What is Merlin?
Merlin is Lawmatics’ AI suite, designed to help your firm evaluate leads, gather the information needed to move cases forward, and get more done throughout your account. Each Merlin tool supports a different part of your workflow, working together to help your team save time, make informed decisions, and focus on the work that matters most.
Merlin includes:
Merlin Qualify — Evaluates new leads using your firm’s intake criteria and recommends next steps.
Merlin Engage — Communicates with leads to gather missing information and help move cases forward.
Coming Soon! Merlin Copilot — Helps you find information, answer questions, and build automations, and reports through a conversational AI assistant.
Merlin Qualify is an AI-powered lead evaluation tool that helps your firm assess new leads consistently, identify high-priority opportunities, and take action faster. Using your firm’s own intake criteria, Qualify provides clear recommendations and explains the reasoning behind each evaluation.
With Merlin Qualify, you can:
Automatically evaluate new leads using firm-defined criteria
Identify which leads to prioritize, refer out, reject, or review further
Review confidence scores and reasoning behind each recommendation
Trigger automations based on lead evaluation results
Refine your evaluation criteria over time using feedback
Merlin Engage is an AI-powered agent that communicates with leads to gather the information your firm needs to move a case forward. When a lead has not provided enough detail for Merlin Qualify to make a confident recommendation, Engage can automatically follow up, collect the missing information, and send the lead back to Qualify for another evaluation.
With Merlin Engage, you can:
Automatically follow up with leads when important information is missing
Have natural, goal-focused conversations tailored to your firm
Customize how the agent communicates to reflect your firm’s voice and communication style
Update matter information and re-evaluate leads automatically once a conversation is complete
Coming Soon!
Merlin Copilot
Merlin Copilot is an AI assistant built directly into Lawmatics that will help you find information, answer questions, and complete tasks without searching through your account. You will be able to chat with Copilot from anywhere in Lawmatics to get help with the work you’re already doing.
With Merlin Copilot, you will be able to:
Ask questions about a specific matter, including its status, history, and details
Build automations by describing the workflow you want to create
Create reports or one-time exports by asking for the data you need
Where Merlin Lives
Merlin Qualify, Merlin Engage, and the Activity Hub are all available under Merlin in the left navigation. Together, these tools give your firm a connected AI experience across lead evaluation, lead engagement, and everyday work in Lawmatics.
Merlin's Activity Hub
The Activity Hub shows what Qualify and Engage have been doing across your firm. It's the fastest way to see which leads are still inconclusive, which are actively being worked by Engage, and which have wrapped up.
Where to go next:
Coming Soon! Merlin Copilot
Safety, Security, and Data Protection in the Merlin AI Suite
All features of the Merlin AI Suite run on the same foundations:
Your data is never used to train AI models. Not by us, and not by our AI provider.
Your data is never used to train AI models. Not by us, and not by our AI provider.
Lawmatics does not train AI models on your data. We don't build, train, or fine-tune models, and your firm's information is never used to teach a model anything.
Merlin is built on models from OpenAI, accessed through their developer API.
Under OpenAI's API data-usage policy, data submitted through the API is not used to train or improve their models — their default since March 2023. OpenAI processes that data to return a result to us, not to improve their own products.
Nothing you put into Lawmatics is pooled with other firms' data, and nothing from your firm influences what Merlin says to anyone else.
Merlin only ever sees one firm's data — yours. The boundary is enforced by our servers, not by asking the AI nicely.
Merlin only ever sees one firm's data — yours. The boundary is enforced by our servers, not by asking the AI nicely.
Every AI product carries a version of the same risk: a system with broad access, when asked a clever question, might reveal something it shouldn't. We designed the firm boundary so it isn't a matter of the AI's judgement.
When you use Merlin, our backend issues a session permanently bound to your firm and your user account. Every request Merlin makes for data must present that session, and the system determines which firm from the session itself. Merlin has no way to name a firm and no way to ask for a different one — a request that tried would be rejected before touching any data.
A few consequences worth knowing:
Sessions carry an expiry, and can be revoked at any time — for a single user or for an entire firm. Removing a user from your firm invalidates their sessions. Revocation takes effect within five minutes.
Merlin's agent service is not a customer-facing API. Every request into it must carry both a short-lived signed service credential and a valid server-side session handle. Its compute runs in private subnets with no public IP addresses.
That service cannot read your data directly. It goes through the same permission-checked layer the Lawmatics application itself uses.
Merlin isn't handed a copy of your database. Each product has a defined and limited scope.
Merlin isn't handed a copy of your database. Each product has a defined and limited scope.
Merlin Qualify reads the lead's form submission and a set of standard matter fields — case value, practice area, marketing source, contact details, and your firm's custom fields. Qualify never opens, reads, or analyses uploaded files or attachments. Notes are off by default; with the Use Notes toggle on, Qualify reads up to 10 notes from the last 60 days.
Merlin Engage works from the lead's contact details, your firm's configured agent persona and settings, the conversation so far, and the same set of data that Qualify uses or produces. Engage uses that data to have the most effective and human-like conversation with your leads or clients; it doesn't have to ask for things it already knows.
Merlin Copilot sees what you'd see: it retrieves data through permission-checked tools, one request at a time, in response to what you asked. It doesn't pre-load your database.
One thing to know about Copilot access. For search and reporting questions — "how many leads came in from Google last month?" — Copilot works across your firm's records the way a report does. Navigating into an individual matter still respects that user's matter-level access, but Copilot is not yet a full substitute for your firm's matter-level restrictions. If your firm operates ethical walls or limits staff to assigned matters, treat Merlin Copilot access as you would firm-wide report access. It's controlled by a role permission that is off by default for everyone except administrators, and we'd suggest only giving Copilot to users who already have reporting access.
The AI doesn't get to make the decisions that matter without your permission. Merlin AI recommends, and you decide what actually happens each time, until you trust Merlin enough to delegate decisions.
The AI doesn't get to make the decisions that matter without your permission. Merlin AI recommends, and you decide what actually happens each time, until you trust Merlin enough to delegate decisions.
Merlin starts out recommending rather than acting, and you widen its latitude as you get comfortable. That progression is a setting you control, not something Merlin earns on its own.
Approval before sending. Merlin Engage can run in manual mode, where every proposed message pauses for a human to approve, edit, or reject before it goes out. Most firms start here, and some stay here permanently — it's a supported way to run, not a training-wheels phase. To get the most value out of Engage, firms do end up building trust and delegating to the agent.
Delegating over time. As you build confidence in how Merlin handles your leads, you can let it send without stopping for each message. The constraints in the previous section — opt-out, attempt caps, outreach windows, confidence gating, content boundaries — continue to apply either way. Delegating approval doesn't remove the guardrails; it removes the pause.
Escalation to a human. Merlin hands off — with a recorded reason — when a lead asks for a person, sounds frustrated, raises something sensitive, or goes outside your practice areas. Supervisor notifications for these always fire; they aren't a toggle someone can quietly switch off.
Honesty about being AI. You choose how Merlin Engage responds when a lead asks whether they're talking to a person: confirm it's AI and continue, or confirm and hand off to a human. You can supply your own disclosure wording, which Merlin uses word for word — useful if your state regulates AI disclosure. What you cannot configure is Merlin claiming to be human; that floor holds in every mode.
Preview before saving. For reversible changes, Merlin Copilot builds a preview and waits for you. When a request is ambiguous, it asks rather than guessing.
Hard limits sit outside the AI. The rules that matter most are enforced by the system around Merlin rather than by the model's judgement, so they hold even when the AI gets something wrong — and they keep holding after you delegate.
Hard limits sit outside the AI. The rules that matter most are enforced by the system around Merlin rather than by the model's judgement, so they hold even when the AI gets something wrong — and they keep holding after you delegate.
Merlin doesn't run loose inside Lawmatics — it runs inside a harness we built specifically to bound what an AI agent can do, and the constraints in that harness are enforced by ordinary, testable code rather than by the model's judgement. That distinction matters: instructions to a model are a request, and code is a rule.
Merlin can only reach a defined set of tools. Each product is given an explicit, limited set of operations, each with a strictly validated interface. A capability that isn't in that set doesn't exist in the code path, so no amount of clever prompting produces it — there's simply nothing to call. Merlin Engage, for example, is confined to sending a message, saving collected information to the matter, scheduling a follow-up, re-running scoring, and notifying your team.
The model's chosen action can be overridden before it happens. In Merlin Engage the model returns a recommendation, and that recommendation passes through a chain of checks in our own code that can rewrite or block it. These hold even when the AI picks the wrong action, which is the entire point of putting them there:
A lead who replies with a standard opt-out keyword — STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT — is opted out by the system. The engagement terminates, no further message is sent including the closing message, and your supervisors are notified. Carrier-level blocking backs this up independently. Opt-out phrased conversationally ("please stop texting me") is handled by the agent's opt-out path.
Follow-up attempts are capped. Merlin cannot decide to keep texting someone beyond the rules you set for it.
Follow-ups are held to the outreach window you configure, enforced when the send is scheduled. Initial outreach and direct replies to a lead's own message are sent regardless of that window.
Merlin cannot close a conversation out as qualified unless the underlying assessment is confident enough.
Runaway loops are bounded. An engagement that stops making progress is terminated cleanly rather than spinning.
Actions can require your approval before they happen. Approval isn't advice the model can talk its way past — where it's switched on, the workflow genuinely stops and waits for a person. You decide how much latitude to extend, and you can extend it gradually as Merlin earns your confidence.
Content boundaries are fixed, not configurable. Merlin Engage is bound to rules your settings cannot override: it is not a lawyer, it does not give legal advice, estimate case value, or promise outcomes, and it will never claim to be a person. It also never delivers a rejection — a lead can't infer from Merlin that their case was declined.
Testing can't touch the real world. When an engagement runs in test mode, the underlying operations short-circuit on our servers, so no real message, appointment, or record is created even if something upstream mishandles the test flag.
One thing we don't claim. Merlin Engage reads messages from members of the public, which means it processes text we don't control. Our approach there is to constrain what the agent is able to do rather than to try to detect malicious input — because a limit on capability holds regardless of what someone writes. We don't represent that we filter or sanitize the content of incoming messages.
We give you simple tools to help you meet AI regulation. Merlin Engage has configurable controls for AI disclosure, opt-out handling, contact windows and human supervision, so you can set it up to fit the communication rules that apply to your firm and your state.
We give you simple tools to help you meet AI regulation. Merlin Engage has configurable controls for AI disclosure, opt-out handling, contact windows and human supervision, so you can set it up to fit the communication rules that apply to your firm and your state.
AI communication is now regulated in a lot of places at once — state chatbot disclosure laws, federal and state texting rules, and your own bar's guidance on using AI at intake. More than a dozen states have chatbot disclosure laws on the books, and more arrive every session.
Two things are worth saying plainly. First, most of these duties land on your firm as the party communicating with the consumer, not on us as the software vendor — and several of them explicitly say you can't shift the blame to the AI or its vendor. Second, our job is to make those duties easy to satisfy. Below is what you can actually configure. None of this is legal advice, and the rules vary by state and by the kind of work you do — please run your setup past your own counsel.
AI identity. Merlin Engage will never claim to be a person. That's a fixed floor, not a setting, and it holds in every mode and every persona. When a lead asks whether they're talking to AI, you choose what happens:
Acknowledge & Confirm — Merlin confirms it's an AI assistant and asks permission to keep going with intake.
Escalate to a Human — Merlin confirms it's an AI assistant and hands the conversation to your team. This is the default.
Your wording, used exactly. In Acknowledge & Confirm mode you can supply your own disclosure text, and Merlin sends it verbatim rather than paraphrasing. That matters if your state prescribes particular language, or if your firm has wording it has already cleared. Because it's sent as written, the wording is yours to get right.
Merlin Engage can also announce its AI nature upfront. Today Merlin automatically discloses that it's AI when a lead asks. It does not automatically announce itself up front before the first message. Some states require proactive written disclosure before a written interaction begins, and for professions like law that requirement can be the stricter one — Utah is the clearest current example. If you practise somewhere with an up-front disclosure requirement, you can comply by giving your Engage agent the role of "AI Intake Agent" when you set it up, so it will introduce itself as such.
Opt-out. A lead who replies with a standard opt-out keyword — STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT — is opted out by the system: the engagement ends, no further message goes out, and your team is notified. Carrier-level blocking backs this up independently of our software. Opt-out phrased conversationally is handled by the agent's opt-out path. If you operate under state texting rules with their own stop-request requirements, this is the control to look at with your counsel.
Contact windows and frequency. You configure the outreach window Merlin uses when scheduling follow-ups, and follow-up attempts are capped so Merlin can't keep texting someone indefinitely. Note the boundary: the window applies to scheduled follow-ups. Initial outreach and direct replies to a lead's own message are sent regardless, on the reasoning that answering someone who just messaged you is the behavior they expect.
Supervision and records. Bar guidance on AI at intake consistently comes back to supervision — a responsible person able to review what the AI did. Merlin Engage gives you human approval before sending if you want it, escalation to a person with a recorded reason, supervisor notifications that always fire rather than being switchable, and a per-lead audit trail in the Activity Hub covering messages sent, replies, field updates and escalations.
Staying on the right side of the advice line. Merlin Engage is built for intake facts, not legal opinions. It's bound not to give legal advice, estimate case value, or promise outcomes, and it never delivers a rejection — a lead can't infer from Merlin that you've declined their case. Declination stays a decision your firm makes and communicates.
Consent. Leads typically get a message from Merlin Engage because they contacted you first, normally by submitting one of your forms. That means consent provenance lives with your intake form and your own consent language — worth reviewing alongside your Merlin setup rather than separately, to make sure you comply with email- and SMS communication opt-in rules that apply to your firm.
A visible record. Merlin's actions land in the matter's normal activity timeline, clearly marked as Merlin rather than as a member of your staff. The Activity Hub gives you a per-lead audit trail — messages sent, replies received, fields updated, escalations and why. Copilot users can delete their own conversation history.
Merlin runs on the same infrastructure as the rest of Lawmatics, under the same controls — it isn't a bolt-on running somewhere less protected.
Merlin runs on the same infrastructure as the rest of Lawmatics, under the same controls — it isn't a bolt-on running somewhere less protected.
In plain terms: your data is encrypted when stored and encrypted while it travels, it lives in Amazon's US data centres, it's backed up continuously with point-in-time recovery, only a small number of our staff can reach production systems and only through a controlled path, and an independent security firm tests our platform every year.
Specifics for your IT team are in the technical section below.
Compliance and independent review: SOC 2 Type 2 and HIPAA.
Compliance and independent review: SOC 2 Type 2 and HIPAA.
Lawmatics completes an annual SOC 2 Type 2 examination with Sensiba, an independent CPA firm, covering the Security, Availability and Confidentiality trust services criteria together with the HIPAA Security and Breach Notification Rules. Our current report covers 1 April 2025 to 31 March 2026 and is available to customers and prospective customers on request — contact support and we'll route you to the right person, and ask for a bridge letter if your review needs coverage since the report's end date.
Merlin and audit scope — worth being straight about. Merlin was still pre-release during our most recent audit period, so the service Merlin runs on was not part of that examination's population. It comes into scope for the next cycle. The platform Merlin reads from and writes to was in scope, and Merlin is governed by the same policies, change-management process, and infrastructure controls as the rest of Lawmatics.
Annual penetration testing. We engage an independent security firm to test the Lawmatics platform every year, with findings tracked to remediation and retested. Our 2026 test included provisioning two separate firms specifically to verify that one firm cannot reach another firm's data.
What HIPAA coverage means here. Many of our customers handle protected health information. Our HIPAA coverage is examined as part of the same annual report described above, against the HIPAA Security and Breach Notification Rules. Supporting controls include a Business Associate Agreement with our infrastructure provider, ePHI access and emergency-access procedures, encryption of customer data at rest, and a central breach register with defined notification processes. Note that there is no official HIPAA "certification" body — any vendor describing itself as HIPAA certified means a third-party assessment, which is what ours is.
Vulnerability management. Dependencies are scanned daily. Critical vulnerabilities are remediated within 7 days, high within 14, medium within 30.
For security and procurement teams: A condensed control summary.
For security and procurement teams: A condensed control summary.
For anything beyond this (detailed architecture, logging specifics, incident-response procedures, our SOC 2 report) contact support and we'll route you to our security team.
Architecture and isolation
Merlin's agents run in a dedicated service that is not a customer-facing API and exposes no documented public interface. Its compute runs in private subnets with no public IP addresses. Every request into it must present two independent credentials: a short-lived (5-minute) signed service token and a server-side session handle bound to a specific firm and user. All application-data access from that service flows through a controlled, permission-checked tool interface on our primary API; the service holds no credentials for the Lawmatics application database and maintains only a separate datastore for agent conversation state. Tenant context is derived exclusively from the session and cannot be supplied as a request parameter. Sessions carry a 24-hour expiry that slides forward while an engagement is actively running; they are revocable individually or firm-wide, and are invalidated by user removal or credential-version change, with revocation propagating within five minutes. Tenant isolation is enforced at the ORM layer by mandatory firm scoping on tenant-owned models, consistent with our Data Protection Policy requirement for logical separation by unique identifier.
Agent authorization and capability scoping
Each Merlin product is confined to an explicit set of operations exposed through a schema-validated tool interface; capabilities outside that set are absent from the code path rather than merely disallowed by instruction. In Merlin Engage the assessment model specifically is provisioned with no tool access at all — it emits a structured decision that deterministic workflow code then executes against a fixed operation set (message dispatch, field persistence, follow-up scheduling, re-scoring, supervisor notification). Merlin Copilot, by contrast, does execute actions on the user's behalf, mediated by that same permission-checked tool layer with preview-and-confirm interstitials for state-changing operations. Feature-level permission gates are enforced server-side for AI features and default to administrators only. Merlin Engage re-verifies session validity and the operator's effective feature permission before each resumption of a long-running engagement; a failed check terminates the engagement.
Known limitation — per-user permission enforcement.
Matter-level access enforcement is applied at the tool layer for individual-record retrieval, but search and aggregate operations currently execute at firm scope, equivalent to report access. Per-user and feature-level permission enforcement across the full tool surface is in active development. Firms with ethical-wall or matter-restriction requirements should scope Merlin access accordingly; the governing role permission is off by default for non-administrators. We'd rather state this plainly than have you discover it.
Deterministic controls
Safety-critical constraints are implemented in application code rather than model instructions, and are applied as an override chain over the model's proposed action: keyword opt-out suppression with independent carrier-level blocking, send-attempt ceilings, configured outreach-window enforcement on scheduled follow-ups, confidence-gated conversation closure, and loop-liveness ceilings that terminate a non-progressing run. Test-mode isolation is enforced server-side, so operations short-circuit before any external side effect regardless of client-supplied flags. Human-in-the-loop approval is available as a per-firm operating mode for Merlin Engage; where enabled, the workflow suspends and cannot proceed without an explicit human decision. AI self-identification is a non-overridable floor in Merlin Engage's instruction set, taking precedence over persona and tone configuration.
Adversarial input.
Merlin Engage processes untrusted inbound messages from members of the public. Our posture is capability restriction rather than input filtering: effects are confined to a fixed deterministic path, so a crafted message cannot cause an action outside that path. We do not represent that we filter or sanitize prompt content, and we would rather state that plainly than imply a capability we haven't implemented.
Model provider
OpenAI, via the platform API, under an organization- and project-scoped account. OpenAI's published API policy provides that API inputs and outputs are not used for model training. As part of our vendor review programme we hold OpenAI's SOC 2 Type 2 report on file, alongside their ISO/IEC 27001 (information security) and ISO/IEC 42001 (AI management system) certifications. Lawmatics performs no model training or fine-tuning on customer data.
Subprocessors supporting Merlin
Amazon Web Services (infrastructure hosting), OpenAI (model inference), and Langfuse (LLM observability and tracing). Twilio supports SMS delivery for Merlin Engage. All are tracked in our third-party risk management programme and subject to vendor security review. For the AI providers specifically, we hold both OpenAI's and Langfuse's SOC 2 Type 2 reports on file, and both also maintain ISO/IEC 27001 certification.
Auditability
Agent actions are written to the matter activity timeline with agent attribution. Engagement escalations persist structured reason codes. LLM interactions are traced for operational monitoring and cost attribution.
Infrastructure
AWS, us-west-1, single-region for all data-plane resources. Compute on ECS Fargate. Amazon RDS for PostgreSQL 17, Multi-AZ in production, storage_encrypted enabled, deletion protection enabled, encrypted snapshots, with 35-day automated backup retention and point-in-time recovery on the primary application database. Database instances sit in private subnets behind security groups with no public accessibility.
Cryptography
At rest: AES-256 with a minimum 256-bit key length, per our Encryption Policy; key management systems require MFA. In transit: TLS 1.2 minimum with TLS 1.3 supported (ALB policy ELBSecurityPolicy-TLS13-1-2-2021-06), HTTP-to-HTTPS redirection enforced on all listeners, HSTS preload at the load balancer.
Detection and monitoring
Intrusion detection providing continuous network monitoring, and infrastructure logging with automated alerting on anomalous activity — both tested without exception in our most recent SOC 2 examination. Amazon GuardDuty and Amazon Inspector, with ECR image scanning on push. AWS WAF with IP reputation blocking. CloudTrail and CloudWatch with alarming to on-call. Administrator account use is logged for retrospective investigation. Application-layer monitoring via New Relic and Sentry.
Endpoint controls
Workstation full-disk encryption, anti-malware, and screen lock at no more than 15 minutes — all tested without exception in our most recent SOC 2 examination.
Identity and access
Customer authentication via Auth0. MFA is mandatory for all users — authenticator app or SMS; email-based MFA is deliberately not offered, and users cannot disable their own MFA. Optional SSO via Google or Microsoft. Maximum three concurrent sessions per user; sessions expire after six hours. Role-based access control with firm-configurable roles. Internally: MFA enforced across AWS, GitHub, and Google Workspace, largely via SSO; documented and supervisor-approved access requests; privileged access and involuntary terminations revoked within one business day; user access reviews performed annually since 2026; root account use prohibited absent necessity; background checks on new hires.
Resilience
Multi-AZ RDS with automated failover; daily automated backups with point-in-time recovery and backup-failure alerting; Multi-AZ Redis; infrastructure redundancy through replication of critical components. Disaster recovery and business continuity plans are documented, include rebuilding in an alternate region from our infrastructure-as-code definitions, and are tested annually — as is our incident response plan. Backup, BCP/DR testing, and incident-response testing were each tested without exception in our most recent SOC 2 examination. We do not currently publish formal RTO/RPO targets.
Assurance and governance
Annual SOC 2 Type 2 examination by an independent CPA firm; current 2026 report issued and available under request. Independent third-party HIPAA assessment, current 2026 report available on the same basis. Annual third-party penetration test — the 2026 engagement included multi-firm provisioning to verify tenant isolation — with findings tracked to remediation and retested. Documented policy set covering information security, SDLC, change management, encryption, data protection, data classification, data retention, access control, vendor management, incident response, business continuity, and disaster recovery, maintained under a defined annual review cycle. A formal risk assessment and risk treatment plan is maintained, including AI-specific risks, alongside a third-party risk management programme for vendors; both were formalised as documented annual artifacts in 2026, and our most recent report notes exceptions in these areas for the prior period. Annual user access reviews across cloud infrastructure, source control, and identity were formalised on the same basis. Changes ship through pull requests with peer review required by policy and branch protection configured on the main branch, with a documented emergency-change path requiring retroactive approval. Vulnerability remediation SLAs: critical 7 days, high 14 days, medium 30 days.
Security FAQs
Security FAQs
Does Merlin train on our data?
No. Lawmatics does not train AI models, and OpenAI does not train on data sent through their API. Your firm's data is not pooled with any other firm's.
What AI models does Merlin use?
Models from OpenAI, accessed through their developer API and integrated directly into Lawmatics. Merlin is not the consumer version of ChatGPT, and your data is not visible in any consumer AI product.
Can Merlin see another firm's data? Can another firm see ours?
No. Every Merlin request is bound to a session tied to your firm, and the system determines the firm from that session rather than from anything the AI supplies.
Does Merlin read files our clients upload?
No. Merlin Qualify never opens, reads, or analyses uploaded files or attachments.
Will our leads know they're talking to AI?
Merlin Engage will never claim to be human. You configure how it responds when asked — confirm and continue, or confirm and hand off — and you can provide your own disclosure wording.
Can we require approval before Merlin sends anything?
Yes. Merlin Engage has a manual mode where every message waits for a human to approve, edit, or reject it.
Can we configure Merlin to meet our state's AI disclosure rules?
You can configure how Merlin responds when a lead asks whether they're talking to AI, and supply your own disclosure wording which Merlin sends verbatim. Merlin will never claim to be human in any mode. It does not currently announce that it's AI before the first message, so if your state requires proactive up-front written disclosure, check with your counsel before relying on Merlin Engage. See the section above for the full set of controls.
Does Merlin give legal advice to our leads?
No. Merlin Engage is bound to intake facts — it does not give legal advice, estimate case value, or promise outcomes, and it never communicates a declination.
What happens if a lead replies STOP?
The engagement ends and no further messages are sent. Opt-out is handled by the system rather than left to the AI, and carrier-level blocking backs it up.
Can we control who at our firm can use Merlin?
Yes — Merlin access is governed by a role permission that is off by default for everyone except administrators. Be aware that for search and reporting questions Copilot works across your firm's records the way a report does, so grant access with that in mind.
Can we get a copy of your SOC 2 report?
Yes. Our current SOC 2 Type 2 report and our HIPAA assessment report are both available on request — contact support and we'll arrange it.
How is our data encrypted?
Encrypted at rest with AES-256 and in transit with TLS 1.2 or higher. This applies to your whole Lawmatics account, including everything Merlin touches.
Do you publish uptime or recovery-time commitments?
Not currently. We maintain documented disaster recovery procedures and Multi-AZ database failover, but we don't publish formal RTO/RPO targets. If you need these for a vendor assessment, contact us.








