top of page
Banner AI workspace setup for law firms.png

AI Setup and Compliance for Law Firms and Legal Organizations

Commercial workspace setup, carefully configured privacy and account controls, staff training, and a dated record of settings, testing, training, and access closeout, for firms and legal organizations alike. ChatGPT, Claude, Gemini, and Copilot, configured the way an attorney needs them, not the way the free tier ships them.

THE PROBLEM

Your Firm Is Already Using AI.

The Question Is Whether It's Set Up to Protect Your Clients.

Somewhere in your office, someone has already pasted a police report into a free chatbot. Maybe a client at 1:17 a.m. Maybe a well-meaning paralegal. Maybe the browser extension that promised to “supercharge” something and quietly reads everything on the screen.

Consumer AI accounts train on what you type, keep what you upload, and offer none of the contractual protections your confidentiality duties assume. The business versions of the same tools are a different product: no training on your data, commercial terms, admin controls, and settings that can be configured, restricted, and documented. Most firms are paying for the wrong one, or the right one configured wrong.

I set up the correct commercial workspace, configure and verify the applicable privacy and account controls, train your people, deliver attorney-review client AI templates, and put your firm on an audit schedule so the settings stay set. You keep practicing law, and every legal judgment call stays yours.

Attorney-directed support from a confidential independent contractor under a signed services agreement and confidentiality undertaking. VdVLaw is not a law firm and provides no legal advice. Setup and testing use harmless sample data unless the responsible attorney separately authorizes matter data.

staff already using AI.png

WHY THIS DOESN'T WAIT

The Risk Doesn't Stay Flat. It Compounds.

Vendor terms change without notice. Default settings, admin controls, and free-tier terms are revised on the vendor's schedule, not yours. A configuration reviewed once and never revisited is a configuration going stale.

Your legal secretaries and paralegals are probably already using it, and so, most likely, are you. These tools are good at being helpful, and being helpful is the whole design. A good AI tool doesn't interrupt a draft to ask whether what you just typed was supposed to stay private, it just helps. Banning AI outright isn't realistic, and a policy that assumes nobody's using it, staff or attorney, is worse than no policy at all. The goal isn't zero AI use. It's knowing where it's happening and controlling what it touches.

Guidance keeps developing. ABA Formal Opinion 512 and California's guidance on generative AI continue to evolve. Firms with a documented, attorney-directed configuration have more to point to if a question comes up later than firms that never wrote anything down.

Some malpractice carriers are starting to ask. AI-use questions are beginning to appear on professional liability renewal applications. A dated configuration record and training log is something to hand over, not something to reconstruct from memory under a deadline.

Courts are learning to ask how AI-assisted material was made. VdVLaw's own CLE class, The Source Behind the Summary, covers how courts and opposing counsel are starting to question the origin of AI-generated and AI-assisted material. A firm that already documents its own AI workflow is answering from a record, not a memory.

Fixing it later costs more than setting it up now. Reviewing chat histories, memory settings, and connector permissions across a staff after something has already gone wrong takes more time, at higher stakes, than configuring it correctly at the start.

None of this requires guessing. It requires a documented, attorney-directed setup, reviewed on a schedule. That's what this engagement delivers.

WHAT I CONFIGURE AT A GLANCE

What I Configure at a Glance

Subscription & Workspace Review

I review the commercial plan and live checkout before purchase, confirm the right business tier for your firm's size, and set up administrator roles across ChatGPT, Claude, Gemini, or Microsoft Copilot.

01_subscription_review.png
02_privacy_account_controls.png

Privacy & Account Controls

Privacy, memory, retention, sharing, and connector settings are configured, restricted, tested, and documented to the extent the selected plan supports, on every device your firm actually uses.

03_attorney_templates_training.png

Attorney Templates & Staff Training

Client and staff handouts, attorney-review intake and authorization templates informed by ABA Formal Opinion 512 and California guidance, and a staff training session with signed acknowledgments.

04_closeout_recurring_audits.png

Closeout & Recurring Audits

Temporary access revoked, a completion certificate and configuration record delivered for your file, and your firm placed on a recurring audit schedule so the settings stay the way we left them.

WHAT I CONFIGURE

What I Configure, Platform by Platform

Commercial Accounts Only. No Exceptions.

If a platform doesn't offer a business tier with a no-training commitment and commercial terms, it doesn't touch client work. That rule is the foundation of everything else.

BUSINESS / ENTERPRISE

Business workspace, training and memory controls, connector lockdown, the file Library nobody remembers to clean out, and Temporary Chat done right.

ChatGPT (OpenAI)

TEAM / ENTERPRISE

Team workspace with matter-based Projects, connector restrictions, and per-matter deletion workflow for discovery work.

Claude (Anthropic)

GOOGLE WORKSPACE

Admin-console configuration: history, retention, temporary chats, sharing off, Workspace-app access controlled, and the Vault question answered in writing.

Google Gemini

MICROSOFT 365

Work-account Copilot with Enterprise Data Protection verified on every surface: web, Office, Edge, Windows, and the phone in your pocket.

Microsoft Copilot

PROHIBITED

VdVLaw does not configure DeepSeek's hosted services for client work. Its current privacy terms state that personal data is processed and stored in the People's Republic of China. I provide the written policy, staff briefing, and cleanup if it's already been used.

DeepSeek

WHAT YOU GET

A Configured System, Not a Settings Tour

● Commercial workspace configured and verified, with dated before-and-after

       screenshots documenting the reviewed settings.

● Client and staff handouts for each platform: plain-language rules your people will

      actually follow.

● Client AI templates for attorney review: intake, disclosure, acknowledgment, and

      matter-authorization templates informed by ABA Formal Opinion 512 and California

      guidance.

● Raw-discovery workflow: matter authorization, upload logging, and end-of-matter

      deletion sweeps.

● Office AI policy language and staff training with signed acknowledgments.

● Cleanup of prior consumer-account use, handled quietly and documented properly.

● Completion certificate and configuration record for your file: a dated record of settings,

       testing, training, and access closeout.

● Monthly AI Compliance Monitoring, because vendors change defaults and staff click

      “Allow."

documentation and audits.png

DISCOVERY AND CLIENT DATA

Matter Data Gets a Workflow, Not a Free Pass

A commercial workspace makes it possible to work with matter data responsibly. It doesn't decide that you should. Whether a specific document, transcript, or discovery file may go into an AI platform is the responsible attorney's call, made matter by matter.

 

Once that call is made, the workflow I configure handles the mechanics: which users are authorized, what gets logged, and when material is swept out of the workspace at the end of a matter.

Because I work with more than one firm, your matter data is kept separate and apart from every other client I serve: no cross-contamination, no shared records. What comes back to you is your own organized record, and nothing else.

discovery and client data.png

ONGOING PROTECTION

AI Compliance Monitoring for Law Firms and Organizations
(Monthly Service)

AI tools are entering your firm whether you invite them or not. Browser extensions, meeting transcribers, and AI features built into search engines and office software can access privileged client information quietly, and one accidental install can create a confidentiality problem you never see coming.

The monthly AI compliance check keeps your firm's configuration current and your supervision record dated and complete.

Most people won't volunteer what they're using, staff and attorneys alike. A genuinely helpful tool doesn't pause to ask if what you just typed was supposed to stay private, so it doesn't register as something to mention. That's exactly why the network review below doesn't wait for anyone to say something. It looks.

◆ Full audit of browser extensions, Office add-ins, and newly installed software across all firm devices, checked

     against your approved tools list.

◆ Review of third-party app permissions connected to your email and cloud accounts, the most common hidden leak.

◆ Verification that OS-level AI features (Windows Recall, Microsoft Copilot, Apple Intelligence) remain configured

      to policy after updates.

◆ Network review for unapproved AI tool usage, with practical alternatives offered instead of a flat no.

   ◆ Staff attestation collection and a sanctioned request path for new tools, so nothing gets added without a review.

◆ Quarterly re-check of vendor terms on your approved AI tools.

◆ A documented findings log after every visit: a dated supervision record you can point to with clients, insurers, and

     the State Bar if a question ever comes up.

You receive an updated approved and prohibited tools list every month, plus a plain-English summary your whole team can follow. Setup includes technical defaults that make the wrong path the hard path: extensions blocked by default, admin-controlled installs, and app consent restrictions.

The audit catches the settings. The staff check-in catches the people.

Every visit includes both, not just a scan of your systems.

PRICING

Clear Setup Fees. Written Scope Before Work Begins.

Platform

Setup fee (1-3 users)

Primary scope

Microsoft 365 Copilot

$1,250

Enterprise Data Protection across every surface

ChatGPT Business

$750

Business workspace, privacy controls, admin roles, closeout

Claude Team

$800

Team workspace, connectors, per-matter deletion workflow

Google Workspace Gemini

$950

Admin console, retention, sharing, access controls

● Additional platforms in the same engagement: 15% off the second, 20% off the third and fourth.

● Full stack, all four platforms, up to 3 users: $3,000, versus $3,750 priced separately.

● Larger firms: users 4 to 10 add $75 to $125 per user depending on platform. 11 or more users receive a written quote.

● AI Compliance Monitoring (described in Section 8): $150 a month or $275 a quarter for the first platform, up to three

     users. Settings re-verified, staff check-in completed, dated findings log delivered.

● Additional platforms on Compliance Monitoring: $75 a month or $125 a quarter, same review cycle.

● Additional users over three: $15 per review. New-user setup: $150. Departing-user access closeout: $125.

● Justice Access pricing: a 25% reduction on qualifying setup, training, private CLE presentation, and audit fees for

     eligible appointed-counsel and public-interest organizations.

● Travel: no charge for remote work statewide. On-site travel is included with any standard setup in El Dorado County and

     the greater Sacramento area.

● Vendor subscriptions (ChatGPT Business, Claude Team, Google Workspace, Microsoft 365) are separate and paid by the

     firm directly.

Every engagement starts with a written quote. The complete pricing schedule is included with the quote and the signed agreement.

Introductory and referral rates available; ask.

VdVLaw also designs and teaches CLE classes for California attorneys. AI-setup clients receive 15% off a private CLE engagement booked within six months.  → 

HOW IT WORKS

Four Visits, Start to Finish.

Step 1:

       Intake & plan selection. Which platforms, which matters, who administers, what's already leaked into personal

        accounts. You approve the commercial subscription before I touch a setting.

Step 2:

        Configuration. Applicable privacy, retention, sharing, connector, and account controls configured, restricted, tested,

        and documented to the extent supported by the selected plan, on every device your firm actually uses. Synthetic test

        data only.

Step 3:

         Verification & training. I test the configuration, document it with dated evidence, walk the attorney through their

         handout, and train the staff on theirs.

Step 4:

          Handoff & audits. Temporary access revoked, completion certificate signed, first audit scheduled. The settings stay

          set because someone is checking.

Not used for model training” is not the same thing as privileged, confidential, protected by a court order, or safe to upload.

THE CORE RULE OF THE VDVLAW AI SAFETY TOOLKIT

Frequently Asked Questions

Do I have to buy a new AI subscription?

Yes. Free and personal accounts lack the contractual no-training commitments and administrator controls that the business versions carry. You buy the subscription directly from the vendor; I configure it.

Can my firm use real client names and discovery in AI?

Potentially, but a commercial workspace is only one prerequisite. The responsible attorney must approve the specific matter, platform, purpose, users, data categories, and retention or deletion plan, and must also determine whether client communication or informed consent, a protective-order review, court permission, a BAA, contractual approval, or another safeguard is required. VdVLaw configures and documents the technical workflow but does not make those legal determinations

What about DeepSeek?

VdVLaw does not configure DeepSeek's hosted website, application, or hosted API for client work. Its current privacy terms state that personal data is processed and stored in the People's Republic of China. A separately vetted U.S.-hosted or local open-weight deployment would require a separate engagement and security review. Existing use can be reviewed, documented, and cleaned up.

Do you see my client files?

Setup and testing use harmless sample data. I touch matter data only if the responsible attorney separately authorizes it in writing, under a signed confidentiality undertaking.

Why the ongoing audits?

Vendors change defaults, new features arrive pre-enabled, staff click Allow, and browser extensions and AI features get installed without anyone flagging it. A monthly or quarterly re-check keeps the configuration the way we left it, with a dated record.

Is this legal advice?

No. VdVLaw is not a law firm. The responsible attorney makes every legal and ethics decision; I do the technical configuration and documentation under their direction.

What actually happens during a monthly compliance visit?

Two things, every time. A technical check of browser extensions, app permissions, and OS-level AI features across your firm's devices, and a direct check-in with your staff, since a perfectly configured system can still be undone by one person adding a tool nobody reviewed. You get a dated findings log and an updated approved-tools list after each visit.

GET STARTED

Your Clients Are Already Using AI. Get Ahead of It.

Serving attorneys, firms, and legal organizations statewide with a focus on Sacramento, El Dorado, Placer, Amador, and San Joaquin counties. Remote and on-site setup available.

VdVLaw is an attorney-directed legal support and technology-configuration service operated by Robert van der Vijver. VdVLaw is not a law firm, Robert van der Vijver is not an attorney, and neither provides legal advice. Services are performed for attorneys, law firms, legal departments, public agencies, and organizations under the direction of the responsible attorney. The responsible attorney retains all legal and professional-responsibility decisions, including client communication, informed consent, privilege, protective orders, regulated information, and whether particular information may be processed through an AI platform. Contacting VdVLaw does not create an attorney-client relationship. Platform names and trademarks belong to their respective owners. VdVLaw is independent and is not affiliated with, sponsored by, or endorsed by any AI vendor. Vendor plans, pricing, terms, features, and controls may change. The live vendor terms and the signed engagement documents control.

bottom of page