
The TrustMark Report
A live legal AI governance matrix for evaluating AI platforms, legal research systems, connectors, agentic workflows, transcription, document systems, and emerging legal technology.
The TrustMark helps lawyers distinguish between tools appropriate for client-confidential workflows under enterprise terms, tools limited to non-confidential use, tools prohibited for client data, and tools still requiring formal review. A vendor can pass one layer and fail another; a consumer tier can be prohibited while an enterprise tier may be approved; a connector can change the risk profile of an otherwise acceptable product.
Snapshot as of July 9, 2026. Grades are contingent on current vendor terms, executed DPA / MSA where required, enterprise configuration, admin controls, retention settings, and human-review workflows. Vendor policies change frequently.
Executive Dashboard
How to Use This Report
Research, drafting, transcription, discovery, intake, communication, automation, billing, or agentic workflow.
Consumer, Pro, Team, Enterprise, API, ZDR, legal-specific, self-hosted, or custom deployment.
Approved, Enterprise Terms Required, Caution, Prohibited, or Review Required.
Terms, DPA, MSA, BAA, SOC 2, ISO 27001, retention, no-training, subprocessors, admin controls.
Confidentiality, Oversight, Understanding, Notice, Scrutiny, Equity, Learning.
Methodology 2.0
COUNSEL is LegalTek's operational scoring layer, built upon ABA Formal Opinion 512. Version 2.0 adds explicit dimensions for connector, agentic, action-authority, and evidence-confidence scoring.
Rule 1.1 Competence
Reasonable understanding of capabilities and limits. Independent verification is non-delegable.
Rule 1.6 Confidentiality
Evaluate disclosure risk before input. Self-learning tools require informed client consent.
Rule 1.4 Communication
Disclose AI use when asked, when inputting client information, and when output influences significant decisions.
Rule 5.1 / 5.3 Supervision
Managerial lawyers must establish AI policies; supervisory duties extend to third-party GAI providers.
Rule 3.3 / 8.4(c) Candor
Review AI output before assertion to a court. Known failure modes: fabricated opinions, inaccurate analysis.
Rule 1.5 Fees
Bill only actual time. Per-use legal-AI expenses billed at actual cost with advance disclosure.
Scoring dimensions
Scoring pipeline
Interactive Master Matrix
47 of 47 entries
Search, filter by posture, category, data sensitivity, action authority, platform layer, or governance flags. Click a row to reveal the full evidence panel, connector notes, required controls, and last-reviewed date.
| Product | Tier | Category | Posture | Action Authority | Last Reviewed | |
|---|---|---|---|---|---|---|
ChatGPT OpenAI | Free / Plus / Pro / Go | General-Purpose AI | Prohibited | Read, Draft | 2026-07-09 | |
ChatGPT OpenAI | Team / Enterprise / Edu | General-Purpose AI | Approved Connector | Read, Draft, Write | 2026-07-09 | |
OpenAI API OpenAI | Standard / ZDR | General-Purpose AI | Approved Agentic | Read, Draft, Trigger Automation | 2026-07-09 | |
Claude Anthropic | Free / Pro / Max | General-Purpose AI | Prohibited | Read, Draft | 2026-07-09 | |
Claude Anthropic | Team / Enterprise / API / Bedrock / Vertex | General-Purpose AI | Approved Connector | Read, Draft, Write | 2026-07-09 | |
Gemini Google | Consumer | General-Purpose AI | Prohibited | Read, Draft | 2026-07-09 | |
Gemini Google | Workspace / Vertex AI | General-Purpose AI | Approved | Read, Draft, Write | 2026-07-09 | |
Grok xAI | All tiers | General-Purpose AI | Prohibited | Read, Draft | 2026-07-09 | |
Perplexity Perplexity AI | Free / Pro | General-Purpose AI | Restricted | Read | 2026-07-09 | |
Perplexity Enterprise Pro Perplexity AI | Enterprise | General-Purpose AI | Ent. Terms | Read, Draft | 2026-07-09 | |
Comet Browser Perplexity AI | Standard | Agentic | Review Req. Agentic | Read, Draft, Send/Share +1 | 2026-07-09 | |
Manus Manus | Standard | Agentic | Restricted Agentic | Read, Draft, Write +1 | 2026-07-09 | |
OpenClaw Open source | Self-hosted | Agentic | Review Req. Agentic | Read, Draft, Write +1 | 2026-07-09 | |
Hermes Agent Hermes | Standard | Agentic | Review Req. Agentic | Read, Draft, Persistent Agent +1 | 2026-07-09 | |
CrewAI CrewAI | Open source / Enterprise | Agentic | Review Req. Agentic | Read, Draft, Persistent Agent | 2026-07-09 | |
Microsoft Agent Framework Microsoft | Enterprise | Agentic | Ent. Terms Agentic | Read, Draft, Trigger Automation +1 | 2026-07-09 | |
Airia AI Platform Airia | Enterprise | Agentic | Ent. Terms Agentic | Read, Draft, Trigger Automation | 2026-07-09 | |
n8n AI Agent Node n8n | Cloud / Self-hosted | Automation/Workflow | Review Req. Agentic | Read, Draft, Trigger Automation | 2026-07-09 | |
Zapier + AI Actions Zapier | Team / Company | Automation/Workflow | Restricted Agentic | Read, Write, Send/Share +1 | 2026-07-09 | |
Westlaw / CoCounsel Thomson Reuters | Enterprise | Legal-Specific | Approved | Read, Draft | 2026-07-09 | |
Lexis+ with Protégé LexisNexis | Enterprise | Legal-Specific | Approved | Read, Draft | 2026-07-09 | |
Midpage Midpage | Standard | Legal-Specific | Approved | Read, Draft | 2026-07-09 | |
CourtListener Free Law Project | All tiers | Legal-Specific | Approved | Read | 2026-07-09 | |
Harvey Harvey | Enterprise | Legal-Specific | Approved | Read, Draft | 2026-07-09 | |
Legora Legora | Enterprise | Legal-Specific | Ent. Terms | Read, Draft | 2026-07-09 | |
Spellbook Rally | Enterprise | Legal-Specific | Ent. Terms | Read, Draft | 2026-07-09 | |
Clio Duo Clio | Enterprise | Practice Management | Ent. Terms | Read, Draft | 2026-07-09 | |
MyCase IQ MyCase | Enterprise | Practice Management | Ent. Terms | Read, Draft | 2026-07-09 | |
Filevine AIFields / Sidebar Filevine | Enterprise | Practice Management | Ent. Terms | Read, Draft | 2026-07-09 | |
iManage AI iManage | Enterprise | Document/DMS | Ent. Terms | Read, Draft | 2026-07-09 | |
NetDocuments ndMAX NetDocuments | Enterprise | Document/DMS | Ent. Terms | Read, Draft | 2026-07-09 | |
Otter.ai Otter | All tiers | Transcription | Prohibited | Read, Draft | 2026-07-09 | |
Fathom Fathom | Standard | Transcription | Caution | Read | 2026-07-09 | |
Fireflies.ai Fireflies | Enterprise | Transcription | Approved | Read | 2026-07-09 | |
Plaud Plaud | Standard | Transcription | Caution | Read | 2026-07-09 | |
Granola Granola | All tiers | Transcription | Review Req. | Read | 2026-07-09 | |
Wispr Flow Wispr | All tiers | Transcription | Review Req. | Read | 2026-07-09 | |
Microsoft 365 Copilot Microsoft | Enterprise | Productivity | Approved | Read, Draft, Write | 2026-07-09 | |
Microsoft Copilot Microsoft | Consumer (Free / Pro / standalone) | Productivity | Prohibited | Read, Draft | 2026-07-09 | |
Notion AI Notion | Business / Enterprise | Productivity | Ent. Terms | Read, Draft, Write | 2026-07-09 | |
Slack AI Salesforce | Enterprise Grid | Communication | Ent. Terms | Read, Draft | 2026-07-09 | |
Zoom AI Companion Zoom | Enterprise | Communication | Restricted | Read | 2026-07-09 | |
Grammarly Business / Enterprise Grammarly | Enterprise | Productivity | Ent. Terms | Read, Draft | 2026-07-09 | |
Even Realities G1 Even Realities | Consumer smart glasses | Wearable Hardware | Restricted | Read | 2026-07-09 | |
ChatGPT Apps / Connectors / Actions OpenAI | Enterprise-controlled | Connector Platform | Ent. Terms AgenticConnector | Read, Draft, Write +2 | 2026-07-09 | |
Claude Connectors (MCP/OAuth) Anthropic | Enterprise-controlled | Connector Platform | Ent. Terms AgenticConnector | Read, Draft, Write +1 | 2026-07-09 | |
Custom MCP Connectors Firm-authored | Self-hosted | Connector Platform | Review Req. AgenticConnector | Read, Draft, Write +1 | 2026-07-09 |
Developing Law — Heppner Overlay
Reports of United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y. 2026) describe a trial-court ruling that documents a criminal defendant generated using the consumer version of Anthropic's Claude were protected by neither attorney-client privilege nor work product. LegalTek has not yet independently verified the primary court order or docket entry; the case is treated here as developing law until that verification is complete.
The narrow, defensible reading — pending verification — is that consumer-tier AI tools with training-on-inputs or weak confidentiality terms may create privilege and work-product risk, while enterprise, attorney-directed, no-training tools are materially better positioned. AI use does not categorically waive privilege, and a single trial-court decision does not create binding precedent.
Caveats & Limitations
- No-training and security representations are frequently drawn from vendor trust-center pages rather than the operative contract. The binding document is the executed DPA or MSA. Obtain, read, and retain it.
- Vendor policies change quickly. Every grade is a snapshot subject to revision. A product not fully reviewed appears as Review Required, not as approved.
- "De-identified" is not "anonymous." Vendors that train proprietary models on de-identified customer data carry re-identification risk for sensitive matters.
- Recording and wearable-capture tools implicate state two-party and all-party consent statutes independent of the AI-training analysis.
- Public connector-directory listings do not indicate suitability for client data. Custom connectors and MCP servers are governance surfaces, not products, and require firm-authored controls.
- Court orders and lawful process override deletion and retention promises across every platform reviewed.
Request a TrustMark assessment for your firm
We will review your current AI stack, connectors, and agentic workflows against the TrustMark rubric, confirm DPA and subprocessor terms, and deliver a firm-specific matrix with remediation steps.
Source Appendix
Primary sources cited in the grading. Capture the displayed "last updated" date at the moment of contracting — these policies change frequently.
- ABA Comm. on Ethics & Prof'l Responsibility, Formal Op. 512 (2024)
- United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y. 2026) — pending primary-source verification
- NYT v. OpenAI Preservation Order (May 13, 2025)
- OpenAI Privacy Policy
- OpenAI Enterprise Privacy
- Anthropic Consumer Terms Update
- Anthropic ZDR Scope
- Google Workspace AI Privacy
- xAI Privacy Policy
- CoCounsel Security FAQ
- Lexis+ with Protégé
- Midpage
- CourtListener Terms
- Harvey Security
- Microsoft 365 Copilot Privacy
- Even Realities Terms of Service
Disclaimer: The LegalTek TrustMark™ is a proprietary informational governance report maintained by LegalTek.ai. Grades and postures are a snapshot as of the date shown and are contingent on executed vendor terms, admin configuration, and human-review workflows. Vendor policies change frequently. This page is for general informational and educational purposes and does not constitute legal advice. No attorney-client relationship is created by reading this material. LegalTek.ai is a technology company, not a law firm.
LegalTek TrustMark™, COUNSEL Framework™, and SilverTung™ are trademarks of LegalTek.ai.