Every layer of SecureVault's infrastructure is designed to meet the security and compliance requirements of Canada's most regulated industries — from law societies to OSFI-regulated financial institutions.
SecureVault's privacy-by-design architecture satisfies PIPEDA's 10 Fair Information Principles. Automated access logs and privacy impact assessments available on demand.
Agent agreements available for health information custodians. Breach notification workflow built in. All PHI stored exclusively on Canadian servers.
7-year retention with automated scheduling. Immutable audit trail for AML/ATF record-keeping obligations. Search-ready for regulatory examination.
Canadian data residency documentation and signed DPA provided for federally regulated entities managing third-party technology risk under OSFI's B-10 guideline.
Professional-grade client portal experience that satisfies CPA Rules of Professional Conduct for client confidentiality. Income Tax Act 7-year retention included.
Solicitor-client privilege protected under Canadian jurisdiction only. Trust account document management and Law Society compliance reports available.
The US Clarifying Lawful Overseas Use of Data (CLOUD) Act requires US-based technology companies to provide data to US federal agencies regardless of where the data is stored. This applies to Dropbox, Google, Microsoft, and every other US provider — even those with Canadian data centres.
SecureVault is a Canadian company operating exclusively on Canadian infrastructure. We are not subject to the CLOUD Act. Canadian legal process is required to compel any data disclosure — and you will be notified to the extent permitted by law.
| Factor | US Cloud Providers | SecureVault |
|---|---|---|
| CLOUD Act exposure | Yes — US law applies | No — Canadian jurisdiction only |
| Data stored in Canada | Optional | Always — by design |
| Governing law | US Federal law | Canadian law only |
| Notification on legal access | Not guaranteed | Maximum permitted by Canadian law |
| PIPEDA / PHIPA compliance | Partial | Full — built-in |
Enterprise clients receive a full security documentation package including DPA, data residency certificate, and penetration test summaries.