Leah vs Sirion: how they compare in 2026

L
Leah profile
S
Sirion profile
Last verifiedOctober 8, 2026

Leah and Sirion have both sold contract software since 2012, and both now carry agent layers, the Agentic OS at Leah and agentOS at Sirion. Both sell to procurement and finance as well as to legal, yet each publishes a different half of the story. Leah documents how its agents are governed. The customer sets which agents act, on which data and where they escalate, and every action is logged with its rationale. Sirion says its agents act autonomously, with the user in control for strategic exceptions. Its governance page names a program and sends readers to an account executive. Sirion documents how it connects instead. Nine connectors are described by direction of travel, including SAP Ariba, Oracle ERP and Microsoft Dynamics. Leah names SAP, NetSuite and Coupa without that detail. On training the documents differ. Sirion's terms let its systems process customer data to inform machine learning, with no opt out. Leah says customer contracts never train models, and it names its model providers where Sirion names none.

At a glance

Category
LeahContract Review & Drafting
SirionContract Review & Drafting
Founded
Leah2012
Sirion2012
Headquarters
LeahLondon, United Kingdom
SirionLehi, Utah, United States
Last verified
LeahOct 8, 2026
SirionOct 8, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Leah
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

Leah sells AI agents and an orchestration layer that sit on top of a contract lifecycle platform, and that platform works without them. The vendor describes it the other way round. It says other vendors bolted AI onto systems built for manual workflows, while Leah was designed from scratch with orchestration as the foundation. ContractPod Technologies has sold contract lifecycle management since 2012. Leah launched in March 2023 as an AI services hub within that platform, went standalone in May 2023, and Leah Intelligence followed in October 2024. Without the agents, the product is still a working CLM with guided intake, approval routing, DocuSign and Adobe Sign execution and a contract repository. That CLM has its own market and its own Gartner category placement. The orchestration layer on top is model driven.

Sirion
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

Sirion's contract lifecycle platform came before its AI, and the company has traded since 2012. The product is organized as Store, Create and Manage, covering repository, drafting, approval, negotiation, obligation tracking and performance management. Without the agents and agentOS, a working enterprise CLM remains, and Gartner classifies it as one. The models drive the capability Sirion now sells on top of it. Agents are described as extracting and normalizing contracts, assembling first drafts from a playbook, proposing redlines on the other side's paper and monitoring obligations. Customers can also build and deploy their own agents in agentOS.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Leah
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Leah returns to accuracy repeatedly in its materials, and the AI governance page says every action is measured against benchmarks for accuracy, bias and outcome. Neither that page nor the home page publishes a result from that measurement. They give no accuracy figure, no error or hallucination rate, no description of any benchmark or test set and no published evaluation. The product material describes a legal helpdesk that answers contract questions with sources attached, so a user can in principle check an answer against its source. Neither page says what the system does when the customer's own contracts do not support a position.

Sirion
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

A specific grounding claim runs through Sirion's material. Answers are described as carrying citations linked to the customer's own data, and vendor material states that every AI generated response includes citations linked to exact sources, with citation and justification at clause level. Five percentage figures are published prominently, and each measures speed or coverage rather than correctness. They are 90 percent faster centralization, 85 percent faster insights, up to 90 percent faster time to contract, 99 percent on time obligation compliance and 70 percent faster agentic automation. The home page and the trust center, with its AI ethics, compliance and security sections, give no accuracy figure, error or hallucination rate, test set or published evaluation. They do not say what the system does when the customer's contract set does not support an answer.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Leah
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a lawyer checks it are all published: modes, thresholds, review surfaces, and the route a matter takes back to human judgment. A categorical limit on a named mode or tier, stating what its output may not be used for, meets the threshold limb without a number.

Leah's dedicated AI governance page sets out a three stage control loop. In the first stage, policy in, the customer defines which agents may act, on which data, within which thresholds and where escalation is required. Those policies are held as configuration rather than code. In the second, execution governed, every agent action runs through those policies in real time. Approvals, escalations and rejections are applied automatically, and the orchestrator enforces guardrails at each step. In the third, audit out, every decision is logged with the rationale, what the agent did, why, under which policy, on what data and to what outcome. The records are described as tamper resistant and immutable. The loop sets the thresholds, the review points and the route back to human judgment. Leah's home page puts the position in one line, that the workflow runs itself while the judgment stays human. The page does not say what happens after an output is found to be wrong. Default modes are not described, because the customer configures the guardrails rather than receiving them preset.

Sirion
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Agents are said to sense intent, reason over enterprise data and act autonomously. They draft and propose redlines, monitor obligations, surface gaps, alert owners and drive follow through. Sirion's one published statement on oversight is that the user stays in control for strategic exceptions. Its published material does not say what an agent completes without a human, the point at which it stops and escalates, where review happens, or what happens after an output is wrong. Customers can build, test and deploy agents in agentOS, which suggests guardrails can be configured, though no control structure is documented.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Leah
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Leah publishes qualitative quotes from four named people. Noelle Perkins is EVP and Chief Legal Officer at Cushman and Wakefield, and Lidia Kamleh is Chief Legal Officer at Dubai Future Foundation. Frances Bain-Cumberbatch is Chief Legal and External Affairs Officer at Ansa McAL, and Zillia Knight is Senior Legal Officer at Terumo Europe. Three results are published with the customer unnamed. A major American logistics company cut contract review time by 91 percent. A global manufacturer protected more than $18 million of revenue, and an American retail REIT tracked more than $2 million of savings. About 54 enterprise logos appear, including Philips, MUFG, Sandoz, Pernod Ricard, Alaska Airlines and Wood PLC. PwC and KPMG appear among them. PwC entered a commercial alliance in March 2024, and Epiq resells Leah in its Service Cloud. Integreon is quoted as an early adopter that resells it, and Pinsent Masons adopted it for managed legal services in July 2025. Partners and customers are shown together without distinction, and the Chief Product Officer of Execo, another services partner, is among the testimonials.

Sirion
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Three customer representatives speak on the record with their roles and employers. Edzard Janssen is Chief Procurement Officer at RBI. Reinhard Plaza-Bartsch is Head of Digital Supply Chain and Operations at Vodafone. Angella Dikmic is Manager of IT Vendor Management at GTAA. All three quotes are qualitative, and all three people work in procurement or vendor management rather than legal. The five percentage claims name no customer and read as product capabilities, so named customers and published figures are never paired. About 25 enterprise logos appear, including Citi, GE, Coca-Cola, Chevron, PayPal, Bayer, Rolls-Royce, Aramco, Yamaha, DP World and Zalando. Customers are in more than 70 countries, with more than $450 billion of contract value under management. Sirion also publishes a case study library.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Leah
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Leah says customer contract data is never used to train models. The AI governance page treats data leaking into models the customer does not own as a failure it engineered out. It says zero data retention is the only acceptable answer, and that Leah enforces zero retention with OpenAI and Anthropic so they process data but never store it. Encryption is AES-256 at rest and TLS in transit, with keys in Azure Key Vault, rotated and reachable only through controlled service accounts. Role based access control is said to apply at every layer, and single tenant deployment is offered for customers with strict isolation needs. Leah sells to Fortune 500 legal departments, and none of this material addresses privilege or work product.

Sirion
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Vendor library articles say customer data stays within the customer environment and is not used to train external language models. Clause 4.2 of the SaaS Terms, version 6, modified 26 August 2026, says otherwise. It reserves a right for Sirion to have its automated systems review and process Customer Data to generally inform machine learning capabilities in the services. None of the published agreements offers an opt out, and the agreement, not the library articles, is what binds. The rest of the confidentiality framework is published and can be read before signing. The data processing addendum stores and processes all customer data in a Sirion application instance specific to the customer. It sets Article 32 technical and organizational measures, with AES-256 at rest and TLS 1.2 in transit. It imposes need to know and least privilege access with automatic logout, requires deletion within 30 days of termination, and commits to notifying the customer of a confirmed security incident within 72 hours. Section 5 of the SaaS Terms adds mutual confidentiality, with a duty to give prior notice of any authority or court demand so the other party can object. The published agreements and trust center do not address privilege or work product.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Leah
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Leah publishes nothing on the line between a tool and legal advice. Its site carries no disclaimer of any kind and no ethics or professional responsibility page, and it names no bar or ethics guidance, including ABA Formal Opinion 512. The platform is sold to run legal work end to end across legal, procurement and finance teams. In the vendor's own framing, agents carry out commercial work in several steps without routing every decision through a person.

Sirion
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

The platform is sold to procurement, sales and finance teams as well as in house legal, all working on the same contracts. The three customer referees Sirion features are procurement and vendor management leaders, not lawyers. The home page, the trust center index with its AI ethics, compliance and security sections, and the terms and policies index say nothing on where tooling ends and legal advice begins. There is no statement that Sirion does not give legal advice, no professional responsibility or ethics page, no named bar or ethics guidance, including ABA Formal Opinion 512, and no jurisdiction limits.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Leah
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

A dedicated AI governance page names six failure modes the vendor says it engineered out. They include black box decisions that cannot be defended to a regulator or board, and compliance frameworks retrofitted after the fact. Against them the page sets three pillars and a loop of policy, execution and audit. Each action is logged with its rationale and governing policy, in records described as tamper resistant and immutable. The page also says every action is measured against benchmarks for accuracy, bias and outcome, and that accountability is structural rather than aspirational. It names no person or role accountable for model behavior and describes no testing before release. It gives no benchmark method or schedule and discloses no bias measurement result.

Sirion
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

The trust center has a section titled Artificial Intelligence Ethics and Governance, last modified 16 December 2025, and its whole content is three sentences. They say Sirion has set up an AI Governance Program called S-AIGP, which monitors and ensures compliance with the EU AI Act 2024/1689 and other AI regulations as they emerge. Readers are told to contact their Sirion Account Executive for more. Sirion publishes nothing on who owns model behavior, what is tested before release, how the program works, or bias and uneven output.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Leah
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

The AI governance page describes TLS in transit and AES-256 at rest. Encryption keys are managed in Azure Key Vault, rotated regularly and reachable only through tightly controlled service accounts. The page also lists multifactor authentication, secure API gateways, network segmentation, real time monitoring and a documented incident response plan. Audit logs are described as comprehensive, tamper resistant and immutable. For outside assurance, the vendor says an independent Managed Security Service Provider audits it every year and that it is penetration tested regularly.

Sirion
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

The data processing addendum, version 3, modified 2 July 2026, covers retention, access, subprocessors, incidents and encryption. Appendix B sets the retention period by the controller's contractual direction. Clause 8.1 requires deletion or return of all Customer Personal Data, including copies, within 30 days of termination. Any retention the law requires is limited to that purpose and stays under the agreement's protections, and the SaaS Terms add automatic deletion after 30 days as a backstop. Access runs on a need to know and least privilege basis, with automatic logout on inactivity. Subprocessors are named in a list published at its own URL. Sirion gives notice and an objection right for any addition or replacement, imposes equivalent terms on each, and is liable for their breaches. Clause 4.3 commits Sirion to notify the customer within 72 hours of establishing material impact from a confirmed Security Incident, and Appendix B says 48 to 72 hours, with updates until resolved. The definition expressly excludes unsuccessful attempts such as failed logins and denial of service attempts. Encryption is AES-256 at rest and TLS 1.2 in transit.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Leah
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

Section 16.5 of the Master Terms and Annexes sets a General Cap equal to fees paid or payable in the twelve months before the first incident. An Enhanced Cap of three times that applies to breaches of its security or data protection terms, meaning the security clause and the data processing addendum. Indemnities, intellectual property claims, breach of confidentiality and anything that cannot legally be limited are uncapped. Section 17.1 gives the customer an indemnity against third party intellectual property claims. Section 8.2 warrants that the service will perform materially as documented, with a thirty day fix period under 8.3 and termination with a refund if the fix fails. Annex A publishes uptime tiers of 99.00, 99.5 and 99.9 percent by support plan. A tier missed in three consecutive months, or in four months out of six, allows termination with a refund. Three limits apply. Breaches of confidentiality involving Customer Data fall outside the uncapped claim, so they stay capped and rise to the Enhanced Cap only where the security or data protection terms are also breached. The agreement gives no indemnity for AI output, such as inaccurate output, hallucination or training data provenance. Section 9.2 bars the customer from submitting Sensitive Data, including GDPR Article 9 categories, and the provider disclaims liability for it. These terms are version 3.0c. Version 4.0, dated 4 January 2026, changes only the trading name, according to the vendor.

Sirion
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

Sirion publishes its SaaS terms and a separate end user agreement, so both can be read before signing. Clause 7.1 commits Sirion to indemnify and defend the customer against third party claims that use of the services infringes intellectual property. Clause 7.2 sets four exclusions, namely combination with materials Sirion did not provide, unapproved changes, unauthorized use, and use inconsistent with the documentation. Clause 7.3 gives the remedies of securing the right to continue, replacing or modifying the services, or terminating with a pro rata refund of prepaid fees, as Sirion's sole and exclusive liability. Clause 7.4 has the customer indemnify Sirion over customer data. Clause 8.1 caps each party's total liability, across the whole term, at the fees paid for the subscription in the twelve months before the first event giving rise to a claim. Clause 8.2 excludes lost profits, lost or damaged data and consequential loss, and under clause 8.3 the cap does not apply to fees owed, breach of confidentiality or the indemnities. Clause 6.2 warrants that the services perform materially in line with the documentation, with a pro rata refund if Sirion cannot correct a nonconformity reported within ten days. Separate Sirion AI Services terms extend the intellectual property indemnity to the AI features, but exclude claims that come from the customer failing to review or validate output. Section 5.1 of those terms disclaims any warranty that output is accurate or free from hallucinations. No insurance position is published.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Leah
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Leah names its integrations and describes each by function. They cover ERP platforms including SAP and NetSuite, procurement systems including Coupa, financial systems, identity providers including Okta, and existing contract lifecycle tools. DocuSign and Adobe Sign are built in for signing, and a Microsoft Word add in handles redlining. The vendor also describes how the integrations work. It says Leah connects and executes rather than copying data passively, and carries out work across connected systems through the orchestration layer. Leah has a dedicated integrations page, but publishes nothing on what syncs in which direction or what a customer must configure. No document management integration such as iManage or NetDocuments appears, which fits a product built for in house teams rather than law firms.

Sirion
AA on Practice Systems Integration DepthDocumented, verifiable integrations into the systems legal work already lives in, with the depth described: what syncs, in which direction, and what a firm must configure.

Nine named connectors are documented, each with its direction of travel, in the Non-Native Integrations article in Sirion University, last updated 24 February 2026. Four SAP Ariba accelerators cover procurement, bids, awards and contract workspaces. An executed contract request in Sirion creates a purchase requisition in Ariba, and the resulting purchase order is written back. Ariba sourcing events and RFPs become Contract Draft Requests on set triggers, one per bidding supplier with line items mapped, and supplier redlines move into Sirion for legal review. Awarded RFx events create a draft request with awarded line items synced. Contracts finalized in Sirion copy into Ariba Contract Workspaces with metadata, documents, line items and status. Three more connectors cover supplier master data from Ariba, SAP S/4HANA Business Partners on scheduled transfers, and Oracle ERP with logging, error handling and sync status. The Microsoft Dynamics connector runs both ways in auto or manual mode. The article describes configuration through triggers, modes and scheduling rather than as a full guide, and the wider Sirion University catalog needs a login. Sirion's public pages do not document the Word add in or the Salesforce connector to this depth. No document management connector such as iManage or NetDocuments appears on them.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Leah
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

The standard deployment is shared. Single tenant deployment is available for customers with strict isolation requirements. The vendor also offers what it calls a dedicated zero trust private environment in Azure OpenAI Studio, described as fully isolating data from all other customers. Leah runs on Azure, with keys held in Azure Key Vault. On data residency the vendor says only that it supports the residency and regulatory needs typical of large multinational enterprises. It names no region or jurisdiction and describes no customer choice.

Sirion
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Sirion's application is SaaS hosted by a cloud provider, according to the data processing addendum, and all customer data is stored and processed in a Sirion application instance specific to that customer. That isolation commitment sits in a contract rather than in marketing. Four underlying providers appear in the trust center, namely AWS, Azure, Oracle and IBM, which suggests customer choice without offering it as an option. Sirion's published documents make no residency commitment and give no region list or jurisdiction option. Nothing separates where processing happens from where data is stored. A Sirion library article describes the platform's multitenant scalability, which sits awkwardly beside the addendum's customer specific instance, and nothing published reconciles the two.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Leah
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

The AI governance page claims SOC 1 Type I and II, SOC 2 Type I and II, GDPR compliance, CCPA compliance, HIPAA readiness and ISO 27001 alignment. The home page FAQ, on the same site, says only that Leah is SOC 2 Type II certified, so the two pages disagree on what is held. For ISO 27001 and HIPAA the governance page says aligned and ready rather than certified. The auditor is described only as an independent Managed Security Service Provider, a category rather than a named firm. No coverage period, report date or audit scope is given. Penetration testing is said to be regular, with no partner named and no summary published. Leah has no trust center or portal, so there is no published route to request a report.

Sirion
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Appendix B of the data processing addendum names ISO 27001 as a held certification and describes the review process around it. Under clause 7.1, unless agreed otherwise, Sirion will give a copy of its latest security attestation report on the customer's written request, no more than once a year. Clause 7.2 adds a customer audit right, with scope, timing and controls agreed in advance and a reasonable fee. Appendix B also says Sirion reviews its cloud providers' SOC 1, SOC 2 and ISO 27001 reports as part of a shared responsibility model. That is oversight of the infrastructure rather than an attestation over the application. The report route is open to existing customers, so a prospective customer cannot get the report before signing. The addendum names no auditor, coverage period or scope statement for the ISO certificate. Sirion's trust center states ISO 27001:2022 certification. Its SOC 1 Type II and SOC 2 Type II sections explain what those reports cover, and its security page attributes SOC 1 and SOC 2 to the cloud providers Sirion runs on.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Leah
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

The DPA Setup Page lists four model providers against Leah Functionality, each noted as storing or retaining no customer data and each with named jurisdictions. Anthropic PBC is listed for the USA, Japan, and the EU or UK, and OpenAI LLC for the USA, Japan, and the EU or Switzerland. Cohere Inc. is listed for Canada, the USA, the EU or UK, and Japan. Google AI/ML with Google Cloud is listed for the USA, Japan, and the EU, Switzerland or UK. Microsoft Azure Services is listed for hosting and translation, and the private deployment option runs in Azure OpenAI Studio. DPA clause 4.3 requires any new subprocessor to be added to the published list with at least thirty days' notice before it processes customer personal data. Clause 4.4 gives a thirty day objection right on reasonable data protection grounds. If the objection is not resolved, the affected order can be terminated with a refund of prepaid unused fees. No model or version is named for any provider. The platform is described as choosing among several language models for each task and letting customers extend or customize models. Nothing published shows which provider handled a given piece of work.

Sirion
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

An approach built on multiple models sits behind Sirion's AI, combining small purpose built models trained on enterprise contracts with large language models. Sirion presents that as the differentiator against generic models retrofitted for legal use. It names no large language model provider and identifies no model or version. It gives no processing location for the model layer as distinct from the cloud infrastructure. Nothing commits Sirion to notifying customers when any of it changes.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Leah
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Leah publishes no pricing at any level, including the unit of charge. The primary navigation covers platform, solutions, resources and company, and neither it nor the footer sitemap has a pricing page. There is no tier structure, no unit per seat, contract or agent, no volume banding and no indication of what implementation adds. Every call to action across the site is to request a demo. An implementation FAQ says timelines vary with scope and integrations and that a detailed plan is built during evaluation. It says nothing about cost. No published page gives a view of price before a sales process.

Sirion
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing is published at any level, including the unit of charge. Sirion's site has no pricing page, no tier structure, no unit per seat, per contract or per agent, no volume banding and no statement of what implementation adds. Every call to action is a demo request. No published figure lets a prospective customer estimate cost before a sales process, even though Sirion publishes its SaaS terms, end user agreement and data processing addendum in full.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Leah
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Leah publishes dedicated industry pages for CPG and manufacturing, energy and utilities, financial services, healthcare, and pharma and medical devices. It describes its customers as Fortune 500 enterprises in regulated industries. By function it publishes pages for legal leadership, legal operations, sales and revenue, procurement, and finance. The pages carry distinct propositions written for the General Counsel, the contract operations team, the Chief Procurement Officer and the finance leader. The customer roster spans banking, airlines, pharmaceuticals, consumer goods and engineering. No published page says which practice areas, contract types or matters the platform does not support, and none addresses smaller organizations. Law firms appear only indirectly, through managed service partners, rather than as a served segment.

Sirion
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Eight industries have their own pages. Financial services is split into procurement and into capital markets and credit. Insurance has a separate solution for triaging underwriting submissions. The others are automotive, IT services, healthcare, pharmaceuticals and life sciences, telecom, and oil and gas. Five departments have their own pages, covering in house legal, legal operations, procurement, sales and finance. Customers are in more than 70 countries, and the site is in English, German and French. Sirion does not say where the product stops. It excludes no contract or matter types, does not address law firms, government or public sector use, and describes coverage by industry and department rather than area of law.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Leah
Never, in policy only

Leah's security FAQ, on its home page, says customer contract data is never used to train models. The AI governance page treats data leaking into models the customer does not own as a failure it engineered out. It says zero data retention is enforced so that OpenAI and Anthropic process data but never store it. No term in the Master Terms and Annexes v3.0c names training, model training, machine learning or model improvement for customer content, either way.

Two clauses come close. Clause 5.1 limits the provider's use of Customer Data to providing and maintaining the Cloud Service, Support and Professional Services. Clause 5.4 allows use of Usage Data, the provider's technical logs, data and learnings about the customer's use, to run, improve and support the service. Usage Data excludes Customer Data, so the improvement right covers telemetry, not content. Together the clauses fit a ban on training without stating one.

They leave open whether model improvement counts as maintaining the service. The commitment rests on the published policy, not a contract term. Version 4.0 of January 2026 changes only the trading name, according to the vendor.

Sirion
Permitted, in the contract

Library material from Sirion states that customer data stays within the customer environment and is not used to train external language models. Its SaaS Terms, version 6, modified 26 August 2026, reserve the opposite at clause 4.2. Sirion may direct its automated systems to review and process Customer Data to generally inform machine learning capabilities in the Subscription Services. The same clause covers generating aggregated and anonymized industry analytics, with a commitment not to publicly identify the customer or disclose Customer Data to third parties.

The agreement governs over a policy page, so the reservation is what binds the customer. It operates on Customer Data itself rather than on deidentified or aggregated derivatives, which gives it a broader reach than clauses limited to aggregate data. It says generally inform rather than train, so the words leave open whether it authorizes model training in the ordinary sense. The SaaS Terms, the end user agreement and the data processing addendum offer no opt out, consent step, configuration setting or exclusion route.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Leah
Disclosed fixed window

Section 14.4 allows export during the subscription and deletion of Customer Data within sixty days of a request after termination. That is subject to standard backup or record retention policies and legal requirements, and the customer cannot change the period. The data processing addendum adds secure deletion to industry standards at clause 8.2, with a certificate of deletion on request. Schedule 1 commits to export in CSV or a similar format within thirty calendar days and to physical destruction of media by a recognized provider.

Prompts and outputs have no separate window. The agreement treats Customer Data as one class, defined at section 23 as any data, content or materials the customer submits, so prompts and outputs follow that regime. Usage Data sits outside it. Section 5.4 lets the provider collect Usage Data, meaning its technical logs, data and learnings about the customer's use, excluding Customer Data. The provider may use it to run, improve and support the service and for other lawful purposes such as benchmarking.

It may disclose Usage Data externally only if deidentified and aggregated across customers. No deletion duty applies to Usage Data, and section 14.5 makes 5.4 survive termination.

Sirion
Customer controlled, no zero option

The published data processing addendum says the retention period is set by contractual obligations as the controller directs. After termination, personal data is typically kept for 30 days. The window is therefore under customer instruction, with a stated default, in a contract rather than a policy page. The provision covers personal data rather than prompts and generated outputs specifically, and no zero retention setting is offered.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Leah
Claimed, not documented

Leah describes separation at the customer level, through deployment options. The vendor states that single tenant deployment is available for customers with strict data isolation requirements. It says a dedicated zero trust private environment within Azure OpenAI Studio ensures complete isolation from all other customers. Role based access control is stated to be enforced at every layer. That wording makes isolation a deployment option rather than the default, and nothing published describes how customers are separated in the standard shared deployment.

Legal, procurement, finance and shared services teams work in the same system, and nothing published addresses boundaries between them inside a customer.

Sirion
Own model, documented

Separation between customers is set out in the data processing addendum rather than in marketing. All customer data is stated to be stored and processed in a Sirion application instance specific to the customer, within the cloud service. A shared responsibility model applies, in which Sirion secures the software, the customer data and the related access, and the cloud provider secures the underlying facility. Vendor library articles describe role based access control with granular permissions.

Sirion's published material does not describe how access is enforced between teams inside a customer, where legal, procurement, sales and finance share the platform. A Sirion library article also describes the platform's multitenant scalability, and nothing published reconciles that with the addendum's customer specific instance. The buyer is an in house department, so separation between customer tenants is what applies here.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Leah
Notice committed

Section 19, headed Required Disclosures, lets the recipient disclose Confidential Information where the law requires. Where the law permits, the recipient must give advance notice and reasonable cooperation, at the discloser's expense, to obtain confidential treatment. The clause expressly covers Confidential Information including Customer Data. Section 23 confirms that the customer's Confidential Information includes Customer Data, so customer material sits inside the notice duty.

The duty is mutual and binds whichever party receives the demand. Section 14.5 makes section 19 survive termination. Leah publishes no transparency report, so there is no public count of demands received or of how they were answered. These terms are version 3.0c. Version 4.0 of January 2026 changes only the trading name, according to the vendor.

Sirion
Notice committed

Section 5.3 of the SaaS Terms, version 6, modified 26 August 2026, holds the notice commitment. A party receiving a demand from an authority or court for the other party's Confidential Information may comply only after satisfying itself the demand is lawful. It must give as much prior notice as possible, where possible, so the other party can object, and mark the material as the other party's Confidential Information.

The duty is mutual and covers customer material. Confidential Information includes information that should reasonably be understood as confidential, and the AI Module clause at 1.8(b) confirms this by bringing Customer Data back into that definition. The notice duty is limited by the words where possible, not by a legal prohibition. The data processing addendum does not address third party demands. The terms pages, the addendum and the trust center give no transparency report or count of demands.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Leah
Sources named, basis unstated

Leah works on the customer's own material. The vendor states that Leah operates against the customer's policies and playbooks and gains intelligence from the customer's unstructured data and business rules. It answers contract questions from the customer's repository with sources attached. The vendor also refers to Leah operating against established legal precedents, but names no source, jurisdiction, database or rights basis for them.

The product manages a customer's contracts rather than retrieving primary law. No provenance statement backs the precedent reference, and no update cadence is published for anything.

Sirion
Sources named, basis unstated

The working corpus is the customer's own contract set. Answers are described as carrying citations linked to the customer's own data, and agents extract and normalize contracts from sources the customer nominates. Sirion separately states that its purpose built models are trained on millions of enterprise contracts. That describes a second corpus by its makeup, but Sirion names no source, states no license or rights basis, and does not say whose contracts those are.

The product does not retrieve primary law, so the usual questions of jurisdiction and coverage do not arise. No update cadence is published.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Leah
Not addressed

Leah describes no citator, treatment signal or currency check, and does not say whether legal authority is reviewed for later history. The platform manages contracts, obligations and procurement workflows rather than retrieving case law, so a citator is not part of what it sells. The vendor does refer to Leah operating against established legal precedents, without identifying any source. That is the one place the product invokes primary authority, and no verification step is described for it.

Sirion
Not addressed

The platform manages contracts, obligations and supplier performance rather than retrieving case law or legislation, so a citator is not part of what it sells. The home page, the trust center index with its AI ethics, compliance and security sections, and the terms and policies index do not address whether legal authority is reviewed for subsequent history. They describe no citator, treatment signal or currency check.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Leah
Not addressed

The home page and the AI governance page describe no explicit path for Leah to decline to answer or abstain, and no confidence or grounding rating. The governance loop does produce rejections. Approvals, escalations and rejections are applied automatically according to the customer's rules. Those are policy outcomes set by configured guardrails, not the model declining because it cannot ground a response. Neither page says what Leah does when the customer's own contract set or playbook does not cover the question in front of it.

Sirion
Not addressed

Agents that sense intent, reason over enterprise data and act autonomously are central to Sirion's material, along with answers delivered with citations. The home page and the trust center, with its AI ethics, compliance and security sections, do not say what happens when the customer's contract set does not support a response. They document no explicit no answer or abstention path and no confidence or grounding score.

Sirion's statement that users stay in control for strategic exceptions describes escalation rather than how the model behaves under uncertainty.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

Leah
None located

The AI Hallucination Cases database maintained by Damien Charlotin tracks decisions worldwide where a court addressed hallucinated AI content, and records the tool implicated where known. It records no court order, opinion or disciplinary record naming Leah or the former company name ContractPodAi. Published 2026 sanctions trackers and trade press summaries name neither. The platform runs commercial contracting and procurement work rather than producing court filings, so its output does not ordinarily reach a brief.

Sirion
None located

The AI Hallucination Cases database, maintained by Damien Charlotin, tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known. It records no court order, opinion or disciplinary record naming Sirion or SirionLabs, its former company name. Published 2026 sanctions trackers and trade press summaries do not name it either. The platform runs enterprise contracting and supplier governance rather than producing court filings.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Leah
Not addressed

Leah publishes nothing that engages with bar or ethics guidance. That includes ABA Formal Opinion 512, state bar guidance in the United States, and Solicitors Regulation Authority or Law Society material. The company is headquartered in London and sells into legal departments across North America, Europe, Asia and Australia. Its published compliance material covers regulation and security frameworks, namely GDPR, CCPA, HIPAA, SOC and ISO. None of it addresses the professional conduct obligations that bind the lawyers using the product.

Sirion
Not addressed

Sirion's compliance material is oriented to regulation and security frameworks, covering ISO 27001, SOC 1, SOC 2 and the EU AI Act. None of it addresses the professional conduct obligations binding the lawyers who use the product. The home page, the trust center index with its AI ethics, compliance and security sections, and the terms and policies index do not engage with any bar or ethics guidance. That includes ABA Formal Opinion 512 and any state bar or Law Society material.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Leah
Savings claims only

Leah frames its public materials around cost and time removed, quantified at portfolio level. It cites a 91 percent cut in contract review time, more than $18 million of revenue protected and more than $2 million of tracked savings. Its headline figures are more than $125 billion of commercial value managed and more than $10 billion of ROI impact delivered. No per matter record of AI assisted work for fee purposes is described, and no guidance on billing, fee or client disclosure treatment is published.

The vendor describes an immutable audit log of every action, which could in principle support such a record, but does not present it for that purpose. Leah sells to in house functions rather than firms billing clients, so the costs in play are internal cost and outside counsel spend. Its materials address neither.

Sirion
Savings claims only

Public materials are built around speed and automation gains. They cite 90 percent faster contract centralization, 85 percent faster insights, up to 90 percent faster time to contract and 70 percent faster agentic automation. A customer reports as much as a 50 percent rise in tasks automated. The home page, the trust center and the terms and policies index offer no record of AI assisted work by matter for fee purposes, and no guidance on billing, fee or disclosure treatment.

The buyer is an in house function rather than a firm billing a client, so fee disclosure here comes down to internal cost and outside counsel spend, and the published material addresses neither.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Leah
Subprocessors listed

The data processing agreement is Annex B of the Master Terms and Annexes v3.0c. The DPA Setup Page lists every subprocessor with its purpose, location and the product it serves. The list names ABBYY OCR SDK, Anthropic PBC, Cohere Inc., DocuSign or Adobe, Google AI/ML and Google Cloud, Jitterbit, Microsoft Azure Services, OpenAI LLC, QlikTech, Sendgrid, ZOHO, Zuva and four ContractPod group entities. Anthropic, OpenAI, Cohere and Google AI/ML are each listed against Leah Functionality as model providers, noted as storing or retaining no Customer Data, with named jurisdictions.

The DPA itself is the Bonterms DPA, published openly in the same PDF and ready to forward. It incorporates EU Standard Contractual Clauses Modules 2 and 3 and the UK International Data Transfer Addendum. It sets out processing details in Schedule 1 and fixes a 48 hour notice period for security incidents. Clause 4.3 commits to listing any new subprocessor and giving at least 30 days' notice before it processes anything.

Clause 4.4 gives an objection right, with termination and a refund if the objection is not resolved. Version 4.0 of January 2026 changes only the trading name, according to the vendor.

Sirion
Subprocessors listed

Appendix D publishes a Sub-Processor List, stated to be regularly updated, at a named URL that can be reached without a sales conversation. Clause 5.4 commits Sirion to notify the customer of updates and give an opportunity to object to additions or replacements. Clause 5.6 requires equivalent data protection terms on every subprocessor and keeps Sirion liable for their breaches. Sirion publishes no disclosure pack for a firm answering a client's AI clause, and no consent or notification material for clients.

Its published material names no model provider. The trust center's AI ethics page routes AI governance detail to a Sirion Account Executive.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Leah
Partial record

The audit stage of Leah's published governance loop logs every decision. Each entry records what the agent did, why, under which policy, with what data and with what outcome. The records are described as tamper resistant, immutable and ready for any audit. That gives the action, the rule, the inputs and the result for each action. The published description of the log does not include the model. The platform chooses among several language models for each task and identifies no model or version, so the log does not show which system produced a given passage.

No export built for court disclosure or AI use certification is described. The audit framing is regulatory and internal rather than judicial.

Sirion
Partial record

Answers are said to carry citations linked to the customer's own data. Vendor material says every AI response includes citations to exact sources, with citation and justification at clause level. Audit trails are said to record system activity, user actions and data changes. Together these cover the sources retrieved and part of what was done, as a side effect of the product's design. Sirion identifies no model, so its material does not show which system produced a passage, and it describes no export built for court disclosure or AI use certification. The product serves enterprise contracting rather than litigation, so court standing orders are not its usual setting.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • UPL and Professional Responsibility Posture
  • Commercial Transparency
Signals neither addresses in public material
  • Good Law Verification
  • Refusal and Uncertainty Behavior
  • Bar Guidance Alignment

Which one fits

Choose Leah if

  • You want agent control written down. Leah's customer sets which agents may act, on which data and where escalation is required. Each action is logged in records described as tamper resistant and immutable.
  • You want a stated no training policy. Leah says customer contract data is never used to train models, and it holds OpenAI and Anthropic to zero retention. Its master terms limit customer data to running the service.
  • You want liability terms with numbers. Leah's master terms set a general cap of a year of fees and an enhanced cap of three times that for breaches of its security or data protection terms. Uptime of up to 99.9 percent is published by support plan.

Choose Sirion if

  • Your contracts start and end in SAP Ariba or your ERP. Sirion's Ariba accelerators turn sourcing events into contract requests and push finished contracts back to Ariba. Further connectors cover SAP S/4HANA, Oracle ERP and Microsoft Dynamics.
  • You need isolation and incident terms in the contract. Sirion's data processing addendum keeps each customer's data in its own application instance. It deletes the data within 30 days of termination and notifies a confirmed incident within 72 hours of establishing material impact.
  • Your security team wants a route to the audit reports. Sirion's trust center states ISO 27001:2022 certification. Its addendum gives customers the latest attestation report on written request once a year, plus an audit right.

In summary

Leah

Leah, formerly ContractPodAi, runs contracting, procurement and finance work for large enterprises on top of a contract lifecycle product. That product covers intake, playbook review in Microsoft Word, approvals, built in signing and an obligation repository. Its Agentic OS assigns tasks to agents under the Leah Maestro orchestrator. The AI Legal Index records agent permissions, data scope and escalation as settings the customer controls, with each action logged against its policy. Leah's data processing pages name Anthropic, OpenAI, Cohere and Google with their jurisdictions, and its master terms publish liability caps with figures. No price or accuracy measure is published.

Source: AI Legal Index, 2026

Sirion

Sirion is an enterprise contract lifecycle platform in three product lines. Store handles extraction and search, Create handles drafting and negotiation, and Manage tracks obligations and supplier performance. Its agentOS layer lets customers build and run their own agents. It sells to legal, procurement and finance teams in eight named industries, with customers including Citi, GE and Chevron. According to the AI Legal Index, Sirion documents its ERP connectors by direction of travel, from SAP Ariba to Microsoft Dynamics. Its data processing addendum keeps each customer in its own application instance and commits to notice within 72 hours of establishing a confirmed incident's material impact. Clause 4.2 of its terms lets its systems process customer data to inform machine learning.

Source: AI Legal Index, 2026

Questions buyers ask

Leah vs Sirion: which CLM is better for procurement heavy teams?

Sirion documents the procurement plumbing. Its SAP Ariba, Oracle ERP and Microsoft Dynamics connectors are described by direction, and the customer references it features work in procurement and vendor management. Leah names SAP, NetSuite and Coupa without that depth, but sets out in detail how its agents are governed. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Does Sirion or Leah train AI on customer data?

Sirion's SaaS Terms let its automated systems process customer data to generally inform machine learning, with no opt out. That sits beside library material saying data is not used to train external models. Leah says customer contracts are never used to train models, and its terms confine customer data to running the service. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Which AI models do Leah and Sirion use?

Leah names four providers, Anthropic, OpenAI, Cohere and Google, with their jurisdictions, though not model versions. Sirion describes a mix of small models trained on enterprise contracts and large language models, without naming any provider or version. Both publish subprocessor lists with notice and an objection right. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Do Leah and Sirion show sources for AI answers?

Both point answers back to the customer's own contracts. Sirion says every AI response carries citations to exact sources at clause level, with a justification. Leah's legal helpdesk answers contract questions with sources attached. Neither publishes an accuracy figure or says what happens when the contracts on file do not support an answer. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

What do Leah and Sirion both leave unpublished?

Neither publishes a price, an accuracy or hallucination measure, or anything on attorney client privilege. Neither says where its agents stop short of legal advice or engages with ABA Formal Opinion 512. That matters because both sell to procurement, sales and finance teams who work on the same contracts as lawyers. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Disclosure

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything on it comes from public material on the dates shown. How the index grades.

Policy and contract pull in different directions here. Sirion's library material says customer data is not used to train external language models. Clause 4.2 of its SaaS Terms, version 6 of 26 August 2026, lets its automated systems process customer data to generally inform machine learning, with no opt out. The clause says inform rather than train, so its reach is open. Leah's promise never to train sits in policy, not in its master terms. Sirion also calls its platform multitenant in one article while its addendum promises a customer specific instance. Neither vendor reviewed this page.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
October 8, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746