SeraCase AI

Security and Data Processing Notice

Version 1.2Effective August 6, 2026
Contact

Version: 1.2

Effective date: 16 August 2026

This notice describes security and data-processing controls that are implemented in SeraCase AI today. It is product documentation, not a certification claim.

  • Email/password authentication via our auth provider (Supabase Auth).
  • Optional multi-factor authentication (MFA).
  • Session handling with idle-timeout controls and optional trusted-device preferences where enabled.
  • Secure password-reset flows.
  • Traffic between your browser and SeraCase uses HTTPS/TLS.
  • Document uploads may be encrypted at the application layer using AES-256-GCM when the encryption master key is configured for the environment.
  • This is not end-to-end encryption in the sense that SeraCase (or its infrastructure) never holds keys needed to serve your files.
  • Authenticated access to account data.
  • Case ownership checks on user materials.
  • Row-level security (RLS) on user data tables where enabled in the database.
  • Admin tools are restricted to configured admin email addresses.
  • Case documents are stored in private storage (not public buckets).
  • File viewing uses authenticated access or short-lived signed URLs / decrypt proxies as implemented.
  • Uploads are scanned with built-in heuristics.
  • A remote malware scanner may also run when `MALWARE_SCAN_URL` is configured. Production deployments should enable remote scanning.
  • Security-relevant and sensitive actions are recorded in audit logs where implemented (for example admin access denials, certain security events, and selected product actions).
  • SeraCase relies on encrypted backups operated by underlying cloud providers where those providers offer them.
  • SeraCase does not currently operate a separate first-party backup console for customers.
  • Residual copies may exist in provider backups for a limited time after deletion.
  • Users may delete individual materials and use Trash / restore workflows where available.
  • Soft-deleted items may be purged after a retention window (default approximately 30 days unless configured otherwise).
  • Secure deletion removes application-accessible copies and related encryption metadata where implemented.
  • Account deletion may be requested through My Data or by contacting support.
  • Legal holds can pause destructive cleanup for covered materials.

Unless independently verified and formally attained, SeraCase does not claim:

  • SOC 2 certification
  • ISO 27001 certification
  • HIPAA compliance
  • end-to-end encryption of stored documents
  • absolute or “100%” security
  • that uploading materials creates solicitor–client privilege with SeraCase
  • that SeraCase is a law firm or lawyer

Relevant excerpts and structured case context may be sent to AI providers to perform features you request. See the Privacy Policy for providers and cross-border processing.

Use strong unique passwords, enable MFA when available, protect your devices, promptly report suspected compromise, keep independent copies of important documents, and review outputs before filing or sharing. Security controls reduce risk but cannot guarantee that loss, misuse, or unauthorized access will never occur.

  • Security: security@seracase.ca
  • Privacy: privacy@seracase.ca
  • Support: support@seracase.ca

Implementation-ready draft — not a substitute for review by qualified Canadian and British Columbia counsel. Back to home

© 2026 SeraCase AI. All rights reserved.