CaseAgent is built for work that has to stand up later — to a regulator, to a court, to a board. Below, the security primitives we ship by default — and an honest read of what is still on the roadmap.
The product treats the case file as evidence, not as a draft document. Once an action is recorded, it stays recorded — and you can prove it.
Investigation work runs on need-to-know. CaseAgent applies access primitives at the case level, not just the workspace.
Customer data moves and rests under standard encryption. Tenant separation is enforced at the application layer with explicit organization scoping on every database query.
Compliance work is on a clear path. Until the audits are signed, here's what we have today, what's available on request, and what's on the roadmap — without pretending to hold a badge we don't.
We run on managed infrastructure rather than rolling our own — we'd rather spend our time on investigation features than reinvent the operations stack.
We're a small team and we're honest about it. We don't claim a 24×7 SOC. We do have a working incident process and a clear notification commitment.