Enterprise security, Veille AI, Montréal

Your AI inventory is sensitive data. Here is how we protect it.

The information you store in Veille, which AI systems you operate, what data they process, where your compliance gaps are, is among the most strategically sensitive data in your organization. We treat it accordingly. This document explains exactly how.

Hosted in ca-central-1 (Montréal) Storage and application processing in Canada Per-organization isolation DPA with every contract Security questionnaires completed as standard
CA
Data stored and processed in Canada, AWS ca-central-1
1
US inference exception, migrating to Bedrock ca-central-1
72h
Maximum notification SLA for a material security incident
DPA
Data processing agreement provided with every contract, no exceptions
Data architecture

Where your data lives. How it is isolated.

Every component of the Veille platform is deployed in AWS ca-central-1, the Montréal region. All storage and application processing stay in Canada. The one exception today is LLM inference, which runs on Anthropic's API (US) for compliance reasoning over metadata.

Veille platform architecture, data residency and isolation model
Hosting region
AWS ca-central-1, Montréal, QC
No US region
No EU region
Tenant isolation
Dedicated environment (Enterprise)
Logical isolation per organization (Pilot / Scale)
No cross-tenant data access possible
Encryption
AES-256 at rest
TLS 1.3 in transit
Evidence vault, cryptographic hash chain (WORM)
Audit trail
AWS CloudTrail, all API calls logged
Application audit log, immutable, per action
Veille staff access requires a written service request
Storage and application processing remain within AWS ca-central-1 at all times. LLM inference runs on Anthropic's API (US) today, migrating to Bedrock.
Data category What it contains Storage and access
AI system inventoryYour organization's core compliance record System names, operators, data categories, risk tiers, jurisdiction assignments, classification history Encrypted at rest, isolated per organization, accessible only to your authenticated users and, on written request, Veille support
Evidence vault artifactsNotices, PIAs / EFVPs, assessment reports, signed documents Compliance documents you upload or that the system generates on your behalf WORM storage with a verifiable cryptographic hash chain, any modification breaks the chain and is detectable. Write-once with retention; deletion requires an explicit purge request with contractual authorization.
Compliance posture dataGap analyses, obligation status, remediation logs Which obligations are met, which are not, and the full action history for each Encrypted at rest. Audit log on every state change. Not accessible to Veille staff without a written service request.
User accounts and access logsIdentity and authentication records Email addresses, role assignments, login events, session metadata Stored in ca-central-1. MFA enforced. Access logs retained for 12 months minimum.
Connector credentialsAPI keys for cloud integrations (Enterprise tier) AWS, Databricks, MLflow, GitHub, SageMaker read-only integration credentials Stored in AWS Secrets Manager, never in application database. Read-only scope enforced. Rotation on request.
Access controls

Who can see what. And who cannot.

Access to your data is governed by role-based controls within your organization and by explicit authorization requirements for any Veille staff access. The default is closed. Every exception is logged.

Role-based access control

Each user in your organization is assigned a role, admin, compliance lead, auditor, or viewer. Roles determine what data can be read, what actions can be taken, and what can be exported. Roles are assigned by your organization's admin.

Active

Multi-factor authentication

TOTP-based MFA is available for all user accounts. Hardware key (FIDO2/WebAuthn) support is on the roadmap for Q4 2026. Enterprise organizations can enforce MFA as a condition of access.

Q4 2026

Single sign-on (SSO)

SAML 2.0 and OIDC SSO are planned for the Enterprise tier. Organizations will be able to enforce SSO-only access and centralize user provisioning through their identity provider.

Enterprise tier, Roadmap

Staff access policy

Veille staff cannot access your organization's data as part of routine operations. Any access, for support, debugging, or incident response, requires a written service request, generates an immutable log entry, and is subject to quarterly access review.

Active

Isolated audit logs (Enterprise)

Enterprise deployments receive dedicated audit log streams that are isolated from the shared platform. Your internal audit team and your information security team can access these logs directly, independently of Veille operations.

Enterprise tier, Q4 2026

Employee background screening

All Veille employees and contractors who can access production systems undergo background screening prior to onboarding. Access is granted on a least-privilege basis and reviewed quarterly. Offboarding revokes all access within 24 hours.

Active
Certifications and compliance

Where we are. Where we are going.

We are at an early stage. We are honest about that. What follows is our current compliance posture and our committed certification roadmap, with dates we hold ourselves to publicly.

PIPEDA
/ Law 25

Privacy, PIPEDA and Law 25 as processor

Veille operates as a data processor under PIPEDA and the Québec privacy law (Law 25). We process personal information on behalf of our clients under a data processing agreement. Our data practices are designed to meet both frameworks, and we provide DPAs structured under both on request.

Active, DPA available on request
SOC 2
Type II

SOC 2 Type II audit

We are preparing for a SOC 2 Type II audit covering Security, Availability, and Confidentiality trust service criteria. The audit observation period is planned to begin Q2 2026, with the report targeted for Q4 2026. Design partners will receive the draft controls framework on request.

Target: Q4 2026
ISO
27001

ISO 27001 information security management

ISO 27001 certification is planned for 2027 as the organization scales. The information security management system (ISMS) is being built in accordance with ISO 27001 controls from the outset, making certification a formalization of existing practices rather than a retrofit.

Target: 2027
AWS
CAN

AWS Canada infrastructure compliance

AWS ca-central-1 is certified under SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, PCI DSS, and meets the requirements of Canadian provincial and federal privacy regulators for data residency. The full AWS compliance posture for that region is available on the AWS compliance website.

Active, inherited from AWS, View AWS certifications
Subprocessors

Every third party that touches your data. Listed completely.

We maintain a complete list of subprocessors and update it when any change occurs. You will receive 30 days advance notice of any new subprocessor that will have access to your organization's data.

Subprocessor Data location Purpose Data accessed
Amazon Web Services Canada, ca-central-1 Infrastructure hosting, compute, storage, networking, secrets management Storage and application processing in ca-central-1 (Canada); LLM inference residency via Bedrock (Canada), in activation
Anthropic US (migrating to Bedrock) LLM inference for compliance reasoning (Claude) Compliance metadata sent at inference time; vault document content is never sent. No training on your data. Migrating to AWS Bedrock (Canada) for full Canadian residency.
No others None No analytics platforms, no advertising networks, no other US-based SaaS that receives compliance data None

We do not use Salesforce, HubSpot, Intercom, or any other CRM or customer engagement platform that would receive data about your organization's compliance posture. When you contact us, that conversation stays within our email systems, hosted on Google Workspace Canada.

Data processing agreement

The legal framework behind every contract.

A data processing agreement is provided with every Veille contract, regardless of tier. It is not an add-on, not a negotiation, and not an upgrade. It is a baseline.

Data controller / processor relationship

You remain the controller. We are the processor.

Your organization determines the purposes and means of processing your compliance data. Veille processes it on your instructions, under your authority, within the constraints of the DPA. We do not use your data for any purpose other than delivering the service you subscribed to.

Breach notification

72-hour notification SLA. No exceptions.

In the event of a confirmed security incident affecting your data, we notify your designated security contact within 72 hours of detection, earlier when possible. The notification includes the nature of the incident, data affected, and remediation steps underway. This is Veille's processor-to-controller commercial SLA; it is distinct from your own Law 25 obligation to notify the Commission d'accès à l'information "avec diligence" (with diligence), which has no fixed deadline.

Data deletion

Deletion within 30 days of contract end.

Upon contract termination, all your organization's data is deleted from production systems within 30 days. Backup copies are purged within 90 days. You receive a written confirmation of deletion on request. Evidence vault artifacts subject to legal holds are retained only on your explicit written instruction.

Data portability

Your data, in a portable format, on request.

You can request a full export of your organization's data at any time, inventory, evidence vault artifacts, audit logs, and compliance history, in structured formats (JSON, CSV, PDF). We deliver within 10 business days. No egress fee.

The DPA is available for review before you sign anything. Send us an email at [email protected] and we will send the current version within one business day.

Incident response

What happens when something goes wrong.

A credible security posture includes a documented response to failures, not just a description of controls. This is our incident response process, public and committed.

00h
Detection

Detect and classify

AWS GuardDuty, CloudTrail, and application monitoring detect anomalous activity. On-call engineer is notified within minutes. Incident is classified by severity.

02h
Containment

Isolate and contain

Affected systems are isolated. Access is revoked for any compromised credentials. Evidence preservation begins. Scope of impact is assessed.

72h
Notification

Notify affected clients

Written notification to your designated security contact. Includes incident nature, data affected, timeline, and remediation steps. Issued within 72 hours of confirmation, earlier when possible.

Post
Review

Post-incident report

A written post-incident review is shared with affected clients within 30 days. Includes root cause analysis, what changed, and what was put in place to prevent recurrence.

Ongoing security operations
  • AWS GuardDuty, continuous threat detection
  • CloudTrail, all API activity logged and retained
  • Dependency vulnerability scanning on every deploy
  • Static code analysis in CI pipeline
  • Quarterly internal security review
On the roadmap
  • Annual third-party penetration test, target Q4 2026
  • Bug bounty program, target Q1 2027
  • SOC 2 Type II report, target Q4 2026
  • Dedicated security portal for Enterprise clients
  • ISO 27001 certification, target 2027
Security questionnaires

We complete them. No surcharge. No delay.

Every enterprise sale in this space involves a security questionnaire. We complete them as a standard part of the sales process, not as a premium service, not on a separate timeline, and not with a consultant intermediary.

Questionnaire type Turnaround Notes
Standard vendor security questionnaireVSQ, CAIQ, SIG Lite equivalent 5 business days Completed by our security team. Shared in your preferred format. Available for reuse across your procurement system.
Extended security reviewFull SIG, FSQS, or equivalent for regulated institutions 10 business days Completed in collaboration with our legal and technical teams. Standard for financial institutions and public sector procurement.
On-site or virtual security reviewCISO walkthrough, architecture review On request We make our CTO and relevant technical staff available for a live architecture review. No additional fee. Available for Enterprise tier prospects and design partners.
Data processing agreement reviewLegal review of DPA terms 5 business days We engage with reasonable DPA redline requests. Our DPA is structured to be compatible with financial sector requirements and Law 25 processor obligations.
To initiate a security review, send the questionnaire or your preferred format to [email protected]. Include the name of your organization and a brief description of what you're evaluating. We will acknowledge within one business day and confirm the turnaround timeline.

The security brief is yours. No strings attached.

Send us an email. We will respond within one business day with the full security brief, the current DPA, and the subprocessor list in your preferred format. If you have a questionnaire, attach it and we will complete it on the same timeline.

Serge Anthony Maa, Founder, Montréal, 2026 Veille Technologies Inc., Montréal, QC, 2026