Sandstone
Sandstone is an AI platform for in-house legal departments built around the intake, routing and execution of legal requests. Requests arrive from Slack, email, Jira, ServiceNow and the other systems the business already uses, and agents read the intent, gather counterparty history and route work to the lawyer with the right expertise and capacity. A repository holds documents, companies, people and past decisions, and playbooks built from a team's own templates, redlines and policies learn with each use so negotiating positions stay consistent across the organisation. Agentic workflows redline, draft and reply to comments, completing simpler work and handing more complex matters to a lawyer, while reporting aggregates cycle times, risk exposure, capacity and deviation rates. The product works through a Microsoft Word add-in, a Google Workspace add-on and a stated fifty or more integrations including Salesforce, Ironclad, SharePoint, Coupa and Workday. Sandstone publishes its platform terms of service, data processing agreement, security policy and privacy policy in full, and states SOC 2 Type 2 certification and zero data retention agreements with its model providers. Named customers include Middesk, MasterClass, Crexi, Ocrolus and Hypertherm. Sandstone is the trading name of Glaze AI, Inc.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of the capabilities the buyer is sold on: agents that read the intent of an incoming request and route it, playbooks that learn from a team's own redlines and policies with each use, and agentic workflows that redline, draft and reply to comments. Underneath sits a product that would still function without them. The repository of documents, companies, people and past decisions, the matter and task tracking, the intake channels and the reporting on cycle times and capacity are a legal operations system, and the vendor describes the platform in exactly those terms as a single system of record and an operating layer. That is the B band: models as the engine of a core capability, layered on a workflow system that stands without them. Verified 2 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is claimed and never described or measured. Multi-Source Citations is listed as a capability of the agentic workflow surface, alongside redlining and drafting from best practices, and the platform's whole premise is that output is grounded in the organisation's own precedent rather than a general model. Nothing published goes further. No retrieval method is described, no accuracy figure appears on any surface, no test set or evaluation is published, and no statement addresses hallucination. The one place the subject surfaces is a customer story, which describes redlines previously drafted with general-purpose tools that hallucinated Word output, framing the problem as belonging to the tools Sandstone replaced rather than disclosing anything about its own rate. Checked the home page, customers page, security page, security policy, terms of service and privacy policy on 2 September 2026. Verified 2 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The handoff rule is stated more plainly than by any other record in this pull: agents complete simple legal work and hand off complex tasks to lawyers. That is a real division of labour rather than a phrase, and it is supported by described review surfaces, with redlines landing as accept and reject changes and routing sending work to a named owner. Clause 1 of the terms of service adds a written control statement, that these are self-help services provided at the customer's specific direction. What is missing is the boundary itself. Nothing published defines what makes work simple rather than complex, no threshold or confidence condition is described, and nothing states what happens after an agent is wrong. The Google Workspace add-on's published permissions include sending mail on the user's behalf, so agents can act outbound, and no oversight condition is published for that. Verified 2 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Five customers are named with substantive case studies rather than logos: Middesk, a business identity platform with a single in-house counsel; MasterClass, whose General Counsel Kevin Yung is named; Crexi; Ocrolus; and Hypertherm, a global manufacturer. Each story describes the starting position, the specific problem and what the platform was deployed to do, which is real deployment evidence with substance. Two things hold it below A. Not one figure appears anywhere across the five, so nothing is measured, and there are no dates. Several are written in the present progressive, describing what a customer is consolidating or is working to eliminate rather than what it achieved, which reads as deployment in progress. A named customer without figures is the B band exactly. Verified 2 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive and published in the agreement rather than only in marketing. Clause 9.4 of the terms of service commits Sandstone to be able to identify any of the customer's data separately from any other data under its control, and clause 10 imposes mutual confidentiality obligations surviving five years past termination. The security page states plainly that Sandstone does not train models on customer data and that its model providers operate under zero data retention agreements so they do not retain prompts or outputs, which settles the third party model provider limb. Retention is customer-set and export is available. What fails is the privilege limb the top band requires as its own. The privacy policy expressly names Legal Advice and Attorney-Client Privileged Content as a category of sensitive information it processes, including internal legal memos and drafts marked privileged, and then commits to nothing specific about how privileged material is handled. Clause 1 of the terms disclaims an attorney-client relationship with Sandstone, which is a different question. Naming privileged content as an input without addressing its treatment is what holds this at B. Verified 2 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The advice line is addressed head on in the operative agreement, not in a footer. Clause 1 of the terms of service states that Sandstone provides self-help services at the customer's specific direction, that it is not a law firm or a substitute for an attorney, that outputs do not constitute legal advice, that a licensed attorney should be consulted to evaluate accuracy or applicability, and that use does not create an attorney-client relationship. The same clause defines the customer as a user whether a lawyer or a business user of a shared workspace, which faces the fact that non-lawyers operate the product rather than leaving the audience ambiguous. That combination is more than most records in this pull publish. Two limbs of the top band fail: no jurisdiction limits are stated anywhere, and nothing addresses the supervision and competence duties of the lawyers who sign off on the work. No bar or ethics guidance is engaged. Verified 2 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Nothing published addresses governance over model behaviour. No responsible AI page exists, no governance framework, no certification such as ISO 42001, no named owner, no account of what is tested before a model or workflow ships, and nothing whatsoever on uneven output across matter types, counterparties or populations. What exists nearby belongs to other subjects: SOC 2 Type 2 and penetration testing are security, and the zero data retention arrangement with model providers is data protection. Checked the home page, security page, security policy, terms of service, privacy policy, legal centre, customers page and careers material on 2 September 2026. One retrieval limit is recorded rather than held against the vendor: the Vanta-hosted trust centre at trust.sandstone.com renders client side and returned no body, and its own description claims advanced protections for agentic offerings without naming any. Nothing in it is credited or graded, and this D rests on the eight readable surfaces. Verified 2 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Four of the five elements are published with specifics. Retention is customer-controlled, stated as you set retention with export available, and the FAQ is candid that Sandstone still stores what the customer puts in the product to run the service. Encryption is AES-256 at rest and TLS 1.3 in transit. Access control covers SAML single sign-on, role-based permissions, audit logs, session management and user lifecycle management. Incident practice is real: an in-house security team with monitoring and incident response running around the clock, plus a published vulnerability disclosure policy committing to acknowledge a report within 72 hours, provide updates, notify on resolution and offer safe harbour for good-faith research. Clause 9.5 of the terms goes further than most on supply chain governance, requiring the customer's prior written permission before any subcontractor processes its data, with written notice of purpose and due diligence. The gap is the one the B band names: no subprocessor list is published anywhere. Verified 2 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A complete published position, and what it allocates to the customer is everything. Clause 14 gives real service warranties: enough trained personnel, reasonable efforts consistent with prevailing industry standards, provision in accordance with applicable laws, and no intentional introduction of malicious software. Clause 15 then disclaims all other warranties, states that the customer uses the services at its own risk, and records that Sandstone has no duty regarding how the customer interprets or uses the content. Clause 16.2 runs an indemnity from the customer to Sandstone, and no indemnity runs the other way beyond the mutual confidentiality indemnity at clause 10.4. Clause 17.1 then excludes direct damages altogether rather than capping them, so the warranties at clause 14 carry no monetary remedy. No cap figure and no insurance commitment appear. This is B rather than A because nothing here is a recourse a buyer can invoke when output is wrong, and B rather than C because the position is far more than a boilerplate limitation clause. Verified 2 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Reach is broad and depth is not described. Twenty integrations are named with logos across the systems in-house legal work actually crosses, including Microsoft Word, Outlook, Teams and SharePoint, Google Docs and Drive, Slack, Salesforce, Jira, Asana, ServiceNow, Zendesk, HubSpot, Workday, Coupa, Notion, Box, Dropbox, OneDrive, Zip and Ironclad, against a claim of over fifty. Ironclad matters because it is a contract lifecycle system rather than a general business tool. A Google Workspace add-on is published on the Marketplace with its permission scopes enumerated, which is a verifiable artifact. What is absent is what the band asks for beyond names: nothing states what synchronises, in which direction, on what trigger, or what a customer configures, and no developer documentation, API reference or implementation guide was located. Named connections without a description of what they move is the B band. Verified 2 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery is implied throughout and neither of the two limbs this axis asks for is stated. No region or residency option is published anywhere, and the agreement points away from one: clause 9.6 provides that the customer's data will remain wherever Sandstone places it initially, and the customer consents to transfer to group companies, service providers or agents who may be located in other countries. The privacy policy adds that data may be stored in a foreign country whose laws protecting personal information may be less stringent than those where it was collected. No tenancy model is stated: nothing describes the platform as multi-tenant, single-tenant or privately deployed. Network isolation is named on the security page as a control, which describes segmentation rather than tenancy or residency. Under the co-equal limbs rule, either tenancy or region would clear this band and neither is present. Verified 2 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
SOC 2 Type 2 is stated clearly and repeatedly on a security page written for the buyer's security reviewer, alongside annual third-party penetration tests, continuous automated scanning, internal assessments, and a security addendum described as aligned to SOC 2 Type 2 and available for counsel to review. The specifics the top band asks for are not on any public page. No auditor is named, no coverage period or report date is published, and the page states that additional independent assessments are available in the trust centre rather than listed. That trust centre, at trust.sandstone.com, is Vanta-hosted, renders client side and returned no body on 2 September 2026, so neither its contents nor its access tier could be established. That is a retrieval limit and is not graded against the vendor; equally nothing in it is credited, so the grade rests on the security page alone. Verified 2 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Sandstone refers to its model providers repeatedly and identifies none of them. The security page states that model providers operate under zero data retention agreements so they do not retain prompts or outputs, which is a meaningful commitment about what those providers may do, and it is made without ever saying who they are. No model is named, no provider is named, no subprocessor list is published, and nothing states where inference runs. The one structural commitment located runs through the agreement rather than a disclosure: clause 9.5 requires the customer's prior written permission before any subcontractor processes its data, together with written notice of the purpose and of the due diligence performed. That gives a customer a contractual route to learn who is in the chain, which is not the same as the vendor publishing it. Referring to models without identifying what sits underneath is the C band. Verified 2 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The unit and the structure are published without any figure, which is the second limb of this band. Clause 13.2 of the terms of service states that the service is offered on a subscription basis, monthly or yearly at the customer's choice. Clause 13.3 states that services may also be offered on a usage-based model, with the details provided at sign-up and changes carrying 30 days written notice. Clause 13.4 sets out automatic renewal at the then-current non-promotional rate with cancellation in the subscription management section, and 13.5 addresses free trials. A buyer can therefore learn what is being charged for and on what cadence before contacting anyone. What is absent is everything above that floor: no pricing page exists in the site navigation or footer, no tier names or feature splits are published, no figure appears anywhere, and the only commercial route on the site is Book a Demo. The structure is stated in the agreement rather than on any commercial surface, which is an unusual place for a buyer to have to find it. Verified 2 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
The buyer is described precisely by role: the product is built for General Counsel, Chief Legal Officers, associate and assistant General Counsel, practice area leads and legal operations professionals at scaling companies and enterprises. That is more specific than a segment label, and the five customer stories bear it out across a range from a company with a single in-house counsel to a global manufacturer, spanning technology, consumer media, commercial real estate, financial document automation and industrial manufacturing. What is left open is the boundary. No practice areas are enumerated, because coverage is described by workflow rather than by matter type; no company size floor is stated beyond scaling; no jurisdiction or geography appears anywhere; and nothing states what the platform does not support. Law firms are implicitly outside the scope but never named as such. Verified 2 September 2026.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
A public policy or trust page states no training on customer content, with no matching term located in the published agreement.
The commitment is stated twice on the security page, once as a control and once in the review FAQ, and it is extended outward: model providers operate under zero data retention agreements so they do not retain prompts or outputs. It sits on a policy page rather than in the agreement, which is what places it here rather than a rung higher. The published terms of service were checked for a matching term and contain none. What they do contain is clause 9.3, which provides that Sandstone owns derived data, defined as data it creates from the customer's data through aggregation, de-identification or anonymisation for its own internal purposes. That clause names neither training nor machine learning, so it does not reverse the value, but a buyer weighing the no-training promise should read it. The privacy policy adds a narrower statement scoped to the Google Workspace integration, that Google data is not used to train generalised AI or ML models.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
The customer controls the retention window, by product configuration or by contractual instruction, but zero retention is not stated as available.
Retention is under customer control and export is available, stated on the security page as a commitment. Zero retention is not available at the Sandstone layer and the vendor says so directly rather than letting the reader assume otherwise: the FAQ states that zero data retention applies to the model providers, who process a request and do not keep the prompt or output, while Sandstone still stores what the customer puts in the product in order to run the service. That distinction is unusually clearly drawn. Two things temper it. No default window is published for a customer who sets nothing, and the agreement is permissive rather than committed at the end: clause 19.3 says Sandstone may erase the customer's data on termination, and clause 20.2 makes post-termination data retrieval subject to additional fees.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Segregation is asserted in public materials with no published detail on how it is enforced.
The claim is made and never documented. The home page states that agentic workflows operate while respecting permissions across systems, which is an assertion that retrieval honours the access model of the source systems, and it matters here because the platform reaches into Slack, Salesforce, SharePoint, Google Drive, Jira, Box and others where a company's own permissions live. No published material describes how that is enforced, whether it is evaluated per user at query time, or what happens where a source system's permissions and Sandstone's own role-based permissions disagree. The agreement contributes a separability commitment at clause 9.4, that Sandstone will be able to identify the customer's data separately from any other data under its control, which addresses tenant separation rather than separation between users or matters inside one customer. Role-based permissions and SAML single sign-on are named on the security page without detail.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.
The privacy policy addresses compelled disclosure directly, listing a subpoena or court order, compliance with any law, protecting the safety of any individual or the general public, and preventing violation of customer relationship terms. It also states separately that personal information may be disclosed as required by law or governmental audit. Nothing anywhere commits to telling the customer, and nothing reserves discretion over notice either: the question of notification is simply never reached. Checked the privacy policy, the terms of service including the confidentiality clause at 10, the website terms of use, the security page and the security policy on 2 September 2026. Clause 10.3 mentions disclosure to comply with a court order in the context of returning confidential information at the end of the agreement, which is not a notice provision.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
Checked the home page, customers page, security page, terms of service and privacy policy on 2 September 2026. No public material identifies a corpus, and none is claimed. The platform's material is the customer's own contracts, templates, redlines, policies and past decisions, drawn from the systems the business already uses, so it does not retrieve primary law and the coverage and title risks this signal tracks do not arise in their usual form. Nothing published suggests any external legal content is bundled.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Checked the home page, the product surfaces described there, the customers page and the security page on 2 September 2026. No public material addresses subsequent history, treatment flags or citator coverage, and none is claimed. The product is built on the organisation's own precedent and business context rather than on primary authority, so no good law check is offered; the honest reading is that the question is not addressed rather than that a weaker form of checking exists.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Checked the home page, customers page, security page, security policy and terms of service on 2 September 2026. Nothing describes what the platform does when it cannot ground an answer. The nearest published statement is the division of labour on the home page, that agents complete simple legal work and hand off complex tasks to lawyers, which is a routing rule rather than an account of abstention: it does not say what an agent does when it is uncertain within work it has already accepted. No confidence or grounding score is exposed and no no-answer path is documented, so the weaker values are false of this record as well.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
Searched the AI Hallucination Cases database maintained by Damien Charlotin, and reporting drawing on it, on 2 September 2026 on both the product name Sandstone and the corporate name Glaze AI. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product. Two things bound the search: Sandstone is a common word that appears in unrelated company names, and the platform is sold to in-house departments for intake and contract work rather than to litigators for filing, so the exposure this signal tracks is structurally lower than for a research tool.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
Checked the home page, customers page, security page, security policy, terms of service, website terms of use, privacy policy and legal centre on 2 September 2026. No public material engages with ABA Formal Opinion 512, any state bar opinion, or any other named ethics guidance. The terms of service do engage professional responsibility ground in substance at clause 1, stating that Sandstone is not a law firm, that outputs are not legal advice, that a licensed attorney should be consulted, and that no attorney-client relationship arises, but that is the vendor's own framing rather than engagement with the guidance its buyers are bound by, which is what this signal records.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
No located public material addresses billing, fee or disclosure treatment.
Checked the home page, customers page, product descriptions and terms of service on 2 September 2026. Nothing addresses billing, fee or disclosure treatment of AI-assisted work, and no per matter record distinguishing AI-assisted work was located. The platform does emit matter-level measurement: reporting aggregates cycle times, risk exposure, capacity and deviation rates so legal operations can benchmark and report to the business. That records the work, not what the AI did within it, so it does not meet the audit record value. Two points of context. Unlike most records on this signal, no time-savings figure is claimed anywhere, so even the savings-claims value is not made out. And the direction this signal assumes is inverted here: Sandstone's buyer is the in-house department that receives bills rather than the firm that issues them.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The material exists behind a sales conversation or an executed agreement.
The material exists and is reachable only by asking. The security page is written for exactly this purpose, headed as something to send to a security team, and it states that reports, questionnaires and the rest of the review pack are in the trust centre, alongside a security addendum described as available for the customer's counsel to review. That is more than nothing published, so the bottom value is false of this record. It is not a published list either: the trust centre is Vanta-hosted, returned no body on 2 September 2026, and its access tier could not be established, and no subprocessor or model provider list appears on any public page. Clause 9.5 of the terms gives the customer a contractual right of prior written consent before any subcontractor processes its data, with notice of the purpose and the due diligence performed, which is a route to the information rather than a disclosure of it.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located public material addresses court disclosure or verification certification.
Checked the home page, product descriptions, customers page, security page and terms of service on 2 September 2026. Nothing addresses judicial standing orders, AI use disclosure or verification certification. Audit logs are named on the security page as an access control and reporting covers cycle times and workload, neither of which records which model produced which passage or what it retrieved, so no document-level disclosure record is described. The product class is relevant: the platform is sold to in-house departments for intake, contracting and workflow rather than for court filing, so a filing disclosure obligation would usually fall on the outside counsel handling the matter.