Capability catalogue
PATRON runs on your own hardware. Below is what it does in version 1.3.0, straight after installation. Every entry carries a link to the architecture decision behind it - a document in a public repository, readable without asking us for permission.
28 capabilities · 54 decision records · limits stated openly
Applies to PATRON 1.3.0. Published 24 August 2026, last updated 24 August 2026.
Every session with an AI assistant starts from nothing. The finding you reached on Wednesday - that in this matter the deadline runs from service rather than from issue - has to be explained again on Thursday. A firm's knowledge lives in people's heads and in email.
PATRON writes findings to durable memory on your own disk. You say in chat “remember that in this matter the deadline runs from service” and it stays. Next time you ask about that matter, it goes back to it on its own.
Memory is driven by the agent. The model has two tools, remember and recall, and reaches for them on your instruction or when you ask about a matter where something has already been settled. That was a choice, not an oversight. A store that fills itself in the background gives you, six months on, a body of assertions nobody has reviewed or approved, and in a law firm that weighs. Everything lands in a local database and never travels to the model provider's cloud.
Limit: there is no screen today listing what has been remembered. You ask about it in chat, and you ask for changes in chat.
They have no screen of their own and need no operating. They decide whether an answer lands in the substance of the file or merely in its words.
ProblemFull-text search finds a word. A case is made of events, deadlines and people. The question “what happened between the demand and the claim” has no good keyword.
SolutionPATRON searches two ways at once: by meaning and by event structure. It picks passages describing the sequence in the right order, rather than those that happen to contain the word “demand”.
How and whyDocuments are split at the boundaries of drafting units rather than every so many characters. A clause stays a clause, a section of a judgment stays a section. Ranking combines two similarity measures, because a single measure confuses similarity of topic with similarity of facts.
ProblemThe same party appears in fifteen documents under four names. The link between a matter from two years ago and today's only shows up when somebody remembers it.
SolutionPATRON builds a local graph: parties, people, matters, sources and links between documents. It grows with every file you add and stays on your machine.
How and whyAn edge in the graph is an assertion about reality, so it does not appear quietly. The model proposes a link, a person approves it, and the decision travels to the audit trail together with the approver's name. Names are recognised by a rule-based detector - a generative model can produce a value that was never in the document.
LimitThe graph works underneath. There is no screen today for looking at it.
ProblemDocuments from one set of proceedings sit in three places: some in email, some on a drive, some as a scan from the court.
SolutionA matter in PATRON is the complete file for one set of proceedings. You import a folder in one move, and everything you do afterwards - questions, tables, drafts - happens in the context of that matter.
How and whyA matter also marks a confidentiality boundary. General work and work on a client's file have separate roots, so letting client material into a general task takes a deliberate move. It will not happen by accident.
A model can produce a sentence that reads like a quotation from a judgment while the judgment says something else. Anyone checking every footnote by hand gives back the whole gain from using AI. So the checking is done by machine, and the result sits next to the citation.
SolutionThe verdict is stored with the answer, so it is still visible later, in the audit trail.
How and whyVerification is mechanical and does not rest on a second model's opinion. The cascade starts with a literal match, tolerant of whitespace and typesetting differences, and only then reaches for a paraphrase judge: cheap and certain before expensive and debatable.
ProblemA passage can be quoted correctly and still lead the wrong way, because nobody assessed whether it carries the meaning attributed to it.
SolutionA separate signal warns when a proposition is grounded in the text but its substance has not been assessed. That is how a correctly quoted passage most often misleads.
ProblemAn answer built on a judgment pulled from an external database looks exactly as trustworthy as an answer from your own file. If only your documents are verified, source control ends at the edge of your own disk.
SolutionCitations from connectors go through the same cascade as citations from case files and receive the same coloured verdict.
How and whyThis one was forced by measurement. In a run before a demo for a corporate client, a block marked as a verbatim quotation had zero of four sentences covered by the source, and the interface said nothing. Silence is more dangerous here than a negative verdict, because absent information reads as confirmation.
All of it happens on your machine, before anything reaches a model.
ProblemA photocopy from the court is an image. You cannot search it or cite it. And sending case files to cloud OCR is sending case files out.
SolutionPATRON reads PDF, DOCX, DOC and scans. The OCR engine ships in the installer, works without a network and reads text in the language of your edition.
How and whyThe engine sits in the package from the moment of installation. Pulling it down at the first scan would be an outbound move nobody approved. Recognised text reaches the index together with page numbering, so a citation can point at a page.
LimitAn edition reads one language, so a scan in another comes out weaker. A missing language pack switches OCR off instead of recognising in the wrong language - an open gap beats a quiet distortion.
ProblemA document from outside can carry an instruction addressed to the model. An uploaded attachment can try to redirect the agent.
SolutionEvery document passes an input scan before the model sees it. Suspicious content is flagged and the decision goes to the audit trail.
How and whyBy default we flag the suspicious passage and leave it in the file. If PATRON hid the content of a case file from the lawyer in order to protect the model, it would invert the hierarchy - the lawyer decides about the file. Enforcement tightens at the boundary out to the model.
ProblemA question to a cloud model carries a fragment of the case file with it. Names, identity numbers and addresses go along.
SolutionBefore content leaves for the model provider, identifying data is masked. You work on the full text. What goes out carries no identifiers.
How and whyThe detector is rule-based and tuned to the local jurisdiction: identity numbers validated by checksum, company registry numbers by pattern, surnames by an inflection dictionary. Rule-based, because model-driven masking gives a slightly different result each time, and protection of personal data has to give the same one.
A tool that insists you work inside it drops out of the workflow within a week. So PATRON hands work back in the format the firm already uses.
ProblemAn AI assistant hands back finished text. To accept it you have to read the whole thing and find the changes yourself.
SolutionPATRON returns changes as tracked changes in a DOCX file. You see each edit separately and accept or reject it in Word.
How and whyThis is native OOXML, the same format Word writes edits into. The file goes to the client, comes back with their comments and still works. A redline and a comment can sit on the same passage, because a reviewer often changes a sentence and explains why in the same breath.
ProblemAn edit says what to change. It does not say why the other side will attack it.
SolutionPATRON inserts comments into the document: reviewer notes, and separately the devil's advocate counterarguments. They land in Word's comment pane, where a lawyer looks for them.
How and whyComments go into the native OOXML comment layer, so they survive a save and do not mix into the text. Reviewer and devil's advocate are kept apart on purpose. Those are two different roles, and merged into one voice they produce text that praises and attacks at once.
ProblemThe work happens in Word, and the assistant wants to move it into its own window.
SolutionYou download the file, work in Word, upload it back. PATRON reads your tracked changes and comments, including comments addressed to it as an instruction.
How and whyYou give instructions through a comment in the document, where you are already writing. Document versions are kept, so going back to the state before a round of edits takes one move.
ProblemA one-button “improve this draft” either does too little or rewrites text you never wanted touched.
SolutionYou choose the stages: substantive review, devil's advocate, work on language. Any stage can be skipped.
How and whyIf every stage ran by default, you would pay in time and money on tasks that do not need them. High-stakes drafts are recognised by a separate classifier, and their handling is stricter and recorded in full in the audit trail.
ProblemThirty contracts, each with a date, a value, a liquidated damages clause and a notice period to extract. That is a day of retyping into Excel.
SolutionYou define the columns, PATRON fills the table from the whole bundle. Every cell points back to a passage in the source. Export goes to a spreadsheet.
How and whyA cell with no pointer to its source has to be checked from scratch anyway, so each one carries three things: value, source and coverage verdict. The verdict travels on to the audit trail. Column presets ship with the product, so the first table takes a minute.
ProblemAn automated pass always fills something in. Without a way to tell which cells are solid, the review covers all of them anyway.
SolutionCells carry a coverage verdict, so you start the review with those that lack one. A human review of a cell is recorded.
How and whyThis is the same cascade that judges citations in chat. One meaning of the verdict holds across the product, so a lawyer learns it once.
ProblemThe same sequence of steps on every matter of the same kind. Every time from scratch, and every time slightly differently.
SolutionA workflow stores the sequence and runs it on a chosen matter. Fourteen ready workflows ship with the product, across seven practice areas: from a conditions precedent checklist and a change of control review, through NDA, lease and employment agreement reviews, to e-discovery. The commercial agreement review alone fills eighteen columns, from parties and term through to limitation of liability, force majeure and governing law.
How and whyThe starter set ships in the package so that the first run does not require building anything. Workflows have no decision record of their own. They grew as a layer over the table and the citation, and those have their decisions documented alongside.
LimitThe workflow library runs in English transactional terminology: titles, practice areas and column names. Those are the working terms in transactional practice, but the interface around them is in your language.
ProblemA skill added to the agent is code that gets access to case files. Outside code with no controls is an open door.
SolutionEvery skill carries a manifest declaring where it is allowed to reach. PATRON checks file integrity and enforces the declaration on every run.
How and whyA declaration nobody enforces stays a document for reference. The skill's checksum goes to the audit trail, so afterwards you can show which version of a tool worked on the file. A skill reaching beyond its declaration is stopped. Not warned, stopped.
ProblemThe body of law changes. Refreshing a local copy by hand is work nobody does regularly.
SolutionKnowledge packs arrive through a distribution channel with a manifest and a delta, and the application shows a banner when there is something to update.
How and whyThe channel ships the delta alone. With a corpus counted in hundreds of thousands of documents, a full download on every change is not workable. The manifest lets you check exactly what arrived before it enters the index.
“Local-first” as a slogan says nothing about what happens when a task needs three models at once and one of them sits outside Europe. Below is the mechanism that settles it.
ProblemA single AI provider means dependence and a standing question about where case files end up.
SolutionYou connect your own model: OpenRouter, Anthropic, Google, OpenAI or a local model through Ollama. Sensitive matters run entirely without a network.
How and whyA local model takes the same selection path as cloud providers and passes the same routing mechanism. That is what makes “this matter runs offline” a setting in a dropdown rather than a separate mode with its own limitations.
ProblemA multi-model operation mixes providers from different zones, and the user sees one result.
SolutionEvery model call passes a guard that knows the provider's data zone and the ceiling set for the matter. A multi-model operation is classified by the worst zone in the whole set.
How and whyThis is where the whole difference sits. A task of three steps, two local and one reaching a provider outside Europe, has left Europe in its entirety. Averaging would blur that. The ceiling is hard: exceeding it stops the operation instead of logging it and letting it through.
ProblemThe model bill arrives after the fact and there is no way to attribute it to a matter.
SolutionYou set a budget ceiling for a matter. Once it is used up the operation stops, and consumption is visible in the usage view.
How and whyThe ceiling works like the egress ceiling: it stops. A message that lets the operation through is one we read at invoicing time.
ProblemA model key is a payment instrument. Copied along with the database, it runs up costs on somebody else's computer.
SolutionKeys are encrypted with AES-256-GCM, using a secret generated on your machine at first run.
How and whyThe secret is created locally and goes neither into the installer nor into a database backup. Two consequences follow: every new workstation is configured separately, and a leak of the database alone is not a leak of the keys.
An event log that can be edited is a note. Evidence it is not. Every event in PATRON goes into a chain bound by SHA-256 hashes, and changing a single entry breaks the chain and becomes detectable.
A Merkle tree works above the chain so that verification does not require walking the whole history. With a log growing for years, a linear check takes too long, and a check that takes too long never gets run at all. The root is computed automatically and you trigger verification with a button.
For a single event in the log you export an archive for the auditor. Inside is the event itself with its payload masked, a Merkle proof tying it to the root, a checksum over the whole archive and two verifiers: a browser one that opens with nothing to install, and a command-line one built on the Python standard library alone. Plus instructions for the recipient. The verifiers travel inside the archive, because a check that needs our software depends on us, and so is not independent. The scope answers the record-keeping requirements of Article 12 of the AI Act, and the export itself requires firm-administrator rights and is written to the log.
Personal data inside the audit trail itself is masked - otherwise the compliance record would become a second body of data to protect. Full audit trail documentation.
The same machinery also exports a whole document: the content, the verdict on every citation (including those from external sources), the chain excerpt and the model used - an answer to the client asking “how did this analysis come about”. The author of the document downloads it with the Evidence pack button next to the answer, because access follows the case boundary rather than an administrator role. ADR-0152.
ProblemA connector is an external tool with access to case files. Its description can carry an instruction addressed to the model, and the user sees only a name and an icon.
SolutionA connector definition is scanned before it enters the context. The scan result appears in a banner in the application, and the gate's decision goes to the audit trail.
How and whyThe gate sits at backend startup, before the tool is registered. A check after wiring would be inspecting something already working on case files. Permissions are split into rings, so a connector reading case law does not get the rights of a tool writing to the file.
ProblemA legal tool without sources of law is an empty chat window.
SolutionEvery national edition ships with a connector for the law of its own market. Other sources, including EU law and connectors for other countries, you pick from Boutique.
How and whyConnectors are chosen by the lawyer for their own jurisdiction. The connectors themselves run in two runtimes, because some European sources have mature libraries in only one of them. Rewriting those for the sake of uniformity alone would be work for its own sake.
ProblemTranslating the interface is not enough. A lawyer in Italy needs Italian law and Italian concepts, not a Polish product with the labels swapped.
SolutionPATRON comes in nine editions: Polish, English, American, British, Brazilian, Italian, German, Spanish and French. Each has its own jurisdiction profile.
How and whyOne language per installation, with no switch in settings. A switch leads to a database where files, prompts and results mix languages. The language of method belongs to the edition, the language of substance to the document - an answer about a Polish judgment stays faithful to its wording whatever the interface language.
An outbound action can require human approval before it runs. PATRON then holds it as a card to review. The firm's Operator turns the mode on and picks the scope: every action, or high-stakes matters only.
It ships switched off, because in a single-lawyer practice it adds a step to every move. It earns its place where somebody other than the author reviews what the agent did.
This section is part of the product, not small print.
Always a personApproving an edge in the graph, accepting an edit, sending a document - those are human moves.
Colour, not silenceA citation without coverage gets a verdict rather than a quiet interface.
A visible pathThe route to a model provider is visible, masked and recorded in the audit trail. With a local model it does not exist.
Material, not adviceAn answer is working material, and responsibility for the document stays with counsel.
Does PATRON remember what we agreed in earlier sessions?
Yes. You say in chat “remember that in this matter the deadline runs from service, not from issue” and the finding is written to a local database on your disk. Next time you ask about that matter, PATRON goes back to it. The write happens on your instruction rather than automatically in the background, because memory collected on its own builds a store nobody has reviewed. There is no separate screen listing what has been remembered - you ask about it in chat.
How do I know a quotation from a judgment is real?
Every citation carries a coloured verdict. Green means the passage was found in the document word for word, amber means a paraphrase or no access to the source text, red means no coverage. Verification is mechanical and does not rest on a second model's opinion. The same rigour covers citations that connectors pull from external sources.
Do case files leave the firm when I use a cloud model?
A fragment of the file reaches the model provider, but identifying data is masked first by a deterministic detector: national identity numbers validated by checksum, company registry numbers by pattern, surnames by an inflection dictionary. Every call passes a guard that knows the provider's data zone and the hard ceiling set for the matter. With a local model through Ollama nothing leaves the machine.
How is PATRON different from an AI assistant in a browser tab?
It runs on the firm's own hardware, checks every citation against the source document and records the work in a hash chain from which you can export an evidence bundle for an auditor. It returns edits as tracked changes in a DOCX file, so the work stays in the Word workflow. Each of those decisions has a published architecture document you can read before you buy.
Does PATRON work entirely offline?
Yes, with a local model running through Ollama. The OCR engine ships inside the installer and works without a network, the law connector for your market comes with your edition, and the audit bundle verifier runs without reaching our servers. You need a network for cloud models and for knowledge pack updates from Boutique.
What does PATRON not do?
It does not decide - approving an edge in the graph, accepting an edit and sending a document remain human moves. It does not hide uncertainty: a citation without coverage gets a colour, not silence. It does not move case files out without your consent. It does not pretend to be a lawyer - an answer is working material, not legal advice.
PATRON runs on the firm's hardware. The code, the decision records and the verifier are available from the first run.