Security and privacy: where does your clients' data live?
Last updated:
The short answer: on the firm's computer, encrypted, under your control. A firm that runs its clients' files with us is owed a precise answer to where and how the data is kept.
Three places, and only two of them are yours
- On the office computer. The firm's database is encrypted and lives on the office computer. A copy of the data file taken to another computer does not open.
- In the firm's cloud — only if you choose. The backup is encrypted and kept on the office computer. Syncing it to the firm's own cloud (Google Drive, OneDrive or Dropbox) is your choice, off by default — and when enabled, it goes to the firm's own account.
- On CaseFlow's servers: nothing. No CaseFlow server holds your clients' files. So there is no single address whose breach exposes every firm's data.
What does pass through our servers
Our servers handle licensing, signed version updates, and a few optional services a firm chooses to enable: remote signing (the document to be signed is stored temporarily behind a single-use link), and managed AI for a firm that does not want a provider account of its own. Exactly what is processed, where and for how long is written in the privacy policy. The case data itself does not pass through our servers.
Firm-level controls
- App lock and two-step verification for every user.
- Roles and permissions: partner, lawyer, trainee, office staff. Who sees which case and who may change what.
- A full audit log of every action in the system, exported as a file and as a readable report.
- The firm decides what the smart assistant may do, and every proposal it makes waits for the lawyer's approval.
- Signed automatic updates to every seat, from one identified source.
AI and data
The smart assistant works on the firm's data and hands every result back for approval. A firm that enables managed AI sends the model provider only the text the lawyer chose to send; we record a usage meter, never content. The model providers we work with do not train on API data under their terms, and we choose processing regions in the European Union.
Reporting a vulnerability
Found something? Write to security@caseflow.co.il. We acknowledge within one business day, act by severity, and tell the reporter when the fix has shipped.