Security and data protection

CyberSecure Canada certified. Encryption by default, strict access controls, and no training on customer data. Documentation available for procurement review.

Encrypted by default

TLS 1.3 in transit, AES-256 at rest. Industry-standard encryption everywhere data lives.

No training on customer data

Your prompts, documents, and outputs are never used to train or fine-tune any model — ours or anyone else's.

Access controls included

Role-based access, audit logging, and session controls come standard on every plan.

How your data is protected

Independently certified

CyberSecure Canada certified

The Altercation Company Inc., operating as Augure, is certified under CyberSecure Canada, the national cybersecurity certification for Canadian small and medium organizations. Complade Canada Inc., a CyberSecure Canada certification body, audited our security controls across all departments against the CAN/DGSI 104 standard.

Standard
CAN/DGSI 104:2021 / Rev 1: 2024
Certification body
Complade Canada Inc.
Certificate
No. 25031
Valid
Oct 8, 2026 to Oct 8, 2028

Encryption

  • TLS 1.3 between your browser and our servers.
  • AES-256 at rest.
  • Key management with industry-standard rotation and access controls.

Access controls

  • Secure session management with encrypted tokens.
  • Role-based access controls for Knowledge document management.
  • Audit logging for administrative actions and data access events.

Data handling

  • Your conversations, documents and account data are stored on infrastructure in Canada.
  • Zero data retention on inference — prompts are not kept after processing.
  • Customer data is fully separated from model training pipelines.
Sub-processors are listed in our privacy policy

Compliance

  • CyberSecure Canada certified (CAN/DGSI 104), certificate No. 25031.
  • SOC 2 and ISO 27001 readiness underway with Vanta.
  • Designed to support Law 25 and PIPEDA obligations.
  • Infrastructure providers hold SOC 2 and ISO 27001 certifications.
  • Security documentation available for procurement review.
See our live controls in the Trust Centre

We can't make your organization compliant on our own — that depends on your full security posture. Our job is to make sure AI tooling isn't the gap.

Responsible disclosure

If you believe you've found a security vulnerability in an Augure product, we want to hear about it. Email hello@augureai.ca with the details and we'll follow up.

Questions from your security team?

We share security questionnaires, architecture documentation, and audit artefacts on request.