Authentication & access control
Workspace access is authenticated, role-aware, and scoped to the records a user is permitted to work with. Collaboration features are designed around least-privilege sharing rather than broad workspace exposure.
Trust Center / Security
Caseflow is built around authenticated workspace access, role-aware collaboration, document-scoped authorization, controlled AI processing, and reviewable operational workflows.
The security model combines application permissions, backend validation, scoped document access, provider-managed infrastructure controls, and human review requirements.
Workspace access is authenticated, role-aware, and scoped to the records a user is permitted to work with. Collaboration features are designed around least-privilege sharing rather than broad workspace exposure.
Case, task, document, and AI retrieval paths are designed around tenant and case boundaries. Shared access is rebuilt from current permissions before sensitive context is surfaced.
Supported document flows use storage paths plus permission-checked access requests. New migrated case and task uploads avoid storing reusable Firebase download-token URLs.
AI requests go through backend controls, permission-aware retrieval, scoped vector filtering, stale artifact checks, confirmation flows, and human review requirements.
Case history, AI audit metadata, confirmation records, and operational logs support traceability without treating logs as a substitute for professional review.
Support and operational channels route access, privacy, security, and AI handling concerns for review. Incident-response wording avoids unsupported SLA or certification claims.
Caseflow access checks are intended to keep each user inside the workspace, case, task, and document scope they are authorized to use.
Data is stored with provider-managed infrastructure safeguards, while application controls govern who can reach records and files.
Security reports, suspected unauthorized access, and privacy or AI data handling concerns should be submitted through support so they can be routed to the right reviewer. Dedicated vulnerability disclosure SLAs or bug bounty terms should only be published after operational approval.
Include affected URLs, account email, observed behavior, screenshots where safe, and whether data may have been exposed.
Report unexpected case, task, document, invitation, or workspace visibility with the minimum detail needed for triage.
Share the case workflow, AI feature used, and why the generated output or retrieved context appears outside expectations.