Leah vs Luminance: how they compare in 2026
This is a genuine head to head. Both sit in contract review and drafting, both are enterprise platforms covering the contract from intake through negotiation to post execution analysis, both are sold well beyond the legal department, and both are headquartered in the United Kingdom. Leah takes the top two bands on eleven of fifteen axes and Luminance on ten, and they are strong in opposite places. Luminance owns more of the stack than almost anything in this index: it builds and hosts its own legal model, gives every customer a dedicated single tenant instance, offers deployment inside the customer's own environment, and publishes an actual benchmark rather than an adjective. Leah publishes the paperwork: a tiered liability cap with figures, an enumerated list of uncapped claims, a warranty with a thirty day fix period, published uptime tiers with refund, and a named subprocessor list carrying thirty days notice and an objection right. The sharpest difference between them is not on the axis grid at all. Leah states that customer contract data is never used to train models. Luminance has stated in its own press material that its model learns from every NDA or supplier agreement negotiated within the platform, with no aggregation or anonymisation qualifier attached and nothing published on whether a customer can decline. For a contract platform, that is the question to settle first.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of the capability being sold, layered on a contract lifecycle platform that would function without them. The vendor argues the opposite, stating that other vendors bolted AI onto systems built for manual workflows while Leah was designed from scratch with orchestration as the foundation. The published record does not support that reading. ContractPod Technologies has sold contract lifecycle management since 2012; Leah launched in March 2023 as an AI services hub within that platform, went standalone in May 2023, and Leah Intelligence followed in October 2024. Strip out the agents and what remains is a working CLM with guided intake, approval routing, DocuSign and Adobe Sign execution, and a contract repository, which is a product with its own market and its own Gartner category placement. The orchestration layer is real and is genuinely model-driven, which is why this is a B rather than lower.
The artificial intelligence is the product, and the vendor owns more of the stack than almost anyone on this index. Founded by mathematicians in 2015, it runs a multi model architecture it calls a Panel of Judges combining foundation, fine tuned and proprietary models, and ships its own legal intelligence model, Luna Crescent, trained in house and deployed in its own environment. Remove the models and there is no product.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted repeatedly, and at one point claimed to be benchmarked, without a single figure attached. The AI governance page states that every action is measured against benchmarks for accuracy, bias and outcome, and the product material describes a legal helpdesk that answers contract questions with sources attached, which is a grounding claim a reader could in principle check inside the product. Searched the home page and the AI governance page in full on 31 Aug 2026 and located no accuracy figure, no error or hallucination rate, no description of any benchmark or test set, and no published evaluation. The benchmark claim is the sharpest version of the problem this axis exists to catch: a vendor asserting measurement without publishing the measurement. Nothing addresses what the system does when the customer's own contract set does not support a position.
Substantive disclosure with a real gap. The vendor publishes ContractIQ Bench, a proprietary benchmark of 189,000 manually annotated and reviewed data points assessing interpretation of named provision types including liability caps, termination for convenience and confidentiality obligations, tested on held out documents and concepts excluded from training, with blind evaluations by legal experts alongside. It publishes a result, 5 percent higher accuracy than leading general purpose models on contract understanding, and a speed figure of 200 to 400 tokens per second. It also states a design principle directly relevant to this axis: the model is trained to prioritise faithful extraction and to identify absence rather than invent an answer. Two gaps keep it off an A. The published figure is a relative delta with no absolute accuracy rate and no named comparator models, so a reader cannot tell what 5 percent higher is 5 percent higher than. And the benchmark is proprietary, with no sample tasks or rubric published, so an outsider cannot inspect or re run it.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The control structure is published in full and is the thing the vendor sells on. A dedicated AI governance page sets out a three-stage loop. Policy in: the customer defines which agents may act, on which data, within which thresholds, and where escalation is required, with those policies held as configuration rather than code. Execution governed: every agent action runs through those policies in real time, with approvals, escalations and rejections applied automatically and the orchestrator enforcing guardrails at each step. Audit out: every decision is logged with the rationale, what the agent did, why, under which policy, on what data and to what outcome, in records described as tamper-resistant and immutable. That covers the thresholds, the review surfaces and the route back to human judgement, and the home page states the position plainly, that the workflow runs itself while the judgment stays human. What is still missing is what happens after an output is found to be wrong, and default modes are not described because the guardrails are customer-configured rather than shipped.
A real published commitment with a described control mechanism, short of the full structure. The Panel of Judges architecture is itself an oversight design and is documented: multiple models analyse each clause independently and reach consensus, which the vendor states reduces hallucination risk. Outputs are described as traceable, and Traffic Light Analysis ranks deviation risk visually so a reviewer sees where to look. The vendor publishes a position piece arguing that human in the loop alone is insufficient and that systems must be designed for accuracy and transparency, which is a real stated philosophy rather than a slogan. Not located as of 29 Aug 2026: where the review point sits when the product negotiates with a counterparty directly, the threshold at which it escalates to a lawyer, and what the vendor commits to when an output is wrong. That first gap matters here more than for most, because the product sends agreements to counterparties and negotiates on the customer's behalf.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Substantial evidence on both halves of the question, never joined together. Named individuals speak on the record with roles and employers: Noelle Perkins, EVP and Chief Legal Officer at Cushman and Wakefield; Lidia Kamleh, Chief Legal Officer at Dubai Future Foundation; Frances Bain-Cumberbatch, Chief Legal and External Affairs Officer at Ansa McAL; and Zillia Knight, Senior Legal Officer at Terumo Europe. Every one of those quotes is qualitative. Separately, three figures are published with the customer anonymised: a 91 per cent cut in contract review time at a major US logistics company, more than 18 million dollars of revenue protected at a global manufacturer, and more than 2 million dollars of tracked savings at a US retail REIT. Roughly 54 enterprise logos appear, including Philips, MUFG, Sandoz, Pernod Ricard, Alaska Airlines and Wood PLC. A buyer should read that logo strip carefully: PwC and KPMG appear in it, and PwC entered a commercial alliance in March 2024, while Epiq resells Leah inside its Service Cloud, Integreon is quoted as an early adopter reselling onward, and Pinsent Masons adopted it for managed legal services in July 2025. Channel partners and customers are presented together without distinction, and a Chief Product Officer of Execo, another services partner, appears in the testimonial carousel.
Real deployment evidence with substance, short of attribution and method. Named customers appear in vendor and trade material including Hitachi, AMD, BBC Studios, Yokogawa and Koch, alongside a stated base of more than 700 organisations across 70 plus countries and all four of the Big Four consultancies. A customers page is published. The recurring figure, negotiation time reduced by up to 90 percent, is a vendor claim carrying a hedge and is not tied to any named customer, dated, or accompanied by a method. Searched the site, the customers page, the press releases and the resources index on 29 Aug 2026 and located no case study pairing a named organisation with figures and a date.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Specific published commitments on the questions that matter most, with two real gaps. The vendor states that customer contract data is never used to train models, and the AI governance page frames data leaking into models the customer does not own as a failure it engineered out, stating that zero data retention is the only acceptable answer and that it enforces zero retention with OpenAI and Anthropic so that data is processed but never stored by the providers. Encryption is AES-256 at rest and TLS in transit with keys held in Azure Key Vault, rotated and reachable only through controlled service accounts. Role-based access control is stated to be enforced at every layer, and single-tenant deployment is offered for customers with strict isolation requirements. Two gaps. Privilege and work product are not addressed anywhere on the surfaces read on 31 Aug 2026, on a platform sold into Fortune 500 legal departments. And none of it could be checked against an agreement: the legal and privacy pages are linked from every footer but neither could be retrieved, so every commitment recorded here sits on a marketing or governance surface rather than in a contract.
Substantive published commitments, short of the full picture. Segregation is the strongest element and is documented precisely: each customer receives a dedicated single tenant instance with complete isolation and no co mingling of data, which exceeds the level this buyer segment requires under the amended band. Access control is documented at an unusual depth, including that vendor staff cannot view customer documents without explicit authorisation given through the user interface, with all access tracked and audited. Encryption is specified to the key management service, cipher and rotation practice. Two gaps hold this off an A. No training prohibition on customer content was located anywhere in vendor material, which is a conspicuous absence for a vendor that trains its own models and publishes a corpus figure of 220 million legal documents. Attorney client privilege and work product handling is not addressed directly.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Nothing published on the advice line was located. Section 8 places this evidence in footers, disclaimers, terms and any ethics page; three of those four were checked on 31 Aug 2026, across the complete footers of the home page and the AI governance page and the full navigation and footer sitemap covering platform, solutions, resources and company. No disclaimer of any kind appears, there is no ethics or professional responsibility page, no bar or ethics guidance is named including ABA Formal Opinion 512, and no statement was found on the line between a tool and legal advice. The exposure is not trivial: the platform is sold to run legal work end to end across legal, procurement and finance teams, and its own framing is that agents execute multi-step commercial work without routing every decision through a person. The fourth home, the terms page at the site's legal link, could not be retrieved, so this grade is rebuttable on that document alone.
A boilerplate structure sits in the terms while the product is sold well beyond lawyers. Dedicated solution pages target compliance, executive, sales, procurement, finance, human resources and marketing teams alongside legal, and the product negotiates contracts on a customer's behalf. Searched the site, the solution pages, the published terms and conditions, the privacy policy and the resources index on 29 Aug 2026 and located no position on advice versus tooling, no treatment of competence or supervision duties, and no statement of jurisdiction limits, despite operation in more than 70 countries. This is the widest version of the non lawyer distribution question on the index so far, since the tool is marketed to marketing and HR departments.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
The most substantial governance framework published by any vendor in this pull, short of a named owner and any disclosed result. A dedicated AI governance page names six failure modes the vendor says it engineered out, including black-box decisions that cannot be defended to a regulator or board, and compliance frameworks retrofitted after the fact. Against those it sets three pillars and the policy-execution-audit loop, with per-action logging of rationale and governing policy described as tamper-resistant and immutable, which is a mechanism a buyer could audit rather than a principle. It also makes a claim no other vendor in either pull has made: that every action is measured against benchmarks for accuracy, bias and outcome, with the page stating that accountability is structural rather than aspirational. That is why this is not lower. It is not higher because none of the substance behind the claim is published. No individual or role inside the vendor is named as accountable for model behaviour, no pre-release testing regime is described, no benchmark method or cadence is given, and no result of any bias measurement has been disclosed.
Principles and architecture are published without a governance mechanism a buyer could audit. What exists is real and substantial: a published white paper on how the AI is built, a named Director of AI who authors technical material under his own name, a Cambridge based research team, a described validation regime through ContractIQ Bench, and a security advisory board of named external experts. But the security advisory board governs security rather than model behaviour, and no equivalent exists for AI governance. Not located as of 29 Aug 2026: a named owner of model governance, a pre release testing gate as distinct from benchmark results, an AI management certification such as ISO 42001, and anything on uneven output across matter types, parties or populations.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published controls with two specific absences. The AI governance page publishes real operational detail: TLS for data in transit and AES-256 at rest, encryption keys managed through Azure Key Vault, rotated regularly and accessible only through strictly controlled service accounts, multi-factor authentication, secure API gateways, network segmentation, real-time monitoring, and a fully documented incident response plan. Audit logs are described as comprehensive, tamper-resistant and immutable. Assurance is external rather than self-asserted: the vendor states it is audited annually by an independent Managed Security Service Provider and penetration tested regularly. What is absent, checked 31 Aug 2026: no subprocessor list of any kind, with OpenAI and Anthropic named as model providers but no other processor identified, and no breach notification practice or timeline anywhere despite the incident response plan being referenced twice. No retention period for customer content was located either, which is recorded separately in the signals.
Substantive published policy covering most of the ground, at an unusual level of specificity. Published in the security FAQ: AWS Key Management Service encryption at S3 and EC2 level with AES-256 keys rotated regularly, TLS 1.2 or higher in transit, dedicated single tenant instances, role based and division level permissions configured by the customer under least privilege, configurable password and session timeout policy, mandatory staff security training, named threat detection through Darktrace's Enterprise Immune System and Juniper firewalls, and a described incident management process covering detection, mitigation and communication. Backups are stated precisely: nightly to a secondary AWS data centre in the same region, encrypted, retained a minimum of 14 days. Not located as of 29 Aug 2026: a retention period or deletion control for customer documents in normal operation as distinct from backups, and a named subprocessor list.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Row completed 2 September 2026 under R26, from the ContractPodAi Master Terms and Annexes v3.0c dated 29 August 2024, read in full. The whole allocation of loss is published with figures and it is tiered, which almost nothing else in this corpus manages. Section 16.5 sets a General Cap of amounts paid or payable in the twelve months before the first incident, then an Enhanced Cap of three times that figure which applies specifically to the provider's breach of the security clause or either party's breach of the data processing addendum. Uncapped Claims are enumerated: indemnification obligations, intellectual property infringement or misappropriation, breach of confidentiality, and anything that cannot be limited by law. Section 17.1 gives the customer a real indemnity, with the provider defending third-party claims that the service infringes intellectual property rights, remedies ordered at 17.5 as procure, replace or modify, or terminate and refund. Section 8.2 warrants that the service will perform materially as documented and that functionality will not materially decrease during a term, with a concrete remedy at 8.3 of correction within a thirty day fix period failing which the customer terminates and is refunded. Annex A adds published uptime tiers of 99.00, 99.5 and 99.9 per cent by support plan, with termination and refund if missed in three consecutive or four of six months. Three limits belong on the record and none is hidden. The uncapped confidentiality limb expressly excludes breaches related to Customer Data, so the confidentiality failure that would matter most to a contract platform is capped rather than uncapped, mitigated only by the Enhanced Cap where the security clause is also breached. There is no AI-specific or output indemnity: nothing addresses inaccurate output, hallucination, or training data provenance, and the indemnity at 17.7 is the exclusive remedy for intellectual property claims. And section 9.2 requires the customer not to submit Sensitive Data, defined to include GDPR Article 9 special categories, government identifiers and financial account numbers, with the provider disclaiming liability for such use, which is a meaningful allocation for a platform used on live matters. Trials and betas carry no warranty, indemnity, service level or support and are capped at one thousand US dollars under section 21. Version note: v3.0c is the version published and readable; the current v4.0 dated 4 January 2026 sits behind a viewer neither the operator nor this reader could render, and the vendor's own change note states the only modification is the update to the new trading name.
Liability is addressed only through published terms carrying a standard structure. Terms and conditions are published openly alongside a privacy policy, cookie policy and anti slavery statement, so a buyer can read the allocation of loss before entering a sales process, which keeps this above a pure absence. Searched those documents, the security page and the security standards white paper entry point on 29 Aug 2026 and located no indemnity running to the customer for third party claims arising from output, no warranty on output, no stated liability cap figure and no insurance position. Worth noting the product negotiates with counterparties on a customer's behalf, which raises the recourse question more sharply than a review only tool.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations into enterprise systems, named and functionally described, short of implementer documentation. The named set is the right one for this buyer and unusually broad for the category: ERP platforms including SAP and NetSuite, source-to-pay and procurement systems including Coupa, financial systems, identity providers including Okta, and existing contract lifecycle tools, alongside DocuSign and Adobe Sign built in for execution and a Microsoft Word add-in for redlining. The vendor describes the integration model rather than just listing logos, stating that integration is connect-and-execute, that Leah does not replicate data passively, and that it executes work across connected systems through the orchestration layer, which is a meaningful architectural claim. What was not reached on 31 Aug 2026 is depth: the dedicated integrations page was not opened, and nothing read states what syncs in which direction or what a customer must configure. No document management integration such as iManage or NetDocuments appears, consistent with an in-house rather than law firm product.
Integrations are asserted at platform level with no documentation an implementer could use. The vendor describes connecting intake, negotiation, workflow and repository intelligence in one platform, and a Collaborate product exists for working with counterparties, and third party sources reference Microsoft Word and Outlook working surfaces. What was not located on the vendor's own property as of 29 Aug 2026, after checking the platform pages, the technology page, the security page and the resources index, is any integrations page, any named connector for document management, contract lifecycle, e signature, CRM or ERP, and any description of what an integration moves or what an administrator configures. For an enterprise platform sold to procurement and finance functions, that absence is notable.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The tenancy model is addressed directly and the regions are not. Single-tenant deployment is stated to be available for customers with strict data isolation requirements, and beyond that the vendor offers what it calls a dedicated zero-trust private environment within Azure OpenAI Studio, described as ensuring complete data isolation from all other customers, which tells a buyer both that the default is shared and that a separated option exists. The infrastructure is identified as Azure, with encryption keys held in Azure Key Vault. Two things hold this at B, checked 31 Aug 2026. Data residency is addressed only in the abstract, with the vendor saying it supports the residency and regulatory requirements typical of large multinational enterprises and naming no region, no jurisdiction and no customer-selectable option. And nothing states where processing happens as distinct from where data is stored, which matters on a platform that routes work dynamically across multiple model providers.
Deployment model is stated clearly with partial residency detail. Three things are published and specific: a dedicated single tenant AWS instance per customer with complete isolation, deployment within the customer's own environment as an alternative to the hosted option, and backup to a secondary AWS data centre within the same region, which confirms data stays in region. The vendor states AWS global infrastructure provides a solution tailored to geographic requirements. What is missing is the list: no named available regions, no statement of which regions a customer may select, and no statement of where processing happens as distinct from where data is stored. The single tenant and on premises options are genuinely stronger than most of this index.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
A long list of frameworks with no scope, no date, no auditor and no report, and the property contradicts itself on what is held. The AI governance page claims SOC 1 Type I and II, SOC 2 Type I and II, GDPR compliant, CCPA compliant, HIPAA ready and ISO 27001 aligned. The home page FAQ, on the same property, says only that Leah is SOC 2 Type II certified. Credit where it is due: the hedged wording is honest, since the page says aligned and ready rather than certified for ISO 27001 and HIPAA, and most vendors blur exactly that line. But the substance an attestation is judged on is missing entirely. The auditor is identified only as an independent Managed Security Service Provider, which is a category rather than a name; no coverage period or report date is given; no audit scope is described; penetration testing is said to be regular with no partner named and no summary published; and no trust centre or portal exists anywhere on the property, so there is no route to request a report either. Checked 31 Aug 2026.
Certification is real and stated with correct nouns, short of accessible evidence. ISO 27001:2022 is named with its version and described as certification, and the SOC 2 Type 2 language is precise: the vendor says successful completion of a SOC 2 Type 2 examination assessing controls related to security, availability and confidentiality, which is the correct noun for SOC 2 and names the trust services criteria in scope. That is more careful phrasing than most vendors on this index manage. Regular independent third party penetration testing is stated. A named external security advisory board including a former Director General of MI5 and two former Darktrace executives is published with full biographies. What is missing is the evidence route: no trust portal was located, no report is downloadable or requestable through a published flow, and no coverage period, report date or auditor name was located as of 29 Aug 2026. A security standards white paper is published, which is the nearest thing to an evidence route.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Amended 2 September 2026 under R42, after the Master Terms and Annexes v3.0c were read in full. The original note recorded that nothing committed the vendor to notifying customers when the provider set or the models change; that is withdrawn. DPA clause 4.3 requires a new subprocessor to be added to the published list and the customer notified at least thirty days before it processes any customer personal data, and clause 4.4 gives a thirty day objection right on reasonable data protection grounds, with termination of the affected order and a refund of prepaid unused fees if the objection cannot be resolved. The provider set is also larger than first recorded. The DPA Setup Page names four model providers rather than two, each listed against Leah Functionality with a parenthetical that no customer data is stored or retained by that provider and each with named jurisdictions: Anthropic PBC across the USA, Japan and the EU or UK; OpenAI LLC across the USA, Japan and the EU or Switzerland; Cohere Inc. across Canada, the USA, the EU or UK and Japan; and Google AI/ML alongside Google Cloud across the USA, Japan and the EU, Switzerland or UK. Microsoft Azure Services is separately listed for data hosting and translation, and the private deployment option remains identified as Azure OpenAI Studio. The grade does not move, and the limb that holds it is unchanged: no model or version is named for any of the four providers, and naming the house is not naming the model. The architectural disclosure problem also stands and is sharper with four providers than with two. The platform is described as dynamically selecting across multiple advanced language models to match each task to the right model, and as allowing customers to extend or customise models, so which provider handled a given piece of legal work remains unknowable to the buyer from anything published.
The supply chain is partly disclosed and the architecture is described in more depth than most. The vendor publishes that it runs a multi model Panel of Judges combining foundation, fine tuned and proprietary models, that it continuously evaluates and selects the best model per task, and that its own model Luna Crescent is deployed inside its own AWS environment. It states the supply chain consequence explicitly and in the customer's terms: owning the model reduces reliance on external model providers, limits data exposure to additional subprocessors, and protects customers from third party availability, pricing and access disruption. Hosting is named as AWS. What is not published is which foundation models sit in the panel, from which providers, or which tasks route to them, and no subprocessor list or change notification commitment was located as of 29 Aug 2026. A buyer therefore knows the shape of the chain and its own model, but not the third party links in it.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. Searched the home page, the AI governance page, the full primary navigation covering platform, solutions, resources and company, and the complete footer sitemap on 31 Aug 2026. There is no pricing page, no tier structure, no per-seat, per-contract or per-agent unit, no volume banding, and no indication of what implementation adds. Every call to action across the property is to request a demo. The closest the vendor comes is an implementation FAQ stating that timelines vary with scope and integrations and that a detailed plan is built during evaluation, which is a statement about effort rather than cost. Nothing published would let a prospective buyer form any view of price before entering a sales process.
Checked the site navigation, the platform and solution pages, the customers page, the about section and the footer on 29 Aug 2026. No pricing page exists on the property, no rate is published, no unit of charge is stated and no tier structure appears. Every commercial path terminates in a demo request. No free trial or self serve entry point was located, and no third party pricing figure was located either.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is documented precisely across two dimensions and the boundaries are never stated. By industry the vendor publishes dedicated pages for CPG and manufacturing, energy and utilities, financial services, healthcare, and pharma and medical devices, and describes its customers as Fortune 500 enterprises in regulated industries. By function it publishes pages for legal leadership, legal operations, sales and revenue, procurement, and finance, with distinct propositions written for the General Counsel, the contract operations team, the Chief Procurement Officer and the finance leader. The customer roster evidences that spread rather than merely claiming it, spanning banking, airlines, pharmaceuticals, consumer goods and engineering. What is absent is the far edge. No statement identifies which practice areas, contract types or matters the platform does not support, nothing addresses smaller organisations, and law firms appear only indirectly through managed service partners rather than as a served segment. Checked 31 Aug 2026.
Who the product serves is documented precisely across two dimensions, each with its own published pages. Six industries: manufacturing, financial services, pharmaceutical, technology, insurance and chemical. Eight business functions: legal, compliance, executive, sales, procurement, finance, human resources and marketing. Both law firms and corporate legal departments are addressed, with a stated base of more than 700 organisations across more than 70 countries including all four Big Four consultancies and named enterprises. An academic programme is published as a separate segment. The practice boundary is clear from the structure and consistent throughout: this is contract work end to end, from generation through negotiation to post execution analysis and investigation, and nothing on the property claims litigation or research capability it does not have.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The security FAQ on the home page states that customer contract data is never used to train models, and the AI governance page reinforces it, naming data leaking into models the customer does not own as a failure it engineered out and stating that zero data retention is the only acceptable answer, enforced against the named providers so that data is processed but never stored by OpenAI or Anthropic. Amended 2 September 2026.
The original summary recorded that no agreement could be retrieved; that is withdrawn, because the Master Terms and Annexes v3.0c have now been read in full. The value does not move, and the reason is worth stating for a reader. No term in the agreement names training, model training, machine learning or model improvement in relation to customer content, either to permit it or to prohibit it. Two clauses bear on it without reaching it.
Clause 5.1 confines the provider's access to and use of Customer Data to providing and maintaining the Cloud Service, Support and Professional Services. Clause 5.4 reserves a right to use Usage Data, defined as the provider's technical logs, data and learnings about the customer's use, to operate, improve and support the service, and expressly excludes Customer Data from that definition, so the improvement permission runs to telemetry rather than to content.
Read together they are consistent with a prohibition on training without stating one, and whether model improvement falls inside providing and maintaining the service is precisely the question they leave open. The commitment recorded here therefore rests on the published policy statement rather than on a located contractual term. Version note: v3.0c is the version that renders; v4.0 of January 2026 sits behind a viewer that could not be rendered, and the vendor states the only change is the trading name.
Public material states that platform-derived customer content trains the model. The vendor's press release of 17 February 2022 states that its AI has been exposed to more than 100 million documents, that it is also learning from the interactions between humans and the documents, and that it learns from every NDA or supplier agreement negotiated within Luminance, every clause that causes an M&A transaction to fall apart and every piece of data culled during eDiscovery; the May 2023 Ask Lumi release repeats that the Legal Pre-Trained Transformer learns solely from legally verified documents, now put at more than 150 million.
No aggregation, anonymisation or de-identification qualifier is stated, and nothing published says whether a customer can decline or whether learning from one customer's negotiations is confined to that customer. The published terms and conditions and privacy policy, read at the original build, carry no matching term in either direction. The statement is dated and the vendor's current pages describe the corpus without repeating the learning-from-customers sentence, which is recorded as age rather than withdrawal.
Amended 6 September 2026 from silent, on the basis that a vendor statement of what its model learned from is a stated position rather than an absence.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Row completed 2 September 2026 under R26 from the Master Terms and Annexes v3.0c, read in full. A specific period is published and the customer cannot vary it: section 14.4 provides for export during the subscription term and deletion of Customer Data within sixty days of request after termination, subject to a carve-out for standard backup or record retention policies and legal requirements. The data processing addendum tightens it, requiring deletion in accordance with industry-standard secure deletion practices at clause 8.2 with a certificate of deletion on request, and Schedule 1 commits to export in CSV or similar format within thirty calendar days and physical destruction of media by a recognised provider.
What is absent is any prompt-specific or output-specific window: the agreement governs Customer Data as a class, defined at section 23 as any data, content or materials the customer submits to its accounts, so prompts and outputs inherit that regime rather than having one of their own. One layer sits outside it and a buyer should see it. Section 5.4 permits the provider to collect Usage Data, defined as its technical logs, data and learnings about the customer's use but expressly excluding Customer Data, and to use it to operate, improve and support the service and for other lawful business purposes including benchmarking and reports, with external disclosure only where de-identified and aggregated across customers.
No deletion obligation attaches to Usage Data anywhere in the agreement, and section 14.5 makes 5.4 survive termination.
Retention is acknowledged and partly quantified without a period for the primary system. The security FAQ states each customer instance is backed up nightly to a secondary AWS data centre in the same region, encrypted, and kept for a minimum of 14 days, which is a real published figure and a floor a buyer can plan against. What was not located as of 29 Aug 2026 is any retention period for documents, prompts or outputs in normal operation, any customer control over that window, or any deletion commitment. A minimum backup retention states how long data persists after deletion rather than how long it is held.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Separation is asserted at customer level and offered as an architecture rather than a control. The vendor states that single-tenant deployment is available for customers with strict data isolation requirements, and that a dedicated zero-trust private environment within Azure OpenAI Studio ensures complete isolation from all other customers, with role-based access control stated to be enforced at every layer. What that wording also establishes is that isolation is a deployment option rather than the default, and nothing published describes how customers are separated in the standard shared deployment.
Nothing addresses boundaries inside a customer either, which matters on a platform where legal, procurement, finance and shared services teams work in the same system. Searched the home page and the AI governance page on 31 Aug 2026; the privacy statement could not be retrieved.
The product maintains its own documented permission model and documents it more thoroughly than any other record on this index. Between customers, isolation is architectural: a dedicated single tenant instance each, stated to ensure complete isolation with no co mingling of data. Inside a customer, the vendor publishes division level permissions administered by the customer under least privilege, role based configuration, customer configurable password and session timeout policy, and a statement that vendor staff cannot view customer documents without explicit authorisation given through the interface, with all access tracked and audited.
Division level permissions are the nearest published equivalent to a wall. Recorded at the own model value rather than the positive one because no document management integration was located whose permissions retrieval could inherit at query time, and because conflicts and ethical walls are not addressed as such.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Row completed 2 September 2026 under R26 from the Master Terms and Annexes v3.0c, read in full. Section 19, headed Required Disclosures, permits the recipient to disclose Confidential Information to the extent required by law and then commits, where law permits, to the quoted advance notice plus reasonable cooperation at the discloser's expense to obtain confidential treatment for the information. Two features make this stronger than it first reads.
The clause says Confidential Information including Customer Data in terms, so customer material is inside the notice obligation rather than needing to be argued into it, and section 23 confirms that the customer's Confidential Information includes Customer Data. And the obligation is reciprocal, binding whichever party receives the demand. Section 14.5 makes section 19 survive termination. It is not the top value because no transparency report was located: nothing published records how many demands have been received or how they were answered.
Version note: v3.0c is the readable version; the current v4.0 of January 2026 sits behind a viewer that could not be rendered, and the vendor states the only change is the new trading name.
Searched the published terms and conditions, the privacy policy, the security page and its FAQ, and the security standards white paper entry point on 29 Aug 2026. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. Noted for a future reader: the single tenant and on premises deployment options materially change what a vendor could produce in response to such a request, but the vendor does not make that argument in published material and it is not recorded as a value here.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The working corpus is the customer's own material and is identified as such: the vendor states that Leah operates against the customer's policies and playbooks, gains intelligence from the customer's unstructured data and business rules, and answers contract questions from the customer's repository with sources attached. Alongside that it refers to Leah operating against established legal precedents, which names no source, no jurisdiction, no database and no rights basis.
The product manages a customer's contracts rather than retrieving primary law, so the usual coverage question does not arise in full, but the precedent reference is unsupported by any provenance statement. No update cadence is published for anything.
The corpus here is contract and legal document data underpinning a proprietary model rather than primary law, and it is quantified in detail without being sourced. Published: more than 220 million verified legal documents the platform has been exposed to over a decade, a curated training selection spanning roughly 3.4 million legal concepts and data points, breadth described as spanning virtually every industry including complex agreements, difficult file formats and obscure drafting styles, and a separate benchmark corpus of 189,000 manually annotated data points.
What is not published is where any of it came from or on what rights basis it was assembled. Trade coverage notes that many documents in the training base were not publicly disclosed. Recorded at the weakest value because scale and character are described while the source and licence basis are not.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Searched the home page and the AI governance page in full, together with the complete navigation and footer sitemap, on 31 Aug 2026. Nothing addresses whether legal authority is checked for subsequent history, and no citator, treatment signal or currency check was located. The platform manages contracts, obligations and procurement workflows rather than retrieving case law, so a citator is not part of what it sells. Worth recording alongside that: the vendor refers to Leah operating against established legal precedents without identifying any source, so the one place primary authority is invoked carries no verification mechanism.
Searched the site, the six platform product pages, the technology page and the resources index on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is a contract lifecycle product whose grounding is contract language and the customer's own precedent rather than case law, so a citator is largely outside its design.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Searched the home page and the AI governance page in full on 31 Aug 2026. No explicit no-answer or abstention path is documented and no confidence or grounding score was located. The governance loop does produce rejections, with approvals, escalations and rejections applied automatically according to the customer's rules, but those are policy outcomes decided by configured guardrails rather than the model declining to answer because it cannot ground a response.
Nothing published states what Leah does when the customer's own contract set or playbook does not cover the question in front of it.
The vendor documents abstention behaviour as an explicit design objective, which is the first time this signal has recorded anything above an absence on this index. Published: the proprietary model is trained to prioritise faithful extraction from source documents, and where information is not present it is designed to identify that absence rather than invent an answer, with the vendor stating this is what instils trust for legal professionals.
Vendor material separately describes flagging what is absent as well as what is present as a capability advantage. Recorded at the documented value rather than the demonstrable one because no published evaluation of the abstention behaviour itself was located as of 29 Aug 2026: the ContractIQ Bench results address interpretation accuracy rather than refusal rate.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, searched on both the current product name and the former company name ContractPodAi, alongside 2026 sanctions trackers and trade press summaries.
This is a statement about the public record on the date shown rather than a clearance, and it is bounded by what that database covers. The platform runs commercial contracting and procurement work rather than producing court filings, so its output does not ordinarily reach a brief.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one.
This is a statement about the public record on the date shown and not a clearance. Note that this is a contract lifecycle product rather than a litigation or research tool, so its output is unlikely to reach a court filing as cited authority, and note that the database is weighted toward US filings while this vendor is UK founded and operates across 70 plus countries.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Searched the home page, the AI governance page and the complete navigation and footer sitemap on 31 Aug 2026. No engagement with any bar or ethics guidance was located, including ABA Formal Opinion 512, US state bar guidance, and Solicitors Regulation Authority or Law Society material despite the company being headquartered in London and selling into legal departments across North America, Europe, Asia and Australia.
The compliance material published is regulatory and security-framework oriented, covering GDPR, CCPA, HIPAA, SOC and ISO, and none of it addresses the professional conduct obligations that bind the lawyers using the product.
Searched the site, the insights and white papers indexes, the press releases and the resources hub on 29 Aug 2026. No engagement with any named ethics opinion or professional guidance was located, including ABA Formal Opinion 512, US state bar guidance, and Solicitors Regulation Authority or Law Society guidance given the company's UK base. The vendor publishes substantial thought leadership on AI reliability, including a piece arguing that human in the loop alone is insufficient, which engages with the professional risk question in substance while naming no guidance a buyer is bound by.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials are framed around cost and time removed, and quantified at portfolio level: a 91 per cent cut in contract review time, more than 18 million dollars of revenue protected, more than 2 million dollars of tracked savings, and headline figures of more than 125 billion dollars of commercial value managed and more than 10 billion dollars of ROI impact delivered. Searched the home page and the AI governance page on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee purposes and no published guidance on billing, fee or client disclosure treatment.
The immutable per-action audit log the vendor describes could in principle support such a record, but nothing presents it for that purpose. The buyer is an in-house function rather than a firm billing a client, so the question lands on internal cost and outside counsel spend, and neither is addressed.
Savings are claimed with nothing published on the client's side of the equation. The recurring published claim is negotiation time reduced by up to 90 percent, alongside speed framing throughout including a stated four times faster generation than generalist tools. Searched the site, the platform pages, the customers page and the resources index on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment. The vendor sells to law firms as well as corporate teams, so the firm side of that question applies.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
Amended 2 September 2026 under R42. The original summary, written 31 August 2026, recorded that no subprocessor list of any kind existed and that the data processing agreement, if published, sat behind a legal page that could not be retrieved. Both statements are withdrawn: the Master Terms and Annexes v3.0c render in full at the URL above, and the DPA is Annex B of that same document. All three limbs are now met. The DPA Setup Page carries a full subprocessor list with purpose, location and the product each is used in, running to ABBYY OCR SDK, Anthropic PBC, Cohere Inc., DocuSign or Adobe, Google AI/ML and Google Cloud, Jitterbit, Microsoft Azure Services, OpenAI LLC, QlikTech, Sendgrid, ZOHO, Zuva and four ContractPod group entities.
The model providers are named directly rather than inferred, with Anthropic, OpenAI, Cohere and Google AI/ML each listed against Leah Functionality, each carrying a parenthetical that no Customer Data is stored or retained by that provider, and each with named jurisdictions. And the forwardable artifact exists in the Bonterms DPA itself, published ungated as part of the same PDF, with EU Standard Contractual Clauses Modules 2 and 3 incorporated, the UK International Data Transfer Addendum for UK transfers, Schedule 1 setting out the processing details a client would ask for, and a Specified Notice Period for security incidents of 48 hours, which is tighter than the 72 hours most of this corpus publishes.
Clause 4.3 commits to adding a new subprocessor to the list and notifying at least 30 days before it processes anything, with an objection right at 4.4 and termination with refund if the objection cannot be resolved. The private deployment environment identified on the vendor's AI governance page as Azure OpenAI Studio remains part of the picture. Version note: v3.0c is the version that renders; v4.0 of January 2026 sits behind a viewer that could not be rendered, and the vendor states the only change is the trading name.
Substantial security material is published openly, including a detailed security FAQ, named certifications, a named external security advisory board and a security standards white paper, all reachable without a sales conversation. But the specific artifacts this signal turns on were not located as of 29 Aug 2026: no subprocessor list, no statement of which model providers see customer content, and no client facing consent or notification pack a firm could forward to its own client.
The vendor does state that owning its model limits data exposure to additional subprocessors, which is an argument about the shape of the chain rather than a disclosure of it. Recorded as not addressed because no list exists to point to.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
The strongest partial record read in this pull, missing one element. The audit stage of the published governance loop logs every decision with what the agent did, why, against which policy, with what data, and what the outcome was, in records the vendor describes as tamper-resistant, immutable and ready for any audit. That covers the action, the governing rule, the inputs and the result at per-action granularity. The missing element is the model: the platform selects dynamically across multiple LLMs per task and no model or version is identified anywhere, so which system produced a given passage cannot be established from the record.
No export designed for a court disclosure or AI-use certification was located, and the audit framing throughout is regulatory and internal rather than judicial. Checked 31 Aug 2026.
Searched the site, the platform product pages, the technology page and the security page on 29 Aug 2026. Vendor material states outputs are traceable and that all data access is tracked and audited, so elements of an access trail exist. But no per document export covering model used, sources retrieved and human verification together was located, and the model used would be difficult to state in any case given the Panel of Judges architecture routes tasks across multiple models.
Noted for context: this is a contracting product rather than a litigation product, so a judicial AI disclosure order is less likely to reach its output.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- Commercial Transparency
- Good Law Verification
- Bar Guidance Alignment
Which one fits
Choose Leah if
- You need the allocation of loss on paper before you sign. Leah's master terms set a general cap at the fees paid in the twelve months before the first incident, an enhanced cap at three times that figure where the security clause or the data processing addendum is breached, enumerate uncapped claims covering indemnification, intellectual property and confidentiality, and add a customer indemnity, a warranty with a thirty day correction period and published uptime tiers of 99.00, 99.5 and 99.9 per cent with termination and refund. On Luminance the index located no cap figure, no output warranty and no indemnity running to the customer, which matters more than usual because that product negotiates with counterparties on the customer's behalf.
- The training question has to be answered no. Leah's security FAQ states that customer contract data is never used to train models, and its governance page commits to zero retention with its named providers so that data is processed but never stored by them. Luminance's own press material states that its model learns from the negotiations conducted inside the platform, and the index located no training prohibition anywhere in its material, which is a conspicuous absence for a vendor that trains its own model on a corpus it puts at 220 million legal documents.
- You want to know who is in the chain and to hear about it when it changes. Leah's data processing addendum names Anthropic, OpenAI, Cohere and Google AI/ML with the jurisdictions for each, requires a new subprocessor to be added to the published list at least thirty days before it processes customer personal data, and gives a thirty day objection right with termination and refund of prepaid fees. Luminance names AWS and its own Luna model, and does not publish which foundation models sit in the Panel of Judges, from which providers, or which tasks route to them.
Choose Luminance if
- Isolation and location are hard requirements. Every Luminance customer receives a dedicated single tenant instance with complete isolation and no co mingling of data, deployment inside the customer's own environment is offered as an alternative to the hosted option, backups run nightly to a secondary AWS data centre in the same region, encrypted and kept a minimum of fourteen days, and vendor staff cannot view customer documents without explicit authorisation granted through the interface, with all access tracked and audited. Leah's default is shared, with single tenancy available for customers with strict isolation requirements.
- You want an accuracy claim you can at least argue with. Luminance publishes ContractIQ Bench, a benchmark of 189,000 manually annotated and reviewed data points assessing interpretation of named provision types including liability caps, termination for convenience and confidentiality obligations, tested on held out documents and concepts excluded from training with blind evaluation by legal experts alongside, and it states that the model is trained to prioritise faithful extraction and to identify absence rather than invent an answer. Leah asserts that every action is measured against benchmarks for accuracy, bias and outcome and publishes no figure, method or cadence at all.
- The buyer is not only the legal team. Luminance publishes dedicated pages for six industries and eight business functions including compliance, procurement, finance, human resources and marketing, serves both law firms and corporate departments, and is consistent throughout about where its boundary sits, which is contract work end to end rather than litigation or research. That is the axis where this index grades it A and Leah B: Leah documents its industry and function coverage well but never states the far edge, and reaches law firms only indirectly through managed service partners.
In summary
Leah
Leah is an agentic platform for contracting, legal, procurement and finance at large enterprises, sold by ContractPod Technologies of London and formerly known as ContractPodAi. It runs multiple large language models selected dynamically per task, with Anthropic, OpenAI, Cohere and Google AI/ML named as providers in its data processing addendum under zero retention terms, and wraps them in a published governance loop: the customer defines which agents may act, on which data and within which thresholds, and every action is logged with its rationale, the governing policy and the outcome. The AI Legal Index grades it in the top two bands on eleven of fifteen capability axes, strongest on autonomy and oversight and on AI liability and recourse, where the master terms publish a general cap at twelve months of fees, an enhanced cap at three times that figure and an enumerated list of uncapped claims. As of 2 September 2026 the index located no published price, no accuracy figure and no named model version.
Luminance
Luminance is a contract lifecycle platform covering generation, negotiation, analysis, compliance and investigation, founded in Cambridge in 2015 by mathematicians and sold to legal, compliance, executive, sales, procurement, finance, human resources and marketing functions across more than 700 organisations in over 70 countries. It runs a multi model architecture it calls a Panel of Judges, in which several models analyse each clause independently and reach consensus, and in June 2026 it introduced Luna Crescent, its own legal intelligence model deployed inside its own AWS environment. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes, with A grades on AI centrality and on firm and practice coverage, and it is one of the few vendors in this index to publish a benchmark at all: ContractIQ Bench, built on 189,000 manually annotated and reviewed data points and tested on held out documents. As of 29 August 2026 the index located no published price, no absolute accuracy rate and no training prohibition on customer content.
Questions buyers ask
Are Leah and Luminance alternatives to each other?
Yes, more directly than most pairs on this index. Both are filed under contract review and drafting, both are enterprise platforms covering the contract from intake through negotiation to post execution analysis, both are sold to procurement and finance alongside legal, and both are headquartered in the United Kingdom. They diverge on architecture rather than on scope. Luminance builds and hosts its own legal model and gives each customer a single tenant instance. Leah orchestrates four named third party providers underneath a policy layer the customer configures. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 14, 2026. No vendor pays for placement.
Does Luminance train its model on customer contracts?
Its own published material says the model learns from work done inside the platform. A press release of 17 February 2022 states that the AI learns from every NDA or supplier agreement negotiated within Luminance, every clause that causes an M&A transaction to fall apart and every piece of data culled during ediscovery, and the Ask Lumi release of May 2023 repeats that its legal model learns solely from legally verified documents, then put at more than 150 million. No aggregation or anonymisation qualifier is attached, nothing published says whether a customer can decline or whether learning from one customer's negotiations is confined to that customer, and the index located no matching term in the published terms and conditions or privacy policy in either direction. Those statements are dated and the current pages do not repeat them, which this index records as age rather than withdrawal. Leah, by contrast, states that customer contract data is never used to train models. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 14, 2026. No vendor pays for placement.
Which one publishes more about liability?
Leah, by a wide margin, and it is one of very few vendors in this index to publish the allocation of loss with figures. Its master terms set a general cap at the amounts paid in the twelve months before the first incident, an enhanced cap at three times that figure for breach of the security clause or the data processing addendum, and list uncapped claims covering indemnification, intellectual property and confidentiality, with a customer indemnity, a warranty carrying a thirty day fix period and published uptime tiers with termination and refund. Luminance publishes its terms and conditions openly, which earns credit, but the index located no cap figure, no indemnity for third party claims arising from output, no warranty on output and no insurance position. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 14, 2026. No vendor pays for placement.
Which one can be deployed inside our own environment?
Luminance. It offers deployment within the customer's own environment as an alternative to the hosted option, and every hosted customer receives a dedicated single tenant AWS instance with complete isolation and no co mingling of data. Leah's default is shared, with single tenant deployment available for customers with strict isolation requirements and a separate dedicated private environment offered within Azure OpenAI Studio. Neither publishes a list of available regions or a customer selectable residency option, and neither states where processing happens as distinct from where data is stored. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 14, 2026. No vendor pays for placement.
What do Leah and Luminance both leave unpublished?
Price, the advice line and privilege. Neither publishes a rate, a tier structure or a unit of charge, so every commercial path on both properties ends at a demo request. Neither states where the tool stops and legal advice begins, and neither names a bar or ethics authority, which is a live question for both given each is marketed to procurement, finance and other functions well outside the legal department. Neither addresses legal professional privilege or work product directly. And neither names the specific models or versions behind a given piece of work, Leah because it routes dynamically across four providers and Luminance because it does not publish which foundation models sit in its panel. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 14, 2026. No vendor pays for placement.
Three things to weigh. Both vendors assert measurement and only one publishes a number, and that number is thinner than it looks: Luminance reports 5 per cent higher accuracy than leading general purpose models on contract understanding, with no absolute rate and no comparator named, so a reader cannot tell what it is 5 per cent better than, and the benchmark is proprietary with no sample tasks or rubric published. Leah states that every agent action is measured against benchmarks for accuracy, bias and outcome and publishes nothing behind it. Second, the training record on Luminance rests on dated vendor statements, a press release of 17 February 2022 and the Ask Lumi release of May 2023, and its current pages describe the corpus without repeating the sentence about learning from customer negotiations, which this index records as age rather than withdrawal. Third, both readings hit a retrieval limit. On Leah the version read is v3.0c of the master terms, because the current v4.0 sits behind a viewer that would not render. On Luminance no integrations page, trust portal or downloadable report was located, so two low grades there record what could not be found rather than what the vendor refused. Leah was verified on 2 September 2026 and Luminance on 29 August 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.