Private-VPC AI for law firms

Your firm's AI, in your own private cloud.
No shared endpoints. No training. Ever.

ClientShield Tracks B and C run Claude Opus 4.8 on Amazon Bedrock inside a private VPC — no public internet traversal, no shared inference infrastructure, no data commingling. SOC 2 Type II. HIPAA-eligible. Contractually zero training on your documents. The compliance stack a firm's security committee actually asks for.

Start Your 5-Day Free Trial Read the full security posture
SOC 2 Type II via Bedrock
HIPAA-Eligible
AES-256 · TLS 1.3
Zero training on client data

Where your data goes when you hit "Analyze"

Three hops. All inside AWS. No third-party model providers. No public model endpoints. No prompt logging outside your account boundary.

Step 01

Your browser

Document uploaded over TLS 1.3 to the ClientShield application, deployed in AWS us-east-1 with per-tenant DynamoDB partition isolation and customer-managed KMS keys.

Step 02 · Private VPC

Claude Opus 4.8 on Bedrock

Inference request travels a PrivateLink endpoint — never the public internet — into a Bedrock VPC endpoint. Prompt and response stay inside your AWS account boundary.

Step 03

Back to your browser

Response returned over the same private path. Nothing is retained by the model provider. Nothing enters a training set. Nothing is visible to Anthropic or to other tenants.

"No training on your data" — what that actually means

Every legal-AI vendor claims some version of this. The specifics matter. Here's what we mean, in the language your security committee will want to verify.

01

Zero-retention inference

Amazon Bedrock does not store prompts or responses after the inference call completes. Anthropic, as the underlying model provider, contractually does not receive customer data through Bedrock. Confirmed in the AWS Bedrock service agreement and Anthropic's data-handling addendum for Bedrock deployments.

02

No model improvement, ever

Your documents are not used to fine-tune, retrain, evaluate, or improve any foundation model. This is not a policy we chose — it is the default posture of Bedrock's foundation-model API and it is enforced at the platform layer, not at the vendor layer.

03

Region-pinned inference

All inference is pinned to a specific AWS region (default: us-east-1). Requests do not fail over to other regions or providers. Cross-border data transfer is not a concern because there is no cross-border traversal.

04

Per-tenant isolation

DynamoDB partition-key isolation ensures no cross-tenant data access at the storage layer. Your firm's documents, embeddings, and audit logs are physically separable from every other tenant's data, and can be exported or deleted independently.

05

Audit-log completeness

Every document access, every inference call, every user action logged with immutable CloudTrail entries. Exportable for your firm's internal audit or a client's diligence request. Six-year retention by default to align with common ethics-rule documentation requirements.

Why "private VPC" is not the same as "SaaS with SOC 2"

Most legal-AI vendors run on shared, multi-tenant inference. SOC 2 Type II covers process — not architecture. Here is what the underlying deployment actually looks like.

Public LLM API

ChatGPT · Gemini · Claude.ai

  • Shared multi-tenant inference
  • Prompts may be retained for abuse review
  • Public internet endpoints
  • Default training on user data (opt-out at best)
  • No SOC 2 scope over your matter
Typical legal-AI SaaS

Shared-VPC vendor

  • SOC 2 Type II — but on the app, not the model
  • Shared model endpoint across all customers
  • Data flows across vendor infrastructure
  • "No training" often only against the app's fine-tuned layer
  • Model provider terms opaque to you
ClientShield · Tracks B–C

Private VPC on Bedrock

  • PrivateLink to Bedrock — no public internet
  • Bedrock-level SOC 2 Type II and HIPAA-eligibility
  • Anthropic contractually excluded from your data
  • Zero-retention inference by platform default
  • Per-tenant KMS keys, per-tenant partition isolation

What your security committee gets from us

The exact artifacts a firm-level or client-side diligence process asks for.

SOC 2 Type II report (via Bedrock)

Amazon Bedrock's SOC 2 Type II report is annually audited by third parties. ClientShield's application layer inherits Bedrock's infrastructure controls and adds tenant isolation, PII tokenization, and audit logging as described in our Type-II bridge letter — available under NDA.

Data Processing Addendum (DPA)

Signed DPA with technical and organizational measures, sub-processor list (AWS, Anthropic-via-Bedrock, CourtListener), transfer mechanisms, and DSAR support. Aligned with GDPR requirements even for U.S.-only firms handling international clients.

Model governance documentation

Documented model version pinning, deprecation policy, prompt-injection defenses, and Bedrock Guardrails configuration. Every inference call is versioned and reproducible for audit or expert-witness purposes.

Architecture whitepaper

Data-flow diagrams for ingest, inference, storage, export, and deletion. IAM boundary conditions restricting Bedrock access to VPC-endpoint sources only. VPC-endpoint policy documented at the resource level.

The questions to ask any private-AI vendor

Print this. Send it to every vendor you evaluate. ClientShield answers "yes" to all seven.

Private-AI diligence — the seven questions

  • Is inference multi-tenant or single-tenant per customer? Ours: single-tenant path through a customer-scoped PrivateLink endpoint into Bedrock.
  • Does the model provider ever see prompt or response content? Ours: no — Anthropic is contractually excluded from Bedrock customer data.
  • Is data ever used to train, fine-tune, or evaluate any model? Ours: never — enforced at the Bedrock platform layer, not left to vendor policy.
  • Is inference pinned to a specific AWS region? Ours: yes — us-east-1 by default, region change requires an explicit customer request.
  • What is the retention period for prompts, responses, and embeddings? Ours: zero for the model call; customer-configurable at the storage layer.
  • Do you provide a SOC 2 Type II report with bridge letters? Ours: yes — Bedrock's report plus our application-layer bridge letter, under NDA.
  • Can we independently audit or export our data at any time? Ours: yes — full CloudTrail export, per-tenant DynamoDB export, and verifiable deletion including backups.

Your clients' secrets stay yours.

5-day free trial of Track C — the full platform, including private-VPC inference, on Claude Opus 4.8, with SOC 2 Type II and HIPAA-eligible infrastructure.

Start Your Free Trial Read the security page

No credit card required for the 5-day trial