How we protect your data and your clients' information · Updated June 2026
CaseNote Vault's security program is designed to align with the AICPA SOC 2 Trust Service Criteria across all five principles:
Security
System protected against unauthorized access
Availability
System available for operation and use as committed
Confidentiality
Information designated as confidential is protected
Processing Integrity
System processing is complete, valid, and accurate
Privacy
Personal information collected and used per policy
CaseNote Vault conducts regular security reviews to identify and address vulnerabilities before they can be exploited:
If you discover a potential security vulnerability in CaseNote Vault, please report it responsibly to security@casenotevault.com. We will acknowledge reports within 48 hours and work to address confirmed vulnerabilities promptly. We do not take legal action against good-faith security researchers.
Security Contact