Cloud AI tools route every query through third-party servers — a privilege risk your ethics committee can't approve. Rendex runs entirely on your hardware. Every answer cites the source document and page. Nothing ever touches the internet.
Every response includes document + page citations. Click to open the exact source text.
Every query, login, document access, and permission change is logged to an immutable audit table for review.
Runs inside your environment. No telemetry. No license checks. No vendor access.*
Designed for attorney-client privilege
Spends 25 minutes before every client call hunting through folders, emails, and iManage for the right version of a contract.
Spends half a day looking for a motion your firm already wrote two years ago. It exists. Nobody can find it.
Takes two weeks to review documents in a data room that should take two days. The documents are there. The bottleneck is search.
Drag in contracts, briefs, filings — PDF, DOCX, TXT. Rendex indexes everything locally. Scanned PDFs get OCR'd on-device. Your IT runs our installer in under an hour.
"Find all non-compete clauses over 50 miles." "When does the Brightline lease auto-renew?" Ask questions like you'd ask a senior associate.
Every answer links to the exact source document, section, and page. Click any citation to see the original text. Verify in seconds, not hours.
“What changed between the March and June drafts of the MSA?” — cited to both versions
“List every indemnification clause across these 40 contracts” — cited to document and page
“Build a timeline from the Smith matter file” — every event cited to its source
“Draft a witness outline for Dr. Lee using the deposition transcripts” — cited to exhibits
“Do we have prior work product on restrictive covenants in Texas?” — filtered by matter
PDF, DOCX, TXT
OCR for scans
Chunking &
text extraction
Qdrant
vector database
Ollama
GPU-accelerated
Doc + page
+ section
Runs on a device in your office. Zero outbound network connections. You can unplug the internet cable and it still works. No data sent to any third party, ever.
We never see your data. We're the plumber who installs the pipes, not the water company. If Rendex disappears, your system keeps running.
Click any citation to see the exact source text highlighted. The AI is constrained to retrieved documents — no hallucinated case law, no made-up clauses.
Delete a document and it's gone — completely, immediately, verifiably. No residual knowledge in the model. No shadow copies on someone else's server.
Five roles from Admin to Staff. Matter-level permissions. Ethical walls enforced at the query level. Every access logged to an immutable audit trail.
Docker Compose handles everything. Your IT team runs our installer in under an hour with guided onboarding, or we ship a pre-configured workstation. No infrastructure changes.
These are representative scenarios, not guarantees. Results depend on document quality, practice area, and adoption. The 90-day evaluation gives your team time to measure real impact before committing to an annual license.
Not cloud AI. No data is sent to OpenAI, Google, Anthropic, or any third party. Ever.
Not a legal advice engine. Rendex retrieves and cites your documents. It does not practice law.
Not training on your data. The AI model is pre-trained and never modified by firm documents.
Not storing data in the model. Documents exist in a vector database and can be removed instantly.
No network calls leave the server. No telemetry, no license checks, no API calls. Verify: run tcpdump or your network monitor during operation.
After initial Docker image pull, the system runs with zero internet. Deploy on fully air-gapped networks via USB transfer. Verify: disconnect the network cable — Rendex keeps running.
All browser-to-server traffic encrypted via HTTPS with TLS 1.3. Self-signed cert generated at install, replaceable with your own CA cert. Verify: check the certificate in your browser.
All inter-container traffic stays on an internal Docker network. PostgreSQL, Qdrant, and Ollama are not exposed to the host network. Two open ports total: 80 and 443.
Five roles (Admin to Staff). Matter-level permissions enforce ethical walls at the query layer. No cross-matter leakage. Verify: log in as a restricted user and attempt a cross-matter query.
OpenID Connect with JWKS signature validation. Your firm's MFA, Conditional Access, and device compliance policies apply automatically. Revoke access in Azure — Rendex locks them out instantly.
Every query, login, document access, and permission change is logged to a tamper-proof append-only table in PostgreSQL. Exportable for compliance review. Verify: query the audit table directly.
Rendex is architected around SOC 2 control objectives: access control, audit logging, encryption, change management. Not yet independently audited — we're transparent about that.
Rendex has no backdoor, remote shell, or auto-update mechanism. We cannot access your system. Updates are manual, versioned Docker images you pull on your schedule.
Rendex only indexes documents your firm uploads. Zero training on third-party corpora. No scraped case law, no licensed content. If you didn't upload it, it doesn't exist in the system.
Remove a document and it's purged from the vector database and file system immediately. No residual embeddings. No shadow copies. Verify: delete a document, then search for its content.
Eight Docker containers. Two open ports (80, 443). Rate-limited API. No public-facing admin panel. PostgreSQL bound to internal Docker network only.
* After installation (or offline image load), Rendex operates with zero outbound network access. Initial setup requires a one-time Docker image pull or offline USB transfer.
Attorneys click "Sign in with Microsoft" and they're in. OpenID Connect authorization code flow with JWKS signature validation. No SAML XML. No federation headaches. Your IT registers one app in Azure and it's done.
Conditional Access, MFA, device compliance, geo-restrictions — whatever your firm enforces in Azure AD applies to Rendex automatically. We inherit your security posture instead of reinventing it.
Add and remove users from Azure AD — Rendex follows. When someone leaves the firm, their access is revoked instantly. Domain allowlisting ensures only @yourfirm.com accounts can authenticate. Optional auto-provisioning creates Rendex accounts on first login.
If Azure AD is unreachable, the local admin account always works. Every SSO login, failure, and provisioning event is logged to the immutable audit trail. Full visibility for compliance and incident response.
Most firms with 15+ attorneys already have a workstation or server that meets these specs. We'll help you confirm during the pilot call.
A single script checks prerequisites, generates secrets, creates TLS certificates, pulls all containers, and starts the stack. Works on Linux/Mac (./install.sh) or Windows (install.ps1).
./install.sh
Navigate to your server's IP address over HTTPS. Log in with the admin credentials you chose. Upload documents and start asking questions.
https://your-server-ip
Verify all services are operational. Hit the health endpoint in your browser or terminal, or check container status directly with Docker Compose.
curl https://your-server/api/health
docker compose down and delete data volumes — no residual data.
docker compose down and the software is removed. Your documents remain exactly where they were. No lock-in, no export fees, no data held hostage. The 3-month minimum exists so we can properly onboard your team — after that, cancel anytime.$15,000–$18,000 for a structured 90-day evaluation on your hardware. Full platform, up to 15 users, real documents. Evaluation investment credited toward your first-year annual license.
For general inquiries, security questionnaires, pricing questions, or partnership discussions.
info@rendex.law15-minute intro call. We'll walk through a live demo and answer any technical questions your team has.
Schedule a Call →We respond to every email within one business day.