Security, taken seriously.
We document the applicable protections and product-specific data locations for the workflow you plan to run. Confirm the details with us before relying on a residency or compliance requirement.
Last updated: December 2024
Security details that matter
Encryption
Controls and protocols are documented by product and planned setup.
Scope
Product-specific data locations — confirm the full workflow, including connected services.
Monitoring
Monitoring and alerting controls depend on the applicable environment.
Evidence
We publish security statements that can be supported by the applicable product scope.
How your data is protected
Four foundations, each logged and reviewed on a fixed cadence.
Encryption everywhere
AES-256 encryption at rest, TLS 1.3 in transit with perfect forward secrecy. Your data is encrypted before it leaves your browser.
Least-privilege access
Staff access to customer data is role-restricted, granted only when support work requires it, and every access is recorded in the audit trail.
Multi-factor authentication
Secure your account with authenticator-app (TOTP) MFA — required for all admin accounts.
Role-based access control
Granular permissions let you control exactly who can see and do what in your organization — from full admin access to scoped vendor access.
Built on secure foundations
Defense in depth — every layer of the stack has its own protections.
Application layer
Secure code practices, input validation, XSS/CSRF protection.
Network layer
DDoS protection, WAF, private VPC, encrypted tunnels.
Data layer
AES-256 encryption, secure key management via AWS KMS with customer-managed keys and automatic rotation with zero downtime. Keys are stored separately from data, never in plaintext, with strictly controlled and logged access. Encrypted backups.
Physical layer
Hosting location and connected-service controls depend on the product and planned setup. Confirm the applicable environment before relying on a residency requirement.
Zero-trust access
Every request verified, every action audited.
- Roles. Admin (full system access, security settings), staff (client management, limited admin), client (own data access, portal features), and vendor (scoped access to assigned clients only).
- Sessions. Automatic timeout and concurrent session limits on every account.
- Support access, controlled. Staff access customer data only when support work requires it. Every access is role-restricted and recorded in the audit trail.
Ongoing protection
Security isn't a feature we shipped once. It's a practice.
24/7 monitoring
Real-time threat detection and automated incident response. Our security team is always watching, with automated anomaly detection and complete audit trails retained for 7 years.
Secure backups
Encrypted daily backups with 30-day retention, stored within Canada.
Vulnerability scanning
Continuous automated scanning of our infrastructure, reviewed on our internal audit cadence. Critical vulnerabilities are prioritized for immediate patching.
Incident response
Documented incident response plan with internal targets: detection in under 1 hour, triage in under 2 hours, containment in under 4 hours, full recovery in under 24 hours. Security incidents communicated within 72 hours.
Data location, explained by product
Storage and processing locations depend on the product and connected services. We review the planned workflow and document the applicable locations before you rely on a residency requirement.
- Product-specific hosting location is confirmed during setup
- Connected-service processing is included in the review
- Residency requirements are assessed against the full workflow
- Privacy obligations and data-processing details are documented for the planned setup
Compliance standards
Where we stand, plainly — reviewed on our internal audit cadence: daily automated scans, weekly access reviews, monthly compliance assessments.
PIPEDA
We design for applicable Canadian privacy obligations; confirm the specific scope for your setup.
GDPR
Readiness depends on the product, connected services, and customer setup.
Bank-grade encryption
Active. AES-256 with HSM-backed key management.
The full regulatory picture — frameworks, audits, and your rights — lives on our compliance page.
Report a security issue
If you've discovered a potential security concern, please contact our security team directly at security@omgsystems.ca. For anything else, get in touch.
Questions about this?
A person answers, not a form. We respond within 48 hours.
security@omgsystems.caOMGsystems Inc. · Durham, Ontario, Canada