Law Firm Automate Free AI consultation
Security

Security that meets the bar

Consumer AI tools move your confidential client documents across the internet under a terms of service you had no part in writing. Here you pick the boundary instead: a self-hosted deployment that keeps everything within your four walls, or a frontier model under an enterprise agreement your firm signs. You set which matters are eligible for which.

Self-hosted deployment

Your data never leaves

Everything in this section is true of the self-hosted path, where the models run on hardware your firm owns or on a single-tenant deployment inside your own cloud account.

100% on-premise deployment

The AI runs entirely on hardware inside your office. No cloud servers, no external hosting, no data center dependencies. Your firm owns and controls the physical infrastructure.

Zero external connections

The system operates on your local network only. There are no outbound API calls, no telemetry, and no data transmitted outside your building. Ever.

Attorney-client privilege protected

Because no data leaves your premises, you eliminate the risk of inadvertent disclosure through third-party AI services. Privilege stays intact by design, not by policy.

No third-party access

No external company can access, read, train on, or store your documents. Your data is never part of someone else's training set.

Frontier models

When the work needs the strongest model

For matters where capability has to win, the same interface routes to a frontier model under a commercial agreement your firm signs rather than a consumer terms of service. Each guarantee below is a term of the providers' enterprise agreements, which is what makes it printable.

Never used to train the model

Your matters are not used to train the model, on any route we offer: Claude, GPT and Gemini, reached directly or through Amazon Bedrock, Google Vertex AI or Azure OpenAI.

Zero-retention where supported

Zero-retention operation wherever the provider supports it, so nothing persists on their side after the answer comes back.

Inference stays in your region

Inference pinned to a region your IT team has already approved. Where a firm already holds a cloud contract, that usually means no new vendor and no new region for the security review to clear.

SOC 2 Type II underneath

Every route here runs on SOC 2 Type II audited infrastructure. That is the providers holding the audit, which is the report your client will actually ask to see referenced.

A BAA where PHI is involved

Where a matter touches protected health information, we sign a business associate agreement rather than leaving the question open.

You decide what is eligible

Matter-level rules govern which work is allowed to reach a frontier model at all, and everything that does carries the same audit trail and matter permissions as the self-hosted path.

Access control

Everyone has access, nobody has too much

Role-based permissions

Partners, associates, paralegals, and staff each get tailored access levels. Control who can use which AI features and access which document sets.

Unlimited users, no extra cost

Every employee at your firm gets access. No per-seat licensing, no usage caps, no reason to limit who benefits from the AI.

Authentication integration

Works with your existing identity provider: Active Directory, SSO, or other enterprise authentication systems your firm already uses.

Audit logging

Full audit trail of who accessed what and when, on either path. Meet compliance requirements and maintain oversight of all AI interactions within your firm.

Compliance

Built for legal compliance

ABA Model Rules compliance

Designed to align with ABA Model Rules of Professional Conduct regarding client confidentiality, competence in technology use, and supervision of AI tools.

State bar requirements

Meets the evolving state-level guidelines around AI usage in legal practice. On the self-hosted path, no data sharing means no gray areas around ethics opinions.

Data sovereignty

Self-hosted, your data physically resides in your office. On a frontier model, it resides in the region your IT team picked. Either way you know the jurisdiction, the applicable regulations, and who has legal access.

Air-gap capable

For firms with the strictest security requirements, the self-hosted system can operate completely air-gapped, fully disconnected from the internet while remaining fully functional.

Bring this page to your security review

Schedule a demo to walk through the architecture, or ask for the written security overview and hand it straight to the reviewer.