ProteusX Legal AI · Security
Security and data handling, stated plainly.
What the workspace keeps, what the model provider keeps, and what each firm’s setup has to meet. Where something depends on agreements or settings, we say so.
The sample matter holds no client data
New accounts start with a synthetic sample matter made from fictional documents. You choose from its set questions. There is no box for your own questions and no document upload until your firm’s setup is complete. Even so, don’t enter client or other confidential information anywhere during the trial.
The sample is not set up for protected health information or zero data retention. Those conditions apply only to a firm environment that has been set up and reviewed for them.
Firm setup is reviewed, never automatic
Signing up never switches on a firm environment. When you request setup, ProteusX reviews it with your firm, and client documents are accepted only after every item below has been checked:
- agreements between your firm and ProteusX, including a data processing agreement and, where health information is involved, a business associate agreement;
- how your team signs in;
- a review of any systems you asked to connect;
- zero-data-retention model settings for your firm’s project;
- a retention policy;
- tested backup and restore, and a tested rollback;
- approved costs.
What the workspace stores
The workspace is useful because it keeps things: the documents and guidance a firm adds to its library, and the conversations its people keep. These are stored in the firm’s own environment. Sample answers are kept so you can come back to them.
Your account’s setup record keeps only setup details: your firm’s display name, practice area, the workflows you’re interested in, your preferred sign-in, the names of systems you’d like connected, your retention preference, which terms you accepted, and where you are in setup. It is not designed to hold case or document content, questions, answers, or passwords for other systems.
The retention preference you choose is recorded as a request. How long firm data is kept, and how deletion and backups work, is agreed with each firm before setup is complete. We don’t publish a general retention period here.
Zero data retention is about the model provider
Zero data retention (ZDR) describes whether the AI model provider keeps prompts and responses. It is separate from what the workspace itself stores. On Google Cloud it depends on how the account, project, model and features are configured, and Google’s zero data retention documentation lists the conditions. For a setup that requires ZDR, that means:
- an approved exception from prompt logging for abuse monitoring, where the account is in scope for it;
- request-response logging left disabled;
- no Grounding with Google Search or Google Maps, which Google says retain data;
- stored conversation state turned off wherever an API would otherwise keep it;
- no model features that Google says may prevent ZDR.
These settings are checked for each firm’s exact project and model. An agreement or setting that applied to one project isn’t treated as proof for another.
HIPAA-supporting setups
Google states that there is no HHS-recognized certification for HIPAA compliance and that compliance is a shared responsibility (Google Cloud HIPAA overview). ProteusX Legal AI is not “HIPAA certified”, and we don’t claim SOC 2 or other certifications on this page.
Before protected health information is in scope for a firm:
- the firm and ProteusX have the required agreements in place, including a business associate agreement;
- the Google Cloud services involved are covered by Google’s business associate agreement, and pre-GA offerings are not used with health information;
- the firm’s environment has been configured and reviewed for that use.
Separate environments and named access
Each firm that completes setup gets its own Google Cloud project, database, storage and service accounts, rather than sharing a database with other firms.
Accounts use Google Cloud Identity Platform, and sign-in requires a verified email address. Firm access is checked on the server, not in the browser. A person needs both an approved email domain and to be named on the firm’s member list with a role. A matching domain alone never gives anyone access.
Model processing, encryption and logging
The workspace is built to answer with Google Gemini models on Google Cloud, through a regional Vertex AI endpoint set for each firm’s project. Search and Maps grounding tools are not used. The model for each firm is confirmed during setup. The live fictional sample uses Gemini 2.5 Flash through regional Vertex AI. It is not admitted for client data, protected health information or provider zero data retention.
Setup requires HTTPS for workspace traffic and Google Cloud storage with encryption at rest.
Application logs are designed to keep request metadata, such as the model, status and response time, and to leave out prompt and answer text. Product analytics are limited to non-content steps: starting sign-up, verifying an account, finishing onboarding, opening the sample, and requesting setup.
Checking answers
AI can miss or misread things. Open the source, read it in context, and use your own judgment before relying on an answer. ProteusX Legal AI is not a law firm and does not give legal advice.
Try it on the sample matter
The sample uses fictional documents, so you can see how cited answers work before any client material is involved.