← Home

Security & Compliance

Building Passport Trust Center - Enterprise-grade security for your portfolio data.

SOC 2 Readiness

Building Passport follows SOC 2 Type II readiness practices. Our controls are designed around the Trust Services Criteria for Security, Availability, and Confidentiality. Formal certification is planned as part of our enterprise roadmap. We engage with independent assessors to validate our control environment.

Data Processing Agreement (DPA)

A standard Data Processing Agreement is available on request. The DPA covers: scope and nature of processing, data categories, data subject categories, technical and organizational measures, subprocessor engagement, data breach notification, data deletion and return procedures.

Contact security@nanosealnb.ca to request a signed DPA.

Subprocessors

Building Passport uses the following subprocessors:

SubprocessorLocationPurpose
Sherlock HostingCanada (ca-central-1)Infrastructure hosting
VercelUS / GlobalCDN
ResendCanada / USEmail delivery
GitHubUSSource control

Incident Response

Our incident response procedure follows NIST SP 800-61 guidelines:

  1. Preparation - Documented playbooks, trained responders, and tooling in place before incidents occur.
  2. Detection & Analysis - Continuous monitoring and alerting to identify and validate security events.
  3. Containment & Eradication - Immediate isolation of affected systems and removal of threats.
  4. Recovery - Restoration of services from verified clean backups with validation.
  5. Post-Incident Review - Root cause analysis, lessons learned, and control improvements.

Notified customers will receive an initial incident notification within 24 hours of confirmed severity.

Data Retention Policy

Customer data is retained for the duration of the active contract plus 90 days. After termination:

  • Data export available during notice period
  • Secure deletion within 90 days of contract end
  • Backups retained for 7 days post-deletion
  • Anonymized/de-identified data may be retained for product improvement

Encryption

Data is encrypted at rest using AES-256 (PostgreSQL) and in transit using TLS 1.3. API communications require mutual TLS where supported.

Data Ownership

Customer owns their uploaded data. Self-service export available at any time. No customer data is shared with other tenants.

Audit Trail

All data mutations are logged with timestamp, actor, action, and affected records. Audit logs are retained for 12 months.

Backup Policy

Automated daily database backups with 7-day retention. Point-in-time recovery capability. Backups stored in the same Canadian region (ca-central-1).

Uptime SLA

Target 99.9% API uptime for production. Monitoring via Sherlock health checks. Incident communication via status page (coming soon).

Contact

Security: security@nanosealnb.ca | Privacy: privacy@nanosealnb.ca | DPA: dpa@nanosealnb.ca

Privacy

NanoSeal NB does not sell personal information. Customer data is never exposed to other tenants. For complete details on data collection, use, retention, and your rights, see the full Privacy Policy.