KYP Manager

Security Overview

Last updated July 2026. A plain-language summary of the controls protecting your information.

Identity and access

Every user — advisors, compliance, administrators and portal clients — signs in with a password plus multi-factor authentication (authenticator app). New and changed passwords are screened against known breach corpora using a k-anonymity check, so a password already circulating in credential-stuffing lists is rejected — without the password itself ever leaving the platform. Sessions expire on inactivity and carry an absolute lifetime cap. Access is role-based and least-privilege: portal clients can only ever reach their own records, and firms can restrict advisors to their assigned clients.

Data isolation and encryption

All data is hosted in Canada. Every firm's records are isolated by database row-level security, verified by automated cross-tenant tests on every code change. Sensitive fields (names, contact details, financial profiles, advisor notes) are additionally encrypted at the application layer with per-record keys under a rotatable master key — on top of encryption at rest and TLS in transit.

Auditability

Every create, edit, export and administrative action — and every vault-document download, by staff or by the client — is recorded in an append-only audit log attributed to the acting user. Clients can see recent activity on their own records on their portal Settings page ("Access to My Information").

Application security

Defence-in-depth at the web layer: strict Content-Security-Policy, CSRF protection on every state-changing request, security headers (HSTS, frame denial, referrer policy), rate limiting on sensitive endpoints, and server-side permission checks independent of the UI.

What we are working toward

Advisors can also grant external professionals (an accountant or lawyer) time-limited access to specific vault documents via an expiring, revocable link — with every download recorded and visible to the client. Roadmap items we are open about: passkey (phishing-resistant) sign-in alongside TOTP, upload malware scanning, and periodic independent penetration testing. Ask us for current status.

Reporting a concern

Suspected vulnerabilities or security incidents: contact your advisory firm or the platform operator immediately. We investigate all reports and will notify affected firms without undue delay if an incident affects their data.