Turn incidents into audit-ready evidence packs — fast.

CasePack helps MSPs run consistent incident reporting across tenant workspaces, collect artifacts, build response timelines, and generate client/auditor-ready reports and evidence packs in minutes.

Built with MSP design partners
Self-host (Docker/K8s)
Evidence stored in your S3-compatible object store
SSO via Keycloak
Report templates and audit-friendly exports
Tenant RBAC controls
CasePack Dashboard — incident tracking and evidence management

The MSP problem

Why incident documentation is broken

Incidents live in tickets... evidence lives everywhere.

Scattered screenshots, logs in email, IOCs in chat. Good luck finding it all when you need it.

Deadlines and documentation are hard to standardize across tenants.

Every tenant workspace has different requirements. Every incident becomes a fire drill.

Clients, insurers, and auditors want a clear story + proof.

They don't want your ticket history. They want a timeline, evidence, and a professional report.

Outcomes

What you get out of CasePack

Consistent incident workflow per tenant

Same process, every time. No more ad-hoc scrambles.

One-click Evidence Pack export (PDF/ZIP)

Timeline, artifacts, and audit log in a professional bundle.

Timeline + roles + audit trail

Track who did what, when, and which actions each role can take.

Less email chaos

Share links, send requests, get approvals — all in one place.

Minutes to produce a pack
Fewer back-and-forths

How it works

From incident to evidence pack in 5 steps

Step 01

Intake from PSA ticket / webhook

Automatically create a case from your existing PSA workflow. No double-entry — webhooks watch for new tickets and create incidents automatically.

Step 02

Build the response timeline

Record what happened, who acted, and which response phase each event belongs to. The report narrative forms while the team works.

Step 03

Upload artifacts

Logs, screenshots, IOCs, emails — store everything in one place with full version history and tamper-evident audit trail.

Step 04

Generate the right report

Choose triage, executive, final evidence pack, or NIS2 notification templates and preview the result before producing files.

Step 05

Export the Evidence Pack

PDF report, ZIP bundle, manifest, and audit log — generated in one click. Hand the pack to your client or their auditor and move on.

Features

See CasePack in action

Built by MSPs, for MSPs. Every screen is designed to save you time.

See everything at a glance

KPIs, open incidents, recent evidence, and overdue milestones — all on one screen. Know exactly where every tenant workspace stands.

Product

Two products, one mission

Start with the Reporting Kit. Add the Client Portal when you need it.

Available now

Incident Reporting Kit

Everything you need to document incidents professionally and consistently.

  • Deadline milestones (NIS2-style)
  • Response timeline events
  • Report templates and previews
  • Tenant-level RBAC
  • Evidence pack export
  • Audit-friendly role controls
Coming soon

Client Evidence Portal

A secure portal for clients to upload documents and sign off on reports.

  • Secure client upload links
  • Document requests
  • Sign-off workflows
  • Fewer email threads

Integrations

Connects to your stack

PSA-first by design, with storage and identity paths for hosted and self-hosted deployments.

PSA

CW
ConnectWiseAvailable
HP
HaloPSAAvailable
AT
AutotaskAvailable
WH
Generic webhookAvailable

Storage

S3
SeaweedFS / S3-compatible storage
RG
Ceph RGW or AWS S3
PG
Postgres

Identity

KC
Keycloak
SS
SSO-ready
Start PSA-first. Add SIEM ingestion when the operational workflow is ready for it.

FAQ

Common questions

No. CasePack sits beside your SIEM/EDR/PSA. It turns incident work into a consistent report and evidence pack without replacing your tooling.

No. CasePack compliments your PSA. Intake can start from a PSA ticket or webhook. CasePack adds a structured incident workspace and exportable deliverables.

CasePack Self-Hosted Connected is recruiting a private MSP design-partner cohort for the supported Docker Compose / Podman profile. Your PostgreSQL and S3-compatible evidence storage remain on your infrastructure.

Not for the Reporting Kit. The portal is optional and designed for secure client uploads and approvals.

A professional Evidence Pack (PDF/ZIP) with timeline, artifacts list, and audit log, ready for clients, insurers, or auditors.
Still have questions? Book a demo

Ready to streamline incident documentation?

Start building audit-ready evidence packs in minutes.

Plans start at €149/mo. Cancel anytime.

We reply within 48h. No spam.Private design-partner preview