Contract Management (CLM)
ContractHero
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 2 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by ContractHero GmbH · www.contracthero.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
ContractHero is a web-based contract-management platform from ContractHero GmbH in Halle (Saale), strongest on integration and exit and weakest on pricing transparency, where every tier is 'Auf Anfrage'. Named integrations include SAP, MS Dynamics, Salesforce, HubSpot, SharePoint, DocuSign, PowerBI and Lucanet, with an open REST API and webhooks, and the terms promise all customer data for download at termination. Repository and obligations scores 5-6, built on OCR full-text search that respects role permissions and a calendar consolidating notice periods, end dates and task deadlines. AI extraction control is the most settled score at 4: the pipeline from OCR to prompt is documented, prompts are customer-editable with a test button, and each AI-filled field links to its source — yet no model provider is named and we found no public information on where AI and OCR processing run. Negotiation and approval scores 4-6; authoring and templates 3-4. Sovereignty splits 4-6: judges crediting the German entity and the German hosting claim score high, those focused on the unnamed commissioned service provider and the website-only privacy policy score low.
Speaks for it
- Named integrations across SAP, MS Dynamics, Salesforce, HubSpot, SharePoint, DocuSign, PowerBI and Lucanet, with an open REST API and webhooks
- Multi-stage approval groups with conditions on category, team, status and contract value, every approval and rejection logged with timestamp and person
- AI-filled fields linking to their source passage, with customer-editable prompts, a test-in-contract button and re-analysis that never overwrites values
- OCR full-text search covering scanned contracts within role and team permissions, with notice periods and end dates consolidated in one calendar
- A contractual promise that all customer data is supplied for download in a readable, editable format on termination
Held against it
- Prices given only 'Auf Anfrage' — no base-fee, onboarding or add-on figure published, so no annual cost is computable from public pages
- We found no public information naming the AI or OCR model provider or where contract text is processed
- We found no public information on redlining, version comparison or counterparty access, and only organisation members can be assigned as approvers
- The published privacy policy covers website services only, while the terms permit storage with an unnamed commissioned service provider
- Drafting evidenced as templates and a Word add-in, with no public information on clause libraries, fallbacks or conditional logic
Best for
- You need a central contract repository with OCR full-text search over scanned documents and a calendar of notice periods, end dates and task deadlines
- Your stack runs on SAP, MS Dynamics, Salesforce, HubSpot, SharePoint or DocuSign and you want an open REST API plus a contractual exit path
- You run internal approval chains with value thresholds and need each approval and rejection logged with timestamp and person
- You want AI extraction your team can verify field by field, with prompts tested against real contracts before activation
Avoid if
- You must put an annual cost into next year's budget without a sales conversation — no price figure is public
- You need to negotiate and redline drafts with counterparties inside the system — the captured evidence covers internal approval only, and external people cannot be assigned as approvers
- Your data-protection review requires a published product subprocessor list and a product DPA before award — the captured privacy policy covers website services only and the terms permit an unnamed commissioned service provider
- Your legal team expects governed drafting with approved clause libraries, fallbacks and playbook checks rather than templates and a Word add-in
The scores
Negotiation, redlining & approval
Show reasoningHide reasoning
How this is scored
Getting from draft to agreed text with a counterparty and through internal sign-off: redlining in Word and in the browser, external collaboration, version comparison, approval workflows, and a record of who approved which version.
0 — No negotiation support; versions are emailed back and forth outside the system.
3 — Comments and a version list inside the system, but no redline comparison, no Word round-trip, and approvals handled by email.
5 — Redlining with tracked changes, a Word add-in or round-trip that keeps changes, counterparty access without a licence, version comparison, and configurable approval steps by contract type or value.
8 — Conditional approval routing (value, deviation from playbook, risk), parallel and sequential approvers with delegation, an audit trail of every change and approval per version, and internal comments kept separate from what the counterparty sees.
10 — Negotiation is an auditable record: every concession traceable to who proposed and who approved it, approval rules an auditor or the board can read, negotiation duration reported per contract type, and the full history exportable with the signed version.
The General Counsel
The approval machinery is real and well documented: ordered multi-step approval groups with conditions on category, team, status and contract value using comparison operators, delegation-style groups, rejection stopping the flow with a stated reason, and every approval and rejection recorded with timestamp and person in a change log. But we found no public information on redlining, version comparison or counterparty access — external approvers are explicitly excluded — so the Word round-trip with opposing counsel happens outside the system. 2 8 9
The Procurement Analyst
Internal sign-off is properly modelled: approval rules gate signature and deletion, conditions span category, team, status and amount fields with equals and greater-than operators, approval groups are ordered with any one member completing a step, rejection stops the flow with a reason, and every approval and rejection is recorded with timestamp and person in a change log. Negotiating with the counterparty is where the evidence stops: we found no public information on redlining, tracked changes, version comparison or counterparty access, and the help centre states only organisation members can be assigned as approvers. 2 8 9
The Sales Ops Owner
Approval routing is close to what I need: rules fire on category, team, status and amount fields with comparison operators, run through ordered groups where one member's sign-off completes a step, and every approval and rejection is recorded with timestamp and person. The negotiation half is unevidenced though — we found no public information on redlining, tracked changes, counterparty access or version comparison — so getting a draft to agreed text with a customer still happens outside the system. 2 8 9
The IT Integrator
Internal sign-off is solidly built: rules triggered by signature or deletion, conditions on category, team, status and amount fields with comparison operators, ordered multi-stage approval groups, and every approval or rejection recorded with timestamp, person and reason in a change log. I found no public information on redlining, tracked changes, version comparison or counterparty access — the help pages state external people cannot be assigned as approvers — so the negotiation half of the journey is unevidenced while the approval half is strong. 2 8 9
The Data Protection Officer
Internal sign-off is genuinely strong: rule conditions include contract value with comparison operators, multi-stage ordered approval groups where any member can complete a step, immediate stop on rejection, and every approval and rejection recorded with timestamp, person and, for deletions, a mandatory reason visible in the change log. Approvers must be internal members, and we found no public information on redlining, version comparison or counterparty access to negotiate a draft. 8 9 2
The Skeptic
The internal gate is well built: multi-stage approval groups with drag-drop ordering, any-member completion covering absences, conditions on contract value with comparison operators, and every approval and rejection logged with timestamp and person. But it gates signing and deletion, not negotiation — approvers are restricted to organisation members, and we found no public information on redlining, tracked changes, version comparison, or a Word round-trip that keeps them. 2 8 9
Repository, deadlines & obligations
Show reasoningHide reasoning
How this is scored
Knowing what has been signed and what it requires: a searchable repository with metadata, notice periods and renewal dates captured and reminded, obligations tracked to an owner, access rights by department, and reporting on the portfolio.
0 — A file store with folders; no metadata, no dates and no reminders.
3 — Metadata fields and an end date with an email reminder, but notice periods and auto-renewal are not modelled and reminders go to one person.
5 — Notice periods, renewal terms and end dates modelled as fields, reminders with escalation to named owners, full-text search including scanned contracts (OCR), and access rights per department or contract type.
8 — Obligations and milestones tracked with owners and status, contract hierarchies (framework, amendments, orders) linked, reminders logged so a missed deadline can be traced, and portfolio reports on renewals, value and counterparties.
10 — The repository is a system of record a company can be audited on: every deadline derived from a cited clause, reminders and their acknowledgements logged, retention and deletion rules per contract type, and a portfolio view a CFO can use for commitments and cancellations.
The General Counsel
Notice periods, end dates and renewal and deadline management are modelled and consolidated into a calendar view with task deadlines, OCR full-text search covers scanned contracts and respects per-team and per-category access rights, and contracts can be linked with attachments. We found no public information on obligations tracked to a named owner with status, on logged reminders that make a missed deadline traceable, or on portfolio reporting across renewals, value and counterparties. 1 2 10 11
The Procurement Analyst
The things I check first are evidenced: notice periods and end dates sit as first-class dates in a calendar that also carries tasks and contact deadlines, automatic deadline and renewal management is marketed as core, the AI extracts notice periods and terms with each value linked to its source passage, and OCR full-text search respects team and category permissions with per-entity separation. We found no public information on reminders escalating to a named owner, obligations or milestones tracked with owners and status, logged reminders, or portfolio reports on renewals, value and counterparties — a Reporting & Insights module is named but never detailed. 1 2 4 10 11 12
The Sales Ops Owner
The repository side is credible: a central database with full-text search that works on scanned contracts, notice periods and end dates surfaced in a calendar with reminders, contracts linkable with attachments, and search and export respecting role and team permissions. We found no public information on obligations tracked to a named owner with status, on logged reminders that make a missed deadline traceable, or on portfolio reports across renewals, value and counterparties. 1 2 10 11 12
The IT Integrator
Notice periods, end dates and terms are modelled fields that the calendar consolidates alongside task and contact deadlines, full-text search runs over scanned PDFs inside role permissions, and access separation reaches team and category level with custom fields carried into exports. Obligations tracked to a named owner, logged reminder acknowledgements and detailed portfolio reporting are where I found no public information — a Reporting & Insights module is named but not documented. 2 10 11 15
The Data Protection Officer
Notice periods, end dates and deadline/renewal management are modelled and consolidated in a calendar with month, week, day and agenda views, and full-text search covers scanned contracts via OCR while respecting role and team permissions. We found no public information on reminders escalating to named owners, obligations and milestones tracked with owner and status, or logged reminder acknowledgements, and the reporting module is named without portfolio detail. 11 10 2 1
The Skeptic
Notice periods and end dates are real fields, surfaced in a calendar together with task and contact deadlines, while OCR full-text search reaches scanned contracts in under two seconds and respects role permissions. Above that the pages go quiet: we found no public information on obligations tracked to a named owner, on reminders logged so a missed deadline can be traced, or on what the Reporting module actually reports. 1 2 10 11
AI extraction & review transparency
Show reasoningHide reasoning
How this is scored
Whether the AI that extracts dates and clauses or reviews a draft is disclosed, verifiable and controllable: named model provider and processing location, no training on customer contracts, extracted values shown with their source passage, and features the customer can switch off. A product without AI features is judged on stating so.
0 — AI extraction or review is marketed with no statement of the model, where it runs, or what happens to the contract text.
3 — AI features described as a benefit with a general privacy assurance, but no model provider named, no statement on training, and extracted values shown without their source.
5 — The model provider or subprocessor named, a stated commitment not to train on customer contracts, extracted values linked to the source passage for confirmation, and AI features that can be disabled per account.
8 — AI processing available within the EU, each AI feature documented with its purpose and inputs, accuracy or confidence shown per extracted field, review results traceable to the playbook rule that triggered them, and an EU AI Act position published.
10 — AI is an accountable assistant: customer choice of model or EU-only processing, no retention of contract text by the model provider stated contractually, every AI-suggested value logged with who confirmed or corrected it, and AI off by default until the customer enables it.
The General Counsel
Extraction is documented and controllable to an unusual degree: the pipeline from OCR through chunked reading is published, prompts and instructions are customer-authored with test-before-activate, re-analysis never overwrites existing values, and every AI-filled field links to its source passage with a verification step. But no model provider is named, there is no statement on training on customer contracts, the EU AI Act appears only as a mention on the legal notice, and we found no public information on disabling AI features per account. 3 4 12 13
The Procurement Analyst
Where the AI shows its work, it does so well: AI-filled fields carry a jump-to-source reference, a verification step is documented, prompts and instructions are configurable per field, and a test button runs a prompt against a real contract before activation. But we found no public information on the model provider or where the contract text is processed, no commitment on training with customer contracts, and the EU AI Act appears only as a word on the imprint — for a repository of confidential commitments that is trust, not control. 4 12 13
The Sales Ops Owner
Every AI-filled field links to its source passage with a jump-to-source view and a verification step, prompts are configurable per field with a test-in-contract button, and re-analysis never overwrites existing values — that is real control over extraction. But we found no public information naming the model provider, on where AI and OCR processing run, on whether customer contracts are used for training, or on switching AI features off; the EU AI Act and ISO 27001 appear as mentions. 4 12 13
The IT Integrator
The extraction pipeline is documented step by step from OCR through chunking to prompt and instruction, and AI-filled fields carry a jump-to-source link with a verification workflow and a test-in-contract button — genuinely good control for the people confirming values. But I found no public information naming the model provider, where AI and OCR processing runs, whether customer contracts are used for training, or any way to disable the AI features per account. 12 13
The Data Protection Officer
Extracted values carry a jump-to-source reference that can be verified field by field, the pipeline (OCR, layout recognition, chunking, prompt, instruction) is publicly documented, and a test-before-activate button plus re-runs that never overwrite existing values give the customer real control over accuracy. We found no public information on which model provider receives the contract text, whether that text is retained or used for training, where AI and OCR processing run, any per-account way to switch AI off, or an AI Act position beyond the term appearing — and the published privacy policy covers only the website, so the counterparties' data in every contract is not visibly covered by a product DPA. 12 13 3
The Skeptic
This is the rare tool that shows its receipts: AI-filled fields carry a jump-to-source link, the pipeline from OCR through chunking to a find-prompt and answer-instruction is documented, prompts are customer-editable with a test-in-contract button, and re-analysis never overwrites values. Everything around the model is unstated — we found no public information naming the provider, its processing location, a commitment not to train on customer contracts, per-field accuracy, or a switch to disable AI — and an MCP connector sends contract data read-only to Claude and ChatGPT with no processing location stated either. 1 12 13
Integrations, signature & exit
Show reasoningHide reasoning
How this is scored
How contracts connect to the rest of the company and leave it again: CRM, procurement and ERP integration, e-signature (and which eIDAS level), SSO, an API, and a documented export of documents together with their metadata, versions and audit trail.
0 — No integrations, no API and no stated export; contracts can only be downloaded one by one.
3 — One CRM or storage integration and a bulk download of files, but metadata, versions and audit trail stay behind.
5 — A documented API, integrations with named CRM and storage systems, e-signature integrated with the level stated (simple, advanced or qualified), SSO, and a bulk export of documents with their metadata.
8 — Maintained integrations with systems common in DACH (SAP, Microsoft 365, Salesforce, DATEV-connected or procurement tools), qualified electronic signature available, webhooks, SCIM, and an export that includes versions, approvals and audit trail in an open format.
10 — Exit is designed in: a versioned API with a deprecation policy, a documented migration path in and out with the format stated, deletion after contract end confirmed, and the full repository — files, metadata, obligations and history — handed back without a professional-services fee.
The General Counsel
An open API with webhooks, SSO, and named integrations including SAP, MS Dynamics, Salesforce, HubSpot, SharePoint and DocuSign, with the digital signature named as FES and unlimited signatures from the Professional tier. Exit is supported contractually — on termination all customer data is provided for download in a readable, editable format — though the export delivers contract data as a spreadsheet with the original PDFs as a separate bulk download, and we found no public information on exporting versions, approvals or the audit trail, or on a qualified signature and SCIM. 2 5 14 15
The Procurement Analyst
The integration list reads like my stack: SAP, MS Dynamics, Salesforce, HubSpot, SharePoint, DocuSign, PowerBI and Lucanet, with an open API and webhooks, single sign-on, and an e-signature whose designation (FES) is stated. The terms also promise that on termination all customer data and documents are supplied for download in a readable, editable format, and the bulk export covers every field including custom ones — though as xlsx metadata with PDFs via a separate download action, and we found no public information on exporting versions, approvals or audit trail, on qualified signature, SCIM, or a migration path with formats stated. 2 5 14 15
The Sales Ops Owner
Integrations hit the DACH list — SAP, MS Dynamics, Salesforce, HubSpot, PowerBI, Lucanet, SharePoint and DocuSign — with an open REST API, webhooks and SSO, and digital signature is stated as FES, an advanced level. Exit is thinner: bulk export delivers contract data as an xlsx table only, original PDFs come via a separate bulk download, and we found no public information on exporting versions, approvals and audit trail, on SCIM, or on a qualified electronic signature. 2 5 14 15
The IT Integrator
REST API and webhooks sit in Professional, custom SSO and MFA in Enterprise, SAP, Microsoft SharePoint, Salesforce, HubSpot and DocuSign are named as integrations, and the signature level is stated as FES — advanced, with qualified signature nowhere in the captured pages. As the one who migrates out: the bulk export delivers contract data as a spreadsheet only, original PDFs require a separate bulk download, and I found no public information on versions or audit trail in the export, on SCIM or on API versioning — though the terms do guarantee all customer data is made available for download when the contract ends. 2 5 14 15
The Data Protection Officer
A REST API with webhooks, named integrations including SAP, MS Dynamics, Salesforce, HubSpot, SharePoint, PowerBI and DocuSign, SSO with MFA at Enterprise, digital signatures labelled FES, and a contractual promise to provide all customer data for download in a readable, editable format on termination give a credible connect-and-leave story. Exports deliver contract metadata as an xlsx table with the original PDFs only via a separate bulk download, and we found no public information on a qualified signature option, SCIM, or an export that includes versions, approvals and audit trail in an open format. 14 2 15 5
The Skeptic
Entry points are named and DACH-relevant: open REST API with webhooks, SAP, MS Dynamics, Salesforce, HubSpot, SharePoint and DocuSign, SSO with MFA on the top tier, and signatures stated as FES, the advanced eIDAS level. Exit is thinner — the bulk export is an xlsx of contract fields including custom ones, original PDFs come only through a separate bulk download, the terms promise all customer data for download at termination, and we found no public information on exporting versions, approvals or audit history, on qualified signature, or on SCIM. 2 5 14 15
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Who the contracting entity is, where contracts and their extracted data are hosted, and who the subprocessors are — including the AI and OCR providers the text is passed to. Independently sourced by the sovereignty pipeline; weighted with care here because a contract repository holds a company's most confidential commitments and those of its counterparties.
0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and AI processing of unclear location.
3 — EU hosting offered as an option while the contracting entity is non-EU, or the subprocessor list is absent, or AI and OCR processing run outside the EU without saying so.
5 — EU hosting as standard and an EU contracting entity, but parts of the chain — AI models, OCR, email delivery, support — are non-EU without an explained safeguard.
8 — EU hosting on named infrastructure, EU contracting entity, subprocessor list published including AI and OCR providers with locations, and a DPA covering contract data as the customer's processing.
10 — Sovereign end to end and evidenced: vendor, entity, hosting and every subprocessor European, AI processing within the EU on providers the customer can see, certifications (ISO 27001, BSI C5 or equivalent) published.
The General Counsel
A German contracting entity in Halle, German hosting claimed across the pricing and homepage, and ISO 27001 and the EU AI Act mentioned on the legal notice. The captured pages give different coverage for hosting: the marketing pages state hosting in Germany while the privacy policy covers only the website — hosted in the US by Webflow with US processors such as Google Analytics and Zapier — and we found no public information on product subprocessors, including the AI and OCR providers my clients' contracts would flow through. 1 3 4 5
The Procurement Analyst
The entity, the address and the claim are German: ContractHero GmbH in Halle, hosting and development in Germany, a Berlin data protection officer, ISO 27001 and the EU AI Act named on the imprint. The chain underneath stays dark: the terms permit storage with an unnamed commissioned service provider plus a failover data centre, the privacy policy we captured covers the website only with several US processors, and we found no public information on the product's subprocessors or on where the AI and OCR that read my contracts actually run. 1 3 4 5
The Sales Ops Owner
ContractHero GmbH in Halle is the contracting entity and the marketing pages claim hosting and development in Germany, with the terms saying the software runs on servers of ContractHero or a commissioned service provider. The captured privacy policy covers the website only and names several US subprocessors there, and we found no public information on the product's own subprocessor list, on where AI and OCR processing run, or on a DPA covering contract data — which matters when the repository holds our counterparties' most confidential commitments. 1 3 4 5
The IT Integrator
A German GmbH with a commercial register entry, hosting in Germany claimed as standard and development in Germany, plus a German data protection officer and an ISO 27001 mention. What I cannot see is the product-data chain: the published subprocessor list covers website services only, the terms say the software runs on servers of ContractHero or a commissioned service provider without naming it, the captured privacy policy says nothing about product data storage, and I found no public information on where AI and OCR processing happens. 1 3 4 5
The Data Protection Officer
The contracting entity is ContractHero GmbH in Halle (Saale) with a register entry, and German hosting is claimed as standard on marketing and pricing pages; the terms, however, place the software on servers of ContractHero or a commissioned service provider without naming it. The only subprocessor list we found covers website services (several US providers such as Webflow, AWS CloudFront, Google Analytics), and we found no public information naming the hosting, AI model or OCR providers for the product, or on a DPA covering contract data — a material gap for a repository holding a company's and its counterparties' most confidential commitments. 4 1 7 3 5
The Skeptic
A German GmbH in Halle, German hosting and development claimed on the marketing pages, and ISO 27001 and the EU AI Act name-checked — but the only published privacy policy covers the website, hosted in the US by Webflow with US processors such as Calendly, Google Analytics and Zapier. For the product that holds the contracts we found no public information on subprocessors, on which AI or OCR provider reads the text or where, or on the commissioned service provider the terms permit to hold the data; the extraction article's note that English training data dominates hints at a general model of unstated origin. 1 3 4 5
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real annual cost from public pages alone: the pricing basis (per user, per contract, per module), which features sit in which tier, add-ons for AI, e-signature volume or integrations, onboarding and migration fees, and the minimum term.
0 — No public prices at all; every tier is a sales conversation.
3 — A starting price exists, but the pricing basis (users, contracts, modules) or which features sit in which tier is unstated — the invoice is unknowable.
5 — Tier prices public with the pricing basis and main limits given, but at least one commonly needed piece (AI features, signature volume, integrations, extra users or onboarding) is unpriced.
8 — Every tier priced publicly with its basis and limits, add-on prices listed, onboarding and migration costs stated, minimum term and VAT treatment given.
10 — Complete price computability: annual invoice derivable for a given number of users, contracts and signatures, with every add-on, overage and implementation fee published.
The General Counsel
The tier structure is public — three plans with user and contract limits and their feature mapping — and the terms disclose the fee mechanics: a base fee plus a one-time onboarding fee, add-ons for users, entities and modules, twelve-month minimum renewal and three months' notice for price changes. But every figure is given only "auf Anfrage" (on request), so no annual invoice can be computed from public pages. 2 5
The Procurement Analyst
The tier structure is public and unusually clear about limits — 500 contracts and 5 users at Essential, unlimited contracts with 15 users at Professional and 50 at Enterprise, add-ons booked for users, entities and modules, a base fee plus a one-time onboarding fee, and a 12-month auto-renewal with three months' notice in the vendor's own terms. But not one euro figure is published: prices are 'Auf Anfrage' and live only in the signed offer, so no buyer can compute an annual cost from these pages. 2 5
The Sales Ops Owner
No public prices at all — every tier is "auf Anfrage" (on request) — though the tiers and their limits are published, from five users and five hundred contracts up to fifty users with unlimited contracts, and the terms disclose a base fee plus a one-time onboarding fee, automatic renewal of at least twelve months with three months' notice, and mid-term add-ons priced at whatever the current rates are. For next year's budget that is unusable: I cannot derive an annual invoice or price the extra users, companies and modules a growing sales org books. 2 5
The IT Integrator
Every price is given as 'Auf Anfrage' — the terms put the base fee, a one-time onboarding or implementation fee and add-on prices for users, companies and modules in the signed offer, so the real annual cost is computable only after the sales conversation. Credit where due: tier contents, user and contract limits per tier, the minimum term and the notice period are public. 2 5
The Data Protection Officer
All prices are given only "auf Anfrage": the tiers, their user and contract limits (500/5, unlimited/15, unlimited/50) and which features sit in each are published, and the terms disclose the basis (base fee plus one-time onboarding, add-ons for users, companies and modules) along with auto-renewal and price-change rules. No figures for the base fee, onboarding, add-ons or overages appear anywhere, so a buyer cannot compute the annual invoice from public pages. 2 5
The Skeptic
No price figure appears anywhere: three tiers are described with their user and contract limits, then "Auf Anfrage". The terms disclose the invoice's shape — base fee plus a one-time onboarding fee, add-on users, entities and modules at prices current at booking — but no amounts, so a real annual cost cannot be computed from public pages; the penalty arithmetic, by contrast, is public to the cent at 1.5% monthly interest and a 25 Euro fee per payment reminder. 2 5
European sovereignty — proven facts
2 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in DE | 3/3 pts | 4 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 2 Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 1 Oct 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency. The German hosting claim appears on pricing/homepage marketing pages; the excerpted privacy policy covers only the website (which is hosted in the US by Webflow) and says nothing about where the product's customer data is stored.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 11 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 5 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 subprocessors facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 hosting fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 legal fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
Sources (15)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.contracthero.com Checked 1 Oct 2026 Details →
- 2 Pricing page www.contracthero.com Checked 1 Oct 2026 Details →
- 3 Privacy policy www.contracthero.com Checked 1 Oct 2026 Details →
- 4 Legal notice www.contracthero.com Checked 1 Oct 2026 Details →
- 5 Terms of service www.contracthero.com Checked 1 Oct 2026 Details →
- 6 Drafting, templates & clause library — found from sitemap www.contracthero.com Checked 1 Oct 2026 Details →
- 7 Drafting, templates & clause library — found from sitemap www.contracthero.com Checked 1 Oct 2026 Details →
- 8 Negotiation, redlining & approval — found from sitemap support.contracthero.com Checked 1 Oct 2026 Details →
- 9 Negotiation, redlining & approval — found from sitemap support.contracthero.com Checked 1 Oct 2026 Details →
- 10 Repository, deadlines & obligations — found from sitemap support.contracthero.com Checked 1 Oct 2026 Details →
- 11 Repository, deadlines & obligations — found from sitemap support.contracthero.com Checked 1 Oct 2026 Details →
- 12 AI extraction & review transparency — found from sitemap support.contracthero.com Checked 1 Oct 2026 Details →
- 13 AI extraction & review transparency — found from sitemap support.contracthero.com Checked 1 Oct 2026 Details →
- 14 Integrations, signature & exit — found from sitemap www.contracthero.com Checked 1 Oct 2026 Details →
- 15 Integrations, signature & exit — found from sitemap support.contracthero.com Checked 1 Oct 2026 Details →