How we preserve privilege, resist subpoenas, and self-authenticate
The three things plaintiff firms get burned on in qui tam / FCA / SEC whistleblower work are privilege, discovery, and authentication. We engineered against all three. Here is the architecture in language built for the partner who wants to know whether they can put their name on the engagement letter.
Kovel-style retention as a SaaS subprocessor
Your engagement letter with the relator retains JIL Sovereign as a SaaS subprocessor under your direction and control - the same legal posture courts have accepted for e-discovery vendors (Relativity, Disco, Logikcull) and forensic accountants under United States v. Kovel, 296 F.2d 918 (2d Cir. 1961) and its progeny. We operate as a "necessary professional" assisting in the rendition of legal services.
Critically, your client's underlying material lives in your AWS S3 bucket under your KMS keys, in your chosen region. JIL processes in flight only and never persists payload to disk. Privilege is unbroken because we don't hold what could be subpoenaed.
What this means for you: A defendant who serves a subpoena on JIL recovers commitments, not privileged material. The privilege defense lives at your firm's perimeter - the same place it lives today for every other case. We do not extend or distribute your privilege boundary.
What a subpoena to JIL produces (and doesn't)
When a defendant serves a subpoena on JIL Sovereign for records related to your case, here is exactly what we can - and cannot - produce:
What we CAN produce
- L1 anchor records (hashes, timestamps, signatures, engine version)
- Block heights on the JIL Sovereign Compliance Network
- BFT validator signature sets (14-of-20)
- Engine version commit hash (for replay)
None of this is the underlying client material. It's the math.
What we CANNOT produce
- Your client's underlying documents (we never persisted them)
- Specific identifiers (tokenized at customer boundary, crosswalk in your KMS)
- Reasoning content (Bedrock contractually does not retain prompts; SageMaker KV cleared between sessions)
- Privileged work product (lives in your S3 under your IAM)
A subpoena to JIL for these items returns an honest answer: not held.
Why this matters in qui tam: Defendants routinely subpoena every vendor in the chain looking for ways to crack privilege or contaminate work product. The 14-of-20 BFT validator quorum across 13+ jurisdictions adds a second layer - even if one validator is compelled, the audit trail is independently verifiable from the others. No single point of compulsion.
FRE 902(14) self-authentication - what it actually buys you
Federal Rule of Evidence 902(14), effective December 2017, makes electronic records authenticated by a qualified digital identification process self-authenticating - meaning no records-custodian deposition is required to put the record in front of the jury.
Our CREB® bundle satisfies the rule with: cryptographic hash (SHA-256), distributed timestamp (BFT validator quorum), and a signature set from validators in multiple jurisdictions. The bundle drops into evidence at filing. Opposing counsel can still challenge weight, materiality, or relevance, but cannot meaningfully challenge authenticity on records-keeping objections.
The practical effect: Your firm doesn't produce a JIL employee for a records-custodian deposition. You don't need to litigate authenticity. You attach the CREB as Exhibit A and focus your time on the merits.
Frameworks and inheritance
Bar ethics and customer-side InfoSec teams typically ask for the same documentation stack. Here is where we are - dated, no overstatement:
- SOC 2 Type II: in flight with auditor; minimum 6 months of operational evidence required before attestation. Target attestation: Q4 2027.
- HITRUST CSF i1: engagement scoped; AWS infrastructure inheritance shortens scope materially. Target: 2026-2027.
- HIPAA Security Rule: self-attested today. BAA available for execution before any PHI flows.
- FedRAMP Moderate: readiness assessment underway on JIL agency-sponsored track. AWS Bedrock + SageMaker FedRAMP High in GovCloud provides inheritable controls for federal/CMS workloads.
- ISO 27001 + ISO 27017: in roadmap; dates pending SOC 2 Type II completion.
- Annual third-party pen test: bundled with the SOC 2 + HITRUST SOW.
States and circuits where we have written counsel opinions
Recovery-tied SKUs and other fee structures vary by jurisdiction. Our counsel maintains written opinions on the SaaS-subprocessor posture in:
- New York
- Delaware
- District of Columbia
- California
- Texas
- Illinois
- Massachusetts
- Florida
Coverage is being extended on a per-anchor-firm basis. Additional jurisdictions handled by partner-firm local counsel under a Kovel umbrella.
Want our counsel and yours on a call?
We're happy to do a joint counsel-to-counsel call to walk through Kovel posture, BAA scope, and the privilege architecture. Anchor-firm partnerships start with that call.