What we do today to protect confidential case files.
Case files are hosted by InjuryAgent on encrypted, access-controlled infrastructure. Finished work product is delivered into your firm’s own cloud storage. What follows are our design commitments — the controls the platform is built around today.
InjuryAgent is early. We describe what the platform does today and what is planned; we don’t claim certifications we don’t hold. If a control below matters to your review, ask us how it’s implemented and we’ll show you.
The controls the platform is built around.
Each item below is a product-level constraint we can demonstrate today — not a certification claim.
Encryption in transit and at rest
TLS on every connection between browser, application, storage, and model providers. Case files and database records are encrypted at rest by the storage provider.
Row-level access controls
Access is enforced at the row level in the database. Cross-firm and cross-matter reads are structurally prevented, not policy-gated.
Client-consented, revocable access
A claimant grants explicit consent before any firm sees their file, and can revoke it at any time. Consent state is part of the record.
Per-delivery audit logging
Every document delivery, every model call, and every attorney approval is written to a per-matter audit log the firm can read.
Least-privilege internal roles
InjuryAgent staff do not access firm data by default. Production access requires named authorization, is time-bounded, and is recorded.
OAuth tokens stored server-side only
Tokens for connected storage (e.g. Dropbox for work-product delivery) are held server-side and never exposed to the browser.
A provider-abstraction layer, not a single-vendor lock.
Every model call goes through a ModelProvider interface. A firm can point the secondary slot at a self-hosted or firm-controlled endpoint without changing any workflow.
- Primary slot
- Lovable AI Gateway
- Secondary / firm-BYO slot
- Available on request
Status reflects this deployment’s live configuration.