Leading Security & Reliability
Overview
- Time and again, Cerenade is selected as the software provider of choice given our uncompromising prioritization of security. eIMMIGRATION is fortified by the Cerenade team with the strongest security practices available across data security, infrastructure security, product security and access control, organizational security, compliance, monitoring, and testing. This includes investment into a single-tenant database model and on-the-fly data geo-replication, systems that cost us more to offer (which is why our competitors do not) but that we find critical given an unprecedented level of threats facing the global digital domain today.
- As you consider platforms other than eIMMIGRATION, do yourself a favor and ask the other platform providers if they use a single-tenant database model. If they do not, contact our team, who is happy to demonstrate the major vulnerabilities such platforms are susceptible to.
- Below, you can find an overview of Cerenade and eIMMIGRATION’s security experience, protocols, and posture. For a more detailed view, please visit: https://www.cerenade.com/security/
30+ years of security excellence
Cerenade has over 30 years experience serving clients in security-intensive industries, including NASA, the US Department of State, dozens of other governmental agencies, hundreds of corporate enterprises, and thousands of law firms (with tens of thousands of legal professionals!). Our experienced team of security experts leverages best practices in product design, software development, and incident response to keep your organization operational 24x7x365. We also recognize that security begins internally: our robust organizational security protocols and practices include limitations to accessing customer data, SSO + 2FA authentication for our business operations and development environments, technical protection policies including firewall and encryption, and physical + administrative controls for workplace resource access.
Staying ahead with regular R&D, testing, and monitoring
Security has been and continues to be a key area of research & development investment at Cerenade to ensure our posture remains on the cutting edge and compliant with the best industry standards (such as PCI DSS, ISO 27001, and SOC TSP). In addition to regularly reviewing and updating systems and protocols, our team continuously tests and monitors our products, development environments, and business operations environments through a robust set of security tools, including Azure’s Microsoft Defender for Cloud, firewalls, and sophisticated intrusion detection mechanisms to check user sessions / IP for suspicious activity. While we’re confident in our internal capabilities, we take extra precaution by working with external parties such as a certified cybersecurity agency for annual penetration testing and security consultants to stay on-top of trends and vulnerability news.
Advanced Data Security
Cerenade invests heavily to retain a unique, first-class security posture for protecting eIMMIGRATION user data and maintaining high data availability. We are the only immigration practice software vendor to offer a single-tenant database model, which essentially means that each customer’s data is housed in its own database instead of a shared database between all customers (which is vulnerable to several exploits). We also offer on-the-fly geo-replication to provide an enhanced means of data backup / recovery and ensure at worst only 15 minutes of work is lost in a natural disaster or failure (compared to the “secure” industry standard of at worst losing 24 hours of work). Lastly, Cerenade leverages its own forms technology in eIMMIGRATION to keep form data confidential from third-party forms technology vendors (who can exploit such access, sell / share your data with other third-party vendors, and mask liability if the data is hacked by a malicious party). All of these advanced data security measures require extra investment and maintenance from Cerenade; however, as a technology developer and vendor, the onus is on us to ensure our customers (who likely do not have backgrounds in data security!) are protected by state-of-the-art systems.
Infrastructure Security
Cerenade hosts eIMMIGRATION data (including cases, forms, client info, billing, and more) on Microsoft Azure servers and partners with Azure to provide bank-grade security on heavily fortified infrastructure. Data is encrypted using best-in-class protocols both in-transit (using TLS) and at-rest (using TDE with 256-bit AES, among other algorithms) on Azure servers. Microsoft Azure datacenters are protected by a number of physical security measures, including compliance with ISO/IEC 27001:2013 and NIST SP 800-53, 24x7x365 monitoring and administration by Microsoft’s security operations staff, robust access request and approval protocols, security guard patrols and video surveillance throughout datacenters and facility perimeters, and 2FA requirements including biometrics for employees.
Product Security and Access Control
eIMMIGRATION is loaded with a variety of product security and access control mechanisms, including 2FA, SSO (including enterprise-wide deployments for organizational policies via Microsoft Azure AD SSO and Google SSO), role-based permissions and configuration via eIMMIGRATION’s administrator portal, optional strong password policies, and optional log-in lock policies.
Compliance
eIMMIGRATION is compliant with PCI DSS, GDPR, HIPAA, ISO27001, SOC 1/2, FedRAMP, multiple country-specific standards (such as UK G-Cloud, Australia IRAP, Singapore MTCS), and more via adherence from both Cerenade and Microsoft Azure.