Trust pack for vendor review
Trust pack for vendor review
If your brokerage, firm, or practice runs a vendor review before approving new software, this page collects the answers in the order the questionnaire usually asks for them.
The trust centre is the source of truth. If anything here disagrees with it, the trust centre wins — and please tell us so we can fix this page.
Data residency
Customer data is stored on servers hosted in Canada. Backups are kept in the same jurisdiction. There is no routine replication of customer data outside the country.
Encryption
- At rest: AES-256-GCM. Sensitive fields are encrypted in the database.
- In transit: TLS 1.2+ for every request between the browser, the API, and internal services.
- Passwords: hashed with bcrypt; never stored in plain text and never visible to operators.
- Two-factor secrets: TOTP shared secrets are encrypted at rest with the same AES-256-GCM scheme.
Authentication controls available to your staff
- Password with TOTP two-factor authentication.
- Passkeys (WebAuthn) — phishing-resistant, with the private key never leaving the device. A passkey is bound to a single domain, so staff who use both
hivi-x.caandmy-id.caregister one on each. - Optional "Sign in with Google".
AI processing
All AI that touches customer data — extraction, search, form mapping, transcription — runs on infrastructure hivi-x operates. Customer data is not sent to OpenAI, Google, Anthropic, or any other third-party AI provider.
Every AI-suggested value is presented as a draft for a human to review before it is saved or sent.
Sub-processors
The current list is published on the trust centre and is short by design:
| Provider | Purpose | What is shared |
|---|---|---|
| Stripe | Payments and subscriptions | Billing email, customer ID, subscription status. Card data goes to Stripe directly and is never stored by hivi-x. |
| Google (OAuth) | Optional "Sign in with Google" | Only when a user chooses Google sign-in: an OAuth handshake, account identifier, and email. |
| Email provider | Transactional email | Recipient address and message body. Profile fields are not included in notification emails. |
None of these are used for AI inference. The trust centre is updated when the list changes, and we will email you directly on request.
Data processing agreement
A DPA is available on request. Email the privacy address listed on the trust centre and include the legal name of the contracting entity.
Privacy law position
- Practices are designed against PIPEDA. hivi-x does not claim a PIPEDA certification — no standard certification of that kind exists.
- Access, correction, export, and deletion rights under PIPEDA, Quebec Law 25, and GDPR are exercised through Data Requests.
- hivi-x does not hold a SOC 2 report, or a third-party attestation against HIPAA, PHIPA, or GDPR. If your review requires one, say so early — we will tell you plainly what we can and cannot sign rather than let a procurement cycle run on a false assumption.
Retention and deletion
- Data is retained while the account is active.
- Account deletion removes profile data, uploaded files, and templates from active databases.
- Encrypted backups containing deleted records are rotated out within 30 days.
- Stripe retains billing records on its side as required by tax and payment regulation.
A subscription lapsing is not a deletion event: if a trial ends or a plan is cancelled, client files, checklists, and uploads are retained — access to the workspace is what pauses. See Business trial and billing.
Incident notification
- Affected users are notified by email within 72 hours of confirming an incident.
- A public post-mortem is published on the trust centre.
- Incidents meeting PIPEDA's "real risk of significant harm" threshold are reported to the Office of the Privacy Commissioner of Canada.
Incident history to date is published on the trust centre.
Client-side access
Clients of your business do not need an account to send you documents. A guest link is scoped to one client of one business, verified with an emailed one-time code, and expires. See Send your first guest link for what the client experience looks like and what the link does and does not expose.
Related
- Trust centre — the source of truth for every claim above
- Privacy Policy
- Business Terms
- Data Requests
Answers are general operational information only — not legal, tax, regulatory, clinical, privacy, immigration, or professional advice. Requirements vary by matter, client, and regulator.
Frequently asked questions
- Where is hivi-x customer data hosted?
- In Canada. Application data and backups stay in the same jurisdiction, with no routine replication outside the country.
- Does hivi-x send client documents to third-party AI providers?
- No. All AI extraction, search, and form mapping runs on infrastructure hivi-x operates. Customer data is not sent to OpenAI, Google, Anthropic, or any other third-party AI provider.
- Is a data processing agreement available?
- Yes, on request. Email the privacy address on the trust centre with the name of the contracting entity.
- Does hivi-x have SOC 2?
- No. hivi-x does not hold a SOC 2 report, and does not hold a third-party attestation against PIPEDA, PHIPA, GDPR, or HIPAA. We will answer a questionnaire honestly rather than imply a certification we do not have.
- How quickly are security incidents disclosed?
- Affected users are notified by email within 72 hours of confirming an incident, and incidents meeting PIPEDA's real-risk-of-significant-harm threshold are reported to the Office of the Privacy Commissioner of Canada.
Organize client document intake with checklists
hivi-x helps Ontario professionals collect client documents with reusable checklists, secure Canadian hosting, and exportable PDF packages.