Security

Last updated: August 24, 2026

A transparent look at how we protect your data and your clients' data including our ongoing work toward Quebec's Law 25.

1. Hosted in Canada

Our application infrastructure database and AI routing gateway runs on a self-hosted server located in Canada, not on a third-party managed cloud.

2. A Controlled AI Gateway

AI calls go through our own self-hosted internal gateway rather than exposing the application directly to a third-party provider. This lets us control and evolve our model providers without changing the client architecture.

3. No Free Public AI Tools

AI calls run through commercial, business-grade APIs never the free public version of a chatbot.

4. Sensitive Data Encrypted at Rest

Sensitive credentials, such as calendar connections, are encrypted (AES-256-GCM) before being stored.

5. Minimized Telemetry

Technical logs used for performance and cost monitoring never contain the content of conversations or AI exchanges only technical metadata.

6. Strict Isolation Between Clients

Each client can only access their own data, enforced at the database level with row-level security not just in the application layer.

7. Our Law 25 Compliance Work

We are actively conducting a privacy impact assessment (évaluation des facteurs relatifs à la vie privée) to formalize and document our compliance approach, in particular for data transfers related to our AI providers. This is active work, not a finished certification we'll update this page as it progresses.

8. Contact Us

Questions about security or privacy? We'd be glad to help. Automathing Inc. Email: info@automathing.ca Quebec, Canada