Quintessentia Network logo QuintessentiaNetwork Inc.
Trust

Security, residency and honesty

Everything a security reviewer normally has to email us for — where your data lives (Canada or the United States, your choice), who can touch it, which third parties are involved, and what we don't yet have.

What we do not have, stated plainly: Quintessentia Network Inc. is not SOC 2 certified and is not ISO 27001 certified. We are a small, owner-operated Canadian firm serving clients in Canada and the United States. If your procurement process requires either certification from every vendor, we will not pass it today — and we would rather you learn that here than three meetings in.

What we offer instead is documented practice, data residency in the country you choose, contractual commitments, and the option to run everything inside your own infrastructure so the trust boundary never leaves your organisation.

This page is a summary; the agreement governs. Everything below describes how we work by default. If a specific point matters to your procurement, ask us to write it into the contract for your engagement — and if we cannot commit to it for your project, we will say so before you sign rather than after.

Residency

Where your data lives

Chosen per engagement and written into the contract before work starts.

Canadian regions
AWS ca-central-1 (Montreal) or Azure Canada Central (Toronto). Our default for Canadian clients and for work involving personal information under PIPEDA or personal health information under PHIPA.
United States regions
AWS or Azure in U.S. regions for U.S. clients, including HIPAA-eligible services where an engagement requires them. Region is selected with you and named in the contract.
Your own cloud tenancy
We build inside your AWS, Azure or GCP account, in whichever region you already use. You hold the keys, the logs and the bill; we hold scoped access that you can revoke.
Your own hardware
Fully on-premise deployment, including self-hosted open-weight models where no data may leave your network at all.
Cross-border transfer
If a workflow genuinely requires a service hosted outside your chosen country, we name it in writing before you sign, explain exactly what data crosses the border, and you decide. We do not move data across borders silently — in either direction.
Sub-processors

Third parties in the chain

Any engagement's exact sub-processor list is attached to its Data Processing Agreement. These are the categories we use, and we name the specific vendor and region per project.

Model providers
Large language model APIs, selected per engagement and named in your DPA. We select providers and service tiers whose published terms state that data submitted through the API is not used to train their models, and we name the provider, tier and region in your agreement so you can check that against their terms yourself rather than taking our word for it. Where no third-party provider is acceptable, self-hosted open-weight models are available.
Cloud infrastructure
AWS or Microsoft Azure in Canadian or U.S. regions, or your own account. Named per engagement.
This website
Static hosting, plus Google Fonts and Fontshare for typefaces (your browser requests these directly). We run no advertising trackers, no analytics cookies and no session recording on this site, and we set no cookies of our own. See our privacy policy.
Practice

How we handle your data

Encryption

TLS 1.2+ for all data in transit. Encryption at rest using the platform-native mechanisms of the chosen cloud, or full-disk encryption on dedicated hardware.

Access control

Least-privilege, per-engagement credentials. Multi-factor authentication on every account with access to client systems. Access is scoped to the named individuals on your engagement and revoked at project close or on your request.

Secrets

Credentials are stored in a secrets manager, never in source code, configuration files or messages. Client secrets are never committed to version control.

Human oversight

Every automation we build has a defined approval gate before irreversible actions — payments, external communications, record deletion, or anything affecting a person's entitlements. Fully autonomous execution is reserved for reversible, low-consequence steps and is agreed in writing.

Auditability

Every automated decision is logged with its inputs, the model and version used, the output, and whether a human approved it. Logs are yours and are retained on infrastructure you control where the engagement allows.

Retention & deletion

We retain client data only as long as the engagement requires. On request or at project close we delete our working copies and confirm in writing. Where we build in your tenancy, retention is governed entirely by your own policies.

Incident response

If we become aware of a breach involving your data we will notify you without undue delay, with what we know, what is affected, and what we are doing. Where PIPEDA's real-risk-of-significant-harm threshold is met, we support your reporting obligations to the Office of the Privacy Commissioner of Canada.

Confidentiality

Mutual NDA available before any discovery conversation. Client work and client identities are never used as marketing references without written permission.

Regulatory

Frameworks we build against

PIPEDA (Canada)
Canada's federal private-sector privacy law. We build to identified purposes, proportionate safeguards, retention limits and breach notification.
PHIPA (Ontario)
Where a client is a health information custodian, our role under PHIPA — agent, electronic service provider, or both — is determined with you and named in the agreement, along with the restrictions that follow from it. That determination is yours to make with your privacy officer; we will not assume a status on your behalf.
Quebec Law 25
Where a client has Quebec employees or customers, we account for its stricter requirements, including assessment of cross-border transfers and disclosure where a decision is based exclusively on automated processing.
HIPAA (United States)
Where a U.S. client is a covered entity or business associate, we work under a Business Associate Agreement and build on HIPAA-eligible cloud services in a U.S. region. To be precise: there is no such thing as a "HIPAA-certified" vendor — what exists is a signed BAA and controls that meet the Security Rule. We will not claim more than that.
U.S. state privacy laws
Where the CCPA/CPRA or a comparable state statute applies to a client, we build to its requirements on purpose limitation, retention, deletion and service-provider obligations, and reflect them in the agreement.
CASL (Canada) & CAN-SPAM (U.S.)
Any automation we build that sends commercial email is built to the applicable regime — consent basis, sender identification and a working unsubscribe path. CASL is materially stricter than CAN-SPAM; where a client sends into both countries we build to the stricter standard.
Accessibility
We build client-facing interfaces to WCAG 2.0 Level AA — the standard behind Ontario's AODA and the reference point for U.S. ADA web-accessibility expectations — and we test against it before handover. Where a specific success criterion cannot be met in a given interface, we tell you which one and why, rather than claiming a blanket pass.
Federal AI legislation
We will be straight with you: the AI portion of Bill C-27 (AIDA) did not become law, and there is currently no in-force federal AI statute in Canada. Any vendor selling you "AIDA compliance" is selling something that does not exist. We build to AI governance good practice — documented purpose, human oversight, logging and evaluation — and we track legislation as it develops.
FAQ

Questions worth asking first

Each answer restates a commitment set out above. This page is a summary; the agreement governs.

Are you SOC 2 or ISO 27001 certified?

No. Quintessentia Network Inc. is not SOC 2 certified and is not ISO 27001 certified. We are a small, owner-operated Canadian firm serving clients in Canada and the United States. If your procurement process requires either certification from every vendor, we will not pass it today — and we would rather you learn that here than three meetings in. What we offer instead is documented practice, data residency in the country you choose, contractual commitments, and the option to run everything inside your own infrastructure so the trust boundary never leaves your organisation.

Where will our data live?

Chosen per engagement and written into the contract before work starts. The Canadian regions are AWS ca-central-1 (Montreal) or Azure Canada Central (Toronto) — our default for Canadian clients and for work involving personal information under PIPEDA or personal health information under PHIPA. For U.S. clients we use AWS or Azure in U.S. regions, including HIPAA-eligible services where an engagement requires them. We can also build inside your AWS, Azure or GCP account, in whichever region you already use, or fully on-premise on your own hardware.

Is our data used to train anyone's models?

We select providers and service tiers whose published terms state that data submitted through the API is not used to train their models, and we name the provider, tier and region in your agreement so you can check that against their terms yourself rather than taking our word for it. Where no third-party provider is acceptable, self-hosted open-weight models are available.

Does data ever cross the border?

Not silently — in either direction. If a workflow genuinely requires a service hosted outside your chosen country, we name it in writing before you sign, explain exactly what data crosses the border, and you decide.

What happens to our data when the engagement ends?

We retain client data only as long as the engagement requires. On request or at project close we delete our working copies and confirm in writing. Access is scoped to the named individuals on your engagement and revoked at project close or on your request. Where we build in your tenancy, retention is governed entirely by your own policies.

Security questions before a call?

Send your vendor security questionnaire and we'll complete it honestly — including the questions where the answer is "not yet."

Get in touch