Security & trust
Security posture, in plain language.
This page is maintained by Mortivo to answer common security and privacy questions about Mortivo CaseCheck. It reflects current, in-force controls only.
Scope note. This page is not an independent certification. It states current, enabled controls and practices; it does not claim regulatory compliance or third-party audit outcomes. Where a control is provided by an underlying platform, that shared responsibility is called out.
Access & authentication
- Each firm is a separate tenant. Data cannot be read across tenant boundaries.
- User accounts have defined roles (adviser, reviewer, admin) with permission checks on every action.
- Sign-in is via email and password. Additional authentication factors are on the near-term roadmap.
- Administrative access to production data by Mortivo staff is limited, logged and reason-tracked.
Data handling
- Uploaded documents are stored in tenant-isolated object storage.
- Direct document reads always go through short-lived signed URLs — never public links.
- Extracted facts and case data are held in a database with row-level access controls tied to the tenant and role of the caller.
- During the controlled beta, CaseCheck operates on fictional data only. A tenant-level flag prevents production data being used until it is explicitly enabled through a documented approval procedure.
Encryption
- Traffic to and within the platform is protected with modern TLS.
- Data at rest is encrypted using the underlying platform's managed encryption.
- Application-layer field encryption is under review as part of ongoing data-protection work.
Hosting & subprocessors
CaseCheck runs on the Lovable Cloud platform, which uses Supabase (on AWS) for data storage and an AI gateway for model inference. Hosting region is selected within the UK/EU where the underlying platform plan supports it. The current subprocessor list and their roles are available on request from privacy@mortivocasecheck.co.uk.
Audit logging
- Case, document and finding activity is captured in an append-only audit trail.
- Each entry records who acted, when, and against which case or document.
- AI-generated findings record the rule and prompt version they were produced under.
Backups & continuity
- The underlying database platform provides point-in-time recovery within the plan-defined window.
- Recovery objectives and business-continuity procedures are documented internally and reviewed on a scheduled cycle.
Reporting a vulnerability
If you believe you have found a security issue, please contact us at security@mortivocasecheck.co.uk. Please include enough detail to reproduce the issue and refrain from public disclosure while we investigate.