Trust centre

What protects your members' data

Everything below is either working today or openly marked as unfinished.

Last reviewed 25 August 2026

Compliance standards

Where we stand against each standard. No outside audit has been completed against any of them.

  • PCI DSS

    Audit ready

    Card details go straight to our payment processor, so Sembr never receives a card number. That puts us in SAQ A, the smallest scope there is.

  • CASL

    Audit ready

    Consent is recorded, unsubscribes are honoured, and implied consent expires on its own clock rather than sitting there forever.

  • PIPEDA

    Preparing

    Built around the ten principles. Privacy counsel has not reviewed it yet.

  • CCPA and CPRA

    Preparing

    We never sell member data or share it for advertising, which is the right this law is built around. The rest has had no legal review.

  • Quebec Law 25

    Preparing

    Quebec sits outside our current privacy scope, and the impact assessment the law requires has not been done.

  • WCAG 2.2 AA

    Preparing

    The standard Ontario's accessibility law points at. The site and product are built to it, and no accessibility audit has been done.

  • SOC 2

    Preparing

    Controls are being built and evidenced against the Trust Services Criteria. No report exists and no auditor has been engaged.

  • ISO 27001

    Preparing

    Controls are aligned to Annex A. There is no certificate and no certification body involved.

The short version

  • Separated

    Your records are walled off from every other organization inside the database, not just in the software.

  • Yours to take

    Export everything, any time, in JSON, CSV or SQL. No fee, no ticket, no notice period.

  • In Canada

    The database and every member file sit in Toronto. The nightly backup copy stays in Toronto too.

  • Tamper-evident

    Every change is written to a sealed log. Alter a record and the chain breaks where it was altered.

  • Answerable

    A member can ask for their data and get it. The 30-day clock is tracked for your staff.

  • Never sold

    We do not sell member data or share it for advertising. No trackers, no ad pixels, no brokers.

The controls

Open a section to read the detail. Anything unfinished is listed in the same place as everything else, not tucked away at the bottom.

  • In place
  • Partly done
  • Not yet
Isolation and infrastructure

Where your data lives, who can reach it, and what happens if the worst does.

  • Tenant isolation

    One organization cannot read another

    In place

    The separation is enforced by the database, not by the application. A request that arrives without an organization attached gets nothing back rather than everything.

  • Residency

    Your data is stored in Canada

    In place

    The database runs in Toronto and is reachable only from our own servers on a private network, never from the open internet.

  • Residency

    Member files stay in Canada, including the backup

    In place

    Uploads and data-request bundles are stored in Toronto. The nightly backup copy is made server to server inside the same region, so those files never leave the country at any point.

  • Backups

    The database is backed up daily

    In place

    Automatic daily backups, plus the ability to rewind to any moment in the last week.

  • Recovery

    We have never done a full practice restore

    Not yet

    The backups exist. The restore has never been rehearsed end to end, so we cannot tell you how long a recovery would take, and we will not quote a number until we have run one. No end-to-end restore has been performed against the member database, so no recovery time objective is known or claimed.

  • Backups

    Support and internal systems are backed up offsite

    In place

    Encrypted every night and copied off the machine they came from, kept for 35 days. This covers support conversations and internal tooling, not member records.

Owning your data

Leaving should cost nothing, and a member who asks to be forgotten should actually be forgotten.

  • Portability

    Export everything, whenever you want

    In place

    Every record we hold for your organization, in JSON, CSV or SQL, on demand. No charge and no support ticket. Each export is recorded in the log.

  • Erasure

    A member can be erased without breaking your books

    Partly done

    Personal details are erased in place while invoices and payments stay intact and anonymous. The backup copy of a member's uploaded files is deleted at the same time as the live copy, whether or not the live copy is still there. That step is not switched on in production yet, because the restricted storage credential it needs does not exist, and every run says so in its own logs. Until it does, a deleted file can survive in the backup copy.

  • Rights requests

    Member data requests run on a tracked clock

    In place

    A request is logged with a due date 30 days out and your staff can see it. One extension is allowed, and taking it has to be recorded.

  • Payments

    Card numbers never reach us

    In place

    Payment details go straight to our processor. We hold a token and a receipt, never a card number.

Proof and record-keeping

What we can show you about what happened, and where that record is still thin.

  • Audit log

    The log cannot be altered without it showing

    In place

    Every change is written to a sealed log where each entry is bound to the one before it. Alter a record and the chain breaks where it was altered.

  • Audit coverage

    Sign-ins are not logged yet

    Partly done

    Changes to records are logged. Authentication events are not, so the log cannot yet answer who signed in and when. Sign-in, sign-out, failed-login and session-revocation events are not written to the audit log, so the trail cannot reconstruct account access.

  • Audit log

    The log has no copy outside the system it records

    Not yet

    The sealed log lives in the same database as the records it describes. Anyone who could reach the database could reach both. No append-only copy of the audit chain exists outside the primary database, so a sufficiently privileged actor could alter records and the log describing them together.

  • Logging

    Personal details are kept out of the log

    Partly done

    Application logs record what failed and where, not who it happened to. On paths that handle personal data the exception type is recorded rather than its message. Coverage is a naming-pattern grep plus a shared exception helper, not a type-aware guarantee. A log call that formats personal data through an unrecognised path would not be caught. No cross-file data-flow analysis runs today.

Privacy and third parties

Who else touches member data, and what we will never do with it.

  • Data use

    We never sell or share member data

    In place

    No advertising platforms, no data brokers, no tracking pixels, and no analytics product that receives personal data.

  • Transparency

    Every third party is named

    In place

    The vendors that touch member data are listed publicly with what each one receives and where it stores it.

How we work

The habits and gates behind the software, including the ones we have not built yet.

  • Access

    Nobody else has access

    In place

    Sembr is one person. No contractor, agency or third party holds a credential to the production systems.

  • Release gate

    Known vulnerabilities block a release

    In place

    Every change runs dependency, secret and static-analysis scans, and a known vulnerability fails the build rather than filing a note.

  • Release gate

    The isolation rules are enforced by the build

    In place

    The rules that keep organizations separate are checked by the build itself, so breaking one fails a pull request instead of reaching production.

  • Incident response

    The breach procedure has never been rehearsed

    Partly done

    A written breach procedure exists. It has not been practised, so we do not know how long the steps in it actually take. No tabletop or live rehearsal of the breach-notification procedure has been run, so notification timelines are written rather than measured.

  • Independent assurance

    No outside party has reviewed any of this

    Not yet

    No penetration test, no independent code review, no privacy counsel review, no accessibility audit and no certification against any framework. Everything on this page is our own assessment of our own work. No SOC 2 report, ISO certification, penetration test, independent code review, privacy counsel review or accessibility audit exists. Every claim in this register is self-attested and evidenced from our own systems.

Documents

Everything here opens without asking. There are no audit reports to request, because no audit has happened, and listing one behind a request form would tell you it exists.

Compliance requests

Security questionnaires, subprocessor questions, and anything you need that is not published here go to one address. A person reads it and answers with specifics.

privacy@sembr.co

If your board or your insurer needs something in a particular format, say so and we will fill it in rather than sending you a brochure.