PRODUCT / 03 · ATRIUM

Atrium.

A federated knowledge platform for law firms. Source binaries stay in your existing DMS — iManage, NetDocuments, Litera. Claims, classifications, and audit are centralised in a German-hosted substrate. A seven-rung disclosure ladder governs what each principal can see of each document.

View the disclosure ladder Federation model
FederationHybrid (Model D) · binaries local, claims central
HostingGermany · GDPR-resident · 7-year retention
AuditAppend-only · hash-chained · externally anchored
Atrium entity dossier
FIG. 04 · Atrium · entity dossier PLATE / 04
DISCLOSURE LADDER

Seven rungs between invisible and full document.

Every search hit, every cross-silo reference, every external request resolves to a rung on this ladder. Each step up requires more authority — and, often, a steward in the loop.

Atrium disclosure ladder — typographic feature
FIG. 05 · The Disclosure Ladder · typographic feature PLATE / 05
L0Invisible

Caller receives no acknowledgment. The document is not in their universe.

policy default
L1Existence

"A document matching your query exists." No metadata, no preview, no facets.

policy default
L2Faceted

Classification facets visible (matter type, jurisdiction, year, sector). No text.

steward · above Internal
L3Sanitised abstract

A machine-generated, identifier-stripped summary. Parties, named clauses, and figures removed.

steward · above Internal
L4Redacted view

Document with named-entity, monetary, and personal data redacted in-place.

steward · above Internal
L5Full claim

Full extracted claim text and provenance. No source binary.

role + group authorisation
L6Full document

Source binary fetched from the originating DMS, served through Atrium with audit.

step-up auth + audit
// every disclosure event records: caller · rung · classification · steward · justification · timestamp
FEDERATION MODEL

Hybrid federation. Binaries stay where they were. Claims travel.

Atrium implements Model D of a four-model federation taxonomy. Source documents remain in the firm's existing DMS — they are never copied, never re-hosted. Atrium ingests only the claims: extracted assertions, classifications, citations, and provenance metadata.

On a full-document request (L6), Atrium fetches the binary from the originating DMS at request time, through that DMS's own authorisation, with the fetch itself recorded in the append-only audit trail.

model Acentralised — full corpus replicated to Atriumnot used
model Bfederated read — Atrium queries DMS at request timenot used
model Cclaim-only — no document fetch, even with authorityopt-in
model Dhybrid — claims central, binaries local, fetch on demanddefault
Atrium search
CAPABILITIES

What Atrium does once you've connected it.

C.01

Connectors

iManage, NetDocuments, Litera, and other major legal DMS systems. Documents are read in place; nothing is replicated.

C.02

Canonical classification

Each DMS's native classification scheme is mapped onto a canonical five-level ladder — Public, External, Internal, Restricted, Privileged.

C.03

Steward in the loop

L2, L3, and L4 disclosures above Internal route through a Silo Steward queue. Approvals, rejections, justifications all logged.

C.04

Step-up authentication

First view of Restricted or Privileged in a session, bulk export, reclassification, and override all require a second factor and are audited.

C.05

Policy engine

OPA-compatible policy sidecar (regorus, embedded). Disclosure rules are versioned policy, not application code.

C.06

External anchoring

Hash-chained audit log periodically anchored to an external witness — the firm proves the log existed, in this state, at this time.

C.07

WASM verifier

An independent, source-available WASM module re-verifies any audit segment. Trust the log without trusting the host.

C.08

Role surface

Tenant Admin · Silo Admin · Silo Steward · Group Compliance · Client Relationship Partner. Each has scoped, audited capabilities.

SPECIFICATION

The substrate.

apiRust · Axum · asyncruntime
desktopReact + Tauriruntime
data planePostgreSQL · OpenSearch · Redis · NATS JetStreamstorage
policyOPA · regorus (embedded Rego) · versioned, signed policy bundlesauthz
federation modelModel D · hybrid · claims central, binaries remain in originating DMSmodel
disclosure ladderL0 invisible · L1 existence · L2 faceted · L3 abstract · L4 redacted · L5 claim · L6 fullpolicy
classification ladderPublic · External · Internal · Restricted · Privileged (5 canonical levels)policy
connectorsiManage · NetDocuments · Litera · others on requestintegration
auditAppend-only · hash-chained · externally anchored · independent WASM verifier · 7-year retentionaudit
hostingGermany · GDPR data residency · per-tenant isolationdeploy
rolesTenant Admin · Silo Admin · Silo Steward · Group Compliance · Client Relationship Partnerauthz
step-upFirst privileged read · bulk export · reclassify · override · cross-silo · all require 2FA + auditauthn

Federate without copying. Disclose without leaking.