LexSteward
Pillar 5 · Private by default

Privilege-grade, by default.

No training. No retention. Never a consumer chatbot. Your clients’ data is processed by a frontier model under a signed BAA, in a confidential, zero-data-retention environment that retains nothing and trains on nothing. Below, in plain English: which AI runs, where your clients’ data goes, and what we will never do with it — the vendors, the contracts and the commitments, not a model version we might swap next quarter. You carry your own confidentiality duty; this is built to help you meet it.

Confidential AI

Built to protect privilege — not just promise it.

Most AI tools ask you to trust a policy. LexSteward is built so confidentiality is the architecture — and so you can show it, to a client, a partner, or a bar reviewer.

No training, no retention

Your clients’ data is processed under a signed BAA in a confidential environment that retains nothing and trains on nothing. Never a consumer chatbot. Every firm is isolated to its own data and every AI action is logged. A self-hosted model inside our own boundary is on the roadmap.

Only what’s needed ever leaves a matter

Before anything is processed, we strip the personal details the task doesn’t need. “Minimum necessary,” applied automatically.

Nothing is kept that shouldn’t be

Prompts and answers aren’t logged or retained after the work is done.

One matter can’t leak into another

Each matter’s information is isolated; the AI working one case can’t surface another client’s details.

A record for every matter — that you can verify

Every AI action is written to a tamper-evident log (what ran, where, with your sign-off), built so tampering is detectable.

You carry the confidentiality duty. This is built to help you meet it — and to prove you did.

For your clients’ data: a confidential, zero-data-retention environment

Anything touching your clients’ data runs on Anthropic’s Claude via Amazon Bedrock, under a signed BAA, in a confidential configuration that retains nothing and trains on nothing. Your clients’ data is never kept by the provider, never used to train a model, and never mixed with another firm’s. Self-hosted open-weight models running fully inside our own boundary are on the roadmap — they are not what runs today, and we would rather say so than let you assume it.

What we contract for, in writing

The protection is contractual and architectural, not a promise that no vendor is involved: a signed BAA, zero data retention, no training on your data, and a confidential compute configuration, with per-firm isolation and a full audit log of every AI action. Nothing Ward produces acts, sends or bills without your approval.

The strong model plans; the efficient ones do the work.

Rather than send every task to one big model, a stronger model breaks the work into steps, lightweight models carry them out, and the stronger one checks the result. You get high-quality reasoning without paying frontier prices for routine work — and for your clients’ data, every model in that chain runs under the same BAA-backed, zero-retention contract, so the efficiency never costs you privacy. Nothing in the chain trains on your matters or keeps them afterwards. We’re rolling this out; you never pick or manage any of it — the system does.

You’re always in control.

The AI proposes; you approve. Anything legal, client-facing, billed, or deadline-related waits for your one-click sign-off. You choose your plan (which sets your AI’s power and capacity) and your spend cap, and you set a spend cap. The AI is sized to your plan, and we’ll always warn you before any limit — never cut you off mid-work. You never have to pick or manage a model; the system selects the right one for each task.

It shows its work.

Ward’s answers are grounded in your own files — not the open web, and not a guess. The next layer makes that visible everywhere: an exact, openable pin-cite behind every grounded fact, and a // verify flag where there’s no source yet, so you can check any line against its source. That provenance layer is rolling out; grounded answers are live today.

What we never do

Send your clients’ data to a consumer chatbot, or to any model without a signed BAA and zero-data-retention terms.
Retain or train on your clients’ data.
Move money, file, or contact a client without your approval.

Where each kind of work runs

Where each kind of work runs. To be exact about a word this page uses a lot: “governed” describes the contract and the controls, not a network perimeter — your isolated tenant, a signed BAA, zero data retention, no training, and a full audit log. It does not mean your data stays on our machines: as the table shows, it is processed by Anthropic’s Claude via Amazon Bedrock under those terms. Cloud-first; your data region is set when you sign up and stays fixed.

The work The brain Where it runs Data leaves the boundary?
Your clients’ / privileged data Anthropic’s Claude via Amazon Bedrock Processed under our signed BAA in a confidential, zero-data-retention configuration. Never retained, never used for training, isolated per firm. Yes — to Bedrock, under BAA + ZDR
Product help, general chat, marketing / SEO / content (non-client) Anthropic’s Claude via Amazon Bedrock Same contract. This is not client data. Yes — to Bedrock, under BAA + ZDR
Heavier frontier work you route explicitly Anthropic’s Claude via Amazon Bedrock Same contract; metered so you see what it costs. Yes — to Bedrock, under BAA + ZDR, metered

Your clients' data is never trained on, and never kept.

Confidentiality isn't a setting — it's the architecture. What this means in practice:

Contracted, not just promised

Your clients' privileged data is processed under a signed BAA with zero-data-retention terms in a confidential configuration. It is never retained by the provider, never used to train a model, and never mixed with another firm's. That is a contract you can read, not a claim you have to take on faith.

Built for your confidentiality duty

Built for the confidentiality and privilege standards your practice is held to. The same wall that runs legal work governed also keeps client data out of the AI training loop and the AI vendor's retained logs — by contract, not policy.

Provable, with a report

The confidentiality report — routing metadata, model used, opt-in log and a signed boundary assertion for any matter — is in preview and not switched on yet. What is live today is the audit log underneath it: every AI action on a matter is recorded and exportable.

The licensed attorney of record remains responsible for all legal work product and for the privilege analysis. This boundary architecture is a tool to help you meet your duty — not a substitute for it.

Who holds the key

Your data is encrypted at the field level. Two postures, depending on your tier.

Every plan

Your own revocable key.

Each firm’s data is encrypted with a key unique to your firm, isolated from every other tenant, and the key is never shared with a model provider. Revoke it and the data is cryptographically unrecoverable (crypto-shred). Your data region is set at signup and stays fixed. We administer the key on your behalf so the system can run for you.

Sovereign · by engagement, not yet generally available

You hold the key.

For firms with a hard data-sovereignty requirement, Sovereign adds bring-your-own-KMS: the key lives in your control, with dedicated AI capacity and tighter controls for protected content. The design goal is true zero-knowledge, so that we would become technically unable to read your protected content — not a shipped configuration today, delivered by engagement. Talk to us about your requirements and timeline.

Talk to us about Sovereign

Your data is yours — and getting it out is one click.

Confidentiality is only half of trust. The other half is never losing the work. Today that rests on full on-demand export: everything you put in, out again, anytime, in open formats. The automated backup and disaster-recovery programme below is designed and not yet running — we would rather tell you that than let you assume a safety net you do not have.

Not running yet. Everything in this section is the backup/DR design we are building to. Until it ships, treat export as your backup: export on a schedule that suits you, and keep a copy under your own control.

Continuous backup (planned). Automatic backups with point-in-time rollback, so a bad day costs minutes rather than days. Designed, not yet running.
Immutable copy (planned). At least one copy that cannot be altered or deleted, even by an attacker. Designed, not yet running.
Independent locations (planned). Copies in more than one place, including one outside our main host, so no single failure can wipe it out. Designed, not yet running.
Canadian residency (planned). When Canadian residency ships, it will hold all the way down to backups. Canadian residency is not live today.
Tested restores (planned). Restores exercised automatically, because a backup nobody has restored is not a backup. Designed, not yet running.
Always yours to take (live). Export everything, anytime, in open formats. There is no lock-in and no export fee. (Scheduled export to your own storage arrives with the backup/DR work above.)

No one can promise nothing will ever break. What we can promise today is that your data is never trapped: export is live, complete, and one click. We will say so here the day the backup programme above is running and rehearsed — and not a day before.

Your clients’ data is never used to train a model and is never retained by an AI provider. AI runs under contract in a confidential, zero-data-retention environment, scoped to your firm, with every action logged.

Run my free AI audit Get early access

LexSteward is a marketing-technology platform, not a law firm, and does not provide legal services or legal advice. Vendors and safeguards are disclosed by function and reviewed regularly; specific model versions are an implementation detail and may change without weakening these commitments.