LegalOn vs Spellbook: how they compare in 2026
The real question here is whose playbook you want. LegalOn ships more than 135 playbooks written by its own attorneys covering around 10,000 legal issues, so a team without settled standards gets a position on day one. Spellbook expects you to bring yours and encodes it. That difference explains almost everything else. LegalOn takes the strongest measurement disclosure anywhere in this index, publishing a 2026 benchmark of 3,282 pairwise reviews against eleven named models with the method described and the judge independently verified, and it backs deployments with named customers carrying figures. Spellbook counters on the supply chain, naming OpenAI and Anthropic and describing zero data retention precisely, where LegalOn names only its Azure OpenAI arrangement. Spellbook is the better fit for a law firm. LegalOn is built for the contracting function, lawyers or not.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the product. Review, redlining, Assistant, the intake and triage agent, the Playbook Agent, translation and Vault extraction are all generative or machine learning capabilities. The vendor's own framing is that it builds a harness on top of foundation models: legal content, review architecture, evaluation design and model orchestration. Remove the models and what remains is a library of attorney written playbooks with nothing to execute them.
The models are the product. Review, Draft, Ask, Compare and the Associate agent are all generative capabilities delivered through a Word add in that exists to carry them. The company pivoted its whole business to generative AI in 2022, rebranding from Rally to Spellbook. Remove the models and there is no product, only an empty add in.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
The most complete measurement disclosure on the index. The vendor publishes a 2026 Contract Review Benchmark testing 11 named AI models against its own system across 3,282 pairwise reviews on 21 precision critical guidelines, with the methodology described: contracts are broken into structured provision level checks, each evaluated against a precise legal standard, scored by an LLM judge whose outputs were independently validated by legal experts against professional standards. Failure modes are named rather than implied, the finding being that general purpose models from Anthropic, Google and OpenAI produce confident sounding answers that are frequently wrong on provision level review. Speed is measured alongside accuracy. The report is downloadable and the vendor states its own scepticism standard for vendor benchmarks in publishing it. Output grounds to the playbook standard with citations and clickable references to source. The obvious caveat, that this is the vendor's own benchmark of its own product, is disclosed by the vendor itself and does not pull it below the A band, which asks for named, dated, checkable evidence rather than third party evidence.
Grounding is real and documented with the method described, short of published figures. The vendor states its architecture explicitly and unusually: it does not fine tune, it connects general purpose models to proprietary market data and requires them to fetch and cite rather than rely on learned patterns, on the stated reasoning that putting documents into a model's long term memory encourages hallucination. Compare benchmarks a clause against a stated corpus of more than 2,300 contract types and explains why differences matter, and Ask is published as producing answers with citations. The vendor also publishes educational material on hallucination risk aimed at its own users. Not located as of 29 Aug 2026: any accuracy figure, hallucination rate, test set or evaluation for its own product. Worth noting the CEO has publicly questioned third party benchmarking studies of legal AI tools while the company publishes no measurement of its own.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A real published commitment with described review surfaces, short of the full control structure. The vendor states the design principle explicitly: it is built to hand off what a lawyer would hand off and hold the line where a lawyer would hold it, every output is sourced and easy to verify, and final judgment and control stays with the user. The intake agent has a described escalation rule: standard paper moves on its own and only real exceptions reach a lawyer. Review returns pass or fail indicators with risk ranked low, medium or high and clickable references, and redlines land as tracked changes a lawyer accepts or rejects. Not located as of 29 Aug 2026: where the threshold sits that separates standard paper from an exception, who configures it, and what the vendor commits to when an agent is wrong.
A real written commitment that the models work alongside a supervising lawyer, with a genuine review surface, short of the full control structure. Associate is described as the first AI agent that can work through multi document legal matters with your oversight, which states the oversight position in the product's own headline claim. The delivery model is itself the review mechanism: output arrives as tracked redlines inside a Word document the lawyer accepts or rejects clause by clause, which is a more concrete control point than most of this market publishes. Not located as of 29 Aug 2026: what the agent decides on its own within a matter, the threshold at which it stops, and what happens after an output is wrong.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers with figures and a method a reader can assess. Multiple published case studies pair a named organisation with a quantified result and the work it applies to: TriHealth at 75 percent reduction in contract review time on clinical trial agreements and vendor contracts, Industrial Service Solutions saving a lead reviewer 15 plus hours a week across named agreement types, a named software customer at 70 percent reduction in NDA review time, and MCEA Holdings at 50 percent more contracts handled without added headcount with senior oversight now under 10 percent. Individually attributed quotes come from named counsel at named organisations including TriHealth, Onshore Companies, Astrophysics and Tekscend Photomasks. The logo wall names large enterprises including Panasonic, Toshiba, Suntory, Ingersoll Rand, Wikimedia and the University of Washington, and the vendor states more than 9,000 legal teams. Short of nothing material: the figures are customer reported rather than independently audited, which is normal for this evidence class.
Real deployment evidence with substance, short of the full A bar. Multiple named customer stories are published with individually attributed detail, including Dropbox with a named associate general counsel on video, Panasonic on saving three weeks building an RFP process, KMSC Law with a named partner, Alturas Capital Partners, Elevare Law and Westaway with a named managing partner. The logo wall names large enterprises including eBay, Fender, Crocs, Franklin Templeton, Hapag Lloyd, Valentino and DirecTV, and the vendor states more than 4,500 legal teams across 80 plus countries. Figures appear but attach loosely: a named partner states Spellbook helps him bill an extra hour a day, and Panasonic's three weeks is a stated saving. Not located as of 29 Aug 2026: a dated case study carrying figures with a method a reader can assess.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments, short of the full picture. The training position is specific and covers the model provider layer: the vendor works with Microsoft's Azure OpenAI service under protections that no customer data is used to train, retrain or improve those models and that no customer data is stored for any period, explicitly including for abuse monitoring and debugging. That last clause is a real detail most vendors omit. Segregation is documented as segregated environments per customer account with strict access controls, which meets the applicable level for an in house buyer under the amended band. Encryption at rest and in transit is stated. Two gaps hold this off an A. Attorney client privilege and work product handling is not addressed directly in located material. Retention and deletion of customer documents in the vendor's own systems, as distinct from the model provider layer, is not stated.
Substantive published commitments, short of the full picture. Zero data retention agreements are stated as negotiated with both named model providers, OpenAI and Anthropic, with the mechanism described precisely: customer data in requests and responses is not persisted and exists only in memory to process a request. That is a stronger and more specific statement than most of this market publishes. Encryption, SSO through Microsoft Entra with enforced MFA, and audit controls are stated. Two gaps hold this off an A. Attorney client privilege and work product handling is not addressed directly in located material. Segregation between users or matters inside a customer is not documented, and for a firm facing product the applicable standard under the amended band is matter level walls.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
A boilerplate disclaimer sits in the terms while the product is sold to non lawyers by design. A disclaimer is published in the terms and conditions, and the vendor's framing of holding the line where a lawyer would hold it is a real design statement. But dedicated solution pages target procurement, sales, contract management and legal operations, and vendor material states directly that AI contract review is not only for lawyers and that procurement managers, sales contract teams and compliance officers use it without routing everything through legal. Searched the site, the solution pages, the published terms and conditions and the resource hub on 29 Aug 2026 and located no position on the advice line, no treatment of competence or supervision duties, and no statement of jurisdiction limits, despite playbooks covering dozens of countries.
The audience is unambiguous, transactional lawyers at firms and in house teams, with a signup form that asks a prospect to confirm they are a legal professional and offers no path for non lawyers. The vendor publishes educational material engaging with a lawyer's duty of competence and the obligation to verify AI output. What was not located, after checking the site, the solutions pages, the published terms of service and the learning hub on 29 Aug 2026, is a published position on the advice line, on supervision duties as distinct from competence, or on jurisdiction limits, despite the product being sold in more than 80 countries.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A published governance framework with real substance, short of a named owner or bias testing. What is published goes beyond principles: a described evaluation regime with an LLM judge validated against attorney assessment, a named internal AI function through published contributors including a VP of AI and a data scientist, an attorney authored content pipeline with playbooks maintained as law changes, and a stated commitment to ongoing transparent evaluation across future task areas including redlines, research, extraction and drafting. Testing is therefore both described and executed rather than asserted. Not located as of 29 Aug 2026: pre release testing gates as distinct from published benchmark results, a named accountable owner for model governance, and any disclosure about uneven output across matter types, parties or populations.
A published governance framework with real substance and independent validation, short of testing results or a named owner. The vendor commissioned and publishes an independent legal opinion from CMS Law on its classification under the EU AI Act, states it was assessed as low risk, and makes the full opinion letter downloadable from its trust portal along with the controls implemented for that classification. Commissioning an outside law firm to classify your own AI system and then publishing the letter is a governance artifact rather than a principles page, and no other vendor on this index has published one. Not located as of 29 Aug 2026: a named internal owner of model governance, published pre release testing results for model behaviour, or any disclosure about uneven output across matter types, parties or populations.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy covering most of the ground. Published: segregated environments per customer account with strict access controls, encryption at rest and in transit over public networks, hosting named as AWS and Google Cloud Platform in the US, annual penetration testing plus regular vulnerability testing, a described patch management process, and zero storage at the model provider layer including for abuse monitoring. A trust center is published at a stable URL. Not located as of 29 Aug 2026: a stated retention period or deletion control for customer documents in the vendor's own systems, a named subprocessor list, and an incident or breach notification practice. Retention is the notable absence given Vault is designed to hold every signed agreement indefinitely.
Substantive published policy covering most of the ground, short of the full set. Published and specific: zero data retention at the model layer with both providers named and the mechanism described, a complete third party subprocessor list with processing locations in the trust portal, AWS named as primary cloud provider, storage and processing locations stated as Canada and the US, access control through Microsoft Entra so a customer enforces its own authentication and MFA policy, breach notification addressed through implemented HIPAA Breach Notification rule controls with signed business associate agreements downloadable, and a published vulnerability disclosure policy. What holds this off an A is deletion, which the A band requires alongside the rest: searched the security page and FAQ, the published terms of service, the privacy policy and the trust portal entry point on 29 Aug 2026 and located no stated retention period for the vendor's own storage of documents, prompts and outputs, no customer control over that window, and no deletion commitment. This record's own prompt-and-output-retention signal row records the same gap.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Liability is addressed only through a standard limitation and disclaimer structure. Terms and conditions are published openly and carry a dedicated disclaimer section, so a buyer can read the allocation of loss before entering a sales process, which keeps this above a pure absence. Searched those terms, the privacy policy, the security page and the trust center entry point on 29 Aug 2026 and located no indemnity running to the customer for third party claims arising from output, no warranty on output, no stated liability cap figure and no insurance position.
Liability is addressed only through published terms a buyer can read in advance, without a position on the exposure the product creates. Terms of service, a privacy policy and a refund policy are all published openly, which is more than several vendors on this index manage, and the refund policy is an unusual published commercial commitment. But searched those documents, the security page and the trust portal entry point on 29 Aug 2026 and located no indemnity running to the customer for third party claims arising from output, no warranty on output, no stated liability cap figure and no insurance position. The vendor will sign a business associate agreement for protected health information, which is a regulatory undertaking rather than recourse for wrong output.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations exist and are documented, short of implementer level depth. A Microsoft Word integration has its own product page and is where review and redlining happen, browser review is supported for docx and PDF, and the intake agent ingests requests from email, Slack or a web form and routes them. Matter management, Vault storage and entity management mean the product covers more of the workflow natively rather than integrating to it. Not located as of 29 Aug 2026: legal document management connectors such as iManage or NetDocuments, contract lifecycle or e signature connectors, and per integration documentation of what moves in which direction and what an administrator configures. No integrations index page was located.
Real integrations exist and are documented, short of depth. The product is delivered as a Microsoft Word add in and also runs in Google Docs, which is the deepest possible integration into the surface where transactional drafting actually happens rather than a connector alongside it. A dedicated integrations page is published, and the ACM product describes contracts arriving from email, Slack and Salesforce. Authentication integrates with Microsoft Entra. Not located as of 29 Aug 2026: legal specific document management connectors such as iManage or NetDocuments, and per integration documentation describing what moves in which direction and what an administrator configures.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery is stated and the region is fixed rather than offered. The vendor publishes that hosting runs on AWS and Google Cloud Platform in the US, which is a real residency statement, and states segregated environments per customer account, which speaks to isolation. What is missing is choice and detail: no selectable region, no single tenant or private deployment option, and no statement of where processing happens as distinct from where data is stored. For a vendor with a Japanese parent business, playbooks across dozens of countries and stated GDPR compliance, the absence of any EU or Japan processing option on the global site is a live buyer question the page does not address.
Deployment model is stated clearly with partial residency detail. The vendor publishes that AWS is the primary cloud provider and that customer data is stored and processed in data centres in Canada and the US, with a full list of subprocessors and their locations in the trust portal. That is a real residency statement naming both jurisdictions. What is missing is customer choice and tenancy: no selectable region, no single tenant or private deployment option, and no statement of the tenancy model was located as of 29 Aug 2026. For a vendor selling into more than 80 countries, the absence of an EU or UK processing option is a live buyer question the site does not address.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real and stated with an open route, short of accessible evidence. SOC 2 Type II is stated as certified with the standard correctly attributed to the AICPA, and ISO/IEC 27001:2022 and ISO/IEC 27017:2015 are both named with their versions and with what each covers explained, the 27017 description correctly identifying it as cloud specific controls for multi tenant and virtualised environments. Annual penetration testing is stated. A trust center is published at a stable URL, a self serve route rather than a sales gate. Two things hold this off an A. No coverage period, audit scope, report date or named auditor was located as of 29 Aug 2026. And the home page certification strip lists ISO 27007, which is the guidelines standard for auditing information security management systems and is not a certifiable standard for an operator, while the security page itself correctly says 27017. Recorded as a discrepancy between two pages of the same site rather than as a conclusion about the vendor.
Certification is real and stated with an open route to the evidence, short of published scope. SOC 2 Type II and HIPAA are both named, and the badges on the home page link directly to named, dated resources in the trust portal rather than sitting as decorative images, which is a materially better pattern than most of this market and is why this is not a C. The trust portal is at a stable URL and carries downloadable documents including business associate agreements and the EU AI Act opinion letter. Under the three tier test this is a self serve request flow rather than a sales gate. What was not located as of 29 Aug 2026 is the audit coverage period, the scope, or the name of the auditing firm.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The supply chain is partly disclosed and the disclosure is specific where it exists. The vendor names Microsoft's Azure OpenAI service as a model provider and states the contractual protections attached to it, and its published benchmark names Anthropic, Google and OpenAI models as the systems it tests against and states that its own harness is built on top of foundation models, with Claude Opus 4.6 named in coverage of that benchmark. Hosting is named as AWS and Google Cloud Platform. What is missing is the direct question: which model serves the product's own live output, since the named models appear as benchmark comparators rather than as a stated production stack. Not located as of 29 Aug 2026: a subprocessor list, and any commitment to notify customers when the model supply chain changes.
The models underneath are named, their providers identified, where they run is stated, and the commercial terms binding them are disclosed. The vendor names GPT-5 and Claude Opus as the models powering the product on its own home page, names OpenAI and Anthropic as the providers, states the zero data retention agreements negotiated with each and what that means technically, names AWS as the primary cloud provider, states processing locations as Canada and the US, and publishes a complete third party subprocessor list at a stable trust portal URL. Naming the specific model versions in marketing copy is rare and is what a customer inheriting the dependency actually needs. Short of the very top only in that no explicit commitment to notify customers before the model supply chain changes was located, though the subprocessor list is the mechanism through which such a change would surface.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Checked the pricing page, the home page, the platform and solution pages and the footer on 29 Aug 2026. A pricing page exists in the navigation but publishes no rate, no unit of charge, no tier structure and no seat minimum. Every commercial path on the property terminates in a demo request or a sales phone number, which is sales gated and earns no credit. No free trial or self serve entry point was located. Third party pricing figures for this vendor were not located either.
Pricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not. The pricing page publishes two named tiers, Law Firms and In House Teams, itemises what each includes, states that pricing is structured around the number of team members on a licence, and confirms a 7 day free trial with extended trials available for larger organisations. Free access for academic institutions is published. So a buyer learns the unit of charge and the packaging without a sales call. No figure appears at any tier, and the only route to one is a demo booking. Checked the pricing page, the home page and the footer on 29 Aug 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Who the product serves is documented precisely, with the boundaries visible in the structure rather than only claimed. Six buyer functions carry dedicated pages: in house legal, legal operations, procurement, contract management, sales and law firms. Six verticals carry their own: construction, financial services, business services, private markets, healthcare and manufacturing, with software named separately. Practice coverage is stated at the level of contract type and negotiating position rather than in general terms, with more than 135 playbooks across roughly 10,000 legal issues, each specific to whether the customer is sending or receiving the paper, and international playbooks giving jurisdiction specific guidance across dozens of countries. Translation covers 28 plus languages. The self limit is clear from the structure: this is contract and contracting work, not litigation, and nothing on the property claims otherwise.
Segment and practice coverage is described with substance, short of the boundaries. Two buyer segments carry dedicated pages, law firms and in house legal, and six industries have their own: energy, healthcare, financial services, technology, manufacturing, and retail and consumer goods. Firm size is addressed in the trial form from 1 to 10 through 200 plus, and the vendor states more than 4,500 teams across 80 plus countries. Practice focus is stated clearly and repeatedly as transactional and commercial legal work rather than claimed broadly, which is a real self limit. Short of an A because litigation appears as an option in the signup form while nothing on the site describes litigation support, and because no statement of which practice areas or firm sizes the product is not built for was located.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The security page states the position at the model provider layer with unusual specificity: working with Microsoft's Azure OpenAI service under protections that no customer data is used to train, retrain or improve those models, and that no customer data is stored for any period of time, explicitly including for abuse monitoring and debugging. The home page adds that nothing shared with the vendor ever trains a third party model. Two limits on what that covers, both recorded rather than resolved: the commitment as written addresses third party models rather than the vendor's own systems, and it was located on the security page rather than in the published terms and conditions, which were searched on 29 Aug 2026.
The vendor states plainly that zero data retention means its model providers never learn from, train on or store customer data, and the security FAQ describes the mechanism: agreements negotiated with OpenAI and Anthropic under which customer data in requests and responses is not persisted and exists only in memory to process a request. The commitment as located covers the model providers specifically and sits on a public security page and pricing page rather than in a term of the published customer agreement, which was searched on 29 Aug 2026. No separate statement was located as to whether the vendor itself trains on customer content, as distinct from its providers.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
At the model provider layer the answer is zero and is stated plainly, including a specific carve out that storage does not occur even for abuse monitoring or debugging, which closes a gap most vendors leave open. What was not located as of 29 Aug 2026, after checking the security page, the published terms and conditions, the privacy policy and the trust center entry point, is any retention period for the vendor's own storage, any customer control over that window, or any deletion commitment. That gap matters more here than for most: Vault is a product designed to hold every signed agreement as a permanent searchable record, so a buyer is being asked to store contracts indefinitely with no published retention or deletion terms.
At the model provider layer the answer is specific and zero: data in requests and responses is not persisted and exists only in memory. That is a real published retention position for the part of the pipeline buyers ask about most. What was not located as of 29 Aug 2026, after checking the security page, the published terms of service, the privacy policy and the trust portal entry point, is any statement of how long the vendor itself retains prompts, documents and outputs in its own systems, whether a customer controls that window, or whether deletion is available. Recorded at the middle value because retention is acknowledged and answered for one layer without a period for the other.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own documented segregation model rather than inheriting one from a document management system. Segregated environments per customer account with strict access controls are stated, and ISO 27017 certification is described as covering cloud specific controls for multi tenant and virtualised environments, which speaks to the same boundary. That is tenant level separation, documented. What is not addressed is segregation between users or matters inside a customer, and no legal document management integration was located whose permissions retrieval could enforce at query time. The product is sold primarily to in house teams, where tenant level separation is the applicable question, but a dedicated law firm solution page also exists.
Searched the security page, the integrations page, the published terms of service and the trust portal entry point on 29 Aug 2026. No vendor material addresses ethical walls or segregation between users or matters. Authentication runs through Microsoft Entra, so a firm enforces its own identity policy at sign in, but that governs who can open the add in rather than what the product may retrieve per user. No legal document management integration was located whose permissions retrieval could inherit at query time. For a product sold to law firms this is the applicable standard and it is not addressed.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Searched the published terms and conditions, the privacy policy, the security page and the trust center entry point on 29 Aug 2026. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. This records a search across the published documents that did not surface the clause rather than a reading of every document end to end.
Searched the published terms of service, the privacy policy, the security page and FAQ, and the trust portal entry point on 29 Aug 2026. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. This records a search across the published documents that did not surface the clause rather than a reading of every document end to end.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The corpus here is attorney written playbook content rather than primary law, which is the right shape for a contract review product and reads differently against a signal written for case law. Provenance is unusually well stated for what it is: the vendor names its own attorneys as the authors, states the content is built and maintained in house and kept current as laws and standards change, and quantifies it at more than 135 playbooks across roughly 10,000 legal issues covering dozens of countries. Because the vendor authored the content, the licensing question that this signal exists to probe largely does not arise. What is not published is the update cadence in concrete terms, or which underlying legal sources the attorneys drew on when writing the standards.
The corpus here is contract market data rather than primary law, which is the right shape for a transactional product and reads differently against a signal written for case law. Coverage is quantified: Compare benchmarks a clause against a stated more than 2,300 contract types and thousands of similar agreements, and the vendor describes the architecture as fetching from proprietary market data sources and citing them. What is not published is where that market data comes from, on what rights basis it was assembled, or how current it is. Searched the Compare feature page, the clause index, the state of contracts report page and the security pages on 29 Aug 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Searched the site, the Review and Playbooks product pages, the knowledge core page and the resource hub on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked. The vendor does state that playbooks are maintained as laws change, which is the nearest equivalent for this product type and is a currency commitment about its own content rather than a citator. Noted for context: this is a contract review product whose grounding is playbook standards rather than case law, so a citator is largely outside its design.
Searched the site, the Ask and Compare feature pages, the learning hub and the help centre entry point on 29 Aug 2026. No material was located addressing whether authority returned carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is a transactional contract product whose grounding corpus is contract market data rather than case law, so a citator is largely outside its design. The absence is recorded as found, and a reader should weigh it against what the product is for.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
The product exposes a structured confidence signal rather than an abstention path. Review returns pass or fail indicators per playbook item with risk ranked low, medium or high, and clickable references to the source or to suggested locations, so a reader sees how strongly a provision is flagged and can check it. Searched the site, the product pages, the benchmark material and the resource hub on 29 Aug 2026 and located no explicit no answer path, and no published statement of what the product does when it cannot ground an assessment.
Searched the site, the feature pages, the learning hub and the help centre entry point on 29 Aug 2026. No published material describes what the product does when it cannot ground an answer, and no explicit no answer path or confidence signal exposed to the user was located. The vendor publishes a clear architectural position that models should fetch and cite rather than rely on learned patterns, which is about how an answer is grounded rather than what happens when nothing supports one.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note that the product is a contract review tool rather than a litigation or research tool, so its output is unlikely to reach a court filing as cited authority in the first place.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note that this vendor publishes its own editorial content about AI hallucination sanctions, which surfaces in searches for its name and is not a record about the product. Note also that the product is transactional rather than litigation facing, so its output is less likely to reach a court filing in the first place.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Searched the site, the blog, the resource hub, the newsroom and the published guides on 29 Aug 2026. No engagement with any named ethics opinion was located, including ABA Formal Opinion 512, any state bar guidance, or any Japanese bar association guidance given the parent company's origin. The vendor publishes substantial research and survey material about how legal teams adopt AI, and an evaluation programme, both of which address performance and adoption rather than the professional responsibility obligations its buyers are bound by.
Public materials refer to professional responsibility in general terms without naming guidance. The vendor publishes substantial educational content on hallucination risk that engages with a lawyer's duty of competence and candour to the court and the obligation to verify AI output, and it is named exclusive AI partner of the Canadian Bar Association, which is a relationship with a bar association rather than engagement with its guidance. Searched the site, the learning hub, the blog and the guides and reports index on 29 Aug 2026 and located no engagement with a named ethics opinion, including ABA Formal Opinion 512, any state bar guidance, or any Canadian law society guidance.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Savings are claimed prominently and quantified, with nothing published on the client side of the equation. Published figures include 85 percent faster contract review, a 75 percent reduction in review time at a named healthcare customer, 15 plus hours saved per week for a named lead reviewer, and a customer quote about saving thousands in outside counsel costs. Searched the site, the customer stories, the resource hub and the published terms on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment. Noted for context: the primary buyer is an in house team that does not bill a client by the hour, though a dedicated law firm solution page exists and that buyer does.
Savings are claimed with nothing published on the client's side of the equation, and unusually the framing runs the other way. A published customer quote from a named partner states the product probably helps him bill an extra hour a day, and the pricing page is headed on boosting profitability, alongside a published return on investment calculator and repeated ten times faster drafting claims. Searched the site, the pricing page, the customer stories and the learning hub on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment. A published claim about billing more hours, in a market where ethics guidance is direct that a lawyer bills for time actually spent, is the sharpest version of this signal on the index so far.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A trust center is published at a stable URL and the security page names certifications, hosting providers and the model provider protections, which is real material a buyer can read without a sales conversation. But the specific artifacts this signal turns on were not located as of 29 Aug 2026: no subprocessor list, no consolidated statement of which model providers see customer content beyond the single named Azure OpenAI relationship, and no client facing consent or notification pack a firm could forward to its own client. Recorded as not addressed rather than at the subprocessor value because no list exists to point to.
A firm can assemble most of what a client AI clause asks for without a sales conversation. Published through a trust portal at a stable URL: a complete third party subprocessor list with processing locations, named model providers with the zero data retention terms binding them, a dated SOC 2 Type II resource, a HIPAA resource, signed business associate agreements from vendors handling protected health information, and an independent EU AI Act classification opinion from CMS Law. Short of the top value because the material is a self serve portal rather than a client facing consent or notification pack the firm could forward as assembled, and no such pack was located as of 29 Aug 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Searched the site, the product pages, the matter management and Vault pages and the resource hub on 29 Aug 2026. Review output carries citations and clickable references to source, and matter management records cycle times and workload, so elements of a trail exist. But no per document export covering model used, sources retrieved and human verification together was located, and the model used is not identifiable from published material in any case. Noted for context: this is a contracting product rather than a litigation product, so a judicial AI disclosure order is less likely to reach its output.
Searched the site, the feature pages, the security page and the help centre entry point on 29 Aug 2026. The vendor states audit controls exist and Ask is published as returning answers with citations, but no per document export covering model used, sources retrieved and human verification together was located, and no disclosure or certification support material was located. Noted for context: this is a transactional drafting product whose output is contracts rather than court filings, so a judicial AI disclosure order is less likely to reach it. Recorded as found.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- Third Party Request and Subpoena Notice
- Good Law Verification
- Court Disclosure Support
Which one fits
Choose LegalOn if
- You have no settled contract standards and need them supplied. More than 135 attorney written playbooks covering roughly 10,000 legal issues means a position on day one, rather than a system waiting for you to encode one.
- Measurement matters to your risk committee. LegalOn publishes the most complete accuracy disclosure in this index: a 2026 benchmark of 3,282 pairwise reviews across 21 precision critical guidelines against eleven named models, with the scoring method described.
- Your intake comes from everywhere. The intake agent ingests requests from email, Slack or a web form and routes them, with a described escalation rule that moves standard paper on and stops elsewhere.
Choose Spellbook if
- Lawyers are your users and Word is where they work. Spellbook delivers review and drafting as tracked redlines inside the document, and its signup asks a prospect to confirm they are a legal professional.
- You need to know which models see your client data. Spellbook names OpenAI and Anthropic and states negotiated zero data retention with both, describing the mechanism. LegalOn names its Azure OpenAI protections but discloses less of the wider chain.
- Your standards already exist and encoding them is the job. Playbooks in Spellbook are yours, which is the right shape when a firm's negotiating position is the asset rather than something to be supplied.
In summary
LegalOn
LegalOn is a contract review and legal workflow platform for in house legal, legal operations, procurement and contracting teams, built around attorney written playbooks rather than customer built ones, shipping more than 135 pre built playbooks covering around 10,000 legal issues. The AI Legal Index grades it in the top two bands on eleven of fifteen capability axes and awards it the most complete measurement disclosure in the entire index: a published 2026 Contract Review Benchmark testing eleven named AI models across 3,282 pairwise reviews on 21 precision critical guidelines, with the methodology described and the scoring judge independently verified. It also carries A grades on operational evidence, with named customers and quantified results, and on coverage of who it serves. It publishes no rate of any kind.
Spellbook
Spellbook is AI contract review and drafting for transactional lawyers, delivered primarily as a Microsoft Word add in and also working in Google Docs. The AI Legal Index grades it in the top two bands on twelve of fifteen capability axes, with an A on model supply chain disclosure: it names OpenAI and Anthropic as providers and states negotiated zero data retention agreements with both, describing the mechanism precisely enough for a buyer to verify. Its architectural position is published rather than implied, stating that it does not fine tune and instead requires models to fetch and cite on the reasoning that long term memory encourages fabrication. It publishes named customer stories including Dropbox and Panasonic, and states more than 4,500 teams across 80 plus countries.
Questions buyers ask
Spellbook vs LegalOn: which is better for contract review?
It depends on whether you have contract standards already. LegalOn supplies them, shipping more than 135 attorney written playbooks covering around 10,000 legal issues, which suits a team without a settled position. Spellbook encodes yours. On the AI Legal Index grid Spellbook sits in the top two bands on twelve of fifteen axes and LegalOn on eleven, so the grades are close and the fit question decides it.
Which one publishes accuracy figures?
LegalOn, and by a wide margin. It publishes a 2026 Contract Review Benchmark testing eleven named AI models against its own system across 3,282 pairwise reviews on 21 precision critical guidelines, with contracts broken into provision level checks and the scoring judge independently verified. The AI Legal Index records this as the most complete measurement disclosure in the index. Spellbook documents its grounding method clearly but publishes no accuracy figure.
Is LegalOn only for lawyers?
No, and that is a real difference from Spellbook. LegalOn publishes dedicated pages for procurement, sales, contract management and legal operations alongside in house legal and law firms, and its own material states that AI contract review is not only for lawyers. Spellbook's signup asks prospects to confirm they are a legal professional and offers no path for non lawyers. If a non lawyer will use the tool, that shapes the professional responsibility question you need to ask.
Do LegalOn or Spellbook train on customer data?
Neither states that it does. LegalOn works with Microsoft Azure OpenAI under protections stating no customer data is used to train, retrain or improve those models and none is stored for any period, explicitly including for abuse monitoring and debugging, which is an unusually specific clause. Spellbook names OpenAI and Anthropic and states negotiated zero data retention agreements with both, with data existing only in memory to process a request.
What do LegalOn and Spellbook both leave unpublished?
Neither publishes a position on liability or recourse when a review misses something or gets it wrong. Neither publishes a position on the advice line, on competence and supervision duties, or on jurisdiction limits. And neither publishes a rate: LegalOn has a pricing page in its navigation that carries no number, unit or tier, and Spellbook publishes tier names and a licensing basis without a figure.
The sharpest difference on this page is one neither vendor frames as a difference. LegalOn sells deliberately beyond lawyers, with dedicated pages for procurement, sales, contract management and legal operations, and its own material states that AI contract review is not only for lawyers. Spellbook's signup asks a prospect to confirm they are a legal professional and offers no path for anyone else. Both carry the same middling grade on professional responsibility, but the exposure is not the same shape: a tool reviewing contracts for a procurement team raises questions a tool reviewing them for an attorney does not. Neither vendor reviewed this page and neither pays for inclusion.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.