Security
Built like grown-up software.
Encryption in transit + at rest. Regional data residency. SOC 2 in progress. Annual penetration testing. PIPEDA + Quebec Law 25 + GDPR posture.
Pillars
What we ship by default.
Encryption
TLS 1.3 in transit. AES-256 at rest. Keys managed by AWS KMS.
Data residency
Canadian customer data in AWS ca-central-1 (Montréal). US data in us-east-2 (Ohio).
SOC 2 Type II
Audit in progress. Report available under NDA when issued.
Penetration testing
Annual 3rd-party pentest. Last conducted Q1 2026.
Access control
Role-based permissions, MFA enforced for staff, audit logs retained 25 months.
STIR/SHAKEN
Attestation A on every owned outbound number. No spoofed caller ID.