Security & Privacy

The question every solicitor asks first: where does the data go?

Nowhere. This page is the honest, detailed answer — not a footnote, because for a firm bound by client confidentiality and GDPR, this is usually the actual buying decision.

On-premises by design

The AI models that read, summarise and draft run on your firm's own hardware. There's no architecture in which a client document is sent out for processing — it isn't an option that gets switched off, it was never built as a path in the first place.

No third-party AI API calls

No client document, name or PPS number is ever sent to OpenAI, Anthropic, Google or any other external AI provider. Not for a "quick check," not as a fallback — never.

Irish data residency

Client data stays on infrastructure the firm controls, in Ireland, under the firm's own IT governance — not routed through a foreign cloud region as an implementation detail.

Human-in-the-loop, not a limitation

The AI is never the last step in a decision

Nowhere in the platform does the AI autonomously file a document, send it anywhere, or make a client-facing decision without a solicitor or staff member explicitly confirming it. The AI's job is the first 90% — read, extract, rank, draft, suggest. The last 10% — the actual decision — is always a person's.

This isn't marketed as a workaround for something the AI can't yet do on its own. It's the model, on purpose, because a firm's professional obligations don't transfer to software.

Where confirmation happens

ActionWho confirms
Filing incoming post to a client fileStaff member, one click
Marking a checklist item completeFee-earner or staff
Sending a drafted letter or noteSolicitor
Closing a compliance reviewReviewing solicitor
Treating a conflict flag as clearedFirm's conflict process
Explainable and reversible

Governance infrastructure, not just a feature

Every output can be checked in seconds, and nothing fails silently — which means what starts as a time-saver also holds up as a compliance record.

Citations, not assertions

Findings cite their source — the actual passage in the actual document — so a solicitor can verify an answer without re-reading the whole file.

Confidence-based routing

When the AI isn't confident — a hard-to-read scan, an ambiguous client match, a borderline compliance call — the item routes to a person instead of guessing.

Flagged, logged, and escalated

Failed or uncertain actions are flagged, logged, and emailed to a named person — not just for recovery, but as a standing record a firm can point to if a file is ever questioned. Nothing is silently dropped.

GDPR posture

Designed around the obligations a solicitors' firm already carries

Data minimisation in style-learning

When Lexicore learns a firm's document templates to draft in-house style, sensitive client data is stripped out first — the model learns the firm's phrasing and structure, not its clients' personal details.

No secondary use of client data

Client documents are used to serve that firm, for that firm's own matters — not pooled, not used to train a shared model, not repurposed for any other firm or any other purpose.

Controller stays the firm

The firm remains the data controller throughout. Lexicore runs inside the firm's own infrastructure and governance rather than introducing a new external processor relationship for client documents.

An audit trail that holds up

Every AI suggestion, every human confirmation, and every flagged exception is logged — the kind of record a firm can stand behind if a file is ever questioned.

Data protection obligations sit with each firm as data controller. Lexicore's role is to make the technical footprint as small and as firmly on-premises as possible — firms should still confirm specifics against their own DPO's requirements before go-live.

Ask us the hard question directly

Happy to walk your IT lead or DPO through exactly how the infrastructure is set up — before any file goes near it.

Talk to Us
Talk to Us