Do you know what your team shared with public AI this week?
You cannot know, and that is the problem. Soverance installs a private AI server inside your office. Your attorneys use it through a simple chat interface. Nothing they type, and no document they upload, ever leaves the building.
The problem, seat by seat
One careless paste can touch a case.
Under deadline pressure, staff put case facts and records into whatever chatbot is at hand. Courts have already ordered attorneys to disclose and account for everything shared with ChatGPT, down to the Bates number.
Clients are writing AI into their terms.
Outside counsel guidelines increasingly restrict client material in public AI tools. A firm that cannot answer that questionnaire cleanly is risking the engagement, and a single confidentiality incident costs clients, not just fines.
The ban does not survive contact with phones.
Nearly half of employees admit pasting non-public information into public AI tools. No policy memo stops it, and no firewall reaches a personal device. What dries up shadow AI is an approved tool people prefer to use.
The risk is not using AI. It is not knowing where your client's records are going.
Your firm probably already uses AI, whether you approved it or not. Under deadline pressure, associates and paralegals paste case facts, medical records, and draft arguments into whatever chatbot is on their phone. Every one of those prompts becomes a record held by a third party.
That record can be subpoenaed. It can be swept into discovery. It can be reviewed by the provider's staff, retained under the provider's legal-hold policies, and stored in any country where the provider operates. Courts have already treated careless AI-assisted review as grounds for privilege waiver over tens of thousands of documents.
A written policy banning public AI does not stop this. It just pushes it out of sight. The only thing that stops shadow AI is an approved tool that is genuinely better than the shortcut.
The documents where AI helps most are the ones you are no longer allowed to put in it.
Think about what actually moves your cases: medical records, discovery productions, deposition transcripts, expert reports, damages analysis, settlement strategy. Nearly all of it is confidential, privileged, protected health information, or covered by a protective order.
That is exactly the material that courts and the AI providers themselves now say must not go into open AI tools:
- Federal courts have entered protective orders that bar confidential information from mainstream AI platforms by name, and at least one court has barred open AI tools for all discovery material in the case, confidential or not.
- Court systems have adopted policies prohibiting confidential, privileged, or health information in any AI that does not run on a private model, and some expressly direct counsel toward enterprise tools or locally hosted tools.
- Google's Gemini terms instruct users not to submit sensitive, confidential, or personal information to the free service. OpenAI's own privacy policy tells users to take special care in deciding what information they provide.
- Everywhere a specific order does not reach, the duty of confidentiality still does. Putting a client's chart into a tool that retains it on a third party's servers is an ethics question with an increasingly obvious answer.
So run the honest math. Public AI is available for the small slice of your work that involves nothing confidential, and off-limits for the large slice that does. In a plaintiff practice built on medical records, that means AI is permitted precisely where it is useless and prohibited precisely where it would pay for itself.
That leaves your firm two real options: do the heavy document work by hand forever, or use an AI that qualifies as closed. A machine inside your office, on your network, holding your data and no one else's, qualifies by architecture. The confidential work is not the exception it has to avoid. It is the entire reason it exists.
You do not have to take our word for it.
Three excerpts, quoted in full, from the orders and policies now governing what may go into public AI tools.
"The practical effect is that you may not upload, input, or submit Confidential Information into any mainstream AI tool like standard ChatGPT, Claude, Gemini, or similar platforms."
"It should be assumed that all information entered into a public model generative AI platform, such as ChatGPT, will immediately become public."
"Users must protect confidentiality and privilege when employing AI tools. Absent reliable assurances that inputs will not be (i) stored, (ii) reviewed by humans, or (iii) used to train models, public AI tools shall not be used with confidential, privileged, sealed, proprietary, or otherwise protected information. Counsel should consider (...) locally hosted tools with adequate security."
One machine. In your office. Under your control.
Soverance builds a dedicated AI workstation, sized to your firm, and installs it on your premises. Your team opens a chat interface in their browser, on your local network, and works the way they already work with AI: summarize this deposition, build a timeline from these records, compare this expert report against the chart, draft a first pass of this letter.
The difference is architectural, not contractual:
No third party.
There is no provider between your attorneys and the model. No account to subpoena, no vendor logs, no terms of service that change with a website post.
No training on your data.
A cloud provider promises this in a contract. Our machine cannot do it, because your data never reaches anyone who could.
Real deletion.
Deleting a conversation on our machine is a file operation your IT controls. No 30-day retention windows, no safety carve-outs, no backups in unknown jurisdictions.
Your logs, not theirs.
If a court ever asks what went into the tool, your answer is complete, local, and short: nothing left this office.
No per-token bill.
You buy the machine once. A firm processing thousands of pages of records per case never sees a usage invoice.
We handle everything: hardware, model installation, security configuration, on-site setup, team training, and ongoing support with a one-year hardware warranty.
Built by a forensic physician. Not by a software vendor.
Soverance was founded by a forensic physician with a health-law degree from Penn and more than a thousand medical-legal expert opinions delivered, working alongside an engineer who builds enterprise AI systems. We configure your machine knowing what a medical malpractice, personal injury, or mass tort practice actually does with a 3,000-page chart.
Generic AI vendors sell efficiency. We understand the medical record, the privilege problem, and the managing partner who carries the liability if either goes wrong.
What you can put in each tool, and where your data lives
| Dimension | Free public AI | Enterprise cloud AI | Soverance local AI |
|---|---|---|---|
| The case file: what you can work on | |||
| Medical records and personal information | No, the providers themselves say not to submit it | Only with a BAA and careful configuration | Yes, it never leaves your walls |
| Discovery productions | Courts have begun barring open AI for discovery material | Depends on each protective order | Yes, nothing is disclosed to a third party |
| Documents under a protective order or seal | No, recent orders bar mainstream platforms by name | A case-by-case call under each order | Yes, it qualifies as closed by architecture |
| Privileged strategy and work product | Becomes a record a third party keeps | Protected by contract, not by architecture | Yes, custody stays inside the firm |
| Where your data lives | |||
| Your prompts leave the office | Yes | Yes | Never |
| Used to train models | Yes, by default | No, by contract | Impossible by design |
| Human reviewers can read inputs | Yes, per the providers' own terms | Limited, for abuse review | No one |
| Prompt logs a third party holds | Yes | Yes, retained for provider monitoring | None exist |
| Deletion | Delayed, with legal and safety carve-outs | Governed by provider policy | Immediate, under your control |
| Terms can change unilaterally | Yes | Yes | You own the machine |
| Cost model | Free, because you are the product | Per seat, per token, forever | One-time, unlimited use |
Better models will come. Your firm already owns the platform.
The server is the platform; the intelligence on it is software. When stronger models are released, we install and tune them on the machine your firm already owns, as routine work under the maintenance plan. Your investment gets better with time instead of becoming outdated.
And because you own all of it, your firm is never hostage to a vendor's fate or a vendor's pricing. If anything ever happened to us, your server, your model, and your data would keep working exactly as they did the day before. That is the difference between buying an asset and renting a dependency.
And when your firm wants more than the standard interface, we build on top of it as separate projects: automations for your document types, integration with your case management system, routines that turn a repeated task into one click. Custom work, quoted per project, running on the server you already own.
Your clients are already asking about this.
Your clients hand you the most sensitive records of their lives: medical histories, finances, family matters. Being able to tell them, in one sentence, that those records never leave your building is a promise few firms can make. It matters just as much to the referring attorneys and co-counsel who send you cases.
And where institutional clients ask how their data is handled, your firm has an answer most firms do not. Corporate clients and institutions increasingly require their outside counsel to disclose how client data is handled, and many outside counsel guidelines now restrict putting client information into public AI tools without prior consent. Firms that cannot answer those questionnaires cleanly are putting engagements at risk.
Your firm can tell every client, in one sentence: our AI work on your file never touches the cloud. Confidentiality stops being only a duty. It becomes part of how the firm sells itself.
What this does not do
We sell to lawyers, so we will be precise.
A local AI does not make your records disappear from discovery, and we would never claim it does. It removes the third-party disclosure vector and keeps the chain of control inside your firm.
It does not eliminate the duty to verify. AI output, local or cloud, must be reviewed by a licensed attorney before it touches a filing. Courts have been unambiguous about that, and so are we.
And a local machine is only as secure as its setup. That is why we do not ship you a computer. We deliver a configured, hardened system, installed and supported, ready on day one.
Questions managing partners ask us
Our current tool is HIPAA compliant and SOC 2 certified. Isn't that enough?
Compliance certifications govern how a third party handles your data. They do not change the fact that a third party has it. Enterprise cloud tools still log prompts for their own monitoring and legal-disclosure obligations. Local removes the third party entirely, which is a different category of protection, not a stronger version of the same one.
Can't we just use public AI only on non-confidential material?
You can, and that is the policy most firms write. Two problems. First, in a records-heavy practice, the non-confidential slice is close to nothing, so the policy amounts to not using AI on real casework. Second, the policy depends on every attorney and paralegal correctly classifying every document, every time, under deadline pressure, on their own devices. One wrong call and the protected material is on a third party's server. A local machine does not depend on perfect judgment, because there is nowhere wrong for the document to go.
We already prohibit public AI at the firm.
So does almost every firm we talk to. The prohibition works on paper and fails on phones. The firms that actually control AI usage are the ones that provide an approved tool people prefer to use.
Is a local model as capable as ChatGPT?
For frontier research tasks, top cloud models still lead. For the work your firm does every day with sensitive material, summarizing records, building chronologies, comparing documents, first drafts under attorney review, current open models running on serious hardware are more than sufficient. We demo the machine on your own documents so you judge it on your work, not our claims.
If we go local, are our AI records still discoverable?
If they are relevant, yes. Discovery does not care where the AI runs, and a federal court has already ordered an expert's AI prompts produced even though the model ran on a private cloud server. What local changes is who controls the records. Your logs and your retention policy are yours, written before any dispute, instead of sitting inside a third party's legal department, subject to court orders you are never warned about. You answer discovery on your terms, from a complete record you control.
What if it breaks?
One-year hardware warranty, plus a support and maintenance plan. The machine runs on your network, so it keeps working even when a cloud provider has an outage on your filing deadline.
How much does it cost?
It depends on firm size and how many attorneys use it at once. Configurations start in the range of a mid-level associate's quarterly cost and pay for themselves against per-seat AI subscriptions and, more importantly, against a single privilege incident. Exact figures are presented in a specific proposal.
See it before you decide anything.
Bring us a redacted sample of the documents your team works with. We will show you the machine handling them, live, with the network cable in your hand if you want it.
No data leaves the room. That is the whole point.