Litigation intelligence · by Tampa Dynamics
Answers you can cite.
Silence you can trust.
Private Intelligence™ turns your firm's depositions, expert reports, and work product into a private, permission-aware knowledge base. Every answer is cited to document, page, and passage — and when the record doesn't support an answer, it says so.
White-label · multi-tenant · deployed inside an AWS boundary · content never trains models
- Q. What has Dr. Marsh conceded about
- photogrammetric crush measurement?
- A. In a 2023 Polk County matter, she
- conceded on cross that crush measurement
- from consumer photographs carries an
- uncertainty band of ±40 percent[1]
- — a concession noted in the court's order
- on the motion in limine[2]
Illustration — synthetic matter data. No client information.
Institutional memory walks out the door
Every closed matter leaves behind deposition admissions, expert vulnerabilities, verdict intelligence, and hard-won strategy. Most of it is never seen again — siloed in matter folders, or lost when the team moves on. Generic AI tools make it worse: they answer confidently without citations, and they have no concept of privilege, ethical walls, or who is allowed to see what.
Private Intelligence™ is built on the opposite premise: an answer is only useful if you can cite it, and only safe if the asker was entitled to the material behind it.
The platform, from contribution to cited answer
Contribute
Attorneys, paralegals, and consultants submit documents through a branded portal. Uploads land in quarantine, are scanned, and have text, parties, experts, dates, and candidate PII extracted automatically.
Review gate
Nothing becomes searchable firm-wide until a reviewer approves its classification and visibility tier. Near-duplicates are flagged; privileged material is structurally blocked from broader sharing — enforced in the schema, not by policy alone.
Ask
Anyone asks in plain language — about an expert, a venue, a standard of care, a prior admission. Scoped to a matter, or across everything they're entitled to see.
Authorized retrieval
The asker's grants — matter membership, role, visibility tiers, ethical walls — are joined into the retrieval query itself, inside the database, before search runs. Material the asker cannot open cannot be retrieved, summarized, or even influence the answer.
Cited answer — or “not found”
Answers stream with inline citations that open the viewer at the exact page and passage. Citations are verified after synthesis; an answer without at least one verified citation is never shown as fact — it renders as “not found,” and feeds the firm's knowledge-gap analytics.
Permission-aware by construction
Authorization is not a filter applied to search results. It is the shape of the search itself — enforced in the database, verified continuously.
- Authorization before retrieval
- Effective access — matter membership, role grants, visibility tiers, minus ethical walls — is computed per user and joined inside the retrieval SQL, ahead of similarity ranking. Revoking access is effective on the very next query.
- Tenant isolation
- Every tenant's data is separated by database row-level security that the application role cannot bypass, keyed to the verified session and request domain. A session minted on one tenant's domain is rejected on another's and logged as a security event.
- Ethical walls
- Per-matter screens override every other grant, including reviewer roles. A walled user cannot retrieve walled material at any visibility tier — the platform answers them with “not found,” never with a redacted hint.
- Privilege safeguards
- Documents flagged privileged are hard-blocked from network sharing by a schema constraint, not just application code. Review gates keep drafts and work product out of firm-wide search until a human approves tier and classification.
- Append-only audit
- Logins, uploads, reviews, views, downloads, and queries are logged content-free to an audit trail that rejects edits and deletions at the database layer.
- Hostile-input boundary
- Ingested documents are treated as untrusted input. Extraction runs with structured output only; answer synthesis has no tools and cannot act on instructions embedded in documents.
- Continuous verification
- An automated permission-probe suite runs synthetic users against questions answerable only from material they are barred from — cross-tenant, cross-wall, cross-tier. Any leak fails the build before it ships.
Evidence discipline, measured — not asserted
Retrieval quality is scored against a citation-accuracy evaluation set: for every question, did verified citations point at the documents that actually support the answer? Every change to retrieval must move that scorecard. Weak matches are cut before synthesis, so an off-topic question produces an honest “not found” rather than confidently cited noise.
How a pilot is judged
- Citation accuracy: at least 85% of an evaluation set — built jointly with your team from your own corpus — answered with a correct citation.
- Zero authorization leaks: no answer may cite a document the asker cannot open, verified by the continuously running permission-probe suite.
- Adoption you can see: usage, contribution, and knowledge-gap dashboards for firm leadership from day one.
These are pilot acceptance criteria agreed in writing — targets the platform must meet for your engagement to proceed, not guarantees of future performance.
Beyond search: the firm's private intelligence layer
- Expert intelligence
- Experts are extracted at ingestion and resolved into living profiles: credentials, specialty, typical side, jurisdictions, challenge history, and every appearance across your corpus — each appearance linked to the underlying document, and visible only to users entitled to open it.
- Knowledge-gap analytics
- “Not found” is a signal. The platform clusters unanswered questions by topic, expert, and jurisdiction into a ranked list of what your organization keeps asking for but hasn't preserved — a preservation agenda, not a guess.
- Contribution culture
- Dashboards show which offices are building the asset and which are letting it walk out the door: submissions, review latency, matters closed with and without knowledge preservation.
- Your brand, not ours
- White-label to the ground: your domain, your colors, your terminology — “matters” for a firm, “claims files” for an insurer — applied per tenant at request time.
Packages
| Capability | Base | Premium | Enterprise |
|---|---|---|---|
| Branded portal, ingestion, cited answers, roles, review gates, audit, usage analytics | ✓ | ✓ | ✓ |
| Expert profiles & appearance history | read-only | ✓ full | ✓ full |
| Matter workspaces, contribution workflows, close-out preservation | — | ✓ | ✓ |
| Single sign-on (SAML / OIDC) & enterprise identity controls | — | — | ✓ |
Deployment & data stewardship
- Inside the boundary
- The platform deploys within an AWS environment: private networking, encryption in transit and at rest, per-tenant encryption keys for content. Model inference runs through Amazon Bedrock, so customer content is processed inside that boundary rather than sent to third-party model APIs.
- No training on your content
- Customer content is used to answer your users' questions. It is not used to train or fine-tune models, and it is never shared across tenants.
- Health information
- Built on HIPAA-eligible services, with a Business Associate Agreement available for engagements involving protected health information. Candidate PII and PHI are flagged at ingestion for human review. No software product is itself “HIPAA certified”; compliance is a shared program between the platform's safeguards and your own policies and workforce practices.
- Retention & holds
- Per-tenant retention policies, legal-hold flags that suspend deletion by matter, and logged, certificate-producing destruction.
Limited pilot cohort
Put your own corpus on the record
Pilots run on your documents, against acceptance criteria we agree in writing — citation accuracy on an evaluation set built with your team, and zero authorization leaks, continuously verified.
Please don't include confidential or case-sensitive information in an introductory message.
Pilot intake
Start with the corpus, not the demo.
Tell us what the pilot would run on and what would have to be true for it to count. We'll review whether the evaluation set is buildable before proposing scope.
Private Intelligence™ is software. It is not a law firm, does not provide legal advice, and its output — including answers, citations, and expert profiles — is research assistance that must be verified by a qualified professional before reliance. Features described here are under active development and may change. Illustrations use synthetic, fictional matter data.