Security and confidentiality
Security designed for confidential legal research.
BIA Edge gives authorized users access to immigration-law sources from the AI tool they already use. The controls below protect that retrieval layer while keeping the separate AI-client boundary clear.
Last updated: July 13, 2026
Current security posture
BIA Edge is not currently SOC 2 certified or compliant. The security program is being prepared for SOC 2 Type I readiness and an independent assessment. Independent penetration testing remains a planned assurance step, not a completed claim.
What happens to a research request
MCP search terms, citations, and questions are processed transiently to answer the request. BIA Edge usage counters retain the calling identity, tool name, date, counts, timing, and error or rate-limit totals—not raw tool arguments or attorney query text. Requests use bodies rather than query-string URLs, error reporting is configured not to capture request bodies, and content-bearing fields are fingerprinted when operational correlation is needed.
BIA Edge does not sell user data and does not use account data, access-request messages, saved searches, website queries, API requests, or MCP queries to train foundation models. Operational logs are minimized and ordinarily kept for no more than 90 days unless a documented security, abuse, reliability, access-dispute, legal, or required business-record exception applies.
Your AI client is a separate security boundary
Your chosen AI client processes the conversation, decides which MCP calls to make, receives BIA Edge results, and may retain that material under its own agreement and administrator settings. BIA Edge’s no-training commitment applies only to BIA Edge. BIA Edge cannot configure the client provider’s retention, training, human-review, residency, or workspace controls.
For confidential client work, use a firm-approved organizational workspace or another no-training account whose agreement and settings meet the firm’s requirements. Avoid client identifiers unless they are necessary and authorized. BIA Edge is a legal-source retrieval service, not a client-file repository or case-management system.
Identity and access
Remote MCP access uses authorized, revocable named-user OAuth identities. Issued API keys are stored as hashes, can be scoped, can expire, and can be revoked independently. The legacy shared production bearer has been retired.
Administrator MFA is required in the BIA Edge application and across current administrative providers where supported. Ordinary-user TOTP remains optional. Public website-account registration is closed, and browser-cookie authenticated mutation requests are protected by a same-origin check.
Infrastructure and recovery
Public services use TLS. Application services reach the production database over private networking with separate, least-privilege runtime and purpose-bound automation roles. Production writes, releases, and sensitive operating changes are coordinated through supervised, auditable change windows.
The managed production database uses high availability and point-in-time recovery. BIA Edge completed an isolated recovery exercise that restored a production recovery point, verified the schema and corpus, exercised a rollback-only write, and confirmed production remained healthy.
Secure engineering and monitoring
Releases are protected by automated tests and dependency, static-analysis, and secret-scanning checks. Dependencies and CI actions are pinned, reviewed findings are held to exact regression baselines, and vulnerability remediation targets are defined by severity. Security-relevant operating evidence is collected automatically and retained for 90 days with privacy and size gates.
DNSSEC protects the biaedge.com DNS chain. Strict DMARC instructs receivers to reject unauthenticated mail for the current non-sending domain. Marketing analytics are disabled in production and are structurally excluded from legal-research, MCP access, documentation, privacy, security, terms, support, authenticated, and API surfaces.
Public legal records and security reports
The BIA Edge library is built from public legal materials, which may contain names, docket facts, and agency or court details because the source published them. To request review of a record, email the source URL, BIA Edge document identifier, and specific concern to chris@chrishammondlaw.com.
To report a vulnerability or security concern, email chris@chrishammondlaw.com with “BIA Edge security report” in the subject line. Do not post exploit details or confidential client information in a public forum.
Related policies: Privacy Policy, Terms of Service, and AI Disclaimer.