Trust

Security & data

You are trusting AICQ with the records your licence depends on. Here is exactly how they are protected. Questions a QAP or IT reviewer would ask are welcome: info@aicqsystems.com.

Canadian data residency

Your documents, records, and backups are stored at rest in Canada (AWS ca-central-1, Montreal) and are not replicated to storage outside Canada. Some processing happens outside Canada: our application runs on infrastructure in the United States, and documents submitted for automated review are transmitted to a third-party processing provider in the United States, which returns the findings and does not retain your content for training. Email delivery and website analytics are also operated by United States providers. While data is in another country it is subject to that country's laws and may be accessible to its courts and law enforcement under a lawful order. A full list of our providers and where each processes data is in our Privacy policy.

Encryption

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Uploaded files additionally carry a server-computed SHA-256 hash, so any alteration of a stored document is detectable.

Tenant isolation

AICQ is multi-tenant with database-enforced row-level security: every query is scoped to your organization by the database itself, not by application code alone. Your QAP's access to your site is checked against their active assignment on every request.

Data integrity (ALCOA+)

The audit trail is append-only — entries are never updated or deleted, and every entry records who, what, when (UTC), and the before/after state. Records are soft-deleted only, never destroyed, and all regulatory timestamps are server-side.

Retention (s.232)

The Cannabis Regulations require records to be retained for at least two years. AICQ enforces this: records cannot be hard-deleted inside the retention window, and offboarding includes a full export plus retention of your records for the remainder of the window.

Access control

Four-tier role model (operator, manager/AQAP, QAP, platform admin) with least-privilege defaults. Platform-admin actions are separately flagged in the audit trail. AI processing runs server-side only; no API keys or regulated data are exposed to the browser.

Backups and availability

Databases are backed up daily with point-in-time recovery through our infrastructure provider. Files are stored redundantly within the Canadian region.

Privacy (PIPEDA)

We collect only the personal information needed to operate the service (names, work emails, roles) and handle it under PIPEDA. See the Privacy Policy for detail. We do not sell data, and your quality records are never used to train AI models.

Compliance roadmap

AICQ is engineered to data-integrity principles today (ALCOA+, append-only audit, tenant isolation). A SOC 2 Type I assessment is on our roadmap as the platform scales; the control design already anticipates it. QAPs and security reviewers can request our system description at info@aicqsystems.com.

Last updated July 2026.