Attorney-Client Privilege Guarantees
The concern is simple: does sending privileged material through an AI vendor waive privilege? With Vault AI nothing is sent to a vendor at all — here is how that is enforced, and where the responsibility stays with you.
This page describes platform design. It is not legal advice, and privilege analysis depends on your jurisdiction and engagement terms.
Confidentiality is contractual, not just technical
- The DPA binds TokenGrill to confidentiality and to processing only on your documented instructions.
- We assert no licence over your content. We do not use it to train, tune, or evaluate models — and we could not, since it never reaches us.
- No human at TokenGrill can read customer prompts or responses. There is no content to read, because none leaves your building.
Disclosure is minimised by design
- Processing happens on hardware your firm owns and physically controls — there is no disclosure to a third party to analyse.
- Each matter is indexed in its own scoped workspace with role-based access, so exposure inside the firm is limited too.
- Working memory is cleared when a run completes, and the appliance can operate fully offline with no network at all.
You keep an evidentiary record
Every privileged action is written to an append-only audit log on the appliance: who ran what, on which matter, at what time, which local engine executed each step, and confirmation that the step never left the box. If you ever have to demonstrate that reasonable measures were taken to preserve confidentiality, that record is the artefact you produce.
What stays with you
- Deciding which matters may be processed with an AI tool at all.
- Client consent and engagement-letter language where your jurisdiction expects it.
- Reviewing output before it is relied on — the grounding check flags unsupported claims, it does not replace a lawyer.
Need this in writing for your review?
We share the underlying documentation with security and risk teams under NDA, and will walk your counsel through anything on this page.
Request documentation