Back to Home
    LegalTek TrustMark — Legal AI Governance Matrix seal
    LegalTek TrustMark™
    ABA Formal Op. 512
    COUNSEL Framework
    Governance Matrix

    The TrustMark Report

    A live legal AI governance matrix for evaluating AI platforms, legal research systems, connectors, agentic workflows, transcription, document systems, and emerging legal technology.

    The TrustMark helps lawyers distinguish between tools appropriate for client-confidential workflows under enterprise terms, tools limited to non-confidential use, tools prohibited for client data, and tools still requiring formal review. A vendor can pass one layer and fail another; a consumer tier can be prohibited while an enterprise tier may be approved; a connector can change the risk profile of an otherwise acceptable product.

    Snapshot as of July 9, 2026. Grades are contingent on current vendor terms, executed DPA / MSA where required, enterprise configuration, admin controls, retention settings, and human-review workflows. Vendor policies change frequently.

    Executive Dashboard

    07-09
    Last Reviewed
    July 9, 2026

    How to Use This Report

    1
    Choose the workflow

    Research, drafting, transcription, discovery, intake, communication, automation, billing, or agentic workflow.

    2
    Choose the product tier

    Consumer, Pro, Team, Enterprise, API, ZDR, legal-specific, self-hosted, or custom deployment.

    3
    Check the TrustMark posture

    Approved, Enterprise Terms Required, Caution, Prohibited, or Review Required.

    4
    Confirm the evidence

    Terms, DPA, MSA, BAA, SOC 2, ISO 27001, retention, no-training, subprocessors, admin controls.

    5
    Apply COUNSEL controls

    Confidentiality, Oversight, Understanding, Notice, Scrutiny, Equity, Learning.

    Methodology 2.0

    COUNSEL is LegalTek's operational scoring layer, built upon ABA Formal Opinion 512. Version 2.0 adds explicit dimensions for connector, agentic, action-authority, and evidence-confidence scoring.

    Rule 1.1 Competence

    Reasonable understanding of capabilities and limits. Independent verification is non-delegable.

    Rule 1.6 Confidentiality

    Evaluate disclosure risk before input. Self-learning tools require informed client consent.

    Rule 1.4 Communication

    Disclose AI use when asked, when inputting client information, and when output influences significant decisions.

    Rule 5.1 / 5.3 Supervision

    Managerial lawyers must establish AI policies; supervisory duties extend to third-party GAI providers.

    Rule 3.3 / 8.4(c) Candor

    Review AI output before assertion to a court. Known failure modes: fabricated opinions, inaccurate analysis.

    Rule 1.5 Fees

    Bill only actual time. Per-use legal-AI expenses billed at actual cost with advance disclosure.

    Scoring dimensions

    Model training on inputsContractual no-training commitmentRetention and deletionDPA / MSA availabilityEnterprise vs consumer tierSubprocessorsSecurity certificationsBAA availabilityAdmin controlsAudit logsConnector availabilityAction authorityAgentic capabilityHuman approval gatesData sensitivitySource confidenceLast reviewed date

    Scoring pipeline

    Vendor Terms→
    Data Handling→
    Security→
    Connector Pathway→
    Agentic Capability→
    COUNSEL Crosswalk→
    TrustMark Posture

    Interactive Master Matrix

    47 of 47 entries

    Search, filter by posture, category, data sensitivity, action authority, platform layer, or governance flags. Click a row to reveal the full evidence panel, connector notes, required controls, and last-reviewed date.

    Flags:

    Developing Law — Heppner Overlay

    Pending Primary Source Verification

    Reports of United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y. 2026) describe a trial-court ruling that documents a criminal defendant generated using the consumer version of Anthropic's Claude were protected by neither attorney-client privilege nor work product. LegalTek has not yet independently verified the primary court order or docket entry; the case is treated here as developing law until that verification is complete.

    The narrow, defensible reading — pending verification — is that consumer-tier AI tools with training-on-inputs or weak confidentiality terms may create privilege and work-product risk, while enterprise, attorney-directed, no-training tools are materially better positioned. AI use does not categorically waive privilege, and a single trial-court decision does not create binding precedent.

    Legal disclaimer. This report is for informational and educational purposes only. It is not legal advice, does not create an attorney-client relationship, and does not substitute for firm-specific review of governing law, client facts, vendor contracts, and professional-responsibility obligations.

    Caveats & Limitations

    • No-training and security representations are frequently drawn from vendor trust-center pages rather than the operative contract. The binding document is the executed DPA or MSA. Obtain, read, and retain it.
    • Vendor policies change quickly. Every grade is a snapshot subject to revision. A product not fully reviewed appears as Review Required, not as approved.
    • "De-identified" is not "anonymous." Vendors that train proprietary models on de-identified customer data carry re-identification risk for sensitive matters.
    • Recording and wearable-capture tools implicate state two-party and all-party consent statutes independent of the AI-training analysis.
    • Public connector-directory listings do not indicate suitability for client data. Custom connectors and MCP servers are governance surfaces, not products, and require firm-authored controls.
    • Court orders and lawful process override deletion and retention promises across every platform reviewed.
    Get TrustMark Certified

    Request a TrustMark assessment for your firm

    We will review your current AI stack, connectors, and agentic workflows against the TrustMark rubric, confirm DPA and subprocessor terms, and deliver a firm-specific matrix with remediation steps.

    Source Appendix

    Primary sources cited in the grading. Capture the displayed "last updated" date at the moment of contracting — these policies change frequently.

    Disclaimer: The LegalTek TrustMark™ is a proprietary informational governance report maintained by LegalTek.ai. Grades and postures are a snapshot as of the date shown and are contingent on executed vendor terms, admin configuration, and human-review workflows. Vendor policies change frequently. This page is for general informational and educational purposes and does not constitute legal advice. No attorney-client relationship is created by reading this material. LegalTek.ai is a technology company, not a law firm.

    LegalTek TrustMark™, COUNSEL Framework™, and SilverTung™ are trademarks of LegalTek.ai.

    Vendor Terms Evaluation

    LegalTek evaluates third-party AI tools against the COUNSEL Framework before recommending them for legal workflows. Below is our assessment of productivity and legal-research vendors commonly considered by attorneys.

    Analysis based on publicly posted Terms of Service and Privacy documentation. This is not legal advice; firms must conduct independent due diligence before deploying any vendor with client data.

    Automated re-evaluation cadence: every 30 days|Granola: v1.0 · updated —|Wispr Flow: v1.0 · updated —|Midpage: v1.0 · updated —|CourtListener: v1.0 · updated —|Even Realities: v1.0 · updated —|Honcho: v1.0 · updated —|Buzz: v1.0 · updated —|Obsidian: v1.0 · updated —|Agent OS: v1.0 · updated —

    Granola

    AI meeting notetaker · Evaluation v1.0 · Last updated —

    Link to Terms of Service ● unchecked

    Strengths

    • • Layered Terms structure (Platform, Application, User) separates enterprise from consumer obligations.
    • • API documentation is public and permits programmatic access with issued keys.
    • • Distinguishes personal use from organization-bound acceptance for authorized signatories.

    Concerns for Legal Use

    • • Meeting audio and AI summaries constitute attorney-client communications when used on privileged calls — retention and access disclosures must be scrutinized before enabling on client matters.
    • • Terms do not publicly commit to no-training on customer meeting content at the free/personal tier; enterprise DPAs must be negotiated separately.
    • • Consent-to-record obligations shift entirely to the user; Ohio and most one-party-consent states are covered, but all-party-consent jurisdictions (CA, FL, IL, PA, WA) require affirmative disclosure.

    COUNSEL Crosswalk

    Confidentiality — Requires enterprise DPA
    Oversight — User-mediated
    Understanding — Terms are readable
    Notice — Third-party consent not automated
    Scrutiny — Limited third-party audit disclosure
    Equity — Not addressed in ToS
    Learning — Model training policy not publicly explicit for personal tier

    LegalTek Assessment: Acceptable for internal, non-privileged meetings. Not currently eligible for the LegalTek Trust Mark™ for use on client-privileged calls without a negotiated enterprise agreement, BAA (where PHI is possible), and documented all-party consent workflows.

    Sources & Audit Trail — Granola2 documents · click to expand
    DocumentExact URLPublisher dateRetrieved by LegalTek
    Application Terms of Servicemonitoredhttps://docs.granola.ai/help-center/policies/terms-of-service/application-terms-of-servicenot statedAug 6, 2026
    Privacy Policyhttps://docs.granola.ai/help-center/policies/privacy-policynot statedAug 6, 2026
    Evaluation record
    v1.0 · —
    Last automated URL check
    no check recorded yet
    Check result
    —

    Retrieval dates record when LegalTek read the document text that this assessment relies on. Publishers may revise terms without notice; the automated checker verifies only that the URL still resolves, not that the text is unchanged. Verify the live document before relying on this assessment. Not legal advice.

    Wispr Flow

    Voice-to-text dictation · Evaluation v1.0 · Last updated —

    Link to Terms of Service ● unchecked

    Strengths

    • • Explicit user ownership of Inputs and assignment of Outputs back to the user (§2.B).
    • • Third-party LLM providers (OpenAI, Anthropic) contractually barred from training on user data; 30-day deletion (§6).
    • • User-controllable model-training toggle via published Data Controls Policy.
    • • Privacy Mode: no dictation stored on Wispr servers.
    • • SOC 2 Type II, ISO 27001, and HIPAA certified per public privacy disclosures.
    • • Prohibits AI Features for automated legally-significant decisions without adequate human review (§3.B) — aligned with COUNSEL Oversight.
    • • Prohibits recording third parties without consent (§3.A).

    Concerns for Legal Use

    • • Standard "AS IS" warranty disclaimer on Output accuracy (§12) — attorneys remain solely responsible for verifying dictated content before filing.
    • • Broad license to "reproduce, modify, distribute, transmit, export, display, store" Customer Content for service operation (§2.B). Confirm scope in enterprise agreement for privileged dictation.
    • • Third-Party Outputs clause disclaims uniqueness — dictation refined by generative AI may resemble other users' Outputs (§2.D).
    • • Limitation of liability excludes consequential damages (§13) — standard SaaS but relevant for malpractice-exposure analysis.

    COUNSEL Crosswalk

    Confidentiality — Privacy Mode + HIPAA + 30-day vendor deletion
    Oversight — Explicit human-review requirement (§3.B)
    Understanding — Clear, sectioned ToS
    Notice — Data Controls Policy published; recording consent required
    Scrutiny — SOC 2 Type II, ISO 27001, HIPAA
    Equity — Anti-discrimination clause in §3.B
    Learning — Opt-out training toggle, no third-party training

    LegalTek Assessment: Materially stronger data-governance posture than most productivity vendors. Provisionally aligned with LegalTek Verified™ baseline for attorney dictation workflows when Privacy Mode is enabled and model-training is disabled at the account level. Firms should still execute a BAA before dictating any PHI and confirm data-residency requirements for regulated matters.

    Sources & Audit Trail — Wispr Flow2 documents · click to expand
    DocumentExact URLPublisher dateRetrieved by LegalTek
    Terms of Servicemonitoredhttps://wisprflow.ai/terms-of-servicenot statedAug 6, 2026
    Privacy Policyhttps://wisprflow.ai/privacynot statedAug 6, 2026
    Evaluation record
    v1.0 · —
    Last automated URL check
    no check recorded yet
    Check result
    —

    Retrieval dates record when LegalTek read the document text that this assessment relies on. Publishers may revise terms without notice; the automated checker verifies only that the URL still resolves, not that the text is unchanged. Verify the live document before relying on this assessment. Not legal advice.

    Midpage

    AI legal research & drafting · Evaluation v1.0 · Last updated —

    Link to Terms of Service ● unchecked

    Strengths

    • • Explicit public commitment: Midpage does not use customer data to train or fine-tune AI models.
    • • Agreements with AI model providers contractually bar those vendors from training on Midpage customer data.
    • • SOC 2 Type II certified with annual independent validation.
    • • AES-256 encryption at rest and TLS 1.2+ in transit.
    • • Plugin integrations do not store submitted queries, uploads, or outputs.
    • • Source-grounded RAG architecture generates answers exclusively from reviewed cases with hyperlinked, verifiable citations — materially reducing Rule 1.1 hallucination risk.

    Concerns for Legal Use

    • • As a venture-stage vendor, enterprise DPA and BAA must be confirmed in writing before processing client-confidential or PHI matters.
    • • Model providers (subprocessors) may retain submitted queries for up to 60 days per disclosed subprocessor terms.
    • • Web app stores product data including user queries, uploaded materials, and generated outputs while the account remains active; deletion is within 60 days of account closure or valid request.
    • • Attorneys must independently verify citations and analysis before filing — the platform is a research accelerator, not a substitute for professional judgment.

    COUNSEL Crosswalk

    Confidentiality — No training + encryption + plugin no-storage
    Oversight — Attorney-directed research required
    Understanding — Source-grounded citations reduce hallucination risk
    Notice — 60-day model-provider retention disclosed
    Scrutiny — SOC 2 Type II
    Equity — Not addressed in public documentation
    Learning — No training on customer data; subprocessor contracts prohibit training

    LegalTek Assessment: Strong data-governance posture for a venture-stage legal-AI vendor. The explicit no-training commitment, SOC 2 Type II certification, and source-grounded RAG architecture make it a promising candidate for LegalTek Verified™ status once a signed DPA and BAA (where applicable) are confirmed. Firms should enable plugin integrations where possible to minimize data retention.

    Sources & Audit Trail — Midpage2 documents · click to expand
    DocumentExact URLPublisher dateRetrieved by LegalTek
    Terms and Conditionsmonitoredhttps://www.midpage.ai/terms-and-conditionsnot statedAug 6, 2026
    Privacy Policyhttps://www.midpage.ai/privacy-policynot statedAug 6, 2026
    Evaluation record
    v1.0 · —
    Last automated URL check
    no check recorded yet
    Check result
    —

    Retrieval dates record when LegalTek read the document text that this assessment relies on. Publishers may revise terms without notice; the automated checker verifies only that the URL still resolves, not that the text is unchanged. Verify the live document before relying on this assessment. Not legal advice.

    CourtListener

    Free legal research database · Evaluation v1.0 · Last updated —

    Link to Terms of Service ● unchecked

    Strengths

    • • Non-profit mission (Free Law Project) with no commercial incentive to monetize user data.
    • • Core service hosts only public court opinions — no client-confidential data is ingested into an AI training pipeline through ordinary search use.
    • • Does not sell visitor information; usage logs are deleted automatically at 12 weeks.
    • • Transparent removal policy: documents are not removed without a court order, protecting the integrity of the public record.
    • • Anonymized data may be shared with academic researchers for system improvement, but not for commercial AI model training.

    Concerns for Legal Use

    • • Terms explicitly disclaim reliability and accuracy of reproduced documents — attorneys must independently verify every citation and quotation before filing.
    • • "AS IS" warranty disclaimer with no representations regarding truthfulness, accuracy, or relevancy of communicated information.
    • • Broad limitation of liability excludes direct, indirect, incidental, special, and consequential damages.
    • • Service may be discontinued or altered without prior notice; no guarantee of perpetual availability.
    • • Searches and usage patterns are logged (albeit anonymized after 12 weeks) — consider this for sensitive research topics.

    COUNSEL Crosswalk

    Confidentiality — N/A for public-record research; search logs retained 12 weeks
    Oversight — Attorney must verify all citations (disclaimed reliability)
    Understanding — Clear scope: public opinions only
    Notice — Terms and Privacy Policy publicly posted
    Scrutiny — Non-profit transparency; open-source ethos
    Equity — Public access to law mission
    Learning — Anonymized logs used for search enhancement only

    LegalTek Assessment: CourtListener is a public-interest research tool, not a confidential data processor. For researching public court opinions, it presents no Rule 1.6 confidentiality risk. The primary COUNSEL duty implicated is Understanding — attorneys must independently verify citations because the Terms explicitly disclaim accuracy. Recommended for general legal research and citation verification workflows; not a substitute for verified primary-source review before filing.

    Sources & Audit Trail — CourtListener1 document · click to expand
    DocumentExact URLPublisher dateRetrieved by LegalTek
    Terms of Service & Privacy Policy (combined)monitoredhttps://www.courtlistener.com/terms/not statedAug 6, 2026
    Evaluation record
    v1.0 · —
    Last automated URL check
    no check recorded yet
    Check result
    —

    Retrieval dates record when LegalTek read the document text that this assessment relies on. Publishers may revise terms without notice; the automated checker verifies only that the URL still resolves, not that the text is unchanged. Verify the live document before relying on this assessment. Not legal advice.

    Even Realities

    Smart glasses / wearable HUD hardware · Evaluation v1.0 · Last updated —

    Link to Terms of Service ● unchecked

    Strengths

    • • Terms are publicly hosted on the vendor's support portal and clearly identify governing law, dispute resolution, and account-termination rights.
    • • Hardware-first form factor (prescription-ready smart glasses with on-lens HUD) means most day-to-day use does not require continuous cloud capture.
    • • Consumer purchase model — no automatic corporate telemetry ingestion of firm systems.
    • • Companion-app permissions are user-controllable at the OS level (Bluetooth, mic, notifications).

    Concerns for Legal Use

    • • Terms are consumer-focused: broad "AS IS / AS AVAILABLE" warranty disclaimer and limitation of liability. No enterprise DPA or BAA is publicly offered.
    • • No public no-training commitment covering audio, imagery, or conversational data captured via the glasses or companion app.
    • • Wearable capture in privileged settings triggers Rule 1.6 confidentiality duties and, in all-party-consent jurisdictions (CA, FL, IL, PA, WA), affirmative disclosure to every participant.
    • • Most federal and state courthouses prohibit recording devices in courtrooms and secure areas — the glasses can qualify as a recording device even when passive.
    • • Third-party AI services integrated through the companion app may be governed by separate terms outside Even Realities' control.

    COUNSEL Crosswalk

    Confidentiality — No enterprise DPA/BAA; consumer terms only
    Oversight — User-mediated; no admin controls surface
    Understanding — ToS publicly hosted and readable
    Notice — All-party consent obligations shift entirely to user
    Scrutiny — No public security certifications enumerated
    Equity — Not addressed in ToS
    Learning — No public no-training commitment on captured data

    LegalTek Assessment: Acceptable as a personal HUD for non-privileged reading, navigation, and translation. Not recommended for wear during client meetings, depositions, mediations, or courtroom appearances without (1) a negotiated enterprise agreement addressing training and retention, (2) firm-level device and consent policies, and (3) affirmative all-party disclosure in every applicable jurisdiction. Not currently eligible for the LegalTek Trust Mark™ for privileged workflows.

    Sources & Audit Trail — Even Realities1 document · click to expand
    DocumentExact URLPublisher dateRetrieved by LegalTek
    Terms of Service (support article)monitoredhttps://support.evenrealities.com/hc/en-us/articles/14290554040335-Terms-of-Servicenot statedAug 6, 2026
    Evaluation record
    v1.0 · —
    Last automated URL check
    no check recorded yet
    Check result
    —

    Retrieval dates record when LegalTek read the document text that this assessment relies on. Publishers may revise terms without notice; the automated checker verifies only that the URL still resolves, not that the text is unchanged. Verify the live document before relying on this assessment. Not legal advice.

    Honcho

    AI memory & personalization API (Plastic Labs) · Evaluation v1.0 · Last updated —

    Link to Terms of Service ● unchecked

    Strengths

    • • Unusually transparent privacy documentation: named subprocessor table (Supabase, Fly.io, Stripe, Vercel, Sentry, PostHog, AWS) including optional inference providers (Anthropic, Groq, Google Cloud).
    • • Explicit opt-in-only training posture: public model training on customer content does not occur without affirmative opt-in.
    • • Stated encryption controls: TLS 1.2+ in transit and AES-256 at rest.
    • • Published retention schedule with configurable content retention (90-day default), immediate hard-delete purge endpoint, and 90-day backup expiry.
    • • Open-source (AGPL-3.0) build available for self-hosting, which keeps memory data inside firm-controlled infrastructure.

    Concerns for Legal Use

    • • Vendor states plainly that the hosted service is not certified under SOC 2, HIPAA, or comparable frameworks — a material gap for firms with client security addenda.
    • • Non-public fine-tuning on de-identified data is contemplated; de-identification of legal matter context is difficult to assure.
    • • The product's purpose is to persist user context over time, so privileged facts accumulate by design rather than incidentally.
    • • Hosting is primarily US-based; data-residency commitments for cross-border matters are not enumerated.
    • • No formal DPA offering is stated in the public Terms; must be confirmed in writing.

    COUNSEL Crosswalk

    Confidentiality — Encryption + purge endpoint, but no SOC 2/HIPAA
    Oversight — Developer-controlled; no legal-specific review gate
    Understanding — Detailed, readable ToS and Privacy Policy
    Notification — Subprocessors and retention published in-document
    Scrutiny — No third-party audit or certification
    Equity — Not addressed in ToS
    Learning — Opt-in only for public model training

    LegalTek Assessment: Best-in-class disclosure hygiene for an early-stage infrastructure vendor, but the absence of any independent certification keeps the hosted tier outside Trust Mark eligibility for privileged data. Firms building matter-aware assistants should prefer the self-hosted AGPL build inside firm infrastructure, or restrict the hosted API to non-privileged, non-client context.

    Sources & Audit Trail — Honcho2 documents · click to expand
    DocumentExact URLPublisher dateRetrieved by LegalTek
    Terms of Servicemonitoredhttps://app.honcho.dev/tosnot statedAug 6, 2026
    Privacy Policyhttps://app.honcho.dev/privacynot statedAug 6, 2026
    Evaluation record
    v1.0 · —
    Last automated URL check
    no check recorded yet
    Check result
    —

    Retrieval dates record when LegalTek read the document text that this assessment relies on. Publishers may revise terms without notice; the automated checker verifies only that the URL still resolves, not that the text is unchanged. Verify the live document before relying on this assessment. Not legal advice.

    Buzz (Block, Inc.)

    Nostr-based human + AI-agent workspace, developer preview · Evaluation v1.0 · Last updated —

    Link to Terms of Service ● unchecked

    Strengths

    • • Bring-your-own-model architecture: Block states plainly that it does not provide, resell, or host any AI model, so no Block-side inference layer touches matter content by default.
    • • The content license granted to Block is limited to operating, securing, moderating, and improving the Service — there is no separate grant to train foundation models on customer content.
    • • The license terminates when content is deleted, subject only to legally required preservation, limited-duration backups, and copies others already made.
    • • Customer retains ownership of all content; the Terms expressly disclaim any transfer of ownership.
    • • The Buzz client is open source and self-hostable, and the Terms confirm self-hosted instances fall outside the Block-operated Service entirely — a viable firm-infrastructure deployment path.
    • • The agent provisions are unusually explicit about human accountability: no deceptive presentation of agents as humans, and express allocation of oversight duty to the operator.

    Concerns for Legal Use

    • • Developer preview. Features are offered on a preview, beta, or experimental basis, provided "as is," and may be changed or removed — a poor fit for matter-critical systems.
    • • Relay architecture is the central Rule 1.6 issue: content published to a Buzz Relay is stored, indexed, and distributed under the Nostr protocol, and the Service may connect to third-party relays Block neither controls nor includes in the Service.
    • • Agent-to-model egress is uncontrolled by the vendor: when an agent runs, content it can access — including other users' messages in any channel that agent can reach — may be transmitted to the model provider the customer chose, under that provider's terms, not Block's.
    • • No key recovery. Identity is a cryptographic keypair; Block states it generally cannot restore a lost or compromised key, so key loss can mean permanent loss of matter records.
    • • Anyone holding a private key can act as the holder — an authentication model that demands firm-managed key custody policy before any client data enters a workspace.
    • • Admins bear the compliance burden: access control, permissions, monitoring, and enforcement inside a workspace are contractually the Admin's responsibility.
    • • Mandatory individual arbitration and a class-action waiver (opt-out available), plus broad warranty disclaimers and liability limits.
    • • Feedback assignment is total — all feedback becomes Block's exclusive property, including any IP rights in it.
    • • No SOC 2, ISO 27001, HIPAA, or BAA availability appears in the public Terms, and no DPA is referenced for the hosted tier.

    COUNSEL Crosswalk

    Confidentiality — Relay distribution and agent egress both exceed a single trust boundary
    Oversight — Operator oversight duty stated expressly; no built-in approval gate
    Understanding — Detailed, well-sectioned Terms with defined agent vocabulary
    Notification — Third-party relays and subprocessors not enumerated
    Scrutiny — No certifications; preview-stage service
    Equity — Not addressed in ToS
    Learning — No model-training grant to Block; training risk shifts to the model you connect

    LegalTek Assessment: Architecturally interesting and, on the training question, better drafted than most agent platforms — Block takes no training license and hosts no model. The disqualifier for privileged data is structural, not editorial: a protocol-based relay that indexes and distributes events, an explicit possibility of third-party relays outside the Service, and agent-to-model egress that can carry other users' channel content to whichever provider the customer connected. Under Rule 1.6 and Rule 5.3, that is three trust boundaries the firm must govern and only one the vendor controls. Not eligible for the LegalTek Trust Mark™ for client-confidential work in the hosted developer preview. Firms interested in the model should evaluate the self-hostable open-source client inside firm infrastructure, with a written key-custody policy, a channel-scoping policy limiting what any agent can read, and a connected-model provider that itself carries a no-training commitment.

    Sources & Audit Trail — Buzz (Block, Inc.)2 documents · click to expand
    DocumentExact URLPublisher dateRetrieved by LegalTek
    Terms of Servicemonitoredhttps://buzz.xyz/terms-of-serviceJul 17, 2026 (stated)Aug 6, 2026
    Privacy Policyhttps://buzz.xyz/privacy-policynot statedAug 6, 2026
    Evaluation record
    v1.0 · —
    Last automated URL check
    no check recorded yet
    Check result
    —

    Retrieval dates record when LegalTek read the document text that this assessment relies on. Publishers may revise terms without notice; the automated checker verifies only that the URL still resolves, not that the text is unchanged. Verify the live document before relying on this assessment. Not legal advice.

    Obsidian

    Local-first Markdown knowledge base (optional Sync/Publish) · Evaluation v1.0 · Last updated —

    Link to Terms of Service ● unchecked

    Strengths

    • • Local-first architecture: notes are plain Markdown files on the attorney's own device, so ordinary use involves no vendor-side processing of matter content.
    • • No first-party AI model trains on note content, because the core application does not transmit vault content to the vendor.
    • • Optional cloud add-ons only: Sync and Publish are separately purchased and separately scoped.
    • • Deletion terms for the paid tiers are specific — data removed immediately on user cancellation, or one month after a lapsed subscription.
    • • Plain-file storage supports firm records-retention and matter-closure workflows without vendor dependency.

    Concerns for Legal Use

    • • Legal documents are thin and templated — the Privacy Policy still refers to the developers' earlier product, Dynalist, rather than Obsidian.
    • • Security language is generic; no TLS version, at-rest algorithm, or contractual end-to-end-encryption commitment appears in the legal text. Sync's end-to-end encryption is documented in help and marketing pages, not in the Terms.
    • • Subprocessors are not named; the policy relies on a general assurance that third parties are bound by appropriate agreements.
    • • The real AI exposure is the community plugin ecosystem: third-party AI plugins can transmit vault content to outside model providers under their terms, entirely outside Obsidian's control.
    • • No DPA, BAA, or security certification is offered in public documentation.

    COUNSEL Crosswalk

    Confidentiality — Strong by architecture (local files); weak by contract
    Oversight — Attorney-authored notes; no automation by default
    Understanding — Templated legal documents referencing a prior product
    Notification — Subprocessors not named
    Scrutiny — No certifications; E2EE claim outside the ToS
    Equity — Not addressed in ToS
    Learning — No first-party training pipeline

    LegalTek Assessment: Recommended for attorney work-product capture in a local-only configuration on an encrypted, firm-managed device. Sync and Publish, and any AI plugin, should be treated as separate vendor decisions requiring their own review — Publish in particular renders notes publicly, an obvious Rule 1.6 hazard if a matter vault is misconfigured. Firms should maintain an approved-plugin allowlist before permitting AI extensions on matter vaults.

    Sources & Audit Trail — Obsidian2 documents · click to expand
    DocumentExact URLPublisher dateRetrieved by LegalTek
    Terms of Servicemonitoredhttps://obsidian.md/termsnot statedAug 6, 2026
    Privacy Policyhttps://obsidian.md/privacynot statedAug 6, 2026
    Evaluation record
    v1.0 · —
    Last automated URL check
    no check recorded yet
    Check result
    —

    Retrieval dates record when LegalTek read the document text that this assessment relies on. Publishers may revise terms without notice; the automated checker verifies only that the URL still resolves, not that the text is unchanged. Verify the live document before relying on this assessment. Not legal advice.

    Agent OS

    Open-source spec framework for coding agents (Builder Methods) · Evaluation v1.0 · Last updated —

    Link to License (no ToS published) ● unchecked

    Strengths

    • • Not a hosted service: Agent OS is a set of Markdown standards and spec files installed into the user's own repository, so there is no vendor-side collection, retention, or training pipeline.
    • • MIT-licensed open source, permitting firm-internal modification and audit of every instruction file.
    • • Runs entirely inside the developer's environment and chosen coding agent.
    • • Its purpose — forcing explicit specifications and standards before an agent acts — is structurally aligned with COUNSEL Oversight and documented-process discipline.

    Concerns for Legal Use

    • • No Terms of Service and no Privacy Policy are published; the only governing instrument located is the MIT license on the public repository. Firms requiring a vendor contract have nothing to countersign.
    • • MIT terms disclaim all warranties and all liability — the entire risk of agent behavior sits with the firm.
    • • The real data exposure belongs to the underlying coding agent (for example Claude Code or Cursor), which transmits repository context under its own terms; Agent OS neither constrains nor discloses that flow.
    • • Open-source instruction files are mutable supply-chain inputs — updates should be pinned and reviewed rather than pulled blindly.
    • • Nothing in the framework enforces confidentiality; placing client data in a repo governed by Agent OS specs does not protect it.

    COUNSEL Crosswalk

    Confidentiality — No vendor data flow; risk sits with the coding agent
    Oversight — Spec-first workflow encourages human review gates
    Understanding — All instruction files are readable plain text
    Notification — No privacy policy or disclosure document exists
    Scrutiny — Source is auditable; no third-party assessment
    Equity — Not addressed
    Learning — No training pipeline (not a service)

    LegalTek Assessment: Evaluated as a development methodology rather than a data processor. Safe to adopt for firm-side engineering because it introduces no new vendor data flow, but it confers no confidentiality protection and carries no vendor accountability. Trust Mark review should be directed at the underlying coding agent and at the firm's repository controls, not at Agent OS itself.

    Sources & Audit Trail — Agent OS2 documents · click to expand
    DocumentExact URLPublisher dateRetrieved by LegalTek
    MIT License (governing terms)monitoredhttps://github.com/buildermethods/agent-os/blob/main/LICENSEnot statedAug 6, 2026
    Project repository & documentationhttps://github.com/buildermethods/agent-osnot statedAug 6, 2026
    Evaluation record
    v1.0 · —
    Last automated URL check
    no check recorded yet
    Check result
    —

    Retrieval dates record when LegalTek read the document text that this assessment relies on. Publishers may revise terms without notice; the automated checker verifies only that the URL still resolves, not that the text is unchanged. Verify the live document before relying on this assessment. Not legal advice.

    Side-by-Side Summary

    CriterionGranolaWispr FlowMidpageCourtListenerEven RealitiesHonchoBuzz (Block)ObsidianAgent OS
    User owns OutputNot explicit in public termsYes — assigned to userNot explicit in public termsN/A (public data)Not addressed (consumer hardware)Customer content licensed to vendor for service deliveryYes — ownership expressly retainedYes — files stay on deviceYes — MIT license, user's repo
    No training on customer dataEnterprise-tier onlyUser-toggle + third-party barredExplicit no-training commitmentN/A (no AI training pipeline)Not publicly committedOpt-in only for public modelsNo training license to BlockN/A (no first-party AI)N/A (not a service)
    Public security certificationsNot publicly enumeratedSOC 2 Type II · ISO 27001 · HIPAASOC 2 Type IINon-profit / 501(c)(3)Not publicly enumeratedNone — vendor states not SOC 2 / HIPAANone found; developer previewNone foundN/A (open-source framework)
    Local/on-device privacy modeCloud-processedPrivacy Mode availablePlugin mode stores nothingN/A (web search)On-device HUD; cloud services via companion appSelf-hostable (AGPL-3.0)Self-hostable open-source clientLocal-first by defaultFully local files
    Human-review requirement for legal AI useNot addressedContractually requiredAttorney-directed by designRequired (disclaimed reliability)Required (broad AS-IS disclaimer)Not addressed (developer API)Operator oversight duty stated in TermsAttorney-authored notesSpec-first review encouraged
    Preliminary Trust Mark eligibilityNot recommended for privileged workflows without enterprise DPAProvisionally LegalTek Verified™ with Privacy ModePromising candidate once DPA confirmedRecommended for public-record researchNot recommended for privileged useSelf-hosted only for privileged contextNot eligible in hosted preview; self-host for privileged contextRecommended in local-only configurationOut of scope — review the underlying coding agent

    AI Strategy and Governance for Modern Law Firms

    Founded by Matthew A. Mishak, Esq. — Harvard Business School Executive Education Graduate, MIT Sloan Artificial Intelligence Graduate.

    Mission

    LegalTek.ai proves you don't have to choose between speed and care, scale and quality, efficiency and ethics. Dedicated to closing the justice gap through ethical AI adoption.

    The COUNSEL Framework for Ethical AI in Law

    Mapped to and operationalizing ABA Formal Opinion 512 (the ABA does not endorse vendor frameworks). COUNSEL stands for: Confidentiality, Oversight, Understanding, Notification, Scrutiny, Equity, and Lifetime Learning.

    SilverTung AI Concierge

    A managed AI service for legal professionals with human oversight, ethical guardrails, and COUNSEL Framework compliance.

    Core Values

    Contact

    Website: https://legaltek.ai | Twitter: @legaltek_ai