Juro vs SpotDraft: how they compare in 2026
Juro and SpotDraft are two midmarket contract lifecycle platforms sold to the same in house team, and the grid separates them by disclosure rather than by function. Juro sits in the top two bands on twelve of fifteen axes, SpotDraft on eight. Juro publishes the paperwork and the model layer: master services agreements for United States and non United States customers, standalone AI terms carrying a version history, a data processing agreement and an EU Data Act addendum, all dated and downloadable, alongside a plain statement that its AI runs on OpenAI's GPT model provided by Microsoft on Azure servers. SpotDraft answers on where the data lives and on professional guidance. It states logical separation within a multi tenant infrastructure, personal data held in a customer selected region across the United States, the European Union, India and the Middle East and not transmitted outside it, servers on Google Cloud in the Netherlands, and per contract encryption keys, and it is the only record in the index naming two ethics guidance documents.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of a core capability on a platform that would function without them. Juro is a full contract lifecycle system first: create from templates, route for approval, negotiate, sign with a native electronic signature built to meet advanced electronic signature requirements, store, and track. Strip out AI Review, AI Extract, AI Assistant and Operator and a working CLM with eSignature and workflow remains, which is a product with its own market. The vendor positions the AI as the differentiator against that baseline, arguing that unlike legacy CLMs its platform does the work rather than accelerating it, and Operator is genuinely model-driven. But the founding product dates from 2016 and the AI features were added on top, which is the B band rather than the A.
The models power several core capabilities on a platform that would function without them. SpotDraft is a full contract lifecycle system first: templates, conditional workflows and approvals, a collaborative editor, native eSignature meeting ESIGN, eIDAS and ECA, a repository, reporting and analytics. Strip out SpotDraft AI, VerifAI, Intake and Sidebar and a working CLM with signature and workflow remains, which is a product with its own market. The AI is substantial rather than decorative, covering review inside Word, automatic extraction of more than a thousand metadata types, and agents for regulatory change tracking, and the vendor now brands itself context-aware AI-native CLM. But the platform predates that framing and the B band describes it: the machine learning is the engine of a core capability layered on a workflow system.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Unusually candid about fallibility and entirely unmeasured. The candour is real and it is contractual: clause 3.1 of the published AI terms states that AI Features make mistakes and may produce output that does not accurately reflect real people, places, facts or laws including legal authorities, and the responsible AI page states plainly that generative AI is predictive by nature and can never be 100 per cent accurate. Very few vendors write that into an agreement. Grounding is asserted at the product level, with Operator described as citing its sources when answering questions about the repository. What does not exist anywhere on the pages read on 31 Aug 2026 is measurement: no accuracy figure, no error or hallucination rate, no test set, no benchmark and no published evaluation. The retrieval method behind Operator's citations is not described, and the accuracy mechanisms the vendor does document are input-side aids, the AI playbook for setting context and constraints and prompt shortcuts, rather than measured output quality.
Nothing published on accuracy or grounding for a product that reviews and drafts contracts. Searched the home page, the pricing page and the security page in full on 31 Aug 2026. No accuracy figure, no error or hallucination rate, no benchmark, no test set, no published evaluation, and no description of how AI output is grounded in the customer's own documents or of whether the reader can trace an assertion back to a source. The figures the vendor does publish measure speed and cost: contracts reviewed 15 times faster with VerifAI, two times faster closings, 65 per cent lower cost and 70 per cent less review time. The nearest thing to an accuracy statement is the claim that the AI operates in the customer's company-specific context and follows the customer's rules, which describes configuration rather than correctness. The SpotDraft AI and VerifAI product pages were not opened, so this grade is rebuttable if either publishes a measured figure.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The oversight commitment is contractual rather than aspirational, which is rare on this axis. Clause 3.1 of the AI terms requires the customer to use human review to identify and correct errors in AI output before using or relying on it for any purpose, and clause 2(e) prohibits misrepresenting AI output as human-generated. The responsible AI page frames the tool as a highly capable trainee lawyer whose output should be checked, and advises using AI features only for tasks the user could complete and verify unaided. Real review surfaces exist in the product rather than being asserted: approval routing is a core module, and the AI playbook lets a customer set context and constraints for AI tasks at template or document level. What is missing is the rest of the control structure. Nothing published states what the agents run unattended in the AI intake and review flow, at what threshold the system stops and escalates, or what happens after an output is wrong.
Oversight is real at the workflow layer and undescribed at the model layer. The product publishes a genuine human control structure for contracting: conditional approval routing with thresholds shown explicitly, including an illustration of approvals escalating to the Head of Finance below a deal value and to the CFO and CEO above it, contract-level audit logs tracing changes by both the customer and the counterparty, version history for every draft, and role-based permissions scoped by contract type, entity and department. What is absent is any statement about the AI itself: nothing published says what SpotDraft AI, VerifAI or the Sidebar agents do unattended, at what point a human must review model output, what the agents can change without approval, or what happens after an output is wrong. The framing that the AI follows the customer's rules implies constraint without describing one. Checked 31 Aug 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
The deepest customer evidence read in this pull, and still short of the A band on two limbs. Named individuals with named roles, employers and locations each carry a figure: Jessica Zwaan, COO at Talentful, an 86 per cent reduction in time to sign; Victoria Sorving, Chief Legal Officer at Funnel, an 88 per cent reduction in manual contract reviews and 8,000 manual touchpoints removed; Paul Harker, Global Head of Legal at Luno, a 91 per cent time saving per contract; Clio Anderson Garwood, Senior Legal Counsel at Paddle, three and a half hours saved per contract; Pareen Kohlhaas, COO at COOP Careers, five times faster contracting; Chris McFalls at Goldin, 20,000 contracts a year; and Chantelle Zemba, General Counsel at Deliveroo, eight years as a customer. The pricing page adds further figures against named customers including 8,000 dollars saved a year at Tibber and 48 hours a month at Eucalyptus. Missing for an A: no deployment dates and no method behind any figure. Two link errors were noted on 31 Aug 2026, with the Funnel quote linking to a case study for RVU and the ANC quote linking to one for Iptor, and the individual case study pages were not opened.
A deep roster of named in-house lawyers, with the figures kept separate from them. Named individuals with roles and employers include Anna Claveria Brannan, Deputy General Counsel at IPSY; Susan Koenig, formerly Senior Legal Operations Manager at Abnormal Security; Micah Nessan, formerly General Counsel at Guideline; Reason Abajuo, VP of Legal and Corporate Affairs at Chaberton Energy; Lizzy Gagan, Senior Legal Counsel at Beamery; Arzu Hasanova, Legal Counsel at Circularise; Aditi Kapoor, Director of Legal at Gameskraft; and Natasha Wilson, Head of Legal at SUN Mobility. Every quote is qualitative. The quantified claims carry no customer at all: two times faster closings, 65 per cent lower cost, 70 per cent less review time, and contracts reviewed 15 times faster. Two things a reader should weigh: two of the referees are identified as former employees of the companies named, and the case study pages were not opened on 31 Aug 2026, so dates and method remain rebuttable.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive commitments in the agreement rather than on a marketing page, short of segregation and privilege. Clause 1.2 of the published AI terms prohibits Juro from using customer data as training data for any AI model except a customer-specific model used only to serve that customer, and requires any such model to be erased within 60 days of termination. Clause 1.1 assigns the customer all right title and interest in AI output and treats it as customer data. The model provider is named openly as OpenAI's GPT model provided by Microsoft on Azure servers, and the responsible AI page states that strict confidentiality obligations are in place with both the customer and the technology providers. A data processing agreement and a subprocessor list are published without a gate. Two gaps hold this at B. Nothing published documents how one customer's repository is separated from another's, or how access is enforced between teams inside a customer where sales, HR and procurement all self-serve. And privilege and work product are not addressed directly; the nearest material is a general acknowledgement on the responsible AI page that regulated professionals have confidentiality obligations.
Strong data handling, and silence on the question this axis turns on. The security page is specific about protection: customer data logically separated within a multi-tenant infrastructure, per-contract unique encryption keys held in HashiCorp Vault backed by Google Cloud KMS, AES-256 at rest, FIPS-140-certified encryption, data classified into public, company confidential, customer confidential and personal, least privilege access with unique IDs, and confidentiality, audit and incident response protocols enforced on third-party vendors handling scoped data. What is missing is the training position. Searched the home page, the pricing page and the security page in full on 31 Aug 2026 and located no statement of whether customer contracts are used to train any model, by SpotDraft or by any model provider, and no retention period for prompts or outputs. Privilege and work product are not addressed either. The trust centre and the published terms of service were not opened, so this is rebuttable on either.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Real material on output reliability, nothing on the advice line, and an audience that makes the gap matter. The published AI terms require human review before reliance and prohibit passing AI output off as human-generated, and the responsible AI page acknowledges that regulated professionals need confidence that AI use will not compromise their confidentiality obligations. But searched the home page, the trust centre index, the responsible AI page, the pricing page and the terms index on 31 Aug 2026 and located no statement that Juro is not a law firm and does not provide legal advice, no ethics or professional responsibility page, no named bar or ethics guidance including ABA Formal Opinion 512, and no jurisdiction limits. The exposure is higher here than for a lawyer-only tool because the product is explicitly sold on the basis that colleagues in sales, HR, procurement and finance self-serve on contracts without legal involvement, and the pricing FAQ says so directly.
A published position that names guidance from two jurisdictions, which nothing else in this pull does. The home page states that SpotDraft's AI features are designed with attention to the principles in the California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law of November 2023 and the American Bar Association's Formal Opinion 512 on generative AI of July 2024. Both are named with their issuing body and date rather than gestured at, and the statement sits on the home page rather than buried in a policy. Two things hold it at B. No statement was located that SpotDraft does not provide legal advice, and nothing addresses a lawyer's own competence and supervision duties or any jurisdiction limit on use. And the claim is one of attention to principles rather than a mapping of product behaviour to specific obligations, so a buyer cannot see which principle is met by which control. Checked 31 Aug 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A published governance framework with real substance, short of a named owner and any testing results. The responsible AI page, dated 15 January 2026, defines responsible AI as designing systems that align with human values and prevent harm, then names the three harm categories the vendor considers most pertinent to contracting, privacy, confidentiality and accuracy, and sets out what it does about each. The mechanisms are auditable rather than rhetorical: a data protection impact assessment template offered pre-populated with information about the AI Assistant, two published data protection guides covering AI Assistant and AI Extract, an EU AI Act guide in the trust centre written for customers, and the AI playbook as the documented control on context and constraints. What is absent is the bias half of this axis, and the vendor says so itself, listing bias and intellectual property ownership as other challenges it considers less pertinent and does not address. No individual or role is named as accountable for model behaviour and no pre-release testing regime or evaluation result is published.
A governance apparatus exists and is documented, but it governs the company rather than the models. The security page publishes real structure: a formalised risk governance policy approved by management defining an Enterprise Risk Management programme, periodic operational risk assessments compiled into management reports with risks rated, assigned to an owner and tracked to treatment or acceptance, regular privacy risk assessments run through vendor due diligence, and an information security team led by the Chief Technology Officer overseeing the process. That is a named accountable executive and a working risk mechanism, which is more than most of this pull publishes. None of it addresses model behaviour. Searched the home page, the pricing page and the security page on 31 Aug 2026 and located nothing on what is tested before an AI release ships, no responsible AI framework, and nothing whatsoever on bias or uneven output across contract types, counterparties or populations.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy across most of this ground. A subprocessor list is published openly at the trust centre and names entities rather than categories: Algolia, AWS and MongoDB for infrastructure, Google Analytics, Heap, Mixpanel, Metabase and Hotjar for analytics, HubSpot, Intercom, Sendgrid and Sumo for communications, Stripe for payments, and Salesforce, Slack and Google as customer-initiated integrations. A data processing agreement is published as a dated downloadable document. The trust centre carries dedicated articles on application security, network and infrastructure security, and application resilience, alongside a public status page and a stated 99.9 per cent platform uptime. Access, portability and erasure rights are set out in plain language. Two gaps, checked 31 Aug 2026. No retention period for contracts, prompts or outputs was located; the only period published anywhere is the 60 days within which a customer-specific model must be erased after termination. And no incident or breach notification practice was located on the pages read, though the application security and infrastructure articles were not opened and may carry it.
Detailed, specific and current, missing a named subprocessor list. The security page carries a last-updated date of 17 October 2025 and publishes: FIPS-140-certified encryption, AES-256 at rest, per-contract unique keys in HashiCorp Vault backed by Google Cloud KMS, primary and backup servers on Google Cloud Platform in the Netherlands, data classification across four sensitivity tiers, least privilege access with unique IDs and enforced password policies, a documented business continuity and disaster recovery programme, automated patch management, continuous CVE tracking for third-party packages, regular threat modelling, independent penetration testers, and routine static analysis and vulnerability scanning. A predefined security incident response process is stated and described as refined through regular exercises. Two gaps checked 31 Aug 2026: no subprocessor is named anywhere, though the page states that fourth parties such as backup providers and subcontractors have no access to scoped systems or data, and no retention period for customer content is published.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A real published position, and the AI-specific part of it is unusually explicit. Juro publishes its Master Services Agreements for US and non-US customers as dated downloadable documents, alongside separate AI terms carrying a last-updated date of 11 March 2025 and a link to the superseded February 2025 version, so a buyer can read the allocation of loss and its history before entering a sales process. Clause 3.2 of the AI terms then does something few vendors do in either direction: it states expressly that any indemnity Juro provides under the MSA relating to non-infringement of intellectual property or other third party rights does not apply to AI output. So there is an indemnity, and the buyer is told plainly that it stops at the AI. Paired with clause 3.1, which puts the duty to identify and correct errors on the customer, the position on wrong output is clear and it is adverse to the buyer. What could not be verified on 31 Aug 2026 is the rest: the Master Services Agreement was not opened, so the liability cap, any warranty and any insurance position were not read, and this grade is rebuttable in either direction on that document.
Written 31 Aug 2026 as an R7 amendment; left unwritten in the original build because the agreement had not been opened and this axis has no substitute surface. Surface read 31 Aug 2026: the SpotDraft Terms of Use on the vendor's own Legal Hub at legal.spotdraft.com, version 2.3, last updated 21 February 2024, read in full, with five prior versions listed and downloadable from the same page. Liability is addressed only through limitation and disclaimer, which is what fixes the grade. Clause 8.3 caps SpotDraft's total cumulative liability, in contract or tort, at one hundred Indian rupees, a figure worth roughly one United States dollar. Clause 8.2 excludes consequential, indirect and special damages including loss of data and profits. Clauses 5.2 and 5.3 disclaim any warranty of fitness, of error-free or uninterrupted use, and expressly waive the warranty of non-infringement. Clause 9 is an indemnity running only from the customer to SpotDraft; no vendor indemnity to the customer was located anywhere in the document. Clause 5.5 disclaims any liability for consequences arising from use of the Platform, and 5.4 states that SpotDraft gives no legal advice. Governing law is India with exclusive jurisdiction in the courts at Bangalore, and the contracting entity is Draftspotting Technologies Private Limited together with affiliates including Draftspotting Inc. One scope point a buyer should weigh: this is the published Terms of Use reached from the signup path, and clause 11.8 contemplates additional terms when other services are purchased, so an enterprise subscriber may well contract on a negotiated master agreement that is not published. The index grades what is published and readable before signing, and what is published is this.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations, individually documented, into the systems an in-house team actually works in. Each has its own page: Salesforce, HubSpot, Slack, Microsoft Word, Docusign, Google Drive, Zapier and a REST API, plus MCP connections to Claude and ChatGPT, with Pipedrive, Greenhouse, Workday, SharePoint and Companies House named elsewhere. An integrations index exists. The pricing FAQ adds something implementer-useful and commercially candid, distinguishing out-of-the-box integrations available on all plans, naming Slack, Google Drive and Companies House, from deeper integrations that cost extra, naming Salesforce, HubSpot and Workday. What is missing for an A is depth: the individual integration pages were not opened on 31 Aug 2026, so what each connection actually moves, in which direction, and what a customer must configure was not verified. No document management integration such as iManage or NetDocuments appears, which is consistent with an in-house rather than law firm product.
Real integrations, individually documented, into the systems an in-house team works in. The vendor states more than 30 integrations and gives each its own page, with Salesforce, HubSpot, Slack, Microsoft Word for desktop, Google Drive, DocuSign, Greenhouse, Google Forms, Jira and Zapier all linked directly from the pricing page. The Word integration is treated as a first-class surface rather than an afterthought: VerifAI runs review inside Microsoft Word, negotiation and redlining are described as working in Word, Slack or SpotDraft itself, and one named customer specifically credits the Word desktop editor with driving adoption. Single sign-on covers Office 365, Google Workspace, Okta, Active Directory and custom SAML with zero-touch provisioning. What was not established on 31 Aug 2026 is depth: the integrations index and the individual integration pages were not opened, so what each connection moves and in which direction was not verified. No document management integration such as iManage or NetDocuments appears, consistent with an in-house rather than law firm product.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery is implied and neither the tenancy model nor the region is stated on any surface read. AWS appears on the published subprocessor list as infrastructure, and the AI processing location is stated on the responsible AI page as Microsoft Azure servers, which is a real statement about where inference happens. Beyond that, searched the home page, the trust centre index, the responsible AI page, the pricing page and the terms index on 31 Aug 2026 and located no statement of whether the platform is multi-tenant or single-tenant, no region options, no data residency commitment, and no private or on-premises deployment option. Two trust centre articles not opened, on network and infrastructure security and on the GDPR, are the likely home for a residency statement, so this grade is rebuttable on either. The gap is more visible than usual because the vendor states it serves customers in more than 85 countries and publishes an EU Data Act addendum.
Both halves of this axis are answered, which almost nothing in this pull manages. The tenancy model is stated plainly rather than implied: customer data is logically separated within a secure multi-tenant infrastructure, so a buyer knows it is shared and knows what separates it. Residency is stated as a customer choice with an explicit boundary commitment: personal data is stored within selected regions covering the US, EU, India and the Middle East, and is not transmitted outside those locations. Where the data physically sits is named to the country, with primary and backup servers on Google Cloud Platform in the Netherlands. The processing layer is identified as Google Cloud Platform throughout, and encryption keys are held per contract in HashiCorp Vault backed by Google Cloud KMS, which tells a buyer where key custody sits as distinct from where data rests. What would sharpen it further is a statement of which region applies by default and whether contract content follows the same rule as personal data, since the regional commitment is written in terms of personal data specifically.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The trust centre is genuinely open, which is rarer than it sounds, and the attestation behind it is not evidenced. Juro publishes a trust centre with ten substantive articles readable without a form, an email address or an NDA, covering the UK GDPR, the GDPR, the CCPA, the EU AI Act, the EU Data Act, advanced electronic signatures, application security, network and infrastructure security, application resilience and responsible AI use, filterable by compliance, security and privacy. That is a materially better access route than the gated portals elsewhere in this cohort. SOC 2 Type 2 certification is stated repeatedly, with a badge in the site footer and a dedicated trust centre article described as covering the SOC 2 Type II attestation, and a public status page and a 99.9 per cent uptime figure sit alongside it. What was not located on 31 Aug 2026 is the substance an attestation is judged on: no auditor is named, no coverage period or report date is given, no scope is described, no route to obtain the report is stated, and no penetration test summary or testing partner appears. The infrastructure article was not opened and may name the auditor.
Marks are displayed, a trust centre exists, and the property contradicts itself on the standard actually held. Four compliance marks appear as icons on the home page, the pricing page and the security page: ISO, GDPR, HIPAA and AICPA SOC 2, with the home page listing them as ISO 27001, SOC 2 Type II, GDPR and HIPAA. The footer of every page then reads that SpotDraft is an ISO/IEC 27001:2013 certified company, and 27001:2013 was superseded by the 2022 revision, so the site simultaneously claims a current certification and names a retired version of it. A separate trust centre is linked at trustcenter.spotdraft.com and is credited here as a genuine access route, though it was not opened on 31 Aug 2026. What could not be established from any page read: no auditor is named, no coverage period or report date is given for the SOC 2, no scope is described, and while independent penetration testers are said to be engaged, no partner is named and no summary is published.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The supply chain is named to a level most of this market does not reach, without a change commitment. The responsible AI page states that Juro's AI tools are built using OpenAI's GPT model, provided by Microsoft on Azure servers, which identifies the model family, the provider, the delivery route and where inference runs in a single sentence, and the vendor ties the arrangement to how it protects confidentiality. Three gaps, checked 31 Aug 2026. No specific model version is named, and the illustrative discussion on that page refers to GPT-4, which may or may not be what the product runs today. Nothing commits Juro to notifying customers when the provider or model changes. And there is an internal inconsistency worth a buyer's attention: neither OpenAI nor Microsoft appears on the published subprocessor list at the trust centre, which names Algolia, AWS and MongoDB as infrastructure and does not mention the model provider that processes contract content.
Nothing published about the model supply chain a customer inherits. Searched the home page, the pricing page and the security page in full on 31 Aug 2026. No model provider is named, no model or version is identified, no architecture is described beyond the statement that the AI is embedded in SpotDraft and operates in the customer's company-specific context, no subprocessor list exists, and nothing commits the vendor to notifying customers when any of it changes. The security page is otherwise unusually granular, naming HashiCorp Vault, Google Cloud KMS, JAMF, FileVault and BitLocker among its tooling, which makes the absence of any model provider conspicuous rather than incidental. The SpotDraft AI and VerifAI product pages and the trust centre were not opened, so this is rebuttable if any of them names a provider.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The unit and the structure are published without the figure, which is the B band exactly and more than most of this cohort offers. The pricing page states the charging model directly: all plans include unlimited users, unlimited workflows and unlimited templates, and price is driven by monthly contract volume and by the complexity of integrations. The volume bands a buyer is placed into are published, running from fewer than 20 contracts a month through to more than 1,000. Which integrations carry extra cost is named, with Slack, Google Drive and Companies House included and Salesforce, HubSpot and Workday charged. Billing currencies are stated as USD, GBP or EUR, non-profit discounts are offered, and a 20 per cent first-year discount for signing in the month of the demo is published. No figure is reachable: the on-page calculator collects volume, contract types, AI features and integrations and then requires name and email, and the approximate price field rendered as 0 USD when read on 31 Aug 2026. Nothing states what implementation adds.
The unit and structure are published without the figure, and one thing is answered that no other vendor in this pull answers. The pricing page states the charging model directly: plans are priced on either users or contract volume, with the vendor framing the choice as avoiding wasted spend. It then addresses implementation explicitly, which is the third limb of this axis and is normally silent everywhere: in-house implementation is always included, covering workflow and integration setup and migration of legacy contracts, with no extra fees and no outsourcing, and every customer receives a dedicated customer success manager and 24 hours a day support at no additional cost. An implementation timeline is published as a week one to week six sequence. What is absent is any number: no rate, no band, no floor and no currency appears anywhere, and every call to action on the page is Get Pricing or a demo request. Checked 31 Aug 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described with substance on the axis the vendor sells, and the boundaries are left open. Dedicated pages exist for five buying teams, legal, HR, procurement, sales and finance, with legal positioned as the function that controls templates and workflows while the others self-serve within them. Contract types are named concretely on the pricing calculator: NDAs, employment contracts, MSAs, SOWs, order forms, M&A documents and vendor agreements. The vendor states it serves customers in more than 85 countries and gives a usage floor rather than leaving fit vague, saying businesses signing around ten or more contracts a month will see a return. What is absent is the far edge. No law firm segment is addressed, which follows from this being an in-house product but is never stated. Nothing addresses government or court use. And the industry navigation is published but non-functional, with B2B SaaS, food delivery, auto marketplace and travel marketplace all resolving to empty anchors when checked on 31 Aug 2026.
Segment coverage is described with substance on two axes and the boundaries are left open. Five buying teams carry dedicated pages, legal, sales, finance, HR and procurement, with legal positioned as the owner and the others as self-serve participants. Five industries carry their own pages: SaaS, HR tech, edtech, healthtech and fintech, which is a narrower and more honest vertical set than the everything-for-everyone lists common in this category. The home page states the audience directly as high-performing in-house legal teams. What is absent is the far edge. No law firm segment is addressed, nothing covers government or public sector use, no contract types or matters are named as unsupported, and the practice dimension is expressed as industry and internal function rather than as areas of law. Checked 31 Aug 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The prohibition sits in the agreement rather than on a policy page. Clause 1.2 of Juro's published AI terms, last updated 11 March 2025, states that Juro may not use customer data as training data for any AI model, with a single carve-out for a customer-specific model used only to provide services to that same customer, and requires any customer-specific model to be erased within 60 days of termination for any reason. The carve-out is confined to the customer's own benefit, so no other customer's model is trained on their data. The responsible AI page states the position more absolutely, that Juro does not use customer data to train foundational models and does not use contract data to train any model, which is slightly wider than the contract itself allows.
Searched the home page, the pricing page and the security page in full on 31 Aug 2026, including the security page's data security, infrastructure security, product security and risk governance sections and its five-question FAQ. No located material addresses whether customer contracts, prompts or outputs are used to train any model, either by SpotDraft or by an underlying model provider. The nearest statements are that the AI is embedded in SpotDraft, operates in the customer's company-specific context and follows the customer's rules, and that the platform is risk free AI on the customer's terms, none of which is a commitment about training. No model provider is named anywhere either. The trust centre and the published terms of service were not opened, so this value is rebuttable on either document.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is acknowledged without a period for contracts, prompts or outputs. The only period published anywhere is in clause 1.2 of the AI terms, which requires erasure of any customer-specific model within 60 days of termination, and that governs a derived model rather than the underlying content. The trust centre privacy summary confirms that data from contracts is collected and that customers can port their data or be forgotten, which acknowledges retention and gives a deletion route without stating a window or a customer-configurable setting. Searched the home page, the trust centre index, the responsible AI page, the pricing page and the terms index on 31 Aug 2026; the published data processing agreement was not opened and may state a period.
Searched the home page, the pricing page and the security page on 31 Aug 2026. No retention period for contracts, prompts or generated outputs is published. Retention appears only as a heading within the security page's data handling practices, where data classification and retention are named together and the text describes classification into public, company confidential, customer confidential and personal tiers without stating how long anything is kept. Secure data disposal is listed among the data centre measures without a period attached. No customer-configurable retention setting is described.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Searched the home page, the trust centre index, the responsible AI page, the AI terms, the pricing page and the terms index on 31 Aug 2026. No public material addresses how one customer's repository is separated from another's, and none addresses access boundaries inside a customer, which matters here because the product is sold on the basis that sales, HR, procurement and finance colleagues self-serve alongside legal in the same workspace. The nearest published material is contractual rather than architectural: clause 1.2 of the AI terms prevents customer data training a model that serves anyone else, and clause 1.3 states that output generated for other users is not the customer's data. Neither describes how retrieval or permissions are enforced. The buyer is an in-house department, so tenant-level separation rather than matter-level walls is the relevant test.
Separation is documented at two levels rather than asserted. Between customers, the security page states that customer data is logically separated within a secure multi-tenant infrastructure, and adds that each contract is protected with a unique encryption key held in HashiCorp Vault backed by Google Cloud KMS, which is a finer-grained control than tenant-level isolation alone. Within a customer, roles and permissions are described as fully customisable and scoped by contract type, organisational entity and department, with contract-level permissions ensuring documents are visible only to authorised personnel without manual sharing. What is not published is how retrieval and the AI features apply those permissions at query time, so whether a model answering a question respects the same boundaries is unstated. The buyer is an in-house department, so tenant and entity level separation is the relevant test.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Written 31 Aug 2026 as an R7 amendment, on the Juro Data Processing Agreement last updated 7 March 2025, read in full; the original pass had not opened it. The commitment sits at Appendix 3, paragraph 4.4(k), given for the purposes of clause 15(1)(a) of the Standard Contractual Clauses, and it obliges Juro to notify the customer of government access requests while leaving notification of data subjects to the customer. A buyer should note its reach. Appendix 3 applies only where the corresponding law applies, so this operates through the European route where the SCCs are engaged on a restricted transfer, and no equivalent government-access notice clause was located in the CCPA appendix or in the general terms for a customer outside that route. Separately, paragraph 11.2 provides that a third party purporting to be a controller of customer personal data will be directed to the customer, and paragraph 8.2(a) routes data subject requests the same way. No transparency report or count of requests received was located on the DPA, the terms index or the trust centre, which is what keeps this below the top value.
Searched the home page, the pricing page and the security page on 31 Aug 2026. No located material addresses what happens if a third party, law enforcement agency or court requests customer data from SpotDraft, and no commitment to notify the customer was found. No transparency report exists. The security page does state that third-party vendors handling scoped data are bound by confidentiality, audit and incident response protocols, and that fourth parties such as backup providers and subcontractors have no access to scoped systems or data, but neither addresses compelled disclosure. The published privacy policy and terms of service, which are the usual home for this provision, were not opened.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The corpus behind the product's answers is the customer's own contract repository, which is identified plainly: Operator is described as understanding the customer's documents and citing its sources, and AI Extract pulls data points from the customer's executed contracts. The underlying foundation model is separately identified as OpenAI's GPT model provided by Microsoft on Azure. Juro does not retrieve primary law, so questions of case law and statutory coverage do not arise in the usual form. No licence or rights basis is stated for the foundation model's own training corpus beyond a general description, and no update cadence is published for anything.
The working corpus is the customer's own contract set and is identified as such: the repository is described as centralising all of a customer's contracts and automatically pulling over a thousand types of contract metadata using AI, and the AI is described as operating in the customer's company-specific context and following the customer's rules. No external legal corpus is claimed and the product does not retrieve primary law, so the usual jurisdiction and coverage questions do not arise. What is not stated is the provenance of anything underneath: no training corpus for the models themselves is described, no source is named and no licence or rights basis is given.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Searched the home page, the trust centre index, the responsible AI page, the AI terms and the pricing page on 31 Aug 2026. Nothing addresses whether legal authority is checked for subsequent history, and no citator, treatment signal or currency check was located. The product manages a customer's contracts rather than retrieving primary law, so a citator is not part of what it sells. Worth recording alongside that: clause 3.1 of the AI terms acknowledges that output may fail to reflect laws accurately, including legal authorities, which is an unusual admission from a product that does not hold itself out as a research tool.
Searched the home page, the pricing page and the security page on 31 Aug 2026. Nothing addresses whether legal authority is checked for subsequent history, and no citator, treatment signal or currency check was located. The platform manages a customer's own contracts rather than retrieving case law or legislation, so a citator is not part of what it sells. One product does touch adjacent ground: Sidebar is described as helping users stay ahead of regulatory change with AI agents, which concerns the currency of regulation rather than the standing of cited authority, and no source or verification method is published for it.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Searched the home page, the responsible AI page, the AI terms, the trust centre index and the pricing page on 31 Aug 2026. No explicit no-answer or abstention path is documented and no confidence or grounding score was located. What Juro does publish is an acknowledgement of fallibility rather than a description of behaviour: the responsible AI page states that generative AI is predictive by nature and can never be 100 per cent accurate, and clause 3.1 of the AI terms states that AI features make mistakes and shifts the duty to identify and correct them onto the customer. That is candid about uncertainty and silent on what the system itself does when it cannot ground an answer.
Searched the home page, the pricing page and the security page on 31 Aug 2026. No explicit no-answer or abstention path is documented, no confidence or grounding score was located, and nothing states what the product does when the customer's contract set or playbook does not cover the question put to it. Published material addresses configuration rather than uncertainty, describing AI that operates in the customer's context and follows the customer's rules. The SpotDraft AI and VerifAI product pages were not opened, so this value is rebuttable if either documents abstention behaviour.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, searched on both the product name and the company name Juro Online Limited, alongside 2026 sanctions trackers and trade press summaries. This is a statement about the public record on the date shown rather than a clearance, and it is bounded by what that database covers. The product manages commercial contracts for in-house teams rather than producing court filings, so its output does not ordinarily reach a brief.
No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, searched on the product name alongside 2026 sanctions trackers and trade press summaries. This is a statement about the public record on the date shown rather than a clearance, and it is bounded by what that database covers. The product manages commercial contracts for in-house teams rather than producing court filings, so its output does not ordinarily reach a brief.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Public materials refer to professional responsibility in general terms without naming guidance. The responsible AI page states that regulated professionals such as lawyers need confidence that their use of AI will not compromise their professional obligations of confidentiality, and extends the same point to HR professionals protecting employee confidences, framing it as a reason not to use tools that train on customer data. That is engagement with the obligation rather than with the guidance. Searched the home page, the trust centre index and its ten articles, the responsible AI page, the AI terms and the terms index on 31 Aug 2026 and located no named ethics opinion, including ABA Formal Opinion 512, no US state bar guidance and no Solicitors Regulation Authority or Law Society material, despite the vendor being UK-founded and serving more than 85 countries.
Two named ethics guidance documents from two jurisdictions are cited on the home page: the California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law, dated November 2023, and the American Bar Association's Formal Opinion 512 on generative AI, dated July 2024. Both are given with issuing body and date, and the vendor states its AI features are designed with attention to the principles in each, ensuring responsible and secure usage throughout contracting workflows. This is the only vendor read in this pull to name more than one. It is recorded at the named-guidance value rather than higher because what is published is a statement of attention to principles, not a mapping showing which obligation is met by which product control, and no other jurisdiction's guidance is addressed.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials are built around time and headcount saved, and quantified more heavily than most: an 86 per cent reduction in time to sign, a 91 per cent time saving per contract, three and a half hours saved per contract, 8,000 dollars saved a year, 48 hours saved a month, and one full-time hire avoided, each attached to a named customer. Searched the home page, the pricing page, the trust centre, the responsible AI page and the AI terms on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee purposes and no published guidance on billing, fee or disclosure treatment. The buyer is an in-house department rather than a firm billing a client, so the question lands on internal cost and outside counsel spend rather than on the hourly bill, and nothing addresses either.
Public materials are framed around speed and cost removed: two times faster closings, 65 per cent lower cost, 70 per cent less review time, and contracts reviewed 15 times faster with VerifAI. Searched the home page, the pricing page and the security page on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee purposes and no published guidance on billing, fee or disclosure treatment. The contract-level audit logging the vendor describes, which traces changes by both the creator and the counterparty and retains every version, could support such a record, but nothing presents it for that purpose. The buyer is an in-house department rather than a firm billing a client, so the question lands on internal cost, and it is not addressed.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A subprocessor list is published openly at the trust centre and names entities rather than categories, covering Algolia, AWS and MongoDB for infrastructure, Google Analytics, Heap, Mixpanel, Metabase and Hotjar for analytics, HubSpot, Intercom, Sendgrid and Sumo for communications, Stripe for payments, and Salesforce, Slack and Google as customer-initiated integrations. Alongside it sit a published data processing agreement, an EU Data Act addendum, separate AI terms and a pre-populated data protection impact assessment template offered to customers, all reachable without an agreement in place. Two things stop this reaching the top value. The list does not include the model provider: neither OpenAI nor Microsoft appears on it, although the responsible AI page identifies them as processing contract content. And no client-facing consent or notification pack was located on 31 Aug 2026.
Searched the home page, the pricing page and the security page in full on 31 Aug 2026. No subprocessor list was located and no model provider is named anywhere, so a legal team cannot tell a client which third parties see contract content. No client-facing consent or notification material exists. What is published instead is a set of assurances about third parties rather than an identification of them: vendors handling scoped data are said to be bound by confidentiality, audit and incident response protocols, and fourth parties such as backup providers and subcontractors are stated to have no access to scoped systems or data. A trust centre is linked at trustcenter.spotdraft.com and a request route for security documentation appears on the security page, both of which are plausible homes for the missing material; neither was opened.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Searched the home page, the trust centre index, the responsible AI page, the AI terms and the pricing page on 31 Aug 2026 and located nothing addressing court disclosure, AI-use certification or the production of a verification record. The product manages commercial contracts for in-house teams rather than producing court filings, so a judicial standing order is not its usual context. Two adjacent elements exist without amounting to a record: Operator is described as citing its sources when it answers, and clause 2(e) of the AI terms prohibits misrepresenting AI output as human-generated, which is an obligation on the customer rather than a capability to evidence what the model did.
Some elements of a record exist and are described with unusual precision for this signal. The security page states that the platform has extensive audit logging allowing user actions to be traced at contract level, capturing not only signing and creation events but the trail of changes made by both the creator and the counterparty, and that every version of a contract created by a user is kept to give a clear document history. That covers what changed, by whom and when, at document level. Two elements are missing: no model is identified anywhere on the property, so which system produced a given passage cannot be established, and nothing distinguishes an AI-generated change from a human one in the log as described. No export designed for a court disclosure or AI-use certification was located on 31 Aug 2026.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- Good Law Verification
- Refusal and Uncertainty Behaviour
Which one fits
Choose Juro if
- You want the agreement in front of you before the demo. Juro publishes master services agreements for United States and non United States customers, standalone AI terms carrying a last updated date of 11 March 2025 with the superseded version still linked, a data processing agreement, an EU Data Act addendum, API terms and evaluation terms, all as dated downloadable documents, and clause 3.2 of those AI terms tells a buyer where the indemnity stops, which is at AI output.
- You need the training prohibition in a term rather than on a page. Clause 1.2 of Juro's AI terms states that Juro may not use customer data as training data for any AI model, with a single carve out for a customer specific model used only to serve that same customer, and requires any such model to be erased within 60 days of termination for any reason.
- A client asks whose model reads its contracts. Juro states openly that its AI runs on OpenAI's GPT model provided by Microsoft on Azure servers, which names the model family, the provider, the delivery route and where inference happens in one sentence, and it publishes a subprocessor list and ten trust centre articles readable with no form, email or NDA.
Choose SpotDraft if
- Your data has to stay in a named region. SpotDraft states that customer data is logically separated within a secure multi tenant infrastructure, that personal data is stored within a selected region across the United States, the European Union, India and the Middle East and is not transmitted outside those locations, and that primary and backup servers sit on Google Cloud Platform in the Netherlands with per contract encryption keys in HashiCorp Vault.
- Your risk committee wants the ethics guidance named. SpotDraft states that its AI features are designed with attention to the California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law of November 2023 and to the American Bar Association's Formal Opinion 512 of July 2024, both given with issuing body and date.
- You do not want implementation quoted separately after signature. SpotDraft states that in house implementation is always included, covering workflow and integration setup and migration of legacy contracts with no extra fees and no outsourcing, publishes a week one to week six rollout sequence, and includes a dedicated customer success manager and support at no additional cost.
In summary
Juro
Juro is an end to end contract lifecycle platform for in house teams, built so that colleagues outside legal can create and complete contracts inside templates and workflows legal controls, with AI Review for triage and redlining, AI Extract for pulling data from executed contracts, an assistant, and Operator, a conversational agent over the repository that cites its sources. The AI Legal Index grades it in the top two bands on twelve of fifteen capability axes. Its most specific published material is contractual: clause 1.2 of its AI terms bars using customer data to train any model except a customer specific one serving only that customer, erased within 60 days of termination. As of 31 August 2026 the index located no accuracy measurement, no retention period and no tenancy or region statement.
SpotDraft
SpotDraft is a contract lifecycle platform for in house legal teams covering template driven creation, conditional approval workflows, negotiation and redlining in Word, native eSignature, a repository that extracts more than a thousand metadata types, and AI through VerifAI review, Intake and the Sidebar agents. The AI Legal Index grades it in the top two bands on eight of fifteen capability axes, with an A on deployment model and data residency: customer data is logically separated within a multi tenant infrastructure, personal data is held in a customer selected region across the United States, the European Union, India and the Middle East and stated not to travel outside it, and servers run on Google Cloud in the Netherlands with per contract keys in HashiCorp Vault. As of 31 August 2026 the index located no accuracy figure, no model provider named and no training position.
Questions buyers ask
Juro vs SpotDraft: which is better for an in house legal team?
The AI Legal Index places Juro in the top two bands on twelve of fifteen capability axes and SpotDraft on eight, and the gap is disclosure rather than function. Juro publishes its agreements, its AI terms and the model layer behind the product. SpotDraft publishes where data is stored and processed, names two ethics guidance documents, and includes implementation at no extra cost. Neither publishes an accuracy measurement or a rate.
Does Juro train its AI on customer contracts?
No, and the prohibition sits in the agreement rather than on a policy page. Clause 1.2 of Juro's published AI terms states that Juro may not use customer data as training data for any AI model, carving out only a customer specific model used solely to serve that same customer, which must be erased within 60 days of termination for any reason. Its responsible AI page states the same commitment in summary form, that customer data is not used to train foundational models. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Where does SpotDraft store contract data?
SpotDraft states that personal data is stored within a region the customer selects across the United States, the European Union, India and the Middle East, and is not transmitted outside those locations. Primary and backup servers run on Google Cloud Platform in the Netherlands, encryption is AES-256 at rest with a unique key per contract held in HashiCorp Vault backed by Google Cloud KMS. The regional commitment is written in terms of personal data, and no statement was located confirming that contract content follows the same rule. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Do either name the AI models they use?
Juro does. It names OpenAI's GPT model provided by Microsoft on Azure servers, which is more than almost anything else in this market publishes, though no version is given and no commitment to notify customers of a change was located. One point a buyer should note: neither OpenAI nor Microsoft appears on Juro's published subprocessor list, which names Algolia, AWS and MongoDB as infrastructure. On the SpotDraft record the index located no model, provider or architecture at all. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What do Juro and SpotDraft both leave unpublished?
Neither publishes an accuracy measurement for contract review: no error rate, test set, benchmark or evaluation was located on either record. Neither states a retention period for contracts, prompts or generated output. Neither publishes a rate, although both publish the unit of charge and the structure around it. And neither addresses legal professional privilege or work product, which matters because both platforms hold the whole contract estate for a legal department. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Read Juro's AI terms directly, because they say plainly what most vendors leave unsaid. Clause 3.2 states that the indemnity in the master services agreement does not apply to AI output, and clause 3.1 puts the duty to identify and correct errors on the customer, so the allocation of loss for wrong output is published, dated and versioned before any sales conversation. On SpotDraft, the published Terms of Use cap total liability at one hundred Indian rupees, and the same document contemplates further terms where other services are purchased, so an enterprise buyer may sign a master agreement that is not published. Its site footer also states ISO/IEC 27001:2013, a superseded revision. Both records were verified on 31 August 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.