← Back to kingsfield.ai

Trust and security

Kingsfield rules on your citations without ever holding your client's identity. Here is exactly what reaches our server, what does not, and what we keep.

The short version

Neither Kingsfield nor WalkerNash Development LLC ever receives your clients' personal identifiers. The PII Shield replaces them with tokens in your browser before your draft is sent, so the judge reads only a de-identified draft. Anything PII-shaped the shield misses is rejected and discarded at our door, before the judge sees it. The judge rules on the de-identified draft in memory and does not keep it; only a content hash and the written verdict are retained, which together form the signed Audit Capsule. The Shield works one way: it tokenizes on the way out and nothing is mapped back, so the capsule returns PII-free with no identities to restore.

Client identifiers never leave your machine

The PII Shield runs in your browser. Before a draft is sent, it replaces client identifiers with tokens, so names, account numbers, and other personal data are swapped for placeholders on your own computer. What travels to our server is a de-identified draft. The Shield is forward-only: the replacement happens on your computer, and nothing that could map a token back to a real identity is ever transmitted to us.

PII-shaped input is rejected at the door

A fail-closed firewall sits in front of the judge. If anything PII-shaped reaches our server, the firewall rejects the whole submission and discards it before the judge reads a single line. The rejection records only the categories that tripped it, never the data itself. This is a backstop to the browser shield, not a replacement for it: two independent checks would both have to miss for any identifier to slip through.

We do not keep your draft

The judge rules on the de-identified draft in memory and returns a verdict. It does not store the draft. What we retain is a content hash and the written verdict, which together form the signed record below. We do not build a library of your filings, and we do not sell or share what you submit.

A verdict you can verify

Every ruling comes back as a signed Audit Capsule: a SHA3-256 hash chain plus an Ed25519 signature, roughly 4 KB, and PII-free. It travels with your brief and lets anyone confirm what was checked and what the judge returned, without exposing your client.

Hosted once, on your terms

The primary-law corpus and the judge model are hosted once and reached over MCP, so no firm carries the hardware. Kingsfield adjudicates; it does not generate. If you bring your own model for drafting, your keys and your workflow stay with you. Kingsfield only ever sees the de-identified draft you choose to submit.

What we do not claim

We do not hold SOC 2, ISO 27001, HITRUST, or similar certifications, and we will not imply that we do. Our security position is the architecture described on this page: tokenize before it leaves your machine, reject PII at the door, keep no draft. The attestations identified above are audits of how a vendor handles the client data it retains. By architectural design, Kingsfield and WalkerNash retain no client data, so such an audit has nothing to examine.