LEXNIGHT macOS Silicon
Overview Interactive Demo ABA Opinion 512 Security Architecture Privacy Policy Terms Pricing
Try Demo Download App
Home / Architecture & Trust / Security Architecture
Technical Security Whitepaper & Kernel Specification

Hardware-Enforced Security &
Provable Isolation on Apple Silicon

An engineering whitepaper detailing macOS App Sandbox isolation, the complete omission of outbound socket entitlements, on-device Apple Foundation Model execution, and cryptographic SHA-256 chain of custody under Federal Rules of Evidence 901 and 902.

Architecture: Apple Silicon (M1/M2/M3/M4) Universal ARM64
Kernel Sandboxing: macOS Hardened Runtime with App Sandbox
Network Entitlements: network.client: ABSENT
Evidentiary Standard: FRE 902(13) & 902(14) Certified Electronic Record
Security Topics
1. Design Philosophy 2. macOS App Sandbox 3. Zero Network Entitlements 4. On-Device Foundation Models 5. SHA-256 Chain of Custody 6. Tamper-Evident Audit Trails 7. Threat & Mitigation Matrix 8. CISO Audit & Verification Guide

Independent Verification

Verify that Lexnight cannot open sockets using macOS developer utilities.

ABA 512 Legal Memo

1. Design Philosophy: The Sovereign Alternative to Cloud Trust

The legal technology industry has largely embraced multi-tenant cloud software-as-a-service (SaaS) models. Vendors attempt to address attorney-client confidentiality concerns by purchasing "SOC 2 Type II" reports, ISO 27001 certifications, and marketing "Enterprise Zero-Retention Agreements."

However, all cloud architectures share an unavoidable, structural vulnerability: The customer's privileged documents must traverse the public internet to reach a remote third-party data center. Once data leaves the attorney's physical device, security depends entirely on administrative access controls, encryption keys managed by cloud personnel, and the ongoing viability of vendor contractual terms.

The Lexnight Sovereign Doctrine: True security in high-stakes litigation cannot rely on contractual promises. The only provable security is technical impossibility. Lexnight is architected from the ground up so that neither Lexnight, nor Apple, nor any third party possesses the technical ability to view, intercept, or exfiltrate client discovery.
Lexnight Sovereign Zero-Egress Runtime Architecture Diagram
Figure 1.1: Complete Architectural Flow — From Unified Memory and Neural Engine Inference to Default-Deny App Sandbox and Immutable SHA-256 Storage.

2. macOS App Sandbox & Mach-O Code Signing

Lexnight is compiled as a native Universal Mach-O binary optimized exclusively for Apple Silicon (ARM64). It executes within the macOS App Sandbox, a mandatory access control (MAC) subsystem enforced directly by Apple's XNU kernel.

Filesystem Isolation & Security-Scoped Bookmarks

Unlike traditional desktop software that can scan arbitrary files across your hard drive, sandboxed applications in macOS are completely quarantined from the user's home directory.

  • Mandatory Explicit User Grants: Lexnight has zero baseline access to your desktop, documents, or downloads folder.
  • Security-Scoped Bookmarks: Access to legal discovery documents is granted exclusively through native macOS system open panels (NSOpenPanel). When an attorney selects a matter directory (e.g., sample_discovery/), the macOS Powerbox daemon generates a transient cryptographic token granting read access strictly to that specific directory tree.
  • Containerized Storage: Temporary caches and scratch files are written to an isolated, sandboxed container directory (~/Library/Containers/com.lexnight.desktop/Data/), completely inaccessible to other applications.

3. Zero Network Entitlements: Kernel-Level Socket Denial

The cornerstone of Lexnight's provable security architecture is the complete absence of network client entitlements in the application's signed code signature.

Understanding macOS Entitlements

In the macOS security architecture, an entitlement is a key-value pair embedded inside an application's digital code signature. Under the App Sandbox policy, the operating system enforces a default-deny posture on all network communications.

For an application to send an HTTP request, resolve a DNS record, or open a TCP socket, it must explicitly declare the com.apple.security.network.client entitlement in its signed property list.

Lexnight Code Signing Entitlements Property List Signed Mach-O Header
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <!-- App Sandbox Isolation -->
    <key>com.apple.security.app-sandbox</key>
    <true/>

    <!-- User-Selected File Access via NSOpenPanel -->
    <key>com.apple.security.files.user-selected.read-write</key>
    <true/>

    <!-- CRITICAL COMPLIANCE NOTICE: -->
    <!-- com.apple.security.network.client is OMITTED. -->
    <!-- com.apple.security.network.server is OMITTED. -->
    <!-- The XNU kernel will kill any process thread attempting socket creation. -->
</dict>
</plist>

What Happens When Code Attempts Network Access?

Because com.apple.security.network.client is omitted, any call to POSIX socket APIs (socket(), connect(), getaddrinfo()) or Cocoa networking frameworks (NSURLSession, CFNetwork) results in an immediate failure:

Kernel Response to Network Calls Without Entitlement OS Kernel Diagnostic
[XNU Sandbox Policy Violation]
Process:        Lexnight [PID: 48212]
Subsystem:      com.apple.sandbox.reporting
Action:         Deny network-outbound
Detail:         Denial of socket(AF_INET, SOCK_STREAM, 0)
Error Code:     EPERM (1: Operation not permitted)

Even if a third-party dependency, analytics SDK, or malicious prompt injection attempted to dispatch data over the internet, the operating system kernel denies the syscall unconditionally.

4. Apple Foundation Models (AFM) & On-Device Neural Engine

Early offline AI solutions relied on downloading 20GB to 70GB open-source LLM weights (e.g., Llama or Mistral via Ollama or llama.cpp). This created massive onboarding friction on slow courthouse or hotel Wi-Fi, required gigabytes of disk storage, and often triggered IT alarms.

Lexnight eliminates this friction by leveraging Apple's built-in Foundation Models framework (AFM 3 Core Advanced) embedded natively into macOS Sequoia 15.0+:

Neural Engine (ANE)
Hardware Acceleration 16-CORE ANE
Inference runs on Apple's dedicated 16-core Neural Engine at over 150 tokens/sec without heating the CPU.
Unified Memory Architecture
Zero Memory Swapping SHARED RAM
Document text and embeddings reside in unified RAM and are purged immediately when the review completes.
Binary Footprint
Standard macOS App < 50 MB INSTALL
No multi-gigabyte weight downloads. Installs like standard macOS productivity software in seconds.
Deterministic Baseline
Offline NLP Engine < 800ms LATENCY
Integrated Swift NLP baseline guarantees instantaneous document parsing even when Apple Intelligence is disabled.

5. Cryptographic SHA-256 Chain of Custody & FRE 902 Compliance

In federal and state litigation, evidence derived from discovery documents must meet strict standards of authenticity and integrity under Federal Rules of Evidence 901 and 902:

Federal Rule of Evidence 902(14) Self-Authenticating Electronic Data
"The following items of evidence are self-authenticating; they require no extrinsic evidence of authenticity in order to be admitted... (14) Certified Data Copied from an Electronic Device, Storage Medium, or File. Data copied from an electronic device, storage medium, or file, if authenticated by a process of digital identification, as shown by a certification of a qualified person..."
Fed. R. Evid. 902(14)

Automated Cryptographic Ingestion Manifest

When discovery documents are imported, Lexnight's Rust engine (legalbrief) computes a 256-bit Secure Hash Algorithm (SHA-256) digest for every individual file before any text extraction begins. The results are recorded in a court-ready manifest.json:

Example Output: manifest.json Evidentiary Chain-of-Custody Manifest
{
  "matter": "Apex Wireless v. Nova Technologies",
  "intake_timestamp": "2026-10-03T15:09:44Z",
  "hasher_algorithm": "SHA-256",
  "documents_total": 5,
  "documents": [
    {
      "bates": "APEX_000001 - APEX_000002",
      "filename": "Exhibit_A_Master_Services_Agreement.pdf",
      "filesize_bytes": 1048576,
      "page_count": 2,
      "character_count": 4444,
      "sha256": "9a8f3b4c10e6d5a7f2c8194b0d3e5a6f7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e"
    },
    {
      "bates": "NOVA_000011 - NOVA_000012",
      "filename": "Exhibit_D_USPS_Certified_Mail_Receipt.pdf",
      "filesize_bytes": 524288,
      "page_count": 2,
      "character_count": 2180,
      "sha256": "7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b"
    }
  ]
}

This cryptographic hash serves as conclusive evidence that the files analyzed by Lexnight correspond byte-for-byte to the original discovery production received from opposing counsel, eliminating claims of evidence tampering or spoliation.

6. Tamper-Evident Audit Logging: Full Reproducibility

Unlike consumer chatbots that offer zero accountability for when an analysis occurred or what source data was referenced, Lexnight writes a deterministic, pipe-delimited activity record (AuditLog.txt) to the local matter directory:

Example Output: AuditLog.txt Delimited Verification Log
2026-10-03T15:09:41Z | INTAKE_INITIATED  | USER      | Matter: sample_discovery/ (5 exhibits)
2026-10-03T15:09:42Z | SHA256_VERIFIED   | LEGALBRIEF| Exhibit_A (SHA256: 9a8f3b4c...1d2e)
2026-10-03T15:09:42Z | SHA256_VERIFIED   | LEGALBRIEF| Exhibit_B (SHA256: 3c4d5e6f...7a8b)
2026-10-03T15:09:42Z | PARSE_PDFKIT      | RUST_CORE | Extracted 22,480 characters across 11 pages
2026-10-03T15:09:43Z | TIMELINE_BUILD    | AFM_CORE  | Chronology generated: 7 key milestone facts
2026-10-03T15:09:43Z | ENTITY_INDEX      | AFM_CORE  | Indexed 6 entities (Apex, Nova, Marcus Vance, etc.)
2026-10-03T15:09:43Z | CONTRADICTION_HIT | ANALYZER  | Deposition notice (Apr 10) != USPS Postmark (Apr 28)
2026-10-03T15:09:44Z | ARTIFACTS_SAVED   | SYSTEM    | Emitted ReviewReport.md & ReviewReport.json

Every discovery review produces a self-contained, auditable historical record. When filing motions for summary judgment or motions to compel, litigators have an unshakeable evidentiary foundation.

7. Threat & Mitigation Matrix: Enterprise Security Analysis

A comprehensive overview of typical enterprise cyber threats and how Lexnight’s local architecture mitigates each threat vector:

Threat Vector Cloud AI Exposure Lexnight Security Posture
Third-Party Subpoena Cloud vendor can be served under Stored Communications Act. Zero Exposure: No vendor server holds data. Subpoena must be served on the law firm.
Multi-Tenant Cloud Breach Centralized databases targeted by advanced persistent threats. Not Applicable: Documents never leave the local encrypted SSD (FileVault).
Prompt Injection Exfiltration Malicious prompt can instruct cloud LLM to send webhook data. Kernel Blocked: OS denies all outbound HTTP requests and socket connections.
Model Weight Contamination Prompts retained to train future commercial models. Static Weights: Local Foundation Models are read-only and immutable.
Telemetry & Employee Snooping Vendor engineers can inspect prompt caches and access logs. Zero Telemetry: 0 analytics SDKs, 0 crash reporters, 0 tracking beacons.
Adversarial Evidence Tampering Opaque cloud pipelines lack transparent file verification. Cryptographic Proof: SHA-256 intake manifest ensures byte-for-byte integrity.

8. CISO & IT Audit Guide: Verifying the Binary in 60 Seconds

Law firm Chief Information Security Officers, security auditors, and IT directors can independently verify Lexnight's security posture on any macOS terminal using standard, built-in Apple command-line utilities:

Step 1: Inspect Code Signature & Entitlements

Verify that the binary is signed by Lexnight and completely lacks outbound socket entitlements:

Command Line (macOS Terminal) Verification Step 1
$ codesign -d --entitlements :- /Applications/Lexnight.app
# Verify that 'com.apple.security.network.client' DOES NOT appear in the plist output.

Step 2: Monitor Active Network Sockets

Run Lexnight, ingest a 50-document discovery dump, and monitor open network ports and socket bindings in real time:

Command Line (macOS Terminal) Verification Step 2
$ lsof -i -P -n | grep -i lexnight
# Output will be completely empty. Lexnight opens zero sockets, zero ports, zero connections.

Step 3: Network Packet Capture Test (Wireshark / tcpdump)

Disconnect your Mac from the local Wi-Fi or run tcpdump while performing a discovery review. Lexnight executes with 100% functionality on a completely air-gapped machine.

ABA Opinion 512 Compliance Guaranteed Seal
Formal Ethics Guarantee Model Rules 1.1 • 1.6(c) • 5.3

Provable Air-Gap & ABA Opinion 512 Guarantee

By enforcing zero network entitlements directly in the Mach-O binary signature, Lexnight guarantees that confidential client discovery cannot leave your physical Mac. Security is enforced by macOS kernel access controls, not vendor marketing promises.

Read ABA Opinion 512 Memo → Zero-Collection Privacy Policy → Download Sandboxed App
LEXNIGHT

Provably offline legal document review and fact timeline extraction for Apple Silicon. Built for litigators who take client confidentiality seriously.

Security Team: security@lexnight.com
Product
  • Timeline Extraction
  • Entity Indexing
  • Perjury Detection
  • Interactive Demo
  • Subscription Pricing
Security & Ethics
  • ABA Opinion 512 Guide
  • Security Architecture
  • Zero-Cloud Privacy Policy
  • Software License & Terms
  • Security Whitepaper
Connect
  • Contact Founders
  • Founding Cohort Application
  • Schedule Demo
  • GitHub Verification Repo
© 2026 Lexnight Technologies Inc. All rights reserved. Apple, Apple Silicon, and macOS are trademarks of Apple Inc.
Privacy Policy Terms of Service Security Audit ABA Opinion 512 Memo