Encrypted & Audited Case Management

Legal Case Management Built for Security

Organize evidence, build chronological timelines, manage court forms, and prepare your defense — all in one encrypted, fully audited platform. Built for self-represented litigants, solo practitioners, and law firms.

AES-256 Encrypted
MFA / Two-Factor
Org Data Isolation
SSO (SAML + OIDC)
PIPEDA Compliant
SCIM Provisioning

Trusted by self-represented litigants, solo practitioners, and law firms across Ontario

Everything You Need

A Complete Platform for Legal Case Management

From evidence intake to court-ready exports, CaseWrit handles every step of case preparation with security at its core.

Evidence Management

Upload, organize, and track every piece of evidence with full chain of custody. Automatic OCR extracts text from images and PDFs.

  • OCR text extraction
  • Auto-categorization
  • Chain of custody tracking
  • Court exhibit numbering

Timeline Builder

Build comprehensive chronological timelines that cross-reference evidence. Automatically detect contradictions in opposing claims.

  • Chronological event tracking
  • Evidence cross-references
  • Contradiction detection
  • Court-ready formatting

Smart Court Forms

Access 31+ Ontario court forms with AI-powered prompt generation. Pre-fill from case data and track form lifecycle from draft to filed.

  • 31+ Ontario court forms
  • AI prompt generator
  • Pre-fill from case data
  • Lifecycle tracking (draft to filed)

Charge & Court Date Tracking

Track criminal charges, bail conditions, and upcoming court dates in one place. Never miss a deadline.

  • Criminal charge tracking
  • Bail condition management
  • Court calendar
  • Deadline reminders

Legal Research

AI-powered legal research with bring-your-own-key model. Find relevant case law and integrate citations directly into your work.

  • AI-powered (BYOK)
  • Case law citations
  • CanLII integration
  • Research notes & bookmarks

Disclosure Management

Track Crown, defense, and third-party disclosure with full OCR pipeline. Know exactly what you have and what is still outstanding.

  • Full OCR pipeline
  • Status tracking per item
  • Crown / defense / third-party
  • Outstanding disclosure alerts

Multi-Tenant Security

Complete organization isolation with per-user encryption keys and granular role-based access control.

8

Org Roles

7

Case Roles

32

Permission Flags

Full Audit Trail

Every action is logged with HMAC integrity verification. Organization-scoped audit trails help maintain compliance and accountability.

  • HMAC-SHA256 integrity on every log entry
  • Tamper verification & detection
  • CSV/JSON audit log exports
  • Organization-scoped compliance

Client Portal

Give clients secure, controlled access to their case. Manage visibility at a granular level and accept evidence uploads securely.

  • Secure client access
  • Controlled visibility per item
  • Evidence upload by clients
  • Communication logging

Export & Court Prep

Generate court-ready PDF Book of Documents with cover page, table of contents, and 10 numbered sections. HMAC integrity on all exports.

  • PDF Book of Documents with TOC
  • HMAC integrity verification
  • Complete case data with cross-references
  • JSON & CSV exports

Chat & Communication Analysis

Parse and analyze conversations from WhatsApp, Signal, and iMessage. Pin important messages and analyze participant patterns.

  • WhatsApp / Signal / iMessage parsing
  • Message pin system
  • Participant analysis
  • Timeline integration

Succession Planning

Compliant with Law Society of Ontario Rule 3.7-1.1. Secure key recovery via Shamir's Secret Sharing ensures business continuity.

  • LSO Rule 3.7-1.1 compliant
  • Shamir's Secret Sharing key recovery
  • Designated successor access
  • Emergency key reconstruction
Security & Authentication

Enterprise-Grade Security for Sensitive Legal Data

Your clients' data deserves the highest level of protection. CaseWrit is built from the ground up with defense-in-depth security across encryption, authentication, and infrastructure.

Encryption & Data Protection

AES-256-GCM Encryption

All sensitive data encrypted at rest using AES-256-GCM — the same standard used by military and financial institutions.

Per-User Key Derivation

Each user's encryption key is derived via PBKDF2 with 310,000 iterations. Data is decrypted only during authenticated requests.

OAuth Token Encryption

Third-party OAuth tokens and OIDC client secrets encrypted before storage using AES-256-GCM with separate key derivation.

Deployment-Specific Salts

Master key derivation uses deployment-unique salts. No two deployments share the same derived encryption key.

Authentication & Identity

Multi-Factor Authentication

TOTP-based MFA with Google Authenticator, Authy, or Microsoft Authenticator. 10 encrypted backup codes for recovery.

SSO (SAML 2.0 + OIDC)

Enterprise single sign-on per organization. Connect Okta, Azure AD, Google Workspace, or any SAML/OIDC identity provider.

SCIM 2.0 Provisioning

Automatic user provisioning and deprovisioning. When an employee is added or removed in your IdP, CaseWrit syncs instantly.

Break-Glass Access

Designated emergency account can always bypass SSO enforcement. If your identity provider goes down, the org owner still gets in.

Session Management

View all active sessions, force-logout compromised devices remotely, and automatic session revocation on password reset.

Login Notifications

Email alert when your account is accessed from a new IP address. Includes device name, IP, and timestamp.

Password Breach Detection

Passwords checked against HaveIBeenPwned during registration and reset. Breached passwords are blocked before they're ever stored.

Atomic Account Lockout

After 5 failed login attempts, accounts lock for 15 minutes. Uses atomic database operations — parallel attacks can't bypass the counter.

Infrastructure & Compliance

Organization Boundaries

Strict tenant isolation — data from one law firm can never be accessed by another. Enforced on every API request with cross-org audit logging.

HMAC-SHA256 Audit Trail

Every action signed with HMAC-SHA256. Tamper verification endpoint detects modifications. CSV/JSON audit exports for compliance.

100% Rate-Limited APIs

All 52 API endpoints have rate limiting. Authentication endpoints use IP-based limits. File processing endpoints have per-user throttling.

Security Headers

Full suite: CSP, HSTS (preload), CORP, COOP, X-Frame-Options, frame-ancestors, Permissions-Policy. API responses are never cached.

security.txt (RFC 9116)

Vulnerability disclosure contact at /.well-known/security.txt. Security researchers can report issues responsibly.

Role-Based Access Control

8 organization roles, 7 case roles, 32 granular permission flags. Privileged attorney notes protected with separate permission checks.

Soft-Delete & Chain of Custody

Evidence is never hard-deleted. Cross-references preserved with audit annotations. Evidence history logged with CRITICAL-level failure alerts.

SSO Enforcement

Organizations can mandate SSO for all members — password login disabled. Only the break-glass account can bypass enforcement.

Privacy by Design

Your Data, Your Control

CaseWrit is built on privacy-by-design principles. Every feature considers data minimization, consent, and your rights under Canadian privacy law.

PIPEDA Compliance

Full alignment with Canada's Personal Information Protection and Electronic Documents Act, including all 10 fair information principles.

  • Accountability — designated privacy contact and organizational responsibility
  • Identifying Purposes — clear disclosure of why data is collected
  • Consent — granular consent management (analytics, marketing, third-party)
  • Limiting Collection — only data necessary for case management
  • Limiting Use — data used only for stated purposes
  • Accuracy — user correction rights via privacy request API
  • Safeguards — AES-256-GCM encryption, per-user keys, org isolation
  • Openness — comprehensive privacy policy, cookie policy, terms of service
  • Individual Access — data access request API with full data export
  • Challenging Compliance — privacy contact for complaints and inquiries

Data Subject Rights (Built-In APIs)

Right of Access

Request all data we hold about you

Right to Correction

Request corrections to your data

Right to Deletion

Request erasure of your data

Right to Portability

Export your data in standard format

Consent Management

Granular cookie consent banner on first visit. Users choose between essential-only, preferences, and analytics cookies. Consent preferences tracked per user with full audit trail.

Essential CookiesPreference CookiesAnalytics CookiesConsent Audit TrailRevocable Anytime

Data Retention & Deletion

Soft-delete model — data is never hard-deleted to preserve legal chain of custody. Deletion requests processed via PIPEDA API with complete audit trail. Filed court documents are archived, never destroyed.

Soft-Delete OnlyChain of CustodyLegal Hold SupportAutomated ProcessingAudit-Logged Deletion

Platform Responsibility Model

CaseWrit operates as a secure platform provider — like a building that houses law offices. We are responsible for the security and integrity of the platform. Each subscribing organization is responsible for the content, accuracy, and compliance of their own data.

CaseWrit is responsible for:

  • • Platform security and encryption
  • • Tenant data isolation
  • • Uptime and infrastructure
  • • Privacy compliance tooling

Each organization is responsible for:

  • • Data accuracy and completeness
  • • Client consent and disclosure
  • • Legal compliance in their jurisdiction
  • • User access and permissions within their org

Get Started in Minutes

How It Works

From sign-up to court-ready in four straightforward steps.

01

Create Your Organization

Set up your law firm, solo practice, or self-represented litigant account in under two minutes.

02

Create a Case & Add Your Team

Create a case, invite collaborators, and assign roles with granular permissions.

03

Upload Everything

Add evidence, charges, court dates, and disclosure. Everything auto-organizes with reference IDs.

04

Prepare for Court

Generate court-ready exports, fill forms, and build your Book of Documents with full integrity verification.

Get Started Free

No credit card required

Important Platform Disclaimer

CaseWrit is a case management tool, not a law firm. CaseWrit does not provide legal advice, legal representation, or legal opinions. Any AI-generated content (including form suggestions and research results) is provided for informational purposes only and must be independently verified.

Each organization is solely responsible for its own data, compliance, and legal obligations. CaseWrit makes no representations about the accuracy or suitability of any content for any particular legal proceeding.

CaseWrit operates as a platform provider. Content and data are managed exclusively by the subscribing organization. CaseWrit does not review, monitor, or take responsibility for user-generated content stored on the platform.

Jurisdiction

Currently Optimized for Ontario, Canada

CaseWrit currently supports court forms and workflows for the Ontario Court of Justice and the Superior Court of Justice of Ontario.

Federal court forms and other provincial jurisdictions coming soon.

Ready to Organize Your Case?

Join legal professionals across Ontario who trust CaseWrit to manage their most sensitive cases with confidence.