Malbek

Malbek is an enterprise contract lifecycle management platform sold to corporate legal departments and to the sales, procurement and finance teams that contract alongside them. The core CLM handles contract creation, workflow, approvals, repository and milestone tracking, and three further modules sit on top of it: Malbek AI, which surfaces contextual insights and recommendations from contract data; BusinessIQ, which turns a contract portfolio into reporting on revenue, risk and commercial exposure; and Klix, a clickwrap solution for online agreements. Malbek Marketplace configures integrations through a no-code drag-and-drop interface, with more than 50 available including a native bi-directional Salesforce connector alongside NetSuite, SAP, Coupa, Slack, DocuSign and Adobe Sign, and a REST API where no productized connector exists. The company states that customer inputs, outputs and embeddings are never accessible to its large language model vendors and are never used to train models, with foundation models reached through AWS Bedrock and Azure alongside Malbek's own proprietary models in a cross-validating ensemble. Malbek is SOC 2 Type II and SOC 1 Type II certified and runs on AWS. There is no published price: quotes are built per customer from user count, user type, modules and integration connectors. Malbek was named a Leader in the 2025 Gartner Magic Quadrant for Contract Life Cycle Management.

Vendor site
Last verifiedSeptember 4, 2026

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The models are the engine of a core capability layered on a product that stands without them. Malbek's own framing is an AI-charged CLM: the platform underneath is contract creation, workflow, approvals, repository, milestones and clickwrap, and the AI arrives as separately named and separately sold modules, Malbek AI for insights and recommendations and BusinessIQ for portfolio-level commercial intelligence. The pricing page confirms the separation by making modules one of the four variables a quote is built from. Remove the models and a functioning contract lifecycle management system remains, which is the distinction this band draws. Checked 4 September 2026.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Grounding is described architecturally rather than asserted as a slogan. The security FAQ sets out an Ensemble LLM architecture deploying specialised AI agents in a cross-validating chain configuration, combining proprietary Malbek AI and ML models with foundation models reached through AWS Bedrock and Azure, which the vendor states ensures well-grounded and cited results. A cross-validating chain is a real control and is more than most records on this axis publish. What is missing is measurement: no accuracy figure is published, no test set is described, no evaluation is linked, and no failure mode is named anywhere, including hallucination. Grounding to primary authority does not bite on a contract lifecycle product, where the corpus is the customer's own repository, and is not counted either way.

Source: Vendor Published
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Autonomy is claimed and oversight is not described. The platform is marketed on eliminating manual effort across the contracting process, streamlining negotiations, shortening review cycles and surfacing timely recommendations, and a published customer testimonial states that approximately 80 per cent of that customer's templates no longer require legal review. Nothing published describes what the system does unattended versus what a human approves, no review surface is named, no threshold is stated at which a matter returns to a lawyer, and no account is given of what happens after an output is wrong. The word recommendations implies an advisory posture but no control structure sits behind it. Searched the home page, platform and module pages, the security and compliance page and the plans page on 4 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Real deployment evidence with substance, short of assessable measurement. Named customers appear as logos including EDF, SurveyMonkey, Aptean, Articulate, Lighthouse, TIBCO, Cetera, J.D. Power and Darden. Testimonials carry names and roles rather than initials: Ellen Kranz, Senior Contracts Specialist, states approximately 80 per cent of templates no longer require legal review and describes contracts being active within minutes or hours; Adrienne Schaal, Director of Legal Operations, describes a Salesforce integration configured in minutes and field mapping without IT; Jeff Peduto, SVP Operations, describes 90 days notice before renewal dates. Malbek was named a Leader in the 2025 Gartner Magic Quadrant for Contract Life Cycle Management. What holds this at B is that the figures sit inside quotations with no method, date or baseline, and the separate by-the-numbers panel, including 120 per cent retention and 90 per cent recommending, states no basis, sample or date for any figure.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Substantive published commitments on confidentiality and training use, short of the full picture. The security and compliance FAQ is specific where most vendors are vague: client inputs, outputs, embeddings and training data are stated never to be shared with other customers, never accessible to the large language model vendor, never used to improve or train future models, and never used to enhance third-party products, with the same commitments said to be imposed on partners, subcontractors and sub-processors. Enterprise-grade data isolation is asserted, supported by role-based access controls with field-level permissions, single sign-on, multi-factor authentication and AES-256 encryption. The limb this band commonly finds missing, what the underlying model provider may retain, is answered here rather than absent. What is not published is retention or deletion, and privilege and work product are not addressed at all, which is defensible for a corporate CLM whose buyer is an in-house department rather than a firm but is still an unmet limb. The commitments also live on a marketing FAQ rather than in an agreement a buyer can read, because the terms of service did not render.

Source: Vendor Published
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

The marketing describes the product in terms that displace legal review while no position on the advice line is published anywhere reachable. A featured customer quotation states that approximately 80 per cent of that customer's templates no longer require legal review and that sales teams start contracts and mark them active after signature within minutes, and the departmental pages sell contract handling directly to sales, procurement and finance. Against that, no disclaimer, no statement of what the product is and is not, no competence or supervision language and no jurisdiction limit was located on the home page, the platform and module pages, the security and compliance page or the plans page. The terms of service is the surface most likely to carry a disclaimer and it did not render, so the possibility that one exists there is not excluded; the grade rests on what the marketing does say rather than on that gap. Checked 4 September 2026.

Source: Vendor Published
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

What is published under the AI heading is security rather than governance, and the two are different subjects on this axis. The AI safeguards answer is genuinely detailed, naming defences against instruction override attacks, data exfiltration through format manipulation, output format hijacking, CSV injection, multi-stage attack chains and delimiter confusion, which is a more specific account of LLM attack surface than most records carry. None of it addresses governance: nobody inside Malbek is named as accountable for AI outcomes, no pre-release evaluation of model output is described, no testing results are published, and there is no responsible AI statement, no ISO 42001 and nothing whatever on bias or uneven output across contract types or counterparties. The release process answer describes QA certification and change control for the platform generally, which is software governance rather than model governance.

Source: Vendor Published
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Substantive published policy covering most of the ground. Access control is set out in detail: a zero trust approach, AES-256 encryption, role-based access controls with field-level permissions, single sign-on and multi-factor authentication, continuous monitoring and threat detection, background checks on personnel, regular security awareness training and a security team monitoring systems around the clock. Incident practice is stated, with a structured response plan prioritising transparency, and third-party audits and penetration testing are said to run regularly. A business continuity and disaster recovery plan is described in outline, with the full policy available under NDA. What is missing from the set is retention and deletion, which are not stated anywhere reachable, and the subprocessor list, which exists but sits inside the Vanta-hosted trust centre and did not render. Checked 4 September 2026.

Source: Vendor Published
Not Rated

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Not yet assessed.

AA on Practice Systems Integration DepthDocumented, verifiable integrations into the systems legal work already lives in, with the depth described: what syncs, in which direction, and what a firm must configure.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Documented integrations into the systems contracting actually runs through, with depth described. More than 50 integrations are published and organised by type across CRM, ERP, e-signature, storage and SSO, with a browsable directory. The Salesforce connector is described to the level this band asks for: a productized native connector enabling complete bi-directional data synchronisation, configurable in minutes, and a customer quotation independently describes mapping new fields as business needs change without IT involvement. Named targets include NetSuite, SAP, Coupa, Slack, OneTrust, Adobe Sign, DocuSign and Azure OpenAI. Malbek Marketplace is a no-code drag-and-drop interface for configuring connections, which answers what a customer must set up, and a REST API is published for targets without a productized connector. The plans page states which integrations are complimentary and which cost extra, which is a configuration fact most vendors omit.

Source: Vendor Published
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Neither limb this axis needs is published. Data residency options are listed as a data protection feature but no region is named, no set of options is enumerated, and nothing states where a given customer's data would sit. Tenancy is not addressed at all: no statement describes whether the platform is single or multi-tenant or how customers are separated at the infrastructure level, and the closest published detail is the assertion of enterprise-grade data isolation on the security page, which is a claim rather than a tenancy model. Hosting on AWS is named, which identifies the infrastructure provider without answering either limb. Searched the home page, the platform and module pages, the security and compliance page and the plans page on 4 September 2026.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Note amended 4 September 2026 under R27 on a newly located document, the security and compliance page at malbek.io/security-and-compliance, last modified 14 April 2026, which the original pass did not reach. Grade unchanged. What is now located and was not before: Malbek states that it is SOC 2 Type II and SOC 1 Type II certified in its own right, which is a first-party claim about Malbek rather than about its host. That distinction matters on this record because the certifications separately listed on the same page, ISO 9001, ISO 27001, ISO 27017, ISO 27018, PCI DSS Level 1 and SOC 1, 2 and 3, are expressly AWS's for the cloud infrastructure and are not credited to Malbek. The page also records regular third-party security audits and penetration testing with independent auditors evaluating the security posture, background checks and annual security awareness training for personnel, 24/7 monitoring by a dedicated security team, and a structured incident response plan. Compliance is claimed with GDPR, CCPA, CFR 21 Part 11 and GxP. It holds at B because none of the accessible-evidence limbs is met: no certifying body or auditor is named, no report date, observation period or scope statement is published, no report is offered at any access tier, and the disaster recovery policy is stated to be available only under NDA. The trust centre at trust.malbek.io is Vanta-hosted and returned metadata with no body. On the third-party verifiability test a buyer cannot check either certification against a register without contacting Malbek.

Source: Vendor Published
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Note amended 4 September 2026 under R27 on a newly located document, the security and compliance page at malbek.io/security-and-compliance, last modified 14 April 2026, which the original pass did not reach. Grade unchanged and better evidenced. The architecture is now described rather than asserted: Malbek publishes an Ensemble LLM architecture deploying specialised AI agents in a cross-validating chain configuration, combining proprietary Malbek AI and ML models with foundation models reached through AWS Bedrock and Azure. So a buyer can establish that both in-house and third-party models are in use and by what route they are reached, and Azure OpenAI appears among the integration logos on the plans page. The same page states that when external large language model APIs are used, Malbek adheres to each provider's terms and engages only vendors meeting its data protection standards, and that client inputs, outputs, embeddings and training data are never accessible to the LLM vendor and never used to improve or train models. A sub-processors page is published at malbek.io/sub-processors and was not opened in this pass. What keeps this at B rather than above it: no individual model is named, the foundation model providers behind Bedrock and Azure are not identified, no location is given for inference as distinct from hosting, and no commitment to notify customers when a model or provider changes was located.

Source: Vendor Published
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

The unit and structure are stated without the figure, which is this band's second limb. The plans page publishes the four variables a quote is built from: user types, number of users, modules, and Malbek connections. The pricing FAQ adds that customers pay only for what they need against a custom quote estimated on those inputs, that some integrations are complimentary while others carry additional cost, and that implementation is scoped per customer from a few datapoints. Support, training and the help centre are stated to carry no additional cost, with monthly training included. What is not published is any number, any band, any tier name or any feature split between packages, so the shape of the model is visible and its scale is not. A VendorPricing row is written on the published structure.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Segment coverage is described with substance and the boundary is left open. Four buying departments each carry their own solution page, Sales, Legal, Procurement and Finance, with a stated purpose for each, and four industries each carry their own page, Life Sciences, Manufacturing, Consumer Packaged Goods and Retail, with regulated-agreement handling called out for life sciences and high-volume supplier and promotional contracting for CPG. Compliance coverage extends the picture with GDPR, CCPA, CFR 21 Part 11 and GxP named. The buyer is a corporate enterprise rather than a law firm, and law firms are neither claimed nor excluded. What is missing is the edge: no contract types are enumerated as supported, no organisation size is stated, government use is not addressed, and nothing says where the product stops.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Never, in policy only

A public policy or trust page states no training on customer content, with no matching term located in the published agreement.

The security and compliance FAQ answers the question directly and in the negative, stating that enterprise-grade data isolation guarantees customer data is never used for model training, and separately that client inputs, outputs, embeddings and training data are never accessible to the large language model vendor, never used to improve or train future models, and never used to enhance third-party products. The same commitments are said to be required of partners, subcontractors and sub-processors. The commitment sits on a public security page rather than in an agreement: a terms of service is published at malbek.io/terms-of-service but its body is delivered through Malbek's own Klix clickwrap module and returned no content on 4 September 2026 in either URL form, so no matching contractual term could be located or excluded.

Source: Vendor Publishedcustomer data is never used for model trainingAs of Sep 4, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Not addressed

No located public material states how long prompts and outputs are retained.

Written as an amendment on 4 September 2026, closing a row left unwritten under R7. Malbek addresses what happens to inputs and outputs in unusual detail and never states how long they are kept. The security and compliance page, last modified 14 April 2026, records that client inputs, outputs, embeddings and training data are never accessible to the LLM vendor, never used to improve LLM models or train future AI models, and never used to enhance third-party products, and describes enterprise-grade data isolation. That covers access and permitted use rather than duration: no retention period, no deletion commitment and no end-of-subscription position appears on any surface reached. Retrieval limit, named so it is not read as a finding: the terms of service and privacy policy bodies are served through Malbek's own Klix clickwrap module and returned page frames with no clause text on two separate attempts, on 4 September 2026, the second using operator-supplied URLs, and a search on distinctive clause language returned nothing indexed. The trust centre at trust.malbek.io is Vanta-hosted and returned metadata only.

Source: Vendor Publishednever used to improve LLM models or train future AI modelsAs of Sep 4, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Claimed, not documented

Segregation is asserted in public materials with no published detail on how it is enforced.

Segregation is asserted in public material without published detail on how it is enforced. The security and compliance page states enterprise-grade data isolation and that client inputs, outputs and embeddings are never shared with other customers, and lists role-based access controls with field-level permissions among its data protection features. Nothing published describes the isolation mechanism, the tenancy model, or how permissions are administered, and no material addresses separation between matters or contract sets within a single customer.

Source: Vendor PublishedEnterprise-grade data isolationAs of Sep 4, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Not addressed

No located term or policy addresses third party requests for customer data.

Written as an amendment on 4 September 2026, closing a row left unwritten under R7. No located public material addresses disclosure of customer data in response to a subpoena, court order or governmental request, and nothing commits to notifying the customer or reserves discretion over notice. The security and compliance page was read in full on 4 September 2026 and covers encryption, access control, operational security, third-party audits, disaster recovery and AI safeguards without reaching compelled disclosure at any point. The sub-processors page and privacy policy are the surfaces that would ordinarily carry it. Retrieval limit, named so this is not read as a finding: the privacy policy and terms of service bodies are served through Malbek's own Klix clickwrap module and returned page frames with no clause text on two attempts, the second using operator-supplied URLs, and a search on distinctive clause language returned nothing indexed. The trust centre is Vanta-hosted and returned metadata only. There is nothing to quote because the position was not located rather than stated.

Source: Operator VerifiedAs of Sep 4, 2026
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Not addressed

No located public material identifies the corpus behind the product’s answers.

No located public material identifies a corpus behind the product's answers, and the product's design makes the question narrow: Malbek analyses the customer's own contract repository rather than retrieving external legal content, with BusinessIQ described as distilling that repository into generative intelligence. No external database, publisher or content licence is named on any surface, and no jurisdiction coverage is claimed. Searched the home page, the platform and module pages, the security and compliance page and the plans page on 4 September 2026.

Source: Operator VerifiedAs of Sep 4, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

Nothing on any located surface addresses whether authority is checked for subsequent history. The product does not retrieve primary law: it operates on the customer's contract repository, surfacing clause-level risk, obligations and commercial exposure rather than case law or statute. The question therefore does not bite on this product class, and the honest value is the absence rather than a penalty. Searched the home page, the platform and module pages, the security and compliance page and the plans page on 4 September 2026.

Source: Operator VerifiedAs of Sep 4, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

No located public material addresses what the product does when it cannot ground an answer. The Ensemble LLM architecture is described as a cross-validating chain of specialised agents ensuring well-grounded and cited results, which is a quality control rather than an abstention path, and no confidence score, grounding score or no-answer behaviour is described as visible to the user. Hallucination is not named anywhere on the reachable surfaces, including in the AI safeguards answer, which addresses adversarial attack rather than model error. Searched the home page, the platform and module pages, the security and compliance page and the plans page on 4 September 2026.

Source: Operator VerifiedAs of Sep 4, 2026

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

The AI Hallucination Cases database maintained by Damien Charlotin was searched on 4 September 2026 on the product and company name Malbek. No court order, opinion or disciplinary record naming the product was located. This records the state of the public record on that date and is not a finding about the product.

Source: Operator VerifiedAs of Sep 4, 2026Evidence
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No located public material engages with bar or ethics guidance. The ethics answer on the security and compliance page describes corporate conduct policies covering anti-slavery, anti-bribery, anti-discrimination and sustainability, which are business ethics rather than professional responsibility, and no bar association, regulator, ethics opinion or professional code is named on any surface. The buyer is a corporate department rather than a regulated practitioner, which explains the absence without changing it. Searched the home page, the platform and module pages, the security and compliance page and the plans page on 4 September 2026.

Source: Operator VerifiedAs of Sep 4, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure.

Public materials claim savings without addressing billing or disclosure. A featured customer states that approximately 80 per cent of templates no longer require legal review, another that the money spent on the system came back tenfold, and the by-the-numbers panel claims 91 per cent say Malbek enables and enhances productivity. Nothing addresses what happens to a bill when AI-assisted work compresses the time it takes, and no per-matter record of AI-assisted work is described. The buyer here is an in-house department rather than a firm billing a client, which is the inverse of the direction this signal assumes.

Source: Vendor PublishedAs of Sep 4, 2026

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Subprocessors listed

A current subprocessor or model provider list is published.

A model provider statement is published openly on the security and compliance page, naming AWS Bedrock and Azure as the routes to foundation models alongside Malbek's own proprietary models, together with a statement that inputs, outputs and embeddings are never accessible to the LLM vendor. That answers which providers stand behind the AI without a sales conversation. What is not openly published is a forwardable pack: the formal subprocessor register sits inside the Vanta-hosted trust centre at trust.malbek.io, which returned page metadata with no body on 4 September 2026, no data processing agreement was located at any access tier, and the disaster recovery policy is stated to be available under NDA.

Source: Vendor PublishedAs of Sep 4, 2026

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Not addressed

No located public material addresses court disclosure or verification certification.

No located public material addresses court disclosure or verification certification. No audit trail or activity export is described on any reachable surface, the model used for a given output is not disclosed to the customer, and no record of human verification is mentioned. The platform is a contract lifecycle system for corporate contracting rather than a litigation product, so the question bites weakly, but nothing published answers it. Searched the home page, the platform and module pages, the security and compliance page and the plans page on 4 September 2026.

Source: Operator VerifiedAs of Sep 4, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 4, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746