Skip to content

Trust Center

Security, privacy, and AI governance, in the open.

Everything here states its real status. Live means it is running today. Aligned means our controls map to a published framework. Roadmap means it is planned and named honestly, not implied. On request means a document we will share with a serious buyer.

For the detailed narrative, see the Security & Trust page.

Security

Live
Tenant isolation at the database layer (RLS)
Verified on every release by an automated cross-tenant matrix across every table.
Live
Encryption in transit (TLS 1.2+, HSTS preload) and at rest (AES-256)
Live
MFA, SSO (SAML/OIDC), and SCIM provisioning
Included in every paid plan, not sold as an upgrade.
Live
Role-based access control and separation of duties
Enforced in the database, not only the interface.
Live
Admin and append-only financial audit logs
Live
Secrets encrypted at rest
Live
Recurring adversarial security testing + CI regression net
Findings become automated invariants so they cannot recur silently.
Roadmap
Independent third-party penetration test

AI governance

Live
No customer data used to train models
AI runs on the Anthropic API, which does not train on API data.
Live
Permission-aware AI
AI operates within the user's own workspace and permissions; it cannot reach another tenant.
Live
Human-in-the-loop for consequential actions
Live
Per-action autonomy controls + workspace AI kill-switch
Live
AI usage metering and action logging
Live
CSA AI Controls Matrix (AICM) assessed
Published as CSA STAR for AI Level 1 in the STAR Registry.

Privacy

Live
Data retention and deletion policy
30-day archive for deleted projects; deletion on request.
Live
Published subprocessor list
On request
Data Processing Agreement (DPA)
Available on request; finalized per engagement.
Live
Deactivation revokes access while preserving history
Roadmap
Canadian data residency
Production is currently US-hosted. A Canadian-region deployment is available on request; we do not claim Canadian residency as default.
Roadmap
Privacy-regime documentation (PIPEDA / GDPR / FERPA)
Produced when a buyer requires it.

Accessibility

Roadmap
WCAG 2.2 AA target
Assessed against WCAG 2.2 AA; remediation of data-dense views and rich widgets in progress.
Live
Skip link, landmarks, named controls, visible focus, reflow
On request
Accessibility Conformance Report (VPAT)
Evidence-based ACR available on request.

Compliance status

Live
CSA STAR Level 1 (CAIQ self-assessment)
Listed in the CSA STAR Registry.
Live
CSA STAR for AI Level 1 (AI-CAIQ self-assessment)
Listed in the CSA STAR Registry.
Aligned
CIS Controls v8.1 - Implementation Group 1
Mapping maintained; not a certification.
Aligned
OWASP ASVS and SAMM
Development aligned to these; not a certification.
Roadmap
CyberSecure Canada
Roadmap
SOC 2 (Type I then Type II)

Documentation (available on request)

On request
Security whitepaper
On request
Architecture and data-flow overview
On request
Incident response plan
On request
Business continuity / disaster recovery overview
On request
AI and data usage policy
On request
CAIQ / HECVAT responses
On request
CIS IG1 and OWASP ASVS mappings
On request
Accessibility Conformance Report (VPAT)

Security or procurement question?

We respond to security questionnaires and share the documents above with serious buyers. Reach out and we will get you what your review needs.

[email protected]