Security and Data-Handling Summary
Last updated: 30 July 2026
This summary is intended to support customer due diligence. Contractual security obligations are set out in Schedule 2 of the Terms.
Current technical controls
- Passwordless Kinde authentication and authenticated backend requests.
- JWT issuer, audience and RS256 signature verification.
- HTTPS/TLS transport, restricted production CORS, input validation, rate limiting and upload limits.
- Uploaded documents are parsed in application memory; case bodies are not deliberately written to Firestore.
- Firestore is limited to authenticated user identifiers and credit balances.
- Application logging is designed not to include case bodies or document text.
- Cloud Run and Firestore are configured in London; Kinde is configured in its UK—London region.
- Firestore scheduled backups and point-in-time recovery are disabled.
- Subprocessor, incident and deletion obligations are set out in the Data Processing Schedule.
Important limitations
- Gemini project logging is enabled for seven days and ClauseCast has not obtained Gemini zero-data-retention approval.
- ClauseCast does not claim that Gemini processing, provider support or all security operations are confined to the UK.
- ClauseCast does not currently claim an external information-security certification or independent penetration-test assurance.
Recommended law-firm use
Unless the firm’s authorised compliance or information-security function has approved identifiable use, submit only anonymised or appropriately pseudonymised commercial case material. Firms should assess confidentiality, privilege, data-protection, client-information and supervision requirements before using the Service on a matter.
Security and procurement enquiries may be sent to admin@clausecast.com.