Compliance & Certification Readiness

Last reviewed: July 29, 2026. This is a self-assessment and readiness record, not legal advice, an external audit, or a certification claim.

Certification status

AreaStatusEvidence and remaining work
Privacy controlsImplemented controlsPublished collection purposes and retention periods; IP addresses excluded from analytics; access to analytics is restricted; automated deletion schedules are implemented.
PIPEDA readinessPartialTechnical safeguards, openness, collection limits, and retention controls exist. The operator must appoint and publish a privacy contact, establish access/correction and complaint procedures, maintain breach records, and obtain legal review before claiming compliance.
AccessibilityAutomated checks passedKeyboard, semantic, responsive, colour-contrast, and static accessibility checks are part of the test suite. Manual screen-reader and disabled-user testing and an external WCAG audit remain outstanding.
SecurityHardened; not certifiedHTTPS, restrictive security headers, same-origin checks, input validation, rate limiting, file-signature checks, retention, and protected administration are implemented. No SOC 2, ISO 27001, PCI DSS, or independent penetration-test certification is claimed.
CASLNot currently usedThe service does not operate a promotional email or SMS program. Before adding one, the operator must implement consent records, sender identification, and a working unsubscribe process.

Applicable guidance

Release evidence

Each release is checked for formatting, syntax, application health, security controls, data handling, rooms, moderation, file transfer, browser behaviour, accessibility, load, reconnects, and deployment errors. Passing automated tests reduces risk but does not establish legal compliance or third-party certification.