Dispute records are among the most sensitive documents a firm holds: privileged advice, commercial secrets, evidence that decides eight-figure outcomes. The productivity case for AI tools is real; so is the confidentiality risk of choosing badly. These are the questions we believe any firm should ask - of us or of anyone.
1. Is our data used to train any model? The only acceptable answer is an unqualified no, in the contract. Watch for hedges like "may be used to improve our services".
2. Who can see our documents? Ask specifically about the vendor's own staff. The strong answer is: no routine access exists, support access requires written consent per incident, and every access lands in an audit log the client can inspect.
3. Where does the data live, and where does it travel? Demand a named region and a complete subprocessor list with what each one sees. A vendor who cannot produce that list quickly does not have one.
4. Can it be permanently deleted - and proven? Deletion should destroy database rows and stored originals, verify the destruction, and produce written confirmation. "We delete on request" without a verification mechanism is a promise, not a control.
5. What happens when the AI is wrong? The honest answer describes gates, not accuracy claims: what stops an unsupported statement from reaching a filed document? In datum's case, a code-enforced citation gate blocks export of any factual sentence the record does not support - it cannot be talked out of refusing.
6. What is certified, and what is merely claimed? Certifications matter, and so does candour about their absence. A young vendor stating plainly what is live, what closes at deployment, and what awaits counsel or audit is showing you its real security culture - which is what you are actually evaluating.
Our own answers to all six, stated without gloss, are at datumclaims.com/trust.