaching a chat sidebar to the existing product, noting most incumbent CLM vendors took the bolt on path. Extraction has been the core of the product since the beginning: identifying and pulling payment deadlines, governing law, liability, renewal and commercial obligation terms out of executed agreements is a model task, and the analytics layer that made the company's name is built on that extracted output, so the models generate the data the rest of the product reasons over. Held at B rather than A because the repository, workflow, approval routing and reporting infrastructure still stands without the model layer, and because the rebuild is four months old at the date of this record, so the AI native claim describes a recent architectural decision rather than a long established one. Revisit on the next pull.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted and the grounding behind it is not documented. Vendor material claims precision redlining, advanced AI and proprietary legal AI models trained on legal terminology with legal engineered prompts. Real structure exists in the AI Playbooks mechanism, where each play is tied to a clause and the system proposes varying degrees of revision to match preferred terms with minimal language change, so output is anchored to a customer authored standard a reviewer can check. What is missing is everything this axis measures: searched the site, the Ironclad AI and Jurist product pages, the security page and the support documentation via search on 29 Aug 2026 and located no accuracy figure, no hallucination rate, no test set, no evaluation, and no description of the retrieval method or how output grounds to a source a reader can open.
The vendor tells buyers to demand the exact measurement it does not publish, which is the sharpest instance of that pattern in the pull. Its own published buyer guidance on evaluating AI contract management states that buyers should demand precision and recall benchmarks on their own documents and maintain review workflows for exceptions. That is correct advice and it is the right metric for extraction work. LinkSquares publishes no precision or recall figure of its own, for any clause type, on any corpus. Extraction accuracy is claimed as a differentiator in comparison content and quantified nowhere. Also absent: no error rate by clause type, no statement of behaviour on non standard or ambiguous language, no confidence indication on extracted values, and no evaluation methodology. The gap is consequential because extraction failures in this product are silent: a missed renewal date or auto renewal clause does not announce itself, it simply never appears in the report the legal team relies on. Checked the LinkAI page, the security page, the comparison and buyer guide material and the home page on 29 Aug 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A written commitment that the models work alongside a supervising human, with real and specific review surfaces, short of published thresholds. The vendor states human in the loop governance ensures every agent works transparently, is auditable and controllable, and says plainly that the customer is in charge, with governed and auditable AI review frameworks the customer can review, override and continuously govern across teams and contract types. The control surface is administrative as well as rhetorical: playbook permissions let administrators configure which users and groups may view, create and edit playbooks, and a Manager Agent routes tasks across the agent family so orchestration is visible. Vendor material states the agents automate repetitive lower risk work while strategic negotiation and nuanced risk assessment stay with the lawyer, which is a stated allocation. Not located as of 29 Aug 2026: the threshold at which an agent stops or escalates, and what the vendor commits to when an output is wrong.
The product is marketed as agentic and the oversight model is not described. LinkSquares positions itself as agentic CLM and states that the platform handles the bulk of standard contracts automatically, which is an autonomy claim with commercial substance behind it. Its own buyer guidance recommends maintaining review workflows for exceptions, so the vendor knows where the human belongs. What is not published for its own product: which contract types or value thresholds can complete without human review, what makes a contract standard enough to be handled automatically, whether an agent can send or approve a contract unattended, what confidence threshold routes an exception to a person, and what the audit record shows when an agent rather than a lawyer made the call. Marketing an agent and describing its limits are different acts and only the first has happened. Checked the home page, the LinkAI page, the comparison material and the buyer guide material on 29 Aug 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Real deployment evidence with substance, short of dated attribution and method. A named customer carries a figure: NEXT Insurance is published as giving legal operations 50 percent of its time back with Jurist. Attributed customer quotes carry before and after numbers, including a first pass redline moving from 30 minutes to a couple of hours down to a solid first draft in minutes, and an MNDA review or custom order form clause drafting moving from an hour to a day down to minutes or seconds. A customer stories section is published. Not located as of 29 Aug 2026: a dated case study with a stated method a reader could assess, and the identity of the speakers behind several of the quoted figures.
Customers are named, a case study carries figures, and one of those figures does not survive arithmetic. Named customers: DraftKings, TIME, ProPharma and Asurion, with more than 1,200 customers stated. Independent placement is dated and repeated: G2 Leader in contract lifecycle management for five consecutive years including the Winter 2026 Grid Report, with a stated 98 percent of users reporting the product moving in the right direction. A named case study, Softonic, reports outside counsel costs reduced by 40 percent, which is a coherent and checkable claim from a named company. Held at B rather than A on the quality of the other figures. The same case study reports NDA processing time cut by nearly 400 percent, and a reduction of more than 100 percent is not a possible quantity, so the claim is either a throughput multiple described as a reduction or an error, and either way it cannot be read as stated. A separately published 360 percent ROI over three years carries no methodology, sample or baseline. A vendor that names its customers and publishes an impossible percentage is being open and imprecise at the same time, and the record should say both.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments, and unusually the vendor addresses its own training use directly rather than only its providers. Published: strict do not train and zero data retention policies enforced with external LLM providers; any customer data used to train Ironclad's own models is anonymised and aggregated before use; output generated for other customers by models trained on a customer's data will never include that customer's data; and training data protection is stated as covered by the same security standards as the rest of the platform. Certification covers the privacy trust category under SOC 2 and includes ISO 27701 for privacy information management. Two gaps hold this off an A. Attorney client privilege and work product handling is not addressed directly in located material. Segregation between customers, users or matters is not documented on the pages checked.
Confidentiality is well evidenced at platform level and privilege is not addressed. Published: SOC 2 Type II, ISO 27001 and GDPR compliance on a dedicated security page, encryption of all contracts and data, and a stated commitment that customer data stays private within the platform. Independent review material describes data residency and retention controls as mature enough that a public company legal operations lead does not need to negotiate addenda, which is a practitioner assessment rather than vendor material and is treated as supporting. What is absent: any treatment of legal professional privilege or attorney work product, and any statement about the confidentiality of proprietary negotiation playbooks and clause libraries, which are the closest thing in this product to work product and which the vendor elsewhere states are isolated. The platform is used by legal, sales, procurement, finance and HR in the same instance, so the boundary between legal's own analysis and the wider business is a live question and is not described. Checked the security page, the LinkAI page, the data privacy solution page and the home page on 29 Aug 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The intended audience is broad by design and no position on the advice line was located. Dedicated pages address legal operations and general counsel alongside procurement and IT, and vendor material describes the platform as serving business teams that touch contracts, with the AI proposing redlines and drafting negotiation ready revisions for those users. Searched the site, the product and persona pages, the security page and the support documentation via search on 29 Aug 2026 and located no statement on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits. The human in the loop governance language is a control statement rather than a professional responsibility position, and the two are not the same thing.
Not located. The product drafts, reviews and approves contracts and is explicitly sold for use by sales, procurement, HR, marketing and finance alongside legal, so non lawyers act on machine generated contract analysis by design and the vendor describes that as a feature. Nothing published addresses the professional dimension: no statement that output is not legal advice, no guidance on when a contract should reach a lawyer, no positioning on the in house counsel's supervisory role over self service authoring by business users, and no engagement with any bar guidance. Checked the home page, the LinkAI page, the solution pages and the buyer guide material on 29 Aug 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A published governance framework with real substance, short of testing results, a named owner and any bias disclosure. What exists is a described mechanism rather than a principles page: governed and auditable AI review frameworks, human in the loop governance stated as ensuring every agent is transparent, auditable and controllable, customer ability to review, override and continuously govern agent behaviour across teams and contract types, and administrator configurable permissions determining who may view, create and edit the playbooks that drive AI behaviour. A chief technology officer is named publicly as owning the AI roadmap. Not located as of 29 Aug 2026: an AI management certification such as ISO 42001, published pre release testing results, a named accountable owner for model governance as distinct from the technology function, and anything on uneven output across matter types, parties or populations.
The vendor publishes governance guidance for its customers and nothing about its own models. Its buyer guide recommends implementing quarterly AI governance reviews to monitor bias, validate accuracy and enforce compliance, and lists model governance covering audit trails, PII handling and zero retention options as things a buyer should expect from a vendor. Every one of those is advice pointed outward. For LinkAI itself the located material amounts to a claim that it is designed with enterprise grade data security and governance built in. No AI policy, no model card, no bias or fairness testing, no evaluation methodology or result, no accuracy monitoring, no drift statement, no named governance body and no ISO 42001 despite holding ISO 27001. Same shape as FinregE, which analyses regulatory obligations for customers in structured detail and turns none of that rigour on itself, and graded the same way for consistency. Checked the LinkAI page, the security page, the buyer guide material and the comparison content on 29 Aug 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy covering most of the ground. Certification breadth is the strongest element and is stated precisely: routine audits producing third party SOC 1 and SOC 2 Type II reports certified against multiple trust categories named as security, availability, confidentiality and privacy, plus ISO 27001, 27701, 27017 and 27018, a dedicated GDPR programme, and Cloud Security Alliance membership with Trusted Cloud Provider status. Data centre operations run on public cloud providers the vendor states are themselves certified under SOC 2, ISO 27001 and PCI DSS, across multiple regions. Zero data retention is enforced at the external model layer. Not located as of 29 Aug 2026: a stated retention period or deletion control for customer contracts and prompts in Ironclad's own systems, a named subprocessor list, and an incident or breach notification practice.
A real and repeated training commitment, with a carve out that has to be read carefully. The vendor states that contract data is never shared with or used to train any third party LLM providers, that contract data and proprietary playbooks are completely isolated and never used to train public AI models, and that data stays completely private within the LinkSquares platform. That answers the dominant risk for a CLM, which is customer contract text reaching an external model provider, and it answers it in plain words rather than by implication. Held at B rather than A because of what the wording leaves open. Both formulations are scoped to third party and public models. Neither states that LinkSquares does not use customer contract data to train or tune its own models inside its own platform, and stays completely private within the LinkSquares platform is consistent with internal training rather than exclusive of it. No retention position for AI processed content is published either, and the vendor's own buyer guide lists zero retention options as something a buyer should demand without stating whether this product offers one. A well drafted sentence that stops precisely where the harder commitment would begin.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Searched the site navigation, the security page, the Ironclad AI and Jurist product pages, the support documentation and the article library via search on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer agreement or master services agreement was located as published on the property. Recorded as a pure absence on the surfaces checked. Rebuttable with a single link to a published agreement, which for an enterprise platform of this size may well exist somewhere not surfaced by the searches run.
No published position located. Nothing was found on liability for AI output, warranty, service levels or remedy where an extraction is wrong, a clause is missed, or an agentic action progresses a contract that should have been escalated. The exposure is concrete: the platform is stated to handle the bulk of standard contracts automatically, and a missed auto renewal or liability cap in an executed agreement is a loss the customer discovers later with no published vendor position on it. Checked the home page, the LinkAI page, the security page and the site navigation on 29 Aug 2026. Enterprise agreements govern this and are not public, and no public terms page was located in this pass.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations exist and are documented, and the vendor treats them as a primary differentiator. Named specifically: Salesforce, described by the vendor as the number one Salesforce integration in the market, and Coupa, with a dedicated integrations page and a stated claim of the deepest integrations in the market. The workflow layer is itself integration: teams create, manage and collaborate on contracts from inside the systems they already use rather than switching into the CLM. Orientation is toward enterprise commercial systems rather than legal document management, which fits a CLM buyer. Not located as of 29 Aug 2026: legal specific document management connectors such as iManage or NetDocuments, and per integration documentation describing what moves in which direction and what an administrator configures.
Integrations are named, numerous and aimed at where contract work actually happens. Named: Microsoft Word, Google Docs, Microsoft 365, Salesforce, Slack, DocuSign and HubSpot, with the vendor stating that clause libraries and playbooks are accessible from inside the drafting environment so users do not switch tabs or upload files. Word and Google Docs native drafting is the integration that matters most for this product class and it is present, and the CRM and e-signature connections cover the pre signature path end to end. Held at B rather than A on a gap identified in independent review material and not contradicted by anything located: no generally available developer facing API, which limits a customer's ability to move contract data into systems the vendor has not built a connector for. No document management system such as iManage or NetDocuments is named either. Checked the LinkAI page, the comparison material, the home page and independent review material on 29 Aug 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Residency is offered without the processing location being addressed, which is the B band. The vendor states it leverages multiple data centre regions from its cloud providers specifically to meet data residency requirements, which is a real published residency position rather than a geography footnote. What is missing: the cloud providers are described only as public cloud vendors and are not named, no available regions are listed, no customer selectable region is stated, no tenancy model is given, and no statement separates where processing happens from where data is stored. Checked the security page and the platform pages via search on 29 Aug 2026.
Residency is described in third party assessment and not in vendor material located here. Independent review material states that data residency and retention controls are mature enough that a public company legal operations lead does not have to negotiate addenda, which is a specific practitioner claim about the existence and quality of residency controls. No vendor page located in this pass names a hosting provider, enumerates regions, states a residency commitment, or describes single tenant or private deployment options. Source basis recorded as Third Party Estimated on that footing rather than credited as vendor disclosure. Correction candidate: the dedicated security page carries certification statements and may carry residency detail below the summary content read here.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real and stated with correct scope language, short of accessible evidence. The vendor names SOC 1 and SOC 2 Type II from routine third party audits and, unusually, names the trust categories certified against: security, availability, confidentiality and privacy. ISO 27001, 27701, 27017 and 27018 are all named, which is a broader ISO set than most of this index carries, and Cloud Security Alliance membership with Trusted Cloud Provider status is stated. Supply chain assurance is addressed by stating that the underlying cloud vendors are themselves SOC 2, ISO 27001 and PCI DSS certified. What was not located as of 29 Aug 2026 is the evidence route: no audit coverage period, no report date, no named auditing firm, and no trust portal or published request flow for obtaining the reports.
Two named certifications on a dedicated security page, published openly rather than gated. SOC 2 Type II and ISO 27001 are both stated, alongside GDPR compliance and encryption of all contracts and data, on a page whose purpose is security rather than as a line in marketing copy. Both certifications are corroborated across independent review material, which describes them as the two certifications that clear most enterprise procurement gates. Publishing the status openly with no login is better than the request flow tier and is the reason this sits at the top of B. Held below A on three absences: no auditing firm is named for either certification, no certificate date, examination period or expiry is published so currency cannot be established, and no trust centre or documentation request route was located, so a reviewer wanting the report itself has no stated path. Consistent with Regology and Onspring at B, and below Lexis+ AI and Exterro at A, which add currency, scope detail and a verifiable route.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The vendor refers to models without identifying what sits underneath. Two layers are acknowledged and the distinction between them is drawn clearly, which is more than most manage: proprietary legal AI models built by Ironclad with legal engineered prompts, and external LLM providers bound by do not train and zero data retention terms. That tells a buyer the shape of the chain and the commercial terms binding it. What it does not tell them is who is in it. Searched the site, the Ironclad AI and Jurist pages, the security page and the article library via search on 29 Aug 2026 and located no named external model provider, no statement of where models run, no subprocessor list, and no commitment to notify customers when the supply chain changes.
The category is acknowledged and no party is named, and the acknowledgement is inadvertent. By committing that contract data is never shared with third party LLM providers, the vendor confirms that such providers exist in the architecture, since a commitment not to share with them is only meaningful if they are there. Nothing names any of them: no provider, model family or version, no subprocessor list, and no statement of what runs where between the vendor's own infrastructure and any external model. For a product now rebuilt on an agentic architecture, the identity of the underlying models is a question an enterprise security review asks directly. Compare Onspring at B, the only record on this index naming its provider outright. Checked the LinkAI page, the security page, the comparison material and the home page on 29 Aug 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Checked the site navigation, the platform and product pages, the persona pages and the security page via search on 29 Aug 2026. No pricing page was located on the property, no rate is published, no unit of charge is stated and no tier structure appears. Every commercial path located terminates in a demo request. No free trial or self serve entry point was located. Consistent with third party coverage describing implementation cost as dependent on the scope of the CLM deployment rather than on a published rate.
No pricing published at any level. No price, no range, no tier structure and no unit of charge, and the vendor's own buyer guidance tells readers to compare user based, usage based and record based pricing models without disclosing which of those it uses itself. Third party reconstruction places the median around $31,000 per year with a starter tier near $10,000 and enterprise above $75,000, which is independent estimation rather than disclosure and is recorded as context rather than credited. That estimated range is material to a buyer because it places the product outside the reach of small teams, which is exactly the kind of fit judgement published pricing would let a reader make for themselves. Checked the home page, the LinkAI page, the pricing navigation and independent review material on 29 Aug 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is described with substance, short of the boundaries. Four buyer personas carry their own published positioning: legal operations, general counsel, procurement and IT, and the vendor addresses business teams beyond legal that touch contracts. Enterprise class and global business teams are stated as the target, and at least one industry, manufacturing, carries dedicated positioning around leakage and contract performance. Practice scope is clear and consistent throughout: contracting end to end from intake to post signature, with no claim to litigation or research capability. Not located as of 29 Aug 2026: a statement of which organisation sizes or contract types the platform is not built for, and an enumerated industry or practice area list comparable to the strongest records on this index.
Coverage is stated in the terms that matter for contract work, which is clause and lifecycle scope rather than jurisdictions. Named clause and term coverage: payment deadlines, governing law provisions, liability clauses, renewal language and commercial obligations, with batch analysis across large legacy portfolios for M&A due diligence and repository audit. Lifecycle coverage runs pre signature through post signature in one platform, and the user set extends beyond legal to sales, procurement, finance, HR and marketing, which is honest about who actually touches contracts. More than 1,200 customers across the in house market. Held at B rather than A because coverage is not characterised where it would matter to a buyer: no statement of which contract types or languages are supported, no jurisdictional scope for governing law extraction despite that being a named capability, and no indication of extraction depth by agreement type. Independent review also identifies the scope boundary honestly, noting no primary law research capability, which is correct and is a category fact rather than a gap.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The clearest opt in on this signal in the index, and the vendor argues for it openly rather than burying it. Published: customers may opt into allowing Ironclad to train its own models on their contracting data; any customer data so used is anonymised and aggregated before use; output generated for other customers by models trained on that data will never include the contributing customer's data; and the customer stays in control with data kept confidential. Separately and distinctly, strict do not train and zero data retention policies are enforced with external LLM providers, so the third party layer is prohibited while the vendor's own layer is permitted with consent. Recorded at opt in because training occurs only where the customer has affirmatively enabled it. What was not located as of 29 Aug 2026 is where the opt in is exercised, whether it sits in the agreement or a product setting, and whether it can be withdrawn.
Policy never, and the scope of the never is the finding. READ THE QUALIFIER: the quoted commitment is to public AI models, and the parallel statement on the LinkAI page is that contract data is never shared with or used to train any third party LLM providers. Both are scoped to models outside the vendor. Neither states that LinkSquares does not use customer contract data to train or tune its own models, and the accompanying phrase that data stays completely private within the LinkSquares platform is consistent with internal training rather than exclusive of it. Recorded at policy never because a real and repeated commitment exists and covers the dominant risk for a CLM, which is contract text reaching an external provider, and erasing it as silent would misdescribe the record. Recorded as policy rather than contractual because it appears on product and comparison pages rather than in terms or a data processing agreement. A carefully drafted sentence that stops precisely where the harder commitment would begin. Checked the LinkAI page, the security page, the comparison material and the home page on 29 Aug 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is answered at the external model layer and unaddressed for the platform itself. The vendor states it enforces zero data retention with external LLM providers, so prompts and completions are not persisted by those providers. Searched the security page, the platform pages, the article library and the support documentation via search on 29 Aug 2026 and located no retention period for contracts, prompts or outputs held in Ironclad's own repository, no customer control over that window, and no deletion commitment. That gap is material here because the product is a system of record designed to hold every executed agreement indefinitely, so the retention question is the core of what the customer is buying.
Not addressed, and the vendor's own buyer guidance shows it knows the question. That guidance lists zero retention options among the things a buyer should expect from an AI contract management vendor, alongside audit trails and PII handling. No statement was located as to whether LinkSquares itself offers a zero retention option, what its default retention period is for AI processed contract content or extracted output, or whether any of it is customer configurable. Advising buyers to demand a control without stating whether you provide it is the pattern this record repeats across three axes. Checked the buyer guide material, the LinkAI page, the security page and the data privacy solution page on 29 Aug 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own documented permission model rather than inheriting one from a document management system. Published support documentation states that administrators can configure Ironclad users and groups to permit or restrict which users may view, create and edit AI Playbooks, so the standards driving AI behaviour are themselves access controlled, and the workflow layer routes and assigns contracts across named reviewers. That is a documented internal permission model. What was not located as of 29 Aug 2026 is segregation of the contract repository itself between users or matters, any ethical wall concept, and any legal document management integration whose permissions retrieval could inherit at query time. Noted for context: the buyer here is an in house or business team rather than a firm carrying conflicts obligations, so the question reads differently than it would for a firm facing product.
Not addressed for this product. The vendor's buyer guidance names MFA and SSO among the controls a buyer should expect, and independent material notes role based access controls as standard across enterprise CLM platforms generally, but neither is a statement about what LinkSquares implements. The structural question is live: the platform is sold for use by legal, sales, procurement, finance, HR and marketing in a single instance holding the whole contract estate, and nothing published describes what separates legal's own analysis, playbooks and risk annotations from the business users working in the same system. No document management system integration exists to inherit permissions from. Checked the security page, the LinkAI page, the solution pages and the home page on 29 Aug 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Searched the security page, the site navigation, the article library and the support documentation via search on 29 Aug 2026. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. No published customer agreement or data processing agreement was located on the property either, so the search covered the public pages rather than the contract documents.
Not addressed. No government or law enforcement request clause, no commitment to notify a customer before producing their data, and no transparency report were located. The dedicated security page states SOC 2 Type II, ISO 27001, GDPR compliance and encryption and does not reach third party requests. Checked the security page, the data privacy solution page, the home page and the site navigation on 29 Aug 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No primary law corpus is identified because the product does not hold one. Retrieval runs against the customer's own contract repository and their own AI Playbooks, and the vendor's proprietary models are described as trained on legal terminology and contract management architecture with legal engineered prompts, plus, where customers opt in, anonymised and aggregated customer contracting data. That last element is the closest thing to a vendor corpus and its provenance is disclosed in principle, being customer contributed under consent, though no scale figure, licence basis or update cadence is published for it. Searched the site, the Ironclad AI page and the article library on 29 Aug 2026.
Not addressed, and inapplicable in the usual sense. The product operates on the customer's own executed and draft agreements rather than on published law, so there is no external legal corpus to name, license or date. Recorded rather than omitted because the underlying question has a live form here that is unanswered: what the extraction models were trained on. Extraction of governing law, liability and renewal terms across contract types implies a substantial training corpus of agreements, and nothing published states whether that corpus was licensed, synthetic, publicly sourced, or built from customer contracts. The commitment not to train third party models on customer data speaks to future flow and not to what already built the extraction capability. Checked the LinkAI page, the security page and the comparison material on 29 Aug 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Searched the site, the product pages and the support documentation via search on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is a contract lifecycle platform grounded in the customer's own playbooks and repository, with no case law research surface, so a citator is outside its design entirely.
Not addressed, and inapplicable on the facts. LinkSquares analyses contracts rather than researching law and produces no citation to legal authority, so a citator would have nothing to check. Independent review material identifies the same scope boundary directly, noting the absence of primary law research on case law, statutes and regulations, which is a category fact rather than a defect. Recorded as a scope fact so a reader does not mistake an inapplicable row for a disclosure failure, consistent with the treatment of this row on Legal Tracker, Mitratech, TrialView and Exterro. Checked the LinkAI page and the comparison material on 29 Aug 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Searched the site, the Ironclad AI and Jurist pages, the agent launch material and the support documentation via search on 29 Aug 2026. No published material describes what the product does when it cannot ground an answer, and no explicit no answer path or confidence signal exposed to the user was located. The Review Agent is documented as identifying missing clauses and compliance gaps, which is flagging what is absent from a contract rather than the system declining to answer, and the two were not conflated.
Not addressed. Nothing published describes an explicit no answer path, abstention behaviour or confidence signal for extraction, review or the agentic layer. The vendor's own buyer guidance recommends maintaining review workflows for exceptions, which implies exceptions are identifiable, and nothing states how LinkAI identifies one: whether a low confidence extraction is flagged, left blank, or filled with a best guess that reads identically to a confident one. For a product whose output is a structured field in a report, an unflagged wrong value and an unflagged missing value are both invisible to the person relying on it. Checked the LinkAI page, the buyer guide material, the comparison content and the home page on 29 Aug 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note that this is a contract lifecycle product with no case law research surface, so its output is very unlikely to reach a court filing as cited authority.
None located, with the instrument named. General web searches combining the vendor and product names with court, order, sanction, contract dispute and extraction error terms returned nothing on 29 Aug 2026, and no named docket database or court record tracker was searched. The product generates no citations to legal authority, so the classic fabricated case failure mode does not arise, and the analogous risk would be a missed or misextracted contract term surfacing in a commercial dispute. Recorded as a statement about what this search found, not as a clearance.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Searched the site, the article library, the persona pages and the community and resources sections via search on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512 and state bar guidance. The vendor publishes substantial material on AI governance, auditability and human in the loop control, which addresses how its own system is controlled rather than the professional responsibility obligations its legal buyers are bound by.
Not addressed. No named ethics opinion, no ABA Formal Opinion 512, no state bar guidance and no engagement with professional conduct rules was located, despite the vendor publishing a substantial library of in house counsel guidance covering AI adoption, governance reviews, procurement and change management. The omission is notable given that library's scope: it advises legal departments on how to govern AI adoption without engaging the professional rules those departments' lawyers work under. Checked the buyer guide material, the in house insights library, the LinkAI page and the home page on 29 Aug 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Savings are claimed and quantified with nothing published on the client's side of the equation. Published figures include a named customer recovering 50 percent of legal operations time, first pass redlines moving from up to a couple of hours down to minutes, and MNDA review moving from up to a day down to minutes or seconds, alongside framing about scaling review without adding headcount. Searched the site, the product pages, the article library and the support documentation via search on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment. Noted for context: the buyer is an in house or business team that does not bill a client by the hour, so this signal reads differently for this segment.
Savings claims only, including one that cannot be read as stated. Published: a named customer, Softonic, reducing outside counsel costs by 40 percent, which is coherent and attributable, alongside a stated 360 percent ROI over three years and contract review times reduced by up to 400 percent. A reduction of more than 100 percent is not a possible quantity, so the last figure is either a throughput multiple presented as a reduction or an error, and it is recorded here as unreadable rather than credited. Nothing appears on the client side of the equation: no position on billing for AI assisted contract work, and no record a department could produce showing what portion of a review was machine performed. Checked the LinkAI page, the comparison material and the case study content on 29 Aug 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
Substantial certification material is published openly, including SOC 1 and SOC 2 Type II with the trust categories named, ISO 27001, 27701, 27017 and 27018, a GDPR programme and Cloud Security Alliance Trusted Cloud Provider status, all reachable without a sales conversation. But the artifacts this signal turns on were not located as of 29 Aug 2026: no subprocessor list, no statement naming which model providers see customer content, no published data processing agreement, and no client facing consent or notification pack. The vendor states its external LLM providers are bound by do not train and zero data retention terms without naming them, which is a statement about the terms rather than a disclosure of the chain. Recorded as not addressed because no list exists to point to.
Not addressed, with one genuine open element. The dedicated security page publishes SOC 2 Type II, ISO 27001 and GDPR compliance without a login, so a department has something citable immediately, and open publication is better than a gated summary. Everything else a forwardable pack needs is missing: no subprocessor list, no named model provider, no data processing agreement, no trust centre and no documentation request route were located, so there is no path to the underlying reports and no way to answer a client's question about which third parties process its contract data. Recorded as not addressed because a certification summary is not a disclosure pack and no request route exists. Checked the security page, the data privacy solution page, the LinkAI page and the site navigation on 29 Aug 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of a record are available and the auditability language is more specific than most. The vendor publishes governed and auditable AI review frameworks with human in the loop review, stating customers get transparent auditable AI behaviour they can review, override and continuously govern across teams and contract types, and the workflow layer records routing, assignment and approvals per contract. Two elements are missing: no per document export covering model used, sources retrieved and human verification together was located, and no model is named anywhere in published material so the model used could not be stated. Noted for context: this is a contracting platform rather than a litigation product, so a judicial AI disclosure order is unlikely to reach its output.
Not addressed, and close to inapplicable in the form this signal usually takes. LinkSquares produces contract analysis and executed agreement data rather than work product filed with a court, so the model used, sources retrieved and human verification export a judicial standing order asks for has no natural object. Recorded as a scope fact rather than omitted. Worth noting the adjacent gap that does apply: nothing indicates the platform records which contract fields were AI extracted as opposed to human entered, or whether a person confirmed an extracted value, so a party relying on repository data in a dispute could not evidence how any given term got into the record. Checked the LinkAI page, the comparison material and the home page on 29 Aug 2026.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- AI Liability and Recourse
- Commercial Transparency
- Third Party Request and Subpoena Notice
- Primary Law Corpus Provenance
- Good Law Verification
- Refusal and Uncertainty Behaviour
- Bar Guidance Alignment
- Outside Counsel Guideline Readiness
Which one fits
Choose Ironclad if
- You want the AI's standards under access control, not just its output under review. Ironclad publishes administrator configurable permissions determining which users and groups may view, create and edit the AI Playbooks that drive AI behaviour, states that customers can review, override and continuously govern agent behaviour across teams and contract types, and routes work through a Manager Agent so orchestration is visible.
- Your procurement gate is a list of standards. Ironclad names SOC 1 and SOC 2 Type II from routine third party audits and states the trust categories certified against, being security, availability, confidentiality and privacy, alongside ISO 27001, 27701, 27017 and 27018, a GDPR programme and Cloud Security Alliance Trusted Cloud Provider status.
- You want the training question answered in both directions. Ironclad states strict do not train and zero data retention terms with its external model providers, and separately that customers may opt in to Ironclad training its own models on their contracting data, with that data anonymised and aggregated first and output for other customers never including the contributing customer's data.
Choose LinkSquares if
- You want a customer you can look up and a number you can read. LinkSquares names DraftKings, TIME, ProPharma and Asurion among more than 1,200 customers, publishes a case study with Softonic reporting outside counsel costs reduced by 40 per cent, and has been placed a G2 Leader in contract lifecycle management for five consecutive years including the Winter 2026 report.
- Your problem is the legacy repository rather than tomorrow's contract. LinkSquares built its business on extraction aimed at the terms in house teams track most, being payment deadlines, governing law, liability clauses, renewal language and commercial obligations, with batch analysis across large volumes of legacy agreements for due diligence and repository audit.
- You want the AI rebuilt rather than bolted on. LinkAI launched on 5 May 2026 as an agentic architecture replacing the previous approach, and independent review credits it specifically as a rebuild rather than a chat sidebar attached to an existing product, with clause libraries and playbooks reachable inside Word and Google Docs rather than in a separate tab.
In summary
Ironclad
Ironclad is an enterprise contract lifecycle management platform covering intake, contract creation, no code workflow automation, approvals, negotiation, signature, repository and analytics, with AI embedded across it through AI Playbooks and the Jurist family of agents. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes. Its control surface is the most specific in this pair: administrators configure which users and groups may view, create and edit the playbooks that drive AI behaviour, and the vendor states that customers can review, override and continuously govern agent behaviour across teams and contract types. Certification runs to SOC 1 and SOC 2 Type II with the trust categories named, alongside ISO 27001, 27701, 27017 and 27018. As of 29 August 2026 the index located no customer agreement, no liability position and no published price.
LinkSquares
LinkSquares is a contract lifecycle management platform for in house legal teams, covering pre signature drafting, review and approval alongside a post signature repository with extraction and analytics, with its AI layer LinkAI rebuilt on an agentic architecture in May 2026. The AI Legal Index grades it in the top two bands on six of fifteen capability axes. Extraction is the historic strength, aimed at payment deadlines, governing law provisions, liability clauses and renewal language with batch analysis across legacy portfolios, and the vendor names DraftKings, TIME, ProPharma and Asurion alongside a case study reporting outside counsel costs reduced by 40 per cent. As of 29 August 2026 the index located no precision or recall figure, no customer agreement, no model provider named and no published price.
Questions buyers ask
Ironclad vs LinkSquares: which is better for in house contract management?
The AI Legal Index places Ironclad in the top two bands on ten of fifteen capability axes and LinkSquares on six. Ironclad publishes more about how its AI is controlled and audited and more about what it does with customer data, including an opt in for training its own models. LinkSquares publishes more customer evidence, including a named case study with a figure, and rebuilt its AI layer on an agentic architecture in May 2026. Neither publishes a customer agreement or a price.
Does either train its AI on your contracts?
They answer differently. Ironclad states strict do not train and zero data retention terms with external model providers, and separately that customers may opt in to Ironclad training its own models on their contracting data, anonymised and aggregated first. LinkSquares states that contract data is never shared with or used to train any third party LLM providers and never used to train public AI models. Both LinkSquares formulations are scoped to models outside the vendor, so its own models are not addressed. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
What certifications do Ironclad and LinkSquares publish?
Ironclad names SOC 1 and SOC 2 Type II with the trust categories listed as security, availability, confidentiality and privacy, plus ISO 27001, 27701, 27017 and 27018 and Cloud Security Alliance Trusted Cloud Provider status. LinkSquares publishes SOC 2 Type II, ISO 27001 and GDPR compliance openly on a dedicated security page with no login. Neither names an auditing firm, publishes a coverage period or report date, or offers a stated route to the reports themselves. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
Which one publishes accuracy figures for contract extraction?
Neither does. LinkSquares publishes buyer guidance recommending that buyers demand precision and recall benchmarks on their own documents, which is the right metric for extraction work, and publishes no figure of its own for any clause type. Ironclad claims precision redlining and proprietary legal AI models without an accuracy figure, hallucination rate, test set or evaluation. On a product whose failures are silent, a missed renewal date simply never appears in the report, this is the gap that matters most. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
What do Ironclad and LinkSquares both leave unpublished?
Neither publishes a customer agreement, so neither states an indemnity, a liability cap, a warranty on output or an insurance position. Neither publishes a price, a tier structure or a unit of charge. Neither names a model or a provider underneath its AI, although both confirm external providers exist. Neither names an ethics opinion or bar guidance. And neither describes what the system does when it cannot ground an answer or extract a term reliably. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
Two things to read closely, and both concern scope rather than substance. LinkSquares publishes buyer guidance telling readers to demand precision and recall benchmarks on their own documents and to expect zero data retention options from an AI contract vendor, and publishes neither for itself. Its training commitment is also scoped to third party and public models, so whether customer contract data trains LinkSquares' own models is left open. On Ironclad, no customer agreement was located on the property, so the absence of a liability position and a retention period records what could not be found rather than terms that are unfavourable, and its residency statement names neither the regions available nor the cloud providers behind them. Both records were verified on 29 August 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.