The information you store in Veille, which AI systems you operate, what data they process, where your compliance gaps are, is among the most strategically sensitive data in your organization. We treat it accordingly. This document explains exactly how.
Every component of the Veille platform is deployed in AWS ca-central-1, the Montréal region. All storage and application processing stay in Canada. The one exception today is LLM inference, which runs on Anthropic's API (US) for compliance reasoning over metadata.
| Data category | What it contains | Storage and access |
|---|---|---|
| AI system inventoryYour organization's core compliance record | System names, operators, data categories, risk tiers, jurisdiction assignments, classification history | Encrypted at rest, isolated per organization, accessible only to your authenticated users and, on written request, Veille support |
| Evidence vault artifactsNotices, PIAs / EFVPs, assessment reports, signed documents | Compliance documents you upload or that the system generates on your behalf | WORM storage with a verifiable cryptographic hash chain, any modification breaks the chain and is detectable. Write-once with retention; deletion requires an explicit purge request with contractual authorization. |
| Compliance posture dataGap analyses, obligation status, remediation logs | Which obligations are met, which are not, and the full action history for each | Encrypted at rest. Audit log on every state change. Not accessible to Veille staff without a written service request. |
| User accounts and access logsIdentity and authentication records | Email addresses, role assignments, login events, session metadata | Stored in ca-central-1. MFA enforced. Access logs retained for 12 months minimum. |
| Connector credentialsAPI keys for cloud integrations (Enterprise tier) | AWS, Databricks, MLflow, GitHub, SageMaker read-only integration credentials | Stored in AWS Secrets Manager, never in application database. Read-only scope enforced. Rotation on request. |
Access to your data is governed by role-based controls within your organization and by explicit authorization requirements for any Veille staff access. The default is closed. Every exception is logged.
Each user in your organization is assigned a role, admin, compliance lead, auditor, or viewer. Roles determine what data can be read, what actions can be taken, and what can be exported. Roles are assigned by your organization's admin.
ActiveTOTP-based MFA is available for all user accounts. Hardware key (FIDO2/WebAuthn) support is on the roadmap for Q4 2026. Enterprise organizations can enforce MFA as a condition of access.
Q4 2026SAML 2.0 and OIDC SSO are planned for the Enterprise tier. Organizations will be able to enforce SSO-only access and centralize user provisioning through their identity provider.
Enterprise tier, RoadmapVeille staff cannot access your organization's data as part of routine operations. Any access, for support, debugging, or incident response, requires a written service request, generates an immutable log entry, and is subject to quarterly access review.
ActiveEnterprise deployments receive dedicated audit log streams that are isolated from the shared platform. Your internal audit team and your information security team can access these logs directly, independently of Veille operations.
Enterprise tier, Q4 2026All Veille employees and contractors who can access production systems undergo background screening prior to onboarding. Access is granted on a least-privilege basis and reviewed quarterly. Offboarding revokes all access within 24 hours.
ActiveWe are at an early stage. We are honest about that. What follows is our current compliance posture and our committed certification roadmap, with dates we hold ourselves to publicly.
Veille operates as a data processor under PIPEDA and the Québec privacy law (Law 25). We process personal information on behalf of our clients under a data processing agreement. Our data practices are designed to meet both frameworks, and we provide DPAs structured under both on request.
We are preparing for a SOC 2 Type II audit covering Security, Availability, and Confidentiality trust service criteria. The audit observation period is planned to begin Q2 2026, with the report targeted for Q4 2026. Design partners will receive the draft controls framework on request.
ISO 27001 certification is planned for 2027 as the organization scales. The information security management system (ISMS) is being built in accordance with ISO 27001 controls from the outset, making certification a formalization of existing practices rather than a retrofit.
AWS ca-central-1 is certified under SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, PCI DSS, and meets the requirements of Canadian provincial and federal privacy regulators for data residency. The full AWS compliance posture for that region is available on the AWS compliance website.
We maintain a complete list of subprocessors and update it when any change occurs. You will receive 30 days advance notice of any new subprocessor that will have access to your organization's data.
| Subprocessor | Data location | Purpose | Data accessed |
|---|---|---|---|
| Amazon Web Services | Canada, ca-central-1 | Infrastructure hosting, compute, storage, networking, secrets management | Storage and application processing in ca-central-1 (Canada); LLM inference residency via Bedrock (Canada), in activation |
| Anthropic | US (migrating to Bedrock) | LLM inference for compliance reasoning (Claude) | Compliance metadata sent at inference time; vault document content is never sent. No training on your data. Migrating to AWS Bedrock (Canada) for full Canadian residency. |
| No others | None | No analytics platforms, no advertising networks, no other US-based SaaS that receives compliance data | None |
We do not use Salesforce, HubSpot, Intercom, or any other CRM or customer engagement platform that would receive data about your organization's compliance posture. When you contact us, that conversation stays within our email systems, hosted on Google Workspace Canada.
A data processing agreement is provided with every Veille contract, regardless of tier. It is not an add-on, not a negotiation, and not an upgrade. It is a baseline.
Your organization determines the purposes and means of processing your compliance data. Veille processes it on your instructions, under your authority, within the constraints of the DPA. We do not use your data for any purpose other than delivering the service you subscribed to.
In the event of a confirmed security incident affecting your data, we notify your designated security contact within 72 hours of detection, earlier when possible. The notification includes the nature of the incident, data affected, and remediation steps underway. This is Veille's processor-to-controller commercial SLA; it is distinct from your own Law 25 obligation to notify the Commission d'accès à l'information "avec diligence" (with diligence), which has no fixed deadline.
Upon contract termination, all your organization's data is deleted from production systems within 30 days. Backup copies are purged within 90 days. You receive a written confirmation of deletion on request. Evidence vault artifacts subject to legal holds are retained only on your explicit written instruction.
You can request a full export of your organization's data at any time, inventory, evidence vault artifacts, audit logs, and compliance history, in structured formats (JSON, CSV, PDF). We deliver within 10 business days. No egress fee.
The DPA is available for review before you sign anything. Send us an email at [email protected] and we will send the current version within one business day.
A credible security posture includes a documented response to failures, not just a description of controls. This is our incident response process, public and committed.
AWS GuardDuty, CloudTrail, and application monitoring detect anomalous activity. On-call engineer is notified within minutes. Incident is classified by severity.
Affected systems are isolated. Access is revoked for any compromised credentials. Evidence preservation begins. Scope of impact is assessed.
Written notification to your designated security contact. Includes incident nature, data affected, timeline, and remediation steps. Issued within 72 hours of confirmation, earlier when possible.
A written post-incident review is shared with affected clients within 30 days. Includes root cause analysis, what changed, and what was put in place to prevent recurrence.
Every enterprise sale in this space involves a security questionnaire. We complete them as a standard part of the sales process, not as a premium service, not on a separate timeline, and not with a consultant intermediary.
| Questionnaire type | Turnaround | Notes |
|---|---|---|
| Standard vendor security questionnaireVSQ, CAIQ, SIG Lite equivalent | 5 business days | Completed by our security team. Shared in your preferred format. Available for reuse across your procurement system. |
| Extended security reviewFull SIG, FSQS, or equivalent for regulated institutions | 10 business days | Completed in collaboration with our legal and technical teams. Standard for financial institutions and public sector procurement. |
| On-site or virtual security reviewCISO walkthrough, architecture review | On request | We make our CTO and relevant technical staff available for a live architecture review. No additional fee. Available for Enterprise tier prospects and design partners. |
| Data processing agreement reviewLegal review of DPA terms | 5 business days | We engage with reasonable DPA redline requests. Our DPA is structured to be compatible with financial sector requirements and Law 25 processor obligations. |
Send us an email. We will respond within one business day with the full security brief, the current DPA, and the subprocessor list in your preferred format. If you have a questionnaire, attach it and we will complete it on the same timeline.