Responsible AI, built for environments where compliance can't be compromised - our partnership with Leeway.
- Tamar van de Paal

- 5 days ago
- 3 min read
We're proud to share our work with Leeway, one of Amsterdam's leading IP, technology, and media law firms.
Leeway advises some of the most recognisable names in tech, fashion, retail and entertainment on exactly the things that are hardest to protect: intellectual property, high stakes deals, privacy and data. For a practice like theirs, off-the-shelf AI was never going to be an option. Confidentiality, security, and compliance aren't features to them, they're the foundation of the work.
So we built something together, and then put it to the hardest test there is: daily use by the lawyers themselves.
Over a close, hands-on collaboration, we designed a responsible AI environment to the standard a top IP firm holds itself to. Today it's fully integrated into how the Leeway team works. Not a pilot or a proof of concept. A working part of their practice, pressure-tested by people whose profession is scrutinising exactly this kind of framework.
What we built and refined with Leeway isn't a one-off. It's the same environment every Mindro client works within.
For our clients, many of them in M&A and other deal advisories, a single leaked detail can move a deal. The compliance posture isn't a premium tier or a custom build. It's the baseline. Field-tested with one of the most demanding practices, and standard for everyone on the platform.

So how is that environment actually built?
Not the way a consumer AI tool works. Instead of a public, web-based app that transmits extensive session data, Mindro runs on an controlled architecture that acts as a secure gateway between the organisation and the AI models, sending only what a task requires and limiting metadata exposure by design.
→ Same-cloud, EU-only processing. Mindro and its supported models, e.g. Claude and Gemini, via Vertex AI, operate inside Google Cloud's EU data centres. Your data is processed entirely within a single, secure cloud environment, eliminating unnecessary data transmissions.
→ Fully traceable and auditable. Every interaction is logged and attributable, giving your organisation a complete, reviewable record of how and when AI was used — the accountability trail that compliance, audit, and oversight depend on.
→ No training on your data. Enterprise agreements contractually prohibit the providers from using your inputs or outputs to train or improve their general models. Prompts and outputs are logged only briefly for abuse and security detection, then deleted.
→ Encrypted and certified end to end. All data is encrypted in transit and at rest with AES-256, access is restricted to authorised personnel on a need-to-know basis, and the underlying infrastructure carries ISO/IEC 27001, 27017, and 27018 certifications.
On top of that architecture sit the capabilities that make it genuinely useful
→ Model orchestration — Claude, Gemini, and European open-source models like Mistral, with the freedom to choose the right one for each task..
→ Deep integration with existing IT — including a dedicated SharePoint integration, so teams bring their own documents and knowledge into AI workflows without copying data into yet another system.
→ Collaborative workspaces — so people work together on the same project, with shared context and shared oversight.
→ Grounding in real sources — including integrated open legal resources, so output is anchored in authoritative references.
And underpinning all of it, a principle that matters more today than it did even a year ago: your data stays in Europe, not just at rest, but through inference. Input, processing, and output all happen inside EU data centres. With data sovereignty back at the top of the agenda, where your information actually gets processed is no longer a technical detail. It's a strategic one.
What started as an exploration has become a genuine partnership, and we're only getting started. The next set of capabilities is already in development, built on the same principle that got us here: advanced AI, built for compliance, kept European, made for environments where confidentiality can't be compromised.
Proud of what we've built with the Leeway team. Excited for what's next.




Comments