Is this your company?Buyers are checking Casemark here. Claim casemark.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Welcome to CaseMark’s Trust Center! CaseMark is the privacy-first, AI-assisted workflow and summarization platform for the legal industry. Trusted by over 7,000 legal professionals, we deliver the broadest set of legal summaries on the market while maintaining a best-in-class privacy and security promise unmatched in the industry. This page provides an overview of our commitment to compliance and security. Here, you can explore our certifications, request documentation, and review high-level details of the controls we follow. To access sensitive documents, simply click the lock icon next to th
SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Subprocessors
List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
Hosting
Add where you host (AWS, GCP, Azure) and data residency.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Casemark SOC 2 compliant?
Casemark is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Casemark HIPAA compliant?
According to Casemark's public trust center, Casemark is HIPAA compliant. On SOC2C this listing is Listed.
Is Casemark SOC 2 Type I or Type II?
Casemark is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Casemark's SOC 2 for a vendor risk assessment?
Yes. Casemark's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Casemark penetration tested?
Casemark hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Can I get Casemark's SOC 2 report?
Casemark's SOC 2 report is available on request. Request access through SOC2C and we coordinate the company-side NDA and delivery.
Is Casemark secure?
Security isn't a single yes/no, but Casemark is SOC 2 Type II compliant and holds SOC 2 Type II, HIPAA. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Casemark have a bug bounty or vulnerability disclosure program?
Casemark hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@casemark.com or via a /security page.
Who are Casemark's subprocessors?
Casemark's subprocessors aren't listed on SOC2C yet. The company can add them so buyers can assess fourth-party risk.
Where does Casemark host or store data?
Casemark's hosting and data-residency details aren't listed on SOC2C yet. The company can add where it hosts (AWS, GCP, Azure) and which data it handles.
Where is Casemark's trust center or security page?
Casemark's trust center is at https://trust.casemark.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Where can I find information about CaseMark’s uptime and downtimes?
Check out https://status.casemark.com/ You can subscribe for updates, view uptimes, be notified of any outages, and view historical data.
Is CaseMark willing to sign a BAA?
After understanding your use case and HIPAA-related compliance requirements, CaseMark may provide a Business Agent Agreement for signature. Please contact us for further information.
Does CaseMark offer an API?
Yes, please check out https://www.casemark.com/features/api
Does CaseMark use cookies?
Yes, please check out https://www.casemark.com/cookies
Are you a data controller or data processor?
Under the GDPR, a “controller” means a person who “determines the purposes and means of the processing of personal data,” while a “processor” “processes personal data on behalf of the controller.” (GDPR Art. 4(7)-(8).) CaseMark acts as the processor of customer data that is provided to us in order to provide our products and services, such as customers’ and their clients’ personal data processed in order to access and use our services. In these situations, we act as the processor of customer data because we are processing the data on behalf of and at the direction of its customers. The choice of what data is shared, what summary type is used and how information is used or shared is done by the customer / end user of our product.
Where are your servers located?
Our cloud infrastructure is hosted on Amazon Web Services and Azure within the United States, with the flexibility to store customer data in additional countries as needed.
How long is data retained by CaseMark?
Data is securely retained for 30 days, or for the length of our agreement with you. Should you end your relationship with us, your data will be deleted within 30 days of its creation.
How is data deleted?
Data is securely destroyed either upon reaching the end of its retention period or upon your request, following a rigorous process that adheres to ISO-certified standards. This ensures that your data is handled and eliminated in a manner that meets international security and privacy protocols. You can also delete data by clicking on the trash icon next to each file. This removes the file and the associated chat messaging (if applicable).
Do you support Single Sign-On (SSO)?
CaseMark offers Single Sign-On (SSO) using Security Assertion Markup Language (SAML) to enhance both security and user experience.