Summize
Summize is a contract intelligence system for in-house legal teams that works inside the tools a business already uses rather than asking people to move into a new platform. It runs in Outlook, Teams, Slack, Gmail, Word, Salesforce, HubSpot and Jira, so a salesperson can check renewal terms without leaving Salesforce and a request can be raised without leaving Teams. The product is organised in three layers: a Knowledge Layer holding playbooks and policies, a Contract Operations Layer covering the lifecycle from first request to signature, and an agentic AI layer called SIA, or Summize Intelligence Agents, which answers contract questions across the business using that knowledge. Use cases are grouped as request, review, repository and analytics, with dedicated material for legal, sales, finance, HR and procurement teams. Summize holds ISO 27001 accreditation certified by ISOQAR under UKAS, and states that customer prompts, completions and embeddings are exclusive to each customer and are not available to OpenAI or used to improve OpenAI models. Its published subscription agreement separately permits Summize to use Customer Data in aggregated, anonymised form to improve the software through machine learning analysis. The agreement carries an intellectual property indemnity, a warranty that the software will be free from material errors and defects, and liability caps set as the greater of a fixed sum or a multiple of charges. There is no published price. Summize Ltd is a UK company and the agreement is governed by English law.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of a core capability layered on a product that stands without them. Summize publishes its own three-layer architecture and only the third is AI: a Knowledge Layer holding playbooks and policies, a Contract Operations Layer running the lifecycle from first request to signature inside existing tools, and an agentic AI layer, SIA, described as surfacing that knowledge as instant answers. Remove SIA and a working contract request, repository and operations system remains, embedded in Outlook, Teams, Slack and Salesforce. The vendor's own framing of the layers as distinct, each one powering the next, is what settles this. Checked 4 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted without measurement. SIA is described as providing instant, reliable answers grounded in the customer's own knowledge and standards, which identifies the grounding source as the Knowledge Layer of playbooks and policies but describes no retrieval method behind it. The security page states that on a consistent basis Summize evaluates the effectiveness, quality and security of its AI models, which is an assessment practice asserted with no published result, no test set, no cadence and no scope. No accuracy figure appears anywhere. No failure mode is named on any surface: hallucination is not discussed, and the published performance figures are all speed and volume rather than correctness. Searched the home page, the security page, the AI layer page, the website terms and the SaaS terms on 4 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Oversight is asserted as a slogan rather than described as a mechanism. The positioning is explicit that the business becomes more self-sufficient while legal remains in full control, and that queries which used to reach legal's inbox are answered instantly by the people who needed them. Nothing published says what SIA answers alone versus what a lawyer approves, no threshold is stated, no review surface is described, and nothing addresses what happens when an answer is wrong. The phrase legal remains in full control is the whole of the oversight position, which is the case this band describes. Searched the home page, the AI layer page, the security page and the SaaS terms on 4 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Real deployment evidence with substance, short of measurement tied to a named customer. Named customers carry attributed quotations and dedicated case study pages: Steven McGeagh at Huel on ease of adoption, Julia Trius at Edpuzzle on receiving agreements already in the required format, and Derek Ihnen at Boon Edam on reduced review time. Logos include Revolut, SeatGeek, Miami Heat, Matillion, Sigma Computing, CodeRabbit, KSE and IPC Systems. Figures are published and specific: three times faster contract creation, 40 per cent reduction in deal length, 50 per cent reduction in processing time, six times more contracts reviewed, and two minutes against two hours for an NDA. One figure carries an independent method, a 4,062 per cent ROI attributed to Nucleus Research, which is a named analyst firm rather than an internal claim. Held at B because none of the figures is tied to any of the named customers, none carries a date, and the case study pages were not opened in this pass, so they are credited for existing rather than for their contents.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments, and the agreement is readable, which is why this sits above the assertion band. Clause 6.1 grants Summize a licence to store, transmit and process Customer Data solely as necessary to provide the services and states that nothing in the agreement grants any other rights in it. Clause 6.2 requires physical, technical and organisational measures aligned with good industry practice, clause 6.5 imposes confidentiality with named exceptions, clause 6.6 requires daily encrypted backups available to the customer on request, and clause 9.2 requires prompt deletion or return of all Customer Data at the customer's option on termination. The position on the model provider is explicit rather than inferred: customer prompts, completions, embeddings and training data are stated to be exclusive to each customer and not available to OpenAI or used to improve OpenAI models. Three limbs are unmet. Training is permitted rather than prohibited, because clause 6.4 reserves the right to use Customer Data in aggregated, anonymised form to improve the software through machine learning analysis. Segregation is asserted as siloed AI with no published detail on enforcement. And privilege and work product are not addressed anywhere, which is defensible for a product whose buyer is a corporate department rather than a firm but is still absent.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Nothing published addresses the advice line for a product explicitly sold to people who are not lawyers. Summize markets contract answers to sales, finance, HR and procurement teams, states that queries which used to find their way to legal's inbox are taken care of, and gives the example of a salesperson checking renewal terms and a CFO querying payment performance without involving legal. Against that, no statement anywhere says what the output is and is not, no disclaimer distinguishes information from legal advice, no competence or supervision language appears, and no jurisdiction limit is stated despite customers in both the UK and the US. This grade rests on a document that was read rather than on a gap that could not be tested: the SaaS terms and conditions were retrieved in full on 4 September 2026 and contain warranties, indemnities and liability caps but no advice-line provision at all. The website terms of use likewise disclaim only the website. The nearest thing to a position is the marketing line that legal remains in full control, which is about workflow rather than about advice.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Principles are published without a mechanism a buyer could audit. The security page sets out four AI commitments: siloed AI practices, regular assessments of effectiveness, quality and security, ongoing updates to AI capabilities, and a customer feedback loop. Each is a sentence. No owner inside Summize is named as accountable for AI outcomes, no pre-release testing regime is described, no assessment result is published, and there is nothing whatever on bias or uneven output across contract types or counterparties. The company publishes an EU AI Act explainer written by its own General Counsel, which is regulatory commentary for the reader's benefit rather than a disclosure of Summize's own governance. ISO 27001 is an information security standard and does not answer this axis.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy covering most of the ground. Deletion is contractual and specific: clause 9.2 requires Summize to promptly delete or return all Customer Data at the customer's option on termination, with retention only where law requires and continuing confidentiality obligations over anything retained. Clause 6.6 requires backups no less frequently than daily, secure and encrypted, in a commonly used machine-readable format and available to the customer on request. Access control rests on ISO 27001 with DevSecOps practices and internal password, equipment and data confidentiality policies described, and clause 3.2 gives an annual audit right over user and password compliance. Regular third-party penetration testing is stated. Two elements of the set are missing: no retention period is stated for the term of the agreement, only for its end, and no subprocessor list is published, with Appendix 3 referenced in clause 8.4 as defining Sub-Processors but not rendered in the published document.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
The strongest liability position located in this pull, and all of it readable before signing. Clause 7.2 gives the customer an intellectual property infringement indemnity covering claims, liabilities, losses, damages and reasonably incurred costs, with a single named carve-out at 7.3 for unapproved combinations, and 7.4 sets out the conduct-of-claim mechanics including that Summize may not settle without unconditionally releasing the customer. The caps are set as a floor rather than a ceiling, which is unusual and materially better for a smaller buyer: clause 8.3 caps general liability at the greater of 100,000 pounds or 150 per cent of total charges, and clause 8.2 sets a separate super-cap for breach of the security and data protection obligations at the greater of 500,000 pounds or 500 per cent of total charges. Clause 8.1 preserves liability for wilful misconduct and anything not excludable by law, and 8.4 makes Summize liable for its subcontractors and sub-processors as if their acts were its own. Warranties are real and invocable: clause 3.6 warrants the software will comply with its specification in all material respects and be free from material errors and defects, 3.5 requires reasonable skill, care, diligence and foresight, 3.8 warrants against malicious code on an ongoing basis, and 7.1 warrants Summize holds the rights needed to supply the service. No insurance position was located. Notably there is no disclaimer of output accuracy in this agreement, unlike several peers.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The integration set is the product's central claim and it is documented rather than listed. Named targets are Outlook, Microsoft Teams, Slack, Gmail, Microsoft Word, Salesforce, HubSpot and Jira, plus Summize Sign for e-signature and a Claude integration, each with its own dedicated page. What each integration surfaces is described concretely rather than as a logo: a salesperson checking renewal terms inside Salesforce, a CFO querying payment performance across the supplier base, contract context and assistance available in the tool without a new login to manage. The positioning is explicit that there is no separate platform to adopt, which is a statement about direction of travel between systems. Configuration effort is published too: implementation runs in sprints of three to four weeks under a named HERO methodology with in-house implementation staff, typically fully rolled out within twelve weeks. The individual integration pages were not opened, so the grade rests on the named set, the described in-tool behaviour and the published implementation model rather than on their contents.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Neither limb is stated for the platform. The only hosting location published anywhere is in the website terms of use, which state that the Website is hosted on servers located in the United Kingdom; that governs the marketing site rather than the software, and a website term does not grade the platform. For the platform itself the home page says data never leaves your environment and the FAQ says it is built on Azure enterprise-grade infrastructure, which names the infrastructure provider without naming a region and without stating where customer contract data is stored. Tenancy is not addressed: siloed AI describes the handling of prompts and embeddings rather than a tenancy model, and no material states whether the platform is single or multi-tenant. Searched the home page, the security page, the website terms and the SaaS terms on 4 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real and stated, and better identified than most records in this band: the ISO 27001 badge names ISOQAR as the certification body and UKAS as the accrediting body, so a buyer can in principle verify the claim against a third party's register rather than take the vendor's word for it. That is the limb most records on this axis miss. What is missing is the rest of the accessible evidence: no certificate number, no scope or statement of applicability, no issue or expiry date, no trust portal, and no route to obtain a report. Penetration testing is described as regular and third-party with no firm named and no dates. A security whitepaper authored by named CTO Richard Somerfield is offered behind an on-page form, which is a request flow rather than open publication. One point stated plainly because the page states it plainly: **SOC 2 is not held.** Summize says it audits infrastructure in line with standards including SOC II and that it intends to investigate and work towards SOC II accreditation in the future, which is intent and is credited to nothing.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Providers are named without change notification, which is this band's first limb. OpenAI is identified explicitly and in a form that tells a buyer something useful: customer prompts, completions, embeddings and training data are stated not to be available to OpenAI or used to improve OpenAI models, which both names the provider and states what it may not do. The FAQ adds that SIA is built on Azure enterprise-grade infrastructure, which locates the deployment. What is absent is the rest: no specific model or model version is named, no commitment to notify customers when a model or provider changes was located, and no subprocessor register is published, with Appendix 3 referenced in the agreement as defining Sub-Processors but not rendered in the published text.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The unit and structure are stated without the figure, and unusually the evidence sits in the published agreement rather than on a pricing page, because there is no pricing page anywhere in the navigation or footer. The SaaS terms define the Order Form as setting out user numbers and type of software licence, which publishes the unit of charge as per-user by licence type. The term structure is published: an initial term with automatic renewal for successive twelve-month periods and 90 days written notice to prevent renewal. So is the escalation: clause 2.2(b) caps any renewal increase at 10 per cent over the preceding twelve-month term for the same plan, tier and package unless a higher cap is agreed, which is a real commercial protection a buyer can read before contracting. Payment terms are 30 days from a valid invoice, fees are exclusive of VAT and sales tax but inclusive of other taxes, and expenses require prior written approval. No figure, band, tier name or feature split is published anywhere.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is described with substance and the boundary is left open. Five buying teams each carry a dedicated page: Legal, Sales, Finance, HR and Procurement. Eight sectors each carry their own page: Software, Sports, Finance, Manufacturing, Business Services, Media and Internet, Retail and Telecommunications. Four use cases are published as request, review, repository and analytics, and NDAs are named as a specific contract type with a stated handling time. The buyer is a corporate in-house function rather than a law firm, and law firms are neither claimed nor excluded. What is missing is the edge: no organisation size is stated, no contract types beyond NDAs are enumerated as supported, government use is not addressed, and nothing says where the product stops.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The published agreement expressly reserves a right to train on customer content, with no opt out located. Any de identification, anonymisation or aggregation qualifier is recorded in the summary.
Clause 6.4 of the published SaaS terms expressly reserves the right, notwithstanding the security and data protection clauses that precede it, to use Customer Data in aggregated, anonymised form to improve the Services or Software by automated decision processing or machine learning analysis. The clause names machine learning and operates on Customer Data, which is what this value turns on, and the de-identification qualifier is recorded here rather than treated as removing the permission. Both sides are recorded because they are reconcilable rather than contradictory on a careful reading: the home page promises a contractual guarantee that data is never used to train external models, and the security page states that customer prompts, completions, embeddings and training data are not available to OpenAI or used to improve OpenAI models. Those statements are about third-party models. Clause 6.4 permits Summize's own machine learning analysis on aggregated, anonymised Customer Data. A buyer reading only the marketing would not expect clause 6.4, and a buyer reading only clause 6.4 would not know the external-model position is stronger.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is acknowledged in public materials with no stated period.
Retention is acknowledged in the published agreement without a stated period. Clause 6.6 requires Summize to perform and maintain backups of all Customer Data no less frequently than daily, secure and encrypted, in a commonly used machine-readable format and available to the customer on request. Clause 9.2 addresses the end of the relationship, requiring prompt deletion or return of all Customer Data at the customer's option on termination, with retention permitted only where and for as long as law requires and continuing confidentiality over anything retained. Nothing states how long prompts, outputs or uploaded contracts are held during the term, and no configurable retention window is described.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Segregation is asserted in public materials with no published detail on how it is enforced.
Segregation is asserted in public materials without published detail on how it is enforced. The security page describes siloed AI practices under which customer prompts, completions, embeddings and training data are available exclusively to that customer and not to other customers, and the home page FAQ repeats it as a siloed AI approach keeping each customer's prompts, data and outputs exclusive to them. No material describes the isolation mechanism, the tenancy model, or how access is administered beyond the agreement's user and password provisions, and nothing addresses separation between matters or contract sets inside a single customer.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.
Clause 6.5 of the SaaS terms requires both parties to keep the other's confidential information, expressly including Customer Data, confidential and not to disclose it to any third party unless required by applicable law or regulation, permitted in writing by the other party, or the information has become public without default. Compelled disclosure is therefore addressed directly. No commitment to notify the customer of such a request was located anywhere, and no discretion over notice is reserved either. Searched the SaaS terms, the website terms of use and the security page on 4 September 2026; the agreement notes that a separate confidentiality agreement, if the parties have one, takes precedence over clause 6.5, and no such template is published.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
No located public material identifies an external corpus, and the product's design makes the question narrow. Summize grounds its answers in the customer's own Knowledge Layer of playbooks and policies and in that customer's contract repository, rather than retrieving primary law. No external database, publisher or content licence is named on any surface and no jurisdictional coverage is claimed. Searched the home page, the three layer pages, the security page and the SaaS terms on 4 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Nothing on any located surface addresses whether authority is checked for subsequent history. The product does not retrieve primary law: it operates on the customer's own contracts, playbooks and policies to answer contract questions and run the contract lifecycle. The question therefore does not bite on this product class and the honest value is the absence rather than a penalty. Searched the home page, the three layer pages, the security page and the SaaS terms on 4 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
No located public material addresses what the product does when it cannot ground an answer. SIA is described as providing instant, reliable answers grounded in the customer's own knowledge and standards, which is a claim about the normal case rather than the failure case. No abstention path, no no-answer behaviour and no confidence or grounding score visible to the user is described, and hallucination is not discussed anywhere including on the dedicated security page. Searched the home page, the AI layer page, the security page and the SaaS terms on 4 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
The AI Hallucination Cases database maintained by Damien Charlotin was searched on 4 September 2026 on the product and company name Summize. No court order, opinion or disciplinary record naming the product was located. This records the state of the public record on that date and is not a finding about the product.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No located public material engages with bar or ethics guidance. Summize publishes an explainer on the EU AI Act written by its own General Counsel, which is commentary on a regulation for the reader's benefit rather than engagement with professional responsibility guidance about the vendor's own product, and no bar association, law society, regulator or ethics opinion is named on any surface. The buyer is a corporate in-house function rather than a regulated practitioner in private practice, which explains the absence without changing it. Searched the home page, the security page, the layer pages, the website terms and the SaaS terms on 4 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Public materials claim time and cost savings without addressing billing or disclosure. Published figures include three times faster contract creation, a 40 per cent reduction in deal length, a 50 per cent reduction in contract processing time, six times more contracts reviewed, two minutes against two hours for an NDA, and a 4,062 per cent return on investment attributed to Nucleus Research. Nothing addresses what happens to a bill when AI-assisted work compresses the time it takes, and no per-matter record of AI-assisted work is described. The buyer is an in-house department rather than a firm billing a client, which is the inverse of the direction this signal assumes.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
A model provider is named openly on the public security page, which states that customer prompts, completions, embeddings and training data are not available to OpenAI or used to improve OpenAI models, and the home page FAQ adds that the system is built on Azure infrastructure. That is a statement about who touches customer content, reachable without a sales conversation. What is not published is a subprocessor register or a forwardable client-facing pack: Appendix 3 is referenced in clause 8.4 of the SaaS terms as defining Sub-Processors but is not rendered in the published document, no data processing agreement was located at any access tier, and the security whitepaper is offered behind an on-page form rather than published openly.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located public material addresses court disclosure or verification certification.
No located public material addresses court disclosure or verification certification. No audit trail or activity export is described on any surface, the model behind a given answer is not disclosed to the customer, and no record of human verification is mentioned. The product is a corporate contract intelligence system rather than a litigation tool, so the question bites weakly, but nothing published answers it. Searched the home page, the three layer pages, the security page and the SaaS terms on 4 September 2026.