Security that meets the bar
Consumer AI tools move your confidential client documents across the internet under a terms of service you had no part in writing. Here you pick the boundary instead: a self-hosted deployment that keeps everything within your four walls, or a frontier model under an enterprise agreement your firm signs. You set which matters are eligible for which.
Your data never leaves
Everything in this section is true of the self-hosted path, where the models run on hardware your firm owns or on a single-tenant deployment inside your own cloud account.
100% on-premise deployment
The AI runs entirely on hardware inside your office. No cloud servers, no external hosting, no data center dependencies. Your firm owns and controls the physical infrastructure.
Zero external connections
The system operates on your local network only. There are no outbound API calls, no telemetry, and no data transmitted outside your building. Ever.
Attorney-client privilege protected
Because no data leaves your premises, you eliminate the risk of inadvertent disclosure through third-party AI services. Privilege stays intact by design, not by policy.
No third-party access
No external company can access, read, train on, or store your documents. Your data is never part of someone else's training set.
When the work needs the strongest model
For matters where capability has to win, the same interface routes to a frontier model under a commercial agreement your firm signs rather than a consumer terms of service. Each guarantee below is a term of the providers' enterprise agreements, which is what makes it printable.
Never used to train the model
Your matters are not used to train the model, on any route we offer: Claude, GPT and Gemini, reached directly or through Amazon Bedrock, Google Vertex AI or Azure OpenAI.
Zero-retention where supported
Zero-retention operation wherever the provider supports it, so nothing persists on their side after the answer comes back.
Inference stays in your region
Inference pinned to a region your IT team has already approved. Where a firm already holds a cloud contract, that usually means no new vendor and no new region for the security review to clear.
SOC 2 Type II underneath
Every route here runs on SOC 2 Type II audited infrastructure. That is the providers holding the audit, which is the report your client will actually ask to see referenced.
A BAA where PHI is involved
Where a matter touches protected health information, we sign a business associate agreement rather than leaving the question open.
You decide what is eligible
Matter-level rules govern which work is allowed to reach a frontier model at all, and everything that does carries the same audit trail and matter permissions as the self-hosted path.
Everyone has access, nobody has too much
Role-based permissions
Partners, associates, paralegals, and staff each get tailored access levels. Control who can use which AI features and access which document sets.
Unlimited users, no extra cost
Every employee at your firm gets access. No per-seat licensing, no usage caps, no reason to limit who benefits from the AI.
Authentication integration
Works with your existing identity provider: Active Directory, SSO, or other enterprise authentication systems your firm already uses.
Audit logging
Full audit trail of who accessed what and when, on either path. Meet compliance requirements and maintain oversight of all AI interactions within your firm.
Built for legal compliance
ABA Model Rules compliance
Designed to align with ABA Model Rules of Professional Conduct regarding client confidentiality, competence in technology use, and supervision of AI tools.
State bar requirements
Meets the evolving state-level guidelines around AI usage in legal practice. On the self-hosted path, no data sharing means no gray areas around ethics opinions.
Data sovereignty
Self-hosted, your data physically resides in your office. On a frontier model, it resides in the region your IT team picked. Either way you know the jurisdiction, the applicable regulations, and who has legal access.
Air-gap capable
For firms with the strictest security requirements, the self-hosted system can operate completely air-gapped, fully disconnected from the internet while remaining fully functional.
Bring this page to your security review
Schedule a demo to walk through the architecture, or ask for the written security overview and hand it straight to the reviewer.