Security
Immigration data is some of the most sensitive personal information there is. ImmPilot treats it that way, at every layer of the platform.
TLS 1.2+ in transit and AES-256 at rest for every byte of client and case data.
Passwordless magic links, TOTP MFA, and SSO / SAML on Enterprise plans.
Granular roles for RCICs, paralegals, admins, and clients — enforced at the database.
Row-level security policies verify every read and write against the requesting user's role and tenant.
Every action, actor, and timestamp captured in an immutable audit log with export.
Continuous point-in-time backups with tested restore procedures and 30-day retention.
Documented RTO/RPO with cross-region redundancy for Enterprise deployments.
Every firm is fully isolated at the database and storage layer — no shared rows, no shared files.
Data hosted on Canadian infrastructure by default, with region selection for Enterprise.
PIPEDA-aligned data handling, minimum-necessary collection, and configurable retention windows.
SOC-2 controls, DPA on request, sub-processor list, and vulnerability disclosure program.
SOC-2 Type II attestation and ISO 27001 alignment in progress. Documented status shared on request.
ImmPilot secures the platform, infrastructure, and default controls. Your firm is responsible for administering user access, enforcing your internal policies, and handling client data within your legal and professional obligations. We publish configuration guidance to help you meet your responsibilities.
Enterprise customers receive a Data Processing Agreement (DPA), sub-processor list, and access to compliance documentation upon request.
Our team is happy to walk through architecture, controls, and compliance in detail.
Talk to our team