LitigusAI
Your clients’ documents never get uploaded to the cloud.
The short version
LitigusAI is a desktop application. Matter work and client documents remain on your licensed device, in the folders you control, under the protections your firm already maintains. LitigusAI does not operate a client-file vault or document library on our servers.
Cloud services orchestrate only the processing you approve. No client document or data is stored on LitigusAI hardware, and client content is not used to train any model.
What desktop custody eliminates
Most legal AI products require your firm to upload client documents to a cloud workspace for processing. Even a secure cloud drive creates risks that desktop custody eliminates by design:
- No breach target. A platform holding thousands of firms’ client documents on its servers is a single high-value target. LitigusAI has no such vault. There is nothing to breach because the documents are never uploaded.
- No subpoena exposure via the vendor. Documents on a vendor’s server can be compelled by subpoena directed at the vendor, potentially bypassing the attorney entirely. Documents on the attorney’s device are protected by attorney-client privilege and work-product doctrine, and require a subpoena directed at the attorney.
- No insider access. Cloud-stored documents are accessible to the vendor’s employees and contractors. LitigusAI cannot access client documents because they are never uploaded.
- Data residency stays with the firm. Documents remain under the firm’s existing physical security, backup policies, and access controls. They do not inherit the vendor’s data center risks.
Zero data retention
LitigusAI was designed to be a zero-data-retention platform. Your clients’ documents never get uploaded to the cloud. You will never upload client documents to LitigusAI, and no copy of any client data will ever be saved to LitigusAI’s infrastructure. No client data is stored on our hardware, and there is no second copy of the matter on our servers. Material does transit to a model provider when a step requires inference, and the section below states exactly what that means today.
What leaves the device for processing
When an assignment requires model inference, only the specific material needed for that processing step is transmitted to a model provider. Prompts and outputs are never used to train any model.
Most of those steps route to provider endpoints engaged under contractual zero-data-retention terms, which means the provider does not keep the request or the response. During this private beta a small number of seats route to endpoints that are outside the United States or not yet under such a term, and we do not claim otherwise while that is true. Every seat must declare its data posture before it can run, and a seat that claims confidentiality has to name the retention term behind the claim rather than assert it. Firms evaluating LitigusAI for privileged work can request the current per-seat posture at info@litigusai.com.
Public legal research runs against the Litigus Library, LitigusAI’s own case-law library hosted on purpose-built infrastructure, rather than requiring your private matter files to live inside a third-party research vault. The Library holds only public case law. No client data ever touches it.
Local document processing
Document processing, including OCR, Bates numbering, format conversion, and text extraction, runs locally on your device through a loopback service. Matter bytes stay on your hardware. No document is uploaded to a cloud service for processing.
Trust-zone isolation
Every file and data source inside LitigusAI is classified into a trust zone:
- Client file zone. Your clients’ documents, correspondence, and pleadings. Full-trust legal workflow agents can read these. Operational agents (maintenance, concierge) are denied access.
- Firm knowledge zone. Domain knowledge, style profiles, and skills. Scoped to tenant cloud processing only.
- Adversary-authored zone. Documents from opposing parties or unknown sources. Scanned for prompt injection before processing.
- Approved web zone. Public legal sources, treated as untrusted external data.
Violations are logged as security events with severity levels and appended to the framework audit trail.
Default-deny egress
Outbound data transmission is default-deny. Content is classified by trust zone, and each classification determines where it can be sent:
- Local by default. Client-file and privileged content stays on the device except the specific material transmitted for a processing step you approve.
- Tenant cloud allowed. Firm knowledge may use approved cloud services.
- Approved external model allowed. Processing material may transit to a provider whose declared posture admits it.
- Public. Approved web sources treated as already public.
Prompt injection detection
LitigusAI scans all ingress text for prompt injection patterns, including instruction-override attempts, secret exfiltration attempts, and tool-bypass attempts. Findings are classified by severity and logged as security events. Adversary-authored documents are treated as untrusted input throughout processing.
Security event logging
The platform records security-relevant events to an append-only audit trail, including:
- Trust boundary violations
- Prompt injection detection and deflection
- Permission escalation attempts
- Review bypass attempts
- Unauthorized file access attempts
Verification and attorney control
Delivered work is subject to independent AI review and citation checks against the opinion text before it reaches you. That does not replace your professional judgment. You supervise the work, decide what is filed or sent, and remain the responsible attorney.
LitigusAI can make mistakes. Attorneys must review and verify AI-assisted work product before use.
Mobile access
Mobile apps are designed as a secure window into work that remains under desktop execution authority, not as a second repository of client files. Pairing can be revoked from the desktop.
What this architecture does and does not eliminate
- Processing transit. When an assignment requires model inference, the specific material needed for that step is transmitted to an approved provider. On most seats that provider is under a zero-retention term and keeps nothing. In every case the material does transit. This is a brief window, not persistent storage.
- Billing and authentication. Account authentication is handled by Clerk and payment processing by Stripe. Both carry their own security certifications. LitigusAI does not store, transmit, or process payment card data.
- Private beta. Security controls, provider terms, and product surfaces continue to evolve. The architecture described above is the current implementation, not a completed certification package.
Beta scope and ongoing hardening
If you need a detailed questionnaire for firm IT or a provider diligence packet, contact info@litigusai.com.
Related reading
For architecture principles in founder voice, see Under the hood. For how we handle website and application data, see the Privacy Policy.