Privacy and security
What TrustChain holds
Compliance documents belonging to your clients — permits, certificates, invoices, bills of lading — together with the structured data extracted from them, and the record of who uploaded, verified, viewed and deleted each one.
Where your data lives
| What | Where | Provider |
|---|---|---|
| Documents and database | Canada — AWS Canada Central (ca-central-1) | Supabase |
| Weekly backups | Cloudflare R2 | Cloudflare |
| Website and application | Global CDN | Netlify |
| AI extraction (in transit only) | United States | Anthropic |
Your documents and database are stored in Canada.
Two things are not, and we would rather you heard them from us. AI extraction happens in the United States — an uploaded document is transmitted to Anthropic's API, read, and the extracted fields returned. It is not retained there, and the document itself is stored only in Canada, but it does cross the border to be read. Backups sit in Cloudflare R2, which offers North American location hints rather than a Canada-specific guarantee.
So the accurate statement is "stored in Canada, with AI processing in the United States" — not "your data never leaves Canada." We won't make the stronger claim, because it isn't true.
Canadian privacy law (PIPEDA) permits transferring personal information outside Canada provided comparable protection is maintained, and requires that you be told. This section is that notice. If a contract of yours requires that no personal information leave Canada under any circumstances, the AI extraction step would need addressing first — please raise it before onboarding rather than after.
How your data is protected
Separation between brokerages
Every record carries the brokerage that owns it, and access is enforced by database-level Row Level Security — not by application code that could be bypassed. Stored files are filed under brokerage / client / document, and the storage rules check that path on every read. One brokerage cannot reach another's data even by crafting a direct request.
Encryption
Data is encrypted in transit (TLS) and at rest by our infrastructure providers.
Original documents are private
Uploaded files are not publicly addressable. Viewing one issues a signed link that expires within minutes.
Access control and two-factor authentication
Accounts are scoped by role — platform operator, brokerage administrator, and optionally your own clients with access only to their own documents. Two-factor authentication is available to every account and, where enabled, is enforced at the database rather than in the browser: a compromised password alone will not read your records even if the application interface is bypassed entirely.
Audit trail
Document creation, verification and deletion are recorded with the person responsible and the time. Privileged actions such as plan changes, account creation and suspensions are logged separately in a record that ordinary accounts cannot read or alter.
Backups
Database tables and stored files are copied daily to separate infrastructure under a different provider, so a failure at the primary provider does not take the backups with it. That means at most a day's activity is ever without an independent copy. This matters more than it might sound: our provider's own backups cover the database but exclude stored files, so this is the only thing standing behind your original documents.
Independent security review
TrustChain has undergone a documented adversarial and OWASP/STRIDE security assessment. Every finding was remediated and verified in production. A summary is available on request.
Artificial intelligence
TrustChain uses Anthropic's Claude models to read uploaded documents and pre-fill fields.
Your documents are not used to train AI models. TrustChain accesses Claude through Anthropic's commercial API, which is governed by Anthropic's Commercial Terms of Service — these state that Anthropic does not train models on customer content submitted through it.
The AI never makes a compliance decision. It reads a document and suggests values. A person at your brokerage reviews and confirms every record before it is saved. Extracted output is restricted to a fixed set of known fields — anything else the model returns is discarded rather than stored.
The AI sometimes declines to read a document. When that happens the platform tells you, and you enter the fields manually. Nothing is lost.
Sub-processors
Companies that process data on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, document storage | Canada (AWS ca-central-1) |
| Cloudflare | API layer, DNS, backup storage, email routing | Global |
| Anthropic | AI document extraction | USA |
| Netlify | Website and application hosting | Global CDN |
| Resend | Outbound email (invitations, expiry reminders) | USA |
We will give reasonable notice before adding a sub-processor that handles customer content.
What we do not have
Stated directly, because you would find out anyway and it is better heard from us.
- No SOC 2 or ISO 27001 certification. Our infrastructure providers hold those certifications; TrustChain itself does not. These are not the same thing and we will not imply otherwise.
- No penetration test by a third party. The security assessment was thorough and documented, but it was not an external certified engagement.
- No 24/7 support or contractual uptime guarantee. TrustChain is operated by a small team. Support is best-effort during business hours.
- No self-serve data deletion. Deleting your data is a request we action manually, not a button.
- Limited automated alerting. We are alerted automatically if backups stop running or if the platform becomes unreachable. We are not alerted on unusual account activity — that is reviewed on a schedule, not watched continuously. In practice a customer may notice something before we do, which is why we would rather you called us early than waited to be sure.
Your data is yours
You can export it at any time, in full, including the original documents — not just the extracted fields. The audit package produces an index plus every stored file.
If you leave, you keep access to export for the period set out in our Terms of Service. Your records are not deleted automatically at the end of that window.
Retention obligations remain yours. CBSA record-keeping duties sit with the importer of record. TrustChain helps you meet them; it does not assume them.
Incidents
We have a written incident-response procedure. It covers what counts as a breach, how we contain one in the first hour, how we assess whether it must be reported, who we notify and in what order, and how we record it. A copy is available on request.
If we become aware of a breach of security safeguards involving your data, we will tell you promptly — with what we know, what is affected, and what we are doing about it. We would rather contact you while we are still investigating than wait until we have a tidy answer.
Where the law requires it, we will report to the Office of the Privacy Commissioner of Canada and notify affected individuals, as soon as feasible. We keep a record of every breach for 24 months, including those that do not meet the reporting threshold — that is a legal obligation under PIPEDA and we treat it as one.
If a breach affects your clients, you may have your own notification duties that depend on our timeline. We will tell you everything we know about what of yours was involved, so you can meet them.
Questions
Email support-trustchain@biruer.com. If you are evaluating TrustChain and need detail beyond this page — the security assessment summary, or specifics on any of the above — ask, and you'll get a direct answer rather than a brochure.