CaseCounsel
The legal operations platform for in-house teams

The AI-first front door for the business.

CaseCounsel is where every legal request starts — and ends. Casey answers what she can from your own playbooks, escalates what needs you, and reviews every invoice from outside counsel against your billing guidelines.

Prototype build · no credit card · Auth0 SSO

app.legaltech.test/dashboard
CaseCounsel dashboard with in-house legal metrics, active matters, and recent requests

Built on

Next.js 15FastAPIAuth0 OrganizationsGemini + AnthropicAES-256-GCM envelope encryption

The product in 60 seconds

Three things in-house teams stop doing manually.

Spend control

Budgets, optional RFPs, and AI-reviewed invoices against your billing guidelines. Approve, reduce, or reject line-by-line — with comments that go straight back to the instructing firm.

Spend deep-dive

Casey, your AI conduit

Casey triages new requests, drafts answers from your playbooks, surfaces similar matters, and reviews invoices. Deterministic dummy mode by default; opt into live Gemini with an explicit key.

AI deep-dive

Business Portal + knowledge base

Your own business teams raise requests and self-serve answers. An intake becomes a matter in two clicks — or never needs to become one.

Portal deep-dive

Every capability, one platform

Built for how in-house legal actually works.

Nine capabilities shipped, tested, and wired end-to-end — from the first business request to a paid invoice from outside counsel.

Intake from the business

Product, commercial, and operations teams raise requests through the Business Portal. Casey triages severity and type; the in-house inbox filters by urgency in one click.

Casey answers first

Before a matter opens, Casey drafts a suggested answer and surfaces similar past matters plus relevant playbooks from your knowledge base. Most requests never need external counsel.

Matter management

Every matter holds docs, emails, tasks, budgets, and invoices in one place. Status lifecycle, lead lawyer, external counsel connections. Soft-delete with audit continuity.

Knowledge that stays fresh

Playbooks, opinions, and precedent — authored internally, tagged, and filtered by visibility (business-facing vs. legal-only). Casey flags stale articles when newer ones are uploaded.

Budget approval + RFP

Structured scoping and budget approval before instructing a firm. Optional RFP across a panel. No more scattered email threads and spreadsheet tracking.

AI invoice review

Incoming invoices from external firms are checked line-by-line against your billing guidelines. Block billing, rate caps, disallowed tasks — flagged before you read a single line.

External counsel portal

Instructed firms get a separate Law Firm Portal with per-matter scoping. They submit time, draft invoices, and see your responses without touching your in-house system.

Encrypted at rest

AES-256-GCM envelope encryption. Per-tenant DEK wrapped by a master KEK. HMAC lookup hashes for equality search without plaintext.

Multi-tenant RBAC

Auth0 Organizations for SSO. Configurable roles over a shipped permission catalog. Audit events on every mutation.

The Business Portal

Give the business a front door to legal.

No more forwarded emails and shadow Slack threads. Product managers, commercial leads, and operations raise structured requests, see the timeline, and find answers in your internal knowledge base before they ever need a lawyer's time.

Business-user view

/business/requests/…
Business user viewing their legal request on the Business Portal

In-house inbox

/requests
In-house legal requests inbox with Casey triage and suggested answers

Secure by design

Legal data never sits in plaintext.

Envelope encryption, tenant-isolated keys, RBAC, and audit logging are foundational — not an upsell.

AES-256-GCM at rest

Per-tenant DEK wrapped by a master KEK. PII columns encrypt transparently via a SQLAlchemy TypeDecorator.

Auth0 Organizations

SSO per legal team. Tenant identity from a verified JWT claim — never a request body.

Permission-scoped RBAC

Shipped permission catalog + configurable roles per team. Every route gates on a code.

Immutable audit trail

Every mutation lands in audit_events with actor + path + request ID. No plaintext PII in logs.

OWASP ASVS L2

Input validation at every boundary. 401 vs 403 never blurred. Strict CSP + HSTS posture.

No secrets in git

gitleaks + dependency audits on every PR. KEK moves to Azure Key Vault at cutover.

Pricing

Per-seat SaaS. Indicative tiers today.

Every feature ships in every tier — the split is seat count and support depth. Real billing turns on at production launch; the current page is indicative.

FAQ

Frequently asked

Ready to see it in action?

Book a 20-minute walkthrough. We'll show you the Business Portal, Casey's suggested answers, and AI-reviewed invoices on a real matter.