• Vendor Security
  • Data Privacy
  • AI Procurement

I Helped Build a FedRAMP Program From Inside a Vendor. Here's What Law Firms Aren't Asking.

Judith Soto5 min read
A long marble corridor in an institutional building
On this page

I went to law school before I ever sold a piece of software.

I earned my JD at Brooklyn Law School and hold bar admission in New York and New Jersey. Before I was Head of Sales at OurFirm.ai, I was the subject matter expert who helped operationalize a brand-new FedRAMP program at a software vendor, working across product, security, implementation, and support to get an entire vertical built and authorized for federal accounts. I later ran security-focused sales cycles for Public Sector accounts at Salesforce, the conversations where a CISO or admin team walks through their own security posture before a deal closes. Building that muscle from inside a vendor, then sitting across from security teams year after year, taught me the same lesson from two directions: what a genuine security control looks like, and what a policy promise dressed up as one looks like.

I carried that instinct into legal tech. And I have noticed something. Law firms, some of the most risk-averse institutions in American business, are buying AI tools with less security scrutiny than a mid-market SaaS deal would get from a federal procurement officer.

That is not a knock on litigators. Evaluating a legal research platform on citation accuracy or drafting quality is the job you trained for. Evaluating whether the vendor's contracts bar its subprocessors from training on your client's documents is a different discipline entirely. It is the discipline I spent years building into a vendor's operations, and the one I now walk through with security teams on the other side of the table.

Here is what that discipline asks, translated for the litigation context.

Six questions before you sign
  1. 01
    Where does the isolation happen?Whether matter data is segregated at the tenant level architecturally, not by policy.
  2. 02
    Does the model train on what you upload?Whether a contract enforces that no with every subprocessor, backed by zero data retention.
  3. 03
    What happens in the first 72 hours?The contractual notification timeline: what they must tell you, and by when.
  4. 04
    Who else touches the data?The subprocessor list, and the security review the vendor ran on each.
  5. 05
    What are the remediation timelines?How fast they patch a critical vulnerability, and how often they penetration test.
  6. 06
    Can you get your data back?What happens on termination, and how fast they honor a deletion request.

Where does the isolation happen?

Not "is our data secure," which every vendor will answer yes to without blinking. The real question is whether the vendor logically segregates your matter data at the tenant level, and whether that segregation is architectural or just a policy promise. A privilege log means nothing if the underlying storage commingles firms.

Does the model train on what you upload?

This is the question I watch most legal buyers skip entirely. It is not enough for a vendor to say no. Ask whether a contract enforces that "no" with every subprocessor in the chain, including the underlying model providers, and whether zero data retention beyond the session needed for inference backs it up.

Verbal assurance is not a control.

Judith Soto, Head of Sales

What happens in the first 72 hours of an incident?

Every vendor has a breach response plan on a slide somewhere. Fewer have a contractual notification timeline. Ask what they must tell you, and by when, if something goes wrong. Then ask what "without undue delay" means in their paper, because that phrase alone tells you how they negotiated the addendum.

Who else touches the data, and did anyone vet them?

Subprocessor lists are not a formality. Every AI vendor sits on top of other vendors, model providers, cloud infrastructure, sometimes a third-party research index. Ask for the list. Ask what security and privacy review the vendor ran on each subprocessor before onboarding, and whether that review is ongoing or a one-time gate.

What are the actual remediation timelines?

Not "we take security seriously." Specific numbers. How fast do they patch a critical vulnerability versus a low-severity one. How often do they penetration test the platform, and who runs it. A vendor that has never had a third party try to break in has never had to find out where the gaps are.

Can you get your data back, and can you make them delete it?

Retention policy should be something you configure, not something you discover. Ask what happens to your data on termination, how quickly they honor a deletion request, and whether backups age out on a schedule you can see.

The risk concentrates as the platform does

None of this is exotic. It is the standard checklist any enterprise security team runs before signing anything. The gap is that most litigation teams are not bringing IT or security into an AI purchase the way they would for a case management system or a document repository, even though the AI tool is often now holding more sensitive matter data than either.

That gap matters more, not less, as firms move toward running an entire case through a single platform. The more of the litigation lifecycle, filing, research, drafting, judicial intelligence, that firms consolidate into one command center, the more concentrated the risk sits in that one vendor relationship. Centralization is a genuine advantage when it comes to speed and consistency. It is also exactly why the security questions above stop being optional.

You are not just trusting a tool with a document anymore. You are trusting it with the case.

Judith Soto, Head of Sales

I did not write this to tell you our answers are better than the next vendor's. I wrote it because too few firms are asking the questions in the first place, and a market only gets more secure when buyers start demanding proof instead of assurance.

We publish ours. Read our own answers to these questions in the Security Addendum and the Data Processing Addendum, or start at the Trust Center for the full picture.

Ask every vendor the same. If they cannot answer in writing, that is your answer.

See how OurFirm.ai answers every one of these questions, in writing.

Visit the Trust Center

Frequently asked questions

What security questions should a law firm ask before buying an AI tool?
Six, at a minimum: whether your matter data is isolated at the tenant level architecturally rather than by policy; whether a contract bars every subprocessor from training on your uploads; what the contractual incident notification timeline is; who the subprocessors are and how they were vetted; the actual patch and penetration-test cadence; and whether you can retrieve and force deletion of your data on termination.
How do I know if an AI vendor trains its models on what I upload?
A verbal no is not a control. Ask whether a contract enforces that no with every subprocessor in the chain, including the underlying model providers, and whether zero data retention beyond the session needed for inference backs it up in writing.
Why does data isolation matter for attorney-client privilege?
A privilege log means nothing if the underlying storage commingles firms. The question is whether the vendor logically segregates your matter data at the tenant level, and whether that segregation is architectural or just a policy promise.
Where can I see OurFirm.ai's own answers to these questions?
They are published. Our Security Addendum and Data Processing Addendum spell out the technical and contractual controls, and the Trust Center collects the full picture in one place.

Keep reading

Put it to work on your next matter.

Book a DemoMore from the blog