On-premise & zero retention

Your client’s secrets never leave the building.

The Vault AI appliance processes every contract and case file on-premise, 100% contained from the internet. There is no cloud endpoint, no external provider, and no vendor account holding your matter data. Here is exactly how that works, down to the access controls on the box and the limits worth knowing.

100% on-premise0 bytes egressMatter-level segregationImmutable local audit logs
01Three privacy pillars

Confidentiality by hardware, not a policy promise

Because the appliance sits inside your firm, privilege is enforced by placement — not by a vendor contract. There is no endpoint to review, because there is no endpoint.

On-premise by defaultImmutable local logsMatter-level segregation

100% on-premise & contained execution

The Vault AI appliance runs entirely inside your firm. By default, no prompt, completion, or document ever leaves the building — there is no cloud endpoint to leak to. The box is the server, so confidentiality is enforced by hardware, not a policy.

100% local100% On-Premise & ContainedZero egress by default

Immutable local audit trail

Every step is written to an append-only audit log that lives on the appliance itself. It records which local model handled each node, with timestamps and hashes — ready for your risk committee, auditor, or opposing counsel's challenge.

Append-onlyOn-boxPer-step attribution

Matter-level segregation

Each matter is indexed in its own scoped workspace on the appliance, with role-based access tiers for partners, associates, and staff. Teams see only the matters they are assigned to, and working memory is cleared when a run completes.

Per-matter scopingRole-based accessMemory cleared
02Request lifecycle

What happens to your data, step by step

From the moment a prompt enters the appliance to the moment the answer lands in your workspace, every byte stays on hardware you own — and working memory is cleared on completion.

Intake on-boxRun localClear & log
  1. 01

    On-box intake

    The prompt and any uploaded documents enter the appliance over your LAN, VPN, or a direct peer-to-peer link and stay there. Nothing is copied to an external service, an object store, or a vendor account.

    Stays on-box · scoped to the matter workspace

  2. 02

    Local Tier-0 execution

    The matter is resolved entirely by the appliance's RAG-enabled local engine, grounded on your own indexed documents. No egress, no external provider — 100% of queries run this way.

    100% local · 0 bytes egress · unlimited queries

  3. 03

    Off-grid operation

    The box runs in Offline mode with no outbound access, or Office mode on your LAN only. Attorneys reach it from a phone, laptop, or tablet over the firm VPN or peer-to-peer — never through a vendor cloud.

    0 bytes egress · VPN or peer-to-peer access

  4. 04

    Delivery & audit

    The answer is returned to your device from the appliance. Working memory for the run is cleared immediately after delivery, and an audit hash is recorded to the append-only log on the box.

    0 bytes egress · memory cleared · audit hash recorded

04Access control on the box

Who can reach what, inside the appliance

Confidentiality inside the firm matters as much as confidentiality outside it. The appliance scopes every matter and every device, so teams see only the work they are assigned to.

Role-based tiersROLES

Partner, associate, staff scopes

Matter workspacesSCOPE

Each matter indexed separately

Encrypted local storeAES-256

Full-disk encryption on the box

Device enrolmentMTLS

Only firm devices may connect

VPN or peer-to-peerLAN

No public ingress, ever

Purge on demandWIPE

Delete a matter index in one click

Session expiryTTL

Idle sessions closed automatically

05Compliance alignment

Defensible to a risk committee — or a court

TokenGrill's privacy posture is built to map onto the obligations your firm already answers to — with every query resolved on-premise.

ABA Model Rule 1.6

Confidentiality is enforced structurally: client data never leaves the appliance at all. There is no third-party processor to disclose to and no cloud endpoint to review — the confidentiality obligation is met by hardware placement alone.

Attorney-client privilege

Privilege-encumbered content stays in-house on the appliance. No external model, vendor, or subprocessor ever receives the parties, deal terms, or identifiers.

No data retention, by construction

No retention agreement is needed at all — nothing egresses. Prompts and completions live only in appliance memory for the duration of the request and are discarded on completion.

Determinate audit trail

An immutable, hash-anchored log on the appliance records which local engine handled each step and the hash of that step — defensible to a risk committee or court. Client content never enters the log.

06Privilege audit trail

Every step, recorded and hash-anchored

A sample of the immutable log the appliance produces for a single request. It records per-step local engine attribution and timing — without ever holding the client content itself.

Append-onlyStored on-boxPer-step attribution
Timestamp (UTC)NodeModelNote
  • 2026-08-15T19:42:11ZINTAKEon-box3 documents indexed · 0 stored off-box
  • 2026-08-15T19:42:11ZPLANon-box2 steps · est. 1,480 tokens
  • 2026-08-15T19:42:13ZNODE-1local-slmTier-0 · 0 bytes egress · 612 tok
  • 2026-08-15T19:42:15ZNODE-2local-slmTier-0 · 0 bytes egress · 940 tok
  • 2026-08-15T19:42:16ZDELIVERon-boxmemory cleared · hash 0x9f3a

Every row is tagged on-box or local-slm — no step in this run left the appliance, and no byte reached an external network.

Want the security review pack?

We’ll walk your risk committee through the appliance architecture, the access-control model, and the audit trail the box produces for your matter types.

Reserve Your Vault AI