Before a legal AI vendor touches your data, get clear answers to six questions: Does the tool train on our inputs? Is our data isolated from other customers’? Who inside our firm can access what? Where is the data stored and for how long? How is it deleted? And what happens to our data if we leave? If a vendor can’t answer these plainly, that’s your answer.
The six questions, and what a good answer sounds like
- “Do you train your models on our inputs?” The answer you want is a contractual no. “We don’t by default” is weaker than “we never do, and it’s in the agreement.”
- “Is our data isolated?” Your firm’s data should be segregated, not pooled with other customers’ in a shared training set.
- “Who controls access?” You should be able to set permissions by role — especially for financial data, where not every user should see every number.
- “Where is our data stored, and how long?” Look for clear storage locations and defined retention windows, not vague assurances.
- “How is data deleted?” You want a real deletion process, not indefinite retention “for quality.”
- “What happens to our data when we leave?” Portability and deletion on exit should be spelled out before you sign, not discovered later.
Why this matters more for financial data
Legal AI security conversations usually center on documents. Financial data deserves the same scrutiny. Billing records, trust balances, and realization data are confidential client information under the ethics rules, and they’re increasingly the data firms want to query with AI. The vendor questions above apply to every system that holds those numbers — which is a good reason to keep financial data in fewer, better-governed places rather than scattered across tools you’d have to vet one by one.
Our complete legal AI security evaluation guide turns these questions into a full checklist you can bring to a vendor call.
Frequently asked questions
What’s the single most important vendor question? Whether they train on your inputs. A contractual no is the foundation everything else builds on.
Are enterprise AI tools safer than consumer ones for law firms? Usually, because they more often commit to no-training terms, data isolation, and access controls. But verify — don’t assume “enterprise” guarantees it.
Should IT or the operator ask these questions? Both. IT can assess the technical answers; the operator ensures the access controls match how the firm actually works. For deeper context on the privilege stakes, see our AI data-privacy guide.
Published by
The LeanLaw Team
The LeanLaw Team is the legal-finance content team behind LeanLaw — the billing, trust accounting, and revenue-reporting platform built natively on QuickBooks Online. Drawing on years of work alongside law firms and the accountants who serve them, the team writes about trust accounting, IOLTA compliance, legal billing, and law-firm financial operations. LeanLaw is a QuickBooks Online Premium App Partner.
Related articles