solutions · legal practice

Wytness for legal practice

Audit your AI agents without breaching privilege.

YOUR RUNTIMEWYTNESS · OPERATORYour AI agentsees matter identifierin clearWytness PII layermint pseudonym · sign event<PII:MATTER_TOKEN_*>keys never leave yousignedOperator surfaceholds pseudonym onlywytness_envelope_sigagt_merkle_entry_hashSupervising lawyerapproves where policyrequires itBar regulator, ethics committee, SRA, ASCR exportsigned export · pseudonyms only · tamper-evident

the question every regulator asks

Can you produce the evidence?

ABA Model Rule 1.6, NY Bar Opinion 2024-5, the SRA's AI Risk Outlook, and ASCR Rule 9 all land on the same duty: you own what your AI ingests, emits, and discloses to a vendor along the way. Traditional observability sends the prompt to the vendor — and the prompt contains the privileged content, so the act of logging is the act of disclosing. When a bar regulator asks what you sent to which vendor, the honest answer today is "everything, to several, with no audit trail of who saw what when."

NY Bar Opinion 2024-5ABA Model Rule 1.6ABA Rule 1.1 Comment 8CA Rules of Prof. Conduct 1.1SRA AI Risk Outlook 2024ASCR Rule 9CCBE Guide on AI (2022)EU AI Act Article 50

a scenario

An ethics-committee question, with and without

A mid-tier Brisbane firm runs a drafting assistant across 180 fee-earners — reading iManage matter files, retrieving precedent, producing first drafts a partner reviews. The firm acts for two competing groups bidding on the same government tender. The ethics committee asks: prove the agent drafting for Group A never retrieved from Group B's matters, prove no prompt went to a public model endpoint, and show who held supervising authority for each run.

Without Wytness that's iManage access logs (no concept of agents), OpenAI request logs (no concept of matters), and a copilot vendor dashboard (no signatures, no chain of custody). With it, it's one signed export — agent, matter token, fee-earner, tool calls, model endpoint, supervising-lawyer flag — with zero cross-matter retrieval confirmed in Registry. Client names never appear; they never left the firm's runtime. One meeting, accepted.

event.json
Legal audit record

// Event identity:

id:"evt_01HX9F7WZP4G2K8N6BQM3V"
time:"2026-05-22T11:14:08.412Z"
agent_id:"agt_legal_drafter_v3"
source:"agt://legal-draft-assistant/v3"

// What the agent did:

tool_name:"matter_database.retrieve"
decision:"allow"
source_format:"wytness_agt_py"Python wrapper
supervising_lawyer_id:"lwr_b1f4"

// Parameters (PII tokenised before this row was sealed):

data.matter_id:"<PII:MATTER_TOKEN_a3f9b1c4>"pseudonymised
data.client_ref:"<PII:CLIENT_TOKEN_8e2d>"pseudonymised
data.doc_class:"precedent"
data.matter_status:"active"

// Integrity proof (3-layer):

agt_merkle_prev_hash:"sha256:3f7a91c4..."chain link
agt_merkle_entry_hash:"sha256:e1c2f47a8b..."SHA-256
wytness_envelope_sig:"MEUCIQDk9p2xR..."Ed25519
wytness_envelope_key_id:"key_8c2a"

one precedent retrieval from the scenario — matter and client arrive as tokens

the deliverable

What you can prove

  • Which agent touched which matter, for which client, on whose supervising-lawyer authority, to the granularity the conflicts team can audit.
  • That privileged content never left your environment in clear: only pseudonymised tokens and non-privileged metadata reach Wytness.
  • That an agent drafting for Client A did not retrieve from Client B's matter files: cross-matter contamination flagged in real time, not at the end of the year.
  • That every external destination an agent sent text to was on the approved list at the time of the call.
  • That a discovery request asking 'show every AI-assisted document touching this matter' can be answered in a day, not by a litigation-support sprint.

how the surfaces map

Three surfaces, one product.

/product/ledger

Ledger

Every privileged-matter action signed per event with your browser-generated key; client identifiers, matter numbers, and party names pseudonymised in your runtime before egress. BYOS keeps the raw events in your tenancy; Evidence Packs map to SOC 2, ISO 27001, and the bar opinion of your jurisdiction.

/product/registry

Registry

Inventory of every drafting, research, and review agent with tool lists and model-version history. Anomaly rules flag cross-matter contamination, destinations off the approved list, off-hours retrieval against sealed matters, and behaviour shifts after a model upgrade that warrant ethics re-review.

/product/shield

Shield

Sensitive actions — billable drafts, external communications, sealed-court files, public model endpoints — gated behind partner or supervising-lawyer approval, routed to the workflow your firm already uses.

for your auditor

Frameworks that matter here

SOC 2 Type II

Trust services criteria your firm's IT team already evaluates for vendors.

ISO 27001:2022

Controls the magic circle and global firms recognise.

EU AI Act

Generally limited-risk for legal use; Article 50 transparency still applies.

GDPR

Article 6 lawful basis and Article 32 security for matter data in the EU.

ABA Model Rules 1.1 / 1.6 / 5.3

Competence, confidentiality, supervision of non-lawyer assistance.

ILTA AI Governance Framework

Practical control mapping referenced by firm-side IT directors.

the boundary

What Wytness does not do

  • We are not a document management system. Wytness records what your agents did against iManage, NetDocuments, or SharePoint; it does not replace the DMS itself.
  • We are not a conflicts-of-interest engine. We surface cross-matter contamination signals; the formal conflicts judgement remains the partner's call under your firm's existing rules.
  • We do not provide legal advice on whether your specific AI use is compliant in your jurisdiction. That conversation is between your general counsel, your ethics partner, and your bar association.

Questions about AI compliance for your practice? Ask us.

We set no cookies. Sign-in and preferences use essential first-party browser storage only — no tracking, advertising, or third-party analytics. Privacy Policy