Trust

eFileIQ Security & Trust

Last updated: July 3, 2026

eFileIQ handles sensitive compliance data and your company’s CPSC eFiling credentials, so security is built into the Service from the ground up rather than added on. This page explains how Corporate Systems Associates, Inc. protects your data. It is provided for information and does not modify the commitments in our Terms of Service or Privacy Policy.

Infrastructure and hosting

The Service runs on Microsoft Azure, with data processed and stored in Azure regions located in the United States. We rely on Microsoft Azure’s hardened, certified data centers — Microsoft Azure maintains SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, and PCI DSS certifications for the infrastructure eFileIQ runs on. eFileIQ itself is not independently SOC 2 audited today. We do not operate our own physical servers. Uploaded documents are held in private object storage and structured records in a managed database, both restricted to the Service.

Encryption

In transit. All traffic to and from the Service is encrypted with TLS 1.2 or higher. The customer portal, back-office console, and API are served over HTTPS only.

At rest. Stored data is encrypted at rest with AES-256 across object storage, our managed database, service bus, and application logs.

CPSC credentials. Your CPSC eFiling token and secret are held in a hardware-backed key vault (FIPS 140-2 Level 2) with Microsoft-managed keys, are never displayed back to you after entry, are used solely to submit filings you have approved for your company, and are never used for any other company’s filings.

Tenant isolation

The Service is multi-tenant, and every record is scoped to the company that owns it so that no customer can access another customer’s data. This isolation is enforced in application code and verified by an automated isolation test suite; a continuous-integration gate blocks any code path that is not tenant-scoped from reaching production.

Account security

Authentication. Sign-in for the customer portal and back-office console is handled by Microsoft Entra External ID, using industry-standard OpenID Connect and OAuth 2.0.

Multi-factor authentication. Every sign-in requires two factors: the user’s password and a one-time code delivered to the user’s registered email address. Multi-factor authentication is enforced at every sign-in and cannot be bypassed by the user.

Brute-force protection. Repeated failed sign-in attempts are throttled and locked out by our identity provider, according to Microsoft Entra External ID’s smart-lockout policies.

Sessions. Sessions use signed, HttpOnly, Secure cookies and short-lived access tokens issued by our identity provider, and can be revoked from your identity-provider session controls if a device is lost.

Staff access

Our staff do not have standing access to your Customer Data. When troubleshooting requires viewing Customer Data, that access is limited to what is needed to reproduce the issue, tied to a specific support request, and recorded in our audit log. We do not use your compliance data or credentials for any purpose other than operating the Service for you.

AI providers

For extraction, classification, and in-app assistant features, portions of your uploaded reports are transmitted to Anthropic PBC via Anthropic’s Claude API. Anthropic does not use Customer Data submitted through its API to train its models. AI-generated outputs (including extracted fields, suggested citations, and assistant answers) are provisional and require your review before any filing.

Sub-processors

We use a small number of service providers to operate the Service. Each is contractually bound to use data only to provide its service to us. This list is kept consistent with the sub-processor disclosure in our Privacy Policy.

Sub-processor Purpose Location
Microsoft Azure Hosting, storage, managed database, key vault, service bus, communication services (outbound transactional email), and application insights United States
Anthropic PBC AI-based extraction and assistant features via the Claude API United States
Mailgun Inbound email intake, when your company enables the email-upload feature United States

See the full Sub-processors page for detail and change-notification signup.

We will update this list before adding a new sub-processor. Data is also transmitted to the U.S. Consumer Product Safety Commission and to the customs broker your company designates — at your direction, as recipients you choose, and not as our sub-processors.

International data transfers

The Service is operated from and hosted in the region noted above, and your data is processed there. Where applicable data-protection law requires safeguards for international transfers — for example, for customers in the European Economic Area, the United Kingdom, or Switzerland — we rely on appropriate transfer mechanisms, such as the European Commission’s Standard Contractual Clauses and their UK and Swiss equivalents, which we will enter into with your company on request. This mirrors the International Data Transfers section of our Privacy Policy.

Availability

We aim to keep the Service available and monitored, and we design for resilience. Unless your company has a signed agreement containing an express uptime commitment, no service-level guarantee applies. Filing outcomes also depend on the CPSC’s systems, broker systems, and other third parties outside our control, consistent with our Terms of Service.

Audit trail

Actions taken within your account — uploads, extractions, approvals, edits, sign-ins, filings, and administrative changes — are recorded in an append-only audit log. Audit records are cryptographically hash-chained so tampering is detectable.

Security incidents

If we become aware of a security incident that affects the confidentiality or integrity of your Customer Data, we will notify your account’s administrative email without undue delay and as required by applicable law, and provide reasonably available information about the incident, its impact, and any remediation steps.

Responsible disclosure

We welcome reports from security researchers. If you believe you have found a vulnerability in the Service, please report it to us at security@efileiq.com with enough detail to reproduce the issue. We ask that you give us a reasonable opportunity to investigate and remediate before any public disclosure, that you do not access, modify, or delete data that is not your own, and that you avoid any action that could degrade the Service for other customers. We will acknowledge valid reports and work in good faith to resolve confirmed issues promptly. We will not pursue legal action against researchers who act in good faith and within these guidelines.

Reporting a concern

If you have a security question or want to report a concern, contact Corporate Systems Associates, Inc. through our contact page or at security@efileiq.com.