Icertis
Enterprise contract lifecycle platform, Icertis Contract Intelligence, covering authoring, negotiation, approval, execution, obligation management, risk and compliance and analytics across buy side and sell side agreements. Renamed from Icertis Contract Management as the positioning moved from storing and routing contracts to extracting structured data from them. AI runs through the platform as Icertis Copilots and a contract intelligence engine that extracts clauses, obligations and risk, with an agent layer branded Vera introduced across Engage, Operate and Analyze in 2026, described by the vendor as acting autonomously within boundaries the customer sets. Built on Microsoft Azure with Microsoft as a strategic partner. Founded 2009, based in Bellevue, Washington, with more than $851m raised. States 30 percent of the Fortune 100 as customers across 90 plus countries. Publishes an annual State of Contracting research report.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
MEMBERSHIP: the AI bar is cleared. The brief flagged this vendor for a check on whether the AI is real, and it is: Icertis Copilots, a contract intelligence engine extracting clauses, obligations and risk, and a Vera agent layer shipped across Engage, Operate and Analyze in 2026, with the vendor stating agents act autonomously within boundaries the customer sets. That is shipped capability rather than an AI roadmap. GRADE: the models are the engine of a core capability layered on a product that would function without them. The platform covers authoring, negotiation, approval, execution, obligation management and analytics, and it existed and sold as Icertis Contract Management before the AI positioning; the rename to Contract Intelligence marks the layer being added rather than the product being rebuilt. Third B in a row on this axis, and the first of the four flagged legacy platform names to be tested.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted without measurement and without a described grounding method. Vendor material describes a contract intelligence engine that extracts clauses, obligations and risk and turns them into queryable data, and an enterprise wide intelligence layer that understands business and industry context, all of which is capability description rather than accuracy evidence. Searched the vendor site, the research and blog sections, the platform pages and the published State of Contracting material on 29 Aug 2026 and located no accuracy figure, no hallucination rate, no test set, no evaluation and no description of how output grounds to a source the reader can open. Worth recording alongside this, from a third party source rather than the vendor: a Gartner Peer Insights reviewer states their organisation has not been impressed with the Discovery tool AI. That is a single unverified customer view, is not treated as evidence for the grade, and is noted only because this axis exists to weigh published accuracy claims against what buyers can check.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A real published commitment with a stated control concept, short of the mechanism. The vendor's own framing is specific and unusually well chosen: agents act autonomously within boundaries you set, so you can move fast and safely, and the platform is described as human first alongside AI native. That states both that the system acts alone and that the customer defines the limit, which is more than an assertion of human in the loop. The vendor's own published research reports that 44 percent of contracting leaders lack sufficient trust in AI's autonomous capabilities, so it is engaging with the question rather than avoiding it. Not located as of 29 Aug 2026: how a boundary is configured, what an agent does when it reaches one, what review surface a human gets, and what the vendor commits to when an output is wrong.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Unattributed testimonials and scale claims stand in for deployment evidence. Customer quotes are published but the customers are anonymised by revenue band rather than named, including an IT services customer with more than $30 billion in annual revenue and a healthcare and biotech customer with more than $1 billion. Scale is claimed at 30 percent of the Fortune 100 across 90 plus countries and millions of contracts. Third party recognition is real and quantified: named a Customers' Choice vendor in the 2025 Gartner Peer Insights Voice of the Customer report for CLM, with 93 percent of customers recommending the platform across 84 ratings. That is measured satisfaction rather than a deployment outcome. Searched the vendor site, the customer and research sections and the news index on 29 Aug 2026 and located no named customer paired with figures, a date and an assessable method.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Confidentiality is asserted in general terms and the current documentation was not reachable. The clearest located statement of data handling is that the platform stores agreements on a GDPR compliant cloud infrastructure with all data encrypted at rest and in transit under a permission based management approach, which appears in a company news item from 2017. That the most specific confidentiality statement locatable dates from nearly a decade ago is itself the finding. Searched the vendor site, the platform and company sections, the news index and three separate targeted searches for a trust centre or security page on 29 Aug 2026 without reaching one. Not located: any statement on whether customer content may be used to train models, any treatment of attorney client privilege or work product, any segregation model between customers or users, and any retention or deletion terms. See the build log note on this record's evidence floor.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The audience is broad by design and no position on the advice line was located. The platform is sold across legal, procurement, sales, finance and HR, handling NDAs, service agreements and HR paperwork alongside commercial contracts, and the AI drafts, redlines and negotiates for those users. Searched the vendor site, the platform and solutions pages, the company section and the research library on 29 Aug 2026 and located no statement on advice versus tooling, no treatment of competence or supervision duties, and no jurisdiction limits despite operation in more than 90 countries. The human first framing is a design posture rather than a professional responsibility position.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Responsible AI principles are published without a mechanism a buyer could audit. The vendor positions itself as AI native and human first, states that agents operate within customer set boundaries, and publishes annual research engaging seriously with buyer concerns about AI, reporting that 55 percent of contracting leaders cite data output quality as a significant concern and 44 percent lack sufficient trust in autonomous AI. Engaging publicly with the trust deficit in your own category is a real editorial position. But searched the vendor site, the research library, the company section and three targeted searches on 29 Aug 2026 and located no published AI governance framework, no AI management certification such as ISO 42001, no named owner of model governance, no pre release testing regime, and nothing on uneven output across matter types, parties or populations.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
A generic security posture covers the platform without addressing what happens to documents and prompts after processing. Located: encryption at rest and in transit and permission based management, from a 2017 company news item; hosting on Microsoft Azure; and, from a Microsoft published customer story rather than from Icertis, use of Defender for Cloud to monitor Azure OpenAI deployments, detect malicious prompts and enforce security policies, with built in ISO 27001, SOC 2 and NIST framework mappings across subscriptions and multicloud visibility into AWS. That last source is a partner marketing case study about Icertis as a Microsoft customer, not Icertis publishing its own posture, and is weighted accordingly. Not located as of 29 Aug 2026: retention period, deletion control, subprocessor list, and incident or breach notification practice.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Searched the vendor site navigation, the platform and solutions pages, the company section, the news and research libraries and three targeted searches on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer agreement, terms of service or master services agreement was located as published on the property. Recorded as a pure absence on the surfaces reached. Rebuttable with a single link, and see the build log note on this record's evidence floor.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integration is claimed at platform level without documentation an implementer could use. The vendor describes an enterprise wide contract intelligence layer connecting agreements, data and systems, and Microsoft Azure hosting with Microsoft as a strategic partner is stated, which implies but does not document connection into the Microsoft estate. Searched the vendor site, the platform pages and the company section on 29 Aug 2026 and located no integrations page, no named connector for ERP, CRM, document management or e signature, and no description of what any integration moves or what an administrator configures. For an enterprise platform whose competitive set is named as including SAP Ariba and DocuSign CLM, and which sells into procurement and finance, that absence on the pages reached is notable.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery is stated and neither the tenancy model nor the region is given. Microsoft Azure is named as the hosting platform, which is more than several records on this index disclose, and the vendor states operation across 90 plus countries and support for multiple nations and languages. Searched the vendor site, the platform pages and the company section on 29 Aug 2026 and located no list of available regions, no customer selectable residency, no tenancy model, and no statement separating where processing happens from where data is stored. Operating in many countries is a market claim rather than a residency position.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
CORRECTED 29 Aug 2026 during the trust portal sweep. The grade stays at C but the previous reasoning was wrong and is withdrawn. That note stated no certification was stated by the vendor on any page reached and that standards references came only from a Microsoft published customer story. A vendor published document has since been located on icertis.com, an information security framework, in which the vendor states it is an ISO 27001, ISO 27017 and ISO 27018 certified organisation, holds SOC 2 Type 1 and Type 2 certifications, complies with ITAR, and hosts the ICI Platform on Microsoft Azure, directing readers to Azure's own compliance documentation for data centre coverage. So the certifications are named by the vendor after all, and the earlier note misstated that. Why the grade nonetheless remains C. The document is versioned Q1 2022 and is the only vendor published certification statement located after four separate searches, so the currency of every claim in it is unverified more than four years on. No ISO version numbers are given, so whether the 27001 certification sits at the 2013 or 2022 revision is unknown, and the 2013 revision has since been withdrawn. No coverage period, no audit scope, no report date and no named auditing firm were located. No trust portal or published request route for compliance reports was located. Naming standards in a stale document without scope, currency or an evidence route is the C band. Rebuttable by any current certification page.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The vendor refers to AI capability without identifying what sits underneath, though the chain is partly inferable. Microsoft is named as a strategic partner and Azure as the platform, and a Microsoft published customer story records Icertis monitoring Azure OpenAI deployments, which indicates Azure OpenAI is in the stack. That is a partner disclosure rather than a vendor one, and the distinction matters: naming a hosting partnership is not naming which models serve which task. Searched the vendor site, the platform and research pages and the company section on 29 Aug 2026 and located no named model provider stated by Icertis, no statement of where models run, no subprocessor list, and no commitment to notify customers when the supply chain changes.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Checked the vendor site navigation, the platform and solutions pages, the company section and the research library on 29 Aug 2026. No pricing page was located, no rate is published, no unit of charge is stated and no tier structure appears. Every commercial path located terminates in a demo or contact request. No free trial or self serve entry point was located, and no third party pricing figure was located either.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is described with substance, short of the boundaries. The buyer is stated clearly as the large enterprise, with 30 percent of the Fortune 100 claimed across 90 plus countries and multiple languages, and the platform explicitly spans buy side and sell side agreements rather than one direction. Industry breakouts are published in the vendor's own research covering public sector, healthcare and life sciences, and banking and insurance among others. Functional coverage spans legal, procurement, sales, finance and HR. Not located as of 29 Aug 2026: any statement of which organisation sizes, contract types or practice areas the platform is not built for. Third party reviews state that small and most mid market businesses will find it more platform than they need, which is exactly the boundary statement the vendor does not make itself.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way.
Searched the vendor site, the platform and company sections, the news and research libraries, and ran three separate targeted searches for a trust centre or security page on 29 Aug 2026 without reaching one. No located term or policy addresses whether customer content may be used to train models, either way. Recorded as silent under the rule that a value is never inferred from the absence of a contradiction. Note the evidence limit stated in the build log: this is the one record on the index where the vendor's own security material was not reached, so this value reflects what a buyer can find by searching rather than a reading of a located policy that stays quiet.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
Searched the vendor site, the platform and company sections, the news and research libraries and three targeted searches on 29 Aug 2026. No public material states how long contracts, prompts or outputs are retained, whether a customer controls the window, or whether deletion is available. The platform is a system of record designed to hold executed agreements and their obligations for their full life, so retention is central to what is being bought, and no published terms attach to it on the surfaces reached.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Segregation is asserted in public materials with no published detail on how it is enforced.
Segregation is asserted in public materials with no published detail on how it is enforced. The located statement is that the platform stores agreements on GDPR compliant infrastructure with encryption at rest and in transit under a permission based management approach, and third party review material refers to standardised workflows and access controls. That is an access model asserted rather than described: no roles, no scoping rules, no statement of whether retrieval by the AI layer respects those permissions per user, and the primary source is a company news item from 2017. No document management integration was located whose permissions the product could inherit. Recorded at claimed but not documented.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located term or policy addresses third party requests for customer data.
Searched the vendor site, the company section, the news library and three targeted searches for published terms, a privacy policy or a trust centre on 29 Aug 2026. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. No published customer agreement or data processing agreement was reached on the property, so the search covered public marketing and news pages rather than contract documents.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
No primary law corpus is identified because the product does not appear to hold one. Retrieval runs against the customer's own contract repository, templates and clause library, so the corpus is the customer's own agreements and its provenance is theirs. Searched the vendor site, the platform pages and the research library on 29 Aug 2026 and located no vendor supplied legal corpus, no licence basis and no update cadence. Noted for a reader: this is the same architectural shape as Definely and Ironclad, where the absence on this signal describes the product design rather than a disclosure failure.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Searched the vendor site, the platform pages and the research library on 29 Aug 2026. No material was located addressing whether authority carries a treatment signal or whether subsequent history is checked, and no commercial citator licence was located. Noted for context: this is a contract lifecycle platform grounded in the customer's own agreements with no case law research surface, so a citator is outside its design entirely.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Searched the vendor site, the platform pages, the research library and the 2026 event coverage on 29 Aug 2026. No published material describes what the product does when it cannot ground an answer, and no explicit no answer path or confidence signal exposed to the user was located. The vendor's boundaries language describes limits a customer sets on what an agent may do, which is a permission concept rather than a statement about what the system does when it does not know.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. Note that this is a contract lifecycle platform with no case law research surface, so its output is very unlikely to reach a court filing as cited authority.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
Searched the vendor site, the research library including the State of Contracting reports, the blog and the news index on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located, including ABA Formal Opinion 512 and state bar guidance. The vendor publishes substantial annual research on AI adoption and trust in contracting, which surveys practitioner sentiment rather than engaging with the professional responsibility rules its legal buyers are bound by.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Vendor material is framed around business outcomes rather than hours: growing revenue, controlling costs, mitigating risk and ensuring compliance, with published claims about drafting faster and executing with greater precision. Searched the vendor site, the platform pages, the research library and the news index on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no guidance on billing, fee or client disclosure treatment. Noted for context: the buyer is a corporate legal, procurement or finance function rather than a firm billing a client by the hour, so this signal reads differently for this segment, and the savings framing here is enterprise cost rather than billable time.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
Searched the vendor site, the company section, the news and research libraries and three targeted searches for a trust centre, security page or certification listing on 29 Aug 2026 without reaching one. No subprocessor list, no statement of which model providers see customer content, no published data processing agreement and no client facing consent or notification material was located. Standards references located for this vendor come from a Microsoft published customer story rather than from Icertis, which is not a disclosure a firm could forward to its own client as the vendor's own commitment.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located public material addresses court disclosure or verification certification.
Searched the vendor site, the platform pages and the research library on 29 Aug 2026. Third party review material refers to standardised workflows and access controls, and the platform tracks obligations and approvals per contract, so a workflow trail plausibly exists, but no vendor material describes an export covering model used, sources retrieved and human verification together, and no model is named by the vendor so the model used could not be stated. Noted for context: this is a contracting platform rather than a litigation product, so a judicial AI disclosure order is unlikely to reach its output.