<img height="1" width="1" src="https://www.facebook.com/tr?id=1214483435298340&amp;ev=PageView &amp;noscript=1">

Engineered for security

The security of your data is our highest priority. We've built Casefleet from the ground up on this principle.

Security is a top priority at Casefleet and is considered a key part of company culture. Every single piece of Casefleet application code, infrastructure, and operations is continually audited for its security impact.

All of Casefleet's infrastructure is hosted on Amazon Web Services. For more information regarding their security practices, please visit their security website.

Application security

Battle tested frameworks

Casefleet uses tried and true web application frameworks to ensure the integrity of communication between the client and the server. Techniques include:

    1. XSS protection
    2. CSRF protection
    3. Signed cookie based session management
    4. Rate limiting
    5. Audit logging

Anonymized data

When possible, data is anonymized via a UUID. By doing so, each component in the Casefleet infrastructure is only aware of the bare minimum required to serve its purpose.

Password hashing

Passwords are never stored in plain text. They are all hashed before storing in the database.

Virus and malware scanning

All files loaded into Casefleet are automatically scanned for viruses and malware. This helps prevent the spread of potentially harmful files in your firm.

Network & storage security

Encryption in transit

All external and internal communication requires encryption via TLS. All of our web servers require an SSL connection from end users in order to access the application. In addition, all communication between internal systems is required to be encrypted.

Encryption at rest

All stored data is encrypted when written to disk. In the case of a physical security breach, the attacker would have no way of reading client data.

Virtual private cloud

Casefleet infrastructure responsible for handling end-user data lives entirely within a virtual network. This network is engineered to expose only required components to the public internet. All other components require secure access via the private network.


Agile development with code review

Casefleet adheres to an agile methodology of development. All code is subject to automated testing for security and integrity. After automated testing, code is reviewed and signed off on by another engineer for security and integrity. Then the code is tested for quality in a staging environment. Only after these steps are complete is the code allowed to be released.

Backups & recovery

All data stored within Casefleet is automatically backed up on a daily basis and retained for an extended period of time. In the case of a disaster recovery scenario, this data can be used to restore the application back to the last known operational state.

Employee equipment

All employees are issued a company laptop that is returned upon termination. Every employee laptop has disk encryption enabled to prevent theft from compromising the system. In addition, all engineers with production level access have a firewall enabled and network monitoring tools installed.

Employee access

All access is given under the principle of least privilege. This access is revoked upon employee termination. Where available, two factor authentication is required for all work applications. This access is monitored and audited regularly.

Physical security

All Casefleet data is stored in Amazon Web Services. For more information regarding their physical security please visit their website.

The Casefleet offices require key card access. All access is monitored via security cameras.

Account security

In addition to the security steps we have taken, every account has security features to further harden access to your data.

Two factor authentication

Every user account can enable two factor authentication to add an additional security layer to your account. Every time you log in, you will be prompted to enter a code from your phone in order to access your data.

Single sign on

Enterprise plans have the option to enable single sign on via SAML2. This integration allows you to manage your users via a third party authentication provider.

Permissions levels

Every administrator within Casefleet can granularly control what data is visible to which users. This ensures privileged and confidential information stays that way, while allowing you to invite all of your collaborators.

Session tracking

Every time you log into Casefleet, a unique "session" tied to your web browser and IP address is generated. If more than one valid sessions exist at any time, Casefleet pushes an alert to the application notifying you of the additional login and providing an opportunity to take further steps as needed, such as adding two-factor authentication to your account.

Start your free trial today