Product For students For practitioners For enterprises Pricing Security Resources FAQ Newsroom · Coming soon Docs · Coming soon Sign in Get started

Security

How your work is handled.

Built so your work is encrypted in transit and at rest, never used to train a model, and deleted when you ask. The status of each commitment is listed below.

Do not upload client information, privileged, confidential or court-restricted material, or personal information about another person.

Your work

Your data stays yours

Uploads and drafts belong to you. We do not sell, publish or use them as examples.

Training

Not used to train models

Your material is not used to train the models behind CaseWise. Provider terms appear below.

Sources

Public law, official records

CaseWise searches openly available Australian law and provides links to available source records.

At a glance

The commitments we hold to.

Eight commitments that govern how CaseWise is built and run. Each one appears in the table below with its current status.

01 Encrypted in transit and at rest Every upload, draft and question travels over TLS and is encrypted where it is stored.
02 Deleted when you ask You can ask for your uploads and drafts to be deleted, and we act on that request.
03 Not used to train models Uploads, drafts and questions do not train models. Provider terms are pending confirmation.
04 Kept apart from others Each account is isolated, so no other account reaches your work and yours reaches none.
05 Least-privilege access Production access is limited to the people who need it, and every grant is recorded.
06 Backed up and watched Automated backups, with alerting on unusual activity, are pending confirmation.
07 Reviewed before shipping Every change is peer reviewed and scanned, and dependencies are audited regularly.
08 Told without delay A written plan, a defined escalation path, and notice to affected accounts.

The specifics

The detail procurement asks for.

The answers a security review asks for, in the order it usually asks them. Where something is not yet in place, the status says so rather than implying otherwise.

Hosting and residency The regions where material is stored and processed, and any regional options, are confirmed in writing on request and stated here only once confirmed. Not yet confirmed
Encryption TLS in transit, and encryption at rest across databases and file storage. In place
Model providers Named providers process prompts under contract, with no training rights over your material. Not yet confirmed
Data isolation Each account is logically separated, and nothing is reused across accounts. In place
Access control Least privilege into production, plus roles and permissions inside group accounts. In place
Backups and recovery Automated backups, with monitoring and alerting on unusual activity. Not yet confirmed
Secure development Peer review and automated scanning on every change, with regular dependency audits. In place
Retention and deletion How long material is kept, and the deletion window, both stated in the agreement. In place
Sub-processors The full list of third parties and what each one receives, published and kept current. Not yet confirmed
Incident response A written plan with escalation paths, and notice to affected accounts on a confirmed breach. In place
Independent assurance Any formal audit or standard, stated only once held, with the documents available on request. Not yet confirmed

Doing a security review?

Send your questionnaire and we answer in writing, item by item. Where something is not yet in place the answer says so, and we do not claim an audit we do not hold.

Request the detail →

Security review

Security questions are answered in the FAQ.

What is stored, whether your work trains a model, and which third parties are involved.

Read security questions →