Cyber Chain TechnologiesNEXUSBook a Confidential DiscussionSign in

How we handle your data

You apply vendor-risk scrutiny for a living. This page is written for that review: the commitments below are how we operate, and each one belongs in the agreement we sign with you — hold us to them in writing, not on trust.

Canadian data residency

Client data is stored and processed on Canadian-resident infrastructure. Where an engagement involves any cross-border component, it is disclosed and agreed in writing before any data moves — never discovered after the fact.

NDA before disclosure

We sign a mutual non-disclosure agreement before you share anything sensitive. Assessment details, gap findings, vendor lists, and internal documents are covered from the first working conversation.

No training on client data

Client data is never used to train AI models — ours or anyone else's. AI systems in our platform run inference only, and every model and prompt version used to produce an output is recorded.

Human review of every AI output

AI-drafted content in our platform is flagged as such and requires review and approval by a qualified professional before it is treated as a deliverable. Assessment results are readiness estimates reviewed by people — not automated compliance determinations.

Least data, least access

We collect the minimum needed for the engagement. Our healthcare tooling is designed to operate on governance metadata, not personal health information. Access is role-based, and client tenants are strictly separated.

Audit trails throughout

Actions in our platform are logged in append-only audit records: who did what, when, and on what evidence. If you ask us how a recommendation was produced, we can show you.

Breach notification

If an incident affects your data, we notify you promptly with what we know, what we're doing, and what we recommend — supporting your own PHIPA, FIPPA/MFIPPA, or contractual notification duties rather than complicating them.

Exit with your data

On engagement end, your data is returned or destroyed per the agreement, with destruction confirmed — the same clause we tell clients to demand from every AI vendor.

Have a vendor-assessment questionnaire? Send it — answering them properly is part of the job.

Book a Confidential Discussion