Appendix A — Service Description

Last updated July 2026 · v.02

Required Appendix to the Master Services Agreement.

1. Overview of the Service

Clasp is a cloud-based legal operations and document management platform designed to support workflow automation, matter organization, document handling, and related operational functions. The Service is delivered as a hosted, multi-tenant software platform accessible through a web interface.

Customer receives seat-based access to the Service as specified in the applicable Order Form. The Service includes only the features and functionality made available by Clasp as of the Effective Date or expressly stated in an Order Form. The Service does not include any future features, modules, or enhancements unless separately purchased or agreed in writing.

2. Core Platform Components

2.1 Document Management

The Service provides tools for uploading, organizing, viewing, and sharing documents. Supported ingestion methods include:

  • direct user upload

  • imports from Google Drive, Dropbox, and OneDrive

  • client portal uploads

  • email ingestion

  • Clasp’s migration tool

Documents are processed using OCR (via Unstructured.io) for text extraction and indexing. OCR is read-only and does not modify document content.

2.2 Matter & Workflow Organization

The Service supports matter-level organization, including:

  • matter folders

  • task tracking

  • document grouping

  • lightweight activity logs showing significant actions

The Service does not currently include a customer-facing audit log module or reporting suite.

2.3 Search & Retrieval

Search functionality is supported through metadata, OCR-extracted text, and stored embeddings. Embeddings may persist until configurable deletion logic is implemented. Search does not transmit Customer Data to external large language models.

2.4 Public Sharing

Customer may share documents using:

  • time-limited signed URLs

  • email-based invitations

Public sharing is Customer-controlled. Clasp is not responsible for mis-addressed or forwarded links or access by recipients selected by Customer.

3. AI-Assisted Functionality

AI-Assisted Functionality is limited to internal, non-generative components that operate on metadata, embeddings, or derived representations of Customer Data. These components may support:

  • search relevance

  • document organization

  • workflow efficiency

  • draft time-entry suggestions based solely on metadata

AI-Assisted Functionality:

  • does not access document text

  • does not perform automated decision-making

  • does not transmit Customer Data to external large language models

  • does not generate legal advice, legal analysis, or document drafts

All outputs require human review and approval. AI-Assisted Functionality is further described in Section 7 of the Master Services Agreement.

4. E-Signature Functionality

The Service includes an electronic signature module that allows Users to prepare, send, and execute documents electronically. E-Signature Functionality:

  • is provided solely for convenience

  • is not a certified or qualified electronic signature system

  • does not include identity verification, notarization, or witness services

  • locks documents upon completion, creating immutable records that cannot be deleted or altered.

Clasp does not represent or warrant compliance with ESIGN, UETA, or any state-specific electronic signature requirements.

5. Integrations

The Service may interoperate with certain Third-Party Services, including:

  • cloud storage providers

  • email delivery services

  • authentication-related email delivery services (for OTP codes)

  • OCR vendors

  • messaging and notification services

Integrations are provided as-is. Customer’s use of Third-Party Services is governed solely by those providers’ terms. Clasp is not responsible for outages, configuration changes, or performance issues caused by Third-Party Services.

6. Hosting & Storage Architecture

Customer Data is stored in Google Cloud Storage in per-organization buckets. Clasp selects hosting regions and configurations; region selection is not configurable by Customer.

Clasp does not provide:

  • multi-region replication

  • disaster recovery RTO/RPO guarantees

  • secondary backup sites

  • cold-storage tiers (unless introduced in the future)

Clasp does not maintain separate customer-data backups outside of Google Cloud’s native durability and redundancy.

7. Security Architecture (Summary)

A detailed description of Clasp’s security measures is provided in Appendix B (Security Baseline). The Service includes:

  • encryption at rest using Clasp’s cloud infrastructure

  • OTP-based authentication

  • role-based access controls (Firm User, Admin, Super Admin)

  • enterprise-grade secrets management

  • administrative, technical, and physical safeguards consistent with Appendix B

Clasp does not represent or warrant compliance with SOC-2, ISO 27001, GDPR, HIPAA, CCPA, or any other regulatory framework.

Clasp does not currently provide customer-managed encryption keys. If introduced in the future, such features may limit or disable certain functionality.

8. Environments

The Service includes a single production environment. Clasp does not provide:

  • sandbox environments

  • staging environments

  • development environments

  • customer-specific environment provisioning

9. Usage Model

The Service is provided on a seat-based access model. Seat counts are specified in the Order Form.

The Service does not impose:

  • storage limits

  • bandwidth limits

  • API usage limits

  • file size limits

  • retention caps

unless expressly stated in an Order Form.

Clasp may implement automated true-up logic as part of future billing updates.

10. Support

Support commitments, if any, are defined exclusively in Appendix E (Support & SLAs). Appendix A does not create or imply any support obligations.

11. Professional Services

Clasp does not provide:

  • onboarding

  • implementation

  • migration

  • configuration

  • custom development

  • IT support

unless separately agreed in Appendix I (Professional Services).

12. Limitations & Exclusions

The Service does not include:

  • generative AI

  • automated decision-making

  • audit log reporting modules

  • custom development

  • future functionality commitments

  • DR/BCP guarantees

  • multi-region hosting

  • sandbox or staging environments

  • enterprise integrations not expressly supported

  • any feature not available as of the Effective Date unless separately purchased

Clasp is not responsible for outages, configuration changes, or performance issues caused by Third-Party Services.

13. Documentation

Clasp may provide user guides, technical documentation, and other materials describing the Service. Documentation is for informational purposes only and does not create contractual commitments.