Trust, documented.
The frameworks we operate against. The sub-processors that touch your data. The response times we commit to in writing. For the technical posture of redactlabs.ca itself, see Security Posture.
What governs the work.
We operate against published standards and map every engagement back to them. Where regulated clients need board-ready evidence, the mapping is the evidence.
| Framework | What it is | Scope |
|---|---|---|
| NIST CSF 2.0 | Govern, Identify, Protect, Detect, Respond, Recover. Released February 2024 — the first major revision in a decade. Our default control taxonomy. | Every engagement |
| CIS Controls v8 | 18 control categories across three Implementation Groups. IG2 for charities and growing SMBs; IG3 for regulated and high-revenue clients. | Technical depth |
| CyberSecure Canada | Federal SMB certification on the CAN/CIOSC 104:2021 baseline. 13 baseline controls, mapped on every engagement. | Minimum bar |
| PIPEDA | Federal private-sector privacy law. Privacy-impact assessments, OPC-aligned breach response, board-ready documentation. | All commercial CA clients |
| Quebec Law 25 | Modernized Quebec private-sector privacy. Privacy officers, mandatory PIAs, breach notification, GDPR-style consent. Penalties up to C$25M or 4% of turnover. | Clients operating in Quebec |
| PHIPA | Ontario’s Personal Health Information Protection Act. Consent, breach-notification, and record-keeping for health-information custodians. | Ontario health clients |
Every vendor, named.
The infrastructure that delivers RedactLabs services, listed up front so procurement does not have to ask.
| Sub-processor | Purpose | Data region |
|---|---|---|
| Cloudflare | Edge, DNS, WAF, Workers, R2 object storage | Global anycast; CA-resident KV/R2 where contracted |
| Resend | Transactional email delivery | United States |
| Microsoft 365 | Internal email, collaboration, document storage | Canada (data residency) |
| Proton Business Suite | Encrypted email, secure file storage, calendar, VPN | Switzerland / EU |
| Proton Pass Business | Credential vaulting and shared secrets | Switzerland / EU |
| GitHub | Source control for Worker templates and tooling | United States |
Engagement-specific tools — EDR, SIEM, identity, backup — are scoped per engagement and named in your statement of work. We never recommend a vendor whose referral fee we have not disclosed to you in writing.
Acknowledgement, in writing.
Acknowledgement targets, not resolution targets. Resolution depends on scope.
| Engagement | Acknowledge | Hours |
|---|---|---|
| Managed Cybersecurity — critical incident | 15 minutes | 24/7 |
| Managed Cybersecurity — standard | 1 business hour | Mon–Fri, 9–5 ET |
| Managed Service Desk — priority retainer | 1 hour | Business hours + after-hours |
| Managed Service Desk — standard retainer | 4 business hours | Mon–Fri, 9–5 ET |
| Security vulnerability reports | 72 hours | See Security Posture |
| Sales / scoping enquiries | 1 business day | Mon–Fri, 9–5 ET |
Held briefly. Purged on schedule.
What we hold, where it lives, and how long it stays.
- Form submissions
- CA-region object storage, PII hashed at write time. 30-day retention, then purged. No free-text bodies in plaintext.
- Edge access logs
- IPs stored as /24 ranges only, never full addresses. 30-day retention. Rate-limiting and incident triage.
- Client engagement data
- CA-region Microsoft 365 with conditional access. Retained for the engagement plus 7 years for tax and audit, then purged.
- Newsletter subscribers
- Email address only. One-click unsubscribe in every send. Resend, with subscriber state in our own CA-region Workers KV. Never sold, never shared.
The full pack, under NDA.
DPA, MSA template, sub-processor list, insurance certificates, and a SOC-style control summary. Available under NDA to active and prospective enterprise clients.