Home/ Trust
Trust

Trust, documented.

The frameworks we operate against. The sub-processors that touch your data. The response times we commit to in writing. For the technical posture of redactlabs.ca itself, see Security Posture.

Compliance, by source

What governs the work.

We operate against published standards and map every engagement back to them. Where regulated clients need board-ready evidence, the mapping is the evidence.

Compliance frameworks, by source
FrameworkWhat it isScope
NIST CSF 2.0Govern, Identify, Protect, Detect, Respond, Recover. Released February 2024 — the first major revision in a decade. Our default control taxonomy.Every engagement
CIS Controls v818 control categories across three Implementation Groups. IG2 for charities and growing SMBs; IG3 for regulated and high-revenue clients.Technical depth
CyberSecure CanadaFederal SMB certification on the CAN/CIOSC 104:2021 baseline. 13 baseline controls, mapped on every engagement.Minimum bar
PIPEDAFederal private-sector privacy law. Privacy-impact assessments, OPC-aligned breach response, board-ready documentation.All commercial CA clients
Quebec Law 25Modernized Quebec private-sector privacy. Privacy officers, mandatory PIAs, breach notification, GDPR-style consent. Penalties up to C$25M or 4% of turnover.Clients operating in Quebec
PHIPAOntario’s Personal Health Information Protection Act. Consent, breach-notification, and record-keeping for health-information custodians.Ontario health clients
Sub-processors

Every vendor, named.

The infrastructure that delivers RedactLabs services, listed up front so procurement does not have to ask.

Sub-processors that touch client data
Sub-processorPurposeData region
CloudflareEdge, DNS, WAF, Workers, R2 object storageGlobal anycast; CA-resident KV/R2 where contracted
ResendTransactional email deliveryUnited States
Microsoft 365Internal email, collaboration, document storageCanada (data residency)
Proton Business SuiteEncrypted email, secure file storage, calendar, VPNSwitzerland / EU
Proton Pass BusinessCredential vaulting and shared secretsSwitzerland / EU
GitHubSource control for Worker templates and toolingUnited States

Engagement-specific tools — EDR, SIEM, identity, backup — are scoped per engagement and named in your statement of work. We never recommend a vendor whose referral fee we have not disclosed to you in writing.

Response times, committed

Acknowledgement, in writing.

Acknowledgement targets, not resolution targets. Resolution depends on scope.

Response-time commitments by engagement
EngagementAcknowledgeHours
Managed Cybersecurity — critical incident15 minutes24/7
Managed Cybersecurity — standard1 business hourMon–Fri, 9–5 ET
Managed Service Desk — priority retainer1 hourBusiness hours + after-hours
Managed Service Desk — standard retainer4 business hoursMon–Fri, 9–5 ET
Security vulnerability reports72 hoursSee Security Posture
Sales / scoping enquiries1 business dayMon–Fri, 9–5 ET
Data retention

Held briefly. Purged on schedule.

What we hold, where it lives, and how long it stays.

Form submissions
CA-region object storage, PII hashed at write time. 30-day retention, then purged. No free-text bodies in plaintext.
Edge access logs
IPs stored as /24 ranges only, never full addresses. 30-day retention. Rate-limiting and incident triage.
Client engagement data
CA-region Microsoft 365 with conditional access. Retained for the engagement plus 7 years for tax and audit, then purged.
Newsletter subscribers
Email address only. One-click unsubscribe in every send. Resend, with subscriber state in our own CA-region Workers KV. Never sold, never shared.
Audit pack

The full pack, under NDA.

DPA, MSA template, sub-processor list, insurance certificates, and a SOC-style control summary. Available under NDA to active and prospective enterprise clients.