Skip to content

Legal AI Security: Built So Client Files Stay Client Files

Legal AI security means encryption in transit and at rest, strict per-firm data isolation, and a hard guarantee that client data never trains AI models. This page documents how Caseagent is being built to that bar, stated as design commitments, because we are pre-launch and will not claim certifications we do not hold. If you are still comparing platforms, these are the controls to demand of any legal practice management software that touches privileged files.

Talk to sales
Encrypted in transit & at rest Never trained on client data Pre-launch: commitments, not certificates
Exhibit A Data handling

How client data is protected

Case files are privileged material. Caseagent is built so protection is the default, not a tier upgrade, on every plan from Solo up.

A-1

Encrypted in transit

All traffic between your browser and Caseagent is encrypted with TLS. There is no unencrypted path into or out of the system.

A-2

Encrypted at rest

Documents, chronologies, drafts, and deadline data are stored encrypted at rest, including backups.

A-3

Isolated per firm

Each firm's matters live in their own isolated space. Caseagent is built so one firm's data can never leak into another firm's context, results, or drafts.

A-4

Least-privilege access

Our staff do not browse client files. Operational access is limited, logged, and reserved for support you request or incidents that require it.

Exhibit B The AI stance

Your files are never training data

The question every firm asks first, answered without hedging. This is the same stance stated on our confidentiality FAQ.

B-1
Client data never trains models. Files, drafts, and matter data are never used to train AI models, ours or any provider's. The agent reads your file to work your matter, and nothing else.
NO TRAINING
B-2
Demo text is never stored. Case summaries pasted into the public demo are processed for your session and discarded. No demo input is written to a database.
NOT STORED
B-3
AI output is labeled and gated. Every draft is marked for attorney review, and every citation is flagged for verification. See the review gate in how the AI legal assistant works.
FLAGGED
B-4
Export any time. Your firm's work product is exportable in standard formats. No lock-in is a design commitment: if you leave, your files leave with you.
YOUR DATA
Exhibit C For legal ops & IT

Controls planned for the Enterprise tier

Everything a procurement or legal ops review will ask for is planned into the Enterprise tier from day one. Statuses below are honest: these ship with Enterprise onboarding, and we will not sell them as live before they are.

Control What it covers Status
SSO / SAML Sign-in through your identity provider (Okta, Entra ID, Google Workspace); no separate passwords to manage. Planned for Enterprise at launch
Role-based permissions Attorney, paralegal, staff, and admin roles; matter-level access control for walled-off engagements. Planned for Enterprise at launch
Audit logs Who viewed, edited, exported, or approved what, and when: an exportable record for your own compliance reviews. Planned for Enterprise at launch
SLA Contractual uptime and support-response commitments with defined remedies. Planned for Enterprise agreements
DPA A data processing agreement covering processing scope, subprocessors, and the no-training commitment in contract form. Planned for Enterprise agreements
Security review We complete your firm's vendor security questionnaire and walk your IT team through the architecture, including how legal document management permissions and retention are handled. Available now, by email

Evaluating Caseagent for a 50+ lawyer firm? Talk to sales and we'll schedule a security walkthrough. Tier details are on the pricing page.

Exhibit D Honesty clause

What we claim, and what we don't

Security pages are where startups exaggerate. Ours works the other way: if it is not true yet, it is listed as a commitment or a roadmap item, never as a badge.

We do not claim certifications we do not hold. Caseagent is not yet SOC 2 audited and makes no compliance certification claims today. SOC 2 readiness is on the roadmap, and the controls on this page are being built with that audit in mind.

Design commitments are still commitments. Everything phrased as "Caseagent is built so that" on this page is an engineering constraint we hold ourselves to now, in early access, and will stand behind contractually in the Enterprise DPA.

The disclaimer applies here too. Caseagent is a tool for lawyers, not legal advice. Security controls protect your data; a licensed attorney still reviews every output before it matters.

Exhibit E Responsible disclosure

Found a vulnerability? Tell us.

We take reports from security researchers seriously and respond to every good-faith submission.

E-1
Email team@caseagent.com with the subject "Security vulnerability report" and enough detail to reproduce the issue.
REPORT
E-2
We acknowledge reports promptly, keep you informed while we investigate, and credit researchers who report in good faith if they want credit.
RESPONSE
E-3
Do not access data that is not yours, degrade the service, or publicly disclose before we have had a reasonable window to fix. We will not pursue good-faith research conducted within those lines.
GOOD FAITH
SECURITY FILE · OPEN

Bring your security questionnaire. We'll answer it.

Join the early-access list, or write to us directly for an Enterprise security walkthrough. Either way, you'll get straight answers from the team building the controls.

Talk to sales