Last updated 14 September 2026
Security and data protection
Where your data lives
- Application data is stored in Supabase on AWS in eu-west-1 (Ireland).
- Meeting capture through Recall.ai is pinned to the EU (eu-central-1).
- Casily is operated from Ireland by an Irish company. There is no non-EU parent.
Isolation between workspaces
- Every table carrying customer data has row-level security enabled — 45 of 45 tables in the application schema.
- Access is scoped to workspace membership and enforced in the database, not only in the application.
Transcripts and retention
- Casily extracts the proof-relevant passages from a transcript and can then discard the raw transcript.
- Three settings per workspace: discard after extraction, keep for seven days, or keep indefinitely. New workspaces default to discarding the raw transcript after extraction; workspaces created earlier keep the setting they chose.
- Raw text is only discarded once extraction has succeeded, so nothing is lost silently.
- Extracted passages are retained. Those are kept.
Files and exports
- Uploaded files and workspace exports are held in private storage buckets. Neither is publicly readable.
- Downloads use signed, time-limited URLs: one hour for proof files, five minutes for exports. Export archives are deleted after seven days.
- Video poster images are served from our own domain, so opening a proof page sends nothing to any video provider.
Credentials
- API keys and webhook secrets for connected tools are encrypted at rest with AES-256-GCM.
- Tokens issued for the MCP connector are stored hashed, never in plaintext.
Audit trail
- Workspace activity is written to an append-only audit log that cannot be edited or deleted from the application.
- Logged events include member changes, internal approvals, every customer approval action, testimonial requests, document exports, retention changes, integration connections, and deletion requests.
Deletion
- Workspace deletion is owner-only and requires typing the workspace name. Connected provider webhooks are revoked before any data is removed, and deletion stops if revocation fails.
- Outstanding customer approval, testimonial and invite links are invalidated.
- Account deletion removes memberships, connected-tool credentials, issued tokens and the user record.
Analytics and error reporting
- Casily runs no third-party analytics and no session recording. No behavioural or usage tracking is sent to any third party.
- If a page fails to load, the error and the page path are reported to Lovable, our hosting provider, so the fault can be diagnosed. No proof content, transcript content or customer records are included.
Two-factor authentication
- Two-factor authentication using an authenticator app is available to every user in Settings. A second authenticator can be added as a backup. Recovery codes are not offered.
- Workspace owners can require two-factor authentication for all members of their workspace, and an owner can reset a member's factors if they lose their device.
What we don't have yet
- Casily has not completed a SOC 2 or ISO 27001 audit.
- Penetration testing has not been carried out by a third party.
The third parties that may process customer data on our behalf are listed on our sub-processor list. For security questions or a DPA, email philip@casily.ai.