Skip to main content
Industry Guide

Your Client's Secrets, Locked Down

Law firms are adopting AI at an unprecedented pace — for legal research, document review, and drafting. But every prompt containing case strategy, client names, or settlement figures creates a privilege waiver risk. Shield keeps your firm's confidential data on your machines, where it belongs.

See How It WorksTalk to Our Team
Waiver Risk
Privilege can be lost with one prompt

Under the attorney-client privilege, voluntary disclosure to a third party can waive the privilege — not just for that communication, but for the entire subject matter. Pasting case strategy into an AI tool constitutes disclosure to the AI provider, creating arguable waiver of privilege.

Source: Federal Rules of Evidence 502; ABA Formal Opinion 512
5 Frameworks
Compliance obligations converge on AI use

Legal professionals face overlapping obligations from the ABA Model Rules, state bar ethics opinions, GDPR, and client NDAs. Each framework independently requires protection of confidential information — and AI tools create disclosure risk under all of them simultaneously.

Source: ABA Model Rules of Professional Conduct; GDPR Art. 28
Zero
Third-party data sharing required

Because Shield runs locally on your firm's machines, it never stores, transmits, or processes client data on Purfect Labs servers. The AI provider never sees the original data — only redacted placeholders. Your compliance scope doesn't expand.

Shield operates entirely within your firm's network boundary

Privilege waiver is not theoretical

ABA Formal Opinion 512 makes clear that lawyers have a duty of competence regarding technology, and that using AI tools requires reasonable efforts to protect client confidentiality. Courts have consistently held that voluntary disclosure to third parties can waive attorney-client privilege — including for the entire subject matter of the communication. A single prompt containing case strategy, client identities, or settlement figures creates an arguable waiver. Shield eliminates this vector: the AI provider never receives the original privileged content, so no disclosure occurs.

Interactive Demo

What Confidential Legal Data Looks Like in AI Prompts

Three real-world scenarios where legal professionals send confidential data to AI models. Click each tab to see the raw prompt with privileged and personally identifiable information — and how Shield redacts it before it leaves your firm's network.

Associate Drafting Case Strategy Memo with AI

A junior associate asks an AI assistant to help draft a settlement strategy memo, pasting client details, opposing counsel names, and confidential settlement figures into the prompt.

Before Shield
Draft a settlement strategy memo for our client AcmeCorp (plaintiff in Case No. 2026-CV-08421, Superior Court of California, County of San Mateo) vs. Zenith Industries. Current settlement offer: $4.2M. Opposing counsel: Morrison & Hayes LLP, lead attorney David Keller (bar #284917). Key exposure: internal email from CFO Rachel Tan (rachel.tan@acmecorp.com, SSN 528-41-9732) discussing $1.8M unreported liability. Mediation scheduled for September 18, 2026 before Judge Patricia Okonkwo.
After Shield
Draft a settlement strategy memo for our client [CLIENT_NAME] (plaintiff in Case No. [CASE_NUMBER], [COURT]) vs. [OPPOSING_PARTY]. Current settlement offer: [AMOUNT]. Opposing counsel: [FIRM_NAME], lead attorney [ATTORNEY_NAME] (bar #[BAR_NUMBER]). Key exposure: internal email from [EXECUTIVE_NAME] ([EMAIL], SSN [SSN]) discussing [AMOUNT] unreported liability. Mediation scheduled for [DATE] before Judge [JUDGE_NAME].
10 Confidential Data Points Detected
Privileged — ClientClient Name
Privileged — CaseCase Number
Privileged — SettlementSettlement Amount
PII — NameAttorney Name
PII — IDBar Number
PII — NameExecutive Name
PII — EmailEmail Address
PII — SSNSocial Security Number
Privileged — FinancialUnreported Liability
Privileged — PersonnelJudge Name

Compliance Mapping

How Shield Maps to Legal Ethics & Compliance

Legal professionals face overlapping obligations from the ABA Model Rules, state bar ethics opinions, client NDAs, and data protection regulations. Shield's local proxy architecture satisfies confidentiality requirements across multiple frameworks — without adding cloud dependencies to your firm's compliance scope.

FrameworkRequirementHow Shield Addresses It
Attorney-Client Privilege
Communications between attorney and client must remain confidential. Waiver occurs if privileged information is disclosed to third parties — including AI providers.Shield redacts client identities, case details, and privileged communications before they leave your firm's network. No waiver risk — the AI provider never receives the original privileged content.
ABA Model Rule 1.6
A lawyer shall not reveal information relating to the representation of a client unless the client gives informed consent. This extends to information transmitted through technology.Shield's local proxy ensures client information is redacted at the network edge. Attorneys can leverage AI tools while maintaining the confidentiality required by Rule 1.6 — informed consent is easier to obtain when you can demonstrate technical safeguards are in place.
ABA Model Rule 1.1 (Competence)
A lawyer shall provide competent representation. Comment 8: lawyers should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology.Shield enables firms to adopt AI technology competently — by addressing the confidentiality risks that would otherwise make AI use ethically problematic. Firms can demonstrate technological competence while protecting client data.
GDPR (EU Clients)
Law firms processing personal data of EU data subjects must comply with GDPR requirements for data protection, cross-border transfers, and data processor agreements.Shield's local redaction means personal data never crosses borders to AI providers. No data processor agreement is needed with the AI provider because they never receive personal data — only redacted placeholders.
State Bar Data Security
Many state bars now require reasonable data security measures. Firms must protect client data against unauthorized access, including through third-party technology vendors.Shield provides auditable protection with cryptographic hashing of every redaction event. Firms can demonstrate to state bar investigators exactly what data was protected and when — with tamper-evident logs.

Architecture

Client Data Never Leaves Your Firm's Network

Shield runs as a local proxy on your firm's machines. When an attorney, paralegal, or administrator sends a prompt to an AI model, Shield intercepts it — redacts all confidential data — and only then forwards the clean prompt to the external LLM. The redaction mapping stays on your machine, and responses are rehydrated locally before anyone sees them.

⚖️ Law FirmDMS / PMS / Emailprompt + confidential🛡️ ShieldRedacts & HashesAudit Log (local)clean prompt🤖 AI ProviderChatGPT / Clauderesponse rehydrated locallyYOUR FIRM NETWORKINTERNET

Local Installation

Install Shield on any Mac, Windows, or Linux machine in your firm. No cloud infrastructure, no vendor data access — client data never leaves your network.

One Environment Variable

Set SHIELD_PROXY_URL and every AI call from that machine flows through Shield automatically. Zero changes to your existing legal tech stack.

Tamper-Evident Audit Trail

Every redaction event is logged with a cryptographic hash. Demonstrate to clients, bar investigators, and courts exactly what data was protected and when.

Configurable Policies

Choose which data categories to redact. Add custom patterns for your firm's internal matter numbering and client coding systems. Run in audit-only mode to validate coverage first.

Ready to Protect Client Confidentiality in AI Workflows?

Shield runs on your firm's existing infrastructure. No cloud. No third-party data sharing. No privilege waiver risk. Deploy in under an hour and give your attorneys the AI tools they need — without compromising client confidentiality.

Explore ShieldTalk to Our Team

Frequently Asked Questions

It can — and that's the problem Shield solves. When you paste confidential client information into ChatGPT, Claude, or any cloud AI tool, you are disclosing that information to the AI provider. Under the attorney-client privilege, voluntary disclosure to a third party can waive the privilege — potentially for the entire subject matter, not just that one prompt. Shield eliminates this risk by redacting all confidential information before it leaves your firm's network. The AI provider never receives privileged content — only redacted placeholders. When the response comes back, Shield rehydrates the original terms on your machine, so you see the complete answer without the AI ever having seen the sensitive data.
Yes. Shield's filter packs catch structured identifiers (case numbers, bar numbers, SSNs, financial account numbers, policy numbers, NPI numbers, regulatory reference numbers) and unstructured confidential information (legal strategy discussions, settlement figures, deal terms, witness testimony). The secret detection engine uses entropy analysis to catch custom client codes, internal matter numbers, and proprietary naming conventions that regex patterns miss — common in large-firm matter management systems.
Shield provides a technical control that strengthens your NDA compliance. Most client NDAs require 'reasonable safeguards' for confidential information. By redacting confidential data before it reaches external AI providers, Shield creates a demonstrable technical safeguard. You can show clients — and regulators — exactly how their data is protected, with tamper-evident audit logs documenting every redaction event. This also simplifies client consent conversations: it's easier to get a client to agree to AI-assisted work when you can prove the AI provider never sees their confidential information.
Shield operates at the API layer, not the application layer. If a legal AI tool calls an external LLM provider (OpenAI, Anthropic, Google, etc.) through an API, Shield can intercept and redact those calls. If the tool uses its own proprietary models running on the vendor's infrastructure, Shield can still protect the outbound traffic — but the vendor's own data handling practices would also apply. Shield is complementary to legal AI tools: it adds a layer of protection for any AI call that leaves your network, regardless of which application initiated it.
Yes. When your firm represents EU-based clients or handles data subject to GDPR, cross-border data transfers to AI providers (most of whom operate US-based infrastructure) create compliance challenges. Shield solves this by ensuring that personal data never crosses borders in the first place — it's redacted locally before any API call leaves your network. The AI provider receives only placeholders, not personal data. This eliminates the need for Standard Contractual Clauses or data processing agreements with AI providers for the redacted data categories.
No. Shield operates at the network perimeter, redacting data as it leaves for external AI providers. Your internal systems — including conflict check databases, document management systems, and matter management platforms — continue to operate normally. Shield only intercepts outbound API calls to external LLM providers. It doesn't touch your internal network traffic or interfere with any internal legal software.