Security and data protection

Encryption by default, strict access controls, and no training on customer data. Documentation available for procurement review.

Law 25 · Quebec privacyPIPEDA · Federal privacySOC 2 · Provider stackISO 27001 · Provider stack

Encrypted by default

TLS 1.3 in transit, AES-256 at rest. Industry-standard encryption everywhere data lives.

No training on customer data

Your prompts, documents, and outputs are never used to train or fine-tune any model — ours or anyone else's.

Access controls included

Role-based access, audit logging, and session controls come standard on every plan.

How your data is protected

Encryption

  • TLS 1.3 between your browser and our servers.
  • AES-256 across all stored data.
  • Key management with industry-standard rotation and access controls.

Access controls

  • Secure session management with encrypted tokens.
  • Role-based access controls for Knowledge document management.
  • Audit logging for administrative actions and data access events.
  • Automatic logout after inactivity.

Data handling

  • Customer data is stored on infrastructure in Canada.
  • Model providers operate under zero-data-retention agreements — prompts are not retained after processing.
  • Customer data is fully separated from model training pipelines.
Sub-processors are listed in our privacy policy

Compliance

  • Designed to support Law 25 and PIPEDA obligations.
  • Infrastructure providers hold SOC 2 and ISO 27001 certifications.
  • Security documentation available for procurement review.

We can't make your organization compliant on our own — that depends on your full security posture. Our job is to make sure AI tooling isn't the gap.

Responsible disclosure

If you believe you've found a security vulnerability in an Augure product, we want to hear about it. Email hello@augureai.ca with the details and we'll follow up.

Questions from your security team?

We share security questionnaires, architecture documentation, and audit artefacts on request.