protection against unauthorized access
Every I-9 holds a Social Security number, a passport, an immigration document. We protect that data with encryption, isolated cloud infrastructure, and independently examined controls. Here is exactly how.

In December 2025, Render Compliance, LLC completed a SOC 2 Type 1 examination of i9 Intelligence's Form I-9 Compliance Software. A Type 1 report evaluates whether our security controls are suitably designed to meet the AICPA Trust Services Criteria, as of a point in time.
The examination covered four Trust Services Categories:
protection against unauthorized access
the system is there when you need it
sensitive data is restricted and protected
personal information is handled responsibly
personal information is handled responsibly
Type 2 is underway now. A SOC 2 Type 2 examination tests whether those controls operate effectively over time, not just at a point in time. Our observation period completes in November 2026, with the report expected January 2027.
Our platform runs on Microsoft Azure, whose data centers carry their own SOC and ISO certifications. Our SOC 2 report is available to prospective and current customers under NDA.
No vague promises. Here are the actual controls that safeguard every I-9 in our platform.
Sensitive fields are unreadable, even to us.
Only the right people, on approved devices.
Your data never touches the open internet.
Enterprise cloud, hardened configuration.
Secure by design, from token to endpoint.
Controls are only as strong as the team.
Data is hosted on Microsoft Azure inside a private network, reachable only through private endpoints, not the public internet.
Only authorized personnel on company-managed devices can touch customer data, gated by role-based access and MFA. Personal devices are prohibited.
We keep AI away from personally identifiable information. Your employees' SSNs, passports, and documents are never used to train third-party AI models.
Built to keep you audit-ready
The I-9 is always the employer's legal responsibility, and no vendor can take that on for you. What we can do is make an audit a non-event: every action is captured in a complete audit trail, records are stored securely, and you can produce a full, defensible set within the 72-hour window of a Notice of Inspection.
Request our SOC 2 report, ask for a security questionnaire, or put us in front of your IT and compliance reviewers. We built this page for exactly that conversation.