Trust Centre

Make an informed decision before uploading R&D evidence

SR&ED records can contain trade secrets, employee information, financial data, and security-sensitive technical detail. This centre distinguishes controls that exist today from customer choices, operating targets, and capabilities that are not yet available.

Last reviewed: July 10, 2026

How to read our claims

Implemented

A control represented in the current product or deployment configuration.

Customer option

A choice the customer can make to reduce scope or risk.

Operational target

A service objective, not a contractual SLA unless included in a signed agreement.

Not yet available

Do not assume the capability exists or design a control around it.

Current trust snapshot

AreaStatusWhat that means
Transport and storageImplementedTLS in transit and managed-platform disk encryption at rest.
Integration secretsImplementedOAuth access and refresh tokens receive application-level authenticated encryption.
Tenant and role controlsImplementedOrganization-scoped records and owner, accountant, and member roles.
Authenticator-app MFAImplementedOptional TOTP MFA has password-confirmed enrollment, encrypted setup secrets, one-time backup codes, a login challenge, and audited enable/disable events.
Organization AI policyImplementedAn owner can disable AI, require customer-supplied keys, and allow only selected AI providers.
Data inventory and exportImplementedOwners can inspect record counts and download a sanitized organization JSON export; project binders remain available for accountant handoff.
Integration offboardingImplementedBefore disconnecting, owners see imported-evidence and citation counts and choose whether to retain or permanently purge matching provider evidence.
Sensitive database fieldsPartial onlyOAuth tokens and claim filing workspaces are encrypted at field level; workspace ciphertext is bound to its organization and project. General evidence, narratives, and expenditure records rely on platform encryption at rest and application access controls.
Independent assuranceNot yet availableNo SOC 2 report, independent penetration-test report, or security certification is offered today.
Canada-only residencyNot guaranteedCore production hosting is currently in the United States on Render; feature providers may use other locations. Do not use the service where Canada-only residency is mandatory.
CRA records archiveCustomer-controlledExport regularly and retain authoritative records in your own approved repository. SR&ED Copilot is not the sole archive for statutory retention.

A lower-risk evaluation path

  1. Classify first. Ask your security, privacy, tax, and legal owners which records may leave approved systems.
  2. Start narrow. Use one completed, low-sensitivity project and manual evidence entry before enabling integrations.
  3. Minimize content. Exclude credentials, source code, personal health information, customer data, and details unnecessary to explain the experiment.
  4. Keep originals. Preserve source records in Git, ticketing, document management, or another approved system and export the project binder regularly.
  5. Require review. Have the technical lead validate facts and citations and have a qualified accountant or SR&ED advisor make tax and filing decisions.

Procurement package

The public materials are designed to support an initial review, not to replace your own due diligence. A customer-specific MSA, confidentiality agreement, security schedule, DPA, audit right, residency term, or SLA exists only if it is separately executed.

Ask before relying on an unstated control

If a control is not explicitly marked implemented, treat it as unavailable. Send security, privacy, or procurement questions to hello@sredcopilot.ca.