ValdraBY CANUCKT All legal documents →

Security Overview

Valdra — Canuckt Synergy Solutions Inc. Version 1.0 · 28 July 2026

A summary for security and privacy reviewers. Written to answer the questions you are going to ask anyway.


The short version

Where is our data? Canada. Beauharnois, Québec. Backups also in Canada.
Is it encrypted? TLS 1.3 in transit. Encrypted at rest and in backups.
Who can see it? Named personnel only, key-based access, least privilege.
Is access logged? Yes — immutable audit log, exportable by you.
Do you train AI on our data? No.
Are you SOC 2 certified? Not yet. Programme in place, certification in progress.
Uptime commitment? 99.0% monthly with service credits.
Breach notification? Within 48 hours of us becoming aware.

Data residency

Production infrastructure is in Beauharnois, Québec, Canada (OVH). Customer records are stored and processed there. Encrypted backups replicate to separate Canadian infrastructure.

We do not store primary customer data outside Canada, and will not without 30 days' notice and your right to terminate.

Encryption

Access control

For your users: - Multi-factor authentication available to every account, and enforceable organisation-wide by your administrator. - Role-based access: admin, member, auditor, viewer — least privilege by default. - Optional IP allowlisting for administrative actions. - Optional SAML single sign-on and SCIM provisioning. - Passwordless sign-in by time-limited link; no password database to breach.

For our personnel: - Production access restricted to named individuals, key-based only, password authentication disabled. - Access on a least-privilege basis, reviewed when roles change. - Written confidentiality obligations. - Administrative access is recorded in the audit log.

Logging and audit

An immutable audit log records authentication, administrative actions and changes to compliance records — attributed to a user, timestamped, and exportable by you without needing to ask us. That last point matters for regulators who expect the custodian to produce records independently.

Application errors are monitored automatically, with personal information scrubbed before transmission.

AI processing

Valdra uses AI to draft recommendations, policies and reports.

Resilience and continuity

Secure development

Incident response

If your data is involved, we notify you within 48 hours of becoming aware, with what happened, what data was affected, likely consequences and our response — enough for you to meet your own obligations to the Privacy Commissioner of Canada or, where PHIPA applies, the Information and Privacy Commissioner of Ontario.

Security contact: [email protected]

Certifications — stated plainly

We operate a formal information security and AI management programme aligned to SOC 2 Type II, ISO/IEC 27001 and ISO/IEC 42001 — run inside Valdra itself, which is the same product you would be buying.

We are not yet certified against those standards. Certification takes an audit period and we are working through it.

We could have written this section to imply otherwise. We would rather you knew exactly where we stand — and could verify it — than discover a gap during your own audit. If certification is a hard requirement for you today, tell us and we will be straight about the timeline.

What we would tell you if you asked us privately

We are a small company. That has real advantages — you get a direct line to the person who builds the product, and issues get fixed in hours rather than quarters. It also means we do not yet have 24/7 staffed operations or multi-region redundancy, which is exactly why our uptime commitment is 99.0% rather than a number we could not consistently meet.

We will tell you when that changes.


Questions, or need a completed security questionnaire? [email protected] — we respond to reasonable questionnaires at no charge.