Leah
Agentic platform for contracting, legal, procurement and finance, sold to large enterprises and formerly known as ContractPodAi. The contract lifecycle product covers guided intake and document upload, playbook-driven review and redlining inside Microsoft Word, conditional approval routing with automatic escalation, execution through built-in DocuSign and Adobe Sign integrations, and a repository with cognitive search, obligation tracking and renewal alerts, alongside a legal helpdesk that answers contract questions with sources attached. Around it sits what the vendor calls the Agentic OS: a skills-based orchestration layer that assigns work to domain agents for legal, contracting, procurement and finance, a no-code builder for composing workflows and apps, and Leah Maestro as an orchestrator across them. The governance model is published in detail and is the platform's main selling point against general-purpose AI: the customer defines which agents may act, on which data, within which thresholds and where escalation is required, those policies are held as configuration rather than code and applied by the orchestrator at run time, and every action is logged with the rationale, the governing policy and the outcome in records the vendor describes as tamper-resistant and immutable. Leah runs on multiple large language models selected dynamically per task, with OpenAI and Anthropic named as providers under zero data retention terms, keys held in Azure Key Vault, and a dedicated private environment available in Azure OpenAI Studio for customers needing full isolation. Integrations include SAP, NetSuite, Coupa, Okta and existing contract lifecycle systems. Leah is a product of ContractPod Technologies Limited, an independent company headquartered in London with offices across North America, Europe, Asia and Australia, and PwC, Epiq, Integreon and Pinsent Masons deliver or resell it as alliance and implementation partners.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of the capability being sold, layered on a contract lifecycle platform that would function without them. The vendor argues the opposite, stating that other vendors bolted AI onto systems built for manual workflows while Leah was designed from scratch with orchestration as the foundation. The published record does not support that reading. ContractPod Technologies has sold contract lifecycle management since 2012; Leah launched in March 2023 as an AI services hub within that platform, went standalone in May 2023, and Leah Intelligence followed in October 2024. Strip out the agents and what remains is a working CLM with guided intake, approval routing, DocuSign and Adobe Sign execution, and a contract repository, which is a product with its own market and its own Gartner category placement. The orchestration layer is real and is genuinely model-driven, which is why this is a B rather than lower.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted repeatedly, and at one point claimed to be benchmarked, without a single figure attached. The AI governance page states that every action is measured against benchmarks for accuracy, bias and outcome, and the product material describes a legal helpdesk that answers contract questions with sources attached, which is a grounding claim a reader could in principle check inside the product. Searched the home page and the AI governance page in full on 31 Aug 2026 and located no accuracy figure, no error or hallucination rate, no description of any benchmark or test set, and no published evaluation. The benchmark claim is the sharpest version of the problem this axis exists to catch: a vendor asserting measurement without publishing the measurement. Nothing addresses what the system does when the customer's own contract set does not support a position.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The control structure is published in full and is the thing the vendor sells on. A dedicated AI governance page sets out a three-stage loop. Policy in: the customer defines which agents may act, on which data, within which thresholds, and where escalation is required, with those policies held as configuration rather than code. Execution governed: every agent action runs through those policies in real time, with approvals, escalations and rejections applied automatically and the orchestrator enforcing guardrails at each step. Audit out: every decision is logged with the rationale, what the agent did, why, under which policy, on what data and to what outcome, in records described as tamper-resistant and immutable. That covers the thresholds, the review surfaces and the route back to human judgement, and the home page states the position plainly, that the workflow runs itself while the judgment stays human. What is still missing is what happens after an output is found to be wrong, and default modes are not described because the guardrails are customer-configured rather than shipped.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Substantial evidence on both halves of the question, never joined together. Named individuals speak on the record with roles and employers: Noelle Perkins, EVP and Chief Legal Officer at Cushman and Wakefield; Lidia Kamleh, Chief Legal Officer at Dubai Future Foundation; Frances Bain-Cumberbatch, Chief Legal and External Affairs Officer at Ansa McAL; and Zillia Knight, Senior Legal Officer at Terumo Europe. Every one of those quotes is qualitative. Separately, three figures are published with the customer anonymised: a 91 per cent cut in contract review time at a major US logistics company, more than 18 million dollars of revenue protected at a global manufacturer, and more than 2 million dollars of tracked savings at a US retail REIT. Roughly 54 enterprise logos appear, including Philips, MUFG, Sandoz, Pernod Ricard, Alaska Airlines and Wood PLC. A buyer should read that logo strip carefully: PwC and KPMG appear in it, and PwC entered a commercial alliance in March 2024, while Epiq resells Leah inside its Service Cloud, Integreon is quoted as an early adopter reselling onward, and Pinsent Masons adopted it for managed legal services in July 2025. Channel partners and customers are presented together without distinction, and a Chief Product Officer of Execo, another services partner, appears in the testimonial carousel.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Specific published commitments on the questions that matter most, with two real gaps. The vendor states that customer contract data is never used to train models, and the AI governance page frames data leaking into models the customer does not own as a failure it engineered out, stating that zero data retention is the only acceptable answer and that it enforces zero retention with OpenAI and Anthropic so that data is processed but never stored by the providers. Encryption is AES-256 at rest and TLS in transit with keys held in Azure Key Vault, rotated and reachable only through controlled service accounts. Role-based access control is stated to be enforced at every layer, and single-tenant deployment is offered for customers with strict isolation requirements. Two gaps. Privilege and work product are not addressed anywhere on the surfaces read on 31 Aug 2026, on a platform sold into Fortune 500 legal departments. And none of it could be checked against an agreement: the legal and privacy pages are linked from every footer but neither could be retrieved, so every commitment recorded here sits on a marketing or governance surface rather than in a contract.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Nothing published on the advice line was located. Section 8 places this evidence in footers, disclaimers, terms and any ethics page; three of those four were checked on 31 Aug 2026, across the complete footers of the home page and the AI governance page and the full navigation and footer sitemap covering platform, solutions, resources and company. No disclaimer of any kind appears, there is no ethics or professional responsibility page, no bar or ethics guidance is named including ABA Formal Opinion 512, and no statement was found on the line between a tool and legal advice. The exposure is not trivial: the platform is sold to run legal work end to end across legal, procurement and finance teams, and its own framing is that agents execute multi-step commercial work without routing every decision through a person. The fourth home, the terms page at the site's legal link, could not be retrieved, so this grade is rebuttable on that document alone.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
The most substantial governance framework published by any vendor in this pull, short of a named owner and any disclosed result. A dedicated AI governance page names six failure modes the vendor says it engineered out, including black-box decisions that cannot be defended to a regulator or board, and compliance frameworks retrofitted after the fact. Against those it sets three pillars and the policy-execution-audit loop, with per-action logging of rationale and governing policy described as tamper-resistant and immutable, which is a mechanism a buyer could audit rather than a principle. It also makes a claim no other vendor in either pull has made: that every action is measured against benchmarks for accuracy, bias and outcome, with the page stating that accountability is structural rather than aspirational. That is why this is not lower. It is not higher because none of the substance behind the claim is published. No individual or role inside the vendor is named as accountable for model behaviour, no pre-release testing regime is described, no benchmark method or cadence is given, and no result of any bias measurement has been disclosed.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published controls with two specific absences. The AI governance page publishes real operational detail: TLS for data in transit and AES-256 at rest, encryption keys managed through Azure Key Vault, rotated regularly and accessible only through strictly controlled service accounts, multi-factor authentication, secure API gateways, network segmentation, real-time monitoring, and a fully documented incident response plan. Audit logs are described as comprehensive, tamper-resistant and immutable. Assurance is external rather than self-asserted: the vendor states it is audited annually by an independent Managed Security Service Provider and penetration tested regularly. What is absent, checked 31 Aug 2026: no subprocessor list of any kind, with OpenAI and Anthropic named as model providers but no other processor identified, and no breach notification practice or timeline anywhere despite the incident response plan being referenced twice. No retention period for customer content was located either, which is recorded separately in the signals.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Not yet assessed.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations into enterprise systems, named and functionally described, short of implementer documentation. The named set is the right one for this buyer and unusually broad for the category: ERP platforms including SAP and NetSuite, source-to-pay and procurement systems including Coupa, financial systems, identity providers including Okta, and existing contract lifecycle tools, alongside DocuSign and Adobe Sign built in for execution and a Microsoft Word add-in for redlining. The vendor describes the integration model rather than just listing logos, stating that integration is connect-and-execute, that Leah does not replicate data passively, and that it executes work across connected systems through the orchestration layer, which is a meaningful architectural claim. What was not reached on 31 Aug 2026 is depth: the dedicated integrations page was not opened, and nothing read states what syncs in which direction or what a customer must configure. No document management integration such as iManage or NetDocuments appears, consistent with an in-house rather than law firm product.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The tenancy model is addressed directly and the regions are not. Single-tenant deployment is stated to be available for customers with strict data isolation requirements, and beyond that the vendor offers what it calls a dedicated zero-trust private environment within Azure OpenAI Studio, described as ensuring complete data isolation from all other customers, which tells a buyer both that the default is shared and that a separated option exists. The infrastructure is identified as Azure, with encryption keys held in Azure Key Vault. Two things hold this at B, checked 31 Aug 2026. Data residency is addressed only in the abstract, with the vendor saying it supports the residency and regulatory requirements typical of large multinational enterprises and naming no region, no jurisdiction and no customer-selectable option. And nothing states where processing happens as distinct from where data is stored, which matters on a platform that routes work dynamically across multiple model providers.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
A long list of frameworks with no scope, no date, no auditor and no report, and the property contradicts itself on what is held. The AI governance page claims SOC 1 Type I and II, SOC 2 Type I and II, GDPR compliant, CCPA compliant, HIPAA ready and ISO 27001 aligned. The home page FAQ, on the same property, says only that Leah is SOC 2 Type II certified. Credit where it is due: the hedged wording is honest, since the page says aligned and ready rather than certified for ISO 27001 and HIPAA, and most vendors blur exactly that line. But the substance an attestation is judged on is missing entirely. The auditor is identified only as an independent Managed Security Service Provider, which is a category rather than a name; no coverage period or report date is given; no audit scope is described; penetration testing is said to be regular with no partner named and no summary published; and no trust centre or portal exists anywhere on the property, so there is no route to request a report either. Checked 31 Aug 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Providers named with a stated retention position, and a routing model that limits what naming them tells you. OpenAI and Anthropic are both identified as the underlying model providers, with zero data retention stated to be enforced against each so that customer data is processed but never stored by them, and the private deployment option is named specifically as Azure OpenAI Studio, which identifies where inference runs. Three gaps, checked 31 Aug 2026. No model or version is named for either provider. Nothing commits the vendor to notifying customers when the provider set or the models change. And the architecture itself creates a disclosure problem the vendor does not address: the platform is described as dynamically selecting across multiple advanced LLMs to match each task with the right model, and as allowing customers to extend or customise models, so which provider handled a given piece of legal work is not knowable to the buyer from anything published.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. Searched the home page, the AI governance page, the full primary navigation covering platform, solutions, resources and company, and the complete footer sitemap on 31 Aug 2026. There is no pricing page, no tier structure, no per-seat, per-contract or per-agent unit, no volume banding, and no indication of what implementation adds. Every call to action across the property is to request a demo. The closest the vendor comes is an implementation FAQ stating that timelines vary with scope and integrations and that a detailed plan is built during evaluation, which is a statement about effort rather than cost. Nothing published would let a prospective buyer form any view of price before entering a sales process.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is documented precisely across two dimensions and the boundaries are never stated. By industry the vendor publishes dedicated pages for CPG and manufacturing, energy and utilities, financial services, healthcare, and pharma and medical devices, and describes its customers as Fortune 500 enterprises in regulated industries. By function it publishes pages for legal leadership, legal operations, sales and revenue, procurement, and finance, with distinct propositions written for the General Counsel, the contract operations team, the Chief Procurement Officer and the finance leader. The customer roster evidences that spread rather than merely claiming it, spanning banking, airlines, pharmaceuticals, consumer goods and engineering. What is absent is the far edge. No statement identifies which practice areas, contract types or matters the platform does not support, nothing addresses smaller organisations, and law firms appear only indirectly through managed service partners rather than as a served segment. Checked 31 Aug 2026.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
A public policy or trust page states no training on customer content, with no matching term located in the published agreement.
The security FAQ on the home page states that customer contract data is never used to train models, and the AI governance page reinforces the position from the other direction, naming data leaking into models the customer does not own as a failure it engineered out and stating that zero data retention is the only acceptable answer. That position is stated to be enforced against the named providers, with data processed but never stored by OpenAI or Anthropic. No matching term could be checked in any agreement: the legal and privacy pages are linked from every page footer but neither could be retrieved on 31 Aug 2026, by direct fetch or through the search index, so the commitment recorded here is a published policy statement rather than a located contractual term. Rebuttable on either document.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
This signal has not been recorded for this vendor yet. It is not a finding either way.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Segregation is asserted in public materials with no published detail on how it is enforced.
Separation is asserted at customer level and offered as an architecture rather than a control. The vendor states that single-tenant deployment is available for customers with strict data isolation requirements, and that a dedicated zero-trust private environment within Azure OpenAI Studio ensures complete isolation from all other customers, with role-based access control stated to be enforced at every layer. What that wording also establishes is that isolation is a deployment option rather than the default, and nothing published describes how customers are separated in the standard shared deployment. Nothing addresses boundaries inside a customer either, which matters on a platform where legal, procurement, finance and shared services teams work in the same system. Searched the home page and the AI governance page on 31 Aug 2026; the privacy statement could not be retrieved.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
This signal has not been recorded for this vendor yet. It is not a finding either way.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Sources are identified without stating the licence or rights basis.
The working corpus is the customer's own material and is identified as such: the vendor states that Leah operates against the customer's policies and playbooks, gains intelligence from the customer's unstructured data and business rules, and answers contract questions from the customer's repository with sources attached. Alongside that it refers to Leah operating against established legal precedents, which names no source, no jurisdiction, no database and no rights basis. The product manages a customer's contracts rather than retrieving primary law, so the usual coverage question does not arise in full, but the precedent reference is unsupported by any provenance statement. No update cadence is published for anything.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Searched the home page and the AI governance page in full, together with the complete navigation and footer sitemap, on 31 Aug 2026. Nothing addresses whether legal authority is checked for subsequent history, and no citator, treatment signal or currency check was located. The platform manages contracts, obligations and procurement workflows rather than retrieving case law, so a citator is not part of what it sells. Worth recording alongside that: the vendor refers to Leah operating against established legal precedents without identifying any source, so the one place primary authority is invoked carries no verification mechanism.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Searched the home page and the AI governance page in full on 31 Aug 2026. No explicit no-answer or abstention path is documented and no confidence or grounding score was located. The governance loop does produce rejections, with approvals, escalations and rejections applied automatically according to the customer's rules, but those are policy outcomes decided by configured guardrails rather than the model declining to answer because it cannot ground a response. Nothing published states what Leah does when the customer's own contract set or playbook does not cover the question in front of it.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, searched on both the current product name and the former company name ContractPodAi, alongside 2026 sanctions trackers and trade press summaries. This is a statement about the public record on the date shown rather than a clearance, and it is bounded by what that database covers. The platform runs commercial contracting and procurement work rather than producing court filings, so its output does not ordinarily reach a brief.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
Searched the home page, the AI governance page and the complete navigation and footer sitemap on 31 Aug 2026. No engagement with any bar or ethics guidance was located, including ABA Formal Opinion 512, US state bar guidance, and Solicitors Regulation Authority or Law Society material despite the company being headquartered in London and selling into legal departments across North America, Europe, Asia and Australia. The compliance material published is regulatory and security-framework oriented, covering GDPR, CCPA, HIPAA, SOC and ISO, and none of it addresses the professional conduct obligations that bind the lawyers using the product.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Public materials are framed around cost and time removed, and quantified at portfolio level: a 91 per cent cut in contract review time, more than 18 million dollars of revenue protected, more than 2 million dollars of tracked savings, and headline figures of more than 125 billion dollars of commercial value managed and more than 10 billion dollars of ROI impact delivered. Searched the home page and the AI governance page on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee purposes and no published guidance on billing, fee or client disclosure treatment. The immutable per-action audit log the vendor describes could in principle support such a record, but nothing presents it for that purpose. The buyer is an in-house function rather than a firm billing a client, so the question lands on internal cost and outside counsel spend, and neither is addressed.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
A model provider list is published without a gate: OpenAI and Anthropic are both named as the providers processing customer content, with zero data retention stated to be enforced against each, and the private deployment environment is identified as Azure OpenAI Studio. That is the disclosure most useful to a legal team answering a client AI clause and it is readable before any agreement is in place. Nothing beyond it was located on 31 Aug 2026. No subprocessor list of any kind exists, so processors other than the model providers are unidentified. No client-facing consent or notification material was found, no trust centre or portal exists on the property, and the data processing agreement, if one is published, sits behind the legal page that could not be retrieved.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
The strongest partial record read in this pull, missing one element. The audit stage of the published governance loop logs every decision with what the agent did, why, against which policy, with what data, and what the outcome was, in records the vendor describes as tamper-resistant, immutable and ready for any audit. That covers the action, the governing rule, the inputs and the result at per-action granularity. The missing element is the model: the platform selects dynamically across multiple LLMs per task and no model or version is identified anywhere, so which system produced a given passage cannot be established from the record. No export designed for a court disclosure or AI-use certification was located, and the audit framing throughout is regulatory and internal rather than judicial. Checked 31 Aug 2026.