Confidential document review with AI.
A plain-English guide to reviewing sensitive files without sending them out.
Document review is where AI is most useful and most dangerous at once. The work that benefits most, reading a data room, summarizing a deposition, comparing contract versions, combing an investigation file, is exactly the work you can least afford to leak. This is a guide to what happens when a confidential document meets a cloud AI, and how to get the benefit without the exposure.
What an upload actually does
When you attach a document to a public AI tool, the file itself, not a summary of it, is transmitted to the vendor's servers. There the model reads it, and depending on the service and the plan it may be retained for a window, written to logs, reviewed by staff for abuse or quality, or handed to other processors the vendor relies on. Some plans promise the content will not be used to train models. That is worth having, but it is a narrower promise than it sounds: the document has still left your environment, and a retention window, a log, or a breach can each reach it.
Why the transfer is the exposure
For ordinary files, this is a manageable risk. For privileged, regulated, or contractually restricted material, the transfer itself is the problem, before you even ask what the vendor does next. An NDA that says material stays with named parties does not contemplate a copy sitting on a third party's servers. A privilege claim is cleaner when the document never left the firm. A regulatory duty to control where sensitive records live is not satisfied by a promise about how they are processed elsewhere. In each case the question is not "is the vendor careful," it is "did the document leave my control," and with a cloud tool the answer is yes.
What on-premise review changes
An on-premise document AI reads files on a system that sits inside your own control. The document is opened, analyzed, and answered on that machine, and there is no outbound path for it to travel. You get the same capability, summarizing, comparing, extracting, answering questions across a large set, without a single page leaving the building. The exposure that made the whole exercise risky is simply removed, because the files never move.
How to verify nothing leaves
The test is refreshingly concrete. Ask where the model runs, whether there is any outbound network path once it is installed, and who keeps access after setup. Then check it physically: a genuinely isolated system keeps reading and answering your documents with the network unplugged. If it does, nothing you loaded was ever going anywhere. See what a Garnet build can and cannot see, and for the strict settings, what air-gapped means and how to prove it.
The honest tradeoffs
Keeping documents on-premise means the system is sized for your volume up front, updated deliberately rather than automatically, and maintained so it keeps working over time. A frontier cloud model may still be sharper on the very hardest reasoning, and anything that genuinely needs live outside data belongs elsewhere. For confidential document work, though, the on-premise system answers immediately and only to you, which is the property that matters here. For an even-handed comparison of commissioning a build versus assembling one, see build versus buy.
How a commissioned build gets there
A private document AI you would trust with a data room is a real build: sizing the system to your document volume, tuning a capable local model to your material, hardening the boundary so nothing phones home, and leaving something that keeps working after handover. A Garnet build installs that system inside your office, network-isolated by default, with no standing access for anyone, including us. For privileged legal review specifically, see AI and attorney-client privilege; for regulated health data, AI and HIPAA; and for teams and institutions, on-premise AI for law firms and in-house teams.
Commissioned; scoped and priced individually. A conversation, not a checkout.