Trust & Compliance

Your books. Your data.
Your rules.

We build financial software, which means we hold the most sensitive information a business has. Here is exactly how we protect it — and what we will and won't claim.

Stored in Canada
Montréal region — your data does not leave the country
Yours to take
Complete export of every record, any time, no negotiation
Indigenous-owned
Built in Conklin, Alberta — and OCAP®-aligned by design

What we hold ourselves to

PI-ATAWI Investment Enterprise is an Indigenous-owned Canadian software company. Every product we build — PI-ATAWI ONE, our client portals, and every web application we deliver — is held to the standard below from the first line of code, not patched on afterward.

This page separates three different things on purpose: laws we comply with today, principles we design by, and independent assurance we are working toward. Where something is not yet earned, it is marked as planned — and it stays marked until it is real.

Where your data lives

In place

All customer data is stored and processed in Canada, in the AWS Montréal region (ca-central-1). We do not move Canadian data to foreign jurisdictions for processing.

Data sovereignty and OCAP®

In place

We design in alignment with the OCAP® principles — ownership, control, access, and possession — established by the First Nations Information Governance Centre.

In our products that means your organization owns its data, controls who sees it, can access all of it, and can take possession of it: a complete export of every record you have ever entered, in open formats, available to you at any time. No request process. No negotiation.

OCAP® is a registered trademark of the First Nations Information Governance Centre.

Privacy

In place

We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Personal Information Protection Act (PIPA), including their breach-reporting requirements, and we design to meet Quebec's Law 25 obligations where they apply.

Our Privacy Policy sets out what we collect, why we collect it, and the rights you hold over it.

Payment security (PCI DSS)

In place

Card data never touches PI-ATAWI systems. All card payments happen on the hosted, PCI DSS–certified pages of our payment processor. PI-ATAWI maintains PCI DSS compliance for its own role under Self-Assessment Questionnaire A — the standard for businesses whose payment pages are fully hosted by a certified provider.

We will never build a form, a log, or a database table that stores a card number. Our software refuses card numbers even when one is typed into a free-text field.

Anti-spam (CASL)

In place

Compliance with Canada's Anti-Spam Legislation is enforced by our software itself, not left to user discipline. Every recipient of a commercial message is checked for a lawful consent basis at the moment of sending, refusals are recorded rather than silently skipped, unsubscribes take effect immediately and permanently, and proof of consent — including double opt-in timestamps — is retained.

Financial record integrity

In place

Our accounting products are built on a principle borrowed from paper ledgers: nothing financial is ever erased. Corrections are made by traceable reversal, every change is written to a permanent audit log, and posted records are immutable.

That design supports the Canada Revenue Agency's expectation that books and records be kept and remain intact for six years.

Security architecture

In place

Multi-factor authentication. Access control enforced at the database layer, not only in the application — so a flaw in the interface cannot expose another organization's records. Encryption in transit and at rest. Banking details and secrets sealed in an encrypted vault with every access audited. Independent security review of every code change before it ships.

Independent assurance

On our roadmap

We believe claims should be verifiable by someone other than us. A SOC 2 examination by an independent CPA firm is on our roadmap, and our systems, controls, and evidence are built to its Trust Services Criteria today.

When our SOC 2 report is issued, it will be available to customers under NDA and this page will say so. Until then, we will not claim it.

What we don't claim

Our software is built to help you meet your own obligations — enforcing consent under CASL, keeping records to the standard the CRA expects, and protecting the personal information you hold. But your compliance program remains yours. What we provide is the enforcement machinery and the evidence trail to stand behind it.

We will also never market a certification we have not earned. Where this page says a standard is on our roadmap, it stays that way until an independent examiner says otherwise.

Software you can put your books in.

Built in Canada, hosted in Canada, and designed so your data stays yours.

Get in Touch