ContractWorks

United States · www.contractworks.com · 13 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 13 sub-vendors.

Insights

Last updated 2026-07-25 · revision 2

13 direct vendors, 184 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

ContractWorks exhibits high migration readiness due to its fundamental cloud-based SaaS delivery model and the availability of a robust REST API. The API allows for programmatic management, bulk uploads, and integration with CRMs, ERPs, and reporting tools, which significantly eases data migration and system integration efforts. The company's modern tech stack, incorporating AI, NLP, and generative AI for core functionalities, suggests an architecture that is likely modular and adaptable. Furthermore, adherence to SOC 2 Type 2 and HIPAA compliance frameworks indicates well-defined processes and controls that can facilitate a compliant migration. The use of a Managed VPC, dedicated firewalls, and managed backup/disaster recovery solutions points to a well-architected and secure cloud environment. However, the assessment is hampered by the lack of information regarding specific data residency requirements and the broader regulatory environment, which are critical factors for migration planning. Financial stability data is also missing, which could impact the ability to fund a migration. The vendor lock-in risk is explicitly stated as "Unknown," and the contradictory vendor data (0 total vendors vs. 15 services from diverse countries) makes it difficult to fully assess the complexity of vendor relationships during a potential migration. Despite these unknowns, the inherent cloud-native nature and strong API capabilities position ContractWorks favorably for migration.

Compliance

6 in-scope frameworks identified; showing 3.

CCPA — Compliant

ContractWorks/Onit explicitly addresses CCPA compliance in its Privacy Policy with a dedicated section for California residents. The policy enumerates all required CCPA disclosures: categories of personal information collected (6 categories explicitly listed), right to access, right to data portability, right to deletion, right to non-discrimination, and the process for exercising rights (email and OneTrust privacy request form). The company explicitly states it has not sold personal information in the preceding 12 months. The risk is Low because the company has clearly invested in CCPA compliance infrastructure and makes comprehensive public disclosures. Onit is headquartered in Atlanta, GA, but serves California residents and businesses, making CCPA applicable.

Evidence: https://www.onit.com/privacy-cookies/, https://onit-privacy.my.onetrust.com/webform/b861774e-94fa-4384-aa2c-68a2171fa00f/25a04d4c-2089-4e82-b0eb-88f05833cb36

ISO 27001 (source) — Assessment Required

No public evidence of ISO 27001 certification was found for ContractWorks or its parent company Onit, Inc. The company's security page focuses on SSAE-18 SOC 2 Type 2, SOC 1 Type 2, and HIPAA compliance, with no mention of ISO 27001. For a global SaaS provider serving enterprise legal teams across multiple jurisdictions (including EU customers such as UEFA), the absence of ISO 27001 certification represents a moderate risk, particularly for enterprise customers in regulated industries or EU/EEA markets where ISO 27001 is commonly expected. The risk is Medium rather than High because the company has robust SOC 2 Type 2 compliance (which covers overlapping security controls), and ISO 27001 is not legally mandated for CLM SaaS providers. However, the lack of ISO 27001 may be a competitive disadvantage and a gap for customers requiring it contractually.

Evidence: https://www.onit.com/security/, https://www.onit.com/products/clm/contractworks/

GDPR (source) — Partially Compliant

ContractWorks (operated by Onit, Inc., HQ: Atlanta, GA, USA) is a US-based SaaS provider that explicitly acknowledges GDPR applicability in its Privacy Policy, enumerating EU/EEA resident rights (right to access, correction, erasure, portability, objection, and complaint to supervisory authority). The company has published a Data Processing Addendum (DPA) and maintains a sub-processors list, which are foundational GDPR compliance mechanisms. However, the privacy policy states data may be transferred to and processed in the United States and other countries where Onit operates, and while it references 'suitable safeguards' for international transfers, no specific transfer mechanism (e.g., Standard Contractual Clauses, adequacy decision) is explicitly named in publicly available documentation. The risk is Medium rather than High because the company has clearly invested in GDPR compliance infrastructure (DPA, privacy rights framework, OneTrust privacy request portal), but gaps in publicly documented transfer mechanisms and the absence of a named EU Data Protection Officer (DPO) introduce residual risk. Enforcement risk is real given the company serves global enterprise legal teams, including EU-based clients (e.g., UEFA is listed as a customer).

Evidence: https://www.onit.com/privacy-cookies/, https://www.onit.com/data-processing-addendum-for-the-onit-companies/, https://www.onit.com/sub-processors/, https://www.onit.com/legal-center/, https://www.onit.com/products/clm/contractworks/

Financials

Three-year financials

Financial Resilience Score: 6/10

ContractWorks is a privately held SaaS product owned by Onit, Inc., which is also private and backed by K1 Investment Management (approximately US$200M growth equity raised in 2019). Neither entity files with the SEC, so no audited financials are available for FY2022, FY2023, or FY2024. Financial resilience must therefore be assessed qualitatively. The recurring SaaS subscription model typically provides predictable revenue and strong gross margins, and Onit's active M&A strategy (BusyLamp, SimpleLegal, AXDRAFT, McCarthyFinch, Legal Files, LawBase) suggests continued access to capital. However, the opacity of financials, potential PE-related leverage, heavy AI R&D spend, and integration/consolidation risk (ContractWorks brand being absorbed into Onit's Unity/OnitX CLM platform) create meaningful uncertainty. The CLM market is also highly competitive, with better-funded rivals such as Ironclad, DocuSign CLM, Icertis, Agiloft, and Evisort. Overall the company appears reasonably resilient but unverifiable from public filings.

Key strengths: Backed by K1 Investment Management (~US$200M raised in 2019), Recurring SaaS subscription revenue model with typically strong gross margins, Part of Onit's broader CLM/ELM portfolio serving 3,000+ customers worldwide, Active M&A strategy expanding product and geographic reach, Established brand in-market since ~2014 with mid-market traction

Risk factors: No public financial disclosure; liquidity, leverage, and profitability unverifiable, Brand consolidation into Onit platform may lead to product rationalization and customer disruption, Highly competitive CLM market with better-funded rivals (Ironclad, DocuSign CLM, Icertis, Agiloft, Evisort), Heavy AI R&D investment could weigh on group profitability, PE-backed roll-up structures often carry meaningful leverage (unquantifiable here)

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report