Skip to content
← Back to Blog
Private executive office overlooking a city skyline
Confidentiality Sovereignty Design choices

7 min

Practice

Confidential by Construction

For a law firm, confidentiality is not a feature to be added. The only durable way to guarantee it is to design so the exposure never exists. This article demonstrates, property by property, how that guarantee is built.

For most software, confidentiality is a layer of protection added on top of a product that would otherwise expose data. Encryption, access controls, compliance certifications: the familiar apparatus of security bolted onto an architecture that, left to itself, would send information somewhere it should not go. This approach can work. But it is, by its nature, a defence: a wall built around a risk that the design created. For a law firm, where confidentiality is not a preference but the very condition of practice, a defence around a risk is a weaker thing than the absence of the risk altogether.

MAX's confidentiality does not rest on a promise, it rests on a demonstration. Three architectural properties, set at the moment of design, suffice to establish that none of the situations that constitute a risk in competing products can, by construction, occur with MAX. These three properties are independent of each other, verifiable, and each can be stated as a simple theorem.

PROPERTY 1 — NO DESTINATION, THEREFORE NO TRANSIT

Most legal AI tools require the firm's data to leave the firm's environment for a third-party platform. To use the tool, one sends one's matter, one's client information, one's privileged work, out to a system that lives elsewhere. The providers then build defences around that journey, and many of those defences are genuinely good. But the journey itself is what creates the exposure, and no defence around a journey is ever quite as strong as not having to make the journey at all.

A defence around a risk is always weaker than the absence of the risk. The strongest confidentiality is the exposure that was never created.

MAX does not own a separate platform. This is a direct consequence of the decision, described elsewhere, not to build an interface. Because there is no MAX destination for the work to travel to, the firm's data does not have to leave the firm's environment in order for MAX to be useful. This property is not an option, it is mechanical: a transit that does not exist cannot be intercepted, redirected, or mishandled.

One might object that no AI product works without interacting with a model, and that the models themselves are hosted elsewhere. The objection is well-founded, and it is precisely what Property 2 below addresses. But as regards the durable storage of the firm's data, of matters handled, of the encoded methodology, of the institutional memory, MAX does not create, by construction, a point of accumulation outside the firm. The journey that constituted the main exposure in competing products simply does not occur.

PROPERTY 2 — NO TRAINING, THEREFORE NO PROPAGATION

A second way data can leak from an AI tool is subtler than transit. When a model is trained on the data fed to it, that data integrates into its general knowledge and can, under certain conditions, resurface in answers given to other users. This is called propagation. For a law firm, it is an unacceptable risk, because client information that would resurface in an answer to another firm would constitute a breach of professional confidentiality, regardless of any malicious intent.

A guarantee commits the one who gives it. A property depends on no one.

MAX, by construction, does not train the underlying models on the firm's data or its clients' data. The data crosses the models for the time of an operation, then disappears. It does not enrich the model's knowledge. It does not resurface, in any form, in answers given to other users. Propagation, like transit, is rendered impossible by the architecture of the product, not avoided by a contractual promise.

This property deserves to be distinguished from a contractual guarantee one finds at many providers in the form of "we do not train on your data". Such a guarantee commits the provider, and it is broken the day the provider decides to break it, or the day terms of service are modified, often without any user noticing the change at the time it occurs. Our property is not a guarantee; it is a characteristic of the way the system is built. For it to cease being true, MAX would have to become another product. And it is precisely this robustness that distinguishes a guarantee from an architectural property.

PROPERTY 3 — EUROPEAN HOSTING, THEREFORE GDPR APPLICABILITY

The third property concerns the legal framework applicable to operations. MAX is hosted within the European Union, and the whole of the processing operates within the frame of the GDPR and the emerging requirements of the AI Act. This point matters less as a technical property than as a legal one: it guarantees that the firm's rights over its own data, and its clients' rights over theirs, are governed by a predictable and enforceable framework, and not by terms of service that could be unilaterally modified.

This property is, in the current state of the market, rarer than one would think. Many legal AI tools operate from jurisdictions where the protections offered to processed data are noticeably weaker, and where the scope of the firm's rights over its own data is more uncertain. The choice of European hosting is a constraint, which carries an operational cost and which closes some technical options. But it is what makes Property 3 verifiable, and it is that verifiability that distinguishes a guarantee from a promise.

This third property unfolds in several concrete directions that the profession will recognise. The right of access and erasure remains fully exercisable, in line with the GDPR. The obligation of minimising the data processed applies by default. Transfers outside the EU, where they are technically unavoidable, are framed by the European legal mechanisms provided for this purpose. The AI Act, as its provisions come into force, adds requirements of documentation, traceability and human oversight whose compliance MAX already carries. None of this is added to MAX: all of it flows from the initial choice to host in Europe, and from the decision to treat the European framework as a feature of the architecture rather than an obligation to be worked around.

These are not promotional commitments layered onto the product after the fact. They are properties of an architecture designed not to create the exposure those commitments would otherwise have to defend against.

Why sovereignty follows the same logic

Sovereignty, properly understood, is the same idea extended from data to dependence. A firm is sovereign over its work when it depends on no single outside party to keep functioning, when it is not locked to one provider's roadmap or one platform's permission. Because MAX sits above the models and is bound to none of them, the firm that uses MAX keeps its freedom to choose and to change. The value it builds up over time, its memory, its methodology, its governance, belongs to the firm and lives in the layer, not in any external model that could be priced, restricted or withdrawn.

This sovereignty can be verified in several concrete situations the profession will recognise. If a model provider abruptly changes its pricing conditions, the firm substitutes the model without having to rebuild its use. If a new regulation forbids a certain type of international data transit, MAX continues to function without ever having performed it. If a sensitive question arises about the jurisdiction applicable to a processing operation, the answer is documented from the design stage, not negotiated case by case. Each of these points is, taken individually, minor. Strung together, they outline an autonomy that is no longer just marketing, but operational, and that distinguishes a tool the firm leans on from a tool the firm depends on.

This is why we treat confidentiality and sovereignty not as marketing themes but as architectural facts. A theme can be claimed by anyone. A fact is built in, or it is not. The three properties set out above are verifiable. They do not depend on our good faith, our commercial vigilance, or our financial solidity. They are true because they flow from the way MAX has been built, and they will remain so for as long as MAX remains what it is. That is, for a law firm, the only kind of guarantee that truly deserves the name: one that no longer depends on who is making it.

Anyone can claim confidentiality and sovereignty as themes. They are only real when they are built into the architecture, not promised on top of it.

← Back to Blog

Recommended next