Security

Enterprise-grade protection built for the sensitive nature of immigration law.

Trust Center

Access Our Full Security Documentation

Request audit reports, review our governance posture, and explore all security controls at the CaseBlink Trust Center.

Pillars

Secure. Private. Reliable.

Personal identifiable data is kept safe and never used beyond the duration of the language model prediction.

Secure Cloud Infrastructure

Enterprise-grade cloud architecture.

  • AES-256 encryption at rest and in transit
  • Isolated tenant environments
  • Continuous threat monitoring & alerting

Zero LLM Data Retention

Client data is never stored or trained on.

  • Data purged immediately after each operation
  • No model training on client content
  • Full data lifecycle transparency

Single Sign-On (SSO)

Streamlined, secure access for your entire firm through your existing identity provider.

  • SAML 2.0 & OIDC support
  • Works with Okta, Azure AD, Google Workspace & more
  • Centralized user provisioning & deprovisioning

Industry Best Practices

Top notch security standards.

  • Regular third-party penetration testing
  • Vulnerability disclosure program
  • Security-first engineering culture

Internal Security Controls

Strict internal policies.

  • Role-based fine-grained access controls
  • Rigorous change management processes
  • Employee security training & audits

SOC 2 Type 2 Compliant

Independently audited and certified to the highest compliance standards.

  • Annual SOC 2 Type 2 audit
  • GDPR & CCPA aligned data practices
  • Audit logs for all sensitive operations
Controls

Controls

View all 52 controls →

Access Control

  • Access Control Policy and Procedures
  • Access Provisioning
  • Access Termination
View all 9

Business Continuity & Disaster Recovery

  • Capacity Planning
  • Contingency Plan Testing
  • Redundant Secondary System
  • System Backup

Configuration & Change Management

  • Change Management and Software Development
  • Configuration Management

Contingency Planning

  • Capacity Planning
  • Contingency Plan Testing
  • Redundant Secondary System
  • System Backup

Incident Response

  • Incident Response Plan
  • Incident Response Testing

Information Security Program

  • Guidelines and Support Resources
  • Information Security Policy and Procedures
  • Information Security Program Leadership
FAQ

Security Questions

Yes. CaseBlink has completed both SOC 2 Type 1 (2024) and SOC 2 Type 2 (2025) audits. You can request access to these audit reports directly through our Trust Center at trust.caseblink.com.

No. We have a zero data retention policy contract with our AI API providers. User data is not retained beyond the duration of operations, and all data is immediately deleted post-prompt processing.

CaseBlink runs on cloud-native infrastructure with Google Cloud Platform, leveraging industry-leading security and privacy capabilities built into GCP.

All customer and client data is encrypted both at-rest and in-transit using industry best practices. This ensures your sensitive immigration case data is always protected.

We operate a rigorous Information Security Management Program that includes policies for fine-grained access controls, change management, and data privacy. Our controls span Access Control, Incident Response, Business Continuity, Configuration Management, and more — totaling 52 verified controls.

All security documentation, including SOC 2 audit reports and our ZDR OpenAI agreement, can be requested through our Trust Center at trust.caseblink.com. You can also reach our team directly at info@caseblink.com.

Get started

Unlock premium AI for
Your Immigration Firm

Join hundreds of forward-thinking firms and win more cases with less effort.