ProofGuard AI
Resources · Security

Security questionsto ask beforeadopting legal AI.

Client confidentiality does not change when the tool does. Before a firm puts client information into an AI system, it should know where that information goes, who can see it and what happens to it afterward.
PROOFGUARD AI · OCTOBER 5, 2026 · 9 MIN READ

The professional duties that apply

In the United States, the ABA Model Rules of Professional Conduct frame the question. Rule 1.1 requires competence, and its commentary includes keeping up with the benefits and risks of relevant technology. Rule 1.6(c) requires reasonable efforts to prevent unauthorized access to or disclosure of client information. In July 2024 the ABA issued Formal Opinion 512 on generative AI, which applies these duties to AI tools, including the need to understand how a tool uses the information entered into it and, in some cases, to obtain the client's informed consent.

State rules and bar opinions vary, and firms outside the United States have their own professional and data protection rules. The practical consequence is the same everywhere: a firm needs clear, written answers from its vendor.

Data storage and model training

  • Where is client data stored and processed, and in which countries?
  • Is client data, including prompts and documents, used to train or improve any model? If not, is that commitment in the contract?
  • Which third parties, including AI model providers, receive client data, and on what terms? Ask for the list of subprocessors.
  • How long is data kept, and how is it deleted on request or at the end of the contract?
  • Is data encrypted in transit and at rest, and who manages the keys?
  • Is each client kept in a separate environment, or do clients share databases?

Access control and audit

  • Does the system support single sign on and multi factor authentication?
  • Can access be limited by role and by matter, including ethical walls between teams?
  • Which vendor employees can access client data, under what approval, and is that access logged?
  • Does the firm receive audit logs showing who viewed, changed or exported matter data?

Independent assurance

A SOC 2 report is an independent auditor's examination of a service organization's controls under the AICPA Trust Services Criteria. A Type I report evaluates whether controls are designed appropriately at a point in time. A Type II report also tests whether they operated effectively over a period, commonly several months to a year. Ask which type the vendor has, the period it covers, which services are in scope, and whether the auditor noted exceptions. Ask also how the vendor's own AI providers are assessed.

Incidents, continuity and exit

  • How quickly will the vendor notify the firm of a security incident affecting its data, and what information will it provide?
  • Does the vendor carry cyber insurance, and what does it cover?
  • How are backups made and tested, and what is the recovery time if the service fails?
  • In what format can the firm export all of its data at the end of the contract, and at what cost?

Questions about AI output

  • Does the system show the sources behind its statements so they can be verified?
  • Is AI output clearly marked as a draft until a person approves it?
  • Can the firm see which version of the system produced a given output, for later review?

Next steps

Put these questions in writing, keep the answers with the engagement file, and review them when the vendor changes its service or its AI providers. Where client consent is needed, explain the tool and its data handling in plain language.

ProofGuard AI publishes how it answers these questions on its Data Security and SOC 2 pages. Contact us for a security review of a specific build.

More resources