Ironclad vs Sirion: how they compare in 2026
Ironclad and Sirion are two enterprise contract lifecycle platforms that meet in the same procurement, and the grid barely separates them: Ironclad sits in the top two bands on ten of fifteen axes, Sirion on nine. What differs is which half of the disclosure each publishes. Ironclad publishes the control surface, with administrator configurable permissions over who may view, create and edit the playbooks that drive AI behaviour, and a certification set naming SOC 1 and SOC 2 Type II with the trust categories listed alongside ISO 27001, 27701, 27017 and 27018. Sirion publishes the paperwork. Its SaaS terms, end user agreement and data processing addendum are all open, carrying an intellectual property indemnity with named exclusions and a remedy ladder, deletion of customer personal data within 30 days of termination, a 72 hour incident notification commitment and a subprocessor list with an objection right. On the Ironclad record the index located no customer agreement at all.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of a core capability, layered on a product that would function without them as a workflow system. Ironclad is a contract lifecycle management platform: intake, no code Workflow Designer, approvals, routing, signature, repository, analytics and integrations all predate and stand without generative AI, and the vendor sells that workflow layer as its foundation. What the models drive is real and central rather than peripheral, which is why this is not a C: AI Playbooks with each play tied to a clause do the redlining, and Jurist runs a named family of agents for drafting, editing, review, research, intake and redlining under a Manager Agent, with Conversational Search over the repository. Second B on this axis after Definely, and for the same structural reason: an established product with a substantial AI layer rather than an AI native one.
The models drive the capability being sold and sit on a contract lifecycle platform that predates them and would function without them. Sirion has traded since 2012 and the product is structured as Store, Create and Manage, covering repository, drafting, approval, negotiation, obligation tracking and performance management. Strip out the agents and agentOS and a working enterprise CLM remains, which is the category Gartner placed it in. The agentic layer is real rather than cosmetic, with agents described as extracting and normalising contracts, assembling first drafts from a playbook, proposing redlines on third-party paper and monitoring obligations, and agentOS lets a customer build and deploy their own. That is the B band: the machine learning is the engine of a core capability layered on a workflow system.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted and the grounding behind it is not documented. Vendor material claims precision redlining, advanced AI and proprietary legal AI models trained on legal terminology with legal engineered prompts. Real structure exists in the AI Playbooks mechanism, where each play is tied to a clause and the system proposes varying degrees of revision to match preferred terms with minimal language change, so output is anchored to a customer authored standard a reviewer can check. What is missing is everything this axis measures: searched the site, the Ironclad AI and Jurist product pages, the security page and the support documentation via search on 29 Aug 2026 and located no accuracy figure, no hallucination rate, no test set, no evaluation, and no description of the retrieval method or how output grounds to a source a reader can open.
Accuracy is asserted at length and measured nowhere. The grounding claim is specific and repeated: answers are described as carrying citations linked to the customer's own data, and vendor material states that every AI-generated response includes citations linked to exact sources with clause-level citation and justification. Five percentage figures are published prominently, but every one measures speed or coverage rather than correctness: 90 per cent faster centralisation, 85 per cent faster insights, up to 90 per cent faster time to contract, 99 per cent on-time obligation compliance, 70 per cent faster agentic automation. Searched the home page, the trust centre and its AI ethics, compliance and security sections on 31 Aug 2026 and located no accuracy figure, no error or hallucination rate, no test set and no published evaluation. Nothing addresses what the system does when the customer's contract set does not support an answer.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A written commitment that the models work alongside a supervising human, with real and specific review surfaces, short of published thresholds. The vendor states human in the loop governance ensures every agent works transparently, is auditable and controllable, and says plainly that the customer is in charge, with governed and auditable AI review frameworks the customer can review, override and continuously govern across teams and contract types. The control surface is administrative as well as rhetorical: playbook permissions let administrators configure which users and groups may view, create and edit playbooks, and a Manager Agent routes tasks across the agent family so orchestration is visible. Vendor material states the agents automate repetitive lower risk work while strategic negotiation and nuanced risk assessment stay with the lawyer, which is a stated allocation. Not located as of 29 Aug 2026: the threshold at which an agent stops or escalates, and what the vendor commits to when an output is wrong.
Autonomy is claimed and the oversight mechanism is asserted in a phrase rather than described. Agents are said to sense intent, reason over enterprise data and act autonomously, to assemble first drafts and propose redlines, and to monitor obligations, surface gaps, trigger owners and drive follow-through. The single oversight statement located is that the user stays in control for strategic exceptions. What that leaves unpublished is everything the axis asks for: what an agent completes without a human, the threshold at which it stops and escalates, where the review point sits, and what happens after an output is wrong. agentOS is described as letting customers build, test and deploy agents, which implies configurable guardrails, but no control structure is documented. Searched the home page and the trust centre on 31 Aug 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Real deployment evidence with substance, short of dated attribution and method. A named customer carries a figure: NEXT Insurance is published as giving legal operations 50 percent of its time back with Jurist. Attributed customer quotes carry before and after numbers, including a first pass redline moving from 30 minutes to a couple of hours down to a solid first draft in minutes, and an MNDA review or custom order form clause drafting moving from an hour to a day down to minutes or seconds. A customer stories section is published. Not located as of 29 Aug 2026: a dated case study with a stated method a reader could assess, and the identity of the speakers behind several of the quoted figures.
Named customers and published figures, never attached to each other. Three individuals speak on the record with roles and employers: Edzard Janssen, Chief Procurement Officer at RBI; Reinhard Plaza-Bartsch, Head of Digital Supply Chain and Operations at Vodafone; and Angella Dikmic, Manager of IT Vendor Management at GTAA. All three quotes are qualitative. The five percentage claims carry no customer at all and read as product capabilities. Roughly 25 enterprise logos appear including Citi, GE, Coca-Cola, Chevron, PayPal, Bayer, Rolls-Royce, Aramco, Yamaha, DP World and Zalando, with customers stated across more than 70 countries and contract value under management put at more than 450 billion dollars. Two things a reader should note: all three named referees sit in procurement or vendor management rather than legal, on a platform indexed here as a legal product; and the case study library was not opened on 31 Aug 2026, so dates and method remain rebuttable.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments, and unusually the vendor addresses its own training use directly rather than only its providers. Published: strict do not train and zero data retention policies enforced with external LLM providers; any customer data used to train Ironclad's own models is anonymised and aggregated before use; output generated for other customers by models trained on a customer's data will never include that customer's data; and training data protection is stated as covered by the same security standards as the rest of the platform. Certification covers the privacy trust category under SOC 2 and includes ISO 27701 for privacy information management. Two gaps hold this off an A. Attorney client privilege and work product handling is not addressed directly in located material. Segregation between customers, users or matters is not documented on the pages checked.
Note amended 31 Aug 2026 under R23 as amended; grade held at B, and the reasoning for holding it is set out because the underlying facts have moved against the vendor. The original note recorded that the no-training commitment was located only in vendor library articles rather than in the agreement. The SaaS Terms have since been read in full, version 6, modified 26 August 2026, and the position is worse than a silence: clause 4.2 reserves a right for Sirion to direct its automated systems to review and process Customer Data to generally inform machine learning capabilities in the Subscription Services, with no opt-out located. The published no-training statement and the governing agreement therefore contradict each other, and under the documents-beat-marketing rule the agreement is what binds. What still supports the grade is the rest of the confidentiality architecture, which is genuinely substantive and readable before signing: the data processing addendum stores and processes all customer data in a customer-specific Sirion application instance, sets Article 32 technical and organisational measures with AES-256 at rest and TLS 1.2 in transit, imposes need-to-know and least-privilege access with automatic logout, requires deletion within 30 days of termination, and commits to notifying the customer of a confirmed security incident within 72 hours. SaaS Terms section 5 adds a mutual confidentiality regime with a duty to give prior notice of any authority or court demand so the other party can object. Privilege and work product remain unaddressed on every surface read. The grade is held rather than dropped because the C band describes confidentiality asserted in general terms or reachable only through a sales conversation, and neither is true here. A reader who takes the B band's requirement of substantive commitments on training use to mean commitments not contradicted by the agreement would grade this C, and that reading is defensible on these facts.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The intended audience is broad by design and no position on the advice line was located. Dedicated pages address legal operations and general counsel alongside procurement and IT, and vendor material describes the platform as serving business teams that touch contracts, with the AI proposing redlines and drafting negotiation ready revisions for those users. Searched the site, the product and persona pages, the security page and the support documentation via search on 29 Aug 2026 and located no statement on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits. The human in the loop governance language is a control statement rather than a professional responsibility position, and the two are not the same thing.
Nothing published on the advice line was located. Searched the home page, the full trust centre index and its AI ethics, compliance and security sections, and the terms and policies index on 31 Aug 2026. No statement that Sirion does not provide legal advice, no professional responsibility or ethics page, no named bar or ethics guidance including ABA Formal Opinion 512, and no jurisdiction limits. The exposure is not theoretical: the platform is sold to procurement, sales and finance departments alongside in-house legal, all working on the same contracts, and the three customer referees the vendor chose to feature are procurement and vendor management leaders rather than lawyers. The SaaS terms and end user agreement were read only in fragments through the search index, so this grade is rebuttable if either carries a professional advice disclaimer.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A published governance framework with real substance, short of testing results, a named owner and any bias disclosure. What exists is a described mechanism rather than a principles page: governed and auditable AI review frameworks, human in the loop governance stated as ensuring every agent is transparent, auditable and controllable, customer ability to review, override and continuously govern agent behaviour across teams and contract types, and administrator configurable permissions determining who may view, create and edit the playbooks that drive AI behaviour. A chief technology officer is named publicly as owning the AI roadmap. Not located as of 29 Aug 2026: an AI management certification such as ISO 42001, published pre release testing results, a named accountable owner for model governance as distinct from the technology function, and anything on uneven output across matter types, parties or populations.
The trust centre carries a section titled Artificial Intelligence Ethics and Governance, and its entire published content is three sentences: that Sirion has instituted an AI Governance Program abbreviated S-AIGP, that the programme monitors and ensures compliance with the EU AI Act 2024/1689 and other global AI regulations as they emerge, and that the reader should contact their Sirion Account Executive for more information. The page was last modified 16 December 2025. Naming a programme and a regulation, then routing the substance to a sales conversation, is not a governance position: nothing is published about who owns model behaviour, what is tested before release, how the programme operates, or anything at all concerning bias or uneven output. Under the gating rule a referral to an account executive is the sales-gated tier and earns no credit. This is the sharpest example in this pull of a governance artifact that exists as a heading rather than as disclosure.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy covering most of the ground. Certification breadth is the strongest element and is stated precisely: routine audits producing third party SOC 1 and SOC 2 Type II reports certified against multiple trust categories named as security, availability, confidentiality and privacy, plus ISO 27001, 27701, 27017 and 27018, a dedicated GDPR programme, and Cloud Security Alliance membership with Trusted Cloud Provider status. Data centre operations run on public cloud providers the vendor states are themselves certified under SOC 2, ISO 27001 and PCI DSS, across multiple regions. Zero data retention is enforced at the external model layer. Not located as of 29 Aug 2026: a stated retention period or deletion control for customer contracts and prompts in Ironclad's own systems, a named subprocessor list, and an incident or breach notification practice.
Amended 31 Aug 2026 under R23 as amended, from B to A. The Data Processing Addendum at /terms-and-policies/data-processing-addendum/, version 3, modified 2 July 2026, was read in full on 31 Aug 2026; the original grading rested on fragments recovered through the search index, and the full document supplies every element this axis asks for. Retention and deletion: Appendix B sets the retention period by the controller's contractual direction, and clause 8.1 requires deletion or return of all Customer Personal Data including copies within 30 days of termination, with any law-compelled retention limited to the purposes requiring it and kept under the Agreement's protections. The SaaS Terms add automatic deletion after 30 days as a backstop. Access control: defined permissions on need-to-know and least-privilege-by-default, with automatic logout on inactivity. Subprocessors: a named Sub-Processor List published at its own URL, with a commitment to notify and an objection right on any addition or replacement, equivalent contractual terms imposed on each, and Sirion remaining liable for their breaches. Incident practice: clause 4.3 commits to notifying the customer within 72 hours of establishing material impact from a confirmed Security Incident, with Appendix B stating 48 to 72 hours and continuing communication until resolution, and the definition expressly excludes unsuccessful attempts such as failed logins and denial-of-service attempts, which is a precision most vendors leave out. Encryption is AES-256 at rest and TLS 1.2 in transit. All five limbs are published, current and specific enough to hold the vendor to, which is what separates A from B here; the earlier B rested on the subprocessor list and incident window not having been located rather than on their absence.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Searched the site navigation, the security page, the Ironclad AI and Jurist product pages, the support documentation and the article library via search on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer agreement or master services agreement was located as published on the property. Recorded as a pure absence on the surfaces checked. Rebuttable with a single link to a published agreement, which for an enterprise platform of this size may well exist somewhere not surfaced by the searches run.
A real published position, readable before signing, short of the cap and silent on AI output. The SaaS terms and a separate end user agreement are both published openly. Clause 7.1 commits Sirion to indemnify and defend the customer against third-party claims that use of the subscription services infringes intellectual property rights. Clause 7.2 sets four named exclusions, covering combination with materials Sirion did not provide, unapproved modification, unauthorised use, and use inconsistent with the documentation. Clause 7.3 gives a remedy ladder of securing the right to continue, replacing or modifying the services, or terminating with a pro-rata refund of prepaid fees as Sirion's sole and exclusive liability. Clause 7.4 runs a reciprocal indemnity from the customer over customer data. What could not be established on 31 Aug 2026: the liability cap, since only fragments of the limitation clause were retrievable through the search index; any warranty on output; any insurance position; and any AI-specific treatment, since neither agreement carves AI output in or out of the indemnity.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations exist and are documented, and the vendor treats them as a primary differentiator. Named specifically: Salesforce, described by the vendor as the number one Salesforce integration in the market, and Coupa, with a dedicated integrations page and a stated claim of the deepest integrations in the market. The workflow layer is itself integration: teams create, manage and collaborate on contracts from inside the systems they already use rather than switching into the CLM. Orientation is toward enterprise commercial systems rather than legal document management, which fits a CLM buyer. Not located as of 29 Aug 2026: legal specific document management connectors such as iManage or NetDocuments, and per integration documentation describing what moves in which direction and what an administrator configures.
Written 31 Aug 2026 as an R7 amendment; this row was left unwritten in the original build because no integration surface had been opened and grading an absence would have scored a research gap against the vendor. Surface read on 31 Aug 2026: the Non-Native Integrations article in Sirion University at /sirion-university/integrations/non-native-integrations/, last updated 24 February 2026. It documents nine named connectors with the direction of travel stated for each, which is the depth this axis asks for and which almost nothing else in the corpus publishes. Four SAP Ariba accelerators cover procurement, bids, awards and contract workspaces: an executed contract request in Sirion creates a purchase requisition in Ariba and the resulting purchase order is written back to Sirion; Ariba sourcing events and RFPs convert into Contract Draft Requests on defined workflow triggers, one per bidding supplier with line items mapped from bid detail, and supplier redlines transfer into Sirion for legal review; awarded RFx events create a new draft request with awarded line items synced; and contracts finalised in Sirion replicate into Ariba Contract Workspaces with metadata, documents, line items and workflow status, by event-driven asynchronous processing. Three more cover supplier master data from Ariba, SAP S/4HANA Business Partners on scheduled transfers, and Oracle ERP with built-in logging, error handling and sync status visibility. The Microsoft Dynamics connector is explicitly bidirectional and runs in auto or manual mode. Configuration is described at the level of triggers, modes and scheduling rather than a full implementation guide, and the wider Sirion University catalogue requires a login. The documented depth sits on the procurement and ERP side; the Microsoft Word add-in is distributed through AppSource and Salesforce through AppExchange, but neither is documented to this depth on a page read, and no document management system connector such as iManage or NetDocuments was located.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Residency is offered without the processing location being addressed, which is the B band. The vendor states it leverages multiple data centre regions from its cloud providers specifically to meet data residency requirements, which is a real published residency position rather than a geography footnote. What is missing: the cloud providers are described only as public cloud vendors and are not named, no available regions are listed, no customer selectable region is stated, no tenancy model is given, and no statement separates where processing happens from where data is stored. Checked the security page and the platform pages via search on 29 Aug 2026.
The tenancy model is stated in the agreement and the regions are not stated anywhere. The data processing addendum states that the Sirion application is a SaaS application hosted by a cloud service provider and that all customer data is stored and processed in a customer-specific Sirion application instance, which is a real isolation statement carried in a contractual document rather than a marketing claim. The trust centre names four underlying providers, AWS, Azure, Oracle and IBM, which is unusually broad and implies customer choice without stating it as an option. Two gaps checked 31 Aug 2026: no data residency commitment, region list or jurisdiction option was located anywhere, and nothing addresses where processing happens as distinct from where data is stored. One tension worth a buyer's attention: a Sirion library article describes the platform's multi-tenant scalability, which sits awkwardly beside the addendum's customer-specific instance, and nothing published reconciles the two.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real and stated with correct scope language, short of accessible evidence. The vendor names SOC 1 and SOC 2 Type II from routine third party audits and, unusually, names the trust categories certified against: security, availability, confidentiality and privacy. ISO 27001, 27701, 27017 and 27018 are all named, which is a broader ISO set than most of this index carries, and Cloud Security Alliance membership with Trusted Cloud Provider status is stated. Supply chain assurance is addressed by stating that the underlying cloud vendors are themselves SOC 2, ISO 27001 and PCI DSS certified. What was not located as of 29 Aug 2026 is the evidence route: no audit coverage period, no report date, no named auditing firm, and no trust portal or published request flow for obtaining the reports.
Note amended 31 Aug 2026 under R23 as amended; grade unchanged at B. The Data Processing Addendum, read in full on 31 Aug 2026 where the original grading had only fragments, supplies two things the earlier note recorded as missing. Appendix B names ISO 27001 as a held security certification and describes the review regime around it, and clause 7.1 gives a contractual access route: unless otherwise agreed, Sirion will provide a copy of its most current security attestation report on the customer's written request, no more than once annually. Clause 7.2 adds a customer audit right, with scope, timing and controls agreed in advance and a reasonable fee chargeable. Appendix B also records that the cloud provider's own SOC 1, SOC 2 and ISO 27001 reports are assessed by Sirion as part of a shared responsibility model, which is oversight of infrastructure rather than an attestation over the application and is not credited here. The grade stays at B because the access route is a contractual entitlement running to an existing customer, not a way for a buyer to obtain evidence before signing, and because no auditor is named, no coverage period is stated, and no scope statement says which systems the ISO certificate covers. Under R5 the line is the sales conversation, and a report obtainable only after execution sits below the self-serve tier that can reach A.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The vendor refers to models without identifying what sits underneath. Two layers are acknowledged and the distinction between them is drawn clearly, which is more than most manage: proprietary legal AI models built by Ironclad with legal engineered prompts, and external LLM providers bound by do not train and zero data retention terms. That tells a buyer the shape of the chain and the commercial terms binding it. What it does not tell them is who is in it. Searched the site, the Ironclad AI and Jurist pages, the security page and the article library via search on 29 Aug 2026 and located no named external model provider, no statement of where models run, no subprocessor list, and no commitment to notify customers when the supply chain changes.
The architecture is described and nothing underneath it is identified. Vendor material sets out a multi-model approach combining purpose-built small models trained on enterprise contracts with large language models, and presents that as the differentiator against generic models retrofitted for legal use. No large language model provider is named, no model or version is identified, no processing location is given for the model layer as distinct from the cloud infrastructure, and nothing commits Sirion to notifying customers when any of it changes. This sits above the floor because the architecture is genuinely described rather than gestured at, and below anything higher because a buyer inherits dependencies it cannot see. Searched the home page, the trust centre and its AI ethics, compliance and security sections on 31 Aug 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Checked the site navigation, the platform and product pages, the persona pages and the security page via search on 29 Aug 2026. No pricing page was located on the property, no rate is published, no unit of charge is stated and no tier structure appears. Every commercial path located terminates in a demo request. No free trial or self serve entry point was located. Consistent with third party coverage describing implementation cost as dependent on the scope of the CLM deployment rather than on a published rate.
No pricing information is published at any level, including the unit of charge. Searched the home page, the full primary navigation across platform, solutions, resources and company, the footer sitemap, the trust centre and the terms and policies index on 31 Aug 2026. There is no pricing page, no tier structure, no per-seat, per-contract or per-agent unit, no volume banding and no statement of what implementation adds. Every call to action is a demo request. Nothing published would let a prospective buyer form any view of cost before entering a sales process, which is a notable contrast with the vendor's willingness to publish its SaaS terms, end user agreement and data processing addendum in full.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is described with substance, short of the boundaries. Four buyer personas carry their own published positioning: legal operations, general counsel, procurement and IT, and the vendor addresses business teams beyond legal that touch contracts. Enterprise class and global business teams are stated as the target, and at least one industry, manufacturing, carries dedicated positioning around leakage and contract performance. Practice scope is clear and consistent throughout: contracting end to end from intake to post signature, with no claim to litigation or research capability. Not located as of 29 Aug 2026: a statement of which organisation sizes or contract types the platform is not built for, and an enumerated industry or practice area list comparable to the strongest records on this index.
Segment coverage is documented precisely on two axes and the boundaries are left open. Eight industry verticals carry dedicated pages: financial services split into procurement and capital markets and credit, insurance with a separate underwriting submissions triage solution, automotive, IT services, healthcare, pharmaceuticals and life sciences, telecom, and oil and gas. Five departments carry their own pages: in-house legal, legal operations, procurement, sales and finance. Customers are stated across more than 70 countries and the site publishes in English, German and French. What is absent is any statement of where the product stops: no contract types or matter types are excluded, nothing addresses law firms, government or public sector use, and the practice dimension is expressed as industry and department rather than as areas of law. Checked 31 Aug 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The clearest opt in on this signal in the index, and the vendor argues for it openly rather than burying it. Published: customers may opt into allowing Ironclad to train its own models on their contracting data; any customer data so used is anonymised and aggregated before use; output generated for other customers by models trained on that data will never include the contributing customer's data; and the customer stays in control with data kept confidential. Separately and distinctly, strict do not train and zero data retention policies are enforced with external LLM providers, so the third party layer is prohibited while the vendor's own layer is permitted with consent. Recorded at opt in because training occurs only where the customer has affirmatively enabled it. What was not located as of 29 Aug 2026 is where the opt in is exercised, whether it sits in the agreement or a product setting, and whether it can be withdrawn.
Amended 31 Aug 2026 from policy-never, under R23 as amended: the SaaS Terms were read in full, where the original grading had only fragments, and the earlier value rested expressly on no training prohibition having been found in the portions then retrievable. Both sides of the record, because the gap between them is the finding. Sirion's library material states that customer data stays within the customer environment and is not used to train external language models. Its SaaS Terms, version 6, modified 26 August 2026, reserve the opposite at clause 4.2: Sirion may direct its automated systems to review and process Customer Data to generally inform machine learning capabilities in the Subscription Services, alongside generating aggregated and anonymised industry analytics, with a commitment not to publicly identify the customer or disclose Customer Data to third parties. The agreement governs over a policy page, so the reservation is what a buyer is bound by. Two features of the wording a reader should weigh directly. The reservation operates on Customer Data itself rather than on de-identified or aggregated derivatives, which makes it broader in reach than clauses that are limited to aggregate data. But it says generally inform rather than train, so whether it authorises model training in the ordinary sense is a question the words leave open. No opt-out, consent step, configuration setting or exclusion route was located in the SaaS Terms, the end user agreement or the data processing addendum.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is answered at the external model layer and unaddressed for the platform itself. The vendor states it enforces zero data retention with external LLM providers, so prompts and completions are not persisted by those providers. Searched the security page, the platform pages, the article library and the support documentation via search on 29 Aug 2026 and located no retention period for contracts, prompts or outputs held in Ironclad's own repository, no customer control over that window, and no deletion commitment. That gap is material here because the product is a system of record designed to hold every executed agreement indefinitely, so the retention question is the core of what the customer is buying.
The published data processing addendum states that the retention period is determined by contractual obligations as directed by the controller, and that after termination personal data processed on the controller's behalf is retained typically for a period of 30 days. That places the window under customer instruction with a stated default, in a contractual document rather than a policy page, which is stronger than most of this pull. Two qualifications: the provision is framed around personal data rather than prompts and generated outputs specifically, and no zero-retention setting is offered or described. Read 31 Aug 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own documented permission model rather than inheriting one from a document management system. Published support documentation states that administrators can configure Ironclad users and groups to permit or restrict which users may view, create and edit AI Playbooks, so the standards driving AI behaviour are themselves access controlled, and the workflow layer routes and assigns contracts across named reviewers. That is a documented internal permission model. What was not located as of 29 Aug 2026 is segregation of the contract repository itself between users or matters, any ethical wall concept, and any legal document management integration whose permissions retrieval could inherit at query time. Noted for context: the buyer here is an in house or business team rather than a firm carrying conflicts obligations, so the question reads differently than it would for a firm facing product.
Separation between customers is documented in the data processing addendum rather than asserted in marketing: all customer data is stated to be stored and processed in a customer-specific Sirion application instance in the cloud service, under a shared responsibility model in which Sirion secures the software, the customer data and the related access while the cloud provider secures the underlying facility. Role-based access control with granular permissions is described in vendor library articles. Two things to note. Nothing describes how access is enforced between teams inside a customer, which matters where legal, procurement, sales and finance share the platform. And a Sirion library article describes the platform's multi-tenant scalability, which is not reconciled anywhere with the addendum's customer-specific instance. The buyer is an in-house department, so tenant-level separation is the relevant test.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Searched the security page, the site navigation, the article library and the support documentation via search on 29 Aug 2026. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. No published customer agreement or data processing agreement was located on the property either, so the search covered the public pages rather than the contract documents.
Written 31 Aug 2026 as an R7 amendment. The commitment is in the SaaS Terms at section 5.3, version 6, modified 26 August 2026, and not in the Data Processing Addendum, which was read in full the same day and does not address third-party demands anywhere. Section 5.3 permits a party receiving a demand from a competent authority or court for the other party's Confidential Information to comply only if it has satisfied itself the demand is lawful, given the disclosing party as much prior notice as possible where possible so that party can object, and marked the material as the disclosing party's Confidential Information. The obligation is mutual and it reaches customer material: Confidential Information is defined to cover information that should reasonably be understood to be confidential, and the AI Module clause at 1.8(b) confirms the reading by carving Customer Data back into that definition. The notice duty is qualified by where possible rather than by legal prohibition, which is softer than the usual formulation. No transparency report or count of demands received was located on the terms pages, the DPA or the trust centre, which is what keeps this below the top value.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No primary law corpus is identified because the product does not hold one. Retrieval runs against the customer's own contract repository and their own AI Playbooks, and the vendor's proprietary models are described as trained on legal terminology and contract management architecture with legal engineered prompts, plus, where customers opt in, anonymised and aggregated customer contracting data. That last element is the closest thing to a vendor corpus and its provenance is disclosed in principle, being customer contributed under consent, though no scale figure, licence basis or update cadence is published for it. Searched the site, the Ironclad AI page and the article library on 29 Aug 2026.
The working corpus is the customer's own contract set and is identified as such, with answers described as carrying citations linked to the customer's own data and agents extracting and normalising contracts from customer-nominated sources. Sirion separately states that its purpose-built models are trained on millions of enterprise contracts, which identifies a second corpus at the level of composition without naming any source, stating any licence or rights basis, or explaining whose contracts those are. The product does not retrieve primary law, so the usual jurisdiction and coverage questions do not arise. No update cadence is published.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Searched the site, the product pages and the support documentation via search on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is a contract lifecycle platform grounded in the customer's own playbooks and repository, with no case law research surface, so a citator is outside its design entirely.
Searched the home page, the trust centre index and its AI ethics, compliance and security sections, and the terms and policies index on 31 Aug 2026. Nothing addresses whether legal authority is checked for subsequent history, and no citator, treatment signal or currency check was located. The platform manages contracts, obligations and supplier performance rather than retrieving case law or legislation, so a citator is not part of what it sells.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Searched the site, the Ironclad AI and Jurist pages, the agent launch material and the support documentation via search on 29 Aug 2026. No published material describes what the product does when it cannot ground an answer, and no explicit no answer path or confidence signal exposed to the user was located. The Review Agent is documented as identifying missing clauses and compliance gaps, which is flagging what is absent from a contract rather than the system declining to answer, and the two were not conflated.
Searched the home page, the trust centre and its AI ethics, compliance and security sections on 31 Aug 2026. No explicit no-answer or abstention path is documented and no confidence or grounding score was located. Published material runs the other way, describing agents that sense intent, reason over enterprise data and act autonomously, and answers delivered with citations, without stating what happens when the customer's contract set does not support a response. The nearest adjacent material is the statement that users stay in control for strategic exceptions, which describes an escalation posture rather than model behaviour under uncertainty.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note that this is a contract lifecycle product with no case law research surface, so its output is very unlikely to reach a court filing as cited authority.
No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, searched on both the product name and the former company name SirionLabs, alongside 2026 sanctions trackers and trade press summaries. This is a statement about the public record on the date shown rather than a clearance, and it is bounded by what that database covers. The platform runs enterprise contracting and supplier governance rather than producing court filings.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Searched the site, the article library, the persona pages and the community and resources sections via search on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512 and state bar guidance. The vendor publishes substantial material on AI governance, auditability and human in the loop control, which addresses how its own system is controlled rather than the professional responsibility obligations its legal buyers are bound by.
Searched the home page, the full trust centre index and its AI ethics, compliance and security sections, and the terms and policies index on 31 Aug 2026. No engagement with any bar or ethics guidance was located, including ABA Formal Opinion 512 and any state bar or Law Society material. The compliance material published is regulatory and security-framework oriented, covering ISO 27001, SOC 1, SOC 2 and the EU AI Act, and none of it addresses the professional conduct obligations binding the lawyers who use the product.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Savings are claimed and quantified with nothing published on the client's side of the equation. Published figures include a named customer recovering 50 percent of legal operations time, first pass redlines moving from up to a couple of hours down to minutes, and MNDA review moving from up to a day down to minutes or seconds, alongside framing about scaling review without adding headcount. Searched the site, the product pages, the article library and the support documentation via search on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment. Noted for context: the buyer is an in house or business team that does not bill a client by the hour, so this signal reads differently for this segment.
Public materials are built around speed and automation gains: 90 per cent faster contract centralisation, 85 per cent faster insights, up to 90 per cent faster time to contract, 70 per cent faster agentic automation, and a customer reporting as much as a 50 per cent uptick in tasks automated. Searched the home page, the trust centre and the terms and policies index on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee purposes and no published guidance on billing, fee or disclosure treatment. The buyer is an in-house function rather than a firm billing a client, so the question lands on internal cost and outside counsel spend, and neither is addressed.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
Substantial certification material is published openly, including SOC 1 and SOC 2 Type II with the trust categories named, ISO 27001, 27701, 27017 and 27018, a GDPR programme and Cloud Security Alliance Trusted Cloud Provider status, all reachable without a sales conversation. But the artifacts this signal turns on were not located as of 29 Aug 2026: no subprocessor list, no statement naming which model providers see customer content, no published data processing agreement, and no client facing consent or notification pack. The vendor states its external LLM providers are bound by do not train and zero data retention terms without naming them, which is a statement about the terms rather than a disclosure of the chain. Recorded as not addressed because no list exists to point to.
Amended 31 Aug 2026 under R23 as amended: the Data Processing Addendum was read in full, where the original grading had only fragments, and it closes the gap the earlier value rested on. Appendix D publishes a Sub-Processor List, stated to be regularly updated, at a named URL reachable without a sales conversation, and clause 5.4 commits Sirion to notify the customer of updates and give an opportunity to object to additions or replacements. Clause 5.6 requires equivalent data protection terms on every sub-processor and keeps Sirion liable for their breaches. That is the artifact this value turns on and it is published, which lifts the record off the request-only tier. It stops short of a disclosure pack: no model provider is named in the located material, and no client-facing consent or notification material exists for a firm answering a client's AI clause. The AI governance detail that would accompany such a pack is still routed to a Sirion Account Executive on the trust centre's AI ethics page.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of a record are available and the auditability language is more specific than most. The vendor publishes governed and auditable AI review frameworks with human in the loop review, stating customers get transparent auditable AI behaviour they can review, override and continuously govern across teams and contract types, and the workflow layer records routing, assignment and approvals per contract. Two elements are missing: no per document export covering model used, sources retrieved and human verification together was located, and no model is named anywhere in published material so the model used could not be stated. Noted for context: this is a contracting platform rather than a litigation product, so a judicial AI disclosure order is unlikely to reach its output.
Some elements of a record exist as a by-product of the product's design. Answers are described as delivering citations linked to the customer's own data, vendor material states that every AI-generated response includes citations linked to exact sources with clause-level citation and justification, and granular audit trails are described as recording system activities, user actions and data modifications. That covers sources retrieved and, in part, what was done. Two elements are missing: no model is identified anywhere on the property, so which system produced a given passage cannot be established, and no export designed for a court disclosure or AI-use certification was located on 31 Aug 2026. The product serves enterprise contracting rather than litigation, so a judicial standing order is not its usual context.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- Commercial Transparency
- Good Law Verification
- Refusal and Uncertainty Behaviour
- Bar Guidance Alignment
Which one fits
Choose Ironclad if
- You want the standards that drive the AI under access control, not just its output under review. Ironclad publishes administrator configurable permissions determining which users and groups may view, create and edit the AI Playbooks behind its redlining, states that customers can review, override and continuously govern agent behaviour across teams and contract types, and routes work through a Manager Agent so orchestration is visible.
- Your procurement gate is a list of standards with scope attached. Ironclad names SOC 1 and SOC 2 Type II from routine third party audits and states the trust categories certified against, being security, availability, confidentiality and privacy, alongside ISO 27001, 27701, 27017 and 27018, a GDPR programme and Cloud Security Alliance Trusted Cloud Provider status.
- You want the training question answered in both directions. Ironclad states strict do not train and zero data retention terms with its external model providers, and separately that customers may opt in to Ironclad training its own models on their contracting data, with that data anonymised and aggregated first and output generated for other customers never including the contributing customer's data.
Choose Sirion if
- You want to read the contract before the demo. Sirion publishes its SaaS terms, an end user agreement and a data processing addendum openly. Clause 7.1 carries an intellectual property indemnity with four named exclusions and a remedy ladder of securing the right to continue, replacing the services or terminating with a pro rata refund, and section 5.3 requires prior notice of a court or authority demand so the other party can object.
- Your privacy review works through a checklist. Sirion's data processing addendum sets retention by the controller's direction with deletion of all customer personal data within 30 days of termination, publishes a subprocessor list at its own URL with notification and an objection right on any addition, commits to notifying a confirmed security incident within 72 hours, and specifies AES-256 at rest and TLS 1.2 in transit.
- Your contracts have to move through SAP or Oracle. Sirion documents nine named connectors with the direction of travel stated for each, including four SAP Ariba accelerators where an executed contract request creates a purchase requisition and the resulting purchase order is written back, supplier master data from Ariba, SAP S/4HANA on scheduled transfers, Oracle ERP with logging and sync status, and a bidirectional Microsoft Dynamics connector.
In summary
Ironclad
Ironclad is an enterprise contract lifecycle management platform covering intake, contract creation, no code workflow automation, approvals, negotiation, signature, repository and analytics, with AI Playbooks driving redlining and the Jurist family of agents running drafting, editing, review, research, intake and redlining under a Manager Agent. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes. Its clearest published control is administrative: administrators configure which users and groups may view, create and edit the playbooks the AI works from, and the vendor states customers can review, override and continuously govern agent behaviour. As of 29 August 2026 the index located no customer agreement, no liability position, no named model provider and no published price.
Sirion
Sirion is an enterprise contract lifecycle platform organised around Store for extraction, repository and conversational search, Create for drafting and negotiation, and Manage for obligations and performance, with an agentOS layer for building and deploying custom agents, sold to legal, legal operations, procurement, sales and finance. The AI Legal Index grades it in the top two bands on nine of fifteen capability axes, with A grades on practice systems integration depth and on AI safety and data stewardship. Its data processing addendum sets deletion within 30 days of termination, publishes a subprocessor list with an objection right and commits to notifying a confirmed security incident within 72 hours. As of 31 August 2026 the index located no accuracy figure, no named model provider and no published price.
Questions buyers ask
Ironclad vs Sirion: which is better for enterprise contract lifecycle management?
The AI Legal Index places Ironclad in the top two bands on ten of fifteen capability axes and Sirion on nine, which is close enough that the choice turns on which half of the disclosure a buyer needs. Ironclad publishes more about how the AI is controlled and certified. Sirion publishes the agreements, the data processing addendum and the integration documentation. Neither publishes a price or an accuracy measurement.
Does Sirion use customer contract data to train its AI?
Two documents speak to it. Sirion's library material states that customer data stays within the customer environment and is not used to train external language models. Clause 4.2 of its SaaS terms reserves a right for Sirion to direct automated systems to review and process customer data to generally inform machine learning capabilities in the subscription services, with no opt out located anywhere in the terms, the end user agreement or the data processing addendum. The AI Legal Index records the agreement, because that is the document that governs the relationship.
Which one publishes its contract terms?
Sirion. Its SaaS terms, end user agreement and data processing addendum are all published openly, carrying an intellectual property indemnity, a mutual confidentiality regime with notice of authority demands, a 30 day deletion commitment and a published subprocessor list. On the Ironclad record the index located no customer agreement of any kind as of 29 August 2026, so no indemnity, liability cap, warranty on output or insurance position is published, and none of it is readable before entering a sales process. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What do Ironclad and Sirion publish about integrations?
Sirion documents integrations to a depth almost nothing else in this index matches: nine named connectors with the direction of travel for each, covering SAP Ariba, SAP S/4HANA, Oracle ERP and a bidirectional Microsoft Dynamics connector, with triggers and sync modes described. Ironclad names Salesforce and Coupa and treats integration as a differentiator, and no page located describes what any individual integration moves, in which direction, or what an administrator configures. Neither names a legal document management connector. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What do Ironclad and Sirion both leave unpublished?
Neither publishes a price, a tier structure or a unit of charge, so both route every commercial question to a demo. Neither names a model or a provider behind its AI, although both confirm external models are involved. Neither publishes an accuracy figure, hallucination rate or test set for contract review. And neither states that its output is not legal advice, which matters because both platforms are sold to procurement, sales and finance teams alongside legal. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
One finding here needs both documents named. Sirion's library material states that customer data stays within the customer environment and is not used to train external language models. Clause 4.2 of its SaaS terms, version 6 modified 26 August 2026, reserves a right for Sirion to direct its automated systems to review and process customer data to generally inform machine learning capabilities in the subscription services, with no opt out located, and the index records the agreement because that is the document that governs. The clause says generally inform rather than train and operates on customer data rather than de identified derivatives, so the wording is worth reading directly. Ironclad publishes no customer agreement at all, so its own position sits in product material. Ironclad was verified on 29 August 2026 and Sirion on 31 August 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.