AES-256 Encryption
Documents are encrypted with AES-256-GCM before storage.
Each file uses a unique IV and authentication tag. Encryption keys are never stored beside ciphertext.
SeraCase Trust Center
SeraCase is a secure AI case management platform designed to help you organize and understand your legal information — for individuals, families, lawyers, and mediators.
Security
How your documents stay protected
Privacy
Your data, your ownership, your choices
Compliance
Our path toward enterprise assurance
AI Transparency
What Sera reviews — and what she never does
Data Protection
Isolation, deletion, and export rights
Infrastructure
Secure cloud foundations
Backups
Resilience you can rely on
Incident Response
How we prepare and respond
Contact Security
Talk with our security team
AES-256 Encryption
Files encrypted before storage with per-file keys.
Private Storage
No public buckets — signed access only.
AI Privacy
Case-scoped AI context. No cross-user learning.
Audit Logging
Security actions recorded for transparency.
Enterprise Security
MFA, RLS, malware scanning, and session controls.
Canadian Privacy Focus
Built for confidential legal case materials.
Documents are encrypted with AES-256-GCM before storage.
Each file uses a unique IV and authentication tag. Encryption keys are never stored beside ciphertext.
Traffic between your browser and SeraCase uses HTTPS/TLS.
Sessions and API calls travel over encrypted connections to protect credentials and case materials in transit.
Uploads live in private cloud buckets — not public links.
Objects are not publicly listable. Access uses short-lived signed URLs or authenticated decrypt proxies.
Database policies restrict each account to its own records.
Supabase RLS and ownership checks help ensure users cannot read another user’s cases, files, or chats.
Uploads are scanned before processing continues.
Heuristic checks and optional remote scanning run before OCR/AI. Suspicious files are quarantined.
Executable payloads and known test signatures are blocked.
Dangerous extensions, magic-byte executables, and EICAR-style signatures are rejected with clear user messages.
See the full list on the Security page.