C
Contract Logix

Contract Logix is a contract lifecycle management platform sold to legal, procurement, finance and sales teams, covering contract request and authoring, negotiation, execution, a central repository, and automated tracking of obligations, renewals and milestones. Two AI capabilities are named and they sit on opposite sides of signature, which the vendor is careful to say are not stages in a sequence. The Contract Intelligence Engine works post-execution on the signed portfolio and is described as the AI extraction layer inside Contract Logix: AI Contract Analysis reads contract language and detects which key terms and clauses are present, while AI Data Extraction, branded AIDE, pulls chosen properties into the platform as structured data across 92 pre-built standard fields plus customer-defined fields driven by extraction prompts, with Custom Data Objects capturing line-item detail including calculated fields and row-level dates, and the ability to reprocess an entire portfolio against a new configuration without re-loading documents.

The vendor publishes an accuracy figure for it, approximately 95 per cent or better on standard fields rising to roughly 99 per cent with human validation in the loop. Contract Logix Review works pre-signature during negotiation and delivers first-pass redlines against the organisation's own standards inside Microsoft Word or Google Docs. A managed service, Contract Logix Organize, designs the data model and bulk-imports legacy contracts.

The platform runs on Microsoft Azure and publishes a detailed security page covering role-based and feature-based permissions, a designated System Owner, SSO via SAML 2.0 against named identity providers, employee background screening, and customer-set data deletion and archiving policies. The company reports more than 60,000 legal, procurement, finance and sales professionals across hundreds of brands. Contract Logix, LLC is based at 55 Technology Drive, Lowell, Massachusetts.

It was acquired by LegalSifter on 22 October 2024, confirmed on both companies' own newsrooms, and the parties announced a unified team and product roadmap; LegalSifter, itself a portfolio company of Carrick Capital Partners, is separately indexed here, and Contract Logix continues to sell under its own name on its own domain with its own agreement and its own purchase path.

Vendor siteLowell, Massachusetts, United States
Last verifiedSeptember 13, 2026
Compare with other vendors

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The models are the engine of core capabilities layered on a product that would function without them, which is the B band. Two AI capabilities are named, each with its own page and its own place in the lifecycle. The Contract Intelligence Engine is described as the AI extraction layer inside Contract Logix and runs post-execution: AI Contract Analysis detects which key terms and clauses are present in contract language, and AI Data Extraction, branded AIDE, pulls chosen properties into the platform as structured data.

The supporting detail is more concrete than most in this lane: 92 pre-built standard fields, customer-defined fields driven by extraction prompts, Custom Data Objects for line-item detail with calculated fields and row-level dates, and portfolio-wide reprocessing against a new configuration without re-loading documents. Contract Logix Review runs pre-signature and delivers first-pass redlines against the organisation's own standards inside Microsoft Word or Google Docs, and the vendor states expressly that the two share a platform but are not stages in a sequence.

What keeps this off A is that the product underneath is a full contract lifecycle management platform. Remove the models and the request intake, authoring, negotiation workflow, repository, permissions and automated tracking of obligations, renewals and milestones all remain, and those are what the company sold for years before either AI capability existed. The extraction layer converts what was manual data entry into an automated read of the signed portfolio, which is a large improvement to a system that stands without it. Verified 13 September 2026.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

An accuracy figure is published without the test set or the failure modes, which lands in the B band, and the shape of the disclosure is worth recording because it is rare. The product page states that AIDE delivers approximately 95 per cent or better accuracy on the standard extraction fields, rising to roughly 99 per cent with human validation in the loop. Publishing the delta is the notable part: it tells a buyer that the system is wrong on the order of one field in twenty unaided, which is closer to naming an error rate than anything else located in this lane, and it prices the human review step rather than assuming it away.

Three things hold it at B rather than A. The A band asks for measured accuracy with the test set described and the failure modes named, and neither is published: nothing states what corpus the figure was measured on, how many documents or fields, of what type, or in which languages, and no failure mode is named, so a buyer cannot tell whether the missing five per cent is spread evenly or concentrated in particular field types.

The qualifiers do real work in the vendor's favour, since approximately and roughly are not figures an outsider can test. And no independent validation of either number exists. R15 governs the remaining limbs and they are recorded as inapplicable rather than counted against the record: the grounding and linked-primary-source limbs do not bite on a system extracting from the customer's own executed contracts, because there is no external authority being cited whose existence could be fabricated. Verified 13 September 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

A written commitment that the models work alongside a human reviewer with a real review surface, short of the full control structure, which is the B band. What lifts this above an assurance is that the human step is quantified rather than asserted. The published accuracy claim is expressed as approximately 95 per cent or better unaided rising to roughly 99 per cent with human validation in the loop, so the vendor has priced the review step into its own headline figure and, by implication, told the buyer what happens if the step is skipped.

Very few records in this corpus put a number on the difference the human makes. The second AI capability is framed the same way: Review produces first-pass redlines against the organisation's standards, and first-pass is the vendor's own characterisation of what the output is, which sets an expectation that a person completes the work. What the A band requires is not published. No threshold is stated at which the system defers or escalates, no confidence signal is described on an individual extraction, nothing states which fields or clause types the system will not attempt, and nothing describes what happens after an extraction is found to be wrong beyond the general ability to reprocess a portfolio against a new configuration.

R124(2) was applied to the first-pass framing and it does not qualify: it describes the maturity of the output rather than attaching a boundary to a named tier stating what that tier's output may not be used for, which is the test that distinguished Verbit. Verified 13 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Real deployment evidence with substance, short of the attribution and method the A band requires, which is the B band. Scale is published as a figure rather than a gesture: more than 60,000 legal, procurement, finance and sales professionals use the platform, across what the company describes as hundreds of brands. One testimonial does the work that most in this corpus do not, joining a named organisation to a named role and a concrete before-and-after: the Director of Contracts at Soar Technology describes a question that used to take three days being answered in five minutes.

That is a named customer, an identified seat and a figure in a single artifact, which is more than the B band's own description of the common failure, being a named customer without figures or figures without the named customer. Three things keep it from A. It is one instance, so the evidence is an example rather than a body. Nothing is dated, so a reader cannot tell when the deployment happened or over what period the improvement was observed.

And no method accompanies the figure, so the three-days-to-five-minutes comparison cannot be assessed: nothing states what the question was, what the old process involved, or whether the comparison is like for like. The named accuracy figures on the product page are measurements of the model rather than of a deployment and are graded on the citation accuracy row instead of being counted twice here. Verified 13 September 2026.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Substantive published commitments on access and data handling, short of the full picture and silent on privilege, which is the B band. What is published is unusually detailed for a vendor with no published customer agreement, and it is operational rather than promotional. The security page describes role-based and feature-based permissions set by the customer's own administrator, a designated System Owner from the customer organisation who invites users and grants access in-application, mandatory email validation of every user, policy-driven passwords with complexity configurable by the customer, and single sign-on via SAML 2.0 against named identity providers.

Personnel controls are described in more specificity than anywhere else in this lane, covering background screening and routine privacy, security and regulatory training. Data deletion and archiving is customer-set, with application and service-level controls supporting the customer's own policies and restore restricted to users holding the right role. The privacy policy is materially better drafted than several comparators because it covers privacy practices in connection with the services as well as the websites, so the platform is not carved out.

Three limbs fail. Privilege and work product are not addressed anywhere located. No position is published on what any AI model provider may see or retain, because no provider is identified at all. And the substantive contractual commitments sit in an agreement that is not published, the website terms expressly carving out a separately executed customer agreement, so a buyer cannot read the confidentiality terms before entering a sales conversation. Verified 13 September 2026.

Source: Vendor Published
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Nothing published on the advice line was located for a product that produces legal work and is sold to people who are not lawyers, which is the D band including its own parenthetical. The parenthetical fits directly. The stated audience is legal, procurement, finance and sales, and the platform carries solution pages by department, role, process and company size, so non-lawyers are an intended and named user group rather than an incidental one.

What the AI produces for them is legal work on any ordinary description: Contract Logix Review delivers first-pass redlines against the organisation's standards inside Word or Google Docs, and the Intelligence Engine detects which key terms and clauses are present in an executed contract. Nothing published states whether that output is legal advice, whether a lawyer should review a redline before it reaches a counterparty, what a procurement or finance user may rely on it for, or who inside the customer is accountable when the extraction of a governing law or indemnity clause is wrong.

The grade is recorded knowing the vendor addresses legal buyers seriously, which is why it is worth saying that this is not an audience-ambiguity problem. There is a dedicated Legal Department page naming General Counsel, Paralegal and Compliance Officer with a role page each, and a published Corporate Counsel's Guide to contract lifecycle management. The audience is clearly identified; it is the professional line through the middle of it that is unaddressed. No competence or supervision statement and no jurisdiction limit for the AI were located. Verified 13 September 2026.

Source: Vendor Published
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Nothing published on AI governance was located, which is the D band. The page inventory was taken from the navigation and footer under R20 and covers the platform pages, the Contract Intelligence Engine, Review, Organize, security and data privacy, hosting on Azure, integrations, the solution pages by industry, department, role, process and company size, the company pages, the news section and the blog. No responsible AI page, AI policy, AI principles statement, acceptable use position or AI governance section exists anywhere in it.

No framework is named, whether NIST, ISO 42001 or any other. No accountable owner for model behaviour is identified. No testing regime is described and no evaluation result is disclosed beyond the headline accuracy figures, which measure output quality rather than governance and are graded on the citation accuracy row. Bias is not addressed in any form. The absence is established rather than untested: the vendor publishes a detailed security page, a substantive privacy policy and a product page carrying a quantified accuracy claim, so this is an estate that documents itself carefully and has not extended that habit to how the models are governed.

It is worth naming what that means for a buyer on this particular product. The Intelligence Engine's extractions populate the obligation and renewal tracking the platform is bought for, and Review's redlines are applied against the organisation's own standard positions, so uneven model behaviour across contract types, counterparties or languages would propagate silently into the record and nothing published would let a buyer test for it. Verified 13 September 2026.

Source: Vendor Published
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Substantive published policy covering most of the ground, short of the full set on subprocessors and incident practice, which is the B band and both of the gaps it names. Deletion and archiving are addressed with an approach that is genuinely customer-led rather than vendor-stated: application and service-level controls support the customer's own deletion and archiving policies, the customer sets its own requirements for how data should be deleted and archived, and restore is restricted to users holding the appropriate role.

Access control is the strongest limb, with role-based and feature-based permissions administered by the customer, a designated System Owner, email validation of every user, configurable password policy and SAML 2.0 single sign-on against Azure Active Directory, ADFS, DUO, Okta and Ping. Personnel security is described in unusual detail, covering background screening and routine privacy, security and regulatory training including HIPAA.

Hosting on Microsoft Azure has its own page. Two limbs are missing and they are the two the band anticipates. No subprocessor list exists: the privacy policy refers to service providers and states they may be located outside the United States, without naming one, so a buyer cannot establish who touches its contracts. And no incident practice is published, with no breach notification commitment, no notification window and no description of what a customer would be told or when.

Nothing states a retention period for prompts or extraction outputs as distinct from stored contracts. Verified 13 September 2026.

Source: Vendor Published
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

No published position on liability for AI output was located, which is the D band, and the cause is a choice rather than a retrieval limit. The footer Terms and Conditions are website terms on their face: they govern use of the Site and apply to visitors, users and others who access the Site. Their entire-agreement clause expressly carves out any current mutually executed written agreement between the customer and Contract Logix, which establishes two things at once.

A customer agreement exists, so the silence is not because the vendor has nothing; and it is not published, so a buyer cannot read the allocation of risk before entering a sales process. That distinction matters for how this D is read: this is not a vendor that failed to draft the terms, it is one that declines to publish them. Consequently nothing is established on any limb the axis tests. No warranty of any kind attaches to the extraction output, notwithstanding that the vendor publishes an approximately 95 per cent accuracy figure and therefore acknowledges a material error rate.

No liability cap is stated. No indemnity in either direction is published. No service level, no uptime commitment and no insurance position were located. Nothing addresses who bears the loss when a mis-extracted renewal date or liability cap propagates into the obligation tracking the platform is bought to run. What the website terms do settle is jurisdiction: Massachusetts law, non-exclusive. R85 does not apply, because nothing was blocked. Verified 13 September 2026.

Source: Vendor Published
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Real integrations exist and named connections are documented, short of the depth the A band describes, which is the B band. The strongest evidence is that one of the two AI capabilities runs inside the applications the work already happens in: Contract Logix Review delivers its first-pass redlines inside Microsoft Word or Google Docs, so a negotiator does not leave the drafting surface to use it. That is integration into a system legal work lives in rather than a connector list.

Identity integration is documented with named counterparties rather than described generically, single sign-on running over SAML 2.0 against Azure Active Directory, ADFS, DUO, Okta and Ping, which is enough detail for an implementer to know whether their estate is covered. A dedicated Integrations page exists in the platform navigation and hosting on Microsoft Azure has its own page. What the A band asks for and was not established is depth: what each connection moves, in which direction, and what a customer must configure.

No practice management, document management, matter management or e-signature system is named as supported on the surfaces read, and no ERP or procurement suite is named, which matters because procurement and finance are two of the four stated buyer groups and those buyers would be integrating with systems of record. The Integrations page itself was not opened; under R25 it corroborates a grade that stands on the Word and Google Docs hosting and the named identity providers, and it is what would move this row. Verified 13 September 2026.

Source: Vendor Published
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Cloud delivery is named without either the tenancy model or the region, which under R38 is the C band because tenancy and region are co-equal limbs and neither is published. What is published is the hosting arrangement: Microsoft Azure-based cloud products, with a dedicated page for it, and the security page describes Azure-supported infrastructure controls. Under ground rules section 3 and R16 that is the infrastructure provider's arrangement rather than a residency commitment, and it is recorded as such rather than credited as one.

Naming the hyperscaler tells a buyer whose data centres are involved and nothing about where its own contracts sit. Region is unaddressed. No data centre location, country or region is stated anywhere located, no regional election is offered to customers, and no data residency page exists. The one statement bearing on location runs the other way and is recorded because a buyer with cross-border obligations needs it: the privacy policy states that the company's service providers may be located outside the United States, without naming them or the countries involved.

Tenancy is equally unaddressed. Nothing states whether a customer's contract repository sits in a shared or isolated environment, no separation model is described, and no single-tenant, private cloud or on-premises option is offered or refused. Nothing states where the extraction models run relative to where documents are stored. The absences are established rather than untested, the estate carrying a dedicated hosting page and a detailed security page that address neither. Verified 13 September 2026.

Source: Vendor Published
DD on Security Certifications and Trust CenterNo independent security attestation located.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

No independent security attestation was located, which is the D band. No SOC 1, SOC 2, ISO 27001 or equivalent certification is claimed anywhere on the estate, no penetration test summary or third-party assessment is referenced, and there is no trust centre, compliance page or security portal. What exists in place of attestation is a self-description: a detailed security page setting out the vendor's own controls, covering permissions, single sign-on, password policy, employee background screening, training including HIPAA, customer-set deletion and archiving, and Azure-based hosting.

Those are the vendor's statements about itself and the axis asks for something a third party has checked. One certification claim exists and is expressly not credited, on the standard pull 7 set for this record. The privacy policy claims certification under the EU-U.S. Data Privacy Framework, the UK Extension and the Swiss-U.S. DPF, names BBB National Programs as the independent recourse mechanism, and acknowledges FTC investigatory jurisdiction.

Two things follow. First, the DPF is a self-certification programme administered by the Department of Commerce rather than an independent audit, so even verified it would not answer what this axis asks. Second, it could not be verified: dataprivacyframework.gov is a client-side search application and no participant record was reached, on this pass or in pull 7. Under R85 and rule 6.6 that is a retrieval limit recorded as such, it is not evidence the certification is absent, and nothing adverse is inferred from it. It is simply not credited unverified. Verified 13 September 2026.

Source: Vendor Published
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Nothing published about the model supply chain a customer inherits was located, which is the D band. The product pages describe what the AI does in real detail, covering 92 pre-built extraction fields, extraction prompts, Custom Data Objects, portfolio reprocessing and an accuracy figure with a human-validation delta, and say nothing whatever about what performs the work. No model is named, no version is given, no provider is identified, no distinction is drawn between proprietary and third-party models, and no architecture is described beyond the branding of the Intelligence Engine and AIDE.

Nothing states whether Review's redlining and the Engine's extraction run on the same models. Recorded and expressly not credited under ground rules section 3 and R16, because it is the obvious candidate for a misread: Microsoft Azure is named as the hosting platform and has its own page, and single sign-on runs against Azure Active Directory among others. Naming the cloud a system runs on is infrastructure disclosure, not model disclosure, and it does not tell a buyer whether an Azure-hosted service, an Azure OpenAI deployment, a third-party API or an in-house model reads its contracts.

Nothing addresses what any provider may retain of a document sent for extraction, and no commitment to notify customers of a change is published. The absence is established rather than untested: the vendor publishes a subprocessor-shaped statement in its privacy policy referring to service providers who may sit outside the United States, and names none of them. Verified 13 September 2026.

Source: Vendor Published
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

No pricing information is published at any level, including the unit of charge, which is the D band. The page inventory taken from the navigation and footer under R20 carries platform pages, product pages, solution pages by industry, department, role, process and company size, company pages, news and a blog, and a demo request route. There is no pricing page. No rate, band, per-seat figure, minimum commitment, term length or implementation charge appears anywhere on the estate, and the website Terms and Conditions govern use of the site rather than any subscription, with the commercial terms sitting in the separately executed customer agreement that is not published.

So a buyer cannot establish even the shape of the commercial model from first-party material: not whether the platform is charged per user, per contract, per seat tier or by volume, and not what implementation adds. Under R10's closing discipline no structure means no row, and a page that only invites a sales conversation is an absence belonging in this note alone, so no VendorPricing row is written for this record. Recorded because it bears on how the D is read and because R41 excludes it from the grade: third-party aggregator listings describe a subscription model varying by user count, contract volume and feature tier, name Submitter, Read-Only and Full-User subscription levels, and state that implementation is charged separately.

None of that is first-party, none of it is credited, and one such listing gives the starting price simply as contact vendor, which corroborates that nothing is published rather than that anything was missed. Verified 13 September 2026.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Segment coverage is described with real substance and the boundaries are left open, which is the B band. The legal buyer is addressed on a dedicated page rather than inferred from a list, which is what settled 5.4 on route A for this record: a Legal Department page opening on the people who run Legal's contracts every day, with three legal seats named and given a page each, being General Counsel, framed around governing the contract portfolio with visibility, control and standard positions, Paralegal, and Compliance Officer, supported by a published Corporate Counsel's Guide to contract lifecycle management.

Beyond legal, coverage is organised along four axes at once, with solution pages by industry, by department, by role, by process and by company size. Named industries include healthcare, manufacturing, pharmaceutical, and oil, gas and energy, which is a coherent regulated-and-heavy-industry cluster rather than a scatter. Scale is published at more than 60,000 professionals across hundreds of brands. What is left open is the boundary in both directions.

No contract type or agreement family is named as well or poorly handled by the extraction models, and the 92 standard fields are counted without being enumerated or scoped, so a buyer cannot tell whether its own agreement types are covered. No language coverage is stated. No customer size floor or ceiling is given despite company size being a published navigation axis. And the record should be read knowing legal is one of four stated buyer groups alongside procurement, finance and sales, which is a real difference from the specialist tools in this lane. Verified 13 September 2026.

Source: Vendor Published
Sources on file

4 public documents

The public pages on file for Contract Logix, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Purpose limited, in the contract

The customer agreement or data processing addendum contractually limits use of Customer Data to providing the contracted service, and no surface names training either way. The limit is bound, which a policy page is not, but it is not an express training prohibition. If any surface names training in either direction, one of the other values is true and this one is not.

Customer content is stated to be used only for delivering the service, with no separate training permission and no training prohibition either, which is this value and the disposition of the item carried into pull 8. The privacy policy is the operative surface and it is better drafted than several comparators in this lane, covering privacy practices in connection with the services as well as the websites, so the platform is not carved out and the commitments reach uploaded contracts rather than only site visitors.

Within it, processing is framed by purpose: personal information is handled for the purposes for which it was collected or subsequently authorised, sensitive information attracts an affirmative opt-in before any disclosure to a third party or any use beyond the original purpose, and onward transfers to service providers carry a continuing responsibility. What is absent is any sentence in either direction about models.

No provision permits customer content to train, fine-tune or improve any model, and no provision prohibits it. So the buyer is left with a purpose limitation that would not obviously admit training, and no express confirmation. Two points bound the value. This is a policy position rather than a contractual one: the website terms carve out a separately executed customer agreement which is not published, so the contractual values on this signal cannot be reached and R43(1) is run but not discharged.

And no model provider is identified anywhere on the estate, so nothing states what any third party may do with a document sent for extraction.

Source: Vendor PublishedAs of Sep 13, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Customer controlled, no zero option

The customer controls the retention window, by product configuration or by contractual instruction, but zero retention is not stated as available.

Retention is put in the customer's hands rather than fixed by the vendor, which is this value and an uncommon shape in this corpus. The security page states that the platform provides application and service-level controls to support the customer's own data deletion and archiving policies, and that the customer sets its own requirements for how its data should be deleted and archived. Restoration is bounded by the same permission model, only users holding the appropriate role being able to restore data within the application.

So a buyer with a records retention schedule can implement it here rather than accepting a vendor default, which is a genuine answer to the question this signal asks and is stronger than the disclosed-vague position most records in this lane occupy. Three limits are recorded so the value is not read as more than it is. No default is published, so nothing states what happens to data at a customer that configures nothing.

No maximum or backstop is stated, so the controls are described without an outer bound the vendor commits to. And the controls are described for customer data in the repository rather than for the AI material specifically: nothing states whether a prompt, an extraction candidate or an intermediate output is retained separately from the contract it was drawn from, or whether reprocessing a portfolio against a new configuration leaves prior extraction results in place.

No deletion-on-termination commitment was located, which sits in the unpublished customer agreement if it exists at all.

Source: Vendor Publishedallows you to set your requirements or policies around how your data should be deleted and archivedAs of Sep 13, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Own model, documented

The product maintains its own permission model, documented, requiring the firm to keep it aligned.

A permission model is documented in enough detail for an administrator to plan against, which is this value. The security page describes two dimensions of control rather than one: role-based and feature-based permissions, created by the customer's own administrator, giving the IT or business group control over what information can be accessed by whom, with multiple user types and the ability to add and remove roles supporting granular control.

The model has a named owner inside the customer organisation, a designated System Owner who invites other users and grants access through in-application tools rather than through the vendor. Identity is bounded at the entry point too: every user must be validated by email before use, must then set a policy-driven password whose complexity the customer's administrator configures, and single sign-on is available over SAML 2.0 against Azure Active Directory, ADFS, DUO, Okta and Ping.

Restore rights are tied to the same roles. That is a documented model rather than an assertion of care, which is what separates this value from the one below it. What is not addressed is the legal framing. Nothing describes walls between matters, clients or counterparties as a concept, and nothing states whether a permission boundary can be made invisible rather than merely inaccessible, which is the distinction a conflicts wall turns on.

The product's centre of gravity is a company's own contract portfolio rather than client matters, so the gap is less acute here than on a firm-facing tool, and legal is one of four stated buyer groups.

Source: Vendor Publishedrole-based and feature-based permissions for your organization's usersAs of Sep 13, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Not addressed

No located term or policy addresses third party requests for customer data.

No located public material addresses what happens when a third party demands customer data. Nothing states whether the vendor would notify the customer of a subpoena, a warrant or a regulatory demand, whether it would give the customer an opportunity to object or to seek relief before producing, or whether it would narrow or challenge a demand. No transparency report is published and no law enforcement guidelines page exists.

The one adjacent provision located concerns a different route and is recorded rather than credited: the privacy policy acknowledges that Contract Logix is subject to the investigatory and enforcement powers of the Federal Trade Commission in connection with its Data Privacy Framework commitments, which is a statement about the vendor's own regulatory exposure and says nothing about notice to a customer whose contracts are demanded.

The absence has weight on this product because of what the repository holds: a company's executed agreements, which are exactly what a litigant, a regulator or a counterparty in a dispute would seek, and a customer that cannot establish the vendor's notice practice cannot plan for that. The value is recorded as the floor rather than as a finding about the vendor's actual conduct, because the instrument that would ordinarily carry a notice clause is the customer agreement, and the website terms expressly carve that agreement out and it is not published.

Surfaces read on the date shown were the privacy policy, the website Terms and Conditions, the security page and the platform pages.

Source: Vendor PublishedAs of Sep 13, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Not addressed

No located public material identifies the corpus behind the product’s answers.

No located public material identifies a source corpus, and R15 governs the weight. This product answers from no body of law. The Intelligence Engine reads the customer's own executed contracts, detecting which key terms and clauses are present and pulling chosen properties into the platform as structured data, and Review works against the organisation's own standard positions. There is therefore no licensed legal corpus whose provenance this signal would ordinarily test, and the vendor is not withholding something its product class implies.

What is genuinely unaddressed, and why a value is recorded rather than the limb being treated as wholly inapplicable, is the provenance of whatever sits behind the extraction models. The vendor publishes 92 pre-built standard extraction fields and an accuracy figure for them, which implies models trained or tuned on a body of contracts, and nothing states what that body was: whether public filings, licensed corpora, synthetic data, or other customers' agreements.

The last of those is the one a buyer would want excluded and nothing excludes it, which connects this row to the purpose-limited position recorded on the training signal. Nothing addresses licensing of any third-party material, and no model provider is named whose own training corpus could be inquired into. The surfaces read on the date shown were the Intelligence Engine page, the Review page, the security page, the privacy policy and the website terms.

Source: Vendor PublishedAs of Sep 13, 2026Evidence

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

No located public material addresses whether authority is checked for subsequent history, and on this product the question does not arise. Nothing in the platform cites law. The AI reads a company's own executed contracts and its own standard positions; no proposition about the state of the law is produced whose treatment a lawyer would verify in a citator, and no case, statute or regulation is cited to the user. R15 governs and the limb is recorded as inapplicable rather than failed.

One adjacency is named so it is not mistaken for the thing, because it is the closest analogue this product has to a currency problem. Extracted provisions describe a contract as it stood when it was read, and the platform's value proposition depends on those extractions staying true: obligation and renewal tracking runs off them. Nothing published describes how the system detects that an amendment, side letter or novation has changed a term it already extracted, or what happens to a tracked obligation when the underlying clause is renegotiated.

The vendor does publish the ability to reprocess an entire portfolio against a new configuration without re-loading documents, which addresses changes to the extraction schema rather than changes to the contracts. That is a data currency question and it is not graded here. The surfaces read on the date shown were the Intelligence Engine page, the Review page, the platform pages, the security page and the privacy policy.

Source: Vendor PublishedAs of Sep 13, 2026Evidence

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

No located public material describes what the system does when it cannot produce a reliable answer. The vendor comes closer than most to acknowledging that the situation arises, which is why the adjacency is recorded rather than the row left bare: the published accuracy claim of approximately 95 per cent or better on standard fields, rising to roughly 99 per cent with human validation in the loop, is an admission that roughly one field in twenty is wrong unaided.

Having conceded the error rate, the vendor says nothing about how the error surfaces. Nothing states that a low-confidence extraction is flagged for review, that a field the model cannot locate is returned as absent rather than as a nearest match, that a confidence score attaches to individual extractions, or that any field type is excluded as unreliable. Nothing describes what Review does when a clause has no counterpart in the organisation's standards.

The gap matters because of where the output goes. Extractions populate the obligation and renewal tracking the platform is bought to run, so a silently wrong extraction becomes a missed renewal or an untracked obligation rather than a visibly wrong answer someone would question, and the published human-validation delta implies the review step is the only mechanism catching it. Nothing published indicates which way the system errs when uncertain.

Surfaces read on the date shown were the Intelligence Engine page, the Review page, the platform pages, the security page and the privacy policy.

Source: Vendor Publishedapproximately 95%+ accuracyAs of Sep 13, 2026Evidence

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

None located

No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.

Searched on 13 September 2026 against the company name and both AI product names, across reporting and trackers covering court decisions on AI-generated fabricated citations. None located. No decision, sanction or disciplinary referral names Contract Logix, the Contract Intelligence Engine or Contract Logix Review. This discharges the R3 item carried from pull 7 on this name. Context is recorded so the absence reads as tested rather than assumed, the field now being substantial: reported instances include a Wyoming federal sanction of 5,000 dollars over eight non-existent cases produced by ChatGPT, a 6,000 dollar sanction in Indiana, a 1,500 dollar sanction in the Eastern District of California, a show-cause order requiring patent counsel in Kansas to explain nonexistent quotations and citations, four lawyers sanctioned in Mississippi where both sides filed fabricated authority, and a Kentucky decision treating hallucinated citations as a fraud-on-the-court concern.

General-purpose assistants rather than contract platforms are what those accounts describe. Under R119 this signal records fabricated legal citations in filings and nothing else, so no other proceeding involving this vendor appears here or is implied by this value. One point of product context: neither AI capability generates citations to legal authority, working on the customer's own executed contracts and its own standard positions, so the exposure this signal tracks is structurally low.

Source: Bar Guidance or Court RecordAs of Sep 13, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No located public material engages with bar or ethics guidance, in general terms or otherwise. No bar opinion is cited, no rule of professional conduct of any jurisdiction is named, and nothing connects either AI capability to the obligations of a lawyer relying on its output. Nor is professional responsibility engaged generically: no statement was located asking customers to use the product consistently with their professional duties.

The gap is worth stating precisely rather than generally, because this vendor addresses legal buyers deliberately. There is a dedicated Legal Department page, three named legal seats each with a page of its own covering General Counsel, Paralegal and Compliance Officer, and a published Corporate Counsel's Guide to contract lifecycle management. So the estate speaks to lawyers directly and at length, and says nothing about the professional line running through a tool that produces first-pass redlines against an organisation's standards and extracts governing law and indemnity terms from executed agreements.

The regulatory engagement that does exist runs entirely to data protection rather than conduct, the privacy policy claiming GDPR and CCPA compliance and Data Privacy Framework certification and naming BBB National Programs as its recourse mechanism, and the security page referencing HIPAA training for personnel. Those bind the vendor as a processor, not the customer as a lawyer, and they are recorded here so the absence is not read as an absence of all regulatory awareness.

Source: Vendor PublishedAs of Sep 13, 2026Evidence

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Outside the fee relationship

The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.

The vendor sits outside the lawyer-client fee relationship, which is this value. The buyer here is an organisation managing its own contracts, and the stated audience is that organisation's legal, procurement, finance and sales functions, with solution pages by department, role, process, industry and company size and named legal seats covering General Counsel, Paralegal and Compliance Officer. Those are in-house seats.

There is no client on the other side of the work and therefore no bill on which AI-assisted efficiency could be passed on, discounted or disclosed, so the question this signal asks does not arise in the form it was written for. The value records that structural position rather than a gap in the vendor's disclosure, which is the distinction between this value and the floor. Two qualifications are recorded so the value is not read too broadly.

The corpus has seen in-house-facing platforms bought by law firms for their own back office, and nothing on this estate excludes a firm from being a customer, so a firm using the platform on client matters would find nothing published about marking AI-assisted work for a fee note; that is noted rather than graded, because the product is not sold on that basis. And the efficiency claims that do exist are framed as internal time saved, the published testimonial describing a three-day question answered in five minutes for a Director of Contracts, which measures the customer's own effort rather than time billed onward. Recorded and not credited under R21 and R24.

Source: Vendor PublishedAs of Sep 13, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Not addressed

No located public material supports a client side disclosure obligation.

None of the three artifacts a firm would need is published, which is the floor. There is no subprocessor list of any kind. The privacy policy refers to service providers and states they may be located outside the United States, and names not one of them, which is the shape R29 distinguishes from a partial list: a category acknowledged without a single entity identified is not a list. There is no model provider statement, because no model or provider is named anywhere on the estate, so a customer cannot tell a client which third party reads its contracts, or indeed whether any third party does.

And there is no forwardable client-facing pack: no data processing addendum, no standard contractual clauses, no consent or notification template, and no security or privacy questionnaire response available for onward transmission. The instrument that would ordinarily carry the first and third of those is the customer agreement, and the website terms expressly carve out a separately executed agreement which is not published, so nothing in this set can be read before entering a sales process.

Recorded and expressly not credited under R29 and ground rules section 3: Microsoft Azure is named as the hosting platform and named identity providers appear for single sign-on, and neither is a subprocessor disclosure for the AI. The Data Privacy Framework claim in the privacy policy is a transfer mechanism rather than a disclosure artifact and is separately unverified.

Source: Vendor PublishedAs of Sep 13, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Not addressed

No located public material addresses court disclosure or verification certification.

No located public material addresses disclosure of AI involvement in legal work, which is the floor. Nothing states that an extracted field is marked as machine-generated rather than manually entered, that a redline produced by Review carries any indication of its origin, or that any record of AI involvement survives into an export or a report. No audit trail of AI use is described, no per-contract or per-matter record a customer could produce, no certification template, and no guidance on whether or when AI assistance should be disclosed to a counterparty, an auditor, a regulator or a court.

The exposure is real but indirect for this product class and the note says which way it runs rather than overstating it. The output is a structured data record and a draft redline rather than a filing, so the likely forum is a counterparty in a dispute, an auditor testing the contract register, or a regulator, rather than a judge. What a customer would want in any of those settings is the ability to show which terms in its own contract record were read by a machine and which by a person, particularly given the vendor's own published figure of approximately 95 per cent accuracy unaided, and nothing published provides it.

The permission model does support built-in role-based restore and administrator control, which is access governance rather than provenance, and is recorded here so it is not mistaken for an AI audit record. Surfaces read on the date shown were the Intelligence Engine page, the Review page, the security page, the privacy policy and the website terms.

Source: Vendor PublishedAs of Sep 13, 2026Evidence
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 13, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746