What to Ask Before You Upload a Single Privileged File to Any AI Platform
At our recent nursing home panel, Anytime AI's John Blake asked the panelists what plaintiff firms should ask an AI vendor before signing on. Attorney Jody Moore's answer came down to one word: privacy.

What Do Law Firms Need to Ask Legal AI Vendors Before Signing?
When Moore Hutchins Moore LLP attorney Jody Moore was asked what questions she asked before trusting an AI platform with client files, she didn't talk about features.
She talked about proof: whether the vendor could show that privileged material and protected health information stayed inside a closed system and out of any model's training data.
That's the standard worth applying to any vendor handling nursing home litigation files, medical records, or case strategy: not a reassurance, but a closed system you can actually verify.
Why "We Take Security Seriously" Isn't an Answer
Every legal AI vendor says they take security seriously. It is in every product page, every sales deck, and every demo intro. It is also one of the least meaningful things a vendor can tell you, because it describes an intention, not a standard.
The attorneys who get into trouble with legal AI data security are not the ones who ignored the issue. They are the ones who accepted a vendor's security narrative at face value without asking the questions that would have revealed what was actually underneath it. A platform that processes client medical records, privileged communications, and confidential case strategy without independently verified security controls is a liability, regardless of how confidently the sales team describes their commitment to data protection.
The shift that protects a firm is moving from "do you take security seriously" to "show me the documentation." Certified standards exist precisely because self-reported security commitments are not enough. Knowing which certifications to ask for, what they actually require, and where the gaps are even when a vendor has them is what separates rigorous vendor evaluation from a checkbox exercise.
This is what that evaluation looks like in practice.
SOC 2 Type I vs. Type II: A Difference That Actually Matters
SOC 2 is the security standard most plaintiff attorneys have heard of, and for good reason. It is the framework that governs how technology vendors protect the data they handle, and it is the right baseline to require of any legal AI platform. But not all SOC 2 certifications are the same, and the difference between Type I and Type II matters significantly for law firms evaluating vendors.
According to the AICPA, which administers the SOC framework, a SOC 2 Type I report documents that a vendor's security controls are designed appropriately at a single point in time. A SOC 2 Type II report goes further: it verifies that those controls actually operated effectively over an extended period, typically six to twelve months, through independent third-party auditing.
The practical difference is significant. A vendor with a SOC 2 Type I certification has had their security architecture reviewed and approved on paper. A vendor with SOC 2 Type II certification has had their actual security practices independently audited over time, with documentation that the controls work in practice, not just in design.
For plaintiff firms evaluating a SOC 2 certified legal AI platform, the right question is not "are you SOC 2 certified" but "do you hold a current SOC 2 Type II report, and can you provide it?" Any vendor unwilling or unable to answer that question with documentation rather than a talking point has told you something important about what their security claims are actually worth.
Does AI Train on My Data? Legal Platforms, Terms of Service, and How to Find Out
The data training question is one of the most important in legal AI vendor evaluation, and it is also one of the most reliably obscured in vendor communications.
Many AI platforms, including consumer-grade tools that have found their way into law firm workflows, use the data their users upload to improve their underlying models. Your client's medical records, case notes, and privileged communications become part of the training dataset that makes the tool more useful for everyone else. This is not always disclosed prominently, but it is almost always disclosed somewhere, typically in the terms of service in language like "we may use your inputs to improve our services."
Finding out whether a platform trains on your data requires reading the terms of service rather than the product page, and asking a direct question in writing before signing anything. The question to ask is: "Does your platform use data uploaded by law firm users to train, fine-tune, or improve your AI models, and is that commitment documented in the contract?"
A vendor that operates under a genuine zero data training policy should be able to answer that question immediately, in writing, with a contractual commitment rather than a verbal assurance. A vendor that hedges, redirects to their privacy policy, or describes data handling in ways that don't directly address model training is not a vendor that has made a clean commitment on this point.
For plaintiff attorneys asking "does AI train on my data" as part of a legal AI vendor comparison or looking for clarity on which legal AI doesn't train on your data, the answer should be explicit and verifiable, not inferred from the absence of language to the contrary.
The HIPAA Question Most Attorneys Forget to Ask
Most plaintiff attorneys know that HIPAA, the Health Insurance Portability and Accountability Act, applies to the medical records they handle on behalf of clients. Fewer think to ask whether their AI vendor has formalized that obligation in the way HIPAA actually requires.
Under HIPAA's Privacy and Security Rules, any vendor that processes protected health information on behalf of a covered entity is required to operate under a Business Associate Agreement, a formal contract that defines how PHI can be used, what security standards must be met, and what happens in the event of a breach. Without a BAA, the law firm's use of that vendor to process client medical records is not HIPAA compliant, regardless of how secure the vendor's infrastructure actually is.
The question most attorneys forget to ask is not "are you HIPAA compliant" but "will you sign a BAA, and what does your BAA say about AI model training?" Those are different questions with different answers. A vendor can maintain secure infrastructure that meets HIPAA's technical standards while still retaining contractual rights to use PHI for model improvement purposes unless the BAA explicitly prohibits it. HIPAA compliance and zero data training are not the same commitment.
Any HIPAA compliant legal AI vendor worth signing with should be willing to sign a BAA before any client data is uploaded, and that BAA should explicitly address whether uploaded PHI can be used for model training. Anytime AI's FAQ and security documentation includes an 18-page Data Privacy and Security policy statement that covers these commitments in full, the kind of documentation that should exist for any vendor you're seriously evaluating.
What Attorney-Client Privilege Requires of Your AI Vendor
The attorney-client privilege issue with legal AI is straightforward, though it is often overlooked until it becomes a problem.
When an attorney uploads a privileged communication, a case strategy document, or a client's confidential disclosures to a third-party AI platform, they are transmitting that information outside the attorney-client relationship. Whether that transmission affects the privileged status of the communication depends on what the vendor does with the data, and specifically on whether the vendor's infrastructure and data handling practices constitute a disclosure to a party outside the privilege.
A vendor that stores and processes data in a closed environment that is inaccessible to the vendor's own team for training or improvement purposes presents a fundamentally different privilege risk profile than one that retains, analyzes, or trains on user inputs. The former is structured to maintain the confidential character of the information. The latter, depending on how broadly the vendor's access extends, may not be.
The practical implication for vendor evaluation is this: before uploading any privileged material to a legal AI platform, an attorney should be able to confirm that the vendor's data handling practices are consistent with maintaining the confidentiality of attorney-client communications, and that confirmation should be contractual, not verbal.
Encryption: What AES-256 and TLS 1.2 Actually Mean for Your Case Files
Data training and HIPAA compliance get most of the attention in legal AI security conversations, but encryption is the foundational layer underneath all of it, and it is where the gap between serious vendors and everyone else is most technically concrete.
Encryption comes in two forms that matter for law firms: encryption at rest and encryption in transit. Encryption at rest protects data while it is stored on a vendor's servers. Encryption in transit protects data while it is moving between your firm and the vendor's platform, for example when you upload a case file or retrieve a demand draft.
The current standard for encryption at rest is AES-256, the Advanced Encryption Standard with a 256-bit key. It is the same standard used by financial institutions and federal agencies for protecting sensitive data, and it is the benchmark to ask for by name when evaluating a legal AI vendor. For encryption in transit, the standard is TLS 1.2 or higher, which ensures that data moving between your browser or application and the vendor's servers cannot be intercepted or read in transit.
These are not obscure technical specifications. They are the documented baseline that a vendor either meets or doesn't, and asking for them specifically is a useful way to distinguish vendors who have actually built security infrastructure from those who have written about it. A vendor that cannot confirm AES-256 encryption at rest and TLS 1.2 or higher in transit has not met the baseline standard for handling sensitive legal and medical data.
Anytime AI uses AES-256 encryption at rest and TLS 1.2+ encryption in transit across the platform, meaning client medical records and privileged case files are protected both while stored and while moving. That is the same standard plaintiffs' firms should be requiring from every vendor they evaluate.
The Vendor Evaluation Checklist: Questions to Ask Before You Sign
Based on the issues covered above, here is the evaluation framework for plaintiff firms comparing legal AI platforms at the vendor-vetting stage.
On encryption: Does the platform use AES-256 encryption for data at rest and TLS 1.2 or higher for data in transit? Can the vendor confirm both standards in writing, not just on the product page?
On SOC 2 certification: Does the vendor hold a current SOC 2 Type II report? Can they provide it, or confirm it is available upon request? If they reference SOC 2 without specifying Type II, ask explicitly.
On data training: Does the platform train, fine-tune, or improve AI models using data uploaded by law firm users? Is that commitment documented in the contract, not just described on the product page? Does the terms of service contain any language permitting use of uploaded data for model improvement?
On HIPAA: Will the vendor sign a Business Associate Agreement before any PHI is uploaded? Does the BAA explicitly address AI model training and prohibit the use of PHI for that purpose?
On privilege and data access: Is uploaded data processed in a closed infrastructure that the vendor's own engineering or data team cannot access for training or improvement purposes? What data is retained after a task is completed, and who has access to it?
On verification and audit: Can the vendor provide independent third-party documentation of their security practices beyond the product page? Is their SOC 2 Type II report current, and what period does it cover?
On portability and deletion: What happens to your data if you end the relationship? Can you request deletion of all stored data, and is there a documented process for that request?
Any vendor that cannot answer these questions clearly and in writing before you sign is not a vendor you should be uploading client files to.
How Anytime AI Answers Every One of These Questions
Anytime AI's security architecture is built on a closed AI infrastructure with a strict zero data training policy. Client files, medical records, and privileged communications uploaded to the platform are never used to train any AI models. That commitment is contractual, documented, and reflected in the core architecture of how the platform processes and stores data, not a product page claim that disappears when you read the terms of service.
On encryption: Anytime AI uses AES-256 encryption at rest and TLS 1.2+ encryption in transit, meaning case files and medical records are protected both while stored on the platform and while moving between your firm and the server. These are the same standards used by financial institutions for sensitive data, and they are documented and verifiable, not just described.
On SOC 2: Anytime AI maintains SOC 2 Type II certification, meaning its security controls have been independently audited over time, not just reviewed on paper. The Why Anytime AI page covers the full compliance picture, including HIPAA, SOC 2, and the platform's approach to data lifecycle management.
On HIPAA: Anytime AI supports HIPAA-compliant workflows and is designed to operate as a business associate under the relevant legal framework, including executing Business Associate Agreements with law firms that handle protected health information. The BAA addresses data training explicitly.
On privilege: The platform processes data within a closed environment. Your case files do not inform the model's outputs for other users, are not retained by the vendor for improvement purposes, and are not accessible to Anytime AI's engineering team for training. The data does the work you assign it and stays where it belongs.
The checklist above is not hypothetical. It is the evaluation framework that a genuinely secure legal AI vendor should be able to clear without hesitation. Anytime AI clears it, in writing, before you upload your first file.
Final Thoughts
The security conversation in legal AI has matured enough that "we take security seriously" is no longer sufficient. Attorneys evaluating platforms now have the framework to ask better questions, and vendors that cannot answer those questions with documentation rather than talking points have effectively answered them.
SOC 2 Type II certification, AES-256 and TLS 1.2+ encryption, a contractual zero data training commitment, a HIPAA-compliant BAA that addresses model training explicitly, and a closed infrastructure that protects privileged communications are not premium features. They are the baseline for any platform a plaintiff firm should be trusting with its clients' most sensitive information.
The one question that exposes a vendor that doesn't meet that baseline is also the simplest one: can you put that in writing? The answer tells you everything you need to know.
FAQs
What is the difference between SOC 2 Type I and SOC 2 Type II for legal AI platforms?
SOC 2 Type I certifies that a vendor's security controls are appropriately designed at a single point in time, whereas SOC 2 Type II certifies that those controls actually operated effectively over an extended period through independent third-party auditing. For law firms evaluating vendors, Type II provides meaningfully stronger assurance than Type I because it verifies real-world security practice rather than design intent.
What encryption standards should a legal AI platform use?
The two standards to ask for by name are AES-256 encryption at rest, which protects data stored on the vendor's servers, and TLS 1.2 or higher encryption in transit, which protects data moving between your firm and the platform. A vendor that cannot confirm both in writing has not met the baseline for handling client medical records and privileged case files.
Does AI train on my data?
It depends entirely on the platform. Many AI tools, including some marketed to legal professionals, use uploaded data to improve their models by default. The only way to know for certain is to read the terms of service carefully and ask the vendor directly whether uploaded data is used for model training, and to get that answer in writing as part of the contract.
Which legal AI platforms don't train on your data?
Platforms with a genuine zero data training policy, like Anytime AI, make that commitment contractual and verifiable rather than just describing it on a product page. When evaluating any vendor, ask for a contractual commitment that explicitly prohibits the use of uploaded data for model training, and confirm that the terms of service contains no language permitting it.
What should I look for in a HIPAA compliant legal AI platform?
At minimum: a vendor willing to sign a Business Associate Agreement (BAA) that explicitly addresses AI model training and prohibits use of PHI for that purpose, and independently verified security controls that meet HIPAA's technical safeguard requirements. HIPAA compliance and zero data training are different commitments, so confirm both separately.
What is the most important question to ask a legal AI vendor during evaluation?
"Can you put that in writing?" Any security commitment a vendor is unwilling to formalize contractually, whether about data training, HIPAA compliance, or privileged information handling, is a commitment they are not actually making.
Get Started
Ready to go deeper — and safer?
See how Anytime AI gives plaintiff firms the strategic edge
and the security their clients deserve.