The Vault AI appliance processes every contract and case file on-premise, 100% contained from the internet. There is no cloud endpoint, no external provider, and no vendor account holding your matter data. Here is exactly how that works, down to the access controls on the box and the limits worth knowing.
100% on-premise0 bytes egressMatter-level segregationImmutable local audit logs
01Three privacy pillars
Confidentiality by hardware, not a policy promise
Because the appliance sits inside your firm, privilege is enforced by placement — not by a vendor contract. There is no endpoint to review, because there is no endpoint.
On-premise by defaultImmutable local logsMatter-level segregation
100% on-premise & contained execution
The Vault AI appliance runs entirely inside your firm. By default, no prompt, completion, or document ever leaves the building — there is no cloud endpoint to leak to. The box is the server, so confidentiality is enforced by hardware, not a policy.
100% local100% On-Premise & ContainedZero egress by default
Immutable local audit trail
Every step is written to an append-only audit log that lives on the appliance itself. It records which local model handled each node, with timestamps and hashes — ready for your risk committee, auditor, or opposing counsel's challenge.
Append-onlyOn-boxPer-step attribution
Matter-level segregation
Each matter is indexed in its own scoped workspace on the appliance, with role-based access tiers for partners, associates, and staff. Teams see only the matters they are assigned to, and working memory is cleared when a run completes.
Per-matter scopingRole-based accessMemory cleared
02Request lifecycle
What happens to your data, step by step
From the moment a prompt enters the appliance to the moment the answer lands in your workspace, every byte stays on hardware you own — and working memory is cleared on completion.
Intake on-boxRun localClear & log
01
On-box intake
The prompt and any uploaded documents enter the appliance over your LAN, VPN, or a direct peer-to-peer link and stay there. Nothing is copied to an external service, an object store, or a vendor account.
Stays on-box · scoped to the matter workspace
02
Local Tier-0 execution
The matter is resolved entirely by the appliance's RAG-enabled local engine, grounded on your own indexed documents. No egress, no external provider — 100% of queries run this way.
100% local · 0 bytes egress · unlimited queries
03
Off-grid operation
The box runs in Offline mode with no outbound access, or Office mode on your LAN only. Attorneys reach it from a phone, laptop, or tablet over the firm VPN or peer-to-peer — never through a vendor cloud.
0 bytes egress · VPN or peer-to-peer access
04
Delivery & audit
The answer is returned to your device from the appliance. Working memory for the run is cleared immediately after delivery, and an audit hash is recorded to the append-only log on the box.
0 bytes egress · memory cleared · audit hash recorded
04Access control on the box
Who can reach what, inside the appliance
Confidentiality inside the firm matters as much as confidentiality outside it. The appliance scopes every matter and every device, so teams see only the work they are assigned to.
Role-based tiersROLES
Partner, associate, staff scopes
Matter workspacesSCOPE
Each matter indexed separately
Encrypted local storeAES-256
Full-disk encryption on the box
Device enrolmentMTLS
Only firm devices may connect
VPN or peer-to-peerLAN
No public ingress, ever
Purge on demandWIPE
Delete a matter index in one click
Session expiryTTL
Idle sessions closed automatically
05Compliance alignment
Defensible to a risk committee — or a court
TokenGrill's privacy posture is built to map onto the obligations your firm already answers to — with every query resolved on-premise.
ABA Model Rule 1.6
Confidentiality is enforced structurally: client data never leaves the appliance at all. There is no third-party processor to disclose to and no cloud endpoint to review — the confidentiality obligation is met by hardware placement alone.
Attorney-client privilege
Privilege-encumbered content stays in-house on the appliance. No external model, vendor, or subprocessor ever receives the parties, deal terms, or identifiers.
No data retention, by construction
No retention agreement is needed at all — nothing egresses. Prompts and completions live only in appliance memory for the duration of the request and are discarded on completion.
Determinate audit trail
An immutable, hash-anchored log on the appliance records which local engine handled each step and the hash of that step — defensible to a risk committee or court. Client content never enters the log.
06Privilege audit trail
Every step, recorded and hash-anchored
A sample of the immutable log the appliance produces for a single request. It records per-step local engine attribution and timing — without ever holding the client content itself.
Every row is tagged on-box or local-slm — no step in this run left the appliance, and no byte reached an external network.
Want the security review pack?
We’ll walk your risk committee through the appliance architecture, the access-control model, and the audit trail the box produces for your matter types.