Docs / Legal Privilege

Legal Privilege

A workspace pack on the same core masking engine — not a second SDK. When entitled, legal_privilege is merged into enabled_packs and force-enables email, phone, and nationalId, plus pack-only matterNumber ([MATTER_NUMBER_n]) for Shield, SDK, and CLI --key scans. Policies dictionaries emit hard egress tokens [PRIVILEGE_TERM] and [MATTER_CODENAME] — never vaulted originals.

On this page+

What it does

  • Force-on via pack merge into enabled_packs — same resolution order as PCI / Financial and HIPAA / PHI.
  • Privilege-oriented and matter-codename dictionaries from Dashboard → Policies sync through GET /v1/config (gated when the pack is not entitled).
  • Matter / case / docket number detector with legal-file lexical context to limit false positives.
  • Telemetry can attribute pack-forced masks so Startup+ Audit Logs CSV/JSON evidence export shows industry pack provenance.

What it is not

  • Not a privilege log, waiver tracker, or ethics engine.
  • Not court-admissible redaction certification or full matter DLP.
  • Not network DLP — masking runs on-device / in-process before the model call.

Entitlement

  • Industry pack — $49/mo on Startup+ from Dashboard → Add-ons. Never plan-included (including Business+).
  • Developer must upgrade to Startup before Subscribe is available.
  • Ops can still grant via enterprise_grant for partners; when Active the pack appears in enabled_packs.
  • See also limitations and on-device architecture.