CapGRC
Back to platform
Security & hosting

Your GRC hosted and secured in Canada

Your GRC data is among the most sensitive in your organization. At CapGRC, security is not a feature: it's our foundation.

Canada only

Hosting

AES-256

Encryption

High availability

Availability

Daily

Backups

Hosting exclusively in Canada

All your data, risks, compliance evidence, audit reports, personal information, is stored in data centers located in Canada. No transfer to foreign servers.

  • Data centers located in Canada
  • Aligned with Law 25 data sovereignty
  • Compatible with Canadian public-sector expectations
  • Canadian cloud infrastructure
  • Data Processing Agreement (DPA) available

Data location

Production data
Canada
Primary backups
Canada
Secondary backups
Canada (separate region)
Logs and audit trails
Canada
CDN (static assets)
Canadian points of presence

Security architecture

End-to-end encryption

  • AES-256 encryption of data at rest
  • TLS 1.3 for communications in transit
  • Backup encryption
  • Key management with periodic rotation

Access control

  • MFA available, mandatory for administrators
  • Granular RBAC per module, data and entity
  • SSO / SAML with Azure AD, Okta, Google Workspace
  • User action logging

Infrastructure protection

  • Web application firewall (WAF)
  • DDoS protection
  • Regular vulnerability scanning
  • Annual penetration testing by third parties

Continuity & resilience

  • Daily backups with configured retention
  • Contractually defined RTO / RPO objectives
  • Redundancy in Canada
  • Documented business continuity plan (BCP)

Monitoring & detection

  • Infrastructure monitoring
  • Security alerts and centralized logging
  • Abnormal behavior tracking
  • Incident notification process

Compliance & certifications

  • Law 25 compliant hosting (data in Canada)
  • SOC 2 Type II in progress for CapGRC
  • Responsible disclosure policy
  • Third-party security audits

Compliance & certifications

01

Law 25

Compliant

Exclusive hosting in Canada, DPIA completed, DPO designated, active incident register.

02

SOC 2 Type II

In progress

Certification process underway. Trust Services Criteria controls are being progressively strengthened.

03

ISO 27001

Planned

ISO 27001 certification program planned alongside the SOC 2 initiative.

04

PIPEDA / Bill C-27

Compliant

Processing of personal information compliant with the Personal Information Protection Act.

CA

High availability in Canada

Redundant infrastructure in Canada, automatic daily backups and a documented incident response process. Contractual commitments (SLA) are specified according to your plan.

Request security report

Questions about our security?

Our team can provide our security policy, answer your vendor questionnaires and share audit materials under NDA.