P
PostSig

PostSig is a post-signature contract performance platform from PostSig, Inc. of San Francisco, used mostly by market data, finance, procurement, legal and compliance teams at hedge funds, asset managers, banks and investment firms. Its LineageAI engine reads agreements together with their amendments, service orders, side letters, invoices and approvals to work out which terms govern now, and answers business questions such as whether an invoice matches the agreed price, when a renewal or cancel-by date falls, what obligations and audit rights apply, and whether vendor data may be used in AI workflows, with each answer linked to its source documents.

The platform also keeps an inventory of licences and usage, tracks spend and renewals, imports signed agreements from DocuSign, and offers a governed MCP connection for enterprise AI assistants. A separate Investor Rights Intelligence product tracks investor rights and obligations. Pricing is not published.

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The models drive the core task inside a platform that would still work without them. LineageAI reads agreements with their amendments, service orders, invoices and approvals to decide which terms govern and answers business questions from them. The inventory, spend and renewal tracking, dashboards, reports and document workspace would still run as a contract and spend system without the models. Verified 22 September 2026.

Source: Vendor Published
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Answers are linked to their sources; accuracy is not measured. The site says every conclusion links back to the agreements, records and provisions behind it, so a user can open the customer's own documents to check an answer. No accuracy rate, test or evaluation is published, and the Terms of Service warn that AI output may be inaccurate and must be validated by the customer before any use. The product does not cite legal authority. Verified 22 September 2026.

Source: Vendor Published
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Oversight is asserted rather than built out. The legal-teams page says PostSig gives business users source-backed answers so legal can focus on standards and exceptions, and that it does not replace legal review; the MCP page says each request from an approved AI client is checked for user, data set, scope and policy. The design sends routine contract questions to business users without a lawyer, and no review step, threshold or limit on what answers may be used for is described; the terms put validation of output on the customer. Verified 22 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Named customers without measured results. The home page quotes Sheena Clark of UNA Data Group, Gary Glasser of Birch Hill Equity Partners and Chris Petrescu of CP Capital, alongside investor endorsements. Its headline figures, more than $1 billion of economic value governed, 3.2 million business records connected and 50,000 rights and obligations tracked, describe platform scale rather than customer outcomes. Verified 22 September 2026.

Source: Vendor Published
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Confidentiality is addressed in the agreement, alongside a right to train on de-identified data. The Terms of Service bind both parties to confidentiality and require advance notice, where the law permits, before customer data is disclosed under a subpoena or court order; the security page says content is accessible only to authorised users and logically isolated between customers. The same terms let PostSig create aggregated data from customer data, defined as de-identified or aggregated so it no longer reasonably identifies the customer or an individual, and use it to train, develop or enhance its AI models or other large language models, with no opt-out located, while the home page says there is no training on customer data.

Which AI providers process customer data, how long it is kept after termination beyond a discretionary 30-day window, and privilege are not addressed. Verified 22 September 2026.

Source: Vendor Published
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

A boilerplate disclaimer against advice-shaped marketing. The Terms of Service say AI output is not to be relied on as a source of fact or a substitute for professional advice, and the legal-teams page says PostSig does not replace legal review. The legal solution page, however, sells automatic legal translations into lay terms and a reduction in the legal guidance lawyers give other teams, so that business users answer contract questions themselves. Who reviews those answers is not addressed. Verified 22 September 2026.

Source: Vendor Published
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Checked the home, about, legal solution, legal-teams, security and MCP pages, the Terms of Service and the Privacy Policy on 22 September 2026. No AI governance framework, accountable owner, testing before release, or finding on how answers perform across contract types or document sets was located. Verified 22 September 2026.

Source: Operator Verified
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Security controls are described in general terms; retention, deletion and subprocessors are not committed. The security page says content is accessible only to authorised users, logically isolated between customers, securely stored and monitored, with defined incident procedures and a Data Processing Addendum on request; the home page adds audit logs, encryption and penetration testing. The Terms of Service let PostSig delete customer data at its discretion from 30 days after termination, with no obligation to delete, and backups may be kept. No subprocessor list or incident notification timeframe was located. Verified 22 September 2026.

Source: Vendor Published
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

A standard limitation clause, and no indemnity from PostSig. The Terms of Service cap liability at the fees paid in the prior twelve months, exclude indirect damages, and warrant only that the service performs materially as documented. Use of any AI output is at the customer's sole risk, and the only indemnity runs from the customer to PostSig. Verified 22 September 2026.

Source: Vendor Published
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Named connections, some with the flow described. A DocuSign integration imports signed agreements into PostSig in one step, and PostSig MCP gives approved AI clients such as Claude Enterprise and ChatGPT Enterprise access to its answers after checking user, data set, scope and policy. ERP and accounts-payable data are referred to as inputs. What syncs in each direction and how connections are configured is not documented. Verified 22 September 2026.

Source: Vendor Published
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Residency is offered without a region. The home page says sensitive records can be kept in the right region and jurisdiction, and the security page says customer environments are logically isolated. No region, hosting provider, processing location or deployment option other than the hosted service is named. Verified 22 September 2026.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

A named attestation and auditor, report under NDA. The security page says PostSig is SOC 2 Type II compliant, that the audit was conducted by Prescient Assurance, and that the report and detailed security controls are available to customers under NDA on request. No report period is published. Verified 22 September 2026.

Source: Vendor Published
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

A named engine, with nothing said about what sits underneath. The site presents LineageAI as its cross-document intelligence, and the Terms of Service say aspects of the service rely on AI models. No model, model provider, inference location or change notification is published. Verified 22 September 2026.

Source: Vendor Published
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Checked the home, CPM, inventory and legal pages and the Terms of Service on 22 September 2026. No price, unit or tier is published; the terms say fees are set in each order and describe only payment mechanics, in US dollars, due in 30 days, non-refundable and with a 1.5% monthly late charge. Verified 22 September 2026.

Source: Operator Verified
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Buyers and use cases are named, short of limits. The site addresses market data, finance, procurement, legal, and risk and compliance teams at hedge funds, asset managers, banks, venture and private equity firms, family offices and data vendors, with use cases such as invoice reconciliation, renewals, usage and entitlements, DORA evidence and investor rights. The contract types and markets it does not handle are not stated. Verified 22 September 2026.

Source: Vendor Published
Sources on file

4 public documents

The public pages on file for PostSig, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Permitted, in the contract

The published agreement expressly reserves a right to train on customer content, with no opt out located. Any de identification, anonymisation or aggregation qualifier is recorded in the summary.

The Terms of Service let PostSig create aggregated data from customer data, defined as customer data de-identified or aggregated so that it no longer reasonably identifies the customer or an individual, and use that data and usage data to train, develop or enhance its AI models or other large language models. No opt-out was located. The home page says there is no training on customer data; the published terms say otherwise for de-identified or aggregated data.

Source: Vendor Publishedto train, develop, or enhance Vendor’s AI models or any other large language modelsAs of Sep 22, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Disclosed without a period

Retention is acknowledged in public materials with no stated period.

The Terms of Service let a customer request an export on termination and say that, from 30 days after the agreement ends, PostSig has no obligation to keep customer data and may delete it at its discretion; backups may be kept. The Privacy Policy keeps personal information as long as necessary. No retention period for questions asked or answers generated is stated.

Source: Vendor Publishedmay delete the applicable Customer Data at any time in its sole discretionAs of Sep 22, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Claimed, not documented

Segregation is asserted in public materials with no published detail on how it is enforced.

The home page says access respects existing controls, the security page says content is accessible only to authorised users and logically isolated between customers, and the MCP page says each AI request is checked for user, data set, scope and policy. How permissions are set within a customer, or whether they are taken from a source system, is not described.

Source: Vendor PublishedAccess respects existing controls.As of Sep 22, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Notice committed

Terms commit to notice where lawfully permitted. No transparency report located.

The Terms of Service allow either party to disclose customer data or other confidential information if required by law, subpoena or court order, provided that, where the law permits, it notifies the other party in advance and cooperates in seeking confidential treatment. No transparency report was located.

Source: Vendor Publishednotifies the other party in advanceAs of Sep 22, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Not addressed

No located public material identifies the corpus behind the product’s answers.

Checked the home, legal solution, legal-teams and CPM pages on 22 September 2026. The product works on each customer's own agreements, invoices and records; no body of law behind its answers is identified.

Source: Operator VerifiedAs of Sep 22, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

Checked the home, legal solution, legal-teams and CPM pages on 22 September 2026. The product does not cite legal authority, and nothing addresses checking authority for later treatment.

Source: Operator VerifiedAs of Sep 22, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

Checked the home, legal-teams, CPM and MCP pages on 22 September 2026. Nothing describes what the product does when the documents do not answer a question or when governing terms conflict.

Source: Operator VerifiedAs of Sep 22, 2026

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

None located

No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.

Searched the AI Hallucination Cases database maintained by Damien Charlotin on 22 September 2026 for PostSig, and no recorded case was returned. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product.

Source: Bar Guidance or Court RecordAs of Sep 22, 2026Evidence
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

Checked the home, legal solution, legal-teams and security pages, the Terms of Service and the Privacy Policy on 22 September 2026. No material engages with lawyers' professional or ethical obligations or names any ethics opinion.

Source: Operator VerifiedAs of Sep 22, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Outside the fee relationship

The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.

The product is bought by companies to manage their own vendor and investment agreements, with in-house legal teams among the users, so it does not sit between a lawyer and a billed client.

Source: Vendor PublishedAs of Sep 22, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Not addressed

No located public material supports a client side disclosure obligation.

Checked the security and legal pages and the Terms of Service on 22 September 2026. The SOC 2 report and a Data Processing Addendum are available on request; no subprocessor or model provider list and no client-facing disclosure material was located.

Source: Operator VerifiedAs of Sep 22, 2026

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Not addressed

No located public material addresses court disclosure or verification certification.

Checked the home, legal-teams, security and MCP pages on 22 September 2026. The site mentions audit logs across workflows, but nothing addresses recording or disclosing AI use in material put before a court.

Source: Operator VerifiedAs of Sep 22, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 22, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746