Security & compliance built for regulated casework.
Immigration firms handle sensitive personal data under PIPEDA and CICC professional obligations. ImmigrateOS stores your client and case data in Google Cloud Canada regions — with MFA, audit trails, and access controls at the core.
Your client data stays in Canada.
RCIC firms ask where files live before they trust a platform. ImmigrateOS is built for Canadian immigration practice — client records, case files, documents, messages, and audit logs are stored and processed in Google Cloud Canada regions, not US-only data centers.
- Montreal by default — Cloud Run, Cloud SQL, Cloud Storage, and Memorystore in northamerica-northeast1
- Toronto available — northamerica-northeast2 for firms that prefer it
- Same-region processing — API, database, documents, and queue cache stay co-located
- Encrypted end to end — TLS in transit, AES-256 at rest on Google Cloud
- MFA for firm staff — organization-enforced multi-factor authentication via WorkOS AuthKit
- Separate client portal auth — clients sign in through a dedicated portal identity layer, isolated from firm staff accounts
Immutable audit log
Every case status change, document access, and financial transaction is recorded — who, what, and when — so you can answer regulator or client questions with evidence.
Document versioning
Re-uploads create new versions instead of overwriting files. Nothing disappears silently when a passport is renewed or a form is corrected.
Role-based access & MFA
Owner, Senior Consultant, Consultant, Paralegal, Front Desk, and Accountant roles each see only what their job requires. Firm owners can require multi-factor authentication for every staff login.
Secure payments
Client payments run through Stripe Connect — PCI-compliant checkout in the portal. Your firm never stores card numbers in ImmigrateOS.
Data export
Export client records, case history, documents, and financial data before cancellation — your firm's data stays portable.
Human-in-the-loop AI
AI drafts checklists, messages, and risk flags for consultant review. Nothing is sent to clients or submitted to government portals automatically.
Infrastructure & data handling
ImmigrateOS runs entirely on Google Cloud — no AWS, no Railway. Production workloads use:
- Cloud Run — NestJS API, deployed in your firm's Canada region
- Cloud SQL — PostgreSQL for client records, cases, tasks, invoices, and audit logs
- Cloud Storage — versioned document files with immutable version history
- Memorystore — Redis for background jobs and queue processing, co-located with your data
The firm application interface is served via Vercel (CDN). Sensitive client and case data is read and written only through the Canada-hosted API — it is not stored on Vercel edge nodes. Staff authentication uses WorkOS AuthKit; the client portal uses a separate identity provider. Access to production systems is restricted to authorized personnel on a need-to-know basis.
PIPEDA & CICC compliance posture
ImmigrateOS is designed for Canadian immigration consulting firms operating under the Personal Information Protection and Electronic Documents Act (PIPEDA) and the College of Immigration and Citizenship Consultants (CICC) Code of Professional Conduct. The platform supports your obligations with:
- Accountability & safeguards — role-based access, MFA, encryption, and immutable audit logs on sensitive writes
- Limiting collection & use — case-scoped data model; AI drafts require consultant review before reaching clients or government systems
- Openness & individual access — clients interact through the portal; firms can export full records on request or offboarding
- Professional file integrity — document versioning preserves every upload; case status changes are logged with who, what, and when
ImmigrateOS is a software platform, not legal advice. Your firm remains responsible for its regulatory compliance — we provide the controls and documentation to support your due diligence.
Subprocessors & cross-border processing
Some integrated services process limited data outside Canada when you enable them — for example, Stripe (payments), Resend (transactional email), OpenRouter (AI drafting), Google Calendar, Microsoft 365, QuickBooks, or Xero sync. Core case and client data remains in your Google Cloud Canada region unless you connect an integration that requires otherwise. Enterprise customers can request our full subprocessor list and data processing addendum.
Enterprise security review
Enterprise customers can request a dedicated security and compliance review — subprocessors, retention schedules, incident response, and region confirmation for your account. Contact us to start that process.