
Security & Confidentiality
You guard attorney-client privilege every day. Here's how CaseSignal guards everything you put in it.
CaseSignal requests the narrowest Gmail permission that exists: send-only. We have no ability to read, search, or browse your inbox, and we never ask for it.
Every draft sits in your review queue until a person at your firm approves it. There is no fully automatic mode, by design.
All traffic runs over TLS, and your workspace data is encrypted at rest on our infrastructure. Connection tokens are stored server-side, never in your browser.
Every firm's cases, drafts, and connections live in their own isolated workspace tied to their account. One firm can never see another's data.
Drafting runs on Anthropic's Claude under commercial API terms, which means your case information is not used to train AI models. We never sell or share your data. Period.
Nothing about your cases is ever published to a webpage or shareable link. Updates travel one way: as email, from your own address, after your approval.
CaseSignal stores only what it needs to do its one job: the case summaries and client contact details you add or sync, and the updates you draft and send. Documents you upload are used to draft the update and attach to the outgoing email, inside your own workspace.
Just as important is what never touches our systems. Your passwords are handled by our sign-in provider, Clerk, with Google sign-in available. Your card number goes directly to Stripe, our payment processor; we never see or store it. And because our Gmail access is send-only, the contents of your inbox are simply beyond our reach.
When you connect Clio, we read only the case, contact, calendar, and document details needed to draft updates, and you can revoke that access at any moment from either side.
Security questions or something to report? Write to our team. We read every message.
