Product security
How Cases protects your cases inside the application.
- Workspace isolationMonitored
Every query is scoped to your workspace, and every route declares who may call it.
- Passwordless and SSO sign-inMonitored
Sign-in by one-time email code or Google and Microsoft SSO; no passwords to leak.
- Role-based accessMonitored
Private and shared cases, with per-case membership decided by your administrators.
- Tamper-evident audit trailMonitored
Reads, changes and decisions are recorded with who, what and when; entries are never deleted.
- Legal holdMonitored
A case under legal hold cannot be altered or deleted until the hold is released.
- Secure development lifecycleMonitored
Peer-reviewed changes, dependency scanning and automated tests gate every release.
- Annual penetration testingMonitored
An independent firm tests the application and infrastructure every year and after major changes.