
GDPR
HIPAA
SOC 2 Type II Readiness
CSA STAR Level 1
The Strophe Trust Center describes how we protect customer data, supervise immigration work product, and operate our platform. This page is maintained for customers, partners, and security reviewers.
Strophe uses industry-standard encryption for sensitive data in transit and at rest. Access to production systems is restricted, logged, and limited to personnel with a business need.
Mapped controls across infrastructure, organization, product, internal procedures, and data privacy. All listed controls are currently in place.
Information security for use of cloud services
Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization's information security requirements.
Information transfer
Information transfer rules, procedures, or agreements shall be in place for all types of transfer facilities within the organization and between the organization and other parties.
Access control
Rules to control physical and logical access to information and other associated assets shall be established and implemented based on business and information security requirements.
Segregation in networks
Groups of information services, users and information systems shall be segregated on networks.
Backup and recovery
Backup copies of information, software and systems shall be maintained and tested in accordance with the agreed topic-specific policy on backup.
Information security policy
A set of policies for information security shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals.
Roles and responsibilities
Information security roles and responsibilities shall be defined and allocated according to the organization needs.
Security awareness and training
Personnel of the organization and relevant interested parties shall receive appropriate information security awareness, education and training.
Risk assessment
Information security risks shall be identified, analyzed and evaluated, taking into account the information to be protected.
Secure development lifecycle
Rules for the development of software and systems shall be established and applied to developments within the organization.
Vulnerability management
Information about technical vulnerabilities of information systems in use shall be obtained, the organization's exposure to such vulnerabilities shall be evaluated and appropriate measures shall be taken.
Authentication and session management
Secure authentication technologies and procedures shall be implemented based on information access restrictions and the topic-specific policy on access control.
Change management
Changes to information processing facilities and information systems shall be subject to change management procedures.
Incident response
The organization shall establish and communicate information security incident management responsibilities and procedures.
Business continuity
Information security continuity shall be embedded in the organization's business continuity management systems.
Supplier relationships
Processes and procedures shall be defined and implemented to manage the information security risks associated with the use of supplier's products or services.
Logging and monitoring
Logs that record activities, exceptions, faults and information security events shall be produced, stored, protected and analysed.
Data classification
Information shall be classified according to the information security needs of the organization based on confidentiality, integrity, availability and relevant interested party requirements.
Data retention and disposal
Records shall be protected from loss, destruction, falsification, unauthorized access and unauthorized release in accordance with legal, regulatory, contractual and business requirements.
Privacy by design
Privacy and protection of personally identifiable information shall be ensured in the design and development of information systems.
Consent and notice
Privacy notices and consent mechanisms shall be provided to data subjects in accordance with applicable privacy requirements.
We retain case and intake data according to our privacy program and legal obligations. Inactive matter data that remains in limbo without progression may be deleted after a defined retention period.
Review gates, role-based permissions, and attorney certification are built into the filing workflow before anything is submitted to a government agency.
Review our legal and privacy documentation on the main Strophe site:
For security disclosures, privacy requests, or trust questionnaires, contact security@strophe.com or legal@strophe.com.