Confidentiality, enforced by architecture.
Pretext holds privileged material for a living. Every control below is enforced in the database engine or the cloud platform, where a bug in application code cannot undo it, and every claim on this page maps to a specific mechanism we can show a firm's IT lead or outside counsel on request.
Your firm's data is walled off at every layer.
Isolation is not one check in one place. It is the same rule enforced independently at each layer a request passes through, so that no single mistake can expose another firm's file.
| Layer | How isolation is enforced |
|---|---|
| Identity | Each firm has its own identity tenant on Google Cloud Identity Platform. A user cannot authenticate into a firm they do not belong to. Passwords must be twelve characters across four character classes, and time-based one-time-code MFA is available to every firm and can be made mandatory for a firm. |
| Sessions | Sessions expire server-side after 24 hours of inactivity. An expired session cannot ping itself back to life. Only a fresh sign-in revives it. |
| API | Every request carries a Google-signed token. The firm is resolved on the server from that token. No client-supplied firm identifier is ever trusted. |
| Database | Row-level security on every firm-private table filters by the firm bound to the session, enforced inside PostgreSQL. The application role cannot bypass it. A query that forgets its filter still returns nothing from another firm. |
| Files | Evidence is stored in firm-namespaced paths and moves only through 15-minute signed links minted after the API has confirmed the firm. Public access to the bucket is prevented at the platform level. |
| AI requests | A request to the model carries one firm's material only. Cross-firm context is structurally absent from every prompt. |
| Logs | Logs carry identifiers, never case content. Request and response bodies are not logged on case endpoints. |
| Assistant | No conversation is stored anywhere. There are no chat tables in the database. History lives in the attorney's browser and dies when they leave the page. |
The AI reads your case, answers, and keeps nothing.
Google Cloud formally granted FiveFold an exception to prompt logging for Pretext production. Retention is not a policy promise. It is switched off at the platform level.
No prompt logging, no caching
The two retention surfaces Google offers for generative AI, abuse-monitoring prompt logs and data caching, are both closed for Pretext production. The exception attaches to our production project and covers every model call the product makes: extraction, attorney-facing analysis, transcription, and the assistant.
Never used to train any model
Your case files are never used to train any model, under Google Cloud's enterprise terms. Pretext runs Gemini on Vertex AI inside a dedicated FiveFold project, not through a consumer API.
Encrypted with customer-managed keys
The case database and the evidence bucket are encrypted with keys FiveFold manages in Cloud KMS, not provider defaults. The database has no public address at all. It sits on a private network reachable only by the application.
Hardened edge, keyless operations
All traffic enters through a global load balancer with a web application firewall and rate limiting. The application accepts traffic from nowhere else. No service-account keys exist; an organization policy forbids creating them, and deployments are keyless.
Nothing leaves but structured codes
The only data that ever leaves a firm's private records is structured, de-identified outcome coding from criminal matters, through a single database-enforced doorway. Family and disciplinary matters never leave at all. How the shared layer is built →
Delete means delete
Delete a case and every file, transcript, chronology, and analysis goes with it, removed from the database and swept from storage. Firm data is deletable on request, and shared-layer contributions carry an internal-only attribution precisely so right-to-delete works.
Where your file lives, and how it comes back.
Case data lives at rest in Google Cloud's Northern Virginia region in a dedicated FiveFold project. The recovery posture is stated plainly here, and we would rather describe a restore-based design accurately than promise a failover story we have not built.
Point-in-time recovery
The case database takes an automated backup every day and streams its transaction log continuously, so it can be restored to any moment in the last seven days, not just to last night. Seven daily backups are retained.
Backups stored across regions
Database backups are stored in Google's United States multi-region, independent of the region that serves the application, so a regional outage does not take the backups with it.
Evidence storage with soft delete
Every object in the evidence bucket remains recoverable for seven days after deletion, which protects against an accidental or malicious delete while still honoring a firm's deletion request after the window.
An application tier that scales and restarts
The application runs on Cloud Run across multiple zones, scales with demand, and is rebuilt from source on every deployment. The sign-in surface is served from a global content network. The whole environment is defined in scripts and runbooks and can be rebuilt in another region from backups.
Where we are headed
Most legal technology stops at SOC 2 or ISO 27001. Those are general controls attestations, and they are useful. The FBI CJIS Security Policy is different: it is the standard written specifically for criminal justice information, the material a defense file is made of. Pretext is being built toward that standard, from the encryption and identity controls above to the audit trail, and we intend to have that alignment independently assessed as our firm base grows.
Ask us the hard questions.
Where does our data live?
Google Cloud, Northern Virginia, in a dedicated FiveFold project, encrypted at rest with customer-managed keys.
Who is the AI vendor?
Google, Gemini on Vertex AI, under Google Cloud's enterprise terms. No third-party AI vendor holds the data.
Can another firm ever see our cases?
No. Isolation is enforced in the database engine, the identity layer, the storage paths, and the assembly of every AI request.
What do you retain if we leave?
Firm data is deletable on request. Shared-layer contributions carry an internal-only attribution so they can be removed too.
The evidence behind each claim on this page, including the Google approval for the prompt-logging exception, is available to a firm's IT lead or counsel on request: rob.pulliam@fivefoldintel.com.
Built for privileged materials.
Two weeks free, in your firm's own isolated environment, with every control on this page already in force. No setup, no card, no obligation.