SecurityPlatform capability

CaseSeal: privilege architecture (roadmap)

Legal files are not ordinary SaaS data. Luthor ships application hardening today and is building CaseSeal (per-matter envelope encryption and lawyer-visible access receipts) without claiming HSM, attested compute, or controls that are not yet independently verified.

Trust as enforceable controls

A privacy policy and a “human in the loop” label are not enough for privileged files. Luthor’s security page states exactly what is protected now, what CaseSeal adds, and which claims wait for independent verification. That honesty is part of the product.

Hardening that is real today

Private buckets, matter-bound privileged reads, database-enforced tenant invariants, header-only bearer auth, content-verified file limits, strict egress redaction, and confidentiality-first AI defaults reduce exposure. They do not make the autonomous server-side agent blind to plaintext, and Luthor will not pretend otherwise.

CaseSeal destination

CaseSeal aims for per-matter envelope encryption and lawyer-visible access receipts. Until those gates are met and independently verified, Luthor describes CaseSeal as the production target, not a checkbox on a homepage, and does not claim HSM or attested compute.