Legal
Confidentiality & Security Statement
Last updated: 17 August 2026
This page exists so that a firm’s IT provider, risk partner or compliance reviewer can assess CaseWax without a call. It is written to answer the questions a standard vendor security questionnaire asks. Anything here can be verified by installing the software on a machine with no network connection.
1. Summary for reviewers
CaseWax is a single Windows desktop application. It performs document search, question answering and call transcription entirely on the computer it is installed on. There is no server component, no user account, no cloud tenancy and no data transfer to us or to any third party as part of normal use.
Consequently, most controls that a questionnaire is designed to test — data centre security, encryption in transit, sub-processor lists, breach notification for hosted data, data residency, deletion on termination — have no subject matter here. We hold none of your data at any point.
2. What data the software touches
- Your documents. Read in place from folders you nominate (PDF, Word, plain text). They are not copied into application storage, moved, or transmitted.
- A local index. The application stores derived data about your documents on the same machine so it can search by meaning. This is encrypted and bound to the Windows user account, and is unreadable if copied to another computer.
- Call audio and transcripts. Captured from your microphone and system audio only while you have recording running, processed locally, and written to disk on the same machine.
- Your questions and answers. Generated and retained locally. We have no mechanism to see them.
3. Network behaviour
The application is designed to run with no internet connection, including on a machine that has never been connected. Language model inference runs on local hardware, so there is no API call to a model provider and no prompt or document content leaves the device.
Licence activation is offline as well. The licence key is validated on the machine itself. No activation server is contacted, at first run or at any point afterwards, and there is no periodic re-validation call. A machine that is permanently air-gapped can be licensed and can keep working indefinitely.
There is no telemetry, no analytics SDK, no crash or error reporting, and no usage reporting of any kind. We do not know what you asked, which files you hold, or whether you opened the program today, because nothing is sent for us to know it from.
Windows itself will continue to make its own network connections — operating system updates, Defender, time synchronisation and so on — entirely independently of this software. If you run a packet capture during evaluation, that traffic belongs to the operating system, not to CaseWax.
Every claim in this section is testable in about five minutes: install the software on a machine with the network adapter disabled, activate the licence, index a folder and ask a question. We would rather you verified it than took our word for it.
Updates are not fetched either. The application has no update mechanism of its own and never checks a server for a new version. When a new build exists — including one adjusted for your own practice — you are sent an installer directly and you choose whether and when to run it. Your IT provider therefore controls every version change, and nothing is pushed to a machine without a person putting it there.
4. Third parties and sub-processors
None for the desktop software. No analytics SDK, no crash-reporting service, no model API, no storage provider. There is no sub-processor list because there are no sub-processors to list.
Separately, this marketing website is hosted by a third-party host and the enquiry form is delivered through a third-party form service. Those touch only the contact details you choose to type into the form. They never touch case data. See the Privacy Policy.
5. Professional-conduct considerations
Guidance on lawyers’ use of generative AI — ABA Formal Opinion 512 (29 July 2024) in the United States, and comparable guidance from other regulators — is largely concerned with what happens when client confidential information is entered into a tool that transmits or retains it elsewhere, whether the tool trains on inputs, what diligence the firm performed on the vendor, and whether the client must be told and asked.
Because no client information is transmitted to us or to any third party, and because the software does not train on your files, those questions have no transfer to attach to. That is a description of how the software behaves, not legal advice: your obligations under your own rules of professional conduct remain yours to assess, and you should do so.
6. Recording and consent
The transcription feature records only while you start and run it. It does not join meetings as a participant, and it does not notify other attendees, because it is capturing audio on your own machine rather than acting inside the meeting platform.
That places the consent obligation entirely with you. Recording law varies: a number of US states and many other jurisdictions require the consent of every party, and professional guidance generally advises telling a client before recording them regardless of what the statute permits. You should obtain consent exactly as you would for any other recording.
7. Certifications
We do not hold SOC 2, ISO 27001 or equivalent attestation, and we would rather say so plainly than imply otherwise. Those frameworks certify how an organisation safeguards data entrusted to it; the relevant fact here is that no data is entrusted to us. Where a questionnaire has no applicable answer, we are happy to complete it in writing and to say “not applicable — no data transfer” against the items that do not apply.
8. Supplier details
[TO COMPLETE] Legal entity name, registered address, registration number, VAT ID, governing law and jurisdiction, and a named contact with a role. A reviewer will look for this section first; leaving it blank costs more trust than anything else on this page. The same details belong in the imprint.
Built and supported by Roman Havryliuk. Questions from IT providers and risk reviewers are answered directly, not routed through a sales team.