Data Security and Privacy

How Conformii protects your compliance data and meets privacy requirements.

Our Security Approach

Conformii handles sensitive compliance and regulatory data for organizations in regulated industries. Security is a core design principle, not an afterthought.

Data Storage

All Conformii data is stored in Canadian data centres. For clients with specific data residency requirements, we can confirm the specific hosting region for your instance.

Encryption

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Evidence files and obligation records receive the same encryption treatment.

Access Controls

  • Role-based access controls ensure users only see what they need to
  • All access events are logged in the audit trail
  • Multi-factor authentication is available and can be enforced organization-wide by your Administrator
  • Session timeouts are configurable
  • Compliance and Certifications

    Conformii maintains SOC 2 Type II certification. Our security practices are reviewed annually by an independent auditor. Documentation is available to clients under NDA.

    Data Portability and Deletion

    You own your data. At any time, you can request a full export of your organization's data — obligations, evidence, audit logs and configuration — in standard formats. On subscription termination, data is retained for 90 days before deletion, giving you time to complete your export.

    Privacy

    Conformii collects only the data necessary to provide the service. User data is not sold or shared with third parties. Our full privacy policy is available at conformii.com/privacy.

    Need more help?

    Your Conformii client success manager is available to answer questions, walk through configuration and help you get the most from the platform.