Security
Plain answers to the questions that matter most to procurement teams, directors, and IT staff at victim services and law enforcement organizations.
Frequently Asked Questions
AIDARO uses a hybrid infrastructure model designed to protect Canadian data sovereignty for your permanent records while maintaining performance.
Yes. Under Canada's federal privacy law, PIPEDA, cross-border data transfer and processing is permitted. PIPEDA requires organizations to maintain comparable privacy protection when data is processed in another country and to be fully transparent about the arrangement.
Our Data Processing Addendum (DPA) formally documents these protections. It is designed to help your organization meet its own accountability and transparency obligations under PIPEDA.
No. AIDARO does not run on shared public cloud infrastructure such as Amazon Web Services, Microsoft Azure, or Google Cloud. Our application runs entirely on dedicated physical servers owned, managed, and controlled exclusively by our organization. Your data is never co-mingled with data from other companies or tenants.
Physical and logical access to both our Canadian storage infrastructure and our US application server is strictly restricted. Only our internal system administrators are granted access. All administrators are comprehensively vetted and background-checked. No external contractors, cloud providers, or third-party vendors have standing access to the servers.
Because our application platform runs on a server in the United States, temporary data sets processed by the application are subject to US jurisdiction. Under the US CLOUD Act, US federal authorities can compel data disclosures through valid legal orders.
We take several steps to reduce this risk as much as possible:
Full details are documented in our Data Processing Addendum.
If we confirm a security incident that affects your organization's data, we will notify you within 24 hours. We will provide the technical details you need to meet your mandatory breach-reporting obligations to the Office of the Privacy Commissioner of Canada. We maintain a comprehensive incident response plan for exactly this scenario.