Security
Your clients' trust is the product. We protect it.
CaseLens is built so a firm's data stays a firm's data — and a client's case stays the client's. Here's exactly what that means.
Row-level security on every record
Every case, document, note, and message is gated at the database. A request that isn't authorized for a row simply doesn't see it — there's no application-layer bypass.
Firm-level data isolation
Each firm is its own tenant. One firm never sees another firm's matters, clients, or files — enforced by the same database rules, not just our UI.
Attorney private notes stay private
Internal strategy notes are scoped to the attorney's firm. Clients see their own case, updates, and questions — never the attorney's working notes.
Encryption in transit and at rest
All traffic uses HTTPS. Data is encrypted at rest in our managed Postgres and object storage, including uploaded documents.
Modern authentication
Email and password with strength requirements, with optional magic-link sign-in for clients. Sessions are short-lived and refreshable; you can sign out from any device.
Client-facing layer on top of your system of record
CaseLens is designed to live alongside your existing practice management system, not replace it. Your matters of record stay where they already are; CaseLens is what your clients log into.
An honest note on certifications
We don't claim certifications we haven't earned. We describe what the product actually does today. If your firm needs documentation for a specific control — data residency, audit logs, custom retention — get in touch and we'll be straight with you about what's in place and what isn't.
To report a security concern, email security@caselens.app.