Client files never leave the building.
We build small, fine-tuned models that run on infrastructure your firm controls — first-pass document review, clause extraction, intake triage — with no third-party processing of privileged material.
Private AI for law firms means a small model fine-tuned on your document types, running on hardware the firm controls — a server in your office or your private cloud tenancy. No client file reaches a third-party API, so confidentiality, privilege, and engagement-letter restrictions hold by architecture, not by contract. Published migrations report 66–80% lower inference costs on routine workloads (Forethought, on AWS).
Law firms have the clearest version of the problem we work on. The tasks that would benefit most from AI — first-pass review, clause extraction, intake triage, bundle preparation — are exactly the tasks you cannot route through a third-party API without a hard conversation about confidentiality, privilege, and what your engagement letters actually permit. Banks, insurers, and institutional clients increasingly restrict external data processing in their engagement terms outright, and their audits ask exactly where matter data goes. A frontier API is a data processor, whether the vendor's marketing calls it that or not.
A small model changes the shape of the question. A 3–7B model fine-tuned on your document types runs on hardware inside your perimeter — a server in your office or your private cloud tenancy. Nothing is transmitted to, retained by, or trained on by a third party. The question “where does client data go” gets a one-word answer: nowhere. The client audit questionnaire becomes a one-line answer, and your existing security controls keep applying, because the system lives behind them.
There is a second, quieter problem this solves. Fee earners paste things into public chatbots because there is no approved alternative — and the fix isn't another memo from your COLP. It's a sanctioned tool that's genuinely better for the work, running where the work is allowed to happen.
This page carries our deepest groundwork. Crit Studio started with private AI for England & Wales firms of 10–50 fee earners, and the packages below reflect that: scoped for a COLP to review. The same pattern serves US firms — the engagement terms differ, the engineering doesn't.
Four systems, one perimeter.
For E&W firms, the obligations point one direction: confidentiality under the SRA Code, legal professional privilege, and UK GDPR all reward the same architecture — fewer third parties touching client material means fewer questions to answer. We design deployments so your COLP can describe the data flow in one sentence: client data stays on infrastructure the firm controls, and nothing leaves the perimeter. We're engineers, not your compliance advisers — but we build systems whose data flow is short enough to explain to one.
Packages scoped for a COLP to review.
US firms start with The Crit — the same audit.
We haven't shipped inside a law firm yet, and we won't pretend otherwise. Here is the published evidence the economics hold — and here is how we'd prove it on your matters, against a frozen eval set, before you commit.
| Published result | Source |
|---|---|
| Inference costs fell 66–80% after moving routine workloads to fine-tuned small models | Forethought, published on AWS |
| Task accuracy rose from 81% to 93% while inference costs fell 50–68% | distil labs × Knowunity, vendor-reported |
| Serving costs fell roughly 50% on dedicated small-model infrastructure | distil labs on Cerebrium, vendor-reported |
| Task-specific small models to see 3× the adoption of general-purpose LLMs by 2027 | Gartner forecast |
Does any client data leave the firm?
No. The model runs on hardware the firm controls — a server in your office or your private cloud tenancy — and processes matters there. Nothing is transmitted to, retained by, or trained on by a third party, and your existing security controls keep applying because the system lives behind them.
What does this look like to our COLP?
A one-sentence data flow: client data stays on infrastructure the firm controls, and nothing leaves the perimeter. We scope every engagement as a package written for a COLP to review, and each deployment comes with an audit trail your firm operates itself.
Do you only work with England & Wales firms?
No. The engineering is identical for US firms; only the engagement terms differ. Our deepest groundwork is England & Wales — firms of 10–50 fee earners, packages scoped for a COLP to review. US firms start with The Crit.
Privilege survives the AI.
- Files never leave the firm
- No public AI in the chain
- Confidentiality by custody
- COLP-ready audit log
We’re engineers, not your compliance advisers — the architecture keeps your existing compliance intact instead of adding a vendor to it.
See if the numbers hold in your matters.
The Crit is a teardown of your AI spend and workflows: where a small model wins, where an API is fine, and where AI shouldn't be used at all. You get the numbers either way.
If your workload doesn't clear roughly 50M tokens a month and you have no privacy constraint, a frontier API is probably fine — and we'll tell you so.