Security & Compliance

Last updated: May 2026

HPO Canada is architected for the most security-sensitive deployments in Canadian enterprise, government, and healthcare. This page summarises our current compliance posture, technical controls, and data-sovereignty options. For detailed audit reports, penetration test summaries, or a signed NDA-backed security questionnaire, contact gurbachan@hpocanada.com.

Current compliance posture

πŸ‡ΈπŸ‡¬ Singapore PDPA Compliant πŸ‡¨πŸ‡¦ PIPEDA Compliant πŸ‡ͺπŸ‡Ί GDPR Compliant πŸ“‹ ISO 27001 Aligned πŸ” SOC 2 Type II β€” In Progress πŸ›οΈ Gov Canada PBMM β€” In Progress

Compliant means our policies, controls, and data-handling practices are aligned with the framework’s published requirements and we will cooperate with customer audits.
Aligned means our controls map to the framework but we have not yet completed third-party certification.
In Progress means we are actively working with auditors toward formal certification; estimated completion timelines are available on request.

Encryption

Access control

Audit logging

AI model safety

Data sovereignty options

Infrastructure security

Incident response

HPO Canada maintains a documented incident-response playbook covering detection, containment, eradication, recovery, and customer notification. Material security incidents are communicated to affected customers within 72 hours of confirmation, per GDPR Article 33 and PIPEDA breach-notification guidance.

Sub-processors

Our current sub-processor registry is available on request under NDA and includes Amazon Web Services, Google Cloud, and Pinecone. Updates are announced in advance via our service-status page.

Security contact

Report a vulnerability or request a security review at gurbachan@hpocanada.com. We support encrypted email via PGP on request.