Book a DemoSign Up
> trust_and_security

Security-first architecture, built for the trust requirements of visa infrastructure.

We process passport data, government documents, and personal identity records. Security is not a feature — it is the foundation.

> what_we_collect_and_why

What we do — and don't do — with your data.

// collect

Passport and application data

Passport data, travel document scans, and application information submitted by agents and travelers for visa processing.

// use

For visa processing — only

Solely to process applications on behalf of agents and travelers. No data sold to third parties. No advertising profiling.

// retain

Retention with control

Kept only as long as needed to process and meet legal obligations, then deleted or archived per your data retention policy.

// access

Role-based access

Agent data is visible only to that agency's account. Propellus operations staff access is logged and audited.

// Detailed retention schedules are defined per engagement in our data processing agreements.

> infrastructure

Enterprise-grade cloud infrastructure.

// infrastructure_status all systems operational
hostingAWS and Microsoft Azure checking…

Dual-cloud deployment across AWS and Microsoft Azure for resilience and regional reach.

data_residencyRegion-specific hosting available for government requirements checking…

Applications and documents can be pinned to a specific region to meet government data-sovereignty rules.

tlsEncryption in transit — TLS 1.3 checking…

All traffic is encrypted in transit using TLS 1.3, the current industry standard.

at_restEncryption applied to data at rest — full specification in our security documentation checking…

Data at rest is encrypted — the full specification is available in our security documentation.

accessRole-based · principle of least privilege checking…

Access is granted by role on a least-privilege basis — users see only what their role requires.

auditAll data access events logged checking…

Every access to sensitive data is logged for audit and compliance review.

> compliance

Building toward enterprise and government certification.

Today
Security-first architecture. Cloud infrastructure. Role-based access. Data sovereignty options for government requirements.
Q3 2026
SOC 2 Type II audit initiated. Formal security policy documentation published.
2027
ISO 27001 evaluation. Government-specific compliance certifications by jurisdiction.

// certification badges (SOC 2, ISO 27001) are intentionally not displayed until those processes are confirmed in progress.

> enterprise_and_government_due_diligence

Request our security documentation.

For procurement teams, government IT evaluators, and enterprise security reviews: we provide full security documentation on request. NDAs honoured. No information shared without written agreement.

Contact: security@propellus.co