Legal
Acceptable Use Policy
How the service may and may not be used, and what happens if that is breached.
DRAFT for review by a California attorney — not published.
Relationship to the master Agreement.
SAAS-AGREEMENT-DRAFT.mdclause 2.3
already states acceptable use in outline. This policy expands it; it does not
replace it, and where the two differ the Agreement prevails.The suspension discipline is the master’s, and it must survive. Clause 6.6(c)
commits that read and export access to Regulated Records continues even during
suspension for non-payment — “a fee dispute is not a reason to put a law
practice out of reach of its trust records”. In California that reasoning is
sharpened by the five-year trust-record retention duty and by the State Bar’s
expectation that a firm can produce those records on demand.⚠ The California instance is deployed and healthy, but registration is closed. This is an instrument for launch.
Version: [[ x.y ]] · Effective: [[ date ]]
1. What this policy is for
This policy sets out how the Service may and may not be used, to keep it secure,
available and lawful for every firm that relies on it. It applies to the Customer
and to everyone the Customer authorizes to use the Service.
2. You are responsible for your users
The Customer is responsible for its Users’ compliance, for keeping credentials
secure, for supervising its staff, and for telling us promptly if it believes an
account has been compromised or misused.
3. Prohibited use — security
You must not:
- attempt to gain unauthorized access to the Service, to another customer’s data, or
to any system or network connected to the Service; - attempt to circumvent, disable or test any authentication, authorization,
isolation or rate-limiting measure; - conduct penetration testing, vulnerability scanning or load testing without our
prior written permission — we will consider reasonable requests, and we would
rather work with you than find out afterward; - introduce malicious code, or upload material designed to damage or disrupt any
system; - reverse engineer, decompile or attempt to extract the source code of the Service,
except to the extent applicable law expressly permits despite this restriction; - use the Service to attack, probe or send unsolicited bulk messages to anyone;
- exceed documented API rate limits.
If you find a security vulnerability, please tell us at
[[ security contact ]]. We will not pursue a researcher who reports a genuine
issue in good faith, does not access or exfiltrate other customers’ data, and gives
us a reasonable opportunity to fix it before disclosing it.
4. Prohibited use — legal and professional
You must not use the Service:
- for any unlawful purpose, or to store or transmit unlawful material;
- to infringe anyone’s intellectual property rights;
- to store or transmit material you have no right to hold;
- to harass, threaten or defame any person;
- in a way that breaches your obligations under the California Rules of
Professional Conduct, or any duty you owe to your client or to the State Bar of
California; - in a way that breaches applicable privacy law.
A note on the AI assistant. If you enable it, everything it produces is a
draft for practitioner review, and it cannot move money or issue a bill — there is
no such tool and no such code path. You remain responsible for reviewing its
output before relying on it or sending it to a client. If you use your own AI
provider key, the content travels under your agreement with that provider.
5. Prohibited use — access and resources
You must not:
- share credentials, or allow anyone outside the Customer to use the Service, except
as the Order permits; - resell, sublicense or provide the Service as a service to third parties without our
written agreement; - use automated means to extract data at a scale or rate that degrades the Service
for others — the export function exists for this; please use it; - deliberately consume resources in a way designed to disrupt the Service.
A note on volume. We do not impose hidden usage traps. If your legitimate use
grows beyond what the Order contemplates, we will talk to you about it — we will not
suspend you for succeeding.
6. Things this policy deliberately does not prohibit
For the avoidance of doubt, none of the following breaches this policy:
- storing privileged, confidential or sensitive information, including
information about alleged criminal conduct — the Service is built for exactly
this; - client trust account records of any volume, retained for as long as your
professional obligations require; - exporting your own data at any time, including in bulk;
- criticizing the Service publicly, or discussing it with the State Bar of
California, your auditor, your malpractice carrier, or in a CTAPP submission; - using the Service for any area of law that is lawful.
Internal: this clause is deliberate. For a product holding privileged files and
client trust records, a firm must know that ordinary professional use cannot
trigger enforcement — and that a communication to its regulator certainly
cannot.
7. What happens if this policy is breached
Our response will be proportionate.
- Normally we will contact you first, explain the problem, and give you a
reasonable opportunity to correct it. - If the breach continues, or is serious, we may suspend the affected access,
telling you what we are doing and why. - We may suspend without prior notice only where there is a genuine and immediate
risk — for example an active security compromise, or where the law requires it.
We will tell you as soon as we can afterward and explain why. - We will restore access promptly once the cause is resolved.
- Termination for material breach is governed by clause 11.2 of the Agreement.
Suspension never cuts you off from your trust records. Whatever the reason, we
will continue to provide read access to, and export of, your client trust account
records and client files, consistently with clause 6.6(c) of the Agreement.
A dispute with us is not a reason to leave a firm unable to answer the State
Bar, and a regulatory demand does not pause because an invoice is outstanding.
We will not suspend an entire firm’s access over a single user’s isolated
breach where a narrower measure will address it.
8. Reporting
To report misuse, a security issue, or a concern about another user’s conduct,
contact us at [[ contact ]].
9. Changes
We may update this policy. Where a change materially increases your obligations we
will give at least [[ N ]] days' notice.
Open items
| ref | item |
|---|---|
G-EWDOC2 |
Security and abuse contact addresses — must be real and monitored |
| — | Notice period in clause 9 |
| — | Reverse-engineering carve-out to be confirmed against US copyright law [[ not read ]] |
| — | California instance deployed; registration closed |