Law-firm buyer due diligence

What must be established before client information goes in?

Separate a synthetic walkthrough from a formal law-firm approval of confidential matter processing. Open requirements are not completed certifications.

Status and decision requirements

AreaDescribed approachWhat a lawyer must check
Independent security testingExternal penetration testing has not been represented as complete.Obtain scope, findings, remediations and suitable assurance before privileged client use.
Provider retentionOpenAI training use is described as disabled; standard abuse monitoring may retain customer content up to 30 days; ZDR is not approved.Evaluate privilege, confidentiality and contractual restrictions for the intended material.
Access separationAuthentication, roles and matter membership are described.Request negative-test evidence, user-access reviews and incident/audit procedures.
Recovery and continuityEncrypted backup and limited restore evidence are described; full-service recovery commitments remain open.Agree measurable recovery objectives, responsibilities and a tested exit route.
Solicitor acceptanceNo completed independent practising-solicitor outcome is claimed.Require an unaided review including failures, source accuracy and signed conclusions.
UK GDPR and contractsCustomer-specific processor terms are not supplied by this public checklist.Check Article 28 obligations, roles, lawful bases, retention, subprocessors, transfers and audit assistance.
Supplier continuityLegalRAG Pro identifies a sole-trader operator.Agree service support, insurance where relevant, IP, liability, continuity and data portability.
Costs and valueNo published price or independently measured ROI is claimed.Request a written quotation and measure the full cost and quality-adjusted benefit of a pilot.

Three different admission decisions

Synthetic demonstration

Assess interface and workflow without confidential or privileged client material.

Controlled evaluation

Agree participants, permission boundaries, success and failure measures; keep data synthetic until assurance is adequate.

Production with client matters

Require law-firm legal, security and professional sign-off, documented supplier terms, support and exit arrangements.

Evidence to request

Ask for a versioned technical specification, current security-assurance report, data-flow and subprocessor schedule, customer processing agreement, support and incident-response commitments, recovery evidence, export/deletion specification, supplier-continuity plan and independent solicitor assessment.

Reference guidance: ICO privacy transparency and the SRA misuse of AI warning. Neither implies regulatory approval of LegalRAG Pro.

This is a checklist, not an assurance report, Article 28 agreement, insurance certificate or completed third-party review.