Security

Security and Data Residency

Plain answers to the questions that matter most to procurement teams, directors, and IT staff at victim services and law enforcement organizations.

🇨🇦
Files and Documents
All uploaded files, documents, and attachments. Stored on dedicated servers within Canada. Never cross the border.
🖥️
Application Processing
Core application platform on a dedicated US server owned entirely by our organization. Temporary data only. Full disclosure in our DPA.
🔐
Backups and Recovery
All system backups and disaster recovery archives. Encrypted and stored within Ontario, Canada.

Frequently Asked Questions

Q1 Where is our organization's data stored?

AIDARO uses a hybrid infrastructure model designed to protect Canadian data sovereignty for your permanent records while maintaining performance.

  • Uploaded files and documents: Stored strictly on dedicated servers within Canada. Police reports, witness statements, case files, and any other attachments you upload never leave Canadian borders.
  • Application processing: The core application platform runs on a dedicated server in the United States. This server is owned and operated exclusively by our organization. Temporary data sets pass through it as part of normal application operation.
  • System backups: All backups and disaster recovery archives are encrypted and stored within Ontario, Canada.

Q2 Is this setup compliant with PIPEDA?

Yes. Under Canada's federal privacy law, PIPEDA, cross-border data transfer and processing is permitted. PIPEDA requires organizations to maintain comparable privacy protection when data is processed in another country and to be fully transparent about the arrangement.

Our Data Processing Addendum (DPA) formally documents these protections. It is designed to help your organization meet its own accountability and transparency obligations under PIPEDA.

Q3 Does a third-party cloud provider have access to our data?

No. AIDARO does not run on shared public cloud infrastructure such as Amazon Web Services, Microsoft Azure, or Google Cloud. Our application runs entirely on dedicated physical servers owned, managed, and controlled exclusively by our organization. Your data is never co-mingled with data from other companies or tenants.

Q4 Who has administrative access to the servers?

Physical and logical access to both our Canadian storage infrastructure and our US application server is strictly restricted. Only our internal system administrators are granted access. All administrators are comprehensively vetted and background-checked. No external contractors, cloud providers, or third-party vendors have standing access to the servers.

Q5 What is the risk from the US CLOUD Act?

Because our application platform runs on a server in the United States, temporary data sets processed by the application are subject to US jurisdiction. Under the US CLOUD Act, US federal authorities can compel data disclosures through valid legal orders.

We take several steps to reduce this risk as much as possible:

  • The highest-sensitivity files (police reports, witness statements, case documents) are stored entirely in Canada and are not hosted on the US server.
  • We review all legal requests carefully and use every available legal avenue to challenge requests that are overbroad or not properly authorized.
  • We will notify your organization immediately of any intercept request unless we are legally prohibited from doing so.

Full details are documented in our Data Processing Addendum.

Q6 How is data protected in transit and at rest?

  • In transit: All data moving between your organization's devices and our servers is protected using TLS (Transport Layer Security). This applies to all connections including between our Canadian and US infrastructure.
  • At rest: All data stored on our servers, including on the Canadian file servers, the US application server, and the Ontario backup archives, is encrypted using AES-256 bit encryption.

Q7 What access controls does the platform use?

  • Role-based access control (RBAC): Each user can only see and interact with the data their role permits. Access is set at the organization level by your administrators.
  • Multi-factor authentication (MFA): MFA is available for all users and can be made mandatory by your organization's administrators.
  • Audit logging: Every login, data change, and file access is logged and stored. Your administrators can access these logs at any time.
  • Session management: Sessions expire after a set period. Inactive sessions are terminated automatically.

Q8 What happens if there is a security breach?

If we confirm a security incident that affects your organization's data, we will notify you within 24 hours. We will provide the technical details you need to meet your mandatory breach-reporting obligations to the Office of the Privacy Commissioner of Canada. We maintain a comprehensive incident response plan for exactly this scenario.

Read the Data Processing Addendum Privacy Policy Request a Demo