Court-scoped access
Authenticated requests operate in an authorized court context, and court records are queried and changed within that scope.
Security and procurement
Court Nox supports security, accessibility, legal, and procurement diligence with a clear distinction between implemented controls, customer-specific configuration, and roadmap work.
Implemented in the platform
The list below describes current product design and production configuration. A buyer-specific response may narrow, expand, or condition these statements based on deployment, integrations, contract terms, and the records in scope.
Authenticated requests operate in an authorized court context, and court records are queried and changed within that scope.
Server-side role and permission checks protect administrative, judicial, staff, counsel, and platform-level actions.
Court users, counsel, jurors, public responders, and temporary sessions use purpose-specific routes and authorization checks.
Inactive accounts are rejected and session versioning allows previously issued application sessions to be invalidated.
Protected workflows record actor, court, action, result, request context, and timing while designated secret fields are redacted.
Training courts are visibly separated from live courts and server-side policy blocks outbound communications and external integrations.
The production deployment is configured for HTTPS and keeps application, database, and object-storage services behind the public edge.
Demo-generated records use an archive-first reset path so training data can be refreshed without silently deleting its history.
Current assurance status
Requirements vary across state, local, and federal buyers. These statuses prevent a roadmap item from being mistaken for a completed independent assessment or government authorization.
Program underway
WCAG 2.2 Level AA is the product target. A public statement is available; formal evaluation is not yet complete.
Roadmap
The planned package uses the VPAT 2.5Rev WCAG and 508 editions, supported by one documented evaluation program.
Not claimed
Court Nox does not currently represent that it has completed a SOC 2 examination.
Not claimed
Court Nox does not currently represent authorization or compliance under these frameworks. Applicable requirements are evaluated with each buyer.
Procurement workflow
Confirm the court, workflows, users, records, integrations, hosting constraints, and applicable standards.
Answer the buyer questionnaire using the deployed architecture, current controls, contracts, and documented gaps.
Agree on remediation, configuration, data handling, implementation, and acceptance criteria before launch.
Keep approved decisions, security artifacts, accessibility findings, and changes tied to the customer scope.
Buyer questions
For a scoped security questionnaire, data-flow review, or accessibility request, contact info@courtnox.com.
No. Court Nox does not currently claim FedRAMP authorization. We will identify hosting and control gaps plainly when a procurement requires FedRAMP or a state authorization framework.
Not yet. Court Nox has published its current accessibility status and is preparing a testing and remediation program before issuing VPAT 2.5Rev WCAG and 508 Accessibility Conformance Reports.
The application uses court-scoped authorization and data access, with role-aware workflows inside the active court context. The exact deployment and isolation requirements are confirmed during procurement.
Yes. Responses are grounded in the actual deployment and contract scope. Items that are planned, customer-configured, or not currently supported are identified rather than presented as completed controls.
Accessibility program