Probity IQ exists to prove that AI is handled responsibly. That obligation starts with us. This page sets out how we secure your data, protect privacy, keep your information in Canada, and govern our own AI.
Security is built into the platform rather than added afterward. Our practices include:
For questions about our security program, contact security@probityiq.com.
Probity IQ is multi-tenant by design and isolates every organization's data from every other. Access is denied by default, and each request is scoped to a single organization before any data is read. We treat cross-tenant isolation as a required, tested control, not an assumption.
We are transparent about what we collect, why, how long we keep it, and who we share it with. For most of the data that flows through the platform, the interaction records your AI systems generate, Probity IQ acts as a service provider that processes that information on your behalf and under your instructions. You remain responsible for the personal information you send us, and our handling of it is governed by your agreement with us.
We practice data minimization, support redaction, apply configurable retention, and honour deletion. A Data Processing Agreement is available on request. Full detail is in our Privacy Notice.
Probity IQ is Canada-first. Customer data is stored in Canada. Where any processing would occur outside Canada, we apply appropriate safeguards and assess the transfer in line with Canadian privacy law, including Quebec's Law 25.
We govern our own AI with the same discipline we ask of customers. Probity IQ's own AI features are run through Probity IQ, and we are glad to share our own scorecard. Our commitments:
Probity IQ is designed around Canadian obligations, including PIPEDA and Quebec's Law 25, and is mapped to our published control framework. We are honest about where we are on formal certification:
SOC 2 Type II In progress
We are building toward a SOC 2 Type II examination of our security controls.
ISO/IEC 27001 Planned
An ISO/IEC 27001 information security management certification is on our roadmap.
We will update this page as each milestone is reached, and we will not claim a certification we have not earned. To request our current security documentation, contact security@probityiq.com.
We use a limited set of vetted service providers to operate the platform, for example hosting and infrastructure. We maintain a current list of sub-processors and the data they handle, available on request at privacy@probityiq.com. We require appropriate security and privacy commitments from each.
If you believe you have found a security vulnerability, please report it to security@probityiq.com. We will acknowledge your report and work with you in good faith to resolve it. Please do not publicly disclose an issue until we have had a reasonable opportunity to address it.
For privacy questions or requests, contact privacy@probityiq.com.