CPCSC and AI Tools: Which Ones Pass Security Review
Defence suppliers need CPCSC compliance and AI that won't fail security review. Here's how Canadian AI tools clear both hurdles without slowing procurement.
If you supply the Department of National Defence, you need CPCSC — the Canadian Program for Cyber Security Certification. That much you already know. What you're really asking is narrower: can you use AI tools without failing your security review, and which ones won't get flagged. The short answer is yes, but the tool you pick matters more than most procurement teams realize.
CPCSC is Canada's answer to CMMC, the US defence cybersecurity standard. It exists because Canada needed its own certification scheme instead of leaning on an American one indefinitely. If you're a supplier or subcontractor touching defence data, you need to show your security controls hold up — and that includes any software touching that data, AI included.
Why does AI keep failing security review?
Three reasons, and they repeat across almost every review file.
The first is legal reach. If your AI vendor is a US company, US law can reach your data even when it sits on a server in Toronto. That's the CLOUD Act, and reviewers know to ask about it.
The second is model origin. Some AI tools run on models built or hosted in China or by companies with unclear ownership structures. That's an automatic red flag in a defence context, full stop.
The third is plain data handling. Where does your prompt go? Who can read it? Does the vendor train future models on your conversations? Reviewers ask these questions because CPCSC assessors ask them too, and a vague answer costs you time.
None of these three problems are exotic. They come up in almost every AI procurement conversation involving a regulated Canadian organization, whether it's a hospital, a law firm, or a company building parts for a submarine.
What does "Canadian AI" actually mean here?
It means the company runs under Canadian law, not American law with a Canadian sales office. A genuinely Canadian AI platform has no US parent company and no US investors sitting above it in the ownership chain. That distinction is not cosmetic. It determines which government's laws can compel access to your data.
Augure is one example. It's a Canadian company, built for Canadian regulatory requirements including Quebec's privacy law and the federal privacy law, PIPEDA. Augure has no US corporate parent and no US investors. Customer conversations, documents, and AI inference are never handled by US-jurisdiction providers, so the CLOUD Act's reach over US-controlled providers doesn't extend to that customer content. That's a scoped, specific claim, not a blanket promise that nothing anywhere touches anything American.
Here's the honest version of where the data goes: inference runs on Canadian infrastructure for some model tiers, and with vetted EU partners under zero-data-retention agreements for others, including failover. Payment processing and email delivery involve limited US processing, because that's how card networks and email work almost everywhere. All of it is documented in the privacy policy, not buried in it.
A defence supplier's AI vendor should be able to name every country their data touches, in one sentence, without a lawyer in the room.
If your current AI vendor can't do that, that's the review failure waiting to happen.
Will a Canadian AI platform slow down my CPCSC certification?
It should speed it up, if anything. Reviewers spend less time chasing down foreign subprocessors when the answer is simple: Canadian company, Canadian jurisdiction, documented EU inference for specific tiers, no US ownership anywhere in the chain.
Compare that to explaining a US-headquartered AI vendor's data flows to a CPCSC assessor. You'll need subprocessor lists, data flow diagrams, and probably a call with the vendor's legal team. That's weeks, not days.
A Canadian AI platform doesn't guarantee you pass CPCSC. No vendor can promise that — certification covers your whole security program, not one tool. But it removes one of the three common failure points before the assessor even asks the question.
What does this cost?
Augure's free plan gives you 50 messages a day, five documents, and basic web search — C$0. That's enough to test whether it fits your workflow.
The Pro plan is C$20 a month per user. No message limits, a generous compute allowance, 100 documents, and persistent memory, meaning Augure remembers context across conversations instead of starting fresh every time. For a nine-person shop handling proposals and technical documents, this is usually the right tier.
Max runs C$80 a month and adds deep research agents and four times the compute. Larger suppliers with review workflows or dedicated compliance staff tend to land here. Enterprise pricing is custom and includes single sign-on and dedicated support, which larger primes often require anyway.
None of these numbers are trying to compete with what a US AI subscription costs. They're trying to answer a different question: what does it cost to remove a legal-reach problem from your next security review.
Do I still need my own security controls?
Yes. This is the part that's easy to skip past. CPCSC certifies your organization: your access controls, your incident response plan, your employee training, your network segmentation. An AI tool is one input into that picture, not a replacement for it.
Using a Canadian AI platform takes one recurring objection off the table. It does not touch the other forty items on your CPCSC checklist. If your password policy is weak or your staff share credentials over email, no vendor choice fixes that.
What it does do is stop a reviewer from spending an afternoon asking where your chat logs live.
What to do this week
- Pull your current AI tool's data policy and check one thing: does it name a US parent company or US-based hosting for the AI processing itself, not just the website.
- List every AI tool your team actually uses day to day, including the ones nobody officially approved. Shadow AI use is a common finding in CPCSC gap assessments.
- Test a Canadian AI tool on one real task this week, not a demo scenario. See if it holds up before your next procurement conversation forces the question.
Augure is Canadian, and it starts free. If your team is heading into a CPCSC review this year, look at augureai.ca and see whether it fits before your assessor asks the question first.
Where this comes from: CPCSC requirements are published by Public Services and Procurement Canada; the CLOUD Act is US federal law governing data held by US-jurisdiction providers.
About Augure
Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.
More insights
View all →Municipal governments and AI: FIPPA-compliant adoption
Can you use AI in a Canadian clinic without breaking PHIPA?
Exam integrity in the AI era: How Canadian schools are responding
Put this to work: Augure for regulated organizations →