Trust
Security at Casebound
Effective August 10, 2026
Casebound uses tenant-scoped authorization, administrator-issued school roles, private object storage, encrypted transport, versioned database migrations, a least-privilege runtime database role, audit events, rate limits, security headers, monitoring hooks, and tested CI checks.
Report a vulnerability
Email emersonmeade29@gmail.com with the subject “Casebound security report.” Include the affected URL, reproduction steps, impact, and a safe contact method. Do not access student data, disrupt service, use social engineering, or publish details before we have had a reasonable opportunity to remediate.
Response commitment
We aim to acknowledge good-faith reports within two business days, triage critical issues within one business day, and provide status updates through remediation. Good-faith research consistent with this policy will not be pursued as unauthorized access by Casebound.
Assurance status
Independent penetration testing and formal audit attestations are not yet complete. Casebound will provide current evidence and will not represent planned controls or certifications as finished.