Canadian data residency by default
Applications and their data run in Canadian regions unless you specifically ask otherwise. For public-sector, health and financial buyers this is frequently the first question and often a hard requirement.
Platform
What we buildHelp centreSecurityComplianceReliabilityScalabilityEfficiency Platform overviewSolutions
Startup foundersEstablished businessesOperations teamsIntegrations
Payments, billing & taxAccounting & ERPIdentity, access & auditEmail deliverySMS & voiceElectronic signature All integrationsCompliant
The questionnaire always arrives. Usually attached to the biggest contract you have been offered, with two weeks to answer it.
The evidence exists before you need it, because assembling it afterwards is how deals slip a quarter.
Compliance is not a feature anyone wants. It is a gate — and it appears at precisely the moment you least want a gate, when a serious customer has finally said yes and their procurement team wants to know where your data lives, who can see it, how long you keep it, and what happens if you disappear. A startup that has to invent those answers under deadline usually loses weeks. A startup whose platform already has them answers in an afternoon.
Applications and their data run in Canadian regions unless you specifically ask otherwise. For public-sector, health and financial buyers this is frequently the first question and often a hard requirement.
What personal information your application holds, why it holds it, where it sits, and how long it is kept. A data inventory is the document every assessment asks for and almost nobody has.
The third parties involved in running your application — hosting, email delivery, error tracking — listed by name and purpose, so you can hand the list over rather than reconstruct it.
Retention periods are configured and enforced rather than aspirational. When data is meant to be deleted, it is deleted, including from backups on a defined cycle.
Quebec's Law 25, Canada's PIPEDA and the GDPR ask overlapping questions. The platform answers them the same way.
When someone asks what you hold about them, you can produce it and export it in a machine-readable form — within the statutory window rather than after it.
The right to erasure is only real if the data is findable. Applications are built so a person's records can be located and removed without a developer writing a one-off script.
Where consent is the basis for processing, it is captured with a timestamp and a version of what was agreed to — which is the part regulators ask about.
Law 25 and the GDPR both impose reporting obligations with short clocks. The incident process is written to those clocks, so the deadline is not discovered during the incident.
Collect the minimum, default to the private setting, and make the choices legible to the person. Law 25 requires this by default rather than on request.
A security review is an evidence exercise. These are the artifacts it asks for.
The written answers to the questions that appear in every assessment: architecture, encryption, access control, backups, incident response. Kept current, ready to send.
Common frameworks answered ahead of time, so a buyer's 200-line spreadsheet is a mapping exercise rather than a research project.
Formal certification, with the independent audit and continuous evidence collection behind it.
Roadmap · next
For buyers and markets where the ISO framework is the one that counts.
Roadmap · later
For customers whose policy requires the application to run in infrastructure they control.
Roadmap · later
The specifics
Status is stated plainly. Anything marked roadmap is not available today, and we will not imply otherwise in a sales conversation.
| Item | What you get |
|---|---|
| Data residency | Canada by default; other regions on request |
| Quebec Law 25 | Aligned — privacy by default, consent records, breach process |
| PIPEDA | Aligned |
| GDPR | Data subject rights supported: access, correction, portability, erasure |
| Data inventory | Maintained per application |
| Sub-processors | Documented and available on request |
| Retention | Configurable per data type, enforced automatically |
| Security overview | Written document, kept current |
| SOC 2 Type II | Roadmap — next |
| ISO 27001 | Roadmap — later |
| Customer-owned cloud | Roadmap — later |
| HIPAA / PCI-DSS | Not in scope today; tell us early if you need it |
Not today. It is the next formal step on the roadmap, and we would rather tell you that plainly than let it be inferred. What exists now is the underlying practice — encryption, access control, audit logging, incident response — and the written evidence of it, which is what most buyers actually examine before certification becomes a blocker.
Yes, and we would rather review it early in the conversation than in the week the contract is meant to be signed.
Say so in the first conversation. Canadian residency is the default, other regions are possible, and it is far cheaper to decide this before an application is built than after.
HIPAA-regulated workloads are not in scope today. Bring it up immediately if it applies to you — that is a reason for us to say no early rather than mid-project.
Start here
A 30-minute call is enough for us to tell you whether we can build it, what it will cost to run, and when it goes live.