StropheTrust Center

Trust Center

Compliance

  • GDPR

    GDPR

  • HIPAA

    HIPAA

  • SOC 2 Type II Readiness

    SOC 2 Type II Readiness

  • CSA STAR Level 1

    CSA STAR Level 1

Overview

The Strophe Trust Center describes how we protect customer data, supervise immigration work product, and operate our platform. This page is maintained for customers, partners, and security reviewers.

Security

Strophe uses industry-standard encryption for sensitive data in transit and at rest. Access to production systems is restricted, logged, and limited to personnel with a business need.

  • Encryption for sensitive case and identity data
  • Role-based access across firm client intake, staff, and attorney surfaces
  • Append-only audit logging for material case events

Controls

Mapped controls across infrastructure, organization, product, internal procedures, and data privacy. All listed controls are currently in place.

Infrastructure security

ControlStatus
  • Information security for use of cloud services

    Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization's information security requirements.

  • Information transfer

    Information transfer rules, procedures, or agreements shall be in place for all types of transfer facilities within the organization and between the organization and other parties.

  • Access control

    Rules to control physical and logical access to information and other associated assets shall be established and implemented based on business and information security requirements.

  • Segregation in networks

    Groups of information services, users and information systems shall be segregated on networks.

  • Backup and recovery

    Backup copies of information, software and systems shall be maintained and tested in accordance with the agreed topic-specific policy on backup.

Organizational security

ControlStatus
  • Information security policy

    A set of policies for information security shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals.

  • Roles and responsibilities

    Information security roles and responsibilities shall be defined and allocated according to the organization needs.

  • Security awareness and training

    Personnel of the organization and relevant interested parties shall receive appropriate information security awareness, education and training.

  • Risk assessment

    Information security risks shall be identified, analyzed and evaluated, taking into account the information to be protected.

Product security

ControlStatus
  • Secure development lifecycle

    Rules for the development of software and systems shall be established and applied to developments within the organization.

  • Vulnerability management

    Information about technical vulnerabilities of information systems in use shall be obtained, the organization's exposure to such vulnerabilities shall be evaluated and appropriate measures shall be taken.

  • Authentication and session management

    Secure authentication technologies and procedures shall be implemented based on information access restrictions and the topic-specific policy on access control.

  • Change management

    Changes to information processing facilities and information systems shall be subject to change management procedures.

Internal security procedures

ControlStatus
  • Incident response

    The organization shall establish and communicate information security incident management responsibilities and procedures.

  • Business continuity

    Information security continuity shall be embedded in the organization's business continuity management systems.

  • Supplier relationships

    Processes and procedures shall be defined and implemented to manage the information security risks associated with the use of supplier's products or services.

  • Logging and monitoring

    Logs that record activities, exceptions, faults and information security events shall be produced, stored, protected and analysed.

Data and privacy

ControlStatus
  • Data classification

    Information shall be classified according to the information security needs of the organization based on confidentiality, integrity, availability and relevant interested party requirements.

  • Data retention and disposal

    Records shall be protected from loss, destruction, falsification, unauthorized access and unauthorized release in accordance with legal, regulatory, contractual and business requirements.

  • Privacy by design

    Privacy and protection of personally identifiable information shall be ensured in the design and development of information systems.

  • Consent and notice

    Privacy notices and consent mechanisms shall be provided to data subjects in accordance with applicable privacy requirements.

Data retention

We retain case and intake data according to our privacy program and legal obligations. Inactive matter data that remains in limbo without progression may be deleted after a defined retention period.

Policies

Review our legal and privacy documentation on the main Strophe site:

Contact

For security disclosures, privacy requests, or trust questionnaires, contact security@strophe.com or legal@strophe.com.