Trust and security
Last updated 1 September 2026. Self-hosting and evidence control are part of why teams pay. “No default evidence egress” does not mean the host never makes a network request.
Evidence and licensing
Case evidence stays on customer infrastructure. License validation is for entitlement and host binding. Typical check-in data includes license identifier, host-binding material, and entitlement state. Case evidence, artifacts, and investigation notes are not included in license validation traffic.
AI egress
AI is off by default. A local model stays in-environment. An approved external provider can receive selected prompts and context only when enabled. Optional OpenCTI/MISP lookups occur only when configured.
Operations you own
TLS termination, operating-system maintenance, backups, recovery, disk encryption, and log retention are customer responsibilities unless a signed agreement says otherwise. CaseScope does not currently advertise a certified evidence-at-rest encryption module.
Supported versions
Current production source 4.26.13 and the prior supported release as listed on Releases.
Vulnerability disclosure
Email security@casescope.net with a short summary only. Do not send exploit PoCs, full evidence dumps, or customer data through the public website form or ordinary email until we arrange a channel. We will acknowledge and provide a safer path for sensitive detail. Incident notification to customers, if any, will be defined in a signed agreement.
Dependencies
Third-party components (EVTX tooling, Hayabusa, Volatility3, Zeek, and libraries) remain under their own licenses. A component list can be discussed with licensed customers; this page is not an SBOM.