SOC 2 for legal tech companies selling to law firms
A law firm’s duty to protect client data becomes your vendor review. Here is what it asks.
SOC 2 for legal tech starts with the buyer’s own rules. Under the American Bar Association (ABA) Model Rules, a lawyer must make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, client information.1 That duty reaches outside services, including Internet-based storage of client information.2
Your vendor review is how a firm shows it made those efforts. A SOC 2 report answers part of it. Your written answers cover the rest.
The rules are a template. Each state adopts its own, and the ABA says so: the rules and opinions of individual jurisdictions are controlling.3 The structure below holds across them, but the firm’s own jurisdiction decides the details.
What the rules ask of the firm
Reasonable is a judgment, and the ABA says what goes into it. Comment [18] to Rule 1.6 lists the sensitivity of the information, the likelihood of disclosure without more safeguards, the cost and difficulty of adding them, and whether they make the tools too hard to use.4 A client can also require measures beyond the rule.
Formal Opinion 477R, issued in 2017, turns that into a fact-based analysis and adds a list for choosing a technology vendor.3 The factors are reference checks and vendor credentials, the vendor’s security policies and protocols, its hiring practices, confidentiality agreements, a conflicts check system to screen for adversity, and an available legal forum if the vendor breaks the agreement.
Formal Opinion 512, from July 2024, applies the same duties to generative AI tools. It tells lawyers to read and understand a tool’s terms of use and privacy policy, and it requires informed client consent before client information goes into a self-learning tool.5 It also points lawyers to questions about the vendor: whether the tool keeps information after the service ends, and whether the lawyer will be notified of a breach or of legal process seeking client information.
What a vendor can show for each factor
Read the 477R list as a questionnaire. Each line has a document that answers it, and a SOC 2 report covers some of them directly.
| Due diligence factor | What answers it |
|---|---|
| Reference checks and vendor credentials | Your SOC 2 report, with the CPA firm named, plus customer references you are free to give |
| Security policies and protocols | Your policy set, and the system description and controls in the report |
| Hiring practices | Your background check and onboarding policy, which the report tests where it is a control |
| Confidentiality agreements | Staff confidentiality agreements and the customer agreement or data processing addendum |
| Conflicts check to screen for adversity | A written statement of who on your staff can see customer matter data, and how tenants are kept apart |
| A legal forum for relief | The governing law and venue clauses in your agreement |
The conflicts factor is particular to legal buyers. A firm can be adverse to another of your customers, and your answer is an access model, not a promise. For the rest of the questionnaire, how to answer a security questionnaire has wording, and the vendor assessment template shows the questions from the firm’s side.
What that means for your system
Four parts of a legal tech product follow directly from these rules.
- Confidentiality commitments
- Security tests who can reach data and how it moves. If your contracts make confidentiality commitments about matter data, the Confidentiality category tests how you identify and dispose of it.6 The scoping tool decides whether it belongs.
- Data location and deletion
- Where client documents are stored, and what happens to them when a firm leaves. Opinion 512 asks exactly that of AI tools. Write the deletion rule down and keep the evidence that it ran. A data retention policy is the home for it.
- AI subprocessors
- If your product sends documents to a model provider, the firm’s duty to read the terms runs through you to that provider. The guide for AI companies covers training clauses, retention at the provider and the carve-out.
- Breach and legal process notice
- Say how fast you tell a firm about an incident, and what you do when someone serves you with a demand for a firm’s data. Both belong in your incident response plan and your agreement.
Be clear about our limit. Polara G.R.C. scopes Security only, fixed rather than a setting. If a firm’s contract needs Confidentiality tested, a firm that runs that scope directly is the right route.
What a SOC 2 does not promise
A SOC 2 report says whether your controls meet the criteria in scope, as described, for the date or period examined.7 It does not say whether attorney-client privilege survives a given use of your product. That is a legal question for the lawyer.
It also does not say a firm’s use of your tool is reasonable, or that the firm has met its own duties. The rules leave that judgment with the lawyer. Your report is evidence for it. Say that plainly in your security overview.
If a reviewer wants to see what a report contains before yours exists, the sample report walkthrough shows the structure section by section. If you also build for agencies or banks, the guides for agencies and fintech apply the same structure to a different buyer.
Through Polara Labs it is audit-ready starting at about a week of focused work. Onboarding is $2,000 one time, then SOC 2 Type 2 is $600 a month on a 12-month term, and your first SOC 2 Type 2 audit is included in the term. A Type 1 report is optional: $2,000 added later, or $4,000 in total with onboarding, with the engagement fee for the independent partner auditor inside it. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
Do law firms require SOC 2 from legal tech vendors?
Which ABA rules apply to a law firm's software vendors?
Does SOC 2 cover attorney-client privilege?
What does ABA Formal Opinion 512 mean for AI legal tech vendors?
Should a legal tech SOC 2 include Confidentiality?
Sources
- Model Rules of Professional Conduct, Rule 1.6: Confidentiality of Information
- Rule 5.3 Responsibilities Regarding Nonlawyer Assistance, Comment
- Formal Opinion 477R: Securing Communication of Protected Client Information
- Rule 1.6 Confidentiality of Information, Comment
- Formal Opinion 512: Generative Artificial Intelligence Tools
- TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy
- SOC 2 Report
Get audit-ready without a compliance team.
The readiness assessment is free, with no payment and no card. Onboarding is $2,000 one time, then SOC 2 Type 2 is $600 a month on a 12-month term, and your first SOC 2 Type 2 audit is included in the term. You can be audit-ready starting at about a week.
Take the free assessmentPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.