Now available: Early Access for law firms

AI due diligence
recorded
before the crash!

Anchor BlackBox™ is the governance recorder for AI-assisted legal work. The only system that can reconstruct, in court, exactly how your firm used AI, responsibly and ethically. Every prompt. Every version. Every approval. Every chain intact.

Built on
Enterprise-grade cloud infrastructure HIPAA Business Associate Agreement Zero-knowledge anonymization Client identity never leaves the firm Tamper-evident ledger
The Anchor BlackBox™ Recorder

Built for the courtroom.
Deployed in the cloud.

Every AI session your firm runs is captured, timestamped, and sealed inside Anchor BlackBox™. When opposing counsel asks what your AI did, you open it. Tamper-evident. Anonymized by default. No dark rooms.

Anchor BlackBox™ Recorder
The Anchor BlackBox™ Demo

Sixty seconds that explain everything.

Anchor BlackBox
Click The Anchor BlackBox™
Motion granted. Demo loading...
The Governing Precedent

What Heppner actually exposes.

A federal court just found that a criminal defendant's self-directed AI use was not privileged, in part because his prompts, unredacted, went straight to a third-party platform under terms permitting training use and disclosure. That is a data exposure problem before it is a privilege problem.

United States v. Heppner · S.D.N.Y. · Feb. 17, 2026

What actually happened

Bradley Heppner used consumer Claude on his own initiative to draft defense strategy notes, then shared the output with counsel. Judge Rakoff found no privilege, in part because his prompts (containing his own case facts) reached Anthropic with nothing removed, under a privacy policy permitting training use and third-party disclosure.

What Reached Claude in Heppner

Heppner's own words. His own case facts. Sent directly to Anthropic, under Anthropic's standard consumer terms: usable for training, disclosable in connection with claims or litigation.

What Would Reach Claude Through Anchor BlackBox™

Nothing identifiable. AIDR™ and AICR™ replace client identity, case numbers, and Privilege Data with deterministic tokens before anything is transmitted (Version 1 to Version 2). Claude never sees a real name, a real matter, or PHI.

What this changes, and what it does not. Anonymization does not make an AI exchange automatically privileged. Direction and purpose still matter, and Heppner's opinion turned on those grounds too. What it does change: the exposure the court's confidentiality analysis is actually about (privileged or PHI-bearing content permanently reaching a third party's training and disclosure pipeline) never happens in the first place. There is nothing of that nature in transit to expose.


The Anchor BlackBox™ Architecture

Two recorders.
One complete record.

Every commercial aircraft carries two recorders: the Flight Data Recorder and the Cockpit Voice Recorder. Together, they reconstruct everything. Anchor BlackBox™ uses the same architecture for AI-assisted legal work.

Recorder 1

AIDR™

AI Data Recorder

Records the facts of every AI interaction: the data layer equivalent of a Flight Data Recorder. AIDR answers what happened at the infrastructure level.

  • Matter, user, model, and version logged at session open
  • Client authorization event, time-stamped and signed
  • Routing decision and anonymization log
  • Governance events: competence acknowledgments, approvals, flags
  • Four-version audit log per interaction (original, anonymized-sent, anonymized-received, re-injected final)
  • Chain Score computed and written at session close
✈ FDR Analogy Records flight dynamics, control inputs, navigation: the instrument data.
🚙 EDR Analogy Records throttle, speed, brake, safety belt, etc.: the forensic data.
Recorder 2

AICR™

Conversation AI Recorder

Records every prompt, every output, every correction, and every governance flag: the conversation layer equivalent of a Cockpit Voice Recorder. AICR enables Governance Replay™.

  • Every prompt, original and anonymized, Version 1 and Version 2
  • Every AI output, anonymized received and re-injected, Version 3 and Version 4
  • Human corrections, attorney-added notes, and override events
  • Every hallucination flag and authority verification result
  • Governance Replay™: full session reconstruction on demand
  • Privilege Data detection log: law firm names, case numbers, opposing counsel, trade secrets
✈ CVR Analogy Records every word spoken in the cockpit: the conversation record.

AIDR™ Four-Version Audit Log: Every Interaction

Version 1
Original Prompt

Contains all client identifiers. Never transmitted. AIDR-only storage. Attorney eyes only.

Version 2
Anonymized Sent

Deterministic tokens replace all PHI, PII, and Privilege Data. Transmitted to LLM API. Zero client identity exposed.

Version 3
Anonymized Received

Raw LLM output with tokenized placeholders intact. Recorded before re-injection. Immutable.

Version 4
Re-Injected Final

Client identifiers restored via Anonymization State Key. Delivered to attorney. Signed and timestamped.


One Continuous Workflow

From the AI's first answer to the moment it leaves the building.

Recording a session is not the same as supervising it, and supervising a draft is not the same as controlling what actually ships. Anchor BlackBox™ closes both gaps, at the two moments they actually matter.

Moment One · While It's Being Drafted

The flag fires at V4, not when someone remembers to look.

Every AI response is tested for hallucination and authority risk on the anonymized text (V3), before client identity is ever restored (V4). The resulting Green, Yellow, or Red signal is recorded, and it reaches the approving attorney automatically the moment the draft is submitted through Anchor BlackBox™, whether or not the person who saw it first said anything.

See how AICR™ enforces this →
Moment Two · The Instant It Ships

Outbound Sentinel™ checks the whole matter, not just the page.

Before anything reaches a court docket, opposing counsel, co-counsel, or an expert witness, the final version is scanned against every flag ever raised on that matter, contextually, not by exact text. Earlier sign-off does not exempt it. A hit escalates straight to the firm's top partner stakeholders, and only a clean document earns the Green Chain Score™.

See how the Delivery Chain enforces this →

Supervision that does not depend on memory. Between these two moments, nothing about whether your firm's AI use is defensible is left to a paralegal remembering, an attorney assuming, or a busy partner trusting that someone already checked. The record enforces it either way.


Anchor BlackBox™ Framework

Chain of AI Custody™

Just as eDiscovery created chain of custody for evidence, Anchor BlackBox™ creates Chain of AI Custody™ for AI-assisted work product. Six chains. One unbroken record.

🤖

AI Chain

Which model, which version, which API endpoint, which inference parameters were used on each request.

Recorded by AIDR™
👤

Human Chain

Which attorney made which request, applied which correction, and provided which approval at each step.

Recorded by AICR™
📄

Document Chain

Every version of every document the AI touched: input, intermediate, and final, with diff-level provenance.

Recorded by AICR™
📬

Delivery Chain

How and when each AI-assisted work product was delivered to the client, with delivery confirmation and receipt log.

Recorded by AIDR™

Approval Chain

Every governance checkpoint: competence acknowledgment, supervision sign-off, client authorization event, final release.

Recorded by AIDR™ + AICR™

Chronology

A cryptographic timestamp on every event. The full chronology sealed at session close. Immutable. Court-producible on demand.

Tamper-Evident Ledger

Anchor BlackBox™ Risk Intelligence

Your Chain Score™.

Every AI-assisted work product in your firm gets a Chain Score™, computed automatically at session close. Green. Yellow. Red. You always know exactly where you stand.

Green

Verified

All six chains intact. AIDR™ and AICR™ records complete and consistent. Court-producible on demand. This is where every matter should land.

Yellow

Partial

One or more chains are degraded: missing a timestamp, a version, or a supervision event. Requires attorney review before the matter can be considered defensible.

Red

Orphan

No AIDR™ or AICR™ records. The document exists in the system with no traceable provenance. Maximum malpractice exposure. The absence of evidence is itself evidence.

"An Orphan Work Product classification is not a metadata flag. In a discovery challenge, a document with no provenance chain is a document you cannot defend. It represents the complete absence of the record a court can demand."

Anchor BlackBox™. Chain Score™ Technical Specification
The Questions Are Already Changing

Today's questions won't be about whether you used AI.

Yesterday's questions

Did you use AI on this matter?
Is your firm using ChatGPT?
What's your AI policy?

Today's questions

Can you reconstruct every AI interaction on this matter?
Was client identity ever exposed to the AI provider?
Where is the contemporaneous record? Produce it now.
What is the Chain Score™ on this work product?

"When a partner asks 'Did you use AI on this matter?' You need more than a yes. You need the recorder."

Anchor BlackBox™: The Black Box Recorder for AI-Assisted Legal Work™

What Anchor BlackBox™ Is Not

Not a monitoring tool.
The governance layer.

Anchor BlackBox™ is not a citation checker, a hallucination detector, or an AI assistant. It is the governance infrastructure that makes every AI tool your firm already uses legally defensible.

✗ Not a citation checker ✗ Not a monitoring tool ✗ Not an AI assistant ✗ Not a BAA substitute ✓ The governance recorder ✓ Anonymized before it reaches any LLM ✓ The Chain of AI Custody™ system ✓ Works with any AI tool your firm already uses
Competitive Differentiation

How Anchor BlackBox™
stands alone.

Every other AI tool in legal focuses on what AI can do. Anchor BlackBox™ focuses on what your firm can prove.

Capability Anchor BlackBox™ anchorblackbox.com General AI Assistants
(Harvey, GPT, Claude, etc.)
AI Governance Tools
(logging, monitoring)
Counsel-directed AI use, documented ✓ By architecture ✗ Fails by design ✗ Fails by design
Client identity never transmitted to LLM ✓ Zero-trust BlackBox layer ✗ Transmitted in every prompt ✗ Not addressed
AIDR™ dual-recorder architecture ✓ AIDR + AICR ✗ No recorder ~ Logging only
Four-version audit log per interaction ✓ V1–V4 per session
Chain of AI Custody™ (6 chains) ✓ Computed automatically
Chain Score™ (Green / Yellow / Red) ✓ Per work product
Orphan Work Product detection ✓ Automatic classification ~ Manual audit only
Privilege Data as discrete detection category ✓ Third category (PHI + PII + Privilege)
Tamper-evident, cryptographically sealed ledger ✓ Court-producible ~ Varies
Kovel Documentation Package, one click ✓ Four documents auto-generated
Works with any AI tool the firm uses ✓ Provider-agnostic ✗ Single-vendor ~ Limited

Enterprise-Grade Infrastructure

Built for the security
posture your clients expect.

Anchor BlackBox™ runs on enterprise-grade, zero-trust cloud infrastructure. Every control is documented. Every configuration is auditable. Your IT team will recognize the security posture.

🛡

HIPAA BAA

Signed Business Associate Agreement available. Write-once storage for healthcare matters.

🔒

Encrypted Transport

Mutual TLS on every endpoint. Authenticated, token-based access on all protected routes. No public-facing surfaces.

🧩

Per-Firm Isolation

Each firm runs in a fully isolated compute environment. No cross-tenant data access. No shared memory.

🔑

Encrypted at Rest

Application-layer encryption applied before every write. Managed key infrastructure with restricted access.

🌐

Data Residency Controls

Data residency enforcement at the storage layer. EU, US, and APAC jurisdictions supported.

📊

Audit Log Export

HIPAA-aligned audit log export. Every access event. Every admin action.

🤖

API Traffic Protection

Automated anomaly detection on all API traffic. Rate limiting, bot scoring, DDoS mitigation.

Merkle Root Ledger

Cryptographic timestamping and hashing seal every session record at close. Optional blockchain anchoring for maximum defensibility.


The Anchor BlackBox™ Defense Package

One click.
Full Kovel coverage.

The Kovel Documentation Package is four documents, generated automatically from AIDR™ and AICR™ records, that establish counsel direction and firm-wide governance under the Kovel doctrine and ABA Formal Opinion 512, supporting attorney-client privilege protection for AI-assisted work.

Kovel Documentation Package

Generated per matter, on demand. Every document is auto-populated from your AIDR™ and AICR™ records, signed, timestamped, and ready to produce to opposing counsel, the court, or your malpractice carrier.

📋 Counsel Direction Memo
Counsel's direction, documented
📘 Firm AI Governance Policy
Baseline governance framework
🔗 Session Chain of Custody
Complete AIDR™ + AICR™ records
📜 Commercial Terms Certificate
LLM provider terms confirmation
Generate Package

Per matter. Auto-populated.
Signed and timestamped.

Early Access

The recorder is
ready when you are.

Anchor BlackBox™ is currently in early access for mid-market law firms of 5–150 attorneys. Request access today.

Request Early Access

Controlled. Documented. Defensible.™
At Industry Events

Trade Show Ready

From ABA TECHSHOW to regional bar association conferences, Anchor BlackBox™ arrives in force. Six branded giveaways designed to start the conversation about AI governance before you say a word.

Anchor BlackBox™ giveaways