Guarded like privilege depends on it
Law firms hold other people’s secrets for a living. The platform that holds your firm has to meet a higher bar. Here’s how we do it.
Role-based access control
Attorney, paralegal and staff roles scope what every user can see and do, down to per-file permissions on case documents.
Encrypted in transit
All traffic runs over HTTPS/TLS, including document uploads and downloads via time-limited presigned URLs.
Session protection
Token-based authentication with refresh rotation and automatic inactivity sign-out on every device.
Audit everything
Sign-in activity reports, full case version history, document signing activity logs, and account change history.
HIPAA & BAA workflows
Business Associate Agreement handling is built into the admin console for health-adjacent practices.
PCI-compliant payments
Card data never touches our servers. Payments run through PCI-compliant, legal-specific processing with tokenized sessions.
Client-side privacy
Client portal access is email-verified per share; upload links can be disabled the moment they’ve served their purpose.
Trust account integrity
Operating and IOLTA funds are separated at the payment-routing layer, with per-case ledgers for reconciliation.
The AI reads what you hand it, and forgets it.
LawOffice.AI drafts, summarizes and checks documents with Claude by Anthropic, uses OpenAI for the voice assistant and AI libraries, and indexes discovery sets with Google Cloud. Here is exactly what happens to a document when a member of your firm uses those features.
Your documents are never training data
The AI reads a document only when a member of your firm attaches it to a request. It is sent for that request and is not used to train or improve any model, under Business Associate Agreements with Anthropic, OpenAI and Google Cloud.
Zero data retention at the model
Documents travel inside the request itself. Nothing is uploaded to a model provider’s file store, and the model provider does not keep your inputs or outputs after the response is returned.
Prepared copies stay in your own storage
When a Word or Excel file is converted for the AI to read, the converted copy is kept in your firm’s encrypted cloud storage for thirty days so repeat use is fast, then deleted. It never leaves your environment.
Drafts and conversations are not stored by us
What the AI writes lands in your Word document, and nothing else. Case chat lives in your browser session. The platform keeps no copy of prompts, conversations or drafts.
Case citations are checked, not researched
LawOffice.AI does not do legal research. The AI is instructed to cite case law only from the documents you attach, and every case citation in a draft is checked against CourtListener, a public database of court opinions, so a cite that no case is reported at, or that belongs to a different case, is flagged in red. Only the citation itself is sent for that check, never your document. The check confirms a case exists under that name; it does not confirm what the case holds, and it is no substitute for reading the opinion.
An audit trail for every run
Each AI run is logged to your office: who ran it, when, which feature, which case, which documents it read, and what it cost. The AI Activity report shows the log and the usage totals per member and per feature, and exports to a spreadsheet.
Your work product stays yours
Extraction tables, discovery set indexes and document type style guides are stored for your office because they are your work product. An administrator can delete any of them at any time, including the search index behind a discovery set.
Every AI charge is itemized per member and per run on the office’s bill, at published rates. The executed agreements with each provider are available to administrators inside the platform.
Ask us the hard questions.
Security reviews welcome. Bring your IT consultant, your malpractice carrier’s checklist, or your bar’s trust-accounting rules. We enjoy this part.
No credit card required · Free onboarding · Cancel anytime
