Practice note
Legal-AI vendors say “hosted in Canada” a lot. Sometimes it means what a lawyer thinks it means. Often it does not. Here is how to read the claim, and the follow-up questions that make the real answer appear.
The problem with the phrase
“Data residency” sounds like one fact. It is at least four: where your files are stored, where they are processed, where the backups live, and where every sub-processor in the chain operates. A vendor can truthfully say “hosted in Canada” while the AI processing itself, the most sensitive step, happens on infrastructure in another country. That is not necessarily a problem. An undisclosed version of it is.
The practical reality of the current market is worth knowing: the frontier AI models that do serious legal work run on infrastructure operated by a small number of providers, and Canadian-resident inference at that tier is scarce. So when any vendor implies the AI step itself is Canadian end to end, that claim deserves your sharpest follow-up, not your relief.
The checklist
1. “Where is my data stored, where is it processed, and where are the backups?” Three answers, not one. An honest vendor gives them separately without being pressed.
2. “Name the sub-processors and their countries.” The AI model provider is the one that matters most. If the vendor will not name it, the confidentiality analysis cannot be done.
3. “Is anything used to train anything?” The contractual answer, not the marketing answer. Ask to see where the contract says it.
4. “How long does each party in the chain retain anything?” Named periods beat “industry standard.” A short, stated retention for AI processing inputs is a real answer; silence is also an answer.
5. “What does my client hear about all of this?” Whatever the architecture is, the client-consent and disclosure story has to describe it accurately. A vendor whose consent language does not match its own data flow has told you something important.
None of this is legal advice, and your own judgment about your obligations governs. The point is narrower: these questions have specific answers, and a vendor who has done the work can give them in writing.
Our own answer
CaseClarity’s answer to question one: your firm’s system, files, and backups live in Canadian regions, on a system built for your firm and used by no one else. Our answer to question two is the one vendors usually skip, so we put it on the security page in plain words: AI model processing runs on Anthropic’s API on US infrastructure, under a no-training contractual posture with data-protection agreements and short-cycle deletion, and the written client-consent workflow included with every deployment covers exactly that processing. We would rather state the exception plainly than sell you a residency the architecture does not have.
There is no contact form. We are a team you email: hello@caseclarity.ai