Skip to main content

Ethics

Is AI safe for client data? What lawyers actually need to check

A plain-English checklist for whether a legal AI tool is safe for confidential client data — training, retention, encryption, and the questions to ask a vendor.

By The Draftiro team · Legal product· 9 min read·Published

"Is it safe to put my client's information into an AI tool?" is the right question — and the honest answer is "it depends entirely on the tool's contract and architecture, not on whether it says 'secure' on the homepage." Here is what actually determines the answer, and the questions to ask before you paste a single client fact.

The four things that decide it

  1. Does the tool train on your inputs? This is the big one. Consumer chatbot tiers often reserve the right to use your inputs to improve their models. Enterprise and paid API tiers usually contractually prohibit it. The difference is the contract, not the brand.
  2. How long is your data retained, and can you delete it? Ask for the retention period and whether you can request deletion. Indefinite retention with no deletion path is a confidentiality problem under Model Rule 1.6.
  3. Is data encrypted in transit and at rest? TLS in transit and strong encryption at rest (e.g. AES-256) is table stakes. Draftiro encrypts data at rest with AES-256.
  4. Where does the data live, and who are the subprocessors? You should be able to see the list of subprocessors and the hosting region. Draftiro stores data in AWS us-east-1 via Supabase and publishes its subprocessor list.

What ABA Op. 512 requires of you

ABA Formal Opinion 512 ties AI use to your existing duty of confidentiality (Rule 1.6). In plain terms: do not feed client information into a tool that retains it for training without informed consent. The opinion doesn't ban AI — it asks you to understand the tool and protect the confidences. A tool with a clean, contractual no-training posture makes that compliance straightforward.

The questions to ask any legal AI vendor

  • "Do you train models on my inputs? Show me the clause."
  • "What is your data retention period, and how do I delete my data?"
  • "Is data encrypted at rest, and with what?"
  • "Who are your subprocessors and what region is my data in?"
  • "Do you have a DPA I can sign?"

Where Draftiro stands

Draftiro runs on Google Gemini's paid enterprise API tier, which is contractually prohibited from training on inputs — so your data never trains AI models. Data is encrypted at rest with AES-256, isolated per firm with Postgres row-level security, and stored in AWS us-east-1. A DPA is available on request. Our SOC 2 Type II is in progress, not yet complete — we won't claim otherwise. See the full posture on our security page.

None of this is legal advice about your specific duties — it's the checklist we'd want a careful solo to run before trusting any tool with a client's confidences.

This article was published by the Draftiro team and reviewed by our attorney advisors. See our team and how we track AI ethics opinions.

Try Draftiro free

We use essential cookies to keep you signed in and privacy-friendly, cookieless analytics to improve Draftiro. No third-party advertising trackers.