At intake, personal identifiers are force-redacted to typed role tags — [CLIENT], [ADDRESS], [ID] — on our secure server, before the case-analysis model reads a word. Your client reviews exactly what’s hidden, it runs on your own AI account, and nothing is kept long-term. Confidential by architecture, not by policy.
They disclose the sensitive facts a matter turns on — because they have to. The duty of confidentiality attaches from the very first message, before anyone has reviewed the case.
Names, addresses and reference numbers are replaced with typed role tags on our secure server — enforced, so a tampered browser can’t switch it off.
Before the file is built, your client reviews exactly what is hidden and approves it. Nothing goes further until they do.
Only the role-tagged version reaches the case-analysis model. It never holds an identity — and nothing identifying is stored, so there’s nothing to breach or subpoena later.
“Hi, my name is Maria Alvarez. My former landlord, Daniel Foss, changed the locks at 14 Ferry Road while I was away. My tenancy reference is HB-2291.”
4 personal identifiers detected
“Hi, my name is [CLIENT]. My former landlord, [OTHER_PARTY], changed the locks at [ADDRESS] while I was away. My tenancy reference is [DOC_ID].”
Identifiers replaced on the server — before the case-analysis model is ever called.
The client’s own words, identifiers and all.
Every identifier becomes a typed role tag, server-side.
They see and approve exactly what’s hidden.
Only the protected version — then it’s deleted.
A prospective client discloses the sensitive facts a matter turns on the moment they reach out — before anyone has read it, and before there’s a retainer. So the intake itself has to be private, not just the file that comes after. Most people already sense the risk, and disclose anyway.
are concerned that information they enter into generative-AI tools could become public.1
Cisco 2024 (global)The duty of confidentiality attaches the moment a prospective client speaks — not when they sign.
The principle this is built aroundNothing leaves for analysis until your client has seen and confirmed what’s hidden.
The safe roomPeople will hand over sensitive facts whether or not the channel is safe. The only thing you control is whether it is.1
Cisco 2024 Consumer Privacy SurveyHeard in confidence. Their identity is stripped to role tags before the reasoning model ever reads it.
They see the safe room. Exactly what’s hidden is shown for review — no black box, no guessing.
They can stop anytime. Control stays with the client, and nothing is retained once the matter is delivered.
The safe room shows your client exactly what’s hidden. This shows them exactly what’s sent: a plain-language summary of everything captured, which they read, correct, and confirm before it ever reaches your team. Two forms of control over one intake — nothing leaves until they say so.
A consumer chatbot ships every word to a model and keeps the log. PROVEAiBLE is built the other way — around what counts as confidential in the work you actually take, and the rules where you practise. Layer on layer.
Tuned to your matter types — reference numbers, medical record IDs, a minor’s name — so the right things are caught, not a generic name-and-email list.
The tags map to how your practitioners read a file — [CLIENT], [OTHER_PARTY], [MINOR] — consistent across every intake.
Configured to the confidentiality and retention obligations where you practise. A firm across several jurisdictions gets one intake that adapts to each.
Every call runs under your organisation’s key (BYOK), governed by your provider’s terms — never ours. We never hold your key, and never see the identities.
That’s the difference between an intake built around your duty of confidentiality and a chatbot that keeps the log.
After accuracy, data privacy and security is the reason lawyers hold back on AI — sharpest at the mid-size firms handling the most sensitive matters. Because identifiers never reach the model and nothing is retained, the risk is gone before a policy is ever read.
US · ABA 2024 Tech Report2 · ABA Journal3You can’t lose what you don’t hold. Case data is processed transiently and deleted on delivery — no client identities sit in a database waiting for a breach, and there’s nothing in the model to hand to opposing lawyers.
US · Embroker4 · Clio / IBM 20245 See the full compliance architecture →In 2025, a US federal court ordered a major AI provider to preserve consumer chatbot conversations — including ones users had deleted, and later to produce 20 million of those conversations to the opposing party in discovery. U.S. District Court, S.D.N.Y., 2025 — New York Times v. OpenAI
That’s the risk of letting a client pour their case into a consumer chatbot: the data is retained, and it can be compelled. PROVEAiBLE is built the opposite way — identifiers are redacted before the case-analysis model sees them, and case data is deleted the moment it’s delivered to you. See how the redaction happens →
[CLIENT] and [OTHER_PARTY] are what the case-analysis model processes. The mapping to real names is held separately and never transmitted — enforced server-side, so a tampered browser can’t disable it.
Every AI call is made under your organisation’s own account (BYOK) and governed by your provider’s terms — not ours. We never hold your key.
Completed intakes are deleted on delivery; incomplete sessions are purged within 90 days. No client PII is stored in our database.
No. When a client uploads a document its text is first extracted by OCR — a named sub-processor, purely to read the page. Personal identifiers are then replaced with typed role tags such as [CLIENT] and [ADDRESS] on our secure server. Only that role-tagged version reaches the case-analysis model, so the reasoning AI never works from your client’s identity.
No. Redaction is enforced server-side, not in the browser. A tampered or scripted browser can’t switch it off, because identifiers are replaced on our server before the case-analysis model is ever called. It’s a technical constraint, not a setting.
Your organisation does. The intake runs on your own AI account (bring your own key), so every call is made under your provider account and governed by their terms — never ours. The price is our fee; AI usage is billed by your provider, never through us.
No client PII is kept long-term. Case data is processed transiently: completed intakes are deleted on delivery and incomplete sessions are purged within 90 days. Nothing sits in a database waiting to be breached or subpoenaed. See the full compliance architecture →
I’ll send you a private demo — you’ll watch identifiers replaced with role tags in real time, before the model ever reads them. Or see the full product →
Free, no card, no call.