BorderPass is designed, operated and independently reviewed to protect some of the most sensitive documents a person owns.
Schools and employers completing a vendor assessment can request the full security documentation.
Production application access is limited to authorised users. Privileged access to the production network requires a business need. The network is segmented to prevent unauthorised access to customer data. Firewall rulesets are reviewed at least annually and intrusion detection runs continuously.
New employees undergo background checks. Employees and contractors sign confidentiality agreements and acknowledge a code of conduct. Security awareness training is completed within thirty days of hire and annually thereafter. Access is revoked on termination.
Formal retention and disposal procedures govern how data is kept and destroyed. A data classification policy restricts confidential data to authorised personnel. Customer data is purged from the application environment when a customer leaves the service.
Host-based vulnerability scans run at least quarterly across all external-facing systems. Critical and high findings are tracked to remediation. Infrastructure is patched on a routine schedule and in response to identified vulnerabilities.
Risk assessments are performed at least annually and account for fraud. The board is briefed annually on cybersecurity and privacy risk. Vendor agreements carry confidentiality and privacy commitments. Cybersecurity insurance is maintained.
BorderPass provides the tools and the structured workflow. The regulated review of an application is performed by licensed counsel, who carry professional obligations of their own.
Applications are reviewed by lawyers licensed to practise. Each is accountable to the law society or bar that licenses them, and must maintain good standing under that regulator’s conduct rules, continuing professional development requirements, and annual reporting.
Practising lawyers carry professional liability insurance as a condition of their licence. That coverage sits alongside the cybersecurity insurance BorderPass maintains at the company level.
Client information held by a licensed lawyer is subject to the duty of confidentiality imposed by their regulator. That duty is independent of the platform’s own access controls and confidentiality agreements, and it survives them.
Applicant records are classified, restricted to authorised personnel, and governed by formal retention and disposal procedures. Institutions running a vendor assessment can request the SOC 2 Type II report, the control set, and the subprocessor list, and BorderPass can complete a HECVAT for institutional review.
Work permit and LMIA files hold employee personal data alongside payroll, organisational and other commercial information. The same access restrictions, confidentiality agreements and retention procedures apply across both, and access is limited to authorised users with a business need.
Schools and employers running a vendor assessment can request access to the documents a review needs.
Yes. BorderPass holds SOC 2 Type II, independently audited, with current status shown on each control in the Trust Center.
Primary infrastructure is hosted in Canada.
Written agreements with vendors and third parties include confidentiality and privacy commitments. The full subprocessor list is available in the Trust Center.
Production application access is limited to authorised users, and privileged network access requires a business need. Employees and contractors sign confidentiality agreements, complete security awareness training, and have access revoked on termination.
Customer data containing confidential information is purged from the application environment when a customer leaves the service, under formal retention and disposal procedures.
Yes. Institutions running a vendor assessment can request a completed HECVAT alongside the SOC 2 Type II report and control set.
A licensed lawyer, accountable to the law society or bar that licenses them, carrying professional liability insurance and bound by a professional duty of confidentiality.
Write to security@borderpass.ai. Reports made in good faith are welcome.
Request access to the BorderPass Trust Center. Approved reviewers receive the SOC 2 Type II report, the full control set with current status, the subprocessor list, and ten policy documents.
Request access to the audit report, control set, subprocessor list, and policy documents.