Compliance as a Service, built for your industry
- ISO 27001
- SOC 2
- ISO 42001
- HIPAA
- PHIPA
- PCI DSS
- GDPR
- NIST CSF
- ISO 27701
Built around what your buyers actually ask for
SaaS and technology
Enterprise buyers block deals on a SOC 2 Type 2. European ones ask for ISO 27001. Most growing Canadian SaaS companies end up needing both.
Healthcare and digital health
PHIPA in Ontario, HIPAA if you touch US patient data, and a hospital vendor security review that reads like an audit on its own.
Financial services and fintech
SOC 2 and PCI DSS from customers, plus OSFI Guideline B-13 and B-10 expectations pushed down from every federally regulated institution you serve.
AI and machine learning
No AI statute is in force in Canada, so buyers fall back on ISO 42001 and the NIST AI RMF — the assurance they can actually ask you to produce.
Public sector and GovTech
Canadian RFPs that require in-country hosting, Protected B handling, and evidence a procurement officer can verify without taking your word for it.
Professional and managed services
You hold other people's data, so their auditors become your auditors. SOC 2 is the usual answer, ISO 27001 once you operate internationally.
What the programme looks like in your sector
SaaS and technology
The pattern is predictable. A Type 1 unblocks the deal in front of you; a Type 2 keeps the next twelve months of deals moving. If you sell into Europe or the UK, ISO 27001 arrives shortly after. We scope both together so one evidence pipeline and one policy set serves them, rather than running the same project twice a year apart. Cloud, identity and ticketing systems are connected to AI agents that collect evidence continuously, so the questionnaire stops being a fire drill.
Healthcare and digital health
Ontario’s PHIPA places explicit obligations on health information custodians and their agents, and hospital procurement teams test them properly — their vendor security reviews are frequently harder than the certification audit itself. Data residency is rarely negotiable. We design the ISMS so custodian and agent responsibilities are documented, evidence sits in Canada, and the answers to a hospital’s review come out of the same control set your SOC 2 auditor samples.
Financial services and fintech
If you sell to a federally regulated financial institution, its obligations become your requirements. OSFI Guideline B-13 on technology and cyber risk management and Guideline B-10 on third-party risk both push responsibilities down the supply chain, and your customer’s second line will ask you to evidence them. We map your control set to what the institution needs to see, so one programme answers the audit, the questionnaire and the annual third-party review.
AI and machine learning
There is no AI statute in force in Canada — the Artificial Intelligence and Data Act died with Bill C-27 — which means buyers cannot point at a law and instead ask for the assurance that does exist. ISO/IEC 42001 is that mechanism: a certifiable AI management system covering your AI policy, risk assessment, impact assessment and the Annex A controls. We build the AIMS on top of your existing ISMS rather than beside it, because the two share most of their evidence.
Public sector and GovTech
Canadian federal and provincial RFPs routinely require that data stays in Canada and that controls align to recognised profiles. Assertions do not survive evaluation — what does is a documented scope, a defensible risk assessment and evidence someone outside your company can test. We prepare the ISMS and the evidence pack with the RFP reviewer as the audience, and help you select a certification body accredited by the Standards Council of Canada.
Professional and managed services
Holding other people’s data makes their auditors your auditors, and the requests arrive from every client independently and on their own schedule. The economics only work if one control set answers all of them. We scope a single programme covering the systems your clients actually touch, then run continuous monitoring so each new client review is a report you already have rather than a project you have to start.
Compliance as a Service, whatever the framework
A named compliance manager
One person who owns the certification date, makes the scoping calls with you, and sits across from the auditor. Not a support queue.
AI agents on the evidence
Agents connect to your cloud, identity, ticketing and HR systems and collect evidence continuously — around 95% of the work that usually falls on engineers.
Continuous control monitoring
Drift is flagged when it happens rather than discovered by an auditor, which is what makes year two a continuation instead of another project.
Auditor selection and liaison
We help you choose the CPA firm or accredited certification body, brief them, and handle the engagement and any findings on your behalf.
SOC 2 preparation and ISO 27001 certification across Canada
Most compliance vendors selling into Canada are US companies running your evidence through US infrastructure. For a Canadian health, financial or public-sector buyer, that is the first question they ask, and it is often the one that ends the conversation.
Toronto and the GTA
We are here. Scoping workshops, risk assessment sessions and management reviews can run in person where that moves things faster.
Ontario and Canada-wide
The same programme runs remotely for clients in Ottawa, Montreal, Calgary and Vancouver, with a certification body accredited by the Standards Council of Canada.
SOC 2 and ISO 27001 together
Canadian companies selling into the US and Europe are asked for both. Run together from Toronto, one programme answers both requests.
Canadian data residency compliance
- PIPEDA — federal private-sector privacy law, the baseline in most Canadian contracts
- PHIPA — Ontario health information, where custodian and agent obligations are explicit
- Quebec Law 25 — assessment required before transferring data outside the province
- Alberta and British Columbia PIPA — provincial private-sector privacy regimes
- OSFI B-13 and B-10 — technology, cyber and third-party risk expectations pushed down by regulated institutions
- Public-sector procurement — many Canadian RFPs require in-country hosting outright