Private AI · how it works

The model is yours.
The standards stay yours.

Your firm picks the model and owns it, with your own files ranked above anything it was trained on. Sidian sets up the deployment, wherever you want it, and runs the Sidian AI control layer around it inside DataGuard.

Firm-chosenYour Modelprivate or open-source

ROUTER

Sends each request to the right model and the right files.

GROUNDING

Ranks your files above the model's own memory, and reads the reasoning while it forms.

GOVERNANCE

Stops on an uncertain answer instead of writing it, and keeps the record of why.

One request. Three concurrent controls, never a pipeline.

The benchmark

Private does not mean second best.

The same open-weights model your firm owns, before and after the Sidian AI control layer, against the frontier models the legal AI tools run on.

GPQA Diamond · higher is better

  • The model on its own
  • Added by the Sidian AI control layer
Gemini 3.1 ProGoogle's cloud
94.4%
Qwen3.8 27B, yoursYour machine
92.4%82.2 + 10.2
GPT-5.6 SolOpenAI's cloud
91.9%
Claude Opus 5Anthropic's cloud
87.0%

Frontier and base-model scores are OpenRouter's own evaluations, one fixed question set put through each provider's live endpoint on 17 September 2026. The lift is Sidian's published figure for the control layer on that same model.

148×Fewer parameters

Fits on one machine you control. Frontier models are reported to carry trillions.

“I don't know”What it says on a gap

Decided while it answers, against your files.

That takes a 27-billion-parameter model your firm owns past Claude Opus 5 and past GPT‑5.6 Sol. So the question is not which model is cleverest. It is whose building the work happens in.

Where it lives

Your model. Your building. Your record.

Most of what passes between a firm and its client is confidential, and some of it is privileged. None of it has to leave the firm for the AI to be useful.

Sidian sets it up in any of the three.
  • Your building
  • Your cloud
  • A machine Sidian runs

No hardware to buy and nobody to hire. Sidian installs and configures all three, and operates the third.

You own the weights wherever it runs. The machine is dedicated to your firm and closed to the internet, and nothing dials out except the connectors you approve.

And when privileged material does go out, you can show what left.
  1. You approve the sendNothing leaves on the model's say-so.
  2. DataGuard removes what should not leaveAnd names the rule that fired, on which passage.
  3. The entry is hash-chainedSo an altered log reads as altered.

For a file shared through a connector you approved, DataGuard records where it went, the policy it applied and what it changed. When a client or your carrier asks what went out, that is a record rather than a recollection.

Here is the same question asked twice. Once to a generic AI tool with no access to your files, once to your firm's own AI connected to your real documents.

Router · 01

Only answers from documents actually in this case.

Same request to both"What documents were produced in the data breach incident?"

A generic AI tool
with no access to your files

Generic assistantNo case connection
What documents were produced in the data breach incident?
The data breach involved the customer database from what looks like an older version of the system, around March 2022. I recall seeing references to server logs from Exhibit 14 and an intrusion alert from some exhibit about security.
No check performedNot connected to your case files

These exhibit references cannot be confirmed

This tool never saw the real Doe v. TechCorp document set. Those exhibit numbers could be right or invented, and nothing in the answer tells you which.

This would go straight into a filing unless someone happened to check every exhibit by hand.

Your firm's AI,
connected to your real documents

Doe v. TechCorpCase No. 3:22-cv-0451
What documents were produced in the data breach incident?
The data breach occurred on March 12, 2022, affecting customer records stored in the cloud database.
Review flag · routerSourced from case documents

Answers from the connected case document set

Exhibit 14, page 3; Exhibit 7, page 1; Exhibit 22, page 5Approved source · Doe v. TechCorp, case no. 3:22-cv-0451

Every exhibit number is checkable, because it only pulls from what is actually in the case.

Grounding · 02

A citation should point to something real.

Same request to both"Find case law supporting our motion to compel arbitration."

A generic AI tool
with no access to your files

Generic assistantNo source connection
Find case law supporting our motion to compel arbitration.
Found this case:
No check performedNot connected to a real index
Bellweather v. Trent Holdings, 214 F.3d 902 (7th Cir. 2019)

This case cannot be found anywhere

No matching case in any real record. This is the problem behind reported incidents like Mata v. Avianca: a citation with nothing real behind it.

This would go straight into a brief unless someone happened to check it by hand.

Your firm's AI,
connected to your real documents

Sokol v. Meridian FreightCase law
Find case law supporting our motion to compel arbitration.
Checked against your connected case law index:
Source matchGrounded citation
Halvorsen Logistics v. Whitfield Transit, 502 F.4th 118 (9th Cir. 2024)

This case is real and on file

Arbitration compelled under FAA §4. Found in your firm's connected case law research index, so you can open the source and check it yourself.

Cited, with the source attached.

Caught automatically, every time, because it checks a real index before answering.

Governance · 03

A rewrite should not quietly change the deal.

Same request to both"Rewrite clause 7.2 in plain English."

A generic AI tool
with no access to your files

Generic assistantNo case connection
Rewrite clause 7.2 in plain English.
Here's a clearer version.
Rewritten clauseThe settlement payment is $50,000, due within ten business days.
No check performedNot connected to your file

Nothing here was compared to anything

This tool never saw the real clause 7.2. The number could be right or wrong, and nothing in the answer tells you which.

You would only catch this if a person happened to reread the whole clause by hand.

Your firm's AI,
connected to your real documents

Mason v. AlderClause 7.2
Rewrite clause 7.2 in plain English.
Here is a clearer version for review.
Rewritten clauseThe settlement payment is $50,000, due within ten business days.
Review flag · governanceChecked against the real clause

This number does not match the file

$500,000$50,000

The clause on file says $500,000. This rewrite says $50,000. Flagged before it reached you.

Keep the source value.
Restored: $500,000.

Caught automatically, every time, because it checks the real file first.

The comparison · 04

Two real tools lawyers already trust. One structural difference.

Harvey and Spellbook are genuinely useful, widely adopted legal AI tools. The difference is not which one writes better. It is where your data goes, whose model it runs on, and what happens when the AI is not sure.

What Harvey is built forLegal research, memo and brief drafting, and due diligence review, run through Harvey's hosted models.
What Spellbook is built forContract drafting and redlining inside Microsoft Word, using GPT‑5, Claude, and other third‑party models (Spellbook's own description of its product).
 HarveySpellbookYour private AIDelivered by Sidian
Where your data goesProcessed on Harvey's cloud infrastructureSent through GPT‑5, Opus and other outside model providersStays on one machine dedicated to your firm, in your building, in your own cloud, or run for you by Sidian. Closed to the internet except the connectors you approve
Whose model it runs onOpenAI, Anthropic and Google models routed on Harvey's platform, plus its own model post-trained on an open-weight baseThe third-party frontier models Spellbook connects toThe open-weights model your firm chooses, owned by the firm whoever is running the machine it sits on
Hallucination rate, independently publishedNot published at the task level, per public reportingNot published, per available public sourcesNo independently audited rate, and the benchmark published above is not one either. Every answer shows its source, so the thing you rely on is the citation and not the score
Who checks the answerThe model checks its own work. Harvey states its system hallucinates less than the underlying foundation model, but does not publish how that check happens or how well it holds upNot documented as a separate, independent checkThe reasoning is read while the answer forms, and a step that drifts off your documents is corrected before the sentence is written, rather than a second pass grading a finished draft
Risk of an ungrounded frontier model on legal questionsA 2024 Stanford study found general-purpose AI models, used directly on real legal questions with no independent source check, gave an unsupported or incorrect answer 58 to 88% of the time depending on the model. This describes the risk of using a frontier model raw, not a published number for Harvey or Spellbook's actual productYour own files outrank the model's training data, and an answer drifting off them is caught while it forms. This is a substantial reduction in that risk, not a claim to have removed it
When the AI is not sureNot documented as a separate, visible controlNot documented as a separate, visible controlIt says so and holds for your review rather than committing, at a strictness threshold your firm sets
What you can show about one privileged fileNot documented publicly at the file level. Harvey states it does not train on customer data and requires zero data retention from its model providersNot documented publicly at the file level. Spellbook states it holds zero-data-retention agreements with OpenAI and AnthropicA hash-chained record of every file that left through a connector you approved, naming the rule that applied and what it changed
If you ever switch toolsYour work stays on Harvey's platformYour work stays on Spellbook's platformYour model and your data leave with you

Neither Harvey nor Spellbook publishes an equivalent to the Sidian AI control layer, with Router, Grounding and Governance running as separate, visible controls. The comparison above is about what each platform documents publicly, not a claim about what happens inside either one.

Sources

  • GPQA Diamond is the hardest subset of GPQA (Rein et al., 2023), a graduate-level multiple-choice science benchmark written so that experts in the subject still miss a meaningful share of it and unrestricted web search does not help
  • The Gemini 3.1 Pro, Qwen3.8 27B, GPT‑5.6 Sol and Claude Opus 5 scores are OpenRouter's own evaluations, run across one fixed question set through each provider's live endpoint on 17 September 2026 (openrouter.ai/benchmarks/gpqa-diamond)
  • The Sidian AI control layer's technical specification requires deployment "100% locally on firm hardware or Virtual Private Clouds (VPCs)", with no logs and no document content held outside the firm. In the managed option Sidian provisions and operates that machine
  • The 92.4% with the control layer, the 27-billion-parameter figure and the 148x comparison come from the September 2026 technical overview for the control layer. No major lab publishes a frontier-model parameter count, so the 148x compares against a reported number rather than a disclosed one
  • Harvey added Anthropic and Google models alongside the OpenAI models it already ran on 13 May 2025, "integrated through their respective cloud providers (AWS Bedrock, Google Vertex)", quoted from harvey.ai/blog/expanding-harveys-model-offerings
  • Harvey announced Tenet, its first in-house legal model, on 23 August 2026, post-trained with Fireworks AI on Moonshot AI's open-weight Kimi K3 base
  • Spellbook: "powered by state-of-the-art LLMs like GPT5 and Opus", quoted directly from spellbook.com, checked 17 September 2026
  • Harvey: SOC 2, ISO, GDPR and EU‑US Data Privacy Framework certifications and ethical-wall sync are real and documented at harvey.ai/security
  • Harvey states "we don't use inputs, outputs, or uploaded documents to train underlying models" and requires Zero Data Retention from model providers (harvey.ai/security); Spellbook states it has zero-data-retention agreements with OpenAI and Anthropic (spellbook.com/security). Both checked 17 September 2026. Neither publishes a per-file record of what left a firm, which is what the privilege row compares
  • Neither Harvey nor Spellbook has published an independently audited, task-level hallucination rate as of this writing
  • The widely cited Stanford HAI and RegLab legal-AI hallucination study (2024) tested Lexis+ AI and Westlaw AI-Assisted Research specifically. It did not test Harvey or Spellbook, and the 58 to 88% figure used in the comparison table is Dahl et al.'s separate "Large Legal Fictions" (2024) finding for general-purpose models used raw on legal questions, not a Harvey or Spellbook specific number
  • Mata v. Avianca is a real, widely reported sanctions matter involving fabricated case citations from ungrounded AI use, referenced here generically as a well-known industry example

See it on your own matter.

Book a short call with Ben, Sidian's founder. Bring a real question from a live matter and watch the answer come back with its source attached. No slides.

Loading the calendarOr open the booking page

15 minutes, no commitment.