Trust Centre

Security & Data Handling

Last reviewed: July 10, 2026

Maturity notice: SR&ED Copilot is an early-access product and handles data that may be highly sensitive. The controls below are not independently audited or certified. Treat “not available” as a real limitation, not as a pending procurement answer.

1. Control status

ControlCurrent statusScope and boundary
TLS in transitImplementedHTTPS/TLS is enforced at the managed hosting edge.
Managed disk encryption at restImplementedApplication and database storage rely on hosting-provider encryption.
Password storageImplementedPasswords are hashed with bcrypt and are not stored in plaintext.
Authentication cookiesImplementedProduction authentication cookies are HTTP-only, secure, and SameSite=Strict.
Organization and role boundariesImplementedRecords are scoped to an organization with owner, accountant, and member permissions.
OAuth token field encryptionImplementedStored integration access and refresh tokens use application-level AES-256-GCM authenticated encryption.
Claim filing workspace encryptionImplementedClaimant identity, personnel, cost-planning, and accountant-handoff workspace data use application-level AES-256-GCM encryption bound to the organization and project.
Rate limitingImplementedAuthentication, API, webhook, and narrative-generation paths have request limits.
Authenticator-app MFAImplementedOptional TOTP MFA includes password-confirmed enrollment, encrypted setup secrets, one-time backup codes, login challenge, and audited enable/disable events.
Organization AI policyImplementedOwners can allow hosted and customer-key AI, require customer keys, disable external AI, and restrict providers.
Organization data inventory and exportImplementedOwners can inspect record counts and download a sanitized JSON export without authentication or OAuth secrets.
Integration disconnect dispositionImplementedOwners preview provider-wide evidence, citation, and narrative impact. Purge is blocked for approved/submitted narratives and returns affected draft/review narratives to draft.
Retention planning controlImplemented, advisoryNew workspaces default to an 84-month planning window. The setting flags older evidence and does not silently delete it.
Action audit recordsImplemented, selected eventsEvidence changes, narrative generation/review, organization changes, and exports are among the recorded actions. Login events are not represented as comprehensively audited.
Evidence, narrative, and expenditure field encryptionNot implementedThese fields rely on managed disk encryption and application access controls rather than per-field encryption.
SOC 2 or other independent certificationNot availableNo independent assurance report is offered today.
Independent penetration-test reportNot availableNo completed independent report is offered today.
Canada-only data residencyNot availableData may be processed in Canada or the United States.

2. Identity and access

  • Each request is authenticated and associated with a user and organization before protected data is returned.
  • Owner, accountant, and member roles separate organization administration, review, and contribution workflows.
  • Password reset revokes the user's current token generation and clears stored sessions.
  • Authentication and password-reset routes are rate limited.
  • Users can enable authenticator-app MFA after password confirmation. Setup expires after 10 minutes, backup codes are one-time use, login requires an MFA challenge, and disabling requires the password plus a current factor.
  • SAML SSO, SCIM provisioning, domain verification, and conditional-access integration are not currently available.

Account owners should invite named users, apply the least-privileged role, review membership regularly, and remove users promptly. Shared accounts should not be used.

3. What customer content can contain

Depending on customer choices, the platform can hold Git commit metadata and text, Jira or Azure DevOps work items, Slack or Teams messages, employee attribution and timestamps, project and experiment descriptions, expenditure and personnel records, AI prompts, generated narratives, citations, reviews, and exports.

Prefer

  • short, factual evidence summaries;
  • links or identifiers back to approved source systems;
  • pseudonyms or role labels where names are unnecessary;
  • only the records relevant to the experiment; and
  • a low-sensitivity pilot project first.

Do not upload

  • passwords, private keys, tokens, or secrets;
  • full source code when a narrow summary is sufficient;
  • personal health or payment-card information;
  • customer production data or vulnerability details unrelated to the claim; or
  • anything prohibited by employer or customer policy.

4. AI narrative data flow

  1. The user chooses a model and evidence for a generation or improvement request, subject to the organization policy.
  2. The enforced minimization policy builds context from project name, description, fiscal year, and technology stack; selected evidence IDs, sources, titles, summaries, dates, and tags; generation instructions; and draft narrative text when improving a draft. Evidence links and raw integration payloads are excluded.
  3. The request is sent to Cohere, Anthropic, or OpenAI according to the selected model.
  4. The returned draft is stored with the project for human review and editing.
  5. The reviewer must validate statements and citations before approval or export.
ProviderWhen data is sentCustomer control
CohereWhen the hosted default Cohere model is usedChoose the evidence and redact unnecessary content
AnthropicWhen an Anthropic model is selected and hosted or customer credentials are availableChoose the evidence, model, and credential mode
OpenAIWhen an OpenAI model is selected and hosted or customer credentials are availableChoose the evidence, model, and credential mode

A customer-supplied API key is used for that request and is not intentionally stored, but the prompt still goes to the selected provider. SR&ED Copilot does not use customer data to train its own model and relies on applicable provider API terms for provider training restrictions. See the Subprocessor Register.

An organization owner can allow hosted and customer-key requests, require customer-supplied keys, disable external AI entirely, and choose which of Cohere, Anthropic, and OpenAI are permitted.

5. Integration lifecycle and offboarding

  1. An account owner reviews the requested scope and authorizes a connection.
  2. OAuth tokens are stored with application-level authenticated encryption.
  3. The Service fetches or receives supported records and stores the resulting evidence under the selected organization and project.
  4. Before disconnecting, the owner sees provider-wide imported-evidence, citation, and narrative impact for the organization.
  5. The owner explicitly chooses to keep imported evidence or permanently purge matching provider evidence. Purge is blocked while approved/submitted narratives rely on that evidence; affected draft/review narratives return to draft. The choice and impact counts are audited.
  6. The connection credentials are removed and future access stops; the owner should separately review or revoke the provider-side connected-app grant.

For incident containment, disconnect the source, rotate or revoke the grant in the source system, review imported evidence, remove affected records, and contact hello@sredcopilot.ca. Disconnection alone is not erasure.

6. Data residency and transfers

Current state: core production hosting is currently in the United States on Render. Disclosed feature providers may process data in the United States, Canada, or other locations on global systems. Canadian-only storage and processing is not available as a self-service configuration.

A provider's Canadian headquarters does not by itself establish Canadian processing for a particular request. Customers with a hard residency requirement should not use the Service for covered data until a written, verified deployment arrangement is in place.

7. Incident response and notification

Reports are triaged through email; there is no public 24/7 security hotline today. After validating that a security incident may have affected customer data, we target notice without unreasonable delay and within 72 hours. We do not wait for complete forensic certainty if available facts support customer action. Applicable law or a signed agreement may require a shorter period.

The initial notice should include known scope, affected data or systems, containment, recommended action, and the next update time. Details may change as the investigation continues. See Service Commitments.

8. Retention, continuity, and export

New workspaces default to an 84-month conservative retention-planning window, while existing organization settings remain explicit. The setting flags older evidence and does not silently delete it. The Service is not the customer's statutory archive; retention mechanics still vary by record type, account status, delete actions, verified requests, and managed-provider backup rotation.

  • Keep original commits, tickets, messages, approvals, payroll records, and other source records in approved systems.
  • Export project preparer review binders after review milestones and before subscription cancellation.
  • Organization owners can inspect a data inventory and download a sanitized JSON export covering customer records, decrypted portable claim-workspace data, and audit history without authentication secrets, OAuth tokens, or payment-provider identifiers.
  • Confirm the organization's retention setting and do not assume it guarantees preservation or deletion on a particular date.
  • Use a verified privacy request for account-level export or deletion needs not covered by product controls.

9. Assurance and roadmap

There is no SOC 2 Type II report, independent penetration-test report, formal security certification, or claim of certified PIPEDA compliance today. Public descriptions and a reasonable questionnaire response can support initial due diligence, but they are not independent assurance.

Current improvement priorities

  • broader application-level encryption for highly sensitive fields;
  • repeatable backup-restore and disaster-recovery exercises;
  • independent security testing and remediation evidence; and
  • more complete customer-visible audit and administration controls.

Not a current promise

Roadmap items have no committed delivery date unless included in a signed agreement. Do not approve the Service based on an expected future control.

10. Customer security checklist

  • Complete security, privacy, legal, tax, and records-retention review before onboarding.
  • Confirm that Canada/US processing and the listed subprocessors are acceptable.
  • Use one low-sensitivity project and manual capture before enabling integrations.
  • Minimize fields and redact secrets, personal data, and unnecessary technical detail.
  • Assign named users, least-privileged roles, and an account owner responsible for offboarding.
  • Keep authoritative records elsewhere and test the export with the accountant.
  • Do not rely on any control not explicitly marked implemented.