Secure content management for regulated organisations

Keep sensitive content useful.
Keep control of what happens to it.

Casewelt stores, shares and governs sensitive business files, with policy-aware access, lifecycle controls and a queryable record of each important action.

  • OIDC identity
  • Named external recipients
  • Inbound file requests
  • Retention & legal hold
  • Queryable audit
  • API & webhooks
Live Casewelt portal: Secure Room 1 GOVERNED workspace, workspaces and folders in the sidebar, Recent, Favorites and Removed views, and a file list showing size, added date and a Hold badge.

UK company Product of Sial Networks Limited

OIDC Organisation identity through the customer’s identity provider

API & signed webhooks Automation on a documented contract

Privacy-first website No advertising or analytics cookies

Product

Four controls around the same object.

SECURE CONTENT

Sensitive files stay in a governed working lifecycle.

Each object keeps its organisation, folder and version identity as it moves through normal work.

Platform overview →
EXTERNAL SHARING

Share the document without exposing the workspace.

Named recipients, version binding, expiry and revoke.

Secure sharing →
GOVERNANCE

Retention, classification and hold stay on the object.

Delete decisions can then consult the same lifecycle state instead of relying on a separate administrative process.

Lifecycle controls →
AUDIT

Ask “who opened it?” directly against the product record.

Actor, object, version and decision remain connected to the event.

Auditability →

Product evidence

The current portal Files surface.

Captured 25 August 2026 from the live portal. Inbox, activity, search, favorites and inbound file requests sit with the governed workspace. Organisation branding is tenant-configured. Bytes still come from Casewelt, not a storage URL.

Live Casewelt portal: Secure Room 1 GOVERNED, list view with search, folder actions and Upload, showing file size, added date and a file held under legal hold.
AVAILABLEGOVERNED workspaceAPI-backed listBytes in object store

Lifecycle

One file. One governed lifecycle.

Create

A workspace object is created with organisation, folder and version identity. Policy can control who may create it, and the event records the actor and timestamp.

PDFQ4 Board Pack.pdfNew object · Board & Governance

Classify

Classification lives on the object itself, so the organisation’s label remains attached to the file and can be used by later policy decisions.

Policy can require a label before share. Evidence: classification set or changed.

PDFQ4 Board Pack.pdfRestrictedRestricted

Share

External access is represented as a share object with a named recipient, known version and explicit expiry.

Policy can allow or deny create-share. Evidence: share created or policy_denied.

Verify recipient

The recipient proves control of the intended mailbox before content is served. External access stays separate from employee identity and workspace navigation.

Policy can require verification before bytes. Evidence: recipient proof events.

Open

Opening the file is an authorised action against a specific version. A valid session can still be denied by policy.

Evidence: opened, version, decision.

11:04 Opened Q4 Board Pack.pdf · version 3 · ALLOW

Revoke

Revocation ends the share or session directly. Subsequent attempts are denied and remain visible in the event record.

Policy can require revoke on incident.

Retain

Retention rules stay attached to the object and determine how long it must remain before disposition can proceed.

Policy can block early delete. Evidence: retain / dispose decisions.

Retention
7-year policy

Hold

Legal hold pauses lifecycle deletion while the object remains available under normal access policy. Applying the hold and blocking deletion are both recorded.

DeleteQ4 Board Pack.pdfBLOCKED

Audit

The product record can be queried directly by actor, object, version, decision and outcome.

Opened v3ALLOW

External collaboration

Share the document. Not the workspace.

A Casewelt share names the recipient, points to a known version, carries its own lifetime and can be revoked independently of staff access. External recipients use a separate trust surface and never inherit workspace navigation.

How secure sharing works

Safe failure

Security is easiest to see when something must stop.

A useful security demo includes a denial. Casewelt records blocked and rejected actions alongside successful ones, so the control boundary can be inspected directly.

DENIED

External share

Policy does not permit this file to be shared externally.

BLOCKED

Delete under legal hold

A hold prevents lifecycle deletion.

STOPPED

Revoked session

The active user session no longer has authority.

REJECTED

Placement conflict

The requested operation conflicts with regional placement controls.

PDF
Q4 Board Pack.pdfGovernance stays on the object
Classification
Restricted
Retention
7-year policy
Legal hold
Off
Delete
Allowed

Governance

Governance stays with the content.

Policy controls whether an action is allowed now. Retention defines how long the content must remain. Hold pauses deletion when preservation is required. Each control acts on the same file but answers a different operational question.

Lifecycle controls

Who opened this file?External recipient · v3 · ALLOW

Which policy allowed it?create-share evaluated

When was access revoked?Share ended · later open DENIED

Audit & evidence

“Who opened it?” should be a query.

Search the product record by actor, object, version and decision to answer the question directly.

Explore auditability

Integrations

Works with the systems you already operate.

The public integration contract is currently protocol-level. Casewelt supports OIDC-compatible identity providers, structured events, signed webhooks, HTTP APIs and machine identities with mTLS. Vendor-specific integrations should be named only after they are shipped and tested.

Identity

  • OIDC-compatible identity providers

SIEM / observability

  • Structured events
  • Signed webhooks

Key management

  • Envelope encryption in the product
  • Customer-managed key backends: architecture direction

Automation

  • HTTP API
  • Machine principals / mTLS

Use cases

Built for sensitive workflows.

BOARD

Board & executive

Share board packs with auditors without exposing internal workspaces.

LEGAL

Legal

Holds, retention and controlled sharing while preserving evidence.

Security architecture

Built so the control model can be inspected.

OIDC, tenant isolation, envelope encryption, session revocation, mTLS for machine identities, an append-oriented audit model, signed webhooks. Customer-managed keys and regional cells are deployment decisions reviewed against the customer’s environment and requirements.

Next step

Bring us one sensitive-content workflow.

We can walk through how Casewelt would handle access, sharing, lifecycle governance and audit for a real workflow.