Security / Why Sanctum Lex

The better alternative to shared cloud legal AI

Harvey and its peers are good products built on a compromise: your privileged work product has to move onto their infrastructure before it becomes useful. Sanctum Lex removes the compromise. Same class of model, same workflows, none of the transfer.

Side by side

Three architectures, three risk profiles

Cloud hosted legal AI covers products such as Harvey and CoCounsel. General purpose assistants covers the frontier chat tools your lawyers already have open in another tab. On the row that matters most, only one column can say the documents never left.

CapabilitySanctum LexCloud hosted legal AIGeneral purpose assistants
Where inference runsInside your own enclave, on hardware you controlVendor managed cloud, shared infrastructureVendor managed cloud, consumer scale
TenancySingle tenant. One firm per nodeMulti tenant with logical separationMulti tenant
Outbound data pathNone. Zero egress by architectureEncrypted transit to the vendor's regionEncrypted transit, broad service surface
Training on your work productImpossible. The corpus never leavesContractually excludedDepends on plan and settings
Privilege handlingClassified at ingest, enforced before inferenceApplied at the application layerNot modelled
Evidence for your auditorsLive telemetry and a local audit log they can readVendor attestations and reportsVendor attestations
If the vendor is breachedYour documents were never thereYour documents are in scopeYour documents are in scope
Model currencyMost capable model available, deployed into the enclaveVendor's current frontier modelVendor's current frontier model

Comparison reflects published architecture as we understand it. Vendors change their offerings, so confirm current terms with each provider before relying on this table.

Why firms move, and move quickly

The security review stops being the bottleneck

Most evaluations die in front of the risk committee because the corpus has to move. When the answer to where does the document go is nowhere, the longest step in procurement collapses to a walkthrough.

Outside counsel guidelines are satisfied on day one

Client engagement terms increasingly forbid processing work product on shared infrastructure. A single tenant enclave meets that clause as written, with a data handling statement you can hand to the client.

Answers your partners will actually rely on

Every passage returns with its file, page, and matter. A partner checks the source in one click rather than re-doing the work to be sure.

The knowledge asset stays yours

Your precedent bank, your memoranda, your closed matters. They train nothing outside the building and they compound inside it.

What the enclave changes in the numbers

0
Documents leaving the firm to make the product work
27.9 hrs
Manual equivalent recovered per completed agent run
4 weeks
From sealed node to a practice group running live work
1
Security review, reused for every subsequent group

First month

What the first thirty days look like

Week one

Node sealed

Hardware provisioned inside your perimeter, enclave attested, first matter ingested under scope.

Week two

Group live

One practice group running real work, with prompts and review standards captured as they settle.

Week three

Review passed

Security walks the architecture and reads the local audit log. The data handling statement is issued.

Week four

Value reported

Hours reclaimed and matters touched, drawn from the audit log rather than a survey.

The short version

Every other option asks you to accept that your privileged documents sit on infrastructure you do not control. We think that trade was never necessary, and we built the product that proves it.

Objections

The four questions we always get

  • Does a private deployment mean a weaker model?

    No. The enclave runs the most capable model available and it is updated in place. Sovereignty is about where the weights execute, not how good they are.

  • What happens when we need more capacity?

    Nodes are added inside your environment. Scaling is a hardware conversation with your own infrastructure team, not a licence renegotiation.

  • How long until a group is live?

    A first practice group runs live work in weeks, not quarters, because there is no data transfer to negotiate first.

  • Who can see our matters?

    Nobody outside your firm, including us. There is no vendor console into your enclave and no support path that reads your documents.

Bring us the hardest question your committee has.

We will answer it in a live session, on documents you choose, with the audit log open on screen.