Security isn't a feature. It's the architecture.
Every product we build starts with a Canadian-first infrastructure decision. Your product data is stored and processed in the Canadian region, encrypted, and isolated from every other customer.
Data Residency
Your data stays in Canada. Period.
Canadian hosting
All infrastructure runs in AWS ca-central-1 (Montreal). Databases, compute, storage, everything stays within Canadian borders.
Self-hosted AI on the healthcare tier
Sentinel's healthcare tier runs AI models on infrastructure you control, with no third-party AI API calls. Prompts, documents, and conversations stay inside the deployment. Other tiers may route through a model provider, named in your agreement and in our subprocessor list.
PIPEDA & PHIPA compliant
Our infrastructure is designed from the ground up to meet federal and Ontario provincial privacy requirements for personal health information.
Compliance
Built for regulated industries.
PIPEDA
Canada's federal privacy law governing how private-sector organizations collect, use, and disclose personal information. Our data handling practices are built around the ten PIPEDA fair information principles, and we act as a service provider to the organizations accountable for the data.
PHIPA
Ontario's Personal Health Information Protection Act sets the standard for health data. We contract as an electronic service provider under O. Reg. 329/04 s.6(1), and our systems enforce access controls, audit logging, and data minimization.
Privacy reform
Bill C-27 died when Parliament was prorogued in January 2025, so PIPEDA still governs. The direction of reform is clear, and we build to it: explicit consent, data minimization, and disclosure of automated processing. Read our CPPA guide →
Regulation 299/10
Ontario's Quality Assurance Measures regulation governs developmental services agencies. Meridian is purpose-built to scan compliance data against these requirements automatically.
SOC 2 Type II
In progressWe're undergoing SOC 2 Type II audit covering security, availability, and confidentiality controls. Targeting attestation in Q4 2026. Status updates available on request under NDA.
Annual penetration testing
Independent third-party security firm conducts an annual pen test covering web application, infrastructure, and social engineering vectors. Findings remediated within 30 days. Executive summary available to enterprise customers.
Infrastructure
How we protect your data.
Encryption at rest
All stored data is encrypted using AES-256, the same standard used by financial institutions and government agencies worldwide.
Encryption in transit
Every connection uses TLS 1.2 or higher, with TLS 1.3 preferred. Traffic between your browser, our servers, and our databases is encrypted in transit.
Isolated tenancy
Each customer's data is logically isolated. One agency's information is never accessible to another, enforced at the database and application layer.
No external AI calls on the healthcare tier
On Sentinel's healthcare tier the models run on local infrastructure, so prompts, documents, and conversations never leave the deployment to reach a third-party AI provider.
Audit logging
All access to sensitive data is logged with timestamps, user identity, and action type. Logs are retained for 12 months for compliance review and incident investigation.
Automated backups
Database backups run daily with point-in-time recovery. Backups are encrypted and stored in the same Canadian region as the primary data.
FAQ
Security questions, answered.
Where is my data stored?
All product data is stored in AWS ca-central-1 (Montreal, Quebec): databases, file storage, backups, and AI model artifacts. We do not replicate it outside Canada. AWS is a US-headquartered provider running Canadian infrastructure, so the region controls where data sits rather than whose jurisdiction the provider answers to. Our website and sales tools are separate and listed in the privacy policy.
Who can access my data?
Only authorized Merakey engineers with a legitimate operational need can access customer data, and all access is logged. We operate on a principle of least privilege. Your agency's data is never shared with another customer. The only third parties involved are the infrastructure providers we name in our subprocessor list, which process it on our instructions and cannot use it for anything else.
What happens if there's a breach?
We have a documented incident response plan. PIPEDA requires reporting a breach of security safeguards as soon as feasible where there is a real risk of significant harm; our own commitment is to notify affected customers within 72 hours of confirming a breach. We also notify the Office of the Privacy Commissioner of Canada and, where applicable, the Ontario Information and Privacy Commissioner.
Is Sentinel truly self-hosted?
On the healthcare tier, yes. Sentinel runs AI models on infrastructure you control, with no API calls to any external AI provider, and prompts, documents, and outputs stay entirely within the deployment, whether that runs on our Canadian servers or your own hardware. Other tiers may route through a third-party model provider; where they do, we name it in your agreement and in our subprocessor list, and your data is still never used to train anyone's models.
How do you handle backups?
Automated daily backups with point-in-time recovery, all encrypted at rest using AES-256 and stored in the same Canadian region as the primary database. Backup retention follows a 30-day rolling window. We test restoration procedures regularly to ensure recoverability.
Get in touch
Have security questions? Let's talk.
If your agency has specific security or compliance requirements, we're happy to walk through our infrastructure and answer any questions.
Get in Touch