New

Federal courts are recognizing AI-assisted legal preparation as legitimate and protected. Caseworth is built for exactly this moment.

Learn more →
Security & Compliance

Built to protectyour case data

Caseworth handles sensitive legal information. Here is exactly how we encrypt it, who we share it with, and how our architecture keeps consumer guidance compliant with unauthorized practice of law rules in every state.

Key principles
  • No sharing with insurance companies or opposing counsel
  • PII scrubbing on error monitoring; session replays masked and consent-gated
  • TLS 1.3 in transit, AES-256 at rest
  • Non-essential analytics and tracking only run with your consent
  • Transparent vendor disclosure — full list in the Privacy and Cookie policies
The Pillars

Six commitmentswe engineer intoevery release

These are not aspirations. Each pillar maps to controls in our codebase, our infrastructure, and our vendor contracts.

01 / ENCRYPTION
TLS 1.3 and AES-256

All API traffic moves over TLS 1.3. Database storage at Supabase is encrypted at rest with AES-256. Passwords are bcrypt hashed with salt.

02 / ACCESS CONTROL
Least privilege, MFA enforced

JWT auth via Supabase, role-based access between consumer and professional, row-level security in the database, MFA required for all production access.

03 / PII SCRUBBING
Sentry never sees case facts

Emails, phone numbers, SSNs, ZIP codes, injury descriptions, plaintiff and defendant names, and settlement amounts are stripped before any error event leaves our backend.

04 / NETWORK
DDoS, firewall, rate limits

Application-level firewall rules, DDoS protection at the Fly.io edge, and per-route rate limiting prevent abuse and brute force.

05 / UPL ARCHITECTURE
Consumer guidance, not legal advice

Our consumer flow is isolated from professional analysis. A guardrail layer enforces information-only output and refuses jurisdiction-specific legal opinions.

06 / AUDITS
Annual pen tests and SOC 2

Independent third parties run external penetration tests yearly. We undergo regular SOC 2 Type II audits to validate the controls above.

UPL Compliance

How we keepconsumer guidanceon the right side

Caseworth provides legal information to consumers and analytical tools to licensed attorneys. The two product surfaces run on separate prompts, separate models, and separate guardrails. Federal courts are increasingly recognizing AI-assisted legal preparation as legitimate and protected, and our architecture is built to meet that bar in every state.

Read the Full UPL Framework
What is enforced
  • No jurisdiction-specific legal opinions to consumers
  • No predicting case outcomes as advice
  • Consumer reports labeled as information, not representation
  • Clear hand-off path to a licensed attorney
  • Audited refusal patterns for prohibited prompts
Vendors

A transparentlist of whotouches your data

Every party below has a defined purpose, a documented data scope, and a published privacy policy. For the complete categorized list including analytics and tracking services, see our Privacy Policy (Section 4A) and Cookie Policy (Section 3).

INFRA
Supabase

Auth and database. Stores email, user ID, hashed passwords, and case analysis results. SOC 2 Type II, ISO 27001.

INFRA
Fly.io

Backend API hosting. Receives request metadata only. Logs retained for seven days. SOC 2 Type II.

PAYMENTS
Stripe

Consumer plan billing. PCI DSS Level 1. Caseworth never stores full credit card numbers.

AI
OpenRouter

LLM gateway for GPT-4, Claude, and others. Does not train on user data. Case facts processed in real time, not stored for training.

ERRORS
Sentry

Error monitoring with PII scrubbing enabled. Receives stack traces, endpoint names, and timing only — never emails, case facts, or medical records. Sentry Session Replay (masked) is consent-gated and only runs with user consent.

EMAIL
Resend

Transactional email for password resets and receipts. Thirty day retention.

SECURITY
Cloudflare Turnstile

Bot and abuse prevention on public-facing forms. No advertising or behavioral data use.

SUPPORT
Intercom

In-app customer support chat. Receives support conversation data and user ID.

ANALYTICS
GA4 / PostHog / FullStory

Website and product analytics, plus session replay for UX analysis. All three are consent-gated — they do not run until you accept via the cookie banner.

ADS
Google Ads conversion

Measures whether users who arrived via a Google ad completed a signup. Consent-gated via Google Consent Mode v2.

What we don't do

No retargeting.No data sales.No exceptions.

  • No retargeting or behavioral ad networks beyond Google Ads conversion measurement (consent-gated, no data sold)
  • No cross-site tracking cookies
  • No sale of user data to any third party
  • No sharing of case details with insurance companies or opposing counsel
  • No retention of case data beyond necessary processing
Consumer Health Data

Special handling formedical andinjury information

Consumer tools such as Lexstimate let individuals submit medical records, injury descriptions, and diagnostic or procedure codes to receive an informational case-value estimate. Because this is sensitive health information, we apply heightened safeguards on top of the pillars above.

ENCRYPTION
Encrypted in transit and at rest

Medical and injury detail moves over TLS 1.3 and is stored encrypted with AES-256, the same standard applied to all case data.

ACCESS
Least-privilege access controls

Access to records containing health detail is restricted by role and row-level security. Consumer health data is never shared with insurance companies or opposing counsel.

MINIMIZATION
Collect only what is needed

We collect health information only as needed to generate your estimate and retain it only for as long as necessary to provide the Service.

MASKING
Masked on monitoring and replay

Error monitoring (Sentry) scrubs injury descriptions and medical detail before events leave our backend, and masks all text and media in any diagnostic replay. Session-replay analytics is disabled entirely on every consumer flow where medical or injury detail may be entered — Lexstimate, analysis, intake, and chat — and records only on non-sensitive routes, only after you consent.

For full detail on how we handle personal and health information, and the rights available to residents of certain states, see our Privacy Policy and our Washington Consumer Health Data Privacy Policy.

Disclosure

Found something?Tell us directly.

For security inquiries, vulnerability disclosure, or to request a copy of our latest security report under NDA, email security@caseworth.io. We respond to verified reports within one business day.

General Contact

Ready to knowwhat cases like yourshave actually been worth?

Start free. No credit card needed. Get your Lexstimate report instantly. Understand your deadline and see the observed outcome range for comparable cases.