Skip to content
Security roadmap

What is in place, and what is coming

A vendor that answers yes to everything is a vendor people stop believing. So this page says where we actually stand: what is demonstrable today, what is committed with an owner and a date, and what is still under consideration.

A missed date stays on this page until it is met. We do not quietly remove a line that has become awkward.

Last reviewed:

In place today

Verifiable right now, in the contract or in the product. These are not plans.

  • Written agreement covering data processing

    Clause 14 of the master agreement covers ownership, purposes, confidentiality, sub-processors, processing outside Quebec, incidents, verification and retention. It is the written agreement section 17 of Law 25 requires for a communication outside Quebec.

    Owner
    Leadership
    Target
    Available
  • Customer audit right

    On fifteen business days' written notice, once per twelve-month period, you may verify our compliance with our confidentiality and security obligations. We may answer with reports and equivalent questionnaires.

    Owner
    Leadership
    Target
    Clause 14.10
  • Hosting in Canada

    Dedicated instance hosted in Canada — the Canada Central (Toronto) region by default — with backup replication to a second Canadian region. A Canada East (Québec City) region goes through private hosting; the shared cloud has only one Canadian region today.

    Owner
    Engineering
    Target
    Default configuration
  • Provider policies visible in the console

    Training, retention, duration, publication and identifier requirements, read live for every provider. An unavailable policy shows as unknown, never as an absence of retention.

    Owner
    Engineering
    Target
    Shipped
  • Law 25 and GDPR detection inside the conversation

    Per-message scanning for passwords, secrets and personal information, confidentiality mode, retrospective batch scans and an administrator review queue. A paid option, off by default, and the detection is itself an outbound call to a model.

    Owner
    Engineering
    Target
    Shipped
  • Incident notice to your designated officer

    Prompt notice to your privacy officer, with the nature of the incident, the people affected, the period and the measures taken. Your own duty to report to the Commission d'accès à l'information remains yours; we support it. No number of hours is written into the contract — that is a separate gap, listed below.

    Owner
    Engineering
    Target
    Clause 14.9

Committed, with a date

These do not exist yet. They have an owner and a date, taken from our internal registers.

  • Contractual notice period for a sub-processor change

    A fixed period to tell you before a hosting or artificial-intelligence sub-processor is added, and publication of the corresponding list. It is the most frequent request from our customers' legal counsel, and one of the few points where Law 25 turns the question directly operational.

    Owner
    Leadership and engineering
    Target
    30 September 2026
  • Residency commitment available as an option

    Today a residency constraint on inference must be negotiated in the order form. The goal is to make it a documented option, with the list of models actually available under that constraint and its effect on capability.

    Owner
    Leadership and engineering
    Target
    30 September 2026
  • Penetration test by an independent third party

    Our current testing is internal, documented and reproducible, but it is not independent assurance. An external engagement is planned.

    Owner
    Leadership
    Target
    30 September 2026
  • Incident-response exercise

    The plan is written and publishes its severity tiers and notification clock. It has never been exercised, and a plan never exercised is a hypothesis. A tabletop exercise is scheduled.

    Owner
    Engineering and leadership
    Target
    30 September 2026
  • Published policy on staff access to customer data

    The contract already limits access to a need-to-know basis. What is missing is the published policy: who, in what circumstances, with what trace, and in particular how the impersonation feature is governed in a managed instance.

    Owner
    Leadership
    Target
    31 August 2026

Under consideration

These do not have a date yet. Listing them here without one is more useful than inventing one — and if any of them matters to you, saying so helps us prioritize it.

  • SOC 2, ISO 27001 or ISO 42001 certification

    We hold none and no engagement is under way. A certification attests to a scope chosen by the certified organization; it does not replace reading the controls. In the meantime, the audit right in clause 14.10 and this page are what we offer in its place.

    Owner
    Leadership
    Target
    No date announced
  • Technical lock on zero-retention routing

    Selecting providers that do not train rests today on configuration and on the contract. The control that would technically restrict every call to zero-retention endpoints does not yet exist. Worth noting: such a lock would not cover web search or external tools, which fall under their own policies.

    Owner
    Engineering
    Target
    No date announced
  • Configurable retention per workspace

    No retention-period setting for conversations, documents or knowledge bases. Some features carry fixed caps written into the product; the rest is deleted manually or through the compliance scans.

    Owner
    Engineering
    Target
    No date announced
  • Firm deletion deadline after the contract ends

    Clause 14.11 provides for deletion after the transition period, without a number of days. Customers ask for a fixed deadline, typically forty-five days. The question is open and has not been settled.

    Owner
    Leadership
    Target
    No date announced
  • An incident-notification deadline expressed in hours

    Section 14.9 commits us to notice “without delay”, with no number of hours. Your own clocks do carry numbers — 24 hours to the AMF, 24 hours to OSFI, 72 hours to the supervisory authority under the GDPR — and they start from your discovery, not from our notice. As long as the contract carries no figure, your ability to hold them depends on our speed with nothing bounding it. It is the most-cited gap elsewhere on this site, and it was missing from the page that serves as the register.

    Owner
    Management
    Target
    No date announced
  • Log export and recovery objectives

    No export feed from the audit log to a third-party security tool, and no recovery time and recovery point objectives documented and proven by a restore drill.

    Owner
    Engineering
    Target
    No date announced
  • Enforced multi-factor authentication on single sign-on and email-code logins

    The product enforces multi-factor authentication itself: native TOTP and passkeys, requirable through a conditional-access policy. What is still missing: that policy does not cover Microsoft or Google single sign-on, nor email-code sign-in, which remain governed by the provider's own policy. Session idle and absolute timeouts exist but ship disabled by default.

    Owner
    Engineering
    Target
    No date announced
  • GDPR-aligned data processing addendum

    The master agreement is written around Law 25 obligations. As it stands it carries no separate addendum aligned with GDPR Article 28, and no standard contractual clauses for transfers outside the European Union. A customer subject to GDPR therefore has to request them on the order form.

    Owner
    Leadership
    Target
    No date announced
  • Marking AI-generated content

    The platform puts no notice or watermark on generated text you copy out of the tool. This is not a future requirement: the Chambre de l'assurance has asked for it since November 2024, and several professional orders point the same way. Today, marking is entirely on the user.

    Owner
    Engineering
    Target
    No date announced
  • A report of the information that fed a given answer

    You can reconstruct by hand what fed an answer — the prompt, the attachments, the knowledge bases attached, the cited sources — but there is no exportable report that lists them. The Chambre de l'assurance asks that you be able to supply that list on request and correct anything wrong in it; that is a product capability, not a policy.

    Owner
    Engineering
    Target
    No date announced
  • Archival durability and a certificate of destruction

    Several records-keeping regulations require the system to stay legible and accessible for ten years after a file is closed, and a certificate of confidential destruction at the end of that period. We offer neither: a conversation platform is not an archiving system, and a record you must keep has to be exported into yours. We say so rather than letting you assume otherwise.

    Owner
    Engineering and management
    Target
    No date announced
  • The model kill switch on server-picked steps

    The kill switch binds every model a user picks, administrators included. It does not yet bind the calls the server makes on its own, and several of them carry real content: the extraction of the text of a document added to a knowledge base, or pulled from a SharePoint, OneDrive or Google Drive connector — which goes through a model pinned in the code; the Law 25 detector, which sends the text of the message to the cheapest model that can hold it; the conversation title, which sends up to 600 characters of it, plus 600 of the reply; the agent's screenshot; and the raw audio of the Learning module. The full list is now published on the Confidentiality and compliance page, with what leaves and to which model. What is needed: that the same access check apply to those calls as it applies to a user's. No date announced.

    Owner
    Engineering
    Target
    No date announced

How we hold this page

Four rules, applied to our internal documents before they were applied here.

  • A dated gap beats a promise

    A named gap, with an owner and a date, lets a buyer decide. An unnamed gap forces them to find it in due diligence, and what they find is not just the gap: it is that it was kept from them.

  • A pessimistic error is corrected like an optimistic one

    We have described our own controls as weaker than they were. That is an error in the same way the opposite is, and it is corrected with the same standard of evidence.

  • A control verified by reading is flagged as such

    When a control is confirmed by reading the code rather than executing it, we say so. The difference matters to anyone assessing residual risk.

  • The list grows when we look

    An audit that finds fewer things than the last one is more often a worse audit than a better product. This list grows when we look seriously, and it shortens only when something is genuinely fixed.

Is one of these a blocker for you?

Say so now rather than at the end of a process. Some can be handled in the order form; others are a reason for us to recommend a different approach — including not putting certain data in the platform yet.

Security question or vulnerability report: support@hilointelligence.ca.