The question every solicitor asks first: where does the data go?
Nowhere. This page is the honest, detailed answer — not a footnote, because for a firm bound by client confidentiality and GDPR, this is usually the actual buying decision.
On-premises by design
The AI models that read, summarise and draft run on your firm's own hardware. There's no architecture in which a client document is sent out for processing — it isn't an option that gets switched off, it was never built as a path in the first place.
No third-party AI API calls
No client document, name or PPS number is ever sent to OpenAI, Anthropic, Google or any other external AI provider. Not for a "quick check," not as a fallback — never.
Irish data residency
Client data stays on infrastructure the firm controls, in Ireland, under the firm's own IT governance — not routed through a foreign cloud region as an implementation detail.
The AI is never the last step in a decision
Nowhere in the platform does the AI autonomously file a document, send it anywhere, or make a client-facing decision without a solicitor or staff member explicitly confirming it. The AI's job is the first 90% — read, extract, rank, draft, suggest. The last 10% — the actual decision — is always a person's.
This isn't marketed as a workaround for something the AI can't yet do on its own. It's the model, on purpose, because a firm's professional obligations don't transfer to software.
Where confirmation happens
| Action | Who confirms |
|---|---|
| Filing incoming post to a client file | Staff member, one click |
| Marking a checklist item complete | Fee-earner or staff |
| Sending a drafted letter or note | Solicitor |
| Closing a compliance review | Reviewing solicitor |
| Treating a conflict flag as cleared | Firm's conflict process |
Every output can be checked in seconds — and nothing fails silently
Citations, not assertions
Findings cite their source — the actual passage in the actual document — so a solicitor can verify an answer without re-reading the whole file.
Confidence-based routing
When the AI isn't confident — a hard-to-read scan, an ambiguous client match, a borderline compliance call — the item routes to a person instead of guessing.
Flagged, logged, and emailed
Failed or uncertain actions are flagged, logged, and emailed to a named person. Nothing is silently dropped, and there's always a record of what happened and why.
Designed around the obligations a solicitors' firm already carries
Data minimisation in style-learning
When Lexicore learns a firm's document templates to draft in-house style, sensitive client data is stripped out first — the model learns the firm's phrasing and structure, not its clients' personal details.
No secondary use of client data
Client documents are used to serve that firm, for that firm's own matters — not pooled, not used to train a shared model, not repurposed for any other firm or any other purpose.
Controller stays the firm
The firm remains the data controller throughout. Lexicore runs inside the firm's own infrastructure and governance rather than introducing a new external processor relationship for client documents.
An audit trail that holds up
Every AI suggestion, every human confirmation, and every flagged exception is logged — the kind of record a firm can stand behind if a file is ever questioned.
Data protection obligations sit with each firm as data controller. Lexicore's role is to make the technical footprint as small and as firmly on-premises as possible — firms should still confirm specifics against their own DPO's requirements before go-live.
Ask us the hard question directly
Happy to walk your IT lead or DPO through exactly how the infrastructure is set up — before any file goes near it.