Summize

Summize is a contract intelligence system for in-house legal teams that works inside the tools a business already uses rather than asking people to move into a new platform. It runs in Outlook, Teams, Slack, Gmail, Word, Salesforce, HubSpot and Jira, so a salesperson can check renewal terms without leaving Salesforce and a request can be raised without leaving Teams. The product is organised in three layers: a Knowledge Layer holding playbooks and policies, a Contract Operations Layer covering the lifecycle from first request to signature, and an agentic AI layer called SIA, or Summize Intelligence Agents, which answers contract questions across the business using that knowledge. Use cases are grouped as request, review, repository and analytics, with dedicated material for legal, sales, finance, HR and procurement teams. Summize holds ISO 27001 accreditation certified by ISOQAR under UKAS, and states that customer prompts, completions and embeddings are exclusive to each customer and are not available to OpenAI or used to improve OpenAI models. Its published subscription agreement separately permits Summize to use Customer Data in aggregated, anonymised form to improve the software through machine learning analysis. The agreement carries an intellectual property indemnity, a warranty that the software will be free from material errors and defects, and liability caps set as the greater of a fixed sum or a multiple of charges. There is no published price. Summize Ltd is a UK company and the agreement is governed by English law.

Vendor site
Last verifiedSeptember 4, 2026

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The models are the engine of a core capability layered on a product that stands without them. Summize publishes its own three-layer architecture and only the third is AI: a Knowledge Layer holding playbooks and policies, a Contract Operations Layer running the lifecycle from first request to signature inside existing tools, and an agentic AI layer, SIA, described as surfacing that knowledge as instant answers. Remove SIA and a working contract request, repository and operations system remains, embedded in Outlook, Teams, Slack and Salesforce. The vendor's own framing of the layers as distinct, each one powering the next, is what settles this. Checked 4 September 2026.

Source: Vendor Published
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Accuracy is asserted without measurement. SIA is described as providing instant, reliable answers grounded in the customer's own knowledge and standards, which identifies the grounding source as the Knowledge Layer of playbooks and policies but describes no retrieval method behind it. The security page states that on a consistent basis Summize evaluates the effectiveness, quality and security of its AI models, which is an assessment practice asserted with no published result, no test set, no cadence and no scope. No accuracy figure appears anywhere. No failure mode is named on any surface: hallucination is not discussed, and the published performance figures are all speed and volume rather than correctness. Searched the home page, the security page, the AI layer page, the website terms and the SaaS terms on 4 September 2026.

Source: Vendor Published
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Oversight is asserted as a slogan rather than described as a mechanism. The positioning is explicit that the business becomes more self-sufficient while legal remains in full control, and that queries which used to reach legal's inbox are answered instantly by the people who needed them. Nothing published says what SIA answers alone versus what a lawyer approves, no threshold is stated, no review surface is described, and nothing addresses what happens when an answer is wrong. The phrase legal remains in full control is the whole of the oversight position, which is the case this band describes. Searched the home page, the AI layer page, the security page and the SaaS terms on 4 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Real deployment evidence with substance, short of measurement tied to a named customer. Named customers carry attributed quotations and dedicated case study pages: Steven McGeagh at Huel on ease of adoption, Julia Trius at Edpuzzle on receiving agreements already in the required format, and Derek Ihnen at Boon Edam on reduced review time. Logos include Revolut, SeatGeek, Miami Heat, Matillion, Sigma Computing, CodeRabbit, KSE and IPC Systems. Figures are published and specific: three times faster contract creation, 40 per cent reduction in deal length, 50 per cent reduction in processing time, six times more contracts reviewed, and two minutes against two hours for an NDA. One figure carries an independent method, a 4,062 per cent ROI attributed to Nucleus Research, which is a named analyst firm rather than an internal claim. Held at B because none of the figures is tied to any of the named customers, none carries a date, and the case study pages were not opened in this pass, so they are credited for existing rather than for their contents.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Substantive published commitments, and the agreement is readable, which is why this sits above the assertion band. Clause 6.1 grants Summize a licence to store, transmit and process Customer Data solely as necessary to provide the services and states that nothing in the agreement grants any other rights in it. Clause 6.2 requires physical, technical and organisational measures aligned with good industry practice, clause 6.5 imposes confidentiality with named exceptions, clause 6.6 requires daily encrypted backups available to the customer on request, and clause 9.2 requires prompt deletion or return of all Customer Data at the customer's option on termination. The position on the model provider is explicit rather than inferred: customer prompts, completions, embeddings and training data are stated to be exclusive to each customer and not available to OpenAI or used to improve OpenAI models. Three limbs are unmet. Training is permitted rather than prohibited, because clause 6.4 reserves the right to use Customer Data in aggregated, anonymised form to improve the software through machine learning analysis. Segregation is asserted as siloed AI with no published detail on enforcement. And privilege and work product are not addressed anywhere, which is defensible for a product whose buyer is a corporate department rather than a firm but is still absent.

Source: Vendor Published
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Nothing published addresses the advice line for a product explicitly sold to people who are not lawyers. Summize markets contract answers to sales, finance, HR and procurement teams, states that queries which used to find their way to legal's inbox are taken care of, and gives the example of a salesperson checking renewal terms and a CFO querying payment performance without involving legal. Against that, no statement anywhere says what the output is and is not, no disclaimer distinguishes information from legal advice, no competence or supervision language appears, and no jurisdiction limit is stated despite customers in both the UK and the US. This grade rests on a document that was read rather than on a gap that could not be tested: the SaaS terms and conditions were retrieved in full on 4 September 2026 and contain warranties, indemnities and liability caps but no advice-line provision at all. The website terms of use likewise disclaim only the website. The nearest thing to a position is the marketing line that legal remains in full control, which is about workflow rather than about advice.

Source: Vendor Published
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Principles are published without a mechanism a buyer could audit. The security page sets out four AI commitments: siloed AI practices, regular assessments of effectiveness, quality and security, ongoing updates to AI capabilities, and a customer feedback loop. Each is a sentence. No owner inside Summize is named as accountable for AI outcomes, no pre-release testing regime is described, no assessment result is published, and there is nothing whatever on bias or uneven output across contract types or counterparties. The company publishes an EU AI Act explainer written by its own General Counsel, which is regulatory commentary for the reader's benefit rather than a disclosure of Summize's own governance. ISO 27001 is an information security standard and does not answer this axis.

Source: Vendor Published
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Substantive published policy covering most of the ground. Deletion is contractual and specific: clause 9.2 requires Summize to promptly delete or return all Customer Data at the customer's option on termination, with retention only where law requires and continuing confidentiality obligations over anything retained. Clause 6.6 requires backups no less frequently than daily, secure and encrypted, in a commonly used machine-readable format and available to the customer on request. Access control rests on ISO 27001 with DevSecOps practices and internal password, equipment and data confidentiality policies described, and clause 3.2 gives an annual audit right over user and password compliance. Regular third-party penetration testing is stated. Two elements of the set are missing: no retention period is stated for the term of the agreement, only for its end, and no subprocessor list is published, with Appendix 3 referenced in clause 8.4 as defining Sub-Processors but not rendered in the published document.

Source: Vendor Published
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

The strongest liability position located in this pull, and all of it readable before signing. Clause 7.2 gives the customer an intellectual property infringement indemnity covering claims, liabilities, losses, damages and reasonably incurred costs, with a single named carve-out at 7.3 for unapproved combinations, and 7.4 sets out the conduct-of-claim mechanics including that Summize may not settle without unconditionally releasing the customer. The caps are set as a floor rather than a ceiling, which is unusual and materially better for a smaller buyer: clause 8.3 caps general liability at the greater of 100,000 pounds or 150 per cent of total charges, and clause 8.2 sets a separate super-cap for breach of the security and data protection obligations at the greater of 500,000 pounds or 500 per cent of total charges. Clause 8.1 preserves liability for wilful misconduct and anything not excludable by law, and 8.4 makes Summize liable for its subcontractors and sub-processors as if their acts were its own. Warranties are real and invocable: clause 3.6 warrants the software will comply with its specification in all material respects and be free from material errors and defects, 3.5 requires reasonable skill, care, diligence and foresight, 3.8 warrants against malicious code on an ongoing basis, and 7.1 warrants Summize holds the rights needed to supply the service. No insurance position was located. Notably there is no disclaimer of output accuracy in this agreement, unlike several peers.

Source: Vendor Published
AA on Practice Systems Integration DepthDocumented, verifiable integrations into the systems legal work already lives in, with the depth described: what syncs, in which direction, and what a firm must configure.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

The integration set is the product's central claim and it is documented rather than listed. Named targets are Outlook, Microsoft Teams, Slack, Gmail, Microsoft Word, Salesforce, HubSpot and Jira, plus Summize Sign for e-signature and a Claude integration, each with its own dedicated page. What each integration surfaces is described concretely rather than as a logo: a salesperson checking renewal terms inside Salesforce, a CFO querying payment performance across the supplier base, contract context and assistance available in the tool without a new login to manage. The positioning is explicit that there is no separate platform to adopt, which is a statement about direction of travel between systems. Configuration effort is published too: implementation runs in sprints of three to four weeks under a named HERO methodology with in-house implementation staff, typically fully rolled out within twelve weeks. The individual integration pages were not opened, so the grade rests on the named set, the described in-tool behaviour and the published implementation model rather than on their contents.

Source: Vendor Published
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Neither limb is stated for the platform. The only hosting location published anywhere is in the website terms of use, which state that the Website is hosted on servers located in the United Kingdom; that governs the marketing site rather than the software, and a website term does not grade the platform. For the platform itself the home page says data never leaves your environment and the FAQ says it is built on Azure enterprise-grade infrastructure, which names the infrastructure provider without naming a region and without stating where customer contract data is stored. Tenancy is not addressed: siloed AI describes the handling of prompts and embeddings rather than a tenancy model, and no material states whether the platform is single or multi-tenant. Searched the home page, the security page, the website terms and the SaaS terms on 4 September 2026.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Certification is real and stated, and better identified than most records in this band: the ISO 27001 badge names ISOQAR as the certification body and UKAS as the accrediting body, so a buyer can in principle verify the claim against a third party's register rather than take the vendor's word for it. That is the limb most records on this axis miss. What is missing is the rest of the accessible evidence: no certificate number, no scope or statement of applicability, no issue or expiry date, no trust portal, and no route to obtain a report. Penetration testing is described as regular and third-party with no firm named and no dates. A security whitepaper authored by named CTO Richard Somerfield is offered behind an on-page form, which is a request flow rather than open publication. One point stated plainly because the page states it plainly: **SOC 2 is not held.** Summize says it audits infrastructure in line with standards including SOC II and that it intends to investigate and work towards SOC II accreditation in the future, which is intent and is credited to nothing.

Source: Vendor Published
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Providers are named without change notification, which is this band's first limb. OpenAI is identified explicitly and in a form that tells a buyer something useful: customer prompts, completions, embeddings and training data are stated not to be available to OpenAI or used to improve OpenAI models, which both names the provider and states what it may not do. The FAQ adds that SIA is built on Azure enterprise-grade infrastructure, which locates the deployment. What is absent is the rest: no specific model or model version is named, no commitment to notify customers when a model or provider changes was located, and no subprocessor register is published, with Appendix 3 referenced in the agreement as defining Sub-Processors but not rendered in the published text.

Source: Vendor Published
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

The unit and structure are stated without the figure, and unusually the evidence sits in the published agreement rather than on a pricing page, because there is no pricing page anywhere in the navigation or footer. The SaaS terms define the Order Form as setting out user numbers and type of software licence, which publishes the unit of charge as per-user by licence type. The term structure is published: an initial term with automatic renewal for successive twelve-month periods and 90 days written notice to prevent renewal. So is the escalation: clause 2.2(b) caps any renewal increase at 10 per cent over the preceding twelve-month term for the same plan, tier and package unless a higher cap is agreed, which is a real commercial protection a buyer can read before contracting. Payment terms are 30 days from a valid invoice, fees are exclusive of VAT and sales tax but inclusive of other taxes, and expenses require prior written approval. No figure, band, tier name or feature split is published anywhere.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Segment coverage is described with substance and the boundary is left open. Five buying teams each carry a dedicated page: Legal, Sales, Finance, HR and Procurement. Eight sectors each carry their own page: Software, Sports, Finance, Manufacturing, Business Services, Media and Internet, Retail and Telecommunications. Four use cases are published as request, review, repository and analytics, and NDAs are named as a specific contract type with a stated handling time. The buyer is a corporate in-house function rather than a law firm, and law firms are neither claimed nor excluded. What is missing is the edge: no organisation size is stated, no contract types beyond NDAs are enumerated as supported, government use is not addressed, and nothing says where the product stops.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Permitted, in the contract

The published agreement expressly reserves a right to train on customer content, with no opt out located. Any de identification, anonymisation or aggregation qualifier is recorded in the summary.

Clause 6.4 of the published SaaS terms expressly reserves the right, notwithstanding the security and data protection clauses that precede it, to use Customer Data in aggregated, anonymised form to improve the Services or Software by automated decision processing or machine learning analysis. The clause names machine learning and operates on Customer Data, which is what this value turns on, and the de-identification qualifier is recorded here rather than treated as removing the permission. Both sides are recorded because they are reconcilable rather than contradictory on a careful reading: the home page promises a contractual guarantee that data is never used to train external models, and the security page states that customer prompts, completions, embeddings and training data are not available to OpenAI or used to improve OpenAI models. Those statements are about third-party models. Clause 6.4 permits Summize's own machine learning analysis on aggregated, anonymised Customer Data. A buyer reading only the marketing would not expect clause 6.4, and a buyer reading only clause 6.4 would not know the external-model position is stronger.

Source: Vendor PublishedSummize may use Customer Data in aggregated, anonymised formAs of Sep 4, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Disclosed without a period

Retention is acknowledged in public materials with no stated period.

Retention is acknowledged in the published agreement without a stated period. Clause 6.6 requires Summize to perform and maintain backups of all Customer Data no less frequently than daily, secure and encrypted, in a commonly used machine-readable format and available to the customer on request. Clause 9.2 addresses the end of the relationship, requiring prompt deletion or return of all Customer Data at the customer's option on termination, with retention permitted only where and for as long as law requires and continuing confidentiality over anything retained. Nothing states how long prompts, outputs or uploaded contracts are held during the term, and no configurable retention window is described.

Source: Vendor Publishedregular (and not less frequently than daily) secure and encrypted back-upsAs of Sep 4, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Claimed, not documented

Segregation is asserted in public materials with no published detail on how it is enforced.

Segregation is asserted in public materials without published detail on how it is enforced. The security page describes siloed AI practices under which customer prompts, completions, embeddings and training data are available exclusively to that customer and not to other customers, and the home page FAQ repeats it as a siloed AI approach keeping each customer's prompts, data and outputs exclusive to them. No material describes the isolation mechanism, the tenancy model, or how access is administered beyond the agreement's user and password provisions, and nothing addresses separation between matters or contract sets inside a single customer.

Source: Vendor Publishedprompts, completions, embeddings and training data are only available exclusively to each customerAs of Sep 4, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Disclosure addressed, notice absent

Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.

Clause 6.5 of the SaaS terms requires both parties to keep the other's confidential information, expressly including Customer Data, confidential and not to disclose it to any third party unless required by applicable law or regulation, permitted in writing by the other party, or the information has become public without default. Compelled disclosure is therefore addressed directly. No commitment to notify the customer of such a request was located anywhere, and no discretion over notice is reserved either. Searched the SaaS terms, the website terms of use and the security page on 4 September 2026; the agreement notes that a separate confidentiality agreement, if the parties have one, takes precedence over clause 6.5, and no such template is published.

Source: Vendor PublishedRequired by applicable law or regulationAs of Sep 4, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Not addressed

No located public material identifies the corpus behind the product’s answers.

No located public material identifies an external corpus, and the product's design makes the question narrow. Summize grounds its answers in the customer's own Knowledge Layer of playbooks and policies and in that customer's contract repository, rather than retrieving primary law. No external database, publisher or content licence is named on any surface and no jurisdictional coverage is claimed. Searched the home page, the three layer pages, the security page and the SaaS terms on 4 September 2026.

Source: Operator VerifiedAs of Sep 4, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

Nothing on any located surface addresses whether authority is checked for subsequent history. The product does not retrieve primary law: it operates on the customer's own contracts, playbooks and policies to answer contract questions and run the contract lifecycle. The question therefore does not bite on this product class and the honest value is the absence rather than a penalty. Searched the home page, the three layer pages, the security page and the SaaS terms on 4 September 2026.

Source: Operator VerifiedAs of Sep 4, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

No located public material addresses what the product does when it cannot ground an answer. SIA is described as providing instant, reliable answers grounded in the customer's own knowledge and standards, which is a claim about the normal case rather than the failure case. No abstention path, no no-answer behaviour and no confidence or grounding score visible to the user is described, and hallucination is not discussed anywhere including on the dedicated security page. Searched the home page, the AI layer page, the security page and the SaaS terms on 4 September 2026.

Source: Operator VerifiedAs of Sep 4, 2026

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

The AI Hallucination Cases database maintained by Damien Charlotin was searched on 4 September 2026 on the product and company name Summize. No court order, opinion or disciplinary record naming the product was located. This records the state of the public record on that date and is not a finding about the product.

Source: Operator VerifiedAs of Sep 4, 2026Evidence
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No located public material engages with bar or ethics guidance. Summize publishes an explainer on the EU AI Act written by its own General Counsel, which is commentary on a regulation for the reader's benefit rather than engagement with professional responsibility guidance about the vendor's own product, and no bar association, law society, regulator or ethics opinion is named on any surface. The buyer is a corporate in-house function rather than a regulated practitioner in private practice, which explains the absence without changing it. Searched the home page, the security page, the layer pages, the website terms and the SaaS terms on 4 September 2026.

Source: Operator VerifiedAs of Sep 4, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure.

Public materials claim time and cost savings without addressing billing or disclosure. Published figures include three times faster contract creation, a 40 per cent reduction in deal length, a 50 per cent reduction in contract processing time, six times more contracts reviewed, two minutes against two hours for an NDA, and a 4,062 per cent return on investment attributed to Nucleus Research. Nothing addresses what happens to a bill when AI-assisted work compresses the time it takes, and no per-matter record of AI-assisted work is described. The buyer is an in-house department rather than a firm billing a client, which is the inverse of the direction this signal assumes.

Source: Vendor PublishedAs of Sep 4, 2026

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Subprocessors listed

A current subprocessor or model provider list is published.

A model provider is named openly on the public security page, which states that customer prompts, completions, embeddings and training data are not available to OpenAI or used to improve OpenAI models, and the home page FAQ adds that the system is built on Azure infrastructure. That is a statement about who touches customer content, reachable without a sales conversation. What is not published is a subprocessor register or a forwardable client-facing pack: Appendix 3 is referenced in clause 8.4 of the SaaS terms as defining Sub-Processors but is not rendered in the published document, no data processing agreement was located at any access tier, and the security whitepaper is offered behind an on-page form rather than published openly.

Source: Vendor PublishedAs of Sep 4, 2026

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Not addressed

No located public material addresses court disclosure or verification certification.

No located public material addresses court disclosure or verification certification. No audit trail or activity export is described on any surface, the model behind a given answer is not disclosed to the customer, and no record of human verification is mentioned. The product is a corporate contract intelligence system rather than a litigation tool, so the question bites weakly, but nothing published answers it. Searched the home page, the three layer pages, the security page and the SaaS terms on 4 September 2026.

Source: Operator VerifiedAs of Sep 4, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 4, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746