Casewave
SECURITY

Your clients' information,
handled carefully.

You're putting your book into someone else's software. That's a real decision, and it deserves a real answer rather than a padlock icon.

Here is what we hold, what we don't, who can read it, and what we will never do with it.

WHAT WE DON'T KEEP

The safest data is data we don't have

Some of this is deliberate absence, not protection.

We don't store signed documents

Executed carrier forms stay in DocuSign, which is the system of record. Casewave keeps a reference and a status, not a copy of the document your client signed.

Access is temporary and logged

When you need to view an executed document to submit it, Casewave issues a link that works once and expires. Every time one is issued, it's recorded.

Casey never asks for the sensitive numbers

Social security numbers, bank account details, and driver's license numbers are never collected in conversation. When a carrier form needs them, they're entered in DocuSign instead.

ENCRYPTION

Encrypted field by field

Not one lock on the whole building.

Sensitive fields are each encrypted individually with AES-256-GCM, and every ciphertext is bound to the specific record it belongs to, so a value copied out of one client's record cannot be decrypted anywhere else. Encryption keys are issued per account and narrowed further by purpose, so no single key opens everything.

ENCRYPTED TODAY

  • Client dates of birth
  • Policy numbers
  • Agent notes on a client
  • Intake questionnaire responses

A client's intake answers are encrypted under their own key, separate from your other client data.

ACCESS

The app can't read your data on its own

Decryption is a separate, audited step.

Casewave's application cannot decrypt anything by itself. Reading an encrypted field requires a separate service running in an isolated environment that holds the only credential capable of it. That split is the point: if the application were compromised, it still could not read your book.

AUTHENTICATED

Every decryption request is verified and tied to the account making it, so a valid session cannot reach another agent's data.

LIMITED

Requests are rate-limited, which bounds how much could be reached even with a stolen session.

RECORDED

Every decryption writes an audit record noting who, which record, and when. Never the value itself.

THE ASSISTANT

What Casey is, and isn't

Written into the product and into the terms, in the same words.

She tells your clients she's an AI.

Casey identifies herself as an AI assistant at the start of every conversation and stays identifiable throughout. The wording in the product matches the wording in our terms.

She doesn't give advice.

Casey gives no insurance advice and makes no recommendations. When a client asks whether they have enough coverage or which product to choose, she routes them to you.

We're not a licensed producer.

Casewave is a technology provider. We are not a carrier, not an agency, not the agent of record, and not a licensed producer.

Conversations get cleaned up.

After a request completes, identifying details are removed from the conversation while the record of what was requested and what was done is kept.

OUR POSITION

We don't sell your data. We don't want to.

Casewave does not sell customer data, share it for advertising, use it to train AI models, or package it into data products. This isn't a default we inherited. It's a decision we made deliberately and wrote into our terms.

Your book is your business asset. It stays that way.

PROGRAM

The unglamorous parts

What's in place behind the product.

Written security program

A documented information security program covering how we handle and protect data.

Incident response plan

A written plan with a named individual responsible for it.

Automated security scanning

Every code change is automatically scanned for exposed secrets, vulnerable dependencies, insecure code, and misconfigured infrastructure.

Published terms

Our privacy policy, agent terms, client portal terms, and acceptable use policy are public.

Vulnerability reporting

A published address for reporting a security issue, monitored by a person.

QUESTIONS

Common questions

What agents ask before putting a book into new software.

Is Casewave SOC 2 certified?

No. We're an early-stage company and we're not going to claim a certification we don't hold. What we can tell you is exactly how the system is built, which is what this page is for.

Can Casewave employees read my clients' information?

Reading an encrypted field requires going through a separate, audited decryption service, and every request it serves is recorded.

Who else touches my data?

The third-party services Casewave relies on are listed on our subprocessors page, which we keep current. See our subprocessors →

What happens to the documents my clients sign?

They stay in your DocuSign account, under your retention settings. Casewave doesn't keep a copy.

Does Casey train on my clients' conversations?

No. We don't use customer data to train AI models.

Who owns my book of business?

You do. Casewave is software you use to manage it.

START SELLING MORE

Give up servicing for good.