Here is the problem. Legal AI would give you hours back on document review, on drafting, on the assembly work that consumes your staff's week. But the tools that do it want your client's deposition, the medical file, the financial records, uploaded to their servers. RPC 1.6 protects all of that, and the prevailing standard asks you to make reasonable efforts to prevent its unauthorized disclosure. Handing a client file to a third party is a disclosure. So the careful firm, your firm, stays on the sidelines, and the cost of caution is real: time savings you can't responsibly take.
You do not actually have a confidentiality problem with AI. You have a problem with where cloud tools send your data. Those are different problems, and the second is solvable by architecture.
The worry is well founded, because once a client's documents leave your control, you inherit a stack of questions you can't fully answer:
None of this makes cloud tools categorically improper. The reasonableness standard is fact specific and stops short of a ban. The diligence is real, though, and it lands on you, which is exactly why "just try the free tool" never sat right.
Running it in your office means the software runs on hardware your firm owns, on your network, away from a vendor's cloud. That flips the default from "everything leaves by design" to "nothing leaves unless you decide it does." In practice, it gives you the time savings while shrinking the confidentiality surface:
You get the hours back without making the trade RPC 1.6 wouldn't let you make.
We would rather tell you the truth than sell you a slogan, because the truth is what lets you sleep once you deploy:
National guidance has started mapping this terrain. ABA Formal Opinion 512 (2024) addresses generative AI; Opinions 477R and 483 cover securing electronic information and responding to breaches. All three are persuasive in Nevada and stop short of binding authority, yet they describe the diligence a careful firm is expected to have done. A tool that runs on hardware you own makes that diligence tractable instead of theoretical.
Cloud or on hardware you own, these questions separate a choice that protects confidentiality from a leap of faith. Before a client file touches any product, get plain answers:
A vendor who answers these plainly is one you can evaluate. One who won't has answered the most important question already.
DilloLex is the answer that runs in your own office: an appliance your firm owns that keeps your raw documents and the identities in them on your network, designed so the AI reasoning runs on the box itself, with no client or confidential content ever sent to any outside AI service. We document the exact data flow with your firm, in writing, before you go live, and we'll walk your team (and your malpractice carrier) through it, residual risk included. We're honest about what this changes and what it doesn't: running the AI on the box does not by itself discharge your RPC 1.6 duty. That candor is the point. It's how a careful firm finally gets the time back without compromising the duty that made it careful.
See the security architecture →Thirty minutes on the phone. Bring your RPC 1.6 questions and we'll answer them plainly, architecture included.