We build financial software, which means we hold the most sensitive information a business has. Here is exactly how we protect it — and what we will and won't claim.
PI-ATAWI Investment Enterprise is an Indigenous-owned Canadian software company. Every product we build — PI-ATAWI ONE, our client portals, and every web application we deliver — is held to the standard below from the first line of code, not patched on afterward.
This page separates three different things on purpose: laws we comply with today, principles we design by, and independent assurance we are working toward. Where something is not yet earned, it is marked as planned — and it stays marked until it is real.
All customer data is stored and processed in Canada, in the AWS Montréal region (ca-central-1). We do not move Canadian data to foreign jurisdictions for processing.
We design in alignment with the OCAP® principles — ownership, control, access, and possession — established by the First Nations Information Governance Centre.
In our products that means your organization owns its data, controls who sees it, can access all of it, and can take possession of it: a complete export of every record you have ever entered, in open formats, available to you at any time. No request process. No negotiation.
OCAP® is a registered trademark of the First Nations Information Governance Centre.
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Personal Information Protection Act (PIPA), including their breach-reporting requirements, and we design to meet Quebec's Law 25 obligations where they apply.
Our Privacy Policy sets out what we collect, why we collect it, and the rights you hold over it.
Card data never touches PI-ATAWI systems. All card payments happen on the hosted, PCI DSS–certified pages of our payment processor. PI-ATAWI maintains PCI DSS compliance for its own role under Self-Assessment Questionnaire A — the standard for businesses whose payment pages are fully hosted by a certified provider.
We will never build a form, a log, or a database table that stores a card number. Our software refuses card numbers even when one is typed into a free-text field.
Compliance with Canada's Anti-Spam Legislation is enforced by our software itself, not left to user discipline. Every recipient of a commercial message is checked for a lawful consent basis at the moment of sending, refusals are recorded rather than silently skipped, unsubscribes take effect immediately and permanently, and proof of consent — including double opt-in timestamps — is retained.
Our accounting products are built on a principle borrowed from paper ledgers: nothing financial is ever erased. Corrections are made by traceable reversal, every change is written to a permanent audit log, and posted records are immutable.
That design supports the Canada Revenue Agency's expectation that books and records be kept and remain intact for six years.
Multi-factor authentication. Access control enforced at the database layer, not only in the application — so a flaw in the interface cannot expose another organization's records. Encryption in transit and at rest. Banking details and secrets sealed in an encrypted vault with every access audited. Independent security review of every code change before it ships.
We believe claims should be verifiable by someone other than us. A SOC 2 examination by an independent CPA firm is on our roadmap, and our systems, controls, and evidence are built to its Trust Services Criteria today.
When our SOC 2 report is issued, it will be available to customers under NDA and this page will say so. Until then, we will not claim it.
Our software is built to help you meet your own obligations — enforcing consent under CASL, keeping records to the standard the CRA expects, and protecting the personal information you hold. But your compliance program remains yours. What we provide is the enforcement machinery and the evidence trail to stand behind it.
We will also never market a certification we have not earned. Where this page says a standard is on our roadmap, it stays that way until an independent examiner says otherwise.
Built in Canada, hosted in Canada, and designed so your data stays yours.