Stays on your network
No inbound internet access. Encrypted disk. Raw files processed locally.
The AI runs on the box
Drafting and analysis are built to run on the appliance your firm owns, right inside your office.
Every connection is mutually authenticated
The appliance connects over mutual TLS. Both ends present a certificate and each verifies the other before any traffic moves, so a stolen password alone gets nobody in.
No AI account to keep
No API key, no per-token bill, no outside model in the loop. The reasoning lives on hardware your firm owns.
What leaves the building, and what doesn’t.
One honest table beats fifteen hedges. If a vendor cannot give you this table, ask why.
The appliance accepts no inbound connections; every connection it makes, it initiates. It does reach your own cloud storage if you connect it, so it is not sealed off from the internet. The scope is that no outside AI service is in the loop.
Three questions to ask before you upload anything.
The duty does not transfer to a vendor when you click accept.
Where does the reasoning physically happen?
If the answer is a data center, your client files are leaving the office. Ask for the location, not the marketing word for it.
What happens to our files if we stop paying?
With a subscription, access ends and your work product sits behind someone else’s login. With an owned appliance, nothing happens.
Is our content used to improve the model?
Ask for it in writing, and ask what “aggregated” or “de-identified” means in their contract. Here the question does not arise: no outside model sees it.
The rest of the security model.
No, and any vendor claiming that about a machine that syncs your storage is being loose with the truth. It accepts no inbound connections and sends no client content to an outside AI service, but it does reach the cloud storage and managed-service tools your firm selects.
The appliance calls out to public court and legislative sources to stay current. No matter data goes with the request.
Access follows the folder structure and permissions your IT already set. There is no separate vendor-side account list to audit.
No, and no product does. What it changes is the diligence: no third-party AI processor to vet, no cross-border transfer question, no vendor breach that reaches your client files.
Your matter files live where they always did — your local path or mapped drive — so a replacement machine picks up where the last one stopped. The disk is encrypted at rest.
Book thirty minutes.
We will walk you through the data flow description before the system goes live.
Every day, 8am to 8pm. A founder answers — never a salesperson.