Home Compliance Security and privacy

Where your data lives, and who can touch it.

Our security, privacy and data residency posture, written for the security reviewer. No invented certifications, no vague assurances: what we actually do, per engagement, in writing.

Security review

The answers, in questionnaire order.

Each row below matches a standard section of a vendor security questionnaire. Where a detail is engagement-specific, the statement of work names it.

Data residency

Client production data is hosted in Canadian regions, named per engagement in the statement of work. This website itself is static, sets no cookies and runs no third-party trackers: there is no visitor data to reside anywhere.

Encryption

TLS for all data in transit. Encryption at rest on the client systems we provision.

Access control

Least-privilege access: people get the minimum access their role requires, and no more. Multi-factor authentication on all administrative access. When someone leaves an engagement, access is removed within one business day.

Subprocessors

Published per engagement in the statement of work, so you approve the list before work starts. None are embedded in this website.

Backups and retention

Backup schedules and retention periods are defined per engagement in the statement of work. At contract end, client data is returned or destroyed on request, and we confirm in writing.

Incident response

If an incident affects client data, we notify affected clients without undue delay and cooperate fully with municipal and provincial reporting obligations.

Privacy law posture

PIPEDA governs our commercial work. For public-sector work, MFIPPA and FIPPA obligations flow into our contracts, and we support records requests within contract timelines.

Records and freedom of information

We cooperate with freedom-of-information production timelines in municipal contracts, and we keep engagement records organized so production is fast when a request lands.

Status verified August 2026

What we do not claim

We hold no third-party security certifications today, and we do not pretend otherwise. What you get instead is a small firm where the people who hold the credentials are the people doing the work, contractual commitments on everything above, and answers to your security questionnaire from the principals, in writing, before award.

Have a security questionnaire for us?

Send it. We complete vendor security and privacy forms as part of onboarding, and the answers match this page.

Book a 20-min call