Sovereign AI for law firms
The studios a law firm runs on its own hardware. Privilege preserved because data never leaves the building. Offline-verifiable records.

A law firm should not have to send its clients' secrets to a third party to get useful software. We build a sovereign operating system that runs on hardware the firm owns, inside the firm's own building, with the studios a practice actually uses: legal research, documents, email, matter and time. Privilege is preserved because the data never leaves, and every action is written to a record you can verify offline.
The problem with renting your practice
Most firms now run on rented software. The matters, the drafts, the client correspondence, the billing, all of it lives on estates owned by companies in another country, processed under terms those companies write and change. For an ordinary business that is a commercial choice. For a law firm it is a professional one, because the material in question is privileged.
Privilege is not a feature you switch on. It is a state that depends on control. The moment a client's confidence sits on a machine you do not own, read by software you cannot inspect, held by a company that can be served with an order, the control has moved. You can paper over that with contracts, but the file has still left the building.
We take a different position. The software should run where the work already sits: on the firm's own hardware, in the firm's own rooms, with nothing leaving.
What a firm actually runs
A practice does not need a hundred disconnected apps. It needs a handful of tools that share the same data and answer to the same assistant. On our operating system these are studios, and they run on one platform rather than as separate products bolted together.
Our legal research and drafting studio works over the firm's own precedents, filed matters and knowledge, not a public index. Ask it to pull the firm's standard position on a clause and it reads your bank of documents, because that is where your answer lives.
Our document system handles the drafting, comparison and version history that a firm lives on. Redlines, clause libraries and house style stay inside, and the assistant can draft, compare and summarise without a single page leaving the estate.
Our email system replaces the rented mailbox. Correspondence stays on the firm's hardware, and the assistant can triage, summarise a thread, and surface the matter a message belongs to, without a copy of that correspondence sitting on an outside server.
Our matter and time studio ties the work to the file and the clock. Time recorded against the right matter, documents linked to the right client, deadlines tracked in one place. Because it shares data with the other studios, a draft produced in the document system is already attached to the matter it belongs to.
One assistant runs across all of them. It is the same assistant whether you are drafting, searching, clearing email or recording time, and it works on the firm's own data because that data never moves. There is no separate model to integrate and nothing to send outward for it to be useful.
Privilege preserved because the data stays
The plainest way to keep a confidence is to never let it leave. Our studios read and write the firm's files where they already are. When the assistant drafts an advice note, it reads the matter file on your machine and writes the note back to your machine. No part of that round trip crosses your boundary.
Air-gapped operation is the default here, not a premium tier. A firm can run the whole platform with no route to the outside world, and the studios still work, because the intelligence that drives them runs locally on the hardware you bought. That is the difference between software you own and software you rent: the useful part does not depend on a connection to someone else's building.
Records you can verify offline
Clients, regulators and courts increasingly want to know not just what a firm holds but what its software did. We write every action the assistant takes to an Open Audit Record. When a document was read, when a draft was produced, when a field was changed, by which instruction: it is all recorded at the level of the action, not the login.
The record is verifiable offline. You do not need to trust a vendor dashboard or keep a live connection to a supplier to prove the sequence of events. You can hand a regulator a record that stands on its own. For a profession that runs on the ability to evidence what happened and when, an audit trail you can check without asking anyone's permission is worth more than a promise.
What it saves against the rented stack
The commercial case is straightforward once you count what a firm pays to rent the same functions from several suppliers at once. The standard model is per user, per month, billed separately for the mailbox and office suite, the meetings and messaging tools, and the practice and CRM systems.
Here is the method, so you can run it on your own numbers rather than take ours. Take the published list price of each incumbent, per user per month. Multiply by your headcount. Multiply by twelve. Add the products together. A firm rarely rents one tool; it rents a mail and office bundle, a separate messaging and meetings product, and a separate matter or CRM system, each with its own per-seat line.
Worked example, using the firm's own figures. A firm of 40 fee earners and staff, paying a combined published list price of X per user per month across those products, spends 40 times X times 12 each year, every year, indefinitely, and owns none of it at the end. That is the number to hold up against owning the stack outright and running it on hardware that is yours. We do not publish a MICKAI price here; the point is the shape of the comparison, which any firm can complete with the incumbents' own public rates.
The rented model also has a cost that does not show on the invoice. Every renewal is a negotiation you can lose, every price rise is theirs to set, and every one of those products holds your data as the reason you cannot leave. Owning the stack removes that leverage.
Beyond private deployment
We know private and on-premise deployment is not new, and we start from respect for it. A private tenant keeps your data in your instance, and that matters. Our value sits beyond that baseline.
Three things separate us. First, the audit is at the level of the action, not the session, so you can evidence what the software did and not merely who logged in. Second, air-gapped is the default, so the firm can run with no outside route at all and still have working studios. Third, this is the whole software stack rather than a model you have to integrate: the operating system, the studios and the assistant arrive together and share the firm's data, so there is nothing to wire up between vendors.
We build for the regulated small and mid-sized firm in particular, the practice that carries the same duties of confidence as the largest firms but without a department to manage a sprawl of suppliers. Owning one platform is simpler to run than renting five.
The position underneath
Everything above runs on one sovereign operating system. The studios are not separate apps that happen to share a login; they are parts of the same platform, working over the firm's own data, driven by one assistant. That is what makes privilege straightforward to keep and the audit straightforward to prove: there is one place the data lives, and it is yours.
We hold the work behind this in a filed patent estate, 104 UK patent applications with 2,340 claims, filed and on the record. The studios are built and run on that operating system today. What we sell a law firm is control: the software your practice runs on, on hardware you own, with your clients' confidences never leaving the building and a record of every action you can verify for yourself.
Frequently asked questions
Does the data ever leave our offices?
No. The operating system and every studio run on hardware you own, inside your building. Nothing is sent to an outside provider to read a matter, draft a document or answer a question. Air-gapped is the default, not an upgrade.
How does this protect privilege?
Privilege depends on control. When your documents, email and matter files sit on your own machines and are processed there, no third party holds a copy and no third party can be compelled to hand one over. The assistant reads your files where they already are.
What can we actually verify about what the system did?
Every action the assistant takes is written to an Open Audit Record: what was read, what was drafted, what was changed, and when. The record is verifiable offline, so you can prove the chain of events without trusting a vendor dashboard or a network connection.
How is this different from a private cloud deployment?
Private deployment keeps data in your tenant but still runs on someone else's estate under their terms. We start from your building as the baseline and go further: action-level audit, air-gapped operation, and the whole software stack rather than a model you have to wire into other people's tools.
Is this one product or many?
One operating system with many studios. Legal research, documents, email, matter and time all run on the same platform and share the firm's own data. There is one assistant across all of it, so you are not stitching together separate apps.
Do we need certifications from you to trust it?
We do not ask you to trust a badge. We hold no certifications and claim none. Trust here comes from architecture you can inspect: the data stays put, the audit record is verifiable offline, and the software runs on hardware you control.