How our AI works.
In plain English: which AI runs, where your clients’ data goes, and what we will never do with it. We tell you the vendors, the boundary, and the commitments — not a model version we might swap next quarter. You carry your own confidentiality duty; this is built to help you meet it.
For your clients’ data: open-weight, inside our boundary
Anything touching your clients’ data runs on open-weight models — such as Llama-, Qwen-, and Mistral-class models — hosted entirely inside our secure boundary. Your clients’ data never leaves it, is never retained by the model, and is never used to train anything.
For frontier work: Anthropic’s Claude — only if you opt in
For the most demanding non-client work — or work you explicitly choose to send — we offer Anthropic’s Claude as an optional frontier brain, under a zero-data-retention, BAA-backed contract. You decide what, if anything, is ever routed to Claude. By default, client data isn’t — it’s off until you turn it on.
You’re always in control.
The AI proposes; you approve. Anything legal, client-facing, billed, or deadline-related waits for your one-click sign-off. You choose your plan (which sets the AI’s horsepower), your routing (what stays local vs. what may use Claude), and a spend cap. You never have to pick or manage a model — the system selects the right one for each task.
What we never do
Where each kind of work runs
The data boundary, by the kind of work. “In-boundary” means inside the controlled environment — your isolated tenant plus our no-retention model pool — not your firm’s own hardware. Cloud-first; your data region is set when you sign up and stays fixed.
| The work | The brain | Where it runs | Data leaves the boundary? |
|---|---|---|---|
| Your clients’ / privileged data | Open-weight, in-boundary | Our shared, no-retention model pool, in your data region (US firms in the US, Canadian firms in Canada) | No |
| Product help, general chat, marketing / SEO / content (non-client) | Open-weight, or Claude if you allow it | In-boundary pool — or Anthropic, only for non-client work you’ve allowed | Only if Claude, and only non-client |
| Work you explicitly route to Claude | Anthropic’s Claude (opt-in) | Anthropic, under a zero-data-retention, BAA-backed contract | Yes — opt-in, ZDR + BAA, metered |
Who holds the key
Your data is encrypted at the field level. Two postures, depending on your tier.
Your own revocable key.
Each firm’s data is encrypted with a key unique to your firm — isolated from every other tenant and never sent to any third-party AI. Revoke it and the data is cryptographically unrecoverable (crypto-shred). Your data region is set at signup and stays fixed. We administer the key on your behalf so the system can run for you.
You hold the key.
For firms with a hard data-sovereignty requirement, Sovereign adds bring-your-own-KMS: the key lives in your control, with dedicated in-boundary AI and Claude off for protected content. The result is true zero-knowledge — we become technically unable to read your protected content. Premium / contact us.
Talk to us about SovereignYour clients’ data stays in-boundary — never sent to any outside AI, never retained, and never used to train a model.
LexSteward is a marketing-technology platform, not a law firm, and does not provide legal services or legal advice. Vendors and safeguards are disclosed by function and reviewed regularly; specific model versions are an implementation detail and may change without weakening these commitments.