ImmPilotImmPilot
Trust center

Enterprise-grade trust for immigration practices

Security, privacy, availability, and AI governance — designed for firms that answer to regulators, clients, and their own conscience.

Trust pillars

Twelve pillars, one platform

Every technical control translates to a concrete business outcome.

Enterprise security

Continuous scanning, hardened infrastructure, and secure-by-default engineering. Business benefit: fewer surprises, cleaner procurement reviews.

Privacy protection

Client data belongs to your firm. We process only what's required — never for AI training. Business benefit: defensible client confidentiality.

Tenant isolation

Every firm operates in an isolated tenant enforced at the database layer via row-level security. Business benefit: no accidental data leaks across firms.

Role-based access control

Granular RCIC, associate, paralegal, and administrator roles with least-privilege defaults. Business benefit: right people, right data, always.

Encryption

TLS in transit; AES-256 at rest for database and file storage. Business benefit: data protected on the wire and on disk.

Audit logging

Every meaningful action is logged with actor, timestamp, and payload. Business benefit: defensible answers when regulators or clients ask.

Backup strategy

Automated encrypted backups with point-in-time restore and documented recovery runbooks. Business benefit: real recoverability, not just checkbox backups.

Monitoring

24/7 platform monitoring, alerting, and incident response. Business benefit: issues found before your clients notice.

Canadian hosting

Data stored and processed in Canadian regions. Business benefit: meets firm and client residency expectations.

Disaster recovery

Documented DR plan with tested recovery objectives. Business benefit: your practice keeps running through infrastructure failures.

AI governance

Human-in-the-loop by design. AI produces suggestions with citations; RCICs sign off. Business benefit: keeps regulatory responsibility with the licensed practitioner.

Compliance roadmap

SOC 2 Type II in progress, PIPEDA alignment, and DPA on request. Business benefit: a credible enterprise procurement story.
Trust FAQ

Answers procurement will ask

  • Your firm. We are the processor; you are the controller. Data can be exported at any time.

  • In Canadian regions of our cloud provider, with encryption in transit and at rest.

  • No. Client data is never used to train foundation models. AI usage is scoped per case and logged.

  • SOC 2 Type II is in progress. We can share our current security overview, DPA, and sub-processors under NDA on request.

  • Database-layer row-level security policies gate every read and write by tenant_id. Isolation is enforced by the database, not the application.

  • You keep access to export your data for a defined window. We then delete on schedule per your DPA.

Operating company

Who you're contracting with

ImmPilot is the product brand. All commercial, contractual, billing, and legal responsibility sits with our operating company.

Operating company
Canadian International Business Development CORP
Product brand
ImmPilot
Jurisdiction
British Columbia, Canada
Registered office
Vancouver, British Columbia, Canada
Commercial responsibility
All subscriptions, invoices, receipts, and legal agreements are issued by Canadian International Business Development CORP.
Related

Compliance & Audit Readiness

See how ImmPilot supports professional record keeping, standardized workflows, and audit preparedness across your practice.

Ready for procurement review?

Request our trust package

Security overview, DPA, sub-processors, and architecture diagrams for your compliance team.

No credit card required • Setup in minutes • Secure Canadian cloud infrastructure