# Compliance & Trust Requirements

**Date:** July 19, 2026
**Status:** v1
**Scope:** Trackmint (work tracking + billing + AI doc-to-form) — all tiers (Basic / Mid / Mid + Pack) and all v1 packs (Legal-Bankruptcy, Software Dev) plus planned packs (General Contractor, medical-adjacent SSDI/PI).
**Feeds:** 05-prd.md v2.2 (Compliance requirements C1–C14).
**Source:** compliance-research.md (full July 2026 research findings).

---

## 1. Executive summary

Running AI over privileged client documents is legal and ethically defensible — but only if it is engineered that way from day one, not bolted on later. ABA Formal Opinion 512 and the wave of state bar guidance that followed it all land on the same three-part answer: use LLM providers under zero-retention, no-training API terms; capture informed client consent where confidential data touches a third-party AI tool; and keep a lawyer in the loop reviewing every AI output before it goes anywhere. Trackmint's existing design (confidence scores, source tracing, mandatory review — PR8) is already the shape regulators want; compliance work is mostly about making those guarantees contractual, logged, and provable. The second existential rule is who we sell to: bankruptcy software marketed to consumers becomes a "bankruptcy petition preparer" under 11 U.S.C. §110 and can constitute unauthorized practice of law (In re Reynoso held exactly that for petition-prep software) — so Trackmint sells to attorneys only, positions itself as a platform not a law firm, and never offers consumer-direct petition preparation. Third, trust is a sales artifact: solo and small firms won't ask for SOC 2 by name, but their bar associations, malpractice carriers, and larger referral partners will — SOC 2 Type I underway at launch and Type II within 12 months is the ticket that keeps deals from dying in diligence. Payments stay easy as long as we stay in PCI SAQ-A scope with hosted checkout and never route fees out of anything resembling a trust account. IOLTA/trust accounting, FCRA credit-report imports, and state-privacy deletion workflows are real obligations but Phase 2 — they gate the Legal pack's growth features, not the launch. HIPAA only enters the picture when medical-adjacent packs (SSDI, personal injury) arrive, and it arrives as a designed "HIPAA-ready mode" with a BAA program, not a retrofit. The prioritized checklist in Section 3 is the build order: everything in the MVP column is a launch gate; nothing in Phase 2/3 blocks shipping.

---

## 2. Research findings

### 2.1 Legal ethics of AI on client data — ABA Formal Opinion 512 and state bar guidance

**ABA Formal Opinion 512 (July 2024)** is the controlling framework for how lawyers may use generative AI, and therefore the spec sheet for any AI feature we sell to attorneys. Its requirements map to the Model Rules:

- **Rule 1.1 (Competence):** lawyers must understand, at a reasonable level, how the AI tool works, its limits, and its risks — so Trackmint must publish a plain-English data-flow and model-behavior document attorneys can rely on for their own diligence (this also satisfies state bar "vendor diligence" expectations).
- **Rule 1.6 (Confidentiality):** the core issue. Inputting client information into a "self-learning" tool that may expose it to other users or use it for training risks impermissible disclosure. The accepted engineering answer: commercial LLM APIs under **zero-data-retention / no-training terms**, per-tenant isolation, and prompts/outputs excluded from vendor and application logs. Where confidential information is submitted to a third-party tool, **informed client consent** may be required — the product must make consent capturable and recordable per client/matter.
- **Rules 5.1/5.3 (Supervision):** AI is treated like a nonlawyer assistant — its work must be supervised and verified. Product translation: an unmissable **"AI-generated — attorney review required"** gate on every extraction and draft, with review status tracked.
- **Rules 1.4, 1.5:** clients must be consulted where AI use is material to the representation; AI time savings must flow to clients under fee-reasonableness rules, and lawyers may not bill clients for time spent learning the tool — which makes per-case AI pricing (PM5) easier to justify than hourly data entry.

**State bar guidance** converges on the same checklist, with three anchor opinions: **California COPRAC** practical guidance — do not input confidential information unless the provider *cannot* use it to train or share it; anonymize where possible (and California is amending its Rules of Professional Conduct for AI in 2026); **Florida Bar Ethics Op 24-1 (Jan 2024)** — a green light with caveats, recommending informed client consent before using third-party generative AI with confidential information; **NYC Bar Formal Op 2024-5** — consent required for tools that share or retain client data, with AI CLE requirements coming. Similar guidance is accumulating in other states. **Design consequence:** build once to the strictest common denominator — zero-retention pipeline + consent record field + review gate — and every state's guidance is satisfied.

**The verdict from the research:** client data CAN legally go through an LLM if four things hold — (1) contractual no-training, (2) zero/minimal retention, (3) lawyer-facing disclosure documentation, and (4) a consent-capture mechanism in the product.

**LLM provider terms (as of the July 2026 research):**

| Provider | Training on customer data | Retention | HIPAA/BAA |
|---|---|---|---|
| **Anthropic Claude API** | No-training by default | **Zero-data-retention (ZDR) available per-org** via sales | BAA offered |
| **OpenAI API / Enterprise** | No-training by default | Default 30-day abuse retention; **ZDR for eligible endpoints on approval** | BAA by request |
| **AWS Bedrock** | Model providers never see customer data | **No storage/logging of prompts by architecture**; enforceable via AWS SCPs | HIPAA-eligible under the AWS BAA |
| **Azure OpenAI** | No training | 30-day abuse-monitoring storage **unless "modified abuse monitoring" exemption approved** | Microsoft BAA |

Cleanest story for bar-regulated buyers: **AWS Bedrock, or ZDR-enabled Anthropic/OpenAI**. Default 30-day abuse retention (OpenAI, Azure without exemption) is *not* the zero-retention posture C1 promises — the ZDR/exemption paperwork is part of the launch gate.

**Requirements → C1, C2, C3.**

### 2.2 Unauthorized practice of law and 11 U.S.C. §110 — who we may sell to

Bankruptcy is the one vertical where the *software itself* can be found to practice law. **11 U.S.C. §110** defines a "bankruptcy petition preparer" as a person **other than an attorney or an attorney's employee** who prepares filing documents for compensation — imposing signature/identification requirements, fee limits, and fines. Software CAN be a BPP: in **In re Reynoso (9th Cir. 2007)**, a consumer-facing web application that produced petitions for a fee was held to be a bankruptcy petition preparer engaged in the unauthorized practice of law, because it delivered personalized guidance beyond the merely clerical. The safe harbor is equally well established: when the software is used **by an attorney as a tool of that attorney's practice**, the attorney — not the software — is the preparer and §110 does not apply. That is exactly how Best Case, NextChapter, Jubilee, and Glade position.

Positioning rules that keep Trackmint in the safe lane:

- **Attorney-only sales** for the Legal-Bankruptcy pack: license terms require the customer to be a licensed attorney or law firm; the pack is not sold to consumers or non-attorney "document preparation" businesses.
- **No consumer-direct petition preparation, ever** — the client portal collects documents for the attorney; it never generates legal documents for an unrepresented consumer.
- **Platform-not-law-firm disclaimers** throughout marketing, ToS, and product: Trackmint provides software; it does not provide legal advice, and no attorney-client relationship is formed with Trackmint.
- The attorney signs and files; Trackmint's output is a draft for attorney review (reinforcing 2.1's review gate).

**Requirement → C6 (and C3).**

### 2.3 Privilege, data ownership, and contract terms

Attorney-client privilege can be threatened by vendor terms that grant the vendor rights to use customer content. The governing line comes from **ABA Formal Op 477R and 20+ state cloud-ethics opinions**: cloud storage of client data is permitted with "reasonable efforts," and privilege is generally **not** waived when the cloud provider has **no right to use the content** — which makes the ToS itself a privilege-protection mechanism. If our ToS claimed broad rights to use, analyze, or train on uploaded documents, opposing counsel could argue confidentiality was not maintained. The contract stack must therefore say, unambiguously:

- **Customer owns all content**; Trackmint takes no license beyond what is strictly necessary to provide the service; **no training on customer data**, no human review of customer content except with permission for support.
- **Data Processing Addendum (DPA)** available to every customer (not enterprise-gated), listing subprocessors (cloud host, LLM provider, OCR provider, payment processor) and their retention terms.
- **Breach notification commitment: 72 hours** to affected customers — faster than most state statutes require, and the number attorneys' own client obligations push them to demand.
- Data return/deletion on termination; full export at any time (extends PR11).

**Requirement → C5.**

### 2.4 Security baseline, breach notification, and privacy law

The competitive benchmark is **Clio's security/trust page** — the table-stakes checklist a legal-SaaS buyer now expects: SOC 2 Type II + SOC 1, annual pen tests, TLS 1.2+/AES-256, RBAC, 2FA/SSO, session and IP audit logging, monitored backups, DR testing, and an explicit AI promise (no training on customer data, real-time AI processing without storage). Our baseline, which every bar guidance document, malpractice-carrier questionnaire, and security review assumes:

- **AES-256 encryption at rest, TLS 1.2+ in transit** (no legacy TLS).
- **MFA** available and encouraged for all users; required for admin roles.
- **RBAC at the matter level** — ethical walls: a user can be excluded from specific matters, not just workspaces (this is also a conflicts-of-interest feature attorneys expect).
- **Immutable audit log** of document, financial, and permission actions (who viewed/edited/exported what, when).
- **Encrypted backups** with tested restore; **US-based hosting** stated publicly (state bars and government-adjacent clients ask).
- A **public trust page** (security practices, subprocessors, uptime, certifications) — cheap to build, disproportionately effective in small-firm sales.

**Breach notification:** all 50 states have breach-notification statutes, and they key on exactly the data we store — SSNs, financial account numbers, medical data — with statutory deadlines typically 30–60 days. Lawyers carry their own duty to notify clients of a material breach (**ABA Formal Op 483**), which is why our **contractual 72-hour notice to firm customers** (C5) matters: it gives them room to meet their own obligations. A written breach-response plan (50-state notification map + contractual commitments) is an MVP artifact.

**GLBA:** does **not** apply to law firms practicing law (*ABA v. FTC*, D.C. Cir. 2005) and does not apply to Trackmint as a practice-management SaaS. But note the direction of travel: since May 2024 the **FTC Safeguards Rule requires nonbank financial institutions to report breaches affecting 500+ consumers within 30 days** (unencrypted data; encryption is a safe harbor). We voluntarily adopt the Safeguards elements — risk assessment, MFA, encryption, vendor oversight, incident response — as cheap credibility with financially-regulated adjacent buyers.

**State privacy laws** (~20 comprehensive state laws by 2026): CCPA/CPRA applies at >$25M revenue OR 100K+ CA consumers OR 50%+ revenue from selling data, and has covered B2B and employee data since 2023 — Trackmint starts below thresholds but customers increasingly pass obligations down. As a processor/service provider the obligations are contractual: a **DPA with processing restrictions, deletion/return commitments, subprocessor flow-downs, and consumer-rights support**. Phase 2: the DPA v2 plus **deletion-request workflows** (delete a client's personal data across matters, with legal-hold and records-retention carve-outs so we never auto-delete what a court or bar rule requires be kept). GDPR only if EU users materialize — deferred.

**Requirements → C4 (baseline, MVP), C5 (breach commitments, MVP), and C12 (privacy DPA + deletion, Phase 2).**

### 2.5 SOC 2 — the trust ticket

SOC 2 is not legally required; it is commercially required. It is the one artifact that answers bar-diligence questionnaires, malpractice-carrier security addenda, and mid-market procurement in a single PDF — and law-firm vendor questionnaires increasingly expect **Type II** specifically. Cost/timeline from the research: **Type I takes 3–6 months at ~$7.5K–60K; Type II adds a 3–12 month observation period (6–15 months total) at ~$12K–100K+**; the standard startup path — Drata/Vanta-class automation plus a $10K–30K audit — lands the MVP at **~$20–50K all-in**, consistent with market-financial.md's budget band. Plan:

- **Type I (point-in-time) audit underway at launch** — "SOC 2 Type I in progress, report expected [date]" is sales-usable language.
- **Type II (observation period) within 12 months** of launch.
- Scope the audit to the production platform including the AI pipeline — an AI pipeline *inside* the SOC 2 boundary is a differentiator against AI-native competitors who exclude it.
- Publish status on the trust page; use the compliance-automation tooling to keep audit cost near the bottom of the band.

**Requirement → C9.**

### 2.6 Payments compliance — PCI DSS SAQ-A and trust-safe fee routing

- **PCI scope:** by using hosted checkout from the embedded processor (Stripe-class, per PRD R5 "partner, don't build"), card data never touches Trackmint servers, keeping us in **SAQ-A**, the lightest self-assessment. Rule: no card-number field is ever rendered by our code; no PAN is ever stored, logged, or proxied.
- **PCI DSS v4.0.1 nuance:** merchants using **iframe/embedded** checkout must now address the **script-integrity requirements (6.4.3 — script inventory/authorization, and 11.6.1 — payment-page tamper detection)** or obtain written confirmation from the processor that it covers them; a **full-redirect** checkout is exempt. Decision input for the payments build: full redirect is the lowest-compliance-cost default; if we embed, we budget for 6.4.3/11.6.1 or get the processor's written coverage.
- **Platform/Connect model:** each firm is its own merchant of record on the processor's platform — Trackmint is the platform, not the merchant, which keeps underwriting and chargeback liability with the processor/firm relationship.
- **Trust-safe fee routing:** the legal-payments industry exists because generic processors debit **processing fees and chargebacks from the deposit account** — catastrophic if that account is a trust account (it creates a disbursement of client funds to the vendor). Even before the IOLTA module ships, Trackmint's payment flows must guarantee: **fees and chargebacks are never debited from an account designated as trust**; earned fees route to operating. This is the LawPay/Confido-class behavior and a prerequisite for ever being credible in legal payments, and it informs the processor decision in PRD Open Question 4.

**Requirement → C8.**

### 2.7 Trust accounting / IOLTA (Phase 2, Legal pack)

Deferred from v1 (PRD Section 9) but its compliance shape is fixed now so nothing in the v1 data model blocks it. Note the framing: **no state bar "certifies" trust-accounting software — the lawyer is always the accountable party**, so the product's job is to make compliance the path of least resistance:

- **Monthly three-way reconciliation** — bank statement vs. trust journal vs. sum of client ledgers — is the universal bar-audit standard, and **California's CTAPP (Client Trust Account Protection Program) now mandates monthly reconciliation plus annual self-certification**; the module should generate the monthly reconciliation and the CTAPP-ready records.
- **Negative-balance blocking:** per-client sub-ledgers with a **hard block** on disbursing more than that client holds (the classic disbarment pattern; PracticePanther's trust bugs are the cautionary tale).
- **No commingling:** earned vs. client funds separated; no operating expenses paid from trust; **no disbursing before deposits clear** (cleared-funds tracking); retainers clearly labeled non-trust until the module exists (already in PRD 7.3).
- **Record retention:** complete, immutable trust records retained **five years** after representation ends (ABA Model Rule 1.15; some states longer — retention period must be configurable upward), with bar-audit-ready exports.

**Requirement → C10.** Sequencing per PRD Section 10: post-SOC 2 Type I, once the Legal pack has traction.

### 2.8 Regulated data types — Rule 9037 SSNs, FCRA credit reports, WH-347 payroll, HIPAA/PHI

- **Fed. R. Bankr. P. 9037 (redaction):** court filings may show only the **last four digits of SSNs** (plus birth year only, minors' initials, truncated account numbers). Because our pipeline extracts full SSNs from W-2s and pay stubs, the export step must **auto-redact to last-4 on every court-bound PDF** while the full SSN is stored **field-level encrypted** with masked display and permissioned reveal (the PRD 7.3 stance). The single exception: **the full SSN appears only on Form 121 (Statement About Your Social Security Numbers), which is submitted to the court but not publicly docketed** — the export pipeline treats Form 121 as the one full-SSN output. Incumbents' refusal to store full SSNs pushes users into side systems — we store it, encrypted, and never let it leak into a filing.
- **CM/ECF reality (feeds A7/A11):** there is **no public write API** for CM/ECF — filing happens through each district's system using the **attorney's own credentials**, with per-court rules for non-attorney "filing agents." Product consequences: court-compliant PDFs per local rules at v1 (A7), and when e-filing arrives (A11), a **secure per-attorney, per-district ECF credential vault** rather than any shared-credential scheme.
- **FCRA (credit report import — A12):** consumer credit reports require a **permissible purpose — in bankruptcy, the consumer's written instructions** — and an end-user certification. The compliant pattern used by NextChapter-class tools: integrate a **licensed credit-report reseller**, with the **attorney as the certified end user** acting on the client's authorization; Trackmint is the conduit and must **never become the reseller/CRA itself** (that role carries heavy FCRA obligations). Report data inherits the same encryption and access controls as SSNs.
- **WH-347 certified payroll (GC pack):** the DOL form **prohibits full SSNs on the submitted form** (last-4 or another individually identifying number; no home addresses on the form) — but **FAR 52.222-8 / Davis-Bacon requires the contractor to MAINTAIN full SSNs and addresses in its own records and produce them on request**. So truncation alone is wrong: the product must both auto-truncate to last-4 on every generated WH-347/export AND retain the full SSN field-level encrypted (and out of AI logs) so the contractor can meet the record-keeping duty. State portals (e.g., CA DIR eCPR) have their own formats — per-state templates later.
- **HIPAA (Phase 3, SSDI/personal-injury pack):** HIPAA applies through the chain covered entity → business associate → subcontractor. Nuance from the research: a **plaintiff-side PI/SSDI firm obtaining records under the client's own authorization is usually NOT HIPAA-regulated**; but a firm **defending a hospital or insurer is a business associate**, which makes Trackmint a **subcontractor business associate** — Security Rule compliance, breach notification (HIPAA's statutory 60-day rule; our contractual ~72h is stricter), and a **BAA program** covering both our customers and every subprocessor touching PHI (AWS, LLM provider). Design decision: a **"HIPAA-ready mode"** switchable per firm (stricter logging, BAA-covered subprocessor routing) rather than making every tenant carry HIPAA overhead — and we do not market HIPAA at MVP, since bankruptcy does not need it.

**Requirements → C7 (MVP), C11 (Phase 2), C13, C14 (Phase 3).**

---

## 3. Prioritized checklist

### MVP (launch gates — P0)

- [ ] Zero-retention, no-training LLM API terms in place; prompts/outputs excluded from all logs; per-tenant isolation documented (C1)
- [ ] Per-firm AI toggle; per-matter AI opt-out; client-consent record field on the matter (C2)
- [ ] "AI-generated — attorney review required" gate on every extraction and draft; review status tracked and auditable (C3)
- [ ] Security baseline live: AES-256 at rest, TLS 1.2+, MFA, matter-level RBAC, immutable audit log, encrypted backups, US hosting, public trust page (C4)
- [ ] ToS/DPA shipped: customer owns content, no vendor use rights, 72-hour breach notice, subprocessor list (C5)
- [ ] Breach response plan written: 50-state notification map + contractual customer-notice commitments (C5 support)
- [ ] UPL guardrails: attorney-only Legal-pack sales, platform-not-law-firm disclaimers, no consumer-direct petition path (C6)
- [ ] Rule 9037 auto-redaction (last-4 SSN) on all court-bound PDFs; full SSN field-level encrypted with masked display (C7)
- [ ] Payments in SAQ-A scope via hosted checkout; fee routing that never debits trust-designated accounts (C8)
- [ ] SOC 2 Type I audit engaged and underway at launch; trust page states status (C9, first half)

### Phase 2 (first 12 months)

- [ ] SOC 2 Type II report delivered (C9, second half)
- [ ] IOLTA module: monthly three-way reconciliation (CA CTAPP-ready), negative-balance blocking, cleared-funds tracking, 5-year immutable records, bar-audit exports (C10 — Legal pack, post-Type I)
- [ ] FCRA-compliant credit-report import via licensed reseller, attorney as certified end user (C11)
- [ ] State-privacy DPA and deletion-request workflows with legal-hold carve-outs (C12)

### Phase 3 (with the packs that need them)

- [ ] WH-347 output truncation (last-4 SSN) for the GC pack's certified payroll, with full-SSN encrypted retention for the FAR 52.222-8 record-keeping duty (C13)
- [ ] HIPAA-ready mode + BAA program (Trackmint and subprocessors) for the SSDI/PI pack (C14)
- [ ] Per-district e-filing automation with filing-agent support (with A11) — includes the per-attorney, per-district ECF credential vault
- [ ] Data residency / GDPR program if EU demand materializes; voluntary GLBA-grade program documentation

---

## 4. Cross-cutting product specs (one-liners)

- **No customer document, prompt, or extraction ever trains a model — ours or a vendor's.**
- **Every AI output is a draft: nothing is exportable or sendable until a human marks it reviewed.**
- **A full SSN exists in exactly one place — an encrypted field — and every rendered surface shows last-4 unless a permissioned reveal is logged.**
- **Card numbers never touch our servers; fees never touch trust money.**
- **Every document view/download/AI-scan, consent, review, reveal, and disbursement writes an immutable audit event (user, matter, timestamp, IP).**
- **Trust ledger invariant, enforced in code: client sub-ledger ≥ 0; trust ≠ operating; fees never debit trust.**
- **Anything we promise on the trust page is enforced in code or CI, not policy documents.**
- **Deletion honors the law twice: we delete on request, except where retention is legally required — and we can prove both.**
- **Compliance features ship per pack: firms only carry the regulatory overhead of the verticals they bought.**

---

## 5. Key sources

- ABA Formal Opinion 512 (generative AI, July 2024); ABA Formal Op 477R (cloud/confidentiality); ABA Formal Op 483 (breach-notification duty)
- Florida Bar Ethics Op 24-1; California COPRAC generative-AI practical guidance; NYC Bar Formal Op 2024-5
- Anthropic ZDR/BAA documentation; OpenAI Enterprise Privacy; AWS Bedrock data-retention architecture; Azure OpenAI data-privacy documentation
- Clio security/trust pages (competitive security baseline)
- HHS business associate guidance (HIPAA BA/subcontractor chain)
- *ABA v. FTC* (D.C. Cir. 2005) and McDermott analysis of GLBA scope; FTC Safeguards Rule breach-reporting amendment (May 2024)
- FTC FCRA guidance (permissible purpose, end-user certification)
- PCI DSS v4.0.1 and SAQ-A guidance (incl. reqs 6.4.3 / 11.6.1 script integrity — Hyperproof analysis)
- ABA IOLTA compliance guide; California State Bar CTAPP (Client Trust Account Protection Program)
- 11 U.S.C. §110; *In re Reynoso* (9th Cir. 2007; ABI analysis); DOJ bankruptcy petition preparer guidelines
- Drata/Vanta SOC 2 cost and timeline benchmarks; state comprehensive-privacy-law maps
- Fed. R. Bankr. P. 9037; PACER/CM/ECF non-attorney filer (filing agent) rules
- DOL WH-347 form instructions; FAR 52.222-8 (Davis-Bacon payroll record-keeping)

---

*End of document.*
