SpotDraft

Contract lifecycle platform for in-house legal teams, covering template-driven creation, conditional approval workflows, negotiation and redlining in Word, Slack or the browser, native eSignature meeting ESIGN, eIDAS and ECA standards, a repository that extracts more than a thousand metadata types automatically, reporting and contract analytics. AI runs across it as SpotDraft AI, with VerifAI providing contract review inside Microsoft Word, and two newer modules: Intake for capturing and routing legal requests, and Sidebar, described as AI agents for asking questions, reviewing and tracking regulatory change. A Legal Hub product manages a company's public-facing online terms, and Clickwrap collects contract acceptance. More than 30 integrations each carry their own page, including Salesforce, HubSpot, Slack, Microsoft Word for desktop, Google Drive, DocuSign, Greenhouse, Jira and Zapier. Infrastructure runs on Google Cloud Platform with primary and backup servers in the Netherlands, per-contract encryption keys held in HashiCorp Vault backed by Google Cloud KMS, AES-256 at rest, and personal data stored within a customer's selected region across the US, EU, India and the Middle East. Access controls are configurable by contract type, organisational entity and department, with SSO through Office 365, Google Workspace, Okta or SAML, and contract-level audit logging that traces changes by both the customer and the counterparty. SpotDraft states that its AI features are designed with attention to the California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law and to ABA Formal Opinion 512. The company is independent, raised $54 million to expand its AI contract lifecycle management work, and publishes ISO 27001, SOC 2, GDPR and HIPAA compliance marks alongside a trust centre.

Vendor site
Last verifiedAugust 31, 2026

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The models power several core capabilities on a platform that would function without them. SpotDraft is a full contract lifecycle system first: templates, conditional workflows and approvals, a collaborative editor, native eSignature meeting ESIGN, eIDAS and ECA, a repository, reporting and analytics. Strip out SpotDraft AI, VerifAI, Intake and Sidebar and a working CLM with signature and workflow remains, which is a product with its own market. The AI is substantial rather than decorative, covering review inside Word, automatic extraction of more than a thousand metadata types, and agents for regulatory change tracking, and the vendor now brands itself context-aware AI-native CLM. But the platform predates that framing and the B band describes it: the machine learning is the engine of a core capability layered on a workflow system.

Source: Vendor Published
DD on Citation Accuracy and Hallucination DisclosureNothing published on accuracy or grounding for a product that produces legal assertions, or a bare claim that the system does not hallucinate.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Nothing published on accuracy or grounding for a product that reviews and drafts contracts. Searched the home page, the pricing page and the security page in full on 31 Aug 2026. No accuracy figure, no error or hallucination rate, no benchmark, no test set, no published evaluation, and no description of how AI output is grounded in the customer's own documents or of whether the reader can trace an assertion back to a source. The figures the vendor does publish measure speed and cost: contracts reviewed 15 times faster with VerifAI, two times faster closings, 65 per cent lower cost and 70 per cent less review time. The nearest thing to an accuracy statement is the claim that the AI operates in the customer's company-specific context and follows the customer's rules, which describes configuration rather than correctness. The SpotDraft AI and VerifAI product pages were not opened, so this grade is rebuttable if either publishes a measured figure.

Source: Operator Verified
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Oversight is real at the workflow layer and undescribed at the model layer. The product publishes a genuine human control structure for contracting: conditional approval routing with thresholds shown explicitly, including an illustration of approvals escalating to the Head of Finance below a deal value and to the CFO and CEO above it, contract-level audit logs tracing changes by both the customer and the counterparty, version history for every draft, and role-based permissions scoped by contract type, entity and department. What is absent is any statement about the AI itself: nothing published says what SpotDraft AI, VerifAI or the Sidebar agents do unattended, at what point a human must review model output, what the agents can change without approval, or what happens after an output is wrong. The framing that the AI follows the customer's rules implies constraint without describing one. Checked 31 Aug 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

A deep roster of named in-house lawyers, with the figures kept separate from them. Named individuals with roles and employers include Anna Claveria Brannan, Deputy General Counsel at IPSY; Susan Koenig, formerly Senior Legal Operations Manager at Abnormal Security; Micah Nessan, formerly General Counsel at Guideline; Reason Abajuo, VP of Legal and Corporate Affairs at Chaberton Energy; Lizzy Gagan, Senior Legal Counsel at Beamery; Arzu Hasanova, Legal Counsel at Circularise; Aditi Kapoor, Director of Legal at Gameskraft; and Natasha Wilson, Head of Legal at SUN Mobility. Every quote is qualitative. The quantified claims carry no customer at all: two times faster closings, 65 per cent lower cost, 70 per cent less review time, and contracts reviewed 15 times faster. Two things a reader should weigh: two of the referees are identified as former employees of the companies named, and the case study pages were not opened on 31 Aug 2026, so dates and method remain rebuttable.

Source: Vendor Published
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Strong data handling, and silence on the question this axis turns on. The security page is specific about protection: customer data logically separated within a multi-tenant infrastructure, per-contract unique encryption keys held in HashiCorp Vault backed by Google Cloud KMS, AES-256 at rest, FIPS-140-certified encryption, data classified into public, company confidential, customer confidential and personal, least privilege access with unique IDs, and confidentiality, audit and incident response protocols enforced on third-party vendors handling scoped data. What is missing is the training position. Searched the home page, the pricing page and the security page in full on 31 Aug 2026 and located no statement of whether customer contracts are used to train any model, by SpotDraft or by any model provider, and no retention period for prompts or outputs. Privilege and work product are not addressed either. The trust centre and the published terms of service were not opened, so this is rebuttable on either.

Source: Vendor Published
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

A published position that names guidance from two jurisdictions, which nothing else in this pull does. The home page states that SpotDraft's AI features are designed with attention to the principles in the California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law of November 2023 and the American Bar Association's Formal Opinion 512 on generative AI of July 2024. Both are named with their issuing body and date rather than gestured at, and the statement sits on the home page rather than buried in a policy. Two things hold it at B. No statement was located that SpotDraft does not provide legal advice, and nothing addresses a lawyer's own competence and supervision duties or any jurisdiction limit on use. And the claim is one of attention to principles rather than a mapping of product behaviour to specific obligations, so a buyer cannot see which principle is met by which control. Checked 31 Aug 2026.

Source: Vendor Published
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

A governance apparatus exists and is documented, but it governs the company rather than the models. The security page publishes real structure: a formalised risk governance policy approved by management defining an Enterprise Risk Management programme, periodic operational risk assessments compiled into management reports with risks rated, assigned to an owner and tracked to treatment or acceptance, regular privacy risk assessments run through vendor due diligence, and an information security team led by the Chief Technology Officer overseeing the process. That is a named accountable executive and a working risk mechanism, which is more than most of this pull publishes. None of it addresses model behaviour. Searched the home page, the pricing page and the security page on 31 Aug 2026 and located nothing on what is tested before an AI release ships, no responsible AI framework, and nothing whatsoever on bias or uneven output across contract types, counterparties or populations.

Source: Vendor Published
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Detailed, specific and current, missing a named subprocessor list. The security page carries a last-updated date of 17 October 2025 and publishes: FIPS-140-certified encryption, AES-256 at rest, per-contract unique keys in HashiCorp Vault backed by Google Cloud KMS, primary and backup servers on Google Cloud Platform in the Netherlands, data classification across four sensitivity tiers, least privilege access with unique IDs and enforced password policies, a documented business continuity and disaster recovery programme, automated patch management, continuous CVE tracking for third-party packages, regular threat modelling, independent penetration testers, and routine static analysis and vulnerability scanning. A predefined security incident response process is stated and described as refined through regular exercises. Two gaps checked 31 Aug 2026: no subprocessor is named anywhere, though the page states that fourth parties such as backup providers and subcontractors have no access to scoped systems or data, and no retention period for customer content is published.

Source: Vendor Published
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Written 31 Aug 2026 as an R7 amendment; left unwritten in the original build because the agreement had not been opened and this axis has no substitute surface. Surface read 31 Aug 2026: the SpotDraft Terms of Use on the vendor's own Legal Hub at legal.spotdraft.com, version 2.3, last updated 21 February 2024, read in full, with five prior versions listed and downloadable from the same page. Liability is addressed only through limitation and disclaimer, which is what fixes the grade. Clause 8.3 caps SpotDraft's total cumulative liability, in contract or tort, at one hundred Indian rupees, a figure worth roughly one United States dollar. Clause 8.2 excludes consequential, indirect and special damages including loss of data and profits. Clauses 5.2 and 5.3 disclaim any warranty of fitness, of error-free or uninterrupted use, and expressly waive the warranty of non-infringement. Clause 9 is an indemnity running only from the customer to SpotDraft; no vendor indemnity to the customer was located anywhere in the document. Clause 5.5 disclaims any liability for consequences arising from use of the Platform, and 5.4 states that SpotDraft gives no legal advice. Governing law is India with exclusive jurisdiction in the courts at Bangalore, and the contracting entity is Draftspotting Technologies Private Limited together with affiliates including Draftspotting Inc. One scope point a buyer should weigh: this is the published Terms of Use reached from the signup path, and clause 11.8 contemplates additional terms when other services are purchased, so an enterprise subscriber may well contract on a negotiated master agreement that is not published. The index grades what is published and readable before signing, and what is published is this.

Source: Vendor Published
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Real integrations, individually documented, into the systems an in-house team works in. The vendor states more than 30 integrations and gives each its own page, with Salesforce, HubSpot, Slack, Microsoft Word for desktop, Google Drive, DocuSign, Greenhouse, Google Forms, Jira and Zapier all linked directly from the pricing page. The Word integration is treated as a first-class surface rather than an afterthought: VerifAI runs review inside Microsoft Word, negotiation and redlining are described as working in Word, Slack or SpotDraft itself, and one named customer specifically credits the Word desktop editor with driving adoption. Single sign-on covers Office 365, Google Workspace, Okta, Active Directory and custom SAML with zero-touch provisioning. What was not established on 31 Aug 2026 is depth: the integrations index and the individual integration pages were not opened, so what each connection moves and in which direction was not verified. No document management integration such as iManage or NetDocuments appears, consistent with an in-house rather than law firm product.

Source: Vendor Published
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Both halves of this axis are answered, which almost nothing in this pull manages. The tenancy model is stated plainly rather than implied: customer data is logically separated within a secure multi-tenant infrastructure, so a buyer knows it is shared and knows what separates it. Residency is stated as a customer choice with an explicit boundary commitment: personal data is stored within selected regions covering the US, EU, India and the Middle East, and is not transmitted outside those locations. Where the data physically sits is named to the country, with primary and backup servers on Google Cloud Platform in the Netherlands. The processing layer is identified as Google Cloud Platform throughout, and encryption keys are held per contract in HashiCorp Vault backed by Google Cloud KMS, which tells a buyer where key custody sits as distinct from where data rests. What would sharpen it further is a statement of which region applies by default and whether contract content follows the same rule as personal data, since the regional commitment is written in terms of personal data specifically.

Source: Vendor Published
CC on Security Certifications and Trust CenterBadges appear on the site with no scope, no date, and no report available.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Marks are displayed, a trust centre exists, and the property contradicts itself on the standard actually held. Four compliance marks appear as icons on the home page, the pricing page and the security page: ISO, GDPR, HIPAA and AICPA SOC 2, with the home page listing them as ISO 27001, SOC 2 Type II, GDPR and HIPAA. The footer of every page then reads that SpotDraft is an ISO/IEC 27001:2013 certified company, and 27001:2013 was superseded by the 2022 revision, so the site simultaneously claims a current certification and names a retired version of it. A separate trust centre is linked at trustcenter.spotdraft.com and is credited here as a genuine access route, though it was not opened on 31 Aug 2026. What could not be established from any page read: no auditor is named, no coverage period or report date is given for the SOC 2, no scope is described, and while independent penetration testers are said to be engaged, no partner is named and no summary is published.

Source: Vendor Published
DD on Model Supply Chain DisclosureNothing published about the model supply chain a customer inherits.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Nothing published about the model supply chain a customer inherits. Searched the home page, the pricing page and the security page in full on 31 Aug 2026. No model provider is named, no model or version is identified, no architecture is described beyond the statement that the AI is embedded in SpotDraft and operates in the customer's company-specific context, no subprocessor list exists, and nothing commits the vendor to notifying customers when any of it changes. The security page is otherwise unusually granular, naming HashiCorp Vault, Google Cloud KMS, JAMF, FileVault and BitLocker among its tooling, which makes the absence of any model provider conspicuous rather than incidental. The SpotDraft AI and VerifAI product pages and the trust centre were not opened, so this is rebuttable if any of them names a provider.

Source: Operator Verified
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

The unit and structure are published without the figure, and one thing is answered that no other vendor in this pull answers. The pricing page states the charging model directly: plans are priced on either users or contract volume, with the vendor framing the choice as avoiding wasted spend. It then addresses implementation explicitly, which is the third limb of this axis and is normally silent everywhere: in-house implementation is always included, covering workflow and integration setup and migration of legacy contracts, with no extra fees and no outsourcing, and every customer receives a dedicated customer success manager and 24 hours a day support at no additional cost. An implementation timeline is published as a week one to week six sequence. What is absent is any number: no rate, no band, no floor and no currency appears anywhere, and every call to action on the page is Get Pricing or a demo request. Checked 31 Aug 2026.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Segment coverage is described with substance on two axes and the boundaries are left open. Five buying teams carry dedicated pages, legal, sales, finance, HR and procurement, with legal positioned as the owner and the others as self-serve participants. Five industries carry their own pages: SaaS, HR tech, edtech, healthtech and fintech, which is a narrower and more honest vertical set than the everything-for-everyone lists common in this category. The home page states the audience directly as high-performing in-house legal teams. What is absent is the far edge. No law firm segment is addressed, nothing covers government or public sector use, no contract types or matters are named as unsupported, and the practice dimension is expressed as industry and internal function rather than as areas of law. Checked 31 Aug 2026.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Terms silent

No located term or policy addresses the question either way.

Searched the home page, the pricing page and the security page in full on 31 Aug 2026, including the security page's data security, infrastructure security, product security and risk governance sections and its five-question FAQ. No located material addresses whether customer contracts, prompts or outputs are used to train any model, either by SpotDraft or by an underlying model provider. The nearest statements are that the AI is embedded in SpotDraft, operates in the customer's company-specific context and follows the customer's rules, and that the platform is risk free AI on the customer's terms, none of which is a commitment about training. No model provider is named anywhere either. The trust centre and the published terms of service were not opened, so this value is rebuttable on either document.

Source: Operator VerifiedAs of Aug 31, 2026

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Not addressed

No located public material states how long prompts and outputs are retained.

Searched the home page, the pricing page and the security page on 31 Aug 2026. No retention period for contracts, prompts or generated outputs is published. Retention appears only as a heading within the security page's data handling practices, where data classification and retention are named together and the text describes classification into public, company confidential, customer confidential and personal tiers without stating how long anything is kept. Secure data disposal is listed among the data centre measures without a period attached. No customer-configurable retention setting is described.

Source: Operator VerifiedAs of Aug 31, 2026

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Own model, documented

The product maintains its own permission model, documented, requiring the firm to keep it aligned.

Separation is documented at two levels rather than asserted. Between customers, the security page states that customer data is logically separated within a secure multi-tenant infrastructure, and adds that each contract is protected with a unique encryption key held in HashiCorp Vault backed by Google Cloud KMS, which is a finer-grained control than tenant-level isolation alone. Within a customer, roles and permissions are described as fully customisable and scoped by contract type, organisational entity and department, with contract-level permissions ensuring documents are visible only to authorised personnel without manual sharing. What is not published is how retrieval and the AI features apply those permissions at query time, so whether a model answering a question respects the same boundaries is unstated. The buyer is an in-house department, so tenant and entity level separation is the relevant test.

Source: Vendor Publishedlogically separated within a secure multi-tenant infrastructureAs of Aug 31, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Not addressed

No located term or policy addresses third party requests for customer data.

Searched the home page, the pricing page and the security page on 31 Aug 2026. No located material addresses what happens if a third party, law enforcement agency or court requests customer data from SpotDraft, and no commitment to notify the customer was found. No transparency report exists. The security page does state that third-party vendors handling scoped data are bound by confidentiality, audit and incident response protocols, and that fourth parties such as backup providers and subcontractors have no access to scoped systems or data, but neither addresses compelled disclosure. The published privacy policy and terms of service, which are the usual home for this provision, were not opened.

Source: Operator VerifiedAs of Aug 31, 2026
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Sources named, basis unstated

Sources are identified without stating the licence or rights basis.

The working corpus is the customer's own contract set and is identified as such: the repository is described as centralising all of a customer's contracts and automatically pulling over a thousand types of contract metadata using AI, and the AI is described as operating in the customer's company-specific context and following the customer's rules. No external legal corpus is claimed and the product does not retrieve primary law, so the usual jurisdiction and coverage questions do not arise. What is not stated is the provenance of anything underneath: no training corpus for the models themselves is described, no source is named and no licence or rights basis is given.

Source: Vendor PublishedAs of Aug 31, 2026Evidence

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

Searched the home page, the pricing page and the security page on 31 Aug 2026. Nothing addresses whether legal authority is checked for subsequent history, and no citator, treatment signal or currency check was located. The platform manages a customer's own contracts rather than retrieving case law or legislation, so a citator is not part of what it sells. One product does touch adjacent ground: Sidebar is described as helping users stay ahead of regulatory change with AI agents, which concerns the currency of regulation rather than the standing of cited authority, and no source or verification method is published for it.

Source: Operator VerifiedAs of Aug 31, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

Searched the home page, the pricing page and the security page on 31 Aug 2026. No explicit no-answer or abstention path is documented, no confidence or grounding score was located, and nothing states what the product does when the customer's contract set or playbook does not cover the question put to it. Published material addresses configuration rather than uncertainty, describing AI that operates in the customer's context and follows the customer's rules. The SpotDraft AI and VerifAI product pages were not opened, so this value is rebuttable if either documents abstention behaviour.

Source: Operator VerifiedAs of Aug 31, 2026

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, searched on the product name alongside 2026 sanctions trackers and trade press summaries. This is a statement about the public record on the date shown rather than a clearance, and it is bounded by what that database covers. The product manages commercial contracts for in-house teams rather than producing court filings, so its output does not ordinarily reach a brief.

Source: Operator VerifiedAs of Aug 31, 2026Evidence
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Named guidance addressed

Public materials engage with at least one named ethics opinion.

Two named ethics guidance documents from two jurisdictions are cited on the home page: the California State Bar's Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law, dated November 2023, and the American Bar Association's Formal Opinion 512 on generative AI, dated July 2024. Both are given with issuing body and date, and the vendor states its AI features are designed with attention to the principles in each, ensuring responsible and secure usage throughout contracting workflows. This is the only vendor read in this pull to name more than one. It is recorded at the named-guidance value rather than higher because what is published is a statement of attention to principles, not a mapping showing which obligation is met by which product control, and no other jurisdiction's guidance is addressed.

Source: Vendor Publishedthe California State Bar's Practical Guidance for the Use of Generative Artificial IntelligenceAs of Aug 31, 2026Evidence

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure.

Public materials are framed around speed and cost removed: two times faster closings, 65 per cent lower cost, 70 per cent less review time, and contracts reviewed 15 times faster with VerifAI. Searched the home page, the pricing page and the security page on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee purposes and no published guidance on billing, fee or disclosure treatment. The contract-level audit logging the vendor describes, which traces changes by both the creator and the counterparty and retains every version, could support such a record, but nothing presents it for that purpose. The buyer is an in-house department rather than a firm billing a client, so the question lands on internal cost, and it is not addressed.

Source: Vendor PublishedAs of Aug 31, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

On request only

The material exists behind a sales conversation or an executed agreement.

Searched the home page, the pricing page and the security page in full on 31 Aug 2026. No subprocessor list was located and no model provider is named anywhere, so a legal team cannot tell a client which third parties see contract content. No client-facing consent or notification material exists. What is published instead is a set of assurances about third parties rather than an identification of them: vendors handling scoped data are said to be bound by confidentiality, audit and incident response protocols, and fourth parties such as backup providers and subcontractors are stated to have no access to scoped systems or data. A trust centre is linked at trustcenter.spotdraft.com and a request route for security documentation appears on the security page, both of which are plausible homes for the missing material; neither was opened.

Source: Operator VerifiedAs of Aug 31, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

Some elements of a record exist and are described with unusual precision for this signal. The security page states that the platform has extensive audit logging allowing user actions to be traced at contract level, capturing not only signing and creation events but the trail of changes made by both the creator and the counterparty, and that every version of a contract created by a user is kept to give a clear document history. That covers what changed, by whom and when, at document level. Two elements are missing: no model is identified anywhere on the property, so which system produced a given passage cannot be established, and nothing distinguishes an AI-generated change from a human one in the log as described. No export designed for a court disclosure or AI-use certification was located on 31 Aug 2026.

Source: Vendor PublishedAs of Aug 31, 2026Evidence
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 1, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746