CaseFirst is legal technology, not a law firm. It helps you organise and present information but does not provide legal advice or assess the legal merits of your case.

Security & data

Plain-English notes on how CaseFirst handles your case information.

Hosting (UK-oriented)

CaseFirst is built for people dealing with UK disputes and is operated with UK data-protection expectations in mind. We aim to host production systems in the UK or wider EEA where practical. Exact production hosting location and provider details will be published here when confirmed — we do not invent certifications or audit badges we have not obtained.

Encryption in transit

In production, the site should be served over HTTPS so data between your browser and the server is encrypted in transit. Session cookies are marked Secure when HTTPS is detected.

Passwords and secrets

There is no traditional password account for MVP access. Cases are reached via a long random token in your browser session, or via an optional short-lived magic link emailed to you. Application secrets (database, payment, AI keys) stay on the server configuration — they are not exposed in the browser.

Upload isolation

Evidence files are stored in a dedicated uploads area with script execution disabled (IIS web.config). Access is gated through the application using your case token — not by browsing a public folder listing.

What AI Review can see

When you run CaseFirst AI Review, the service receives text and evidence metadata (titles, types, descriptions) from your organised case file — not the binary contents of uploaded files. AI Review checks file quality and completeness only; it does not assess legal merits.

Magic links

Optional continue links are one-time tokens. Only a cryptographic hash is stored; the raw token is never saved in the database. Links expire quickly (around 45 minutes). Emails do not include case narratives or party details.

Payments

Optional AI Review unlocks are processed by Stripe. Card details are handled by Stripe’s checkout — CaseFirst does not store full card numbers on its own servers.

Export and deletion

You can export a Case Pack (and evidence ZIP where available) from your case at any time. To request deletion of case data, contact us at chris@cliqto.com with enough detail for us to locate the relevant case (for example a case reference from your Case Pack). We will confirm the process and timelines when we respond — a formal self-serve deletion portal is not yet available.

ICO registration

ICO registration details will appear here when registered.

See also our Privacy Policy and Terms.