Juro vs SpotDraft: how they compare in 2026

Juro profileSpotDraft profile
Last verifiedSeptember 3, 2026

Juro and SpotDraft are two midmarket contract lifecycle platforms sold to the same in house team, and the grid separates them by disclosure rather than by function. Juro sits in the top two bands on twelve of fifteen axes, SpotDraft on eight. Juro publishes the paperwork and the model layer: master services agreements for United States and non United States customers, standalone AI terms carrying a version history, a data processing agreement and an EU Data Act addendum, all dated and downloadable, alongside a plain statement that its AI runs on OpenAI's GPT model provided by Microsoft on Azure servers. SpotDraft answers on where the data lives and on professional guidance. It states logical separation within a multi tenant infrastructure, personal data held in a customer selected region across the United States, the European Union, India and the Middle East and not transmitted outside it, servers on Google Cloud in the Netherlands, and per contract encryption keys, and it is the only record in the index naming two ethics guidance documents.

At a glance

Category
JuroContract Review & Drafting
SpotDraftContract Review & Drafting
Founded
Juro2016
SpotDraftNot published
Headquarters
JuroLondon, United Kingdom
SpotDraftNot published
Last verified
JuroAug 31, 2026
SpotDraftAug 31, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Juro
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models are the engine of a core capability on a platform that would function without them. Juro is a full contract lifecycle system first: create from templates, route for approval, negotiate, sign with a native electronic signature built to meet advanced electronic signature requirements, store, and track. Strip out AI Review, AI Extract, AI Assistant and Operator and a working CLM with eSignature and workflow remains, which is a product with its own market. The vendor positions the AI as the differentiator against that baseline, arguing that unlike legacy CLMs its platform does the work rather than accelerating it, and Operator is genuinely model-driven. But the founding product dates from 2016 and the AI features were added on top, which is the B band rather than the A.

SpotDraft
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models power several core capabilities on a platform that would function without them. SpotDraft is a full contract lifecycle system first: templates, conditional workflows and approvals, a collaborative editor, native eSignature meeting ESIGN, eIDAS and ECA, a repository, reporting and analytics. Strip out SpotDraft AI, VerifAI, Intake and Sidebar and a working CLM with signature and workflow remains, which is a product with its own market. The AI is substantial rather than decorative, covering review inside Word, automatic extraction of more than a thousand metadata types, and agents for regulatory change tracking, and the vendor now brands itself context-aware AI-native CLM. But the platform predates that framing and the B band describes it: the machine learning is the engine of a core capability layered on a workflow system.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Juro
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Unusually candid about fallibility and entirely unmeasured. The candour is real and it is contractual: clause 3.1 of the published AI terms states that AI Features make mistakes and may produce output that does not accurately reflect real people, places, facts or laws including legal authorities, and the responsible AI page states plainly that generative AI is predictive by nature and can never be 100 per cent accurate. Very few vendors write that into an agreement. Grounding is asserted at the product level, with Operator described as citing its sources when answering questions about the repository. What does not exist anywhere on the pages read on 31 Aug 2026 is measurement: no accuracy figure, no error or hallucination rate, no test set, no benchmark and no published evaluation. The retrieval method behind Operator's citations is not described, and the accuracy mechanisms the vendor does document are input-side aids, the AI playbook for setting context and constraints and prompt shortcuts, rather than measured output quality.

SpotDraft
DD on Citation Accuracy and Hallucination DisclosureNothing published on accuracy or grounding for a product that produces legal assertions, or a bare claim that the system does not hallucinate.

Nothing published on accuracy or grounding for a product that reviews and drafts contracts. Searched the home page, the pricing page and the security page in full on 31 Aug 2026. No accuracy figure, no error or hallucination rate, no benchmark, no test set, no published evaluation, and no description of how AI output is grounded in the customer's own documents or of whether the reader can trace an assertion back to a source. The figures the vendor does publish measure speed and cost: contracts reviewed 15 times faster with VerifAI, two times faster closings, 65 per cent lower cost and 70 per cent less review time. The nearest thing to an accuracy statement is the claim that the AI operates in the customer's company-specific context and follows the customer's rules, which describes configuration rather than correctness. The SpotDraft AI and VerifAI product pages were not opened, so this grade is rebuttable if either publishes a measured figure.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Juro
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

The oversight commitment is contractual rather than aspirational, which is rare on this axis. Clause 3.1 of the AI terms requires the customer to use human review to identify and correct errors in AI output before using or relying on it for any purpose, and clause 2(e) prohibits misrepresenting AI output as human-generated. The responsible AI page frames the tool as a highly capable trainee lawyer whose output should be checked, and advises using AI features only for tasks the user could complete and verify unaided. Real review surfaces exist in the product rather than being asserted: approval routing is a core module, and the AI playbook lets a customer set context and constraints for AI tasks at template or document level. What is missing is the rest of the control structure. Nothing published states what the agents run unattended in the AI intake and review flow, at what threshold the system stops and escalates, or what happens after an output is wrong.

SpotDraft
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Oversight is real at the workflow layer and undescribed at the model layer. The product publishes a genuine human control structure for contracting: conditional approval routing with thresholds shown explicitly, including an illustration of approvals escalating to the Head of Finance below a deal value and to the CFO and CEO above it, contract-level audit logs tracing changes by both the customer and the counterparty, version history for every draft, and role-based permissions scoped by contract type, entity and department. What is absent is any statement about the AI itself: nothing published says what SpotDraft AI, VerifAI or the Sidebar agents do unattended, at what point a human must review model output, what the agents can change without approval, or what happens after an output is wrong. The framing that the AI follows the customer's rules implies constraint without describing one. Checked 31 Aug 2026.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Juro
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

The deepest customer evidence read in this pull, and still short of the A band on two limbs. Named individuals with named roles, employers and locations each carry a figure: Jessica Zwaan, COO at Talentful, an 86 per cent reduction in time to sign; Victoria Sorving, Chief Legal Officer at Funnel, an 88 per cent reduction in manual contract reviews and 8,000 manual touchpoints removed; Paul Harker, Global Head of Legal at Luno, a 91 per cent time saving per contract; Clio Anderson Garwood, Senior Legal Counsel at Paddle, three and a half hours saved per contract; Pareen Kohlhaas, COO at COOP Careers, five times faster contracting; Chris McFalls at Goldin, 20,000 contracts a year; and Chantelle Zemba, General Counsel at Deliveroo, eight years as a customer. The pricing page adds further figures against named customers including 8,000 dollars saved a year at Tibber and 48 hours a month at Eucalyptus. Missing for an A: no deployment dates and no method behind any figure. Two link errors were noted on 31 Aug 2026, with the Funnel quote linking to a case study for RVU and the ANC quote linking to one for Iptor, and the individual case study pages were not opened.

SpotDraft
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

A deep roster of named in-house lawyers, with the figures kept separate from them. Named individuals with roles and employers include Anna Claveria Brannan, Deputy General Counsel at IPSY; Susan Koenig, formerly Senior Legal Operations Manager at Abnormal Security; Micah Nessan, formerly General Counsel at Guideline; Reason Abajuo, VP of Legal and Corporate Affairs at Chaberton Energy; Lizzy Gagan, Senior Legal Counsel at Beamery; Arzu Hasanova, Legal Counsel at Circularise; Aditi Kapoor, Director of Legal at Gameskraft; and Natasha Wilson, Head of Legal at SUN Mobility. Every quote is qualitative. The quantified claims carry no customer at all: two times faster closings, 65 per cent lower cost, 70 per cent less review time, and contracts reviewed 15 times faster. Two things a reader should weigh: two of the referees are identified as former employees of the companies named, and the case study pages were not opened on 31 Aug 2026, so dates and method remain rebuttable.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Juro
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Substantive commitments in the agreement rather than on a marketing page, short of segregation and privilege. Clause 1.2 of the published AI terms prohibits Juro from using customer data as training data for any AI model except a customer-specific model used only to serve that customer, and requires any such model to be erased within 60 days of termination. Clause 1.1 assigns the customer all right title and interest in AI output and treats it as customer data. The model provider is named openly as OpenAI's GPT model provided by Microsoft on Azure servers, and the responsible AI page states that strict confidentiality obligations are in place with both the customer and the technology providers. A data processing agreement and a subprocessor list are published without a gate. Two gaps hold this at B. Nothing published documents how one customer's repository is separated from another's, or how access is enforced between teams inside a customer where sales, HR and procurement all self-serve. And privilege and work product are not addressed directly; the nearest material is a general acknowledgement on the responsible AI page that regulated professionals have confidentiality obligations.

SpotDraft
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Strong data handling, and silence on the question this axis turns on. The security page is specific about protection: customer data logically separated within a multi-tenant infrastructure, per-contract unique encryption keys held in HashiCorp Vault backed by Google Cloud KMS, AES-256 at rest, FIPS-140-certified encryption, data classified into public, company confidential, customer confidential and personal, least privilege access with unique IDs, and confidentiality, audit and incident response protocols enforced on third-party vendors handling scoped data. What is missing is the training position. Searched the home page, the pricing page and the security page in full on 31 Aug 2026 and located no statement of whether customer contracts are used to train any model, by SpotDraft or by any model provider, and no retention period for prompts or outputs. Privilege and work product are not addressed either. The trust centre and the published terms of service were not opened, so this is rebuttable on either.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Juro
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

Real material on output reliability, nothing on the advice line, and an audience that makes the gap matter. The published AI terms require human review before reliance and prohibit passing AI output off as human-generated, and the responsible AI page acknowledges that regulated professionals need confidence that AI use will not compromise their confidentiality obligations. But searched the home page, the trust centre index, the responsible AI page, the pricing page and the terms index on 31 Aug 2026 and located no statement that Juro is not a law firm and does not provide legal advice, no ethics or professional responsibility page, no named bar or ethics guidance including ABA Formal Opinion 512, and no jurisdiction limits. The exposure is higher here than for a lawyer-only tool because the product is explicitly sold on the basis that colleagues in sales, HR, procurement and finance self-serve on contracts without legal involvement, and the pricing FAQ says so directly.

SpotDraft
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

A published position that names guidance from two jurisdictions, which nothing else in this pull does. The home page states that SpotDraft's AI features are designed with attention to the principles in the California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law of November 2023 and the American Bar Association's Formal Opinion 512 on generative AI of July 2024. Both are named with their issuing body and date rather than gestured at, and the statement sits on the home page rather than buried in a policy. Two things hold it at B. No statement was located that SpotDraft does not provide legal advice, and nothing addresses a lawyer's own competence and supervision duties or any jurisdiction limit on use. And the claim is one of attention to principles rather than a mapping of product behaviour to specific obligations, so a buyer cannot see which principle is met by which control. Checked 31 Aug 2026.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Juro
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

A published governance framework with real substance, short of a named owner and any testing results. The responsible AI page, dated 15 January 2026, defines responsible AI as designing systems that align with human values and prevent harm, then names the three harm categories the vendor considers most pertinent to contracting, privacy, confidentiality and accuracy, and sets out what it does about each. The mechanisms are auditable rather than rhetorical: a data protection impact assessment template offered pre-populated with information about the AI Assistant, two published data protection guides covering AI Assistant and AI Extract, an EU AI Act guide in the trust centre written for customers, and the AI playbook as the documented control on context and constraints. What is absent is the bias half of this axis, and the vendor says so itself, listing bias and intellectual property ownership as other challenges it considers less pertinent and does not address. No individual or role is named as accountable for model behaviour and no pre-release testing regime or evaluation result is published.

SpotDraft
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

A governance apparatus exists and is documented, but it governs the company rather than the models. The security page publishes real structure: a formalised risk governance policy approved by management defining an Enterprise Risk Management programme, periodic operational risk assessments compiled into management reports with risks rated, assigned to an owner and tracked to treatment or acceptance, regular privacy risk assessments run through vendor due diligence, and an information security team led by the Chief Technology Officer overseeing the process. That is a named accountable executive and a working risk mechanism, which is more than most of this pull publishes. None of it addresses model behaviour. Searched the home page, the pricing page and the security page on 31 Aug 2026 and located nothing on what is tested before an AI release ships, no responsible AI framework, and nothing whatsoever on bias or uneven output across contract types, counterparties or populations.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Juro
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Substantive published policy across most of this ground. A subprocessor list is published openly at the trust centre and names entities rather than categories: Algolia, AWS and MongoDB for infrastructure, Google Analytics, Heap, Mixpanel, Metabase and Hotjar for analytics, HubSpot, Intercom, Sendgrid and Sumo for communications, Stripe for payments, and Salesforce, Slack and Google as customer-initiated integrations. A data processing agreement is published as a dated downloadable document. The trust centre carries dedicated articles on application security, network and infrastructure security, and application resilience, alongside a public status page and a stated 99.9 per cent platform uptime. Access, portability and erasure rights are set out in plain language. Two gaps, checked 31 Aug 2026. No retention period for contracts, prompts or outputs was located; the only period published anywhere is the 60 days within which a customer-specific model must be erased after termination. And no incident or breach notification practice was located on the pages read, though the application security and infrastructure articles were not opened and may carry it.

SpotDraft
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Detailed, specific and current, missing a named subprocessor list. The security page carries a last-updated date of 17 October 2025 and publishes: FIPS-140-certified encryption, AES-256 at rest, per-contract unique keys in HashiCorp Vault backed by Google Cloud KMS, primary and backup servers on Google Cloud Platform in the Netherlands, data classification across four sensitivity tiers, least privilege access with unique IDs and enforced password policies, a documented business continuity and disaster recovery programme, automated patch management, continuous CVE tracking for third-party packages, regular threat modelling, independent penetration testers, and routine static analysis and vulnerability scanning. A predefined security incident response process is stated and described as refined through regular exercises. Two gaps checked 31 Aug 2026: no subprocessor is named anywhere, though the page states that fourth parties such as backup providers and subcontractors have no access to scoped systems or data, and no retention period for customer content is published.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Juro
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

A real published position, and the AI-specific part of it is unusually explicit. Juro publishes its Master Services Agreements for US and non-US customers as dated downloadable documents, alongside separate AI terms carrying a last-updated date of 11 March 2025 and a link to the superseded February 2025 version, so a buyer can read the allocation of loss and its history before entering a sales process. Clause 3.2 of the AI terms then does something few vendors do in either direction: it states expressly that any indemnity Juro provides under the MSA relating to non-infringement of intellectual property or other third party rights does not apply to AI output. So there is an indemnity, and the buyer is told plainly that it stops at the AI. Paired with clause 3.1, which puts the duty to identify and correct errors on the customer, the position on wrong output is clear and it is adverse to the buyer. What could not be verified on 31 Aug 2026 is the rest: the Master Services Agreement was not opened, so the liability cap, any warranty and any insurance position were not read, and this grade is rebuttable in either direction on that document.

SpotDraft
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

Written 31 Aug 2026 as an R7 amendment; left unwritten in the original build because the agreement had not been opened and this axis has no substitute surface. Surface read 31 Aug 2026: the SpotDraft Terms of Use on the vendor's own Legal Hub at legal.spotdraft.com, version 2.3, last updated 21 February 2024, read in full, with five prior versions listed and downloadable from the same page. Liability is addressed only through limitation and disclaimer, which is what fixes the grade. Clause 8.3 caps SpotDraft's total cumulative liability, in contract or tort, at one hundred Indian rupees, a figure worth roughly one United States dollar. Clause 8.2 excludes consequential, indirect and special damages including loss of data and profits. Clauses 5.2 and 5.3 disclaim any warranty of fitness, of error-free or uninterrupted use, and expressly waive the warranty of non-infringement. Clause 9 is an indemnity running only from the customer to SpotDraft; no vendor indemnity to the customer was located anywhere in the document. Clause 5.5 disclaims any liability for consequences arising from use of the Platform, and 5.4 states that SpotDraft gives no legal advice. Governing law is India with exclusive jurisdiction in the courts at Bangalore, and the contracting entity is Draftspotting Technologies Private Limited together with affiliates including Draftspotting Inc. One scope point a buyer should weigh: this is the published Terms of Use reached from the signup path, and clause 11.8 contemplates additional terms when other services are purchased, so an enterprise subscriber may well contract on a negotiated master agreement that is not published. The index grades what is published and readable before signing, and what is published is this.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Juro
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Real integrations, individually documented, into the systems an in-house team actually works in. Each has its own page: Salesforce, HubSpot, Slack, Microsoft Word, Docusign, Google Drive, Zapier and a REST API, plus MCP connections to Claude and ChatGPT, with Pipedrive, Greenhouse, Workday, SharePoint and Companies House named elsewhere. An integrations index exists. The pricing FAQ adds something implementer-useful and commercially candid, distinguishing out-of-the-box integrations available on all plans, naming Slack, Google Drive and Companies House, from deeper integrations that cost extra, naming Salesforce, HubSpot and Workday. What is missing for an A is depth: the individual integration pages were not opened on 31 Aug 2026, so what each connection actually moves, in which direction, and what a customer must configure was not verified. No document management integration such as iManage or NetDocuments appears, which is consistent with an in-house rather than law firm product.

SpotDraft
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Real integrations, individually documented, into the systems an in-house team works in. The vendor states more than 30 integrations and gives each its own page, with Salesforce, HubSpot, Slack, Microsoft Word for desktop, Google Drive, DocuSign, Greenhouse, Google Forms, Jira and Zapier all linked directly from the pricing page. The Word integration is treated as a first-class surface rather than an afterthought: VerifAI runs review inside Microsoft Word, negotiation and redlining are described as working in Word, Slack or SpotDraft itself, and one named customer specifically credits the Word desktop editor with driving adoption. Single sign-on covers Office 365, Google Workspace, Okta, Active Directory and custom SAML with zero-touch provisioning. What was not established on 31 Aug 2026 is depth: the integrations index and the individual integration pages were not opened, so what each connection moves and in which direction was not verified. No document management integration such as iManage or NetDocuments appears, consistent with an in-house rather than law firm product.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Juro
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Cloud delivery is implied and neither the tenancy model nor the region is stated on any surface read. AWS appears on the published subprocessor list as infrastructure, and the AI processing location is stated on the responsible AI page as Microsoft Azure servers, which is a real statement about where inference happens. Beyond that, searched the home page, the trust centre index, the responsible AI page, the pricing page and the terms index on 31 Aug 2026 and located no statement of whether the platform is multi-tenant or single-tenant, no region options, no data residency commitment, and no private or on-premises deployment option. Two trust centre articles not opened, on network and infrastructure security and on the GDPR, are the likely home for a residency statement, so this grade is rebuttable on either. The gap is more visible than usual because the vendor states it serves customers in more than 85 countries and publishes an EU Data Act addendum.

SpotDraft
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

Both halves of this axis are answered, which almost nothing in this pull manages. The tenancy model is stated plainly rather than implied: customer data is logically separated within a secure multi-tenant infrastructure, so a buyer knows it is shared and knows what separates it. Residency is stated as a customer choice with an explicit boundary commitment: personal data is stored within selected regions covering the US, EU, India and the Middle East, and is not transmitted outside those locations. Where the data physically sits is named to the country, with primary and backup servers on Google Cloud Platform in the Netherlands. The processing layer is identified as Google Cloud Platform throughout, and encryption keys are held per contract in HashiCorp Vault backed by Google Cloud KMS, which tells a buyer where key custody sits as distinct from where data rests. What would sharpen it further is a statement of which region applies by default and whether contract content follows the same rule as personal data, since the regional commitment is written in terms of personal data specifically.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Juro
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

The trust centre is genuinely open, which is rarer than it sounds, and the attestation behind it is not evidenced. Juro publishes a trust centre with ten substantive articles readable without a form, an email address or an NDA, covering the UK GDPR, the GDPR, the CCPA, the EU AI Act, the EU Data Act, advanced electronic signatures, application security, network and infrastructure security, application resilience and responsible AI use, filterable by compliance, security and privacy. That is a materially better access route than the gated portals elsewhere in this cohort. SOC 2 Type 2 certification is stated repeatedly, with a badge in the site footer and a dedicated trust centre article described as covering the SOC 2 Type II attestation, and a public status page and a 99.9 per cent uptime figure sit alongside it. What was not located on 31 Aug 2026 is the substance an attestation is judged on: no auditor is named, no coverage period or report date is given, no scope is described, no route to obtain the report is stated, and no penetration test summary or testing partner appears. The infrastructure article was not opened and may name the auditor.

SpotDraft
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

Marks are displayed, a trust centre exists, and the property contradicts itself on the standard actually held. Four compliance marks appear as icons on the home page, the pricing page and the security page: ISO, GDPR, HIPAA and AICPA SOC 2, with the home page listing them as ISO 27001, SOC 2 Type II, GDPR and HIPAA. The footer of every page then reads that SpotDraft is an ISO/IEC 27001:2013 certified company, and 27001:2013 was superseded by the 2022 revision, so the site simultaneously claims a current certification and names a retired version of it. A separate trust centre is linked at trustcenter.spotdraft.com and is credited here as a genuine access route, though it was not opened on 31 Aug 2026. What could not be established from any page read: no auditor is named, no coverage period or report date is given for the SOC 2, no scope is described, and while independent penetration testers are said to be engaged, no partner is named and no summary is published.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Juro
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

The supply chain is named to a level most of this market does not reach, without a change commitment. The responsible AI page states that Juro's AI tools are built using OpenAI's GPT model, provided by Microsoft on Azure servers, which identifies the model family, the provider, the delivery route and where inference runs in a single sentence, and the vendor ties the arrangement to how it protects confidentiality. Three gaps, checked 31 Aug 2026. No specific model version is named, and the illustrative discussion on that page refers to GPT-4, which may or may not be what the product runs today. Nothing commits Juro to notifying customers when the provider or model changes. And there is an internal inconsistency worth a buyer's attention: neither OpenAI nor Microsoft appears on the published subprocessor list at the trust centre, which names Algolia, AWS and MongoDB as infrastructure and does not mention the model provider that processes contract content.

SpotDraft
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

Nothing published about the model supply chain a customer inherits. Searched the home page, the pricing page and the security page in full on 31 Aug 2026. No model provider is named, no model or version is identified, no architecture is described beyond the statement that the AI is embedded in SpotDraft and operates in the customer's company-specific context, no subprocessor list exists, and nothing commits the vendor to notifying customers when any of it changes. The security page is otherwise unusually granular, naming HashiCorp Vault, Google Cloud KMS, JAMF, FileVault and BitLocker among its tooling, which makes the absence of any model provider conspicuous rather than incidental. The SpotDraft AI and VerifAI product pages and the trust centre were not opened, so this is rebuttable if any of them names a provider.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Juro
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

The unit and the structure are published without the figure, which is the B band exactly and more than most of this cohort offers. The pricing page states the charging model directly: all plans include unlimited users, unlimited workflows and unlimited templates, and price is driven by monthly contract volume and by the complexity of integrations. The volume bands a buyer is placed into are published, running from fewer than 20 contracts a month through to more than 1,000. Which integrations carry extra cost is named, with Slack, Google Drive and Companies House included and Salesforce, HubSpot and Workday charged. Billing currencies are stated as USD, GBP or EUR, non-profit discounts are offered, and a 20 per cent first-year discount for signing in the month of the demo is published. No figure is reachable: the on-page calculator collects volume, contract types, AI features and integrations and then requires name and email, and the approximate price field rendered as 0 USD when read on 31 Aug 2026. Nothing states what implementation adds.

SpotDraft
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

The unit and structure are published without the figure, and one thing is answered that no other vendor in this pull answers. The pricing page states the charging model directly: plans are priced on either users or contract volume, with the vendor framing the choice as avoiding wasted spend. It then addresses implementation explicitly, which is the third limb of this axis and is normally silent everywhere: in-house implementation is always included, covering workflow and integration setup and migration of legacy contracts, with no extra fees and no outsourcing, and every customer receives a dedicated customer success manager and 24 hours a day support at no additional cost. An implementation timeline is published as a week one to week six sequence. What is absent is any number: no rate, no band, no floor and no currency appears anywhere, and every call to action on the page is Get Pricing or a demo request. Checked 31 Aug 2026.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Juro
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Coverage is described with substance on the axis the vendor sells, and the boundaries are left open. Dedicated pages exist for five buying teams, legal, HR, procurement, sales and finance, with legal positioned as the function that controls templates and workflows while the others self-serve within them. Contract types are named concretely on the pricing calculator: NDAs, employment contracts, MSAs, SOWs, order forms, M&A documents and vendor agreements. The vendor states it serves customers in more than 85 countries and gives a usage floor rather than leaving fit vague, saying businesses signing around ten or more contracts a month will see a return. What is absent is the far edge. No law firm segment is addressed, which follows from this being an in-house product but is never stated. Nothing addresses government or court use. And the industry navigation is published but non-functional, with B2B SaaS, food delivery, auto marketplace and travel marketplace all resolving to empty anchors when checked on 31 Aug 2026.

SpotDraft
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Segment coverage is described with substance on two axes and the boundaries are left open. Five buying teams carry dedicated pages, legal, sales, finance, HR and procurement, with legal positioned as the owner and the others as self-serve participants. Five industries carry their own pages: SaaS, HR tech, edtech, healthtech and fintech, which is a narrower and more honest vertical set than the everything-for-everyone lists common in this category. The home page states the audience directly as high-performing in-house legal teams. What is absent is the far edge. No law firm segment is addressed, nothing covers government or public sector use, no contract types or matters are named as unsupported, and the practice dimension is expressed as industry and internal function rather than as areas of law. Checked 31 Aug 2026.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Juro
Never, in the contract

The prohibition sits in the agreement rather than on a policy page. Clause 1.2 of Juro's published AI terms, last updated 11 March 2025, states that Juro may not use customer data as training data for any AI model, with a single carve-out for a customer-specific model used only to provide services to that same customer, and requires any customer-specific model to be erased within 60 days of termination for any reason. The carve-out is confined to the customer's own benefit, so no other customer's model is trained on their data. The responsible AI page states the position more absolutely, that Juro does not use customer data to train foundational models and does not use contract data to train any model, which is slightly wider than the contract itself allows.

SpotDraft
Terms silent

Searched the home page, the pricing page and the security page in full on 31 Aug 2026, including the security page's data security, infrastructure security, product security and risk governance sections and its five-question FAQ. No located material addresses whether customer contracts, prompts or outputs are used to train any model, either by SpotDraft or by an underlying model provider. The nearest statements are that the AI is embedded in SpotDraft, operates in the customer's company-specific context and follows the customer's rules, and that the platform is risk free AI on the customer's terms, none of which is a commitment about training. No model provider is named anywhere either. The trust centre and the published terms of service were not opened, so this value is rebuttable on either document.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Juro
Disclosed without a period

Retention is acknowledged without a period for contracts, prompts or outputs. The only period published anywhere is in clause 1.2 of the AI terms, which requires erasure of any customer-specific model within 60 days of termination, and that governs a derived model rather than the underlying content. The trust centre privacy summary confirms that data from contracts is collected and that customers can port their data or be forgotten, which acknowledges retention and gives a deletion route without stating a window or a customer-configurable setting. Searched the home page, the trust centre index, the responsible AI page, the pricing page and the terms index on 31 Aug 2026; the published data processing agreement was not opened and may state a period.

SpotDraft
Not addressed

Searched the home page, the pricing page and the security page on 31 Aug 2026. No retention period for contracts, prompts or generated outputs is published. Retention appears only as a heading within the security page's data handling practices, where data classification and retention are named together and the text describes classification into public, company confidential, customer confidential and personal tiers without stating how long anything is kept. Secure data disposal is listed among the data centre measures without a period attached. No customer-configurable retention setting is described.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Juro
Not addressed

Searched the home page, the trust centre index, the responsible AI page, the AI terms, the pricing page and the terms index on 31 Aug 2026. No public material addresses how one customer's repository is separated from another's, and none addresses access boundaries inside a customer, which matters here because the product is sold on the basis that sales, HR, procurement and finance colleagues self-serve alongside legal in the same workspace. The nearest published material is contractual rather than architectural: clause 1.2 of the AI terms prevents customer data training a model that serves anyone else, and clause 1.3 states that output generated for other users is not the customer's data. Neither describes how retrieval or permissions are enforced. The buyer is an in-house department, so tenant-level separation rather than matter-level walls is the relevant test.

SpotDraft
Own model, documented

Separation is documented at two levels rather than asserted. Between customers, the security page states that customer data is logically separated within a secure multi-tenant infrastructure, and adds that each contract is protected with a unique encryption key held in HashiCorp Vault backed by Google Cloud KMS, which is a finer-grained control than tenant-level isolation alone. Within a customer, roles and permissions are described as fully customisable and scoped by contract type, organisational entity and department, with contract-level permissions ensuring documents are visible only to authorised personnel without manual sharing. What is not published is how retrieval and the AI features apply those permissions at query time, so whether a model answering a question respects the same boundaries is unstated. The buyer is an in-house department, so tenant and entity level separation is the relevant test.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Juro
Notice committed

Written 31 Aug 2026 as an R7 amendment, on the Juro Data Processing Agreement last updated 7 March 2025, read in full; the original pass had not opened it. The commitment sits at Appendix 3, paragraph 4.4(k), given for the purposes of clause 15(1)(a) of the Standard Contractual Clauses, and it obliges Juro to notify the customer of government access requests while leaving notification of data subjects to the customer. A buyer should note its reach. Appendix 3 applies only where the corresponding law applies, so this operates through the European route where the SCCs are engaged on a restricted transfer, and no equivalent government-access notice clause was located in the CCPA appendix or in the general terms for a customer outside that route. Separately, paragraph 11.2 provides that a third party purporting to be a controller of customer personal data will be directed to the customer, and paragraph 8.2(a) routes data subject requests the same way. No transparency report or count of requests received was located on the DPA, the terms index or the trust centre, which is what keeps this below the top value.

SpotDraft
Not addressed

Searched the home page, the pricing page and the security page on 31 Aug 2026. No located material addresses what happens if a third party, law enforcement agency or court requests customer data from SpotDraft, and no commitment to notify the customer was found. No transparency report exists. The security page does state that third-party vendors handling scoped data are bound by confidentiality, audit and incident response protocols, and that fourth parties such as backup providers and subcontractors have no access to scoped systems or data, but neither addresses compelled disclosure. The published privacy policy and terms of service, which are the usual home for this provision, were not opened.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Juro
Sources named, basis unstated

The corpus behind the product's answers is the customer's own contract repository, which is identified plainly: Operator is described as understanding the customer's documents and citing its sources, and AI Extract pulls data points from the customer's executed contracts. The underlying foundation model is separately identified as OpenAI's GPT model provided by Microsoft on Azure. Juro does not retrieve primary law, so questions of case law and statutory coverage do not arise in the usual form. No licence or rights basis is stated for the foundation model's own training corpus beyond a general description, and no update cadence is published for anything.

SpotDraft
Sources named, basis unstated

The working corpus is the customer's own contract set and is identified as such: the repository is described as centralising all of a customer's contracts and automatically pulling over a thousand types of contract metadata using AI, and the AI is described as operating in the customer's company-specific context and following the customer's rules. No external legal corpus is claimed and the product does not retrieve primary law, so the usual jurisdiction and coverage questions do not arise. What is not stated is the provenance of anything underneath: no training corpus for the models themselves is described, no source is named and no licence or rights basis is given.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Juro
Not addressed

Searched the home page, the trust centre index, the responsible AI page, the AI terms and the pricing page on 31 Aug 2026. Nothing addresses whether legal authority is checked for subsequent history, and no citator, treatment signal or currency check was located. The product manages a customer's contracts rather than retrieving primary law, so a citator is not part of what it sells. Worth recording alongside that: clause 3.1 of the AI terms acknowledges that output may fail to reflect laws accurately, including legal authorities, which is an unusual admission from a product that does not hold itself out as a research tool.

SpotDraft
Not addressed

Searched the home page, the pricing page and the security page on 31 Aug 2026. Nothing addresses whether legal authority is checked for subsequent history, and no citator, treatment signal or currency check was located. The platform manages a customer's own contracts rather than retrieving case law or legislation, so a citator is not part of what it sells. One product does touch adjacent ground: Sidebar is described as helping users stay ahead of regulatory change with AI agents, which concerns the currency of regulation rather than the standing of cited authority, and no source or verification method is published for it.

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Juro
Not addressed

Searched the home page, the responsible AI page, the AI terms, the trust centre index and the pricing page on 31 Aug 2026. No explicit no-answer or abstention path is documented and no confidence or grounding score was located. What Juro does publish is an acknowledgement of fallibility rather than a description of behaviour: the responsible AI page states that generative AI is predictive by nature and can never be 100 per cent accurate, and clause 3.1 of the AI terms states that AI features make mistakes and shifts the duty to identify and correct them onto the customer. That is candid about uncertainty and silent on what the system itself does when it cannot ground an answer.

SpotDraft
Not addressed

Searched the home page, the pricing page and the security page on 31 Aug 2026. No explicit no-answer or abstention path is documented, no confidence or grounding score was located, and nothing states what the product does when the customer's contract set or playbook does not cover the question put to it. Published material addresses configuration rather than uncertainty, describing AI that operates in the customer's context and follows the customer's rules. The SpotDraft AI and VerifAI product pages were not opened, so this value is rebuttable if either documents abstention behaviour.

Fabricated Citation Record

Does a public court record exist involving output from this product?

Juro
None located

No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, searched on both the product name and the company name Juro Online Limited, alongside 2026 sanctions trackers and trade press summaries. This is a statement about the public record on the date shown rather than a clearance, and it is bounded by what that database covers. The product manages commercial contracts for in-house teams rather than producing court filings, so its output does not ordinarily reach a brief.

SpotDraft
None located

No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, searched on the product name alongside 2026 sanctions trackers and trade press summaries. This is a statement about the public record on the date shown rather than a clearance, and it is bounded by what that database covers. The product manages commercial contracts for in-house teams rather than producing court filings, so its output does not ordinarily reach a brief.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Juro
Generic reference

Public materials refer to professional responsibility in general terms without naming guidance. The responsible AI page states that regulated professionals such as lawyers need confidence that their use of AI will not compromise their professional obligations of confidentiality, and extends the same point to HR professionals protecting employee confidences, framing it as a reason not to use tools that train on customer data. That is engagement with the obligation rather than with the guidance. Searched the home page, the trust centre index and its ten articles, the responsible AI page, the AI terms and the terms index on 31 Aug 2026 and located no named ethics opinion, including ABA Formal Opinion 512, no US state bar guidance and no Solicitors Regulation Authority or Law Society material, despite the vendor being UK-founded and serving more than 85 countries.

SpotDraft
Named guidance addressed

Two named ethics guidance documents from two jurisdictions are cited on the home page: the California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law, dated November 2023, and the American Bar Association's Formal Opinion 512 on generative AI, dated July 2024. Both are given with issuing body and date, and the vendor states its AI features are designed with attention to the principles in each, ensuring responsible and secure usage throughout contracting workflows. This is the only vendor read in this pull to name more than one. It is recorded at the named-guidance value rather than higher because what is published is a statement of attention to principles, not a mapping showing which obligation is met by which product control, and no other jurisdiction's guidance is addressed.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Juro
Savings claims only

Public materials are built around time and headcount saved, and quantified more heavily than most: an 86 per cent reduction in time to sign, a 91 per cent time saving per contract, three and a half hours saved per contract, 8,000 dollars saved a year, 48 hours saved a month, and one full-time hire avoided, each attached to a named customer. Searched the home page, the pricing page, the trust centre, the responsible AI page and the AI terms on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee purposes and no published guidance on billing, fee or disclosure treatment. The buyer is an in-house department rather than a firm billing a client, so the question lands on internal cost and outside counsel spend rather than on the hourly bill, and nothing addresses either.

SpotDraft
Savings claims only

Public materials are framed around speed and cost removed: two times faster closings, 65 per cent lower cost, 70 per cent less review time, and contracts reviewed 15 times faster with VerifAI. Searched the home page, the pricing page and the security page on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee purposes and no published guidance on billing, fee or disclosure treatment. The contract-level audit logging the vendor describes, which traces changes by both the creator and the counterparty and retains every version, could support such a record, but nothing presents it for that purpose. The buyer is an in-house department rather than a firm billing a client, so the question lands on internal cost, and it is not addressed.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Juro
Subprocessors listed

A subprocessor list is published openly at the trust centre and names entities rather than categories, covering Algolia, AWS and MongoDB for infrastructure, Google Analytics, Heap, Mixpanel, Metabase and Hotjar for analytics, HubSpot, Intercom, Sendgrid and Sumo for communications, Stripe for payments, and Salesforce, Slack and Google as customer-initiated integrations. Alongside it sit a published data processing agreement, an EU Data Act addendum, separate AI terms and a pre-populated data protection impact assessment template offered to customers, all reachable without an agreement in place. Two things stop this reaching the top value. The list does not include the model provider: neither OpenAI nor Microsoft appears on it, although the responsible AI page identifies them as processing contract content. And no client-facing consent or notification pack was located on 31 Aug 2026.

SpotDraft
On request only

Searched the home page, the pricing page and the security page in full on 31 Aug 2026. No subprocessor list was located and no model provider is named anywhere, so a legal team cannot tell a client which third parties see contract content. No client-facing consent or notification material exists. What is published instead is a set of assurances about third parties rather than an identification of them: vendors handling scoped data are said to be bound by confidentiality, audit and incident response protocols, and fourth parties such as backup providers and subcontractors are stated to have no access to scoped systems or data. A trust centre is linked at trustcenter.spotdraft.com and a request route for security documentation appears on the security page, both of which are plausible homes for the missing material; neither was opened.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Juro
Not addressed

Searched the home page, the trust centre index, the responsible AI page, the AI terms and the pricing page on 31 Aug 2026 and located nothing addressing court disclosure, AI-use certification or the production of a verification record. The product manages commercial contracts for in-house teams rather than producing court filings, so a judicial standing order is not its usual context. Two adjacent elements exist without amounting to a record: Operator is described as citing its sources when it answers, and clause 2(e) of the AI terms prohibits misrepresenting AI output as human-generated, which is an obligation on the customer rather than a capability to evidence what the model did.

SpotDraft
Partial record

Some elements of a record exist and are described with unusual precision for this signal. The security page states that the platform has extensive audit logging allowing user actions to be traced at contract level, capturing not only signing and creation events but the trail of changes made by both the creator and the counterparty, and that every version of a contract created by a user is kept to give a clear document history. That covers what changed, by whom and when, at document level. Two elements are missing: no model is identified anywhere on the property, so which system produced a given passage cannot be established, and nothing distinguishes an AI-generated change from a human one in the log as described. No export designed for a court disclosure or AI-use certification was located on 31 Aug 2026.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.

Signals neither addresses in public material
  • Good Law Verification
  • Refusal and Uncertainty Behaviour

Which one fits

Choose Juro if

  • You want the agreement in front of you before the demo. Juro publishes master services agreements for United States and non United States customers, standalone AI terms carrying a last updated date of 11 March 2025 with the superseded version still linked, a data processing agreement, an EU Data Act addendum, API terms and evaluation terms, all as dated downloadable documents, and clause 3.2 of those AI terms tells a buyer where the indemnity stops, which is at AI output.
  • You need the training prohibition in a term rather than on a page. Clause 1.2 of Juro's AI terms states that Juro may not use customer data as training data for any AI model, with a single carve out for a customer specific model used only to serve that same customer, and requires any such model to be erased within 60 days of termination for any reason.
  • A client asks whose model reads its contracts. Juro states openly that its AI runs on OpenAI's GPT model provided by Microsoft on Azure servers, which names the model family, the provider, the delivery route and where inference happens in one sentence, and it publishes a subprocessor list and ten trust centre articles readable with no form, email or NDA.

Choose SpotDraft if

  • Your data has to stay in a named region. SpotDraft states that customer data is logically separated within a secure multi tenant infrastructure, that personal data is stored within a selected region across the United States, the European Union, India and the Middle East and is not transmitted outside those locations, and that primary and backup servers sit on Google Cloud Platform in the Netherlands with per contract encryption keys in HashiCorp Vault.
  • Your risk committee wants the ethics guidance named. SpotDraft states that its AI features are designed with attention to the California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law of November 2023 and to the American Bar Association's Formal Opinion 512 of July 2024, both given with issuing body and date.
  • You do not want implementation quoted separately after signature. SpotDraft states that in house implementation is always included, covering workflow and integration setup and migration of legacy contracts with no extra fees and no outsourcing, publishes a week one to week six rollout sequence, and includes a dedicated customer success manager and support at no additional cost.

In summary

Juro

Juro is an end to end contract lifecycle platform for in house teams, built so that colleagues outside legal can create and complete contracts inside templates and workflows legal controls, with AI Review for triage and redlining, AI Extract for pulling data from executed contracts, an assistant, and Operator, a conversational agent over the repository that cites its sources. The AI Legal Index grades it in the top two bands on twelve of fifteen capability axes. Its most specific published material is contractual: clause 1.2 of its AI terms bars using customer data to train any model except a customer specific one serving only that customer, erased within 60 days of termination. As of 31 August 2026 the index located no accuracy measurement, no retention period and no tenancy or region statement.

Source: AI Legal Index, 2026

SpotDraft

SpotDraft is a contract lifecycle platform for in house legal teams covering template driven creation, conditional approval workflows, negotiation and redlining in Word, native eSignature, a repository that extracts more than a thousand metadata types, and AI through VerifAI review, Intake and the Sidebar agents. The AI Legal Index grades it in the top two bands on eight of fifteen capability axes, with an A on deployment model and data residency: customer data is logically separated within a multi tenant infrastructure, personal data is held in a customer selected region across the United States, the European Union, India and the Middle East and stated not to travel outside it, and servers run on Google Cloud in the Netherlands with per contract keys in HashiCorp Vault. As of 31 August 2026 the index located no accuracy figure, no model provider named and no training position.

Source: AI Legal Index, 2026

Questions buyers ask

Juro vs SpotDraft: which is better for an in house legal team?

The AI Legal Index places Juro in the top two bands on twelve of fifteen capability axes and SpotDraft on eight, and the gap is disclosure rather than function. Juro publishes its agreements, its AI terms and the model layer behind the product. SpotDraft publishes where data is stored and processed, names two ethics guidance documents, and includes implementation at no extra cost. Neither publishes an accuracy measurement or a rate.

Does Juro train its AI on customer contracts?

No, and the prohibition sits in the agreement rather than on a policy page. Clause 1.2 of Juro's published AI terms states that Juro may not use customer data as training data for any AI model, carving out only a customer specific model used solely to serve that same customer, which must be erased within 60 days of termination for any reason. Its responsible AI page states the same commitment in summary form, that customer data is not used to train foundational models. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Where does SpotDraft store contract data?

SpotDraft states that personal data is stored within a region the customer selects across the United States, the European Union, India and the Middle East, and is not transmitted outside those locations. Primary and backup servers run on Google Cloud Platform in the Netherlands, encryption is AES-256 at rest with a unique key per contract held in HashiCorp Vault backed by Google Cloud KMS. The regional commitment is written in terms of personal data, and no statement was located confirming that contract content follows the same rule. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Do either name the AI models they use?

Juro does. It names OpenAI's GPT model provided by Microsoft on Azure servers, which is more than almost anything else in this market publishes, though no version is given and no commitment to notify customers of a change was located. One point a buyer should note: neither OpenAI nor Microsoft appears on Juro's published subprocessor list, which names Algolia, AWS and MongoDB as infrastructure. On the SpotDraft record the index located no model, provider or architecture at all. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

What do Juro and SpotDraft both leave unpublished?

Neither publishes an accuracy measurement for contract review: no error rate, test set, benchmark or evaluation was located on either record. Neither states a retention period for contracts, prompts or generated output. Neither publishes a rate, although both publish the unit of charge and the structure around it. And neither addresses legal professional privilege or work product, which matters because both platforms hold the whole contract estate for a legal department. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Disclosure

Read Juro's AI terms directly, because they say plainly what most vendors leave unsaid. Clause 3.2 states that the indemnity in the master services agreement does not apply to AI output, and clause 3.1 puts the duty to identify and correct errors on the customer, so the allocation of loss for wrong output is published, dated and versioned before any sales conversation. On SpotDraft, the published Terms of Use cap total liability at one hundred Indian rupees, and the same document contemplates further terms where other services are purchased, so an enterprise buyer may sign a master agreement that is not published. Its site footer also states ISO/IEC 27001:2013, a superseded revision. Both records were verified on 31 August 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 2, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746