Secure document sharing for law firms carries an ethical duty that other industries do not have, which changes both the shortlist and the diligence questions.
At a Glance
| Buy (commercial platform) | Build (in-house) | Add private AI | |
|---|---|---|---|
| Solves for | Fast deployment, vendor-managed compliance | Full control over keys and infrastructure | Privilege-review assistance, without exposing content to a public model |
| Named tools | Kiteworks, Virtru Collaborate, Tresorit, FileCloud | Custom architecture on audited cryptography libraries | Self-hosted open-weight models (Mistral, Qwen, and similar) |
| Who holds the keys | The vendor, unless you pay for key-sovereignty add-ons | Your firm, by design | Same as whichever base system you chose |
| Typical cost | Enterprise per-seat licensing, key-sovereignty tiers priced higher | Engineering time, then ongoing maintenance | From ~$0.805/hr on a 24 GB instance; faster cards cost ~25% more |
| Biggest risk if done wrong | Trusting a vendor's data-handling policy over verifiable key custody | Underestimating everything outside the encryption itself | Treating an AI flag as a legal determination |
Why This Is a Different Problem for Law Firms Than for Anyone Else
Secure document sharing for law firms is not a generic file-transfer problem with a legal label on it. Lawyers carry a specific exposure that most industries don't: an ethical duty, not just a contractual one, to protect client confidences, and a body of case law that's actively being written on what that means for electronic tools. ABA Formal Opinion 477R holds that attorneys must use "reasonable efforts" to prevent inadvertent disclosure of client confidences in electronic communication, and it explicitly requires understanding who controls the encryption keys before trusting a cloud service with privileged material. ILTA's 2025 Security Benchmark treats AES-256 encryption at rest and TLS 1.2+ in transit as the floor for legal document sharing, not a competitive feature.
That last point matters because the stakes for getting it wrong aren't hypothetical anymore. In February 2026, a ruling in the Heppner matter held that using a consumer AI tool whose terms of service allowed data retention and third-party disclosure destroyed attorney-client privilege and forfeited work-product protection entirely. Contrast that with Warner v. Gilbarco, where a federal court in the Eastern District of Michigan declined to compel production of documents a self-represented litigant had prepared using a public AI chatbot, finding work-product protection had survived. The difference between those two outcomes wasn't the technology. It was how the tool handled the underlying data.
Option 1: Buying a Purpose-Built Legal Platform
Several vendors compete specifically on the detail that matters most to a law firm: who actually controls the keys.
- Virtru Collaborate offers a Private Keystore option, letting a firm host its own encryption keys on-premises or in its own cloud tenant rather than trusting a vendor with them, at a higher pricing tier than the standard product.
- Kiteworks positions itself around governance across every channel a firm uses to move privileged material, aiming for a single audit trail rather than one per tool.
- Tresorit built its pitch specifically around lawyers and professional secrecy, using end-to-end encryption structured so no Tresorit employee or third party can access client files.
- FileCloud rounds out the field with a similar private-file-sharing focus aimed at the same buyer.
The tradeoff across all four: you get a vendor's engineering, support, and (for the higher tiers) genuine key sovereignty, in exchange for per-seat licensing that scales with headcount and, for the more advanced tiers, a meaningfully higher price than a basic encrypted-portal product.
Option 2: Building It In-House
The underlying mechanism every one of those platforms relies on isn't proprietary. It's a pattern called envelope encryption, and it's straightforward enough that a small engineering team can build and test it directly rather than take a vendor's word for how it works.
We did exactly that, building a working system called Sealwax specifically to understand this architecture from the inside rather than from a vendor's marketing page. The mechanism: every document gets a random encryption key belonging to it alone, that key is sealed separately to each recipient's public key so only they can unlock it, the notification carries a link rather than the document itself, and destroying a document later means destroying every sealed copy of its key, not just the file, which is what makes deletion actually permanent rather than merely hidden. We tested it with 82 automated tests, including a scenario in which an unrelated third party is confirmed to have no way to decrypt a message they were never sent, exactly the property a firm would need before trusting a system with privileged material.
Building this took roughly the effort of one focused engineering sprint for the core mechanism, plus a comparable amount of time for the test suite that actually proves it holds up, in our case, more lines of test code than application code, a ratio we'd argue is closer to correct than the reverse for anything touching privileged material. What building doesn't include, on its own, is everything a firm actually needs before privileged material touches it: independent security audit, integration with existing practice or document management systems, and the operational discipline to keep a security-critical system patched indefinitely. That's the honest cost of "build" beyond the architecture itself.
Consumer AI tool, terms allowed retention and third-party disclosure.
Public chatbot used by a self-represented litigant.
Not whether AI was involved at all.
Option 3: Custom Integration With Private AI for Privilege Review
This is where 2026's most consequential development for law firms sits, and it's directly downstream of the Heppner ruling. If sending a document to a public AI tool for review can destroy privilege, then any AI assistance a firm wants, drafting help, document summarization, or privilege screening during e-discovery, has to run somewhere the firm controls entirely.
The current consensus among firms building this capability: on-premise deployment is the gold standard for sensitive matters like criminal defense or national security work, with hardware inside the firm's own data center under its existing physical and network safeguards. A slightly lighter-weight version provisions the model inside the firm's own cloud tenant, so the network boundary, logging, and retention settings stay under the firm's administrators rather than a vendor's. Either way, the model never sends firm data to OpenAI, Google, or Anthropic's own servers, which is the entire point.
Two things are worth being direct about before treating this as a solved problem. First, cost, and it is worth being precise because privilege review is bursty rather than constant. Our directory of 24 openly licensed models records VRAM measured at 4-bit and 8-bit quantisation alongside named cloud instances and their memory bandwidth, which is what actually sets review throughput. A model capable of document triage at this level sits in the 24 GB class: roughly $0.805 an hour on an AWS g6.xlarge, or $1.006 on a g5.xlarge, which has the same memory but twice the bandwidth and is therefore close to twice as fast for the same job. For a firm that runs privilege review in concentrated bursts around a production deadline, paying by the hour on the faster card is usually cheaper per document than a dedicated machine sitting idle between matters. Second, and more important: AI cannot currently determine legal privilege on its own. As of 2026, no mainstream AI platform reliably predicts privilege with precision above roughly 85% on real e-discovery datasets, which means the correct use of AI here is to flag candidates for human review, never to make the determination itself, because the cost of a false negative, a waived privilege, vastly exceeds the cost of over-flagging.
Used this way, a private model layered on top of either a bought platform or a custom build genuinely speeds up privilege review and document triage, without ever putting the firm in Heppner's position.
A Concrete Scenario: Sharing a Discovery Production
Picture a mid-sized litigation firm producing 400 documents to opposing counsel in discovery. Under a properly built system, each document is encrypted with a key belonging to it alone, sealed to the specific paralegal or attorney authorized to receive it, and delivered as a link rather than an email attachment. If a clawback becomes necessary, a produced document turns out to have been privileged after all, revoking access means destroying the sealed key for that one document, not scrambling to recall an email that's already been forwarded, downloaded, and possibly saved to a local drive by the recipient. The access log shows exactly when the document was opened and by whom, which matters directly if a dispute later arises over whether opposing counsel reviewed a document before or after a clawback request was sent.
That single capability, provably revocable access after the fact, is the single clearest advantage this architecture has over emailing a PDF, and it's worth testing directly with any platform under consideration, ask a vendor to demonstrate a clawback in a sandbox environment before signing a contract.
Where This Goes Wrong
The most common mistake firms make isn't choosing the wrong platform, it's assuming a signed vendor contract answers the ABA 477R question on its own. A vendor's terms of service can promise encryption while still reserving the right to access content for support purposes, retain data for longer than the firm expects, or hand data to a third party under specific circumstances, exactly the pattern that destroyed privilege in the Heppner matter. Reading the actual data-handling terms, not just the marketing page, is the diligence step firms skip most often.
A second common mistake is treating AI-assisted privilege review as a replacement for attorney judgment rather than a triage step. Given that no mainstream platform currently exceeds roughly 85% precision on real e-discovery datasets, a firm that lets an AI tool make final privilege calls without human review is accepting a false-negative rate that could waive privilege on documents that should have been withheld, a far more expensive mistake than the time saved by skipping human review in the first place.
The Cost of Getting This Wrong
Data breach costs vary sharply by industry, but the professional-services pattern is consistent: the more sensitive the underlying data, the more expensive the eventual breach. Healthcare, the most directly comparable regulated industry with published 2026 figures, averages $6.64 million per breach globally, and UK organisations across all sectors averaged £3.13 million per incident the same year. A law firm breach carries a cost most of those figures don't even capture: a waived privilege doesn't just expose data, it can determine the outcome of the underlying matter itself, a cost with no equivalent dollar figure because it's measured in case outcomes, not just remediation spend.
That asymmetry, a modest ongoing platform cost against a potentially case-determining failure, is why firms in this space have converged on purpose-built tools rather than general-purpose encrypted email, and why the diligence question is never really "is it encrypted." It's "who could be compelled to hand over the keys, and under what circumstances."
- 01Who holds the keys
Could the vendor be compelled to decrypt your files, or only your firm?
- 02What happens at contract end
Is firm data deleted, and can that deletion be proven rather than asserted?
- 03Where does their AI send content
Do the vendor's own AI features pass documents to a third-party model provider?
A Decision Framework for Law Firms
Buy makes sense when you need a signed data-handling agreement and a working system quickly, and your firm doesn't have engineering capacity to maintain a custom platform indefinitely.
Build makes sense when your volume and headcount justify the engineering investment, you need deployment flexibility a commercial platform doesn't offer, such as integration deep inside a specific practice management system, or genuine key sovereignty is a client requirement you can't satisfy any other way.
Add private AI when manual privilege review or document triage has become the actual bottleneck in a matter, and you can commit to keeping the model's role advisory, flagging for a human, rather than determinative.
What This Means If You're Evaluating This for Your Firm
The Heppner ruling changed the calculus for every firm considering AI tools, not just the ones already using them: the question isn't whether AI can help with document review anymore, it's whether the specific deployment you're using can survive a challenge to privilege. That's a due-diligence question worth asking about any encrypted document platform, too, not just the AI layered on top of it: not "is it encrypted," but "who controls the keys, and could you prove it in a motion."
There's also an integration question that determines whether any of these three paths actually gets used day to day. A secure delivery layer that lives outside a firm's existing practice or document management system, Clio, NetDocuments, or iManage, requires attorneys and paralegals to leave their normal workflow to use it, which is exactly the kind of friction that leads busy litigators back to email attachments within a month of rollout. Whichever path a firm chooses, buying a platform, building one, or layering AI on top, the integration question deserves as much diligence as the encryption question, because a secure tool nobody actually uses provides no protection at all.
If key custody is the sticking point, that is a scoping conversation rather than a product comparison, and it is the one we would rather have first. Book a strategy session, or run the AI readiness score to see honestly whether your document systems are ready before any vendor call.
A custom delivery layer integrated into Clio, NetDocuments or iManage sits under our AI automation development service, with the diligence work itself under AI consulting. Tiers are on the pricing page.
Related reading: how to tell if an AI agency can actually build it is the wider version of the vendor-diligence questions above, and AI automation under UK GDPR and HIPAA covers the regulated-data boundary.
Where This Sits in the Wider Picture
The architecture described here is not specific to legal. The same four properties, a unique key per document, a link rather than an attachment, sender-controlled revocation, and a complete access log, show up independently across every regulated industry facing this problem, each for a different regulator and a different worst case.
We built a working system to understand it from the inside rather than from vendor documentation, and published what it cost, what it proved, and what it did not, in secure document delivery across six regulated industries. The healthcare version of the build-versus-buy decision, including the gap list we published rather than hid, is in HIPAA secure messaging: build vs buy.
For the same decision in a different vertical, see title and escrow and accounting and tax.
Frequently Asked Questions
Does using AI on a document automatically waive privilege?
Not automatically, but it depends entirely on the tool. The Heppner ruling found that a consumer AI tool whose terms of service permitted data retention and third-party disclosure destroyed privilege, while a separate case found work-product protection survived use of a public chatbot under different circumstances. The deciding factor is how the tool handles the underlying data, not whether AI was involved at all.
What does "who controls the keys" actually mean in practice?
It means asking whether a vendor could technically decrypt your firm's documents if compelled to, or whether only your firm holds the keys required to do so. Products like Virtru's Private Keystore exist specifically to let a firm answer "only us" rather than "the vendor, in theory."
Is on-premises AI actually necessary, or is a compliant cloud vendor enough?
For the most sensitive matters, criminal defense and national security work specifically, on-premises deployment inside the firm's own data center is considered the current gold standard. For less sensitive work, a private cloud tenant under the firm's own administrative control is a reasonable middle ground.
How accurate is AI at identifying privileged documents?
Not accurate enough to rely on alone. As of 2026, no mainstream platform reliably predicts privilege with precision above roughly 85% on real e-discovery datasets, which is why AI's role should be flagging candidates for a human reviewer, never making the final call.
What would it cost a mid-sized firm to build this instead of buying it?
The core encryption mechanism is buildable in roughly one engineering sprint, with a comparable investment in testing. The larger, ongoing cost is everything around it: integration with existing practice management systems, independent security audit, and long-term maintenance, which a commercial platform's licensing fee is effectively paying someone else to own.
Does adding a private AI layer replace the need for encryption in the first place?
No, it depends on it. The AI layer only makes sense once the underlying documents are already encrypted and access-controlled; its job is to help review and triage what's already protected, not to replace the protection itself.
What should a firm ask a vendor before signing a contract for this kind of platform?
Three questions cover most of the risk: who technically holds the decryption keys and under what legal process could they be compelled to disclose them; what happens to firm data if the contract ends, is it deleted, and can that be verified; and does the vendor's own AI features, if any, send document content to a third-party model provider as part of normal operation. A vendor unable to answer the first question clearly is not a vendor that has thought seriously about attorney-client privilege.
Syed Rayyan is co-founder of ValueStreamAI, leading research and marketing. He runs the firm's evaluation of emerging AI and healthcare tooling and translates technical capability into clear guidance for non-technical decision-makers. Connect on LinkedIn →
