CV
CaseNote Vault™

Data Security

How we protect your data and your clients' information · Updated June 2026

CaseNote Vault is built from the ground up to handle sensitive youth services data responsibly. We implement enterprise-grade security controls appropriate for organizations handling Protected Health Information (PHI), educational records (FERPA), and other sensitive data about the youth and families you serve.

Encryption

  • All data encrypted in transit using TLS 1.2+
  • All data encrypted at rest using AES-256
  • Encryption keys managed with strict access controls
  • Database backups encrypted using the same standards

Role-Based Access Controls

  • Organization Owner — full administrative access
  • Program Admin — program management and reporting
  • Supervisor — approvals, team visibility, compliance
  • Staff — assigned participant records only
  • Auditor — read-only access for reviews

Infrastructure & Isolation

  • Each organization's data is logically isolated
  • No cross-organization data access is architecturally possible
  • Infrastructure hosted on SOC 2-certified cloud providers
  • Regular automated backups with point-in-time recovery
  • Geographic redundancy for high availability

Audit Logging

  • All data access events are logged with user identity
  • All record creation, modification, and deletion logged
  • All document exports and packet generation logged
  • All login and authentication events logged
  • Audit logs are tamper-resistant and retained per policy

Authentication & Sessions

  • Secure session management with automatic expiration
  • Account lockout after failed authentication attempts
  • Secure password requirements enforced
  • Session tokens are cryptographically signed
  • Secure password reset flows with email verification

Incident Response

  • Documented security incident response procedures
  • Breach notification within 72 hours of discovery
  • Dedicated security contact: security@casenotevault.com
  • Post-incident review and remediation processes
  • HIPAA-compliant breach notification procedures

SOC 2 Alignment

CaseNote Vault's security program is designed to align with the AICPA SOC 2 Trust Service Criteria across all five principles:

Security

System protected against unauthorized access

Availability

System available for operation and use as committed

Confidentiality

Information designated as confidential is protected

Processing Integrity

System processing is complete, valid, and accurate

Privacy

Personal information collected and used per policy

Regular Security Reviews

CaseNote Vault conducts regular security reviews to identify and address vulnerabilities before they can be exploited:

  • Periodic internal security assessments and code reviews
  • Dependency and vulnerability scanning for third-party packages
  • Review of access control configurations and permissions
  • Audit log review for anomalous access patterns
  • Annual review of security policies and procedures

Security Vulnerability Reporting

If you discover a potential security vulnerability in CaseNote Vault, please report it responsibly to security@casenotevault.com. We will acknowledge reports within 48 hours and work to address confirmed vulnerabilities promptly. We do not take legal action against good-faith security researchers.

Security Contact