Compliance

SOC 2 Type 2
HIPAA
CCPA
Monitoring
Resources
If you would like to report a vulnerability, please contact [email protected] with a proof of concept, list of tools used, and the output of the tools. Once received, EvenUp will work quickly to reproduce each vulnerability to verify its status before taking the steps needed to address it.
SOC 2 Type 2
HIPAA
CCPA
Vulnerability Disclosure
To report a vulnerability, contact [email protected] with a proof of concept, list of tools used, and the output of the tools. Once received, EvenUp will work quickly to reproduce each vulnerability to verify its status before taking the steps needed to address it.
Exclusions
When reporting vulnerabilities, please consider (i) attack scenario / exploitability, and (ii) security impact of the bug. The following issues are considered out of scope:
- Clickjacking on pages with no sensitive actions
- Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions
- Attacks requiring MITM or physical access to a user's device
- Previously known vulnerable libraries without a working Proof of Concept
- Comma Separated Values (CSV) injection without demonstrating a vulnerability
- Missing best practices in SSL/TLS configuration
- Any activity that could lead to the disruption of our service (DoS)
- Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS
- Attempting to compromise our endpoints by brute forcing
- Missing best practices in Content Security Policy
- Missing HttpOnly or Secure flags on cookies
- Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)
- Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 versions behind latest]
- Software version disclosure / Banner identification issues / Descriptive error messages or headers
- Public Zero-day vulnerabilities that have had an official patch for less than 1 month
- Tabnabbing
- Open redirect - unless an additional security impact can be demonstrated
- Issues that require unlikely user interaction
AI & LEGAL ETHICS
AI and Legal Ethics FAQs
EvenUp’s AI tools are designed to help personal injury firms work more efficiently while keeping trust, confidentiality, and attorney oversight at the center of legal work. These FAQs address common questions about responsible AI use in legal workflows, including client communication, confidentiality, data protection, attorney supervision, AI-assisted outputs, and billing.
This information is provided for general informational purposes only and does not constitute legal advice. Firms remain responsible for determining how to use EvenUp consistent with applicable laws, court rules, professional obligations, engagement terms, and client instructions.
Do I need to tell my clients that my firm uses EvenUp’s AI tools?
Do EvenUp’s AI tools impact client confidentiality or privilege?
Critically, EvenUp is not an open, public AI chatbot. It is an enterprise legal technology platform designed for law firm workflows and for supervision by lawyers. EvenUp maintains security controls, restricts access to customer data, and does not allow third-party AI providers to use customer case files to train models for other customers. We configure these services to minimize data retention and, where available, use zero-retention settings.
Whether privilege or work-product protection applies depends on traditional factors, such as whether the tool was used by or at the direction of counsel, whether the material was created for legal advice or in anticipation of litigation, and whether confidentiality was maintained. EvenUp does not decide or control privilege outcomes for a firm. Each firm and its counsel remain responsible for evaluating privilege, work-product protection, and any discovery requests under applicable rules.
What safeguards should my firm consider when using technology providers generally?
Customers should consider safeguards across four layers:
- Legal and contractual controls: appropriate confidentiality, data processing, security, and, where applicable, Business Associate Agreement commitments.
- Technical controls: strong authentication, role-based access, least-privilege permissions, encryption, logging and monitoring, vulnerability management, and secure account administration.
- Workflow controls: attorney supervision, review of AI-assisted outputs, verification against case records, correction before approval, and clear escalation paths for unexpected or sensitive issues.
- Governance controls: internal AI-use policies, staff training, periodic risk review, audit-log review where available, and clear client or court communication practices where required or appropriate.
What other responsibilities does my firm have when using technology providers like EvenUp?
Those responsibilities include supervising attorneys and staff; overseeing AI-assisted outputs and actions, including reviewing outputs before use where appropriate; complying with court and bar rules; configuring workflows appropriately; maintaining internal policies and training; and securing your firm’s own user accounts, devices, and systems.
AI Agents: Responsible Use and Safeguards
EvenUp uses AI agents to assist law firms with supported legal workflows. Depending on the feature and workflow, agents may process information, use enabled tools, communicate with third parties, or perform other supported actions. EvenUp agents are designed to operate within the capabilities, permissions, and workflows made available to them.
Can EvenUp AI Agents independently add new tools or integrations?
Can an AI Agent act outside the workflows or permissions available to it?
The form of customer direction or authorization may vary by feature. Depending on the workflow, it may occur at the individual-action level or through configuration, enrollment, or other customer-authorized settings.
How does EvenUp monitor AI Agent activity?
Potential security incidents or anomalous activity involving an agent are handled through EvenUp’s applicable security and incident-response processes.
How is customer information protected when AI Agents are used?
Communication Agents
What are Communication Agents?
Can a law firm use EvenUp’s Communication Agents to communicate with clients or other third parties?
EvenUp has built safeguards into the Communication Agent to support compliant use. For example, at the beginning of a voice call, the called party is informed that the call will be recorded and transcribed. If the called party indicates that they do not consent to recording or transcription, the Communication Agent does not continue the conversation and politely ends the call. With respect to client confidentiality and privilege, the Communication Agent operates on behalf of and at the direction of the law firm. The use of the Communication Agent should not itself change the ordinary confidentiality or privilege analysis that would apply if the same activity were performed by an authorized individual acting on the firm’s behalf using any other communication technology.
Do Communication Agents decide on their own who to call?
Billing Back Case Costs
Personal injury firms often use technology and third-party services to support case administration, document preparation, records workflows, communications, and claims processes. Whether and how those costs may be billed to, deducted from, or recovered from clients or case proceeds can raise complex questions under fee agreements, client disclosures, court rules, settlement practices, and professional responsibility obligations.
The information below is intended to provide a starting point for understanding complex questions about billing expenses back to clients. Standards vary by jurisdiction, and this information is not intended to be comprehensive or to serve as legal advice. Please consult an attorney licensed in your jurisdiction.
Can a law firm pass EvenUp costs along to a client?
What is the difference between a case cost and general overhead?
How should a firm determine the amount charged to a client?
How does EvenUp help firms document matter-specific costs?
Should a firm disclose these costs in its client agreement?
Where can I learn more?
Requirements vary by jurisdiction, so firms should review both applicable state-level ethics guidance and any local court rules, standing orders, or judge-specific requirements. Many jurisdictions draw from the ABA’s guidance on lawyers’ use of generative AI. The following resources provide a useful starting point: