Where Does Your Case File Actually Live?
Most legal AI sends your client's file to someone else's servers. On-premise, offline and air-gapped deployment is the alternative — what it means, and what to ask before you sign.
The question that comes after “does it work?”
Most evaluations of legal AI stop at capability. Does it draft well, does it cite accurately, does it save time. Those are the right first questions.
The one that follows is quieter and harder to reverse: when your associate pastes a deposition into that tool, where does the text go, and who keeps a copy?
For most platforms the honest answer is that it leaves your building. It travels to a vendor’s infrastructure, is processed by a model that vendor rents from someone else, and may persist in logs held by a third party you never contracted with. None of that is necessarily improper. It is simply a different arrangement from the one law firms have historically had with their own records — and it is worth naming rather than assuming.
What “third party” means in practice
A firm evaluating software tends to read the security page, see encryption in transit and at rest, and move on. Encryption is necessary and it is not the same question.
The questions that actually determine where your file lives are narrower:
- Does the text of a privileged document leave our network at all?
- If it does, which companies hold it — the vendor, their cloud provider, their model provider?
- How long is it retained, and is it used to improve anyone’s model?
- If we terminate, what is deleted, on whose word, and can that be verified?
Most vendors can answer these. The answers differ enormously, and they are rarely on the pricing page.
The other arrangement
There is a second model, and it is older than the cloud: the software runs on hardware you control.
In an on-premise deployment, the application sits on your own server, inside your own network, under your own access controls. In a fully air-gapped deployment it goes further — the system has no external network path at all. Nothing is sent out because there is nowhere for it to go.
This is how Lawnova can be deployed. In the words of our own appellate product’s page:
“For firms requiring the highest level of data security, COAPP is available as a fully airgapped deployment. Run the entire system on your own isolated infrastructure with zero external network dependencies.”
And for the assistant that does the drafting:
“Run Blue Shark on your own infrastructure with your own local models. No cloud API calls.”
The phrase doing the work there is your own local models. In this arrangement the model itself runs beside your data rather than the data travelling to the model. Which leads to the part most firms do not expect.
You can train it on your own work
Once the model runs on your hardware, your firm’s material becomes an asset rather than a liability.
A practice that has written a thousand suppression motions has a house style, a set of arguments that work in front of particular benches, and a vocabulary its partners actually use. On a shared cloud platform that corpus is something to protect from disclosure. On your own infrastructure it is training data you already own, and the system can be configured and tuned against it — becoming better at your firm’s work specifically, without that work being visible to anyone else.
That is a genuinely different proposition from “the vendor’s model, with your documents pasted in.”
What to ask before you sign
Whichever direction a firm chooses, these questions produce comparable answers across vendors:
- Is on-premise or air-gapped deployment available at all, or is cloud the only option?
- If we self-host, does the AI still call an external API — and if so, for what?
- Which subprocessors touch client text, and can we see that list?
- Is our data used for training, by anyone, under any circumstances?
- On termination, what is deleted, and how is deletion evidenced?
- Can we run the system with no outbound network access whatsoever?
A vendor who answers all six plainly is telling you something. So is one who cannot answer the sixth.
Not a verdict on the cloud
None of this makes cloud deployment wrong. For many firms it is the correct trade: less infrastructure to maintain, faster updates, no server in a closet. Plenty of privileged material is handled responsibly on cloud platforms every day.
The point is narrower. Deployment is a decision, not a detail — and it is one of the few decisions in legal technology that is difficult to reverse after the fact. Firms with unusual confidentiality obligations, government or defence-adjacent work, or clients who ask where their file is kept have a reason to treat it as a first-order question rather than a line in an appendix.
Ask it early. The answer tells you what kind of relationship you are entering.
Continue Reading
Redefining ROI in Legal AI: Moving Beyond Traditional Metrics
Explore the need for new ROI metrics in legal AI to drive true business outcomes.
When an AI Agent Acts on Its Own, Who Is the Defendant?
An agent acted outside its test parameters, created false identities and tried to socially engineer a maintainer. No harm resulted. The legal question it raises will not stay hypothetical.
Certificate of AI Use: What Courts Are Asking For, and Sample Language
Nearly two dozen jurisdictions now require a disclosure or verification statement for AI-assisted filings. What the requirement means and how to word it.