Security & Privacy
How we protect your evidence, your files, and your account. Last updated January 2025.
Encryption in transit and at rest
All data transmitted between your browser and CaseBuilder is encrypted using TLS 1.2 or higher. Your uploaded files are stored in Amazon S3 with server-side encryption (AES-256) enabled by default. No file is ever stored unencrypted.
File retention and deletion
Your files belong to you. We retain your uploaded evidence only for as long as your case exists in CaseBuilder. When you delete a case or a file, it is permanently removed from our storage — including from Amazon S3 — and cannot be recovered.
We do not keep backups of deleted user files. Deletion is permanent and immediate.
We never sell or share your data
Your evidence, case details, and personal information are never sold, rented, or shared with third parties for any commercial purpose. We do not use your files to train AI models. Your content is processed solely to provide you with the CaseBuilder analysis you requested.
- No advertising partners have access to your data
- No data brokers receive your information
- Your files are never used for AI training
- We do not share your information with other users
Session security
CaseBuilder uses secure, HTTP-only session cookies that cannot be accessed by JavaScript. Sessions are bound to your authenticated login and expire automatically. All session traffic is forced over HTTPS — we do not allow unencrypted connections to authenticated pages.
- Cookies are marked Secure and HttpOnly
- SameSite policy is set to Lax to prevent cross-site request forgery
- Sessions are invalidated immediately on logout
Legal and compliance
CaseBuilder is designed for use in legal proceedings and takes the sensitivity of your evidence seriously. We operate infrastructure in the United States. Our storage provider, Amazon Web Services, maintains SOC 2 Type II and ISO 27001 certifications.
CaseBuilder is not a covered entity under HIPAA. If you are uploading protected health information as part of a legal matter, please consult with your attorney about applicable obligations.
Found a security issue?
Please report it responsibly. We take all security reports seriously and respond within 48 hours.