
DocRobot was built for a rule that felt permanent: a confidential document must never reach a model you do not control. That rule was the whole product — redaction on your own machine, before anything was sent anywhere. Since then a capable model has moved onto the laptop, and the constraint the entire design existed to satisfy has quietly dissolved.
What follows is both halves. First the product as it shipped: a working POC that turned an off-limits pile of contracts and filings into usable material, and became the instrument that opened enterprise AI conversations for the firm. Then a rebuild I did on my own — unshipped, uncommissioned — to answer the question the original could not ask. If privacy costs nothing, what is this product actually for?
Role
I led product design 0→1 on the original — the document workspace and the trust model behind it. It shipped as a POC and did double duty as a sales and capability instrument. The rebuild in the second half is mine alone: no client asked for it, none of it shipped, and it exists to test what the product becomes once the constraint it was designed around is gone.
Walkthrough
A closer look, screen by screen.
01 / 09
Redact first, then ask
The order of operations was the design. A document was cleaned of sensitive terms on the user’s own machine before anything uploaded, and only then did the conversation begin. The workspace stayed as approachable as any chat tool, but every answer sat downstream of a guarantee a security review could actually accept.
02 / 09
A review pass, not a black box
Redaction was the first screen of the flow, and it was legible: search for a client name, a date, an account number, and every match lit up in the document itself with a count beside it. Nothing was barred silently — the user confirmed the pass, watched the terms go dark, and only then did Save & Upload exist as an option. The POC did this manually; later iterations flagged names, dates, and account numbers automatically, with the same review step kept in place.
03 / 09
The trust model is the product
The blocker to adoption was never the model’s capability; it was exposure. So the architecture put the boundary where the risk lived: the original file and the redaction pass stayed on the device, and the model only ever received the cleaned copy. That single guarantee is what turned an off-limits pile of contracts and filings into working material, and it is the reason a cautious enterprise would take the meeting at all.
04 / 09
What the guarantee cost
It is worth being honest about the bill. Because the model only ever saw a scrubbed copy, the answers came back scrubbed too — ask who remains liable on termination and the reply names a black bar, because the party’s name was the thing that could not be sent. And since the redaction decision was made per document, per upload, the unit of work was one document at a time. A question spanning three contracts meant three passes, three uploads, three conversations, and an answer the user had to assemble themselves. Both of those were the price of the guarantee, and at the time the guarantee was worth it.
05 / 09
The constraint dissolves
Everything above rests on one assumption: the model lives somewhere else, so anything it reads has left your control. That assumption no longer holds. A model good enough for this work now runs on the machine the documents are already sitting on, which means the redaction pass — the product’s entire reason for existing — is solving a problem that has stopped happening. The interesting question is not whether to delete it. It is what a document tool is for once safety is free, and whether the careful thinking that went into the gate is worth anything at all now. What follows is my own attempt at that answer: a rebuild, built in the same design system, that no client asked for and that has not shipped.
06 / 09
Ask across everything
This is the screen the original could not have produced. With inference happening on the device, there is no upload decision, no per-document exposure, and therefore no reason to keep the unit of work down to one file. The whole library is indexed locally, and the question that used to take three passes — which agreements auto-renew this quarter, and what notice do we owe — is answered once, citing three different documents by name. Note what is missing: no black bars. The parties, the dates, and the account numbers are all in the clear, because nothing was sent anywhere and so nothing had to be hidden. The line under the answer says it plainly — nothing was redacted, because nothing was sent.

07 / 09
Found, not asked
Once reading the corpus is free, the product stops waiting to be asked. A local model can pass over every document as it lands and surface anything carrying a date — renewal windows, notice deadlines, expiring cover — without a prompt and without a person remembering to check. This view is the argument that local inference is not just the old product made private, but a different shape of product: the original was a conversation you had to start, and this is a standing answer that maintains itself. The thing that makes it possible is unglamorous. Continuous background reading of confidential material is only acceptable when the reading never leaves the room.

08 / 09
The redaction moves to the other end
This is the beat I most wanted the rebuild to earn. The obvious move once privacy is free is to throw the redaction work away, and it would be the wrong one — because documents still leave, just not to the model. They leave when a person sends a summary to outside counsel. So the entire search-and-redact craft from the original survives intact, re-hung at the exit: the same term list, the same match counts, the same review-before-you-commit posture, now guarding the one moment that is actually still a boundary. Set this screen beside the original redaction pass and almost nothing has changed except when it happens, which is the most useful thing I learned building it.

09 / 09
Where the documents go now
The original had a privacy screen because a cautious team needed to see the boundary rather than be told about it, and the rebuild keeps that obligation — the diagram just has a different shape to draw. Everything now sits inside one device zone: the originals unaltered, the index, the model, the answers. The gate has not vanished from the picture; it has slid to the right-hand edge, where the only thing that crosses is what someone deliberately exports. Read the two diagrams as a pair and the whole case study is in them. The same commitment, honoured at a different point in the flow, because the thing it was protecting against moved.

What shipped
Shipped a working POC: confidential documents redacted locally, then summarized, queried, and analyzed by a model.
Made the trust model the product — sensitive content never left the machine unredacted, the precondition a security review actually cares about.
Started with manual search-and-redact; later iterations added automatic detection of names, dates, and account numbers.
Used the POC to open AI conversations with cautious enterprise customers — positioning the firm as a partner for their AI plans and building the team’s own AI design and engineering capability.
The rebuild that follows has no results to report. It is a design proposition, not a shipped product.
Selected decisions
- 01
Led with the real adoption blocker — confidential data — and made local redaction the core promise.
- 02
Designed redaction as the first step in the flow, not a bolted-on setting — manual in the POC, automatic in later iterations.
- 03
Kept the document in view and grounded every answer in it, so a team could trace a response back to its source page.
- 04
In the rebuild: moved the unit of work from one document to the whole corpus, which is the thing local inference actually unlocks.
- 05
In the rebuild: kept the redaction craft and moved it to the export step — the constraint changed position rather than disappearing.



