Trust Centre

Security, privacy, and reliability

Compliance Health places security, privacy, and Canadian data sovereignty at the heart of everything we do. Explore the safeguards that protect your organization and your learners.

Highlights

  • All customer data is stored and processed in Canada to satisfy Canadian data sovereignty.
  • Defence-in-depth: Encryption in transit and at rest, RBAC and MFA for privileged access, and continuous audit logging.
  • AI-assisted workflows keep people in the loop with auditable checkpoints for every automated decision.

Data residency

All customer data is securely stored and processed exclusively within Canada, supporting compliance with Canadian privacy and data residency expectations, including PIPEDA and applicable provincial regimes.

Encryption

We employ robust, industry-leading encryption methods:

  • Encryption in transit: All data transfers between your browser and our servers are protected using industry-standard protocols.
  • Encryption at rest: Data stored in our systems utilize industry-standard encryption algorithms.
  • Key management: Encryption keys are securely managed with automatic rotation.

Human-in-the-loop

Compliance Health's AI compliance tools integrate human oversight into critical decision points. Every automated decision undergoes human review, ensuring accountability and accuracy. Comprehensive audit logs track all AI-assisted processes.

ISO/IEC 42001 roadmap

We are dedicated to obtaining ISO/IEC 42001 certification for AI Management Systems, reinforcing our commitment to ethical AI usage and best practices. Our comprehensive controls catalog aligns with responsible AI standards.

Status

Current state

In progress

Target completion

Q2 2027

Security overview

Compliance Health proactively ensures security:

  • All document uploads undergo antivirus scanning.
  • Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) protect administrative access.
  • Comprehensive logging and auditing track all security events.

Policies & documentation

For detailed information about our policies and practices:

Contact us

For any questions related to security, privacy, or compliance: