Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →You are trusting a compliance firm with the evidence of your compliance. That is a fair thing to be careful about, so here is exactly how the platform works, in enough detail that you can check it.
Last reviewed: August 30, 2026
Your scope is the system that delivers your service to your customers. This is where you prepare, and we do not operate your production systems, so for the free workspace we are not a subservice organisation. Mark us out of scope in your register with that reason and the question is closed.
Every framework asks you to assess third parties by risk, and we are a third party. Three things make that a one-minute job rather than a project:
The trust pack below is the same facts as a one-page PDF, written to attach straight to that record.
Servers in Toronto, Canada, on Akamai Connected Cloud, with Cloudflare in front for edge protection. Your data stays in Canada. The origin only accepts traffic from Cloudflare, so the servers are not reachable directly.
TLS in transit, with HSTS so browsers refuse to downgrade. Encryption at rest at the storage layer. Any credential you give an integration is sealed separately with AES-256-GCM, and we cannot display it back to you, only a masked hint.
There are no passwords to leak. Sign-in is a one-time link, valid for 15 minutes, usable once, stored only as a hash. Opening the link does not spend it: it lands on a page that asks you to confirm, so a mail scanner or a chat preview that follows the URL cannot burn your link before you click it. Sign-in requests are rate limited per source. Sessions are HttpOnly, Secure, SameSite cookies.
Every record carries the workspace that owns it, and every query is filtered by it. Identifiers in a URL are checked against your workspace before anything is returned, so changing a number in the address bar returns nothing. We test this by attacking it from one workspace against another.
Owners run the workspace. Members do the work but not billing or team changes. Auditors are read-only and see only what their grant covers. Partner administrators reach only their own client workspaces. You can also define your own roles from the same set of permissions, with one exception: billing can never be delegated to a custom role. Every permission is checked on the server before the write, not by hiding the button, and we verify that by posting every action on every page as every role and confirming the database did not move.
Stored outside anything the web server will serve, renamed to random identifiers, and released only through a handler that checks the file belongs to your workspace. File types are restricted, and anything that could execute in a browser is sent as a download rather than rendered.
During a paid engagement we work inside your records rather than in files of our own. When we do, the screen carries a visible banner naming your organisation, the action is written to our internal audit trail, and anything we draft for you is handed back for you to approve. Your name goes on the approval, not ours.
For as long as the workspace is in use. A workspace with no sign-in for 23 months gets a warning, and is deleted at 24. Ask for deletion sooner and we remove it. Records tied to invoices or signed contracts are kept longer because tax and contract law require it.
We are not SOC 2 audited and there is no certificate behind any of the above. What there is: a platform built by people who assess these controls for a living, a written account of how it works, and a standing offer to answer anything your security team asks before you put data in it.
If you find something wrong with it, tell us at [email protected]. We will not argue with you and we will not threaten anyone who reports a flaw in good faith.
No. Your scope is the system that delivers your service to your customers. A tool you prepare in sits outside that boundary, the same way your ticketing system and your password manager do. Mark it out of scope in your vendor register with that reason, and there is nothing further to do. What does apply is your own vendor management control, which is a control you own rather than a certificate we hold.
Not for the free workspace. A subservice organization operates controls on your behalf that your own control objectives depend on, and recording your assessment in our software is not that. It changes on a paid engagement where we run a named control for you, such as ongoing vulnerability management. Then that control is performed by us and is either carved out or covered by assurance. The statement of work names which controls those are, before you sign.
No. The platform holds what you type into it and the evidence files you choose to upload, which are things like policy documents, access review exports, and configuration screenshots. We do not connect to your production systems and we do not process your customers' data.
No. We are a readiness firm rather than an audited service provider, and there is no such thing as a SOC 2 certificate in any case, only an attestation report. If your procurement process requires an audited vendor, tell us early and we will say plainly whether we meet the bar.
Two cases. If your auditor takes the position that every vendor touching compliance material needs its own attestation report, we do not meet that bar, so raise it early. And on a paid engagement where we operate a named control for you, that control is either carved out or covered by assurance, and the statement of work says which.
Nothing, if we have done our job. The record arrives written: what we hold, where it is hosted, how it is encrypted, who can reach it, and how you get it back out, with our data handling schedule already attached as the terms that apply. It is marked outside your system boundary with the reason on it, so it carries no reassessment cycle and no document for you to chase. Read it, change anything you disagree with, or delete it. It is your register. The trust pack below is the same facts as a one-page PDF if your process wants one separately.
Every register exports to CSV from its own page, policies download as documents, and uploaded files download as you left them. There is no export request and no waiting period. If you want the account deleted, email [email protected] and it goes.
Akamai Connected Cloud hosts the servers in Toronto. Cloudflare sits in front as CDN and edge security. SendGrid carries transactional email. Stripe handles card payments, and we never see or store a card number. That is the whole list for the platform. The privacy policy covers the marketing site as well, including analytics, which the portal itself does not run.