Ciph Lab® — IR™ Continuous Ownership
Stress-Tested on Real Regulatory Filing Workflows Independently Applied · Phase 0 Score: 23/48 Built by a UC Berkeley AI Safety Policy Fellow Delaware Public Benefit Corporation GRACI™ Patent Pending Stress-Tested on Real Regulatory Filing Workflows Independently Applied · Phase 0 Score: 23/48 Built by a UC Berkeley AI Safety Policy Fellow Delaware Public Benefit Corporation GRACI™ Patent Pending
Prototype Built · Continuous Ownership for High-Stakes Enterprise AI

Documents Move.
Ownership Disappears.

Governance software tells you what happened after the fact. GRACI surfaces the gap before the work gets called done.

Enterprise legal teams and their outside counsel already spend $30M+ per company. Only 2% of that spend is software — and 95% of AI deployments never reach production because continuous ownership and verification are missing.

Ciph Lab is building the continuous ownership layer that makes high-stakes AI work production-ready — across legal documents, client matters, and the AI tools now touching both. We start where spend and risk collide hardest: IP.

Or take the free IR™ Readiness Score →
Powered by GRACI™
Built by a UC Berkeley AI Safety Policy Fellow
Delaware PBC
GRACI™ Matrix — Live
G
R
A
C
I
V
⚠ Flagged Verification unassigned — flagged before sign-off.

Named Roles,
Enforced by the System.

Every document — policy or client matter — and every AI tool deployment carries its own ownership requirements. Responsible, Accountable, Consulted, Informed, Governance, and Verification become live conditions. Empty means blocked. Named means cleared.

GGovernance
RResponsible
AAccountable
CConsulted
IInformed
VVerification

This is not another static RACI chart. Ownership lives on the document itself — turning previously ungovernable AI legal work into production-ready, auditable output.

💡

Category Shift: GRC tools log what happened after the fact. GRACI flags missing ownership at the point of work — before it becomes a compliance finding.

Built for Operators.
Not Compliance Dashboards.

Most governance platforms are built for compliance teams to review after the fact. GRACI is built into the point of work itself — for the people actually producing the document or deploying the tool.

Static GRC / RACI
  • Ownership lives in a spreadsheet, separate from the work
  • Drifts the moment it's saved — no one notices until an audit
  • Built for compliance teams reviewing after the fact
  • No distinction between who approved the AI tool and who verified its output
GRACI™ / Ciph Lab
  • Ownership attaches directly to the live document or deployment
  • Gaps surface automatically the moment a role goes missing
  • Built for the operator doing the work, not just the reviewer
  • Governance and Verification are named and distinct, flagged before output is treated as final

Stress-tested, not theoretical: GRACI was built and stress-tested against real-world regulatory filing workflows, then independently applied to a live enterprise AI deployment via our Phase 0 diagnostic — surfacing a quantified governance gap (Phase 0 score: 23/48) that existed on paper but wasn't enforced in practice.

Collaboration Is Where Ownership Disappears.

A policy is updated by one team but never reaches the group still working from the old version. A client file moves from associate to paralegal to partner — and no single record shows who is accountable for what is still outstanding. The same gap now exists when AI tools generate or edit those documents, or when an AI tool is deployed enterprise-wide with no one verifying who's using it and how.

The result is rarely a dramatic failure. It is constant and expensive: version drift, missed sign-offs, and the quiet erosion of ownership across firm policies, client matters, and enterprise AI tools alike.

⚠ Gap Detected — No accountable reviewer assigned since last edit.

Built for the Documents
and Deployments That Carry Real Risk.

Policy Documents
Keep Firm-Wide Policy Current.

Consistently reviewed and traceable, so the version everyone's working from is always the right one — with a clear record of who approved what, and when.

Client Files
Give Every Matter a Chain of Custody.

Know who's responsible for what, at every stage of a matter — without relying on institutional memory or a scattered email trail.

AI Tool Deployments
Name an Owner for Every AI Tool in Use.

From enterprise chatbot rollouts to regulated filings — know who governs which tool, and who verifies its output before it becomes a decision.

Juanita Alvarez
Juanita Alvarez
Founder & CEO, Ciph Lab

"I didn't study this market from the outside — I lived it from the inside."

500+
IP portfolios managedRopes & Gray spinoff, clients incl. Google
$10M+
Outside counsel spend managed10 firms, Amazon Lab126
70%
Contract cycle time cutOkta
🎓 UC Berkeley BASIS AI Safety Fellow 📋 Authored Figma's DSA Transparency Report 🎤 Speaker, AI in Legal Summit 🔐 Privacy & Compliance, Apple
Meet the full team →

The AI Governance
Execution Crisis.

The same structural gap now sits at the center of enterprise legal work — only with higher professional responsibility, privilege risk, and client stakes.

0%
of corporate AI governance functions were handed to existing Legal and Privacy teams — departments staffed by JDs with no operational AI experience.
// IAPP Organizational Governance Report
2 of 3
organizations deploy AI without the operational structures, automated gates, or technical controls to manage the risk — despite having a formal policy on paper.
// CallMiner Enterprise AI Risk Report
0%+
of workers — including 90% of security and dev professionals — use unapproved, unmonitored AI tools at work because the policy lives in a document, not in the code.
// UpGuard Shadow AI Research

GRACI Prototype Built.
Commercial Platform in Development.

We're seeking a small number of design partners — IP groups and enterprise Legal Ops teams — to help shape the commercial platform before it's fully built.

One Protocol.
Structural Opportunity.

Enterprise legal departments already spend ~$30M per company, yet only 2% of that spend is software. At the same time, 95% of AI deployments never reach production because continuous ownership and verification are missing.

Ciph Lab is building the continuous ownership layer that turns this gap into production-ready infrastructure for high-stakes legal and AI-governed work. We start in IP — where outside counsel spend, AI experimentation, and privilege risk collide hardest — then expand into full Enterprise Legal Ops and Corporate Risk.

The same platform becomes the governance standard enterprises require of their outside counsel.