Ironclad vs SpotDraft: how they compare in 2026

I
Ironclad profile
S
SpotDraft profile
Last verifiedOctober 8, 2026

Ironclad and SpotDraft are both contract lifecycle platforms sold to in house legal teams and the business teams around them. Ironclad is the larger enterprise system: a no code workflow designer, AI Playbooks with each play tied to a clause, and Jurist, an agentic contract partner with named agents for drafting, editing, review, research, intake and redlining, plus deep Salesforce and Coupa integrations. It sets out its training terms: Ironclad trains its own models on customer data only where the customer opts in, after anonymizing and aggregating it, and holds external model providers to no training and zero data retention. Its certifications run from SOC 2 Type II across security, availability, confidentiality and privacy to ISO 27001, 27701, 27017 and 27018. SpotDraft is more specific on location and the profession: a residency choice across the US, the EU, India and the Middle East, per contract encryption keys, and named ethics guidance. Ironclad publishes no customer agreement and SpotDraft's published terms cover its signup path. Neither publishes a price or an accuracy measure.

At a glance

Category
IroncladContract Review & Drafting
SpotDraftContract Review & Drafting
Founded
Ironclad2014
SpotDraftNot published
Headquarters
IroncladSan Francisco, California, United States
SpotDraftNot published
Last verified
IroncladAug 29, 2026
SpotDraftAug 31, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Ironclad
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models drive a core capability, layered on a product that would work without them as a workflow system. Ironclad's intake, no code Workflow Designer, approvals, routing, signature, repository, analytics and integrations all predate and stand without generative AI, and the vendor sells that workflow layer as its foundation. What the models drive is real and central: AI Playbooks, with each play tied to a clause, do the redlining, and Jurist runs a named family of agents for drafting, editing, review, research, intake and redlining under a Manager Agent, with Conversational Search over the repository. This is an established product with a substantial AI layer rather than one built on AI from the start.

SpotDraft
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

SpotDraft is a full contract lifecycle system first: templates, conditional workflows and approvals, a shared editor, built in eSignature meeting ESIGN, eIDAS and ECA, a repository, reporting and analytics. Without SpotDraft AI, VerifAI, Intake and Sidebar, a working CLM with signature and workflow remains, with its own market. The AI covers review inside Word, automatic extraction of more than a thousand metadata types, and agents that track regulatory change. SpotDraft now calls itself context aware, AI native CLM, but the platform predates that framing.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Ironclad
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is asserted, and the grounding behind it is not documented. Vendor material claims precise redlining, advanced AI, and proprietary legal AI models trained on legal terminology with prompts engineered for legal work. The AI Playbooks give real structure: each play is tied to a clause, and the system proposes varying degrees of revision to match preferred terms with minimal change, so output is anchored to a standard the customer wrote and a reviewer can check. No accuracy figure, hallucination rate, test set, evaluation, or description of the retrieval method or how output links to a source a user can open is published.

SpotDraft
DD on Citation Accuracy and Hallucination DisclosureNothing published on accuracy or grounding for a product that produces legal assertions, or a bare claim that the system does not hallucinate.

SpotDraft publishes nothing on accuracy or grounding. There is no accuracy figure, error or hallucination rate, benchmark, test set or evaluation on the home, pricing or security pages. Nothing describes how AI output is grounded in the customer's documents or whether a user can trace a statement back to its source. The figures SpotDraft publishes measure speed and cost: contracts reviewed 15 times faster with VerifAI, closings twice as fast, 65 percent lower cost and 70 percent less review time. The nearest thing to an accuracy claim is that the AI works in the customer's own context and follows its rules, which describes setup, not correctness.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Ironclad
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

A written commitment that the models work alongside a supervising human, with real and specific review surfaces, short of published thresholds. The vendor states human in the loop governance ensures every agent works transparently, is auditable and controllable, and says plainly that the customer is in charge, with governed and auditable AI review frameworks the customer can review, override and continuously govern across teams and contract types. The control surface is administrative as well as rhetorical: playbook permissions let administrators configure which users and groups may view, create and edit playbooks, and a Manager Agent routes tasks across the agent family so orchestration is visible. Vendor material states the agents automate repetitive lower risk work while strategic negotiation and nuanced risk assessment stay with the lawyer, which is a stated allocation. Not located: the threshold at which an agent stops or escalates, and what the vendor commits to when an output is wrong.

SpotDraft
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

SpotDraft's approval routing is conditional, with thresholds shown, for example approvals going to the Head of Finance below a deal value and to the CFO and CEO above it. Audit logs trace changes at contract level by both the customer and the counterparty, every draft keeps its version history, and permissions are scoped by contract type, entity and department. Nothing describes control over the AI itself: what SpotDraft AI, VerifAI or the Sidebar agents do unattended, when a person must review model output, what agents can change without approval, or what happens when an output is wrong. Saying the AI follows the customer's rules implies limits without describing any.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Ironclad
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Real deployment evidence with substance, short of dated attribution and method. A named customer carries a figure: NEXT Insurance is published as giving legal operations 50 percent of its time back with Jurist. Attributed customer quotes carry before and after numbers, including a first pass redline moving from 30 minutes to a couple of hours down to a solid first draft in minutes, and an MNDA review or custom order form clause drafting moving from an hour to a day down to minutes or seconds. A customer stories section is published. Not located: a dated case study with a stated method a reader could assess, and the identity of the speakers behind several of the quoted figures.

SpotDraft
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

SpotDraft names in house lawyers with roles and employers: Anna Claveria Brannan, Deputy General Counsel at IPSY; Susan Koenig, formerly Senior Legal Operations Manager at Abnormal Security; Micah Nessan, formerly General Counsel at Guideline; Reason Abajuo, VP of Legal and Corporate Affairs at Chaberton Energy; Lizzy Gagan, Senior Legal Counsel at Beamery; Arzu Hasanova, Legal Counsel at Circularise; Aditi Kapoor, Director of Legal at Gameskraft; and Natasha Wilson, Head of Legal at SUN Mobility. Every quote is qualitative. The quantified claims carry no customer at all: two times faster closings, 65 percent lower cost, 70 percent less review time, and contracts reviewed 15 times faster. Two of the referees are identified as former employees of the companies named.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Ironclad
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Substantive published commitments, and the vendor addresses its own training use directly, not only its providers'. External LLM providers are held to strict terms against training and for zero data retention. Any customer data used to train Ironclad's own models is anonymized and aggregated first, and output generated for other customers by models trained on a customer's data will never include that customer's data. Training data is stated to be covered by the same security standards as the rest of the platform. Certification covers the privacy trust category under SOC 2 and includes ISO 27701 for privacy information management. Two gaps remain. Attorney client privilege and work product handling are not addressed directly in located material, and separation between customers, users or matters is not documented on the pages checked.

SpotDraft
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

SpotDraft's security page says customer data is logically separated within shared, multitenant infrastructure. Each contract has its own encryption key in HashiCorp Vault backed by Google Cloud KMS, with AES-256 at rest and FIPS 140 certified encryption. Data is classified as public, company confidential, customer confidential or personal, and access follows least privilege with unique IDs. Third party vendors handling scoped data must follow confidentiality, audit and incident response rules. Nothing published says whether customer contracts are used to train any model, by SpotDraft or a model provider, and no retention period for prompts or outputs is published. Privilege and work product are not addressed.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Ironclad
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

The intended audience is broad by design and no position on the advice line is published. Dedicated pages address legal operations and general counsel alongside procurement and IT, and vendor material describes the platform as serving business teams that touch contracts, with the AI proposing redlines and drafting negotiation ready revisions for those users. Searched the site, the product and persona pages, the security page and the support documentation via search and located no statement on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits. The human in the loop governance language is a control statement rather than a professional responsibility position, and the two are not the same thing.

SpotDraft
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

SpotDraft's home page says its AI features are designed with attention to the California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law, November 2023. It also names the American Bar Association's Formal Opinion 512 on generative AI, July 2024. Both are named with their issuer and date, on the home page rather than in a policy. Nothing addresses a lawyer's own competence and supervision duties or any limit on use by jurisdiction. The claim is attention to principles, not a mapping of product behavior to specific duties, so which principle each control meets is not shown.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Ironclad
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

A published governance framework with real substance, short of testing results, a named owner and any bias disclosure. The vendor describes a mechanism rather than a principles page. It offers governed and auditable AI review frameworks and human in the loop governance, stated as making every agent transparent, auditable and controllable. Customers can review, override and continuously govern agent behavior across teams and contract types, and administrators set permissions for who may view, create and edit the playbooks that drive AI behavior. A chief technology officer is publicly named as owning the AI roadmap. Not located: an AI management certification such as ISO 42001, published testing results before release, a named owner accountable for model governance as distinct from the technology function, and anything on uneven output across matter types, parties or populations.

SpotDraft
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

SpotDraft's security page describes a formal risk governance policy approved by management that defines an Enterprise Risk Management program. Periodic operational risk assessments feed management reports, with each risk rated, assigned an owner and tracked to treatment or acceptance. Privacy risk is assessed through vendor due diligence, and an information security team led by the Chief Technology Officer oversees the process. None of it covers model behavior. Nothing describes testing before an AI release, there is no responsible AI framework, and nothing addresses bias or uneven output across contract types, counterparties or populations.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Ironclad
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Substantive published policy covering most of the ground. Certification breadth is the strongest element and is stated precisely. Routine audits produce third party SOC 1 and SOC 2 Type II reports certified against security, availability, confidentiality and privacy, alongside ISO 27001, 27701, 27017 and 27018, a dedicated GDPR program, and Trusted Cloud Provider status as a Cloud Security Alliance member. Data centers run on public cloud providers that the vendor says are themselves certified under SOC 2, ISO 27001 and PCI DSS, across multiple regions. Zero data retention is enforced at the external model layer. Not located: a stated retention period or deletion control for customer contracts and prompts in Ironclad's own systems, a named subprocessor list, and an incident or breach notification practice.

SpotDraft
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

SpotDraft's security page, last updated 17 October 2025, describes FIPS 140 certified encryption, AES-256 at rest, and a unique key per contract held in HashiCorp Vault backed by Google Cloud KMS. Primary and backup servers run on Google Cloud Platform in the Netherlands. Data is classified into four sensitivity tiers, and access follows least privilege, with unique IDs and enforced password rules. There is a documented business continuity and disaster recovery program, automated patching, ongoing tracking of known vulnerabilities in third party packages, regular threat modeling, independent penetration testers, and routine code analysis and vulnerability scans. A set incident response process is stated and refined through regular exercises. No subprocessor is named, though the page says fourth parties such as backup providers and subcontractors have no access to scoped systems or data, and no retention period for customer content is published.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Ironclad
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

No published indemnity, liability cap, carve out, warranty on output or insurance position is published, and no customer agreement or master services agreement is published as published on the property.

SpotDraft
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

The SpotDraft Terms of Use on its Legal Hub at legal.spotdraft.com, version 2.3, last updated 21 February 2024, are published with five prior versions downloadable from the same page. Clause 8.3 caps SpotDraft's total liability, in contract or tort, at one hundred Indian rupees, roughly one US dollar. Clause 8.2 excludes consequential, indirect and special damages, including loss of data and profits. Clauses 5.2 and 5.3 disclaim fitness for purpose and error free or uninterrupted use, and expressly waive the warranty of noninfringement. Clause 9 is an indemnity from the customer to SpotDraft only, and the document contains no vendor indemnity. Clause 5.5 disclaims liability for consequences of using the Platform, and 5.4 says SpotDraft gives no legal advice. Indian law governs, with exclusive jurisdiction in the courts at Bangalore. The contracting entity is Draftspotting Technologies Private Limited, with affiliates including Draftspotting Inc. These are the Terms of Use reached from the signup path. Clause 11.8 contemplates added terms for other services, so an enterprise customer may sign a negotiated master agreement that is not published.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Ironclad
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Real integrations exist and are documented, and the vendor treats them as a primary differentiator. Named specifically: Salesforce, described by the vendor as the number one Salesforce integration in the market, and Coupa, with a dedicated integrations page and a stated claim of the deepest integrations in the market. The workflow layer is itself integration: teams create, manage and collaborate on contracts from inside the systems they already use rather than switching into the CLM. Orientation is toward enterprise commercial systems rather than legal document management, which fits a CLM buyer. Not located: legal specific document management connectors such as iManage or NetDocuments, and per integration documentation describing what moves in which direction and what an administrator configures.

SpotDraft
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

SpotDraft states more than 30 integrations and gives each its own page, with Salesforce, HubSpot, Slack, Microsoft Word for desktop, Google Drive, DocuSign, Greenhouse, Google Forms, Jira and Zapier all linked directly from the pricing page. VerifAI runs review inside Microsoft Word, negotiation and redlining are described as working in Word, Slack or SpotDraft itself, and one named customer credits the Word desktop editor with driving adoption. Single sign on covers Office 365, Google Workspace, Okta, Active Directory and custom SAML with zero touch provisioning. No document management integration such as iManage or NetDocuments appears, consistent with an in house rather than law firm product.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Ironclad
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Residency is offered without the processing location being addressed. The vendor says it uses multiple data center regions from its cloud providers specifically to meet data residency requirements, a real published residency position. The cloud providers are described only as public cloud vendors and are not named. No available regions are listed, no customer selectable region is stated, no tenancy model is given, and nothing separates where processing happens from where data is stored.

SpotDraft
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

SpotDraft's customer data is logically separated within shared, multitenant infrastructure. Residency is a customer choice with a clear limit: personal data is stored in selected regions covering the US, EU, India and the Middle East, and is not sent outside them. Primary and backup servers are on Google Cloud Platform in the Netherlands, and Google Cloud Platform runs processing throughout. Encryption keys are held per contract in HashiCorp Vault backed by Google Cloud KMS, which shows where keys are held as well as where data rests. Which region applies by default, and whether contract content follows the same rule as personal data, are not stated; the regional commitment is written for personal data.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Ironclad
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Certification is real and stated with correct scope language, short of accessible evidence. The vendor names SOC 1 and SOC 2 Type II reports from routine third party audits and names the trust categories certified: security, availability, confidentiality and privacy. ISO 27001, 27701, 27017 and 27018 are all named, along with Trusted Cloud Provider status from the Cloud Security Alliance. The vendor says its underlying cloud providers are themselves SOC 2, ISO 27001 and PCI DSS certified. What is not published is a route to the evidence: no audit coverage period, report date or named auditing firm, and no trust portal or published request flow for the reports.

SpotDraft
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

Four compliance marks appear on SpotDraft's home, pricing and security pages: ISO, GDPR, HIPAA and AICPA SOC 2. SpotDraft's home page lists them as ISO 27001, SOC 2 Type II, GDPR and HIPAA. The footer on every page says SpotDraft is ISO/IEC 27001:2013 certified, but 27001:2013 was replaced by the 2022 revision, so the site claims a current certification while naming a retired version. A separate trust center at trustcenter.spotdraft.com is linked. No auditor, coverage period or report date for the SOC 2, or scope, is published outside the trust center. Independent penetration testers are said to be used, but none is named and no summary is published.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Ironclad
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The vendor refers to models without identifying what sits underneath. It acknowledges two layers and distinguishes them clearly: proprietary legal AI models built by Ironclad with prompts engineered for legal work, and external LLM providers bound by terms against training and for zero data retention. That tells a buyer the shape of the chain and the terms binding it, but not who is in it. No named external model provider, statement of where models run, subprocessor list or commitment to notify customers of supply chain changes is published.

SpotDraft
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

SpotDraft publishes nothing about the AI models a customer relies on. No model provider, model or version is named. The only description is that the AI is built into SpotDraft and works in the customer's own context. There is no subprocessor list and no commitment to notify customers of changes. The security page is otherwise detailed, naming HashiCorp Vault, Google Cloud KMS, JAMF, FileVault and BitLocker among its tools.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Ironclad
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing page is published on the property, no rate is published, no unit of charge is stated and no tier structure appears. Every commercial path located terminates in a demo request. No free trial or self serve entry point is published. Consistent with third party coverage describing implementation cost as dependent on the scope of the CLM deployment rather than on a published rate.

SpotDraft
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

SpotDraft's pricing page says plans are priced either by users or by contract volume, framed as avoiding wasted spend. It also covers implementation: in house implementation is always included, covering workflow and integration setup and migration of old contracts, with no extra fees and no outsourcing. Every customer gets a dedicated customer success manager and support around the clock at no extra cost. A six week implementation timeline is published, week by week. No number appears: no rate, floor or currency, and every call to action is Get Pricing or a demo request.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Ironclad
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Segment coverage is described with substance, short of the boundaries. Four buyer personas have their own published positioning: legal operations, general counsel, procurement and IT, and the vendor also addresses business teams beyond legal that handle contracts. Enterprise and global business teams are the stated target, and at least one industry, manufacturing, has dedicated positioning around leakage and contract performance. Practice scope is clear and consistent: contracting end to end from intake to after signature, with no claim to litigation or research capability. Not located: a statement of which organization sizes or contract types the platform is not built for, and a full list of industries or practice areas.

SpotDraft
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

SpotDraft gives five buying teams dedicated pages: legal, sales, finance, HR and procurement, with legal as the owner and the others as self serve users. Five industries have their own pages: SaaS, HR tech, edtech, healthtech and fintech. Its home page names its audience as high performing in house legal teams. No law firm segment is addressed, nothing covers government or public sector use, and no contract types or matters are named as unsupported. Coverage is described by industry and internal function rather than by area of law.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Ironclad
Opt in

Training is opt in, and the vendor argues for it openly. Customers may opt into letting Ironclad train its own models on their contracting data. Any customer data used this way is anonymized and aggregated first, output generated for other customers by models trained on that data will never include the contributing customer's data, and the vendor says the customer stays in control with data kept confidential. Separately, strict terms against training and for zero data retention are enforced with external LLM providers, so the third party layer is barred while the vendor's own layer is permitted with consent.

Training happens only where the customer has enabled it. Not located as of 29 Aug 2026: where the opt in is exercised, whether it sits in the agreement or a product setting, and whether it can be withdrawn.

SpotDraft
Terms silent

Nothing on SpotDraft's home, pricing or security pages, including the security page's data security, infrastructure security, product security and risk governance sections and its five question FAQ, addresses whether customer contracts, prompts or outputs are used to train any model, by SpotDraft or by an underlying model provider. The nearest statements are that the AI is embedded in SpotDraft, operates in a context specific to the customer and follows the customer's rules, and that the platform is risk free AI on the customer's terms, none of which is a commitment about training.

No model provider is named. The trust center was not available to read, so the silence is an absence on the published pages with a retrieval limit on the trust center.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Ironclad
Disclosed without a period

Retention is answered at the external model layer and unaddressed for the platform itself. The vendor states it enforces zero data retention with external LLM providers, so prompts and completions are not persisted by those providers. Searched the security page, the platform pages, the article library and the support documentation via search on 29 Aug 2026 and located no retention period for contracts, prompts or outputs held in Ironclad's own repository, no customer control over that window, and no deletion commitment.

That gap is material here because the product is a system of record designed to hold every executed agreement indefinitely, so the retention question is the core of what the customer is buying.

SpotDraft
Not addressed

No retention period for contracts, prompts or generated outputs is published on SpotDraft's home, pricing or security pages. Retention appears only as a heading within the security page's data handling practices, where data classification and retention are named together and the text describes classification into public, company confidential, customer confidential and personal tiers without stating how long anything is kept.

Secure data disposal is listed among the data center measures without a period attached. No retention setting the customer can configure is described.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Ironclad
Own model, documented

The product maintains its own documented permission model rather than inheriting one from a document management system. Published support documentation states that administrators can configure Ironclad users and groups to permit or restrict which users may view, create and edit AI Playbooks, so the standards driving AI behavior are themselves access controlled, and the workflow layer routes and assigns contracts across named reviewers.

That is a documented internal permission model. What was not located as of 29 Aug 2026 is segregation of the contract repository itself between users or matters, any ethical wall concept, and any legal document management integration whose permissions retrieval could inherit at query time. Noted for context: the buyer here is an in house or business team rather than a firm carrying conflicts obligations, so the question reads differently than it would for a firm facing product.

SpotDraft
Own model, documented

Separation is documented at two levels. Between customers, SpotDraft's security page states that customer data is logically separated within a secure multitenant infrastructure, and adds that each contract is protected with a unique encryption key held in HashiCorp Vault backed by Google Cloud KMS, a finer control than isolation at tenant level alone. Within a customer, roles and permissions are described as fully customizable and scoped by contract type, organizational entity and department, with permissions at contract level ensuring documents are visible only to authorized personnel without manual sharing.

How retrieval and the AI features apply those permissions at query time is not published, so whether a model answering a question respects the same boundaries is not stated. The buyer is an in house department, so separation at tenant and entity level is the relevant test.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Ironclad
Not addressed

Searched the security page, the site navigation, the article library and the support documentation via search on 29 Aug 2026. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. No published customer agreement or data processing agreement was located on the property either, so the search covered the public pages rather than the contract documents.

SpotDraft
Not addressed

Nothing on SpotDraft's home, pricing or security pages addresses what happens if a third party, law enforcement agency or court requests customer data, and no commitment to notify the customer is published. No transparency report exists. The security page states that third party vendors handling scoped data are bound by confidentiality, audit and incident response protocols, and that fourth parties such as backup providers and subcontractors have no access to scoped systems or data, but neither addresses compelled disclosure.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Ironclad
Not addressed

No primary law corpus is identified because the product does not hold one. Retrieval runs against the customer's own contract repository and their own AI Playbooks, and the vendor's proprietary models are described as trained on legal terminology and contract management architecture with legal engineered prompts, plus, where customers opt in, anonymized and aggregated customer contracting data. That last element is the closest thing to a vendor corpus and its provenance is disclosed in principle, being customer contributed under consent, though no scale figure, license basis or update cadence is published for it. Searched the site, the Ironclad AI page and the article library on 29 Aug 2026.

SpotDraft
Sources named, basis unstated

The working corpus is the customer's own contract set and is identified as such: SpotDraft's repository is described as centralizing all of a customer's contracts and automatically pulling over a thousand types of contract metadata using AI, and the AI is described as operating in a context specific to the customer and following the customer's rules. No external legal corpus is claimed and the product does not retrieve primary law, so the usual jurisdiction and coverage questions do not arise. No training corpus for the models themselves is described, no source is named and no license or rights basis is given.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Ironclad
Not addressed

Searched the site, the product pages and the support documentation via search on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator license was located. Noted for context: this is a contract lifecycle platform grounded in the customer's own playbooks and repository, with no case law research surface, so a citator is outside its design entirely.

SpotDraft
Not addressed

Nothing on SpotDraft's home, pricing or security pages addresses whether legal authority is checked for later history, and no citator, treatment signal or currency check is published. The platform manages a customer's own contracts rather than retrieving case law or legislation, so a citator is not part of what it sells. Sidebar is described as helping users stay ahead of regulatory change with AI agents, which concerns the currency of regulation rather than the standing of cited authority, and no source or verification method is published for it.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Ironclad
Not addressed

Searched the site, the Ironclad AI and Jurist pages, the agent launch material and the support documentation via search on 29 Aug 2026. No published material describes what the product does when it cannot ground an answer, and no explicit no answer path or confidence signal exposed to the user was located. The Review Agent is documented as identifying missing clauses and compliance gaps, which is flagging what is absent from a contract rather than the system declining to answer, and the two were not conflated.

SpotDraft
Not addressed

No path for declining to answer is documented on SpotDraft's home, pricing or security pages, no confidence or grounding score is published, and nothing states what the product does when the customer's contract set or playbook does not cover the question put to it. Published material addresses configuration rather than uncertainty, describing AI that operates in the customer's context and follows the customer's rules.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

Ironclad
None located

No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one.

This is a statement about the public record on the date shown and not a clearance. Note that this is a contract lifecycle product with no case law research surface, so its output is very unlikely to reach a court filing as cited authority.

SpotDraft
None located

The AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, together with 2026 sanctions trackers and trade press summaries, records no court order, opinion or disciplinary record naming SpotDraft. This is a statement about the public record rather than a clearance, bounded by what that database covers.

The product manages commercial contracts for in house teams rather than producing court filings, so its output does not ordinarily reach a brief.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Ironclad
Not addressed

Searched the site, the article library, the persona pages and the community and resources sections via search on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512 and state bar guidance. The vendor publishes substantial material on AI governance, auditability and human in the loop control, which addresses how its own system is controlled rather than the professional responsibility obligations its legal buyers are bound by.

SpotDraft
Named guidance addressed

SpotDraft's home page names two ethics guidance documents from two jurisdictions. One is the California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law, dated November 2023. The other is the American Bar Association's Formal Opinion 512 on generative AI, dated July 2024. Both are given with issuer and date. SpotDraft says its AI features are designed with attention to the principles in each, for responsible and secure use across contracting workflows.

What is published is a statement of attention to principles, not a mapping of which duty each product control meets, and no other jurisdiction's guidance is addressed.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Ironclad
Savings claims only

Savings are claimed and quantified, with nothing published on the client's side. Published figures include a named customer recovering 50 percent of legal operations time, first pass redlines dropping from up to a couple of hours to minutes, and MNDA review dropping from up to a day to minutes or seconds, with framing about scaling review without adding headcount. Searched the site, the product pages, the article library and the support documentation on 29 Aug 2026.

No per matter record of work done with AI for fee purposes and no guidance on billing, fees or client disclosure was located. The buyer is an in house or business team that does not bill a client by the hour, so the question applies differently here.

SpotDraft
Savings claims only

SpotDraft's public materials are framed around speed and cost removed: two times faster closings, 65 percent lower cost, 70 percent less review time, and contracts reviewed 15 times faster with VerifAI. No record of AI assisted work for each matter intended for fee purposes, and no guidance on billing, fee or disclosure treatment, is published on the home, pricing or security pages. The contract level audit logging SpotDraft describes, which traces changes by both the creator and the counterparty and retains every version, could support such a record, but nothing presents it for that purpose.

The buyer is an in house department rather than a firm billing a client, so the question lands on internal cost, and it is not addressed.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Ironclad
Not addressed

Substantial certification material is published openly and can be reached without a sales conversation. It covers SOC 1 and SOC 2 Type II with the trust categories named, ISO 27001, 27701, 27017 and 27018, a GDPR program and Cloud Security Alliance Trusted Cloud Provider status. What a client's AI clause asks for was not located as of 29 Aug 2026. There is no subprocessor list, no statement of which model providers see customer content, no published data processing agreement, and no consent or notification pack for clients.

The vendor says its external LLM providers are bound by terms against training and for zero data retention without naming them, which describes the terms rather than disclosing the chain.

SpotDraft
On request only

No subprocessor list is published and no model provider is named on SpotDraft's home, pricing or security pages, so which third parties see contract content is not stated. No consent or notification material for clients is published. Assurances about third parties stand in for identifying them: vendors handling scoped data are said to be bound by confidentiality, audit and incident response protocols, and fourth parties such as backup providers and subcontractors are stated to have no access to scoped systems or data.

A trust center is linked at trustcenter.spotdraft.com, and a request route for security documentation appears on the security page.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Ironclad
Partial record

Some elements of a record are available, and the auditability language is specific. The vendor publishes governed and auditable AI review frameworks with human review, saying customers get transparent, auditable AI behavior they can review, override and continuously govern across teams and contract types. The workflow layer records routing, assignment and approvals for each contract. Two elements are missing. No export per document covering the model used, sources retrieved and human verification was located, and no model is named in published material, so the model used could not be stated.

This is a contracting platform rather than a litigation product, so a court order on AI disclosure is unlikely to reach its output.

SpotDraft
Partial record

SpotDraft's security page says audit logging traces user actions at contract level. It captures signing and creation events and the trail of changes by both the creator and the counterparty, and every version of a contract is kept, which covers what changed, by whom and when. No model is named, so which system produced a passage cannot be established, and nothing in the log, as described, separates an AI change from a human one. No export built for a court disclosure or AI use certification is published.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Signals neither addresses in public material
  • Third Party Request and Subpoena Notice
  • Good Law Verification
  • Refusal and Uncertainty Behavior

Which one fits

Choose Ironclad if

  • You want agents across the whole contract. Ironclad's Jurist runs Manager, Drafting, Editing, Review, Research, Intake and Redlining agents, with Conversational Search over the repository, and AI Playbooks tie each redline to a clause. Administrators set which users and groups may view, create and edit the playbooks that drive the AI.
  • Your security and privacy teams want a wide certification set. Ironclad names SOC 1 and SOC 2 Type II reports covering security, availability, confidentiality and privacy, plus ISO 27001, 27701, 27017 and 27018 and Cloud Security Alliance Trusted Cloud Provider status. It says its public cloud providers are themselves certified under SOC 2, ISO 27001 and PCI DSS.
  • You want training to be your choice. Ironclad trains its own models on customer data only where the customer opts in, anonymizes and aggregates that data first, and holds its external model providers to no training and zero data retention. Output generated for other customers never includes the contributing customer's data.

Choose SpotDraft if

  • Your data has to stay in a named region. SpotDraft stores personal data in the customer's selected region across the US, the EU, India and the Middle East, runs on Google Cloud in the Netherlands, and gives each contract its own encryption key.
  • Your general counsel wants the ethics guidance named. SpotDraft says its AI features follow the California State Bar's November 2023 guidance on generative AI and ABA Formal Opinion 512 of July 2024, and its Terms of Use state that it gives no legal advice. Ironclad names no ethics opinion or bar guidance.
  • You want implementation inside the price. SpotDraft includes workflow and integration setup and migration of old contracts at no extra fee, publishes a six week rollout plan, and prices by users or by contract volume. Ironclad publishes no pricing page or unit of charge.

In summary

Ironclad

Ironclad is an enterprise contract lifecycle management platform covering intake, contract creation, no code workflow automation, approvals, negotiation, signature, repository and analytics, sold to legal, legal operations, procurement, sales and IT teams. AI Playbooks drive redlining with each play tied to a clause, and Jurist runs named agents for drafting, editing, review, research, intake and redlining. According to the AI Legal Index, Ironclad sets out its training terms: its own models train on customer data only where the customer opts in, after anonymization and aggregation, and external model providers are bound against training and to zero data retention. It publishes no customer agreement, subprocessor list or price.

Source: AI Legal Index, 2026

SpotDraft

SpotDraft is a contract lifecycle platform for in house legal teams, covering creation from templates, conditional approval workflows, negotiation and redlining in Word, Slack or the browser, and built in eSignature. Its repository extracts more than a thousand metadata types, VerifAI reviews contracts in Word, and Sidebar agents answer questions and track regulatory change. According to the AI Legal Index, SpotDraft's clearest published positions are on residency and professional guidance: personal data stays in a customer selected region across the US, the EU, India and the Middle East, each contract has its own encryption key, and its AI features cite the California State Bar's guidance and ABA Formal Opinion 512. It names no model provider and publishes no training position or price.

Source: AI Legal Index, 2026

Questions buyers ask

Ironclad vs SpotDraft: which CLM is better for an in house legal team?

Ironclad suits a larger team that wants workflow depth, agents across drafting, review and intake, and deep Salesforce and Coupa integrations. SpotDraft suits a mid market legal team that wants implementation included, data held in a region it chooses and named ethics guidance. Neither publishes a price. Ironclad sets out its certifications and training terms in detail, and SpotDraft sets out its residency and encryption arrangements. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Do Ironclad and SpotDraft train AI on customer contracts?

Ironclad trains its own models on customer data only where the customer opts in, after anonymizing and aggregating it, and says output generated for other customers never includes the contributing customer's data. Training data is covered by the same security standards as the rest of its platform, and external model providers are bound against training and to zero data retention. SpotDraft publishes no position on training. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Where do Ironclad and SpotDraft store data?

Ironclad says it uses multiple data center regions from public cloud providers to meet residency needs, without naming the providers or regions. SpotDraft runs on Google Cloud in the Netherlands and keeps personal data in a region the customer chooses across the US, the EU, India and the Middle East, with each contract's encryption key held in HashiCorp Vault backed by Google Cloud KMS. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

What certifications do Ironclad and SpotDraft publish?

Ironclad names SOC 1 and SOC 2 Type II reports covering security, availability, confidentiality and privacy, ISO 27001, 27701, 27017 and 27018, a GDPR program and Cloud Security Alliance Trusted Cloud Provider status, with ISO 27701 covering privacy information management. SpotDraft lists ISO 27001, SOC 2 Type II, GDPR and HIPAA and links a trust center, and its site footer names the 2013 revision of ISO 27001. Neither names an auditor on its public pages. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

What do Ironclad and SpotDraft both leave unpublished?

Neither publishes a price, an accuracy measure for its AI, a named model provider, a subprocessor list, or anything on legal privilege and work product. Ironclad publishes no customer agreement, and SpotDraft's published terms cover its signup path, so neither publishes the agreement an enterprise customer signs. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Disclosure

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything on it comes from public material on the dates shown. How the index grades.

Ironclad publishes no customer agreement, so its liability terms, indemnities and data processing commitments cannot be read before a sales conversation, and it names no external model provider or subprocessor. SpotDraft's published Terms of Use, version 2.3 of 21 February 2024, cap liability at one hundred Indian rupees and contemplate further terms for other services. Neither vendor reviewed this page.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
October 8, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746