Where we actually stand
No badges we have not earned. This page says what is in place today, what is in progress, and what is a target we hold ourselves to, so your security and privacy review can start from facts.
Compliance posture
Each line is the honest current state. Where something is not finished, it says so.
SOC 2
In placeControls in placeSOC 2 controls are implemented and operating. The Type II report is in progress and will be available under NDA when issued. We do not describe ourselves as “SOC 2 certified”, because that would not be true yet.
Penetration test
In placeCompleted and remediatedAn external penetration test has been completed. All critical and high findings have been remediated and re-tested; medium findings are triaged with a documented decision or fix date.
Law 25 & GDPR
In placeArtifacts publishedA Privacy Officer is designated, a privacy impact assessment is complete, and the data retention matrix is published. Breach notification to the CAI / OPC and affected individuals within 72 hours.
Data residency
In placeAt rest: Canada (ca-central-1)Learning records, course content, assessment responses, certificates and your user directory are at rest in Canada. Some processing happens outside it. Both are stated below, we would rather state them than let you discover them.
PCI DSS
In progressSAQ A / A-EP, determination pendingCard details are entered only into payment UI served by Stripe, hosted pages or embedded Stripe iframes, and never reach EmbayLMS servers. The formal QSA scope determination is pending.
Accessibility
TargetWCAG 2.2 AA targetWe build to WCAG 2.2 AA and test against it. We do not claim certified conformance, and our accessibility statement describes known gaps rather than hiding them.
Your learning data is hosted in Canada
Every piece of customer data we store is at rest in Canada, on AWS ca-central-1 (Montreal), encrypted with KMS: learning records, course content, assessment responses, certificates, uploads, your user directory and our backups. TLS 1.2+ in transit. AI inference, where enabled, runs in the same region. Nothing is stored anywhere else. Processing is a separate question, and we answer it below rather than leaving it to inference.
Where processing happens, stated plainly
Storage and processing are different things, and plenty of vendors let you assume they are the same. Ours are not, so here is the whole picture. Our application runs on Vercel, whose serverless functions are pinned to Montréal (yul1), so since August 2026 the web and API tier executes in Canada, and we verify the region on every deploy. Two processing exceptions remain. Our background job worker runs on Railway, which offers no Canadian region, and it handles user imports and report generation. Transactional email, sign-in, enrollment and reminder messages, is delivered through Resend in the United States, which sees a recipient address and sometimes a first name. In both cases the data is stored in Canada and returns to Canada; what crosses the border is processing, not storage. An unqualified “all your data stays in Canada” would still overstate it, so we do not say it.
Reliability targets
These are the service objectives we hold ourselves to and design against.
99.9%
Availability
< 500 ms
Page load (p95)
< 250 ms
SCORM commit (p95)
within 72 hours
Breach notification
These are objectives, not a published historical record, we do not yet operate a public status page, and we would rather say so than imply a track record we are not showing you.
Documents and requests
Everything below is available without talking to anyone first.
Looking for the detail?
The security page covers tenant isolation, access control, audit logging and the rest of the control narrative.
Read about security →