Data sovereignty is built into how Candidly AI works, not added on top. Your stakeholders' data stays within your borders, processed on infrastructure we host ourselves with zero third-party AI API dependencies. Use this Trust Centre to review our security posture, compliance, and privacy practices, and to request our security documentation.
Risk Profile
Risk Profile
We have secure, reliable hosting that customers can depend on. We are happy to provide details about our risk mitigation practices and recovery objectives upon request.
Product Security
Product Security
We pay great attention to enterprise features such as access control and single sign on. We are happy to provide more details about our enterprise features upon request.
Reports
Reports
We may provide security-related reports upon request.
Self-Assessments
Self-Assessments
We are working on our security compliance. We can provide completed questionnaires upon request.
Data Security
Data Security
Customer and stakeholder data is encrypted in transit and at rest. Access to production data follows least privilege and is logged and reviewed. All data is processed and stored on self-hosted infrastructure.
AI
AI
Candidly AI runs all AI processing on infrastructure we host ourselves, with zero third-party AI API dependencies. We do not use customer or stakeholder data to train third-party AI models. Conversation data is processed in region and is never sent to an outside model.
ESG
ESG
We prioritize and take environmental, social, and governance (ESG) considerations seriously in our operations and decision-making processes.
Data Privacy
Data Privacy
Candidly AI's privacy practices are aligned with PIPEDA and PIPA. We process personal information only as needed to deliver the service. Our subprocessor list is available on request, and customers can exercise data-subject rights at any time.
Access Control
Access Control
Access to systems and data is granted on a least-privilege basis and protected with multi-factor authentication. Access rights are reviewed on a regular schedule and revoked promptly when no longer required. Privileged credentials are rotated on a defined cycle.
Infrastructure
Infrastructure
Candidly AI runs on infrastructure we host ourselves, with in-region data residency so your stakeholders' data stays within your borders. All AI processing runs on our own infrastructure with zero third-party AI API dependencies. Our current footprint is monitored continuously for availability and security, and we add in-region residency as we expand.
Endpoint Security
Endpoint Security
Company devices are encrypted, kept up to date, and configured to our security standards. Endpoint posture is reviewed as part of our control program.
Network Security
Network Security
Our network is protected by a web application firewall and continuous intrusion detection. Traffic is monitored and filtered, and security events are logged and triaged. Network controls are tested as part of our ongoing compliance program.
Corporate Security
Corporate Security
We maintain a documented set of security policies governing how we operate. Personnel complete security awareness training, and vendors are assessed for security and privacy before onboarding. Practices are reinforced through internal review.
Policies
Policies
Our security and privacy policies are reviewed and approved on a regular cycle. Summaries are available here, and full policy documents can be requested under NDA.
Security Grades
Security Grades
We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.
Incident Response
Incident Response
We maintain a documented incident response plan with defined roles, escalation paths, and notification procedures. Affected customers are notified in line with our contractual and legal obligations.
Risk Management
Risk Management
We have a dedicated team that manages security risks. We are happy to provide more details about our risk management practices upon request.
Asset Management
Asset Management
We have strict asset management policies in place to ensure that all assets are accounted for and secure.
BC/DR
BC/DR
We have a business continuity plan in place to ensure that we can continue to operate in the event of a disaster.
Training
Training
We provide security awareness training to all employees to ensure that they are aware of security best practices.
Change Management
Change Management
We have a change and configuration management process in place to ensure that changes are properly reviewed and approved.
Physical & Environment
Physical & Environment
We have physical and environmental controls in place to ensure that our data centers are secure and reliable.
Continuous Monitoring
Continuous Monitoring
We continuously monitor our systems for security threats and vulnerabilities. We are happy to provide more details about our continuous monitoring practices upon request.
- How do I get a copy of your SOC 2 report or other security documents?
- Who are your subprocessors?
- How do you handle security incidents?
- How long is data retained, and can it be deleted?
- What compliance standards do you meet?


