Built to protectyour case data
Caseworth handles sensitive legal information. Here is exactly how we encrypt it, who we share it with, and how our architecture keeps consumer guidance compliant with unauthorized practice of law rules in every state.
- ›No sharing with insurance companies or opposing counsel
- ›PII scrubbing on error monitoring; session replays masked and consent-gated
- ›TLS 1.3 in transit, AES-256 at rest
- ›Non-essential analytics and tracking only run with your consent
- ›Transparent vendor disclosure — full list in the Privacy and Cookie policies
Six commitmentswe engineer intoevery release
These are not aspirations. Each pillar maps to controls in our codebase, our infrastructure, and our vendor contracts.
All API traffic moves over TLS 1.3. Database storage at Supabase is encrypted at rest with AES-256. Passwords are bcrypt hashed with salt.
JWT auth via Supabase, role-based access between consumer and professional, row-level security in the database, MFA required for all production access.
Emails, phone numbers, SSNs, ZIP codes, injury descriptions, plaintiff and defendant names, and settlement amounts are stripped before any error event leaves our backend.
Application-level firewall rules, DDoS protection at the Fly.io edge, and per-route rate limiting prevent abuse and brute force.
Our consumer flow is isolated from professional analysis. A guardrail layer enforces information-only output and refuses jurisdiction-specific legal opinions.
Independent third parties run external penetration tests yearly. We undergo regular SOC 2 Type II audits to validate the controls above.
How we keepconsumer guidanceon the right side
Caseworth provides legal information to consumers and analytical tools to licensed attorneys. The two product surfaces run on separate prompts, separate models, and separate guardrails. Federal courts are increasingly recognizing AI-assisted legal preparation as legitimate and protected, and our architecture is built to meet that bar in every state.
Read the Full UPL Framework- ›No jurisdiction-specific legal opinions to consumers
- ›No predicting case outcomes as advice
- ›Consumer reports labeled as information, not representation
- ›Clear hand-off path to a licensed attorney
- ›Audited refusal patterns for prohibited prompts
A transparentlist of whotouches your data
Every party below has a defined purpose, a documented data scope, and a published privacy policy. For the complete categorized list including analytics and tracking services, see our Privacy Policy (Section 4A) and Cookie Policy (Section 3).
Auth and database. Stores email, user ID, hashed passwords, and case analysis results. SOC 2 Type II, ISO 27001.
Backend API hosting. Receives request metadata only. Logs retained for seven days. SOC 2 Type II.
Consumer plan billing. PCI DSS Level 1. Caseworth never stores full credit card numbers.
LLM gateway for GPT-4, Claude, and others. Does not train on user data. Case facts processed in real time, not stored for training.
Error monitoring with PII scrubbing enabled. Receives stack traces, endpoint names, and timing only — never emails, case facts, or medical records. Sentry Session Replay (masked) is consent-gated and only runs with user consent.
Transactional email for password resets and receipts. Thirty day retention.
Bot and abuse prevention on public-facing forms. No advertising or behavioral data use.
In-app customer support chat. Receives support conversation data and user ID.
Website and product analytics, plus session replay for UX analysis. All three are consent-gated — they do not run until you accept via the cookie banner.
Measures whether users who arrived via a Google ad completed a signup. Consent-gated via Google Consent Mode v2.
No retargeting.No data sales.No exceptions.
- ›No retargeting or behavioral ad networks beyond Google Ads conversion measurement (consent-gated, no data sold)
- ›No cross-site tracking cookies
- ›No sale of user data to any third party
- ›No sharing of case details with insurance companies or opposing counsel
- ›No retention of case data beyond necessary processing
Special handling formedical andinjury information
Consumer tools such as Lexstimate let individuals submit medical records, injury descriptions, and diagnostic or procedure codes to receive an informational case-value estimate. Because this is sensitive health information, we apply heightened safeguards on top of the pillars above.
Medical and injury detail moves over TLS 1.3 and is stored encrypted with AES-256, the same standard applied to all case data.
Access to records containing health detail is restricted by role and row-level security. Consumer health data is never shared with insurance companies or opposing counsel.
We collect health information only as needed to generate your estimate and retain it only for as long as necessary to provide the Service.
Error monitoring (Sentry) scrubs injury descriptions and medical detail before events leave our backend, and masks all text and media in any diagnostic replay. Session-replay analytics is disabled entirely on every consumer flow where medical or injury detail may be entered — Lexstimate, analysis, intake, and chat — and records only on non-sensitive routes, only after you consent.
For full detail on how we handle personal and health information, and the rights available to residents of certain states, see our Privacy Policy and our Washington Consumer Health Data Privacy Policy.
Found something?Tell us directly.
For security inquiries, vulnerability disclosure, or to request a copy of our latest security report under NDA, email security@caseworth.io. We respond to verified reports within one business day.
General ContactReady to knowwhat cases like yourshave actually been worth?
Start free. No credit card needed. Get your Lexstimate report instantly. Understand your deadline and see the observed outcome range for comparable cases.