Law firms and legal teams hold their clients’ most sensitive information, and clients now demand proof of it. Compyl maps one control library to the security frameworks and outside counsel guidelines you’re held to, so you answer every security questionnaire with current evidence.
Every major client sets its own security requirements, the data is privileged, and it lives in more places than any one team controls.
Outside counsel guidelines and client security questionnaires now require proof, often different requirements from every major client.
You hold privileged, highly sensitive client data, and a single exposure can end relationships and trigger ethics obligations.
Client data spreads across document management, email, and co-counsel, making consistent control hard to prove.
Clients, bar rules, privacy law, and assurance frameworks, one control library. Each tile shows who sets it, what it asks, and the shared control Compyl evidences once.
Security requirements clients impose as a condition of engagement.
The report clients most often request as proof of security.
A certifiable ISMS, often required by international clients.
Reasonable efforts to prevent unauthorized disclosure of client information.
Personal data of EU clients, employees, and matter parties.
Reasonable security and privacy rights for California residents.
Applies when you act as a business associate to healthcare clients.
Client payments and trust-account card transactions.
Define controls once and cross-map them to SOC 2, ISO 27001, GDPR, CCPA, and each client’s outside counsel security requirements.
Compyl drafts questionnaire responses from your live control evidence, so security reviews stop slowing down client onboarding and new matters.
Continuously assess the document platforms, e-discovery vendors, and co-counsel who touch client data, and quantify exposure in dollars.
Compyl maps each control and its evidence across every framework and client requirement, so a single artifact, pulled automatically from your stack, answers every review at once.
All cross-mapped to one control library. Explore each, or see the full library of 70+.
“It has brought a sense of relief to my life because, for the first time, we have a real solution in place that is proactively keeping us protected.”
Plenty of tools store a policy. Compyl runs the whole program, controls, evidence, questionnaires, and vendors, across every client you answer to.
Controls, evidence, risk, and vendors in one connected system, across every client and framework.
Evidence refreshes automatically and is scored for health, so you are review-ready every day of the year.
Document management, identity, cloud, and email systems feed evidence automatically.
AI drafts questionnaire answers, maps controls, and triages risk; your partners approve every decision.
FAIR-based quantification turns client-data and vendor risk into numbers firm leadership can act on.
Law firms and legal departments must protect client confidentiality and privilege while increasingly proving it to clients through outside counsel guidelines (OCG) and security questionnaires. Most pursue SOC 2 and ISO 27001 for client assurance, and handle GDPR, CCPA, HIPAA (for health clients), and PCI where payments are involved. Compyl maps one control library to all of them and answers client security questionnaires from your live evidence.
The recurring obligations behind legal-sector compliance, with the source that sets each one.
| Obligation | Source | Cadence | With Compyl |
|---|---|---|---|
| Attest to client security requirements | Outside counsel guidelines | On engagement and annually | Answers drafted from live evidence, per client |
| Complete security questionnaires | Clients and prospects | Every new matter or renewal | Questionnaire Assist with one knowledge base |
| Maintain a SOC 2 report | AICPA SOC 2 | Annual Type II period | Continuous evidence for every criterion |
| Hold ISO 27001 certification | ISO/IEC 27001 | Annual surveillance, 3-year cycle | Annex A controls monitored continuously |
| Protect client confidentiality | ABA Model Rule 1.6 | Continuous | Access, encryption, and monitoring evidenced |
| Notify after a personal-data breach | GDPR Art. 33 | 72 hours to the regulator | Incident workflow with the notification record |
Law firms and legal departments must protect client confidentiality and privilege, and increasingly prove security to clients through outside counsel guidelines and security questionnaires. Most pursue SOC 2 and ISO 27001 for assurance, plus GDPR, CCPA, HIPAA, and PCI depending on clients and payments. Compyl maps one control library to all of them.
Compyl maintains one knowledge base of your controls and live evidence, and drafts questionnaire answers automatically. Instead of re-answering each client’s review from scratch, your team approves AI-drafted responses backed by current proof, so security reviews stop delaying onboarding and new matters.
Yes. Compyl maps your controls to the security requirements clients impose through outside counsel guidelines, and continuously collects the evidence that proves them, so you can demonstrate compliance to each client with current data rather than point-in-time attestations.
Yes. SOC 2 and ISO 27001 are the frameworks clients most often require. Compyl automates evidence collection and continuous monitoring for both, and cross-maps shared controls so achieving the second framework reuses most of the work from the first.
Yes. Compyl continuously assesses and monitors the document platforms, e-discovery vendors, and co-counsel who touch client data, automates their security questionnaires, and quantifies exposure in dollars for firm leadership.
Issued July 29, 2024, it applies the duties of competence, confidentiality, communication and reasonable fees to generative AI. Lawyers must understand a tool’s risks, protect client information, may need informed consent before entering confidential data, and may not bill for time spent learning the tool.
Yes. ABA Formal Opinion 483 says lawyers must monitor for breaches, act promptly to stop them, restore systems and tell current clients when material confidential information is involved. Rule 1.6(c) separately requires reasonable efforts to prevent unauthorized access.
No. The transition to ISO/IEC 27001:2022 ended on October 31, 2025, and 2013-version certificates are no longer valid. Clients reviewing outside counsel now expect a 2022 certificate.
One control library, every client requirement, continuous evidence, and agentic AI that removes the busywork, with your experts in control.