Security

Executor data is handled with case-scoped access, private storage, and explicit legal-boundary messaging.

Data isolation

Case-scoped data access is enforced with RLS policies and role-based permissions.

Document protection

Sensitive files are stored privately and accessed through short-lived signed links.

Least privilege

Collaborator roles are scoped to what each person should view or edit.