Skip to content

Enterprise overview

Architecture

ContextSage Enterprise is a Bring Your Own Hardware (BYOH) deployment. The bridge runs on your firm’s server. No document, embedding, or inference result ever leaves your infrastructure.

Browser (attorney's device)
↕ HTTPS
Bridge (firm's server — your hardware)
├── Gatekeeper (PHI classification)
├── Ollama (inference)
├── sqlite-vec (vector search)
└── Audit log (tamper-evident)

What’s included

FeatureStatus
JWT auth + RBAC (admin, attorney, paralegal, read_only)Planned — E-1
Tamper-evident audit log + exportPlanned — E-2
TLS deployment guidePlanned — E-3
HIPAA Safe Harbor 18-identifier redactionPlanned — E-4
Data retention hooksPlanned — E-5
Amazon Bedrock cloud fallbackPlanned — E-6

Three-layer moat

  • Layer 1 — Zero-trust for PHI: gatekeeper inspects every prompt before any egress. Cloud routing is disabled by default. PHI never leaves uninspected.
  • Layer 2 — HIPAA compliance: auth, RBAC, audit log, Safe Harbor redaction (E-1–E-6).
  • Layer 3 — Domain workflows: matter isolation, cross-matter recall, deadline detection.

Get in touch

Email hello@contextsage.com with your organisation size and deployment requirements.