What is in place, and what is coming
A vendor that answers yes to everything is a vendor people stop believing. So this page says where we actually stand: what is demonstrable today, what is committed with an owner and a date, and what is still under consideration.
A missed date stays on this page until it is met. We do not quietly remove a line that has become awkward.
Last reviewed:
In place today
Verifiable right now, in the contract or in the product. These are not plans.
Written agreement covering data processing
Clause 14 of the master agreement covers ownership, purposes, confidentiality, sub-processors, processing outside Quebec, incidents, verification and retention. It is the written agreement section 17 of Law 25 requires for a communication outside Quebec.
- Owner
- Leadership
- Target
- Available
Customer audit right
On fifteen business days' written notice, once per twelve-month period, you may verify our compliance with our confidentiality and security obligations. We may answer with reports and equivalent questionnaires.
- Owner
- Leadership
- Target
- Clause 14.10
Hosting in Canada
Dedicated instance hosted in Canada — the Canada Central (Toronto) region by default — with backup replication to a second Canadian region. A Canada East (Québec City) region goes through private hosting; the shared cloud has only one Canadian region today.
- Owner
- Engineering
- Target
- Default configuration
Provider policies visible in the console
Training, retention, duration, publication and identifier requirements, read live for every provider. An unavailable policy shows as unknown, never as an absence of retention.
- Owner
- Engineering
- Target
- Shipped
Law 25 and GDPR detection inside the conversation
Per-message scanning for passwords, secrets and personal information, confidentiality mode, retrospective batch scans and an administrator review queue. A paid option, off by default, and the detection is itself an outbound call to a model.
- Owner
- Engineering
- Target
- Shipped
Incident notice to your designated officer
Prompt notice to your privacy officer, with the nature of the incident, the people affected, the period and the measures taken. Your own duty to report to the Commission d'accès à l'information remains yours; we support it. No number of hours is written into the contract — that is a separate gap, listed below.
- Owner
- Engineering
- Target
- Clause 14.9
Committed, with a date
These do not exist yet. They have an owner and a date, taken from our internal registers.
Contractual notice period for a sub-processor change
A fixed period to tell you before a hosting or artificial-intelligence sub-processor is added, and publication of the corresponding list. It is the most frequent request from our customers' legal counsel, and one of the few points where Law 25 turns the question directly operational.
- Owner
- Leadership and engineering
- Target
- 30 September 2026
Residency commitment available as an option
Today a residency constraint on inference must be negotiated in the order form. The goal is to make it a documented option, with the list of models actually available under that constraint and its effect on capability.
- Owner
- Leadership and engineering
- Target
- 30 September 2026
Penetration test by an independent third party
Our current testing is internal, documented and reproducible, but it is not independent assurance. An external engagement is planned.
- Owner
- Leadership
- Target
- 30 September 2026
Incident-response exercise
The plan is written and publishes its severity tiers and notification clock. It has never been exercised, and a plan never exercised is a hypothesis. A tabletop exercise is scheduled.
- Owner
- Engineering and leadership
- Target
- 30 September 2026
Published policy on staff access to customer data
The contract already limits access to a need-to-know basis. What is missing is the published policy: who, in what circumstances, with what trace, and in particular how the impersonation feature is governed in a managed instance.
- Owner
- Leadership
- Target
- 31 August 2026
Under consideration
These do not have a date yet. Listing them here without one is more useful than inventing one — and if any of them matters to you, saying so helps us prioritize it.
SOC 2, ISO 27001 or ISO 42001 certification
We hold none and no engagement is under way. A certification attests to a scope chosen by the certified organization; it does not replace reading the controls. In the meantime, the audit right in clause 14.10 and this page are what we offer in its place.
- Owner
- Leadership
- Target
- No date announced
Technical lock on zero-retention routing
Selecting providers that do not train rests today on configuration and on the contract. The control that would technically restrict every call to zero-retention endpoints does not yet exist. Worth noting: such a lock would not cover web search or external tools, which fall under their own policies.
- Owner
- Engineering
- Target
- No date announced
Configurable retention per workspace
No retention-period setting for conversations, documents or knowledge bases. Some features carry fixed caps written into the product; the rest is deleted manually or through the compliance scans.
- Owner
- Engineering
- Target
- No date announced
Firm deletion deadline after the contract ends
Clause 14.11 provides for deletion after the transition period, without a number of days. Customers ask for a fixed deadline, typically forty-five days. The question is open and has not been settled.
- Owner
- Leadership
- Target
- No date announced
An incident-notification deadline expressed in hours
Section 14.9 commits us to notice “without delay”, with no number of hours. Your own clocks do carry numbers — 24 hours to the AMF, 24 hours to OSFI, 72 hours to the supervisory authority under the GDPR — and they start from your discovery, not from our notice. As long as the contract carries no figure, your ability to hold them depends on our speed with nothing bounding it. It is the most-cited gap elsewhere on this site, and it was missing from the page that serves as the register.
- Owner
- Management
- Target
- No date announced
Log export and recovery objectives
No export feed from the audit log to a third-party security tool, and no recovery time and recovery point objectives documented and proven by a restore drill.
- Owner
- Engineering
- Target
- No date announced
Enforced multi-factor authentication on single sign-on and email-code logins
The product enforces multi-factor authentication itself: native TOTP and passkeys, requirable through a conditional-access policy. What is still missing: that policy does not cover Microsoft or Google single sign-on, nor email-code sign-in, which remain governed by the provider's own policy. Session idle and absolute timeouts exist but ship disabled by default.
- Owner
- Engineering
- Target
- No date announced
GDPR-aligned data processing addendum
The master agreement is written around Law 25 obligations. As it stands it carries no separate addendum aligned with GDPR Article 28, and no standard contractual clauses for transfers outside the European Union. A customer subject to GDPR therefore has to request them on the order form.
- Owner
- Leadership
- Target
- No date announced
Marking AI-generated content
The platform puts no notice or watermark on generated text you copy out of the tool. This is not a future requirement: the Chambre de l'assurance has asked for it since November 2024, and several professional orders point the same way. Today, marking is entirely on the user.
- Owner
- Engineering
- Target
- No date announced
A report of the information that fed a given answer
You can reconstruct by hand what fed an answer — the prompt, the attachments, the knowledge bases attached, the cited sources — but there is no exportable report that lists them. The Chambre de l'assurance asks that you be able to supply that list on request and correct anything wrong in it; that is a product capability, not a policy.
- Owner
- Engineering
- Target
- No date announced
Archival durability and a certificate of destruction
Several records-keeping regulations require the system to stay legible and accessible for ten years after a file is closed, and a certificate of confidential destruction at the end of that period. We offer neither: a conversation platform is not an archiving system, and a record you must keep has to be exported into yours. We say so rather than letting you assume otherwise.
- Owner
- Engineering and management
- Target
- No date announced
The model kill switch on server-picked steps
The kill switch binds every model a user picks, administrators included. It does not yet bind the calls the server makes on its own, and several of them carry real content: the extraction of the text of a document added to a knowledge base, or pulled from a SharePoint, OneDrive or Google Drive connector — which goes through a model pinned in the code; the Law 25 detector, which sends the text of the message to the cheapest model that can hold it; the conversation title, which sends up to 600 characters of it, plus 600 of the reply; the agent's screenshot; and the raw audio of the Learning module. The full list is now published on the Confidentiality and compliance page, with what leaves and to which model. What is needed: that the same access check apply to those calls as it applies to a user's. No date announced.
- Owner
- Engineering
- Target
- No date announced
How we hold this page
Four rules, applied to our internal documents before they were applied here.
A dated gap beats a promise
A named gap, with an owner and a date, lets a buyer decide. An unnamed gap forces them to find it in due diligence, and what they find is not just the gap: it is that it was kept from them.
A pessimistic error is corrected like an optimistic one
We have described our own controls as weaker than they were. That is an error in the same way the opposite is, and it is corrected with the same standard of evidence.
A control verified by reading is flagged as such
When a control is confirmed by reading the code rather than executing it, we say so. The difference matters to anyone assessing residual risk.
The list grows when we look
An audit that finds fewer things than the last one is more often a worse audit than a better product. This list grows when we look seriously, and it shortens only when something is genuinely fixed.
Is one of these a blocker for you?
Say so now rather than at the end of a process. Some can be handled in the order form; others are a reason for us to recommend a different approach — including not putting certain data in the platform yet.
Security question or vulnerability report: support@hilointelligence.ca.