Sandstone vs Streamline AI: how they compare in 2026
These two overlap without being substitutes. Streamline AI runs the front door: requests arrive from forms, Slack, Teams and email, are classified and routed, then move through approval chains, escalations and SLA timers a legal operations team configures without engineering. Sandstone runs what happens next, with agents that redline, draft and reply to comments, completing simpler work and handing complex matters to a lawyer. On the same grid they land a point apart, Streamline AI on twelve of fifteen axes and Sandstone on eleven, and the records are close in shape as well as in score. Streamline holds the only A between them, for publishing both plans with figures, 22,900 dollars for Pro and 26,900 for Enterprise, with the feature split itemised line by line. Sandstone's distinctive commitment is contractual: clause 9.5 requires the customer's prior written permission before any subcontractor processes its data, which is a stronger control than the notification right most vendors offer.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of the capabilities the buyer is sold on: agents that read the intent of an incoming request and route it, playbooks that learn from a team's own redlines and policies with each use, and agentic workflows that redline, draft and reply to comments. Underneath sits a product that would still function without them. The repository of documents, companies, people and past decisions, the matter and task tracking, the intake channels and the reporting on cycle times and capacity are a legal operations system, and the vendor describes the platform in exactly those terms as a single system of record and an operating layer. That is the B band: models as the engine of a core capability, layered on a workflow system that stands without them. Verified 2 September 2026.
The platform underneath is a rules engine and the models sit on top of it. Intake forms, conditional routing, approval chains and SLA timers are described as no-code configuration built on rules, and legal operations teams set them without engineering — that is conventional workflow automation and it predates the AI layer. What the models drive is real and sold as core: AI email intake, automatic classification of every request by type and urgency, a Slack intake agent, the Knowledge Bot, the Velo copilot, an MCP connector, and clause evaluation against a negotiation playbook with one-click redlines. Remove the models and a working intake, matter management and reporting platform remains, which is what the company shipped first. B on the band exactly. Pages read 1 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is claimed and never described or measured. Multi-Source Citations is listed as a capability of the agentic workflow surface, alongside redlining and drafting from best practices, and the platform's whole premise is that output is grounded in the organisation's own precedent rather than a general model. Nothing published goes further. No retrieval method is described, no accuracy figure appears on any surface, no test set or evaluation is published, and no statement addresses hallucination. The one place the subject surfaces is a customer story, which describes redlines previously drafted with general-purpose tools that hallucinated Word output, framing the problem as belonging to the tools Sandstone replaced rather than disclosing anything about its own rate. Checked the home page, customers page, security page, security policy, terms of service and privacy policy on 2 September 2026. Verified 2 September 2026.
Accuracy is asserted and never measured in a form an outsider could test. The home page carries a product illustration contrasting 48% review accuracy for an auto-routed process against 92% for an AI-reviewed one, but it appears inside a dashboard mockup with no test set, no definition of review accuracy, no sample size and no date, so it is a marketing graphic rather than a published benchmark and is not treated as one. Nothing else on the AI feature pages, the security page or the home page publishes an evaluation or names a failure mode. The primary-authority and citator limbs of the higher bands do not apply, since the product classifies and routes legal requests and evaluates clauses against a customer playbook rather than retrieving case law. C: accuracy asserted without measurement.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The handoff rule is stated more plainly than by any other record in this pull: agents complete simple legal work and hand off complex tasks to lawyers. That is a real division of labour rather than a phrase, and it is supported by described review surfaces, with redlines landing as accept and reject changes and routing sending work to a named owner. Clause 1 of the terms of service adds a written control statement, that these are self-help services provided at the customer's specific direction. What is missing is the boundary itself. Nothing published defines what makes work simple rather than complex, no threshold or confidence condition is described, and nothing states what happens after an agent is wrong. The Google Workspace add-on's published permissions include sending mail on the user's behalf, so agents can act outbound, and no oversight condition is published for that. Verified 2 September 2026.
A stated division of labour with customer-owned controls. The how-it-works section commits that automated workflows handle routine tasks while attorneys step in where judgement is required, and that every action is logged and reportable; the agentic automation section frames it as saving human judgement for novel issues. The controls are real and configured by the buyer: approval chains, escalations and SLA tracking are set by legal operations without engineering, conditional logic routes work to a named team or an agent, and role-based access is scoped by team, matter type and function. A complete audit trail covers every request, decision and action. Held at B because no threshold is published at which an agent stops and hands over, nothing states which actions run unattended versus which require sign-off, and the approval chains govern the legal work rather than the AI’s own actions.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Five customers are named with substantive case studies rather than logos: Middesk, a business identity platform with a single in-house counsel; MasterClass, whose General Counsel Kevin Yung is named; Crexi; Ocrolus; and Hypertherm, a global manufacturer. Each story describes the starting position, the specific problem and what the platform was deployed to do, which is real deployment evidence with substance. Two things hold it below A. Not one figure appears anywhere across the five, so nothing is measured, and there are no dates. Several are written in the present progressive, describing what a customer is consolidating or is working to eliminate rather than what it achieved, which reads as deployment in progress. A named customer without figures is the B band exactly. Verified 2 September 2026.
Named customers and figures are both present but they do not meet in the same place. Case studies name the organisation and the outcome: Cityblock Health revamped its legal service model with a 40% reduction in operating expenditure, Hims runs a 30-person legal team on the platform, and Accordion built its legal function on it. Individual users are named with titles and employers — Ilan Hornstein, VP and Deputy General Counsel at 8x8; JP LaMunyon, Senior Legal Manager at Favor; James Harmoush, Senior Counsel at Redwood; Rita Zupancic at Super.com — but those are testimonials without figures. The four headline metrics, 10x faster intake, 50% reduced resolution time, 40% outside counsel savings and 65% reduction in response times, carry no denominator, no customer attribution and no date. B rather than A because nothing read on 1 September 2026 is dated and no method is published for the aggregate claims. G2 ratings and awards were excluded as directory material.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive and published in the agreement rather than only in marketing. Clause 9.4 of the terms of service commits Sandstone to be able to identify any of the customer's data separately from any other data under its control, and clause 10 imposes mutual confidentiality obligations surviving five years past termination. The security page states plainly that Sandstone does not train models on customer data and that its model providers operate under zero data retention agreements so they do not retain prompts or outputs, which settles the third party model provider limb. Retention is customer-set and export is available. What fails is the privilege limb the top band requires as its own. The privacy policy expressly names Legal Advice and Attorney-Client Privileged Content as a category of sensitive information it processes, including internal legal memos and drafts marked privileged, and then commits to nothing specific about how privileged material is handled. Clause 1 of the terms disclaims an attorney-client relationship with Sandstone, which is a different question. Naming privileged content as an input without addressing its treatment is what holds this at B. Verified 2 September 2026.
Substantive on training and segregation, silent on what the model provider retains. The commitment that Streamline does not train AI models on client data is published twice, on the home page and in the FAQ. Segregation is addressed with more specificity than most of this lane: role-based access control is scoped by team, matter type and function, and the security page states that legal users have access to legal-only notes reserved for the legal team, which is a real internal boundary rather than a generic permissions claim. Encryption is AES-256 at rest and TLS with 256-bit in transit, and the subprocessor list is published openly. The gaps: the no-training commitment sits on marketing surfaces and the Terms of Use are robots-disallowed, so whether a matching contractual term exists was not established and no finding is made either way. Nothing states what Clearlaw, the named LLM licensor, may retain. Privilege is addressed only by the terms disclaiming it, which is graded on UPL rather than spent here.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The advice line is addressed head on in the operative agreement, not in a footer. Clause 1 of the terms of service states that Sandstone provides self-help services at the customer's specific direction, that it is not a law firm or a substitute for an attorney, that outputs do not constitute legal advice, that a licensed attorney should be consulted to evaluate accuracy or applicability, and that use does not create an attorney-client relationship. The same clause defines the customer as a user whether a lawyer or a business user of a shared workspace, which faces the fact that non-lawyers operate the product rather than leaving the audience ambiguous. That combination is more than most records in this pull publish. Two limbs of the top band fail: no jurisdiction limits are stated anywhere, and nothing addresses the supervision and competence duties of the lawyers who sign off on the work. No bar or ethics guidance is engaged. Verified 2 September 2026.
A dedicated, product-scoped clause rather than a website disclaimer. Terms of Use clause 2.3, headed that Streamline AI is not a law firm, states that it is not a law firm or an attorney, may not perform services performed by an attorney, is not a substitute for the advice or services of an attorney, and that no attorney-client relationship or privilege is created. The privilege point is worth a buyer’s attention on its own, since it is an express disclaimer rather than silence. The Terms of Use are robots-disallowed to automated retrieval and this clause was recovered through the search index, which is a limit on the reading rather than a gap in the vendor’s disclosure. B rather than A because nothing addresses the buyer’s own supervision and competence duties, no jurisdiction limits are named, and ABA Formal Opinion 512 is not mentioned on any surface read on 1 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Nothing published addresses governance over model behaviour. No responsible AI page exists, no governance framework, no certification such as ISO 42001, no named owner, no account of what is tested before a model or workflow ships, and nothing whatsoever on uneven output across matter types, counterparties or populations. What exists nearby belongs to other subjects: SOC 2 Type 2 and penetration testing are security, and the zero data retention arrangement with model providers is data protection. Checked the home page, security page, security policy, terms of service, privacy policy, legal centre, customers page and careers material on 2 September 2026. One retrieval limit is recorded rather than held against the vendor: the Vanta-hosted trust centre at trust.sandstone.com renders client side and returned no body, and its own description claims advanced protections for agentic offerings without naming any. Nothing in it is credited or graded, and this D rests on the eight readable surfaces. Verified 2 September 2026.
No governance position located. The home page, security page, pricing page, subprocessor list, privacy policy and the recovered portions of the Terms of Use were read on 1 September 2026, and there is no responsible AI page, no named accountable owner, no pre-release testing regime, and no ISO 42001 or equivalent. Nothing addresses whether classification and routing behave evenly across request types, business units or requesters. The gap has teeth here because the AI decides how every inbound legal request is categorised by type and urgency and which team or agent receives it, so a systematic skew would show up as some requests being consistently deprioritised. Security controls and the SOC 2 attestation are a different subject under this band and are graded on Security Certifications.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Four of the five elements are published with specifics. Retention is customer-controlled, stated as you set retention with export available, and the FAQ is candid that Sandstone still stores what the customer puts in the product to run the service. Encryption is AES-256 at rest and TLS 1.3 in transit. Access control covers SAML single sign-on, role-based permissions, audit logs, session management and user lifecycle management. Incident practice is real: an in-house security team with monitoring and incident response running around the clock, plus a published vulnerability disclosure policy committing to acknowledge a report within 72 hours, provide updates, notify on resolution and offer safe harbour for good-faith research. Clause 9.5 of the terms goes further than most on supply chain governance, requiring the customer's prior written permission before any subcontractor processes its data, with written notice of purpose and due diligence. The gap is the one the B band names: no subprocessor list is published anywhere. Verified 2 September 2026.
Most of the ground is covered and incident practice is the hole. Published: AES-256 at rest and TLS with 256-bit encryption in transit, production hosting on AWS, a third-party security agency engaged to review data security protocols, regular third-party audits, vulnerability testing and log review for suspicious activity, single sign-on with Google, Okta and OneLogin, role-based access, and a complete audit trail over every request, decision and action. The subprocessor list is published openly at a public URL with each supplier’s address, contact and purpose — the band’s commonest exception, and Streamline clears it. Retention is acknowledged in the privacy policy for the period necessary to fulfil the stated purposes with deletion available by email request, but no period is given. No incident or breach notification practice was located. One caution recorded rather than credited: the ISO 27001 and SOC 1, 2 and 3 reports cited on the security page belong to the hosting data centres, not to Streamline.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A complete published position, and what it allocates to the customer is everything. Clause 14 gives real service warranties: enough trained personnel, reasonable efforts consistent with prevailing industry standards, provision in accordance with applicable laws, and no intentional introduction of malicious software. Clause 15 then disclaims all other warranties, states that the customer uses the services at its own risk, and records that Sandstone has no duty regarding how the customer interprets or uses the content. Clause 16.2 runs an indemnity from the customer to Sandstone, and no indemnity runs the other way beyond the mutual confidentiality indemnity at clause 10.4. Clause 17.1 then excludes direct damages altogether rather than capping them, so the warranties at clause 14 carry no monetary remedy. No cap figure and no insurance commitment appear. This is B rather than A because nothing here is a recourse a buyer can invoke when output is wrong, and B rather than C because the position is far more than a boilerplate limitation clause. Verified 2 September 2026.
A published position that allocates the loss entirely to the customer. The Terms of Use cap aggregate liability at the amount paid for the service to which the claim relates, or $100 where the claim does not relate to a product or service, and exclude liability to the fullest extent permitted by law with a carve-out preserving warranties and liabilities for New Jersey residents and residents of states that require it. The service, sites and user content are provided as-is without warranty, representation, condition or guarantee of any kind, express or implied. The only indemnity runs from the customer to Streamline. There is no warranty on output, no insurance position and nothing the buyer can invoke when a classification or a clause evaluation is wrong. C: liability addressed only through a limitation clause that disclaims the exposure the product creates. Clause text recovered through the search index because the Terms of Use are robots-disallowed.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Reach is broad and depth is not described. Twenty integrations are named with logos across the systems in-house legal work actually crosses, including Microsoft Word, Outlook, Teams and SharePoint, Google Docs and Drive, Slack, Salesforce, Jira, Asana, ServiceNow, Zendesk, HubSpot, Workday, Coupa, Notion, Box, Dropbox, OneDrive, Zip and Ironclad, against a claim of over fifty. Ironclad matters because it is a contract lifecycle system rather than a general business tool. A Google Workspace add-on is published on the Marketplace with its permission scopes enumerated, which is a verifiable artifact. What is absent is what the band asks for beyond names: nothing states what synchronises, in which direction, on what trigger, or what a customer configures, and no developer documentation, API reference or implementation guide was located. Named connections without a description of what they move is the B band. Verified 2 September 2026.
A real and legally specific integration set, documented by plan rather than by field. The pricing page names what each tier includes: Slack, Microsoft Teams, e-signature through DocuSign and AdobeSign, SSO and SCIM on the lower plan; storage through Google Drive, Box, OneDrive and SharePoint, a Jira custom channel, Salesforce, CLM integration with Ironclad, NetDocuments, and API access on the upper plan. Naming Ironclad and NetDocuments matters in this lane, because those are the contract and document systems in-house legal work already lives in, and tying each integration to a named plan tells an implementer what they must buy to get it. The FAQ adds that integrations are pre-built and that IT involvement is typically limited to integration configuration. B rather than A because what actually syncs and in which direction is not described; the dedicated integrations page was not opened on 1 September 2026 and is the rebuttal route.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery is implied throughout and neither of the two limbs this axis asks for is stated. No region or residency option is published anywhere, and the agreement points away from one: clause 9.6 provides that the customer's data will remain wherever Sandstone places it initially, and the customer consents to transfer to group companies, service providers or agents who may be located in other countries. The privacy policy adds that data may be stored in a foreign country whose laws protecting personal information may be less stringent than those where it was collected. No tenancy model is stated: nothing describes the platform as multi-tenant, single-tenant or privately deployed. Network isolation is named on the security page as a control, which describes segmentation rather than tenancy or residency. Under the co-equal limbs rule, either tenancy or region would clear this band and neither is present. Verified 2 September 2026.
Deployment is stated plainly and residency is partial. Production servers are hosted by Amazon Web Services, named on the security page and confirmed by the subprocessor list, and the home page offers configurable data residency, with regional data hosting sold as a named add-on on the pricing page. The privacy policy states the default position clearly: Streamline is located in the United States, processing takes place in the United States, and data from users outside the US is transferred, processed and stored there under US standards, with model contractual clauses used for EU transfers. What is missing is which regions the add-on actually covers, at what price, and any statement of the tenancy model — the server isolation referred to on the security page is described as a property of AWS data centres rather than of Streamline’s own architecture. B on the first limb: deployment model stated clearly with partial residency detail.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
SOC 2 Type 2 is stated clearly and repeatedly on a security page written for the buyer's security reviewer, alongside annual third-party penetration tests, continuous automated scanning, internal assessments, and a security addendum described as aligned to SOC 2 Type 2 and available for counsel to review. The specifics the top band asks for are not on any public page. No auditor is named, no coverage period or report date is published, and the page states that additional independent assessments are available in the trust centre rather than listed. That trust centre, at trust.sandstone.com, is Vanta-hosted, renders client side and returned no body on 2 September 2026, so neither its contents nor its access tier could be established. That is a retrieval limit and is not graded against the vendor; equally nothing in it is credited, so the grade rests on the security page alone. Verified 2 September 2026.
The certification is real and stated, and there is no route to the evidence. SOC 2 Type II is stated on the home page, the security page and the site footer, and GDPR compliance alongside it. No auditor is named, no coverage period or report date is given, no scope is specified, and no trust centre or portal exists — none was located through the navigation or footer of any page read on 1 September 2026, and there is no stated route by which a buyer could request the report. B rather than C because the standard is named in prose rather than appearing only as a badge image. The ISO 27001 certification and SOC 1, 2 and 3 reports referred to on the security page attach to the hosting data centres rather than to Streamline, and inherited infrastructure attestations are not credited to the vendor here.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Sandstone refers to its model providers repeatedly and identifies none of them. The security page states that model providers operate under zero data retention agreements so they do not retain prompts or outputs, which is a meaningful commitment about what those providers may do, and it is made without ever saying who they are. No model is named, no provider is named, no subprocessor list is published, and nothing states where inference runs. The one structural commitment located runs through the agreement rather than a disclosure: clause 9.5 requires the customer's prior written permission before any subcontractor processes its data, together with written notice of the purpose and of the due diligence performed. That gives a customer a contractual route to learn who is in the chain, which is not the same as the vendor publishing it. Referring to models without identifying what sits underneath is the C band. Verified 2 September 2026.
The supply chain is partly disclosed, and where it exists the disclosure is specific and ungated. The published subprocessor list states that Streamline licenses Clearlaw, Inc. to provide a large language model for its SmartParse product, which is a genuine model-supplier disclosure and more than most of this lane offers. The coverage is partial rather than complete: SmartParse is one capability among at least six the site markets as AI, alongside email intake, request classification, the Slack intake agent, the Knowledge Bot, the Velo copilot and clause evaluation, and no model or provider is identified for any of the others. AWS, MongoDB, Redis, Heroku and Google Workspace appear on the same list but are infrastructure and cannot be spent here. No inference location is stated for the named model, and no commitment to notify customers when the supply chain changes was located on 1 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The unit and the structure are published without any figure, which is the second limb of this band. Clause 13.2 of the terms of service states that the service is offered on a subscription basis, monthly or yearly at the customer's choice. Clause 13.3 states that services may also be offered on a usage-based model, with the details provided at sign-up and changes carrying 30 days written notice. Clause 13.4 sets out automatic renewal at the then-current non-promotional rate with cancellation in the subscription management section, and 13.5 addresses free trials. A buyer can therefore learn what is being charged for and on what cadence before contacting anyone. What is absent is everything above that floor: no pricing page exists in the site navigation or footer, no tier names or feature splits are published, no figure appears anywhere, and the only commercial route on the site is Book a Demo. The structure is stated in the agreement rather than on any commercial surface, which is an unusual place for a buyer to have to find it. Verified 2 September 2026.
The most complete pricing disclosure located in this pull. Both plans carry a figure: Pro starting at $22,900 and Enterprise starting at $26,900, published on an open page reachable without a demo or a form. The unit is stated on both — four core users included, 5,000 business users on Pro and unlimited on Enterprise — and the feature split between the plans is itemised line by line, so a buyer can see exactly what the extra $4,000 buys: storage integrations, Jira, Salesforce, Ironclad, NetDocuments and API access. Implementation is addressed rather than hidden: onboarding is stated to be included in every plan and the FAQ commits to roughly 60 days with a dedicated onboarding team. Three add-ons are named, Knowledgebot, Dynamic Docs and regional data hosting. What keeps this from being comfortable and is recorded as the weakness: the billing period is never stated, the figures are floors, and the add-ons carry no prices.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
The buyer is described precisely by role: the product is built for General Counsel, Chief Legal Officers, associate and assistant General Counsel, practice area leads and legal operations professionals at scaling companies and enterprises. That is more specific than a segment label, and the five customer stories bear it out across a range from a company with a single in-house counsel to a global manufacturer, spanning technology, consumer media, commercial real estate, financial document automation and industrial manufacturing. What is left open is the boundary. No practice areas are enumerated, because coverage is described by workflow rather than by matter type; no company size floor is stated beyond scaling; no jurisdiction or geography appears anywhere; and nothing states what the platform does not support. Law firms are implicitly outside the scope but never named as such. Verified 2 September 2026.
Segment coverage is described precisely and the boundary is real. Five role pages are published — Chief Legal Officer, General Counsel, Assistant General Counsel, legal operations and counsel — alongside two team-size pages for small and scaling legal teams, and the product is positioned throughout as purpose-built for in-house legal rather than for firms. The FAQ states a genuine limit that most vendors avoid, distinguishing the product from a CLM and saying it connects to an existing CLM rather than replacing it, which tells a buyer where the product stops. B rather than A because practice areas are not enumerated beyond contracts and general legal requests, law firm and government use are not addressed at all, and the platform is described as covering every request type without saying which request types it handles poorly.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The commitment is stated twice on the security page, once as a control and once in the review FAQ, and it is extended outward: model providers operate under zero data retention agreements so they do not retain prompts or outputs. It sits on a policy page rather than in the agreement, which is what places it here rather than a rung higher. The published terms of service were checked for a matching term and contain none. What they do contain is clause 9.3, which provides that Sandstone owns derived data, defined as data it creates from the customer's data through aggregation, de-identification or anonymisation for its own internal purposes. That clause names neither training nor machine learning, so it does not reverse the value, but a buyer weighing the no-training promise should read it. The privacy policy adds a narrower statement scoped to the Google Workspace integration, that Google data is not used to train generalised AI or ML models.
The commitment appears twice on public marketing surfaces: as a stated capability on the home page and as a direct answer in the home page FAQ on how Streamline handles customer data. No matching term was located in the agreement, but that is not a finding either way — the Terms of Use at /legal/terms-of-use are robots-disallowed to automated retrieval, and only the liability, indemnity and not-a-law-firm clauses were recoverable through the search index. The privacy policy, last updated 2023 with an internal reference to 2021, predates the AI features and does not mention model training. Recorded as policy rather than contractual on the located evidence.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is under customer control and export is available, stated on the security page as a commitment. Zero retention is not available at the Sandstone layer and the vendor says so directly rather than letting the reader assume otherwise: the FAQ states that zero data retention applies to the model providers, who process a request and do not keep the prompt or output, while Sandstone still stores what the customer puts in the product in order to run the service. That distinction is unusually clearly drawn. Two things temper it. No default window is published for a customer who sets nothing, and the agreement is permissive rather than committed at the end: clause 19.3 says Sandstone may erase the customer's data on termination, and clause 20.2 makes post-termination data retrieval subject to additional fees.
Retention is acknowledged without a period. The privacy policy commits to retaining information for the period necessary to fulfil the stated purposes and the agreement with the customer, unless a longer period is required or permitted by law, and offers deletion of personal information or of an account and all associated data on email request. No period is given, no customer configuration is offered, and nothing separately addresses how long request records, AI classifications or Knowledge Bot exchanges persist, although the platform is built around a durable audit trail of every request and decision.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The claim is made and never documented. The home page states that agentic workflows operate while respecting permissions across systems, which is an assertion that retrieval honours the access model of the source systems, and it matters here because the platform reaches into Slack, Salesforce, SharePoint, Google Drive, Jira, Box and others where a company's own permissions live. No published material describes how that is enforced, whether it is evaluated per user at query time, or what happens where a source system's permissions and Sandstone's own role-based permissions disagree. The agreement contributes a separability commitment at clause 9.4, that Sandstone will be able to identify the customer's data separately from any other data under its control, which addresses tenant separation rather than separation between users or matters inside one customer. Role-based permissions and SAML single sign-on are named on the security page without detail.
Streamline publishes a permission model in its own terms rather than inheriting one. The home page states role-based access control scoped by team, matter type and function, and the security page states that permission levels are designated by role and team, that legal users have access to legal-only notes reserved for the legal team, and that the customer controls the level of access each user has. Recorded as a documented own model rather than inheritance of a document system access list, because the product is the system of record for requests rather than a retrieval layer over an existing repository. No description of how the boundary is enforced at query time by the AI features was located on 1 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
The privacy policy addresses compelled disclosure directly, listing a subpoena or court order, compliance with any law, protecting the safety of any individual or the general public, and preventing violation of customer relationship terms. It also states separately that personal information may be disclosed as required by law or governmental audit. Nothing anywhere commits to telling the customer, and nothing reserves discretion over notice either: the question of notification is simply never reached. Checked the privacy policy, the terms of service including the confidentiality clause at 10, the website terms of use, the security page and the security policy on 2 September 2026. Clause 10.3 mentions disclosure to comply with a court order in the context of returning confidential information at the end of the agreement, which is not a notice provision.
The privacy policy states that Streamline uses customer information solely to administer its services and not for any other reason, except where compelled pursuant to applicable law or by a court order. The standard is narrower than most in this lane, being limited to legal compulsion rather than extending to disclosures the vendor considers permitted or appropriate. No commitment to notify the customer of such a request, and no carve-out for notice where lawfully permitted, was located on 1 September 2026, and no transparency report is published.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Checked the home page, customers page, security page, terms of service and privacy policy on 2 September 2026. No public material identifies a corpus, and none is claimed. The platform's material is the customer's own contracts, templates, redlines, policies and past decisions, drawn from the systems the business already uses, so it does not retrieve primary law and the coverage and title risks this signal tracks do not arise in their usual form. Nothing published suggests any external legal content is bundled.
The product does not retrieve primary law, so there is no legal corpus to source. Streamline’s AI operates on the customer’s own inbound requests, policies and negotiation playbooks, and the Knowledge Bot is described as returning policy-aligned answers from the customer’s material. No public material identifies any statutory or case law source, licence basis or update cadence, checked across the home page, AI feature listings, security page and privacy policy on 1 September 2026. Recorded as not addressed because the question does not arise for this product class.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Checked the home page, the product surfaces described there, the customers page and the security page on 2 September 2026. No public material addresses subsequent history, treatment flags or citator coverage, and none is claimed. The product is built on the organisation's own precedent and business context rather than on primary authority, so no good law check is offered; the honest reading is that the question is not addressed rather than that a weaker form of checking exists.
No citator, and none would apply. The product classifies and routes legal requests, evaluates contract clauses against a customer playbook and answers policy questions from customer content; it does not cite legal authority whose subsequent history could be checked. Nothing on the product or AI feature pages addresses currency of legal authority. Checked 1 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Checked the home page, customers page, security page, security policy and terms of service on 2 September 2026. Nothing describes what the platform does when it cannot ground an answer. The nearest published statement is the division of labour on the home page, that agents complete simple legal work and hand off complex tasks to lawyers, which is a routing rule rather than an account of abstention: it does not say what an agent does when it is uncertain within work it has already accepted. No confidence or grounding score is exposed and no no-answer path is documented, so the weaker values are false of this record as well.
No located public material addresses what the product does when it cannot ground an answer or confidently classify a request. The platform pages describe automatic classification by type and urgency and a Knowledge Bot returning policy-aligned answers, and state that attorneys step in where judgement is required, but that is a division of labour rather than a described abstention path. No confidence signal, no fallback to manual triage on low confidence, and no no-answer behaviour is documented. Checked across the home page, AI feature listings and security page on 1 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
Searched the AI Hallucination Cases database maintained by Damien Charlotin, and reporting drawing on it, on 2 September 2026 on both the product name Sandstone and the corporate name Glaze AI. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product. Two things bound the search: Sandstone is a common word that appears in unrelated company names, and the platform is sold to in-house departments for intake and contract work rather than to litigators for filing, so the exposure this signal tracks is structurally lower than for a research tool.
No court order, opinion or disciplinary record naming this product has been located. The AI Hallucination Cases database maintained by Damien Charlotin was searched on 1 September 2026 on the product name and on the corporate name LegalDesk, alongside general sanctions coverage, and nothing naming the product was found. This is a statement about the public record rather than a finding about the product. The product classifies and routes requests rather than generating citations to legal authority.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Checked the home page, customers page, security page, security policy, terms of service, website terms of use, privacy policy and legal centre on 2 September 2026. No public material engages with ABA Formal Opinion 512, any state bar opinion, or any other named ethics guidance. The terms of service do engage professional responsibility ground in substance at clause 1, stating that Sandstone is not a law firm, that outputs are not legal advice, that a licensed attorney should be consulted, and that no attorney-client relationship arises, but that is the vendor's own framing rather than engagement with the guidance its buyers are bound by, which is what this signal records.
No located public material engages with bar or ethics guidance. ABA Formal Opinion 512 is not named and no state bar opinion appears across the home page, security page, pricing page, privacy policy or the recovered portions of the Terms of Use, checked 1 September 2026. The terms do state that Streamline is not a law firm and that no attorney-client relationship or privilege is created, which is a positioning clause rather than engagement with the guidance its in-house buyers are bound by.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Checked the home page, customers page, product descriptions and terms of service on 2 September 2026. Nothing addresses billing, fee or disclosure treatment of AI-assisted work, and no per matter record distinguishing AI-assisted work was located. The platform does emit matter-level measurement: reporting aggregates cycle times, risk exposure, capacity and deviation rates so legal operations can benchmark and report to the business. That records the work, not what the AI did within it, so it does not meet the audit record value. Two points of context. Unlike most records on this signal, no time-savings figure is claimed anywhere, so even the savings-claims value is not made out. And the direction this signal assumes is inverted here: Sandstone's buyer is the in-house department that receives bills rather than the firm that issues them.
Public materials claim time and cost savings — 10x faster intake, 50% reduced resolution time, 40% outside counsel savings, and a 40% reduction in operating expenditure at Cityblock Health — without addressing how AI-assisted work should be recorded or disclosed on a bill. The platform does emit a complete audit trail of every request, decision and action, but that is an operational record of legal work generally rather than a record of which work was AI-assisted, which is the distinction this signal turns on. The primary buyer is an in-house team that does not bill clients. Checked 1 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The material exists and is reachable only by asking. The security page is written for exactly this purpose, headed as something to send to a security team, and it states that reports, questionnaires and the rest of the review pack are in the trust centre, alongside a security addendum described as available for the customer's counsel to review. That is more than nothing published, so the bottom value is false of this record. It is not a published list either: the trust centre is Vanta-hosted, returned no body on 2 September 2026, and its access tier could not be established, and no subprocessor or model provider list appears on any public page. Clause 9.5 of the terms gives the customer a contractual right of prior written consent before any subcontractor processes its data, with notice of the purpose and the due diligence performed, which is a route to the information rather than a disclosure of it.
A current subprocessor list is published openly at a public URL, with no NDA, form or sales conversation in the way. It names each supplier with an address, a contact and the purpose it serves: Heroku for application containers, AWS for hosting, MongoDB Atlas as database provider, Redis Labs for email routing, Google Workspace for email, and Clearlaw as the licensed large language model provider for the SmartParse product. Naming an LLM supplier on an ungated list is rare in this lane. Recorded at the listed tier rather than higher because no client-facing disclosure pack or DPA annex was located, and because Clearlaw is the only model supplier named while several other AI features are not covered.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Checked the home page, product descriptions, customers page, security page and terms of service on 2 September 2026. Nothing addresses judicial standing orders, AI use disclosure or verification certification. Audit logs are named on the security page as an access control and reporting covers cycle times and workload, neither of which records which model produced which passage or what it retrieved, so no document-level disclosure record is described. The product class is relevant: the platform is sold to in-house departments for intake, contracting and workflow rather than for court filing, so a filing disclosure obligation would usually fall on the outside counsel handling the matter.
No located public material addresses court disclosure or AI-use certification. The platform publishes a complete audit trail over every request, decision and action, and historical analysis across decisions, approvals and governance actions, so some elements of an internal record exist; but nothing identifies which model produced which output, records a human verification step against an AI action, or describes an export framed for a court disclosure obligation. Checked 1 September 2026. The buyer is an in-house legal function managing internal requests rather than a filer, so the question rarely arises.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- AI Governance and Bias Disclosure
- Primary Law Corpus Provenance
- Good Law Verification
- Refusal and Uncertainty Behaviour
- Bar Guidance Alignment
- Court Disclosure Support
Which one fits
Choose Sandstone if
- The work itself is the bottleneck, not the routing. Sandstone's agents redline, draft and reply to comments, completing simpler work and handing complex matters to a lawyer, with playbooks built from the team's own templates, redlines and policies that learn with each use so negotiating positions stay consistent across the organisation.
- You want a say in who else touches the data. Clause 9.5 of Sandstone's terms requires the customer's prior written permission before any subcontractor processes its data, with written notice of the purpose and of the due diligence performed, which is a stronger control than the notification right most vendors offer, and clause 9.4 commits Sandstone to be able to identify a customer's data separately from any other data it holds.
- Your work crosses twenty systems before it is done. Sandstone names integrations across Microsoft Word, Outlook, Teams and SharePoint, Google Docs and Drive, Slack, Salesforce, Jira, ServiceNow, Zendesk, HubSpot, Workday, Coupa, Notion, Box, Dropbox, OneDrive, Zip and Ironclad, with a Word add in and a Google Workspace add on whose permission scopes are published on the Marketplace.
Choose Streamline AI if
- You want to know the cost before the demo. Streamline AI publishes a figure for both plans on an open page, at 22,900 dollars for Pro and 26,900 for Enterprise, with four core users included on each and the feature split itemised line by line so a buyer can see exactly what the difference buys, and onboarding stated to be included with a roughly sixty day implementation.
- The front door is the problem. Streamline captures requests from configurable forms and from Slack, Teams and email, classifies each one by type and urgency, applies routing rules and opens a structured record, then runs conditional routing, approval chains, escalations and SLA timers that legal operations configures without engineering, with access scoped by role, team and matter type and legal only notes staying inside the legal team.
- You need to tell your reviewer who processes what. Streamline publishes its subprocessor list openly at a public URL with each supplier's address, contact and purpose, and it names the model licensor behind one capability, stating that Clearlaw, Inc. is licensed to provide the large language model for SmartParse, which is more than most of this market discloses.
In summary
Sandstone
Sandstone is an AI platform for in house legal departments built around the intake, routing and execution of legal requests, with agents that read intent and route work, a repository of documents, companies, people and past decisions, playbooks built from a team's own templates and redlines, and agentic workflows that redline, draft and reply to comments before handing complex matters to a lawyer. The AI Legal Index grades it in the top two bands on eleven of fifteen capability axes. Its terms require the customer's prior written permission before any subcontractor processes its data, and its security page states zero data retention agreements with model providers. As of 2 September 2026 the index located no named model provider, no accuracy measurement and no AI governance material.
Streamline AI
Streamline AI is the legal front door for an in house team: business users submit requests through configurable forms or from Slack, Teams and email, and the platform classifies each one, applies routing rules and opens a structured record, then runs approval chains, escalations and SLA timers configured by legal operations without engineering, alongside matter management, contract review against a playbook and dashboards. The AI Legal Index grades it in the top two bands on twelve of fifteen capability axes, with an A on commercial transparency: both plans carry a published figure with the feature split itemised. It publishes its subprocessor list openly and names Clearlaw as the model licensor behind SmartParse. As of 1 September 2026 the index located no AI governance material and no accuracy measurement.
Questions buyers ask
Are Sandstone and Streamline AI alternatives to each other?
They overlap without being substitutes. Streamline AI runs the front door, capturing requests, classifying and routing them and moving them through approval chains and SLA timers. Sandstone runs what happens after, with agents redlining, drafting and replying to comments and handing complex matters to a lawyer. A team with an intake problem and a team with an execution problem will not shortlist the same product, though both platforms touch intake. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What does each cost?
Streamline AI publishes both plans on an open page, at 22,900 dollars for Pro and 26,900 for Enterprise, with the feature split itemised and onboarding included, though the billing period is not stated and both figures are floors. Sandstone publishes the structure without the number: its terms state that the service is offered on a monthly or yearly subscription and may also be offered on a usage basis, with automatic renewal at the then current rate, and no pricing page exists on the site. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Do either name the model behind the AI?
Streamline AI names one: its published subprocessor list states that it licenses Clearlaw, Inc. to provide the large language model for SmartParse. That covers one capability among at least six the site markets as AI, and no model or provider is identified for the others. On Sandstone no model or provider is named anywhere, though the security page states that its model providers operate under zero data retention agreements so they do not retain prompts or outputs. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What do they say about your data?
Both state that they do not train on customer data. Sandstone adds zero data retention agreements with its model providers, a commitment to identify customer data separately, mutual confidentiality surviving five years, and customer set retention with export. Streamline states the same training position on its home page and in its FAQ, publishes its subprocessor list openly, and offers configurable data residency as a named add on, with the default position being processing in the United States. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What do Sandstone and Streamline AI both leave unpublished?
Neither publishes an accuracy measurement: no test set, evaluation or named failure mode appears on either record, and Streamline's one accuracy figure sits inside a dashboard illustration rather than a benchmark. Neither publishes an AI governance position. And neither states the threshold that matters most on an agentic product, which is what makes a matter complex enough to reach a lawyer rather than being completed by the system. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
The shared gap is governance. Both products classify or route legal work with models, and neither publishes an accountable owner, a pre release testing regime, or anything on whether outcomes hold evenly across request types, business units or requesters. Two specifics belong alongside it. Sandstone's privacy policy names legal advice and attorney client privileged content as a category of sensitive information it processes, including internal memos and drafts marked privileged, and nothing published states how that material is handled, while clause 17.1 of its terms excludes direct damages altogether rather than capping them. On Streamline AI, the ISO 27001 and SOC reports referenced on its security page attach to the hosting data centres rather than to Streamline, and its terms of use are closed to automated retrieval so the clause text was recovered through the search index. Sandstone was verified on 2 September 2026 and Streamline AI on 1 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.