How We Handle Your Data

The practices behind every engagement.

These apply to every project, from the first discovery call onward. They're the answers to the questions a careful buyer actually asks.

Encrypted in transit and at rest

All data moving between you, our systems, and our infrastructure providers is encrypted using industry-standard TLS. Data stored during a project is encrypted at rest.

Tightly scoped access

Access to client data is limited to what's required to deliver the work. Where systems support it, we use role-based access controls that mirror your organizational structure, so people only see what they should.

We never train models on your data

Your data is never used to train AI models — not ours, and not our providers'. We build on enterprise AI services specifically because they contractually commit to the same. Your information is used to do your work, and nothing else.

Retained only as long as needed

We retain client data only for as long as a project requires it, and we delete it on request. You stay in control of your information for the entire lifecycle of an engagement.

Logged and auditable

The automations we build maintain logging across the interactions they handle, so there's a clear, reviewable record of what the system did and when.

Our Infrastructure

Built on enterprise infrastructure — and we name it.

Mature vendors tell you exactly who touches your data. We won't pretend nothing leaves the building. Here's the stack your data passes through, and the terms that govern it.

Anthropic (Claude)

AI Processing

Powers the language and reasoning in our automations. Operates under enterprise terms that prohibit training on customer data. Processing occurs in the United States.

Microsoft Azure

Cloud Infrastructure

Hosts the automations we build and run. Azure can be provisioned in the region your firm requires where data residency is a constraint.

On data residency: If your firm has a strict data-residency requirement, we'll be direct with you early. Cloud infrastructure can be provisioned in the region you need, but AI processing through Anthropic currently occurs in the United States under enterprise data-protection terms. We'd rather tell you this on the first call than surprise you during a security review.

Standards & Compliance

The frameworks we build against.

We design our controls and processes around the standards that matter most in Canadian insurance. Here's where we stand — stated honestly.

PIPEDA & Quebec's Law 25
We design our data-handling practices around the requirements of Canada's federal privacy law (PIPEDA) and Quebec's Law 25, including data minimization, purpose limitation, and supporting your obligations to your own clients.
SOC 2 principles
Our security controls are designed around the SOC 2 principles of security, availability, and confidentiality. Formal SOC 2 certification is on our roadmap as we scale — we're building the practices toward it now rather than claiming a badge we haven't earned.
Cross-border handling
Where data crosses borders through our AI processing layer, it's governed by enterprise data-protection agreements. For engagements touching health-related information, we align handling with the applicable privacy standards on both sides of the border.

What We'll Sign

The paperwork serious vendors do.

These are table stakes for working with a firm that handles sensitive data. We're glad to put them in writing before any data changes hands.

Mutual NDA

We'll sign a mutual non-disclosure agreement before reviewing any of your workflows or data.

Data Processing Agreement

We'll execute a DPA defining exactly how your data is handled, stored, and protected throughout an engagement.

Prompt incident notification

If a security incident ever affects your data, we commit to notifying you promptly and transparently.

Deletion on request

At the end of an engagement, or any time you ask, we delete your data and confirm it in writing.

We'd rather under-promise and be precise than over-claim and lose your trust. If there's a security question we can't answer yet, we'll tell you. If a requirement is something we'd need to build toward, we'll say so plainly and tell you what it would take. In an industry built on assessing risk honestly, we think that's the only way worth operating.

Security Review

Questions about security, data handling, or compliance? Let's talk.

Send your security questionnaire, your compliance checklist, or just your concerns. We'll give you straight answers — and tell you honestly where we stand on each one.

Book a Security Conversation →