Evidence and licensing

Case evidence stays on customer infrastructure. License validation is for entitlement and host binding. Typical check-in data includes license identifier, host-binding material, and entitlement state. Case evidence, artifacts, and investigation notes are not included in license validation traffic.

AI egress

AI is off by default. A local model stays in-environment. An approved external provider can receive selected prompts and context only when enabled. Optional OpenCTI/MISP lookups occur only when configured.

Operations you own

TLS termination, operating-system maintenance, backups, recovery, disk encryption, and log retention are customer responsibilities unless a signed agreement says otherwise. CaseScope does not currently advertise a certified evidence-at-rest encryption module.

Supported versions

Current production source 4.26.13 and the prior supported release as listed on Releases.

Vulnerability disclosure

Email security@casescope.net with a short summary only. Do not send exploit PoCs, full evidence dumps, or customer data through the public website form or ordinary email until we arrange a channel. We will acknowledge and provide a safer path for sensitive detail. Incident notification to customers, if any, will be defined in a signed agreement.

Dependencies

Third-party components (EVTX tooling, Hayabusa, Volatility3, Zeek, and libraries) remain under their own licenses. A component list can be discussed with licensed customers; this page is not an SBOM.