Every legal AI vendor has a slide in their sales deck that says, "We do not train our models on your data." For legal operations leads, managing partners, and in-house counsel, this phrase has become background noise. The real challenge during procurement is moving past marketing promises to verify exactly how a vendor handles, retains, and secures client data in their actual documentation.
Evaluating these platforms requires a practical, document-driven approach to due diligence. This guide breaks down the published security policies, data retention commitments, and compliance certifications of five widely used legal AI platforms. It translates high-level privacy claims into concrete facts you can bring to your next procurement meeting.
By examining what vendors publish in their security documentation, buyers can compare platforms like Everlaw and DISCO on security, or weigh the enterprise policies of CoCounsel Legal against Lexis+ with Protege. Here is what the documentation actually says.
What "we don't train on your data" actually needs to include
When a vendor claims they do not train on your data, a buyer must look for three distinct pillars of verification.
First, look for a written, contractual no-training commitment. A statement on a blog post or marketing page is not legally binding. The commitment must live in the master services agreement (MSA) or the data processing addendum (DPA).
Second, identify the stated retention window. Many primary vendors do not run their own large language models (LLMs). Instead, they send your prompts and files to third-party model providers. A buyer must confirm the retention window for both the primary vendor and the underlying model provider. Some vendors offer zero data retention or same-day deletion, which minimizes the window of vulnerability.
Third, look for independently audited certifications. Self-attestation is common, but independent audits verify that a vendor actually practices what it publishes. These audits include SOC 2 Type II, ISO 27001, and FedRAMP.
For context, Harvey serves as a benchmark for certification density in the legal AI market. According to Harvey's security page, the vendor holds SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, and AIUC-1 certifications and attestations, which are audited by Schellman (per the Harvey Trust Center). Harvey's documentation states that it requires zero data retention from its model providers by default, and a same-day retention option is available for some customers (as detailed on Harvey's security page). Harvey does not use inputs, outputs, or uploaded documents to train its underlying models.
While this site does not track Harvey as a tool, its public trust stack shows what a fully documented security posture looks like. Now, let us compare the five tracked tools.
Vendor by vendor: what the policy documents say
The following sections detail what the published documentation for each of the five tracked legal AI platforms says about training, retention, and security standards.
CoCounsel Legal (Thomson Reuters)
According to Thomson Reuters security documentation, user prompts and content uploaded to CoCounsel Legal are not used to train or improve CoCounsel, its associated products, or the underlying LLMs. Thomson Reuters states that its third-party model providers, including OpenAI and Google, are contractually prohibited from training on customer data.
To protect confidentiality, Thomson Reuters disables those third-party providers' abuse-monitoring tools. This step ensures that no external human reviewer can see your customer content. Thomson Reuters outlines these protocols in its "The Two Non-Negotiables of Secure Legal AI" post and its CoCounsel security FAQ.
- Buyer note: CoCounsel is a general-purpose legal AI platform. While third-party model training is contractually blocked, confirm that these specific provider agreements are mirrored in your custom firm contract. This is especially true if you are evaluating the platform via a CoCounsel vs. Lexis+ with Protege for Legal Research (2026) comparison.
Lexis+ with Protégé (LexisNexis)
LexisNexis states on its security pages that it never uses customer data to train AI models. The vendor reports that user prompts and uploaded documents are never used to train external AI models.
For technical security, LexisNexis encrypts data with AES-256 at rest and TLS 1.2 or higher in transit. The vendor says it follows the RELX Responsible AI Framework. This framework is detailed in the Lexis+ AI Security Information document published for law schools.
- Buyer note: The RELX framework is an enterprise-wide standard. If you are comparing research tools, make sure to ask for the specific security documentation that covers the new agentic orchestration layer in Lexis+ with Protege.
Everlaw
Per the Everlaw Trust Center, the platform's AI Governance Framework states that none of Everlaw's LLMs will train or fine-tune their models or services on customer data. The underlying LLMs do not retain customer data once processing completes (as documented on Everlaw's AI Assistant Framework page).
Everlaw holds SOC 2 Type 2 certification across security, availability, confidentiality, and privacy. The vendor also maintains an information security management system aligned with ISO 27001.
- Buyer note: Everlaw bundles its core AI features directly into its per-gigabyte rate. When analyzing Everlaw Alternatives for Law Firms (2026), ask the competing vendors if their security certifications cover their AI features as comprehensively as Everlaw's certifications cover theirs.
RelativityOne
Relativity's compliance documentation lists ISO/IEC 27001:2022, ISO/IEC 27018:2019, SOC 2 Type II, SOC 3, HIPAA, IRAP, and CSA CAIQ certifications and attestations. Relativity also holds FedRAMP Moderate authorization. The vendor announced a separate FedRAMP-authorized RelativityOne Government product for agencies in its own newsroom.
For its generative AI features, known as Relativity aiR, the vendor states that Azure OpenAI processing of customer data is not retained beyond the customer's own instance. This data is not used to train generative AI models belonging to Relativity, Microsoft, or any third party, according to the Relativity aiR data solutions page.
- Buyer note: RelativityOne has the most heavily certified security stack of the platforms compared here, as detailed on the Relativity compliance page. Ensure your contract explicitly covers whether your work uses the standard commercial instance or the government-authorized cloud instance.
DISCO (CS DISCO)
According to its own AI features page, CS DISCO states that its Cecilia AI assistant functions within secure cloud perimeters, does not train on your data, and adheres to SOC 2 and HIPAA-ready frameworks (per the DISCO AI features page). The broader DISCO platform undergoes an annual SOC 2 Type 2 audit covering security, availability, and privacy controls.
- Buyer note: DISCO does not publish a specific data retention window for Cecilia AI. While competitors like Harvey offer a same-day retention option, DISCO's public documentation does not state a clear retention window for Cecilia AI. Buyers should flag this gap and ask for written clarification in their custom contract. This is a key point to raise if you are evaluating Everlaw vs. DISCO for AI eDiscovery (2026).
Certifications compared
The following table summarizes the security certifications and frameworks published by each of the five tracked vendors, along with Harvey for context.
| Platform | SOC 2 Type II | ISO 27001 | FedRAMP Moderate | Other Compliance Frameworks |
|---|---|---|---|---|
| RelativityOne | Yes | Yes (ISO/IEC 27001:2022) | Yes | ISO 27018:2019, SOC 3, HIPAA, IRAP, CSA CAIQ |
| Everlaw | Yes | Yes (Aligned) | No | Covered under Everlaw Trust Center |
| DISCO | Yes | No | No | HIPAA-ready frameworks |
| CoCounsel Legal | No published details | No published details | No | Thomson Reuters internal standards |
| Lexis+ with Protégé | No published details | No published details | No | RELX Responsible AI Framework |
| Harvey (context only) | Yes | Yes | No | ISO 27701, ISO 42001, AIUC-1 |
RelativityOne holds the most certifications of the five tracked platforms. This dense compliance profile makes it a common choice for enterprise legal departments and government agencies. Smaller firms can evaluate how these certifications align with their target practice areas by reading Legal AI for Solo & Small Law Firms: A Buyer's Guide.
What state bar rules actually require before you sign
State bar rules increasingly emphasize that attorneys must evaluate vendor data practices before they adopt a tool. Diligence is an ongoing procurement obligation, not a one-time click-through check.
The American Bar Association released ABA Formal Opinion 512 in July 2024. This opinion directs lawyers to understand the risks and benefits of the specific AI tool they plan to use (per the ABA July 2024 news release). Practically, this means lawyers must review a vendor's terms of service, data retention practices, and security posture prior to adoption. This obligation exists before any individual user types client data into the prompt bar.
The New York City Bar Formal Opinion 2024-5, issued in August 2024, expands on these requirements. Titled "Ethical Obligations of Lawyers and Law Firms Relating to the Use of Generative Artificial Intelligence in the Practice of Law," the opinion addresses competence (Rule 1.1), confidentiality (Rule 1.6), and the supervision of nonlawyer assistance (Rules 5.1 to 5.3). The NYC Bar explicitly frames vendor evaluation as an ongoing obligation that requires regular verification of vendor security claims (per the NYC Bar formal opinion page).
We have covered the broader confidentiality risks, state bar opinions, and case law in our guide, Does Your Legal AI Tool Train on Client Data? What the Policies Actually Say. This checklist translates those ethical obligations into specific questions you can ask during procurement.
The diligence checklist
Use the following checklist during procurement to verify vendor claims before signing an agreement.
- Verify the contract, not the marketing: Ensure the "no-training" commitment is written directly into the Master Services Agreement or the Data Processing Addendum. Do not rely on website copy.
- Determine the exact retention window: Ask for the specific data retention window for the AI features. Check if it is zero-retention, same-day retention, or thirty-day retention. Get this window in writing.
- Request the actual SOC 2 Type II report: Do not accept a badge on a webpage as proof. Request the actual auditor's report, verify the date of the audit, and read the section on confidentiality controls.
- Scope the certifications: Confirm whether the vendor's security certifications (such as ISO 27001) apply to the generative AI features specifically, or if they only cover the legacy base platform.
- Map the subprocessors: Ask for a list of all third-party model providers (such as OpenAI or Microsoft Azure). Verify that these subprocessors are contractually bound by the same no-training and retention rules as the primary vendor.
- Audit the gaps: Identify what the vendor does not publish. If a vendor does not state its retention window, treat it as a priority question for your sales representative.
FAQ
Do CoCounsel, Everlaw, RelativityOne, Lexis+, and DISCO train their AI models on client documents?
No, according to each vendor's published security and privacy documentation. These platforms state that customer inputs, prompts, and documents are not used to train or improve their underlying models. Note that these are vendor statements rather than independent audits. You should ensure these commitments are written into your contract.
What certifications should a firm look for in a legal AI vendor?
A firm should look for a SOC 2 Type II certification at a minimum, which proves that a third party has audited the vendor's security and confidentiality controls. For highly sensitive work, look for ISO 27001 alignment or FedRAMP Moderate authorization. RelativityOne is the most heavily certified of the tracked platforms compared here.
Is a vendor's stated no-training policy legally binding?
A no-training policy is only legally binding if it is included in your signed contract or Data Processing Addendum. Marketing PDFs, blog posts, and website pages can be updated or changed by the vendor at any time.
Do state bars require lawyers to vet a vendor's data practices before signing a contract?
Yes. Opinions like ABA Formal Opinion 512 and NYC Bar Formal Opinion 2024-5 require lawyers to evaluate vendor data practices, terms of service, and security protocols prior to adoption. This is an ongoing duty of competence and supervision. The broader ethics and case law framework is detailed in our guide on does your legal AI tool train on client data.
What if a vendor does not publish a specific data retention window?
Treat an unpublished retention window as a diligence flag. Ask the vendor directly to define the retention window for their AI features, and secure the response in writing before transmitting client data. For example, DISCO does not publish an AI-specific retention window for Cecilia AI, which makes it a key question to ask during procurement.
The bottom line
The phrase "we do not train on your data" has become a standard marketing claim in the legal technology industry. The real difference between platforms lies in how those claims are backed by written contracts, verified retention windows, and independent third-party audits.
Use this guide and the diligence checklist to ensure your firm's client data remains secure. Do not rely on verbal assurances during sales calls. Request the SOC 2 Type II reports, verify the subprocessor agreements, and ensure all data commitments are written directly into your final contract.