G
Gatekeeper

Gatekeeper is a vendor and contract lifecycle management platform that treats the supplier and the agreement as one record. It runs contract intake and request workflows, authoring from templates and clause libraries, negotiation and redlining, approval routing with mandated thresholds, integrated electronic signature compliant with ESIGN, UETA and eIDAS, a central repository with obligation and renewal tracking, and modules for vendor onboarding, third-party risk registers, balanced scorecards and spend analysis.

Its distinguishing claim is that vendor due diligence and contracting sit in the same continuous lifecycle rather than in separate systems. The AI layer is called LuminIQ and was launched in March 2025. It is delivered as a library of agents the vendor describes as digital workers: they extract metadata from uploaded agreements, generate plain-language contract summaries, review clauses against approved language, flag risk and policy breaches, identify obligations, route approvals, screen third parties for financial, cyber and sanctions risk, and build workflow cards from intake documents.

The platform publishes an unusually complete contractual estate around that AI, including a standalone set of AI Terms that prohibits training on customer input and requires the customer to label AI-generated output before publishing it, a data processing agreement whose exhibits name every sub-processor with its purpose and location, and a security schedule setting out encryption, key management and access controls.

Delivery is cloud on Amazon Web Services across four selectable hosting regions with a private cloud option, and plans are sold on unlimited users with a quota on the number of third parties managed. Buyers are legal, procurement and finance teams, with named users including the Legal Operations Manager at BlaBlaCar and Associate Corporate Counsel at Cricut. The contracting entities are Gatekeeper Ltd of Jersey and its group companies in the United Kingdom, United States and Canada.

Vendor siteLondon, United Kingdom
Last verifiedSeptember 12, 2026
Compare with other vendors

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The models are the engine of a core capability layered on a product that would function without them, which is B. Gatekeeper has sold vendor and contract lifecycle management since well before the AI arrived, and LuminIQ is described by the vendor as an intelligence layer added to that platform, launched in March 2025 with a first agent for workflow approvals and agents added since. Underneath sits a complete platform that does not depend on it: repository, template and clause authoring, the Kanban workflow engine with mandated approval paths, integrated eSignature compliant with ESIGN, UETA and eIDAS, vendor and employee portals, spend module, risk register and balanced scorecards.

The pricing page shows the same structure, listing Gatekeeper Agents and the AI Suite as capabilities within plans whose quota is measured in third-party records rather than in AI usage. What is recorded on the other side is direction rather than present state: the vendor now leads with agentic AI throughout, claims more than fifty agents, and describes them as a digital workforce that reads, reasons and acts. Remove them and the platform still runs the lifecycle, which is what keeps this off A. Verified 12 September 2026.

Source: Vendor Published
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Accuracy is addressed only by disclaimer and grounding is claimed without a described method, which is C. R15 governs the inapplicable limbs: the product cites no legal authority, so authority grounding and citation-status checking do not bite. What bites is grounding and measurement. The grounding claim is real in outline, the agents working on the customer's own contracts and vendor records inside the platform, generating plain-language summaries from the uploaded agreement, matching clauses against approved language and extracting obligations, and the vendor states that agents explain every decision they make.

That explainability claim is the strongest thing here and it is asserted rather than described: nothing published sets out what an explanation contains, what is retrieved, or how a proposed clause is traced back to the source text. Measurement is absent entirely, and the agreement makes the position explicit rather than leaving it implied. AI Terms clause 6.3 states that neither Gatekeeper nor any AI Provider makes any representation or warranty as to the accuracy, availability, suitability, reliability or content of Output, clause 9 excludes all warranties in relation to AI Functionality, and clause 6.6 requires the customer to check and evaluate the accuracy of any Output and not to rely on Gatekeeper to do it. No figure, test set, error rate or benchmark was located. Verified 12 September 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

A written commitment that the models work alongside a human decision-maker, with real review surfaces, short of the threshold at which the system acts alone. The commitment is contractual and specific. AI Terms clause 6.5 states that Output is a suggestion designed to assist and does not replace the need for the customer to use a human being to decide upon its suitability before it is published, used or relied upon. Clause 6.6 requires the customer to check and evaluate accuracy before use.

Clause 7.4 goes further and bars the customer from using the AI to make automated decisions that may have a detrimental impact on individual rights without appropriate human supervision. The review surfaces are the workflow engine's own: mandated approval paths and thresholds, an audit trail across the lifecycle, and the vendor's claim that agents explain every decision they make, giving transparency and auditability.

R37 rule 2 identifies what is missing. The same estate markets agents as a digital workforce that reads, reasons and acts, autonomously handling contract management and compliance validation, and those claims sit against a human-decides rule with no published boundary between them. No threshold, confidence level or class of work is published at which an agent proceeds or stops, and no mode structure is described. Verified 12 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Real deployment evidence with substance, held at B on the method limb, and it sits at the top of the band. One account is named, figured and specific: CompSource Mutual Insurance, where the vendor reports a 95 per cent reduction in executive review time per contract, 636 hours saved annually described as the equivalent of 17 weeks of capacity, executives reviewing ten-line AI summaries instead of thirteen-page contracts, and the elimination of back-and-forth between legal, finance and procurement.

That is attribution and measurement together, published in a dated January 2026 article. A second carries a figure and a named individual: Krupa Patel, Global Head of Procurement at Funding Circle, on terminating contracts worth $1.3 million. Three further named individuals with titles are quoted without figures, the Legal Operations Manager at BlaBlaCar, a Paralegal at Hakkasan Group and an Associate Corporate Counsel at Cricut, and a customer-story library is published.

What holds it off A is the fourth limb: no method or basis is stated for any figure, so a reader cannot assess how 95 per cent or 636 hours was computed. Headline claims elsewhere are unattributed and should be read as marketing, including average vendor cost reduction of $1.3 million in year one, 75 per cent shorter cycle times and 400 hours saved per audit. Verified 12 September 2026.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Four of the five A limbs are met on published instruments and the fifth is absent, and R33 makes the absent one decisive. Training use is the strongest limb and it is contractual: AI Terms clause 5 states that Input is not used to train or fine-tune any underlying machine learning model, whether proprietary or third-party, and that Gatekeeper prohibits AI Providers from retaining, accessing or using Input or Output to train their models; clause 12 repeats it and adds that no Content is retained by AI Providers beyond the session and no model training, fine-tuning or dataset enhancement is performed.

Segregation is documented in the DPA's security schedule, customer data being stored in a way that logically separates it from other customer data, with a unique per-customer encryption key generated using a FIPS 140-2 compliant library and a master key released only through multi-level executive authorisation. Retention and deletion are stated: deletion or return at the customer's choice, all copies removed within 60 days of termination and from backups within a year.

The third-party model provider position is explicit, the AI Providers being named sub-processors barred from retention and training. The limb that fails is privilege and work product, which is addressed nowhere. On a platform whose own legal-teams page invites counsel to hold their contracts in it, that silence is the whole distance to A. Verified 12 September 2026.

Source: Vendor Published
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

A real published position on advice versus tooling, short of full treatment, and with an omission worth naming. The position is contractual: AI Terms clause 6.5 states that Output is a suggestion and does not replace the need for a human being to decide on its suitability, clause 6.6 puts checking and evaluating accuracy on the customer, and clause 6.6 adds an obligation this corpus has not seen before, that prior to publication or distribution of any Output the customer must add a disclosure notice that it was generated by AI tools.

Clause 7.1 bars using the AI to mislead anyone that Output is human-generated. Clause 7.4 requires appropriate human supervision for automated decisions affecting individual rights. The omission is the interesting part and is recorded rather than inferred: clause 7 restricts the customer from using the AI to offer tailored financial advice without a qualified person reviewing it, and from providing health advice, and names no equivalent restriction for legal advice, on a platform sold to legal teams for clause review and redlining.

No statement that Gatekeeper is not a law firm was located anywhere. What is also missing for A is the supervision and competence dimension, any statement of who may operate which agent, and any jurisdictional limit. Verified 12 September 2026.

Source: Vendor Published
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Governance is expressed as contractual constraint rather than as a programme, with no mechanism, testing regime or accountable owner published, which is C. The substance that keeps it off D is real and unusually detailed for a terms document: the AI Terms define AI Functionality, bind the AI Providers as sub-processors subject to change notification, prohibit training on Input, and set out thirteen acceptable-use restrictions covering misleading users about machine authorship, unsupervised automated decisions affecting individual rights, activities with high risk of economic harm, unqualified financial advice, health advice, political campaigning and lobbying, and attempts to reverse engineer or replicate the models.

That is a published position on what the AI may be used for. None of what the higher bands ask for is present. No responsible AI or AI governance page exists, no framework is named and no certification against one such as ISO 42001 is claimed, nobody inside the vendor is identified as accountable for AI, nothing is published about what is evaluated before an agent ships or how an agent's behaviour is tested, and nothing addresses uneven output across contract types, counterparty drafting or jurisdictions.

An Executive Guide to AI Risk Management is published as a marketing download and concerns managing AI as a third-party risk in the reader's own supply chain rather than governance of this vendor's own AI. Verified 12 September 2026.

Source: Vendor Published
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Retention, deletion, access control, subprocessors and incident practice are all published, current and specific enough to hold the vendor to, which is the A band, and all five rest on the ungated Data Processing Agreement rather than on a marketing page. Retention is bounded in three layers: AI Content is processed transiently and not retained by AI Providers beyond the session under the AI Terms; personal data is retained for the duration of the agreement; and a published data classification scheme drives a retention policy under which deleted records are permanently evicted from active databases.

Deletion is specific: delete or return at the customer's choice, all copies removed from systems within 60 days of termination and from backups within one year, with export and permanent erase tools built into the product. Access control is documented in detail: least privilege and need-to-know roles, two-factor VPN for production access, unique per-customer encryption keys from a FIPS 140-2 compliant library with master-key release requiring multiple levels of executive authorisation, AES-256 at rest, TLS in transit, SIEM logging and alerting, and STIG-based configuration management.

Subprocessors are named individually with purpose and location in Exhibits C, with 30 days' notice of change, ten business days to object and a right to terminate. Incident practice is contractual: notification without undue delay and in any event within 72 hours of discovering a personal data breach. Verified 12 September 2026.

Source: Vendor Published
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Liability for what the AI produces is addressed only by disclaiming it, and here the disclaimer is more complete than most, which is C. AI Terms clause 9 excludes all warranties in relation to AI Functionality and states that no warranty is given for the accuracy, availability, suitability or reliability of Content. Clause 6.4 states that Gatekeeper has no liability or responsibility resulting from the use of or reliance upon any Output, or for any errors or omissions in it.

Clause 10.1 extends that to any damages arising in connection with use of, or inability to use, the AI Functionality, regardless of the form of action and expressly including negligence. Clause 11 runs the indemnity the other way, the customer defending Gatekeeper and the AI Providers against third-party claims relating to Content. Two provisions run in the buyer's favour and are recorded rather than credited, because neither answers what happens when the output is wrong: the DPA makes Gatekeeper liable for breaches caused by its sub-processors to the same extent as if it performed their services directly, and the vendor publishes an insurance position, worldwide cover at an A rated standard including cyber cover extended to IT forensics, legal advice, notification costs and credit monitoring.

That is breach cover, not output cover. The Master Subscription Agreement's general cap was not read and is named as unestablished on this row. Verified 12 September 2026.

Source: Vendor Published
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Real integrations, named and documented, short of the depth an implementer could work from, which is B. The named connections are substantial. Gatekeeper is a NetSuite SuiteApp, described as the only Built for NetSuite application for contract and third-party management and as NetSuite Partner of the Year 2024, and the marketplace listing describes sales teams working entirely within Salesforce while legal works in Gatekeeper.

Identity integration is specific: SAML 2.0 and OAuth 2.0, Google and Microsoft 365 single sign-on, official partnerships with Okta and OneLogin, and SCIM 2.0 user provisioning on higher plans. A RESTful API into any Gatekeeper data point is published as a plan feature, an integration product called Gatekeeper Interconnect is offered as no-code, Workato appears as an integration sub-processor in the DPA, and a Model Context Protocol connector is listed as a plan feature for connecting LuminIQ to the customer's own tools.

Two things hold it off A. What actually syncs, in which direction, and what a customer must configure is described only for the NetSuite path, at the level of vendor, contract and spend data. And the count of supported third-party solutions is inconsistent across the estate, given as over 220 on the platform page and over 4,000 on another, which is recorded rather than resolved. Verified 12 September 2026.

Source: Vendor Published
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Deployment options and residency are published to a level no other record in this lane reaches, which carries the A band. Four hosting regions are named individually and the customer chooses: the DPA's infrastructure sub-processor table lists Amazon Web Services for data hosting in the USA, Ireland, Australia and Canada, and the enterprise page states that a customer may select any region to support its data sovereignty requirements.

A second deployment option is published alongside the shared cloud, a Gatekeeper private cloud for bespoke requirements. Where processing happens is stated as distinct from where data is stored, and stated per processor rather than in the abstract: the group companies that provide support and development are listed individually with their locations, Jersey, the United Kingdom, the United States and Canada, each with its transfer mechanism, EU adequacy for the first two and Standard Contractual Clauses with encryption for the others, and the AI providers carry their own locations, Amazon Bedrock across the same four regions and Anthropic in the United States only.

Resilience detail is published too: data stored in triplicate across two data centres with two separate cross connections and stateless applications recreatable in other regions. The one soft limb, recorded rather than hidden: what the private cloud changes relative to the standard tiers is not described. Verified 12 September 2026.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Certification is real and stated, short of accessible evidence, which is B. The standards are named and the estate is broad: ISO 27001, ISO 9001, SOC 2 Type II completed and announced in January 2026, and SOC 1 Type 2. One commitment is stronger than a badge and is contractual, appearing in both the Terms of Service and the DPA's security schedule: Gatekeeper shall maintain its ISO 27001 certification, or an equivalent, throughout the term of the agreement, and will not use third-party data centres that do not hold equivalent certification.

The DPA sets out the audit regime, an external audit performed at least annually to ISO 27001 standards by independent third-party security professionals at Gatekeeper's expense, alongside a statement elsewhere that all global hosting locations are independently audited quarterly by two security specialist firms. What holds it off A is access to the evidence. The resulting Report is designated Gatekeeper's confidential information and is provided only on written request, no more than once in any twelve months, and subject to the confidentiality terms; no auditor is named, no report period or certificate number is published, and no scope statement accompanies any standard.

A Security Center exists at trust.gatekeeperhq.com and is Vanta-hosted; it returned page metadata with no body to this index's fetcher on 12 September 2026, which is a limit on the reader under R20 and not a finding about the vendor. Verified 12 September 2026.

Source: Vendor Published
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The supply chain is partly disclosed and stops one limb short of A, which is B under R34. Providers are identified by name in an ungated contractual document rather than referenced in the abstract: the Data Processing Agreement's sub-processor table names Amazon Bedrock as an AI Provider operating in the USA, Ireland, Australia and Canada, and Anthropic, PBC, described as providing AI language model services powering internal workflow automation, in the United States.

Where they run is therefore stated per provider. Change notification is contractual and specific: 30 days' prior notice by email of any change to the sub-processor list, a ten business day window to object, and a right to terminate the affected services if no alternative can be provided. The AI Terms bind the providers further, permitting them to use Input only to create Output and prohibiting retention or training. The limb that fails is the first.

No model is named anywhere, and Amazon Bedrock is a hosting service for models rather than a model, so a reader learns the route customer text travels without learning what generates the answer. Two cross-reference defects are recorded rather than resolved: the AI Terms define AI Providers as those set out in clause 3, and clause 3 does not set them out but points to the sub-processor list; and the DPA's Exhibit A refers to a sub-processor list published in Exhibit D, while the document's tables appear at Exhibit C. Verified 12 September 2026.

Source: Vendor Published
CC on Commercial TransparencyPricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Pricing is gated behind a demo while tier names and feature splits are published, so the shape is visible and the number is not, which is the C band in its exact terms. What is published is more than most gated pages carry. Three tiers are named, Pro, Enterprise and Enterprise Plus, and the unit of charge is stated plainly rather than implied: the quota is the number of third parties managed, banded at up to 250, up to 750 and more than 750, with archived third parties excluded from the count.

A feature matrix of roughly twenty rows sets out what differs, and several entries are notable for being unlimited on every tier, including users, live and archived contracts, eSignature licences and senders, and Gatekeeper Agents. Where the tiers diverge is published too: two best-practice AI-enabled workflows on the lower tiers against more above, one custom workflow rising to two and then more, and API access, Model Context Protocol connectivity, SCIM provisioning, remote backup and granular sensitive-data controls positioned as higher-tier capabilities.

One item carries its own unit, MarketIQ Full being marked usage based. No figure, band, term, minimum or implementation cost appears anywhere, and the only route to a number is a demonstration request. Commercial terms were not read: the Master Subscription Agreement was not opened. Verified 12 September 2026.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Segment coverage is described with substance and the boundaries are left open, which is B. The buyer groups are named consistently and legal is one of three, addressed on a page of its own at /legal-teams that speaks to counsel directly about clause deviations, missed approvals, policy enforcement and being brought in too late to prevent risk, alongside procurement and finance, with the CFO named as a fourth audience on the AI page.

That page answers the seed's concern that this is a procurement product with legal attached. Coverage is also described by task rather than only by audience, through six published use-case pages spanning contract creation and execution, renewals and amendments, vendor onboarding, vendor performance, third-party compliance monitoring and vendor consolidation, each with its own claimed outcome. Named users support the spread across functions, from a Legal Operations Manager and a Paralegal to a Global Head of Procurement.

What is left open holds it off A. No practice area within a legal department is identified as supported or unsupported, no industry pages were located, nothing states what the product is not for, and no jurisdictional coverage statement appears despite four hosting regions and group companies on three continents. Verified 12 September 2026.

Source: Vendor Published
Sources on file

5 public documents

The public pages on file for Gatekeeper, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.

Pricing

No published figureUSD, as published, never converted

  • Gatekeeper publishes what its three plans contain but not what any of them costs; the only route to a number is a demo.
  • The thing you are charged for is how many third parties you manage: up to 250 on Pro, up to 750 on Enterprise, and more than that on Enterprise Plus. Suppliers you archive stop counting.
  • Everything that usually gets metered is unlimited on every plan: users, contracts, e-signatures and the AI agents themselves. That is unusual and it is worth knowing before you compare.
  • What you pay more for is workflow capacity and the enterprise plumbing: more pre-built and custom AI workflows, plus API access, a Model Context Protocol connection, automated user provisioning, remote backup and tighter controls on sensitive fields.
  • One feature is charged separately whatever plan you are on, the full version of the third-party risk data service, which is billed on usage.

Published structure with no figure, which is R10's trigger. Three named tiers, Pro, Enterprise and Enterprise Plus, with the unit of charge stated plainly: the quota is the number of third parties, meaning vendors, suppliers, partners and customers, banded at up to 250, up to 750 and more than 750, with archived third parties excluded from the count. A feature matrix of roughly twenty rows sets out what each tier includes.

Unlimited on all three tiers: users, pipeline, live and archived contracts, eSign licences and senders, Gatekeeper Agents, and MarketIQ Lite credit ratings. Scaling with tier: best-practice AI-enabled workflows at two, two and more than two, and custom AI-enabled workflows at one, two and more than two. Positioned as higher-tier capabilities: REST API access, Model Context Protocol connectivity to the customer's own tools, SCIM 2.0 provisioning, remote backup to an external system, and granular sensitive-data controls.

Common to all tiers: single sign-on across Google, Microsoft, OneLogin and Okta, role-based access control groups, the full AI Suite, employee intake and third-party portals, spend module, risk register and balanced scorecards. One line item carries a separate unit and is marked usage based across all tiers, MarketIQ Full, described as financial health monitoring, cyber security ratings and automated risk mitigation.

No figure, band, currency, term, minimum or implementation cost is published anywhere, and the page routes to a demonstration request. A separate purchase path exists on AWS Marketplace, where the listing states that pricing is based on the duration and terms of the contract with the vendor and publishes no figure either.

Confidentiality and data terms: No Business Associate Agreement is offered or referred to on any surface read, and the vendor's own position is that health data is out of scope: the Data Processing Agreement's Exhibit A states that no sensitive data will be processed or transferred, defining that to include data concerning health, while acknowledging that small and limited amounts of special category data may be present in customer data on the basis that the customer is lawfully permitted to process it. What is published instead of a BAA is a full data protection estate: the DPA incorporates the EU, UK and Swiss Standard Contractual Clauses, names the competent supervisory authorities, lists every sub-processor with its location and transfer mechanism, and is accompanied by a separate EU Data Act Addendum.

Note: Tier names, the third-party quota bands and the full feature matrix read from the vendor's own pricing page on 12 September 2026. AI-specific commercial terms read from the AI Terms, and processing and deletion terms from the Data Processing Agreement, both read in full the same day. No figure appears on any surface located, so entryPriceUsd is null and entryPriceDisplay is empty under R10. The row is written under R17 because the published structure lifts Commercial Transparency above D; the axis sits at C, the shape being visible and the number withheld. The Master Subscription Agreement was not opened, so payment terms, renewal, uplift and termination rights are not established.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Never, in the contract

The published terms prohibit training on customer content. Not a policy page, the agreement.

The published agreement prohibits training on customer content, without qualification and in two places, which is the top value and the first record in pull 8 to reach it. AI Terms clause 5 states that Input is not used to train or fine-tune any underlying machine learning models, whether proprietary or third-party, that Gatekeeper prohibits AI Providers from retaining, accessing or using Input or Output to train their models, that Input and Output are processed transiently and not stored or reused beyond what is required to deliver the Services, and that no Input or Output is used for model improvement, corpus building or similar training-related purposes.

Clause 12 repeats the commitment in its own right: Gatekeeper does not use any Content to train any machine learning models, and no Content is retained by AI Providers beyond the session, with no model training, fine-tuning or dataset enhancement performed. This is an agreement rather than a policy page, published ungated and incorporated into the Master Subscription Agreement, and clause 2 provides that the AI Terms prevail over the main agreement in relation to AI Functionality.

The one boundary a reader should note is what the clauses cover: they govern Input and Output as defined, being data provided to and generated by the AI Functionality, and no separate statement was located about aggregated or anonymised usage data outside that definition.

Source: Vendor PublishedInput is not used to train or fine-tune any underlying machine learning models, whether proprietary or third-party.As of Sep 12, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Disclosed fixed window

A specific retention period is published and the customer cannot change it.

A retention boundary is published and the customer cannot change it, which is this value. For prompts and generated output specifically, the boundary is the session: AI Terms clause 12 states that no Content is retained by AI Providers beyond the session, and clause 5 that Input and Output are processed transiently and not stored or reused beyond what is required to deliver the Services. That second formulation carries a qualifier a reader should see, since what is required to deliver the Services is not itself defined, but the session boundary at the provider layer is stated flatly.

Around it the platform-level periods are published in the Data Processing Agreement and are specific rather than gestural: personal data is retained for the duration of the agreement, all copies are deleted from Gatekeeper's systems within 60 days of the effective date of termination unless a different date is agreed or the law requires storage, and partial data held in backups is deleted within one year. The security schedule adds a data classification scheme driving a retention policy under which a deleted record is permanently evicted from active databases and then rotated out of backups, and states that data no longer required is deleted promptly, locked in the first instance to guard against accidental or malicious deletion.

Source: Vendor PublishedNo Content is retained by AI Providers beyond the sessionAs of Sep 12, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Own model, documented

The product maintains its own permission model, documented, requiring the firm to keep it aligned.

The product maintains its own documented permission model that the customer must administer, which is this value. Separation between customers is documented in the Data Processing Agreement's security schedule rather than asserted in marketing: customer data is stored in a way that logically separates it from other customer data, multi-client capability includes separation of functions and of test from production systems, and each customer holds a unique encryption key generated using a FIPS 140-2 compliant library, with the key itself encrypted under a Gatekeeper master key whose release requires multiple levels of executive authorisation and is logged and alerted through a SIEM.

Inside a tenant the model is Gatekeeper's own and is the customer's to run: role and authorisation concepts on least privilege and need-to-know are set out in the security schedule, role-based access control groups are a named plan feature with a documented access group matrix in the knowledge base, and SCIM 2.0 provisioning automates joiners and leavers on higher tiers. What is not addressed is segregation between matters or business units within one tenant, which matters on a platform where legal, procurement and finance work the same records and agents answer across the whole contract and vendor estate.

Source: Vendor PublishedYour Personal Data is stored in a way that logically separates it from other customer data.As of Sep 12, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Notice committed

Terms commit to notice where lawfully permitted. No transparency report located.

Notice is committed in the published agreement where lawfully permitted, and no transparency report exists, which is this value. Data Processing Agreement clause 11.1 is the operative provision: Gatekeeper will notify the customer promptly of any request or complaint regarding the processing of personal data which adversely impacts the customer, unless notification is not permitted under applicable law or a relevant court order.

The carve-out is the ordinary one and the trigger is drawn around adverse impact rather than around compelled disclosure by name, which is a narrower framing than some records in this corpus use and is recorded as such. Two adjacent provisions complete the picture. Clause 8.2 provides that where Gatekeeper receives a request from a data subject it refers the individual back to the customer unless prohibited by law. Clause 11.2 records that Gatekeeper may copy or retain personal data to comply with a legal or regulatory requirement, which tells a customer that data can be held back for legal reasons even where deletion has been instructed.

What is absent is the reporting half: no transparency report, no aggregate figure for demands received and no reporting cadence was located anywhere on the estate.

Source: Vendor PublishedGatekeeper will notify You promptly of any request or complaint regarding the processing of Personal Data, which adversely impacts You, unless such notification is not permitted under applicable law or a relevant court order.As of Sep 12, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Sources named, basis unstated

Sources are identified without stating the licence or rights basis.

The working corpus is identified and the rights basis for it is stated, while nothing is said about what the models bring, which is this value. The source of every answer is the customer's own material: contracts, vendor records, risk data and spend imported into the platform, which the agents read, summarise, classify and extract from inside the tenant. The rights basis for that is set out expressly, which is unusual: AI Terms clause 5 provides that the customer or its licensors own Input and retain all ownership of it, warrants that the customer holds all rights, licences and consents required, and grants Gatekeeper a non-exclusive right to permit itself and its AI Providers to use Input within the AI Functionality for the purpose of generating Output only.

What is not stated is the provenance of anything underneath. The AI Providers are named in the sub-processor list as Amazon Bedrock and Anthropic, and nothing published describes what their models were trained on, under what licence, or with what update cadence, and clause 3.3 passes that question through by making use of the AI Functionality subject to each AI Provider's own terms of service without identifying them.

No external legal or contract corpus is claimed, so the product makes no coverage claim this signal would otherwise test.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

No located public material addresses whether authority is checked for subsequent history, and on this product class the question does not arise in its usual form. The product cites no cases, statutes or regulations to a reader. Its agents work on the customer's own agreements and vendor records: extracting metadata, summarising, matching clauses against an approved library and fallback terms, flagging policy breaches, identifying obligations and screening third parties for financial, cyber and sanctions exposure.

Nothing it produces is a statement about the state of the law that a lawyer would need to check for later treatment. The nearest adjacency is the compliance screening, where agents are described as reviewing third parties against SOC 2, DORA and ESG criteria, and where currency means whether an attestation or a risk signal is still valid rather than whether an authority is still good law; nothing published states how those criteria are kept current either, and that is recorded here rather than graded. Product pages, the AI Terms, the Data Processing Agreement and the pricing matrix were read on the date shown.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

No located public material addresses what the product does when it cannot ground an answer. The nearest published claim is about explanation rather than abstention: the vendor states that Lumin Agents explain every decision they make, giving complete transparency and auditability, and that they read, reason and act on data securely inside the platform. Explanation of a decision taken is not a description of what happens when a decision cannot be taken.

Nothing states that an agent declines, marks an extraction as unsupported, reports that a clause could not be matched to the playbook, escalates rather than answers, or exposes a confidence or grounding score to the reviewer, and no evaluation demonstrating any such behaviour was located. The contractual material allocates the consequences instead of describing the behaviour: AI Terms clause 6.3 disclaims any warranty as to the accuracy or reliability of Output, clause 6.6 requires the customer to check and evaluate accuracy before use and not to rely on Gatekeeper to do it, and clause 6.5 states that Output is a suggestion that does not replace a human deciding on its suitability.

Recorded as an established absence: the product pages, both published addenda and the plan matrix were read on the date shown.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

None located

No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.

Searched on 12 September 2026, on both the product name and the company name, against published trackers of decisions on AI-generated fabricated citations including coverage of the Damien Charlotin AI Hallucination Cases database and two independent sanctions trackers, for any court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product. None located. This is a statement about the public record on that one subject as of the date shown, and under R119 this signal records fabricated citations and nothing else, so it is not a litigation history and no other proceeding involving the vendor would appear here.

Note for a future reader that the product name is also a common noun and the name of unrelated software, including an open-source Kubernetes policy controller, so any future search on this name needs the company qualifier to be meaningful.

Source: Bar Guidance or Court RecordAs of Sep 12, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No located public material engages with bar or ethics guidance. No bar opinion is named anywhere on the estate, ABA Formal Opinion 512 does not appear, no state or Law Society guidance on generative AI is referenced, and nothing maps any agent to a jurisdiction's rules of professional conduct. The absence carries more weight on this record than on most, for two reasons drawn from the vendor's own agreement. AI Terms clause 7 shows the vendor is willing to write profession-specific restrictions when it chooses to: it bars using the AI to offer tailored financial advice without a qualified person reviewing the information, and bars health advice outright, and it names neither legal advice nor any professional conduct obligation, on a platform marketed to legal teams for clause review and redlining.

And clause 6.6 imposes an obligation that touches professional conduct directly, requiring the customer to add a disclosure notice that Output was AI-generated before publishing or distributing it, without connecting that requirement to any court rule, bar guidance or candour obligation that would explain it. The related material on the EU AI Act published on the vendor's blog is educational content about the reader's own obligations, not an alignment statement about this product.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Outside the fee relationship

The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.

The product does not touch a fee between a lawyer and a client, because it is bought by teams that bill no client for the work. The named audiences are in-house functions of the buying organisation, legal, procurement and finance, with the CFO named as the economic buyer on the AI page, and the whole commercial argument is about the buyer's own cost: vendor spend reduced, unwanted renewals stopped, supplier consolidation, cycle times shortened, audit hours saved.

The named customers reflect that, a Global Head of Procurement, a Legal Operations Manager, a Paralegal and an Associate Corporate Counsel, all inside the organisations that own the contracts. Savings claims are extensive and under this value they are recorded here rather than making the row a savings claim, because none of them reaches a client bill: an average $1.3 million cut in vendor costs in year one, 75 per cent shorter contract cycle times, 400 hours saved per audit, and at CompSource Mutual Insurance 636 hours of executive review time saved annually.

Nothing published addresses disclosure of AI use or AI cost in any fee context, and on this side of the relationship nothing needs to.

Source: Vendor PublishedAs of Sep 12, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Disclosure pack published

A subprocessor and model provider list plus client facing disclosure material is published or available without an agreement in place.

The pack a company would forward to answer a counterparty's AI clause is published and ungated, which is the top value. The subprocessor list is not behind a portal or a request form: it is set out in the Data Processing Agreement itself, at Exhibit C, as three tables naming each processor with its purpose and location, covering infrastructure hosting on Amazon Web Services across four regions, the four Gatekeeper group companies with their transfer mechanisms and supplemental measures, and eighteen other processors from Vanta to Workato.

The model provider limb is met from the same table rather than from marketing: Amazon Bedrock is listed as an AI Provider across four regions and Anthropic, PBC as providing AI language model services powering internal workflow automation in the United States. Client-facing disclosure material is met twice over and both artifacts were read in full: the DPA, which incorporates the EU, UK and Swiss Standard Contractual Clauses and names the competent supervisory authorities, and a standalone set of AI Terms written to be read by a customer's counsel, which prohibits training on Input and binds the AI Providers to it.

Change control is contractual: 30 days' notice of any new processor, ten business days to object, and termination if no workaround exists.

Source: Vendor PublishedAll AI Providers are sub-processors of Gatekeeper, who may process personal data of You and Users in providing the AI Functionality.As of Sep 12, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

Some elements of a record exist and no document-level export is described, which is this value, and one element here runs in the opposite direction to the usual finding. Most records in this corpus are silent on whether anyone should be told that output is machine-generated. Gatekeeper makes it a contractual obligation on the customer: AI Terms clause 6.6 requires that, prior to publication or distribution of any Output, the customer must add a disclosure notice that it was generated by AI tools, and clause 7.1 separately bars using the AI to mislead anyone that Output is human-generated.

That is a labelling duty rather than a product capability, and it is imposed rather than supported, which is why it does not lift the row further. The product elements around it are real: the vendor states that agents explain every decision they make with complete transparency and auditability, the workflow engine maintains an audit trail across intake, approval and signature, and system inputs are logged so it can be reviewed retroactively who entered, altered or deleted data.

What is absent is the export. Nothing states that any record identifies which model produced a passage, and no model is named in any event; nothing marks machine-generated text against human-edited text in a portable form; and no disclosure template or court-facing guidance was located.

Source: Vendor PublishedPrior to publication or distribution of any Output, You must add a disclosure notice that the Output was generated by AI tools.As of Sep 12, 2026Evidence
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 12, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746