MEMON SYSTEMS

Legal RAG Compliance Architecture | Memon Systems

Legal AI that retrieves the right law, and the evidence that it did.

I build systems to that standard, and I measure existing ones against it.

For legal-tech vendors held up in enterprise risk assessment, and law firms deploying retrieval under SRA obligations. UK and EU.

what I do

Compliant Data Architecture

Retrieval systems that run inside the client's own cloud tenancy. No data egress, no model provider on the inference path.

How it is delivered

  1. Deployment into client tenancy. AWS or Azure London region. Infrastructure-as-Code delivered for the client's own pipeline to apply.
  2. Open-weight models. Inference stays inside client infrastructure, so no sub-processor and no DPA for a model provider. Legal risk is exchanged for infrastructure risk.
  3. The arithmetic. Self-hosting costs more per query than API pricing below roughly 240M tokens/month, less above it. A machine spun up sparingly for one client costs more per token — a compliance premium, not a saving.
  4. Migration scoped as its own work. An LLM API is stateless; a RAG system holds documents, embeddings, indexes and access rules.
Retrieval Integrity & Evaluation

Recall against a labelled sample, with a documented sampling protocol, is the bar the legal profession set for a retrieval process a court will accept — in e-discovery, from Grossman & Cormack (2011) onward. The same standard applies to RAG retrieval.

What gets measured

  1. Retrieval recall and precision at k across chunking and embedding configurations.
  2. Masking recall and precision, reported separately for direct and quasi-identifiers.
  3. Point-in-time statute correctness. Whether the provision returned was in force on the relevant date.
  4. Version drift. Same query, same corpus, same prompt, across model versions — and the diff.
  5. Citation verification. What fraction of citations resolve to a real document, and what fraction support the proposition. Two numbers.
  6. Abstention under confidence gates. Refusal rate against fabrication rate when the corpus lacks the answer.
  7. Shipped with every benchmark: sample size, bootstrap confidence intervals, seed and variance, and an agreement statistic wherever a model graded an output.
Enterprise Trust Readiness

The evidence pack a legal-tech vendor's enterprise buyer requires from a supplier they have not encountered before. Documentation, not software.

What gets produced

  1. Architecture documentation. Data flow diagrams showing encryption at rest and in transit, threat models, disaster recovery plans.
  2. TPRM questionnaire support. Drafted answers, with the evidence each one rests on attached.
  3. Control-set crosswalks. Systems are designed against NIST AI RMF 1.0, ISO/IEC 42001:2023, ISO/IEC 27001, CSA CAIQ v4, SIG Lite and the OWASP Top 10 for LLM Applications. Designed against and evidenced for — none of them held here.
  4. SOC 2 route for the client. The system is built to be auditable, and I take the CPA firm's auditor through it. No certification is held here.

Start by measuring what your deployment does.

Deployment Audit: £500, fixed scope. Your side runs the battery and sends the responses; I return a dated report against a battery hashed before it ran. Credited in full against the next stage.

See what this costs

about

Abdullah Memon

Abdullah Memon

Memon Systems Ltd

UK Incorporated · No. 17284215

Signing key

A487 3AE7 AEE6 56BF F54E C751 B5C9 93EA B678 58DE

Commits from 29 July 2026 are signed with this key; earlier commits are unsigned. Ed25519, valid to 28 July 2028. Public key.

I measure whether legal AI retrieval systems return the right law, and I build the controls that make the answer auditable to someone who was not in the room.

I work alone. There are no sub-processors in the delivery of client work, no hosting, and no production data leaving your environment.