Leah vs SpotDraft: how they compare in 2026

L
Leah profile
S
SpotDraft profile
Last verifiedOctober 8, 2026

These two sell contract lifecycle management to in house teams, but to different kinds of company. SpotDraft is built around the in house legal team, with industry pages for SaaS, HR tech and fintech and more than 30 integrations from Salesforce to Greenhouse. Leah aims at large regulated enterprises, with agents running contracting, procurement and finance work across SAP, NetSuite and Coupa. Each publishes what the other omits. SpotDraft is open about fit and cost. It names the California State Bar's guidance and ABA Formal Opinion 512. Customers choose a US, EU, India or Middle East region for personal data, and plans are priced by users or contract volume with setup included. Leah is open about its AI. It names four model providers, says customer contracts never train models, and runs agents under logged limits the customer sets. SpotDraft's home, pricing and security pages name no model and say nothing on training. On liability, Leah publishes enterprise caps with figures, while SpotDraft's published Terms of Use, reached from signup, carry a nominal cap.

At a glance

Category
LeahContract Review & Drafting
SpotDraftContract Review & Drafting
Founded
Leah2012
SpotDraft2017
Headquarters
LeahLondon, United Kingdom
SpotDraftNew York, New York, United States
Last verified
LeahOct 8, 2026
SpotDraftOct 8, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Leah
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

Leah sells AI agents and an orchestration layer that sit on top of a contract lifecycle platform, and that platform works without them. The vendor describes it the other way round. It says other vendors bolted AI onto systems built for manual workflows, while Leah was designed from scratch with orchestration as the foundation. ContractPod Technologies has sold contract lifecycle management since 2012. Leah launched in March 2023 as an AI services hub within that platform, went standalone in May 2023, and Leah Intelligence followed in October 2024. Without the agents, the product is still a working CLM with guided intake, approval routing, DocuSign and Adobe Sign execution and a contract repository. That CLM has its own market and its own Gartner category placement. The orchestration layer on top is model driven.

SpotDraft
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

SpotDraft is a full contract lifecycle system, with templates, conditional workflows and approvals, a shared editor, built in eSignature meeting ESIGN, eIDAS and ECA, a repository, reporting and analytics. Without SpotDraft AI, VerifAI, Intake and Sidebar, a working CLM with signature and workflow remains, and that CLM has its own market. The AI covers review inside Word, automatic extraction of more than a thousand metadata types, and agents that track regulatory change. SpotDraft now calls itself context aware, AI native CLM, though the platform predates that framing.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Leah
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Leah returns to accuracy repeatedly in its materials, and the AI governance page says every action is measured against benchmarks for accuracy, bias and outcome. Neither that page nor the home page publishes a result from that measurement. They give no accuracy figure, no error or hallucination rate, no description of any benchmark or test set and no published evaluation. The product material describes a legal helpdesk that answers contract questions with sources attached, so a user can in principle check an answer against its source. Neither page says what the system does when the customer's own contracts do not support a position.

SpotDraft
DD on Citation Accuracy and Hallucination DisclosureNothing published on accuracy or grounding for a product that produces legal assertions, or a bare claim that the system does not hallucinate.

SpotDraft's published figures measure speed and cost. It says contracts are reviewed 15 times faster with VerifAI, closings are twice as fast, cost is 65 percent lower and review takes 70 percent less time. The home, pricing and security pages give no accuracy figure, error or hallucination rate, benchmark, test set or evaluation. They do not describe how AI output is grounded in the customer's documents, or whether a user can trace a statement back to its source. SpotDraft says the AI works in the customer's own context and follows its rules, which describes setup rather than correctness.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Leah
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a lawyer checks it are all published: modes, thresholds, review surfaces, and the route a matter takes back to human judgment. A categorical limit on a named mode or tier, stating what its output may not be used for, meets the threshold limb without a number.

Leah's dedicated AI governance page sets out a three stage control loop. In the first stage, policy in, the customer defines which agents may act, on which data, within which thresholds and where escalation is required. Those policies are held as configuration rather than code. In the second, execution governed, every agent action runs through those policies in real time. Approvals, escalations and rejections are applied automatically, and the orchestrator enforces guardrails at each step. In the third, audit out, every decision is logged with the rationale, what the agent did, why, under which policy, on what data and to what outcome. The records are described as tamper resistant and immutable. The loop sets the thresholds, the review points and the route back to human judgment. Leah's home page puts the position in one line, that the workflow runs itself while the judgment stays human. The page does not say what happens after an output is found to be wrong. Default modes are not described, because the customer configures the guardrails rather than receiving them preset.

SpotDraft
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

SpotDraft's approval routing is conditional, with thresholds shown. In one example, approvals go to the Head of Finance below a deal value and to the CFO and CEO above it. Audit logs trace changes at contract level by both the customer and the counterparty, and every draft keeps its version history. Permissions are scoped by contract type, entity and department. SpotDraft's product and security pages do not describe control over the AI itself. They do not say what SpotDraft AI, VerifAI or the Sidebar agents do unattended, when a person must review model output, what agents can change without approval, or what happens when an output is wrong. SpotDraft says the AI follows the customer's rules, without describing the limits that implies.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Leah
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Leah publishes qualitative quotes from four named people. Noelle Perkins is EVP and Chief Legal Officer at Cushman and Wakefield, and Lidia Kamleh is Chief Legal Officer at Dubai Future Foundation. Frances Bain-Cumberbatch is Chief Legal and External Affairs Officer at Ansa McAL, and Zillia Knight is Senior Legal Officer at Terumo Europe. Three results are published with the customer unnamed. A major American logistics company cut contract review time by 91 percent. A global manufacturer protected more than $18 million of revenue, and an American retail REIT tracked more than $2 million of savings. About 54 enterprise logos appear, including Philips, MUFG, Sandoz, Pernod Ricard, Alaska Airlines and Wood PLC. PwC and KPMG appear among them. PwC entered a commercial alliance in March 2024, and Epiq resells Leah in its Service Cloud. Integreon is quoted as an early adopter that resells it, and Pinsent Masons adopted it for managed legal services in July 2025. Partners and customers are shown together without distinction, and the Chief Product Officer of Execo, another services partner, is among the testimonials.

SpotDraft
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

SpotDraft quotes eight in house lawyers by name, role and employer. Anna Claveria Brannan is Deputy General Counsel at IPSY. Susan Koenig is a former Senior Legal Operations Manager at Abnormal Security, and Micah Nessan a former General Counsel at Guideline. Reason Abajuo is VP of Legal and Corporate Affairs at Chaberton Energy, and Lizzy Gagan is Senior Legal Counsel at Beamery. Arzu Hasanova is Legal Counsel at Circularise, Aditi Kapoor is Director of Legal at Gameskraft, and Natasha Wilson is Head of Legal at SUN Mobility. Every quote is qualitative. The quantified claims name no customer. They are two times faster closings, 65 percent lower cost, 70 percent less review time and contracts reviewed 15 times faster.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Leah
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Leah says customer contract data is never used to train models. The AI governance page treats data leaking into models the customer does not own as a failure it engineered out. It says zero data retention is the only acceptable answer, and that Leah enforces zero retention with OpenAI and Anthropic so they process data but never store it. Encryption is AES-256 at rest and TLS in transit, with keys in Azure Key Vault, rotated and reachable only through controlled service accounts. Role based access control is said to apply at every layer, and single tenant deployment is offered for customers with strict isolation needs. Leah sells to Fortune 500 legal departments, and none of this material addresses privilege or work product.

SpotDraft
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

SpotDraft's security page says customer data is logically separated within shared, multitenant infrastructure. Each contract has its own encryption key in HashiCorp Vault backed by Google Cloud KMS, with AES-256 at rest and FIPS 140 certified encryption. Data is classified as public, company confidential, customer confidential or personal, and access follows least privilege with unique IDs. Third party vendors handling scoped data must follow confidentiality, audit and incident response rules. The home, pricing and security pages do not say whether customer contracts are used to train any model, by SpotDraft or a model provider. They publish no retention period for prompts or outputs and do not address privilege or work product. SpotDraft also links a trust center at trustcenter.spotdraft.com.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Leah
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Leah publishes nothing on the line between a tool and legal advice. Its site carries no disclaimer of any kind and no ethics or professional responsibility page, and it names no bar or ethics guidance, including ABA Formal Opinion 512. The platform is sold to run legal work end to end across legal, procurement and finance teams. In the vendor's own framing, agents carry out commercial work in several steps without routing every decision through a person.

SpotDraft
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

SpotDraft's home page says its AI features are designed with attention to the California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law, issued in November 2023. It also names the American Bar Association's Formal Opinion 512 on generative AI, issued in July 2024. Both appear with issuer and date on the home page rather than in a policy. The page does not address a lawyer's own competence and supervision duties or any limit on use by jurisdiction. It states attention to principles but does not map product behavior to specific duties, so it does not show which principle each control meets.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Leah
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

A dedicated AI governance page names six failure modes the vendor says it engineered out. They include black box decisions that cannot be defended to a regulator or board, and compliance frameworks retrofitted after the fact. Against them the page sets three pillars and a loop of policy, execution and audit. Each action is logged with its rationale and governing policy, in records described as tamper resistant and immutable. The page also says every action is measured against benchmarks for accuracy, bias and outcome, and that accountability is structural rather than aspirational. It names no person or role accountable for model behavior and describes no testing before release. It gives no benchmark method or schedule and discloses no bias measurement result.

SpotDraft
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

SpotDraft's security page describes a formal risk governance policy approved by management that defines an Enterprise Risk Management program. Periodic operational risk assessments feed management reports, with each risk rated, assigned an owner and tracked to treatment or acceptance. Privacy risk is assessed through vendor due diligence, and an information security team led by the Chief Technology Officer oversees the process. The policy does not cover model behavior. SpotDraft's published pages describe no testing before an AI release and no responsible AI framework. They do not address bias or uneven output across contract types, counterparties or populations.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Leah
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

The AI governance page describes TLS in transit and AES-256 at rest. Encryption keys are managed in Azure Key Vault, rotated regularly and reachable only through tightly controlled service accounts. The page also lists multifactor authentication, secure API gateways, network segmentation, real time monitoring and a documented incident response plan. Audit logs are described as comprehensive, tamper resistant and immutable. For outside assurance, the vendor says an independent Managed Security Service Provider audits it every year and that it is penetration tested regularly.

SpotDraft
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

SpotDraft's security page, last updated 17 October 2025, describes FIPS 140 certified encryption, AES-256 at rest, and a unique key per contract held in HashiCorp Vault backed by Google Cloud KMS. Primary and backup servers run on Google Cloud Platform in the Netherlands. Data is classified into four sensitivity tiers, and access follows least privilege, with unique IDs and enforced password rules. The page describes a documented business continuity and disaster recovery program, automated patching and ongoing tracking of known vulnerabilities in third party packages. It also lists regular threat modeling, independent penetration testers, and routine code analysis and vulnerability scans. A set incident response process is stated and refined through regular exercises. The page names no subprocessor, though it says fourth parties such as backup providers and subcontractors have no access to scoped systems or data. It publishes no retention period for customer content.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Leah
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

Section 16.5 of the Master Terms and Annexes sets a General Cap equal to fees paid or payable in the twelve months before the first incident. An Enhanced Cap of three times that applies to breaches of its security or data protection terms, meaning the security clause and the data processing addendum. Indemnities, intellectual property claims, breach of confidentiality and anything that cannot legally be limited are uncapped. Section 17.1 gives the customer an indemnity against third party intellectual property claims. Section 8.2 warrants that the service will perform materially as documented, with a thirty day fix period under 8.3 and termination with a refund if the fix fails. Annex A publishes uptime tiers of 99.00, 99.5 and 99.9 percent by support plan. A tier missed in three consecutive months, or in four months out of six, allows termination with a refund. Three limits apply. Breaches of confidentiality involving Customer Data fall outside the uncapped claim, so they stay capped and rise to the Enhanced Cap only where the security or data protection terms are also breached. The agreement gives no indemnity for AI output, such as inaccurate output, hallucination or training data provenance. Section 9.2 bars the customer from submitting Sensitive Data, including GDPR Article 9 categories, and the provider disclaims liability for it. These terms are version 3.0c. Version 4.0, dated 4 January 2026, changes only the trading name, according to the vendor.

SpotDraft
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

SpotDraft publishes its Terms of Use on its Legal Hub at legal.spotdraft.com. The published version is 2.3, last updated 21 February 2024, and five prior versions can be downloaded from the same page. Clause 8.3 caps SpotDraft's total liability, in contract or tort, at one hundred Indian rupees, roughly USD 1. Clause 8.2 excludes consequential, indirect and special damages, including loss of data and profits. Clauses 5.2 and 5.3 disclaim fitness for purpose and error free or uninterrupted use, and expressly waive the warranty of noninfringement. Clause 9 is an indemnity from the customer to SpotDraft only, and the document contains no vendor indemnity. Clause 5.5 disclaims liability for consequences of using the Platform, and 5.4 says SpotDraft gives no legal advice. Indian law governs, with exclusive jurisdiction in the courts at Bangalore. The contracting entity is Draftspotting Technologies Private Limited, with affiliates including Draftspotting Inc. These Terms of Use are the ones that apply at signup. Clause 11.8 contemplates added terms for other services, so an enterprise customer may sign a negotiated master agreement that is not published.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Leah
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Leah names its integrations and describes each by function. They cover ERP platforms including SAP and NetSuite, procurement systems including Coupa, financial systems, identity providers including Okta, and existing contract lifecycle tools. DocuSign and Adobe Sign are built in for signing, and a Microsoft Word add in handles redlining. The vendor also describes how the integrations work. It says Leah connects and executes rather than copying data passively, and carries out work across connected systems through the orchestration layer. Leah has a dedicated integrations page, but publishes nothing on what syncs in which direction or what a customer must configure. No document management integration such as iManage or NetDocuments appears, which fits a product built for in house teams rather than law firms.

SpotDraft
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

SpotDraft states more than 30 integrations and gives each its own page. Salesforce, HubSpot, Slack, Microsoft Word for desktop, Google Drive, DocuSign, Greenhouse, Google Forms, Jira and Zapier are all linked directly from the pricing page. VerifAI runs review inside Microsoft Word, and negotiation and redlining are described as working in Word, Slack or SpotDraft itself. One named customer credits the Word desktop editor with driving adoption. Single sign on covers Office 365, Google Workspace, Okta, Active Directory and custom SAML with zero touch provisioning. No document management integration such as iManage or NetDocuments appears, which fits a product built for in house teams rather than law firms.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Leah
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

The standard deployment is shared. Single tenant deployment is available for customers with strict isolation requirements. The vendor also offers what it calls a dedicated zero trust private environment in Azure OpenAI Studio, described as fully isolating data from all other customers. Leah runs on Azure, with keys held in Azure Key Vault. On data residency the vendor says only that it supports the residency and regulatory needs typical of large multinational enterprises. It names no region or jurisdiction and describes no customer choice.

SpotDraft
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

SpotDraft's customer data is logically separated within shared, multitenant infrastructure. The customer chooses where personal data is stored, from regions covering the United States, the EU, India and the Middle East, and the data is not sent outside them. Primary and backup servers are on Google Cloud Platform in the Netherlands, and Google Cloud Platform runs processing throughout. Encryption keys are held per contract in HashiCorp Vault backed by Google Cloud KMS. The regional commitment is written for personal data. SpotDraft does not say which region applies by default, or whether contract content follows the same rule as personal data.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Leah
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

The AI governance page claims SOC 1 Type I and II, SOC 2 Type I and II, GDPR compliance, CCPA compliance, HIPAA readiness and ISO 27001 alignment. The home page FAQ, on the same site, says only that Leah is SOC 2 Type II certified, so the two pages disagree on what is held. For ISO 27001 and HIPAA the governance page says aligned and ready rather than certified. The auditor is described only as an independent Managed Security Service Provider, a category rather than a named firm. No coverage period, report date or audit scope is given. Penetration testing is said to be regular, with no partner named and no summary published. Leah has no trust center or portal, so there is no published route to request a report.

SpotDraft
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Four compliance marks, for ISO, GDPR, HIPAA and AICPA SOC 2, appear on SpotDraft's home, pricing and security pages. Its home page lists them as ISO 27001, SOC 2 Type II, GDPR and HIPAA, and the footer on every page reads "An ISO/IEC 27001:2022 Certified Company". SpotDraft's help center lists its SOC 2 Type 2 and ISO 27001 reports with download links, and a March 2023 blog post announced the SOC 2 Type 2 result. SpotDraft also links a separate trust center at trustcenter.spotdraft.com. Outside the reports themselves, no auditor, coverage period, report date or scope is published for the SOC 2. Independent penetration testers are said to be used, but none is named and no summary is published.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Leah
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

The DPA Setup Page lists four model providers against Leah Functionality, each noted as storing or retaining no customer data and each with named jurisdictions. Anthropic PBC is listed for the USA, Japan, and the EU or UK, and OpenAI LLC for the USA, Japan, and the EU or Switzerland. Cohere Inc. is listed for Canada, the USA, the EU or UK, and Japan. Google AI/ML with Google Cloud is listed for the USA, Japan, and the EU, Switzerland or UK. Microsoft Azure Services is listed for hosting and translation, and the private deployment option runs in Azure OpenAI Studio. DPA clause 4.3 requires any new subprocessor to be added to the published list with at least thirty days' notice before it processes customer personal data. Clause 4.4 gives a thirty day objection right on reasonable data protection grounds. If the objection is not resolved, the affected order can be terminated with a refund of prepaid unused fees. No model or version is named for any provider. The platform is described as choosing among several language models for each task and letting customers extend or customize models. Nothing published shows which provider handled a given piece of work.

SpotDraft
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

SpotDraft describes its AI only as built into SpotDraft and working in the customer's own context. Its home, pricing and security pages name no model provider, model or version. They publish no subprocessor list and no commitment to notify customers of changes. The security page is otherwise detailed, naming HashiCorp Vault, Google Cloud KMS, JAMF, FileVault and BitLocker among its tools. SpotDraft also links a trust center at trustcenter.spotdraft.com.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Leah
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Leah publishes no pricing at any level, including the unit of charge. The primary navigation covers platform, solutions, resources and company, and neither it nor the footer sitemap has a pricing page. There is no tier structure, no unit per seat, contract or agent, no volume banding and no indication of what implementation adds. Every call to action across the site is to request a demo. An implementation FAQ says timelines vary with scope and integrations and that a detailed plan is built during evaluation. It says nothing about cost. No published page gives a view of price before a sales process.

SpotDraft
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

SpotDraft's pricing page says plans are priced either by users or by contract volume, which it frames as avoiding wasted spend. The page says in house implementation is always included, covering workflow and integration setup and migration of old contracts, with no extra fees and no outsourcing. Every customer gets a dedicated customer success manager and support around the clock at no extra cost. A six week implementation timeline is published, week by week. The page gives no rate, floor or currency, and every call to action is Get Pricing or a demo request.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Leah
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Leah publishes dedicated industry pages for CPG and manufacturing, energy and utilities, financial services, healthcare, and pharma and medical devices. It describes its customers as Fortune 500 enterprises in regulated industries. By function it publishes pages for legal leadership, legal operations, sales and revenue, procurement, and finance. The pages carry distinct propositions written for the General Counsel, the contract operations team, the Chief Procurement Officer and the finance leader. The customer roster spans banking, airlines, pharmaceuticals, consumer goods and engineering. No published page says which practice areas, contract types or matters the platform does not support, and none addresses smaller organizations. Law firms appear only indirectly, through managed service partners, rather than as a served segment.

SpotDraft
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

SpotDraft has dedicated pages for five buying teams, namely legal, sales, finance, HR and procurement. Legal is cast as the owner and the others as self serve users. Five industries also have their own pages, covering SaaS, HR tech, edtech, healthtech and fintech. Its home page names its audience as high performing in house legal teams. SpotDraft describes coverage by industry and internal function rather than by area of law. It does not address a law firm segment or government and public sector use, and names no contract types or matters as unsupported.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Leah
Never, in policy only

Leah's security FAQ, on its home page, says customer contract data is never used to train models. The AI governance page treats data leaking into models the customer does not own as a failure it engineered out. It says zero data retention is enforced so that OpenAI and Anthropic process data but never store it. No term in the Master Terms and Annexes v3.0c names training, model training, machine learning or model improvement for customer content, either way.

Two clauses come close. Clause 5.1 limits the provider's use of Customer Data to providing and maintaining the Cloud Service, Support and Professional Services. Clause 5.4 allows use of Usage Data, the provider's technical logs, data and learnings about the customer's use, to run, improve and support the service. Usage Data excludes Customer Data, so the improvement right covers telemetry, not content. Together the clauses fit a ban on training without stating one.

They leave open whether model improvement counts as maintaining the service. The commitment rests on the published policy, not a contract term. Version 4.0 of January 2026 changes only the trading name, according to the vendor.

SpotDraft
Terms silent

SpotDraft's home, pricing and security pages do not say whether customer contracts, prompts or outputs are used to train any model, by SpotDraft or by an underlying model provider. That includes the security page's data security, infrastructure security, product security and risk governance sections and its five question FAQ. SpotDraft says its AI is embedded in SpotDraft, operates in a context specific to the customer and follows the customer's rules.

It also calls the platform risk free AI on the customer's terms. None of these statements is a commitment about training. No model provider is named on those pages. SpotDraft also links a trust center at trustcenter.spotdraft.com.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Leah
Disclosed fixed window

Section 14.4 allows export during the subscription and deletion of Customer Data within sixty days of a request after termination. That is subject to standard backup or record retention policies and legal requirements, and the customer cannot change the period. The data processing addendum adds secure deletion to industry standards at clause 8.2, with a certificate of deletion on request. Schedule 1 commits to export in CSV or a similar format within thirty calendar days and to physical destruction of media by a recognized provider.

Prompts and outputs have no separate window. The agreement treats Customer Data as one class, defined at section 23 as any data, content or materials the customer submits, so prompts and outputs follow that regime. Usage Data sits outside it. Section 5.4 lets the provider collect Usage Data, meaning its technical logs, data and learnings about the customer's use, excluding Customer Data. The provider may use it to run, improve and support the service and for other lawful purposes such as benchmarking.

It may disclose Usage Data externally only if deidentified and aggregated across customers. No deletion duty applies to Usage Data, and section 14.5 makes 5.4 survive termination.

SpotDraft
Not addressed

Retention appears on SpotDraft's security page only as a heading, paired with data classification under its data handling practices. The text describes classification into public, company confidential, customer confidential and personal tiers, without saying how long anything is kept. Secure data disposal is listed among the data center measures, with no period attached. The home, pricing and security pages publish no retention period for contracts, prompts or generated outputs, and describe no retention setting the customer can configure.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Leah
Claimed, not documented

Leah describes separation at the customer level, through deployment options. The vendor states that single tenant deployment is available for customers with strict data isolation requirements. It says a dedicated zero trust private environment within Azure OpenAI Studio ensures complete isolation from all other customers. Role based access control is stated to be enforced at every layer. That wording makes isolation a deployment option rather than the default, and nothing published describes how customers are separated in the standard shared deployment.

Legal, procurement, finance and shared services teams work in the same system, and nothing published addresses boundaries between them inside a customer.

SpotDraft
Own model, documented

SpotDraft's security page states that customer data is logically separated within a secure multitenant infrastructure. Each contract is also protected with a unique encryption key held in HashiCorp Vault backed by Google Cloud KMS, which separates data more finely than the tenant alone. Within a customer, roles and permissions are described as fully customizable and scoped by contract type, organizational entity and department.

Permissions at contract level keep documents visible only to authorized personnel without manual sharing. SpotDraft does not publish how retrieval and the AI features apply those permissions at query time, or whether a model answering a question respects the same boundaries. SpotDraft sells to in house departments, and its separation works at tenant and entity level.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Leah
Notice committed

Section 19, headed Required Disclosures, lets the recipient disclose Confidential Information where the law requires. Where the law permits, the recipient must give advance notice and reasonable cooperation, at the discloser's expense, to obtain confidential treatment. The clause expressly covers Confidential Information including Customer Data. Section 23 confirms that the customer's Confidential Information includes Customer Data, so customer material sits inside the notice duty.

The duty is mutual and binds whichever party receives the demand. Section 14.5 makes section 19 survive termination. Leah publishes no transparency report, so there is no public count of demands received or of how they were answered. These terms are version 3.0c. Version 4.0 of January 2026 changes only the trading name, according to the vendor.

SpotDraft
Not addressed

SpotDraft's home, pricing and security pages do not say what happens if a third party, law enforcement agency or court requests customer data, and publish no commitment to notify the customer. SpotDraft publishes no transparency report. The security page says third party vendors handling scoped data are bound by confidentiality, audit and incident response protocols. It says fourth parties such as backup providers and subcontractors have no access to scoped systems or data. Neither statement addresses compelled disclosure.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Leah
Sources named, basis unstated

Leah works on the customer's own material. The vendor states that Leah operates against the customer's policies and playbooks and gains intelligence from the customer's unstructured data and business rules. It answers contract questions from the customer's repository with sources attached. The vendor also refers to Leah operating against established legal precedents, but names no source, jurisdiction, database or rights basis for them.

The product manages a customer's contracts rather than retrieving primary law. No provenance statement backs the precedent reference, and no update cadence is published for anything.

SpotDraft
Sources named, basis unstated

SpotDraft's AI works on the customer's own contract set. The repository is described as centralizing all of a customer's contracts and automatically pulling over a thousand types of contract metadata using AI. The AI is described as operating in a context specific to the customer and following the customer's rules. SpotDraft claims no external legal corpus, and the product does not retrieve primary law. No training corpus for the models themselves is described. No source is named and no license or rights basis is given.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Leah
Not addressed

Leah describes no citator, treatment signal or currency check, and does not say whether legal authority is reviewed for later history. The platform manages contracts, obligations and procurement workflows rather than retrieving case law, so a citator is not part of what it sells. The vendor does refer to Leah operating against established legal precedents, without identifying any source. That is the one place the product invokes primary authority, and no verification step is described for it.

SpotDraft
Not addressed

SpotDraft's home, pricing and security pages describe no citator, treatment signal or currency check, and do not say whether legal authority is reviewed for later history. The platform manages a customer's own contracts rather than retrieving case law or legislation, so a citator is not part of what it sells. Sidebar is described as helping users stay ahead of regulatory change with AI agents. That concerns the currency of regulation rather than the standing of cited authority, and no source or verification method is published for it.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Leah
Not addressed

The home page and the AI governance page describe no explicit path for Leah to decline to answer or abstain, and no confidence or grounding rating. The governance loop does produce rejections. Approvals, escalations and rejections are applied automatically according to the customer's rules. Those are policy outcomes set by configured guardrails, not the model declining because it cannot ground a response. Neither page says what Leah does when the customer's own contract set or playbook does not cover the question in front of it.

SpotDraft
Not addressed

SpotDraft describes its AI as operating in the customer's context and following the customer's rules. Its home, pricing and security pages document no path for declining to answer and publish no confidence or grounding rating. They do not say what the product does when the customer's contract set or playbook does not cover the question put to it. The published material addresses configuration rather than uncertainty.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

Leah
None located

The AI Hallucination Cases database maintained by Damien Charlotin tracks decisions worldwide where a court addressed hallucinated AI content, and records the tool implicated where known. It records no court order, opinion or disciplinary record naming Leah or the former company name ContractPodAi. Published 2026 sanctions trackers and trade press summaries name neither. The platform runs commercial contracting and procurement work rather than producing court filings, so its output does not ordinarily reach a brief.

SpotDraft
None located

The AI Hallucination Cases database maintained by Damien Charlotin tracks decisions worldwide where a court addressed hallucinated AI content, and records the tool implicated where known. It records no court order, opinion or disciplinary record naming SpotDraft. Published 2026 sanctions trackers and trade press summaries do not name it either. The product manages commercial contracts for in house teams rather than producing court filings, so its output does not ordinarily reach a brief.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Leah
Not addressed

Leah publishes nothing that engages with bar or ethics guidance. That includes ABA Formal Opinion 512, state bar guidance in the United States, and Solicitors Regulation Authority or Law Society material. The company is headquartered in London and sells into legal departments across North America, Europe, Asia and Australia. Its published compliance material covers regulation and security frameworks, namely GDPR, CCPA, HIPAA, SOC and ISO. None of it addresses the professional conduct obligations that bind the lawyers using the product.

SpotDraft
Named guidance addressed

SpotDraft's home page names two ethics guidance documents from two jurisdictions. One is the California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law, dated November 2023. The other is the American Bar Association's Formal Opinion 512 on generative AI, dated July 2024. Both are given with issuer and date. SpotDraft says its AI is designed around both, for responsible and secure contracting. The statement does not map which duty each product control meets, and no other jurisdiction's guidance is addressed.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Leah
Savings claims only

Leah frames its public materials around cost and time removed, quantified at portfolio level. It cites a 91 percent cut in contract review time, more than $18 million of revenue protected and more than $2 million of tracked savings. Its headline figures are more than $125 billion of commercial value managed and more than $10 billion of ROI impact delivered. No per matter record of AI assisted work for fee purposes is described, and no guidance on billing, fee or client disclosure treatment is published.

The vendor describes an immutable audit log of every action, which could in principle support such a record, but does not present it for that purpose. Leah sells to in house functions rather than firms billing clients, so the costs in play are internal cost and outside counsel spend. Its materials address neither.

SpotDraft
Savings claims only

SpotDraft frames its public materials around speed and cost removed. It cites two times faster closings, 65 percent lower cost, 70 percent less review time, and contracts reviewed 15 times faster with VerifAI. The home, pricing and security pages publish no record of AI assisted work for each matter for fee purposes, and no guidance on billing, fee or disclosure treatment. SpotDraft describes contract level audit logging that traces changes by both the creator and the counterparty and retains every version.

That log could support such a record, but SpotDraft does not present it for that purpose. SpotDraft sells to in house departments rather than firms billing clients, so the relevant cost is internal, and its materials do not address it.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Leah
Subprocessors listed

The data processing agreement is Annex B of the Master Terms and Annexes v3.0c. The DPA Setup Page lists every subprocessor with its purpose, location and the product it serves. The list names ABBYY OCR SDK, Anthropic PBC, Cohere Inc., DocuSign or Adobe, Google AI/ML and Google Cloud, Jitterbit, Microsoft Azure Services, OpenAI LLC, QlikTech, Sendgrid, ZOHO, Zuva and four ContractPod group entities. Anthropic, OpenAI, Cohere and Google AI/ML are each listed against Leah Functionality as model providers, noted as storing or retaining no Customer Data, with named jurisdictions.

The DPA itself is the Bonterms DPA, published openly in the same PDF and ready to forward. It incorporates EU Standard Contractual Clauses Modules 2 and 3 and the UK International Data Transfer Addendum. It sets out processing details in Schedule 1 and fixes a 48 hour notice period for security incidents. Clause 4.3 commits to listing any new subprocessor and giving at least 30 days' notice before it processes anything.

Clause 4.4 gives an objection right, with termination and a refund if the objection is not resolved. Version 4.0 of January 2026 changes only the trading name, according to the vendor.

SpotDraft
On request only

SpotDraft's security page offers a request route for security documentation, and a trust center is linked at trustcenter.spotdraft.com. The home, pricing and security pages publish no subprocessor list and name no model provider, so they do not say which third parties see contract content. No consent or notification material for clients is published. The security page describes obligations on third parties rather than naming them.

Vendors handling scoped data are said to be bound by confidentiality, audit and incident response protocols. Fourth parties such as backup providers and subcontractors are stated to have no access to scoped systems or data.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Leah
Partial record

The audit stage of Leah's published governance loop logs every decision. Each entry records what the agent did, why, under which policy, with what data and with what outcome. The records are described as tamper resistant, immutable and ready for any audit. That gives the action, the rule, the inputs and the result for each action. The published description of the log does not include the model. The platform chooses among several language models for each task and identifies no model or version, so the log does not show which system produced a given passage.

No export built for court disclosure or AI use certification is described. The audit framing is regulatory and internal rather than judicial.

SpotDraft
Partial record

SpotDraft's security page says audit logging traces user actions at contract level. It captures signing and creation events and the trail of changes by both the creator and the counterparty. Every version of a contract is kept, so the log shows what changed, by whom and when. No model is named, so the log does not show which system produced a passage. As described, it does not separate an AI change from a human one. No export built for a court disclosure or AI use certification is published.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Signals neither addresses in public material
  • Good Law Verification
  • Refusal and Uncertainty Behavior

Which one fits

Choose Leah if

  • You need the model providers and training position in writing. Leah's subprocessor list names Anthropic, OpenAI, Cohere and Google with their jurisdictions. Leah says customer contract data is never used to train models.
  • You want agents under limits you set. The customer decides which agents may act, on which data and where escalation is required. Every action is logged with its rationale, policy and outcome.
  • You need enterprise terms you can read now. Leah's master terms cap liability at a year of fees and triple that for breaches of its security or data protection terms. They also give an intellectual property indemnity and notice before a compelled disclosure.

Choose SpotDraft if

  • You need to keep personal data in one region. SpotDraft stores personal data in the region the customer selects, the US, EU, India or the Middle East. Each contract is encrypted with its own key, held in HashiCorp Vault backed by Google Cloud.
  • You want to know how the price is built and what setup costs. SpotDraft prices plans by users or by contract volume. Setup, contract migration and a customer success manager come at no extra fee, on a published six week rollout.
  • Your lawyers want named ethics guidance. SpotDraft says its AI features were designed with attention to the California State Bar's November 2023 guidance and ABA Formal Opinion 512 of July 2024. Its Terms of Use state that it gives no legal advice.

In summary

Leah

Leah, formerly ContractPodAi, is an agentic contracting platform for large enterprises in regulated industries, with dedicated pages for financial services, healthcare and pharma. Beneath the agents sits a contract lifecycle product covering intake, playbook review in Microsoft Word, approvals, signing and an obligation repository. According to the AI Legal Index, Leah publishes its governance and its supply chain. Customers configure what each agent may do and where it escalates, and every action is logged. Anthropic, OpenAI, Cohere and Google are named as model providers. Its master terms set liability caps, uptime tiers and an intellectual property indemnity. No price or position on bar guidance is published.

Source: AI Legal Index, 2026

SpotDraft

SpotDraft is a contract lifecycle platform for in house legal teams. It covers creation from templates, approval workflows, negotiation in Word, Slack or the browser, and built in electronic signature. Its repository extracts more than a thousand kinds of contract data, and VerifAI reviews contracts inside Word. According to the AI Legal Index, SpotDraft publishes where data lives and how it charges. Personal data stays in a region the customer picks, the US, EU, India or the Middle East. Plans are priced by users or by contract volume, with implementation included. It names the California State Bar's guidance and ABA Formal Opinion 512. Its home, pricing and security pages name no model provider and take no training position.

Source: AI Legal Index, 2026

Questions buyers ask

Leah vs SpotDraft: which CLM is better for an in house legal team?

SpotDraft is the one built around the in house legal team, with many integrations, a choice of data region and a pricing model it explains before the first call. Leah is built for large enterprises that want agents across legal, procurement and finance, with model providers and enterprise terms published. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Does SpotDraft or Leah train AI on customer contracts?

SpotDraft's home, pricing and security pages do not say, and they name no model provider. Leah says customer contract data is never used to train models, and that OpenAI and Anthropic process it under zero retention. Leah's promise sits on its policy pages rather than in its master terms. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

How does SpotDraft pricing compare with Leah?

SpotDraft publishes its structure. Plans are priced by users or by contract volume, with setup, contract migration, a customer success manager and support at any hour included, on a six week rollout. It publishes no figure. Leah publishes no price, unit or structure, and every call to action is a demo request. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

What liability terms do SpotDraft and Leah publish?

Leah's master terms cap liability at a year of fees, three times that for breaches of its security or data protection terms, with an intellectual property indemnity and uptime commitments. SpotDraft's published Terms of Use cap its liability at one hundred Indian rupees under Indian law, with no vendor indemnity. Any negotiated enterprise agreement is not published. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

What do Leah and SpotDraft both leave unpublished?

Neither publishes an accuracy or hallucination measure for its AI review, or anything on attorney client privilege. Leah names no model version, and SpotDraft's main pages name no model at all. Neither describes what its AI does when the contracts on file do not answer a question, and neither indemnifies the customer for AI output. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.

Disclosure

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything on it comes from public material on the dates shown. How the index grades.

SpotDraft's Terms of Use, version 2.3 of 21 February 2024, are reached from its signup path. They cap liability at one hundred Indian rupees and give no vendor indemnity. An enterprise customer may sign a negotiated agreement that is not published. SpotDraft also runs a trust center at trustcenter.spotdraft.com. Its footer names ISO/IEC 27001:2022, and its help center lists SOC 2 Type 2 and ISO 27001 reports for download. Leah's no training promise is a policy rather than a contract term. Neither vendor reviewed this page.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
October 8, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746