Collection Attorneys USA, LLC ("CA/USA") is a law firm engaged in the recovery of consumer receivables. The security and confidentiality of consumer information is central to how we operate. This page summarizes the technical and organizational safeguards we maintain to protect it.
Independent Assurance
Compliance Program
CA/USA maintains a formal information security program aligned with the SOC 2 Trust Services Criteria and the requirements of the Gramm-Leach-Bliley Act (GLBA) and the FTC Safeguards Rule.
SOC 2 Type II Certified
CA/USA is SOC 2 Type II certified, having successfully completed examinations of its collections platform conducted by Johanson Group LLP, an independent CPA firm. CA/USA holds both SOC 2 Type I and SOC 2 Type II reports. Reports are available to clients and partners under NDA upon request.
Continuous Monitoring
Our security controls are monitored continuously through an automated compliance platform that validates control operation against our infrastructure, identity systems, and policies on an ongoing basis.
Documented Policies
CA/USA maintains a complete set of information security policies, including acceptable use, access control, data management, incident response, vendor management, and vulnerability management. Policies are reviewed regularly and are available under NDA upon request.
Cloud Infrastructure
The CA/USA collections platform is hosted on Amazon Web Services (AWS) in United States regions. CA/USA operates no on-premises data centers. AWS maintains its own SOC 2 and ISO 27001 attestations covering the physical and environmental security of its facilities.
Technical & Organizational Controls
Our Safeguards
The safeguards below operate across our platform and workforce, and their operation is validated on a continuous basis.
Encryption at Rest
Consumer data is encrypted at rest using AES-256, with keys managed through a dedicated cloud key management service.
Encryption in Transit
All data in transit is protected with TLS. Email authentication is enforced on our sending domains through SPF, DKIM, and DMARC.
Data Minimization
We operate on a minimum-necessary principle. Data shared with service providers is limited to the fields required for the specific function, and consumer identity resolution remains within CA/USA-controlled systems.
Access Control
Multi-factor authentication is enforced on workforce accounts across our identity, infrastructure, and business platforms. Access is granted on the principle of least privilege and is role-based; production system access is restricted to personnel with a legitimate business need. Access rights are formally reviewed on a recurring basis, and access is revoked promptly upon role change or separation.
Monitoring & Threat Detection
Centralized audit logging is enabled across our cloud environment, with logs retained for at least one year. Managed threat detection and network flow monitoring are active across all in-scope regions, and operational and security alarms provide continuous coverage of production systems with real-time notification to security personnel.
Vulnerability Management
CA/USA maintains a documented vulnerability management program. Infrastructure is scanned on a recurring cadence, findings are triaged by severity, and remediation is tracked to closure. Cloud platform components are patched continuously by the respective providers.
Vendor Management
Third-party service providers are subject to a risk-based vendor management program. Vendors that access or process consumer information undergo security assessments, and data protection obligations — including breach notification and confidentiality requirements — are established contractually. Vendor security posture is reviewed on a recurring basis.
Incident Response
CA/USA maintains a documented incident response plan defining roles, escalation paths, and communication procedures. In the event of a security incident affecting consumer information, affected parties are notified consistent with applicable legal and contractual obligations, including GLBA and FTC Safeguards Rule requirements.
Operating Framework
Regulatory Compliance
Our operations are conducted in accordance with the federal laws and regulations governing consumer debt collection and consumer communications.
FDCPA
Regulation F
GLBA / FTC Safeguards Rule
TCPA
CAN-SPAM Act
E-SIGN Act
Your Choices
Consumer Communication Preferences
Consumers can manage their communication preferences — including opting out of email, text, and phone contact — through our secure online portal. Preference changes are recorded in an auditable ledger and enforced across all outbound communication channels.