Enterprise-Grade Security

    Your data is protected.

    We take security seriously. Every product in the CaseFlow family is built around the same controls: PII redaction before AI, isolated tenant data, audit logging, and UK GDPR compliance from the ground up.

    ICO registered with the UK Information Commissioners Office

    ICO Registered

    CaseFlow Automation Ltd is registered with the UK Information Commissioner's Office (Registration: ZC013423). All processing follows UK GDPR principles, with data minimisation and purpose limitation built into every product.

    How we protect your data

    Secure Authentication

    Email verification, strong password policies, and leaked password protection (HIBP) on every account across the CaseFlow family.

    Data Isolation

    Row-level security ensures each firm's data is fully isolated. No customer ever sees another customer's records.

    PII Redaction Gateway

    Personal identifiers are automatically masked before any text reaches an AI provider. Privacy by design, not by promise.

    UK GDPR Compliant

    Built around UK GDPR principles: lawful basis, data minimisation, purpose limitation, and robust technical safeguards.

    Document Handling by Design

    For most workflows, PDFs and case files are parsed in the browser and only redacted text is sent for processing. Where a product must return a PDF output (for example LegalDocs Assist Medical Pagination, which produces a paginated bundle), source files are uploaded over an encrypted channel into an isolated, access-controlled workspace, processed, and the originals are deleted on completion.

    Role-Based Access Control

    Granular permissions ensure team members only access what they need. Managers oversee their team, while handlers focus on their cases.

    • Manager and senior dashboards
    • Handler-scoped case access
    • Invite-only registration

    Security features

    • Encrypted data at rest and in transit
    • Secure invite-only registration
    • Automatic PII masking before AI processing
    • AI providers do not train on your data
    • Compromised password detection (HIBP)
    • Audit logging for compliance

    Frequently asked questions

    Building something for the claimant industry or regulated advisory firms?

    Whether you're looking to use one of our products, partner with us, or explore what CaseFlow could build next, we'd like to hear from you.

    CaseFlow Automation

    CaseFlow Automation is a family of specialist software products for the claimant industry and regulated advisory firms.

    Contact

    © 2026 CaseFlow Automation Ltd. All rights reserved.

    ICO registered — UK Information Commissioner's OfficeICO Registration: ZC013423