← All posts

News

Why We Stopped Offering Claude to Law Firms (and What a Secure Alternative Looks Like)

CaseMark stopped offering Anthropic's Claude models by default. Here is why: data retention, BAA limits, cost, and the long-term risk of single-vendor lock-in for law firms.

Scott KvetonSeptember 16, 20263 min read
Why We Stopped Offering Claude to Law Firms (and What a Secure Alternative Looks Like)

I sat in on a carrier-hosted Q&A call this past week where a group of defense firms were asking questions about AI. Good questions. The kind of questions I wish more firms were asking. But a few things said about Anthropic and Claude on that call worried me enough that I sent a note to the host afterward, and that note turned into this post.

About a month ago, CaseMark stopped offering Anthropic models to our customers by default. We still turn them on for firms that understand the tradeoffs and want them anyway. But the default is off, and I want to explain why, because I think every law firm using AI on client matters should understand these issues whether they ever touch our product or not.

Three things law firms should know about Claude and Anthropic

1. Zero data retention is no longer the default on Anthropic's best models

For a long time, one of the strongest arguments for Anthropic was zero data retention. You sent a prompt, you got a response, nothing was stored. That was a real differentiator for legal work.

In June 2026 that changed. Anthropic now requires 30 days of data retention on its newest models, which it calls "covered models" (Claude Fable 5 and Claude Mythos 5 as of this writing). That retention applies on every platform where those models are offered, including AWS. If your organization has a zero data retention agreement, you cannot use the covered models at all unless you turn retention back on for that workspace.

Anthropic says the retention exists to support its safety work and that the data is deleted after 30 days. I believe them. But "your client's medical records sit on a third party's servers for a month" is a very different sentence from "nothing is stored," and most attorneys on that call did not know the sentence had changed.

Older Claude models still qualify for zero data retention. The models people actually want to use do not.

2. A BAA is available, but probably not for the way your attorneys are using Claude

I want to be precise here because this one gets garbled. Anthropic does offer a Business Associate Agreement. But it only covers specific commercial configurations: the first-party API and HIPAA-ready Claude Enterprise plans, with certain features disabled.

It does not cover Claude Free, Pro, Max, or Team plans. It does not cover Claude Cowork or beta features. And if your attorneys are pasting a plaintiff's medical chronology into the Claude app on a personal or team subscription, there is no BAA in the picture at all.

In my experience, that is exactly how most attorneys are using it. If your firm handles protected health information, and every insurance defense firm does, you need to know which door your people are walking through.

3. Training on customer data is a policy, and policies change

Anthropic states that retained data is not used for model training without a customer's permission. As of today, that is the policy, and I take it at face value.

Here is what I would ask a firm to think about. OpenAI's consumer products train on user conversations by default. Anthropic's consumer plans already retain everything you type. The line between "we retain it" and "we learn from it" is a line the vendor draws, and the vendor can move it. When you put case information into a frontier model provider's system, you are trusting not just today's terms but every future revision of those terms, and a future model that has absorbed your matter history is not something you can claw back.

I am not saying Anthropic will do this. I am saying the risk is structural, not a matter of any one company's intentions.

The cost problem nobody wants to say out loud

On top of all that, Anthropic's frontier models are expensive. Significantly more expensive than the open-weight alternatives that now match them on the legal tasks that make up the bulk of a defense practice: document review, deposition summaries, medical chronologies, drafting.

I shared a usage report with the call host that I will describe here in anonymized form. A large insurance defense firm, roughly 38 attorneys, running on CaseMark Workspace at a flat $3,500 per month. No overages. Real, daily use across the firm. That is the whole bill.

AI for law firms does not have to cost an arm and a leg. Anyone charging you that way is doing it wrong.

Single-vendor lock-in: what it looks like at the macro level

Step back from Anthropic specifically for a minute. The bigger issue is what happens when an entire profession routes its most sensitive work through one or two model providers.

We have watched this movie before. A platform starts out generous. Terms are favorable, prices are low, the product is delightful. The market consolidates around it. Then the terms tighten, the prices rise, and the switching costs are high enough that nobody leaves. It happened with cloud, with mobile app stores, with social platforms.

With frontier AI it is happening faster, and the stakes for law firms are higher, because the thing being locked in is not your marketing data. It is privileged client communications, work product, and medical records. Retention policies, training policies, and pricing are all being set unilaterally by a handful of companies, and every one of those policies has already changed at least once in the last twelve months.

A firm that depends on a single closed model has no leverage. You cannot audit the weights. You cannot host them yourself. You cannot take the model with you. You can only accept the next revision of the terms or start over.

What a secure alternative to Claude actually looks like

I run a legal AI company, so take this with the appropriate grain of salt. But these are the things I would insist on if I were a managing partner or a carrier's panel counsel manager evaluating any legal AI platform, ours included.

Open-weight models hosted in the United States. Open-weight models can be run on infrastructure you or your vendor control. Nothing goes to a frontier lab. Nothing sits in a retention window someone else defines. CaseMark runs on open-weight models hosted in the US, and that is a deliberate architectural choice, not a cost-cutting one. We have a BAA in place with every single one of our model providers.

Real compliance paper. SOC 2, HIPAA, and a signed BAA should be table stakes, and they should cover the product your attorneys are actually using, not a special enterprise configuration most of them will never touch. CaseMark is SOC 2 and HIPAA certified and signs BAAs as a matter of course.

Custom training on your firm's work. The next step beyond a generic model is one tuned to how your firm writes, how your carriers want reports formatted, and what your practice group considers a good work product. This is only possible with open-weight models, because you cannot fine-tune a closed frontier model on privileged data without handing that data over. We are building this into CaseMark on a per-firm basis and it is where I think the real value for mid-size firms lives.

Custom skills you own. Every CaseMark enterprise engagement includes custom skill development: repeatable workflows built for your firm's matters, your letterhead, your chronology format, your carrier reporting requirements. The skills are portable. If you leave CaseMark, they go with you. That is the opposite of lock-in, and it is the only honest way to sell this.

A vendor you can actually reach. When something goes wrong with a model at a frontier lab, you file a ticket. When something goes wrong at CaseMark, you call us. Mid-size firms do not need a vendor with a trillion-dollar valuation. They need one that picks up the phone, understands insurance defense, and will still be aligned with them when the terms of service change somewhere upstream.

We lean into open, on purpose

I have spent most of my career on the open side of technology. I helped bring OpenID and OAuth to prominence and co-founded the Open Source Lab at Oregon State. So it should not surprise anyone that CaseMark is built to be left.

That sounds like a strange thing for a CEO to say, so let me be concrete about what it means.

Your matter files are yours. Every document, transcript, summary, and chronology in CaseMark can be pulled out with an API key. Not a support ticket, not an export request that takes six weeks. An API key you control.

The skills are yours too. Every default skill on the platform and every custom skill we build for your firm is portable. They are built on an open standard, published through agentskills.legal, and they run anywhere that supports that standard. If you decide next year that a different vendor or your own internal team should run them, take them and go.

The models are open-weight, which means the thing doing the work is not a black box you rent by the month from a lab that can change the terms on you.

We do not believe in lock-in. It is a compelling business model, and it has made a lot of software companies a lot of money, but it is an old school business model and it is not good for our customers. The only reason a firm should stay with CaseMark is that we keep earning it. If we ever stop, I would rather you be able to walk out the door with everything than stay because leaving is too painful.

That is also why I can write a post like this one about a much larger competitor without worrying about it. The argument here is not "trust us instead of them." It is "insist on terms that do not require trust." Any vendor worth working with should be able to meet them.

What I told the call host

I closed my note to the host with a promise to keep showing up to these calls, and I meant it. The point of the calls is to help firms make good decisions about AI, not to sell them CaseMark. But good decisions require accurate information, and the information circulating about Claude and Anthropic right now is a mix of outdated, incomplete, and overly reassuring.

If your firm is looking for a secure alternative to Claude for legal work, start with three questions for any vendor: Where does my data live and for how long? Will you sign a BAA that covers the product my attorneys actually use? And if I leave, what do I take with me?

If you would like to see the anonymized usage report or talk through how this works for a firm your size, reach out.

Keep reading