C
Conga CLM

Conga CLM is the contract lifecycle management product in Conga's commercial operations suite, covering contract request and generation from pre-approved templates and clause libraries, workflow and approval routing, negotiation, electronic signature, a centralised searchable repository, obligation and renewal tracking, and reporting. It is sold in two delivery forms: the original Salesforce-based application, and a full software-as-a-service version running on the Conga Advantage Platform that can sit alongside any CRM, ERP or procure-to-pay system.

Authoring and review happen in Microsoft Word or Google Docs as well as in a browser editor, and the product connects to Conga's own CPQ, document generation, billing and pricing products so that agreed terms and prices flow into the contract. The AI is branded AiMe and runs as a layer across the whole suite rather than inside the CLM alone. In contracting it imports third-party, legacy and acquired agreements in bulk and turns them into structured data without the customer training a model, compares draft language against a negotiation playbook, flags high-risk clauses, proposes redlines, summarises long agreements, answers questions about the repository in natural language, and extracts obligations into dashboards and alerts.

The generative features run on Microsoft Azure OpenAI, and document processing additionally uses Google Cloud Vision for optical character recognition, Amazon Textract for table detection and Zuva for provision extraction, each under a stated zero-retention arrangement. Conga publishes an Artificial Intelligence Addendum, a Data Processing Addendum and a trust centre describing how those features are governed. Buyers are legal, procurement, sales, finance and business operations teams, and named customers include Southwest Airlines, LinkedIn, AXA, Peloton and Cotality. The contracting entity is Conga Corporation of Broomfield, Colorado.

Vendor siteBroomfield, Colorado, United States
Last verifiedSeptember 12, 2026
Compare with other vendors

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The models are the engine of a core capability layered on a product that would function without them, which is B and is the vendor's own architecture. AiMe is described as a shared AI layer running across the whole commercial suite, connecting workflow data across CPQ, CLM, price optimisation and document automation and suggesting next steps, rather than as the CLM itself. Underneath sits a full contract lifecycle platform that long predates it: template and clause-library generation, approval routing, negotiation, electronic signature through Conga Sign, a searchable repository, obligation and renewal tracking, and reporting.

Strip AiMe out and a working CLM remains, which is precisely what the Salesforce-based edition was for years. What is recorded on the other side, because it is moving: the June 2026 platform release is described as AI-enhanced throughout, bulk import and extraction is presented as the way contracts enter the system at all, and the March 2026 AiMe release adds agents that act inside quoting and contracting workflows. The direction is toward the models becoming the product, and the record says so, but the platform is still sold and priced as a contract system with intelligence on top. Verified 12 September 2026.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Grounding is real and documented, short of any accuracy figure an outsider could test, which is B. R15 governs the inapplicable limbs: the product cites no legal authority, so authority grounding and citation-status checking do not bite and are not counted against it. What does bite is grounding and measurement, and the grounding disclosure is stronger than most in this lane. The pipeline is named component by component on the trust centre: Google Cloud Vision for optical character recognition, Amazon Textract for table detection, Zuva for provision extraction and Azure OpenAI for language processing, which tells a reader how a clause becomes an assertion.

Output is grounded in the customer's own repository, playbook and clause library, extraction is described as requiring no model training by the customer, and the vendor states that AiMe surfaces how every recommendation is generated with the reasoning visible to the user and a confidence score shown wherever it makes a suggestion. Accuracy is addressed only as a disclaimer: the Artificial Intelligence Addendum states that outputs may be inaccurate, incomplete or misleading and disclaims all warranty as to accuracy or completeness.

No figure, test set, error rate or published benchmark result was located; third-party models are said to be benchmarked before release and no results are published. Verified 12 September 2026.

Source: Vendor Published
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a lawyer checks it are all published: modes, thresholds, review surfaces, and the route a matter takes back to human judgement.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Modes, constraints, review surfaces and the route back to human judgement are all published, which is the A band, and most of it is contractual rather than marketing. What the system runs alone is stated as a boundary: AiMe never acts autonomously on high-stakes decisions. What constrains it is named as three specific mechanisms, agent guardrails, approval thresholds, and human-in-the-loop confirmation, each of which can be built into a workflow, which is the threshold limb answered in the product's own idiom rather than dodged.

The review surfaces are real and are the strongest part: the vendor states that AiMe surfaces how every recommendation is generated, that users see the reasoning behind AI-driven actions, and that a confidence score is shown wherever AiMe makes a suggestion, alongside redlines a user accepts or rejects and a complete audit trail of every action and approval. The route back to human judgement is contractual: the Artificial Intelligence Addendum makes the customer solely responsible for evaluating and validating outputs, states that the customer shall not rely on AI outputs as the sole basis for any decision with legal, financial, regulatory or other material impact, requires appropriate human review and independent judgment, places authorising and supervising agent actions on the customer, and records that the features are intended to support and not replace human decision-making.

One limit is recorded rather than credited: the guardrails and thresholds are described as configurable rather than as defaults, and the same document states that Conga does not monitor or review AI-generated outputs. Verified 12 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

A named customer without figures, which is the B band's stated shape. The published customer-story library carries dated, named accounts, and one of the three surfaced on the index page is on this product: Cotality, formerly CoreLogic, described as elevating its client service capabilities with Conga CLM, dated 5 September 2024. The other two dated stories name DigiKey on price management, dated 27 April 2026, and Kalixia at 160 times faster document generation, dated 19 March 2025, and neither is the contracting product, so they are recorded rather than credited here.

Around that sit customer logos on the product and pricing pages, Southwest Airlines, LinkedIn, AXA, Peloton, Cotality, T-Mobile, Adobe, Box and Kraft Heinz, which under the C band would stand in for evidence if they were all there was. What keeps the row off A is measurement and attribution together. The CLM story carries no figure. The figures that are published sit apart from any named customer: a 9 per cent revenue increase claimed beside the logo strip with no basis stated, an AI-assisted review claim of 50 per cent less review time on the features page, and three headline counters on the product page that render as zeros.

Analyst placement, G2 Leader recognition across five grids with first rankings for enterprise usability and relationships, is recorded and not credited, since analyst placement is not deployment evidence. Verified 12 September 2026.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Four of the five A limbs are met contractually and one is absent, and R33 makes the absent one decisive. Training use is addressed in the Artificial Intelligence Addendum rather than on a policy page: Conga shall not use AI Inputs or AI Outputs to train or improve any AI or machine learning model beyond the limited licence to provide, maintain or improve the Services for that customer's benefit; Customer Data shall not be used to train global or foundational models serving multiple customers; and no third party may use Customer Data or AI Output to train, fine-tune, validate, test or otherwise develop any model.

Segregation at the level an in-house buyer needs is documented: tenant environments are logically separated with dedicated encryption keys per tenant. Retention and deletion are stated in the Data Processing Addendum, which limits retention to the duration absolutely necessary and requires return and deletion at the customer's election after the agreement ends. The position on third-party model providers is explicit and unusually detailed: prompts, completions, embeddings and training data sent to Azure OpenAI are not available to OpenAI, are not used to improve OpenAI models and are not used to improve Microsoft or third-party products, and a zero-retention arrangement is stated with each document-processing provider.

The limb that fails is privilege and work product, which is addressed nowhere on any surface read. On a product sold to legal departments to hold their agreements, that silence is the whole distance to A. Verified 12 September 2026.

Source: Vendor Published
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

A real published position on advice versus tooling, short of the supervision and competence dimension, which is B. The position is contractual and specific rather than a website disclaimer: the Artificial Intelligence Addendum states that AI-generated outputs may be inaccurate, incomplete or misleading, disclaims any warranty of fitness, makes the customer solely responsible for evaluating and validating outputs before use, and then draws the line that matters here, that the customer shall not rely on AI-generated outputs as the sole basis for any decision that may have legal, financial, regulatory or other material impact, and that appropriate human review and independent judgment should be exercised.

It extends the same allocation to agentic behaviour, making the customer responsible for determining whether agent actions are appropriate and for authorising and supervising them. C does not fire: the audience is named across published function pages, the marketing does not describe the product in advice terms, and the clause is not boilerplate. What is missing for A is the lawyer's own side. Nothing published addresses how a supervising lawyer discharges competence or oversight duties over AI-drafted contract language, nothing states which of the named buyer groups may use which capability, and no jurisdictional limit appears anywhere.

That last gap is sharper than usual on a product marketed to sales and procurement users generating contract positions in the same tenant as legal. Verified 12 September 2026.

Source: Vendor Published
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

A published governance framework with real substance, short of testing results, which is B, and it sits at the top of that band. The substance is documented and contractual, not a principles page. The Artificial Intelligence Addendum records a cross-functional AI Governance Committee responsible for oversight of AI within the Services with a focus on risk management, accountability and compliance, which periodically reviews AI-related risks, controls and mitigation measures including data protection, security and appropriate human oversight.

It commits Conga to internal policies for the ethical and responsible use of AI covering oversight of training data, bias mitigation and human interpretability, to personnel training on responsible development and deployment, and to full cooperation with a customer's own AI impact assessments and transparency obligations. Governance is anchored to a named external framework, the NIST AI Risk Management Framework, by its four core functions of Govern, Map, Measure and Manage.

The vendor also publishes its own regulatory classification, stating that its products qualify as minimal or limited risk AI systems under the EU AI Act, and states that third-party models undergo testing, bias auditing and benchmarking before release with rollback to any prior model version available within hours. What holds it off A is the limb the band names: no results are published. No bias audit finding, evaluation output, model card or statement about uneven performance across contract types or drafting conventions was located anywhere. Verified 12 September 2026.

Source: Vendor Published
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Retention, deletion, access control, subprocessors and incident practice are all published, current and specific enough to hold the vendor to, which is the A band, and every limb rests on a document a buyer can read before signing. Retention: the Data Processing Addendum states that retention of personal data should generally not be required and that any retention is limited to the duration absolutely necessary to perform the Services, with daily backups retained for thirty days, and a zero-retention arrangement stated with each third-party document-processing provider.

Deletion: return and deletion at the customer's election within a reasonable period after the agreement ends, with the customer able to delete within the Services and assistance where it cannot, and a prompt-compliance obligation on deletion requests under the CCPA attachment. Access control is documented control by control: role-based authorisation, least privilege, quarterly access reviews, joiner-mover-leaver revocation, VP-level approval for access escalation, multi-factor authentication, managed firewalls, host-based intrusion detection, encryption at rest and TLS at 256-bit or stronger in transit, per-tenant encryption keys, and no customer data on laptops or removable media.

Subprocessors: a published list, fifteen days' notice before appointing a new one, a right to object with a termination and refund remedy, flow-down obligations, and Conga liable for subprocessor acts as if performing them itself. Incident practice: notification within 48 hours of becoming aware under the DPA, a documented response plan with root-cause analysis, and a 24/7 security team. Verified 12 September 2026.

Source: Vendor Published
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Liability for what the AI produces is addressed only by disclaiming it, which is the C band, and here the disclaimer is unusually explicit rather than buried in a general limitation. The Artificial Intelligence Addendum states that Conga makes no warranty, express or implied, regarding the accuracy, completeness, non-infringement or fitness for a particular purpose of any AI-generated output, that the customer is solely responsible for evaluating and validating outputs, and then that, to the maximum extent permitted by applicable law, Conga shall not be liable for any losses, damages or claims, including third-party claims, arising from the customer's use of, reliance on, or actions taken based on AI-generated outputs or actions performed by agentic AI capabilities.

That is the question this axis asks, answered in the negative and in terms. One genuine allocation runs the other way and is recorded: the Data Processing Addendum makes Conga liable for the acts and omissions of its subprocessors to the same extent as if it had performed the services directly, which matters given how much of the AI pipeline sits with third parties. A limit on this reading is stated plainly: the Master Services Agreement itself was not opened, so the general liability cap, indemnity scope and any insurance position are not established, and a reading of it could move this row.

It would have to reverse the Addendum to do so, and the Addendum is the instrument that governs the AI question. Verified 12 September 2026.

Source: Vendor Published
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Real integrations, named and documented, short of the depth an implementer could work from, which is B. The named connections are substantial and several are structural rather than bolt-on. The product exists in two forms, one of which runs natively on the Salesforce platform and is listed on the Salesforce AppExchange, which is about as deep as a CRM integration gets. Authoring and review run inside Microsoft Word and Google Docs, Microsoft Dynamics is named on the product page, and the vendor states the platform edition connects to any CRM, ERP or procure-to-pay system.

Inside Conga's own estate the connections are described functionally: pricing, terms and configurations from CPQ flow automatically into a contract, documents are generated through Composer and signed through Conga Sign, and price optimisation feeds contract pricing. Supporting surfaces exist and are named, a product documentation site at documentation.conga.com and a developer hub at developer.conga.com. What is not established is depth.

Neither the integrations page nor the developer hub was opened, no field-level mapping or sync direction is published on the surfaces read, and the recurring claim of connecting to any CRM or ERP describes reach without describing what moves. Under R25 those two surfaces would corroborate and could lift this row; they are named here as published and unread. Verified 12 September 2026.

Source: Vendor Published
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Deployment model is stated clearly with partial residency detail, which is B, and the model side is fully answered. Two delivery forms are published and distinguished: the original Salesforce-based application, and a full software-as-a-service edition on the Conga Advantage Platform introduced to give buyers a CLM interface independent of Salesforce. What changes between them is published and material rather than cosmetic, and it is in the agreement: the Data Processing Addendum states that for services hosted on the Salesforce platform Conga does not back up customer data and there is no recovery point objective, against daily backups retained thirty days and a one-hour recovery point objective with a twenty-four hour recovery time objective elsewhere.

Infrastructure is named, Salesforce, Amazon Web Services and Azure, with data stored on servers managed by Salesforce and AWS, and tenant environments logically separated with dedicated encryption keys. Residency is where it falls short of A. Availability is described as multi-region across the United States, the European Union and Asia-Pacific with residency options included, which names continents rather than regions; no region list or menu is published, nothing states which region a given tenant lands in or how a buyer chooses, and where processing happens is not distinguished from where data is stored.

The AI path is the sharpest instance: content reaches Azure OpenAI, Google Cloud Vision, Amazon Textract and Zuva, and no surface states where any of that runs. Verified 12 September 2026.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Certification is real, named and scoped, and the evidence behind it is not reachable without a customer relationship, which is B at the top of the band. A genuine trust centre exists, is ungated and is linked from the site navigation. The standards are named individually rather than displayed as a badge wall: SOC 2 Type II with a stated scope of full platform coverage and audited annually, ISO 27001, ISO 27701 described as the privacy extension to it, PCI DSS, HIPAA Security with annual audits, GDPR, CCPA, alignment to the NIST AI Risk Management Framework, and certification under the EU-US Data Privacy Framework, which is the one item a reader can independently verify because the Data Processing Addendum points to the public Department of Commerce list.

The programme behind them is documented: annual third-party penetration testing, biannual application vulnerability assessment, continuous automated threat hunting, static and dynamic code analysis before release, a severity-based patching service level, background checks, annual security training, and a published vulnerability disclosure programme. Two things hold it off A. No auditor is named, no report period, observation window or certificate number is published for any standard, and no report is carried on the trust centre itself.

The route to the evidence is the Data Processing Addendum, which makes reports available on the customer's request subject to confidentiality, so a prospective buyer cannot read the scope of what was audited before contracting. Verified 12 September 2026.

Source: Vendor Published
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The supply chain is disclosed further than anything else in this lane and stops one limb short of A, which is B under R34. Providers are identified individually and by function, not gestured at: generative features run on Microsoft Azure OpenAI, and the document-processing agents additionally use Google Cloud Vision for optical character recognition, Amazon Textract for table detection and Zuva for provision extraction, each named with what it does and each under a stated zero-data-retention arrangement.

Where the models run is stated, which few records manage: the Azure OpenAI Service is described as fully controlled by Microsoft, with Microsoft hosting the models in its own Azure environment and the service not interacting with any system operated by OpenAI, and the consequences are spelt out, that prompts, completions, embeddings and training data are tokenised in transit, are not available to OpenAI, and are not used to improve OpenAI, Microsoft or third-party models.

Change notification is contractual and specific: the AI providers are subprocessors, and the Data Processing Addendum gives fifteen days' notice before any new subprocessor is appointed, with the name, location and activity disclosed, a right to object, and termination with a refund if no workaround is available. The limb that fails is the first one. No model is named. The addendum's closest approach is a parenthetical reference to Azure OpenAI GPT, which is a family rather than a version, and no surface states which model generates a summary or a redline or when that changes. Verified 12 September 2026.

Source: Vendor Published
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

No pricing information is published at any level, including the unit of charge, which is the D band and is the plainest instance of it in this lane. The pricing page exists, is linked from the top-level navigation, and carries no price, no band, no term, no tier table, no feature-by-tier comparison, no unit of charge, no minimum, no statement of whether the product is licensed per user, per contract or per platform, and no indication of what implementation adds.

What it does carry is a heading, a paragraph saying that every business is unique and that the vendor provides clear details about product options and associated costs, a list of six things the pricing is said to prioritise, one of which is Transparency, two customer logo strips, and a quote request form. That is a page which invites a sales conversation and nothing else, which R10 identifies as an absence rather than as structure, and it is why no VendorPricing row is written for this record.

The nearest thing to a published tier anywhere on the estate is a line on the platform page inviting the buyer to add CLM Advanced features such as a clause library, version control and redlining, which names one upgrade and three features on a product page; it is recorded here for completeness and is not pricing information. Commercial terms are not published either: the Master Services Agreement was not opened, so payment terms, renewal, uplift caps and termination rights are not established from any surface read. Verified 12 September 2026.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Segment coverage is described with real substance and the boundaries are left open, which is B. Who the product serves is published as its own navigation tier with seven named functions, Legal, Procurement, Sales, Finance, IT, Business Operations and Pricing, each with a page of its own, and the CLM material addresses legal, sales and procurement side by side with a different task list for each: legal gets workflow, authoring, AI reviewing and redlining, contract compliance and risk management, procurement gets obligation management, AI-extracted terms and pricing, and sales gets generation, AI-assisted negotiation and renewals.

Industry coverage is enumerated across seven pages, technology, financial services, healthcare, life sciences, manufacturing, transport and logistics, and distribution, and a process tier organises the same estate by contracting stage. The published customer base bears the breadth out across airlines, insurance, media, retail and property data. What is left open holds it off A. No practice area inside a legal department is named as supported or unsupported, no statement of what the product is not for appears anywhere, nothing distinguishes which capabilities are available to a non-lawyer user in a shared tenant, and there is no jurisdictional or language coverage statement despite the product being sold and localised into German and French. Verified 12 September 2026.

Source: Vendor Published
Sources on file

5 public documents

The public pages on file for Conga CLM, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Permitted, in the contract

The published agreement expressly reserves a right to train on customer content, with no opt out located. Any de identification, anonymisation or aggregation qualifier is recorded in the summary.

Training on customer content is expressly permitted in the published agreement and is fenced more tightly than any other record in this pull, and both halves belong in the reading. The permission is in the Artificial Intelligence Addendum section (c): Conga shall not use Customer Data to train global or foundational models that serve multiple customers, and any model training using Customer Data shall be limited to models specific to the customer's instance or tenant.

So training happens, on the customer's own data, into a model only that customer uses, and no opt-out is located. The fences around it are unusually strong and are contractual, not policy: Conga does not use Customer Data to train third-party foundational models, naming Azure OpenAI GPT as the example; section (d) provides that Conga will not permit any third party to use, directly or indirectly, any Customer Data or AI Output to train, fine-tune, validate, test or otherwise develop any AI system or model; and section (b) states that beyond a limited licence to provide, maintain or improve the Services for that customer's benefit, Conga shall not use AI Inputs or AI Outputs to train or improve any AI or machine learning model.

The trust centre adds that models trained on one customer's data are never used to score or recommend for another and that model training takes place within the customer's environment. One carve-out is reserved: Service Attributes, defined as anonymised and aggregated usage information, may be used to train and refine models, and are stated not to be Customer Data.

Source: Vendor PublishedAny model training using Customer Data shall be limited to models specific to Customer's instance or tenant.As of Sep 12, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Customer controlled, no zero option

The customer controls the retention window, by product configuration or by contractual instruction, but zero retention is not stated as available.

The customer controls the retention window by contractual instruction and no zero-retention setting is published for the product itself, which is this value. The Data Processing Addendum sets the default at Attachment A: retention of personal data should generally not be required, and where it is retained the period is limited to the duration absolutely necessary to perform the Services. Section 9.6 puts the end state in the customer's hands, requiring return and deletion at the customer's election within a reasonable period after the agreement concludes, with the customer responsible for correcting, blocking or deleting within the Services and Conga assisting where it cannot.

The CCPA attachment adds an obligation to comply promptly with any customer instruction to delete. One specific figure is published and is worth having: daily backups of customer data are retained for thirty days, except for services hosted on the Salesforce platform, which Conga does not back up at all. The strongest retention fact on this record sits at the model layer rather than the product layer and is recorded here rather than credited to the top value: Conga states a zero-data-retention policy with each third-party document-processing provider, so documents sent to Azure OpenAI, Google Cloud Vision, Amazon Textract and Zuva are processed in real time and not stored afterwards. No zero-retention setting is offered to the customer inside the Services.

Source: Vendor Publishedany retention period will be limited to the duration absolutely necessary to perform the ServicesAs of Sep 12, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Own model, documented

The product maintains its own permission model, documented, requiring the firm to keep it aligned.

The product maintains its own documented permission model that the customer must administer, which is this value. Separation between customers is documented as architecture rather than asserted: tenant environments are logically separated with dedicated encryption keys, each tenant holds unique keys, and the training position reinforces it, models trained on one customer's data never being used to score or recommend for another and training taking place within the customer's environment.

Inside a tenant the model is Conga's own and is documented in the Data Processing Addendum's security attachment: role-based authorisation, least privilege, quarterly access reviews, multi-factor authentication, and the customer's own ability to limit access to authorised personnel. The trust centre states plainly that rules-based access controls, audit logs and admin tools help the customer configure and manage AiMe, which is the alignment burden this value describes, sitting with the buyer.

The product does not enforce an external document management system's access model at query time, so the top value is not reached. What is not addressed is segregation between matters or business units inside one tenant. That is the live question on this product, because the platform is sold to legal, procurement, sales, finance and IT in the same instance and the assistant answers questions across the whole contract repository in natural language.

Source: Vendor PublishedAiMe tenant environments are logically separated with dedicated encryption keysAs of Sep 12, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Notice committed

Terms commit to notice where lawfully permitted. No transparency report located.

Notice is committed in the published agreement and no transparency report exists, which is this value. The commitment is in the Data Processing Addendum's security attachment at section 4, headed Disclosure by Law: if Conga is required by any law to disclose customer data it will, to the extent permitted by applicable law, give the customer prior notice of the obligation as soon as practical after becoming aware, and will take all steps to enable the customer an opportunity to prevent or limit the disclosure.

The second limb is the useful one, because it is an obligation to help rather than merely to inform. The CCPA attachment carries a parallel and slightly stronger commitment for personal information: where a law requires disclosure for a purpose unrelated to the contracted business purpose, Conga must first inform the customer of the legal requirement and give it an opportunity to object or challenge the requirement, unless applicable law prohibits notice.

Two related provisions round out the picture: Conga will redirect a misdirected data subject request to the customer rather than answering it, and will not respond without the customer's prior written consent unless legally required. What is absent is the reporting half. No transparency report, no aggregate figure for demands received, and no reporting cadence was located on any surface.

Source: Vendor Publishedgive Customer prior notice of the obligation as soon as practical after becoming aware; and take all steps to enable Customer an opportunity to prevent or limit the disclosureAs of Sep 12, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Sources named, basis unstated

Sources are identified without stating the licence or rights basis.

The sources behind the output are identified and no rights basis is stated for any of them, which is this value. The working corpus is the customer's own and is named as such throughout: contracts imported in bulk including third-party, legacy and acquired agreements, the customer's clause library, its negotiation playbook and its approved templates, with the vendor stating that highly precise models are created from the customer's own documents without the customer needing to train them.

The generative layer is identified too, which is more than most records manage: Azure OpenAI provides the language model processing, with Google Cloud Vision, Amazon Textract and Zuva named for optical character recognition, table detection and provision extraction respectively. What is never stated is any rights or licensing basis. Nothing describes what the underlying foundation models were trained on, and Zuva's provision-extraction models, which are trained on contract corpora rather than on the customer's own documents, are named as a component without any account of what sits behind them.

The customer-side basis is the agreement itself, the Artificial Intelligence Addendum leaving the customer with all right, title and interest in its AI Inputs and AI Outputs and granting Conga only a limited licence.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

No located public material addresses whether authority is checked for subsequent history, and on this product class the question does not arise in its usual form. The product cites no cases, statutes or regulations to a reader: it works on the customer's own agreements, comparing draft language to a negotiation playbook, matching against an approved clause library, extracting obligations and dates, summarising, and answering questions about the repository.

Nothing it produces is an assertion about the state of the law that a lawyer would need to check for subsequent treatment. The nearest adjacency is the obligation and renewal tracking, where currency means whether a contractual date or duty is still live rather than whether an authority is still good law, and that is addressed through alerts and dashboards rather than through anything this signal measures. Recorded so the row states the position rather than leaving a reader to infer it from silence. Product, features, trust centre and both published addenda were read on the date shown.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Confidence signal only

The product exposes a confidence or grounding score without an explicit abstention path.

A confidence signal is exposed to the user and no explicit abstention path is published, which is this value exactly. The confidence half is stated plainly and is unusual in this corpus: the vendor commits that AiMe surfaces how every recommendation is generated, that users see the reasoning behind AI-driven actions, and that confidence scores are shown wherever AiMe makes a suggestion. That gives a reviewer a per-suggestion signal to work from, which is more than most records offer.

What is absent is the other half. Nothing published describes what the system does when it cannot ground an answer: no statement that it declines, no marking of an unsupported extraction, no account of what happens when a clause cannot be matched to the playbook or a question cannot be answered from the repository, and no published evaluation demonstrating any such behaviour. The surrounding material allocates the consequences rather than describing the behaviour: the Artificial Intelligence Addendum acknowledges that outputs may be inaccurate, incomplete or misleading, makes the customer solely responsible for validating them, and states that Conga does not monitor or review AI-generated outputs. A guardrails claim appears on the product page without any description of what the guardrails do.

Source: Vendor Publishedconfidence scores are shown wherever AiMe makes a suggestionAs of Sep 12, 2026Evidence

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

None located

No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.

Searched on 12 September 2026, on both the product name and the company name, against published trackers of decisions on AI-generated fabricated citations including coverage of the Damien Charlotin AI Hallucination Cases database and two independent sanctions trackers, for any court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product. None located. This is a statement about the public record on that one subject as of the date shown, and under R119 this signal records fabricated citations and nothing else, so it is not a litigation history and no other proceeding involving the vendor would appear here.

Source: Bar Guidance or Court RecordAs of Sep 12, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No located public material engages with bar or ethics guidance. No bar opinion is named anywhere on the estate, ABA Formal Opinion 512 does not appear, no state guidance on generative AI in legal practice is referenced, and nothing maps any capability to a jurisdiction's rules of professional conduct. This record engages external authority more than most, and none of it is professional responsibility guidance: the Artificial Intelligence Addendum anchors governance to the NIST AI Risk Management Framework, and the trust centre publishes the vendor's own classification of its products as minimal or limited risk AI systems under the EU AI Act.

Both are AI-regulatory instruments addressed to the vendor as an AI system provider, both are graded on the governance axis, and crediting them again here would work one fact across two rows. The nearest thing to a professional-responsibility statement is the Addendum's requirement that the customer not rely on AI outputs as the sole basis for a decision with legal impact and exercise independent judgment, which is graded on the professional responsibility axis and names no guidance in any event.

The absence is worth stating because the same estate shows the vendor is willing and able to engage named frameworks when it chooses to.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Outside the fee relationship

The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.

The product does not touch a fee between a lawyer and a client, because it is bought by teams that bill no client for the work. The named audiences are in-house functions of the buying organisation, legal, procurement, sales, finance, IT and business operations, each with its own published page, and the customer base is corporate rather than law-firm: an airline, an insurer, a property data business, a consumer fitness company and a professional network among the named logos.

Nothing in the estate is addressed to a law firm billing a client. Efficiency claims are extensive, a 9 per cent revenue increase, a 50 per cent reduction in AI-assisted review time, faster deal cycles and reduced supplier costs, and under this value they are recorded here rather than making the row a savings claim, because every one of them is aimed at the buyer's own cost, cycle time or revenue and none reaches a client bill.

Worth noting for a reader coming the other way: because the same platform runs quoting, pricing and billing alongside contracts, the vendor sits close to its customers' own revenue processes, but that is the customer billing its customers rather than a lawyer billing a client, and it is a different object. Nothing published addresses disclosure of AI use or AI cost in any fee context.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Disclosure pack published

A subprocessor and model provider list plus client facing disclosure material is published or available without an agreement in place.

The pack a company would forward to answer a counterparty's AI clause is published and ungated, which is the top value and the first record in this pull to reach it. The model provider statement is the part that usually fails and here it is the strongest: the trust centre names the third-party services behind the AI individually and by function, Google Cloud Vision for optical character recognition, Amazon Textract for table detection, Zuva for provision extraction and Azure OpenAI for language model processing, states a zero-data-retention arrangement with each, and explains what Azure OpenAI does and does not do with prompts and completions.

A subprocessor list is published at conga.com/privacy/subprocessors-and-subcontractors, and the Data Processing Addendum executes Clause 9(a) Option 2 of the Standard Contractual Clauses against it with fifteen days' notice, a right to object and a termination-and-refund remedy. Client-facing disclosure material is the third limb and it is met twice over: the Data Processing Addendum itself, published in full with the SCCs, the UK addendum and Swiss adaptations, and a separate Artificial Intelligence Addendum written to be read by a customer's counsel.

Stated for the record: the model provider limb rests on the trust centre, which was read in full, and the subprocessor list page itself was not opened, so its publication is evidenced by the addendum rather than by its contents.

Source: Vendor PublishedConga's Discovery Agent and Q&A Agent use a small number of specialized third-party services for document processing, including Google Cloud Vision (OCR), AWS Textract (table detection), Zuva (provision extraction), and Azure OpenAI (language model processing).As of Sep 12, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

Several elements of a record exist and no document-level export is described, which is this value. The elements are better than most. The platform maintains a complete audit trail of every action, approval and signature across the contract lifecycle, described by the vendor as supporting compliance and offering full transparency for legal or internal reviews, alongside version control, tracked edits and inline comments in the native editor.

The AI-specific element is the one that matters here and it is published: the vendor commits that AiMe surfaces how every recommendation is generated, that users see the reasoning behind AI-driven actions, and that a confidence score accompanies each suggestion, so the basis of a machine-proposed clause is visible at the point of review rather than lost. What is absent is the export and the model identity. Nothing states that any report or extract identifies which model produced a passage, and the model is in any case not named beyond a family; nothing marks machine-generated text against human-edited text in a form a party could hand to a court; and no disclosure template, certification form or court-facing guidance was located anywhere on the estate.

Source: Vendor PublishedMaintain a complete audit trail of every action, approval, and signature in the contract lifecycleAs of Sep 12, 2026Evidence
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 12, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746