In development
What we can prove today
The controls below exist in the code; we do not list certificates we have not earned.
Numbers in the running policy
Defaults from the product, not a brochure.
- Idle timeout default
- 15 minIdle timeout defaultA session older than this is signed out
- Minimum password length
- 12Minimum password lengthUppercase, lowercase, digit, and symbol required
- Failed sign-ins before lockout
- 5Failed sign-ins before lockoutThe lock lasts 15 minutes
- HSTS max-age
- 1 yearHSTS max-ageEvery response sends Strict-Transport-Security
Where each layer lives
Production data stays in Canada. The edge is optional.
| Layer | Where it runs |
|---|---|
| Production data | Canada Central, Canada East as the pair |
| Cloudflare | Edge only, or absent. Never the system of record |
| Accessibility target | WCAG 2.1 AA, with axe on every pull request |
| SOC 2 | Not earned, so not claimed |
Trust questions
Do you have SOC 2?
No. We do not claim a report we have not earned.
Is production data on Cloudflare?
No. Production data stays in Canada. Cloudflare is edge only, or absent.
What is the accessibility target?
WCAG 2.1 AA. Axe runs on every pull request. An independent audit is not claimed here.
Where is the audit log?
In the product. Administrators can read who changed what, and when.
Ask a trust question
Write in English or French. Name the control you need to see.