All resources

Documentation

Data handling and enterprise security controls

Read · 3 min

This guide covers the operational details: when tokenization happens in a run, how downloads are issued and logged, what deleting a matter actually removes, and the extra security controls Enterprise adds on top.

Tokenization is the first pipeline stage, before anything else touches your files. Petria extracts working text from each exhibit (PDF text layer, tables, Word, and optical character recognition for scans and images), then tokenizes both the document text and the structured intake data on the matter. The token map is stored under that job's prefix, and every downstream stage works from tokens. De-tokenization runs at the end, immediately before delivery, so real names appear in your deliverables and not in the stages between. Your original uploads stay in the matter untouched throughout.

Downloads are issued as time-limited links rather than permanent URLs. Each link expires after a set window, one hour by default, so a link pasted into an email will stop working. Every issuance is recorded with the file, the deliverable type, and the expiry, and the download count on the deliverable is incremented. Requests are checked against your firm's storage prefix, so a link cannot reach another firm's files.

Deleting a matter is irreversible and is not the same as archiving. Archiving takes a matter off your active list but keeps its files. Delete removes every stored object under the matter, removes its job records, and clears the evidence manifest, leaving the matter marked deleted. Trying to delete an already-deleted matter returns an error rather than running twice. One deliberate exception: the audit trail survives a delete. Audit rows are kept, with the matter and job identifiers stripped from them, so you retain a record that actions occurred without retaining the client linkage. If your ethics or retention policy requires proof of destruction, that trail is where it lives. Practical sequence for closing a file: download and store your deliverables in your own document system first, archive the matter while the client relationship is active, then delete when your retention period ends. Once deleted, the deliverables cannot be re-downloaded.

Enterprise adds three more controls, each managed by a firm admin. Single sign-on is configured by supplying your identity provider's metadata in firm settings; once enabled, your team signs in through your provider rather than maintaining separate credentials here, which is usually what an IT or security review is asking for. Audit logs record the actions that matter across your firm, including sign-in and sign-out, matter creation and deletion, job submission, cancellation, and deletion, criteria confirmation and section regeneration, evidence uploads and deletions, download link issuance, structure approval, branding uploads, team invites and removals, settings changes, and client portal activity. The log view filters by action, by actor, and by date range, and pages through results; you can export what you are looking at as CSV or XLSX for a compliance request, or export straight into your configured storage once that storage is set up.

Storage settings let an Enterprise firm keep matter files in its own S3 bucket rather than in Petria's managed storage. You supply a role ARN for Petria to assume, the bucket, a prefix, and optionally a KMS key ARN so objects are encrypted under a key you control. A validate action checks the configuration before you commit to it, and the panel shows whether storage is currently managed, connected, failed, or not yet configured. Validate before you switch: a failed connection means jobs cannot read or write matter files, and the status indicator is the fastest way to see that the problem is configuration rather than the pipeline.

Two notes on what the audit log is and is not. It records that an action happened, by whom, and against what, which is what a client audit or an ethics review typically wants. It is not a copy of the documents, and it is not a substitute for your own document management system. Enterprise firms also run on an isolated job queue, so your work is not waiting behind other firms.