C
ContractSafe
ContractSafe is contract management software built around a searchable repository and renewal tracking, sold as a simple and affordable alternative to larger CLM systems. It stores contracts with tags, custom fields and reminders, and adds approvals, redlining, editing in Microsoft Word, eSignature, templates and intake forms on its higher plans. The AI extracts key terms and dates for a person to accept, answers plain English searches and questions about a contract, and reviews incoming contracts against a playbook of the customer's own rules, linking each failed rule to the clause and suggesting wording.
ContractSafe says the AI suggests and a person decides, and that customer contracts are not used to train AI models. Prices are published: plans start at $450, $660 and $815 a month, prepaid annually, rising with the number of active contracts, with unlimited users and no implementation charge. Data can be hosted in the United States, Canada, the European Union or Australia, and a SOC 2 Type II report is downloadable from its trust center after an instant NDA.
ContractSafe says more than 1,900 organizations use it, including the City of Olympia, and sells to education, healthcare, nonprofits, government and small businesses. ContractSafe LLC is based in Malibu, California, and was founded by Randy Bishop and Ken Button.
ContractSafe, head to head
Side by side on the same 15 capability axes and 12 legal signals: where the two part company, and what neither one publishes.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
ContractSafe is a contract repository first: storage, tagging, custom fields, unlimited reminders and alerts, dashboards and reports, with approvals, redlining, Word editing, eSignature, templates and intake forms on higher plans. AI sits across it as a set of features. AI data extraction suggests key terms and dates for a person to accept, correct or skip; AI Search takes plain English queries; Ask AI answers questions about an open contract; and AI Contract Review checks incoming contracts against a playbook of the customer's rules.
ContractSafe's FAQ says customers can use some of the AI features or none at all, and the repository, search by tag and field, alerts and workflow all work without them. AI extraction and contract chat come with every plan, AI extraction for custom fields and AI Contract Review come with Maximize, and ContractSafe also sells Jump Start, where its paralegals extract data from existing contracts by hand.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
ContractSafe's AI answers from the customer's own contract and points back to it. Ask AI gives answers sourced from the open contract, AI Contract Review links each failed rule to the relevant clause with a plain explanation of why it failed, and extracted values appear as suggestions beside the document for a person to accept or correct. Review runs against rule definitions the customer writes, with preferred and fallback language, rather than a generic template.
The AI page says the AI isn't perfect and that results are easy to review and adjust. No accuracy figure, error rate, test set or evaluation is published for extraction, search, answers or review, and no benchmark is cited. Release testing is described as internal testing followed by a beta with customers who opted in and a staged rollout.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
ContractSafe sets out what each AI mode may do. Extraction only suggests values: a person accepts, corrects or skips each one before it is added, singly or in bulk across contracts. AI Contract Review reads and evaluates the contract and does not edit it; suggested wording is copied into a redline only if the team chooses. Rules that AI drafts for a playbook must be reviewed and accepted by a reviewer before they are added.
AI search returns only contracts the searcher is allowed to see. The AI page states the principle as the AI suggests and a person decides, customers can switch AI features off entirely, and feedback on any result can be given at any time. Every user action is recorded in a timestamped audit trail. Nothing published describes a confidence threshold or what happens to a value that was accepted in error.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
The City of Olympia case study names the customer, a state capital with 600 employees serving 50,000 residents, and quotes Sean Krier. Olympia reports 75 percent less time spent scanning documents, about $10,000 a year saved in staff time, and a rise from 1 to more than 4 on a five point internal survey of contract management. It chose ContractSafe after reviewing more than 20 systems and trialing two. The rollout coincided with the move to remote work at the start of the pandemic, the only date given.
Other named voices include Margaret Howell Benson, General Counsel, Pieter-Francois Theron, CFO of JourneyApps, Donna Yslas of World Oil and Neka Rodriguez of Radiologic Associates of Fredericksburg, with qualitative quotes. ContractSafe says more than 1,900 organizations use it, and the AI features carry no customer outcome figures.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The Terms of Use, effective 22 January 2025, treat customer content as Confidential Information protected with the care ContractSafe gives its own, and leave ownership with the customer (2.3, 3.1). Clause 3.2 licenses ContractSafe to use content to provide and improve the services, extends that license to trusted third parties as needed, and states that those third parties will not use the content to train their AI models.
The AI page says ContractSafe does not use customer data to train AI models, and the security page says confidential contract data is never used to train public AI models. Inside an account, permissions run down to individual folders, tags, users and teams. Privilege and work product are not addressed, and a data processing addendum is sent on request rather than published.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
ContractSafe's Terms of Use, privacy policy, AI pages and security page contain no statement on the line between the product and legal advice, and no reference to lawyers' professional duties. The product is sold to education, healthcare, nonprofits, municipal government and small businesses as well as legal teams, and its users include executive assistants and compliance coordinators. Its AI answers questions such as whether a contract can be assigned and suggests replacement wording when a contract fails a playbook rule.
The nearest statements are about oversight rather than advice: the AI suggests and a person decides, and review is applied against rules the customer writes.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
ContractSafe describes how an AI feature reaches customers: internal testing, a beta with customers who opted in, a check against its security and efficiency requirements, and release in small batches, with customers able to give feedback on results afterward. Its subprocessor list names two AI monitoring services, Braintrust and Langfuse, alongside the model providers. On regulation, the AI page says ContractSafe takes reasonable steps to review changes in laws affecting privacy and AI, including the EU AI Act, without describing what it has done.
No person or team is named as accountable for AI, no test results are published, and nothing addresses whether output differs across contract types, languages or regions.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
ContractSafe's security page describes hosting on Amazon Web Services with AES-256 encryption at rest and in transit, a web application firewall, continuous offsite database backups, a disaster recovery plan, continuous intrusion detection, daily vulnerability scans, regular penetration testing, Sophos endpoint protection and a timestamped audit trail of user actions. Access controls include SAML single sign on, two factor authentication, role based permissions to the document level and optional IP allowlisting.
A subprocessor list names each AI provider and service with its regions. Clause 9.4 of the Terms makes content available for 30 days after termination, after which ContractSafe may delete it, and the privacy policy keeps data while the account is active. No breach notification commitment or incident response practice is published, and the data processing addendum is sent on request.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
The Terms of Use provide the services as is, with no warranty of accuracy (11.1), and commit to commercially reasonable efforts toward 99.9 percent monthly availability (2.1). ContractSafe defends and indemnifies the customer against third party claims that the services infringe a valid US copyright or US patent, excluding the customer's content and modifications, with replacement, modification or a prorated refund as remedies (11.4).
Each party's liability is capped at fees paid under the subscription in the 12 months before the claim, with indemnities and intentional misconduct outside the cap (11.3). The customer indemnifies ContractSafe for its use of the services and its content (11.5). Nothing addresses loss from a wrong AI extraction, answer or suggestion, and no insurance is published. Disputes go to binding arbitration under California law.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
ContractSafe's plan table lists a DocuSign integration, single sign on, Zapier and a Microsoft Word integration on Finalize, and APIs and a Salesforce integration on Maximize. The Word integration is described in direction: edit in Word with tracked changes and sync the result back to ContractSafe. Contracts can also be sent in by email, which the privacy policy says runs through Cloudmailin, and Dropbox Sign appears as an eSignature utility on the subprocessor list.
ContractSafe's own team sets up integrations for customers rather than leaving the work to them. The integrations page lists no further detail, and no API reference, field mapping for Salesforce or document management connection such as iManage or NetDocuments is published.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
ContractSafe runs on Amazon Web Services and offers data residency in the United States, Canada, the European Union and Australia. Its pricing FAQ says that once a region is chosen the data stays entirely within it, and that an account can sit in only one region. AI processing is listed by region on the subprocessor page: Microsoft Azure OpenAI, AWS Bedrock and OpenAI in the US, EU, Canada and Australia, Google Gemini in the US only, and the Langfuse monitoring service in the US and EU, with Braintrust in the US.
Email intake through Cloudmailin is processed in the United States and the European Union. Nothing says which AI feature uses Gemini, and no single tenant or on premises option is described.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
ContractSafe lists SOC 2 Type II certification with an annual audit, ISO 27001 certification, TX-RAMP Level 2 certification, HIPAA compliance and GDPR compliance on its security page. Its trust center, hosted on Vanta, shows real time security posture and lets a prospect sign an NDA instantly and download the full SOC 2 Type II report without a sales call. The pricing FAQ says SOC 2 is certified by an independent audit firm, without naming it.
Clause 8.2(j) of the Terms of Use requires anyone who receives a SOC or penetration test report to keep it confidential and use it only to evaluate ContractSafe. Vulnerabilities can be reported to a published security address. The ISO 27001 version, certificate scope and auditor are not shown on the public pages.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
ContractSafe's AI page says it uses models from OpenAI, Google and Amazon. Its subprocessor page lists the AI providers with their regions: Microsoft Azure OpenAI, AWS Bedrock and OpenAI in the US, EU, Canada and Australia, and Google Gemini in the US, plus Braintrust and Langfuse for AI monitoring. Clause 3.2 of the Terms of Use says third parties that receive content will not use it to train their AI models. No model name or version is given, nothing maps a provider to a feature, and no commitment to notify customers before a provider changes is published.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
ContractSafe publishes prices. Organize starts at $450 a month, Finalize at $660 and Maximize at $815, prepaid annually, for up to 100 active contracts, and the price rises through published volume bands of 101 to 500, 501 to 1,000, 1,001 to 2,500, 2,501 to 5,000, 5,001 to 10,000 and above 10,000. Every plan includes unlimited users, onboarding and training, data and document migration, unlimited archive and attachments and a dedicated customer success manager.
Implementation costs nothing. Only contracts in the repository count, not archived drafts or attachments. A monthly option is offered by card. Jump Start data entry by ContractSafe's paralegals starts at $2.50 per contract. Clause 1.4 of the Terms caps price increases at 5 percent a year for the same plan.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
ContractSafe has pages for education, healthcare, hospitality, nonprofits, small businesses, IT and software, and teams with dispersed staff and vendors, and its named customers include a city government, an oil company, a radiology practice and a software company. It describes itself as built for companies of all sizes and says more than 1,900 organizations use it. Legal is one of several buyers; quotes come from a general counsel, a CFO, an executive assistant and a compliance coordinator.
TX-RAMP certification and a HIPAA compliant offering support Texas public bodies and healthcare. Nothing published sets a size limit, names contract types or languages the AI handles poorly, or addresses law firm use.
6 public documents
The public pages on file for ContractSafe, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.
-
Client Data in Training, Ethical Walls and Matter Segregation, Primary Law Corpus Provenance
Read Oct 8, 2026
-
contractsafe.com/privacy2 signals
Prompt and Output Retention, Third Party Request and Subpoena Notice
Read Oct 8, 2026
-
Billing and Fee Posture
Read Oct 8, 2026
-
contractsafe.com/gdprsubs1 signal
Outside Counsel Guideline Readiness
Read Oct 8, 2026
-
contractsafe.com/security1 signal
Court Disclosure Support
Read Oct 8, 2026
-
Fabricated Citation Record
Read Oct 8, 2026
From $450 a month
- ContractSafe shows its prices on its website.
- The cheapest plan, Organize, starts at $450 a month if you pay for the year up front. Finalize starts at $660 and Maximize at $815.
- The price goes up with the number of active contracts you store, in steps from 100 or fewer to more than 10,000. Old drafts and attachments do not count.
- Everyone in your organization can use it at no extra cost, and setup, moving your old contracts in and training are free.
- AI contract review against your own rules is only in the Maximize plan.
Published price list. Three plans, each priced by features and by the number of active contracts in the repository, with bands of 100 or fewer, 101 to 500, 501 to 1,000, 1,001 to 2,500, 2,501 to 5,000, 5,001 to 10,000 and above 10,000. Starting prices, prepaid annually: Organize $450 a month, Finalize $660 a month, Maximize $815 a month, each for the smallest band. A monthly payment option is offered by credit card; annual plans can be paid by card, ACH or check.
All transactions are in US dollars, and prices shown in other currencies are for reference. Organize includes AI data extraction and AI contract chat; Finalize adds Word integration, approvals, redlining and eSignature; Maximize adds templates, intake forms, APIs, the Salesforce integration, AI extraction for custom fields and AI Contract Review. Unlimited users on every plan. Plans can be upgraded mid term with proration and downgraded at renewal.
Clause 1.4 of the Terms of Use caps increases at 5 percent a year for the same plan, effective at the end of a billing cycle.
Implementation: None. The pricing FAQ says there is no implementation charge and that every plan includes implementation help, migration of existing data and documents, and training. Jump Start, in which ContractSafe's paralegals extract data from existing contracts, is sold separately from $2.50 per contract.
Confidentiality and data terms: ContractSafe states HIPAA compliance and a HIPAA compliant healthcare offering. A data processing addendum is sent on request to support@contractsafe.com, and a data transfer impact assessment and subprocessor list are published.
Note: The $450 floor is the Organize plan for up to 100 active contracts on annual prepayment. The pay monthly option is offered without a published monthly rate. Subscriptions renew automatically and are billed in advance, and a subscription ended mid cycle is not refunded except for breach or where law requires (Terms of Use 1.2, 9.1).
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
A public policy or trust page states no training on customer content, with no matching term located in the published agreement.
The FAQ on ContractSafe's AI page answers whether customer contracts train AI models with a plain no, and the security page says confidential contract data is never used to train public AI models. The Terms of Use, effective 22 January 2025, go part of the way: clause 3.2 licenses ContractSafe to use customer content to provide and improve the services and extends that license to trusted third parties, which will not use the content to train their AI models.
The agreement does not restrict ContractSafe's own training in the same words. The privacy policy, effective 15 December 2023, says ContractSafe may use analytic means to evaluate, train and improve services that process content.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is acknowledged in public materials with no stated period.
The privacy policy keeps information while the account is active, as needed to provide the services and to meet legal obligations, and says some data may be deidentified and kept. Clause 9.4 of the Terms of Use makes a copy of the customer's content available on request for 30 days after termination, with metadata as a CSV file and documents in their native format, after which ContractSafe may delete it. Authorized users can download all documents and data at any time.
No retention period is stated for AI questions, answers, extracted suggestions or review results, and nothing states what the AI providers keep.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
ContractSafe keeps its own permission model and publishes its parts in the plan table: custom roles and permissions, access permissions to folders and tags, permission groups, user level permissions and team level permissions, on every plan. The security page says access can be controlled down to the individual document, and adds SAML single sign on, two factor authentication and optional IP allowlisting. The AI page states that AI search returns only the contracts the searcher is allowed to see, so the AI respects the same permissions at query time.
Read only users and full administrators are both counted as users with no extra charge. Nothing is published on separation between customers beyond hosting on AWS.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Terms commit to notice where lawfully permitted. No transparency report located.
ContractSafe's privacy policy states a policy of challenging government access to data in court before disclosing it, says it will attempt to notify data subjects of any such request where the law allows, and commits to commercially reasonable efforts to notify users about law enforcement or court ordered requests unless prohibited. It adds that nothing in the policy limits a user's own defenses or objections to a request.
Clause 2.2 of the Terms of Use binds ContractSafe to adhere to its privacy policies, and clause 2.3 lets content lose its confidential status where disclosure is required by law, subject to the privacy policy. The policy also reserves release of personal information under legal compulsion, such as a subpoena. No transparency report is published.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Sources are identified without stating the license or rights basis.
ContractSafe's AI works from the customer's own contracts and rules. Ask AI answers from the open contract, AI Contract Review evaluates a contract against rule definitions the customer writes, with its preferred and fallback language, and extraction reads the uploaded document, with each PDF converted to text first. Playbooks can be started from a negotiated contract, highlighted language, a sample playbook or one suggested by contract type, and AI drafted rules are accepted by a reviewer before use.
The product does not retrieve case law or legislation. The models come from OpenAI, Google and Amazon, and nothing describes their training data or the basis on which any data behind them was used.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
ContractSafe manages a customer's own contracts and does not cite case law or legislation, so a citator is not part of the product. Nothing on the AI, review, security or pricing pages addresses checking authority for later history. Playbook rules and fallback language are written and kept current by the customer, and nothing describes how the product flags a rule that a change in law has made out of date.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
ContractSafe describes review rather than abstention. Extracted values are suggestions a person accepts, corrects or skips, AI Contract Review shows pass or fail per rule with an explanation, and suggested wording is offered when available. No confidence score is shown, and nothing says what Ask AI does when the answer is not in the contract or what extraction does with a field it cannot find. The AI page says the AI is not perfect and that results are easy to review and adjust.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.
The AI Hallucination Cases database maintained by Damien Charlotin, which records court decisions worldwide that address hallucinated AI content and the tool involved where known, has no entry naming ContractSafe. This is a statement about the public record rather than a finding about the product, and it covers fabricated content only. ContractSafe manages contracts rather than producing court filings, so its output does not ordinarily reach a brief.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No bar opinion, ethics rule or reference to lawyers' professional obligations appears in ContractSafe's Terms of Use, privacy policy, AI pages, security page or pricing FAQ, and there is no statement that the product does not give legal advice. The AI page's regulatory statement concerns privacy and AI laws such as the EU AI Act, which bind ContractSafe as a provider rather than a lawyer using the product.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.
ContractSafe is bought by organizations to manage their own contracts, and its named customers are a city, companies and a medical practice rather than law firms, so no client bill sits in the loop. Its savings claims are aimed at the buyer's own time and cost, such as the City of Olympia's 75 percent less time scanning documents and about $10,000 a year saved in staff time, and its pricing pitch rests on unlimited users and no implementation charge.
Jump Start, where ContractSafe's paralegals extract data from a customer's existing contracts from $2.50 per contract, is a service sold to the customer, not a fee passed to anyone else. Nothing published addresses fee treatment of AI assisted work for a firm that bills a client.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
ContractSafe publishes a subprocessor page that names its AI providers with regions, Microsoft Azure OpenAI, AWS Bedrock, OpenAI and Google Gemini, its AI monitoring services, Braintrust and Langfuse, and HubSpot and Dropbox Sign. The privacy policy names Cloudmailin, Pendo and Invoiced with their processing locations. A data transfer impact assessment and a data protection policy are published. The data processing addendum is sent on request, and the SOC 2 Type II report is downloadable after an instant NDA in the Vanta trust center; clause 8.2(j) of the Terms of Use requires anyone who receives a SOC or penetration test report to keep it confidential and use it only to evaluate ContractSafe. No client facing AI disclosure material is published.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
ContractSafe records a complete, timestamped audit trail of user actions across all contracts, presented as support for internal compliance reviews and external audits, and edits made in the app are versioned. Because a person must accept each AI extracted value and choose whether to use suggested wording, the record of who added a value exists. Nothing published says whether the audit trail marks a value or a clause as AI suggested, or which model produced it, and no export or template for disclosing AI use is published. The output is contract data and reports rather than court filings.