Home Compliance Security and privacy
Where your data lives, and who can touch it.
Our security, privacy and data residency posture, written for the security reviewer. No invented certifications, no vague assurances: what we actually do, per engagement, in writing.
The answers, in questionnaire order.
Each row below matches a standard section of a vendor security questionnaire. Where a detail is engagement-specific, the statement of work names it.
- Data residency
-
Client production data is hosted in Canadian regions, named per engagement in the statement of work. This website itself is static, sets no cookies and runs no third-party trackers: there is no visitor data to reside anywhere.
- Encryption
-
TLS for all data in transit. Encryption at rest on the client systems we provision.
- Access control
-
Least-privilege access: people get the minimum access their role requires, and no more. Multi-factor authentication on all administrative access. When someone leaves an engagement, access is removed within one business day.
- Subprocessors
-
Published per engagement in the statement of work, so you approve the list before work starts. None are embedded in this website.
- Backups and retention
-
Backup schedules and retention periods are defined per engagement in the statement of work. At contract end, client data is returned or destroyed on request, and we confirm in writing.
- Incident response
-
If an incident affects client data, we notify affected clients without undue delay and cooperate fully with municipal and provincial reporting obligations.
- Privacy law posture
-
PIPEDA governs our commercial work. For public-sector work, MFIPPA and FIPPA obligations flow into our contracts, and we support records requests within contract timelines.
- Records and freedom of information
-
We cooperate with freedom-of-information production timelines in municipal contracts, and we keep engagement records organized so production is fast when a request lands.
Status verified August 2026
What we do not claim
We hold no third-party security certifications today, and we do not pretend otherwise. What you get instead is a small firm where the people who hold the credentials are the people doing the work, contractual commitments on everything above, and answers to your security questionnaire from the principals, in writing, before award.
Have a security questionnaire for us?
Send it. We complete vendor security and privacy forms as part of onboarding, and the answers match this page.