Our Methodology
How DocAI's AI systems analyze contracts, generate risk scores, and produce legal documents — and what the limitations are.
Important: DocAI is an AI-powered informational tool. It is not a law firm and does not provide legal advice. All output should be reviewed by a licensed attorney before being relied upon.
1. Due Diligence Scanner
The Due Diligence Scanner accepts deal parameters (type, jurisdiction, value, structure) and runs them through our AI analysis pipeline to produce a structured risk assessment. No document upload is required — the scanner performs a prospective risk analysis based on deal type and jurisdiction.
How Risk Scores Are Calculated
The risk score (0–100, where 100 = lowest risk) is produced by Claude claude-sonnet-4-6 using a structured JSON prompt. The model evaluates:
- Deal type and industry-specific risk factors (e.g., Howey test proximity for Web3)
- Jurisdiction-specific legal requirements and common failure modes
- Structural risks based on deal structure and value
- Missing clauses commonly required for enforceability
The AI assigns severity levels (HIGH / MEDIUM / LOW) to each identified risk. The overall score reflects the weighted distribution of these risks. Scores are estimates, not legal opinions.
Vertical-Specific Rules
Each industry vertical has additional heuristic rules applied during scanning:
2. Contract Generator Pipeline
Contracts are generated using a two-stage pipeline: template injection followed by AI refinement. We do not generate contracts from scratch — we always start from professionally drafted DOCX templates.
Stage 1: Template Selection
Users select a vertical and template type. Underlying DOCX templates were drafted by licensed attorneys and reflect standard commercial practice for the relevant jurisdiction and deal type. Available templates include: JV Agreement, NDA, LOI, Commission Agreement, Capital Call, Property Management, Token Subscription, and Personal Guarantee.
Stage 2: Variable Injection
3. AI Model & Prompting
All AI analysis uses Anthropic Claude claude-sonnet-4-6 (claude-sonnet-4-6) via the official Anthropic API. We use structured JSON output prompts with explicit role-setting ("You are a senior commercial attorney…") and vertical-specific context injection.
We do not use fine-tuned models, retrieval-augmented generation (RAG), or case law databases at this time. Analysis is based solely on the model's training knowledge and the structured prompts we provide.
Known AI Limitations
- AI can hallucinate — fabricate clauses, party names, or legal citations that do not exist.
- Training data has a knowledge cutoff; recent legislative changes may not be reflected.
- The model cannot verify the actual terms of any existing signed agreement.
- Jurisdiction-specific accuracy varies; US law (especially New York and Delaware) is best-covered.
- AI analysis cannot substitute for a licensed attorney reviewing your specific transaction.
4. Document Templates
Our template library contains 40+ DOCX documents across 6 verticals. Templates were initially drafted to reflect standard commercial practice and have been reviewed for general enforceability. Templates are starting points, not final legal documents.
All generated contracts include placeholder language in brackets (e.g., [PARTY NAME], [DATE]) where information was not provided. These must be reviewed and completed before any document is signed.
5. Data Handling
- Deal inputs and generated contracts are stored in our Supabase database (US region).
- Document content is processed by Anthropic's API. See Anthropic's Privacy Policy.
- We do not sell or share your data with third parties for marketing purposes.
- Scan and contract data is retained for 90 days, then deleted.
6. Payment & Access Control
Free tier: risk score + top 3 risk flags (DD Scanner) or contract preview metadata (Generator). Paid tier ($24–$49): full risk report or DOCX contract download. Payment is processed via NOWPayments (crypto) or card. Access is gated by a paid flag in the database that is set by verified webhook callbacks from our payment processors.
7. What We Do Not Do
- We do not provide legal advice or establish an attorney-client relationship.
- We do not guarantee the enforceability of any generated contract.
- We do not verify the identity of parties, signatures, or notarization.
- We do not file, register, or record any document with any governmental authority.
- We do not provide securities law opinions or regulatory compliance certifications.