Security
Last updated: September 10, 2026 · Version 3.0
Security comes first. Every account, every device and every action is verified before it touches your data — and every step of that verification adapts to your organization. This page states what we commit to; the details are shown in a demo, not published.
Identity and devices
Sign-in is verified in several independent ways: the phone’s SIM card (Android) or device attestation (iPhone), email or your organization’s single sign-on (Google, Microsoft, SAML), a one-time code by text, and an authenticator app (TOTP).
A trust token remembers a device you have verified; sessions expire and can be revoked. Access can be restricted to a country.
Your data
Encrypted in transit and at rest; the keys themselves are stored encrypted. Each organization’s data is isolated from every other’s.
Hosted in Canada — Google Cloud, Montréal region — with any Canadian region available on request; storage can also live on Google Cloud, Azure or AWS. If you bring your own storage, your files stay with your provider.
Access and traceability
Every action goes through a gateway that checks who you are and what your role allows before anything is read or written. Access profiles are defined per role and per situation, down to the field.
Every access and every change is logged with its author and time; consents are logged with the version accepted; electronic signatures are time-stamped.
Protection in operation
- Real-time monitoring and anomaly detection.
- Automated protection against bots.
- Content scanning for sensitive data (DLP).
- Automated scanning of software dependencies; patches applied promptly.
- Review of every security-sensitive code change before it reaches production.
Incident response
- Classification by severity (P1 to P4) and escalation accordingly.
- Immediate isolation of affected systems; compromised accounts suspended and devices revoked within minutes.
- Affected people notified within 72 hours of a confirmed breach, as required by PIPEDA and Quebec’s Law 25.
- Post-incident review within 7 days.
Backups and recovery
- Automated backups with point-in-time recovery.
- Data replicated across several geographic zones.
- Recovery time objective: 4 hours for critical systems; recovery point objective: 1 hour.
- Target availability: 99.9%, monitored around the clock.
Compliance
PIPEDA, Quebec’s Law 25, CRTC rules, CASL and the National Do Not Call List. Beyond IT is a telecommunications service provider registered with the CRTC; its connected-device integrations in healthcare are Class I (self-assessment accepted by Health Canada, May 2026).
SOC 2 and ISO 27001: our infrastructure provider holds SOC 1, 2 and 3 as well as ISO 27001, 27017 and 27018; our own certification is on the roadmap — we do not hold it yet.
Contact
security@beyondit.co · Beyond IT Inc. · Edmonton and Montréal, Canada.