Review at volume, with privilege protected by construction.
The point of reviewing on your own infrastructure is that the most sensitive documents in the matter are the ones that never travel.

What stays true no matter which model runs.
Privilege candidates stay inside
A flagged document is excluded from any external model call from that moment, without waiting for confirmation.
Families stay together
An attachment is reviewed with its parent. Splitting them is how privileged material gets produced.
Coding is attributable
Responsiveness, privilege and significance are recorded against the reviewer, the batch and the version.
QC is recorded
The sample, the checker and the outcome are written down, so defensibility is a document rather than an assurance.
What review produces
A coded set the rest of the matter can rely on.
Coding decisions become the register’s privilege state, the chronology’s significance threshold and the production’s exclusion list — one act of review, read by everything downstream.
- Privilege state carried on the document
- Significance feeds the chronology threshold
- Production excludes by state, not by filter

From documents to a case
The reviewed set becomes the timeline.
Events are proposed from material that has actually been reviewed, at the threshold you set, and each one keeps the custodian and page it was drawn from.
- Only reviewed material is reachable
- Events proposed, never inserted silently
- Custodian and page travel with the event

Intake and batching
From a bundle to a reviewable set, with the rules stated.
Mail, archives and folders go in; batches come out at the size you set, and the parameters are recorded with them.
Assignment
Round-robin or directed, with progress visible.
Each batch shows its reviewer, how far it has gone and what it has raised, to the supervising lawyer.
Production
What went out, when, and to whom.
The production log lives in the matter, so if a clawback is ever needed the question of what was sent is not an investigation.
A clause is the usual answer. Ours is a clause and an architecture.
On every tier. The matter boundary, the approval gate and the signed record are enforced in the runtime — hosted, in your own infrastructure, or on Bernio Pro.
- FRE 502(d)US
A federal court may order that privilege is not waived by disclosure in the proceeding before it.
The order is a backstop, not a plan: privilege candidates are withheld from external processing by state, so the disclosure is far less likely to occur.
- FRCP 26(b)(1)US
Discovery must be proportional to the needs of the case, weighing burden and expense against likely benefit.
Batching parameters, sampling and per-batch cost are recorded, so proportionality is argued from the actual process.
- The Sedona Principles, Third Edition — Principle 6US
Responding parties are best situated to evaluate the procedures and technologies appropriate for producing their own ESI.
Reviewing inside your own perimeter makes that real: the methodology, the parameters and the record all belong to you.
Run a batch against a set you have already reviewed.
A review you know the answer to is the fairest test there is. We put our result next to yours.
Development status
Bernio is in active development with design partners — firms running real matters through the platform and shaping what is built next — and the first commercial contracts are being signed on founding terms. The capabilities described on this page are built and can be demonstrated on a matter type your team handles. Bernio Pro — the on-premise appliance — is an engineering prototype and is not yet commercially available, so any capability on this site that depends on it is marked as such. Descriptions of the product are not warranties; the binding terms for any deployment are those set out in the applicable written agreement.