Your compliance data is hosted in Canada, encrypted, and isolated at the database layer. Here is exactly how — and an honest account of where we are on certifications.
Primary compliance data (assessment results, audit logs, documents) is hosted in Montreal, Canada (Supabase, ca-central region) to meet PIPEDA data-residency expectations. Some operational data (transactional emails, analytics) uses US subprocessors with Standard Contractual Clauses.
Data is encrypted in transit (TLS) and at rest (AES-256) by our infrastructure provider.
Every database table carries row-level security policies — each customer’s data is isolated at the database layer, not just in application code.
Sign-in runs on Supabase Auth — we never roll our own credential storage. Multi-factor authentication is available, and access to production systems is limited and logged.
Automated backups with point-in-time recovery, kept in the Canadian region alongside your data.
Hosted on Supabase and Vercel, which provide DDoS mitigation and platform-level hardening at the edge.
Our AI features (the compliance tools and the website assistant) are powered by Anthropic's Claude models via the Anthropic API. Anthropic does not use API inputs or outputs to train its models. We do not train any model on your compliance data, and we never sell or share it for advertising.
Your compliance records — assessments, tasks, breach register, audit logs — are stored in a Canadian Supabase region (Montreal) with row-level security, so each business can only ever see its own data. When an AI feature runs, the relevant text is processed by the model provider in transit and is not retained as training data.
The website chat assistant is for product questions — please don't paste customer personal information into it. For the full picture of who processes what, see our DPA and subprocessor list.
⚠️ No Certifications Earned Yet
We have not completed SOC 2, ISO 27001, or third-party penetration testing. PIPEDA and CASL are Canadian laws we're designed around, not certifications we hold. Below is our roadmap, not our achievements.
In progress
(Not certified)
Planned
Target: 2027
(Not certified)
Transparency commitment: We list certifications only when earned. Your compliance data is encrypted at rest and in transit, isolated with row-level security, and hosted in Canada (live now in Montreal). We have not completed third-party penetration testing or a SOC 2 audit yet — that work is part of our readiness plan, and we will publish results here when they are earned, not before. PIPEDA is the law the platform is designed around, not a certificate we hold.
What the product covers under CASL, PIPEDA, Quebec Law 25 and AODA — and what it doesn't — is listed obligation by obligation in our framework coverage manifests.
If a security incident affects personal information, we follow PIPEDA's breach-response obligations: assess whether it creates a real risk of significant harm, contain it, notify the Office of the Privacy Commissioner of Canada and affected individuals where the law requires, and keep a record of the breach.
We are an early-stage product, and we will be straight with you: formal monitoring and a documented incident runbook are still being built out as part of our SOC 2 preparation. What is in place today is Canadian data residency, database-level isolation, and a small team that responds directly.
PIPEDA's fair-information principles give you these rights in law.
PIPEDA does not require these. We provide them anyway.
To exercise any of these, email contact@canadacomplianceai.ca
We're a small team — security and data-handling questions go straight to someone who can actually answer them. Ask us anything before you trust us with your compliance data.
Contact us