Privilege-safe AI for law firms of every size: an open, self-hosted stack we build, run, and support, on hardware you own.
Legal AI settled fast into an easy default: rent seats on Harvey or Legora, accept the vendor cloud, call it a strategy. It buys real capability, and it buys the same capability for every rival at the same price. The quieter cost is what the firm hands over on the way in: its positions, its fallbacks, its precedent, its intake habits, poured into a platform it cannot inspect, on a per-seat meter, while its own clients adopt those very tools to stop needing outside counsel. A second path is now genuinely available, and it is not a research project. Open, self-hosted legal AI where privileged matters are pinned to sealed local inference by architecture, with the practice apps around it, runs today on a single machine in a small office, and scales to a firm-wide deployment.
The shifts our research is tracking, named, current, cited.
Harvey reached an $11B valuation with clients running 25,000+ custom agents; Legora raised at a reported $5.6B as the AI operating system for the legal industry. Legal AI works, and every rival can rent exactly the same intelligence.
Harvey →OpenAI's case study on Hebbia is titled, plainly, Automating 90% of finance and legal work with agents. In-house teams are adopting the same platforms firms rent, to stop needing firms. Differentiation has to come from somewhere a vendor cannot sell twice.
OpenAI →The LegalQuants community, lawyer-builders across 17+ jurisdictions, maintains LQ.AI and Donna: open-source legal AI that runs against models you choose, including local open-weight ones, seals privileged matters to local inference by architecture, and verifies every citation character by character.
LegalQuants →The todo.law suite, DPO Central for privacy programmes, Dealroom for clause-by-clause negotiation, AI Sentinel for the EU AI Act, plus Clausemaster and VendorWatch, is open source and self-hostable, with attorney-authored skills licensed per deployment instead of per seat.
todo.law →In legal, privilege decides the compute: the vendors are table stakes every rival can rent, and the firms that compound are the ones that own their harness, their playbooks, and their proof.
The vendor platforms are good, and that is the problem. Capability every competitor can rent is a subscription, not an edge. Rent the layer that embodies your know-how and you are paying, per seat, to teach a system you will never own, in a cloud you cannot audit, while in-house teams buy the same thing to bring work back inside.
So we ship the other half. Donna on the LQ.AI engine gives a firm conversational research with character-verified citations, matter workspaces, knowledge bases, and a tool loop that asks before it reaches anywhere. Underneath it sits a five-tier inference gateway with a hard floor: a privileged matter at Tier 1 is sealed to local inference and the gateway refuses, outright, to route it outward. Around it runs the todo.law suite for the deterministic practice work, privacy programmes, contract negotiation, AI governance, vendor risk. On top of it we compile the firm's own clause libraries and positions into installable skills, in an open format, licensed per deployment rather than per seat.
You choose the posture, not the vendor: a hosted pilot in days, one script on an office computer, an isolated instance we run for you, or dedicated AI hardware in your own building that runs air-gapped. We deploy it, encode your knowledge into it, tune and support the models, and keep it current with backups first and migrations you can read. The proof is dual: the speed of AI-assisted delivery, and a routing log that shows a client exactly which systems touched their matter, at which tier. Clients have started asking. Be the firm with a good answer.
| Workload | Placement | Rationale |
|---|---|---|
| Privileged review, drafting, and matter chat | Sovereign | Sealed local inference on firm hardware. The gateway refuses to route privileged work outward, so this is enforced by architecture, not by policy. |
| Firm playbooks, clause positions, and skills | Sovereign | The moat. Your drafting judgment compiled into installable skills in an open format, running on a deployment you own. |
| Practice operations: privacy programmes, negotiation, AI governance | Sovereign | Deterministic apps that make no model calls at all until you switch one on. Self-hosted, one codebase, your database. |
| Bulk triage, classification, and summarisation | Sovereign | A small local model runs these at near-zero marginal cost (this is the workload where self-hosting actually pays for itself). |
| Hard, non-privileged research and public-law drafting | Frontier | Anonymised, zero-retention, EU-region lanes. Rent top capability precisely where it is safe, and never on the consumer tier. |
Before any platform decision, one question settles the rest: how much of what your organisation knows can be written down precisely enough for a machine to act on it, and who ends up owning that writing. We run a short engagement to answer it, and it produces working artefacts rather than a report.
Two artefacts come out of this. An operating ontology, the nouns: the entities, relationships, and states your business actually runs on, described once and precisely. And agentic skills, the verbs: the procedures, thresholds, and judgments your best people apply, written down, versioned, and testable instead of retold.
A placement map addressed to the CTO or CIO office: what runs on your compute, what is bought, what is rented, who holds the keys, and what each costs. One test cuts through most of the debate. If a supplier vanished on a Friday, what stops working on Monday, and how long would it take you to replace it?
Where an open-weight model fine-tuned or adapted on your own corpus beats a frontier call, where a small purpose-built model for one narrow task beats both, and where the frontier still earns its fee. Geographic sovereignty falls out of that answer rather than having to be argued for on its own.
Privileged corpora cannot lawfully train anyone else's model, which makes a small model adapted on your own work, on your own hardware, the only version of this that can exist.
This is a CTO and CIO office engagement, not a procurement exercise. Your own people have to end up running it, because the moment the encoding is delegated, the thing being encoded quietly stops being yours.
Palantir calls this layer an ontology, and the idea is right: a governed model of your objects, links, and actions that agents can act on. It lives inside their platform. 8090 will design, build, host, and maintain the software around it for you. Both are serious, and both leave the same question open. At the end of it, who owns the layer that holds your judgment? We build the same artefacts in open formats, on compute you control, and hand your CTO the keys.
Legal is the vertical where our application layer is already a finished product. It runs every day in an AI-native boutique practice, on a laptop, and every line of it is open source, so a firm can read it before it trusts it.
DPO Central for privacy programmes, Dealroom for clause-by-clause negotiation, AI Sentinel for the EU AI Act, with Clausemaster and VendorWatch alongside. Deterministic by default: out of the box these apps make no model calls at all, and a named administrator has to switch the assistant on before they ever do.
Matter workspaces, firm knowledge bases, and conversational research with citations verified character by character, inside a governed tool loop that asks for approval before it reaches for case law or any connected system. Built by the LegalQuants community, adopted, run, and supported by us.
We turn the firm's clause libraries, positions, and fallbacks into installable skills in an open format: standard language, the ladder of fallbacks, red flags, a severity rubric, jurisdiction notes. Premium skills carry a named lawyer's attestation and are licensed per deployment, never per seat.
A five-tier inference gateway with a hard floor. A privileged matter at Tier 1 is sealed to local inference and the gateway refuses, outright, to route it outward. Anything that does leave is pseudonymised first, and every call lands in an append-only audit log.
One script on an office computer, an isolated instance we operate, or dedicated AI hardware on a shelf in your own building (128 GB of unified memory, open-weight models up to 120B parameters, quiet enough for the front office, and able to work with the network unplugged).
The suite and the assistant are in daily use at an AI-native boutique practice, self-hosted, on local inference, with the firm's own review skills installed.
todo.law →Everything above is open source and public. The links go to the running product, not to a brochure.
The same software in every posture, so a team can start hosted and end up air-gapped without a migration project. You move along the ladder when you decide to, not when a contract renews.
Your stack stood up on our infrastructure in days and pointed at real work, so it is judged on your matters rather than on a demo. The pilot fee credits against the hardware when you migrate.
Teams that want proof before capital expenditure.
The open-source cores installed on a machine you own, by a script anyone can read first. No account with us, no telemetry, no phone-home. Code flows one way, from us to you, and only when you ask for it.
Small teams, and anyone who wants to inspect the source before trusting it.
An isolated instance per client on sovereign infrastructure, European by default, run, patched, and monitored by us, with the security and backup credentials in your hands rather than ours.
Organisations without an infrastructure team to spare.
Dedicated AI hardware inside your building, with the applications and the open-weight models you choose installed and tested before it ships. It runs with the network unplugged, and it keeps working whatever happens to us.
In legal we ship the appliance as a finished thing: the suite, the assistant, and the open-weight models you choose, installed and tested before the box leaves our hands.
Work that cannot leave the building, ever.
Not promises. Consequences of the architecture: your keys and your data are generated on your machine and stay there, and nothing calls home.
The first of three essays arguing that a law firm's real exposure is not AI, it is renting the layer its differentiation lives in.
Convergence makes model capability a commodity, which puts the value back where it always was: in the boring, deterministic scaffolding.
Where agentic AI and a curated, lawyer-directed skeleton meet, and the two kinds of law firm that come out of it.
We build and operate the suite under the todo.law name: the practice apps, the Donna assistant on the LQ.AI engine, the skills marketplace, and the appliance. Install it yourself on one office computer, let us run an isolated instance, or take the box. Firms of two partners and firms of two hundred start from the same page.
Open source (AGPL for the practice apps, Apache-2.0 for the assistant). Read the code before you trust it, run it yourself, or have us run it.
We send a sector-specific brief with workload-by-workload placement guidance and a reference architecture for sovereign deployment.