What the Model Rules actually require
ABA Model Rules of Professional Conduct · State rules vary
Rule 1.1, Comment 8 — competence includes keeping abreast of the benefits and risks
associated with relevant technology. A lawyer who does not know where a tool sends client material is
not positioned to evaluate its risk.
Rule 1.6(c) — a lawyer must make reasonable efforts to prevent the inadvertent or
unauthorized disclosure of, or unauthorized access to, information relating to the representation. The
standard is reasonableness, not perfection, and it is assessed on the facts.
Neither rule prohibits AI. Both make the deployment model a professional-responsibility question
rather than an IT preference.
Architectural alignment: when the model runs on hardware in the firm's own office,
client material is not transmitted to a model vendor at all. There is no third-party custodian to
assess, no retention policy to interpret, and no training-data question to ask — because the material
never leaves.
What U.S. v. Heppner did and did not hold
S.D.N.Y. 2026 · Rakoff, J. · Subsequent judicial split, April 2026
You will hear this case cited by vendors as authority that using public cloud AI waives
attorney-client privilege. That is not what it says, and a firm should be sceptical of anyone
selling on that reading.
Read the citation carefully. The case is U.S. v. Heppner (S.D.N.Y. 2026),
not "Heppner v. Claude" — a miscitation that circulates widely. The holding is narrow and
fact-specific, resting on three grounds, and a judicial split emerged in April
2026. It does not establish that public cloud AI use categorically waives privilege, and we
do not claim it does.
What it does establish is more useful and less dramatic: how a firm handles client material with
third-party services is now a litigated question rather than a hypothetical one. A firm that
can describe precisely where client material went, and demonstrate it, is in a materially different
position from one that cannot — whichever way the split resolves.
Why we state this plainly: a vendor that overstates a holding to close a deal has
told a firm of litigators something checkable and wrong. We would rather be the vendor whose citation
survives being looked up.
What a firm can actually show
Operational · Evidence rather than assurance
Reasonableness under Rule 1.6(c) is demonstrated with facts. A sovereign deployment produces them as
a by-product of ordinary use:
- Where material is. Client files sit on firm-owned hardware in the firm's
premises, on a storage tier with no public network ports.
- That it is unaltered. Every document is sealed with a SHA-256 content hash on
intake, so its integrity can be re-verified rather than asserted.
- Who reached for it. Retrieving an original requires a physical key touch, and
the request is recorded.
- What the assistant saw. The model reads an indexed representation of the
document, and any answer cites the document and hash behind it.
- When nothing was watching. Monitoring gaps are reported rather than hidden — a
period with no records is disclosed as such.
The distinction that matters to a litigator: most vendors offer assurance — a
policy document and a promise. This offers evidence — artifacts a firm can put in front of a court,
an ethics panel, or a client, and which can be checked independently of the vendor.
What we do not claim
Read this part especially
Sovereignware does not preserve privilege. Privilege is a legal doctrine governed by a court, not a
property a vendor can confer. Nor does this architecture discharge a firm's obligations under Rules
1.1 or 1.6 — those remain the firm's, and are assessed on the firm's whole conduct.
We have not been audited, accredited, or certified by any bar association, standards body, or
third-party assessor. Whether this deployment model is appropriate for a given practice is a decision
for that firm and its ethics counsel.
The honest version: we reduce the number of parties holding client material to
one — the firm — and we produce records the firm can use to demonstrate that. Everything after that
is the firm's judgment, and should be.
Important — what this page is, and what it is not.
This page documents Sovereignware™'s architectural alignment with the professional-conduct
obligations discussed above. It is a posture statement, not a certification claim,
and it is emphatically not legal advice. We have not been audited, accredited, or certified by any
bar association, government agency, or third-party assessor. A firm's obligations under its own
jurisdiction's rules are its own, and the appropriateness of Sovereignware™ for any specific matter
or practice must be evaluated by the firm's own counsel.
Case law described here is summarised for orientation only and may have developed since publication.
Consult primary sources directly.
Related: the full regulatory posture ·
auto dealerships & GLBA