We respect attorney-client confidentiality. No tracking pixels in our emails.
We respect attorney-client confidentiality. No tracking pixels in our emails.

A 15-point SOC 2 evaluation checklist for legal AI vendors—what to request, what Type II means, critical gaps SOC 2 doesn't cover, and supplemental certifications to require.
Material claims in this article were checked against the public sources below on 2026/08/10.
Move from this guide to practical legal AI tool shortlists and comparison pages.
In early 2025, a 200-attorney firm discovered that a legal AI vendor it had been using for 18 months had quietly modified its data handling practices to allow client document content to be used for model training. The change appeared in an updated Terms of Service posted without direct notification to the firm. The firm had a SOC 2 Type II report from the vendor—obtained during the initial procurement process—but had never reviewed the vendor's contractual data use terms separately. The SOC 2 certified the vendor's security controls. It said nothing about whether client data would be used to train models.
That story illustrates the central limitation of SOC 2 as a vendor evaluation framework for law firms: SOC 2 is a security certification, not a data use certification. It tells you that a vendor has controls to prevent unauthorized access to your data. It does not tell you what the vendor is authorized to do with your data.
For law firms evaluating legal AI vendors, SOC 2 is necessary but not sufficient. This guide provides a 15-point checklist that covers what SOC 2 certifies, what it does not, and the supplemental verification required for legal AI vendors specifically.
SOC 2 (Service Organization Control 2) is an auditing standard developed by the American Institute of Certified Public Accountants (AICPA) that evaluates a service organization's controls relevant to security, availability, processing integrity, confidentiality, and privacy. For cloud-hosted software vendors—including legal AI platforms—SOC 2 has become the baseline enterprise security certification.
The legal industry's adoption of SOC 2 as a vendor evaluation requirement accelerated significantly between 2022 and 2024, as law firms moved more client data into cloud-based AI tools and began receiving questions from corporate clients about their vendors' security postures. Large law firm clients—Fortune 500 legal departments, financial institutions—began including vendor security requirements in outside counsel guidelines, creating pressure on firms to document their AI vendor evaluations formally.
The problem is that SOC 2 is often evaluated superficially. A vendor claims to be "SOC 2 certified" and provides a certificate. The law firm procurement process checks the box and moves on. The certificate does not reveal what the audit scope covered, whether the auditor identified exceptions, which of the five trust services criteria were included, or how current the report is.
For legal AI vendors specifically, there are additional dimensions that SOC 2 does not address at all: how does the vendor handle data sent to the model at inference time? Does client document content get used to train future models? Are there contractual confidentiality provisions that protect attorney-client privilege obligations? Is data stored within required geographic jurisdictions?
Law firms have professional responsibility obligations that go beyond standard enterprise data security requirements. Rule 1.6 of the Model Rules of Professional Conduct requires reasonable measures to prevent unauthorized disclosure of client information. The competence required to meet that standard in the AI vendor context is more demanding than checking whether a vendor has a SOC 2 certificate.
SOC 2 Type I reports describe a vendor's security controls and provide an auditor's opinion that those controls are suitably designed to meet the relevant trust services criteria—evaluated at a single point in time.
SOC 2 Type II reports evaluate whether those controls actually operated effectively over a defined period, typically 12 months. Type II requires the auditor to test the controls in operation, not just confirm they exist.
For vendor evaluation purposes, Type II is the meaningful standard. Type I tells you the vendor had controls designed appropriately on the date of the audit; it does not tell you those controls worked. A vendor can obtain a Type I report in a matter of weeks by implementing controls immediately before the audit date—controls they subsequently abandon.
Always require Type II. A vendor offering only Type I should be asked to explain why and given a timeline for Type II completion if the relationship is to continue.
Do not accept a SOC 2 certificate or a one-page attestation letter. Request:
Report Currency:
Scope: 3. Does the scope of the audit include the specific systems used for the legal AI product you are evaluating? 4. Does the scope include AI model inference infrastructure (not just data storage and administrative systems)? 5. Are all five trust services criteria covered, or only Security?
Subservice Organizations: 6. Does the vendor use subservice organizations (e.g., AWS, Azure, OpenAI) that are carved out of the audit scope? 7. If subservice organizations are carved out, does the vendor have separate SOC 2 reports or equivalent certifications for those subservice organizations? 8. Does the vendor have any dependency on third-party AI APIs (e.g., sending your queries to an external LLM) that are not covered by the report?
Exceptions: 9. Are there any exceptions or qualifications in the auditor's opinion? 10. For any exceptions identified, has the vendor provided remediation documentation?
Confidentiality and Privacy Controls: 11. Does the Confidentiality trust services criterion address data categorization for legal/privileged content specifically? 12. Does the Privacy trust services criterion address data retention limits and the ability to delete client data on request? 13. Is there explicit documentation of controls preventing client document content from being used for model training?
Contract Supplement: 14. Does the vendor's Data Processing Agreement or service contract include zero-data-retention commitments for client document content? 15. Does the contract include a HIPAA Business Associate Agreement if you handle health-related client matters?
SOC 2 is critically silent on several issues that matter specifically to legal AI:
Training data use: SOC 2 does not evaluate whether client data is used to train AI models. A vendor with a clean SOC 2 report can still use your client documents for model improvement. The only protection is contractual—a zero-data-retention clause that prohibits this use.
Model security: SOC 2 does not evaluate the security of AI model weights, prompt injection vulnerabilities, or the security of inference-time processing. A vendor with robust data storage controls can still have significant AI-specific security vulnerabilities.
Legal-specific confidentiality: SOC 2 has no concept of attorney-client privilege, work product doctrine, or the specific confidentiality obligations of legal practice. Confidentiality controls in SOC 2 address unauthorized disclosure of data—not the legal significance of the data.
Data residency compliance: SOC 2 does not verify that data stays within specific geographic jurisdictions. A vendor can pass a SOC 2 audit while storing client data in jurisdictions that conflict with EU GDPR or other data localization requirements.
ISO 27001: An international information security management standard that addresses security management systems more comprehensively than SOC 2. ISO 27001 certification requires ongoing surveillance audits, making it a stronger indicator of sustained security posture. For EU clients, ISO 27001 is often more familiar and trusted than SOC 2.
HIPAA Business Associate Agreement: If your firm handles health-related litigation, personal injury, workers' compensation, or any matter involving protected health information, you need a HIPAA BAA with any vendor processing that data. SOC 2 does not substitute for a BAA.
GDPR Data Processing Agreement: For firms representing EU data subjects or subject to GDPR, a formal DPA that satisfies Article 28 requirements is required regardless of SOC 2 status.
A 150-attorney firm evaluating a legal AI research and drafting platform completed the following evaluation:
Step 1: Requested full SOC 2 Type II report. Vendor provided a one-page certificate. Firm pushed back; vendor provided the full report. Report was 14 months old—outside the 12-month currency standard.
Step 2: Requested bridge letter. Vendor provided a management assertion letter signed by its CISO. Checklist items 1–2 addressed.
Step 3: Reviewed scope. Discovered that the AI inference infrastructure—the GPU servers that process legal document queries—was managed by a subservice organization (a major cloud provider) that was carved out of the audit. Requested SOC 2 report for the cloud provider. Cloud provider's report obtained; covered Security and Availability but not Confidentiality.
Step 4: Reviewed exceptions. One exception identified in the original report relating to multi-factor authentication enforcement for administrative accounts. Vendor provided remediation documentation showing the exception was resolved.
Step 5: Reviewed data use terms. Vendor's standard ToS permitted using "aggregate and anonymized" query data for model improvement. Negotiated a zero-data-retention clause for all client document content and queries. Vendor agreed.
Step 6: Confirmed HIPAA BAA was available for firm's personal injury practice group.
Firm approved the vendor with the amended contract terms.
Harvey AI – Offers enterprise agreements with zero-data-retention commitments and SOC 2 Type II; widely used in large law firm deployments.
CoCounsel – Thomson Reuters-backed; strong documentation of security posture and data handling for enterprise deployments.
Relativity – Comprehensive security documentation; SOC 2 Type II with Confidentiality criterion; widely used in ediscovery contexts where security scrutiny is high. Compare Everlaw vs Relativity.
Everlaw – Strong security posture for cloud-based ediscovery; relevant SOC 2 documentation available under NDA.
Ironclad – Contract management platform with enterprise security documentation; relevant for firms evaluating contract AI tools.
Q: A vendor says they are "SOC 2 compliant" but have not completed their first Type II audit. Is this acceptable?
A: Only if the vendor is genuinely new and you have confirmed they are in the audit period. Ask for the start date of the current audit period and expected report delivery date. Require a contractual commitment to provide the Type II report and a right to terminate if significant exceptions are identified.
Q: Our firm's corporate clients are asking us to document our AI vendor security posture. What should we provide?
A: A vendor security summary documenting: the specific AI tools used with client data, each vendor's SOC 2 status (Type II with report date), subservice organization structure, data use and retention terms, and any jurisdiction-specific certifications. This is a standard request in outside counsel questionnaire updates.
Q: If a vendor's SOC 2 report has exceptions, is that automatically disqualifying?
A: Not automatically. Evaluate the nature of the exception (how significant is the control?), when it was identified, whether remediation documentation is available, and whether it has recurred. A single exception with documented remediation is different from recurring exceptions in core security controls.
Q: We use a legal AI tool that routes our queries through a major LLM API. How do we evaluate the security of that indirect arrangement?
A: Identify the specific LLM API in use (OpenAI, Anthropic, etc.) and obtain their enterprise security documentation separately. Confirm whether the legal AI vendor's contract with the LLM provider includes zero-data-retention terms. This is checklist item 8 and is frequently the weakest link in the security chain.
Q: Is there a standard law firm AI vendor security questionnaire we can use?
A: The Sedona Conference and various state bar associations have published AI vendor guidance. The ILTA (International Legal Technology Association) maintains a vendor security questionnaire template. Adapt these frameworks with the 15-point checklist above for legal AI-specific items.
SOC 2 Type II is the necessary baseline for legal AI vendor evaluation—but it is far from sufficient. The checklist above addresses the gaps that matter most for law firms: audit currency, inference infrastructure scope, subservice organization coverage, exception history, and the critical data use issues that SOC 2 does not address at all.
The most important contractual protection for legal AI—zero-data-retention for client document content—has no SOC 2 equivalent. It must be negotiated into the vendor agreement separately. No vendor security certification substitutes for this provision.
Build vendor security evaluation into your annual review cycle, not just the initial procurement. Vendors update their systems, change subservice organizations, and modify data use policies on timelines that do not align with law firm procurement cycles. Bridge letters and periodic re-evaluation keep your documentation current and your firm's professional responsibility posture defensible.
This article reflects independent editorial analysis. LawyerAI does not accept payment for editorial coverage. Tool scores are based on methodology described in Our 5-Dimension Methodology. Last reviewed: 2026-08-10.