Security & Compliance
Your organization handles sensitive employee data. We built Pryvera with security as the foundation, not an afterthought.
Trust Service Criteria: Security, Availability, Confidentiality, Privacy
Personal Health Information Protection Act (Ontario)
Personal Information Protection and Electronic Documents Act (Canada)
SIN and banking data encrypted with bank-grade encryption before database storage. TLS 1.2+ enforced for all data in transit. Database connections use SSL.
Every organization gets a completely separate PostgreSQL database. No shared tables. Your data is physically isolated from all other tenants.
All data hosted exclusively in AWS ca-central-1 (Montreal). No data ever leaves Canadian borders. Backups stored in Canada.
9 granular roles with deny-by-default authorization. Every API route secured. Permission checked on every request. Audit logged.
Azure AD SSO with MFA or built-in TOTP (Authy, Google Authenticator compatible). Account lockout after 5 failed attempts.
Every create, update, and delete operation logged with user, timestamp, and IP. Security events tracked separately. 7-year retention.
Documented incident response plan. Account disable and session revocation in seconds. 72-hour breach notification per PHIPA.
HSTS, Content Security Policy, X-Frame-Options, rate limiting (100/min standard, 10/min strict), CSRF protection on all mutations.
We provide complete security documentation to support your procurement process.