Is this your company? Buyers are checking Casepal here. Claim casepal.co free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
Casepal
Trust level
Listed
Unverified
Listed
Domain
Report
Live
Sourced from public information. Not yet verified by the company.
Casepal is SOC 2 compliant. Casepal also holds ISO 27001, and GDPR.
Compliance & infrastructure
Hosting
GCP
Documents
2Subprocessors
13- GGitLab · Version control
- GGoogle Cloud Platform · Cloud provider
- MMongoDB Atlas · Data storage and processing
- VVanta · Security
- TTwingate · IT
- SSlack · Collaboration
- JJira · Collaboration
- GGoogle Workspace · Identity provider
- DDeel · HRIS
- VVoyage AI · Document EmbeddingsEurope
- MMistral AIEurope
- LLangsmith
Show all 13 subprocessorsShow fewer
- SSearch API · Search functionality
Compliance leadership
The person who leads Casepal's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. Casepal's penetration test vendor isn't listed yet.
Claim this profile to add it.
This listing is partial
6/11 details · 55%SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- DescriptionAdd a one-line description so buyers recognize you.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Casepal SOC 2 compliant?
Casepal is SOC 2 compliant. On SOC2C this listing is Listed.
Is Casepal ISO 27001 certified?
According to Casepal's public trust center, Casepal is ISO 27001 certified. On SOC2C this listing is Listed.
Is Casepal GDPR compliant?
According to Casepal's public trust center, Casepal is GDPR compliant. On SOC2C this listing is Listed.
Can I use Casepal's SOC 2 for a vendor risk assessment?
Yes. Casepal's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Casepal penetration tested?
Casepal hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Casepal secure?
Security isn't a single yes/no, but Casepal is SOC 2 compliant and holds ISO 27001, GDPR. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Casepal have a bug bounty or vulnerability disclosure program?
Casepal hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@casepal.co or via a /security page (Casepal lists a security contact).
Who are Casepal's subprocessors?
Casepal lists 13 subprocessors on its trust center, including GitLab, Google Cloud Platform, MongoDB Atlas, Vanta, Twingate. Buyers use this for fourth-party risk review.
Where does Casepal host or store data?
Casepal hosts on GCP. Data residency details are on its trust center.
Where is Casepal's trust center or security page?
Casepal's trust center is at https://trust.casepal.co. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Does casepal use my legal documents or conversations to train its models?
No, we do not use your legal documents, conversations, or any client data to train our models. We maintain strict data isolation and have a firm policy against using customer data for model training or improvement purposes to ensure complete confidentiality and compliance with legal professional obligations.
Where is casepal data stored?
Under EU Data Center Residency, the compute infrastructure and all Customer Content (production data, backup data and metadata) is hosted within the EU by default.
How do you handle the data we collect?
All production data is encrypted at rest and in transit. We also ensure to retain customer data in as few places as possible and for a short retention timeline.
Where can I find information about casepal's uptime and downtimes?
Check out our Status Page. This will give you the ability to subscribe for updates, view uptimes, be notified of any outages, and view historical data.
What privacy/security settings are available?
We offer comprehensive data control settings allowing you to manage temporary file retention (default 15 minutes), anonymise personally identifiable information (PII), request data exports of your account information, and permanently delete your account data.
Where are your servers located?
Our servers are located in Frankfurt, Germany, ensuring compliance with EU data protection regulations and providing robust data residency options for our users.
Do general-purpose AI providers (like OpenAI, Anthropic) have access to or retain my data when using casepal?
No, general-purpose AI providers cannot access or retain your data when using casepal. We maintain strict Business Associate Agreements (BAA) and Zero Data Retention (ZDR) agreements with our general-purpose AI providers, ensuring that all data is processed ephemerally and automatically deleted after each request is completed.
How does casepal ensure the security of its cloud infrastructure and protect customer data?
We are an Ecosystem Partner of Google Cloud and we are leveraging their enterprise-grade cloud services hosted solely within the EU and with ISO 27001 and SOC 2 Type II certifications. We implement multiple security layers including end-to-end encryption, regular security audits, and strict access controls. Our cloud architecture is designed for high availability while ensuring data isolation, and we maintain comprehensive data processing agreements with all our infrastructure providers to guarantee data privacy and security compliance.