Newcode vs Wordsmith: how they compare in 2026
Newcode and Wordsmith both sell AI workspaces to legal teams. Newcode is a layer across the systems a firm already runs, while Wordsmith is a front door that triages and resolves legal requests from the business. Wordsmith sits in the top two bands on twelve of fifteen axes and Newcode on six of fifteen, identical on eight. The gap is what each publishes about client data. Wordsmith names OpenAI, Anthropic and Google with the contract under which each retains nothing, and states that customer data trains no model. It addresses privilege and ABA Formal Opinion 512 directly and commits to breach notice within 72 hours. Newcode publishes no customer agreement, names no model, and its trust center could not be read. Newcode's counterweight is reach and control. It connects to iManage, Outlook, SharePoint and hundreds of other systems through Model Context Protocol, retrieves within walls the firm defines, and offers local deployment as well as cloud. It names Kirkland & Ellis, DLA Piper and Reed Smith among its customers.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Remove the models and the product has no reason to exist. Newcode holds no documents of its own; it connects to the systems a firm already runs and everything it adds on top is model-driven. Nova retrieves, analyses and drafts with referenced answers. Aurora is described as the AI-native intelligence engine at the heart of the platform, a builder in which a firm assembles agentic workflows from agent nodes, prompt templates and a language model selector. Retrieval itself is agentic rather than a lookup, the vendor describing an agent that plans, searches, evaluates and iterates until the context is right. The published capability list is the same picture in one line: workflow orchestration, contract review, case-law analysis, knowledge ingestion, data structuring, document analysis, structured outputs, legal reasoning and governed execution. Strip out the models and what remains is a permissions and connector layer with nothing to run, which is why the vendor calls the product an AI harness rather than a workspace with AI in it. Checked 5 September 2026.
The machine learning is the mechanism the buyer pays for, and there is no conventional platform underneath it. The product is a four-step flow of receive, route, resolve and record, and the two steps carrying the value are both model-driven: auto-triage that classifies an incoming request by priority, jurisdiction and commercial exposure and routes it to the right lawyer, and resolution that answers or drafts without one. The vendor draws the distinction itself, arguing that technology which only makes a lawyer faster leaves the operating model unchanged. Review, drafting, the assistant, agents, research and intake are each a model capability; repositories and reports are records of what those produced rather than standalone systems. Company incorporated October 2023 with no legacy platform to layer onto.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
The retrieval method is described rather than asserted, and nothing about accuracy is measured. Nova is stated to return referenced answers grounded in the firm's own data or external verified sources, with grounded referenced responses given as a product bullet in its own right. More usefully, the retrieval architecture behind that is set out: the retrieval agent plans, searches, evaluates and iterates until the context is right, guided by firm-defined taxonomy, labels and walls. That is a described method with a stated stopping condition and a stated constraint, which is more than most records in this lane publish and is what the band asks for. The sources are the firm's own documents and named external sources, so a reader can open what an answer rests on. What is absent is any test of it: no accuracy figure, evaluation, test set, error rate or statement of failure modes appears anywhere on the readable estate, and no accuracy or benchmark page exists. Nothing addresses hallucination in either direction, and no published agreement exists in which an accuracy position might otherwise sit.
Grounding is real and described in specifics, and no measured accuracy is published anywhere. On the evidence side: the research module states coverage of more than 130 jurisdictions across 60 countries drawn from curated government, regulatory and authoritative sources, with direct integrations to Companies House, EDGAR and Open Corporates for entity verification; the assistant returns a cited summary with links to the underlying legislation; the Word add-in returns answers described as cited and traceable; and Reports links every extracted value to an exact clause and page number with a click-through to verify. A reader can therefore open and check the source, which is the limb most of this market fails. What does not exist on any surface read on 31 Aug 2026 is a number: no accuracy figure, no hallucination rate, no benchmark, no described test set, no published evaluation of any kind. The vendor also lists smart web search as a source feeding legal answers without stating how a conflict between a curated source and a web result is resolved.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Control is offered as configuration the firm sets, and the boundary of autonomous action is never stated. What is published is real and is about capability rather than restraint: matter-level configuration, granular permissions, audit, firm-defined taxonomy, labels and walls, the ability to choose the model and set the guardrails without waiting on a release, and governed execution named among the platform capabilities. A reasoning trace is visible in the interface, shown as an expandable thought process against each output, which is a genuine review surface. What is missing is the account of what the system does alone. Aurora is sold on deploying agentic workflows at scale to automate complex processes, and the interface shows an Auto toggle on a running task, so the question of when the system acts without a person is raised by the product's own material and answered nowhere. Nothing states which outputs require review, what happens when an agent is wrong, whether generated work is marked as generated, or what guardrails can actually be set to. The band above requires a written commitment that the models work alongside a supervising lawyer, and no such commitment was located.
A real oversight posture with described review surfaces, short of the threshold that would make it a full control structure. The published model is that work reaches a lawyer only when it needs judgement, with routing to a named role shown as part of the flow. The review surfaces are concrete rather than asserted: in Reports a reviewer clicks a cell to verify it against the cited clause and page, then approves and locks the value or flags it for review; in the Word add-in every proposed redline can be accepted, rejected or improved individually. Against that, the company page describes chaining drafting into an end-to-end workflow that receives a request, drafts, routes for approval and sends with no manual step required, and nothing published states the threshold at which the system stops and escalates rather than resolving, or what happens after an output is found to be wrong. The proportion of requests resolved without a lawyer is presented as a headline statistic on the home page but the counter renders as zero, so the autonomy level is unquantified.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
The strongest named customer list in this pull, with no figure attached to any of it. The home page names, in text as well as logos, Kirkland and Ellis, DLA Piper, Reed Smith, Dickinson Wright, Wolters Kluwer, Robinson and Cole, The Bar of Ireland, Wiersholm, Haavind, Awilhelmsen, Ræder Bing, Simonsen Vogt Wiig, Ekko Advokatfirma and Helton, together with Norwegian public bodies including Helsetilsynet, Meteorologisk institutt and the Statsforvalteren offices, closing with a claim of more than one hundred law firms and enterprises. That is attribution a reader can check against real organisations. One testimonial carries a name and a role, Preben Brecke, Managing Partner at Haavind, describing the product as helping structure transactions, sharpen analysis and reach better decisions in private equity, M&A and complex disputes. What is entirely absent is measurement: no figure, no date and no described outcome accompanies any customer, and no case study was located on the readable estate. A customers page exists in the navigation and was not opened in this pass; it is named here as the limit.
Named customers, named individuals and at least one figure, short of dates and method. Trustpilot appears with Anoop Joshi, Chief Trust Officer, alongside a stated 85 percent reduction in contract review time; the Financial Times with Dan Guildford, General Counsel; Belron with Janet McCarthy, General Counsel; and Multiverse with Tara Haig, General Counsel. A logo strip carries 25 named organisations including BT, Canva, Deliveroo, Nikon, Rakuten, Selfridges, Skyscanner and Starling, and dedicated customer story pages exist. Two things hold this at B beyond the missing dates and method. The home page outcome counters, covering share resolved without a lawyer, speed, outside counsel reduction and hours saved per lawyer, all render as zeroes rather than figures, so the platform's own headline results are not actually stated. And the same sentence about lawyers focusing on strategic work is attributed on that page to both Anoop Joshi and Janet McCarthy. Individual case study pages were not opened on 31 Aug 2026, so the date and method limbs are rebuttable.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Walls are named as a product concept and no commitment about them can be read before signing. The home page states that retrieval is guided by firm-defined taxonomy, labels and walls, and that a firm gets governed, auditable, matter-level configuration with granular permissions over what each team can reach. Naming walls at all is unusual and it is why this is not the floor band. Everything else is unavailable. No customer agreement, master services agreement or data processing addendum exists on the estate, confirmed by a full footer inventory that carries only a cookie policy and a privacy policy. The privacy policy states in its own first line that it covers personal data collected when a visitor uses the website or the contact form, so it does not reach matter data. No statement on training use, no privilege or work product treatment, and nothing about what any model provider retains was located. The Vanta-hosted trust centre linked as the site's Security entry returned page metadata with no body on 5 September 2026 and is the rebuttal route; nothing is inferred from it in either direction.
Substantive commitments across most of this ground, with the training promise sitting in policy rather than in a located clause. Privilege is addressed directly rather than skirted: the security page states the product is designed to maintain attorney-client privilege and that its architecture aligns with ABA Formal Opinion 512. The no-training statement is unusually absolute and repeated, extending on a dedicated article to customer data never being used to train any underlying model or included in any pre-training corpus. The third-party model position is the strongest read in this pull: OpenAI, Anthropic and Google are each named with the specific contractual instrument under which zero data retention applies, and prompts and outputs are stated not to be stored, logged or used for training by any provider. Clause 11.2 of the terms binds each party to hold the other's Confidential Information and to use it only for implementing the contract. Two gaps hold it at B. No training prohibition was located in the retrievable portions of the customer agreement, so the commitment a buyer can point to is a policy statement rather than a term, and the data processing agreement that the terms incorporate by reference sits on a trust portal that refused automated access. Separation between customers is asserted as complete with no co-mingling, but no mechanism is documented.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
Nothing published addresses the advice line. No statement that Newcode is not a law firm, no disclaimer that output is not legal advice, no description of the professional judgement required before generated work is used, no jurisdiction limit and nothing on supervision or competence was located. There is no terms of service on the estate in which such a clause could sit, and the privacy policy is scoped to the website. The exposure is broad on this product because the published use cases are the work itself: drafting engagement letters, extracting court dates and deadlines from a scheduling order, conducting discovery, preparing trial submissions, providing strategic advice, and handling government applications, complaints and administrative proceedings. The band above does not fit, because it describes a boilerplate disclaimer sitting in the terms and no terms exist. Searched the home page in full, the legal page and the site footer inventory on 5 September 2026; the trust centre would not render and is the rebuttal route.
A published position that engages with named guidance rather than reciting a disclaimer, short of the competence and supervision limb. The security page names ABA Formal Opinion 512 twice, once in stating that the architecture aligns with it and once in a FAQ answering whether legal professionals must disclose AI use, which tells the reader that obligations vary by jurisdiction and bar association, that some recommend disclosure for substantive use while others do not require it for internal tools, and that teams should review Opinion 512 and applicable local bar guidance. The same page states that the product supports professional legal judgment rather than replacing it, and a published article engages with SRA and bar association duties to prevent unauthorised disclosure of client information. What is missing: nothing published addresses a lawyer's own competence and supervision duties in operating the tool, no jurisdiction limits are placed on the advice line despite research coverage spanning 130 jurisdictions, and no statement that Wordsmith is not a law firm was located on any surface read on 31 Aug 2026, which matters for a product whose stated purpose is resolving legal requests without a lawyer.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
No governance position was located. There is no responsible AI page, no principles statement, no accountable owner or function named for model behaviour, no pre-release evaluation regime, no management system and no certification such as ISO 42001. The vocabulary of governance is present in the product and means something different: governed execution, guardrails and matter-level configuration are controls a customer sets over its own deployment, not disclosure of how the vendor governs the models it ships. The privacy policy's automated decision-making clause addresses only website data and states that no solely automated decisions with legal effect are made there. The gap has a specific shape given the buyer list, which includes national public bodies and a bar association, and given a model-agnostic architecture in which the firm chooses the model: nothing published describes who is accountable for behaviour when the firm has selected the model and built the workflow. Home page, legal page and footer inventoried 5 September 2026; the trust centre would not render.
No governance position for model behaviour was located. Searched the home page, the security page and its full FAQ, the downloads page, the company page, the research, assistant, reports and Word integration pages, and the published articles on data privacy and contract review, on 31 Aug 2026. Nothing names an individual or role accountable for model behaviour, describes what is tested before a release ships, sets out a responsible AI framework or principles, or discloses anything about uneven output across matter types, counterparties or populations. The security disclosure is substantial but it is information security, which is a different subject and does not carry on this axis, and the ISO 27001 certification described as in progress is likewise a security standard rather than an AI management one. One limitation worth stating: the Vanta trust portal linked from the footer refused automated access, and if it carries an AI governance policy this grade is rebuttable on that document alone.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Access control is published at product level and everything downstream of processing is unavailable. What is stated: granular permissions, matter-level configuration, firm-defined labels and walls governing what retrieval can reach, audit described as a platform property, and a choice of cloud or local deployment. That is a real access story. What is absent for customer data is retention, deletion, incident practice and any subprocessor list, none of which appears anywhere readable. The privacy policy is thorough and covers the wrong subject: it states retention periods of twelve months for contact-form correspondence and ninety days for technical logs, tabulates GDPR legal bases, names transfer mechanisms and lists three website providers, Vercel, Resend and Cloudflare Turnstile, while confining itself by its own first line to data collected through the website. No agreement exists on the estate to carry the rest. The Vanta trust centre linked as the site's Security entry returned metadata with no body on 5 September 2026, so its contents are neither credited nor held against the vendor, and it is the rebuttal route on this row.
Substantive published policy across most of the ground, short of an openly reachable subprocessor list. Published on the security page: AES-256 at rest and TLS 1.2 or higher in transit; access restricted on a least privilege basis; SSO through Okta, Azure Active Directory and Google Workspace over OIDC and SAML 2.0 with MFA and role-based access control; annual independent penetration testing; and a formal incident response plan with confirmed breaches notified to affected customers within 72 hours together with details and remediation steps. The privacy policy adds a commitment to notify the customer and any applicable regulator of a suspected breach where legally required, and states that access is limited to those with a genuine business need under a duty of confidentiality. Retention is customer-controlled: data can be permanently deleted at any time, all customer data is permanently deleted on termination, and custom retention policies can be configured. A published article is candid that a platform must retain some information to function, which is more useful than an unqualified zero-retention claim. The gap is that no subprocessor list is published on the open site and no default retention period is stated; both the list and the incident response plan sit on the trust portal.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Nothing published addresses who bears the loss when the system is wrong. The site footer was inventoried in full on 5 September 2026 and carries two legal documents, a cookie policy and a privacy policy, both reached through anchors on a single legal page. There is no terms of service, no master services agreement, no customer agreement and no data processing addendum anywhere on the estate, so no indemnity, liability cap, warranty position, disclaimer of warranties, service level commitment or insurance statement can be read before entering a sales process. The privacy policy is scoped to website visitors and allocates nothing. The band above does not fit, because it requires a standard limitation clause disclaiming the exposure the product creates and there is no clause of any kind. The exposure is not theoretical on a platform that drafts filings, extracts court deadlines and runs agentic workflows for government bodies and international firms. The trust centre would not render and is the rebuttal route.
Liability is addressed through a limitation clause that disclaims the exposure the product creates, with the indemnity running the other way. Clause 8 requires the customer to indemnify Wordsmith, its officers, directors, employees, agents and consultants against liabilities, costs, damages and losses arising from the customer's use of the product and from any breach of the terms, carved back only where the claim arises from Wordsmith's own failure to meet its obligations. Clause 9.1.1 then states that Wordsmith shall not in any circumstances have liability for losses or damages suffered by the customer, subject to exceptions at clauses 9.2 and 9.6. No indemnity running to the customer, no warranty on output and no insurance position was located. A retrieval limit to state plainly: the terms page returns no body text to automated fetching, so the agreement was read through the search index, and the text of clauses 9.2 and 9.6, which carry the exceptions and would ordinarily contain any cap, could not be retrieved on 31 Aug 2026. If either contains a vendor indemnity or an output warranty this grade moves.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The most substantial integration story in this pull, short of documentation an implementer could work from. Newcode's premise is that it connects rather than replaces, and the named counterparties are the systems legal work actually lives in: iManage for document management, Outlook, SharePoint, OneDrive, Teams, and Word, Excel and PowerPoint, delivered through what the vendor describes as seamless reach into more than 750 Model Context Protocol servers. What moves is described at workflow level rather than left as logos, with a published example of drafting an engagement letter from a matter in Outlook using historical letters in SharePoint as fee benchmarks, a DMS search tool inside the assistant, and review, redlining and feedback carried out directly in Word. The vendor's own framing, that context follows the matter rather than the tool, is the correct description of what this axis measures. What is missing is depth a buyer could plan against: no field mapping, sync direction, trigger condition or permission model is documented, no developer or configuration documentation was located, and the 750 figure is a count rather than a list.
Real integrations documented, with depth described in one place and asserted in the rest. The Word add-in is the strongest evidence: it is distributed through Microsoft AppSource under product identifier WA200008590, and its integration page describes what it actually does rather than that it exists, covering running a playbook against a contract in the sidebar, accepting, rejecting or improving each redline in place, querying the repository by at-mention to insert approved clause language, and running research with jurisdiction and language selection. A Slack app has its own install route, and dedicated pages exist for Microsoft 365 and MCP. Research integrates directly with Companies House, EDGAR and Open Corporates. The illustrated request flow shows context pulled from Salesforce, Slack and Ironclad. What is missing: no document management integration such as iManage or NetDocuments was located, the Salesforce and contract lifecycle connections appear in an illustrative workflow rather than in documentation stating what moves and in which direction, and no developer or API reference index was located on the open site on 31 Aug 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The deployment limb is answered with a real option and the region limb is not addressed at all. The home page states that a firm gets cloud or local deployment options, which offers a self-hosted route rather than the single multi-tenant cloud most records in this lane assume, and pairs it with matter-level configuration and granular permissions over what each team can reach. A local deployment option is the strongest form the tenancy question can take, since it puts the customer in control of the environment entirely. Against that, no region is named anywhere for the hosted option, no cloud provider is identified for it, and no residency commitment appears in any readable material. The only geographic facts published are corporate, offices in Oslo, Stockholm, Dublin, New York and Palo Alto, which locate the company rather than the data, and the privacy policy's transfer section concerns website personal data by its own scope. This is the documented band gap where one limb is answered cleanly and the other not at all.
Residency is stated clearly and as a customer choice, and the tenancy model is not stated at all. The security page publishes hosting on AWS with EU data residency by default and US available, and adds a commitment that data is not transferred outside the customer's chosen region without explicit consent, which is a stronger statement than most vendors make because it binds the vendor to the customer's selection rather than merely offering one. The underlying AWS certifications are named as ISO 27001, SOC 1, SOC 2, SOC 3 and PCI DSS Level 1. Three things hold this at B, all checked 31 Aug 2026. Nothing published states whether the platform is multi-tenant or single-tenant, and separation between customers is asserted without a tenancy model behind it. No private, single-tenant or on-premises option was located. And where processing happens as distinct from where data is stored is not addressed: three US-headquartered model providers process prompts, and the relationship between that processing and the customer's chosen region is not explained.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
A real trust portal on a recognised compliance platform, and nothing verifiable from outside it. The site footer links Security to a dedicated trust subdomain hosted on Vanta, which is the artifact this axis asks about and is materially more than a badge image; several records in this pull display certification marks with no portal behind them at all. What could not be established is anything inside it. The page returned title and metadata with no body on 5 September 2026, so no standard, certifying body, examination period, scope statement or report is establishable, and whether the portal fulfils on an email address or requires a sales conversation is unknown. No certification is claimed anywhere in the readable text of the estate, and no badge appears on any page. Under the convention for gated artifacts, where the access tier cannot be established the lower tier is graded and the reason stated, which is what this note does. This is the cheapest available upgrade on the record.
Certification is real and stated and a trust portal is openly linked, but no scope, date or auditor is available on any readable surface. The security page states SOC 2 Type II certification described as independent, GDPR compliance, annual independent penetration testing, and ISO 27001 in progress. A Vanta-hosted trust portal is linked from the site footer without a gate, and the vendor states that provider policies, the data processing agreement and the incident response plan sit there. That portal counts as a genuine access route and is credited here as reachable: it refused automated access through its robots file, which is a retrieval limit on the index's side and not a gap on the vendor's, so nothing is scored against Wordsmith for it. What could not be established from any surface read on 31 Aug 2026 is the substance an attestation is judged on: no auditor is named, no coverage period is given, no report scope is described, and no penetration test partner or summary appears. A badge stating SOC 2 Type II with no scope and no date is what the open site offers, and the portal is where the answer presumably sits.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Model choice is sold as a feature and no model or provider is named. The vendor offers the flexibility to use the language model that works best for a firm, tells buyers to choose the models and set the guardrails without waiting on a release, and shows a language model selector inside an agent node in its workflow builder, so a model layer is not merely acknowledged but made configurable. Naming which models are on offer is the next sentence and it is never written: no provider, no model family, no version and no hosting arrangement for any of them appears in the readable estate, and no commitment to notify customers when the available set changes was located. A model name appears in one interface illustration and is treated here as artwork rather than disclosure, since nothing corroborates it. The question carries weight in proportion to the architecture: a platform whose selling point is model flexibility across a firm's whole document estate is precisely where a buyer needs the list. The trust centre would not render and is the rebuttal route.
The providers are named with unusual precision and the change commitment is absent. The security page identifies all three model providers, OpenAI, Anthropic and Google, states that each is used through a paid enterprise API, and names the specific contractual instrument under which zero data retention applies to each: OpenAI's API Data Usage Policy, Anthropic's Commercial Terms, and the paid API Gemini Terms. Naming the instrument rather than asserting a commitment in the abstract is more than almost any vendor does, and it lets a buyer check the upstream terms directly. Two gaps, checked 31 Aug 2026. No specific model or version is identified for any of the three, so a buyer knows whose models but not which, which matters for a product whose research module also feeds in live web results. And nothing published commits to notifying customers when the provider set or the models change, which for a multi-provider architecture is the disclosure a customer most needs.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. There is no pricing page in the site navigation, which carries solutions, academy, customers, security, about, news, careers and contact, and none in the footer, which carries only the cookie and privacy policies. Every commercial route on the estate is the same single call to action, book a demo. Nothing states whether the platform is licensed per user, per firm, per workflow, per agent run or on consumption, which is a live question on a product sold on agentic execution at scale where usage and cost would ordinarily be linked. No tier names, minimum commitment, term length or implementation cost appears, and because no terms of service or master agreement is published either, the payment provisions that would ordinarily disclose a charging structure are also unavailable. A buyer can learn nothing about cost without entering a sales process. No pricing row is owed on this record.
No pricing information is published at any level, including the unit of charge. Searched on 31 Aug 2026: the main navigation, which carries no pricing entry; the footer Product section, which lists downloads, comparisons, ROI and security and no pricing; the home page, the security page, the downloads page and the company page. Every call to action across the property is to book a demo. Neither a figure, a tier structure, a per-seat or per-matter unit, nor a statement of what implementation adds was located. The agreement confirms that a priced self-service route exists, since the self sign-up terms authorise charging fees by credit card, debit card or automated clearing house on online purchase, but no number is published anywhere a prospective buyer can reach without entering the signup flow or a sales process. The ROI page in the footer was not opened, so this is rebuttable if it carries a rate rather than a calculator.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Five buyer segments are described with distinct substance, and the boundary is never drawn. Law firms are addressed on billable capacity and firm-wide standards; in-house teams on standardising routine work, traceability and turnaround; insurance on matching claim facts to policy wordings and endorsements and surfacing coverage grants, exclusions and conditions precedent; banking and financial institutions on analysing facility agreements, loan agreements and master agreements at volume with review and redlining in Word; and government on case handling across applications, complaints, investigations and administrative proceedings. Each names the instruments and the work of that sector rather than restating a generic pitch, and the customer list corroborates the spread, running from international firms to a bar association to national public agencies. Practice depth is evidenced by named capabilities including fund formation, case-law analysis and jurisdictional comparison. What is absent is the limit: no jurisdiction is stated despite a Nordic base and US offices, no firm size band is given, nothing identifies a practice area or matter type the product does not suit, and nothing addresses the languages supported.
Segment coverage is described with real substance and the boundaries are left open. The property segments explicitly and in dedicated pages: by role for General Counsel and Legal Operations, by requesting team for procurement, sales, security and human resources, and by size across small business, mid-market and enterprise. Geographic and legal coverage is stated concretely as more than 130 jurisdictions across 60 countries, and the site publishes locale variants for eleven countries in five languages. What is absent is any statement of where the product stops. Law firm segments are not addressed, which is consistent with a product built for in-house teams, though external counsel appear only as recipients of shared reports and the position is never stated outright. Government and court use is not addressed. And practice coverage is expressed as the requesting business function rather than as areas of law, so a reader learns which internal team a request comes from but not which areas of law the product is competent in, on a platform whose research module claims 130 jurisdictions. Checked 31 Aug 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No customer agreement is published, and no policy page states a position on training. The agreement search this value requires was run against a full footer inventory on 5 September 2026: the estate publishes a cookie policy and a privacy policy, both reached through anchors on one legal page, and no terms of service, master services agreement or data processing addendum exists. The privacy policy states in its first line that it explains how personal data is collected when a visitor uses the website or the contact form, so it does not reach customer matter data and says nothing about model training in either direction.
No product page states that customer content does or does not train models, and no opt-out or configuration setting is described, on a platform whose own architecture invites the question by letting a firm select the model. The Vanta-hosted trust center linked as the site's Security entry returned page metadata with no body on the same date; it is the rebuttal route and nothing is inferred from it.
The security page states that customer data is not used to train Wordsmith's own models or to improve the platform for other customers, and a published article extends that to customer data never being used to train any underlying model or included in any pre-training corpus. Separately, zero data retention is stated to be contractual with the three model providers, each named with its instrument. That contract is with OpenAI, Anthropic and Google rather than with the customer.
No training prohibition was located in the retrievable portions of the customer agreement on 31 Aug 2026; the terms page returns no body text to automated fetching and was read through the search index, and the data processing agreement the terms incorporate by reference sits on a trust portal that refused automated access. The value is bounded by that and is rebuttable on the DPA.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located material states how long anything the platform handles is kept. The privacy policy does state retention periods, and they are precise and unusually well drafted, ordinarily twelve months for contact-form submissions and related correspondence and ninety days for technical and security logs, with longer retention where required by law. None of that reaches this signal, because the same policy confines itself to personal data collected through the website and the contact form.
Nothing addresses retention of documents retrieved from a firm's connected systems, of the context assembled by the retrieval agent, of prompts, or of the outputs and workflow runs Aurora produces. No deletion or return-of-data commitment for customer material was located and no agreement exists on the estate to carry one. Searched the home page, the legal page and the footer inventory on 5 September 2026; the trust center would not render.
The security page states that customers retain full control of their data, that it can be permanently deleted at any time, that all customer data is permanently deleted from Wordsmith's systems on termination, and that custom retention policies can be configured to match internal data governance requirements. No default retention window is published for prompts or outputs. A published article distinguishes zero training from zero retention and states plainly that a platform must retain some information in order to function, so no-retention is not offered as a setting at the Wordsmith layer; the zero retention that is stated applies to the model providers, where inputs and outputs are said not to be retained after processing.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Walls are named as a control the firm defines, and no mechanism behind them is published. The home page states that the retrieval agent plans, searches, evaluates and iterates guided by firm-defined taxonomy, labels and walls, and separately offers governed, auditable, matter-level configuration with granular permissions determining what each team can reach. Naming ethical walls as a first-class concept, and tying them to what the retrieval agent may see rather than only to what a user may open, is the right shape for this signal and rare in this corpus.
What is absent is any account of how the boundary is enforced: nothing states whether the platform is single or multi-tenant, how a wall is configured or audited, what happens when an agent traverses connected systems that carry their own permissions, or whether walls survive the more than 750 external connections the product claims. No administrator documentation was located, and the trust center would not render.
Separation is asserted at customer level on the security page, which states that data is kept completely separate from other customers with no co-mingling and no cross-contamination, supported by SSO through Okta, Azure Active Directory and Google Workspace and role-based access control. Within a customer, a published article states that playbooks and templates are shared across the organization only where the user chooses to share them.
How either boundary is enforced is not published: searched the home page, the security page, the company page and the product and integration pages on 31 Aug 2026 and located no tenancy model, no description of how retrieval applies access controls at query time, and no statement of whether the repository can be read across internal teams. The buyer here is an in-house department, so the relevant test is tenant-level separation rather than matter-level walls.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located term or policy addresses third party requests for customer data. The confidentiality section of a master agreement is where this evidence normally sits and no such agreement is published on the estate. The privacy policy does address the subject for the data it covers, listing public authorities, courts and regulators among recipients where required by law, and it commits to no notice, reserves no discretion over notice and publishes no transparency report; that provision governs website and contact-form personal data by the policy's own stated scope and does not reach a firm's matter content.
Nothing published states what happens when material held or reachable through the platform is demanded by subpoena, court order or regulatory process, which is a live question for a vendor whose customers include a bar association and national public bodies. Searched the home page, the legal page and the footer inventory on 5 September 2026; the trust center would not render and is the rebuttal route.
Row completed 2 September 2026 under R26. Clause 11.4 of the Wordsmith terms of service permits a party to disclose Confidential Information to the extent required by law, by a governmental or regulatory authority, or by a court of competent jurisdiction, and then commits, to the extent legally permitted, to give the other party as much notice of the disclosure as possible. It adds a further limb that where notice is not prohibited and is given, the disclosing party takes into account the other party's reasonable requests about the content of the disclosure, which is consultation on scope rather than bare notification.
The obligation is reciprocal. Clause 11.5 makes the confidentiality article survive termination. It is not the top value because no transparency report was located. A provenance limit is recorded rather than hidden: the terms page is JavaScript-rendered and its body did not extract on either this reader's tooling or the operator's, so the clause text was recovered from the search index of that same first-party URL rather than from a direct render.
No evidenceQuote is recorded for that reason, since a quotation should rest on text read at source. The substance is not in doubt, but the retrieval route is weaker than a direct fetch and a later grader should know that.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The corpus is the firm's own estate and the external half is named only as a category. Newcode's design point is that it retrieves from the systems a firm already runs rather than from a database of its own, and the vendor describes the result as firm-owned intelligence, so the primary material behind an answer is the customer's. Nova is also described as searching legal and external sources and returning answers grounded in the firm's data or external verified sources, and case-law analysis and legal research appear among the published capabilities, so primary law does enter the product.
What is missing is any identification of it: no publisher, database, jurisdiction set or licensing position is stated for the external legal material, and verified is asserted without saying verified by whom or against what. A jurisdictional comparison tool is offered without naming the jurisdictions it covers. Searched the home page in full, the legal page and the footer inventory on 5 September 2026.
Coverage is described by jurisdiction without identifying the underlying legal corpus. The research module states more than 130 jurisdictions across 60 countries with access to primary legislation, databases and guidance from hundreds of trusted legal sources, described as curated government, regulatory and authoritative sources that are continuously updated, supplemented by smart web search. No individual legislation or case law source is named and no license or public domain basis is stated for any of it.
Three sources are named, but they are corporate registries used for entity verification rather than legal authority: Companies House, EDGAR and Open Corporates. No update cadence or lag is published beyond the word continuously.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Nothing addresses checking authority for subsequent history, on a product that does reach primary law. Case-law analysis and legal research are both named among the published capabilities, Nova carries a legal research tool and a jurisdictional comparison tool, and answers are described as grounded in external verified sources. No citator, treatment signal, currency check or good-law verification is described anywhere, and nothing states what verified means or who performs it.
That gap sits differently here than on a contract or investigations product, because this platform is sold to litigation practices and public bodies for research and analysis, so an authority that has been overturned is a live failure mode rather than an inapplicable limb. Searched the home page, the legal page and the footer inventory on 5 September 2026; the product pages for Nova and Aurora were not opened and are the rebuttal route.
Searched the home page, the security page, the company page, and the research, assistant, reports and Word integration pages on 31 Aug 2026. Nothing addresses whether authority returned to the user is checked for subsequent history, and no citator, treatment signal or good law indicator was located. This signal applies squarely to this product rather than being out of scope, because the research module retrieves primary legislation and returns cited answers linked to it.
The nearest published material concerns currency of sources rather than status of authority: sources are described as continuously updated and smart web search is said to ensure answers reflect the most recent developments, neither of which tells a reader whether a cited provision or decision still stands.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
No located material describes what the system does when it cannot ground an output. One adjacent mechanism is published and is recorded because it comes closer than most: the retrieval agent is described as planning, searching, evaluating and iterating until the context is right, which implies an internal sufficiency test on retrieved context. Nothing states what happens when that test never passes, whether the agent stops, reports the gap, or answers anyway, and no confidence indicator, abstention path or no-answer state is described.
A reasoning trace is visible in the interface as an expandable thought process, which shows what the system did rather than how certain it was. Nothing addresses behavior when a connected system is unreachable or a firm's walls exclude the material an answer would need, which on this architecture is the ordinary case rather than an edge one. Searched the home page, the legal page and the footer inventory on 5 September 2026.
Searched the home page, the security page, the company page and the product pages for research, assistant, agents, reports and the Word add-in on 31 Aug 2026. No explicit no-answer or abstention path is documented and no confidence or grounding score was located. Two features come closest and neither is the same thing: the triage flow is described as surfacing work to a lawyer only when it needs their judgment, which is routing rather than abstention, and Reports allows a reviewer to flag a value that needs review, which is a human action on an answer already given rather than the system declining to give one.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
The AI Hallucination Cases database maintained by Damien Charlotin was searched on 5 September 2026 on the product names Newcode, Nova and Aurora and on the corporate name Newcode.ai AS. No court order, opinion or disciplinary record naming the product or the company was located. One limitation is recorded rather than glossed: Nova and Aurora are common product names across the software industry and are less discriminating search terms than a distinctive one, so a negative result on those two carries less weight than the negative result on Newcode itself. This records the state of the public record on that date and is not a finding about the product.
No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, searched on both the product name and the company name Wordsmith AI Ltd, alongside 2026 sanctions summaries in the trade press.
This is a statement about the public record on the date shown rather than a clearance, and it is bounded by what that database covers. The product is sold to in-house departments rather than to litigators, so its output does not commonly reach a filed brief.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located material engages with bar or ethics guidance at any level. No bar association, law society, rule of professional conduct, ethics opinion or regulator guidance is named or referred to in general terms, and nothing maps what a firm must do to discharge its own supervision and competence duties when agentic workflows it has built are running across its document estate. No advice disclaimer or statement that the company is not a law firm exists either, so there is no adjacent material of the kind that usually accompanies such a reference.
The absence is conspicuous on this record for one reason worth stating: The Bar of Ireland appears in the vendor's own published customer list, so a professional body is a named customer while professional obligations are addressed nowhere. Searched the home page in full, the legal page and the footer inventory on 5 September 2026; the trust center would not render.
Public materials engage with a named ethics opinion. The security page cites ABA Formal Opinion 512 twice: once in stating that the product's architecture aligns with it, and once in a FAQ answering whether legal professionals must disclose AI use to clients, which tells the reader that obligations vary by jurisdiction and bar association, that some recommend disclosure for substantive AI use while others do not require it for internal tools, and that teams should review Opinion 512 together with applicable local bar guidance.
A published article separately engages with SRA and bar association duties to take reasonable steps against unauthorised disclosure of client information. No mapping of the product to named opinions across more than one jurisdiction was located, so local guidance is referred to generically rather than identified.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The billing consequence is named as a benefit and never addressed as a disclosure question. The law firm proposition is published as reducing repetitive administrative work and expanding firm-wide billable capacity, alongside compressing turnaround times, protecting quality at volume and expanding capacity so teams can deliver more. Expanding billable capacity is a direct claim about the economics of the work, and it is the closest thing on the estate to a statement about fees.
Nothing follows from it. No per-matter record of AI-assisted work is described as available, no guidance on fee or disclosure treatment is published, and nothing addresses what a client is told when research, drafting or due diligence on their matter was produced by an agentic workflow the firm configured. The platform does capture the underlying material, since matters are described as traceable and execution as auditable, so the record exists and is offered for governance rather than for disclosure.
Public materials are built around time and cost saved. A customer story states an 85 percent reduction in contract review time, a published article claims contract processing times reduced by 50 to 60 percent, Reports is described as auditing more than 2,800 agreements in days rather than weeks, and the home page presents hours saved per lawyer each week and reduced outside counsel spend as headline outcomes, though those counters render as zeroes.
Searched the home page, security page, company page, product pages and articles on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee or disclosure purposes and no published guidance on billing treatment. The buyer is an in-house department rather than a firm billing a client, so the question lands on outside counsel spend rather than on the hourly bill, but nothing addresses either.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located material would let a firm answer a client's AI clause. No subprocessor register for the platform is published, no model or model provider is named anywhere, no cloud provider is identified for the hosted option, and no data processing addendum, consent pack or notification material exists on the estate. The only subprocessors published are three website providers named in the privacy policy, Vercel, Resend and Cloudflare Turnstile, which serve the marketing site rather than the product and do not touch client content.
The gap is structural rather than incidental on this architecture: the platform is sold on model choice and on reaching more than 750 external systems, so the set of parties that may see client content is both larger and more variable than on a single-model product, and none of it is disclosed. The Vanta-hosted trust center linked as the site's Security entry returned metadata with no body on 5 September 2026 and is the rebuttal route; nothing is credited from it.
A model provider list is published without a gate. The security page names all three providers that see customer content, OpenAI, Anthropic and Google, states that each is accessed through a paid enterprise API, and identifies the specific contractual instrument under which zero data retention applies to each. That is the disclosure most useful to a legal team answering a client AI clause, and it is readable before any agreement is in place.
What could not be confirmed on 31 Aug 2026 is anything beyond it: no full subprocessor list appears on the open site, and the data processing agreement, the provider policies and the incident response plan are all stated to sit on the Vanta trust portal, which is linked openly from the footer but refused automated access, so its contents were not verified and no client-facing consent or notification pack could be confirmed to exist.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Elements of a record exist as a governance property, short of anything built for disclosure. The platform is described as keeping every matter traceable, as offering governed, auditable, matter-level configuration, and as exposing a thought process against outputs, so a firm can see what a workflow did and under what configuration it ran. Nova's answers carry references to the sources retrieved, which is the sources-retrieved element this signal contemplates and is the strongest part of it here.
What is missing is the model and the artifact. No model or version is identified against any output, on a platform where the model is selectable and may differ between workflows and over time, so the record cannot say which system produced what. Nothing marks generated work as generated once it leaves the platform into a document, no record of human verification is captured, and no export is described for producing any of it to a court, a client or a regulator. No disclosure template or guidance is published.
Some elements of a record exist, short of a document-level export. Reports links every extracted value to its source with an exact clause and page number, and a reviewer clicks through to verify it and then approves and locks the value or flags it for review, which produces a per-value record of both the source relied on and the human check. The Word add-in similarly records each proposed redline as accepted, rejected or improved.
The missing element is the model: which of the three providers produced a given passage is not disclosed anywhere on the property, and no export designed to cover model used, sources retrieved and human verification together was located on 31 Aug 2026. The product serves in-house departments rather than producing court filings, so a judicial standing order is not its usual context.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- AI Governance and Bias Disclosure
- Commercial Transparency
- Good Law Verification
- Refusal and Uncertainty Behavior
Which one fits
Choose Newcode if
- Your firm wants AI across the systems it already runs rather than another repository. Newcode connects to iManage, Outlook, SharePoint, OneDrive, Teams and the Office applications, describes reach into more than 750 Model Context Protocol servers, and holds no documents of its own.
- You want to build your own agentic workflows. Newcode's Aurora is a visual builder in which a firm assembles workflows from agents, prompt templates and a model selector, then deploys them, with retrieval bounded by the taxonomy, labels and walls the firm defines.
- You need a local deployment option. Newcode offers cloud or local deployment with matter level configuration and granular permissions, and names Kirkland & Ellis, DLA Piper, Reed Smith, The Bar of Ireland and Norwegian public agencies among its customers.
Choose Wordsmith if
- Your business floods legal with requests through Slack and email. Wordsmith triages each request by priority, jurisdiction and commercial exposure, answers routine ones, and routes the rest to a named lawyer with context from connected systems.
- You must tell clients or the board which models see your data. Wordsmith names OpenAI, Anthropic and Google, each through a paid enterprise API, and the specific contract under which each applies zero data retention, and hosts on AWS with EU residency by default.
- You want answers you can verify cell by cell. Wordsmith's research answers link to the underlying legislation across more than 130 jurisdictions, and its Reports link every extracted value to an exact clause and page for a reviewer to approve or flag.
In summary
Newcode
Newcode, from Newcode.ai AS of Oslo with offices in Stockholm, Dublin, New York and Palo Alto, is an AI workspace that connects to the systems a legal team already runs, including iManage, Outlook and SharePoint, rather than holding documents itself. Its assistant, Nova, searches the firm's material and external sources and returns referenced answers, and Aurora lets a firm build and deploy its own agentic workflows with a choice of model. The AI Legal Index grades it in the top two bands on six of fifteen capability axes, with an A on AI centrality. It offers cloud or local deployment and names Kirkland & Ellis and DLA Piper among customers. As of 5 September 2026 the index located no customer agreement, named model provider or price.
Wordsmith
Wordsmith, founded in 2023 in the United Kingdom, is a legal front door for in house teams that captures requests from Slack and email, triages them by priority, jurisdiction and commercial exposure, and resolves routine ones or routes them to a lawyer, alongside playbook contract review, drafting, agents and research across more than 130 jurisdictions. The AI Legal Index grades it in the top two bands on twelve of fifteen capability axes, with an A on AI centrality. It names OpenAI, Anthropic and Google with zero retention terms, states SOC 2 Type II and EU residency by default, and names Trustpilot, the Financial Times and Belron among customers. As of 31 August 2026 the index located no AI governance position or price.
Questions buyers ask
Newcode vs Wordsmith: which is better for an in house legal team?
On published evidence Wordsmith sits in the top two bands on twelve of fifteen AI Legal Index capability axes and Newcode on six of fifteen, identical on eight, mostly because Wordsmith publishes its model providers, data handling and professional responsibility position. Newcode connects across a firm's existing systems and offers local deployment. Teams that must document their AI supply chain for clients have more to read from Wordsmith.
Which AI models does Wordsmith use?
Wordsmith's security page names OpenAI, Anthropic and Google, each used through a paid enterprise API, and names the contract under which zero data retention applies to each: OpenAI's API data usage policy, Anthropic's commercial terms and the paid API Gemini terms. No specific model or version is named. Newcode lets a firm choose its model but names none of the models on offer. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Does Newcode work with iManage?
Yes. Newcode names iManage among the systems it connects to, alongside Outlook, SharePoint, OneDrive, Teams and the Office applications, and carries a document management search tool inside its assistant. No field mapping or configuration detail is published. Wordsmith announced its own iManage connector on 2 September 2026, describing agentic workflows that find, draft and file documents back into iManage. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Does Wordsmith train AI on customer data?
Wordsmith's security page states that customer data is not used to train its models or to improve the platform for other customers, and a published article says customer data never enters any underlying model's training. That commitment sits on public pages; no matching clause was located in the readable parts of its terms. Newcode publishes no position on training either way. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What do Newcode and Wordsmith both leave unpublished?
A price and an AI governance position. Neither publishes a price, tier or unit of charge, and neither names who is accountable for model behavior, describes testing before release, or reports on uneven output. Neither checks cited authority for later treatment, and neither records which model produced a given answer. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Three readings to weigh. Wordsmith's terms require the customer to indemnify it and state that it has no liability for the customer's losses, subject to exceptions that could not be read; those are published terms. Its no training commitment sits on its security page and in an article rather than in a located clause. Newcode publishes no customer agreement and its Vanta trust center returned no readable content, so its low grades record what could be reached, not a finding that controls are weak. Newcode was verified on 5 September 2026 and Wordsmith on 31 August 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.