Editorial guide
28 Data-Handling Questions Every Law Firm Should Ask an AI Vendor
A due-diligence checklist covering custody, model providers, training, logs, backups, support, subprocessors, retention, incidents, and verification.
By Jake Bauman. Updated August 12, 2026. Under Seal product review; counsel and security review required. No named legal review is claimed unless identified here.
Short answer
A law firm should ask an AI vendor exactly what data enters the system, where each copy goes, which models and subprocessors receive it, whether it is used for training, what humans can access, how logs and backups are handled, how incidents are reported, and how deletion, export, and support are verified.
Key takeaways
- Require answers about the actual configured service, not a generic security page.
- Separate model-provider handling from application, analytics, support, and backup handling.
- Map every promise to a contract term, technical control, or verification receipt.
Editorial methods are identified as such. Numbered links beside a paragraph or section point to the authority or framework relevant to that claim; a source does not certify Under Seal or replace current jurisdiction-specific review.
Data flow and model handling
Basis: external sources listed below
Ask these questions for the exact product tier and deployment configuration being evaluated.
- What files, text, metadata, prompts, responses, embeddings, and logs are created?
- Where is each item processed and stored?
- Which model providers and subprocessors receive any portion?
- Is customer data used for training, evaluation, abuse monitoring, or product improvement?
- Can the system fall back to another model or region?
- Can administrators or support personnel read matter content?
- What product telemetry exists and can it contain matter identifiers?
- Can any data cross a network boundary during setup, license checks, updates, or error handling?
- Which data-location and model-routing settings are contractually fixed rather than defaults?
- How can the firm independently verify that training and retention settings remain applied?
Sources for this section: [1] Formal Opinion 512: Generative Artificial Intelligence Tools (opens in a new tab), [2] Model Rule 1.6: Confidentiality of Information (opens in a new tab), [3] Cybersecurity Framework 2.0 (opens in a new tab), [4] Start with Security: A Guide for Business (opens in a new tab), [5] Business Associates (opens in a new tab)
Access, security, and operations
Basis: external sources listed below
- How are users authenticated and roles enforced?
- How are encryption keys generated, stored, rotated, recovered, and revoked?
- What is logged, who can read logs, and how long are they retained?
- How are updates signed and rolled back?
- What vulnerability, incident, and breach-notification process applies?
- What does remote support require, record, and expose?
- What independent testing and remediation evidence is current?
- Which security controls depend on the firm's hardware, identity provider, or IT administrator?
- How are privileged support actions approved, time-limited, logged, and revoked?
Sources for this section: [3] Cybersecurity Framework 2.0 (opens in a new tab), [4] Start with Security: A Guide for Business (opens in a new tab), [1] Formal Opinion 512: Generative Artificial Intelligence Tools (opens in a new tab)
Lifecycle and legal fit
Basis: external sources listed below
- Where do backups live, who holds the key, and has restore been observed?
- What happens after cancellation to originals, derived data, indexes, logs, and backups?
- Can the firm export usable records without the vendor?
- How is deletion verified?
- What client, matter, tribunal, protective-order, HIPAA, Part 2, and jurisdictional restrictions must the firm assess?
- Which claims are contractual, and which are only product descriptions?
- Who is accountable when a source pin, model output, or integration is wrong?
- What usable evidence will the vendor provide after deletion, restoration, upgrade, and incident drills?
- Which promises survive termination, and where are return, deletion, and backup duties written?
Sources for this section: [1] Formal Opinion 512: Generative Artificial Intelligence Tools (opens in a new tab), [2] Model Rule 1.6: Confidentiality of Information (opens in a new tab), [5] Business Associates (opens in a new tab)
Authorities and frameworks
Each source is classified below. It may govern a specific legal point, offer professional or government guidance, or provide a voluntary framework. The collection does not validate every editorial method in this guide and does not resolve a firm-specific question.
- [1]Formal Opinion 512: Generative Artificial Intelligence Tools Opens in a new tab. — American Bar Association · Ethics guidance
- [2]Model Rule 1.6: Confidentiality of Information Opens in a new tab. — American Bar Association · Model rule
- [3]Cybersecurity Framework 2.0 Opens in a new tab. — National Institute of Standards and Technology · Risk framework
- [4]Start with Security: A Guide for Business Opens in a new tab. — Federal Trade Commission · Government guidance
- [5]Business Associates Opens in a new tab. — U.S. Department of Health and Human Services · Government guidance
Connect the general guidance to the product record
Continue the review
Under Seal is pre-release software, not a law firm. Do not submit matter details or client documents through this website.
Request a no-client-data readiness review