Quebec-hosted · Law 25 · LCJTI · 2FA · daily encrypted backups

Your data.
Yours. Encrypted.

Hosted in Québec, Canada. Backups encrypted with a key we don't store on the server. Per-tenant database isolation. 2FA mandatory for every account. Law 25 art. 17 compliant by design.

Hosting in Québec

Hosted in Québec, Canada. CDN + WAF in front. End-to-end TLS. Data never leaves Canada.

  • Datacenter: Québec, Canada
  • TLS 1.3 in transit
  • Geo-blocking: North America + EU only
  • External uptime monitoring (every 5 min)

Law 25 compliance

Quebec's Act to Modernize Legislative Provisions on the Protection of Personal Information (Bill 64 / Law 25). Compliant by design.

  • Granular consents (marketing, transactional, profiling)
  • 90-day retention with anonymization on deletion
  • Right to access / portability via export
  • Audit log on every data change
  • 72-hour breach notification (art. 65)

LCJTI e-signing

Quebec Act respecting the legal framework for information technology, Sections 38 and 39. Signed quotes hold up in court.

  • 256-bit CSPRNG token per signer
  • Proof PDF: signature, timestamp, IP, user agent, activity log
  • Rate-limited 30 GET / 5 POST per minute per IP
  • Token invalidated immediately after signing

2FA TOTP — mandatory

Time-based one-time passwords via any standard authenticator. Mandatory for every account — like banks, but on your CRM.

  • Google Authenticator, Microsoft, Bitwarden, Authy, 1Password
  • 8 single-use recovery codes
  • Mandatory for every account · 7-day default grace (adjustable 1-336 h)
  • Lost 2FA: recovery codes or admin reset (not in UI)

Encrypted backups

3-2-1 strategy: 3 copies, 2 media types, 1 off-site. GPG passphrase stored outside the server.

  • Daily encrypted database snapshots (AES-256)
  • On-server 7 days + off-site Canadian region 30 days
  • 40-character passphrase stored outside our infrastructure
  • Restore procedure documented and validated periodically

Tenant isolation

Each tenant runs on its own isolated database with its own database credentials scoped strictly to that database. Specifically audited.

  • Dedicated database + dedicated credentials per tenant
  • 32-character random passwords
  • Automated cross-tenant access tests
  • Separate hosting environment per tenant

Things we do that we don't advertise.

  • Weekly automated CVE scan (Composer + Dependabot)
  • Monthly automated kernel patches + reboot (1st Sunday)
  • Weekly security report sent to admin (only if action required)
  • Daily OS security updates applied automatically
  • WAF + geo-blocking on public surfaces (North America + EU only)
  • External uptime monitoring every 5 minutes
  • Additional access protection on admin surfaces (one-time PIN)
  • No third-party tracking scripts on signup or billing flows
  • No analytics on logged-in admin pages (privacy)
/ faq

Security — common questions

Where exactly is my data stored?
Primary database and uploads are hosted in Québec (Canada). Daily encrypted backups are synced to a separate datacenter in another Canadian region (Ontario). Data never leaves Canadian soil — Law 25 art. 17 compliant. Specific subprocessor names are listed in our Privacy Policy as required by law.
Is the data encrypted?
In transit: TLS 1.3 end-to-end. At rest: database tablespace encryption. Backups: AES-256 encryption with a 40-character random passphrase stored outside our infrastructure. Without that passphrase, backup blobs are unreadable — protects against US Cloud Act subpoena.
Can other tenants see my data?
No. Each tenant runs on its own isolated database with its own database credentials scoped strictly to that database. Even in the worst-case scenario where one tenant's credentials leaked, those credentials would only unlock that tenant's data. This was specifically audited.
What 2FA options are supported?
TOTP via any standard authenticator: Google Authenticator, Microsoft Authenticator, Bitwarden, 1Password, Authy. 8 single-use recovery codes generated on enrollment. 2FA is mandatory for every account — tenant admins can adjust the grace period (1-336 h, default 7 days) but cannot disable enforcement.
How does Law 25 compliance work in practice?
Granular consents on contacts (marketing, transactional, profiling) with timestamps. 90-day default retention with anonymization on deletion (PII scrubbed, statistics preserved). Right to access/portability via CSV/Excel/PDF export. Right to be forgotten via UI button. Audit log records every change to your data. DPO/Privacy Officer details on the Privacy page.
What about backups — can I restore?
Yes. Three-layer backup: (1) on-server retention for the last 7 days, (2) off-site Canadian datacenter for 30 days, (3) optional off-network pull for 14 days. Restore procedure documented and periodically validated.
How are passwords stored?
Bcrypt-hashed, never reversible. We cannot see your password. Password reset works via a one-use token sent to your verified email. If you lose your 2FA device, recovery codes are the primary path (admin-side reset exists but is intentionally not exposed in the UI).
What if there's a security incident?
We notify affected customers within 72 hours per Law 25 art. 65 obligations. Audit log allows us to identify exactly which records were modified, when and by whom. We follow a documented incident response procedure (not published, for security). Backups in a separate region mean ransomware on the production environment doesn't take down recovery.
Are you SOC 2 / ISO 27001 certified?
Not yet — those certifications are costly and aimed at larger organizations. We follow the controls (encrypted backups, least-privilege access, audit logs, MFA, dependency scanning, weekly CVE reports), but we don't have a third-party attestation. If you need a formal certification for procurement, talk to us first.
Do you have a public security report?
We publish transparency notes on request (uptime, security patches applied, incidents if any). Email [email protected] to receive them. We don't publish them on a public page yet because we're in soft-launch.

Have a specific security question for procurement?