A document system that knows which matter it is in.
Every file lives inside a matter, carries its privilege state, and remembers the custodian and page it came from.

What stays true no matter which model runs.
Scoping enforced below the app
The matter boundary is applied before any retrieval or model call, not by interface logic.
Privilege travels with the file
Markings are properties of the document, carried into search, retrieval, export and production.
One writer at a time
Check-out locking prevents concurrent edits rather than merely discouraging them.
Versions are kept
Every version is retained with who changed it and when; comparison is between stored versions.
Where documents come from
Intake, coding and privilege, before anything is filed.
Documents arrive through review with their significance and privilege coding attached, and that coding is what the register, the chronology and any export all read from.
- Coding attributable to the reviewer
- Privilege flags propagate downstream
- Families kept together from intake

Provenance
Where a document came from is part of the document.
Custodian, page reference and source production travel with the file — so when a chronology event or a strategy proposition cites it, the citation resolves to a record somebody else can check.
- Custodian and page held on the file
- Citations resolve to the provenance record
- Exports carry the references with them

The register
What exists, who owns it, what state it is in.
Stable document IDs that survive renaming, with privilege, review and four-eyes state shown in the list itself.
Legal hold
Preservation as a state, not a memo to the team.
A matter under hold cannot have documents deleted out of it, and the attempt is logged.
Retention
Tied to the matter lifecycle, not to a calendar.
Retention runs on matter close rather than on a schedule with no idea what the matter is doing.
A clause is the usual answer. Ours is a clause and an architecture.
On every tier. The matter boundary, the approval gate and the signed record are enforced in the runtime — hosted, in your own infrastructure, or on Bernio Pro.
- FRCP 37(e)US
Where ESI that should have been preserved is lost through a failure to take reasonable steps, the court may impose measures up to an adverse-inference instruction.
A hold is a state of the matter that blocks deletion across every document in it, and both the hold and any attempt are written to the audit trail.
- FRE 502(b)US
Inadvertent disclosure does not waive privilege where the holder took reasonable steps to prevent and rectify it.
Privilege markings are properties of the document, applied at retrieval, export and production — so “reasonable steps” is something the system does.
- § 43e BRAO (Germany)EU
A lawyer may engage service providers only as far as necessary, and must obligate them in text form to confidentiality.
When storage and inference run on the firm’s own hardware, the scope of any external engagement narrows to something a firm can describe.
Bring a matter’s file set as it stands today.
We load it and show you the register, the provenance and the version history against your folder tree.
Development status
Bernio is in active development with design partners — firms running real matters through the platform and shaping what is built next — and the first commercial contracts are being signed on founding terms. The capabilities described on this page are built and can be demonstrated on a matter type your team handles. Bernio Pro — the on-premise appliance — is an engineering prototype and is not yet commercially available, so any capability on this site that depends on it is marked as such. Descriptions of the product are not warranties; the binding terms for any deployment are those set out in the applicable written agreement.