See every path that could reach privileged client data

Trident maps the assets, identities, and data stores that hold privileged matter data, then correlates exposure and pentest findings into the paths that could reach a client file.

Privileged matter graph
Client portalPublic surface
Workload identityInherited access
Matter 8F21Privileged documents
Discovery archiveRestricted data
Verified pathOne control closes the route

Capabilities

One graph from exposure to client data

Map where privileged data lives and every path that could reach it. Each route is ranked by real risk and tied to a fix.

Paths to client matter data

Correlate public exposure, identity edges, and findings into ranked paths that reach a store of privileged client data.

Know where matter data lives

Inventory every data store and the identities that can reach it, then explore blast radius outward from any asset.

Matter & tenant isolation

Pentests exercise broken access control and tenant isolation, so one client’s documents can’t bleed into another’s.

Evidence for SOC 2

Track SOC 2 posture against the same graph, with each control gap tied to the path it actually opens.

Ranked by reach to client files

Findings are prioritized by proximity to privileged data, so the shortest list reflects the highest real risk.

Fixes for the owning team

Each path ships its choke-point fix as a draft PR or copy-paste runbook. Every change is human-reviewed.

How it works

From read-only role to a closed path

01

Connect read-only

Attach read-only roles. Trident inventories assets, identities, and the stores that hold client data.

02

Locate the matters

Data stores and the identities reaching them resolve into one queryable graph.

03

Correlate the paths

Exposure, identity, and pentest findings collapse into ranked paths to privileged data.

04

Close the chain

Each path ships its single choke-point fix to the team that owns it.

Outcomes

Protect the matter, prove the control

Stop chasing standalone alerts. Focus on the paths that actually reach privileged client data.

Matter-aware

Data-path context

Tenant-focused

Isolation testing

Evidence-led

Finding review

Retested

After remediation

Scope

Where confidentiality boundaries fail

One raw query bypassing the tenant scope applied everywhere else is the canonical defect in this sector.

What legaltech testing prioritizes

Legal software holds material that is privileged, and a confidentiality failure between two clients is not merely a security incident — it can be a conflict of interest and an ethical exposure for the firm using the product. Trident concentrates on tenant isolation and document-level authorization: whether any request path lets one matter, firm, or client reach another’s material.

Tenant isolation
Whether firm and client boundaries hold across every route, including reporting, export, and administrative paths that were built after the main authorization model and often bypass it.
Document-level authorization
Access to individual documents, matters, and case files by direct identifier, including documents shared, unshared, or moved between matters where the revocation may never have propagated.
Ethical wall enforcement
Whether conflict-of-interest screens implemented in the product actually prevent retrieval, or merely hide material from the interface while leaving it reachable through the API.
Search and indexing leakage
Whether search results, autocomplete, previews, or notifications disclose the existence or content of material the requesting user cannot open — a leak that is invisible in access logs.
Retention and deletion
Whether deleted material is genuinely unreachable across primary stores, backups, exports, and search indexes, given the retention obligations legal work carries.

Frequently asked

Questions teams ask before they start

How do you test tenant isolation properly?

With at least two accounts in genuinely separate tenants, exercising every route with identifiers belonging to the other. Single-tenant testing cannot detect cross-tenant flaws at all, which is why they survive so many engagements and are so often found later by a customer.

Do you access real client documents?

No. Testing uses synthetic matters and documents in test tenants. Proving that a cross-tenant path exists requires two test tenants, not privileged material, and introducing real client data would create risk without improving the finding.

What about the ethical walls our customers configure?

Those are tested as an authorization control like any other: the question is whether the screen prevents retrieval through every path, or only removes material from the interface. Screens enforced at the presentation layer but not in the API are a recurring finding.

Can this support our customers’ security questionnaires?

Yes. Scope, methodology, findings, remediation, and retest evidence covers most of what enterprise legal buyers ask for. Some require an independent assessor’s report as well, which is a separate engagement from testing.

Know what can reach a client file.

Connect a read-only role and see the ranked paths to your privileged data through a read-only connection, with evidence for each path.