Security

Your clients' trust is the product. We protect it.

CaseLens is built so a firm's data stays a firm's data — and a client's case stays the client's. Here's exactly what that means.

Row-level security on every record

Every case, document, note, and message is gated at the database. A request that isn't authorized for a row simply doesn't see it — there's no application-layer bypass.

Firm-level data isolation

Each firm is its own tenant. One firm never sees another firm's matters, clients, or files — enforced by the same database rules, not just our UI.

Attorney private notes stay private

Internal strategy notes are scoped to the attorney's firm. Clients see their own case, updates, and questions — never the attorney's working notes.

Encryption in transit and at rest

All traffic uses HTTPS. Data is encrypted at rest in our managed Postgres and object storage, including uploaded documents.

Modern authentication

Email and password with strength requirements, with optional magic-link sign-in for clients. Sessions are short-lived and refreshable; you can sign out from any device.

Client-facing layer on top of your system of record

CaseLens is designed to live alongside your existing practice management system, not replace it. Your matters of record stay where they already are; CaseLens is what your clients log into.

An honest note on certifications

We don't claim certifications we haven't earned. We describe what the product actually does today. If your firm needs documentation for a specific control — data residency, audit logs, custom retention — get in touch and we'll be straight with you about what's in place and what isn't.

To report a security concern, email security@caselens.app.

Built quietly. Reviewed honestly.

See how it feels for your firm.