Trust Center

    Security, compliance, and transparency

    How we protect your data and maintain compliance. Last updated: September 12, 2026

    Our Commitment

    As a compliance platform, we hold ourselves to the same standards we help our customers achieve. This Trust Center provides transparent, up-to-date information about our security practices, certifications, sub-processors, and incident response procedures.

    We believe trust is earned through transparency. If you have questions about anything on this page, contact our security team at contact@canadacomplianceai.ca

    Certifications

    Compliance status

    Current certification progress and timelines. We only list certifications once earned.

    SOC 2 Type I

    IN PROGRESS

    Third-party audit of security controls. Auditor selection in progress.

    Not yet certified

    ISO 27001

    PLANNED

    Information security management system certification. Planning phase.

    Target 2027

    PIPEDA

    NOT A CERTIFICATION

    PIPEDA and CASL are Canadian laws, not certifications anyone holds. We build our own practices around them; no external audit of those practices has been completed.

    A law we design around

    Sub-processors

    Third-party service providers

    All third-party providers that process customer data. Last updated: September 12, 2026

    PROVIDERPURPOSELOCATIONDATA TYPESSINCE
    SupabaseDatabase, authentication, storageCanada (Montreal region)Customer data, compliance records, audit logsJanuary 2026
    StripePayment processingUnited StatesBilling information, payment card data (PCI DSS Level 1)January 2026
    ResendTransactional email deliveryUnited StatesEmail addresses, email contentJanuary 2026
    VercelApplication hosting, CDNGlobal (edge network)Application code, static assets, logsJanuary 2026
    Google AnalyticsAnonymous usage analyticsUnited StatesAnonymized usage data, IP addresses (anonymized)January 2026

    Subscribe to changes

    We will notify you via email when we add, remove, or change sub-processors. All changes are listed with 30 days advance notice when possible.

    Subscribe to updates
    Security

    Our security practices

    Encryption

    • •Encrypted at rest (AES-256) by our infrastructure provider
    • •Encrypted in transit (TLS)

    Infrastructure

    • •Primary compliance data hosted in Canada (Montreal)
    • •Managed database and hosting providers listed on our subprocessors page

    Access Control

    • •Database row-level security isolating each organization's records
    • •Optional TOTP two-factor authentication
    • •Audit log with CSV export

    Incidents

    • •Breaches assessed for a real risk of significant harm, as PIPEDA requires
    • •Every breach recorded and kept for 24 months
    • •Formal monitoring and a documented runbook are still being built as part of SOC 2 preparation
    Legal

    Data Processing Agreement

    Our Data Processing Agreement (DPA) outlines how we process customer data in compliance with PIPEDA, Quebec Law 25, and other applicable Canadian privacy laws. The DPA includes Standard Contractual Clauses for international data transfers.

    Last updated: January 15, 2026 · Version 1.0

    Security Research

    Responsible disclosure

    If you discover a security vulnerability in Canada Compliance AI, we want to hear from you. We are committed to working with security researchers to verify and address any potential issues.

    How to report

    1. Email contact@canadacomplianceai.ca with details of the vulnerability
    2. Include steps to reproduce, impact assessment, and any proof-of-concept code
    3. Allow us 48 hours to acknowledge receipt and 30 days to investigate
    4. We will keep you informed of our progress and coordinate disclosure timing

    Bug bounty program: planned

    We are planning to launch a formal bug bounty program with monetary rewards. Until then, we will acknowledge all valid reports publicly (with your permission) and provide swag/credits.

    Incident Response

    What happens if there's a breach

    We maintain PIPEDA-compliant breach notification procedures. In the event of a data breach involving real risk of significant harm (RROSH), we will:

    1. 1.

      Detection & containment (0-15 minutes)

      We investigate the alert or report, and isolate the affected systems.

    2. 2.

      Assessment (15-60 minutes)

      Severity evaluation, RROSH calculation, impact analysis, affected data identification.

    3. 3.

      Investigation (1-24 hours)

      Root cause analysis, scope determination, evidence preservation.

    4. 4.

      Notification (24-72 hours)

      Where a breach creates a real risk of significant harm, notify the Office of the Privacy Commissioner and affected individuals as soon as feasible, as PIPEDA s. 10.1 requires. Our internal target is within 72 hours.

    Incident history: No security incidents or data breaches to report as of September 12, 2026.

    System status

    Monitor real-time platform status, scheduled maintenance, and historical uptime.

    Contact security team