Tonkean LegalWorks
Tonkean LegalWorks is matter lifecycle management for in-house legal departments, built around the problem of getting the business to use legal's processes at all. Rather than asking employees to learn a legal system, it meets them where they already work: requests arrive through Slack, Microsoft Teams, email or a branded portal, and an AI Front Door reads plain-language queries, answers simple questions outright, and routes the rest into structured intake. Intake forms adapt to the risk level and matter type of the request and auto-fill from connected systems. From there the platform orchestrates the matter across the tools the work actually touches, syncing contracts between contract lifecycle management and e-signature, routing approvals through chat and email, pulling data from billing systems and coordinating with outside counsel platforms; named connections include Ironclad, TeamConnect, SimpleLegal, DocuSign, Adobe Sign, Salesforce, ServiceNow, JIRA and SharePoint. A set of packaged agents handles recurring legal work, among them an NDA agent, a contract manager agent, conflict check automation, legal mailroom automation and email triage. Legal operations teams configure all of it with no-code tools, mapping playbooks, approval paths and risk tiers so that workflows follow the department's own policy. The governance layer is addressed directly at legal buyers, with role-based access control and ethical walls, full audit logs, item-level data retention and legal holds, and an audit trail of actions and approvals presented as supporting attorney-client privilege. Deployment is offered three ways: a Tonkean-managed multi-tenant public cloud on AWS, a single-tenant dedicated cloud, and self-hosting in the customer's own environment on AWS, Azure or Google Cloud, the latter two available on the enterprise plan at additional cost. Pricing is quoted rather than listed and is charged on monthly tracked users, averaged across the subscription year. LegalWorks is one of three named solutions from Tonkean Inc., a Palo Alto process orchestration company, alongside ProcurementWorks and ServiceWorks, and it has its own general manager.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models drive a core capability on a product that plainly functions without them. What the AI does is real and named: AI Front Door reads plain-language requests, LegalGPT triages and classifies unstructured inbound requests, and packaged agents handle NDA generation and contract work. But underneath sits a no-code process orchestration platform with forms, rules, approval chains, dashboards and integrations, marketed as 100 per cent no-code and sold to procurement and IT in identical form. The clearest evidence is contractual rather than promotional: the published sub-processor table lists Microsoft Azure for AI LLM engine services, OpenAI for AI/ML powered product features and Google Cloud for OCR, and marks all three opt in. A customer who does not opt in receives an orchestration platform with no model behind it. That is the definition of this band rather than the one above. Checked 4 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is described in outline and accuracy is disclaimed rather than measured. The retrieval story is stated: the AI Front Door trawls the data sources the customer has given it access to and generates a document if one does not already exist, and agents draw on connected enterprise systems, so a reader can tell in principle what an output is built from. Nothing beyond that exists. No accuracy figure, no test set, no evaluation, no error rate and no method description appears on any surface, and no output is presented with a traceable citation to the source record it came from. The agreement moves in the opposite direction and does so explicitly: Tonkean does not warrant that the Platform will meet the customer's requirements or expectations, including with respect to any actions or outcomes of use of Tonkean's A.I. Bot. Nothing addresses hallucination in either direction. Searched the LegalWorks page, the security page, the pricing page, the DPA and the customer terms on 4 September 2026; docs.tonkean.com and the AI handbook were not opened.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The division between what runs alone and what reaches a person is published clearly, and the threshold that decides it is the customer's rather than the vendor's. What runs unattended is stated: simple requests such as NDAs and statements of work are auto-handled, urgency is identified on every inbound request, and more complex matters including conflict waivers, intellectual property questions and outside counsel engagements are auto-routed to the right person or practice group. The control structure around it is real, with approval paths and risk tiers mapped to the department's policy, intake forms that adapt by risk level and matter type, and a full audit trail of actions and approvals. What holds this off the top band is that the thresholds are configured by the customer rather than published by the vendor, so a buyer cannot learn from the material what the system will do by default. No confidence signal, no abstention state and no described behaviour where the model misclassifies a request appears anywhere.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Substantial evidence exists for the platform and very little of it is legal. The logo wall on the LegalWorks page runs to twenty enterprises including Google, Lenovo, AbbVie, Workday, Cisco and Intuit, but it is headed trusted by enterprises like and is the same strip used across the site rather than a LegalWorks customer list. The headline figures are unattributed and carry no stated basis: 50 per cent cycle time reduction, 99 per cent of customers reporting higher adoption, 30 employee hours saved weekly, 7.7 billion steps automated annually. Of the three attributed quotes, two are procurement rather than legal, from the Head of Global Procurement at Semrush, who supplies the only hard figure at a cycle time of 19 days falling to 10, and the Head of Procurement at Cockroach Labs. The legal quote is from Mary O'Carroll, identified as former President of CLOC and Head of Legal Operations at Google, and speaks to Tonkean generally rather than to LegalWorks. A customer showcase exists and was not opened. On this record the deployment evidence for the legal product is thinner than the page's overall impression suggests.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The marketing addresses privilege directly and the agreement excludes the material it would protect, which is the gap this axis exists to surface. The LegalWorks governance section is the strongest privilege language in the pull: an audit trail of all actions and approvals presented as helping preserve attorney-client privilege, comprehensive role-based access control and ethical walls, item-level data retention and legal holds. Against that, the customer terms provide that User Content shall not be deemed information acquired by Tonkean, which removes customer content from the contractual confidentiality obligation entirely and refers it instead to the Security section, where Tonkean states it cannot fully ensure or warrant the absolute security and privacy of User Content or personal information. So the confidentiality commitment a buyer can actually enforce over its matter material is materially thinner than the product page implies. Two provisions point the other way and are recorded: Tonkean shall have no right in the User Content beyond the minimal rights required to facilitate use of the Platform and shall not use it for any other purpose, and the DPA bars Tonkean from deriving rights or benefits from Personal Information. Where marketing and agreement conflict the agreement governs, which is why this sits here rather than higher.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
A boilerplate disclaimer sits in a general agreement while the product is marketed in advice-adjacent terms. The customer terms state that the Service provides ideas, suggestions, analyses and other data for informational purposes only and not as advice, and disclaim responsibility for any information provided by the Service. That is a real sentence but a generic one, drafted for a business management platform rather than for a legal product, and the agreement carrying it was last updated May 2019, before LegalWorks and every agent now sold. Against it the marketing describes agents that handle complex contract analysis and negotiation strategies, and an AI Front Door that answers employees' legal questions directly. The audience limits the exposure and is stated plainly: the buyer is a corporate legal department and the requesters are its own employees, so there is no consumer surface and no unlicensed practice question of the ordinary kind. What is absent is everything above the disclaimer: no rule of professional conduct or bar guidance named, no jurisdiction limit, and nothing on how a legal team supervises an agent that answers a business question without a lawyer seeing it.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
No governance position for the vendor's own models was located, on a product whose agents act on matters without a lawyer in the loop for simple requests. There is no responsible AI page, no principles statement, no named owner accountable for model behaviour, no pre-release evaluation or testing regime, and nothing at all on bias, including nothing on whether triage and classification perform evenly across request types, business units or languages. That last gap matters here specifically, because the product's core function is deciding which requests are simple enough to resolve without a lawyer. The security page is thorough and entirely about information security, which the axis definition treats as a different subject and which is graded on the stewardship row rather than counted twice. An AI handbook page exists in the navigation, headed with questions about what an agent is and when one counts as an enterprise agent, and it was not opened; it is named here as the one surface that might carry governance material. Searched the LegalWorks page, the security page, the pricing page and the site navigation on 4 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Almost the whole set is published and one limb is soft. Retention is customer-controlled at unusual granularity, with item-level policies definable down to the field so data is held only as long as a given process needs, and the DPA adds that within 60 days of termination Tonkean will delete or return all Personal Data at the customer's choice and delete existing copies, retaining one copy only where law requires. Access control is described as comprehensive role-based control across data access and process creation, encryption is AES-256 at rest and in transit, and non-repudiation audit logs capture all edits and processed transactions. The sub-processor position is fully published rather than promised, naming each provider, its function and its country. Incident practice exists but is the weak limb: Tonkean commits to notify without undue delay after becoming aware of a Data Incident, with no stated clock, and the same clause bars the customer from publishing anything identifying Tonkean about an incident without prior written approval unless legally compelled, which is worth a buyer's attention.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Liability is addressed only through a limitation clause, and that clause disclaims the exposure the AI creates by name. The cap is short: aggregate liability may not exceed the consideration actually paid in the three months preceding the cause of the claim, against the twelve months more common in this corpus. Excluded damages are broad, covering loss or corruption of data, lost profits and pure economic loss. There is no indemnity running to the customer at all; the only intellectual property remedy is that Tonkean may at its sole discretion procure a licence, modify the Platform or terminate and refund the post-termination period, with the agreement stating that no other rights or remedies will accrue. The indemnity that does exist runs the other way, from customer to Tonkean. The warranty is repair-or-replace for material errors preventing ordinary use and expressly does not extend to any actions or outcomes of use of Tonkean's A.I. Bot. No insurance position was located. The dating is the sharpest fact: the agreement was last updated May 2019, so the instrument governing a 2026 agentic legal product predates it entirely and mentions AI once, to disclaim it.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real integrations into the systems legal work lives in, named individually, with direction described in outline rather than in depth. The legal-specific connections are the ones that count and they are named: Ironclad for contract lifecycle management, TeamConnect for matter management, SimpleLegal for legal spend, alongside DocuSign and Adobe Sign for execution and SharePoint for documents. The wider set covers Salesforce, ServiceNow, JIRA, Slack, Microsoft Teams, email, Coupa and SAP, and the product's stated architecture is an orchestration layer across them rather than a destination to migrate into. Direction of travel is described at summary level, with contracts syncing from CLM to e-signature, approvals routed through email and chat, data pulled from billing systems and coordination with outside counsel platforms. What is missing for the top band is configuration detail: nothing published on the pages read states what a legal team must set up, what fields map, or what an integration requires. A public integration library and developer documentation both exist and were not opened; they are the cheapest available upgrade on this record.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The tenancy picture is published in full and the region menu is not. Three options are described with what separates them: a Tonkean-managed multi-tenant public cloud on AWS, a single-tenant dedicated cloud not shared with other customers and also managed by Tonkean on AWS, and self-hosting in the customer's own environment on AWS, Azure or Google Cloud. The pricing page states which tier each sits in, with multi-tenant included and dedicated, customer-cloud and on-premises available on the enterprise plan at additional cost, so what changes between tiers is answerable. Processing location is establishable from the DPA rather than the marketing: every sub-processor is listed as United States except Tonkean Israel Ltd., and Schedule 2 incorporates the 2021 Standard Contractual Clauses with UK and Swiss addenda for transfers out of the EEA. What is absent is a published region choice for the managed offering, and no page states where data is stored as distinct from where it is processed.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certifications are real, named and scoped, and the evidence behind them is reachable only by customers. The security page states SOC 2 Type 2 compliance, independently audited, in accordance with the AICPA Trust Services Principles and Criteria and named to security, availability and confidentiality, so the scope is published rather than implied. ISO/IEC 27001:2022 is stated as achieved, with the standard version given. A HIPAA compliance page sits alongside them. Three things hold this off the top band. No auditor is named, no audit period or report date is given for either attestation, and access to the reports is expressly limited to existing customers, with the page inviting a customer to ask the team for the latest report. That is narrower than a sales gate: a prospective buyer evaluating the product has no route to the evidence at all, which is the condition the top band exists to distinguish. There is no trust portal, and the badges displayed are the certification marks themselves rather than unsupported logos.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The providers are named with their function and location, the change commitment is contractual, and the models themselves are not identified. Schedule 1 of the published DPA lists each sub-processor with a described service and a country: Microsoft Azure for AI LLM engine services, OpenAI, LLC for AI and machine learning powered product features, and Google Cloud Platform for OCR services, all in the United States, each marked opt in, alongside AWS for cloud storage, Elastic.co for the hosting index database, SendGrid for email and Tonkean Israel Ltd. as an affiliate sub-processor. Change notification is not a promise but a term: Tonkean shall notify before authorising any new sub-processor, the customer has seven days to object, and unresolved objection allows termination of the affected services. What fails is model naming. Azure and OpenAI are providers, not models, and no model or version is identified anywhere, so a buyer cannot establish which model reads a legal request. Provider identification and model naming are separate limbs of the top band and only one is met.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The unit and the structure are published with real rigour and no figure appears anywhere. Charging is on Monthly Tracked Users, and the definition is unusually precise rather than gestural: an MTU is a unique person who in a calendar month submits a form, accesses a workspace app, submits or replies to an item in Slack or Teams, sends or replies to a Tonkean email, or engages by clicking a button or updating an item. The vendor states expressly that MTUs are not named seats and are not a count of records processed, that actions per tracked user are unlimited once counted, and that billing rests on the average MTU across the subscription year so that busy months even out. The quote is built from three components, the platform with unlimited workflows and connectors, the MTU volume, and optional deployment and services, and the hosting and support tiers are itemised with what each includes. No price, band, minimum or term is published and every route ends in a scheduled discussion. A buyer can therefore model the shape of the bill precisely and cannot learn what it costs.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
The buyer and the work are described with substance and the edge of the product is left open. The segment is unambiguous: corporate and government in-house legal departments at enterprise scale, with the material addressed separately to three audiences that a legal operations buyer would recognise, being employees raising requests, the legal team itself, and cross-functional stakeholders in procurement, sales and IT. Practice coverage is expressed as the request types the product handles rather than as practice groups, and the list is specific: NDAs, statements of work, contract review, conflict waivers, intellectual property questions, outside counsel engagement, legal mailroom and email triage, and matter intake generally. Company-size evidence is real, with the customer set drawn from Fortune 500 and Fortune 200 enterprises. What is not stated is where the product stops. Nothing addresses law firm use, no minimum department size is given, no jurisdiction or language coverage is published, and no request type is identified as unsuitable for automated handling.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way.
Nothing published names training in either direction, and two clauses constrain use tightly without naming it. The customer terms provide that Tonkean shall have no right in the User Content except for the minimal rights required to facilitate use of the Platform, and shall not use the User Content for any other purpose. The DPA adds that Tonkean shall not have, derive or exercise any rights or benefits regarding Personal Information processed on the customer's behalf and may use it solely for the purposes for which it was provided. Both would exclude training as a matter of construction, and neither says so. Pointing the other way, the DPA lists rendering Personal Data fully anonymous and non-identifiable among the permitted processing purposes, with no statement of what may then be done with the result. Under the naming test an unnamed clause is not evidence about training in either direction, so the honest value is the absence with the clauses recorded. One further fact belongs on the row: the LLM sub-processors, Microsoft Azure and OpenAI, are marked opt in, so a customer that does not opt in has no model processing its content at all.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
The customer controls the retention window, by product configuration or by contractual instruction, but zero retention is not stated as available.
Retention is configurable by the customer at a finer grain than most products offer. The security page states that item-level data retention policies let a customer define specific retention lengths down to the field level so that sensitive data is available only as long as each process needs, which puts the period in the customer's hands rather than the vendor's. The DPA supplies the end-of-life position: within 60 days of termination Tonkean will delete or return all Personal Data at the customer's choice and delete existing copies, retaining one copy only where law authorises or requires it for legal claims. What is not offered is a stated zero-retention option for prompts and model outputs specifically, and nothing distinguishes the retention of a request record from the retention of the model exchange that resolved it. No default period is published for a customer that configures nothing.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Segregation is asserted in public materials with no published detail on how it is enforced.
Ethical walls are named as a product capability and no separation model is described. The LegalWorks governance section lists comprehensive role-based access control and ethical walls together as a single bullet, alongside full audit logs and item-level retention, and the security page describes RBAC in general terms as ensuring every permission from data access through process creation is secured. Neither states how a wall is defined, at what level it operates, whether it applies to matters, clients or business units, who administers it, or what a walled user sees. Tenant-level separation is a different question and is answered well, with a single-tenant dedicated cloud and a self-hosted option both published, but tenancy separates customers from each other rather than matters within one legal department. Naming a control without describing it is what this value records. Product documentation at docs.tonkean.com was not opened and may describe the mechanism.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Terms commit to notifying the customer where lawfully permitted, and a transparency report is published.
Both limbs are met, and the reporting limb is met more fully than anywhere else located in this pull. On notice, the DPA provides that where processing is required by law or by a court or governmental authority, Tonkean shall inform the customer of the legal requirement before processing unless prohibited on important grounds of public interest. Schedule 2 Part 4 goes considerably further for cross-border transfers: on becoming aware that a government authority seeks access, Tonkean will tell that authority the customer has not authorised disclosure and that demands should be served on the customer instead, will use commercially reasonable legal mechanisms to challenge the demand, and will notify the customer as soon as possible after any emergency access. On reporting, once in every twelve-month period and on written request Tonkean will inform the customer of the types of binding legal demands for personal data it has received, expressly including national security orders and directives and any process issued under section 702 of the US Foreign Intelligence Surveillance Act. Tonkean also commits to resist bulk surveillance requests. The reporting is on request rather than published, which is the one qualification worth carrying.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
The material the models read is the customer's own, and it is identified as such. Published descriptions state that the AI Front Door trawls the data sources the customer has given it access to, and that agents draw on connected enterprise systems including contract lifecycle management, billing, document stores and chat. No external corpus is involved: the product does not retrieve primary law, published precedent or any licensed third-party dataset, and none is named anywhere. There is accordingly no licensing question of the kind this signal was written for and no jurisdictional coverage statement to record. Searched the LegalWorks page, the platform navigation, the security page, the pricing page, the DPA and the customer terms on 4 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Nothing on any located surface addresses checking authority for subsequent history, and the product does not retrieve or present primary law. LegalWorks routes and resolves internal legal requests and generates operational documents such as NDAs and statements of work; no case, statute or regulation is surfaced to a user at any point in the published workflow. The question does not bite on this product class and the value records the honest absence rather than a shortcoming. Searched the LegalWorks page, the security page, the pricing page and the agreements on 4 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
A routing rule is published and no uncertainty behaviour is described. The product states that it autonomously resolves simple requests and routes more complex ones to the correct workflow, person or practice group, naming conflict waivers, intellectual property and outside counsel engagements as the kind that escalate, and it identifies the urgency of every inbound request. That is a real deferral mechanism, and it is recorded here as what exists, but it sorts by request complexity as configured by the customer rather than by the model's own confidence in its answer. Nothing describes what happens when the model cannot classify a request, misreads one, or produces a draft it has insufficient grounding for; no confidence score, no abstention state and no no-answer condition is surfaced to the requester or to the legal team. The gap has practical weight because the requester in this product is a business employee rather than a lawyer, so an unflagged wrong answer may never reach legal at all.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
The AI Hallucination Cases database maintained by Damien Charlotin was searched on 4 September 2026 on the product name LegalWorks and on the company name Tonkean. No court order, opinion or disciplinary record naming the product or the company was located. This records the state of the public record on that date and is not a finding about the product. The signal also sits at an angle to this product class, since LegalWorks routes internal requests and generates operational documents rather than legal citations, so a fabricated citation is not the failure mode it would ordinarily produce.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No bar authority, regulator, conduct rule or ethics opinion is named on any located surface. Nothing on the LegalWorks page, the security page, the pricing page, the DPA or the customer terms engages professional regulation, and no jurisdiction-specific guidance is mapped. The nearest published language is the customer terms' statement that the Service provides analyses for informational purposes only and not as advice, which is a disclaimer rather than an engagement with any professional standard. The absence is worth noting against the product's own privilege claim: the LegalWorks page frames its audit trail as helping preserve attorney-client privilege, which is a professional responsibility concept, and no source of that standard is cited anywhere.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Efficiency claims are published and the billing question is not reached, in part because this product sits on the wrong side of it. The claims are prominent and unattributed: a 50 per cent reduction in cycle time, 30 employee hours saved each week, and a named legal operations endorsement referring to millions of dollars saved. Nothing addresses what happens to a bill when work compresses, and no per-matter record of AI-assisted work is described as available for that purpose. The structural point is worth recording as an edge rather than a defect. The buyer here is an in-house legal department, which pays outside counsel rather than billing a client, so the compression this signal was written to catch does not arise in the ordinary way. The product does coordinate outside counsel engagement and pulls data from billing systems, so a partial grip exists, but nothing published connects automated handling of a matter to what the department is billed for it.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A subprocessor and model provider list plus client facing disclosure material is published or available without an agreement in place.
All three limbs are met from a single published document. The Data Processing Addendum is public and ungated, and Schedule 1 carries a full sub-processor table naming each provider, the service it performs and its country, including the AI entries specifically: Microsoft Azure for AI LLM engine services, OpenAI, LLC for AI and machine learning powered product features and Google Cloud Platform for OCR, all United States and all marked opt in. So the model provider question is answerable in the affirmative rather than by naming infrastructure. The forwardable artifact is the DPA itself, drafted to be given to a counterparty and incorporating the 2021 Standard Contractual Clauses with UK and Swiss addenda. Change notification is contractual, at notice before authorising any new sub-processor with a seven-day objection window and a termination remedy. The direction of this signal inverts on an in-house product, since the buyer is the client rather than the firm, but the artifacts a counterparty would ask for are published and complete.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
A substantial record exists and nothing states that it distinguishes model work from human work. The security page describes non-repudiation logs capturing full records of all edits to solutions and enterprise components and all processed transactions in test and production, and the LegalWorks governance section commits to an audit trail of all actions and approvals framed as supporting audit readiness and the preservation of attorney-client privilege. That is more than most records in this corpus publish and it is why this sits above the floor. What is missing is the AI-specific half. Nothing says the log identifies which requests were resolved autonomously by an agent rather than by a person, no model or version is attributed to a generated document such as an NDA, and no export route for the audit trail is described for a regulator, an auditor or a court. Product documentation was not opened and may describe the log's export format.