WOLF AI field guide
Security and confidentiality in qui tam software.
A qui tam matter carries a confidentiality obligation imposed by a court, not chosen by the firm. Software touching that material has to be evaluated against the seal, against the relator’s exposure, and against protected health information where the matter is a healthcare one.
Published · Last reviewed
Written and maintained by the WOLF AI product team and checked against the public sources cited on this page. It has not been reviewed by outside counsel, and it is not legal advice.
What do the numbers say?
A qui tam complaint is filed in camera and, under 31 U.S.C. § 3730(b)(2), "shall remain under seal for at least 60 days" and is not served on the defendant until the court so orders. Courts routinely extend that period, so the confidentiality obligation on the record set is measured in months or years, not weeks.
Of the more than $6.8 billion in False Claims Act settlements and judgments the Department of Justice reported for fiscal year 2025, over $5.7 billion related to matters involving the health care industry, restoring funds to programs including Medicare, Medicaid, and TRICARE.
Source: DOJ: False Claims Act settlements and judgments exceed $6.8B in fiscal year 2025
Comment 8 to ABA Model Rule 1.1 states that maintaining competence requires a lawyer to keep abreast of "the benefits and risks associated with relevant technology." Adopting an AI-assisted workflow and verifying what it produces are treated as two halves of the same professional obligation, not as separate choices.
Source: ABA Model Rule 1.1: Competence (including technology)
Who is this workflow for?
Firms writing the security requirements for a qui tam software evaluation, and the people who have to sign off on a tool that touches sealed material or a relator’s identity.
When it is the wrong tool. This is not a certification claim, a compliance opinion, or a substitute for your own diligence. It is also not legal advice about your obligations under a seal, which are set by the statute and by the court in your matter.
What documents and inputs do you need?
- The court’s order in the matter, and whatever the seal actually covers.
- The relator’s exposure: employment, identity, and the consequences of disclosure.
- Any protected health information in the record set, and the agreements that must exist before it moves anywhere.
- Your firm’s own approval requirements for tools that touch client material.
How does the workflow actually run?
- 1.Establish what the seal covers in this matter before evaluating any tool against it, because the answer is set by the court rather than by the software.
- 2.Ask each vendor what it retains, for how long, who can access it, and whether client material is used to train models.
- 3.Ask what is certified and what is not, and treat a vague answer as a negative one.
- 4.Agree PHI handling in writing before any healthcare record is shared, not after a pilot has started.
What does this look like in practice?
Illustrative scenario
Illustrative only — a constructed scenario. A firm is scoping a pilot on a matter currently under seal.
- The first question is not about the software. It is what the order in this matter permits, and that question goes to counsel.
- The vendor is asked four things in writing: retention period, access list, training use, and certification status.
- Two answers come back as an offer to discuss it on a call. The firm treats both as a no, and records them that way.
- The pilot is scoped to a matter that is no longer sealed, which costs the firm nothing and removes the question entirely.
What this does not show. Choosing a different matter for the pilot is usually cheaper than resolving the question, and it is a legitimate answer rather than an evasion.
What do you get out, and who reviews it?
- A written record of what each vendor claims, and what it declines to answer.
- An explicit decision about whether sealed material enters a pilot at all.
- A PHI handling agreement, where the matter involves healthcare records.
- Counsel owns every judgement about what the seal permits.
Where does this approach break down?
- WOLF AI holds no HIPAA attestation and has not completed a SOC 2 audit. The security page states the current controls plainly and lists what is not claimed.
- No independent security assessment has been published.
- Encryption in transit and at rest is table stakes and answers none of the retention, access, or training questions.
- What the seal permits in your matter is a legal question for counsel, and nothing on this page answers it.
Common questions
Is WOLF AI HIPAA certified or SOC 2 audited?
No to both. There is no HIPAA attestation and no completed SOC 2 audit, and the security page says so directly rather than implying otherwise. If a certification is a hard requirement for your firm today, that is a legitimate reason to wait.
How long is a qui tam complaint under seal?
Under 31 U.S.C. § 3730(b)(2) a complaint is filed in camera and shall remain under seal for at least 60 days, and is not served on the defendant until the court so orders. Courts routinely extend that, so plan around months rather than weeks.
Is client data used to train models?
Current data-handling practice, retention, and access limits are described on the security page and walked through directly during a demo. Ask the question in writing, of every vendor, and treat an unclear answer as a no.