EvenUp | Trust Center
EvenUp Trust Center
Built for personal injury firms. Designed with trust at the center. The EvenUp Trust Center provides a transparent view into the security, privacy, and compliance practices that support our platform. EvenUp’s security and compliance program has been independently assessed through a SOC 2 Type 2 examination and a HIPAA compliance assessment. We support customers handling sensitive information through appropriate contractual, technical, organizational, and compliance measures. Use this portal to explore our safeguards, controls, and compliance resources, request available documentation, and learn more about how EvenUp handles and protects customer data.
Request access

Compliance

SOC 2 Type 2

HIPAA

CCPA

Monitoring

Continuously monitored by Secureframe

Resources

If you would like to report a vulnerability, please contact [email protected] with a proof of concept, list of tools used, and the output of the tools. Once received, EvenUp will work quickly to reproduce each vulnerability to verify its status before taking the steps needed to address it.

SOC 2 Type 2

HIPAA

CCPA

Vulnerability Disclosure

To report a vulnerability, contact [email protected] with a proof of concept, list of tools used, and the output of the tools. Once received, EvenUp will work quickly to reproduce each vulnerability to verify its status before taking the steps needed to address it.

Exclusions

When reporting vulnerabilities, please consider (i) attack scenario / exploitability, and (ii) security impact of the bug. The following issues are considered out of scope:

  1. Clickjacking on pages with no sensitive actions
  2. Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions
  3. Attacks requiring MITM or physical access to a user's device
  4. Previously known vulnerable libraries without a working Proof of Concept
  5. Comma Separated Values (CSV) injection without demonstrating a vulnerability
  6. Missing best practices in SSL/TLS configuration
  7. Any activity that could lead to the disruption of our service (DoS)
  8. Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS
  9. Attempting to compromise our endpoints by brute forcing
  10. Missing best practices in Content Security Policy
  11. Missing HttpOnly or Secure flags on cookies
  12. Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)
  13. Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 versions behind latest]
  14. Software version disclosure / Banner identification issues / Descriptive error messages or headers
  15. Public Zero-day vulnerabilities that have had an official patch for less than 1 month
  16. Tabnabbing
  17. Open redirect - unless an additional security impact can be demonstrated
  18. Issues that require unlikely user interaction
Read ourAI FAQsto learn more.
EvenUp home page

AI & LEGAL ETHICS

AI and Legal Ethics FAQs

EvenUp’s AI tools are designed to help personal injury firms work more efficiently while keeping trust, confidentiality, and attorney oversight at the center of legal work. These FAQs address common questions about responsible AI use in legal workflows, including client communication, confidentiality, data protection, attorney supervision, AI-assisted outputs, and billing.

This information is provided for general informational purposes only and does not constitute legal advice. Firms remain responsible for determining how to use EvenUp consistent with applicable laws, court rules, professional obligations, engagement terms, and client instructions.

Do I need to tell my clients that my firm uses EvenUp’s AI tools?
Requirements vary by jurisdiction, matter, engagement terms, client instructions, and how the technology is used. As a practical matter, firms may wish to explain in their engagement agreements, privacy notices, or other client-facing materials that they use technology vendors, including AI tools, to support legal services.

More specific requirements may apply to court filings. Some courts and judges require lawyers to disclose the use of AI-assisted tools, certify that filings were independently reviewed, or confirm that factual statements, legal authorities, and citations were verified.
Do EvenUp’s AI tools impact client confidentiality or privilege?
Law firms routinely use technology providers, including EvenUp, without any impact to client confidentiality or privilege. The relevant analysis generally depends on how the technology is used, whether the work remains attorney-supervised, and whether appropriate confidentiality, security, and data-use protections are in place.

EvenUp is an enterprise legal technology platform designed for law firm workflows, not an open, public AI chatbot. Our AI features are intended to support attorney-supervised review. EvenUp maintains security controls, restricts access to customer data, and does not allow third-party AI providers to use customer case files to train models for other customers. We configure these services to minimize data retention and, where available, use zero-retention settings.

Whether privilege or work-product protection applies generally turns on traditional factors, such as whether the tool was used by or at the direction of counsel, whether the material was created for legal advice or in anticipation of litigation, and whether confidentiality was maintained. EvenUp does not decide or control privilege outcomes for a firm. Each firm and its counsel remain responsible for evaluating privilege, work-product protection, and any discovery requests under applicable rules.
What privacy, security, and confidentiality safeguards should my firm consider when using technology providers generally?

Customers should consider safeguards across four layers:

  • Legal and contractual controls: Appropriate confidentiality, data processing, security, and, where applicable, Business Associate Agreement commitments.
  • Technical controls: Strong authentication, role-based access, least-privilege permissions, encryption, logging and monitoring, vulnerability management, and secure account administration.
  • Workflow controls: Attorney supervision, review of AI-assisted outputs, verification against case records, correction before approval, and clear escalation paths for unexpected or sensitive issues.
  • Governance controls: Internal AI-use policies, staff training, periodic risk review, audit-log review where available, and clear client or court communication practices where required or appropriate.
What other responsibilities does my firm have when using technology providers like EvenUp?
EvenUp's services are designed to assist legal teams, not replace attorney judgment or legal review. Your firm remains responsible for its professional, legal, and client-specific obligations.

Those responsibilities include supervising attorneys and staff, reviewing AI-assisted outputs before use, complying with court and bar rules, configuring workflows appropriately, maintaining internal policies and training, and securing your firm's own user accounts, devices, and systems.

Billing Back Case Costs

Personal injury firms often use technology and third-party services to support case administration, document preparation, records workflows, communications, and claims processes. Whether and how those costs may be billed to, deducted from, or recovered from clients or case proceeds can raise complex questions under fee agreements, client disclosures, court rules, settlement practices, and professional responsibility obligations.

The information below is intended to provide a starting point for understanding complex questions about billing expenses back to clients. Different jurisdictions have different standards, and this is not intended to be comprehensive or to serve as legal advice. Please consult an attorney licensed in your jurisdiction.

Can a law firm pass EvenUp costs along to a client?
Law firms can typically seek reimbursement for reasonable and necessary expenses associated with a particular client matter, but not for ordinary expenses of operating a law practice. Whether a specific EvenUp cost may be passed through depends on the jurisdiction, the nature and use of the service, and the firm's agreement with its client.
What is the difference between a case cost and general overhead?
A case cost is generally an expense directly attributable to a particular client matter. General overhead ordinarily includes expenses to maintain the practice more broadly, such as office rent, utilities, or routine office software. Technology costs should be evaluated based on how the service is used, rather than how it is labeled.
How should a firm determine the amount charged to a client?
The amount must be reasonable and should not be used as an additional source of profit. A firm may charge the actual cost incurred or a reasonable amount disclosed and agreed in advance. For subscription or volume-based services used across matters, firms may be able to reasonably allocate costs across all cases used in connection with the service.
How does EvenUp help firms document matter-specific costs?
Depending on the service, EvenUp may provide documentation such as credits consumed, effective case pricing, identified matters where the service was used, itemized charges, matter-level usage, and usage-based overages.
Should the firm disclose these costs in its client agreement?
Firms should clearly communicate the basis on which clients may be responsible for fees and expenses, preferably in writing and before the charge is incurred. EvenUp cannot provide or approve language for a firm's retainer or fee agreement. ABA Model Rule 1.5 addresses the communication and reasonableness of fees and expenses.
Where can I learn more?

Requirements vary by jurisdiction, so firms should review both applicable state-level ethics guidance and any local court rules, standing orders, or judge-specific requirements. Many jurisdictions draw from the ABA’s guidance on lawyers’ use of generative AI. The following resources provide a useful starting point:

FAQs

Access is limited to authorized EvenUp personnel and service providers on a need-to-know basis, with limited access permissions, as necessary to provide and support your account and our services. EvenUp personnel and service providers are subject to contractual confidentiality and data protection requirements, such as data processing agreements and HIPAA-compliant business associate agreements.
EvenUp uses proprietary and third-party AI technologies to analyze case materials, extract and organize relevant information, and help prepare work product for your review and use.
We leverage our experience handling thousands of cases to improve our product and help our models recognize patterns in medical records and case outcomes. Our models learn statistical patterns and are designed not to store or reproduce your documents. We do not allow third-party AI providers, including OpenAI and Anthropic, to use your case files to train their models. We minimize retention and use zero-retention settings where available. Your case files stay with your matters and do not appear in another customer’s work product.
Case data is stored in U.S.-based data centers.
EvenUp maintains administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of your data and to help prevent unauthorized access. These safeguards include access controls, encryption both in transit and at rest, vulnerability management, logging and monitoring, incident response, risk assessment, network security, and vendor governance. Our security program is independently assessed through a SOC 2 Type 2 examination and HIPAA attestation. Relevant reports are available to customers and prospects upon request.
EvenUp maintains a vulnerability-management program that includes automated code, dependency, and API security scanning, code review, security testing, and independent third-party penetration testing at least annually. Potential vulnerabilities are evaluated and remediated based on their severity and risk.
EvenUp hosts case data in cloud infrastructure and generally does not use a separate, single-tenant environment for each customer. Instead, our multi-tenant architecture uses logical separation, authenticated identities, role-based access, and scoped permissions designed to ensure that users and systems can access only the data they are authorized to access. Case data is encrypted in transit and at rest, and access is logged and monitored.
EvenUp stores and processes case data and related records as needed to provide, support, secure, and operate the service. Depending on the workflow, this may include submitted materials, generated outputs, processing artifacts, metadata, operational records, and security or troubleshooting logs. When a customer submits a deletion request, EvenUp honors that request in accordance with applicable law and the customer’s agreement. Deletion may be subject to limited retention where retention is required or permitted for legal, compliance, security, audit, backup, or dispute-resolution purposes. Backup copies, where present, are retained in accordance with EvenUp’s standard backup lifecycle and may be retained for up to one year before deletion.
Unless legally prohibited, our practice is to notify the affected customer promptly so that the customer has an opportunity to review, challenge, or seek to narrow the request. Where disclosure is legally required, we seek to provide only the information we are required to disclose.
this NDA

Monitoring

Change Management

Software Change Testing
Software changes are tested prior to being deployed into production.
Baseline Configurations
Baseline configurations and codebases for production infrastructure, systems, and applications are securely managed.
Approval for System Changes
System changes are approved by at least 1 independent person prior to deployment into production.
Segregation of Environments
Development, staging, and production environments are segregated.

Availability

Testing the Business Continuity and Disaster Recovery Plan
The Business Continuity and Disaster Recovery Plan is periodically tested via tabletop exercises or equivalents. When necessary, Management makes changes to the Business Continuity and Disaster Recovery Plan based on the test results.
Uptime and Availability Monitoring
System tools monitors for uptime and availability based on predetermined criteria.
High Availability Configuration
The system is configured for high availability to support continuous availability, when applicable.
Backup Restoration Testing
Backed-up data is restored to a non-production environment at least annually to validate the integrity of backups.

Organizational Management

Advisor Meetings on Security
Senior management and/or board of directors meets at least annually to review business goals, company initiatives, resource needs, risk management activities, and other internal/external matters. The information security team meets at least annually to discuss security risks, roles & responsibilities, controls, changes, audit results and/or other matters as necessary.
New Hire Screening
Hiring managers screen new hires or internal transfers to assess their qualifications, experience, and competency to fulfill their responsibilities. New hires sign confidentiality agreements or equivalents upon hire.
Information Security Program Review
Management is responsible for the design, implementation, and management of the organization’s security policies and procedures. The policies and procedures are reviewed by management at least annually.
Independent Advisor
The board of directors or equivalent entity function includes senior management and external advisors, who are independent from the company's operations. An information security team has also been established to govern cybersecurity.
Performance Reviews
Internal personnel are evaluated via a formal performance review at least annually
Organizational Chart
Management maintains a formal organizational chart to clearly identify positions of authority and the lines of communication, and publishes the organizational chart to internal personnel.
Internal Control Monitoring
A continuous monitoring solution monitors internal controls used in the achievement of service commitments and system requirements.
Cybersecurity Insurance
Cybersecurity insurance has been procured to help minimize the financial impact of cybersecurity loss events.

Data Retention and Disposal

Retention of Case Data
EvenUp retains case data in accordance with customer agreements and applicable legal, security, and compliance requirements.
Deletion of Case Data
Upon a valid customer request, EvenUp deletes case data in accordance with the customer agreement and applicable retention requirements.

Vulnerability Management

Third-Party Penetration Test
A 3rd party is engaged to conduct a network and application penetration test of the production environment at least annually. Critical and high-risk findings are tracked through resolution.

Incident Response

Lessons Learned
After any identified security incident has been resolved, management provides a "Lessons Learned" document to the team in order to continually improve security and operations.
Tracking a Security Incident
Identified incidents are documented, tracked, and analyzed according to the Incident Response Plan.
Incident Response Plan Testing
The Incident Response Plan is periodically tested via tabletop exercises or equivalents. When necessary, Management makes changes to the Incident Response Plan based on the test results.

Risk Assessment

Risk Assessment
Formal risk assessments are performed, which includes the identification of relevant internal and external threats related to security, availability, confidentiality, and fraud, and an analysis of risks associated with those threats.
Vendor Risk Assessment
New vendors are assessed in accordance with the Vendor Risk Management Policy prior to engaging with the vendor. Reassessment occurs at least annually.
Vendor Risk Management Policy
A Vendor Risk Management Policy defines a framework for the onboarding and management of the vendor relationship lifecycle.

Network Security

Endpoint Security
Company endpoints are managed and configured with a strong password policy, anti-virus, and hard drive encryption
Network Traffic Monitoring
Security tools are implemented to provide monitoring of network traffic to the production environment.

Access Security

Administrative Access is Restricted
Administrative access to production infrastructure is restricted based on the principle of least privilege.
Unique Access IDs
Personnel are assigned unique IDs to access sensitive systems, networks, and information
User Access Reviews
System owners conduct scheduled user access reviews of production servers, databases, and applications to validate internal user access is commensurate with job responsibilities.
Removal of Access
Upon termination or when internal personnel no longer require access, system access is removed, as applicable.
Asset Inventory
A list of system assets, components, and respective owners are maintained and reviewed at least annually
Access to Product is Restricted
Non-console access to production infrastructure is restricted to users with a unique SSH key or access key
Encryption-in-Transit
Service data transmitted over the internet is encrypted-in-transit.
Encryption-at-Rest
Service data is encrypted-at-rest.
Encryption and Key Management Policy
An Encryption and Key Management Policy supports the secure encryption and decryption of app secrets, and governs the use of cryptographic controls.