Your Client's Secrets, Locked Down
Law firms are adopting AI at an unprecedented pace — for legal research, document review, and drafting. But every prompt containing case strategy, client names, or settlement figures creates a privilege waiver risk. Shield keeps your firm's confidential data on your machines, where it belongs.
Under the attorney-client privilege, voluntary disclosure to a third party can waive the privilege — not just for that communication, but for the entire subject matter. Pasting case strategy into an AI tool constitutes disclosure to the AI provider, creating arguable waiver of privilege.
Legal professionals face overlapping obligations from the ABA Model Rules, state bar ethics opinions, GDPR, and client NDAs. Each framework independently requires protection of confidential information — and AI tools create disclosure risk under all of them simultaneously.
Because Shield runs locally on your firm's machines, it never stores, transmits, or processes client data on Purfect Labs servers. The AI provider never sees the original data — only redacted placeholders. Your compliance scope doesn't expand.
Privilege waiver is not theoretical
ABA Formal Opinion 512 makes clear that lawyers have a duty of competence regarding technology, and that using AI tools requires reasonable efforts to protect client confidentiality. Courts have consistently held that voluntary disclosure to third parties can waive attorney-client privilege — including for the entire subject matter of the communication. A single prompt containing case strategy, client identities, or settlement figures creates an arguable waiver. Shield eliminates this vector: the AI provider never receives the original privileged content, so no disclosure occurs.
Interactive Demo
What Confidential Legal Data Looks Like in AI Prompts
Three real-world scenarios where legal professionals send confidential data to AI models. Click each tab to see the raw prompt with privileged and personally identifiable information — and how Shield redacts it before it leaves your firm's network.
Compliance Mapping
How Shield Maps to Legal Ethics & Compliance
Legal professionals face overlapping obligations from the ABA Model Rules, state bar ethics opinions, client NDAs, and data protection regulations. Shield's local proxy architecture satisfies confidentiality requirements across multiple frameworks — without adding cloud dependencies to your firm's compliance scope.
| Framework | Requirement | How Shield Addresses It |
|---|---|---|
Attorney-Client Privilege | Communications between attorney and client must remain confidential. Waiver occurs if privileged information is disclosed to third parties — including AI providers. | Shield redacts client identities, case details, and privileged communications before they leave your firm's network. No waiver risk — the AI provider never receives the original privileged content. |
ABA Model Rule 1.6 | A lawyer shall not reveal information relating to the representation of a client unless the client gives informed consent. This extends to information transmitted through technology. | Shield's local proxy ensures client information is redacted at the network edge. Attorneys can leverage AI tools while maintaining the confidentiality required by Rule 1.6 — informed consent is easier to obtain when you can demonstrate technical safeguards are in place. |
ABA Model Rule 1.1 (Competence) | A lawyer shall provide competent representation. Comment 8: lawyers should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. | Shield enables firms to adopt AI technology competently — by addressing the confidentiality risks that would otherwise make AI use ethically problematic. Firms can demonstrate technological competence while protecting client data. |
GDPR (EU Clients) | Law firms processing personal data of EU data subjects must comply with GDPR requirements for data protection, cross-border transfers, and data processor agreements. | Shield's local redaction means personal data never crosses borders to AI providers. No data processor agreement is needed with the AI provider because they never receive personal data — only redacted placeholders. |
State Bar Data Security | Many state bars now require reasonable data security measures. Firms must protect client data against unauthorized access, including through third-party technology vendors. | Shield provides auditable protection with cryptographic hashing of every redaction event. Firms can demonstrate to state bar investigators exactly what data was protected and when — with tamper-evident logs. |
Architecture
Client Data Never Leaves Your Firm's Network
Shield runs as a local proxy on your firm's machines. When an attorney, paralegal, or administrator sends a prompt to an AI model, Shield intercepts it — redacts all confidential data — and only then forwards the clean prompt to the external LLM. The redaction mapping stays on your machine, and responses are rehydrated locally before anyone sees them.
Local Installation
Install Shield on any Mac, Windows, or Linux machine in your firm. No cloud infrastructure, no vendor data access — client data never leaves your network.
One Environment Variable
Set SHIELD_PROXY_URL and every AI call from that machine flows through Shield automatically. Zero changes to your existing legal tech stack.
Tamper-Evident Audit Trail
Every redaction event is logged with a cryptographic hash. Demonstrate to clients, bar investigators, and courts exactly what data was protected and when.
Configurable Policies
Choose which data categories to redact. Add custom patterns for your firm's internal matter numbering and client coding systems. Run in audit-only mode to validate coverage first.
Ready to Protect Client Confidentiality in AI Workflows?
Shield runs on your firm's existing infrastructure. No cloud. No third-party data sharing. No privilege waiver risk. Deploy in under an hour and give your attorneys the AI tools they need — without compromising client confidentiality.