Diligence, answered before the sales call
Trust & governance
You are considering handing your product catalog to a very small Quebec vendor. This page states the platform’s data-protection posture in full — the same facts that are in our contracts, including the unflattering ones — so you can finish that assessment without a sales call.
Data residency
All Client Data and Personal Data is hosted in the United States. We do not offer Canadian data residency, and this page will not pretend otherwise.
- The authoritative infrastructure — your dedicated database, object storage, transactional email, monitoring, secrets and encryption-key management — runs on Amazon Web Services in the us-east-1 region (United States).
- No Client Data or Personal Data is stored at rest in Canada. That is the wording of our Data Processing Agreement, section 9.1, and it is accurate.
- Public asset links are additionally delivered through a content-delivery network whose edge storage is in New York, United States — the CDN vendor offers no Canadian storage region — with global edge caching that may include a Toronto edge node.
- Authentication, identity and session data is managed by Clerk in the United States. Payment, billing and tax data is processed by Stripe in the United States. DNS resolution for our domains is provided by Cloudflare on its global network.
- Storing and processing data in the United States is a transfer outside Canada within the meaning of section 17 of Quebec’s Law 25. The purpose of the transfer, the named recipients and the protection measures are disclosed in section 9 of the Data Processing Agreement.
Consent records
Accepting our legal terms produces an archived document, not just a flag on an account — and once it is written nobody can alter it, including us.
- Every acceptance is archived as a signed PDF in Amazon S3 under an Object Lock compliance hold for seven years. Compliance mode means the object cannot be modified or deleted before that date by any credential, including our own root account.
- Each record carries the typed signature, the acceptance timestamp, the signer’s IP address, and the exact version and SHA-256 content hash of each of the four legal documents in force at that moment: the Terms of Service, the Acceptable Use Policy, the Privacy Policy and the Data Processing Agreement.
- The same archival path runs whether the acceptance came from a self-serve signup or from an administrator inside the application, so there is one authoritative record per workspace rather than two competing ones.
- When a legal document changes materially, the platform compares the archived versions against the current ones and re-prompts for acceptance instead of treating a stale consent as current.
Audit trail
Administrative actions are written to an immutable, append-only audit log, and the platform ships no way to rewrite it.
- The audit log is append-only by construction: the API exposes read and export endpoints for it and no endpoint that edits or deletes an entry.
- Entries record who acted, which entity was affected, what action was taken, the recorded change payload, and when — including actions taken by system actors and by AI assistants connected through our AI access surface.
- Audit logs and legal-vault archives are explicitly carved out of the deletion that follows termination (Data Processing Agreement, section 12.4), so the compliance record outlives the account it describes.
- An administrator in your own organization can query and export your workspace’s audit history — filtered, and as CSV — through the platform API, scoped to your tenant. You do not have to ask us for it.
Data Processing Agreement and sub-processors
Our Data Processing Agreement is public, and so is the full list of every third party that touches your data.
- Section 8 names every sub-processor in a table giving its service, purpose, the categories of data it handles and its location: Amazon Web Services (database, object storage, email, monitoring, secrets, key management, CDN), Clerk (authentication and identity), Bunny.net (content delivery and edge storage), Stripe (payments, billing and tax) and Cloudflare (DNS and inbound email routing).
- We give thirty days’ written notice before engaging or replacing a sub-processor. If you object on reasonable data-protection grounds you have fifteen days to say so, and if we cannot resolve it you may terminate — and that termination is not treated as termination for cause.
- You may audit our compliance with the agreement once per twelve-month period on thirty days’ notice, at your expense. We may answer with compliance reports, independent assessment results or written responses to your questionnaire.
- We notify you in writing of a breach affecting your data without undue delay, and in any event within seventy-two hours of becoming aware of it.
- On termination we make your data available for export in standard machine-readable formats for thirty days, then permanently delete it from active systems and provide written certification of deletion on request.
Security posture
The technical and organizational measures below are contractual commitments in section 6 of the Data Processing Agreement, not a marketing summary of them.
- Encryption: all data at rest is encrypted with AES-256; all data in transit is encrypted with TLS 1.2 or higher.
- Tenant isolation: each client gets a dedicated Amazon RDS for PostgreSQL database, a dedicated Amazon S3 prefix for assets, and a dedicated Clerk Organization scoping its user identities — separation at the database, storage and identity layers.
- Access control: role-based permissions assigned by your own administrator govern access to your data, and our internal access is restricted to personnel who need it to operate the service.
- Infrastructure: the platform runs on AWS, which holds SOC 2 Type II, ISO 27001 and ISO 27018. Clerk holds SOC 2 Type II; Cloudflare holds SOC 2 Type II and ISO 27001; Stripe holds PCI-DSS Level 1, SOC 1 and SOC 2 Type II, and ISO 27001; Bunny.net is certified to ISO/IEC 27001. Those are our providers’ certifications, not ours.
- Recovery: a Recovery Point Objective of one hour or less, supported by daily automated database backups and point-in-time recovery. Our Recovery Time Objective target is twelve minutes, recorded as a preliminary baseline in a staging-fidelity restore rehearsal; a production-scale rehearsal to ratify it has not been run yet.
What we do not claim
A trust page that only lists strengths is a sales page. These are the gaps a careful reviewer would find anyway, stated first.
- We are not SOC 2 or ISO 27001 certified. Our infrastructure providers are; we are not, and we will not let a provider’s badge stand in for ours.
- We do not offer Canadian data residency. Your data is at rest in the United States, disclosed under Law 25 rather than avoided.
- Our legal pack is founder-attested. External counsel review is planned and has not happened yet — the document headers say so, and so does this page.
- Our twelve-minute recovery-time figure is a preliminary baseline measured at staging fidelity, not a ratified commitment.
- We are a very small vendor. Contractual audit rights, sub-processor notice, breach-notification deadlines and records that cannot be edited after the fact are what we offer in place of a large compliance organization.
The documents themselves
Nothing on this page replaces the agreements. Every commitment above is either written in these four documents or is how the platform behaves today. All four are public and need no signature to read.
Security questionnaire, sub-processor evidence, or a question this page did not answer: legal@smartskumanagementsystem.com