See what a professional incident evidence pack looks like
Request a sample CasePack evidence pack or book a 20-minute workflow review to see how CasePack fits next to your PSA, SIEM, EDR, or existing incident process.
The private design-partner preview runs CasePack on your infrastructure with a supported Docker Compose profile while incident data and evidence remain under your operational control.
Some MSPs and security-sensitive clients are not comfortable sending incident evidence, logs, screenshots, exports, or audit records into a generic SaaS tool.
CasePack Self-Hosted Connected is a private design-partner preview for the same core product flow: incidents, evidence, timelines, reports, NIS2 milestones, audit logs, and exports.
A typical self-hosted CasePack deployment includes:
| Component | Default option | Purpose |
|---|---|---|
| CasePack web app | CasePack SPA | Browser user interface |
| CasePack API | CasePack API | REST API, license checks, evidence, reports, exports |
| Database | PostgreSQL 17 | Incidents, tenants, users, audit log, metadata |
| Identity | Keycloak / OIDC | Sign-in and user authentication |
| Object storage | SeaweedFS S3 gateway by default | Evidence files and generated exports |
The first preview supports the bundled single-server Docker Compose / Podman profile with one API replica. Alternative infrastructure and cluster profiles remain demand-gated.
Accepted design partners receive the pinned Compose configuration and guided onboarding.
Clone the self-host wrapper
Copy .env.example to .env
Set required passwords
Enroll with a short-lived code through the protected licensectl prompt
Start the stack with Docker Compose
Sign in with the bootstrap admin account
Create users and tenant workspaces from CasePack administration
Connected is the only mode available in the MVP. Air-Gapped and Broker are documented roadmap seams, not current products.
Connected: daily refresh with a 30-day signed credential continuity window
Air-Gapped: roadmap; no availability date or price
Broker / HA: roadmap; no availability date or price
CasePack stores evidence in S3-compatible object storage. Self-host deployments can use the bundled SeaweedFS S3 gateway or another compatible backend such as Ceph RGW, AWS S3, or another S3-compatible service.
For browser uploads and downloads, configure a browser-reachable public S3 endpoint when the API and users' browsers reach object storage through different routes.
After deploying CasePack, verify the workflow:
Open the CasePack app and sign in as the bootstrap admin
Confirm the API health endpoint is healthy
Create or open the first tenant workspace
Create an incident
Upload a small evidence file
Generate an evidence pack export
Download the export
For production self-host deployments:
| Requirement | Hosted CasePack | Self-hosted CasePack |
|---|---|---|
| Fastest start | Best fit | Possible, but more setup |
| Data residency control | Depends on hosted environment | Stronger control |
| Existing OIDC/Keycloak alignment | Limited/custom | Stronger fit |
| Reference deployment | Managed by CasePack | Single-server Compose / Podman |
| Private object storage | Not required | Supported |
| Security-sensitive clients | Possible | Strongest fit |
CasePack self-host is designed for MSPs that want a controlled incident reporting stack with PostgreSQL, OIDC, S3-compatible evidence storage, audit history, and exportable evidence packs.
Request a sample CasePack evidence pack or book a 20-minute workflow review to see how CasePack fits next to your PSA, SIEM, EDR, or existing incident process.