“Is this safe for privileged material?”
Three questions wearing one word.
“Is it confidential?” usually means three things at once: what trains on our material, who inside the firm can reach it, and what we can show afterwards.
Engagements typically start at $35,000, and scale with what you connect and where it runs.
What is actually being asked
“Is it confidential?” is nearly always three questions at once, and they have different answers. Does our material become training data for somebody else's model. Can someone inside the firm reach material they should not. And if we are asked to account for how a piece of work was produced, can we.
Answering only the first — which is the easy one — is why so many of these conversations stall without anyone being able to say quite why.
Training
Your corpus is indexed for your organization alone and is never pooled with anyone else's. It is not training data for a public model.
Where you approve an external model provider for part of a workflow, that provider's handling is governed by your approved configuration and their terms. Which is precisely why model access is a policy you set rather than a default we set for you: the answer to this question should be one your firm wrote down, not one a vendor chose on your behalf.
Entitlement, which is the one that is actually hard
Confidentiality inside a firm is not one wall. It is many, and they are specific — to a matter, a client, a team, sometimes a single person. A retrieval system that can read everything is, the first time someone asks a pointed question, a way around all of them at once.
Permissions on the source documents travel into retrieval, and the rule is absolute: nothing is surfaced to a person that they could not already open themselves. Where walls exist they are mapped before indexing, and tested against questions whose answers are known.
Accountability
Every answer names the document, the date and the page it came from, and opens the original. Access, ingestion, model changes and administrative actions are logged and reviewable.
In a professional setting this turns out to matter most. The point is not that the system is trusted — it is that it does not have to be, because any statement it makes can be checked against the underlying material before anyone relies on it.
What software cannot do for you
No system is unhackable. Anyone who tells you otherwise is describing a brochure rather than an architecture.
Software alone does not create legal privilege. Privilege follows the relationship and the conduct around the material; no architecture confers it, and no vendor can tell you your obligations are met.
A certification is not a security guarantee. It records that a process was audited on a date. It does not tell you where your data sits, who can reach it, which models see which work, or what is logged — and those are the questions worth asking, of us and of everyone else you evaluate.
Judgment stays with the person who signs the work. Retrieval and drafting are bounded deliberately: the system finds and composes, and it does not decide.
What to ask any vendor
Including us. A vendor who cannot answer these plainly, in writing, is not ready to hold your material — and the list is short enough to use in a first call.
- 01
Where does our material physically sit, and in whose account?
Why it matters
Cloud, hybrid and on-premise are genuinely different answers. A vendor who cannot draw it on a whiteboard is describing somebody else's infrastructure.
- 02
Can the system surface to a person something they could not already open?
Why it matters
If the answer is anything other than a flat no, retrieval has quietly become a way around access control.
- 03
Which models see which work, and who decides that?
Why it matters
Model routing is a policy. If it is set by the vendor's default, it is not your policy.
- 04
What is logged, who can read the log, and how long is it kept?
Why it matters
Accounting for the work afterwards is the whole of the professional obligation, and it is the part that is hardest to add later.
- 05
What happens to the index when we leave?
Why it matters
A cheap question at the beginning of an engagement and an expensive one at the end. Ask it first.
Questions this raises
The ones that come next in nearly every evaluation, answered plainly.
Does using AI waive privilege?
That is a question for your counsel, and it turns on facts about your practice rather than on any vendor's architecture. What a vendor can tell you is what the system does: where material sits, who can reach it, which models see which work, and what is logged. Those are the inputs your counsel needs in order to answer it. Software alone does not create privilege, and nobody selling software can tell you your obligations are met.
Does Cogneros train public models on our documents?
No. Your corpus is indexed for your organization alone and is never pooled with anyone else's. If you approve an external model provider for part of a workflow, how that provider handles data is governed by your approved configuration and their terms — which is why model access is a policy you set rather than a default we set for you.
Can we use it for material under a protective order?
That depends on the order. The architecture lets you define categories of work that stay inside your network and never reach an external model, which is usually what such an order contemplates. Whether it satisfies yours is a determination your counsel makes with the written architecture in front of them — which is why the architecture is written down during evaluation rather than described in a meeting.
How do we show a client what happens to their material?
Deployment architecture and data-handling terms are put in writing during evaluation, so what you put in front of a client is a document their counsel can review rather than a summary of a sales conversation.
The other questions
These three come up together, in roughly this order, in nearly every evaluation.
On your own servers
AI that runs inside your own network.
Where the reasoning happens is a decision you make rather than a default we set — private cloud, hybrid, or an appliance in your own rack.
Read moreOver your document system
Nothing moves. Nothing gets re-filed.
Cogneros is an intelligence layer over the repositories you already run — originals stay where they are, under the permissions they already carry.
Read moreCompare
Four ways to put AI into a firm.
Public assistants, point tools, private deployment, or building it yourself — what each is good at, and how to tell which one your situation calls for.
See the comparison
Every one of these is settled in writing during evaluation, before anything is indexed — so what your counsel reviews is an architecture rather than a summary of a sales conversation.
Your business has already built the knowledge.
Cogneros makes it available to the people who need it — under your permissions, traced to your own documents.
What an engagement costs
Engagements typically start at $35,000.
Scope follows the repositories you connect and where the system runs — cloud, hybrid, and on-premise are priced differently.
- Prefer email?
- hello@theravengroup.com
- Prefer to talk?
- +1 303-351-1691
- Based in
- Denver, Colorado

