Security

Security at Comply+

Here is how we protect your data, and how customers can verify it with our SOC 2® report.

AICPA SOC 2 seal

SOC 2

Comply+ completed an examination with an independent CPA firm to obtain its SOC 2 Type 1 report, covering the Security criteria for our FINTRAC reporting platform as of September 12, 2026. Independent examination is an important safeguard when handling sensitive customer data.

Customers can access our SOC 2 Type 1 report in the dashboard.

Controls

The controls covered by our SOC 2 report.

Access Control

  • Data Access
  • Logging
  • Password Security

+ more

App Security

  • Code Analysis
  • Dependency Scanning
  • Change Management

+ more

Business Continuity

  • Backups
  • Disaster Recovery Plan

+ more

Corporate Security

  • Employee Training
  • Incident Response Plan
  • Internal Assessments

+ more

Data & Endpoint Security

  • Encryption at Rest
  • Encryption in Transit
  • Access Reviews
  • Disk Encryption

+ more

Full control list

Every control is described in the SOC 2 report, which customers can access in the dashboard.

Some features, including aiSTR™ narrative drafting, rely on third-party providers that may process data outside Canada. Our Terms of Service explain how we use sub-processors.

Your part

Security is shared. Turn on multi-factor authentication when you first log in, and limit Comply+ logins to the people doing your compliance work. When someone leaves, rotate the account password and set up multi-factor authentication again right away, and tell us immediately about any suspected unauthorized access.

Report a security concern

Found a vulnerability or suspect an incident? Email us. We monitor this inbox and respond under our incident response plan.

support@complyplus.ca