Client facts never leave your perimeter.
Deployment that matches your risk posture, true data isolation rather than row filters, and a citation boundary that only abstracted proposition queries ever cross.

Deployment that matches your risk posture.
Standard secure cloud
For most firms. Each firm’s data lives in its own separate database with its own user management: structurally walled off from every other customer, not filtered out of a shared pool by a query clause.
Fully isolated, air-gapped deployment
On request, your firm receives Legawrite.AI as air-gapped legal AI: a self-contained deployment you can place inside a fully isolated environment, running against your own local, isolated model. No data leaves your walls. Built for firms, insurers and matters where “cloud” is not an acceptable answer.
True data isolation, not row filters.
Ingestion and connectors
Every matter has its own dedicated, private ingestion address. If an address is ever compromised, regenerate it in one click and the old one goes dead instantly. Connectors to Google Drive, Dropbox and NetDocuments Early access reach only the folders and workspaces you select, and NetDocuments access follows the permissions your document management system already enforces.
The citation boundary
Matter documents, party names and client facts stay in the firm’s tenant. Only abstracted, citation-free proposition queries cross into the verified corpus. In the air-gapped deployment, nothing crosses at all.
isResponsive() makes zero vendor calls
The eDiscovery engine runs entirely on hardware you control and makes zero calls to any AI vendor’s API. There is nothing for anyone to subpoena from us, because we never have your documents.
Your model, inside your walls
In the air-gapped deployment the model is local and yours. Nothing is metered, and nothing leaves the environment you control.
Audit logging
Who did what, when, to which resource. Non-negotiable in legal technology for compliance and malpractice defense, and the raw material of the sealed record.
Attorney checkpoints
Nothing files itself. The attorney is the decision-maker of record, by design. The system never practices law.
What the recent decisions actually say.
The risk is not AI per se. The risk is careless disclosure and weak vendor terms.
Courts applying settled privilege and work-product doctrine to AI tools have drawn a line between a client independently using a consumer chatbot under terms that permit training and disclosure, and attorney-directed use of an enterprise or on-premises tool with contractual confidentiality. Attorney direction, enterprise-grade tools and contractual confidentiality protections are the three things a firm must be able to show. On-premises and fully local deployment presents the cleanest posture because it avoids third-party disclosure entirely.
Three questions a law firm AI policy should ask about any AI system
- Who processes the input, and under what terms?
- Where does the data go, and is it used to train anything?
- Is the use directed by counsel, and is the record of that direction kept?
Compliance, controls and documents, in one place.
Legawrite.AI protects the security, availability and confidentiality of firm data. Here is where each framework stands, the 79 controls we operate, and the policies your security team can request.
Compliance


Policies your security review will ask for.
20 documented policies and charters. Request any of them, or the full set, and we will send them under NDA.
- Information Security PolicyRequest
- Access Control and Termination PolicyRequest
- Incident Response PolicyRequest
- Breach Notification PolicyRequest
- Business Continuity and Disaster Recovery PlanRequest
- Data Classification PolicyRequest
- Change Management PolicyRequest
- Network Security PolicyRequest
- Baseline Hardening PolicyRequest
- Vendor Management PolicyRequest
- Risk Assessment and Treatment PolicyRequest
- Personnel Security PolicyRequest
- Acceptable Use PolicyRequest
- HIPAA Internal Privacy PolicyRequest
- PHI De-identification Policy and ProcedureRequest
- Chief Information Security Officer PolicyRequest
- Risk and Governance Executive Committee CharterRequest
- IT Leadership Committee CharterRequest
- Board of Directors CharterRequest
- Company HandbookRequest
79 controls across 21 categories.
Every control below is operating today. Select a control to read what it does.
Secure engineering and architecture
8Isolation is structural, designed in, and reviewed before anything reaches production.
Per-firm database isolation
Each firm's data lives in its own separate database with its own user management, walled off structurally rather than filtered out of a shared pool by a query clause.
The citation boundary
Matter documents, party names and client facts stay in the firm's tenant. Only abstracted, citation-free proposition queries cross into the verified corpus.
Air-gapped deployment on request
A self-contained deployment runs inside a fully isolated environment against the firm's own local model. In that mode, nothing crosses the boundary at all.
Zero vendor calls in isResponsive()
The eDiscovery engine runs on hardware the firm controls and makes no calls to any AI vendor's API.
Environment separation
Development, test and production environments are logically separated, and sensitive data is prohibited outside production.
Source code access controls
Every source code change is logged and attributed, and repository access requires multi-factor authentication.
Source code change approval
Changes are tested, peer reviewed and approved before they deploy to production.
Secure development procedures
A secure development policy governs how systems are designed, built and maintained, including defined emergency change procedures.
Identification and authentication
10Only verified people reach systems and firm data, and only with the access their role requires.
Multi-factor authentication
Multi-factor authentication is required for all production platform access, which blocks credential-only attacks.
Production access management
Production access is provisioned, changed and revoked under documented access control procedures.
Access control procedures
Every access grant or change goes through a formal request and approval workflow with a recorded business justification.
Least-privilege production access
Production permissions are held to the minimum necessary, limiting lateral movement if a credential is compromised.
Infrastructure authentication
Unique credentials, SSH keys and multi-factor authentication are required for all production infrastructure.
Quarterly access reviews
Quarterly reviews find and remove dormant accounts, excessive privileges and unauthorized access.
Password policy
Password requirements for sensitive systems are documented and enforced.
Session timeout enforcement
Sessions end automatically after inactivity so unattended systems are not left open.
Matter ingestion address rotation
Every matter has its own private ingestion address. If one is ever exposed, it is regenerated in one click and the old address stops working immediately.
ePHI access authorization and monitoring
Access to ePHI is authorized under supervision and monitored on an ongoing basis to prevent unauthorized use or disclosure.
Cryptographic protections
3Firm data stays confidential in storage and on the wire.
Encryption at rest
Sensitive databases are encrypted at rest with strong encryption, protecting data even if storage is compromised.
Encryption in transit
Data in transit is encrypted with industry-standard protocols to prevent interception over public networks.
Production key management
Production keys are restricted to authorized personnel, with formal procedures for rotation and storage.
Data classification and handling
3Rules based on sensitivity govern how firm data is stored, moved, retained and destroyed.
Data classification and access control
Sensitive data is classified and restricted to authorized personnel, with handling rules set by sensitivity level.
Data retention and deletion policy
Retention periods and secure deletion methods are defined, so data is not kept beyond business need.
Firm data deletion at termination
Firm data is deleted or anonymized after contract termination, leaving no residual exposure.
Continuous monitoring
3Always-on visibility across systems, and a record of every action taken.
Audit logging
Who did what, when, to which resource. The record supports compliance and malpractice defense, and it is the raw material of the sealed record.
Centralized log collection and monitoring
Production logs are collected centrally to detect, investigate and respond to security events.
Login attempt monitoring
Login attempts are logged and monitored for unauthorized or suspicious patterns.
Network security
3Encrypted access paths, filtered traffic and continuous detection.
Secure connection requirements
Authorized personnel reach production only through encrypted channels such as TLS or VPN.
Firewall rule management
Firewall configuration is limited to authorized administrators, and every change is logged and reviewed.
Intrusion detection
Network traffic is monitored continuously, and suspected threats alert security personnel.
Web security
1Customer-facing systems are shielded from injection, fraud and abuse.
Web application firewall
A web application firewall filters malicious traffic, with rules reviewed by management every year.
Vulnerability and patch management
3Gaps are found and closed before they can be exploited.
Vulnerability scanning and remediation
External-facing systems are scanned regularly, and high-risk findings are remediated on documented timelines.
Patch management
Patches are applied promptly with automatic updates and routine compliance checks.
Penetration testing
Annual penetration testing identifies vulnerabilities, and high-risk findings are tracked to remediation.
Endpoint security
4Laptops, workstations and mobile devices are managed and hardened.
Anti-malware protection
Anti-malware and automated scanning protect production infrastructure on a scheduled basis.
Removable media controls
Sensitive data is prohibited on removable media, with rare exceptions requiring encryption and documented approval.
Mobile device management
Device management enforces security policy on all endpoints, with remote wipe for lost devices.
Secure workstation configuration
Workstations are configured to prevent unauthorized access to client data and ePHI.
Configuration management
1Documented baselines keep insecure configuration out of production.
Baseline configuration management
Production systems are hardened to documented baselines and deployed through infrastructure as code for consistent rollout and rollback.
Business continuity and disaster recovery
6Tested recovery plans keep the service running and data intact through disruption.
Business continuity and disaster recovery plan
Continuity and recovery plans are documented, tested every year and revised based on results.
Emergency operations continuity
Communication, responsibilities and escalation paths are defined in advance to keep operations running during a disruption.
Backup and restore testing
Backups run on a schedule, and restore tests confirm exact copies can be recovered after data loss.
Emergency access procedures
Documented procedures keep firm data and ePHI available during a disruption without weakening security controls.
Data preservation during system changes
Complete, retrievable copies of data are preserved before any system is moved, replaced or decommissioned.
Capacity and performance monitoring
Automated monitoring tracks capacity and performance against thresholds and alerts before availability is affected.
Incident response
4Practiced procedures for containment and clear communication.
Security incident logging
Security incidents are logged, escalated to leadership and analyzed for root cause.
Incident response procedures
Incident response procedures are documented, tested every year and refined from lessons learned.
HIPAA incident response policy
HIPAA incident response obligations are documented in policy and acknowledged by all personnel.
ePHI breach notification timeline
Business associates must report ePHI breaches within 60 days of discovery.
Governance
7Named accountability and written policy, reviewed on a fixed cadence.
Information security policies
Security policies and procedures are documented and reviewed every year.
Security roles and responsibilities
Security roles are documented and acknowledged by all personnel.
Information security officer designation
Designated security personnel own and oversee the information security program.
IT leadership committee meetings
IT leadership meets monthly to review security activity against organizational commitments.
Attorney checkpoints
Nothing files itself. The attorney is the decision-maker of record, by design, and the system never practices law.
Whistleblower mechanism
Anonymous channels let personnel report security concerns or fraud without fear of retaliation.
Disciplinary process
Violations of security policy lead to disciplinary action, up to termination.
Compliance
3Regulatory obligations are written down, owned and retained.
HIPAA Security Officer designation
A designated HIPAA Security Officer owns the security policies, with the role and contact details documented.
HIPAA Security Rule policy acknowledgment
HIPAA Security Rule obligations are written into policy and acknowledged by everyone who handles ePHI.
HIPAA documentation retention
HIPAA compliance documentation is retained securely for six years from creation.
Risk management
2Threats are identified, ranked and treated before they become incidents.
Annual risk assessment
An annual risk assessment addresses threats to the confidentiality, integrity and availability of firm data.
Security and privacy risk management
Documented processes govern how risks are identified, assessed, treated and reviewed.
Human resources security
4Screening, agreements and prompt offboarding for everyone with access.
Employee background checks
Candidates are screened before they receive access to systems or sensitive information.
Employee confidentiality agreements
Employees sign confidentiality agreements covering company and firm data.
Contractor confidentiality agreements
Contractors sign confidentiality agreements before receiving access to sensitive data.
Termination access revocation
A termination checklist revokes access, recovers credentials and returns assets within defined timeframes.
Security awareness and training
2Everyone is trained at hire and every year after.
Security awareness training
All personnel complete security awareness training at hire and annually.
ePHI privacy training
Personnel with ePHI access receive additional HIPAA privacy training at hire and annually.
Third-party management
6Vendors and subprocessors are held to the same standard we are.
Vendor management program
Prospective and existing vendors are evaluated every year against documented security requirements.
Business associate agreements
Business associate agreements bind subcontractors to HIPAA privacy and security requirements.
Business associate safeguards and reporting
Business associate agreements require appropriate safeguards and timely incident and breach reporting.
Contractor compliance flow-down
Subcontractors must flow compliance requirements down to their own processors.
Vendor confidentiality and privacy agreements
Vendor agreements carry confidentiality and privacy terms fitted to the services provided.
Contractual security commitments
Security commitments are written into the master services agreement and terms of service.
Change management
2Material changes are communicated before they land.
Material system change communication
Changes that affect security or availability are communicated to personnel with timing and expected impact.
Firm notification of major changes
Major changes that affect availability or functionality are communicated to firms before implementation.
Asset management
2Every production asset is known, owned and retired safely.
Technology asset inventory
All production assets are inventoried, classified and assigned an owner.
Secure media disposal
Media that held sensitive data is purged or destroyed so nothing is recoverable from retired equipment.
Physical and environmental security
2Facilities and hosting are protected against physical access.
Visitor management policy
Visitors sign in, wear badges and are escorted in secure areas.
Cloud provider physical access review
Hosting providers' physical access controls are validated in an annual vendor review.
No controls match that search.
Deployment is a purchase gate. Let’s clear it.
Tell us where your data is allowed to live and we will show you the deployment that fits.