Vendor Risk & Agreements
Vendor Due Diligence Questionnaire
Send these questions in writing to every prospective vendor. Keep their answers. This record shows that you exercised “reasonable efforts” under Rules 1.1, 1.6, and 5.3, and that you evaluated conflicts (Rule 1.7) and communication/breach duties (Rules 1.4, 1.6).
Confidentiality and Privilege
Model Rule 1.6- Will you acknowledge in the contract that all uploaded content and its derivatives—including audio, video, transcripts, annotations, stills, timelines, reels, and defense strategy—are confidential and privileged work product? Who owns that content and its derivatives?
- Do you acknowledge that usage data (including but not limited to usage/access/engagement logs for queries, annotations, transcript, audio, and video) which are defense strategy— is confidential and privileged work product?
- Can you confirm in writing that our uploads and AI outputs will not be used to train or improve any internal or external AI models?
- Do you or any subprocessor run AI transcription, summarization, tagging, or “insights” on our data? Which models or services perform that work?
- Do you or your AI providers retain any record of our prompts, uploads, or outputs for product improvement or any other reason?
- Do you agree that law enforcement or prosecutors or their agents accessing our content and/or usage data absent a subpoena/warrant constitutes a data breach?
- Can you contractually guarantee that no law enforcement or prosecution agency can access our workspace, usage data, annotations, or analytics derived from our data?
- Do you carry cyber-liability insurance covering incidents involving our data? Will you attest to that coverage? What is the monetary limit and scope of your cyber-liability and indemnity insurance related to data breaches that could affect privilege or defense clients? Will you show us proof of this coverage?
- Will your cyber-liability insurance cover law enforcement or prosecutors or their agents accessing our content and/or usage data absent a subpoena/warrant? Will you provide evidence of said coverage?
- What is your immediate internal protocol when an employee or the company receives a subpoena, warrant, or other legal request (“legal request”) for client data?
- If you receive a legal request seeking our data, will you agree to:
- refuse absent legal compulsion, and
- notify us immediately so we can seek protective relief, unless prohibited by law?
- If you receive a legal request seeking our data, will you agree to:
- What specific contractual and policy measures prevent your employees from discussing, using, or selling information they may learn from supporting the defense organization?
Competence and Technology Understanding
Model Rule 1.1; ABA Formal Opinion 512- Do you warn end users that AI output may be incomplete or inaccurate and must be human-verified?
- Where will our data be stored and processed (physical and regional locations)?
- List every subprocessor (cloud provider, email delivery, human transcription service, etc.) that can access client data or transcripts.
- Are all subprocessors bound by written confidentiality, security standards, and rapid-breach-notice duties?
- Will you notify us before adding or changing subprocessors and allow us to object or terminate?
- Do you maintain a written incident-response plan, and will you share a summary of it?
- After detecting unauthorized access or exfiltration of our data, will you notify us without undue delay (e.g., within 72 hours) and include the scope, impact, and mitigation steps?
- After an incident, will you provide the forensic and audit details we need to meet our ethical duties to notify affected clients?
Conflicts of Interest and Vendor Independence
Model Rule 1.7- Do you currently provide products or services to police, sheriffs, prosecutors, investigators, or other law-enforcement entities that involve hosting, analyzing, or indexing digital evidence?
- If your company serves law enforcement, prosecutors, or courts, what mandatory, internal, and technical firewalls are in place to prevent support staff serving those customers from accessing or seeing any data, activity logs, or metadata related to the defense organization?
- Do you guarantee that all product improvements derived from Usage Data, Aggregated Data, and Customer Feedback are contractually restricted from being applied, marketed, or developed for the benefit of law enforcement agencies or related prosecutorial entities? How is this monitored and enforced?
- Do you sell or plan to sell analytics, summaries, or “insights” trained on defender uploads to law-enforcement clients?
- If our data includes Personal Data subject to the GDPR, will you agree to delete or return all Customer Personal Data within ninety (90) days after the termination of processing, based on our choice?
Personnel Training, Access Controls, and Audit Logging
Model Rule 5.3; ABA Formal Opinions 477R, 498- Do you provide mandatory training for all relevant personnel on the ethical obligations of lawyers, specifically regarding confidentiality, and data handling related to attorney-client privilege?
- How do you enforce the principle of least privilege? Is staff access to client data (including logs and metadata) restricted based on their role and business need? How do you ensure those restrictions are honored? What is the process for if they are not honored?
- If any staff (including support or engineering teams) works remotely, what specific security and monitoring protocols are in place to supervise their handling of confidential client data?
- Do you enforce multifactor authentication (MFA), single sign-on (SSO), and role-based access for all accounts, including vendor-support accounts?
- Do you maintain immutable audit logs for all access attempts to the defense data, including access by internal technical/support staff? Do these audit logs show which named user (including vendor staff) accessed which file, when, and what they did?
- Will you provide those audit logs to us on request within 72 hours for litigation, ethics review, or incident response?
Third-Party Audits, Data Rights, and Vendor Continuity
Model Rule 5.3; ABA Formal Opinions 477R, 498- Do you agree to submit to standard, jointly approved, independent, third-party security and ethical audits, with results remaining confidential and privileged work product, confirming our supervisory authority?
- On termination, can we export all original media, transcripts, annotations, highlights, issue tags, and timelines in human-usable formats without punitive fees?
- Will you agree to delete all original, identifiable Customer Data and other Confidential Information upon the expiration or termination of the agreement, unless that data is retained temporarily in standard backups subject to the Agreement’s strict confidentiality restrictions? Will you certify that deletion?
- Will you agree not to retain any “de-identified,” “aggregated,” or “product-improvement” copies of our content data after termination unless we explicitly allow it?
- Do you have anti-retaliation and service-continuity commitments ensuring that our access, pricing, or support will not be affected if we challenge your technology in court?
- Provide documented proof of your financial health for the past three years, including liquidity ratios, debt-to-equity, and revenue trends, to confirm the PDO can assess vendor-continuity risk.