Trust centre
What protects your members' data
Everything below is either working today or openly marked as unfinished.
Last reviewed 25 August 2026
Compliance standards
Where we stand against each standard. No outside audit has been completed against any of them.
-
PCI DSS
Audit ready
Card details go straight to our payment processor, so Sembr never receives a card number. That puts us in SAQ A, the smallest scope there is.
-
CASL
Audit ready
Consent is recorded, unsubscribes are honoured, and implied consent expires on its own clock rather than sitting there forever.
-
PIPEDA
Preparing
Built around the ten principles. Privacy counsel has not reviewed it yet.
-
CCPA and CPRA
Preparing
We never sell member data or share it for advertising, which is the right this law is built around. The rest has had no legal review.
-
Quebec Law 25
Preparing
Quebec sits outside our current privacy scope, and the impact assessment the law requires has not been done.
-
WCAG 2.2 AA
Preparing
The standard Ontario's accessibility law points at. The site and product are built to it, and no accessibility audit has been done.
-
SOC 2
Preparing
Controls are being built and evidenced against the Trust Services Criteria. No report exists and no auditor has been engaged.
-
ISO 27001
Preparing
Controls are aligned to Annex A. There is no certificate and no certification body involved.
The short version
-
Separated
Your records are walled off from every other organization inside the database, not just in the software.
-
Yours to take
Export everything, any time, in JSON, CSV or SQL. No fee, no ticket, no notice period.
-
In Canada
The database and every member file sit in Toronto. The nightly backup copy stays in Toronto too.
-
Tamper-evident
Every change is written to a sealed log. Alter a record and the chain breaks where it was altered.
-
Answerable
A member can ask for their data and get it. The 30-day clock is tracked for your staff.
-
Never sold
We do not sell member data or share it for advertising. No trackers, no ad pixels, no brokers.
The controls
Open a section to read the detail. Anything unfinished is listed in the same place as everything else, not tucked away at the bottom.
- In place
- Partly done
- Not yet
Isolation and infrastructure
Where your data lives, who can reach it, and what happens if the worst does.
-
Tenant isolation
One organization cannot read another
In placeThe separation is enforced by the database, not by the application. A request that arrives without an organization attached gets nothing back rather than everything.
-
Residency
Your data is stored in Canada
In placeThe database runs in Toronto and is reachable only from our own servers on a private network, never from the open internet.
-
Residency
Member files stay in Canada, including the backup
In placeUploads and data-request bundles are stored in Toronto. The nightly backup copy is made server to server inside the same region, so those files never leave the country at any point.
-
Backups
The database is backed up daily
In placeAutomatic daily backups, plus the ability to rewind to any moment in the last week.
-
Recovery
We have never done a full practice restore
Not yetThe backups exist. The restore has never been rehearsed end to end, so we cannot tell you how long a recovery would take, and we will not quote a number until we have run one. No end-to-end restore has been performed against the member database, so no recovery time objective is known or claimed.
-
Backups
Support and internal systems are backed up offsite
In placeEncrypted every night and copied off the machine they came from, kept for 35 days. This covers support conversations and internal tooling, not member records.
Owning your data
Leaving should cost nothing, and a member who asks to be forgotten should actually be forgotten.
-
Portability
Export everything, whenever you want
In placeEvery record we hold for your organization, in JSON, CSV or SQL, on demand. No charge and no support ticket. Each export is recorded in the log.
-
Erasure
A member can be erased without breaking your books
Partly donePersonal details are erased in place while invoices and payments stay intact and anonymous. The backup copy of a member's uploaded files is deleted at the same time as the live copy, whether or not the live copy is still there. That step is not switched on in production yet, because the restricted storage credential it needs does not exist, and every run says so in its own logs. Until it does, a deleted file can survive in the backup copy.
-
Rights requests
Member data requests run on a tracked clock
In placeA request is logged with a due date 30 days out and your staff can see it. One extension is allowed, and taking it has to be recorded.
-
Payments
Card numbers never reach us
In placePayment details go straight to our processor. We hold a token and a receipt, never a card number.
Proof and record-keeping
What we can show you about what happened, and where that record is still thin.
-
Audit log
The log cannot be altered without it showing
In placeEvery change is written to a sealed log where each entry is bound to the one before it. Alter a record and the chain breaks where it was altered.
-
Audit coverage
Sign-ins are not logged yet
Partly doneChanges to records are logged. Authentication events are not, so the log cannot yet answer who signed in and when. Sign-in, sign-out, failed-login and session-revocation events are not written to the audit log, so the trail cannot reconstruct account access.
-
Audit log
The log has no copy outside the system it records
Not yetThe sealed log lives in the same database as the records it describes. Anyone who could reach the database could reach both. No append-only copy of the audit chain exists outside the primary database, so a sufficiently privileged actor could alter records and the log describing them together.
-
Logging
Personal details are kept out of the log
Partly doneApplication logs record what failed and where, not who it happened to. On paths that handle personal data the exception type is recorded rather than its message. Coverage is a naming-pattern grep plus a shared exception helper, not a type-aware guarantee. A log call that formats personal data through an unrecognised path would not be caught. No cross-file data-flow analysis runs today.
Privacy and third parties
Who else touches member data, and what we will never do with it.
-
Data use
We never sell or share member data
In placeNo advertising platforms, no data brokers, no tracking pixels, and no analytics product that receives personal data.
-
Transparency
Every third party is named
In placeThe vendors that touch member data are listed publicly with what each one receives and where it stores it.
How we work
The habits and gates behind the software, including the ones we have not built yet.
-
Access
Nobody else has access
In placeSembr is one person. No contractor, agency or third party holds a credential to the production systems.
-
Release gate
Known vulnerabilities block a release
In placeEvery change runs dependency, secret and static-analysis scans, and a known vulnerability fails the build rather than filing a note.
-
Release gate
The isolation rules are enforced by the build
In placeThe rules that keep organizations separate are checked by the build itself, so breaking one fails a pull request instead of reaching production.
-
Incident response
The breach procedure has never been rehearsed
Partly doneA written breach procedure exists. It has not been practised, so we do not know how long the steps in it actually take. No tabletop or live rehearsal of the breach-notification procedure has been run, so notification timelines are written rather than measured.
-
Independent assurance
No outside party has reviewed any of this
Not yetNo penetration test, no independent code review, no privacy counsel review, no accessibility audit and no certification against any framework. Everything on this page is our own assessment of our own work. No SOC 2 report, ISO certification, penetration test, independent code review, privacy counsel review or accessibility audit exists. Every claim in this register is self-attested and evidenced from our own systems.
Documents
Everything here opens without asking. There are no audit reports to request, because no audit has happened, and listing one behind a request form would tell you it exists.
Compliance requests
Security questionnaires, subprocessor questions, and anything you need that is not published here go to one address. A person reads it and answers with specifics.
privacy@sembr.coIf your board or your insurer needs something in a particular format, say so and we will fill it in rather than sending you a brochure.