SOC 2 for legal tech companies selling to law firms

A law firm’s duty to protect client data becomes your vendor review. Here is what it asks.

SOC 2 for legal tech starts with the buyer’s own rules. Under the American Bar Association (ABA) Model Rules, a lawyer must make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, client information.1 That duty reaches outside services, including Internet-based storage of client information.2

Your vendor review is how a firm shows it made those efforts. A SOC 2 report answers part of it. Your written answers cover the rest.

The rules are a template. Each state adopts its own, and the ABA says so: the rules and opinions of individual jurisdictions are controlling.3 The structure below holds across them, but the firm’s own jurisdiction decides the details.

What the rules ask of the firm

Reasonable is a judgment, and the ABA says what goes into it. Comment [18] to Rule 1.6 lists the sensitivity of the information, the likelihood of disclosure without more safeguards, the cost and difficulty of adding them, and whether they make the tools too hard to use.4 A client can also require measures beyond the rule.

Formal Opinion 477R, issued in 2017, turns that into a fact-based analysis and adds a list for choosing a technology vendor.3 The factors are reference checks and vendor credentials, the vendor’s security policies and protocols, its hiring practices, confidentiality agreements, a conflicts check system to screen for adversity, and an available legal forum if the vendor breaks the agreement.

Formal Opinion 512, from July 2024, applies the same duties to generative AI tools. It tells lawyers to read and understand a tool’s terms of use and privacy policy, and it requires informed client consent before client information goes into a self-learning tool.5 It also points lawyers to questions about the vendor: whether the tool keeps information after the service ends, and whether the lawyer will be notified of a breach or of legal process seeking client information.

What a vendor can show for each factor

Read the 477R list as a questionnaire. Each line has a document that answers it, and a SOC 2 report covers some of them directly.

Due diligence factorWhat answers it
Reference checks and vendor credentialsYour SOC 2 report, with the CPA firm named, plus customer references you are free to give
Security policies and protocolsYour policy set, and the system description and controls in the report
Hiring practicesYour background check and onboarding policy, which the report tests where it is a control
Confidentiality agreementsStaff confidentiality agreements and the customer agreement or data processing addendum
Conflicts check to screen for adversityA written statement of who on your staff can see customer matter data, and how tenants are kept apart
A legal forum for reliefThe governing law and venue clauses in your agreement

The conflicts factor is particular to legal buyers. A firm can be adverse to another of your customers, and your answer is an access model, not a promise. For the rest of the questionnaire, how to answer a security questionnaire has wording, and the vendor assessment template shows the questions from the firm’s side.

What that means for your system

Four parts of a legal tech product follow directly from these rules.

Confidentiality commitments
Security tests who can reach data and how it moves. If your contracts make confidentiality commitments about matter data, the Confidentiality category tests how you identify and dispose of it.6 The scoping tool decides whether it belongs.
Data location and deletion
Where client documents are stored, and what happens to them when a firm leaves. Opinion 512 asks exactly that of AI tools. Write the deletion rule down and keep the evidence that it ran. A data retention policy is the home for it.
AI subprocessors
If your product sends documents to a model provider, the firm’s duty to read the terms runs through you to that provider. The guide for AI companies covers training clauses, retention at the provider and the carve-out.
Breach and legal process notice
Say how fast you tell a firm about an incident, and what you do when someone serves you with a demand for a firm’s data. Both belong in your incident response plan and your agreement.

Be clear about our limit. Polara G.R.C. scopes Security only, fixed rather than a setting. If a firm’s contract needs Confidentiality tested, a firm that runs that scope directly is the right route.

What a SOC 2 does not promise

A SOC 2 report says whether your controls meet the criteria in scope, as described, for the date or period examined.7 It does not say whether attorney-client privilege survives a given use of your product. That is a legal question for the lawyer.

It also does not say a firm’s use of your tool is reasonable, or that the firm has met its own duties. The rules leave that judgment with the lawyer. Your report is evidence for it. Say that plainly in your security overview.

If a reviewer wants to see what a report contains before yours exists, the sample report walkthrough shows the structure section by section. If you also build for agencies or banks, the guides for agencies and fintech apply the same structure to a different buyer.

What it takes, and what it costs

Through Polara Labs it is audit-ready starting at about a week of focused work. Onboarding is $2,000 one time, then SOC 2 Type 2 is $600 a month on a 12-month term, and your first SOC 2 Type 2 audit is included in the term. A Type 1 report is optional: $2,000 added later, or $4,000 in total with onboarding, with the engagement fee for the independent partner auditor inside it. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Questions

Do law firms require SOC 2 from legal tech vendors?
The ABA rules do not name SOC 2. They require a lawyer to make reasonable efforts to protect client information, including when an outside service stores it, and the ABA lists due diligence factors such as the vendor's credentials and security policies. A SOC 2 report is one document that answers several of those at once. Whether a given firm requires one is that firm's policy.
Which ABA rules apply to a law firm's software vendors?
Model Rule 1.6(c) sets the duty to make reasonable efforts against unauthorized disclosure or access, and Comment [18] lists the factors for judging reasonableness. Rule 5.3 and its Comment [3] cover services outside the firm, including Internet-based storage. Formal Opinions 477R and 512 apply those rules to communication technology and to generative AI. State rules control in each jurisdiction.
Does SOC 2 cover attorney-client privilege?
No. A SOC 2 reports on whether a vendor's controls meet the Trust Services Criteria. Whether privilege survives a particular use of a tool is a legal question for the lawyer, and no examination of a vendor answers it.
What does ABA Formal Opinion 512 mean for AI legal tech vendors?
It tells lawyers to read and understand the terms of use, privacy policy and related terms of any generative AI tool they use, and points to vendor questions such as whether the tool keeps information after the service ends and whether the lawyer will be told of a breach. A vendor that answers those in writing makes the lawyer's review possible.
Should a legal tech SOC 2 include Confidentiality?
If your contracts make confidentiality commitments about client matter data, it may belong in scope, and the scoping tool walks the decision. Polara Labs scopes Security only, so a wider scope means a firm that runs it directly. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Sources

  1. Model Rules of Professional Conduct, Rule 1.6: Confidentiality of Information American Bar Association. Paragraph (c), the duty to make reasonable efforts against unauthorized disclosure or access. Checked 2 October 2026.
  2. Rule 5.3 Responsibilities Regarding Nonlawyer Assistance, Comment American Bar Association. Comment [3], on using an Internet-based service to store client information. Checked 2 October 2026.
  3. Formal Opinion 477R: Securing Communication of Protected Client Information American Bar Association. May 2017, revised; includes the due diligence factors for technology vendors. Checked 2 October 2026.
  4. Rule 1.6 Confidentiality of Information, Comment American Bar Association. Comment [18], the factors that decide whether a lawyer’s safeguards are reasonable. Checked 2 October 2026.
  5. Formal Opinion 512: Generative Artificial Intelligence Tools American Bar Association. July 2024; confidentiality, informed consent and vendor terms for generative AI tools. Checked 2 October 2026.
  6. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  7. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.

Get audit-ready without a compliance team.

The readiness assessment is free, with no payment and no card. Onboarding is $2,000 one time, then SOC 2 Type 2 is $600 a month on a 12-month term, and your first SOC 2 Type 2 audit is included in the term. You can be audit-ready starting at about a week.

Take the free assessment

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.