Skip to content

Software companies

Legal practice management software vendors: what is licensable and what is not

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

For a legal practice management software vendor, client matter data is off-limits for licensing: it belongs to law firm customers and carries their confidentiality and privilege duties. Records the vendor creates itself, such as source code, code reviews, issue histories, documentation and product support history about the software, may qualify after a rights review and careful screening.

Key takeaways

  • Matter files, documents, time entry narratives, billing and trust records belong to law firm customers and should be treated as off-limits.
  • Vendor-created records, such as code, reviews, Jira issues and product documentation, are the realistic licensing scope.
  • Support tickets are the gray zone, because users paste matter details, client names and documents into them.
  • An aggregated or de-identified data clause rarely settles the question for legal data; confidentiality duties sit with the firms.
  • Quietly changing customer terms to allow AI use of matter data invites the kind of scrutiny FTC staff have warned about for consumer data.

Why client matter data is off the table#

Client matter data is off the table for a legal practice management vendor because it belongs to law firm customers and is wrapped in duties the vendor cannot waive on their behalf. Matter files, uploaded documents, emails, calendars, conflict databases, time entry narratives, invoices and trust accounting records all describe clients' legal affairs.

Lawyers owe their clients confidentiality under the professional conduct rules of the states where they practice, and much of the material may also be privileged or work product. Your customer agreement almost certainly limits your use of customer data to providing the service. Even when a contract mentions de-identified or aggregated data, a time entry narrative or a document can reveal a client's identity or strategy through its content.

In practice, that means a vendor should plan its licensing scope as if matter data does not exist. Anything else exposes customers to ethics complaints and exposes the vendor to contract claims and lost trust.

A legal software vendor owns the records its own people create while building, selling and supporting the product. That is a meaningful archive: engineering work on deadline calculation, conflict checking, billing rules and document assembly encodes real legal-domain expertise, without containing any client's matter.

Ownership is not the only test. Some records the vendor owns still contain customer information, such as a pull request whose test case was built from a real firm's data export, so every category in the table passes through the same screening before it is described to anyone outside the company.

What a legal software vendor owns and may license
RecordWho controls itLicensable?Main check
Matter files, documents and emailsLaw firm customerNoNot in scope
Time entries, invoices and trust recordsLaw firm customerNoNot in scope
Source code and commit historyVendorMay qualifyThird-party code, secrets, customer-funded custom work
Code reviews and pull requestsVendorMay qualifyTest fixtures or screenshots containing real matter data
Jira issues and bug reportsVendorMay qualify after screeningPasted customer content and attachments
Product support ticketsMixedOnly with customer content removedTicket-level screening and attachment removal
Help center articles and release notesVendorLikelySample screenshots must use fictional matters
Implementation playbooks and templatesVendorMay qualifyCustomer-specific configurations and names
Product usage telemetryDepends on contractUsually notWhether terms permit any use beyond the service

Support tickets are the gray zone#

Support tickets are the gray zone because they mix vendor knowledge with customer content. A ticket about a broken billing export may contain the firm's invoice, the client's name and a screenshot of a matter list, alongside the agent's diagnosis and the engineer's fix.

Screening works at three levels. First, drop whole categories, such as tickets about data recovery, trust account reconciliation or document uploads, that are mostly customer content. Second, remove attachments and screenshots entirely. Third, run de-identification on what remains and sample the result by hand. What survives is usually the product reasoning: symptoms, diagnosis, workaround and fix.

Expect the licensable share to be smaller than the ticket count suggests. That is acceptable, because the value lies in resolution logic linked to code changes, not in volume.

Contract terms to read before licensing anything#

The contract terms to read before licensing any records are the ones that define customer data, your permitted uses and your AI commitments. Read the current templates and the older versions still in force, because long-standing legal customers often sit on paper that predates any AI language.

Map each customer to the template version it signed. If a few large firms negotiated stricter confidentiality or no-AI language, the simplest route is often to exclude every record that mentions them rather than to parse each clause.

  • The customer agreement's definition of customer data and the vendor's permitted uses.
  • Any aggregated, statistical or de-identified data clause, and what it actually allows.
  • The data processing addendum and any security addenda negotiated by larger firms.
  • AI feature terms, including any promise not to train on customer data.
  • Confidentiality clauses that protect customer information beyond personal data.
  • Employee and contractor IP assignments covering the code and documentation you would license.
  • Open-source and third-party licenses inside the codebase.

Do not rewrite customer terms to reach matter data#

Rewriting customer terms to reach matter data is the shortcut that causes the most damage. In a staff post on February 13, 2024, the FTC warned that adopting more permissive data practices, such as using consumers' data for AI training, and disclosing them only through a surreptitious, retroactive change to terms of service or a privacy policy may be unfair or deceptive. That post concerns consumer data, but the principle carries weight with business customers too, and changing a signed law firm agreement generally requires the firm's agreement under its own terms.

Law firms are also unusually careful readers of terms. A vendor that quietly widens its rights over client data risks losing the customers whose trust the product depends on. Keep licensing to records you already own and say so publicly.

AI developers may value a legal vendor's own records because they show how specialized software is built and maintained in a demanding domain. Issue histories that trace a deadline-calculation bug from a support report through a code review to a release show reasoning that general code samples lack.

Measured against the SourceX Enterprise Data Value Framework, a legal vendor's engineering records are strong on domain expertise, human-generated signal and uniqueness, while the privacy burden of screening support tickets pulls net value down. Coding assistants and support assistants are the most likely uses, and the matter data never needs to be part of either.

Illustrative: a practice management vendor scopes its archive#

Illustrative: a fictional vendor sells practice management software to small and mid-sized law firms. Its engineering runs on GitHub and Jira, support on Zendesk and documentation on Confluence. The CEO wants to know what, if anything, could be licensed.

The general counsel rules out all customer data on day one. The team inventories GitHub pull requests and Jira issues for the deadline rules engine and the billing module, finds test fixtures copied from a real firm's export years ago and removes them. Zendesk tickets are limited to product-defect categories with attachments stripped.

The resulting package contains code reviews, linked issues, release notes and screened ticket resolutions. The CEO publishes a short statement to customers explaining that client data is excluded, then moves the package to rights review.

SourceX handles legal software vendor records in five stages, the SourceX five-step transaction of Supply, Rights, Preparation, Approval and Delivery. Only metadata is needed for the first fit check. During Rights, customer agreements and AI feature terms are read against each record family, and during Preparation personal and confidential details are removed before the vendor approves anything for release.

Each approved package carries a SourceX Evidence Packet covering provenance, licensing rights, permitted use, the privacy record and release authorization. For a legal vendor the privacy record matters most: it lists every category of customer content that was excluded, a list the vendor can show law firm customers who ask.

Frequently asked questions

Can we license de-identified matter data if our terms allow aggregated data use?

Treat it as a no unless counsel concludes otherwise for a specific, narrow use. Aggregated data clauses were usually written for benchmarks and product analytics, and legal narratives and documents resist reliable de-identification. Your customers' confidentiality duties do not change because your contract has such a clause.

Do we need law firm customers' consent to license our own source code?

Usually not for code you wrote and own, but check for exceptions. Custom development funded by a customer, code built from a customer's materials and contracts that restrict use of deliverables can all require consent or exclusion. Review each customer-specific branch before including it.

What about legal templates and sample documents we publish?

Templates your team drafted are generally yours, but check where they came from. Templates adapted from customer documents, bar association forms or licensed content providers may carry restrictions. Keep a record of each template's source before including it in any package.

Will licensing our records damage trust with law firm customers?

It can if customers learn about it indirectly. Publish a clear statement of what is licensed and what is excluded, offer to answer questions and keep the scope to vendor-owned records. Transparency about exclusions tends to reassure legal buyers more than silence.

Does a no-training promise in our AI feature terms affect this?

It shapes the boundary. A promise not to train on customer data covers customer content, so it reinforces the exclusion of matter data. It does not usually cover code and engineering records you own, but read the exact wording to confirm.

Sources

  • On February 13, 2024, FTC staff warned that a company adopting more permissive data practices, such as using consumers' data for AI training, and telling consumers only through a surreptitious, retroactive change to its terms of service or privacy policy may be engaging in unfair or deceptive practices. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify