A law firm's offices, stone facade and a street-level entrance
Home Forward Deployed Security Fabric FAQ Resources Blog About Start a Scoping Call
Local AI for Law Firms

Attorney-Client Privilege Doesn't Survive a Cloud API Call

Every prompt an attorney sends to a cloud AI service is client data handed to a third party. We'll build the whole system on your floor instead: the models, the agents, and the orchestration that run your firm's real work, and none of it touches a wire that leaves the building.

Every deployment starts on-site, with the people who do the work.

The Privilege Problem

The Cloud AI Problem for Law Firms

Cloud AI creates a structural conflict with the most fundamental obligation in legal practice: confidentiality.

When an attorney pastes a client contract into ChatGPT, Claude, or any cloud-based AI service, that document leaves the firm's network. It travels across the public internet to a data center owned by a third party. It is processed on shared infrastructure alongside data from thousands of other organizations. Law firms are one of eleven regulated industries where this structural conflict between cloud AI and data confidentiality is most acute. The cloud provider's terms of service - not your engagement letter - govern what happens to that data. Every contract analyzed through cloud AI is a privileged communication handed to a third party. If opposing counsel discovers the transmission, the privilege argument you built your case on may collapse.

ABA Model Rule 1.6(a) requires attorneys to hold client information in confidence. Rule 1.6(c) requires "reasonable efforts to prevent the inadvertent or unauthorized disclosure" of that information. Multiple state bar ethics opinions have addressed whether transmitting client data to cloud AI providers satisfies this standard. The recurring concern: once data leaves the firm's infrastructure, the attorney's ability to control its handling depends entirely on a vendor's privacy policy and contractual commitments - not on the firm's own security measures.

This is the mechanical reality of how cloud AI works, not a theoretical risk. Every API call is a data transmission. Every data transmission is a potential privilege question.

Attorney-Client Privilege
ABA Model Rules
FRCP Discovery Rules
How It Works

What Local AI Means for Your Firm

"No data leaves your building" is a description of network architecture, not marketing language.

Zero External Transmission

The AI models run on a physical server in your office. Prompts go from your workstation to the server over your internal network. No internet connection is required for inference. No data packets leave your building.

A System You Own

This is a physical server sitting in your server room or data closet, running on your power and connected to your network, not a hosted service with "local" branding. You own it outright.

Air-Gap Capable

After initial setup and model installation, the system can operate entirely disconnected from the internet. For firms handling the most sensitive matters, this means complete network isolation - no external connections of any kind.

The Build

We Build It Around How Your Firm Runs

A general model off the shelf knows plenty about law in the abstract and nothing about yours. It's never read your engagement letters, doesn't know your matter numbering, can't tell a managing partner's redline habits from a first-year's. We fix that on purpose.

Island Mountain builds the agents and the orchestration that carry multi-step work start to finish: intake to conflicts check to matter open, discovery review to privilege log, time entries to a billing narrative that reads the way your firm bills. It runs on current open-weight models like Kimi K3, ZAI GLM 5.2, Qwen 3.8+, and Nous Hermes 4, served through Ollama or vLLM behind an OpenWebUI front end, or whatever open weights fit the task. All of it deftly governed by our own agentic orchestration and the Woven Security Fabric. Every action carries an identity, an approval, and a receipt, and the credentials expire the moment the task is done.

When the work needs a model that thinks in your firm's own language, we'll build one. Reasoning models and small language models from scratch, trained to orbit your practice's ontology: your clause library, your jurisdictions, the institutional memory of how a matter really moves. The system learns your jargon, your cadence, the history nobody ever wrote down.

It air-gaps completely for the matters that demand it, and reaches the cloud when a task genuinely needs to. That's your call, matter by matter.

Then we hand it back. On-site onboarding, SOPs written for your people, the keys to the castle dropped into your team's hands so they run and rework the workflows without calling anyone. Want the upkeep off your IT department's plate? We offer tiered support sized to your firm, and we plug in wherever that's easiest. This is your firm's legacy. We build it alongside you, and we won't call it done until your people can run it without us.

Workflows

Workflows a Deployment Supports

These aren't chat prompts. They're agentic workflows the orchestration runs start to finish, each step carrying its own identity and receipt, none of it leaving your network.

Contract Review & Analysis

An agent reads the contract, flags the risk clauses, pulls the obligations and dates, and lines them against your standard terms. It handles the conditional language and the cross-references, and it shows its work so an attorney can check it.

Legal Research Synthesis

Summarize case law, pull the relevant statutes, and synthesize across a stack of sources at once. Long documents and multi-source questions stay on your hardware, start to finish.

Document Drafting

First drafts of briefs, motions, correspondence, and memoranda, structured and ready for an attorney to sharpen. The blank page is the system's problem now, not yours.

Deposition Preparation

Read witness statements against the documentary record, surface the inconsistencies, and build question frameworks. The whole case file gets processed in the building, never handed to a cloud service.

Document Comparison

Compare versions, catch the changed terms, and flag the substantive edits across a revision history. Redlines and track-changes analysis run on-premises.

Billing Narrative Drafting

Turn time entries and case notes into clean, defensible billing narratives in your firm's format. Drafted by the system, signed off by the billing attorney.

The system reasons, drafts, and carries the steps between. It doesn't come with a Westlaw or LexisNexis seat, and it doesn't sign a brief. An attorney still owns the judgment, same as it's always been. What we build is a tool for your lawyers, not a stand-in for one.
Models

The Models We Run, and the Ones We Build

Current Open Weights

Kimi K3, ZAI GLM 5.2, Qwen 3.8+, Nous Hermes 4, and whatever's strongest the month we deploy, served through Ollama or vLLM behind OpenWebUI. Open weights turn over fast, so the honest answer turns over with them. We run the model that fits the task, not the one that looked good on a spec sheet last year.

Built to Orbit Your Practice

When nothing off the shelf speaks your firm's language, we build it. Reasoning models and small language models from scratch, trained on your ontology: your clause library and the way your matters move. Small, sharp, and yours alone.

Governed, Not Just Installed

Every model runs under our agentic orchestration and the Woven Security Fabric. Scoped access, ephemeral credentials, a receipt for every action. Air-gapped when the matter demands it, cloud-connected when a task earns it.

Cost Comparison

Cloud AI vs. an On-Premise Deployment for a 10-Attorney Firm

The cloud costs every month and exposes client data every session. The hardware costs once and keeps everything in-house.

Cloud Legal AI (10 Users) Island Mountain build
Year 1 Cost $6,000 - $24,000 One-time purchase (quoted to the deployment)
Year 3 Cumulative $18,000 - $72,000 Electricity only (~$1,200 - $2,400/yr)
Year 5 Cumulative $30,000 - $120,000 Electricity only
Client Data Location Cloud provider servers Your server room. Period.
Privilege Risk Data transmitted to third party Zero transmission. Zero risk.
Per-Token Fees $15 - $60 per million tokens None. Unlimited use.
Model Control Provider decides models and updates You choose which models to run
Case Management Integration Some platforms offer integrations Not included. General-purpose AI.
Vendor Lock-In Complete None. Permissive open-source licenses.
Cloud estimates based on legal AI platforms charging $50-$200/user/month. Island Mountain electricity estimate assumes 1.5-2.5 kW average draw at $0.12/kWh.
Honest Limitations

What You Do Not Get

Knowing the boundaries matters more than knowing the features.

No Legal-Specific Fine-Tuning

The models are general-purpose large language models, not legal-specific AI. They're strong at reasoning, analysis, and prose generation, but they're general tools rather than Westlaw AI or CoCounsel, with no fine-tuning on case law databases, jurisdiction-specific statutes, or citation formats.

No Case Management Integration

Island Mountain hardware does not integrate with Clio, MyCase, PracticePanther, or other practice management platforms out of the box. The AI runs through OpenWebUI - a browser-based chat interface. Moving data between your case management system and the AI is a manual process.

No Legal Database Access

The system does not connect to Westlaw, LexisNexis, or any external legal research database. The AI works with documents and text you provide to it. It reasons about what you give it - it does not independently search case law or verify citations.

You Own the Maintenance

After the 30-day included support period, your firm is responsible for OS security updates, model updates, and general system maintenance. This is the same maintenance profile as any Linux server in a professional environment. Most managed service providers can handle it.

Ethics Context

Bar Association Ethics and AI Confidentiality

ABA Model Rule 1.6 establishes the duty of confidentiality. Comment [18] to Rule 1.6 specifically addresses electronic transmissions, requiring attorneys to take "special precautions" when the nature of the information warrants it. Multiple state bar associations have issued ethics opinions addressing cloud computing and AI in legal practice.

The recurring theme across these opinions: attorneys may use technology that involves third-party data processing, but they must exercise reasonable care in evaluating the provider's confidentiality protections, understand how client data is handled and stored, and take steps to minimize exposure. The bar does not prohibit cloud AI - but it places the burden of due diligence squarely on the attorney.

Local AI hardware changes the analysis entirely. When client data never leaves the firm's network, the third-party disclosure question does not arise. The confidentiality evaluation becomes straightforward: the data is on your server, in your building, under your physical and network security controls.

Disclaimer: This section describes the general ethics environment regarding AI and attorney-client privilege. It is not legal advice and should not be relied upon for compliance decisions. Consult your state bar's ethics hotline or a legal ethics attorney for guidance specific to your jurisdiction and practice.

Power & Installation: All Island Mountain systems require a dedicated 208V/30A power circuit (NEMA L6-30R). This is standard in server rooms and data closets. Most law firms with an existing server closet already have this infrastructure or can add it for $500-$2,000 through a licensed electrician. The system fits in a standard 4U rack space. Average power draw under typical inference loads is 1.5-2.5 kW.

Law Firm Questions

Questions Law Firms Ask

Does cloud AI violate attorney-client privilege?

Yes. Cloud AI transmits client data to third-party infrastructure, constituting disclosure that risks waiving attorney-client privilege. ABA Model Rule 1.6 requires reasonable efforts to prevent unauthorized disclosure of client information - cloud processing moves confidential data outside the firm's control by design. On-premises AI hardware from Island Mountain eliminates this transmission entirely.

What legal AI workflows does this hardware support?

Island Mountain builds workflows for contract review and clause analysis, legal research synthesis, brief and motion drafting, deposition preparation, document comparison, client intake summarization, and billing narrative drafting. The system runs current open-weight models for analysis and drafting, and custom models where the work needs one. All processing occurs on your own hardware inside your office.

How does the cost compare to cloud AI for a 10-attorney firm?

Cloud AI subscriptions for legal platforms typically cost $50 to $200 per user per month, totaling $6,000 to $24,000 per year for 10 attorneys. Over three years: $18,000 to $72,000 cumulative with continued privilege exposure on every query. An Island Mountain build is a one-time purchase, sized and quoted to your workload. Cost parity typically reached by year two to three.

Does our firm need dedicated IT staff?

No. The system is configured and air-gapped before it lands through a web browser. Setup requires racking the server, connecting power and network, and opening a browser. 30 days of hands-on support are included. Ongoing maintenance is standard Linux server administration - most managed service providers or part-time IT contractors handle it without difficulty.

Island Mountain is an engineering practice, not a compliance authority. References to attorney-client privilege, ABA Model Rules, or bar association ethics opinions on this page reflect factual descriptions of data handling mechanics - not legal advice. Consult qualified counsel for compliance determinations specific to your organization and jurisdiction.

Summary: Local AI infrastructure keeps client information in your control, avoiding the privilege waiver risk that NDAs cannot fix when using cloud AI services.

Related: Can Law Firms Use AI Without Waiving Privilege?

Law Firms Deploying Local AI

Mid-size firm handling 3,000+ contracts per year. Every prompt stays inside our building. Attorney-client privilege is no longer a theoretical risk.

Scenario: Private Legal Practice

Litigation support team processing 50,000 documents for discovery. Local inference means opposing counsel can't subpoena our AI provider for prompt logs.

Scenario: Litigation Practice

Solo practitioner with estate planning focus. Clients trust me with their most sensitive financial data. Cloud AI was never an option.

Scenario: Estate Planning Practice

Start a Conversation About Your Firm's AI Needs

No sales pitch. Describe your use case and we will tell you what we would build.

Ready to Keep Client Data Where It Belongs?

One conversation. No sales pitch. Tell us about your firm's AI needs and we will spec the right system.

Or call directly: 1-341-441-8740

See all eleven industries we serve or explore: Medical Practices · Defense Contractors