Trust center

Enterprise-grade trust for immigration practices

Security, privacy, availability, and AI governance — designed for firms that answer to regulators, clients, and their own conscience.

Trust pillars

Twelve pillars, one platform

Every technical control translates to a concrete business outcome.

Enterprise security

Continuous scanning, hardened infrastructure, and secure-by-default engineering. Business benefit: fewer surprises, cleaner procurement reviews.

Privacy protection

Client data belongs to your firm. We process only what's required — never for AI training. Business benefit: defensible client confidentiality.

Tenant isolation

Every firm operates in an isolated tenant enforced at the database layer via row-level security. Business benefit: no accidental data leaks across firms.

Role-based access control

Granular RCIC, associate, paralegal, and administrator roles with least-privilege defaults. Business benefit: right people, right data, always.

Encryption

TLS in transit; AES-256 at rest for database and file storage. Business benefit: data protected on the wire and on disk.

Audit logging

Every meaningful action is logged with actor, timestamp, and payload. Business benefit: defensible answers when regulators or clients ask.

Backup strategy

Automated encrypted backups with point-in-time restore and documented recovery runbooks. Business benefit: real recoverability, not just checkbox backups.

Monitoring

24/7 platform monitoring, alerting, and incident response. Business benefit: issues found before your clients notice.

Canadian hosting

Data stored and processed in Canadian regions. Business benefit: meets firm and client residency expectations.

Disaster recovery

Documented DR plan with tested recovery objectives. Business benefit: your practice keeps running through infrastructure failures.

AI governance

Human-in-the-loop by design. AI produces suggestions with citations; RCICs sign off. Business benefit: keeps regulatory responsibility with the licensed practitioner.

Compliance roadmap

SOC 2 Type II in progress, PIPEDA alignment, and DPA on request. Business benefit: a credible enterprise procurement story.
Trust FAQ

Answers procurement will ask

  • Your firm. We are the processor; you are the controller. Data can be exported at any time.

  • In Canadian regions of our cloud provider, with encryption in transit and at rest.

  • No. Client data is never used to train foundation models. AI usage is scoped per case and logged.

  • SOC 2 Type II is in progress. We can share our current security overview, DPA, and sub-processors under NDA on request.

  • Database-layer row-level security policies gate every read and write by tenant_id. Isolation is enforced by the database, not the application.

  • You keep access to export your data for a defined window. We then delete on schedule per your DPA.

Ready for procurement review?

Request our trust package

Security overview, DPA, sub-processors, and architecture diagrams for your compliance team.

Canadian hostingTenant-isolated by design24/7 monitoring