Trust Centre
Make an informed decision before uploading R&D evidence
SR&ED records can contain trade secrets, employee information, financial data, and security-sensitive technical detail. This centre distinguishes controls that exist today from customer choices, operating targets, and capabilities that are not yet available.
Last reviewed: July 10, 2026
How to read our claims
A control represented in the current product or deployment configuration.
A choice the customer can make to reduce scope or risk.
A service objective, not a contractual SLA unless included in a signed agreement.
Do not assume the capability exists or design a control around it.
Current trust snapshot
| Area | Status | What that means |
|---|---|---|
| Transport and storage | Implemented | TLS in transit and managed-platform disk encryption at rest. |
| Integration secrets | Implemented | OAuth access and refresh tokens receive application-level authenticated encryption. |
| Tenant and role controls | Implemented | Organization-scoped records and owner, accountant, and member roles. |
| Authenticator-app MFA | Implemented | Optional TOTP MFA has password-confirmed enrollment, encrypted setup secrets, one-time backup codes, a login challenge, and audited enable/disable events. |
| Organization AI policy | Implemented | An owner can disable AI, require customer-supplied keys, and allow only selected AI providers. |
| Data inventory and export | Implemented | Owners can inspect record counts and download a sanitized organization JSON export; project binders remain available for accountant handoff. |
| Integration offboarding | Implemented | Before disconnecting, owners see imported-evidence and citation counts and choose whether to retain or permanently purge matching provider evidence. |
| Sensitive database fields | Partial only | OAuth tokens and claim filing workspaces are encrypted at field level; workspace ciphertext is bound to its organization and project. General evidence, narratives, and expenditure records rely on platform encryption at rest and application access controls. |
| Independent assurance | Not yet available | No SOC 2 report, independent penetration-test report, or security certification is offered today. |
| Canada-only residency | Not guaranteed | Core production hosting is currently in the United States on Render; feature providers may use other locations. Do not use the service where Canada-only residency is mandatory. |
| CRA records archive | Customer-controlled | Export regularly and retain authoritative records in your own approved repository. SR&ED Copilot is not the sole archive for statutory retention. |
A lower-risk evaluation path
- Classify first. Ask your security, privacy, tax, and legal owners which records may leave approved systems.
- Start narrow. Use one completed, low-sensitivity project and manual evidence entry before enabling integrations.
- Minimize content. Exclude credentials, source code, personal health information, customer data, and details unnecessary to explain the experiment.
- Keep originals. Preserve source records in Git, ticketing, document management, or another approved system and export the project binder regularly.
- Require review. Have the technical lead validate facts and citations and have a qualified accountant or SR&ED advisor make tax and filing decisions.
Procurement package
The public materials are designed to support an initial review, not to replace your own due diligence. A customer-specific MSA, confidentiality agreement, security schedule, DPA, audit right, residency term, or SLA exists only if it is separately executed.
Ask before relying on an unstated control
If a control is not explicitly marked implemented, treat it as unavailable. Send security, privacy, or procurement questions to hello@sredcopilot.ca.