Industry · Legal

Client files never leave the building.

We build small, fine-tuned models that run on infrastructure your firm controls — first-pass document review, clause extraction, intake triage — with no third-party processing of privileged material.

Private AI for law firms means a small model fine-tuned on your document types, running on hardware the firm controls — a server in your office or your private cloud tenancy. No client file reaches a third-party API, so confidentiality, privilege, and engagement-letter restrictions hold by architecture, not by contract. Published migrations report 66–80% lower inference costs on routine workloads (Forethought, on AWS).

What changes in your industry

Law firms have the clearest version of the problem we work on. The tasks that would benefit most from AI — first-pass review, clause extraction, intake triage, bundle preparation — are exactly the tasks you cannot route through a third-party API without a hard conversation about confidentiality, privilege, and what your engagement letters actually permit. Banks, insurers, and institutional clients increasingly restrict external data processing in their engagement terms outright, and their audits ask exactly where matter data goes. A frontier API is a data processor, whether the vendor's marketing calls it that or not.

A small model changes the shape of the question. A 3–7B model fine-tuned on your document types runs on hardware inside your perimeter — a server in your office or your private cloud tenancy. Nothing is transmitted to, retained by, or trained on by a third party. The question “where does client data go” gets a one-word answer: nowhere. The client audit questionnaire becomes a one-line answer, and your existing security controls keep applying, because the system lives behind them.

There is a second, quieter problem this solves. Fee earners paste things into public chatbots because there is no approved alternative — and the fix isn't another memo from your COLP. It's a sanctioned tool that's genuinely better for the work, running where the work is allowed to happen.

This page carries our deepest groundwork. Crit Studio started with private AI for England & Wales firms of 10–50 fee earners, and the packages below reflect that: scoped for a COLP to review. The same pattern serves US firms — the engagement terms differ, the engineering doesn't.

The regulatory angle
Read this before your COLP does

For E&W firms, the obligations point one direction: confidentiality under the SRA Code, legal professional privilege, and UK GDPR all reward the same architecture — fewer third parties touching client material means fewer questions to answer. We design deployments so your COLP can describe the data flow in one sentence: client data stays on infrastructure the firm controls, and nothing leaves the perimeter. We're engineers, not your compliance advisers — but we build systems whose data flow is short enough to explain to one.

For England & Wales firms

Packages scoped for a COLP to review.

The ScopingA short assessment of where private AI fits your matters: the data flow, the candidate workflows, and the case for a pilot — written so a COLP can review it. Quoted on the call, in pounds.
The PilotOne workflow, built on your documents inside your infrastructure and measured against a frozen eval set before anything goes live.
AssuranceMonitoring, drift detection, and scheduled re-training once a system runs in production — a monthly retainer scoped to the deployment.

US firms start with The Crit — the same audit.

Proof, with sources

We haven't shipped inside a law firm yet, and we won't pretend otherwise. Here is the published evidence the economics hold — and here is how we'd prove it on your matters, against a frozen eval set, before you commit.

Published resultSource
Inference costs fell 66–80% after moving routine workloads to fine-tuned small modelsForethought, published on AWS
Task accuracy rose from 81% to 93% while inference costs fell 50–68%distil labs × Knowunity, vendor-reported
Serving costs fell roughly 50% on dedicated small-model infrastructuredistil labs on Cerebrium, vendor-reported
Task-specific small models to see 3× the adoption of general-purpose LLMs by 2027Gartner forecast
Questions, answered straight

Does any client data leave the firm?

No. The model runs on hardware the firm controls — a server in your office or your private cloud tenancy — and processes matters there. Nothing is transmitted to, retained by, or trained on by a third party, and your existing security controls keep applying because the system lives behind them.

What does this look like to our COLP?

A one-sentence data flow: client data stays on infrastructure the firm controls, and nothing leaves the perimeter. We scope every engagement as a package written for a COLP to review, and each deployment comes with an audit trail your firm operates itself.

Do you only work with England & Wales firms?

No. The engineering is identical for US firms; only the engagement terms differ. Our deepest groundwork is England & Wales — firms of 10–50 fee earners, packages scoped for a COLP to review. US firms start with The Crit.

Security · by architecture

Privilege survives the AI.

  • Files never leave the firm
  • No public AI in the chain
  • Confidentiality by custody
  • COLP-ready audit log
Built around your duties under
SRA Code UK GDPR Legal privilege

We’re engineers, not your compliance advisers — the architecture keeps your existing compliance intact instead of adding a vendor to it.

Small models · critical hits

See if the numbers hold in your matters.

The Crit is a teardown of your AI spend and workflows: where a small model wins, where an API is fine, and where AI shouldn't be used at all. You get the numbers either way.

If your workload doesn't clear roughly 50M tokens a month and you have no privacy constraint, a frontier API is probably fine — and we'll tell you so.