Board Case Study · PE-Backed SaaS
Forty percent of their customers are law firms with privileged data. Buy, build, or deploy private? And once data residency is solved, a harder question remains: who governs an agent acting autonomously inside a client's legal workflow?
The situation
DataFlow Solutions is a PE-backed SaaS platform, 850 employees, $95M ARR growing 25%, selling workflow automation to law, consulting, and accounting firms. Seventy-eight percent of customers are demanding AI features, and a competitor has just leaked client data to a third-party model, putting the risk on everyone's radar.
Forty percent of DataFlow's customers are law firms handling privileged data, and two major firm clients cannot use any feature that sends data to an external provider. The board faces three paths: a fast third-party API where data leaves the premises; a private small language model on its own infrastructure at $400–600K; or a full on-premises build at $2M with a six-month delay. The EU AI Act now classifies legal AI tools as high-risk.
The PE investment committee meets in six weeks expecting a clear AI strategy, and a delayed rollout could cut the 2026 exit valuation by 15–20%. But even once data residency is solved, a newer gap opens: DataFlow has no framework for governing agentic AI that takes autonomous actions inside privileged client workflows.
“Should we use third-party AI, deploy a private model on our own infrastructure, or build full on-premises capability? And whichever path we choose, do we have the guardrails for AI that acts autonomously inside client workflows?”
Marie Rodriguez · CEO
The decision on the table
The full case, scenario architecture, board materials, and facilitation notes, is shared with boards and partners on request.