9/23/2026
Law Firm AI Receptionist Security Checklist: 12 Questions to Ask Before You Buy
Evaluate AI receptionist privacy, confidentiality, access, retention, recordings, integrations, and oversight with this 12-question law firm checklist

By Attorney Michael Brunman, Co-Founder and CEO of Clerx
An AI receptionist can be used securely by a law firm only when the firm evaluates both the vendor and the configured workflow. The review should cover data collection, encryption, access controls, retention, recordings, integrations, incident response, human oversight, and the handling of prospective-client information.
That answer is less convenient than asking whether a product is “secure,” but it is more useful. Intake security depends on what the system is allowed to collect, which channels it handles, where information is sent, who can retrieve it, and what happens when the expected path breaks.
A vendor may have strong infrastructure while a firm configures an unnecessarily invasive script. The reverse is also possible: a restrained intake script cannot compensate for weak account controls or unclear retention. Security is the combination of technology, workflow, people, and governance.
Why AI receptionist security deserves its own review
An AI receptionist for law firms may receive names, contact details, descriptions of disputes, family information, criminal allegations, immigration facts, medical details, financial information, and the identities of other involved people. Some callers will be existing clients. Others may become prospective clients under applicable professional-conduct rules even if the firm never accepts the matter.
The system may also connect with a calendar, payment service, practice-management platform, CRM, or text channel. Each connection is useful, but each one expands the data flow the firm should understand.
ABA Formal Opinion 512 addresses lawyers' use of generative AI and discusses duties including competence, confidentiality, communication, and supervision. It does not create a single product checklist. The firm still has to evaluate the specific use, applicable jurisdiction, vendor terms, and configured safeguards.
1. What information does the workflow actually need?
Start with the intake purpose, not the available fields. A first interaction rarely needs every fact that may later matter to the legal representation.
For many workflows, the minimum useful set includes identity and contact details, names needed for an initial conflicts process, general matter category, jurisdiction, important dates as stated by the caller, language preference, and enough information to choose the next step.
The principle of collecting only what intake needs reduces friction as well as exposure. If a question does not change routing, qualification, conflicts review, scheduling, or preparation, consider deferring it.
2. Which channels are in scope?
Map every channel separately: phone, website chat, SMS, email, WhatsApp, or social messaging if enabled. The same person may start on one channel and continue on another, but the security and consent considerations are not identical.
For each channel, document what is collected, whether the interaction is recorded or transcribed, how identity is confirmed, where the record is stored, and how the person can reach a human. A law-firm text messaging workflow also needs clear consent, opt-out, ownership, and escalation rules.
3. Is data encrypted in transit and at rest?
Ask the vendor to explain how information is protected while moving between the caller, the intake service, and connected systems, and how stored data is protected. The answer should cover recordings, transcripts, summaries, attachments, exported reports, backups, and integration traffic where applicable.
Do not stop at the word “encrypted.” Ask which data is stored, for how long, in which systems, and whether the protection applies to all supported channels and exports.
4. Who can access intake information?
The firm should apply least-privilege access. A person should receive only the information needed for the person's role.
Build a permission matrix that covers attorneys, intake staff, administrators, vendor support, and integration accounts. Ask whether access is role-based, whether multifactor authentication is available, how accounts are removed when someone leaves, and whether administrative activity can be reviewed.
The same discipline should apply inside the connected practice-management system. A secure intake layer cannot correct an account that every staff member shares.
5. What is recorded, transcribed, and summarized?
Recordings and transcripts are operationally valuable for quality review and context, but they also increase the amount of sensitive information retained. The firm should decide whether recording is needed, which calls are covered, what notice or consent is required, who can listen, and when the recording is deleted.
Applicable federal and state rules vary. A firm should obtain jurisdiction-specific advice for its calling footprint rather than relying on a generic script.
Summaries deserve review too. A summary should report what the caller said without converting it into an unsupported legal conclusion. Test names, numbers, dates, and negative statements because these details can materially change the meaning.
6. How long is each category of data retained?
Retention should be intentional. The answer may differ for recordings, transcripts, lead records, rejected inquiries, current-client messages, analytics, backups, and security logs.
Ask whether the firm can set or request retention periods, export its information, and delete records when appropriate. Also ask what happens to backups and derived data after deletion. The policy should account for professional obligations, business needs, disputes, and applicable law.
“We keep everything indefinitely” is not automatically safer. It may create unnecessary exposure and make later governance harder.
7. Is customer data used to train models?
Ask directly whether the vendor or any subprocessor uses the firm's content to train or improve shared models. Review the contract and privacy terms, not only a sales statement.
Clarify whether opt-out is available, whether the answer differs by feature, and how de-identified or aggregated information is handled. The firm should understand the complete chain, including model providers, transcription services, telephony providers, storage, and analytics where applicable.
8. How do integrations read and write information?
An integration should have a defined purpose and scope. Document which system is the source of truth, what records the intake platform may read, which records it may create or update, and what happens when a matching contact already exists.
The firm's system ownership boundaries should be explicit. For example, the intake layer may create a contact, summary, task, or appointment, while the practice-management platform remains the source of truth for the legal matter.
Review the exact implementation for the Clerx and Clio integration or the Clerx and 8am MyCase integration. A logo in an integration directory does not explain permissions, field mapping, error handling, or duplicate prevention.
9. What happens when the AI is uncertain?
Uncertainty should lead to a controlled fallback, not improvisation. The firm should define when the system transfers a call, takes a priority message, alerts staff, asks a clarifying question, or stops the automated path.
Examples include a legal question, a caller who cannot be understood, a potential emergency, a conflict indicator, a payment exception, or an unsupported request. The division between automation and human judgment should be part of the implementation, not discovered after launch.
10. How are incidents detected, reported, and contained?
Ask the vendor about monitoring, incident-response procedures, customer notification, business continuity, and recovery. The contract should identify responsibilities and a practical contact path if the firm suspects an issue.
Internally, decide who at the firm receives security notices, who can disable or reroute the intake workflow, and how the firm will communicate if an integration is unavailable. An outage plan protects client service as well as data.
11. How is the workflow tested before launch?
Use a written test plan. Include a normal new lead, an existing client, an adverse party, a caller who shares too much, a person asking for legal advice, an urgent indicator, a failed transfer, a duplicate contact, a wrong-language path, a payment exception, and simultaneous inquiries.
Inspect the resulting records, permissions, notifications, recordings, and deletion behavior. The complete intake checklist can provide operational coverage, but security tests should also verify what the system refuses to do.
12. Who owns ongoing review?
Security is not completed at go-live. Assign an owner for quarterly or periodic review of scripts, permissions, integrations, retention, failed interactions, and staff access.
The owner should review changes in firm services, staffing, offices, calendars, and software. Vendor updates and new AI features should also trigger review when they change the data flow or level of automation.
Use the governance cycle in legal AI risk management: identify the use, assess the risk, apply controls, monitor performance, and revise the workflow.
Prospective-client information requires restraint
ABA Model Rule 1.18 addresses duties to prospective clients, including people who consult with a lawyer about possibly forming a client-lawyer relationship. Whether and how a particular interaction qualifies depends on facts and applicable rules, but the operational lesson is clear: do not invite unnecessary disclosure before the firm knows it wants the information.
An intake greeting should explain the purpose of the interaction and avoid promising representation. Questions should gather enough information for routing and conflicts review without asking the person to deliver the complete case theory. Legal questions should go to a lawyer.
Security review should produce concrete artifacts
At the end of the evaluation, the firm should have more than meeting notes. Create:
- a data-flow map;
- a list of approved fields by channel;
- a permission matrix;
- recording and retention rules;
- an integration map;
- escalation and outage procedures;
- a vendor contact and incident path;
- a test script and sign-off record;
- a recurring review schedule.
These artifacts make the review repeatable. They also help the firm explain the workflow to attorneys and staff without relying on technical jargon.
Frequently asked questions
Is an AI receptionist secure for law firms?
It can be, but security depends on both vendor controls and firm configuration. Evaluate data collection, encryption, access, retention, recordings, integrations, incident response, and oversight.
Does using AI violate attorney confidentiality duties?
Not automatically. Lawyers must evaluate the use under applicable professional obligations, including competence, confidentiality, communication, and supervision. ABA Formal Opinion 512 provides relevant guidance, but firms should assess their jurisdiction and facts.
What information should AI intake collect?
Collect the minimum information needed for routing, initial qualification, conflicts review, scheduling, and a useful handoff. Defer detailed facts that do not change the immediate next step.
Should a law firm record AI receptionist calls?
Only under a defined policy that addresses purpose, notice or consent, jurisdiction, access, security, and retention. Firms should obtain appropriate legal guidance for the states and callers involved.
Who should have access to transcripts and recordings?
Access should be role-based and limited to people who need it. Administrative access and account changes should be controlled and reviewable.
How long should intake data be retained?
There is no universal period for every category. Set intentional rules for leads, rejected inquiries, client messages, recordings, transcripts, analytics, logs, and backups based on applicable obligations and business need.
Can an AI receptionist perform a conflict check?
It can collect and structure names for the firm's conflicts process. The firm and its lawyers remain responsible for the actual conflicts analysis and representation decision.
What should happen when the AI is uncertain?
It should follow an approved fallback, such as clarification, transfer, priority alert, or human review. It should not improvise legal advice.
How often should the workflow be reviewed?
Review it on a defined schedule and whenever the firm changes services, staff, systems, channels, or automation scope. Quarterly review is a practical starting cadence for many firms.
What should a vendor security demonstration include?
Ask to see the complete configured journey, permissions, integration records, error paths, escalation, recording behavior, retention controls, and what happens when the normal workflow fails.
Recommended Posts
9/26/2026
Law Firm Intake SLA: Response Times, Ownership, and Escalation for 3-5 Attorney Firms
Build a practical law firm intake SLA covering response times, ownership, qualification, booking, escalation, records, and weekly metrics.
9/25/2026
Missed Call Text-Back for Law Firms: How to Recover More Inquiries
Learn how law firms can recover missed calls with fast, structured SMS intake, callback routing, consultation booking, and CRM continuity.