Protected B aligned
Federal + Provincial ready
Secure & monitored
Canadian-owned

Trust & Compliance

Trust & Compliance at ConnectCorr

ConnectCorr is engineered to Canadian public-sector expectations and the AICPA Trust Services Criteria. This page summarizes the policies we maintain, the controls we operate, and the evidence we can share with institutions and pilot partners under NDA.

SOC 2 Type II — target readinessProtected B alignedPIPEDA · FINTRACCanadian-hosted

Framework

SOC 2 Type II

Trust criteria

Security · Availability · Confidentiality · Processing Integrity · Privacy

Current stage

Readiness — pre-audit

Evidence access

Under NDA, on request

The five Trust Services Criteria

What we do — in plain language.

Every criterion below lists the outcome we commit to, the controls we operate to get there, and the evidence artifacts a pilot partner or auditor can request.

CC / Security

Security

We protect the portal from unauthorized access, whether from the internet or from inside our own team.

Controls we operate

  • Zero-trust network segmentation between the public portal and any institutional bridge — no persistent trust between segments.
  • SSO + phishing-resistant MFA for every employee; hardware keys for anyone with production access.
  • Least-privilege IAM reviewed quarterly. Access is time-bound and requires approval on every request.
  • 24/7 log aggregation with automated alerting for anomalous authentication, data export, and privilege escalation.

Evidence

Shared with pilot partners under NDA.

A / Availability

Availability

Families and institutions can rely on the portal being up when they need it — and we can recover quickly when something breaks.

Controls we operate

  • Target 99.9% monthly availability with a public status page.
  • Multi-zone Canadian hosting with automated failover and daily encrypted backups.
  • Documented Business Continuity and Disaster Recovery plans; recovery drills at least annually.
  • Change management with peer review, automated tests, and staged rollout gates.

Evidence

Shared with pilot partners under NDA.

C / Confidentiality

Confidentiality

Sensitive information — recipient identifiers, sender KYC data, transactions — stays confidential end to end.

Controls we operate

  • AES-256 encryption at rest; TLS 1.3 with modern cipher suites in transit.
  • Field-level encryption on personal identifiers and government ID numbers.
  • Data classification policy — Protected B alignment for institutional data.
  • Documented data retention and secure destruction schedules per jurisdiction.

PI / Processing Integrity

Processing Integrity

Every deposit is processed accurately, completely, and only when authorized — with a full audit trail.

Controls we operate

  • Immutable ledger of every transaction: who, what, when, and where funds moved.
  • Automated AML monitoring flags high-risk patterns (e.g. one sender to many inmate accounts) for human review.
  • Reconciliation against Canadian payment infrastructure runs on every settlement cycle.
  • Debit-only payment path — no credit rails — reducing chargeback and fraud exposure.

Evidence

Shared with pilot partners under NDA.

P / Privacy

Privacy

Personal information is collected fairly, used only for the stated purpose, and handled under Canadian privacy law.

Controls we operate

  • PIPEDA-aligned privacy program; FINTRAC-aligned KYC on sender registration.
  • Consent captured at account creation; users can request access, correction, or deletion of their data.
  • Documented DPIA (Data Protection Impact Assessment) for every material change.
  • Vendor privacy reviews before onboarding; no personal data leaves Canada.

Evidence

Shared with pilot partners under NDA.

Policy library

Documented, versioned, reviewed annually.

Every policy below is approved by leadership, communicated to all personnel, and reviewed at least once per year. Redacted copies are available to prospective partners on request.

  • Information Security Policy
  • Acceptable Use Policy
  • Access Control Policy
  • Change Management Policy
  • Incident Response Policy
  • Business Continuity & DR Policy
  • Vendor Management Policy
  • Data Classification & Handling Policy
  • Data Retention & Destruction Policy
  • Privacy Policy (PIPEDA)
  • AML / KYC Compliance Policy
  • Secure Software Development Policy

Request the readiness pack

Get the PDF, under NDA.

A signed PDF summary of our policies, controls, and evidence. Accept the mutual NDA to unlock the download; a copy is emailed to you for your records.

  • 7-page confidential summary (~55 KB PDF)
  • Executive summary, five Trust Services Criteria, policy library
  • Full evidence pack available on written request
info@connectionsincorrections.ca

Request & NDA acceptance

Required fields marked with *. Confidential — not stored with third parties.

ConnectCorr is currently pre-audit. Readiness materials describe operating controls today; a Type II report will be published on completion of the observation window.