Legal AI
CoCounsel
Medium riskThomson Reuters' professional AI assistant, delivered inside Westlaw Precision for legal work and as CoCounsel Tax, Audit & Accounting for advisory practices.
Is CoCounsel safe for confidential data?
CoCounsel is one of the better-documented legal AI products on data handling: Thomson Reuters publishes a security FAQ stating that all calls to third-party LLM providers (OpenAI, Google) use zero-retention APIs, that those providers are contractually prohibited from training on customer data, and that TR has disabled third-party abuse monitoring so no human at the provider sees prompts. The residual risk is structural rather than contractual: privileged client material still transits OpenAI and Google infrastructure, the zero-retention claim cannot be independently audited by a customer, and courts have not squarely resolved whether routing privileged documents through an LLM vendor could support a privilege-waiver argument. Firms should treat it as safe for confidential work only under a signed agreement, with the security FAQ terms mirrored in the contract.
Risk by plan
The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.
Sold as part of the Westlaw Precision subscription under Thomson Reuters' standard terms; no-training and zero-retention commitments apply.
Same published security posture: zero-retention API calls, no training on user content, U.S. processing, TLS 1.2 in transit and AES-256 at rest.
Data handling
Training on inputs
Thomson Reuters states user content and prompts are not used to train CoCounsel or any third-party LLM, and that OpenAI and Google are contractually prohibited from training on customer data. There is no consumer tier with different terms.
Retention
Third-party LLM calls are made via zero-retention APIs, so prompts are not stored by OpenAI or Google. Uploaded content persists in the customer's CoCounsel account for the life of the account unless deleted by the user.
Residency
Prompts and content are processed and hosted in the United States per the published security FAQ. Non-U.S. firms (including Canadian firms subject to PIPEDA or provincial rules) should confirm cross-border transfer terms in their agreement.
Compliance
- SOC 2Yes
- GDPR / DPAYes
- HIPAA BAANot verified
Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.
New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.
Enterprise controls
- SSO / SAML
- Zero-retention API calls to LLM providers
- Third-party abuse monitoring disabled
- AES-256 at rest, TLS 1.2 in transit
- Standard Thomson Reuters DPA available
Frequently asked questions
Is CoCounsel safe for confidential client data?
Under a signed subscription, its data handling is stronger than most alternatives: zero-retention calls to OpenAI and Google, contractual no-training terms, and abuse monitoring turned off. The open questions are structural — client data still transits third-party AI infrastructure, and you are relying on Thomson Reuters' contracts with its providers rather than anything you can audit. Confirm the security FAQ commitments are incorporated into your firm's agreement.
Does CoCounsel train on my data?
No. Thomson Reuters states that user content and prompts are not used to train CoCounsel, other TR products, or any third-party LLM, and that OpenAI and Google are contractually barred from doing so. That commitment is published in TR's security documentation; get it restated in your contract rather than relying on a web page that can change.
Does using CoCounsel waive privilege?
No court has held that using an enterprise legal AI tool under confidentiality terms waives privilege, and ABA Formal Opinion 512 treats vendor confidentiality terms as central to a lawyer's Rule 1.6 analysis. The greater practical risk is lawyers using free consumer chatbots for the same work outside any agreement — that is where confidentiality and privilege arguments get genuinely uncomfortable, and it is worth pairing a sanctioned tool with controls on the unsanctioned ones.
Policy changelog
- Initial entry published from Thomson Reuters' published security documentation and cited coverage.
Sources
- Thomson Reuters security information for CoCounsel Tax, Audit & Accounting
- Thomson Reuters Data Processing Addendum
- ABA Formal Opinion 512 on generative AI
This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.
CoCounsel is probably already in your organization.
Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.
More AI tool profiles
AI assistant built into Clio Manage, the dominant solo and small-firm practice management platform, answering questions and drafting from the firm's own matter data.
Legal AI platform for law firms and in-house teams: research, drafting, document review, and workflow automation built on foundation models.
LexisNexis' generative AI research and drafting assistant, now sold as Lexis+ with Protégé, grounded in the Lexis primary-law and Shepard's citation database.
Generative AI features (document summarization, drafting, text editing, search) embedded in the MyCase practice management platform for small firms, part of AffiniPay's 8am IQ initiative.