Security and compliance

What we have designed, what exists today, and what we do not have yet. Crediteris is new, and a security reviewer should know exactly where it stands.

How to read this page

Unless a section says otherwise, it describes the platform as designed. Crediteris is in development and is not yet used by any client, so none of these controls has an operating record.

Independent assurance

Crediteris holds no security certification and has had no independent audit. The table below will change as each item is scheduled and completed. We will not describe an audit as done until the report exists.

Certifications and independent tests
ItemStatusNotes
SOC 2 Type II reportNot heldA Type II report covers a period of operation. Crediteris has no operating history yet.
ISO/IEC 27001 certificationNot held
Third-party penetration testNot yet performed
Independent WCAG 2.1 AA audit of the platformNot yet performedSee accessibility below for what has been done.

Where data lives

Client data will be stored and processed in Canada only. The production design uses Microsoft Azure's two Canadian regions, which are more than 700 km apart.

Planned production hosting
ComponentPrimarySecondary
ApplicationAzure Container Apps, Canada Central (Toronto)Canada East (Québec City)
DatabaseAzure Database for PostgreSQL, Canada CentralReplica and geo-backup, Canada East
Files: course media, certificates, exportsAzure Blob Storage, Canada CentralReplicated to Canada East
Encryption keys and secretsAzure Key Vault, Canada Central

Status: designed. This is the production architecture. It is not yet in client use.

A few facts that a residency review will want stated plainly:

  • Microsoft is a US company. The data sits in Canadian regions, but the provider is incorporated in the United States, as is every large cloud provider that operates in Canada.
  • Edge network. We plan to put Cloudflare in front of the application for DDoS protection and a web application firewall, set so that TLS is decrypted only in Cloudflare data centres located in Canada. Cloudflare stores no client data in this design, but it does see traffic in the clear at the edge, and Cloudflare, Inc. is a US company. A client who prefers can have Azure Front Door and Azure's firewall, both in Canada, instead.
  • Demonstration environments contain only synthetic data and may run outside Canada. No client data is ever placed in them.
  • Source code is hosted on GitHub, a US service. It contains no client data.
  • Sub-processors. The full list, including email delivery, is not final. We will publish it on this page before the platform goes into client use.

Encryption

  • In transit: TLS 1.2 or higher, with TLS 1.3 preferred.
  • At rest: AES-256 for the database, file storage and backups.
  • A client can hold its own encryption keys in Azure Key Vault, and rotate or revoke them.

Sign-in and access

  • Single sign-on with SAML 2.0 or OpenID Connect. Groups from your identity provider map to Crediteris roles.
  • Multi-factor authentication for any account that does not use single sign-on.
  • Four roles: learner, observer, administrator and super administrator. Observers are read-only by design: they cannot create, edit, annotate, download or administer anything.
  • Idle sessions end automatically. Access can be restricted to your institution's IP addresses.

Audit trail and records

  • An append-only security log records sign-ins, failed sign-ins, denied access and administrative changes: who, what, when and from where. It can be exported to your SIEM and is kept for the life of the contract.
  • Learning records keep timestamps, every assessment attempt, completions and the version of the content each learner saw, so any past result can be traced to what was actually presented.
  • Records are kept for at least three years, then disposed of securely under a documented retention policy.

Your data is yours

Learning records, results, certificates and learner data belong to the client. You can export them at any time, and in full at the end of a contract, in standard formats another system can import. We do not use client data for analytics, benchmarking or product development without your written permission, and we never use it to train AI models.

Backup and recovery

  • Recovery point: no more than 24 hours of data at risk, with a design target of five minutes.
  • Recovery time: service restored within 24 hours, with a design target of four hours.
  • Restores are tested every quarter, and the result is recorded.
  • Availability: at least 98.5%, from 07:00 to 19:00 in every Canadian time zone.

Status: designed. These are commitments we will contract to. There is no operating record to show against them yet.

What Crediteris never handles

Crediteris is a training system. It does not connect to lending systems, it holds no real borrower files and it makes no credit decisions. Case data is fictional. Free-text fields warn learners not to enter client information, and flag text that looks like a name, business number or account number. That keeps the most sensitive category of banking data out of the platform entirely.

AI

AI features are off by default, and every part of Crediteris works without them. When a client turns one on, it sees only fictional case content and the learner's answer. Client data is never used to train or improve any AI model. Before any AI feature can be enabled we will name the model and the sub-processor behind it. See the product page for what the AI features do.

Accessibility

The platform is specified to meet WCAG 2.1 level AA. Its design system sets out computed colour contrast for every text pair, keyboard access, visible focus, screen reader behaviour, reflow at 320 pixels and Windows high-contrast support. Testing is planned with NVDA, JAWS and VoiceOver. An independent audit, with a published conformance report, has not been done yet.

This website is built to WCAG 2.1 AA. Every page, in both languages, is checked with the axe-core automated tool at desktop and narrow widths, and by keyboard. Automated tools find only some problems, and this site has not been audited independently.

If something on this site or in Crediteris does not work for you, write to hello@crediteris.com in French or English.