Security
Last updated: August 24, 2026
A transparent look at how we protect your data and your clients' data including our ongoing work toward Quebec's Law 25.
1. Hosted in Canada
Our application infrastructure database and AI routing gateway runs on a self-hosted server located in Canada, not on a third-party managed cloud.
2. A Controlled AI Gateway
AI calls go through our own self-hosted internal gateway rather than exposing the application directly to a third-party provider. This lets us control and evolve our model providers without changing the client architecture.
3. No Free Public AI Tools
AI calls run through commercial, business-grade APIs never the free public version of a chatbot.
4. Sensitive Data Encrypted at Rest
Sensitive credentials, such as calendar connections, are encrypted (AES-256-GCM) before being stored.
5. Minimized Telemetry
Technical logs used for performance and cost monitoring never contain the content of conversations or AI exchanges only technical metadata.
6. Strict Isolation Between Clients
Each client can only access their own data, enforced at the database level with row-level security not just in the application layer.
7. Our Law 25 Compliance Work
We are actively conducting a privacy impact assessment (évaluation des facteurs relatifs à la vie privée) to formalize and document our compliance approach, in particular for data transfers related to our AI providers. This is active work, not a finished certification we'll update this page as it progresses.
8. Contact Us
Questions about security or privacy? We'd be glad to help. Automathing Inc. Email: info@automathing.ca Quebec, Canada