Security & data
Plain-English notes on how CaseFirst handles your case information.
Hosting (UK-oriented)
CaseFirst is built for people dealing with UK disputes and is operated with UK data-protection expectations in mind. We aim to host production systems in the UK or wider EEA where practical. Exact production hosting location and provider details will be published here when confirmed — we do not invent certifications or audit badges we have not obtained.
Encryption in transit
In production, the site should be served over HTTPS so data between your browser and the server is encrypted in transit. Session cookies are marked Secure when HTTPS is detected.
Passwords and secrets
There is no traditional password account for MVP access. Cases are reached via a long random token in your browser session, or via an optional short-lived magic link emailed to you. Application secrets (database, payment, AI keys) stay on the server configuration — they are not exposed in the browser.
Upload isolation
Evidence files are stored in a dedicated uploads area with script execution disabled (IIS web.config).
Access is gated through the application using your case token — not by browsing a public folder listing.
What AI Review can see
When you run CaseFirst AI Review, the service receives text and evidence metadata (titles, types, descriptions) from your organised case file — not the binary contents of uploaded files. AI Review checks file quality and completeness only; it does not assess legal merits.
Magic links
Optional continue links are one-time tokens. Only a cryptographic hash is stored; the raw token is never saved in the database. Links expire quickly (around 45 minutes). Emails do not include case narratives or party details.
Payments
Optional AI Review unlocks are processed by Stripe. Card details are handled by Stripe’s checkout — CaseFirst does not store full card numbers on its own servers.
Export and deletion
You can export a Case Pack (and evidence ZIP where available) from your case at any time. To request deletion of case data, contact us at chris@cliqto.com with enough detail for us to locate the relevant case (for example a case reference from your Case Pack). We will confirm the process and timelines when we respond — a formal self-serve deletion portal is not yet available.
ICO registration
ICO registration details will appear here when registered.
See also our Privacy Policy and Terms.