Toronto-based · audit-ready in 3 months · data hosted in Canada

Compliance as a Service, built for your industry

Every industry gets asked for a different proof of security — and asked in a different way. We run the whole programme for SaaS, healthcare, fintech, AI, public sector and professional services teams: scoping, controls, evidence and audit, with a named compliance manager who owns the deadline.
3
Months to audit-ready
13
Frameworks supported
95%
Of evidence work automated
Canada
Data residency, hosted in-country
Solutions by industry

Built around what your buyers actually ask for

Compliance is not one problem. A digital health company and a fintech are answering completely different questions, from different regulators, on different timelines. We scope the programme to the demand your sector actually generates.

SaaS and technology

Enterprise buyers block deals on a SOC 2 Type 2. European ones ask for ISO 27001. Most growing Canadian SaaS companies end up needing both.

Healthcare and digital health

PHIPA in Ontario, HIPAA if you touch US patient data, and a hospital vendor security review that reads like an audit on its own.

Financial services and fintech

SOC 2 and PCI DSS from customers, plus OSFI Guideline B-13 and B-10 expectations pushed down from every federally regulated institution you serve.

AI and machine learning

No AI statute is in force in Canada, so buyers fall back on ISO 42001 and the NIST AI RMF — the assurance they can actually ask you to produce.

Public sector and GovTech

Canadian RFPs that require in-country hosting, Protected B handling, and evidence a procurement officer can verify without taking your word for it.

Professional and managed services

You hold other people's data, so their auditors become your auditors. SOC 2 is the usual answer, ISO 27001 once you operate internationally.

In detail

What the programme looks like in your sector

Usually asked for: SOC 2 Type 2, ISO 27001, and an ever-growing security questionnaire.

The pattern is predictable. A Type 1 unblocks the deal in front of you; a Type 2 keeps the next twelve months of deals moving. If you sell into Europe or the UK, ISO 27001 arrives shortly after. We scope both together so one evidence pipeline and one policy set serves them, rather than running the same project twice a year apart. Cloud, identity and ticketing systems are connected to AI agents that collect evidence continuously, so the questionnaire stops being a fire drill.
Usually asked for: PHIPA alignment, HIPAA where US patient data is involved, SOC 2, and increasingly ISO 27701.

Ontario’s PHIPA places explicit obligations on health information custodians and their agents, and hospital procurement teams test them properly — their vendor security reviews are frequently harder than the certification audit itself. Data residency is rarely negotiable. We design the ISMS so custodian and agent responsibilities are documented, evidence sits in Canada, and the answers to a hospital’s review come out of the same control set your SOC 2 auditor samples.
Usually asked for: SOC 2, ISO 27001, PCI DSS where card data is in scope, and evidence mapped to OSFI expectations.

If you sell to a federally regulated financial institution, its obligations become your requirements. OSFI Guideline B-13 on technology and cyber risk management and Guideline B-10 on third-party risk both push responsibilities down the supply chain, and your customer’s second line will ask you to evidence them. We map your control set to what the institution needs to see, so one programme answers the audit, the questionnaire and the annual third-party review.
Usually asked for: ISO 42001, NIST AI RMF alignment, EU AI Act readiness, with SOC 2 or ISO 27001 underneath.

There is no AI statute in force in Canada — the Artificial Intelligence and Data Act died with Bill C-27 — which means buyers cannot point at a law and instead ask for the assurance that does exist. ISO/IEC 42001 is that mechanism: a certifiable AI management system covering your AI policy, risk assessment, impact assessment and the Annex A controls. We build the AIMS on top of your existing ISMS rather than beside it, because the two share most of their evidence.
Usually asked for: in-country data residency, Protected B handling, ISO 27001, and control evidence a procurement officer can verify.

Canadian federal and provincial RFPs routinely require that data stays in Canada and that controls align to recognised profiles. Assertions do not survive evaluation — what does is a documented scope, a defensible risk assessment and evidence someone outside your company can test. We prepare the ISMS and the evidence pack with the RFP reviewer as the audience, and help you select a certification body accredited by the Standards Council of Canada.
Usually asked for: SOC 2, ISO 27001 for international work, occasionally SOC 1 where you affect client financial reporting.

Holding other people’s data makes their auditors your auditors, and the requests arrive from every client independently and on their own schedule. The economics only work if one control set answers all of them. We scope a single programme covering the systems your clients actually touch, then run continuous monitoring so each new client review is a report you already have rather than a project you have to start.
The engagement model

Compliance as a Service, whatever the framework

The frameworks change by industry. The way we run the programme does not. Compliance as a Service means a person owns the outcome and the software does the repetitive work — not a dashboard handed over with a list of 100 tasks.

A named compliance manager

One person who owns the certification date, makes the scoping calls with you, and sits across from the auditor. Not a support queue.

AI agents on the evidence

Agents connect to your cloud, identity, ticketing and HR systems and collect evidence continuously — around 95% of the work that usually falls on engineers.

Continuous control monitoring

Drift is flagged when it happens rather than discovered by an auditor, which is what makes year two a continuation instead of another project.

Auditor selection and liaison

We help you choose the CPA firm or accredited certification body, brief them, and handle the engagement and any findings on your behalf.

We do not issue your report or certificate. A SOC 2 opinion comes from a licensed CPA firm and an ISO 27001 certificate from an accredited certification body — both independent of whoever built the programme. Any vendor telling you otherwise is describing something that does not exist.
Toronto · Ontario · Canada

SOC 2 preparation and ISO 27001 certification across Canada

Nank.ai is based in Toronto and runs SOC 2 preparation and ISO 27001 certification programmes for organisations across Ontario and the rest of Canada — in your time zone, under Canadian law, with your evidence held in-country.

Most compliance vendors selling into Canada are US companies running your evidence through US infrastructure. For a Canadian health, financial or public-sector buyer, that is the first question they ask, and it is often the one that ends the conversation.

Toronto and the GTA

We are here. Scoping workshops, risk assessment sessions and management reviews can run in person where that moves things faster.

Ontario and Canada-wide

The same programme runs remotely for clients in Ottawa, Montreal, Calgary and Vancouver, with a certification body accredited by the Standards Council of Canada.

SOC 2 and ISO 27001 together

Canadian companies selling into the US and Europe are asked for both. Run together from Toronto, one programme answers both requests.

Canadian data residency compliance

Neither SOC 2 nor ISO 27001 mandates where data lives — but your customers, your contracts and Canadian privacy law frequently do, and your control set is where you prove it. We host compliance evidence in Canada and design controls so residency obligations are demonstrable to an auditor rather than asserted in a questionnaire. The regimes that usually drive the requirement:
Questions

Frequently asked questions

Compliance as a Service means an external team runs your compliance programme end to end rather than selling you software to run it yourself. With Nank.ai that is a named compliance manager who owns the certification date, supported by AI agents that handle evidence collection and continuous control monitoring. You keep the decisions that only you can make — scope, risk appetite, infrastructure changes — and we carry everything else, including the auditor relationship.
Yes. SOC 2 preparation is one of our core services across Canada, run from Toronto. That covers scoping the Trust Services Criteria that genuinely apply to you, building and remediating controls, automating evidence collection, running a readiness review, and selecting and briefing an independent CPA firm. A Type 1 is achievable in as little as three months for a focused scope; a Type 2 additionally needs an observation window during which controls are operating.
Yes. We deliver ISO 27001 certification programmes in Toronto, across Ontario and throughout Canada — Ottawa, Montreal, Calgary, Vancouver and elsewhere. Toronto and GTA clients can have workshops and management reviews run in person; everything else is delivered remotely in your time zone. We help you select a certification body accredited by the Standards Council of Canada or an equivalent IAF member, and support both Stage 1 and Stage 2.
Your compliance evidence is hosted in Canada. Neither SOC 2 nor ISO 27001 mandates data residency on its own, but Canadian privacy law and customer contracts frequently do — PIPEDA federally, PHIPA for Ontario health information, Quebec Law 25 for transfers outside the province, and the PIPA regimes in Alberta and British Columbia. Public-sector RFPs often require in-country hosting outright. We design the controls so those obligations are demonstrable to an auditor rather than simply asserted.
SaaS and technology, healthcare and digital health, financial services and fintech, AI and machine learning, public sector and GovTech, and professional and managed services. The engagement model is the same across all of them; what changes is the framework mix and which regulator or buyer is driving the request. If your sector is not listed, the question we start with is simply who is asking you for proof and what they will accept.
Yes, and for most Canadian companies selling into both the US and Europe it is the cheaper route. The control sets overlap substantially, so one evidence pipeline and one policy set can serve both, with the genuine differences — the ISMS clauses on one side, the Trust Services Criteria on the other — handled deliberately. Sequenced as two separate projects a year apart, you largely pay twice. See our SOC 2 compliance service and ISO 27001 certification service.

Tell us who is asking you for proof

A short call is usually enough to work out which framework your buyers will actually accept, what your scope should be, and how long it will realistically take. We will tell you if you do not need us yet.
[EDITOR: add engagement pricing or a “from $X” figure before publishing — deliberately left blank rather than invented. Also consider adding a customer quote per industry once you have approvals.]
Scroll to Top