Where It Runs

Security that doesn't ask you to trust
someone new.

Quiet runs inside your firm's own Azure environment, not ours. There's no new vendor to evaluate, and client email never leaves your compliance boundary.

The Boundary · 01

There is no server of ours in this picture.

  • Runs in your Azure tenant
  • Built on Microsoft Graph
  • No training on your data
  • Entra ID SSO

Security Spec Sheet · 02

The spec sheet.

01Tenant boundary
Runs inside your Azure subscription. Nothing is copied out. Your data never leaves your compliance boundary.
02Model approval
Uses the Microsoft AI models and agreement your firm has already approved; the thinking just happens inside your tenant, not Microsoft's.
03Matter scoping
Every action is scoped to a specific matter, read from your DMS structure. Quiet does not cross matter boundaries.
04Ethical walls
Mirrors your firm's Intapp Walls or iManage Security Policy Manager configuration, per user, per matter.
05Audit log
Every AI action (retrieval, summary, filing decision) is hash-chained and exportable for your ethics committee.
06Identity
SSO through your existing Entra ID, and Graph API access at the scope Quiet needs to read and file mail. No separate credential system, no new identity provider.
07Data Processing Agreement
Quiet uses the Azure OpenAI resource and Microsoft agreement your firm has already signed. There's no new vendor and no new sub-processor to add to your register.
08Retention
Retention stays your firm's own setting. Quiet honors litigation holds the same way your DMS already does.
09Data residency
Your data stays in your tenant's region: Quiet runs where your Azure tenant runs.
10Encryption
Encrypted in transit (TLS) and at rest, in your own subscription.
11Sub-processors
None beyond Microsoft. Your firm's existing Microsoft agreements govern.
12ABA 512
Built to the supervisory obligation under Rules 1.1, 1.6, and 5.1/5.3, not retrofitted to it.

Regulatory Alignment · 03

The rules this was built for.

The rules this was built for: each rule, when it takes effect, what it requires, and what Quiet does.
RuleEffectiveWhat it requiresWhat Quiet does
ABA Formal Opinion 512 Jul 29, 2024 · US Competent supervision of AI use; consent required for tools that retain or train on client data. Boilerplate engagement-letter language is not sufficient. Quiet doesn't retain or train on client data. The audit log satisfies the supervisory record the opinion asks for.
Model Rules 5.1 / 5.3 Ongoing · US Partners and firms must supervise the conduct of anyone, or anything, working on a matter, including AI tools. Every AI action is attributable, hash-chained, and reviewable, per matter.
Model Rule 1.6 Ongoing · US The duty of confidentiality attaches to wherever client information goes. Client email never leaves your firm's own Azure tenant.
SRA Warning Notice, Misuse of AI Aug 17, 2026 · England & Wales Client information may enter an AI system only with contractual, technical, and organisational safeguards in place. Tenant-isolated deployment satisfies the technical-safeguard requirement without a new vendor relationship.

This page describes Quiet's architecture and is not legal advice. Firms should confirm applicability to their specific matters with their own ethics counsel.

IT Setup · 04

What your IT team sets up.

01Identity
SSO through your existing Entra ID, and Graph API access at the scope Quiet needs to read and file mail. No separate credential system, no new identity provider.
02Deployment
Quiet is deployed into your Azure subscription and connected to the practice group's mailboxes and Teams. Nothing leaves your tenant to do this.
03Support during the pilot
You call us directly. During a pilot, that's a founder on a screen-share with your IT team, not a ticket number.

Questions From Security Committees · 05

What your IT, procurement, and ethics teams
usually ask first.

IT & Infrastructure

Does Quiet ever receive our email?§

No. Quiet installs inside your firm's own Azure subscription and reads mail there. There is no server of ours that any client email passes through.

Is this the same as using Copilot?§

It uses the same underlying approval, not the same infrastructure. Quiet runs on the Microsoft AI models and agreement your firm already approved; the difference is where the thinking happens. Copilot processes on Microsoft's own systems; Quiet processes inside yours.

Does Quiet ever cross between matters?§

No. Every action is scoped to a specific matter, read directly from your DMS structure: iManage, NetDocuments, or SharePoint.

What does our IT team need to set up?§

SSO through your existing Entra ID, and Graph API access at the scope Quiet needs to read and file mail. No separate credential system, no new identity provider.

Procurement & Legal

Do we need a new Data Processing Agreement?§

No. Quiet uses the Azure OpenAI resource and Microsoft agreement your firm has already signed. There's no new vendor and no new sub-processor to add to your register.

What happens to our retention policy?§

Retention stays your firm's own setting. Quiet honors litigation holds the same way your DMS already does.

What happens during the pilot if something breaks?§

You call us directly. During a pilot, that's a founder on a screen-share with your IT team, not a ticket number.

Ethics & Compliance

How does Quiet handle ethical walls?§

It mirrors your firm's existing Intapp Walls or iManage Security Policy Manager configuration, per user and per matter. If someone is walled off, Quiet won't surface it to them, regardless of what's sitting in their inbox. Quiet never creates, modifies, or deletes a wall; your existing system stays the system of record.

What happens to the audit log if something goes wrong?§

Every AI action is hash-chained and exportable in JSONL format. An edit or deletion shows. It's built to be the record your ethics committee pulls when someone asks what the AI did with a specific client's email.

How is this aligned with ABA 512 specifically?§

Built to the supervisory obligation under Rules 1.1, 1.6, and 5.1/5.3, not retrofitted to it. The audit log and matter-scoped retrieval exist because those rules require them.