← Casebound

Trust

Security at Casebound

Effective August 10, 2026

Casebound uses tenant-scoped authorization, administrator-issued school roles, private object storage, encrypted transport, versioned database migrations, a least-privilege runtime database role, audit events, rate limits, security headers, monitoring hooks, and tested CI checks.

Report a vulnerability

Email emersonmeade29@gmail.com with the subject “Casebound security report.” Include the affected URL, reproduction steps, impact, and a safe contact method. Do not access student data, disrupt service, use social engineering, or publish details before we have had a reasonable opportunity to remediate.

Response commitment

We aim to acknowledge good-faith reports within two business days, triage critical issues within one business day, and provide status updates through remediation. Good-faith research consistent with this policy will not be pursued as unauthorized access by Casebound.

Assurance status

Independent penetration testing and formal audit attestations are not yet complete. Casebound will provide current evidence and will not represent planned controls or certifications as finished.