PostSig vs Sirion: how they compare in 2026

P
PostSig profile
S
Sirion profile
Last verifiedSeptember 25, 2026

PostSig and Sirion both manage contract performance after signature: PostSig for market data and finance teams at funds and banks, reading agreements with their amendments, side letters and invoices to work out which terms govern now, and Sirion as a full enterprise lifecycle platform with an agent layer. Sirion sits in the top two bands on nine of fifteen axes and PostSig on five of fifteen, identical on nine. Both published agreements reserve a use of customer data for their own AI: PostSig's terms let it train its models on anonymized or aggregated customer data, and Sirion's let it process customer data to inform its machine learning capabilities, with no opt out located for either. Sirion's lead is its data processing addendum, which keeps each customer in its own application instance, deletes data within 30 days of termination, commits to incident notice within 72 hours and publishes a subprocessor list, and its documented connectors to SAP Ariba, S/4HANA, Oracle and Dynamics. PostSig's counterweight is its focus: it matches invoices to agreed prices, tracks licenses and usage, and connects to enterprise AI assistants through a governed MCP link.

At a glance

Category
PostSigContract Review & Drafting
SirionContract Review & Drafting
Founded
PostSigNot published
Sirion2012
Headquarters
PostSigSan Francisco, CA, United States
SirionNot published
Last verified
PostSigSep 22, 2026
SirionAug 31, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

PostSig
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models drive the core task inside a platform that would still work without them. LineageAI reads agreements with their amendments, service orders, invoices and approvals to decide which terms govern and answers business questions from them. The inventory, spend and renewal tracking, dashboards, reports and document workspace would still run as a contract and spend system without the models. Verified 22 September 2026.

Sirion
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

The models drive the capability being sold and sit on a contract lifecycle platform that predates them and would function without them. Sirion has traded since 2012 and the product is structured as Store, Create and Manage, covering repository, drafting, approval, negotiation, obligation tracking and performance management. Strip out the agents and agentOS and a working enterprise CLM remains, which is the category Gartner placed it in. The agentic layer is real rather than cosmetic, with agents described as extracting and normalising contracts, assembling first drafts from a playbook, proposing redlines on third-party paper and monitoring obligations, and agentOS lets a customer build and deploy their own. That is the B band: the machine learning is the engine of a core capability layered on a workflow system.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

PostSig
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Answers are linked to their sources; accuracy is not measured. The site says every conclusion links back to the agreements, records and provisions behind it, so a user can open the customer's own documents to check an answer. No accuracy rate, test or evaluation is published, and the Terms of Service warn that AI output may be inaccurate and must be validated by the customer before any use. The product does not cite legal authority. Verified 22 September 2026.

Sirion
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is asserted at length and measured nowhere. The grounding claim is specific and repeated: answers are described as carrying citations linked to the customer's own data, and vendor material states that every AI-generated response includes citations linked to exact sources with clause-level citation and justification. Five percentage figures are published prominently, but every one measures speed or coverage rather than correctness: 90 per cent faster centralisation, 85 per cent faster insights, up to 90 per cent faster time to contract, 99 per cent on-time obligation compliance, 70 per cent faster agentic automation. Searched the home page, the trust centre and its AI ethics, compliance and security sections on 31 Aug 2026 and located no accuracy figure, no error or hallucination rate, no test set and no published evaluation. Nothing addresses what the system does when the customer's contract set does not support an answer.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

PostSig
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Oversight is asserted rather than built out. The legal-teams page says PostSig gives business users source-backed answers so legal can focus on standards and exceptions, and that it does not replace legal review; the MCP page says each request from an approved AI client is checked for user, data set, scope and policy. The design sends routine contract questions to business users without a lawyer, and no review step, threshold or limit on what answers may be used for is described; the terms put validation of output on the customer. Verified 22 September 2026.

Sirion
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Autonomy is claimed and the oversight mechanism is asserted in a phrase rather than described. Agents are said to sense intent, reason over enterprise data and act autonomously, to assemble first drafts and propose redlines, and to monitor obligations, surface gaps, trigger owners and drive follow-through. The single oversight statement located is that the user stays in control for strategic exceptions. What that leaves unpublished is everything the axis asks for: what an agent completes without a human, the threshold at which it stops and escalates, where the review point sits, and what happens after an output is wrong. agentOS is described as letting customers build, test and deploy agents, which implies configurable guardrails, but no control structure is documented. Searched the home page and the trust centre on 31 Aug 2026.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

PostSig
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Named customers without measured results. The home page quotes Sheena Clark of UNA Data Group, Gary Glasser of Birch Hill Equity Partners and Chris Petrescu of CP Capital, alongside investor endorsements. Its headline figures, more than $1 billion of economic value governed, 3.2 million business records connected and 50,000 rights and obligations tracked, describe platform scale rather than customer outcomes. Verified 22 September 2026.

Sirion
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Named customers and published figures, never attached to each other. Three individuals speak on the record with roles and employers: Edzard Janssen, Chief Procurement Officer at RBI; Reinhard Plaza-Bartsch, Head of Digital Supply Chain and Operations at Vodafone; and Angella Dikmic, Manager of IT Vendor Management at GTAA. All three quotes are qualitative. The five percentage claims carry no customer at all and read as product capabilities. Roughly 25 enterprise logos appear including Citi, GE, Coca-Cola, Chevron, PayPal, Bayer, Rolls-Royce, Aramco, Yamaha, DP World and Zalando, with customers stated across more than 70 countries and contract value under management put at more than 450 billion dollars. Two things a reader should note: all three named referees sit in procurement or vendor management rather than legal, on a platform indexed here as a legal product; and the case study library was not opened on 31 Aug 2026, so dates and method remain rebuttable.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

PostSig
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Confidentiality is addressed in the agreement, alongside a right to train on de-identified data. The Terms of Service bind both parties to confidentiality and require advance notice, where the law permits, before customer data is disclosed under a subpoena or court order; the security page says content is accessible only to authorised users and logically isolated between customers. The same terms let PostSig create aggregated data from customer data, defined as de-identified or aggregated so it no longer reasonably identifies the customer or an individual, and use it to train, develop or enhance its AI models or other large language models, with no opt-out located, while the home page says there is no training on customer data. Which AI providers process customer data, how long it is kept after termination beyond a discretionary 30-day window, and privilege are not addressed. Verified 22 September 2026.

Sirion
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Note amended 31 Aug 2026 under R23 as amended; grade held at B, and the reasoning for holding it is set out because the underlying facts have moved against the vendor. The original note recorded that the no-training commitment was located only in vendor library articles rather than in the agreement. The SaaS Terms have since been read in full, version 6, modified 26 August 2026, and the position is worse than a silence: clause 4.2 reserves a right for Sirion to direct its automated systems to review and process Customer Data to generally inform machine learning capabilities in the Subscription Services, with no opt-out located. The published no-training statement and the governing agreement therefore contradict each other, and under the documents-beat-marketing rule the agreement is what binds. What still supports the grade is the rest of the confidentiality architecture, which is genuinely substantive and readable before signing: the data processing addendum stores and processes all customer data in a customer-specific Sirion application instance, sets Article 32 technical and organisational measures with AES-256 at rest and TLS 1.2 in transit, imposes need-to-know and least-privilege access with automatic logout, requires deletion within 30 days of termination, and commits to notifying the customer of a confirmed security incident within 72 hours. SaaS Terms section 5 adds a mutual confidentiality regime with a duty to give prior notice of any authority or court demand so the other party can object. Privilege and work product remain unaddressed on every surface read. The grade is held rather than dropped because the C band describes confidentiality asserted in general terms or reachable only through a sales conversation, and neither is true here. A reader who takes the B band's requirement of substantive commitments on training use to mean commitments not contradicted by the agreement would grade this C, and that reading is defensible on these facts.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

PostSig
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

A boilerplate disclaimer against advice-shaped marketing. The Terms of Service say AI output is not to be relied on as a source of fact or a substitute for professional advice, and the legal-teams page says PostSig does not replace legal review. The legal solution page, however, sells automatic legal translations into lay terms and a reduction in the legal guidance lawyers give other teams, so that business users answer contract questions themselves. Who reviews those answers is not addressed. Verified 22 September 2026.

Sirion
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

Nothing published on the advice line was located. Searched the home page, the full trust centre index and its AI ethics, compliance and security sections, and the terms and policies index on 31 Aug 2026. No statement that Sirion does not provide legal advice, no professional responsibility or ethics page, no named bar or ethics guidance including ABA Formal Opinion 512, and no jurisdiction limits. The exposure is not theoretical: the platform is sold to procurement, sales and finance departments alongside in-house legal, all working on the same contracts, and the three customer referees the vendor chose to feature are procurement and vendor management leaders rather than lawyers. The SaaS terms and end user agreement were read only in fragments through the search index, so this grade is rebuttable if either carries a professional advice disclaimer.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

PostSig
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

Checked the home, about, legal solution, legal-teams, security and MCP pages, the Terms of Service and the Privacy Policy on 22 September 2026. No AI governance framework, accountable owner, testing before release, or finding on how answers perform across contract types or document sets was located. Verified 22 September 2026.

Sirion
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

The trust centre carries a section titled Artificial Intelligence Ethics and Governance, and its entire published content is three sentences: that Sirion has instituted an AI Governance Program abbreviated S-AIGP, that the programme monitors and ensures compliance with the EU AI Act 2024/1689 and other global AI regulations as they emerge, and that the reader should contact their Sirion Account Executive for more information. The page was last modified 16 December 2025. Naming a programme and a regulation, then routing the substance to a sales conversation, is not a governance position: nothing is published about who owns model behaviour, what is tested before release, how the programme operates, or anything at all concerning bias or uneven output. Under the gating rule a referral to an account executive is the sales-gated tier and earns no credit. This is the sharpest example in this pull of a governance artifact that exists as a heading rather than as disclosure.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

PostSig
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

Security controls are described in general terms; retention, deletion and subprocessors are not committed. The security page says content is accessible only to authorised users, logically isolated between customers, securely stored and monitored, with defined incident procedures and a Data Processing Addendum on request; the home page adds audit logs, encryption and penetration testing. The Terms of Service let PostSig delete customer data at its discretion from 30 days after termination, with no obligation to delete, and backups may be kept. No subprocessor list or incident notification timeframe was located. Verified 22 September 2026.

Sirion
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

Amended 31 Aug 2026 under R23 as amended, from B to A. The Data Processing Addendum at /terms-and-policies/data-processing-addendum/, version 3, modified 2 July 2026, was read in full on 31 Aug 2026; the original grading rested on fragments recovered through the search index, and the full document supplies every element this axis asks for. Retention and deletion: Appendix B sets the retention period by the controller's contractual direction, and clause 8.1 requires deletion or return of all Customer Personal Data including copies within 30 days of termination, with any law-compelled retention limited to the purposes requiring it and kept under the Agreement's protections. The SaaS Terms add automatic deletion after 30 days as a backstop. Access control: defined permissions on need-to-know and least-privilege-by-default, with automatic logout on inactivity. Subprocessors: a named Sub-Processor List published at its own URL, with a commitment to notify and an objection right on any addition or replacement, equivalent contractual terms imposed on each, and Sirion remaining liable for their breaches. Incident practice: clause 4.3 commits to notifying the customer within 72 hours of establishing material impact from a confirmed Security Incident, with Appendix B stating 48 to 72 hours and continuing communication until resolution, and the definition expressly excludes unsuccessful attempts such as failed logins and denial-of-service attempts, which is a precision most vendors leave out. Encryption is AES-256 at rest and TLS 1.2 in transit. All five limbs are published, current and specific enough to hold the vendor to, which is what separates A from B here; the earlier B rested on the subprocessor list and incident window not having been located rather than on their absence.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

PostSig
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

A standard limitation clause, and no indemnity from PostSig. The Terms of Service cap liability at the fees paid in the prior twelve months, exclude indirect damages, and warrant only that the service performs materially as documented. Use of any AI output is at the customer's sole risk, and the only indemnity runs from the customer to PostSig. Verified 22 September 2026.

Sirion
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

A real published position, readable before signing, short of the cap and silent on AI output. The SaaS terms and a separate end user agreement are both published openly. Clause 7.1 commits Sirion to indemnify and defend the customer against third-party claims that use of the subscription services infringes intellectual property rights. Clause 7.2 sets four named exclusions, covering combination with materials Sirion did not provide, unapproved modification, unauthorised use, and use inconsistent with the documentation. Clause 7.3 gives a remedy ladder of securing the right to continue, replacing or modifying the services, or terminating with a pro-rata refund of prepaid fees as Sirion's sole and exclusive liability. Clause 7.4 runs a reciprocal indemnity from the customer over customer data. What could not be established on 31 Aug 2026: the liability cap, since only fragments of the limitation clause were retrievable through the search index; any warranty on output; any insurance position; and any AI-specific treatment, since neither agreement carves AI output in or out of the indemnity.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

PostSig
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Named connections, some with the flow described. A DocuSign integration imports signed agreements into PostSig in one step, and PostSig MCP gives approved AI clients such as Claude Enterprise and ChatGPT Enterprise access to its answers after checking user, data set, scope and policy. ERP and accounts-payable data are referred to as inputs. What syncs in each direction and how connections are configured is not documented. Verified 22 September 2026.

Sirion
AA on Practice Systems Integration DepthDocumented, verifiable integrations into the systems legal work already lives in, with the depth described: what syncs, in which direction, and what a firm must configure.

Written 31 Aug 2026 as an R7 amendment; this row was left unwritten in the original build because no integration surface had been opened and grading an absence would have scored a research gap against the vendor. Surface read on 31 Aug 2026: the Non-Native Integrations article in Sirion University at /sirion-university/integrations/non-native-integrations/, last updated 24 February 2026. It documents nine named connectors with the direction of travel stated for each, which is the depth this axis asks for and which almost nothing else in the corpus publishes. Four SAP Ariba accelerators cover procurement, bids, awards and contract workspaces: an executed contract request in Sirion creates a purchase requisition in Ariba and the resulting purchase order is written back to Sirion; Ariba sourcing events and RFPs convert into Contract Draft Requests on defined workflow triggers, one per bidding supplier with line items mapped from bid detail, and supplier redlines transfer into Sirion for legal review; awarded RFx events create a new draft request with awarded line items synced; and contracts finalised in Sirion replicate into Ariba Contract Workspaces with metadata, documents, line items and workflow status, by event-driven asynchronous processing. Three more cover supplier master data from Ariba, SAP S/4HANA Business Partners on scheduled transfers, and Oracle ERP with built-in logging, error handling and sync status visibility. The Microsoft Dynamics connector is explicitly bidirectional and runs in auto or manual mode. Configuration is described at the level of triggers, modes and scheduling rather than a full implementation guide, and the wider Sirion University catalogue requires a login. The documented depth sits on the procurement and ERP side; the Microsoft Word add-in is distributed through AppSource and Salesforce through AppExchange, but neither is documented to this depth on a page read, and no document management system connector such as iManage or NetDocuments was located.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

PostSig
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Residency is offered without a region. The home page says sensitive records can be kept in the right region and jurisdiction, and the security page says customer environments are logically isolated. No region, hosting provider, processing location or deployment option other than the hosted service is named. Verified 22 September 2026.

Sirion
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

The tenancy model is stated in the agreement and the regions are not stated anywhere. The data processing addendum states that the Sirion application is a SaaS application hosted by a cloud service provider and that all customer data is stored and processed in a customer-specific Sirion application instance, which is a real isolation statement carried in a contractual document rather than a marketing claim. The trust centre names four underlying providers, AWS, Azure, Oracle and IBM, which is unusually broad and implies customer choice without stating it as an option. Two gaps checked 31 Aug 2026: no data residency commitment, region list or jurisdiction option was located anywhere, and nothing addresses where processing happens as distinct from where data is stored. One tension worth a buyer's attention: a Sirion library article describes the platform's multi-tenant scalability, which sits awkwardly beside the addendum's customer-specific instance, and nothing published reconciles the two.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

PostSig
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

A named attestation and auditor, report under NDA. The security page says PostSig is SOC 2 Type II compliant, that the audit was conducted by Prescient Assurance, and that the report and detailed security controls are available to customers under NDA on request. No report period is published. Verified 22 September 2026.

Sirion
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

The Data Processing Addendum, read in full on 31 Aug 2026, supplies two things. Appendix B names ISO 27001 as a held security certification and describes the review regime around it, and clause 7.1 gives a contractual access route: unless otherwise agreed, Sirion will provide a copy of its most current security attestation report on the customer's written request, no more than once annually. Clause 7.2 adds a customer audit right, with scope, timing and controls agreed in advance and a reasonable fee chargeable. Appendix B also records that the cloud provider's own SOC 1, SOC 2 and ISO 27001 reports are assessed by Sirion as part of a shared responsibility model, which is oversight of infrastructure rather than an attestation over the application and is not credited here. The grade is B because the access route is a contractual entitlement running to an existing customer, not a way for a buyer to obtain evidence before signing, and because no auditor is named, no coverage period is stated, and no scope statement says which systems the ISO certificate covers. The line is the sales conversation, and a report obtainable only after execution sits below the self serve tier that can reach A.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

PostSig
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

A named engine, with nothing said about what sits underneath. The site presents LineageAI as its cross-document intelligence, and the Terms of Service say aspects of the service rely on AI models. No model, model provider, inference location or change notification is published. Verified 22 September 2026.

Sirion
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The architecture is described and nothing underneath it is identified. Vendor material sets out a multi-model approach combining purpose-built small models trained on enterprise contracts with large language models, and presents that as the differentiator against generic models retrofitted for legal use. No large language model provider is named, no model or version is identified, no processing location is given for the model layer as distinct from the cloud infrastructure, and nothing commits Sirion to notifying customers when any of it changes. This sits above the floor because the architecture is genuinely described rather than gestured at, and below anything higher because a buyer inherits dependencies it cannot see. Searched the home page, the trust centre and its AI ethics, compliance and security sections on 31 Aug 2026.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

PostSig
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Checked the home, CPM, inventory and legal pages and the Terms of Service on 22 September 2026. No price, unit or tier is published; the terms say fees are set in each order and describe only payment mechanics, in US dollars, due in 30 days, non-refundable and with a 1.5% monthly late charge. Verified 22 September 2026.

Sirion
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No pricing information is published at any level, including the unit of charge. Searched the home page, the full primary navigation across platform, solutions, resources and company, the footer sitemap, the trust centre and the terms and policies index on 31 Aug 2026. There is no pricing page, no tier structure, no per-seat, per-contract or per-agent unit, no volume banding and no statement of what implementation adds. Every call to action is a demo request. Nothing published would let a prospective buyer form any view of cost before entering a sales process, which is a notable contrast with the vendor's willingness to publish its SaaS terms, end user agreement and data processing addendum in full.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

PostSig
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Buyers and use cases are named, short of limits. The site addresses market data, finance, procurement, legal, and risk and compliance teams at hedge funds, asset managers, banks, venture and private equity firms, family offices and data vendors, with use cases such as invoice reconciliation, renewals, usage and entitlements, DORA evidence and investor rights. The contract types and markets it does not handle are not stated. Verified 22 September 2026.

Sirion
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Segment coverage is documented precisely on two axes and the boundaries are left open. Eight industry verticals carry dedicated pages: financial services split into procurement and capital markets and credit, insurance with a separate underwriting submissions triage solution, automotive, IT services, healthcare, pharmaceuticals and life sciences, telecom, and oil and gas. Five departments carry their own pages: in-house legal, legal operations, procurement, sales and finance. Customers are stated across more than 70 countries and the site publishes in English, German and French. What is absent is any statement of where the product stops: no contract types or matter types are excluded, nothing addresses law firms, government or public sector use, and the practice dimension is expressed as industry and department rather than as areas of law. Checked 31 Aug 2026.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

PostSig
Permitted, in the contract

The Terms of Service let PostSig create aggregated data from customer data, defined as customer data de-identified or aggregated so that it no longer reasonably identifies the customer or an individual, and use that data and usage data to train, develop or enhance its AI models or other large language models. No opt-out was located. The home page says there is no training on customer data; the published terms say otherwise for de-identified or aggregated data.

Sirion
Permitted, in the contract

Amended 31 Aug 2026 from policy-never, under R23 as amended: the SaaS Terms were read in full, where the original grading had only fragments, and the earlier value rested expressly on no training prohibition having been found in the portions then retrievable. Both sides of the record, because the gap between them is the finding. Sirion's library material states that customer data stays within the customer environment and is not used to train external language models.

Its SaaS Terms, version 6, modified 26 August 2026, reserve the opposite at clause 4.2: Sirion may direct its automated systems to review and process Customer Data to generally inform machine learning capabilities in the Subscription Services, alongside generating aggregated and anonymized industry analytics, with a commitment not to publicly identify the customer or disclose Customer Data to third parties. The agreement governs over a policy page, so the reservation is what a buyer is bound by.

Two features of the wording a reader should weigh directly. The reservation operates on Customer Data itself rather than on de-identified or aggregated derivatives, which makes it broader in reach than clauses that are limited to aggregate data. But it says generally inform rather than train, so whether it authorizes model training in the ordinary sense is a question the words leave open. No opt-out, consent step, configuration setting or exclusion route was located in the SaaS Terms, the end user agreement or the data processing addendum.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

PostSig
Disclosed without a period

The Terms of Service let a customer request an export on termination and say that, from 30 days after the agreement ends, PostSig has no obligation to keep customer data and may delete it at its discretion; backups may be kept. The Privacy Policy keeps personal information as long as necessary. No retention period for questions asked or answers generated is stated.

Sirion
Customer controlled, no zero option

The published data processing addendum states that the retention period is determined by contractual obligations as directed by the controller, and that after termination personal data processed on the controller's behalf is retained typically for a period of 30 days. That places the window under customer instruction with a stated default, in a contractual document rather than a policy page, which is stronger than most of this pull.

Two qualifications: the provision is framed around personal data rather than prompts and generated outputs specifically, and no zero-retention setting is offered or described. Read 31 Aug 2026.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

PostSig
Claimed, not documented

The home page says access respects existing controls, the security page says content is accessible only to authorized users and logically isolated between customers, and the MCP page says each AI request is checked for user, data set, scope and policy. How permissions are set within a customer, or whether they are taken from a source system, is not described.

Sirion
Own model, documented

Separation between customers is documented in the data processing addendum rather than asserted in marketing: all customer data is stated to be stored and processed in a customer-specific Sirion application instance in the cloud service, under a shared responsibility model in which Sirion secures the software, the customer data and the related access while the cloud provider secures the underlying facility. Role-based access control with granular permissions is described in vendor library articles.

Two things to note. Nothing describes how access is enforced between teams inside a customer, which matters where legal, procurement, sales and finance share the platform. And a Sirion library article describes the platform's multi-tenant scalability, which is not reconciled anywhere with the addendum's customer-specific instance. The buyer is an in-house department, so tenant-level separation is the relevant test.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

PostSig
Notice committed

The Terms of Service allow either party to disclose customer data or other confidential information if required by law, subpoena or court order, provided that, where the law permits, it notifies the other party in advance and cooperates in seeking confidential treatment. No transparency report was located.

Sirion
Notice committed

Written 31 Aug 2026 as an R7 amendment. The commitment is in the SaaS Terms at section 5.3, version 6, modified 26 August 2026, and not in the Data Processing Addendum, which was read in full the same day and does not address third-party demands anywhere. Section 5.3 permits a party receiving a demand from a competent authority or court for the other party's Confidential Information to comply only if it has satisfied itself the demand is lawful, given the disclosing party as much prior notice as possible where possible so that party can object, and marked the material as the disclosing party's Confidential Information.

The obligation is mutual and it reaches customer material: Confidential Information is defined to cover information that should reasonably be understood to be confidential, and the AI Module clause at 1.8(b) confirms the reading by carving Customer Data back into that definition. The notice duty is qualified by where possible rather than by legal prohibition, which is softer than the usual formulation. No transparency report or count of demands received was located on the terms pages, the DPA or the trust center, which is what keeps this below the top value.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

PostSig
Not addressed

Checked the home, legal solution, legal-teams and CPM pages on 22 September 2026. The product works on each customer's own agreements, invoices and records; no body of law behind its answers is identified.

Sirion
Sources named, basis unstated

The working corpus is the customer's own contract set and is identified as such, with answers described as carrying citations linked to the customer's own data and agents extracting and normalizing contracts from customer-nominated sources. Sirion separately states that its purpose-built models are trained on millions of enterprise contracts, which identifies a second corpus at the level of composition without naming any source, stating any license or rights basis, or explaining whose contracts those are.

The product does not retrieve primary law, so the usual jurisdiction and coverage questions do not arise. No update cadence is published.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

PostSig
Not addressed

Checked the home, legal solution, legal-teams and CPM pages on 22 September 2026. The product does not cite legal authority, and nothing addresses checking authority for later treatment.

Sirion
Not addressed

Searched the home page, the trust center index and its AI ethics, compliance and security sections, and the terms and policies index on 31 Aug 2026. Nothing addresses whether legal authority is checked for subsequent history, and no citator, treatment signal or currency check was located. The platform manages contracts, obligations and supplier performance rather than retrieving case law or legislation, so a citator is not part of what it sells.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

PostSig
Not addressed

Checked the home, legal-teams, CPM and MCP pages on 22 September 2026. Nothing describes what the product does when the documents do not answer a question or when governing terms conflict.

Sirion
Not addressed

Searched the home page, the trust center and its AI ethics, compliance and security sections on 31 Aug 2026. No explicit no-answer or abstention path is documented and no confidence or grounding score was located. Published material runs the other way, describing agents that sense intent, reason over enterprise data and act autonomously, and answers delivered with citations, without stating what happens when the customer's contract set does not support a response.

The nearest adjacent material is the statement that users stay in control for strategic exceptions, which describes an escalation posture rather than model behavior under uncertainty.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

PostSig
None located

Searched the AI Hallucination Cases database maintained by Damien Charlotin on 22 September 2026 for PostSig, and no recorded case was returned. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product.

Sirion
None located

No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, searched on both the product name and the former company name SirionLabs, alongside 2026 sanctions trackers and trade press summaries.

This is a statement about the public record on the date shown rather than a clearance, and it is bounded by what that database covers. The platform runs enterprise contracting and supplier governance rather than producing court filings.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

PostSig
Not addressed

Checked the home, legal solution, legal-teams and security pages, the Terms of Service and the Privacy Policy on 22 September 2026. No material engages with lawyers' professional or ethical obligations or names any ethics opinion.

Sirion
Not addressed

Searched the home page, the full trust center index and its AI ethics, compliance and security sections, and the terms and policies index on 31 Aug 2026. No engagement with any bar or ethics guidance was located, including ABA Formal Opinion 512 and any state bar or Law Society material. The compliance material published is regulatory and security-framework oriented, covering ISO 27001, SOC 1, SOC 2 and the EU AI Act, and none of it addresses the professional conduct obligations binding the lawyers who use the product.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

PostSig
Outside the fee relationship

The product is bought by companies to manage their own vendor and investment agreements, with in-house legal teams among the users, so it does not sit between a lawyer and a billed client.

Sirion
Savings claims only

Public materials are built around speed and automation gains: 90 percent faster contract centralization, 85 percent faster insights, up to 90 percent faster time to contract, 70 percent faster agentic automation, and a customer reporting as much as a 50 percent uptick in tasks automated. Searched the home page, the trust center and the terms and policies index on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee purposes and no published guidance on billing, fee or disclosure treatment.

The buyer is an in-house function rather than a firm billing a client, so the question lands on internal cost and outside counsel spend, and neither is addressed.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

PostSig
Not addressed

Checked the security and legal pages and the Terms of Service on 22 September 2026. The SOC 2 report and a Data Processing Addendum are available on request; no subprocessor or model provider list and no client-facing disclosure material was located.

Sirion
Subprocessors listed

Amended 31 Aug 2026 under R23 as amended: the Data Processing Addendum was read in full, where the original grading had only fragments, and it closes the gap the earlier value rested on. Appendix D publishes a Sub-Processor List, stated to be regularly updated, at a named URL reachable without a sales conversation, and clause 5.4 commits Sirion to notify the customer of updates and give an opportunity to object to additions or replacements.

Clause 5.6 requires equivalent data protection terms on every sub-processor and keeps Sirion liable for their breaches. That is the artifact this value turns on and it is published, which lifts the record off the request-only tier. It stops short of a disclosure pack: no model provider is named in the located material, and no client-facing consent or notification material exists for a firm answering a client's AI clause.

The AI governance detail that would accompany such a pack is still routed to a Sirion Account Executive on the trust center's AI ethics page.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

PostSig
Not addressed

Checked the home, legal-teams, security and MCP pages on 22 September 2026. The site mentions audit logs across workflows, but nothing addresses recording or disclosing AI use in material put before a court.

Sirion
Partial record

Some elements of a record exist as a by-product of the product's design. Answers are described as delivering citations linked to the customer's own data, vendor material states that every AI-generated response includes citations linked to exact sources with clause-level citation and justification, and granular audit trails are described as recording system activities, user actions and data modifications. That covers sources retrieved and, in part, what was done.

Two elements are missing: no model is identified anywhere on the property, so which system produced a given passage cannot be established, and no export designed for a court disclosure or AI-use certification was located on 31 Aug 2026. The product serves enterprise contracting rather than litigation, so a judicial standing order is not its usual context.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • AI Governance and Bias Disclosure
  • Commercial Transparency
Signals neither addresses in public material
  • Good Law Verification
  • Refusal and Uncertainty Behavior
  • Bar Guidance Alignment

Which one fits

Choose PostSig if

  • You need to know which terms govern after years of amendments. PostSig's LineageAI reads agreements with their amendments, service orders, side letters, invoices and approvals, works out which terms apply now, and links each answer to the documents behind it.
  • You manage market data licenses and spend. PostSig checks whether an invoice matches the agreed price, tracks renewals and cancel by dates, keeps an inventory of licenses and usage, and answers whether vendor data may be used in AI workflows.
  • Your firm already uses an enterprise AI assistant. PostSig's MCP connection gives approved clients such as Claude Enterprise and ChatGPT Enterprise its answers after checking user, data set, scope and policy, and it states SOC 2 Type II audited by Prescient Assurance, with the report under NDA.

Choose Sirion if

  • Your contracts must connect to procurement and ERP systems. Sirion documents connectors for SAP Ariba, SAP S/4HANA, Oracle ERP and Microsoft Dynamics with the direction of each flow, from Ariba sourcing events becoming contract draft requests to finished contracts replicating back into Ariba workspaces.
  • You need data handling terms you can hold the vendor to. Sirion's data processing addendum keeps each customer's data in its own application instance, deletes it within 30 days of termination, commits to incident notice within 72 hours, and publishes a subprocessor list with a right to object to changes.
  • You want post signature management inside a full lifecycle platform. Sirion covers extraction and a repository, drafting and negotiation, and performance and obligation management, with agentOS for building and deploying your own agents, and names customers including Citi, GE, Chevron and Bayer.

In summary

PostSig

PostSig, from PostSig, Inc. of San Francisco, is a post signature contract performance platform used mostly by market data, finance, procurement, legal and compliance teams at hedge funds, asset managers, banks and investment firms. Its LineageAI engine reads agreements with their amendments, side letters, invoices and approvals to work out which terms govern now and answers questions on pricing, renewals, obligations and permitted data use, with each answer linked to its sources. The AI Legal Index grades it in the top two bands on five of fifteen capability axes. It imports signed agreements from DocuSign, offers an MCP connection for enterprise AI assistants and states SOC 2 Type II. As of 22 September 2026 the index located no price, named model provider or subprocessor list.

Source: AI Legal Index, 2026

Sirion

Sirion, trading since 2012, is an enterprise contract lifecycle platform organized as Store, Create and Manage, covering extraction and repository, drafting and negotiation, and performance and obligation management, with agentOS for building and deploying custom agents. It runs on AWS, Azure, Oracle and IBM cloud, serves customers in more than 70 countries including Citi and GE, and was a Leader in the 2025 Gartner Magic Quadrant for contract life cycle management. The AI Legal Index grades it in the top two bands on nine of fifteen capability axes, with A grades on data stewardship and integration depth. It publishes its SaaS terms and data processing addendum. As of 31 August 2026 the index located no price, named model provider or accuracy measurement.

Source: AI Legal Index, 2026

Questions buyers ask

PostSig vs Sirion: which is better for post signature contract management?

On published evidence Sirion sits in the top two bands on nine of fifteen AI Legal Index capability axes and PostSig on five of fifteen, mostly because Sirion publishes a detailed data processing addendum and documented ERP connectors. PostSig is narrower and built for financial firms managing vendor, market data and investor agreements, including invoice matching and license tracking. Funds and banks with that specific problem will find more that fits in PostSig.

Do PostSig and Sirion use customer contracts for their own AI?

Their agreements allow it. PostSig's terms of service let it create anonymized or aggregated data from customer data and use it to train, develop or enhance its AI models or other large language models. Clause 4.2 of Sirion's SaaS terms lets it process customer data to generally inform the machine learning capabilities in its service. No opt out was located for either vendor. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

How does PostSig decide which contract terms apply?

PostSig's LineageAI reads the master agreement together with its amendments, service orders, side letters, invoices and approvals to work out which terms govern at a given moment, and links each conclusion back to the agreements and provisions behind it. It does not publish an accuracy rate or describe what it does when documents conflict, and its terms require customers to validate AI output before use. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

What does Sirion's data processing addendum commit to?

It states that each customer's data is stored and processed in a customer specific application instance, encrypted with AES 256 at rest and TLS 1.2 in transit, deleted or returned within 30 days of termination, and that a confirmed security incident will be notified within 72 hours. It publishes a subprocessor list, gives notice and an objection right on changes, and keeps Sirion liable for its subprocessors. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

What do PostSig and Sirion both leave unpublished?

The price, the model and any measure of accuracy. Neither publishes a price or unit of charge, names the AI models or providers it uses, or publishes an accuracy figure. Neither describes an AI governance framework with an owner or testing before release, or says what its AI does when the documents do not support an answer. Neither addresses privilege or names bar guidance on AI. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

Disclosure

Three readings to weigh. The uses of customer data described above are published terms in each vendor's own agreement, PostSig's terms of service and clause 4.2 of Sirion's SaaS terms, and a buyer should read those clauses before uploading contracts. Sirion's AI governance page names a governance program and refers readers to an account executive for detail. Sirion's liability cap could not be read in full. PostSig was verified on 22 September 2026 and Sirion on 31 August 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 24, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746