Claude for Lawyers
Harvey AISecurityConfidentialityLegal EthicsLegal AI

Harvey AI Security: No-Training Terms, Walls, SOC 2 (2026)

Claude for Lawyers··9 min read

Short answer: Yes, Harvey AI is built to be confidential, and most of what it claims is published and auditable. As of September 2026, Harvey's security page states that it does not use inputs, outputs, or uploaded documents to train underlying models, that this commitment is made contractually through its Platform Agreement, that it requires zero data retention from its model providers, and that it enforces firms' existing ethical walls. Its trust center lists SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, and AIUC-1. What Harvey does not publish is a private-cloud or on-premises deployment option, or the names of its sub-processors on the public page. This article separates what is stated, what is in the contract documents Harvey posts, and what a firm would need to confirm in its own agreement.

Is Harvey's no-model-training commitment contractual?

According to Harvey, yes. The security page contains two relevant statements, which we quote exactly because the wording matters for a confidentiality analysis: "We don't use inputs, outputs, or uploaded documents to train underlying models," and "Harvey contractually guarantees through our Platform Agreement that your data stays yours." The same page says "Harvey contractually prohibits model providers from training on customer data" and "Harvey requires Zero Data Retention (ZDR) by model providers." The page also notes an opt-in exception: a firm can explicitly request a bespoke model trained on its own data, in which case that model is created exclusively for that firm.

Two caveats a careful buyer should note. First, we could read the Platform Agreement's public Security Addendum, which states that it "is part of Your Terms with Harvey" and commits to AES-256 encryption at rest, TLS 1.2 or better in transit, annual SOC 2 Type II and ISO 27001 assessments, and breach notification within 48 hours; but the addendum itself does not contain the no-training language. That language would sit in the Platform Agreement or a data-processing addendum that Harvey does not appear to post publicly. So the accurate statement is: Harvey publicly represents that the no-training commitment is contractual, and the enforceable text is in the customer agreement, which your firm should read before signing. Second, "underlying models" is the operative phrase; ask whether the same restriction covers any fine-tuned or Harvey-trained models, since the company launched its own fine-tuned legal model, Tenet, in 2026.

How Harvey handles data: what is published

  • Hosting. Harvey runs on Microsoft Azure, per both the security page and the trust center. Regional processing is offered in the EU and Switzerland or in Australia for customers with residency requirements.
  • Model providers. Harvey uses models from OpenAI, Anthropic, and Google. Its May 2025 announcement says the Anthropic and Google models are accessed through AWS Bedrock and Google Vertex under Harvey's existing security standards. The security page says all model providers are held to zero data retention and a no-training prohibition. See does Harvey use Claude? for the model detail.
  • Encryption. AES-256 at rest and TLS 1.2+ in transit, per the Security Addendum.
  • Retention and deletion. The security page says customers set retention policies and can delete data at any time. The public addendum does not specify post-termination deletion timelines; ask for them.
  • Testing. Automated vulnerability scans and annual third-party penetration tests, per the security page.
  • Sub-processors. The security page says sub-processors and external model providers are held to the same obligations but does not name them on the public page; the trust center is the place to request the list.

Ethical walls and permissions

This is the area where Harvey's enterprise design shows most clearly. The security page states that "Harvey syncs and enforces your firm's existing ethical wall policies," blocking restricted users from accessing or sharing walled content, and that Harvey never creates, modifies, or deletes walls itself; the firm's wall provider stays authoritative. The mechanism is a partnership with Intapp announced in February 2026 and described as generally available in Harvey's July 23, 2026 post: when a wall is created or updated in Intapp Walls for AI, Harvey automatically syncs the policy across Threads, Vault, Review Tables, and Shared Spaces. Document-management integrations follow the same principle; Harvey's NetDocuments help article notes that a user who cannot access a document in NetDocuments cannot upload it into Harvey.

For a solo or small firm this is mostly informational: you do not run Intapp, and your conflicts process lives in your practice-management system. But it illustrates a general rule for any AI tool: the tool should inherit your access controls, not replace them.

Certifications, as published

FrameworkStatus per Harvey trust center (Sept 2026)
SOC 2 Type IICurrent; 2026 audit completed; annual
ISO/IEC 27001Certified and renewed
ISO/IEC 27701 (privacy)Certified
ISO/IEC 42001 (AI management)Certified
AIUC-1 (AI security)Certified by Schellman
IRAP (Australia)Attestation listed
GDPR, CCPA, EU AI ActCompliance listed

Source: trust.harvey.ai. Report copies typically require an NDA request through the trust center. We did not find HIPAA listed on the trust center page at the time of writing, although some third-party directories claim it; if you handle PHI, confirm directly. The security page also says Harvey's audits are conducted by Schellman.

Deployment options: what Harvey does and does not offer

Harvey's published materials describe a multi-tenant cloud service on Azure with regional options. We found no published private-cloud, customer-VPC, or on-premises deployment offering as of September 2026. Some third-party articles describe "private" deployment for Harvey; we could not verify that against anything Harvey itself publishes, so treat it as unconfirmed and ask the vendor. For most law firms this is a non-issue (the same is true of nearly every legal AI vendor), but firms with government or defense clients that require single-tenant or on-prem hosting should ask early.

How do customers perceive Harvey's data security and privacy protections?

Positively, on the limited public record. The review roundup at The Legal Prompts reports that Gartner Peer Insights reviewers specifically praise Harvey's security posture, and security does not appear among the recurring complaints in any editorial review we found (pricing, unused seats, and onboarding do). Harvey's September 2026 acquisition of Guardrails AI, an AI reliability and testing company, per Artificial Lawyer, points the same direction. More on sentiment in what Harvey customers say.

How this compares to using Claude directly

Since Harvey runs Claude among its models, the comparison is really about the wrapper. Anthropic's pricing page states that Team and Enterprise plans do not train on your content by default, and Enterprise adds SSO, audit logs, and admin controls. Anthropic publishes its own SOC 2 Type II and ISO 27001 status at its trust center. What you do not get on a Claude Team plan is Intapp wall sync or DMS-level permission inheritance; at small-firm scale you manage that with Projects and user access instead. Our practical guidance for confidential matters on Claude is in Claude AI pricing for lawyers (which plan for client work) and AI legal ethics under the ABA rules. For the head-to-head, see Claude vs Harvey.

The ethics overlay

Whatever the vendor promises, ABA Formal Opinion 512 puts the confidentiality duty on the lawyer: understand how the tool handles data, get informed consent where required, and do not assume a certification substitutes for reading the terms. Our AI disclosure guide covers when clients and courts need to be told.

Frequently Asked Questions

Related Reading

Get strategies like this every week

The 5-Minute Claude Briefing — one prompt, one ethics insight, one workflow strategy. Free, weekly, built for lawyers.

Subscribe Free