Frequently asked questions
Everything you need to know about ContractShield. Can't find what you're looking for? Our AI assistant is always available to help.
ContractShield is an AI-powered contract platform that analyzes contracts clause-by-clause against your company's configured risk tolerance. It generates risk scores, suggests redlines with tracked changes, and produces ready-to-send response letters — turning days of legal review into minutes of oversight. It can also draft new first-party contracts on your paper from that same risk posture (see the AI Contract Drafting section below).
Three steps: (1) Set up your Company Profile under Company Profile in the admin sidebar — add your company name, logo, and branding. (2) Configure your Risk Posture at the Risk Posture page — define what's non-negotiable, negotiable, and acceptable. (3) Upload your first contract at Contracts → Upload Contract. The AI reads it end to end and returns a clause-by-clause analysis, usually in a couple of minutes.
ContractShield accepts PDF (.pdf), Microsoft Word (.docx), and plain text (.txt) files. Maximum file size is 50MB. For best results with the auto-redline feature, upload DOCX files — PDFs are converted automatically but may lose some formatting.
Most contracts finish in one to three minutes. Long or unusually dense agreements can take up to about five, and very long documents (50+ pages) are processed in chunks, which adds time. The model reads the entire agreement before it writes any analysis, so the first stretch of the progress bar is deliberate reading rather than a stall — the progress panel names the stage it's in throughout. The review runs on our servers, not in your browser: you can close the page or start something else, and you'll get a notification the moment it's done.
You need at least a basic risk posture configured for the AI to evaluate contracts against. Without one, the AI has no baseline to determine what's acceptable vs. risky for your company. You can start with the guided questionnaire — it takes about 10 minutes.
A few common signals: reviewers cannot quickly find previously approved contracts or clause language; customer, product, or vendor details get re-keyed into every new agreement; internal approvals route by forwarded email with no record of who approved what; you cannot search the full text of executed contracts; renewal dates live in a spreadsheet someone has to remember to update. If three or more of those sound familiar, automation is likely past due. The /why-automate page walks through a fuller self-assessment by lifecycle phase (Create, Commit, Manage).
ContractShield runs on Claude Opus 5 from Anthropic. The same model powers contract review, redline generation, AI drafting, and the in-app assistant.
Opus 5 is a reasoning model: on a contract review it works through the agreement before it writes any analysis, which is what lets it weigh a long document against your risk posture rather than pattern-matching clause by clause.
Your contract content is never used to train it — Anthropic's API terms exclude API content from model training. If your platform administrator configures a different model, the in-app assistant will tell you which one is actually running; it reads the live configuration rather than a fixed answer.
Each clause is evaluated against your risk posture and assigned one of four classifications:
- Hardline Violation — Directly conflicts with your non-negotiable terms. Must be changed.
- Gray Area — Falls in a negotiable zone. May need changes depending on context.
- Possible Give — Acceptable risk. You could concede this point during negotiations.
- Within Tolerance — Fully acceptable. No action needed.
The risk score is a number from 1–100 (100 = highest risk) that represents the overall risk level of the contract. It's calculated based on the number and severity of clause classifications. A score under 30 is generally low risk (green), 31–60 is moderate (yellow), 61–80 is high (orange), and 81–100 is critical (red).
A Limitation of Liability clause caps the maximum amount one party can be required to pay the other for damages arising from the contract. Common elements include: (1) an aggregate cap (e.g., "not to exceed 1x contract value"), (2) exclusions of certain damage types (consequential, punitive, incidental), and (3) carve-outs for specific situations like willful misconduct or IP infringement.
An indemnification clause requires one party to compensate the other for losses caused by specified events (like negligence or IP infringement). Key considerations: Is it mutual or one-way? Is it capped? What triggers it? Does it include a duty to defend? ContractShield evaluates indemnification terms against your configured tolerance for each of these factors.
Force Majeure ("superior force") is a clause that excuses performance when extraordinary events occur beyond either party's control — natural disasters, pandemics, war, government actions, etc. Key negotiation points: What events qualify? How long before either party can terminate? Does it include supply chain disruptions? Is pandemic/epidemic explicitly listed?
A non-compete clause restricts one party from engaging in competing business activities during and after the contract term. Enforceability varies by state. Key factors: duration (typically 6–24 months), geographic scope, and definition of "competing." ContractShield flags non-competes based on your configured maximum acceptable duration and scope.
ContractShield supports MSA, SOW, NDA, Amendment, Subcontract, Vendor Agreement, and Lease (commercial lease) contract types. Each type gets specialized analysis — for example, commercial leases are evaluated for lease-specific risks like NNN/CAM obligations, rent escalation terms, tenant improvement allowances, personal guarantees, holdover penalties, and assignment/subletting restrictions, in addition to the standard risk categories.
When reviewing a commercial lease, the AI evaluates additional lease-specific risk categories:
- Rent & Escalation — Base rent, CPI vs. fixed escalation, escalation caps, NNN pass-throughs, and CAM charges.
- Tenant Improvements — TI allowance amount, disbursement terms, build-out approval process, and improvement ownership upon termination.
- Use & Exclusivity — Permitted use restrictions, exclusive use clauses, and co-tenancy requirements.
- Assignment & Subletting — Transfer restrictions, consent standards (sole discretion vs. reasonable), and recapture rights.
- Maintenance & Repairs — Structural vs. non-structural allocation, HVAC, roof, and capital expenditure pass-throughs.
- Holdover & Renewal — Holdover rent multiplier, renewal option terms, and right of first refusal.
- Personal Guarantee — Scope, duration, cap, and burn-off triggers.
These are evaluated alongside the standard risk categories (Liability, Payment, Insurance, Termination, etc.).
Yes. ContractShield identifies whether a lease is triple-net (NNN), modified gross, or full gross, and adjusts its analysis accordingly. For NNN leases, it pays special attention to the scope of pass-through charges, CAM reconciliation and audit rights, management fee caps, and capital expenditure exclusions. It flags common landlord-favorable terms like uncapped management fees or inclusion of non-amortized capital expenditures in NNN charges.
Yes. MSA and SOW are first-class contract types in ContractShield. A review reads every clause of the agreement against your risk posture and classifies it as Hardline Violation, Gray Area, Possible Give, or Within Tolerance — with particular attention, in a typical MSA, to limitation of liability, indemnification, payment and auto-renewal terms, IP ownership, termination rights, warranties, and confidentiality. Anything outside your posture gets suggested replacement language exported as a real Word tracked change, plus response language you can send to the vendor. SOWs and amendments are reviewed as their own documents, and version comparison shows how terms moved between negotiation rounds.
Yes. NDA is a first-class contract type, and the same clause-by-clause review applies — with the usual NDA traps surfacing in the classification: overbroad definitions of confidential information, perpetual survival terms, residuals ("unaided memory") clauses, non-solicit or non-compete riders, and one-way obligations in agreements labeled mutual. Because the first pass runs unattended in a couple of minutes, clean NDAs clear quickly and reviewer time goes to the exceptions.
Yes. Upload a SaaS or subscription agreement as an MSA or Vendor Agreement contract type and it gets the full clause-by-clause review against your posture — including the terms that matter most in subscription deals: SLA remedies limited to service credits, provider rights to use customer data, auto-renewal and price-escalation mechanics, liability caps sitting next to data-breach exposure, and termination/data-return windows. After signature, the executed agreement lives in the encrypted vault with its renewal date extracted, so you get an alert before the auto-renewal window closes.
Currently, ContractShield is optimized for English-language contracts. The AI can process other languages with reduced accuracy, but risk posture matching and clause classification work best with English text.
Yes. Upload a new version of the contract (Document tab → Upload New Version), then click "Run AI Review" again. Each version maintains its own review history, and you can compare versions side-by-side using the diff view.
NIGO errors usually trace back to two things: re-keyed data (customer name, value, term, dates entered by hand) and stale templates being copied around. ContractShield addresses both. Templates and the clause library are managed in one place, so reviewers always start from current, approved language. Counterparty and contract metadata are captured once and reused across the lifecycle — review, redline, signature, and storage — so the same value is not retyped at every step. Fewer hand-offs of structured data means fewer transcription errors slowing down billing, provisioning, or revenue recognition downstream.
Auto-redline generates a Microsoft Word (.docx) file with real tracked changes — deletions shown in red strikethrough, insertions shown in new text — that you can open in Word and use the Accept/Reject buttons. It's ready to send directly to a counterparty.
- Hardline Violations get tracked changes (delete original + insert replacement) AND a Word comment labeled "⚠️ HARDLINE VIOLATION — NON-NEGOTIABLE" with the required replacement language.
- Gray Areas get tracked changes AND a comment labeled "GRAY LINE — Negotiable" with the suggested replacement.
- Possible Gives get a Word comment only (no tracked change) noting the risk and suggested alternative language.
- Within Tolerance clauses pass through unchanged.
Yes, two ways: (1) Use the in-browser Editor tab to accept/reject AI suggestions directly, then export. (2) Download the .docx file, open in Microsoft Word, and use Word's Track Changes tools to accept, reject, or modify individual changes.
All AI-generated tracked changes and comments are authored by "ContractShield AI" so they're easily distinguishable from human edits when the counterparty receives the document.
Yes. The Draft page (in the Work section of the sidebar) generates first-party contracts on your paper. The AI drafts from your active risk posture (hardline rules get your ideal language; concession areas get moderate language), your Company Profile's legal defaults (governing law, entity details, signature block), and clause language your legal team has approved in the Clause Library. You can name a counterparty, enter one-off party details, or draft with placeholders for reuse as a template.
AI drafting is a metered feature, separate from AI reviews:
- Free trial — 2 AI drafts
- Starter — 15 AI drafts/month
- Professional — 60 AI drafts/month
- Business — 150 AI drafts/month
- Enterprise — Unlimited
Every successful generation run counts against the allowance — regenerating a draft counts again, while failed generations never do. Saving a finished draft to Contracts additionally counts against your plan's contract limit, just like an upload. Current usage is always visible on the Draft page and the Billing page.
No. An AI-generated draft is a machine-generated starting point, not legal advice. It can contain errors, omissions, or terms unsuitable for your jurisdiction or deal. Review every draft, run the built-in posture compliance check, and have a licensed attorney review the document before sending or signing it. ContractShield is not a law firm and no attorney-client relationship is created by using it.
Yes. Admins can save any finished draft as an internal template, or as the org standard for its contract type. The org standard becomes the default skeleton every future draft of that type starts from — and it's stamped with the risk posture version it was generated against, so the Draft page warns you when your posture has moved on and the standard is worth regenerating.
The draft becomes a normal contract (version 1 is the drafted document, marked "AI drafted") and follows the standard lifecycle — you can run an AI review on it, negotiate rounds, export redlines, and send it for e-signature exactly like an uploaded contract.
Your risk posture is a structured set of rules defining your company's contract risk tolerance across categories like Liability, Payment Terms, IP, Termination, Insurance, Warranty, Lease & Property, and more. Each rule is classified as Hardline (non-negotiable), Gray Line (negotiable with conditions), or Possible Give (can concede). The AI uses this posture to evaluate every contract consistently.
Two methods: (1) Guided Questionnaire — answer 8–10 questions per category across 10 risk categories, setting each answer's tier. (2) Document Upload — upload a legal playbook or risk matrix, and the AI extracts structured rules from it. You can use one or both methods.
Yes. Hover over any rule to see edit/delete icons. Click the pencil to edit that single rule inline. Or use "Edit Full Posture" to review and edit all rules at once. Both create a new version to preserve audit history.
Yes. Every change creates a new version (v1, v2, v3...). Historical reviews always reference the posture version they were evaluated against. You can view and reactivate any previous version from the Posture History section.
Two mechanisms. (1) Risk posture is centralized and versioned — when legal updates a rule, every new review uses the new version automatically, and historical reviews still show which posture version they were evaluated against. (2) Templates and clause library entries are managed in-app rather than in scattered Word docs. Approved entries can be flagged as "Approved" so reviewers can immediately see which language has been vetted. The result: reviewers stop drafting from a copy of a copy of last quarter's template.
The Clause Library is a repository of reusable, battle-tested clause language that grows with every contract you review. Think of it as your company's institutional knowledge for contract negotiations — proven language that's been tested in real deals.
During contract review, click "Save to Library" on any clause that has suggested replacement language. It auto-populates the title, category, text, source contract, and risk tier. You can also manually create clauses from the Clause Library page.
Admins can mark clauses as "Approved" to indicate the legal team has vetted and approved that specific language. This helps reviewers quickly identify which clause alternatives have been officially sanctioned.
The dashboard opens with a daily briefing and a work queue of every open contract session, plus a pulse strip of four portfolio metrics — total contract value this quarter, active contracts, average risk score, and the share of AI suggestions accepted — each with its trend versus the prior period.
Below the pulse strip, four cards summarize the portfolio: a Risk Posture dial with a severity breakdown, a Pipeline view of active contracts by journey stage (click a stage to filter), a live AI Review Queue, and an Activity feed covering the last 24 hours across your team.
You can export the contracts list as CSV from the Contracts page using the "Export CSV" button. This includes title, counterparty, type, priority, status, value, due date, and reviewer.
Yes. Because every executed agreement is searchable at the full-text level (not just by filename or metadata), you can answer portfolio-level questions in seconds: which contracts are up for renewal in the next 90 days, which counterparties show up across multiple business units, where you have inconsistent terms with the same vendor, and which agreements auto-renew unless someone acts. Renewal and expiration dates surface in the dashboard and in notifications, so opportunities to renegotiate, consolidate vendors, or let a contract lapse stop hiding in folders nobody opens.
- Admin — Full access: manage users, configure risk tolerance, manage all contracts, view audit logs, set priorities, manage departments.
- Reviewer — Upload contracts, trigger AI reviews, view assigned contracts, add manual notes/redlines, approve/reject clauses.
- Staff — Upload contracts, view contracts in their department, read AI results, add comments. Cannot trigger AI reviews or change priority.
- Public — Read-only dashboard: see the contract queue, priority levels, status. No access to contract contents.
Admins can invite users from the Users page (sidebar → Users → Invite User). Enter their name, email, a temporary password, role, and department. They'll be able to log in immediately with those credentials.
- Starter ($299/month) — 50 contracts/month, 5 users, 50 AI reviews/month, 15 AI contract drafts/month, full risk posture engine, auto-redline, clause library.
- Professional ($799/month) — 200 contracts/month, 20 users, 200 AI reviews/month, 60 AI drafts/month, template comparison, review checklists, multi-level approvals, analytics, 25 Docusign envelopes/month with the Docusign e-signature add-on.
- Business ($1,499/month) — 500 contracts/month, 50 users, 500 AI reviews/month, 150 AI drafts/month, obligation tracking, custom workflows, API access, 100 Docusign envelopes/month with the Docusign e-signature add-on.
- Enterprise (Custom) — Unlimited contracts/users/reviews/drafts, SSO, custom integrations, dedicated success manager, Docusign e-signature included.
See the Billing page for full plan details.
Yes. Every new workspace starts on a 30-day free trial — no credit card required. The trial workspace includes 2 contracts, 6 AI reviews, 2 AI contract drafts, and 1 user, which is enough to run ContractShield against real agreements your team is reviewing right now. Separately, paid plans purchased through checkout include a 14-day trial period before the first charge.
Yes, you can change plans at any time. Upgrades take effect immediately. Downgrades take effect at the end of your current billing period.
Docusign e-signature is a $50/month flat add-on on any paid plan (included free with Enterprise). It unlocks sending agreements for signature through the built-in Docusign integration. Monthly envelope allowances come from your plan tier: 25 envelopes/month on Professional, 100 on Business, and unlimited on Enterprise.
All data is encrypted in transit (TLS 1.2+) and at rest using AES-256. Uploaded contract files are encrypted with AES-256-GCM before they touch disk, and the encryption is fail-closed: if encryption cannot complete, the upload is rejected rather than stored unprotected. Access is controlled via role-based permissions with full audit logging, and we do not train AI models on your contract data.
Yes. ContractShield offers two MFA methods: one-time codes emailed to your verified address at sign-in (no app required), or TOTP authenticator apps such as Google Authenticator, Authy, and 1Password. TOTP secrets are encrypted at rest, backup codes are single-use and stored only as hashes, and code verification uses constant-time comparison. Anyone can enable MFA from Account Settings with one click.
No. Contract content sent to our AI provider (Anthropic) is excluded from model training under standard API terms. Your contracts never become training data, and we do not sell or share your data with third parties for advertising or analytics.
Only users with the appropriate role and department access can view contract contents. Public role users can only see the queue metadata (title, status, priority) — not the actual contract text or AI analysis. All access is logged in the Audit Log. Uploaded files are never served as public static files — every download passes through an authenticated, organization-scoped route.
Yes. Every action in ContractShield is logged: uploads, reviews, status changes, clause overrides, user changes, posture edits, and more. Audit entries capture the actor, timestamp, action type, affected record, and IP address, and the logging is designed around SOC 2 Common Criteria (CC6.1, CC7.2). Admins can view the full audit log at Audit Log in the sidebar.
Still have questions?
Our AI assistant is available 24/7 — it knows the product, the plans, and the security model.