AI-Switchboard

Trust and security

Last updated 2026-09-29

The client file, the drafts, the audit database and the transcripts never leave the firm's premises. The only thing that crosses the boundary is the text of a single drafting request and the model's reply, sent under the firm's own Anthropic account.

Where the data goes

  1. Fee-earners and support staff use a browser. Nothing is installed on their machines.
  2. One Windows machine in the firm runs AI-Switchboard under a dedicated service account. Roles, guardrails, secret scanning, verification gates and the review gate all run there.
  3. Each run starts one headless model CLI process, which sends the prompt for that run over HTTPS to the Anthropic API and receives the reply.
  4. Configuration, the audit database, transcripts and skills live in a single folder on that machine, and the firm backs that folder up to its own target.
  5. AI-Switchboard makes no outbound network calls of its own. There is no telemetry, no phone-home, and no remote access.

The model provider, under your own account

Your firm holds its own Anthropic account and contracts with Anthropic directly under its commercial terms. Anthropic does not train on API inputs under those terms, retains request content for thirty days with a trust-and-safety exception, and for firms in the EEA and UK the contracting entity is Anthropic Ireland, Limited. Because the firm holds the account, AI-Switchboard is not in the data chain for model traffic and there is no sub-processor list for it to publish.

Where we do process data: support

If you ask us to help interpret your audit database or transcripts during support, we see that content. That is the only processing role we hold, and it is covered by a short support-only data processing agreement in your terms. Nothing is processed without your request.

What the software enforces

Review gate, on by default
The Word export refuses an unreviewed run. A named fee-earner marks the draft reviewed and that name is stamped into the released document's footer.
Verification gates
A skill can declare a machine check. If it fails, the run fails, whatever the model reported about its own work.
Unconfirmed facts marked
The drafting skills are instructed to mark anything the supplied documents do not confirm as TO CONFIRM rather than assert it, and the Word export highlights each marker for the reviewer. An instruction is not a guarantee, which is why review is enforced before release.
Secret scanning
Output is scanned for credentials, which are redacted in storage and block the export.
Audit trail
Every completed run is logged, whatever started it: dashboard, API, scheduler or command line. The log records what ran, for whom, with which skill and which model, whether verification passed, and who reviewed it.
Named users and roles
In firm-server mode every user has a named account and a role. Administrative actions and ad-hoc runs are restricted to administrators.
Drafting only
AI-Switchboard is designed for drafting from firm-supplied material, not legal research or autonomous advice. It does not check authorities against a legal database. The model can still produce an incorrect or invented citation in a draft, so the named reviewer must verify citations and legal assertions against the source before release.

How AI-Switchboard supports the firm's obligations

The Law Society of Ireland's Guidelines for the Use of Generative Artificial Intelligence by the Legal Profession in Ireland (December 2025) address confidentiality, verification, supervision, competence and the firm's own accountability. This is a map of product controls to those areas, not Law Society approval or a claim that installing software makes a firm compliant. The firm must decide which work is suitable, assess the provider and its terms, train its people, and review its outputs.

On-premises installation
The client file, saved drafts and audit record stay on a machine controlled by the firm. This supports the guidance's "Duty of Confidentiality and Privilege" discussion of local or firm-controlled systems as one possible safeguard. It does not mean all data stays on site: each drafting request's text is sent to Anthropic and the reply comes back.
Firm-owned Anthropic account
The firm holds the model account and pays Anthropic directly, rather than using a staff member's consumer chatbot account. This makes the provider relationship and the data route visible to the firm. Under "Confidentiality and Security" and "Duty of Confidentiality and Privilege", the guidance calls for provider due diligence and appropriate safeguards before client information is entered into a model. The firm must assess Anthropic's terms and the information sent in each request; an account alone is not a safeguard.
Named reviewer gate
A Word document cannot be exported until a named fee-earner records review. This supports the guidance's "Accuracy and understanding", "Independence", "Duty to Supervise" and "Duty to not mislead the court" sections, which place review, verification and responsibility for the final work with legal professionals. Recording a review does not prove that every statement was checked.
TO CONFIRM markers
Drafting skills instruct the model to mark points the supplied material cannot confirm, and the Word export highlights those markers for the reviewer. This helps direct attention to uncertainty, in line with "Hallucinations" and "Duty to not mislead the court". The model can miss a marker: all facts, authorities and legal assertions still need independent verification.
Audit record of completed runs
The record shows what ran, for whom, with which skill and model, whether a configured check passed and who reviewed the output. This helps the firm supervise use and document decisions under "Duty to Supervise" and the "Conclusion" on office policies setting out permitted uses, accountability and safeguards. A run aborted part-way does not yet write an audit row, and a log is not proof that a draft is accurate.
Draft-only output
The product prepares material for a professional to check rather than treating model output as a finished legal document. This reflects "Gen AI in legal practice: Opportunities and Risks", which distinguishes useful drafting assistance from unsuitable uses such as citing case law or giving legal advice. A draft may still contain an error; restricting its intended task does not verify its content.
No autonomous legal advice
The product is not designed to decide what advice to give or send it to a client without a legal professional. The guidance's "Gen AI in legal practice: Opportunities and Risks" says legal advice is not a suitable task for LLMs and places responsibility for the final work with the solicitor. The firm's people must exercise that judgement themselves.

Source: Law Society of Ireland, Guidelines for the Use of Generative AI by the Legal Profession in Ireland (v4, December 2025)

What it does not do yet

  • TLS is not enforced by default in firm-server mode. The installation runbook puts a TLS-terminating reverse proxy in front of the server, and we recommend it, but the software does not refuse to run without it.
  • Access tokens are static bearer tokens held on the firm's own server. There is no expiry, rotation schedule, or multi-factor authentication in the product today. Token rotation and leaver removal are manual steps in the runbook.
  • A leaked credential in a model response is redacted in storage and blocked from export, but the raw text has already been rendered to the screen of the person who ran it.
  • A run aborted part-way on the API or streaming path does not yet write an audit row. Completed runs always do.
  • No third-party penetration test has been performed. No SOC 2 or ISO 27001 certification is held. Those are triggered by a deal that requires them, and this page will say so when they exist.

Compliance is in the box

Your firm is the data controller and, under the EU AI Act, the deployer. AI-Switchboard is the provider. The pack ships the controller-side paperwork so it is a checklist and not a project:

  • A plain-language data-flow description for your privacy notice and your insurer's AI questionnaire.
  • A pre-filled data protection impact assessment for drafting from your own documents.
  • A register-of-processing entry for your records.
  • A deployer checklist for the EU AI Act, including the AI-literacy record.
  • An AI use policy template mapped to the Law Society of Ireland's GenAI guidelines, the SRA's warning notice, the Law Society of Northern Ireland's guidance and the judiciary's AI guidance.

If there is an incident

A defect in AI-Switchboard is ours to fix and ours to disclose. We notify every firm running an affected version, with what the defect is, what an attacker could do with it, whether we have evidence of exploitation, the fix, and what the firm needs to do.

A compromise of your own installation or premises is your incident to run. You are the controller and the 72-hour breach-notification duty is yours. We support by helping you read the audit trail to establish what ran, when, and what was sent to the model.

We tell a firm about a security matter affecting them whether or not we are contractually obliged to.

Reporting a security problem

Email security@ai-switchboard.net. If you believe client confidentiality has been breached, mark the subject line URGENT and say so in the first line. We welcome good-faith reports and do not pursue anyone who makes one. We do not run a paid bounty.

Response commitments
AcknowledgementWithin two business days
Initial assessmentWithin five business days
Updates while a confirmed issue is openAt least weekly, and immediately on any material change

Machine-readable contact: /.well-known/security.txt

What we cannot do

  • We cannot see your data. There is no telemetry and no remote access.
  • We cannot detect an incident on your server for you. Monitoring and alerting are firm-side controls.
  • We cannot restore your data. Backups are yours, to your own target.

You will usually know before we do. That is the design, and it is why the reporting route above is a named control.

Who is accountable

Paul Goodison, Goodison Consulting, is the named owner of security for AI-Switchboard. It is a single-operator supplier and this page says so rather than implying a team that does not exist.