PIPEDA Compliant
All patient data stored exclusively on Canadian servers. Full compliance with federal and provincial privacy legislation.
Every technical safeguard, compliance certification, and data protection measure — documented in one place.
Canadian data centres. Full sovereignty.
PHI stored in Canadian data centres only.
Compliance is non-negotiable.
All patient data stored exclusively on Canadian servers. Full compliance with federal and provincial privacy legislation.
TOTP-based two-factor authentication for all accounts. Required for admin and supervisor roles, protecting access to sensitive PHI.
Every piece of protected health information is encrypted at rest and in transit. Zero plaintext PHI anywhere.
Tamper-proof, immutable audit trails for every action. Export-ready for provincial inspections at any time.
Defense-in-depth security architecture protecting every layer of your data.
Canadian cloud infrastructure with network segmentation, firewall rules, and DDoS protection.
JWT with short-lived tokens, bcrypt password hashing, account lockout after 5 failed attempts.
Role-based access control enforced at the API layer. Multi-tenancy isolation: organization data is architecturally separated.
AES-256 field-level encryption at rest, TLS 1.3 in transit, PHI never appears in application logs.
Immutable audit trail for every sensitive operation. Automated alerts for failed logins, account lockouts, and access events.
Automated monitoring detects anomalous access patterns in real time. Security team is alerted within minutes.
Affected systems are isolated immediately. Incident response team activates the documented IR plan.
Affected organizations notified within 72 hours as required by PIPEDA. Regulatory authorities notified where required.
For organizations requiring detailed security documentation for vendor assessment, compliance reviews, or board approval.
Talk to us. We work with compliance officers and IT teams every day.
Book a Security Review Call →