Your AI provider can waive your clients' privilege.
A UK tribunal has already confirmed it. Every US-parented AI tool, ChatGPT, Copilot, Gemini, Claude, is in the habit of keeping a copy of what you type. A US court can compel them to produce your client data. That is a privilege waiver your firm cannot undo. Hush is built the opposite way: we keep no conversations or documents, we process what you send, then it is gone, so there is no conversation or document for any court to compel.
Try it on one real matter, free →A Microsoft lawyer told the French Senate, under oath, he could not guarantee your data would never be handed to US authorities. We run on hardware we own, with no US parent, so that question does not arise here. Read what was said.
Public AI use can waive privilege.
"Uploading confidential documents into an open-source AI tool, such as ChatGPT, is to place that information into the public domain, resulting in a breach of client confidentiality and a waiver of legal professional privilege."
This is a serious and developing legal risk, not a hypothetical. Privilege, once waived, can be very hard to restore.
Your firm is almost certainly exposed.
of UK fee earners use unapproved AI for client work
of paralegals admit to using ChatGPT on client matters
of firm leaders believe they face "zero risk"
Source: Censuswide survey of 200 UK fee earners and 100 legal leaders, commissioned by Access Legal (May 2026).
"Approved" AI tools are not structurally safe for privilege.
Microsoft Copilot, ChatGPT Enterprise, and Google Gemini are marketed as secure. They are all US-incorporated entities in the habit of keeping a copy of what you type. A contractual promise of UK data residency cannot override a US federal court order.
"Approved" US AI Providers
- US parent entity, subject to CLOUD Act
- US court can compel data production
- Privilege protection is contractual only
- Data processed on rented cloud infrastructure
- Sub-processors in the data chain
Hush AI
- No US parent or subsidiary
- Outside CLOUD Act jurisdiction entirely
- Privilege protection is architectural
- Data processed on hardware we own
- No third-party AI sub-processors, no training on your data
AI that saves fee earners hours, without compromising privilege.
Every request processed on hardware we own, never used for training. Full audit trail for SRA compliance.
Contract review & summarisation
Summarise lengthy contracts, identify key clauses, flag unusual terms with the NDA and contract review tool. Privileged analysis stays privileged.
Legal research & drafting
Draft correspondence, research memos, and skeleton arguments from instructions. Ready for partner review.
Client correspondence
Generate letters, emails, and advice notes from brief context. Professional, accurate, privilege-protected.
Document comparison
Compare contract versions, identify amendments, track changes between drafts without uploading to cloud services.
Case summaries
Condense lengthy case bundles into structured summaries. Chronologies, key issues, party positions.
SRA-compliant audit trail
Every request logged with timestamp and metadata. Exportable records for regulatory compliance and client billing transparency.
Built for SRA-regulated practice.
Every feature designed with the SRA Code of Conduct in mind.
Privilege Protected
No US jurisdiction. No third-party AI sub-processors. No mechanism for foreign court orders.
Your Content, Your Control
API prompts processed and discarded. Chat history stays encrypted on your own device, never on our servers, until you delete it. Never used for training.
Full Audit Trail
Every request logged. Exportable for SRA, client queries, and billing transparency.
Nothing to Compel
We keep no conversations or client documents, we process what you send, then it is gone. On hardware we own, no US parent, so there is nothing for any court, here or abroad, to demand.
ICO Registered
Data controller registered. DPA draft available; a signed DPA is executed before any live personal data flows. DPIA drafted.
Independently Verifiable
Two-week governance evaluation. Your DPO tests our claims. We hide nothing.
Two weeks for your compliance team to verify everything.
Not a free trial. A governance evaluation. Your DPO independently verifies our privacy claims.
Architecture briefing
We share our full data flow diagram. Your DPO reviews jurisdiction and sub-processors. No NDAs needed, we have nothing to hide.
Two-week evaluation
Your fee earners use Hush AI on real work. Your compliance team monitors. We provide full audit logs throughout.
Compliance review
Verify it yourself: send a document, then ask us to produce it. We cannot. Export the full audit trail for your records.
Decision
Your compliance team is satisfied, or they are not. No lock-in. No penalty. The evidence speaks.
Protect your clients' privilege. Architecturally.
Not by contract. Not by policy. By the physical absence of any mechanism for foreign data access.
Request a governance evaluation →Or email [email protected] directly.
Free: the AI prompt pack for solicitors · AI and legal professional privilege · An AI-use policy for law firms · Is your AI provider in the habit of keeping a copy of what you type? · What AI tools actually do with your data · For solicitors in Scotland · For solicitors in Northern Ireland · The new UK data law and AI · AI and your PI cover · Confidential transcription for interviews and dictation · NDA and contract review tool
Frequently asked questions
Can law firms use AI without risking client confidentiality or privilege?
The risk with consumer AI is that confidential or privileged material passes to a third party that can be compelled to disclose it. Hush AI drafts correspondence, research memos and file notes on hardware we own, outside US CLOUD Act jurisdiction, never used for training, so confidential material stays on infrastructure we own, with an audit trail you own.
Is Hush AI within reach of the US CLOUD Act?
No. Hush has no US parent and no US cloud sub-processor for your content, so there is no US entity that could be compelled under the CLOUD Act to disclose client data.
Does Hush AI train on client data?
No. Client content is never used to train models and is stored encrypted locally on your own device until you delete it. A fee-earner reviews every output.
Do you have law firm case studies or reference clients?
We will be straight with you: we are an early-stage company, and you would be among our first firms. So rather than showing you another firm's numbers, the free pilot generates your evidence, a written report built from your own audit-log export that is yours to keep whether or not you continue. The company itself is verifiable today at Companies House (17278687) and the ICO (ZC126901).
Is Hush a private cloud legal AI solution?
Effectively yes, with one difference: a private cloud is usually rented from someone else. Hush runs on hardware we own outright in the UK, so your firm gets the private-deployment properties (no shared US cloud, no conversations or documents kept, never trained on) at £39 a month rather than enterprise pricing.
Do you support solicitors in private practice and small firms?
That is exactly who Hush is built for: solicitors in private practice, from sole practitioners to firms of ten fee earners, including immigration, family, private client, criminal and personal injury work. No IT team is needed, and the first useful draft takes minutes, not a rollout project.
Accountants and financial advisers · HR and people teams · General practice