← Back to Insights
Data Sovereignty

Canadian AI checklist: how to buy a CLOUD Act-free AI stack

A practical checklist for choosing Canadian AI tools that keep customer data out of US jurisdiction. What to ask vendors before you sign.

By Augure·
Canadian technology and compliance

You want an AI tool that doesn't put customer data anywhere a US court can reach it. That's the whole checklist. Everything below is how you check.

The US CLOUD Act lets American authorities compel US companies to hand over data, even data stored outside the United States, if that company controls it. So the question isn't "where are the servers." It's "who's the company, and what government can order them around."

What actually makes an AI tool CLOUD Act-free?

Three things, and you need all three.

The company has no US corporate parent and no US investors with control rights. The infrastructure — the actual servers doing inference — sits outside US jurisdiction. And your data is never decrypted for processing by anyone who answers to a US court.

Miss one of these and the other two don't help much. A Canadian reseller running on top of a US cloud provider is still a US-controlled stack underneath. Encryption at rest looks reassuring on a sales page, but AI has to decrypt your documents to read them. That's the moment the CLOUD Act matters, not before.

Augure is Canadian, with no US corporate parent and no US investors. Customer conversations, documents, and AI inference are never handled by US-jurisdiction providers, so the CLOUD Act's reach over US-controlled providers doesn't extend to that content. That's a scoped claim, and it's the one that matters: it's about your content specifically, not a promise about every wire in the building.

A sceptical reader might ask: if no vendor can promise full compliance, why check any of this at all? Because the checklist doesn't buy you a guarantee. It buys you a defensible answer, the kind you can show a regulator or a nervous client, that says you looked at where the data goes and picked deliberately. That's a different position than "we didn't ask."

Where does my data actually go?

Ask this directly. Any vendor worth using should answer in one paragraph, not a forty-page sub-processor agreement you need a lawyer to read.

For Augure, customer data is stored in Canada. AI inference runs on Canadian infrastructure for some model tiers, and on vetted EU partners under zero-data-retention agreements for others, including during failover. Neither path touches US infrastructure. Two things do run through US systems: payment card processing and email delivery, because that's how Visa and Gmail work almost everywhere. Both are documented in the privacy policy, both are limited, and neither one touches your conversations or your documents.

That last point matters if you're doing your own transfer analysis under Quebec's privacy law. The law asks you to know which flows leave the province and why. Saying "we don't use anything American" when your invoices run through a US card network isn't just imprecise. It's the kind of detail that comes up if a regulator ever asks.

Here's the part people skip: what does that analysis actually involve? You list every vendor touching personal data, note the country each one processes or stores in, and write down why the transfer happens — billing, hosting, email, support. For a nine-person business, that's usually one page and an afternoon, not a legal engagement. The point isn't a perfect document. It's having something to hand over if you're ever asked why a customer's data crossed a border.

Is "Canadian AI" actually different, or is it marketing?

It's different, but you have to check the specific claim, not the label.

A Canadian AI platform means the company is Canadian, operates under Canadian jurisdiction, and isn't answerable to a foreign parent for how it handles your data. That's a real legal distinction, not a branding choice. Canadian AI tools built for Quebec's privacy law and the federal privacy law — called PIPEDA — also tend to handle consent language and retention rules the way Canadian regulators actually expect, because that's the market they were built for.

Where it becomes marketing: vendors that say "Canadian-hosted" while running on Amazon or Microsoft's US-controlled cloud infrastructure. Hosting location and legal jurisdiction are not the same thing. A server in Toronto owned by a company headquartered in Seattle is still, legally, reachable through that company's US ownership. Ask who owns the company, not just where the rack sits.

What should I actually ask a vendor before signing?

One list, because this is the part you'll actually use.

  • Does any part of your AI inference run on US-owned infrastructure, even temporarily?
  • Do you have a US corporate parent, or US investors with board or data-access rights?
  • Where exactly is customer data stored, and where is it processed — not "in the cloud," a country?
  • Is customer data ever used to train your models?
  • What happens to my data if you're acquired by a US company next year?

That last question gets skipped constantly, and it's the one that ages worst. Ownership changes. A Canadian AI tool bought by a US company tomorrow inherits US jurisdiction the day the deal closes, regardless of where the servers stay. If that happens, existing data doesn't retroactively become exempt just because it was collected earlier. The exposure applies going forward from the acquisition, which is exactly why the answer to this question is worth getting in writing now, while it costs nothing to ask.

What does this actually cost me?

Nothing, to start checking. Augure's free tier gives you 50 messages a day, five documents, and basic web search, with no card required. Paid tiers start at C$20 a month for unlimited messages, priority models, and persistent memory — Augure remembers context across sessions, which the free tier doesn't do. A C$80 a month tier adds deep research agents and 50MB uploads, and there's a custom enterprise tier with SSO and dedicated support for larger teams.

For law firms specifically, Augure Legal handles contract review, NDA triage, and Law 25 compliance checks, starting at C$149 a month for a solo practitioner. That's a narrower product for a narrower job, and it's priced like one.

Compare that against what a data breach involving US-jurisdiction exposure actually costs — legal review, client notification, reputational cleanup — and the monthly number stops looking like the expensive option.

What to do this week

Pull your current AI vendor's privacy policy and find the sub-processor list. If you can't find one in ten minutes, that's already an answer.

Ask your vendor the five questions above, in writing, and keep the reply. If they can't say clearly who owns the company and where inference runs, that's an answer too, just not the one you want.

Try a Canadian AI platform on something real this week, not a demo. Augure's free tier is built for exactly that: fifty messages a day, no card, no commitment. Start at augureai.ca.

Where this comes from: The US CLOUD Act allows compelled disclosure from US-controlled providers regardless of where data is stored. Quebec's privacy law requires businesses to assess transfers of personal data outside the province.

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started