For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
Contract Guardian extracts clauses, detects missing clauses, analyzes liability and indemnity, surfaces AI-usage provisions, and flags deviations from an organization-defined playbook. Rerun it against amendments and addenda so the contractual control surface stays aligned with the live risk profile maintained in Supplier Radar.
The core idea: you write down your standard once, as tiers of acceptable language. Coverbase then finds the vendor’s version of each clause, decides which tier it lands in, and gives your reviewer a short list of deviations with the source text quoted and highlighted, instead of an agreement to read end to end.
This is materiality analysis, not redlining. Guardian tells you which clauses deviate and how far. The redline itself still happens in your word processor.
What it does
Clause extraction
Parse MSAs, DPAs, SOWs, BAAs, and order forms to extract clauses, terms, and obligations into structured records.
Missing-clause detection
Compare extracted contracts against your playbook and flag clauses that should be present but aren’t (data breach notification, audit rights, subprocessor flow-down).
Liability and indemnity analysis
Surface liability caps, indemnification scope, and limitation-of-liability language so legal teams can focus review on what deviates from standard.
AI-usage provisions
Detect AI-specific clauses, model training restrictions, output ownership, customer data usage in model improvement, and flag where they’re missing.
Clause sets and risk tiers
A clause set is your playbook. Each reference clause in it is one standard you hold vendors to, carrying a severity, guidance that tells the matcher how to find the clause, the contract components it applies to, and a set of variants: versions of the clause language at different levels of acceptability, tiered 1 to 5. Coverbase matches the vendor’s actual language to the closest variant, and the tier drives the verdict:
Two guardrails sit on top: a low-confidence match is escalated to Needs review rather than auto-passing, and language found outside the components a clause was scoped to is escalated the same way. Where no language is found, the result is Missing when the relevant component is present in the contract, and Not applicable when it isn’t.
Three ways to build one
Clause set library
Copy the packaged SaaS Vendor Risk Clause Set: 15 reference clauses spanning liability, indemnity, confidentiality, data protection, IP, service levels, audit, and AI use, each with multi-tier language already written. Your copy is fully editable.
From your own paper
Upload your template MSA or DPA as a baseline contract. Guardian extracts reference clauses grounded in exact language from your document and creates a clause set from them, ready for you to add fallback tiers.
By hand
Author reference clauses directly for narrow, high-stakes standards. Clauses are versioned, so edits never rewrite the history of reviews already run.
Review and triage
Component-aware analysis
Guardian first detects the logical components inside the linked documents (MSA, DPA, order form, SLA, NDA, SCCs, AI addendum, amendments), then evaluates each reference clause only where it belongs.
Evidence-backed verdicts
Each result carries the extracted vendor language, the matched variant, a confidence score, the source document and page, and highlighted evidence in the PDF.
Assessment insights
Where the vendor has a completed assessment, flagged clauses are cross-referenced against that evidence and given a suggested disposition (no action, revise language, add clause, or escalate) with citations back into the assessment.
Triage as the unit of work
Reviewers mark each flag as no action, accepted risk, or false positive, or escalate it to a tracked finding. The system verdict and the human decision are both preserved on the record.
Follow-up drafts
Select the deviations worth pushing back on and generate an outbound follow-up draft built from those specific clauses. Nothing sends automatically; copy it, or escalate to a finding.
How to integrate
Document submission
Submit contract documents (PDF, DOCX) for analysis. Returns structured clause extraction and playbook deviation report.
Re-evaluation on amendment
Add amendments and addenda to the contract and rerun the review against the existing paper, surfacing what changed in the controlled obligation surface.
Common workflows
Pre-execution redline review
Pre-execution redline review
Submit drafts to Guardian before legal review. It surfaces deviations from your playbook, missing clauses, and unusual liability terms so reviewers focus on the deltas rather than reading every contract end to end.
Contract repository ingestion
Contract repository ingestion
Bulk-process your existing contract portfolio. Guardian extracts obligations, surfaces gaps against your current playbook, and produces a prioritized list of contracts that need renegotiation.
Living obligation tracking
Living obligation tracking
Guardian-extracted obligations feed the Coverbase obligation surface, where they can be assigned, tracked, and linked to controls. When a vendor’s risk profile changes in Supplier Radar, contractual obligations are already in scope.
Field-level contract inventory
Field-level contract inventory
Pair clause review with Document Insights to populate the contract record itself: value, term dates, notice periods, liability caps, and governing law extracted from every document with page citations.
Setting this up? The Contract Guardian guide walks through building a clause set, writing risk-tier variants, and running your first review. Contract Guardian results integrate with the Coverbase obligation and finding surfaces, accessible through the Export API and MCP server.