Skip to content
Security & privacy

How we protect your people and data

You are evaluating a tool that will touch employee mailboxes and behaviour data. Here is what to expect — plain language for security and privacy stakeholders.

What we never do

No real password capture. Dry-run before live send. Tenant isolation. Admin audit trail.

Where data lives

Canada-oriented residency design. Subprocessors published. Architecture shared for reviews.

Canadian privacy

You remain controller/custodian. We are processor under contract — purpose-limited, with breach notice and deletion.

Attestation honesty

SOC 2 / ISO readiness trackers — never certificates we do not hold. Full security package on request.

Canadian privacy

If you are a public body, you remain the custodian under provincial privacy law. PhishGuard acts as your service provider: purpose-limited use, safeguards, breach notice, and deletion at end of relationship. Commercial customers: PIPEDA-aligned practices. Québec: Law 25 addressed in onboarding.

Full detail: Privacy Policy · Subprocessors

Attestation status

We track readiness against Chiaro (SOC 2 control library), ISO 27001:2022, and ISO 27701. We never claim a report or certificate we do not hold.

Demo vs. pilot

The public demo uses sample data — no Google Workspace connection. A paid pilot connects your tenant under agreement, with seat count and success criteria you choose. See Terms · Pilot offer.