Your data is protected.
How we protect your data
Secure Authentication
Email verification, strong password policies, and leaked password protection (HIBP) on every account across the CaseFlow family.
Data Isolation
Row-level security ensures each firm's data is fully isolated. No customer ever sees another customer's records.
PII Redaction Gateway
Personal identifiers are automatically masked before any text reaches an AI provider. Privacy by design, not by promise.
UK GDPR Compliant
Built around UK GDPR principles: lawful basis, data minimisation, purpose limitation, and robust technical safeguards.
Document Handling by Design
For most workflows, PDFs and case files are parsed in the browser and only redacted text is sent for processing. Where a product must return a PDF output (for example LegalDocs Assist Medical Pagination, which produces a paginated bundle), source files are uploaded over an encrypted channel into an isolated, access-controlled workspace, processed, and the originals are deleted on completion.

ICO Registered
CaseFlow Automation Ltd is registered with the UK Information Commissioner's Office (Registration: ZC013423). All processing follows UK GDPR principles, with data minimisation and purpose limitation built into every product.
Our Cyber Essentials certification
CaseFlow Automation holds Cyber Essentials certification covering the whole organisation.
- Organisation certified
- CaseFlow Automation, 7-9 Macon Court, Crewe CW1 6EA
- Scope
- Whole organisation
- Certificate number
- 176bba48-8fb4-4f1a-a685-32d86b40fe3f
- Profile version
- 3.3 (Danzell)
- Date of certification
- 7 August 2026
- Recertification due
- 7 August 2027
- Certification body
- IT Cyber Solutions
- Accreditation partner
- IASME, the National Cyber Security Centre's delivery partner for the scheme
Whole organisation scope matters. Some certificates are issued against a narrow slice of a business, a single office or one product. Ours covers everything CaseFlow Automation runs.
What Cyber Essentials actually covers
Cyber Essentials is a UK Government backed scheme delivered by IASME on behalf of the National Cyber Security Centre. It assesses an organisation against five technical controls.
Firewalls
Boundary and device firewalls are configured to block unapproved inbound traffic by default, with any exception documented and justified.
Secure configuration
Devices and software ship with convenient defaults rather than safe ones. This control covers removing what is not needed, changing default credentials and hardening what remains.
Security update management
Software is supported, licensed and patched. High risk and critical updates are applied within defined timescales, and unsupported software is removed.
User access control
Accounts are issued to named individuals, access is granted on need, administrative privileges are separated from day to day accounts, and access is removed when someone leaves.
Malware protection
Devices are protected against malicious code through anti-malware software, application allow listing, or sandboxing.
What Cyber Essentials does not cover
We would rather be straight with you about the limits of this than let a badge do work it cannot do.
Cyber Essentials is a verified baseline, not an exhaustive audit. It confirms that the five controls above were in place at the point of assessment. It is not the same as Cyber Essentials Plus, which adds a hands on technical audit, and it is not ISO 27001, which certifies a whole information security management system.
The certificate itself carries this wording, and we think it is worth repeating rather than burying: the certificate confirms the organisation's ICT defences were assessed as satisfactory against commodity based cyber attacks at the time of testing, and does not guarantee those defences will remain satisfactory against a cyber attack.
Security is a practice, not a certificate. The certificate is evidence that we take the practice seriously enough to be assessed on it every year.
Verifying this certificate yourself
Do not take a badge on a website as proof of anything. Anyone can put an image in a footer.
Every Cyber Essentials certificate is recorded on an independent registry. Ours is published at the link below, and the registry entry will show as active while the certification is current and lapse if it is not renewed.
Check our certificate on the official registry: https://registry.blockmarktech.com/certificates/176bba48-8fb4-4f1a-a685-32d86b40fe3f/active/
Role-Based Access Control
Granular permissions ensure team members only access what they need. Managers oversee their team, while handlers focus on their cases.
- Manager and senior dashboards
- Handler-scoped case access
- Invite-only registration
Security features
- Encrypted data at rest and in transit
- Secure invite-only registration
- Automatic PII masking before AI processing
- AI providers do not train on your data
- Compromised password detection (HIBP)
- Audit logging for compliance
Working with regulated clients
If you are running a procurement or supplier assurance process, we are used to it and we will not make it difficult. Alongside this certification we can provide a data processing agreement, answer a security questionnaire, and talk through where data is held and who can reach it.
For anything not answered here, contact us and ask. A question we cannot answer straight is a question worth us fixing.