How we protect your data and maintain compliance. Last updated: September 12, 2026
As a compliance platform, we hold ourselves to the same standards we help our customers achieve. This Trust Center provides transparent, up-to-date information about our security practices, certifications, sub-processors, and incident response procedures.
We believe trust is earned through transparency. If you have questions about anything on this page, contact our security team at contact@canadacomplianceai.ca
Current certification progress and timelines. We only list certifications once earned.
Third-party audit of security controls. Auditor selection in progress.
Not yet certified
Information security management system certification. Planning phase.
Target 2027
PIPEDA and CASL are Canadian laws, not certifications anyone holds. We build our own practices around them; no external audit of those practices has been completed.
A law we design around
All third-party providers that process customer data. Last updated: September 12, 2026
| PROVIDER | PURPOSE | LOCATION | DATA TYPES | SINCE |
|---|---|---|---|---|
| Supabase | Database, authentication, storage | Canada (Montreal region) | Customer data, compliance records, audit logs | January 2026 |
| Stripe | Payment processing | United States | Billing information, payment card data (PCI DSS Level 1) | January 2026 |
| Resend | Transactional email delivery | United States | Email addresses, email content | January 2026 |
| Vercel | Application hosting, CDN | Global (edge network) | Application code, static assets, logs | January 2026 |
| Google Analytics | Anonymous usage analytics | United States | Anonymized usage data, IP addresses (anonymized) | January 2026 |
We will notify you via email when we add, remove, or change sub-processors. All changes are listed with 30 days advance notice when possible.
Subscribe to updatesOur Data Processing Agreement (DPA) outlines how we process customer data in compliance with PIPEDA, Quebec Law 25, and other applicable Canadian privacy laws. The DPA includes Standard Contractual Clauses for international data transfers.
Last updated: January 15, 2026 · Version 1.0
If you discover a security vulnerability in Canada Compliance AI, we want to hear from you. We are committed to working with security researchers to verify and address any potential issues.
We are planning to launch a formal bug bounty program with monetary rewards. Until then, we will acknowledge all valid reports publicly (with your permission) and provide swag/credits.
We maintain PIPEDA-compliant breach notification procedures. In the event of a data breach involving real risk of significant harm (RROSH), we will:
We investigate the alert or report, and isolate the affected systems.
Severity evaluation, RROSH calculation, impact analysis, affected data identification.
Root cause analysis, scope determination, evidence preservation.
Where a breach creates a real risk of significant harm, notify the Office of the Privacy Commissioner and affected individuals as soon as feasible, as PIPEDA s. 10.1 requires. Our internal target is within 72 hours.
Incident history: No security incidents or data breaches to report as of September 12, 2026.
Monitor real-time platform status, scheduled maintenance, and historical uptime.