Onspring
No code governance, risk and compliance platform used to build and run GRC programs without developer involvement, spanning risk management, regulatory change management, internal audit, policy management and authoring, control and framework mapping, third party and vendor risk, IT risk, ESG assessment, and business continuity and recovery. Business users configure applications, workflows, surveys, dashboards and reports through the interface rather than through code. Governance frameworks including ISO, NIST and CMMC are supported and mapped to controls. Onspring publishes a separate Corporate Counsel solution for in house legal departments covering legal request intake, matter and task tracking, legal opinions and research, a clause library holding liability, confidentiality, agreement and property management clauses that can be reused across contracts, relation of contracts, policies and clauses to business units and regulations, scheduled recurring review of regulations and clauses, and legal cost and budget tracking. The AI layer is Onspring AI, launched October 2025 as an optional add on module and extended in July 2026 into agentic operation. It is powered by Anthropic's Claude family of models and operates under the oversight of an internal AI governance council. Capabilities include generating and revising long form field content, predictive thought completion, record creation from prompts, surfacing relevant links between controls, employee roles and regulatory requirements, duplicate record detection, and reading and summarising documents such as SOC 2 reports to populate fields. The July 2026 release allows administrators to define rules that prompt agent action, with an assistant present on every screen that can answer from any record or application inside the customer's GRC program, bounded by administrator set limits. Named customers include American Family Insurance, Warner Bros. Discovery and Memorial Hermann Health System. Integrations named include DocuSign, Microsoft 365, Google Drive and Slack, alongside the Onspring API. Maintains an annual SOC 2 Type II attestation.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The clearest case on the index of AI as an addition rather than a foundation, and the vendor says so itself. Onspring is a no code GRC platform that existed and sold for years before any AI shipped. Onspring AI launched October 2025 as an optional add on module that customers enable and configure, extended July 2026 into agentic operation. The vendor's own framing is that customers have total control over when and how it is used, which is a sound commercial position and also an admission that the product works without it. Removing the model layer removes an efficiency layer over data entry, documentation drafting, duplicate detection and record linking, and leaves the entire platform standing. Graded below Everlaw and Relativity at B, where the model layer is bundled into the core product rather than licensed separately. The AI is real, shipped, documented and dated, which is why this is C and not lower. The brief flagged this vendor to check the AI bar and it clears it comfortably; centrality is a different question from existence.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Nothing published. Onspring AI generates and revises long form content, creates records from prompts, completes text predictively, and reads and summarises uploaded documents such as SOC 2 reports to populate fields. Every one of those is a generation task where a wrong output lands in a compliance record, and none carries a published grounding claim, source citation behaviour, accuracy figure, precision or recall measure for duplicate detection or field extraction, hallucination rate, evaluation, or statement of what the assistant does when it has no answer. Searched the Onspring AI announcements of October 2025 and July 2026, the regulatory change management product page, the security page, the platform pages and the corporate counsel solution page on 29 Aug 2026. The gap is sharper here than the grade alone conveys: the assistant is documented as able to answer from every record and application in a customer's GRC program, and nothing states how those answers are grounded in the underlying records.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The strongest autonomy disclosure located in this category, and the only one on the index where the boundary is a configurable customer artifact rather than a vendor assurance. The July 2026 release is explicit that administrators define the rules that prompt agent action, that automation operates within the boundaries set by the system administrator, and that the design intent is a governed assistant that keeps users in control. The module is opt in and configurable to organisational standards, and an internal AI governance council is named as the oversight body. That gives a buyer three separate levers a compliance function can actually evidence to an examiner: whether the module is on, what rules trigger action, and who governs it. Held at B because none of the mechanics are published. No rule syntax, no scope limits, no statement of what an agent may never do, no escalation or human confirmation behaviour, and no description of what the audit trail captures when an agent rather than a person acts. Better positioned than Regology and Norm Ai, both of which describe oversight without a customer set boundary.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Customers are named, which most of this category does not do. American Family Insurance for IT risk and GRC program management, Warner Bros. Discovery for GRC management, Memorial Hermann Health System for audit, and Northgate Resorts with a stated saving of 200 compliance hours from a single integration. The vendor also publishes an annual GRC Benchmarking Report carrying survey findings, including that 70 percent of GRC practitioners see simplifying repeatable administrative work as the largest AI opportunity, which is industry research rather than product evidence but is dated and attributable. Held at B rather than A because the named customers are described at use case level without published outcome methodology, the 200 hours figure carries no baseline or period, and none of the named accounts is a legal department, so the evidence supports the GRC product rather than the corporate counsel solution this index is grading it for.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
General confidentiality is claimed and evidenced; legal specific confidentiality is not addressed at all. The vendor publishes a SOC 2 Type II attestation covering security, availability and confidentiality, and states that information privacy, security and risk management policies are documented with defined roles, responsibilities, policies and procedures protecting stored data. That is a real confidentiality position for a platform generally. What does not exist: any treatment of legal privilege or attorney work product, any statement about the confidentiality of matter records held in the Corporate Counsel solution, and any acknowledgement that a legal department's records on the platform differ in kind from an IT risk register. Checked the security page, the corporate counsel solution page, the platform pages and the AI announcements on 29 Aug 2026. This matters more than usual here because the same platform holds both the legal department's matters and the business units those matters concern.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Not addressed. The Corporate Counsel solution holds legal opinions, legal research and a clause library whose clauses are automatically selected by contract type, and Onspring AI can generate and revise long form field content across the platform. Generated or auto selected contract language reaching a business user without a lawyer in the path is the shape this axis exists to examine, and nothing addresses it. No statement that output is not legal advice, no positioning on the role of the reviewing lawyer, no professional responsibility material of any kind. Checked the corporate counsel solution page, the AI announcements, the platform pages and the resource material on 29 Aug 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A governance body is named and nothing it produces is published. Onspring AI is stated to operate under the oversight of the company's AI governance council, and the module is configurable by customers against their own organisational standards and compliance requirements. Naming an internal governance body at all puts this ahead of most of the roster, where governance disclosure covers security rather than model behaviour. What is missing is everything the council would produce: no AI policy, no model evaluation, no bias testing or fairness assessment, no accuracy monitoring, no drift or regression statement, no model card, no ISO 42001, and no description of what the council reviews or when. A named committee with no published output is a claim rather than evidence, which is the definition of this band. Checked the October 2025 and July 2026 announcements, the security page and the platform pages on 29 Aug 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Platform stewardship is evidenced and AI specific stewardship is not. The SOC 2 Type II attestation covers security, availability and confidentiality, documented privacy, security and risk management policies are stated, and SecurityScorecard is cited as awarding a 100 out of 100 score. Nothing addresses what happens to customer content once it passes into the AI layer: no statement on whether customer records, policies or uploaded documents are used to train or improve any model, no retention position for prompts or generated output, and no description of how data flows to the model provider and back. That last gap is notable because the provider is named, so the vendor has already disclosed the harder fact and stopped short of the easier one. Checked the security page, both AI announcements and the platform pages on 29 Aug 2026. Security certification is graded separately and is not double counted here.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
No published position. Nothing was located on liability for AI output, indemnity, warranty, service levels, or remedy where a generated field value, an auto populated record or an agent action is wrong. The agentic release makes this a live question rather than a theoretical one, since an agent acting on administrator defined rules can write to compliance records that an examiner later reads. The vendor's answer to that risk is architectural, in the form of administrator boundaries and opt in configuration, rather than contractual, and no contractual position is public. Checked the July 2026 agentic announcement, the October 2025 launch announcement, the security page, the platform pages and the site footer on 29 Aug 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integrations are named rather than gestured at, and an open API is documented as the extension path. Named: DocuSign, Microsoft 365, Google Drive and Slack, with the vendor stating that further systems connect through the Onspring API. A published customer account credits a single integration with saving 200 compliance hours, which is integration evidence rather than an integration list. Held at B, and the reason matters for a legal index: not one named integration is a legal practice system. No iManage, no NetDocuments, no SharePoint matter workspace, no e-billing or matter management connector, and nothing that would let the Corporate Counsel solution sit inside a legal department's existing document estate. The integrations are the business software a GRC platform needs. Compare Regology at B for naming ServiceNow, Archer and Hyperproof, which is the same shape: real named integrations aimed at the adjacent stack rather than the legal one.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Nothing located from the vendor. Third party software directories describe the platform as cloud deployment supporting Windows and macOS with no mobile application, and that is directory material rather than vendor disclosure, so it is recorded here as context and not credited. From Onspring's own pages, located nothing on hosting provider, region, data residency commitment, single tenant or dedicated instance options, or where customer data is processed and stored. Checked the security page, the platform pages, the corporate counsel solution page and the site footer on 29 Aug 2026. Research limitation stated rather than hidden: the security page was reached through search result content rather than a full page render, so a residency statement lower on that page would not have been seen. Flagged as a correction candidate on that basis.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
A named attestation with its scope stated and its currency addressed, published on the vendor's own security page. Onspring states an annual SOC 2 Type II attestation prepared in accordance with AICPA standards, and names the trust services criteria covered as security, availability and confidentiality. Naming which criteria are in scope is the detail most vendors omit and it is the difference between a claim and a checkable one, since a SOC 2 covering security alone is a materially narrower report. Annual renewal addresses currency. Also cited: a SecurityScorecard rating of 100 out of 100, which is an external scanner score rather than an audit and is treated as supporting rather than load bearing. Held at B on three gaps: the auditing firm is not named, the examination period is not stated, and no trust centre or self serve request route for the report was located, so under the three tier test the artifact itself is sales gated. Consistent with Regology at B, which names its auditor but not its currency; Onspring names its currency and scope but not its auditor.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The best model supply chain disclosure located in this pull, and the first record to name its provider outright. Onspring states in dated public announcements that Onspring AI is powered by Anthropic's Claude family of generative AI models, repeated across the October 2025 launch and the July 2026 agentic release and carried in independent trade coverage of both. Naming the provider is the single fact a regulated buyer's own supervisor is most likely to ask for, and it is the fact almost every vendor on this index withholds. Held at B rather than A because the disclosure stops at the family name. No specific model or version is identified, no subprocessor list exists, nothing states whether the provider is engaged through an enterprise agreement or what contractual terms govern data sent to it, no data flow description is published, and no statement addresses what happens if the provider is changed. A buyer knows who, and nothing else.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The pricing structure is discoverable and no figure is. Subscription pricing is structured by number of users and by modules selected, with annual and multi year licensing options, additional modules incurring incremental cost, and implementation services included with the GRC Suite under some licensing models. Onspring AI is separately licensed as an add on. Knowing that price scales on seats and modules, and that the AI costs extra, tells a buyer how the bill will grow, which is more than most of this roster discloses. Held at C because no price, range or entry point is published at any level, every route is a quote request, and the vendor's own licensing model is described by third parties as complex, which is a signal in itself. Source basis recorded as Third Party Estimated rather than Vendor Published: the structural detail comes from an independent review platform's product summary, not from an Onspring pricing page, and no vendor pricing page was located on 29 Aug 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is broad across compliance domains and thin across legal ones. Governance frameworks are named at ISO, NIST and CMMC, and the platform spans risk, audit, vendor and third party risk, IT risk, policy, ESG, and business continuity, with named deployments across insurance, media and healthcare. Legal coverage is a single Corporate Counsel solution positioned within business operations, describing matter tracking, requests, opinions, research, a clause library and cost tracking. That is one in house legal use case, not practice coverage: nothing addresses practice areas, jurisdictions, matter types beyond the generic, or any distinction between a legal department's work and the adjacent compliance work the platform was built for. Held at C because the legal offering is real and documented but shallow relative to the platform around it, and because the corporate counsel material carries no visible recent update while the GRC and AI material is refreshed continuously.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way.
Terms are silent. The security page describes what the SOC 2 attestation validates, quoted here, and that scope is about safeguarding data rather than about model training. No statement was located anywhere addressing whether customer records, uploaded documents or prompts are used to train or improve any model, in either direction. The gap is pointed because the vendor already names Anthropic's Claude as the model provider, so it has disclosed the harder fact and left the simpler one unanswered. Checked the security page, the October 2025 and July 2026 AI announcements, the platform pages and the site footer on 29 Aug 2026. Recorded as silent, not as a negative commitment.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
Not addressed. No retention period is published for prompts, assistant conversations, generated field content or agent actions, and nothing indicates whether retention is configurable or can be set to zero. The platform is explicitly a system of record that retains GRC data by design, but that is record retention rather than AI interaction retention, and the two are not the same question. Nothing states whether an administrator can see or purge what users asked the assistant. Checked the security page, both AI announcements and the platform pages on 29 Aug 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Segregation is asserted in public materials with no published detail on how it is enforced.
Claimed and not documented, and the AI release raises the stakes on it. The vendor states clearly defined roles, responsibilities, policies and procedures protecting stored data, so an access model exists and is asserted. Nothing documents its granularity or whether it constrains the AI layer: the July 2026 assistant is described as living on every screen and answering from every record and application in the GRC program, and no published statement says those answers respect the asking user's record permissions. For a platform holding both a legal department's matters and the business units those matters concern, that is the segregation question, and it is unanswered. No document management system exists to inherit permissions from, so the second model shape is the only applicable one. Checked the security page and both AI announcements on 29 Aug 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located term or policy addresses third party requests for customer data.
Not addressed. No government or law enforcement request clause, no commitment to notify a customer before producing their data, and no transparency report were located. Checked the security page, the platform pages and the site footer on 29 Aug 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
Not addressed, and largely not applicable in the usual sense. This product has no primary law corpus: the AI operates over the customer's own GRC records, policies, controls and uploaded documents rather than over published legislation or case law. The one adjacent disclosure is that governance frameworks including ISO, NIST and CMMC are supported and mapped to controls, which names standards bodies rather than a regulatory corpus with sources, jurisdictions and update lag. Regulatory change management is sold as a module, and nothing published names which regulatory sources feed it, which jurisdictions are covered, how current the feed is, or on what licence basis any of it is obtained. That last part is a real gap rather than an inapplicable one. Checked the regulatory change management product page and the platform pages on 29 Aug 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Not addressed. The regulatory change management module monitors regulatory changes and aligns controls with evolving requirements, and Onspring AI can surface related regulatory controls and suggest which analyst to assign a new control to. That is change routing rather than a currency signal: nothing indicates whether the product flags that a regulation a control relies on has been superseded, withdrawn or amended, and no citator or treatment source is named. Checked the regulatory change management page, both AI announcements and the platform pages on 29 Aug 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Not addressed. No explicit no answer path, abstention behaviour, confidence score or uncertainty signal is documented for either the assistant or the agentic features. The July 2026 release describes an assistant making contextualised decisions across workflows and answering from every record in the program, and says nothing about what it does when the records do not support an answer. The published control is the administrator defined boundary on what an agent may act on, which limits scope rather than describing behaviour under uncertainty. Checked both AI announcements, the platform pages and the security page on 29 Aug 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
None located, with the instrument stated so the finding is worth what the search is worth. General web searches combining the vendor and product names with court, opinion, sanction, enforcement and disciplinary terms returned nothing on 29 Aug 2026. No named docket database or court record tracker was searched for this record. Exposure shape is low relative to a research or drafting product: the AI generates internal compliance documentation and populates records rather than producing citations to authority for filing. Recorded as a statement about what was found, not as a clearance.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
Not addressed. No named ethics opinion, no ABA Formal Opinion 512, no state bar guidance and no engagement with professional responsibility material of any kind was located, including on the Corporate Counsel solution page where it would be most expected. The vendor publishes extensively on compliance obligations owed by its customers' organisations and nothing on the professional duties of lawyers using the legal solution. Checked the corporate counsel solution page, the resource and report material, both AI announcements and the platform pages on 29 Aug 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Savings claims only. Published customer material states 200 compliance hours saved from a single integration, and the AI positioning rests on reducing repetitive administrative work, supported by a benchmarking finding that 70 percent of GRC practitioners see simplifying repeatable administrative work as the biggest AI opportunity. All of that describes the customer's internal time. Nothing appears on the client's side of the equation: the Corporate Counsel solution tracks legal costs and budgets as a feature, and no position is published on billing for AI assisted time or on producing a record a department could disclose. Checked the corporate counsel solution page, the customer stories and both AI announcements on 29 Aug 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
Not addressed, with one genuine component present that the value set cannot express. The model provider is named outright, Anthropic's Claude family, in dated announcements, which is the single hardest element of such a pack and one almost no vendor on this index publishes. Everything around it is missing: no subprocessor list, no data processing agreement, no trust centre, and no self serve route to the SOC 2 report, which is stated to exist but is not reachable without a sales conversation. A department could forward the model provider name and nothing else. Recorded as not addressed because no forwardable disclosure pack or request route exists, with the model provider disclosure noted here so it is not lost. Checked the security page, both AI announcements, the platform pages and the site footer on 29 Aug 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Partial record. The platform is built to evidence compliance to auditors and examiners: control authoring, attestations and documentation, evidence capture, task tracking with automated notifications, real time reporting, and framework to control mapping across ISO, NIST and CMMC. A customer can produce what was required, who was assigned, what was done and when. The AI dimension is where it stops short. Nothing indicates that a record carries which fields were AI generated, which model produced them, what sources the assistant drew on, or whether a human confirmed the output before it was saved. With agentic action now writing into records under administrator rules, the distinction between a human entry and an agent entry is exactly what an examiner would probe, and no published export or audit view addresses it. Checked both AI announcements, the regulatory change management page and the platform pages on 29 Aug 2026.