For two weeks in September, a team from Hackmetrix attacked Trifolia with the same techniques a real attacker would use: brute force against the login, attempts to access other users’ documents, code injection in case names, manipulating the AI assistant into ignoring its instructions, poisoning it with fake laws.
This is called pentesting (penetration testing), and it is the most honest way there is to find out whether a system truly protects the information entrusted to it.
When they finished, they had four findings, one of them of high severity. None of them exposed our users’ information: the severity had to do with the cost an attack could generate for Trifolia. We fixed all of them over a weekend, the retest closed them out, and today we have the certification report in hand.
I’m telling this story because many lawyers don’t know these tests exist, and I think they should ask for them from any provider that handles their case files. Trifolia stores queries, documents and litigation strategies from hundreds of law firms. That level of trust rests on external audits, on someone from outside trying to break what we build, and on the discipline to fix what they find.
And there’s a reflection I think matters. I’m glad to see more and more lawyers programming, building their own automations and tools with AI. It’s great news for the profession. But there is a difference between a script that sorts documents on your own computer and a system that receives sensitive client information over the internet. The second brings responsibilities that aren’t visible from the code: encryption, access control, usage limits, monitoring, incident response, and tests like this one. Those tasks fall outside a lawyer’s role, and that’s fine. For systems that handle confidential information, it will always be safer to have them built and maintained by people dedicated to exactly that.
Originally published on LinkedIn on October 7, 2026.