Compliance

SOC 2 Type 2
HIPAA
CCPA
Monitoring
Resources
If you would like to report a vulnerability, please contact [email protected] with a proof of concept, list of tools used, and the output of the tools. Once received, EvenUp will work quickly to reproduce each vulnerability to verify its status before taking the steps needed to address it.
SOC 2 Type 2
HIPAA
CCPA
Vulnerability Disclosure
To report a vulnerability, contact [email protected] with a proof of concept, list of tools used, and the output of the tools. Once received, EvenUp will work quickly to reproduce each vulnerability to verify its status before taking the steps needed to address it.
Exclusions
When reporting vulnerabilities, please consider (i) attack scenario / exploitability, and (ii) security impact of the bug. The following issues are considered out of scope:
- Clickjacking on pages with no sensitive actions
- Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions
- Attacks requiring MITM or physical access to a user's device
- Previously known vulnerable libraries without a working Proof of Concept
- Comma Separated Values (CSV) injection without demonstrating a vulnerability
- Missing best practices in SSL/TLS configuration
- Any activity that could lead to the disruption of our service (DoS)
- Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS
- Attempting to compromise our endpoints by brute forcing
- Missing best practices in Content Security Policy
- Missing HttpOnly or Secure flags on cookies
- Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)
- Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 versions behind latest]
- Software version disclosure / Banner identification issues / Descriptive error messages or headers
- Public Zero-day vulnerabilities that have had an official patch for less than 1 month
- Tabnabbing
- Open redirect - unless an additional security impact can be demonstrated
- Issues that require unlikely user interaction
AI & LEGAL ETHICS
AI and Legal Ethics FAQs
EvenUp’s AI tools are designed to help personal injury firms work more efficiently while keeping trust, confidentiality, and attorney oversight at the center of legal work. These FAQs address common questions about responsible AI use in legal workflows, including client communication, confidentiality, data protection, attorney supervision, AI-assisted outputs, and billing.
This information is provided for general informational purposes only and does not constitute legal advice. Firms remain responsible for determining how to use EvenUp consistent with applicable laws, court rules, professional obligations, engagement terms, and client instructions.
Do I need to tell my clients that my firm uses EvenUp’s AI tools?
More specific requirements may apply to court filings. Some courts and judges require lawyers to disclose the use of AI-assisted tools, certify that filings were independently reviewed, or confirm that factual statements, legal authorities, and citations were verified.
Do EvenUp’s AI tools impact client confidentiality or privilege?
EvenUp is an enterprise legal technology platform designed for law firm workflows, not an open, public AI chatbot. Our AI features are intended to support attorney-supervised review. EvenUp maintains security controls, restricts access to customer data, and does not allow third-party AI providers to use customer case files to train models for other customers. We configure these services to minimize data retention and, where available, use zero-retention settings.
Whether privilege or work-product protection applies generally turns on traditional factors, such as whether the tool was used by or at the direction of counsel, whether the material was created for legal advice or in anticipation of litigation, and whether confidentiality was maintained. EvenUp does not decide or control privilege outcomes for a firm. Each firm and its counsel remain responsible for evaluating privilege, work-product protection, and any discovery requests under applicable rules.
What privacy, security, and confidentiality safeguards should my firm consider when using technology providers generally?
Customers should consider safeguards across four layers:
- Legal and contractual controls: Appropriate confidentiality, data processing, security, and, where applicable, Business Associate Agreement commitments.
- Technical controls: Strong authentication, role-based access, least-privilege permissions, encryption, logging and monitoring, vulnerability management, and secure account administration.
- Workflow controls: Attorney supervision, review of AI-assisted outputs, verification against case records, correction before approval, and clear escalation paths for unexpected or sensitive issues.
- Governance controls: Internal AI-use policies, staff training, periodic risk review, audit-log review where available, and clear client or court communication practices where required or appropriate.
What other responsibilities does my firm have when using technology providers like EvenUp?
Those responsibilities include supervising attorneys and staff, reviewing AI-assisted outputs before use, complying with court and bar rules, configuring workflows appropriately, maintaining internal policies and training, and securing your firm's own user accounts, devices, and systems.
Billing Back Case Costs
Personal injury firms often use technology and third-party services to support case administration, document preparation, records workflows, communications, and claims processes. Whether and how those costs may be billed to, deducted from, or recovered from clients or case proceeds can raise complex questions under fee agreements, client disclosures, court rules, settlement practices, and professional responsibility obligations.
The information below is intended to provide a starting point for understanding complex questions about billing expenses back to clients. Different jurisdictions have different standards, and this is not intended to be comprehensive or to serve as legal advice. Please consult an attorney licensed in your jurisdiction.
Can a law firm pass EvenUp costs along to a client?
What is the difference between a case cost and general overhead?
How should a firm determine the amount charged to a client?
How does EvenUp help firms document matter-specific costs?
Should the firm disclose these costs in its client agreement?
Where can I learn more?
Requirements vary by jurisdiction, so firms should review both applicable state-level ethics guidance and any local court rules, standing orders, or judge-specific requirements. Many jurisdictions draw from the ABA’s guidance on lawyers’ use of generative AI. The following resources provide a useful starting point: