Important Disclaimer
This article provides general information about security and ethics considerations. It is not legal advice about your specific ethical obligations. Always consult your state bar's ethics opinions and your firm's policies before using any cloud service with client documents.
I've talked to hundreds of lawyers about using AI tools for document analysis. The conversation always starts the same way: "This sounds great, but can I ethically upload client documents to a cloud service?"
It's the right question. Attorney-client privilege is sacred. One breach could mean malpractice, bar discipline, and destroyed client relationships. But here's the thing: if you use email, practice management software, or cloud storage, you're already trusting cloud services with confidential information.
The question isn't "Should I use cloud services?" It's "Which cloud services meet my ethical obligations, and how do I use them properly?"
What State Bars Actually Say About Cloud Services
Let's start with what the ethics rules actually require. Most state bars have issued opinions on cloud computing and third-party services. The framework is remarkably consistent across jurisdictions.
The General Framework (ABA and Most States)
Lawyers CAN use cloud services
There's no blanket prohibition. Cloud services are explicitly allowed if they meet security requirements.
Reasonable security measures required
You must take "reasonable" steps to protect client information. What's "reasonable" depends on the sensitivity of the data and available technology.
Understand what happens to data
You need to know how the service handles client data: where it's stored, who has access, how long it's retained, and how it's deleted.
Written agreement about confidentiality
There should be a contract (terms of service count) that addresses confidentiality and data protection.
Stay informed about breaches
Monitor for security incidents and respond appropriately if a breach occurs.
Key Ethics Opinions to Review
- ABA Formal Opinion 477R (2017) - Securing Communication of Protected Client Information
- ABA Formal Opinion 483 (2018) - Lawyers' Obligations After an Electronic Data Breach or Cyberattack
- Your state bar's specific opinions on cloud computing (most states have issued guidance)
Action item: Search "[Your State] bar association cloud computing ethics opinion" and read your jurisdiction's specific guidance.
What "Reasonable Security" Actually Means
The ethics rules require "reasonable" security measures. But what does that mean in practice? Here's how to evaluate whether a cloud service meets the standard.
Encryption in Transit
What it is: Data is encrypted when traveling between your computer and the service's servers.
What to look for:
- TLS 1.2 or 1.3 encryption (check for "https://" in the URL)
- No option to use unencrypted connections
- Service explicitly states encryption standards in their security documentation
Our service: All uploads use TLS 1.3 encryption. No unencrypted option available.
Data Retention Policy
What it is: How long the service keeps your documents and what happens to them.
What to look for:
- Clear statement about how long files are retained
- Automatic deletion policy (not indefinite storage)
- No use of your data for training AI models or other purposes
- Ability to delete files immediately if needed
Our service: Automatic deletion within 24 hours. No permanent storage. Files never used for training or any other purpose.
Access Controls
What it is: Who can see your documents and under what circumstances.
What to look for:
- Isolated processing (your files aren't accessible to other users)
- Limited employee access (only for technical support, with logging)
- No third-party access or data sharing
- Clear policies about government requests
Our service: Isolated container processing. No employee access to file contents. No third-party sharing.
Terms of Service & Privacy Policy
What it is: The legal agreement about how your data is handled.
What to look for:
- Explicit confidentiality provisions
- No broad license to use your content
- Clear data protection commitments
- Reasonable indemnification and liability terms
Action item: Actually read the terms of service. Yes, it's boring. Yes, it's necessary.
Practical Security Measures for Your Firm
Beyond choosing a secure service, here are the practical steps lawyers are taking to protect client confidentiality.
✓ Do These Things
- Use enterprise/API versions of AI tools (not free consumer versions) where your data isn't used for training
- Redact highly sensitive information before upload (client names, SSNs, financial account numbers) when appropriate
- Document your security measures in your firm's written policies
- Get client consent for using cloud services (some firms include this in engagement letters)
- Use services with automatic deletion policies (like our 24-hour auto-delete)
- Train your staff on proper use of cloud services and security protocols
✗ Don't Do These Things
- Don't use free consumer AI tools (like free ChatGPT) where your data trains the model
- Don't assume security - actually verify the service's security practices
- Don't upload extremely sensitive documents without additional precautions (criminal defense, trade secrets, high-profile cases)
- Don't ignore your state bar's guidance - read the ethics opinions for your jurisdiction
- Don't skip the terms of service - you need to know what you're agreeing to
- Don't forget to document - if you can't show you took reasonable precautions, you have a problem
When Cloud Services Aren't Appropriate
For most cases, secure cloud services with proper precautions are fine. But there are exceptions.
Consider Offline Tools For:
- Criminal defense cases - especially high-profile or sensitive matters
- Trade secret litigation - where disclosure could cause irreparable harm
- National security matters - obvious reasons
- High-profile cases with media attention - extra scrutiny warrants extra caution
- Cases where client explicitly requests offline handling - respect client preferences
The Risk Assessment Framework
For each case, ask yourself:
- What's the sensitivity level of this information?
- What's the potential harm if it were disclosed?
- What security measures are available?
- What would a reasonable lawyer do in this situation?
If you're uncomfortable with the risk profile, use offline tools or additional security measures (like encryption before upload).
Creating Your Firm's Cloud Security Policy
Having a written policy isn't just good practice—it's evidence that you're meeting your ethical obligations. Here's what to include.
Sample Policy Outline
1. Approved Services
List the specific cloud services your firm has vetted and approved for client work. Include:
- Service name and purpose
- Security features verified
- Date of last security review
- Approved use cases
2. Security Requirements
Define what "reasonable security" means for your firm:
- Minimum encryption standards (TLS 1.2+)
- Data retention requirements (automatic deletion preferred)
- Access control requirements
- Breach notification expectations
3. Redaction Guidelines
Specify what information should be redacted before cloud upload:
- Client names (in certain contexts)
- Social Security numbers
- Financial account numbers
- Medical record numbers
- Other highly sensitive identifiers
4. Prohibited Uses
Define when cloud services should NOT be used:
- Criminal defense matters (or require additional approval)
- Trade secret cases
- High-profile matters with media attention
- Cases where client has requested offline handling
5. Training Requirements
All staff must complete annual training on cloud security practices and firm policies.
6. Incident Response
Procedures for responding to security breaches or unauthorized access.
The Bottom Line on Security
Using cloud services for legal work isn't a binary choice between "completely safe" and "completely risky." It's about understanding the risks, taking reasonable precautions, and making informed decisions.
Most lawyers are already using cloud services every day: email, practice management software, cloud storage, video conferencing. Document conversion services are no different—they're just another tool that requires proper vetting and appropriate use.
The key is to be intentional: understand what you're using, verify the security measures, document your decisions, and follow your state bar's guidance. Do that, and you're meeting your ethical obligations while gaining the benefits of modern technology.