RankShield Legal
Citation checker Request access
Vendor failure

Your Legal AI Vendor Gets Breached or Shuts Down: Whose Problem Is It?

Every vendor-diligence guide, including ours, is written for the moment before you sign. Almost none is written for the moment the vendor fails. On June 30, 2022, the litigation analytics company Gavelytics shut down with one day's notice to its customers and employees. That is the scenario worth planning for, because when a third party holding your privileged material is breached or goes dark, your professional obligations do not transfer to them. They stay with you.

By Jamie Kloncz, Founder, RankShield 20 min read Published

There are two vendor failures a firm should have a plan for, and they look nothing alike. In the first, the vendor is breached and your client's confidential material is exposed by someone else's security failure. In the second, the vendor simply stops: it shuts down, gets acquired, or is bought and folded into something that no longer does what you needed.

The first has a clear ethical framework and most firms have never read it. ABA Formal Opinion 483, "Lawyers' Obligations after an Electronic Data Breach or Cyberattack," issued in October 2018, addresses what a lawyer must do after a breach, and it reaches breaches that occur at or through a third-party service provider [1][2].

Its most uncomfortable holding is about safe harbors: there are none. On the IAPP's reading of the opinion, a lawyer's post-breach notification obligations are independent of any assessment of how reasonable the lawyer's efforts to avoid the breach were [2]. Doing the diligence properly does not discharge the duty to tell the client when it fails anyway.

The second failure has almost no ethical literature and a great deal of history. Gavelytics closed on June 30, 2022 with a single day's notice; its platform and data were acquired by another company six months later. ROSS Intelligence shut down in December 2020 after litigation with Thomson Reuters left it unable to secure financing. LexisNexis Firm Manager, by contrast, was discontinued with an orderly wind-down planned well in advance, closing on October 31, 2017 [3].

The difference between one day's notice and a planned wind-down is not something a firm controls after the fact. It is decided in a contract signed years earlier, or not decided at all. This article is written from the perspective of a verification vendor, not a law firm, and it is informational rather than legal advice. Opinion 483 is an ABA ethics opinion rather than binding law, jurisdictions vary, and breach-notification statutes apply independently. Confirm your own obligations with counsel.

Opinion 483 reaches breaches that happen at the vendor

The duty does not stop at your own perimeter. Opinion 483 addresses lawyers' obligations after an electronic data breach, and its framework extends to breaches occurring at or through a third-party service provider, with vendor oversight running through the Rule 5.3 duty regarding nonlawyer assistance [1][2].

Firms tend to read breach obligations as being about their own systems. The relevant question is not whose server was compromised, it is whose client confidential information was in it.

The structural route is Rule 5.3, which governs a lawyer's responsibilities regarding nonlawyer assistance. A vendor processing client material is performing work the lawyer is responsible for supervising, and the opinion's framework treats vendors as subject to that oversight obligation rather than as a boundary where the lawyer's duty ends [2].

That has an obvious implication most vendor evaluations miss. The diligence you perform before signing is not only about choosing well. It is the evidence that you exercised the supervision the rule requires, which is a different purpose and a different audience. Our guide to reading a SOC 2 report covers how to assess the controls; this is the reason the assessment itself is worth documenting.

It also means the firm cannot treat a vendor incident as the vendor's announcement to make. The vendor will notify the firm. The firm owes its own communication to its own clients, on its own timeline, and the vendor's public statement does not discharge it.

There is no safe harbor for having done the diligence

The holding that surprises careful firms most: on the IAPP's reading, a lawyer's post-breach notification obligations are independent of a reasonableness assessment of the lawyer's efforts to avoid the breach [2]. Having chosen a well-audited vendor does not reduce the duty to tell the client when that vendor is compromised.

This is the ethical analogue of a finding this site has covered from the litigation side. In Johnson v. Dunn the court treated a firm's existing AI policies as aggravating rather than mitigating, noting the lawyers had benefitted from repeated warnings and internal controls before the failure happened anyway. Opinion 483 does something structurally similar for breaches: good prior conduct does not buy relief from the post-incident duty [2].

The two propositions are worth holding together because firms tend to assume the opposite. Diligence feels like insurance. It is not insurance against the disclosure obligation; it is evidence of supervision, which is a separate benefit.

What diligence does affect is everything downstream of the notification: whether the firm can tell the client what happened, whether contractual remedies exist, whether the vendor is obliged to help, and whether the firm looks like an organization that was paying attention. Those are substantial. They are not the duty.

The practical reframing is that the diligence file and the incident file serve different masters. The first answers whether the firm supervised. The second answers what the firm did when supervision was not enough. A firm that has only the first is missing the one that gets used.

RANKSHIELD LEGAL When the vendor fails, the duty stayswith you Two failure modes, one framework, and a notice period you do not control. No safe harbor Post-breach notification duty is independent of howreasonable your pre-breach efforts were ABA Formal Opinion 483, October 2018 Current yes An obligation exists to communicate with currentclients about a breach Former no The committee declined to require notice to formerclients absent a black letter provision Pointed to Rule 1.16(d) and retention schedules Rule 5.3 Vendor oversight runs through the duty regardingnonlawyer assistance 1 day Notice Gavelytics gave before shutting down, June 302022 LexisNexis Firm Manager: orderly, planned in advance 6 terms Notice, export, insolvency, acquisition, breachtiming, cooperation RankShield Legal rankshieldlegal.com
Source: ABA Formal Op. 483 (Oct 2018) via IAPP; LawSites legal tech failures

Current clients and former clients are not the same question

Opinion 483 draws a line most summaries blur. An obligation exists to communicate with current clients about a data breach. On former clients the committee declined to impose an ethical notice requirement, stating it was unwilling to require notice to a former client in the absence of a black letter provision, and pointing instead to Rule 1.16(d) and to agreements about information handling and record retention [2].

This distinction is worth stating carefully because it is frequently reported the other way, including in summaries that assert Opinion 483 requires notifying both. It does not.

For current clients the position is straightforward: an obligation exists to communicate about a breach, triggered where client interests have a reasonable possibility of being negatively impacted, including where confidential information has been misappropriated, destroyed or compromised, or where the lawyer's ability to provide legal services is substantially impaired [2].

For former clients the committee declined to create an ethical duty, reasoning that the Model Rules contain no black letter provision requiring it. It pointed to Rule 1.16(d), which concerns a lawyer's obligations on termination of a representation, and encouraged firms to reach agreements with clients about how information will be handled and to adopt record-retention schedules [2].

Two consequences follow, and they cut in opposite directions. The first is that a firm holding years of former-client material in a vendor system has less ethical clarity about notification than it probably assumes. The second is more useful: the committee's suggestion is that the answer belongs in the engagement letter and the retention schedule rather than in an ethics opinion. That is a document a firm can change this quarter.

⚠️ Note also that ethics rules are not the only layer. State breach-notification statutes apply to personal information regardless of what the Model Rules say about former clients, and those obligations run on their own triggers and timelines. Nothing in Opinion 483 displaces them.

Because the ABA site blocks automated retrieval of the opinion PDF, the characterizations above are drawn from the IAPP's analysis of Opinion 483 rather than quoted from the opinion text, and are attributed accordingly. The opinion itself is the authoritative statement; read it before relying on any summary, including this one.

The second failure: the vendor that simply stops

Shutdowns do not come with a standard notice period. Gavelytics closed on June 30, 2022 with one day's notice to customers and employees. LexisNexis Firm Manager was discontinued with an orderly wind-down planned in advance, closing October 31, 2017. Both are normal outcomes. Which one you get is decided by your contract [3].

The legal technology graveyard is not hypothetical and it is not confined to marginal products. ROSS Intelligence, an AI legal research company, shut down in December 2020 after litigation with Thomson Reuters left it unable to secure financing. Atrium closed in 2020 having raised $75 million [3].

Gavelytics is the instructive one for planning purposes. A litigation analytics company closed on June 30, 2022, giving customers and employees a single day's notice. Its platform and data were acquired by another company roughly six months later, which is a reasonable outcome and also entirely outside the customers' control during the intervening period [3].

Set that against LexisNexis Firm Manager. Sales were discontinued in January 2017, the shutdown was planned in advance, and the service closed on October 31, 2017 [3]. Same category of event, completely different experience for a firm that had matters running on it.

The variable is not the vendor's decency. It is whether anything in the agreement obliged them to give notice, provide an export, or maintain access during a wind-down. Absent a term, a company in financial distress owes its customers whatever its remaining resources and goodwill allow, which in Gavelytics's case was one day.

Acquisition is the version firms plan for least, because nothing appears to break. The product continues, the login works, and the terms, the retention schedule, the sub-processor list and the data location may all change under a new owner. A firm that verified those things at signing and never again has verified a state of affairs that no longer obtains, which is the argument our RFP guide makes for annual re-checks.

The duty you cannot discharge without the data

Rule 1.16(d) requires a lawyer to surrender papers and property to which the client is entitled on termination of a representation. That is a duty you cannot perform if the material sits in a vendor system you can no longer reach. The vendor's failure becomes your inability to meet an obligation the client is owed.

This is the point at which a vendor problem stops being procurement's and becomes professional responsibility's.

A client whose representation ends is entitled to their file. If a meaningful part of the work product, correspondence, or analysis lives inside a platform that has gone dark, been repossessed by a creditor, or been folded into an acquirer's stack under different terms, the firm owes something it may not be able to produce.

The exposure is quiet because it is deferred. Nothing goes wrong on the day the vendor closes. It goes wrong months later when a client asks for their file, or a matter is transferred, or a malpractice claim requires reconstructing what was done and when.

The verification record has the same shape and the same vulnerability. This site argues consistently that a firm should be able to show which authorities were checked and by whom, and our guide on proving verification to a court works through why. A verification log that exists only inside a vendor's system is a record you do not actually hold.

That is the practical test for any legal AI tool: if this vendor disappeared tomorrow, what would the firm still have. If the honest answer is a login that no longer works, the firm has been renting its own evidence.

1 day notice Gavelytics gave customers and employees before shutting down on June 30, 2022 [3]

What to negotiate before you need it

Five terms decide how a vendor failure lands: notice on discontinuation, export format and retrieval window, what happens on acquisition or insolvency, breach-notification timing to you, and cooperation obligations during your own client notification. All of them are cheap at signing and unobtainable afterwards.

None of these terms is exotic and all of them are easier to obtain during a competitive procurement than during a crisis. The reason firms lack them is that vendor evaluation focuses almost entirely on capability and security posture, both of which describe the vendor working rather than the vendor failing.

The export term deserves the most attention and gets the least. "You can export your data" is not a commitment worth much unless it specifies the format, whether it includes metadata and audit logs, how long access persists after termination, and whether export remains available if the account lapses for non-payment. A CSV of document titles is technically an export.

The insolvency and acquisition provisions are the ones a vendor may resist and the ones that matter most in exactly the scenarios this article describes. A company that is being wound down has limited ability to honour any obligation, which is an argument for escrow or for retaining your own copy rather than for a stronger promise.

  1. Notice period on discontinuationA defined minimum, in writing. The distance between Gavelytics and LexisNexis Firm Manager is the distance between one day and a planned wind-down, and only a contract term makes that predictable [3].
  2. Export: format, scope, and windowSpecify the format, that it includes metadata and audit or verification logs, how long retrieval remains available after termination, and that it survives non-payment. Test the export once while the vendor is healthy.
  3. Acquisition and insolvencyWhat happens to your data, your retention windows, and your negotiated terms if the vendor is acquired or enters insolvency. Consider escrow, and prefer keeping your own copy over relying on a promise from an entity that may not exist.
  4. Breach notification to you, with a clockYou cannot meet your own obligation to a client until the vendor tells you. Set a defined maximum notification period to the firm, and require enough detail to identify which clients' material was involved.
  5. Cooperation during your notificationOpinion 483's framework leaves the client communication with you [1][2]. Require the vendor to provide the facts you need to make it accurate, rather than a press statement.
  6. Keep your own copy of anything evidentiaryVerification records, audit logs, and anything you might need to reconstruct what was done should exist somewhere the firm controls. A record held only by a vendor is a record you can lose without doing anything wrong.

The incident plan needs a vendor branch

Most firm AI incident plans assume the incident happens inside the firm. A vendor breach inverts the sequence: the firm learns late, from someone else, with facts it cannot independently verify, and still owes its clients a communication it must make on its own judgment.

Our guide to the law firm AI incident response plan covers the internal case. The vendor case differs in three ways worth writing into the plan explicitly.

First, discovery is external and delayed. The firm finds out when the vendor decides to say so, which may be well after the fact and may arrive as a general customer notice rather than a specific account finding. The first task is usually establishing whether your data was in scope at all, and the vendor is the only source.

Second, the facts are someone else's. A firm investigating its own incident can look. A firm receiving a vendor notification is dependent on the vendor's characterization, which is being drafted with the vendor's own liability in view. That is a reason to have contractual detail obligations, and a reason to be careful about repeating a vendor's framing to a client as though the firm had verified it.

Third, the notification duty is still the firm's. The client's relationship is with the lawyer. On the Opinion 483 framework, the obligation to communicate with a current client about a breach affecting their confidential information belongs to the firm regardless of whose system failed [1][2].

Naming the vendor branch in the plan costs nothing and changes the first hour. Who contacts the vendor, who decides scope, who drafts the client communication, and who decides whether the vendor's account is sufficient to rely on are all questions better answered before a notice arrives on a Friday afternoon.

What a firm should actually do this quarter

Four things, none of which require a vendor's cooperation: inventory which vendors hold client material, test one export, add the vendor branch to the incident plan, and put information handling and retention into the engagement letter, which is where Opinion 483's committee pointed for the former-client question [2].

The recommendations in this article are unusually cheap, which is the main argument for doing them now rather than after a notification.

Start with the inventory, because most firms cannot currently answer the question. Which vendors hold client confidential material, what categories, for which clients, and under what retention. That single document is the prerequisite for every other step, and it is the thing a firm most wishes it had on the day a vendor notice arrives.

Then test one export. Not read the clause, perform the export, on a real matter, and look at what comes out. This is the step that reliably surprises people, and it is far better to be surprised while the vendor is healthy and answering support tickets.

Add the vendor branch to the incident plan, and put the engagement-letter language in place. On the former-client question the committee's own suggestion was agreements with clients about information handling and record-retention schedules, which is to say the answer is contractual rather than ethical [2]. That is within the firm's control and does not require anyone's permission.

None of this makes a vendor failure less likely. It changes what the failure costs, which is the only variable a firm actually holds.

Questions answered

Straight answers to the common questions

The questions readers ask about this topic, answered directly. No forms, no sales pitch.

JAMIE KLONCZ · SEO AGENCY NAPLES ONLINE

Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.

REQUEST ACCESS →

References

  1. American Bar Association, Standing Committee on Ethics and Professional Responsibility. Formal Opinion 483: Lawyers' Obligations After an Electronic Data Breach or Cyberattack. October 2018. https://www.americanbar.org/content/dam/aba/administrative/professional_responsibility/ethics-opinions/aba-formal-op-483.pdf
  2. International Association of Privacy Professionals. American Bar Association issues ethics opinion on client-data breaches (analysis of Formal Opinion 483). 2018. https://iapp.org/news/a/american-bar-association-issues-ethics-opinion-on-client-data-breaches
  3. LawSites (Robert Ambrogi). The Five Most Momentous Legal Tech Fails. April 2024. https://www.lawnext.com/2024/04/the-five-most-momentous-legal-tech-fails.html
Written by

Jamie Kloncz

Founder, RankShield

Jamie Kloncz is the founder of RankShield, the verifiable AI and quantum security platform behind RankShield Legal. An engineer by training, he built RankShield after his own devices and business were attacked, including an AI voice-cloning scam that targeted his family, on one conviction: unverifiable security is the real danger, so every consequential action should leave a receipt anyone can independently check.

More about Jamie →
Try it · Free

Check a citation against live case-law

Paste a citation from an AI-drafted brief and see whether the case actually exists, resolved against live case-law. Free, no sign-up. Then request early access to certify a full filing.

Try the citation checker