Operating guides / Vendor evaluation

Seven data and security questions for a legal AI vendor

A security page is a starting point. The decision needs written answers tied to the data, people and workflow your firm actually intends to use.

by Hamza Suleman. Published . Operational guidance, not legal advice, procurement assurance or a product recommendation.

Direct answer

What should a law firm ask before using a legal AI vendor?

Map every data type, location, recipient, permitted use, retention rule, access control and failure route. Ask the vendor to answer in writing for the proposed workflow.

The National Cyber Security Centre's cloud-provider guidance starts with the intended use and sensitivity of the data. The ICO's AI contracts and third-parties toolkit similarly treats supplier contracts and responsibilities as part of governance. These questions turn that principle into a first written pass.

1. What data enters the service?

List prompts, uploads, outputs, annotations, embeddings, usage logs, support records and metadata separately. Do not let “customer data” hide several categories that receive different treatment.

2. Where is each data type processed and stored?

Name the countries used for live processing, model inference, support, backups and disaster recovery. Record whether the route changes by feature, model or support request.

3. Who else can access it?

Ask for the current subprocessor list and the circumstances in which vendor staff or subprocessors can access content. Identify which access is logged, reviewed and visible to the firm.

4. What is used to train or improve models?

Separate content, feedback, usage data and derived data. Ask whether the answer is contractual, plan-specific, controlled by an administrator or changed by an individual user's setting.

5. What is retained and how is it deleted?

Get a timescale for prompts, documents, outputs, backups, logs and derived data during the contract and after termination. Ask how deletion is evidenced and which material remains for security or legal reasons.

6. How is access controlled and evidenced?

Check user identity, administrator rights, role separation, matter or workspace boundaries, audit records, export controls and offboarding. A certification badge does not show whether the firm's proposed configuration enforces its own supervision rule.

7. What happens when the service changes or fails?

Record notice for subprocessor, model and terms changes; support and incident routes; breach commitments; export and exit assistance; and what the product does when it cannot support an answer. A silent partial result is a workflow failure even when the service stayed online.

Use the pattern of the answers

Specific written answers are evidence. Vague assurances, undefined terms and promises that exist only in a demonstration are open questions. The firm and its advisers remain responsible for deciding which legal, regulatory, confidentiality and contractual requirements apply.

For the wider context, read our legal AI workflow answers. Explore Margo by Margo Legal, currently in development, or use the Workflow Value Workshop to examine one repeated workflow.

Before procurement

Put the workflow and its data route on one page.

Use the Systems Check to expose missing ownership, approved-use and evidence routes before a product demonstration becomes the decision.