SOC 2 Type 1 examined · Type 2 in progress

Security built for the data you can't afford to lose.

Every I-9 holds a Social Security number, a passport, an immigration document. We protect that data with encryption, isolated cloud infrastructure, and independently examined controls. Here is exactly how.

SOC 2 Type 1
Independently examined, Dec 2025
Encrypted end to end
At rest & in transit
(TLS 1.2)
Microsoft Azure
Isolated, private-endpoint cloud
MFA + Enterprise SSO
Role-based, least-privilege access
PII never trains AI
Your employees' data stays yours

Trusted across industries

DN TANKS
HOLDER
STACY & WITBECK
BOHANNON MASONRY
BRAZOS MASONRY
CORNERSTONE
DN TANKS
HOLDER
STACY & WITBECK
BOHANNON MASONRY
BRAZOS MASONRY
CORNERSTONE

Our controls have been examined by an independent auditor.

In December 2025, Render Compliance, LLC completed a SOC 2 Type 1 examination of i9 Intelligence's Form I-9 Compliance Software. A Type 1 report evaluates whether our security controls are suitably designed to meet the AICPA Trust Services Criteria, as of a point in time.
The examination covered four Trust Services Categories:

Security

protection against unauthorized access

Availability

the system is there when you need it

Confidentiality

sensitive data is restricted and protected

Privacy

personal information is handled responsibly

personal information is handled responsibly

Type 2 is underway now. A SOC 2 Type 2 examination tests whether those controls operate effectively over time, not just at a point in time. Our observation period completes in November 2026, with the report expected January 2027.
Our platform runs on Microsoft Azure, whose data centers carry their own SOC and ISO certifications. Our SOC 2 report is available to prospective and current customers under NDA.

How we protect your data

No vague promises. Here are the actual controls that safeguard every I-9 in our platform.

Encryption everywhere

Sensitive fields are unreadable, even to us.

  • All storage & disks encrypted at rest
  • Always Encrypted on sensitive columns like SSNs
  • TLS 1.2 enforced on every connection
  • Encryption keys held in Azure Key Vault
Identity & access

Only the right people, on approved devices.

  • Role-based access control, least privilege
  • Multi-factor authentication
  • Enterprise SSO via Auth0 / Okta
  • Registered, verified device identity
Network isolation

Your data never touches the open internet.

  • Private virtual network architecture
  • Private endpoints for database, storage & secrets
  • Network security groups control all traffic
  • HTTPS enforced across every property
Infrastructure

Enterprise cloud, hardened configuration.

  • Hosted on Microsoft Azure (SOC/ISO data centers)
  • Isolated compute with separate OS & data disks
  • Redundancy & failover for availability
  • Continuous monitoring via Azure Security Center
Application & API

Secure by design, from token to endpoint.

  • JWT auth with short-lived tokens & full validation
  • Secrets stored in Azure Key Vault, never in code
  • Strict dev / production separation
  • Managed identity — no stored credentials
People & process

Controls are only as strong as the team.

  • Documented policies: access, change, incident response
  • Security training from onboarding forward
  • Company-managed devices only — no BYOD to data
  • Incident response & breach-notification procedures

Where your data lives, and what we do with it

Isolated U.S. cloud

Data is hosted on Microsoft Azure inside a private network, reachable only through private endpoints, not the public internet.

Least privilege, no BYOD

Only authorized personnel on company-managed devices can touch customer data, gated by role-based access and MFA. Personal devices are prohibited.

Never used to train AI

We keep AI away from personally identifiable information. Your employees' SSNs, passports, and documents are never used to train third-party AI models.

Built to keep you audit-ready
The I-9 is always the employer's legal responsibility, and no vendor can take that on for you. What we can do is make an audit a non-event: every action is captured in a complete audit trail, records are stored securely, and you can produce a full, defensible set within the 72-hour window of a Notice of Inspection.

Bring your security team. We'll walk them through it.

Request our SOC 2 report, ask for a security questionnaire, or put us in front of your IT and compliance reviewers. We built this page for exactly that conversation.