Legal data and connected tools

Security and data controls in Prism4.ai

Working with case materials requires clear access boundaries. This page explains permissions for files and chats, connected accounts, external models, and the controls available to users.

Access to chats, files, and case materials

Access in Prism4.ai is determined by material ownership, account rights, and explicitly granted collaboration permissions. Private-source search stays within available context: the connected account, selected signing key and role, files, and permissions for the relevant materials.

Source references let you verify a conclusion within your access. They do not replace checks of document coverage, scan recognition, or currency of the material. Access by authorized administrative and service roles follows separate platform rules.

Service connections and signing keys

Telegram, WhatsApp, Gmail, Google Drive, and other connections operate through their respective accounts and granted permissions. For Ukrainian E-Court, the selected signing key, available role, and rights to a particular proceeding matter. An agent task does not itself expand the connected account's permissions.

Add keys and credentials through the connection interface in settings. Check the selected key and role before working on a case, and the intended recipient before changing sharing or permissions. To end a connection, use its settings and the external service's permission-revocation controls.

Models and external processing

An AI task can send relevant parts of the request and materials to the selected model provider. Connected services also receive the data needed for the requested operation. Processing depends on the chosen model, connection, and task.

Retention and data-use rules differ between providers and models. Check the model description and provider terms before working with confidential materials. Data obtained through Google APIs is additionally governed by Google's user-data rules and the corresponding section of the privacy policy.

Control over actions, devices, and recording

Computer or Android phone access, background recording, and call automation have their own settings and permissions. Supported workflows allow you to observe actions and take over control. Enabling one connection does not authorize every action across every service.

Before sending a message, signing, or filing a document, verify the content, recipient, attachments, and required confirmation. A saved draft and an executed operation have different states. Check the result in the relevant service as well as the agent's response.

Disconnection, deletion, and retention

Managing connections and deleting an account are separate processes. Use connection settings to disconnect a service; for account deletion, follow the request process described in the policy through the account section or support.

Deletion rules and retention periods depend on the data category and are described in the privacy policy. Records needed for legal or payment obligations have separate rules. Data in an external service also follows that service's policies and controls.

Before working with client materials

  • Verify your authorization to use and transfer the materials in this workflow.
  • Choose the relevant account, key, role, and model, and grant the permissions you need.
  • Use a redacted example for an initial demonstration and verify the result's sources.
  • Check provider policies and your organization's requirements for confidential data.

Policies and further information

Planning a legal-team security review?

Contact support to discuss the sources, models, permissions, and implementation requirements relevant to your organization. Start with a workflow description and a redacted example.