Software companies
Legal practice management software vendors: what is licensable and what is not
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
For a legal practice management software vendor, client matter data is off-limits for licensing: it belongs to law firm customers and carries their confidentiality and privilege duties. Records the vendor creates itself, such as source code, code reviews, issue histories, documentation and product support history about the software, may qualify after a rights review and careful screening.
Key takeaways
- Matter files, documents, time entry narratives, billing and trust records belong to law firm customers and should be treated as off-limits.
- Vendor-created records, such as code, reviews, Jira issues and product documentation, are the realistic licensing scope.
- Support tickets are the gray zone, because users paste matter details, client names and documents into them.
- An aggregated or de-identified data clause rarely settles the question for legal data; confidentiality duties sit with the firms.
- Quietly changing customer terms to allow AI use of matter data invites the kind of scrutiny FTC staff have warned about for consumer data.
Why client matter data is off the table#
Client matter data is off the table for a legal practice management vendor because it belongs to law firm customers and is wrapped in duties the vendor cannot waive on their behalf. Matter files, uploaded documents, emails, calendars, conflict databases, time entry narratives, invoices and trust accounting records all describe clients' legal affairs.
Lawyers owe their clients confidentiality under the professional conduct rules of the states where they practice, and much of the material may also be privileged or work product. Your customer agreement almost certainly limits your use of customer data to providing the service. Even when a contract mentions de-identified or aggregated data, a time entry narrative or a document can reveal a client's identity or strategy through its content.
In practice, that means a vendor should plan its licensing scope as if matter data does not exist. Anything else exposes customers to ethics complaints and exposes the vendor to contract claims and lost trust.
What a legal software vendor owns and may license#
A legal software vendor owns the records its own people create while building, selling and supporting the product. That is a meaningful archive: engineering work on deadline calculation, conflict checking, billing rules and document assembly encodes real legal-domain expertise, without containing any client's matter.
Ownership is not the only test. Some records the vendor owns still contain customer information, such as a pull request whose test case was built from a real firm's data export, so every category in the table passes through the same screening before it is described to anyone outside the company.
| Record | Who controls it | Licensable? | Main check |
|---|---|---|---|
| Matter files, documents and emails | Law firm customer | No | Not in scope |
| Time entries, invoices and trust records | Law firm customer | No | Not in scope |
| Source code and commit history | Vendor | May qualify | Third-party code, secrets, customer-funded custom work |
| Code reviews and pull requests | Vendor | May qualify | Test fixtures or screenshots containing real matter data |
| Jira issues and bug reports | Vendor | May qualify after screening | Pasted customer content and attachments |
| Product support tickets | Mixed | Only with customer content removed | Ticket-level screening and attachment removal |
| Help center articles and release notes | Vendor | Likely | Sample screenshots must use fictional matters |
| Implementation playbooks and templates | Vendor | May qualify | Customer-specific configurations and names |
| Product usage telemetry | Depends on contract | Usually not | Whether terms permit any use beyond the service |
Support tickets are the gray zone#
Support tickets are the gray zone because they mix vendor knowledge with customer content. A ticket about a broken billing export may contain the firm's invoice, the client's name and a screenshot of a matter list, alongside the agent's diagnosis and the engineer's fix.
Screening works at three levels. First, drop whole categories, such as tickets about data recovery, trust account reconciliation or document uploads, that are mostly customer content. Second, remove attachments and screenshots entirely. Third, run de-identification on what remains and sample the result by hand. What survives is usually the product reasoning: symptoms, diagnosis, workaround and fix.
Expect the licensable share to be smaller than the ticket count suggests. That is acceptable, because the value lies in resolution logic linked to code changes, not in volume.
Contract terms to read before licensing anything#
The contract terms to read before licensing any records are the ones that define customer data, your permitted uses and your AI commitments. Read the current templates and the older versions still in force, because long-standing legal customers often sit on paper that predates any AI language.
Map each customer to the template version it signed. If a few large firms negotiated stricter confidentiality or no-AI language, the simplest route is often to exclude every record that mentions them rather than to parse each clause.
- The customer agreement's definition of customer data and the vendor's permitted uses.
- Any aggregated, statistical or de-identified data clause, and what it actually allows.
- The data processing addendum and any security addenda negotiated by larger firms.
- AI feature terms, including any promise not to train on customer data.
- Confidentiality clauses that protect customer information beyond personal data.
- Employee and contractor IP assignments covering the code and documentation you would license.
- Open-source and third-party licenses inside the codebase.
Do not rewrite customer terms to reach matter data#
Rewriting customer terms to reach matter data is the shortcut that causes the most damage. In a staff post on February 13, 2024, the FTC warned that adopting more permissive data practices, such as using consumers' data for AI training, and disclosing them only through a surreptitious, retroactive change to terms of service or a privacy policy may be unfair or deceptive. That post concerns consumer data, but the principle carries weight with business customers too, and changing a signed law firm agreement generally requires the firm's agreement under its own terms.
Law firms are also unusually careful readers of terms. A vendor that quietly widens its rights over client data risks losing the customers whose trust the product depends on. Keep licensing to records you already own and say so publicly.
Why AI developers may value a legal vendor's own records#
AI developers may value a legal vendor's own records because they show how specialized software is built and maintained in a demanding domain. Issue histories that trace a deadline-calculation bug from a support report through a code review to a release show reasoning that general code samples lack.
Measured against the SourceX Enterprise Data Value Framework, a legal vendor's engineering records are strong on domain expertise, human-generated signal and uniqueness, while the privacy burden of screening support tickets pulls net value down. Coding assistants and support assistants are the most likely uses, and the matter data never needs to be part of either.
Illustrative: a practice management vendor scopes its archive#
Illustrative: a fictional vendor sells practice management software to small and mid-sized law firms. Its engineering runs on GitHub and Jira, support on Zendesk and documentation on Confluence. The CEO wants to know what, if anything, could be licensed.
The general counsel rules out all customer data on day one. The team inventories GitHub pull requests and Jira issues for the deadline rules engine and the billing module, finds test fixtures copied from a real firm's export years ago and removes them. Zendesk tickets are limited to product-defect categories with attachments stripped.
The resulting package contains code reviews, linked issues, release notes and screened ticket resolutions. The CEO publishes a short statement to customers explaining that client data is excluded, then moves the package to rights review.
How SourceX handles legal software vendor records#
SourceX handles legal software vendor records in five stages, the SourceX five-step transaction of Supply, Rights, Preparation, Approval and Delivery. Only metadata is needed for the first fit check. During Rights, customer agreements and AI feature terms are read against each record family, and during Preparation personal and confidential details are removed before the vendor approves anything for release.
Each approved package carries a SourceX Evidence Packet covering provenance, licensing rights, permitted use, the privacy record and release authorization. For a legal vendor the privacy record matters most: it lists every category of customer content that was excluded, a list the vendor can show law firm customers who ask.
Frequently asked questions
Can we license de-identified matter data if our terms allow aggregated data use?
Treat it as a no unless counsel concludes otherwise for a specific, narrow use. Aggregated data clauses were usually written for benchmarks and product analytics, and legal narratives and documents resist reliable de-identification. Your customers' confidentiality duties do not change because your contract has such a clause.
Do we need law firm customers' consent to license our own source code?
Usually not for code you wrote and own, but check for exceptions. Custom development funded by a customer, code built from a customer's materials and contracts that restrict use of deliverables can all require consent or exclusion. Review each customer-specific branch before including it.
What about legal templates and sample documents we publish?
Templates your team drafted are generally yours, but check where they came from. Templates adapted from customer documents, bar association forms or licensed content providers may carry restrictions. Keep a record of each template's source before including it in any package.
Will licensing our records damage trust with law firm customers?
It can if customers learn about it indirectly. Publish a clear statement of what is licensed and what is excluded, offer to answer questions and keep the scope to vendor-owned records. Transparency about exclusions tends to reassure legal buyers more than silence.
Does a no-training promise in our AI feature terms affect this?
It shapes the boundary. A promise not to train on customer data covers customer content, so it reinforces the exclusion of matter data. It does not usually cover code and engineering records you own, but read the exact wording to confirm.
Sources
- On February 13, 2024, FTC staff warned that a company adopting more permissive data practices, such as using consumers' data for AI training, and telling consumers only through a surreptitious, retroactive change to its terms of service or privacy policy may be engaging in unfair or deceptive practices. Source
Related resources
- QuestionCan SaaS data be licensed?
- InsightConstruction software companies: what project data you can and cannot license
- InsightAI features in acquired products vs licensing records out: a holdco rule
- InsightWho owns code and documents written by contractors?
- IndustrySoftware data
- IndustryClaims administration data
See if your company qualifies
A short company assessment. No data uploads are needed.