Clear controls for data, access and operations
Security in CASAI is explained through architecture, controls and responsibilities — not superlatives. Here is an overview. Full security documentation is provided in procurement and customer dialogue.
Data storage and operations in Sweden
Swedish hosting region
CASAI is hosted in Microsoft Azure in Sweden, in the Sweden Central region.
Backup and disaster recovery
Backup and disaster recovery are located in the Sweden South region.
Safe restore
The database supports point-in-time restore 14 days back, with long-term retention of backups for up to one year.
Protection against mistakes
Versioning and soft delete in storage mean data is not lost through missteps.
Encryption and key management
In transit
All traffic is encrypted with TLS 1.2 or later.
At rest
Data is encrypted at rest with transparent data encryption (TDE) in the database and storage-level encryption (SSE).
Key management
Encryption keys are managed in Azure Key Vault, with support for customer-managed keys.
Network protection
Private endpoints, a web application firewall (WAF) and DDoS protection.
Identity and access
Identity platform
Identities are managed in Microsoft Entra ID.
Role-based access
Access is governed with role-based access control so users only see what they should.
Protected administration
Multi-factor authentication and conditional access are used for privileged access, with time-limited administrator rights.
System identities
Services authenticate with managed identities instead of stored secrets.
Monitoring and incident management
Continuous monitoring
Operations and security are monitored with Azure Monitor, Application Insights, Microsoft Defender for Cloud and Microsoft Sentinel, including database auditing.
Annual penetration tests
The platform is penetration tested annually by an external party.
Documented incident process
Incidents are handled according to a documented process with service levels.
Secure development
Development follows a secure development process with review before deployment.
Responsibilities, data protection and documentation
Data protection
Personal data is handled under a data processing agreement. A list of sub-processors is provided in the data protection dialogue.
The customer's responsibility
The customer is responsible for its user administration, configuration and content in the service.
Documentation on request
Security appendix, data processing agreement, completed security review templates and a technical walkthrough with your IT function.
This overview is based on CASAI's version-controlled security documentation. Details are provided in procurement and customer dialogue — some information is not published openly for security reasons.
Frequently asked questions about security
Where is our data stored?
CASAI is hosted in Microsoft Azure in Sweden, in the Sweden Central region. Backup and disaster recovery are located in Sweden South. Questions about sub-processors are handled in the data protection dialogue before contract signing.
Does CASAI support single sign-on (SSO)?
Not at present. Customer-facing SSO is not yet available in CASAI. Please let us know if SSO is a requirement for you, and we will include it in the dialogue about your setup.
Can we receive security documentation for procurement?
Yes. We provide a security appendix, a data processing agreement and completed security review templates, and we run technical walkthroughs with your IT or security function when needed.
Request security documentation
Contact us and we will share the security appendix, data processing agreement and completed review templates, and book a technical walkthrough if needed. Email: info@casai.io. Phone: +46 8 528 00 102.
