Skip to main content
Security & trust

Security posture, in plain language.

This page is maintained by Mortivo to answer common security and privacy questions about Mortivo CaseCheck. It reflects current, in-force controls only.

Scope note. This page is not an independent certification. It states current, enabled controls and practices; it does not claim regulatory compliance or third-party audit outcomes. Where a control is provided by an underlying platform, that shared responsibility is called out.

Access & authentication

  • Each firm is a separate tenant. Data cannot be read across tenant boundaries.
  • User accounts have defined roles (adviser, reviewer, admin) with permission checks on every action.
  • Sign-in is via email and password. Additional authentication factors are on the near-term roadmap.
  • Administrative access to production data by Mortivo staff is limited, logged and reason-tracked.

Data handling

  • Uploaded documents are stored in tenant-isolated object storage.
  • Direct document reads always go through short-lived signed URLs — never public links.
  • Extracted facts and case data are held in a database with row-level access controls tied to the tenant and role of the caller.
  • During the controlled beta, CaseCheck operates on fictional data only. A tenant-level flag prevents production data being used until it is explicitly enabled through a documented approval procedure.

Encryption

  • Traffic to and within the platform is protected with modern TLS.
  • Data at rest is encrypted using the underlying platform's managed encryption.
  • Application-layer field encryption is under review as part of ongoing data-protection work.

Hosting & subprocessors

CaseCheck runs on the Lovable Cloud platform, which uses Supabase (on AWS) for data storage and an AI gateway for model inference. Hosting region is selected within the UK/EU where the underlying platform plan supports it. The current subprocessor list and their roles are available on request from privacy@mortivocasecheck.co.uk.

Audit logging

  • Case, document and finding activity is captured in an append-only audit trail.
  • Each entry records who acted, when, and against which case or document.
  • AI-generated findings record the rule and prompt version they were produced under.

Backups & continuity

  • The underlying database platform provides point-in-time recovery within the plan-defined window.
  • Recovery objectives and business-continuity procedures are documented internally and reviewed on a scheduled cycle.

Reporting a vulnerability

If you believe you have found a security issue, please contact us at security@mortivocasecheck.co.uk. Please include enough detail to reproduce the issue and refrain from public disclosure while we investigate.