Confidential AI intake · private by architecture

The reasoning AI never sees who your client is.

At intake, personal identifiers are force-redacted to typed role tags — [CLIENT], [ADDRESS], [ID] — on our secure server, before the case-analysis model reads a word. Your client reviews exactly what’s hidden, it runs on your own AI account, and nothing is kept long-term. Confidential by architecture, not by policy.

One intake → nothing to expose

The client speaks freely.

They disclose the sensitive facts a matter turns on — because they have to. The duty of confidentiality attaches from the very first message, before anyone has reviewed the case.

Identity is force-redacted.

Names, addresses and reference numbers are replaced with typed role tags on our secure server — enforced, so a tampered browser can’t switch it off.

The client sees the safe room.

Before the file is built, your client reviews exactly what is hidden and approves it. Nothing goes further until they do.

The model reads a stranger.

Only the role-tagged version reaches the case-analysis model. It never holds an identity — and nothing identifying is stored, so there’s nothing to breach or subpoena later.

Raw intake · client’s own words

“Hi, my name is Maria Alvarez. My former landlord, Daniel Foss, changed the locks at 14 Ferry Road while I was away. My tenancy reference is HB-2291.”

4 personal identifiers detected

Force-redacted · role tags

“Hi, my name is [CLIENT]. My former landlord, [OTHER_PARTY], changed the locks at [ADDRESS] while I was away. My tenancy reference is [DOC_ID].”

Identifiers replaced on the server — before the case-analysis model is ever called.

Safe room · client review
You’re hiding these before anything is sent:
Maria Alvarez[CLIENT]
Daniel Foss[OTHER_PARTY]
14 Ferry Road[ADDRESS]
Approved by client — file may be built
What the practitioner opens
Housing — unlawful lockout, urgent
Parties[CLIENT] v [OTHER_PARTY]
AccountLocks changed during absence; seeks re-entry and possessions.
HeldTwo documents held by the client.
No identity stored · deleted on delivery
01

Raw intake

The client’s own words, identifiers and all.

02

Force-redacted

Every identifier becomes a typed role tag, server-side.

03

Client reviews

They see and approve exactly what’s hidden.

04

Model sees

Only the protected version — then it’s deleted.

Raw intakeRole-taggedClient reviewsModel sees
Why it matters for the client

Confidentiality has to hold from the first message.

A prospective client discloses the sensitive facts a matter turns on the moment they reach out — before anyone has read it, and before there’s a retainer. So the intake itself has to be private, not just the file that comes after. Most people already sense the risk, and disclose anyway.

84%

are concerned that information they enter into generative-AI tools could become public.1

Cisco 2024 (global)
30%

enter personal or confidential information into those tools regardless.1

Cisco 2024 (global)
First message

The duty of confidentiality attaches the moment a prospective client speaks — not when they sign.

The principle this is built around
They approve

Nothing leaves for analysis until your client has seen and confirmed what’s hidden.

The safe room
The confidentiality gap
84%fear it could go public
yet
30%disclose anyway

People will hand over sensitive facts whether or not the channel is safe. The only thing you control is whether it is.1

Cisco 2024 Consumer Privacy Survey

Heard in confidence. Their identity is stripped to role tags before the reasoning model ever reads it.

They see the safe room. Exactly what’s hidden is shown for review — no black box, no guessing.

They can stop anytime. Control stays with the client, and nothing is retained once the matter is delivered.

The second layer of client control

The client confirms exactly what’s sent.

The safe room shows your client exactly what’s hidden. This shows them exactly what’s sent: a plain-language summary of everything captured, which they read, correct, and confirm before it ever reaches your team. Two forms of control over one intake — nothing leaves until they say so.

  • Nothing is delivered until the client has reviewed and confirmed it.
  • They can edit or remove anything that isn’t right — in their own words.
  • Your team opens a client-confirmed matter, not an AI’s best guess.
Not another chatbot

Configured to your firm, and your jurisdiction.

A consumer chatbot ships every word to a model and keeps the log. PROVEAiBLE is built the other way — around what counts as confidential in the work you actually take, and the rules where you practise. Layer on layer.

Layer 01

What counts as an identifier

Tuned to your matter types — reference numbers, medical record IDs, a minor’s name — so the right things are caught, not a generic name-and-email list.

Layer 02

Your role-tag vocabulary

The tags map to how your practitioners read a file — [CLIENT], [OTHER_PARTY], [MINOR] — consistent across every intake.

Layer 03

Your jurisdiction’s rules

Configured to the confidentiality and retention obligations where you practise. A firm across several jurisdictions gets one intake that adapts to each.

Layer 04

Your own AI account

Every call runs under your organisation’s key (BYOK), governed by your provider’s terms — never ours. We never hold your key, and never see the identities.

That’s the difference between an intake built around your duty of confidentiality and a chatbot that keeps the log.

Why it matters for the organisation

The reason lawyers won’t touch AI — removed by architecture.

Ask why a practice hasn’t adopted AI intake and the answer is almost always the same word: confidentiality. Most tools ask you to trust a policy. This one removes the risk from the design — so the objection is answered by architecture, not a promise.

The adoption blocker, removed

47%cite privacy/security as an AI barrier 56%at 10–49-attorney firms

After accuracy, data privacy and security is the reason lawyers hold back on AI — sharpest at the mid-size firms handling the most sensitive matters. Because identifiers never reach the model and nothing is retained, the risk is gone before a policy is ever read.

US · ABA 2024 Tech Report2 · ABA Journal3

Nothing to breach, nothing to subpoena

~36%of firms breached in a year $5.08Maverage legal breach cost

You can’t lose what you don’t hold. Case data is processed transiently and deleted on delivery — no client identities sit in a database waiting for a breach, and there’s nothing in the model to hand to opposing lawyers.

US · Embroker4 · Clio / IBM 20245 See the full compliance architecture →
Privacy by architecture

Nothing sits in a pile waiting to be subpoenaed.

In 2025, a US federal court ordered a major AI provider to preserve consumer chatbot conversations — including ones users had deleted, and later to produce 20 million of those conversations to the opposing party in discovery. U.S. District Court, S.D.N.Y., 2025 — New York Times v. OpenAI

That’s the risk of letting a client pour their case into a consumer chatbot: the data is retained, and it can be compelled. PROVEAiBLE is built the opposite way — identifiers are redacted before the case-analysis model sees them, and case data is deleted the moment it’s delivered to you. See how the redaction happens →

What this means in practice

Three guarantees, not three promises.

The model never sees client names

[CLIENT] and [OTHER_PARTY] are what the case-analysis model processes. The mapping to real names is held separately and never transmitted — enforced server-side, so a tampered browser can’t disable it.

It runs on your own key

Every AI call is made under your organisation’s own account (BYOK) and governed by your provider’s terms — not ours. We never hold your key.

Nothing stays on our servers

Completed intakes are deleted on delivery; incomplete sessions are purged within 90 days. No client PII is stored in our database.

Questions

What practices ask before they start.

Does the AI ever see the client’s real details?

No. When a client uploads a document its text is first extracted by OCR — a named sub-processor, purely to read the page. Personal identifiers are then replaced with typed role tags such as [CLIENT] and [ADDRESS] on our secure server. Only that role-tagged version reaches the case-analysis model, so the reasoning AI never works from your client’s identity.

Can the redaction be bypassed?

No. Redaction is enforced server-side, not in the browser. A tampered or scripted browser can’t switch it off, because identifiers are replaced on our server before the case-analysis model is ever called. It’s a technical constraint, not a setting.

Who controls the AI?

Your organisation does. The intake runs on your own AI account (bring your own key), so every call is made under your provider account and governed by their terms — never ours. The price is our fee; AI usage is billed by your provider, never through us.

Is anything stored?

No client PII is kept long-term. Case data is processed transiently: completed intakes are deleted on delivery and incomplete sessions are purged within 90 days. Nothing sits in a database waiting to be breached or subpoenaed. See the full compliance architecture →

See the redaction happen.

I’ll send you a private demo — you’ll watch identifiers replaced with role tags in real time, before the model ever reads them. Or see the full product →

Got it — your demo is on its way. I’ll email you a private link shortly. — Andrew

Free, no card, no call.

Sources

  1. Cisco — 2024 Consumer Privacy Survey (global): 84% concerned data entered into GenAI could become public; 30% enter personal/confidential information anyway.
  2. ABA (US) — 2024 Legal Technology Survey / Tech Report: data privacy & security cited by 47% as an AI-adoption concern (56% at 10–49-attorney firms).
  3. ABA Journal (US) — AI adoption is growing, but some are hesitant: confidentiality and accuracy among the leading barriers.
  4. Embroker (US) — Law-firm cyberattacks: roughly 36–40% of firms reported a security breach in the past year.
  5. Clio / IBM Cost of a Data Breach 2024 (US) — average breach cost for legal was $5.08M; a majority of breached firms lost sensitive client data.
See it live