PaperVault is built for organizations whose business is trust: law firms, accounting firms, immigration consultancies, and financial services teams handling their clients' most sensitive documents. Security is not a feature we added — it is the constraint we designed around. This page describes how we protect your data, in the same plain terms we use in our contracts.
PaperVault is a brand of Agilio IT Consulting Inc., an Ontario corporation. Our contractual security commitments live in our Terms of Service (Section 10.3) and Data Processing Agreement (Annex B); this page is the readable version. For the product-level view of these controls, see Security & trust in the product.
Data residency
- Primary infrastructure in Canada. Compute, databases, and document storage are hosted in a DigitalOcean data centre in Toronto, Ontario (region TOR1). All customer content persisted at rest remains in Canada.
- Documented exceptions, not surprises. Specific functions — AI processing, transactional email, error monitoring, and compliance-screening lookups — transmit specific categories of data outside Canada. Every one is disclosed, per vendor and per data category, on our Subprocessors page. Customers who require strictly Canadian-only processing can discuss a reduced-feature configuration with us; we will tell you plainly what the architecture does and does not support rather than promise what it cannot deliver.
Encryption and key custody
- Encrypted in transit. All connections use TLS 1.2 or higher, terminated at our content delivery and security layer.
- Encrypted at rest. Customer documents and databases are encrypted at rest using industry-standard encryption.
- Executive-only key custody. This is the control that makes PaperVault different. Decryption keys for customer documents are held exclusively by a small number of designated executive officers of Agilio. PaperVault staff — including support and engineering — cannot read, open, or download the contents of your documents in the ordinary course of their work. Documents are decrypted only in two circumstances: at your express request for support on your own content, or under a legally binding demand from a court or competent authority. Every decryption event is documented.
- Automated processing is not human access. Indexing, classification, and AI features process your content programmatically to deliver the functionality you invoke. No person reads your documents to make those features work.
Account security
Every account has access to modern, phishing-resistant authentication:
- Passkeys — phishing-resistant by design; our recommended sign-in method
- Multi-factor authentication (MFA)
- Single sign-on (SSO) — bring your organization's identity provider
- Magic-link sign-in
Access within your workspace is governed by role-based permissions you control. We will never ask you for your password — any message that does is not from us.
Platform and network security
- Edge protection. All traffic passes through Cloudflare's network: web application firewall, DDoS mitigation, and Turnstile bot protection on public forms and signing pages.
- Least-privilege access. Internal access to production systems is restricted on a need-to-know basis and logged.
- Environment segregation. Development and testing environments are separated from production; our build and deployment pipeline has no access to production databases or document storage.
- Tenant isolation. Customer workspaces are logically isolated; requests are authorized against your tenant on every call.
- Secure development. Changes are code-reviewed and pass automated checks before deployment; vulnerability management is part of the development cycle.
AI features and your data
- Content processed by AI features is used solely to deliver the requested functionality.
- Your content is never used to train AI models — ours or anyone else's — and our AI providers are contractually bound to the same restriction.
- Every AI feature can be disabled independently, per customer, if you prefer not to use it.
- AI outputs are decision support for your professionals, not decisions: your team reviews and remains responsible for outcomes, as our Terms of Service make explicit.
Backups and resilience
- Databases are backed up on a defined schedule with encrypted storage and point-in-time recovery.
- Business continuity and disaster recovery procedures are reviewed periodically.
- The Service is not intended to be your only copy of legally critical records; we encourage customers in regulated industries to maintain their own archival copies, as their own regulators typically require.
Incident response and breach notification
We maintain incident response procedures covering detection, containment, investigation, and remediation. If a security incident affects your personal information, we commit contractually to notify you without undue delay and within 72 hours of confirmation, with the details you need for your own regulatory assessment — including under PIPEDA's real-risk-of-significant-harm standard. See Section 8 of our DPA.
Compliance program
We practice what our platform enables:
- Sanctions and AML screening of our own customers, as described in our Terms of Service — because a compliance platform should not be usable by parties its customers could not lawfully serve.
- Privacy compliance under PIPEDA, with a designated Privacy Officer (privacy@agilio.ca) and Quebec Law 25 readiness. See our Privacy Policy.
- Payment security. Card data is captured directly by Helcim's hosted payment interface and never touches PaperVault systems (SAQ-A posture).
- Transparent subprocessing. Every vendor that touches customer content is listed, with data categories and locations, on our Subprocessors page — including the free public data sources most companies don't bother to disclose.
Certifications roadmap
We are a young company and we will not claim badges we have not earned. Independent attestation (SOC 2) is on our roadmap; until then, this page, our contracts, and our willingness to complete your security questionnaire are our evidence. We respond to security questionnaires and due-diligence requests as described in Section 10 of our DPA.
Report a security concern
If you believe you have found a vulnerability in PaperVault, contact us at security@agilio.ca. We ask for reasonable time to investigate and remediate before public disclosure, and we will not pursue good-faith research conducted within our Terms of Service (penetration testing requires prior written authorization — email us and we will scope it).
Questions
Security due-diligence and questionnaire requests: privacy@agilio.ca
Agilio IT Consulting Inc., 133-290 King Street East, Kitchener, Ontario N2G 2L3, Canada