Security & trust

Control where it matters. Visibility where it helps.

Caseflow combines authenticated access, server-enforced permissions, tenant boundaries, and durable workflow history for benefits implementation work.

01

Authentication

Identity is established through Clerk before Caseflow evaluates application access.

  • Protected account sessions
  • Authenticated server routes
  • Organization membership verification
  • Platform staff verification
02

Authorization

Permissions are enforced against Caseflow records and tenant relationships on the server.

  • Role-aware capabilities
  • Assignment-based visibility
  • Viewer read-only boundaries
  • Broker and company separation
03

Operational history

Important workflow activity stays visible beside the work it affects.

  • Workbook activity history
  • Comment resolution history
  • Support ticket activity
  • Billing audit events
04

Data boundaries

Caseflow is designed around company-scoped workflows and minimal sensitive data collection.

  • Company-level data separation
  • No SSNs required
  • No PHI required
  • Purpose-limited profile data
05

Protected history

Renewals create connected plan years instead of rewriting the record of prior work.

  • Historical workbooks remain intact
  • New plan year per renewal
  • Intentional copy-forward
  • Traceable implementation changes
06

Responsible claims

Security documentation should reflect implemented controls without overstating certifications or guarantees.

  • Clear product boundaries
  • Transparent data practices
  • Ongoing platform review
  • Direct support channel

Need more detail?

Talk through your access model with us.

We can walk through roles, collaboration boundaries, and the data Caseflow is designed to hold.