Security

Security your clients can trust

Immigration data is some of the most sensitive personal information there is. ImmPilot treats it that way, at every layer of the platform.

Encryption

TLS 1.2+ in transit and AES-256 at rest for every byte of client and case data.

Authentication

Passwordless magic links, TOTP MFA, and SSO / SAML on Enterprise plans.

Role-Based Access Control

Granular roles for RCICs, paralegals, admins, and clients — enforced at the database.

Authorization

Row-level security policies verify every read and write against the requesting user's role and tenant.

Audit Logs

Every action, actor, and timestamp captured in an immutable audit log with export.

Backups

Continuous point-in-time backups with tested restore procedures and 30-day retention.

Disaster Recovery

Documented RTO/RPO with cross-region redundancy for Enterprise deployments.

Tenant Isolation

Every firm is fully isolated at the database and storage layer — no shared rows, no shared files.

Canadian Hosting

Data hosted on Canadian infrastructure by default, with region selection for Enterprise.

Privacy

PIPEDA-aligned data handling, minimum-necessary collection, and configurable retention windows.

Compliance

SOC-2 controls, DPA on request, sub-processor list, and vulnerability disclosure program.

Compliance Roadmap

SOC-2 Type II attestation and ISO 27001 alignment in progress. Documented status shared on request.

Shared responsibility

ImmPilot secures the platform, infrastructure, and default controls. Your firm is responsible for administering user access, enforcing your internal policies, and handling client data within your legal and professional obligations. We publish configuration guidance to help you meet your responsibilities.

Enterprise customers receive a Data Processing Agreement (DPA), sub-processor list, and access to compliance documentation upon request.

Have a security question?

Our team is happy to walk through architecture, controls, and compliance in detail.

Talk to our team