Security Policy
Security Policy
Last Updated: August 25, 2026
Dynamanic LLC operates the CaseLens service (the "Service") for the processing of sensitive legal and eDiscovery data. This Security Policy summarizes the technical and organizational measures we maintain to protect that data. It describes our practices and does not, by itself, constitute a certification or warranty.
1. Encryption
- In transit: all connections to the Service are encrypted with TLS 1.2 or higher.
- At rest: document content and sensitive fields are encrypted using AES-256-GCM with key derivation via HKDF/PBKDF2. Personally identifiable fields can be deterministically encrypted to support secure lookups.
2. Access Control
- Role-based access control (RBAC) enforces least-privilege access to matters and documents.
- Multi-factor authentication (MFA) and single sign-on (SSO) are supported for account access.
- Tenant isolation confines each customer's matters and documents to that customer.
3. Auditability
- Security-relevant actions are recorded in an append-only audit log secured with a per-entry hash chain and HMAC signatures, enabling tamper detection.
- Chain-of-custody records are maintained to support the defensibility of eDiscovery workflows.
4. Data Retention and Deletion
- Customer data is retained for the duration of the engagement and deleted in accordance with our Privacy Policy and Data Processing Agreement, with a default deletion window of 90 days after a deletion request or account termination.
5. Incident Response
- We maintain an incident response process and will notify affected customers of a confirmed personal-data breach without undue delay, consistent with applicable law and our Data Processing Agreement.
6. Compliance Alignment
The Service is designed to support controls aligned with industry frameworks including SOC 2, GDPR, and CCPA. References to such frameworks describe design intent and supporting features; they are not a representation that any specific certification or audit has been completed unless separately stated in writing.
7. Responsible Disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability, please email security@dynamanic.io with details and steps to reproduce. We ask that you give us a reasonable opportunity to remediate before any public disclosure, and we will not pursue action against good-faith research conducted under this policy.
8. Contact
Security questions and vulnerability reports: security@dynamanic.io.
This Security Policy supplements, and is subject to, the Terms of Service and Data Processing Agreement.