Sirion
Enterprise contract lifecycle platform organised around three product lines: Store, covering AI extraction, a contract repository and conversational search; Create, covering drafting, negotiation and collaboration; and Manage, covering performance, governance and obligation risk. On top of those sits agentOS, a layer for building, testing and deploying custom agents, connecting them to each other and to enterprise data sources, and orchestrating processes across systems. The interface is conversational rather than form-driven, and the vendor states that answers carry citations linked back to the customer's own data. Published outcome claims are expressed as product capabilities rather than customer results: 90 per cent faster contract centralisation, 85 per cent faster insights on contract terms, up to 90 per cent faster time to contract, 99 per cent on-time obligation compliance and 70 per cent faster agentic automation. The platform is sold across eight named industry verticals including financial services, insurance, healthcare, pharmaceuticals, telecom and oil and gas, and to five named departments covering in-house legal, legal operations, procurement, sales and finance. Sirion publishes its SaaS terms, an end user agreement and a data processing addendum openly, the last of which states that all customer data is stored and processed in a customer-specific application instance. It runs on AWS, Azure, Oracle and IBM cloud infrastructure and holds ISO 27001:2022 certification alongside SOC 1 Type II and SOC 2 Type II reports. Sirion has traded since 2012, serves customers in more than 70 countries including Citi, GE, Coca-Cola, Chevron, Bayer, Rolls-Royce and Zalando, and was named a Leader in the 2025 Gartner Magic Quadrant for Contract Life Cycle Management.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models drive the capability being sold and sit on a contract lifecycle platform that predates them and would function without them. Sirion has traded since 2012 and the product is structured as Store, Create and Manage, covering repository, drafting, approval, negotiation, obligation tracking and performance management. Strip out the agents and agentOS and a working enterprise CLM remains, which is the category Gartner placed it in. The agentic layer is real rather than cosmetic, with agents described as extracting and normalising contracts, assembling first drafts from a playbook, proposing redlines on third-party paper and monitoring obligations, and agentOS lets a customer build and deploy their own. That is the B band: the machine learning is the engine of a core capability layered on a workflow system.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted at length and measured nowhere. The grounding claim is specific and repeated: answers are described as carrying citations linked to the customer's own data, and vendor material states that every AI-generated response includes citations linked to exact sources with clause-level citation and justification. Five percentage figures are published prominently, but every one measures speed or coverage rather than correctness: 90 per cent faster centralisation, 85 per cent faster insights, up to 90 per cent faster time to contract, 99 per cent on-time obligation compliance, 70 per cent faster agentic automation. Searched the home page, the trust centre and its AI ethics, compliance and security sections on 31 Aug 2026 and located no accuracy figure, no error or hallucination rate, no test set and no published evaluation. Nothing addresses what the system does when the customer's contract set does not support an answer.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Autonomy is claimed and the oversight mechanism is asserted in a phrase rather than described. Agents are said to sense intent, reason over enterprise data and act autonomously, to assemble first drafts and propose redlines, and to monitor obligations, surface gaps, trigger owners and drive follow-through. The single oversight statement located is that the user stays in control for strategic exceptions. What that leaves unpublished is everything the axis asks for: what an agent completes without a human, the threshold at which it stops and escalates, where the review point sits, and what happens after an output is wrong. agentOS is described as letting customers build, test and deploy agents, which implies configurable guardrails, but no control structure is documented. Searched the home page and the trust centre on 31 Aug 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers and published figures, never attached to each other. Three individuals speak on the record with roles and employers: Edzard Janssen, Chief Procurement Officer at RBI; Reinhard Plaza-Bartsch, Head of Digital Supply Chain and Operations at Vodafone; and Angella Dikmic, Manager of IT Vendor Management at GTAA. All three quotes are qualitative. The five percentage claims carry no customer at all and read as product capabilities. Roughly 25 enterprise logos appear including Citi, GE, Coca-Cola, Chevron, PayPal, Bayer, Rolls-Royce, Aramco, Yamaha, DP World and Zalando, with customers stated across more than 70 countries and contract value under management put at more than 450 billion dollars. Two things a reader should note: all three named referees sit in procurement or vendor management rather than legal, on a platform indexed here as a legal product; and the case study library was not opened on 31 Aug 2026, so dates and method remain rebuttable.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Note amended 31 Aug 2026 under R23 as amended; grade held at B, and the reasoning for holding it is set out because the underlying facts have moved against the vendor. The original note recorded that the no-training commitment was located only in vendor library articles rather than in the agreement. The SaaS Terms have since been read in full, version 6, modified 26 August 2026, and the position is worse than a silence: clause 4.2 reserves a right for Sirion to direct its automated systems to review and process Customer Data to generally inform machine learning capabilities in the Subscription Services, with no opt-out located. The published no-training statement and the governing agreement therefore contradict each other, and under the documents-beat-marketing rule the agreement is what binds. What still supports the grade is the rest of the confidentiality architecture, which is genuinely substantive and readable before signing: the data processing addendum stores and processes all customer data in a customer-specific Sirion application instance, sets Article 32 technical and organisational measures with AES-256 at rest and TLS 1.2 in transit, imposes need-to-know and least-privilege access with automatic logout, requires deletion within 30 days of termination, and commits to notifying the customer of a confirmed security incident within 72 hours. SaaS Terms section 5 adds a mutual confidentiality regime with a duty to give prior notice of any authority or court demand so the other party can object. Privilege and work product remain unaddressed on every surface read. The grade is held rather than dropped because the C band describes confidentiality asserted in general terms or reachable only through a sales conversation, and neither is true here. A reader who takes the B band's requirement of substantive commitments on training use to mean commitments not contradicted by the agreement would grade this C, and that reading is defensible on these facts.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Nothing published on the advice line was located. Searched the home page, the full trust centre index and its AI ethics, compliance and security sections, and the terms and policies index on 31 Aug 2026. No statement that Sirion does not provide legal advice, no professional responsibility or ethics page, no named bar or ethics guidance including ABA Formal Opinion 512, and no jurisdiction limits. The exposure is not theoretical: the platform is sold to procurement, sales and finance departments alongside in-house legal, all working on the same contracts, and the three customer referees the vendor chose to feature are procurement and vendor management leaders rather than lawyers. The SaaS terms and end user agreement were read only in fragments through the search index, so this grade is rebuttable if either carries a professional advice disclaimer.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
The trust centre carries a section titled Artificial Intelligence Ethics and Governance, and its entire published content is three sentences: that Sirion has instituted an AI Governance Program abbreviated S-AIGP, that the programme monitors and ensures compliance with the EU AI Act 2024/1689 and other global AI regulations as they emerge, and that the reader should contact their Sirion Account Executive for more information. The page was last modified 16 December 2025. Naming a programme and a regulation, then routing the substance to a sales conversation, is not a governance position: nothing is published about who owns model behaviour, what is tested before release, how the programme operates, or anything at all concerning bias or uneven output. Under the gating rule a referral to an account executive is the sales-gated tier and earns no credit. This is the sharpest example in this pull of a governance artifact that exists as a heading rather than as disclosure.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Amended 31 Aug 2026 under R23 as amended, from B to A. The Data Processing Addendum at /terms-and-policies/data-processing-addendum/, version 3, modified 2 July 2026, was read in full on 31 Aug 2026; the original grading rested on fragments recovered through the search index, and the full document supplies every element this axis asks for. Retention and deletion: Appendix B sets the retention period by the controller's contractual direction, and clause 8.1 requires deletion or return of all Customer Personal Data including copies within 30 days of termination, with any law-compelled retention limited to the purposes requiring it and kept under the Agreement's protections. The SaaS Terms add automatic deletion after 30 days as a backstop. Access control: defined permissions on need-to-know and least-privilege-by-default, with automatic logout on inactivity. Subprocessors: a named Sub-Processor List published at its own URL, with a commitment to notify and an objection right on any addition or replacement, equivalent contractual terms imposed on each, and Sirion remaining liable for their breaches. Incident practice: clause 4.3 commits to notifying the customer within 72 hours of establishing material impact from a confirmed Security Incident, with Appendix B stating 48 to 72 hours and continuing communication until resolution, and the definition expressly excludes unsuccessful attempts such as failed logins and denial-of-service attempts, which is a precision most vendors leave out. Encryption is AES-256 at rest and TLS 1.2 in transit. All five limbs are published, current and specific enough to hold the vendor to, which is what separates A from B here; the earlier B rested on the subprocessor list and incident window not having been located rather than on their absence.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A real published position, readable before signing, short of the cap and silent on AI output. The SaaS terms and a separate end user agreement are both published openly. Clause 7.1 commits Sirion to indemnify and defend the customer against third-party claims that use of the subscription services infringes intellectual property rights. Clause 7.2 sets four named exclusions, covering combination with materials Sirion did not provide, unapproved modification, unauthorised use, and use inconsistent with the documentation. Clause 7.3 gives a remedy ladder of securing the right to continue, replacing or modifying the services, or terminating with a pro-rata refund of prepaid fees as Sirion's sole and exclusive liability. Clause 7.4 runs a reciprocal indemnity from the customer over customer data. What could not be established on 31 Aug 2026: the liability cap, since only fragments of the limitation clause were retrievable through the search index; any warranty on output; any insurance position; and any AI-specific treatment, since neither agreement carves AI output in or out of the indemnity.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Written 31 Aug 2026 as an R7 amendment; this row was left unwritten in the original build because no integration surface had been opened and grading an absence would have scored a research gap against the vendor. Surface read on 31 Aug 2026: the Non-Native Integrations article in Sirion University at /sirion-university/integrations/non-native-integrations/, last updated 24 February 2026. It documents nine named connectors with the direction of travel stated for each, which is the depth this axis asks for and which almost nothing else in the corpus publishes. Four SAP Ariba accelerators cover procurement, bids, awards and contract workspaces: an executed contract request in Sirion creates a purchase requisition in Ariba and the resulting purchase order is written back to Sirion; Ariba sourcing events and RFPs convert into Contract Draft Requests on defined workflow triggers, one per bidding supplier with line items mapped from bid detail, and supplier redlines transfer into Sirion for legal review; awarded RFx events create a new draft request with awarded line items synced; and contracts finalised in Sirion replicate into Ariba Contract Workspaces with metadata, documents, line items and workflow status, by event-driven asynchronous processing. Three more cover supplier master data from Ariba, SAP S/4HANA Business Partners on scheduled transfers, and Oracle ERP with built-in logging, error handling and sync status visibility. The Microsoft Dynamics connector is explicitly bidirectional and runs in auto or manual mode. Configuration is described at the level of triggers, modes and scheduling rather than a full implementation guide, and the wider Sirion University catalogue requires a login. The documented depth sits on the procurement and ERP side; the Microsoft Word add-in is distributed through AppSource and Salesforce through AppExchange, but neither is documented to this depth on a page read, and no document management system connector such as iManage or NetDocuments was located.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The tenancy model is stated in the agreement and the regions are not stated anywhere. The data processing addendum states that the Sirion application is a SaaS application hosted by a cloud service provider and that all customer data is stored and processed in a customer-specific Sirion application instance, which is a real isolation statement carried in a contractual document rather than a marketing claim. The trust centre names four underlying providers, AWS, Azure, Oracle and IBM, which is unusually broad and implies customer choice without stating it as an option. Two gaps checked 31 Aug 2026: no data residency commitment, region list or jurisdiction option was located anywhere, and nothing addresses where processing happens as distinct from where data is stored. One tension worth a buyer's attention: a Sirion library article describes the platform's multi-tenant scalability, which sits awkwardly beside the addendum's customer-specific instance, and nothing published reconciles the two.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Note amended 31 Aug 2026 under R23 as amended; grade unchanged at B. The Data Processing Addendum, read in full on 31 Aug 2026 where the original grading had only fragments, supplies two things the earlier note recorded as missing. Appendix B names ISO 27001 as a held security certification and describes the review regime around it, and clause 7.1 gives a contractual access route: unless otherwise agreed, Sirion will provide a copy of its most current security attestation report on the customer's written request, no more than once annually. Clause 7.2 adds a customer audit right, with scope, timing and controls agreed in advance and a reasonable fee chargeable. Appendix B also records that the cloud provider's own SOC 1, SOC 2 and ISO 27001 reports are assessed by Sirion as part of a shared responsibility model, which is oversight of infrastructure rather than an attestation over the application and is not credited here. The grade stays at B because the access route is a contractual entitlement running to an existing customer, not a way for a buyer to obtain evidence before signing, and because no auditor is named, no coverage period is stated, and no scope statement says which systems the ISO certificate covers. Under R5 the line is the sales conversation, and a report obtainable only after execution sits below the self-serve tier that can reach A.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The architecture is described and nothing underneath it is identified. Vendor material sets out a multi-model approach combining purpose-built small models trained on enterprise contracts with large language models, and presents that as the differentiator against generic models retrofitted for legal use. No large language model provider is named, no model or version is identified, no processing location is given for the model layer as distinct from the cloud infrastructure, and nothing commits Sirion to notifying customers when any of it changes. This sits above the floor because the architecture is genuinely described rather than gestured at, and below anything higher because a buyer inherits dependencies it cannot see. Searched the home page, the trust centre and its AI ethics, compliance and security sections on 31 Aug 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. Searched the home page, the full primary navigation across platform, solutions, resources and company, the footer sitemap, the trust centre and the terms and policies index on 31 Aug 2026. There is no pricing page, no tier structure, no per-seat, per-contract or per-agent unit, no volume banding and no statement of what implementation adds. Every call to action is a demo request. Nothing published would let a prospective buyer form any view of cost before entering a sales process, which is a notable contrast with the vendor's willingness to publish its SaaS terms, end user agreement and data processing addendum in full.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is documented precisely on two axes and the boundaries are left open. Eight industry verticals carry dedicated pages: financial services split into procurement and capital markets and credit, insurance with a separate underwriting submissions triage solution, automotive, IT services, healthcare, pharmaceuticals and life sciences, telecom, and oil and gas. Five departments carry their own pages: in-house legal, legal operations, procurement, sales and finance. Customers are stated across more than 70 countries and the site publishes in English, German and French. What is absent is any statement of where the product stops: no contract types or matter types are excluded, nothing addresses law firms, government or public sector use, and the practice dimension is expressed as industry and department rather than as areas of law. Checked 31 Aug 2026.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The published agreement expressly reserves a right to train on customer content, with no opt out located. Any de identification, anonymisation or aggregation qualifier is recorded in the summary.
Amended 31 Aug 2026 from policy-never, under R23 as amended: the SaaS Terms were read in full, where the original grading had only fragments, and the earlier value rested expressly on no training prohibition having been found in the portions then retrievable. Both sides of the record, because the gap between them is the finding. Sirion's library material states that customer data stays within the customer environment and is not used to train external language models. Its SaaS Terms, version 6, modified 26 August 2026, reserve the opposite at clause 4.2: Sirion may direct its automated systems to review and process Customer Data to generally inform machine learning capabilities in the Subscription Services, alongside generating aggregated and anonymised industry analytics, with a commitment not to publicly identify the customer or disclose Customer Data to third parties. The agreement governs over a policy page, so the reservation is what a buyer is bound by. Two features of the wording a reader should weigh directly. The reservation operates on Customer Data itself rather than on de-identified or aggregated derivatives, which makes it broader in reach than clauses that are limited to aggregate data. But it says generally inform rather than train, so whether it authorises model training in the ordinary sense is a question the words leave open. No opt-out, consent step, configuration setting or exclusion route was located in the SaaS Terms, the end user agreement or the data processing addendum.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
The customer controls the retention window, by product configuration or by contractual instruction, but zero retention is not stated as available.
The published data processing addendum states that the retention period is determined by contractual obligations as directed by the controller, and that after termination personal data processed on the controller's behalf is retained typically for a period of 30 days. That places the window under customer instruction with a stated default, in a contractual document rather than a policy page, which is stronger than most of this pull. Two qualifications: the provision is framed around personal data rather than prompts and generated outputs specifically, and no zero-retention setting is offered or described. Read 31 Aug 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
Separation between customers is documented in the data processing addendum rather than asserted in marketing: all customer data is stated to be stored and processed in a customer-specific Sirion application instance in the cloud service, under a shared responsibility model in which Sirion secures the software, the customer data and the related access while the cloud provider secures the underlying facility. Role-based access control with granular permissions is described in vendor library articles. Two things to note. Nothing describes how access is enforced between teams inside a customer, which matters where legal, procurement, sales and finance share the platform. And a Sirion library article describes the platform's multi-tenant scalability, which is not reconciled anywhere with the addendum's customer-specific instance. The buyer is an in-house department, so tenant-level separation is the relevant test.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Terms commit to notice where lawfully permitted. No transparency report located.
Written 31 Aug 2026 as an R7 amendment. The commitment is in the SaaS Terms at section 5.3, version 6, modified 26 August 2026, and not in the Data Processing Addendum, which was read in full the same day and does not address third-party demands anywhere. Section 5.3 permits a party receiving a demand from a competent authority or court for the other party's Confidential Information to comply only if it has satisfied itself the demand is lawful, given the disclosing party as much prior notice as possible where possible so that party can object, and marked the material as the disclosing party's Confidential Information. The obligation is mutual and it reaches customer material: Confidential Information is defined to cover information that should reasonably be understood to be confidential, and the AI Module clause at 1.8(b) confirms the reading by carving Customer Data back into that definition. The notice duty is qualified by where possible rather than by legal prohibition, which is softer than the usual formulation. No transparency report or count of demands received was located on the terms pages, the DPA or the trust centre, which is what keeps this below the top value.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Sources are identified without stating the licence or rights basis.
The working corpus is the customer's own contract set and is identified as such, with answers described as carrying citations linked to the customer's own data and agents extracting and normalising contracts from customer-nominated sources. Sirion separately states that its purpose-built models are trained on millions of enterprise contracts, which identifies a second corpus at the level of composition without naming any source, stating any licence or rights basis, or explaining whose contracts those are. The product does not retrieve primary law, so the usual jurisdiction and coverage questions do not arise. No update cadence is published.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Searched the home page, the trust centre index and its AI ethics, compliance and security sections, and the terms and policies index on 31 Aug 2026. Nothing addresses whether legal authority is checked for subsequent history, and no citator, treatment signal or currency check was located. The platform manages contracts, obligations and supplier performance rather than retrieving case law or legislation, so a citator is not part of what it sells.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Searched the home page, the trust centre and its AI ethics, compliance and security sections on 31 Aug 2026. No explicit no-answer or abstention path is documented and no confidence or grounding score was located. Published material runs the other way, describing agents that sense intent, reason over enterprise data and act autonomously, and answers delivered with citations, without stating what happens when the customer's contract set does not support a response. The nearest adjacent material is the statement that users stay in control for strategic exceptions, which describes an escalation posture rather than model behaviour under uncertainty.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, searched on both the product name and the former company name SirionLabs, alongside 2026 sanctions trackers and trade press summaries. This is a statement about the public record on the date shown rather than a clearance, and it is bounded by what that database covers. The platform runs enterprise contracting and supplier governance rather than producing court filings.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
Searched the home page, the full trust centre index and its AI ethics, compliance and security sections, and the terms and policies index on 31 Aug 2026. No engagement with any bar or ethics guidance was located, including ABA Formal Opinion 512 and any state bar or Law Society material. The compliance material published is regulatory and security-framework oriented, covering ISO 27001, SOC 1, SOC 2 and the EU AI Act, and none of it addresses the professional conduct obligations binding the lawyers who use the product.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Public materials are built around speed and automation gains: 90 per cent faster contract centralisation, 85 per cent faster insights, up to 90 per cent faster time to contract, 70 per cent faster agentic automation, and a customer reporting as much as a 50 per cent uptick in tasks automated. Searched the home page, the trust centre and the terms and policies index on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee purposes and no published guidance on billing, fee or disclosure treatment. The buyer is an in-house function rather than a firm billing a client, so the question lands on internal cost and outside counsel spend, and neither is addressed.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
Amended 31 Aug 2026 under R23 as amended: the Data Processing Addendum was read in full, where the original grading had only fragments, and it closes the gap the earlier value rested on. Appendix D publishes a Sub-Processor List, stated to be regularly updated, at a named URL reachable without a sales conversation, and clause 5.4 commits Sirion to notify the customer of updates and give an opportunity to object to additions or replacements. Clause 5.6 requires equivalent data protection terms on every sub-processor and keeps Sirion liable for their breaches. That is the artifact this value turns on and it is published, which lifts the record off the request-only tier. It stops short of a disclosure pack: no model provider is named in the located material, and no client-facing consent or notification material exists for a firm answering a client's AI clause. The AI governance detail that would accompany such a pack is still routed to a Sirion Account Executive on the trust centre's AI ethics page.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Some elements of a record exist as a by-product of the product's design. Answers are described as delivering citations linked to the customer's own data, vendor material states that every AI-generated response includes citations linked to exact sources with clause-level citation and justification, and granular audit trails are described as recording system activities, user actions and data modifications. That covers sources retrieved and, in part, what was done. Two elements are missing: no model is identified anywhere on the property, so which system produced a given passage cannot be established, and no export designed for a court disclosure or AI-use certification was located on 31 Aug 2026. The product serves enterprise contracting rather than litigation, so a judicial standing order is not its usual context.