BorderPass Logo
    Security and data protection

    Security at BorderPass

    BorderPass is designed, operated and independently reviewed to protect some of the most sensitive documents a person owns.

    Schools and employers completing a vendor assessment can request the full security documentation.

    Controls

    Access and network

    Restricted by default

    Production application access is limited to authorised users. Privileged access to the production network requires a business need. The network is segmented to prevent unauthorised access to customer data. Firewall rulesets are reviewed at least annually and intrusion detection runs continuously.

    People

    Who works on files

    New employees undergo background checks. Employees and contractors sign confidentiality agreements and acknowledge a code of conduct. Security awareness training is completed within thirty days of hire and annually thereafter. Access is revoked on termination.

    Data

    Retention and disposal

    Formal retention and disposal procedures govern how data is kept and destroyed. A data classification policy restricts confidential data to authorised personnel. Customer data is purged from the application environment when a customer leaves the service.

    Vulnerabilities

    Scanned and remediated

    Host-based vulnerability scans run at least quarterly across all external-facing systems. Critical and high findings are tracked to remediation. Infrastructure is patched on a routine schedule and in response to identified vulnerabilities.

    Governance

    Oversight and risk

    Risk assessments are performed at least annually and account for fraud. The board is briefed annually on cybersecurity and privacy risk. Vendor agreements carry confidentiality and privacy commitments. Cybersecurity insurance is maintained.

    Legal counsel

    BorderPass provides the tools and the structured workflow. The regulated review of an application is performed by licensed counsel, who carry professional obligations of their own.

    Regulation

    Accountable to a law society

    Applications are reviewed by lawyers licensed to practise. Each is accountable to the law society or bar that licenses them, and must maintain good standing under that regulator’s conduct rules, continuing professional development requirements, and annual reporting.

    Insurance

    Professional liability coverage

    Practising lawyers carry professional liability insurance as a condition of their licence. That coverage sits alongside the cybersecurity insurance BorderPass maintains at the company level.

    Confidentiality

    A duty owed to the regulator

    Client information held by a licensed lawyer is subject to the duty of confidentiality imposed by their regulator. That duty is independent of the platform’s own access controls and confidentiality agreements, and it survives them.

    For schools and employers

    Schools

    Student information

    Applicant records are classified, restricted to authorised personnel, and governed by formal retention and disposal procedures. Institutions running a vendor assessment can request the SOC 2 Type II report, the control set, and the subprocessor list, and BorderPass can complete a HECVAT for institutional review.

    Employers

    Employee and company information

    Work permit and LMIA files hold employee personal data alongside payroll, organisational and other commercial information. The same access restrictions, confidentiality agreements and retention procedures apply across both, and access is limited to authorised users with a business need.

    Trust Center

    For vendor security reviews

    Schools and employers running a vendor assessment can request access to the documents a review needs.

    • SOC 2 Type II report
    • Full control set, with current status
    • Subprocessor list
    • Information Security Policy
    • Access Control Policy
    • Cryptography Policy
    • Data Management Policy
    • Operations Security Policy
    • Asset Management Policy
    • Human Resource Security Policy
    • Third-Party Management Policy
    • Business Continuity and Disaster Recovery Plan
    • Code of Conduct

    Questions about security

    Is BorderPass SOC 2 compliant?

    Yes. BorderPass holds SOC 2 Type II, independently audited, with current status shown on each control in the Trust Center.

    Where does BorderPass store data?

    Primary infrastructure is hosted in Canada.

    Does BorderPass share data with third parties?

    Written agreements with vendors and third parties include confidentiality and privacy commitments. The full subprocessor list is available in the Trust Center.

    Who can access immigration documents submitted through BorderPass?

    Production application access is limited to authorised users, and privileged network access requires a business need. Employees and contractors sign confidentiality agreements, complete security awareness training, and have access revoked on termination.

    What happens to data when an account closes?

    Customer data containing confidential information is purged from the application environment when a customer leaves the service, under formal retention and disposal procedures.

    Can BorderPass complete a HECVAT?

    Yes. Institutions running a vendor assessment can request a completed HECVAT alongside the SOC 2 Type II report and control set.

    Who reviews an application?

    A licensed lawyer, accountable to the law society or bar that licenses them, carrying professional liability insurance and bound by a professional duty of confidentiality.

    How do I report a security issue?

    Write to security@borderpass.ai. Reports made in good faith are welcome.

    How do I get BorderPass security documentation?

    Request access to the BorderPass Trust Center. Approved reviewers receive the SOC 2 Type II report, the full control set with current status, the subprocessor list, and ten policy documents.

    Running a vendor review?

    Request access to the audit report, control set, subprocessor list, and policy documents.