The problem
The quiet problem
Your week disappears into documents. Drafting, summarizing, comparing versions, hunting for the thing you know you wrote in March. AI could hand some of those hours back. You know it, your competitors know it.
But your work runs on confidentiality. You can’t paste client files into a free chatbot and hope for the best. So the choice looks like: risk it, or fall behind.
Here’s the uncomfortable part: in most firms, that choice already got made without you. Somebody on the team is quietly using public AI tools on work material: no policy, no controls, no record. The risk isn’t hypothetical; it’s just invisible.
And underneath it all, the most honest objection of all: “I don’t know what I don’t know.”
That’s fixable. That’s the whole point of starting with an assessment instead of a sales pitch.
Why not just buy the big-vendor product?
Tools aren’t systems
The big vendors will happily sell you seats. What they sell is a platform, and a platform is not an implementation.
Someone still has to figure out where AI actually belongs in your firm, and where it doesn’t. Set it up around your duty of confidentiality, not around a generic terms-of-service. Load it with your documents. Train your people. Keep it running. Answer the phone when something’s weird.
At enterprise scale, that someone is an IT department. At two to ten people, that someone doesn’t exist. You get the bottom pricing tier and a support queue.
That’s the job I do. Not another tool. The system around the tools, built for one firm at a time: yours.
The method
Assessment first. Fixed price always. Documented everything.
1 · Assess. Two sessions over about two weeks. I map where AI saves your firm real hours safely, you watch a private system work on your own documents, and you get written findings. If a build isn’t worth it for you, the findings say so, in writing.
2 · Price. The assessment produces a fixed price and an exact hardware list. You know the full cost of everything before committing to anything. No hourly meter, no “it depends.”
3 · Build. On hardware you own, in your office. Small visible steps, documented as it’s built. The documentation isn’t an afterthought; it’s a deliverable.
4 · Run. I operate it on retainer: updates, monitoring, backups, support, with response times in writing. You focus on the business.
5 · Hand over as you grow. Everything is documented well enough that any competent professional could take over. You take as much or as little control as you want, on your schedule. The keys are insurance, not homework. Most clients never touch them; they just sleep better owning them.
Proof
Under five minutes. No jargon. No terminal.
Read the demo transcript
Intro
Can your firm actually use AI, without client files ever leaving the office? Let me show you.
Private by design
These are sample documents from a made-up accounting firm because the whole point of this system is that I’d never show you real client files. The AI runs on this machine. This blue badge means local: while it’s on, nothing, not the documents, not your questions, leaves the computer.
Answers with citations
Watch. “What did we agree with Alderwood about the filing deadline?” There’s the answer, and here’s the part that matters: the citation. It shows exactly which document it came from, so you verify the source in one click instead of trusting a chatbot’s memory.
Honest refusal
Now a question these documents can’t answer. “What’s our position on the Henderson audit?” Also note that these four documents below are what’s in the main corpus, and that demo scratch is for the scratch document I will upload later. This is to show you that there is no information or file about the Henderson audit showing you that it doesn’t invent an answer with a confident face. In your business, a wrong answer is worse than no answer, so honest refusal is a feature, not a bug.
Delete an AI’s memory
Here’s the question every owner asks: what if someone adds a document that never should have gone in? Watch closely. I add this file… then, ask about it… it answers. Now, Clear. Ask again… gone. And notice what just happened: it learned that document in seconds, without retraining on it. It reads and remembers in a memory you control. Systems that retrain on your data can never hand you this delete button. It doesn’t know that document ever existed. You control its memory. That’s what owning the system actually means.
The honest cloud toggle
And one honest thing the big vendors won’t lead with: cloud AI is faster and on raw usage, usually cheaper. So this system gives you both. Flip this switch and the badge turns amber, which means this query goes out to a cloud provider. Faster, and that’s exactly why it’s labeled, and why it’s your choice, per task. Sensitive work stays blue. I will never tell you “nothing leaves” while an amber light is on.
Book the assessment
So that’s the system: your documents, answered with citations. Honest refusals. Memory you control. And a clear line between private and cloud. For a small firm, that’s hours back every week without betting client confidentiality on somebody’s terms of service. It starts with a fixed-price assessment: I map what AI can safely do for your firm, on your own documents, and if it isn’t worth it, I’ll tell you that in writing. cairnward.com, book the assessment. My name is Terrence and I answer personally.
What you’ll see:
- It answers questions from a firm’s own documents, with citations to the exact file.
- Asked something the documents don’t contain, it says so instead of inventing an answer.
- A private document gets added by mistake, and deleted from the system’s memory on command. Gone. You watch it happen.
- The one honest toggle: blue means fully local; nothing leaves the machine. Amber means cloud: faster, opt-in, clearly labeled, your choice per task.
And you never touch a terminal. Not in the demo, not ever.
Security & honesty
Security, in plain English
LOCAL
0 bytes leave this machine
CLOUD
This request goes to a cloud provider: labeled, opt-in, your choice
0 bytes leave this machine This request goes to a cloud provider: labeled, opt-in, your choice
- It runs on hardware you own, on an isolated network. By default, nothing leaves.
- Cloud is opt-in, per task, clearly labeled. When you choose it for non-sensitive work, you see it (the amber badge). I will never tell you “no data leaves” while a cloud route is on.
- Nothing you type retrains anything. Documents are indexed only when you add them, and you can remove one from memory on command.
- You get a plain-English security statement you can hand to your attorney or IT reviewer: what the system does, what it doesn’t, what leaves and when.
- Honest cost note: on raw usage, cloud AI is usually cheaper. You buy private AI for control and confidentiality, not to save on subscriptions. Where cloud makes sense, the system uses it, labeled.
This system is designed with security best practices in mind and built to reduce data exposure. It supports your compliance process; it is not a replacement for legal or compliance review, and I’ll never pretend otherwise.
Start here
The Private AI Assessment
Find the hours AI can save your firm, without your client files ever leaving the office.
What’s included
- 90-minute discovery, in person or video: your workflows, your document reality, your risk comfort.
- A shadow-AI and document-exposure map: what’s already happening in your firm that you can’t see.
- A live private-AI session on a handful of your documents: citations, honest refusals, and the delete-on-command moment, in front of you.
- A written findings brief in plain English. Your firm’s capability map: what’s worth doing, what isn’t, and why. Yours to keep either way.
- If a build is warranted: a fixed price and exact hardware list. If it isn’t: I say so, in writing.
How discovery actually works, and what it never does
- Nothing gets installed. No software on your systems, no device on your network, no automated scans. The assessment is a structured conversation and a guided walkthrough. You drive, I look and ask. Look, don’t touch. By design.
- I read what you choose to show me. The exposure map charts categories and flows: what kinds of documents exist, where they live, who and what touches them. Not the contents of your files.
- The live session uses documents you select. A handful, loaded in front of you on my demo system, used in front of you, and deleted in front of you before I pack up. You watch both halves.
- Everything is in writing. Scope letter before we start; findings brief after. If something I did weren’t in that letter, you’d see it.
What’s not included: the build itself, integrations, ongoing support. Those come later, at the fixed price the assessment produces, only if you want them. And no compliance certification: this supports your review process; it doesn’t replace it.
Timeline: two sessions, inside two weeks.
Price: $1,200 fixed. Founder rate for early clients: $950. 100% credits toward a build within 90 days.
Guarantee (first five clients): if you don’t find the assessment worth the fee, you don’t pay. That’s the honest version of a guarantee I can stand behind at this stage.
How you pay: a normal invoice, card or ACH, with written scope first. Nothing vague, nothing up front in cash.
The founder
Who you’re working with
I’m Terrence McKinnon. My favorite work is solving real business problems with technology, and it is what I have built my career around.
Here is what working with me actually looks like. We talk about your business: where it is today, where you want it to be, and what stands between the two. Then I design the smallest system that closes that gap, build it, and hand you the controls as you grow.
The type of business matters less than you might think. If I can see a way to create real value for you, that is the job. If I can’t, I will tell you that plainly and point you somewhere better.
I have been building for the web since 2019: sites, funnels, and marketing systems. The last stretch has gone deep on AI infrastructure and security. I run my own business on AI every single day, under a strict security setup. It is governed by a method I open sourced so anyone can inspect it.
Most of my own work runs on cloud AI, because for my risk profile it is faster and cheaper. Your risk profile is different. When client confidentiality is on the line, the right answer is a private system on hardware you own. That is what I build.
And here is my honest stage: you would be among my first paid clients. That is exactly why the early terms look the way they do. Founder pricing, a guarantee that says you do not pay if it is not worth it, and attention no vendor gives a ten person firm. The risk sits on my side of the table, by design.
The questions you’re probably asking
Straight answers, in plain English. If yours is not here, ask it on the call.
“How do I know this is secure?”
Don’t take my word. Watch. It runs on your hardware on an isolated network; I show you live what can and can’t leave. You get a plain-English security statement for your attorney or IT reviewer. Designed with security best practices in mind; supports your compliance process, not a replacement for legal review.
“What actually happens during the assessment? Are you reading all my data, or installing something?”
Neither. Nothing is installed, nothing scans your systems, no device plugs into your network. The assessment is a structured conversation plus a guided walkthrough of how documents flow through your firm. You drive, I look and ask. The map I deliver charts categories and flows, not file contents. The demo system is my own hardware that I bring; discovery itself isn’t a gadget. It’s a documented method, and you get it in writing.
“How do I know my data is safe with you during the process?”
Because during the assessment it never transfers to me. We work from your screens and your answers. The only documents that touch AI are the few you choose for the live session: used in front of you, deleted in front of you before I pack up. Scope letter before, findings brief after; if anything I did weren’t in that letter, you’d see it. The assessment is look-don’t-touch by design, precisely so that a first engagement with me risks nothing.
“My documents are a mess, and half aren’t even digitized. Do I need to get organized before working with you?”
No. Mess is the normal starting condition, and you don’t clean for the cleaner. Two honest points. First: this system doesn’t need your folders organized the way a human filing system does. It indexes what exists and finds things by meaning, not by location. Getting organized becomes an outcome, not a prerequisite. Second: paper. Digitizing is a solved, boring problem: a scanner plus a simple intake habit. The assessment tells you what’s worth scanning first, because not everything deserves the effort. If your firm is drowning in paper and chaos, that isn’t a reason to wait; it’s most of the reason to start.
“How do you delete memory if I accidentally expose a private document?”
One click. Documents are indexed only when added, and removing one removes it from the system’s memory. I demo the delete live before you ever pay for anything.
“Do the chats save so the model learns from you?”
Nothing you type retrains anything. Your conversations aren’t training data: not locally, and never sent anywhere in local mode.
“Isn’t cloud AI cheaper?”
Usually, yes. I’ll tell you that to your face. You buy private AI for confidentiality and control. Where cloud is the right tool for non-sensitive work, the system uses it, clearly labeled, at your choice.
“Why you instead of an established vendor?”
At 2 to 10 people you get their bottom tier and a ticket queue. I set the system up around your actual documents and duty of confidentiality, run it, hand you ownership with no lock-in, and answer the phone.
“Couldn’t I just build this myself and skip paying you?”
Genuinely, yes. The core components are open-source, and if you have the time and appetite, I’ll cheer you on; my own system is built from the same public parts. What you’d be paying me for is everything around the parts: architecture decisions that prevent quiet failures, security hardening, making it usable for your staff with no terminal, the maintenance habit, the documentation, and someone accountable when it matters. Mostly, you’d be paying to not spend your own billable evenings becoming an infrastructure hobbyist. If your hours are worth more with clients than with config files, that’s the value.
“How do we know you’ll keep maintaining it on the retainer?”
Response times in writing, a documented system you own either way, and a simple incentive: the retainer is my business model. And if I ever disappeared, the documentation is complete enough that any competent professional takes over. That’s not a promise; it’s an artifact you’ll hold.
“Who do we escalate to?”
Me, directly. That’s the honest limit of a solo practice, so the system is designed around it: written response times, boring standard technology, and a handover file. You’re buying a system you own, not dependence on a person.
“What happens if you hit a problem you can’t fix?”
Three honest layers. I build only on boring, widely-documented technology, so problems are searchable, not exotic. Everything is documented so any competent professional could step in; you’re never locked to me. And if something is genuinely beyond me, I say so and help you find the right specialist.
“Why would you build it and then hand me the keys?” / “What if I don’t want the keys?”
The keys are insurance, not homework. Most clients leave them in the drawer and keep me on retainer. Ownership just means you’re never hostage to any vendor, including me.
“How does this actually make or save me money?”
Usually hours: drafting, intake, summarizing, finding things. The assessment quantifies it for your firm. And if the number isn’t compelling, the findings brief says “don’t buy this.”
“Can it actually do work for me, not just chat?”
Yes: document drafting, summarizing, intake, knowledge lookup are the proven starting points. Anything that acts (sends, files, changes things) gets added carefully, with human approval gates, after the basics earn trust.
“What would I actually use it for, day to day? Can you build anything my business needs?”
The honest answer: it depends on your firm, and anyone handing you a generic list is selling. Common starting points for document-heavy firms: drafting from your own precedents, summarizing and comparing documents, intake, finding-the-thing-you-wrote, answering questions from your policies and files. The assessment exists precisely because “what would we use it for” has a specific answer for your firm. That capability map is the deliverable you keep. And no, I won’t build you “anything.” I’ll build what’s worth building, and tell you plainly what isn’t.
“Is this one of those vibe-coded apps? How do I know it’s not just AI-generated software?”
Fair question: a lot of flimsy AI-built products are flooding the market. Two honest answers. First: the core of your system isn’t code I generated. It’s boring, battle-tested open-source infrastructure used by thousands of organizations, assembled and hardened for your firm. Second: where I do use AI to help build (and I do, openly), every piece is reviewed, tested, and documented before it touches your system. The difference between vibe-coding and engineering isn’t whether AI helped. It’s whether a human is accountable for every piece, in writing. You get that documentation, and any professional you choose can audit it. The discipline itself is public. I open-sourced the operating method at github.com/mcterrence/agent-operations-kit, so any professional you choose can audit how I work before you ever hire me.
“What’s the bottleneck of your business?”
Me. I’m a solo practice by design, which caps how many clients I take. That’s exactly why everything is productized, documented, and standardized, so quality never depends on my memory, and why early clients get a level of founder attention that disappears at any bigger shop.
“Why isn’t everyone else doing this?”
Because it doesn’t scale the way software people like. Big vendors need products that sell by the million seats; tailored, in-person installation for a ten-person firm doesn’t fit their model. Most local IT shops don’t do AI architecture; most AI consultants don’t do private infrastructure, or want to drive to your office. The overlap is a gap. Gaps don’t stay open forever, but the trust and documentation built with early clients does.
“What happens after launch?”
Either I run it on retainer (most choose this), or you take the keys with full documentation and a training handover. Both paths are priced in the proposal. No surprises later.
“What are the actual risks of working with you?”
A straight answer, since nobody else will give you one. Risk one: I’m a solo practice, mitigated by documentation so complete any competent professional can take over, and by you owning everything. Risk two: I’m early-stage, mitigated by founder pricing, the don’t-pay-if-it-isn’t-worth-it guarantee, and fixed scopes so surprises can’t compound. Risk three: this technology moves fast, mitigated by boring, standard components and an architecture built to swap parts without rebuilding. What you’d miss by passing: mostly time. The hours keep leaking, and the shadow-AI exposure keeps running unmanaged. Either way, the assessment’s findings are yours, including this risk conversation applied to your firm specifically.
“Is my firm too small for this?”
If the assessment says the economics don’t work, that’s what the findings will say, and it costs you $0 if you’re in the first five and don’t find it worth it. Smaller firms often start with a lighter setup than they expect.
Find out what AI can safely do for your firm.
One fixed-price assessment. Written findings. An honest answer, even if the answer is “don’t buy this.”
· or email hello@cairnward.com. I answer personally.
Prefer to start with a conversation? Book a free 30-minute intro call.
Not a law or accounting firm? If your business runs on confidential documents, the same assessment applies.
Not ready? Watch the demo · under five minutes and come back with questions.