The Managing Partner PacketDoes AI train on our client's data?
The one question that stalls your deal at firms this size, answered so you can forward it to your managing partner today.
The symptom, as lawyers describe it
What it looks like
You raise AI at the firm, and the conversation dies at the same worry every time: that uploading a sensitive case file somewhere means it ends up training a public model.
Nobody has answered that plainly, so the default answer stays no, and you are back at the same worry the next time you raise it.
What lawyers complain about
Quotes are verbatim public posts by practitioners, reproduced without attribution to the individual.
The fix, stated directly
What changes
Customer content is not used to train Irys or any third-party foundation model, unless a firm expressly agrees to that in writing. Ask your rep for the exact Data Processing Agreement clause before you rely on this for a compliance file.
How to verify the same claim for any vendor, including Irys:
- Open the vendor's Terms of Service and DPA. Search for "training data," "model improvement," and "de-identified."
- If the document does not name a specific carve-out for your organization's content, assume it can be used.
- Ask the vendor directly, in writing: "Do you train your model or any third-party model on our data, yes or no." A vendor that will not put that in writing is your answer.
- Confirm the answer matches what is stated in their public security or trust page, not only what a sales rep says on a call.
What lawyers actually ask
Keep going
Pick the next fix
the security questionnaire, which has the SOC 2 and isolation answers this page does not cover.

See Irys on your own matter.
Tell us about your practice and we will set up a walkthrough on the work you actually do.
No credit card. Transparent pricing. 7-day free trial.