INSIGHTS
Confidentiality is a promise, privilege is a protection
What a software vendor can promise you, what a regulated law firm is bound to, and where AI sits between them.
PUBLISHED
CATEGORY
How we work

Someone on the commercial team has an indemnity clause, a call in forty minutes and no lawyer free. So they paste the clause, plus a note on what the business will actually concede, into whichever AI tool is open. The answer comes back in seconds, and it is a good answer.
Then the harder question. If that exchange is ever demanded by a regulator, a counterparty or a court, what protects it?
Confidentiality is a promise. Privilege is a protection.
The two get used interchangeably. They are not the same thing. Confidentiality, as a software vendor sells it, is contractual: a commitment not to disclose your data, not to train on it, to encrypt it, to delete it on request. Breaking it is a real claim. But it runs between you and the vendor, and gives you no basis to withhold the material from someone else who demands it.
Privilege is different in kind. It is a legal protection over communications between a client and a lawyer for the purpose of legal advice, it belongs to the client, and it rests on professional conduct rules that bind the lawyer whatever a contract says. That is the distinction our security page draws: software vendors promise confidentiality, a regulated law firm is bound to it.
The test is not what the interface looks like. It is who is on the other end. Software can find the clause and propose the language, but it cannot be the lawyer whose duties create the privilege.
The channel matters as much as the counsel
Even with a licensed lawyer on the other end, the route the message takes matters. Our self-serve engagement agreement says so rather than burying it: your use of third-party technology to communicate with us may jeopardize, limit or waive attorney-client privilege or work-product protection, the law in this area is unsettled, and we make no representation about the effect of a technology you choose and configure yourself.
The corollary for AI sits in the same document. Because we have invested in protecting client information inside our own systems, we advise clients not to use personal AI tools in connection with the representation, since that use may be discoverable and may waive privilege. Read that as the general rule, not a rule peculiar to us.
Read the terms, not the badge
Certifications tell you a provider has been audited against a standard. We hold SOC 2 Type 2, audited annually by an independent third party against security, availability and confidentiality criteria, and ISO 27001 for our information security management system, with TLS 1.2+ in transit and AES-256 at rest. What happens to the substance of a matter is a different question, answered in two other places.
At the model layer, the term to ask for is zero data retention: inputs and outputs deleted promptly after each response, documents never stored by the model provider and never used to train models. We offer that, and private deployment in dedicated cloud environments including your own tenancy, as enterprise security configurations on qualifying engagements. We do not allow third parties, including foundation model providers, to train on your data.
At the firm layer, the answer lives in the engagement agreement and differs by engagement. Section 6 of our self-serve agreement is a material condition of it: a license to use matter content to develop, test and improve the tools used in the practice, and a separate, irrevocable license to use, disclose, sell and license that content in de-identified form for AI development, with no opt-out. De-identification is designed so the content no longer identifies you, your personnel or your counterparties, recipients are barred by contract from re-identifying it, and our position is that these uses are consistent with our confidentiality duties and do not waive privilege. The enterprise engagement runs on different terms and requires at least $50,000 in annual legal spend.
Three questions cover most of it with any provider, ourselves included: who is accountable by name, what happens to inputs after each response, and what the engagement terms license. AI is not the risk here. Sending legal work through a channel where nobody is answerable for it is the risk.
INSIGHTS
See other articles

Moritz raises $9M
An oversubscribed round closed in four days, led by Y Combinator and 20VC, to build a law firm that works at company speed.

Moritz in the news
Where our funding round was covered across the technology and legal trade press, and what each piece adds.

Why we quote a flat fee before we start
Hourly billing hands you the price only after you have committed. Here is what agreeing it first changes.
