ClientShield Tracks B and C run Claude Opus 4.8 on Amazon Bedrock inside a private VPC — no public internet traversal, no shared inference infrastructure, no data commingling. SOC 2 Type II. HIPAA-eligible. Contractually zero training on your documents. The compliance stack a firm's security committee actually asks for.
Three hops. All inside AWS. No third-party model providers. No public model endpoints. No prompt logging outside your account boundary.
Document uploaded over TLS 1.3 to the ClientShield application, deployed in AWS us-east-1 with per-tenant DynamoDB partition isolation and customer-managed KMS keys.
Inference request travels a PrivateLink endpoint — never the public internet — into a Bedrock VPC endpoint. Prompt and response stay inside your AWS account boundary.
Response returned over the same private path. Nothing is retained by the model provider. Nothing enters a training set. Nothing is visible to Anthropic or to other tenants.
Every legal-AI vendor claims some version of this. The specifics matter. Here's what we mean, in the language your security committee will want to verify.
Amazon Bedrock does not store prompts or responses after the inference call completes. Anthropic, as the underlying model provider, contractually does not receive customer data through Bedrock. Confirmed in the AWS Bedrock service agreement and Anthropic's data-handling addendum for Bedrock deployments.
Your documents are not used to fine-tune, retrain, evaluate, or improve any foundation model. This is not a policy we chose — it is the default posture of Bedrock's foundation-model API and it is enforced at the platform layer, not at the vendor layer.
All inference is pinned to a specific AWS region (default: us-east-1). Requests do not fail over to other regions or providers. Cross-border data transfer is not a concern because there is no cross-border traversal.
DynamoDB partition-key isolation ensures no cross-tenant data access at the storage layer. Your firm's documents, embeddings, and audit logs are physically separable from every other tenant's data, and can be exported or deleted independently.
Every document access, every inference call, every user action logged with immutable CloudTrail entries. Exportable for your firm's internal audit or a client's diligence request. Six-year retention by default to align with common ethics-rule documentation requirements.
Most legal-AI vendors run on shared, multi-tenant inference. SOC 2 Type II covers process — not architecture. Here is what the underlying deployment actually looks like.
The exact artifacts a firm-level or client-side diligence process asks for.
Amazon Bedrock's SOC 2 Type II report is annually audited by third parties. ClientShield's application layer inherits Bedrock's infrastructure controls and adds tenant isolation, PII tokenization, and audit logging as described in our Type-II bridge letter — available under NDA.
Signed DPA with technical and organizational measures, sub-processor list (AWS, Anthropic-via-Bedrock, CourtListener), transfer mechanisms, and DSAR support. Aligned with GDPR requirements even for U.S.-only firms handling international clients.
Documented model version pinning, deprecation policy, prompt-injection defenses, and Bedrock Guardrails configuration. Every inference call is versioned and reproducible for audit or expert-witness purposes.
Data-flow diagrams for ingest, inference, storage, export, and deletion. IAM boundary conditions restricting Bedrock access to VPC-endpoint sources only. VPC-endpoint policy documented at the resource level.
Print this. Send it to every vendor you evaluate. ClientShield answers "yes" to all seven.
5-day free trial of Track C — the full platform, including private-VPC inference, on Claude Opus 4.8, with SOC 2 Type II and HIPAA-eligible infrastructure.
No credit card required for the 5-day trial