CaseFlow Automation Ltd operates LegalDocs-Assist, a SaaS platform that helps UK legal practitioners working in RTA (including credit hire), Employers’ & Public Liability, housing disrepair, and clinical negligence to analyse insurer and defendant correspondence, draft responses, and produce structured case documents — all supported by AI cross-referenced against a curated legal knowledge base.
Security and privacy are built into the platform's architecture, not bolted on. Our approach is grounded in data minimisation, privacy by design, and honest framing of what our controls achieve and where their limits lie.
Key Facts
âś… Encryption: TLS in transit; AES-256 at rest; per-tenant data isolation via Row-Level Security.
âś… Access: Role-based access control, invite-only registration, concurrent session detection, email-verified authentication.
âś… Privacy: Privacy-by-design data handling: browser-side text extraction from source documents and a mandatory server-side PII masking gateway before any text reaches the AI. No client data used for AI model training.
âś… AI Safety: Closed knowledge base, anti-hallucination controls, human-in-the-loop design. AI is decision-support only.
âś… Compliance: UK GDPR / DPA 2018 alignment; ICO registered (ZC013423); DPIA-ready architecture.
LegalDocs-Assist is a browser-based SaaS platform for UK legal practitioners across four practice areas: RTA (including credit hire), Employers’ & Public Liability, housing disrepair, and clinical negligence. Core features include:
| In Scope | Out of Scope |
|---|---|
| Web application (portal), server-side API functions, AI inference layer, data storage, PII masking gateway, authentication system | Client endpoints and devices, client on-premises networks, third-party integrations chosen by the client |
The platform is hosted in the European Union via managed cloud infrastructure. Data residency is EU-based.
| Role | Entity | Scope |
|---|---|---|
| Controller | Client organisation | Determines the purposes and means of processing claim data |
| Processor | CaseFlow Automation Ltd | Processes data on behalf of the client to provide the Service |
| Controller | CaseFlow Automation Ltd | Platform account data (user credentials, usage logs) |
Lawful basis: Contractual necessity for providing the Service; legitimate interest in providing efficient legal support tools.
| Class | Examples | Handling |
|---|---|---|
| Public | Marketing materials, published case law | Standard controls |
| Internal | Platform configuration, usage statistics | Access control, logging |
| Confidential | Correspondence content, case details, AI outputs | Encrypted at rest, RLS isolation, PII masking before AI processing |
| Restricted | Personal identifiers in uploaded correspondence | Masked before AI processing; original text stored in client's isolated partition only |
Layer 1: Browser‑side and server‑side text handling of source documents. Text‑based PDFs are read in the user's browser and only the extracted text is transmitted, for the drafting tools and for the Witness Statement document slots alike. Word and plain‑text documents submitted to the document slots are reduced to text on the server and masked before any AI processing. Three documented exceptions apply where an original file does reach the server: (i) scanned or image‑only documents, briefly processed so the text can be read at all; (ii) photographs and audio recordings submitted to the document slots, which the AI reads directly because there is no text to mask first; and (iii) the Medical Pagination tool (see its own section below). All exception paths run under Zero Data Retention terms, prompts and outputs are not stored by the AI provider, and the platform's automated deletion controls apply.
Layer 2: PII Masking Gateway. Before any text is sent to the AI model, it passes through a mandatory server-side masking gateway covering 16 verified categories: personal names (titled names always; bare / untitled names in high-precision contexts such as field labels, salutations and sign-offs), email addresses, UK phone numbers, National Insurance numbers, NHS numbers (Mod 11 validated), HMRC tax identifiers (Unique Taxpayer References and PAYE references), UK driving licence numbers, vehicle registration marks (VRMs), IBANs, credit and debit card numbers (Luhn-checked), sort codes, bank account numbers, dates of birth (in context), policy and claim references, and street addresses. Detected items are replaced with neutral placeholders such as [NAME_REDACTED], [NHS_REDACTED], [UTR_REDACTED] or [VRM_REDACTED]. An additional aggressive output-side re-scrub runs on AI responses to catch bare First-Last name pairs that slipped past the input gateway, with guards for case citations (X v Y) and known organisation names.
UK postcodes are deliberately preserved. Postcodes are material to BHR locality arguments in credit hire and to venue analysis in housing disrepair; masking them would degrade legal output. Two safeguards make this safe: (i) the AI provider's enterprise terms prohibit training on inputs or outputs, and (ii) an output-side scrubber (postcodeScrubber.ts) strips any postcode appearing in the AI response that was not present in the original input, preventing fabricated locality data.
The masking gateway is mandatory and a strong first layer, but it is pattern‑based and not a perfect filter. We do not claim full redaction or guaranteed coverage; users are asked to send only what the task needs. Every AI‑facing function that receives text invokes the masking gateway before the model call; there is no text path that bypasses it. Inputs that arrive as scans, photographs or audio cannot be masked before reading, because masking requires text. Those paths are documented exceptions protected by Zero Data Retention terms and automated deletion, and any structured fields they produce are masked again in later drafting steps. Each invocation logs the count and categories of items masked. Original values are never logged.
Where the AI runs and what happens to the output. AI drafting and generation happens on our server — that is where the model runs — under the Lovable AI Gateway's Zero Data Retention terms (the provider does not retain or train on the data). The generated output is produced on our server and then deleted shortly after it is returned to the user, not retained. We do not claim that nothing ever touches our servers; the AI output does, briefly.
Party names in the Witness Statement Generator. In the Witness Statement Generator, the party names entered on the form (claimant, defendant, witnesses) are passed to the model so the statement attributes evidence to the correct person. In the analysis tools, titled and labelled names are masked like any other identifier.
AI provider terms. The AI provider operates under the Lovable AI Gateway's Zero Data Retention terms, in force since March 2026: prompts and model responses are not retained by the provider and are not used to train any model.
⚠️ Honest Limitation: Pattern‑based detection cannot catch every possible PII format. A bare name buried in free prose with no surrounding cue may pass the input gateway and is caught, if anywhere, by the aggressive output re-scrub; novel reference formats and data that is only identifiable in combination may also not be detected. The masking gateway acts as an automated safety net — it is not a guarantee — and users are asked to send only what the task needs.
The medical pagination feature is the single deliberate exception to our local-only PDF processing principle. Source PDFs uploaded for this feature are briefly stored in a private, access-controlled storage bucket while the feature processes them. Source PDFs are deleted as soon as the pagination completes, whether successful or not. The output bundle PDF is available for you to download for up to one hour from creation. As soon as you successfully download the bundle, the file is removed from our storage. If for any reason it is not downloaded within an hour, it is automatically deleted by our scheduled cleanup. Our audit records retain the fact that a bundle was generated, but never the content itself.
LegalDocs Assist is designed not to retain personal case data. Uploaded source documents and the outputs the tool generates (witness statements, paginated bundles, chronologies, timelines, advice, correspondence) are deleted shortly after they are produced or on session close, and a scheduled purge runs continuously as a backstop so case content is never retained beyond 24 hours. Controllers are expected to download or save their own copy of any output they need, and to re‑run the tool if needed. Medical‑bundle pagination files are deleted within roughly one hour of completion. Inactive login sessions expire automatically. The only data retained is the minimal account record needed to run the subscription; activity and audit logs are retained as stated elsewhere in this document.
Backups. Uploaded documents and generated bundles are not included in these backups. The database has standard disaster‑recovery backups, but because case content is deleted within 24 hours those backups hold essentially no personal case data, and once a record is deleted there is nothing to restore it from.
Special category (health) data. The Service routinely processes special‑category health data (medical records, injury, treatment) for clinical‑negligence and personal‑injury work. Safeguards: browser‑side processing of source documents, server‑side PII masking before any text reaches the AI, encryption in transit and at rest, and immediate deletion within 24 hours. As data controller, the firm is responsible for the Article 9 lawful basis.
Deletion semantics. Deletion on the platform is immediate and permanent. When a record or document is deleted it is removed from the live database and, where it has associated files, from storage. Deleted storage objects are not held in any backup and cannot be restored.
Account deletion. An individual user account can be deleted on request. The user's profile and account data are removed. Case content created under the controller's tenant remains under the controller's control until the controller deletes it or the contract ends.
Firm-level (tenant) erasure. On contract termination, or on a verified erasure request, we permanently delete the controller's tenant: all case content, witness statements, chronologies, correspondence, generated documents and the associated storage objects, together with the user accounts. This action runs only via a hardened admin path executed by CaseFlow Automation Ltd platform administrators — controllers cannot self-delete a tenant — and requires the tenant to be archived first as a reversible step, then permanently deleted from the archived list as a second gate. It is recorded in a tenant_deletion_audit row that holds only the fact of deletion, who performed it, when, and the row and object counts, never the deleted content itself. The only data retained is the minimal account and billing record required by law, and the Data Processing Agreement audit history, both stripped of unnecessary personal data. This is a contractual commitment honoured operationally, not an automated platform feature.
On termination. On contract termination the tenant is archived immediately; the archive remains reversible for thirty (30) days as a grace period, then permanently deleted from the archived list as a second gate. Tenant erasure is executed within thirty (30) days of contract termination unless the controller requests earlier execution. Statutory account and billing records are retained for the limitation period and then deleted.
Under UK GDPR, data subjects have the rights of access, rectification, erasure, restriction, portability and objection.
Controller-held data (claimant records). For personal data about the controller's own clients and claimants, the controller fulfils data subject requests. CaseFlow Automation Ltd, as processor, supports the controller in fulfilling those requests, including by deleting or exporting the relevant records on the controller's instruction. The technical capability is in place: RLS-scoped queries scope reads and writes to the controller's tenant, and admin-initiated user and tenant deletion paths execute cascading erasure across the database and storage.
Processor-held account data. For account data CaseFlow Automation Ltd holds as controller (user credentials, usage logs), the data subject may exercise these rights directly by contacting info@caseflowautomation.co.uk. Data subjects also have the right to complain to the Information Commissioner's Office.
Platform data is hosted in the EU. Where AI model inference involves processing outside the UK/EEA, this occurs under the provider's enterprise data processing terms which include Standard Contractual Clauses (SCCs) and prohibit the use of input/output data for model training.
| Control | Implementation |
|---|---|
| Registration | Invite-only. Users must be invited by a platform administrator. No self-registration. |
| Email Verification | Required before first login |
| Password Security | Salted hashing (bcrypt); minimum complexity enforced |
| Session Management | Concurrent session detection. Only one active session per user. Automatic expiry for inactive sessions. |
| Password Reset | Secure token-based reset via email |
| Account Suspension | Administrators can immediately suspend user accounts |
Roles are stored in a dedicated user_roles table, separate from user profiles, and enforced via database-level security functions.
| Role | Access Level |
|---|---|
| Handler / User | Own company's data: analyse, draft, view history |
| Senior | Company-wide visibility of team activity |
| Manager | Company-wide visibility, usage statistics, team management |
| Platform Admin | User management, company administration, platform configuration |
Every database table containing client data enforces Row-Level Security (RLS) policies. These policies are evaluated at the database level on every query and cannot be bypassed by the application layer. A user from Company A cannot access, view, or modify data belonging to Company B, even if they manipulate API requests.
AI is used exclusively for decision-support. It drafts, analyses, and suggests. It never makes legal decisions, sends correspondence, or takes autonomous action.
| Feature | AI Role | Human Role |
|---|---|---|
| Witness Statement Generator | Draft a CPR Part 32-compliant statement from structured user inputs | Review, verify factual accuracy, sign with statement of truth |
| Correspondence Analyser | Identify insurer/defendant arguments and cited cases in incoming correspondence | Review, verify, decide response strategy |
| Reply Generator | Draft response cross-referenced against curated case law | Edit, approve, send |
| Liability Assessment | Evaluate accident statement and apportion liability indicatively against authorities | Apply professional judgement, decide strategy |
| Impecuniosity Assessment | Apply the 10-step financial ruleset to claimant statements and supporting documents | Review reasoning, verify documents, decide strategy |
| Case Advice | Provide structured strategic guidance on case posture and next steps, grounded in the curated knowledge base | Treat as decision-support; apply professional judgement |
| Medical Pagination (clinical negligence) | Combine, deduplicate and paginate medical record files into a single bundle | Review bundle and dedupe report before disclosure |
| Clinical Negligence Chronology | Build a date-ordered chronology from medical records and correspondence | Verify dates, content and clinical attribution; finalise narrative |
| Disrepair Chronology (housing disrepair) | Build a date-ordered chronology with severity flags from supplied records | Verify dates and content, finalise narrative |
Every AI output is presented as a draft requiring human review. Users must explicitly accept a disclaimer acknowledging this before accessing AI features.
| Control | Implementation |
|---|---|
| Closed Knowledge Base | AI can only cite cases from a curated, pre-loaded database. It is explicitly instructed not to cite anything outside this set. |
| Explicit System Prompts | Directives including "Do NOT invent case names", "Only cite cases from the provided knowledge base", "If no authority exists, say so." |
| Low Temperature | temperature: 0.3 on all AI calls, reducing creative output and favouring factual responses |
| Knowledge Isolation | GTA claims receive only GTA protocol data; non-GTA claims receive case law only. No cross-contamination of authority sources. |
| Mandatory Limitation Language | When no relevant authority exists, the AI states this explicitly rather than speculating |
⚠️ No AI system can guarantee zero hallucination. These controls significantly reduce the risk, but users should always independently verify case law citations before relying on them.
| Log Type | Content | PII Included? |
|---|---|---|
| Activity Log | Feature usage events with timestamps, user IDs, company IDs | No |
| PII Masking Log | Count and categories of items redacted per invocation | No. Original values are never logged. |
| Authentication Log | Login events, session creation, concurrent session detection | Email addresses (for identification) |
| Error Logs | Application and function errors | Designed to exclude PII |
In the event of a suspected security or AI safety incident:
| Capability | Implementation |
|---|---|
| Database Backups | Automated daily backups with point-in-time recovery; encrypted backup storage |
| Data Redundancy | Managed by cloud infrastructure provider with multi-availability-zone resilience |
| Service Recovery | Stateless server-side functions can be redeployed rapidly; no single point of failure in the processing layer |
| Graceful Degradation | If AI inference is unavailable, the platform's non-AI features (case law library, templates, liability guide, guidance notes) remain operational |
| Data Portability | Client data can be exported on request |
⚠️ Honest Limitation: CaseFlow does not currently maintain a formalised Business Continuity Plan (BCP) or conduct scheduled DR exercises. Recovery capabilities are provided by the underlying managed cloud infrastructure. We are evaluating formal BCP documentation as the platform matures.
CaseFlow uses a limited number of third-party services to deliver the platform:
| Sub-Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Managed Cloud Database Provider | Data storage, authentication, server-side function execution | All platform data (encrypted at rest, RLS-isolated) | EU |
| AI Model Provider (via managed gateway) | AI inference for text analysis and generation | Masked text only (PII redacted before transmission) | May include US/EU; under enterprise DPA with SCCs |
| Email Delivery Service | Transactional emails (invitations, password resets) | Email addresses, first names | EU/US; under DPA |
| Web Hosting / CDN | Static asset delivery | No personal data | Global CDN |
All sub-processors operate under data processing agreements. Client notification will be provided for material changes to the sub-processor list.
| Regulation / Framework | Status |
|---|---|
| UK GDPR / DPA 2018 | Aligned: data minimisation, privacy by design, transparency, accountability, lawful basis documented |
| ICO Registration | Registered (ZC013423) |
| EU AI Act (Decision-Support) | Aligned: human-in-the-loop design, AI outputs labelled as drafts, disclaimers enforced |
| ISO/IEC 27001 | Not certified. Controls are aligned with key domains (see mapping below). Formal certification is under consideration as the platform scales. |
| Cyber Essentials | Under consideration for future certification |
| Domain | Controls Implemented | Evidence / Reference |
|---|---|---|
| Access Control | RBAC, RLS, invite-only registration, session management | Database policies; Admin panel |
| Cryptography | TLS in transit, AES-256 at rest, salted password hashing | Infrastructure configuration |
| Operations Security | Activity logging, PII masking logs, usage dashboards | Activity log table; Admin dashboards |
| Supplier Relationships | Limited sub-processor set; DPAs in place | Sub-processor register (§10) |
| Incident Management | Feature-level kill switches, audit trail, notification procedures | Incident response plan (§8.3) |
| Business Continuity | Automated backups, PITR, stateless architecture | Infrastructure provider capabilities |
| Data Protection | Privacy-by-design data handling, server-side PII masking, data minimisation, no training on client data | PII Masking Architecture document |
| Area | CaseFlow Responsibility | Client Responsibility |
|---|---|---|
| Platform & Infrastructure | Secure hosting, encryption, monitoring, patching | — |
| Identity & Access | Authentication system, RBAC enforcement, session controls | Manage user invitations, remove leavers promptly, enforce strong passwords |
| Data Protection | Encryption, RLS isolation, PII masking, no-training policy | Classify data appropriately; redact/anonymise sensitive data before upload where possible |
| AI Usage | Anti-hallucination controls, closed knowledge base, disclaimers | Review all AI outputs before use; do not treat drafts as verified legal advice |
| Endpoints & Devices | — | Secure devices, keep browsers updated, use trusted networks |
| User Training | Platform guidance, in-app tooltips, onboarding materials | Ensure users understand the tool's purpose and limitations |
| Document | Purpose |
|---|---|
| AI Safety & Security Policy | Detailed AI governance, anti-hallucination controls, prompt security, and user safeguards |
| How We Protect Your Data | Plain-English, step-by-step walkthrough of what happens to your data |
| Data & AI Summary | One-page summary of data processing and AI usage |
| Privacy Policy | Full privacy policy including lawful basis, rights, and contact details |
| PII Masking Architecture: Technical Summary | DPIA-ready technical reference for the PII masking gateway |
| Technical Overview | Architecture, AI capabilities, and security at a glance for procurement audiences |
| Term | Definition |
|---|---|
| RLS | Row-Level Security. Database-level access control that restricts which rows a user can read or modify. |
| PII | Personally Identifiable Information. Data that can identify a natural person. |
| RBAC | Role-Based Access Control. Access permissions determined by assigned roles. |
| GTA | General Terms of Agreement. ABI protocol governing credit hire rates. |
| BHR | Basic Hire Rate. Insurer argument challenging hire charges based on local availability. |
| PITR | Point-in-Time Recovery. Ability to restore a database to a specific moment. |
| SCCs | Standard Contractual Clauses. EU-approved mechanism for international data transfers. |
| DPA | Data Processing Agreement. Contract governing how a processor handles personal data. |
| DPIA | Data Protection Impact Assessment. Risk assessment required for high-risk processing. |
For security-related enquiries, DPIA collaboration, or to request further technical detail:
Email: info@caseflowautomation.co.uk
ICO Registration: ZC013423
Website: legaldocs-assist.co.uk
This document is designed to be honest and specific about our security posture. We describe what we have implemented, acknowledge where we have limitations, and commit to continuous improvement as the platform matures. Trust is earned through transparency, not theatre.