Synthetic demonstration
Assess interface and workflow without confidential or privileged client material.
Law-firm buyer due diligence
Separate a synthetic walkthrough from a formal law-firm approval of confidential matter processing. Open requirements are not completed certifications.
| Area | Described approach | What a lawyer must check |
|---|---|---|
| Independent security testing | External penetration testing has not been represented as complete. | Obtain scope, findings, remediations and suitable assurance before privileged client use. |
| Provider retention | OpenAI training use is described as disabled; standard abuse monitoring may retain customer content up to 30 days; ZDR is not approved. | Evaluate privilege, confidentiality and contractual restrictions for the intended material. |
| Access separation | Authentication, roles and matter membership are described. | Request negative-test evidence, user-access reviews and incident/audit procedures. |
| Recovery and continuity | Encrypted backup and limited restore evidence are described; full-service recovery commitments remain open. | Agree measurable recovery objectives, responsibilities and a tested exit route. |
| Solicitor acceptance | No completed independent practising-solicitor outcome is claimed. | Require an unaided review including failures, source accuracy and signed conclusions. |
| UK GDPR and contracts | Customer-specific processor terms are not supplied by this public checklist. | Check Article 28 obligations, roles, lawful bases, retention, subprocessors, transfers and audit assistance. |
| Supplier continuity | LegalRAG Pro identifies a sole-trader operator. | Agree service support, insurance where relevant, IP, liability, continuity and data portability. |
| Costs and value | No published price or independently measured ROI is claimed. | Request a written quotation and measure the full cost and quality-adjusted benefit of a pilot. |
Assess interface and workflow without confidential or privileged client material.
Agree participants, permission boundaries, success and failure measures; keep data synthetic until assurance is adequate.
Require law-firm legal, security and professional sign-off, documented supplier terms, support and exit arrangements.
Ask for a versioned technical specification, current security-assurance report, data-flow and subprocessor schedule, customer processing agreement, support and incident-response commitments, recovery evidence, export/deletion specification, supplier-continuity plan and independent solicitor assessment.
Reference guidance: ICO privacy transparency and the SRA misuse of AI warning. Neither implies regulatory approval of LegalRAG Pro.
This is a checklist, not an assurance report, Article 28 agreement, insurance certificate or completed third-party review.