The security review stops being the bottleneck
Most evaluations die in front of the risk committee because the corpus has to move. When the answer to where does the document go is nowhere, the longest step in procurement collapses to a walkthrough.
Security / Why Sanctum Lex
Harvey and its peers are good products built on a compromise: your privileged work product has to move onto their infrastructure before it becomes useful. Sanctum Lex removes the compromise. Same class of model, same workflows, none of the transfer.
Side by side
Cloud hosted legal AI covers products such as Harvey and CoCounsel. General purpose assistants covers the frontier chat tools your lawyers already have open in another tab. On the row that matters most, only one column can say the documents never left.
| Capability | Sanctum Lex | Cloud hosted legal AI | General purpose assistants |
|---|---|---|---|
| Where inference runs | Inside your own enclave, on hardware you control | Vendor managed cloud, shared infrastructure | Vendor managed cloud, consumer scale |
| Tenancy | Single tenant. One firm per node | Multi tenant with logical separation | Multi tenant |
| Outbound data path | None. Zero egress by architecture | Encrypted transit to the vendor's region | Encrypted transit, broad service surface |
| Training on your work product | Impossible. The corpus never leaves | Contractually excluded | Depends on plan and settings |
| Privilege handling | Classified at ingest, enforced before inference | Applied at the application layer | Not modelled |
| Evidence for your auditors | Live telemetry and a local audit log they can read | Vendor attestations and reports | Vendor attestations |
| If the vendor is breached | Your documents were never there | Your documents are in scope | Your documents are in scope |
| Model currency | Most capable model available, deployed into the enclave | Vendor's current frontier model | Vendor's current frontier model |
Comparison reflects published architecture as we understand it. Vendors change their offerings, so confirm current terms with each provider before relying on this table.
Most evaluations die in front of the risk committee because the corpus has to move. When the answer to where does the document go is nowhere, the longest step in procurement collapses to a walkthrough.
Client engagement terms increasingly forbid processing work product on shared infrastructure. A single tenant enclave meets that clause as written, with a data handling statement you can hand to the client.
Every passage returns with its file, page, and matter. A partner checks the source in one click rather than re-doing the work to be sure.
Your precedent bank, your memoranda, your closed matters. They train nothing outside the building and they compound inside it.
First month
Week one
Hardware provisioned inside your perimeter, enclave attested, first matter ingested under scope.
Week two
One practice group running real work, with prompts and review standards captured as they settle.
Week three
Security walks the architecture and reads the local audit log. The data handling statement is issued.
Week four
Hours reclaimed and matters touched, drawn from the audit log rather than a survey.
Objections
No. The enclave runs the most capable model available and it is updated in place. Sovereignty is about where the weights execute, not how good they are.
Nodes are added inside your environment. Scaling is a hardware conversation with your own infrastructure team, not a licence renegotiation.
A first practice group runs live work in weeks, not quarters, because there is no data transfer to negotiate first.
Nobody outside your firm, including us. There is no vendor console into your enclave and no support path that reads your documents.
We will answer it in a live session, on documents you choose, with the audit log open on screen.