Frequently Asked Questions

The professional-responsibility and computing/security questions attorneys ask most before putting client materials into BriefBank. Two sections on this page: Attorney Duties & Ethics first, Computing & Security second.

Attorney Duties & Ethics

California-anchored analysis of the professional-responsibility questions lawyers ask before putting client materials into a legal-AI tool. Companion to the Computing & Security section below.

1. Does using BriefBank waive the attorney-client privilege?

Short answer: Generally no — not when the tool is used properly. Waiver requires a disclosure inconsistent with maintaining confidentiality; handing documents to a confidentiality-bound vendor that assists counsel is not that.

California's privilege is entirely statutory (Evid. Code §§ 950–962), and once it attaches it is strong — it protects the whole confidential communication regardless of content, and a court may not even peek in camera to test it (Costco Wholesale Corp. v. Superior Court (2009) 47 Cal.4th 725). So the waiver question turns on one thing: whether the statutory trigger — a disclosure inconsistent with preserving confidence (Evid. Code § 912) — has been pulled.

  • A confidentiality-bound vendor assisting counsel is a "privileged person" — an agent of the lawyer — not an outside third party. Evid. Code § 952 defines the confidential communication to include disclosure to third persons to whom disclosure is reasonably necessary to accomplish the purpose of the consultation, and § 912(d) makes the point express on the waiver side: such a reasonably-necessary disclosure is not a waiver. That is the statutory home of the agent/interpreter/consultant doctrines, with United States v. Kovel, 296 F.2d 918 (2d Cir. 1961), as the federal analogy and the Restatement's "privileged persons" doctrine (Rest.3d Law Governing Lawyers §§ 70, 79) as the gathering label.
  • But application to a specific AI vendor is fact-specific, and we are aware of no controlling California appellate authority on point. A court could distinguish a vendor that merely stores/processes data from a Kovel-style professional necessary to the advice, so the strength of the no-waiver argument tracks the necessity of the vendor, its confidentiality terms, and the attorney's supervision.
  • Distinguish Heppner. United States v. Heppner (S.D.N.Y. 2026) 820 F.Supp.3d 292 is the case adverse counsel will wave around — but it held the material was never privileged: a represented defendant used a public consumer chatbot on his own initiative, apart from and not at the direction of his counsel, with no confidentiality terms. It is a cautionary tale about unsupervised use of a public tool, not a holding that a confidentiality-bound, attorney-directed vendor waives an existing privilege.
When this flips: a free/consumer chatbot whose terms let the provider read, retain, or train on inputs, used without attorney direction or client consent — that is the Heppner fact pattern, where the fight is whether confidentiality ever attached at all.
Not legal advice. This is general analysis of the framework, not advice on your matter. Consult your jurisdiction's ethics counsel before acting.

2. Does using it waive the work-product protection?

Short answer: Generally no — work product is harder to waive than the privilege, and feeding material to a non-adversary tool should not waive it where confidentiality and security make adversary access unlikely.

Two features of the work-product doctrine make this the strongest of the protection questions:

  • It generally waives only on disclosure to an adversary. Unlike the privilege (which a voluntary disclosure to almost any outsider generally waives), work-product waiver turns on disclosure "to an adversary or in a way likely to get in an adversary's hand" — i.e., disclosure that substantially increases the likelihood an adversary obtains the material. On that standard, a generative-AI tool is "a tool, not a person," so feeding it is not disclosure to an adversary. That is the holding of Warner v. Gilbarco, Inc. (E.D. Mich. 2026) 820 F.Supp.3d 629, 636–637 (2026 WL 373043) — a district-court discovery order (persuasive only) holding a litigant's use of a public AI tool did not waive work product. Morgan v. V2X, Inc. (D. Colo. 2026) 2026 WL 864223, *4–*5 (also a discovery order) agreed: "routing information through a third-party system does not forfeit all privacy," and AI interactions "do not automatically compromise work product protections." The classic asymmetry, quoted in Warner: while "a voluntary disclosure to a third person will generally suffice to show waiver of the attorney-client privilege, it should not suffice in itself for waiver of the work product privilege" (United States v. AT&T Co. (D.C. Cir. 1980) 642 F.2d 1285, 1299).
  • It belongs to the attorney, not the client (California: Coito v. Superior Court (2012) 54 Cal.4th 480; Code Civ. Proc. § 2018.030), so a client's stray disclosure does not, by itself, waive it — though a client disclosure that increases adversary access can still support a waiver argument.

If even public AI use preserves work product, an enterprise vendor bound to confidentiality is on still firmer ground. And your queries, clustering, and prompts typically reflect counsel's mental impressions and litigation strategy — if anything, they are core opinion work product (Warner held as much of a litigant's own AI prompts, 820 F.Supp.3d at 636–637).

When this flips: disclosure that actually heads toward the adversary (or is likely to reach one) waives both work product and privilege; and at-issue / implied waiver — affirmatively putting the adequacy of an attorney investigation or reliance on counsel's advice in issue — can waive on the merits regardless of any upload, though it is not automatic merely because advice or attorney conduct is relevant (Wellpoint Health Networks v. Superior Court (1997) 59 Cal.App.4th 110).
Not legal advice. This is general analysis of the framework, not advice on your matter. Consult your jurisdiction's ethics counsel before acting.

3. Does using BriefBank breach my ethical duty of client confidentiality?

Short answer: Generally no — provided you have verified adequate confidentiality, security, retention, and use terms, and obtained the client's informed consent where the facts require it.

This is a different and broader regime than the two above. The privilege and work-product doctrines answer whether material can be compelled from you in a proceeding. The ethical duty of confidentiality (Bus. & Prof. Code § 6068(e)(1), implemented by Cal. Rule of Prof. Conduct 1.6; cf. ABA Model Rule 1.6) answers what you may voluntarily reveal — and it sweeps in all information relating to the representation, from any source, in any setting. The consequence practitioners miss: "not privileged" is never, by itself, a license to disclose. A fact can lose the privilege (or never have had it) and remain a protected client secret — client identity and fee arrangements, for instance, are generally not privileged (Hays v. Wood (1979) 25 Cal.3d 772), yet they remain protected secrets under § 6068(e)(1) that a lawyer may not voluntarily broadcast. California's permissive exception is narrower than the ABA's: § 6068(e)(2) and Rule 1.6(b) permit (not require) disclosure only to prevent a criminal act the lawyer reasonably believes is likely to result in death or substantial bodily harm.

Applied to BriefBank, the operative question isn't "is this privileged?" — it's "am I disclosing representation information through a confidentiality-bound channel, with reasonable care, and with consent where required?" On that test, proper use is defensible:

  • Disclosure to a confidentiality-bound agent who assists the representation is generally not the kind of "revealing" § 6068(e)/Rule 1.6 forbids — the same agent logic that keeps it inside the privilege (Q1) keeps it inside the duty.
  • But the duty attaches a reasonable-care condition and, for generative AI, a consent condition. ABA Formal Op. 477R (2017) and N.Y. State Bar Op. 842 (2010) (both persuasive, not binding in California) allow transmitting and storing client data through a third-party or cloud service where the lawyer makes reasonable efforts to prevent unauthorized access — including an enforceable confidentiality obligation. ABA Formal Op. 512 (2024) adds that the lawyer must understand how the tool retains and uses input data, adopt adequate safeguards, and obtain the client's informed consent before inputting information relating to the representation into a tool that is not adequately protective — so whether consent is required for a particular use turns on the tool's terms, access, retention, training, and risk profile, not on a flat rule.

The trap to avoid: assuming a publicly filed brief is "no longer confidential." Public availability does not strip Rule 1.6 protection — the duty reaches information relating to the representation regardless of whether it is also public (cf. ABA Model Rule 1.6) — and a filed brief still braids in client facts and strategy.

When this flips: a consumer tool with training-on-inputs terms, no enforceable confidentiality obligation, and no consent, is a confidentiality event you should not create — input no confidential data there at all.
Not legal advice. This is general analysis of the framework, not advice on your matter. Consult your jurisdiction's ethics counsel before acting.

4. Can a court compel BriefBank to hand over a lawyer's data about a client?

Short answer: A court can aim a subpoena at BriefBank, but that does not strip the protection. If the material was privileged or work-product in your hands, it stays protected when a confidentiality-bound vendor holds it — the vendor is a custodian/agent, not the holder — so the same objections apply, and the client (privilege) or you (work product) assert them and move to quash.
  • Protection travels with the data; a custodian's possession doesn't waive it. Routing documents through BriefBank as a Kovel-type, confidentiality-bound agent is not a waiver (Evid. Code §§ 952, 912(d)). Whether the subpoena lands on the firm or on the vendor, the material is met with the same privilege and work-product objections, and the holder may "refuse to disclose, and to prevent another from disclosing," the communication (Evid. Code § 954) — a third party's mere possession never made privileged material fair game.
  • The vendor is a custodian, not the privilege holder — and cannot waive for you. The privilege belongs to the client; the work product to the attorney. That is exactly why the diligence checklist insists on a contract term requiring the vendor to notify you of any legal process and not produce without giving you the chance to object, so you assert the protection.
  • Courts have quashed subpoenas to AI vendors for exactly this. Assini v. Hayward (N.Y. Sup. Ct. 2026) quashed subpoenas served on OpenAI seeking a party's ChatGPT/account records. In re OpenAI, Inc. (S.D.N.Y. 2025) denied a motion to compel specific users' ChatGPT logs as neither relevant nor proportional. In re Grand Jury Subpoena (9th Cir. 2025) held an attorney could not even be forced to hand the government a privilege log of protected documents, and sent it back for in-camera review. And Warner v. Gilbarco (E.D. Mich. 2026) held a party's AI prompts/outputs were protected opinion work product and denied the motion to compel them.
  • The one big exception — the Heppner trap. In United States v. Heppner (S.D.N.Y. 2026) the government did obtain the defendant's AI-chat records from the vendor — but only because they were never privileged in the first place (public consumer chatbot, no confidentiality terms, used apart from counsel, and a privacy policy permitting the operator to share inputs). Compellability there turned on the material being unprotected, not on any rule that vendor-held data is discoverable.

Watch-outs (the honest caveats):

  • A subpoena can still issue and force motion practice even when you ultimately win the protection fight — the protection is asserted, not automatic.
  • Vendor terms decide the edge cases. If BriefBank's contract permitted it to retain, share, or train on inputs, or lacked a notify-on-process clause, the Heppner risk creeps in.
  • Logs and metadata the vendor holds (what was searched, when, by whom) are a distinct question from the underlying documents — though queries that reflect attorney strategy are themselves core opinion work product (Warner). (Vendor-held user data is not categorically protected either: in the same OpenAI litigation, a later, separate order compelled anonymized logs on different grounds — the point here is only that such data is not automatically discoverable.)
  • Government / grand-jury / search-warrant demands on the vendor are the hardest scenario (taint teams, in-camera review), but the privilege still attaches and is asserted — it is not lost merely because the demand runs to the vendor.
Not legal advice. This is general analysis of the framework, not advice on your matter. Consult your jurisdiction's ethics counsel before acting.

5. What about the duty of competent representation?

Short answer: This is the duty most likely to trip you up — not because using AI is incompetent, but because failing to verify its output is. Competence is satisfied by understanding the tool and independently checking everything it produces.

Competence (Cal. Rule of Prof. Conduct 1.1; cf. ABA Model Rule 1.1) now has a technology dimension, and ABA Formal Op. 512 (2024) (persuasive) makes it explicit for generative AI: a lawyer must understand the tool's benefits and risks well enough to use it responsibly, and must supervise it as one would a nonlawyer assistant. The single most important competence obligation is output verification:

"[T]here is nothing inherently improper about using a reliable artificial intelligence tool for assistance[,] [b]ut existing rules impose a gatekeeping role on attorneys to ensure the accuracy of their filings."
Mata v. Avianca, Inc. (S.D.N.Y. 2023) 678 F.Supp.3d 443, 448.

The library indexes a growing 2023–2026 line of sanctions decisions punishing lawyers who filed AI-hallucinated citations without checking them — beginning with Mata v. Avianca and continuing through decisions such as Benjamin v. Costco Wholesale Corp. (E.D.N.Y. 2025) (an AI-sanctions case — not to be confused with California's privilege decision Costco v. Superior Court), ByoPlanet Int'l, LLC v. Johansson (S.D. Fla. 2025), In re Richburg (Bankr. D.S.C. 2025), Lexos Media IP v. Overstock.com (D. Kan. 2026), Fletcher v. Experian (5th Cir. 2026), Rivera v. Triad Properties (N.D. Ala. 2026), State v. Coleman (Ohio Ct. App. 2026), State ex rel. Okla. Bar Ass'n v. Reeves (Okla. 2026), Ibach v. Stewart (Ala. 2026), and United States v. Farris (6th Cir. 2026). (Full citations and sources are in the verification table below.) The lesson is uniform: the tool is fine; the unverified filing is the violation. No AI output — citation, quotation, or factual assertion — should be filed or sent without independent human verification against a primary source.

Competence therefore adds two operational duties on top of confidentiality: (a) a responsible attorney who understands the tool's limits owns its use, and (b) every output is checked before it leaves the firm.

Not legal advice. This is general analysis of the framework, not advice on your matter. Consult your jurisdiction's ethics counsel before acting.

6. Do I need to tell my client I'm using BriefBank — and when?

Short answer: There is no per se duty to announce every tool you use, but you must inform the client — and often obtain informed consent — when the AI use (a) would expose the client's confidential information to a provider that is not adequately confidentiality-bound, (b) is material to the representation or to a decision the client is entitled to make, or (c) is required by the client's own engagement terms, a protective order, or a court or regulatory rule.

The obligation flows from three rules read together, plus the governing ethics guidance:

  • Communication (Rule 1.4). A lawyer must reasonably consult with the client about the means of pursuing the objectives and keep the client reasonably informed; where AI use is a significant method affecting the work or its cost, Rule 1.4 can require telling the client. (Cal. Rule of Prof. Conduct 1.4.)
  • Scope and means (Rule 1.2). The client sets the objectives; the lawyer chooses the means but must consult, and an unusual method or a limited scope may require the client's agreement. (Cal. Rule of Prof. Conduct 1.2.)
  • Confidentiality and consent (Rule 1.6). Where inputting client information would reveal it to a provider that is not adequately confidentiality-bound, disclosure requires the client's informed consent — the client's agreement after the lawyer has explained the relevant circumstances and material risks (Cal. Rule of Prof. Conduct 1.6(a); "informed consent" defined at Rule 1.0.1(e), with an "informed written consent" variant where the matter or firm policy calls for it). Conversely, a properly configured enterprise tool bound to confidentiality and not training on inputs generally involves no "revealing" at all (Question 3), so it does not, by itself, trigger a separate consent requirement — though the safest practice is a standing engagement-letter clause.

ABA Formal Op. 512 (2024) (persuasive, not binding in California) frames the question the same way: there is no blanket duty to disclose every AI use, but the lawyer must obtain the client's informed consent before inputting information relating to the representation into a tool that is not adequately protective, and must communicate with the client where AI use is material to the representation.

So the practical triggers — disclose and/or obtain consent when:

  1. Confidential-information exposure. You would input client information into a tool that is not adequately confidentiality-bound (a consumer tool, or one that retains or trains on inputs) → informed consent required (Rule 1.6(a); ABA Op. 512). A confidentiality-bound enterprise tool generally does not require separate consent, but see the engagement-letter clause below.
  2. Materiality. The AI meaningfully affects strategy, the deliverable, the cost, or a decision the client must make → Rule 1.4 communication (and possibly Rule 1.2 agreement).
  3. Sensitivity / heightened risk. Trade secrets, internal investigations, regulated data, or a self-learning tool that trains on inputs → matter-specific informed consent (ABA Op. 512).
  4. External requirements. The client's outside-counsel guidelines or engagement terms, a protective order, an NDA, or a court or regulator rule may independently require disclosure or bar third-party processing → check and comply.

Form of consent. General advance consent in the engagement letter for routine, confidentiality-bound tools; matter-specific informed consent for sensitive matters or non-adequately-protective tools. Informed consent means the client actually understands the material risks and reasonably available alternatives (Rule 1.0.1(e)); use informed written consent where the matter or firm policy calls for it. (See template T3.)

Client vs. court — keep them separate. This question is about disclosure to the client. Whether you must also disclose AI use to the tribunal is a different duty, governed by Rule 3.3 and any judge's standing order (see Question 7); a client-disclosure obligation neither creates nor excuses a court-disclosure one.

Not legal advice. This is general analysis of the framework, not advice on your matter. Consult your jurisdiction's ethics counsel before acting.

7. Any other professional-responsibility issues to watch?

Yes — several sit alongside the above. Proper BriefBank use puts you in a strong position on each; each is a reason the "properly used" conditions matter.

  • Supervision of nonlawyer/vendor assistance (Rule 5.3). The vendor and the AI are treated like a nonlawyer assistant: you must make reasonable efforts to ensure their conduct is compatible with your professional obligations. This is the flip side of what makes the vendor a Kovel-type agent — you supervise it.
  • Candor toward the tribunal (Rule 3.3). This is the duty the hallucination cases in Question 5 actually enforce: presenting fabricated or unverified authority to a court is a candor violation independent of confidentiality. Separately, some judges' standing orders and local rules now require disclosing or certifying AI use in filings — check them before filing; any required certification must be accurate but should not reveal privileged or confidential detail beyond what the order requires.
  • Fees and billing (Rule 1.5). California Rule 1.5 forbids an unconscionable or illegal fee (a different, stricter standard than the ABA's "reasonableness" rule); bill AI-assisted time honestly, and do not bill hours the tool saved as if they were spent. ABA Op. 512 addresses fair billing for AI-assisted work.
  • Safeguarding client data (Cal. Bus. & Prof. Code § 6068(e)(1); Cal. Rule 1.6; ABA Model Rule 1.6(c) as persuasive non-California guidance; ABA Op. 477R; N.Y. Op. 842). The confidentiality duty carries a security component: an enforceable confidentiality obligation in a signed agreement (a DPA/BAA-equivalent), encryption in transit and at rest, access controls, breach-notification terms, a current SOC 2 (or equivalent), and no training on your inputs — enterprise tier, not a consumer plan. Also review the vendor's secondary-use rights, subprocessors/affiliates, data residency and cross-border transfer, and any abuse-monitoring or human-review access to your data. (Note: California Rule 1.6 has no ABA-style "reasonable efforts" cybersecurity subdivision; the security duty flows from § 6068(e)(1) and the competence rule, with ABA Model Rule 1.6(c) as persuasive guidance.)
  • Inadvertent disclosure / receiving privileged material (Fed. R. Evid. 502(a)–(b) in federal proceedings; Rico v. Mitsubishi Motors (2007) 42 Cal.4th 807). FRE 502(b) is the federal safe harbor against inadvertent-disclosure waiver (and 502(a) confines subject-matter waiver to intentional disclosures); reasonable steps to prevent and rectify disclosure protect against inadvertent-waiver arguments. Rico is not a clawback rule but a receiving-lawyer duty: a California lawyer who receives materials that appear privileged or protected must refrain from reading beyond what is necessary, notify opposing counsel, and try to resolve the situation. Diligence here does double duty.
Not legal advice. This is general analysis of the framework, not advice on your matter. Consult your jurisdiction's ethics counsel before acting.

Bottom line — the "properly used" configuration

The same short checklist strengthens your position on every question above. Every time you put representation information into BriefBank (or any legal-AI vendor):

  1. Enterprise terms — a signed, enforceable confidentiality obligation; no training on your inputs; zero/short retention with contractual deletion; named subprocessors; SOC 2; encryption; a notify-on-legal-process clause. (Privilege + confidentiality + data security + subpoena defense.)
  2. Attorney in the loop — a responsible lawyer directs the work and reviews every output; nothing is filed unverified. (Competence + candor + work-product posture.)
  3. Client informed consent where required — engagement-letter clause for routine confidentiality-bound use; matter-specific consent for sensitive matters. (Communication + confidentiality.)
  4. Documented diligence — run and keep the vendor-diligence checklist; re-run it when terms change. (Reasonable-care record for all of the above.)

Table of Authorities

Every authority cited in this Q&A, consolidated and categorized. Cite-check each against the primary source before relying on it in a filing.

Cases

  • Assini v. Hayward (N.Y. Sup. Ct. 2026) 2026 WL 1677232 (persuasive)
  • Benjamin v. Costco Wholesale Corp. (E.D.N.Y. 2025) 779 F.Supp.3d 341 (persuasive)
  • ByoPlanet Int'l, LLC v. Johansson (S.D. Fla. 2025) 792 F.Supp.3d 1341 (persuasive)
  • Coito v. Superior Court (2012) 54 Cal.4th 480
  • Costco Wholesale Corp. v. Superior Court (2009) 47 Cal.4th 725
  • Fletcher v. Experian Information Solutions, Inc. (5th Cir. 2026) 168 F.4th 231 (persuasive)
  • Hays v. Wood (1979) 25 Cal.3d 772
  • Ibach v. Stewart (Ala. 2026) 2026 WL 1110659 (persuasive)
  • In re Columbia/HCA Healthcare Corp. Billing Practices Litig. (6th Cir. 2002) 293 F.3d 289 (persuasive)
  • In re Grand Jury Subpoena (9th Cir. 2025) 127 F.4th 139 (2025 WL 313218) (persuasive)
  • In re OpenAI, Inc., Copyright Infringement Litig. (S.D.N.Y. 2025) 800 F.Supp.3d 602 (2025 WL 2691297) (persuasive)
  • In re Richburg (Bankr. D.S.C. 2025) 671 B.R. 918 (persuasive)
  • Lexos Media IP, LLC v. Overstock.com, Inc. (D. Kan. 2026) 2026 WL 265581 (persuasive)
  • Mata v. Avianca, Inc. (S.D.N.Y. 2023) 678 F.Supp.3d 443 (persuasive)
  • Morgan v. V2X, Inc. (D. Colo. 2026) 2026 WL 864223 (persuasive)
  • Rico v. Mitsubishi Motors Corp. (2007) 42 Cal.4th 807
  • Rivera v. Triad Properties Corp. (N.D. Ala. 2026) 829 F.Supp.3d 983 (persuasive)
  • State ex rel. Oklahoma Bar Ass'n v. Reeves (Okla. 2026) 2026 OK 37, 2026 WL 1480563 (persuasive)
  • State v. Coleman (Ohio Ct. App. 2026) 2026-Ohio-965, 280 N.E.3d 1042 (persuasive; N.E.3d parallel pincite unconfirmed)
  • United States v. AT&T Co. (D.C. Cir. 1980) 642 F.2d 1285 (persuasive)
  • United States v. Farris (6th Cir. 2026) 171 F.4th 920 (persuasive)
  • United States v. Heppner (S.D.N.Y. 2026) 820 F.Supp.3d 292 (2026 WL 436479) (persuasive)
  • United States v. Kovel (2d Cir. 1961) 296 F.2d 918 (persuasive)
  • Warner v. Gilbarco, Inc. (E.D. Mich. 2026) 820 F.Supp.3d 629 (2026 WL 373043) (persuasive)
  • Wellpoint Health Networks, Inc. v. Superior Court (1997) 59 Cal.App.4th 110

California statutes

  • Cal. Bus. & Prof. Code § 6068(e)(1)–(2)
  • Cal. Code Civ. Proc. § 2018.030
  • Cal. Evid. Code §§ 950–962 (art. 3, lawyer-client privilege) — incl. §§ 912 & 912(d), 952, 954

California Rules of Professional Conduct

  • Rule 1.0.1(e) (informed consent — definition)
  • Rule 1.1 (competence)
  • Rule 1.2 (scope of representation)
  • Rule 1.4 (communication)
  • Rule 1.5 (fees — "unconscionable or illegal")
  • Rule 1.6 (confidentiality; incl. Rule 1.6(b))
  • Rule 1.18 (duties to prospective clients)
  • Rule 3.3 (candor toward the tribunal)
  • Rule 5.3 (responsibilities regarding nonlawyer assistants)

Federal rules

  • Fed. R. Evid. 502(a)–(b)

ABA Model Rules (persuasive)

  • ABA Model Rule 1.1 (competence; cmt. [8], technology)
  • ABA Model Rule 1.6 (confidentiality; incl. Rule 1.6(c))

Ethics opinions (persuasive)

  • ABA Formal Opinion 512 (2024) (generative AI)
  • ABA Formal Opinion 477R (2017) (transmitting client information)
  • N.Y. State Bar Ass'n Opinion 842 (2010) (cloud storage)

Secondary authorities

  • Restatement (Third) of the Law Governing Lawyers §§ 70, 79 (2000)

Computing & Security

Plain-language answers to the computing-side questions: where the data lives, how it is protected, what our AI providers see. For the formal control list, see the Security Overview; for legal terms, see the DPA, Privacy Policy, and Subprocessor List.

The basics

Where does my data actually live?

In Microsoft Azure, in the United States — the same underlying cloud platform your firm probably already uses when it stores files in OneDrive or SharePoint. Extracted document text and embeddings live in Azure PostgreSQL; original uploaded file bytes are not retained after ingestion. Details in the Security Overview.

Is my data encrypted?

Yes — encrypted in transit (TLS) between every hop and at rest in Azure storage. Same standard as any modern cloud document management system (DMS).

Who can see my documents?

Only you and the people you explicitly invite to your workspace or a specific matter. BriefBank uses row-level security in the database keyed on your organization ID, so one firm's content is technically isolated from every other firm's content — a query from your workspace physically cannot return another workspace's data. Personnel access is least-privilege and audit-logged.

Does BriefBank train AI on my content?

No. Your documents are never used to train or fine-tune any model — neither ours nor our LLM providers'. Our AI providers operate under zero-retention or short-retention terms; details in the Subprocessor List.

The comparison lawyers usually want to make

How does BriefBank's security posture compare to just using OneDrive or SharePoint?

The confidentiality floor is the same: same Azure infrastructure family, same encryption standards, same US data residency by default. What is genuinely new when you add BriefBank: we become a subprocessor of your firm, and the LLM providers we use become sub-subprocessors. Both are disclosed on our Subprocessor List and contractually covered under our DPA. If your firm is comfortable with the ABA Model Rule 1.6 analysis of a cloud document management system (DMS), BriefBank should slot into the same analysis — but you should run it consciously rather than inherit it.

How is this different from just using Microsoft 365 Copilot?

Copilot searches Microsoft's world — public web content, your Microsoft 365 environment, and the models Microsoft ships. BriefBank searches your firm's work-product — the briefs and memos you've already written — and returns cited answers that link back to the exact paragraph in the exact source PDF. And where a general-purpose search matches keywords, BriefBank's indexing is legal-aware: at ingest time it extracts case citations, identifies authorities, and tags legal issues, so a question about a doctrine surfaces every prior brief that argued it — not just the ones that happened to use the exact phrase. Same security posture, different job.

Certifications and contracts

Is BriefBank SOC 2 certified?

We are operating under SOC 2 Type II-aligned controls today and preserving the audit evidence (access logs, change records, security-event logs) that will support the audit's observation window. Please contact us for control matrix/posture and SOC 2 audit timelines.

Do you sign a DPA / HIPAA BAA?

We provide a standard Data Processing Addendum and negotiate reasonable customization. HIPAA BAA availability depends on the specific use case — contact us at info@aibriefbank.com.

Operational questions

What happens if there is a security incident?

Our incident notification obligations are set out in the Terms §3.7 and the DPA. In practice: you would be notified promptly with the scope, timing, affected data categories, and mitigation steps, and we would provide the information your firm needs to meet its own notification obligations.

How is deletion handled?

Deleting an account, library, document, or chat purges the related database rows and embeddings across both data planes. There are no raw uploaded file bytes to delete separately (we don't retain them after ingestion). Paid deletion requests complete within 30 days; Free-tier content is promptly deleted on account closure. Backups follow the ordinary backup cycle.

Can I try BriefBank without connecting real client matters?

Yes — spin up a workspace with a small set of sample or non-client documents first, get comfortable with how it behaves, then connect real content when your firm is ready. There is no requirement to upload sensitive material to evaluate the product.

Web search is opt-in and off by default. When it is on, only the model-formed query string is sent to our web-search provider (Perplexity Sonar) under its published Zero Data Retention Policy — full document text is never transmitted to the web-search path. Pre-send PII redaction on that path is on our roadmap but not yet built; that limitation is disclosed on the Security Overview.

If you still want to go deeper

Where can I read more?

Start with the Security Overview for the formal control list, the Privacy Policy for what personal data we handle, the DPA for the contractual side, and the Subprocessor List for the vendors that touch data. Anything not covered — email info@aibriefbank.com and we will get you a direct answer.

This FAQ is an accessible companion to the Security Overview and the linked legal documents — it does not replace them. Where an answer here appears to conflict with the Overview, DPA, or Terms, the formal documents control.