Industries / Legal · law firms, notaries, audit firms & legal departments
Professional secrecy is criminal law. Protect your firm.
Art. 321 CP makes disclosing entrusted client secrets a crime for whoever sends the prompt. A prompt with client data is a disclosure unless technical controls prevent it.
See it in action
Omnichannel protection, across all devices.
ChatGPT, Claude, Gemini, Copilot, DeepL and whatever your employees try next week: the same policies, anonymization and audit trail on the work laptop and the work phone.
See scenarios →Check the liability clause in the share purchase agreement between Müller Holding AG and Beat Graf, purchase price CHF 4.2 million.
Check the liability clause in the share purchase agreement between <ORGANIZATION> and <PERSON>, purchase price <AMOUNT>.
Here is the customer list:
Q3_Kundenliste.xlsx (2,400 rows)
NativeAI Guard, BLOCKED: Blocked attachment: Q3_Kundenliste.xlsx. Blocked by policy: Customer Data Leakage Prevention.
The AI governance framework for law firms and legal departments
Five obligations. Here's our part, honestly.
We mark what NativeAI Guard solves for the channels we protect, where it contributes, and what stays with your processes.
Typical scenarios in law firms and legal departments
A lawyer pastes a client contract into ChatGPT to check clauses. Parties, terms and the amount in dispute leave the firm in a single prompt, to a provider that knows no professional secrecy.
A paralegal uploads a statement of claim or a due-diligence dossier as a PDF to an LLM for summarization. The whole document is uploaded, with no client consent covering this processing.
An internal agent searches files, rulings and opposing submissions to prepare a brief. An opposing document with hidden instructions can redirect the agent, and its answer can expose client data from another matter.
Policies, managed
The rulebook for law firms and legal departments is already written. You adapt it.
Swiss DSG, GDPR and EU AI Act, plus your industry's specific duties. Security and compliance practitioners review it; we keep it current as the law changes.
During onboarding we tune the pack to your own data structures and internal rules, working from the compliance documents you already have.
Common questions
Frequently asked questions
Do you become an auxiliary person under Art. 321 CP, and what does that mean contractually?
Yes, as soon as client data passes through our servers for inspection, and we treat it that way. The secrecy duties that apply during processing must also apply to support and maintenance work. We align the data processing agreement and the non-disclosure agreement so that support staff sit inside the same scope of professional secrecy. If you want to avoid that path entirely, run NativeAI Guard on-premises: then no prompt and no log leaves the firm, not even to us.
Our clients require that files never leave the firm. What happens to the content during inspection?
It is processed transiently in volatile memory on our own servers in Switzerland and discarded immediately afterwards. Nothing is written to disk, nothing is used for model training. What remains is the audit entry: who sent what to which model, when, and what NativeAI Guard did about it. That is written into the data processing agreement, where you can check it, not only on this page.
We are a firm of forty lawyers, not a corporation. Is it worth it, and how do we start?
Yes. Smaller organizations get a flat rate instead of a per-user price, and the entry is the same as for a bank: a one-month passive pilot phase that we run end to end, with no change to your workflows. The result is a risk overview of data leaks, shadow AI and AI usage for the partners' meeting. From project start to live operation takes about two weeks, and your effort stays at admin access and a user list.
Protect client privilege when lawyers use AI.
A pilot phase, run by us: a policy starter pack plus a partners'-meeting report on data leaks, shadow AI, usage and costs. Client data is processed transiently, never stored.

