Security & Compliance

Trust Center

Your data security, privacy, and regulatory compliance are foundational to everything we build. Here is exactly how we protect advisors and clients on the platform.

Encryption
AES-256 + TLS 1.3
Privacy
PIPEDA Compliant
Regulatory
CIRO Verified
Infrastructure
Canadian-Hosted
Security

Enterprise-Grade Data Protection

We apply the same security standards used by major financial institutions to protect every piece of data on the platform.

Encryption Standards

All data is protected with industry-leading encryption both in transit and at rest.

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for all data at rest
  • Encrypted database connections via private network
  • HTTPS enforced on all endpoints with HSTS headers
  • API keys and secrets stored in encrypted vaults

Application Security

Security is built into every layer of our application architecture, not bolted on as an afterthought.

  • Input validation and sanitization on all endpoints
  • Rate limiting and DDoS protection
  • SQL injection and XSS prevention
  • Secure session management with token rotation
  • Dependency vulnerability scanning

Access Control

Strict access controls ensure only authorized personnel and systems can access sensitive data.

  • Role-based access control (RBAC) for all systems
  • Multi-factor authentication for admin access
  • Principle of least privilege enforced
  • Audit logging on all administrative actions
  • Automated access reviews and revocation

SOC 2 Roadmap

We are actively building toward SOC 2 Type II certification to formalize our security posture.

  • Security policies and procedures documented
  • Incident response plan established
  • Change management processes in place
  • Vendor security assessments conducted
  • SOC 2 Type II audit targeted for 2027
Privacy

PIPEDA-Compliant Data Practices

We follow Canada's Personal Information Protection and Electronic Documents Act to the letter. Your data is never sold, shared, or used beyond its stated purpose.

Data Collection

We collect only the minimum data required to deliver the matching service and verify regulatory compliance.

  • Advisor data: name, firm, CIRO number, designations, specializations
  • Client data: investment goals, portfolio range, preferences
  • No financial account numbers or SIN collected
  • No credit card data stored on our servers
  • Consent obtained before any data processing

What We Never Do

Clear commitments about what will never happen with your data on this platform.

  • Never sell personal data to third parties
  • Never share data with advertisers or data brokers
  • Never use data for purposes beyond advisor matching
  • Never retain data longer than necessary
  • Never process data outside of Canada without consent

Your Rights Under PIPEDA

As a user of our platform, Canadian privacy law guarantees you specific rights regarding your personal information. We make exercising these rights straightforward.

  • Right to access all personal data we hold about you
  • Right to correct inaccurate or incomplete information
  • Right to withdraw consent and request data deletion
  • Right to know how your data is being used and disclosed
  • Right to file a complaint with our Privacy Officer or the Office of the Privacy Commissioner of Canada
  • All privacy requests processed within 30 days
Regulatory Compliance

Built on Canadian Securities Integrity

Our platform is designed from the ground up to respect CIRO rules, provincial securities regulations, and CSA guidelines.

CIRO Verification

Every advisor is cross-referenced against CIRO's public registry. We verify registration status, firm affiliation, and disciplinary history before any profile goes live.

Provincial Licensing

We verify that advisors hold valid registration in the provinces where they claim to operate, ensuring clients only see properly licensed professionals.

CSA Alignment

Our platform design aligns with Canadian Securities Administrators guidelines on referral arrangements, fee disclosure, and client-advisor relationships.

Designation Verification

CFA, CFP, CIM, FCSI, and PFP designations are independently verified with their respective issuing bodies before being displayed on advisor profiles.

No Investment Advice

CanadaInvesting is a technology platform that facilitates connections. We do not provide investment advice, manage assets, or act as a registered dealer.

Advisor Autonomy

Advisors maintain full professional independence. We never influence investment recommendations, fee structures, or client acceptance decisions.

Infrastructure

Secure, Reliable Technology

Our platform runs on modern, secure infrastructure with continuous monitoring and automated incident response.

Canadian-Hosted Infrastructure

All data is stored and processed on servers located in Canada, ensuring compliance with Canadian data residency expectations.

99.9% Uptime Target

Redundant infrastructure and automated failover ensure the platform remains available when advisors and clients need it.

24/7 Monitoring

Automated monitoring detects anomalies, performance degradation, and security events in real time with immediate alerting.

Automated Backups

Continuous database backups with point-in-time recovery ensure no data is lost, even in the event of a system failure.

Secure Development

Code reviews, automated testing, and staged deployment pipelines ensure changes are thoroughly vetted before reaching production.

Incident Response

Documented incident response procedures with defined escalation paths, communication templates, and post-mortem processes.

Data Retention

Clear Retention & Deletion Policies

We retain data only as long as necessary to provide the service and meet legal obligations. You can request deletion at any time.

Data Type
Retention Period
Deletion Policy
Advisor profile information
Duration of active subscription + 90 days
Automatically purged 90 days after subscription ends
Client matching preferences
Duration of active engagement + 30 days
Deleted upon request or 30 days after last activity
Application form submissions
12 months if not approved
Automatically purged after 12 months if application not approved
Communication logs
6 months
Automatically purged on a rolling 6-month basis
Payment records
7 years (legal requirement)
Retained for tax and legal compliance, then purged
Analytics data
Aggregated and anonymized
Personal identifiers stripped within 30 days
Questions?

Security & Privacy Inquiries

If you have questions about our security practices, privacy policies, or need to exercise your data rights, reach out directly.

Contact Our Team

For security concerns, data access requests, privacy complaints, or general trust-related questions, contact us through any of the following channels. We respond to all security and privacy inquiries within 48 hours.

Built on Trust. Backed by Verification.

Join Canada's most transparent investment advisor marketplace. Every advisor verified. Every data point protected. Every connection earned.

Apply to Join as Advisor Find an Advisor