Security and data handling
Intake packets hold social security numbers, dates of birth, bank balances and a full creditor schedule. Here is exactly what happens to them.
How Casewell protects bankruptcy client data
Encrypted at rest
Client-identifying columns are encrypted in the database, including debtor names, the assembled case information, the read results and file names. A database dump on its own does not yield readable client data.
Seven-day retention sweep
A daily sweep deletes uploaded scans, recorded meetings and generated .BCB files older than seven days, along with old unreferenced files left on disk. The captured case data is redacted 30 days after the case was created. Learned corrections that go unused are removed after 90 days.
Per-firm isolation
Cases, files and learned corrections are scoped to a firm, and every request is authorised against the signed-in user’s firm.
Encrypted private network
Case data moves between our application server and the file generator over an encrypted private network, with no cleartext case data on the public internet.
No model training
Reads use the Anthropic API, whose commercial policy excludes API inputs and outputs from training by default. Recorded meetings are transcribed by AssemblyAI under a signed business associate agreement with no training. Your corrections improve your firm’s reads and nobody else’s. Read Anthropic’s model training policy.
Attorney control is a design constraint
Comparing the reads identifies disagreements between them. Scanned intakes can continue with recommended values automatically. Your team must review the resulting case in Best Case before filing.
- Scan recommendations can continue automatically
- Every confirmation is recorded against the case
- Source snippets are available while the source scan is retained
- Attorney review is required before filing
- Casewell files nothing with any court
What we are still building
Casewell is in beta and it is more useful to say what is not finished than to imply everything is. There is no SOC 2 report yet, and no third-party penetration test has been completed. Firms that need either before adopting a tool should tell us, because it changes what we prioritise.