Technical security
Read the documented controls and current assurance limitations.
Trust & due diligence
A structured pathway for firms assessing the service, its operational boundaries and the controls needed for their proposed use.
Confirm application admission, authorised users, matter membership and roles. Request evidence for the proposed access model.
Review the hosting, identity and AI-provider configuration, the data-processing basis and relevant contractual terms.
Agree retention, deletion, export or handover expectations and the handling of information when the pilot ends.
Assess dependency risks, backup and restoration boundaries, support expectations and an exit process.
Read the documented controls and current assurance limitations.
Inspect how tasks, evidence and professional decisions are intended to remain distinguishable.
Identify the service provider and review the Privacy Policy, Terms of Use and proposed customer agreement.
store=False. The current standard abuse-monitoring profile may retain customer content for up to 30 days. A Zero Data Retention request was submitted to OpenAI on 4 October 2026 and remains pending; no ZDR claim is made.Deployment & information boundaries
Review application access, matter-scoped membership and the information boundaries to settle before confidential material is introduced.
Next step
A controlled pilot can include security, confidentiality, data-processing and exit review before confidential client material is introduced.