Docket Entry

Agentic litigation: security and confidentiality

Security comes before the contract.

Before your firm commits to anything, we prove the confidentiality boundary with you, live. No obligation. No client data. Synthetic information only.

Your firm supplies information we cannot know. We supply information you cannot know. Both enter the drafting environment. The test shows the system used both, and that neither side’s information reached the other.

If it does not pass, we do not move forward. If your team puts time into the test, we match it.

Every connection your firm adds is inside the verification test.

What the boundary is.

We cannot read your files. Your matter is worked on inside the sealed drafting environment, on hardware built to keep what is inside apart from the platform that hosts it and from Docket Entry. We operate the environment, and operating it is not seeing into it. Our people, our website and our administrative tools are designed to hold your contact details, and not the contents of your matter. That is the boundary the test proves. The next section shows who can see what.

Who can see what?

Who can see what
WhoWhat they can receive
Docket EntryYour name, firm and work email, and the status of each job. It is designed to hold none of the contents of your matter.
The sealed environmentYour case files and instructions, the working drafts and the finished draft. Docket Entry is built so that it cannot see inside.
Approved AI providersThe text being worked on, sent with each drafting request. They read it in plain form, outside the sealed environment.
Legal research providersSearch queries, to find and check authorities. A query can show what a case is about.
Your firmThe finished draft. Your lawyers review it, change it and decide what goes to the court.

The distinction that matters: Docket Entry is built so that it cannot read your matter. The outside AI and research providers are different. They sit outside the sealed environment, and each receives what its part of the work requires. The AI providers read that text in plain form.

Technical details

For your technology lead.

Attestation and release fingerprints

The environment produces a cryptographic statement of the exact software and settings it is running. That statement is compared with the fingerprint published for the release, and the system is built to send nothing if the two differ. Each release is signed and its measurement recorded. This has been verified in testing, on test releases.

Credentials

Inside the environment, one component is given the credentials for saved working material: the component that saves it. No other part of the environment is given them.

Encryption in transit and of saved working material

What is sent into the environment is built to travel encrypted. Working material saved so that a job can resume after a restart is stored encrypted, in cloud storage. In testing, an interrupted job resumed from an encrypted checkpoint.

Logging

The system is built to keep confidential values out of logs, links and ordinary requests. That is a rule written into its design. The logs that outside providers keep are their own, and sit outside it.

Retention

Your name, firm and work email are kept up to 24 months after the last contact, as the privacy policy says. Technical logs are kept only as long as needed. Working material saved for a job is built to be deleted once the draft has been collected.

Hostile-content handling

The system is built to treat every motion, exhibit, email and research result as evidence, never as instructions. Other limits are fixed outside the job altogether: a job cannot set its own identity, budget, model, instructions or release, and the list of outside services the drafting environment may reach is fixed at the hosting platform level. A document cannot change any of them.

Provider handling

AI providers sit outside the sealed environment’s hardware isolation and read the text they are sent in plain form. They are on the short, fixed list of services the drafting environment may reach. Every request is built to carry an instruction to the provider: do not collect this text and do not train on it. It is an instruction to the provider, not something Docket Entry can observe. Legal research providers receive search queries.

Questions

Do the AI providers see our documents?

Yes. The text being worked on goes to them with each drafting request, and they read it in plain form. They sit outside the sealed environment.

Do they train on our documents?

Each request is built to carry an instruction to the provider: do not collect this text and do not train on it. The system is built to refuse any provider that will not honour that instruction.

Can Docket Entry see which cases we are working on?

Docket Entry receives your name, firm and work email, and it sees the status of each job. The form takes nothing about a case, and Docket Entry is designed to hold none of the contents of your matter.

Can Docket Entry’s engineers log in to the environment?

By the hosting platform’s design, no operator can log in to it. That is a property of the platform.

What stops a malicious document from steering the system?

The system is built to treat every motion, exhibit, email and research result as evidence, never as instructions. A document also cannot change which model is used, what a job may spend, or which outside services the drafting environment may reach.

How can we verify any of this ourselves?

Before you commit to anything, we prove the confidentiality boundary with your firm, live, using synthetic information only. The environment also states which software it is running, each release is signed, and its fingerprint is published.

Start with the proof, not a client file.

Security is verified first, on synthetic information only. Do not send us confidential material or anything under court seal.

Try it