Compliance
Canadian hosting, with a clear review of your requirements.
CACloud is operated by Canadian Web Hosting from data centres in Toronto and Vancouver. The group holds a SOC 2 Type II report. The privacy laws that apply to the personal data you store here are Canada's PIPEDA and, for Ontario health information, PHIPA.
- 3Facilities, all in Canada
- 2Cities: Toronto and Vancouver
- SOC 2 Type IIReport held
- 1-866-821-8355Phone
- SOC 2 Type II
- PIPEDA
- PHIPA
- Toronto + Vancouver
SOC 2 Type II
A SOC 2 report is an independent auditor's report on how a service company protects customer data. It is written against the AICPA's trust services criteria: security, availability, processing integrity, confidentiality and privacy.
"Type II" is the stronger of the two forms. A Type I report says the controls were designed properly on one day. A Type II report says the auditor tested that the controls actually operated over a review period.
The Canadian Web Hosting group, which operates CACloud, holds a SOC 2 Type II report. We can provide the audited report on request, so your own auditors can read the control list instead of taking our word for it.
Report coverage depends on the services, locations and review period it names. Confirm the scope of your proposed service with our team before relying on it for an audit requirement.
| Standard | Status | Held by |
|---|---|---|
| SOC 2 Type II | Report held. Copy available on request. | Canadian Web Hosting (operator of CACloud) |
Buying hosting that already sits inside an audited control environment is usually cheaper than building the same physical security, storage controls and procedures on your own. That is the practical reason to care about the report.
Controls you can see from outside
Some of the controls in the report are visible in the product itself. Each of these is available on the CACloud platform today.
- SSL certificates for encrypted connections to your site.
- Application-level protection in front of web workloads.
- Hardware and software firewalls, in four layers.
- IP-restricted FTP, so file transfer is only accepted from the addresses you name.
- Managed backups with guaranteed retention.
- 24/7 monitoring by the network operations centre.
- Multi-level intrusion prevention and detection (IPS/IDS).
- Anti-spam, anti-malware and anti-virus filtering.
- Log management, so actions on your account are recorded and can be reviewed.
If your auditor needs a control that is not listed, ask us before you assume it is missing.
PIPEDA: the federal privacy law
PIPEDA is the Personal Information Protection and Electronic Documents Act. It applies to any organisation in Canada that collects personal information in the course of business. Because CACloud collects personal information from its own customers, and hosts personal information for them, our privacy practices follow it.
One thing PIPEDA does not do is require the data to stay in Canada. The Office of the Privacy Commissioner has said plainly that the Act does not prohibit an organisation in Canada from transferring personal information to another jurisdiction for processing. Keeping your data here simply removes one of the questions you would otherwise have to answer about a transfer.
The law's mandatory provisions require an organisation to:
- Get the person's knowledge and consent before collecting personal information.
- Collect personal information only for a reasonable purpose.
- Limit how personal information is used and shared.
- Limit who can access personal information.
- Keep stored personal information accurate and complete.
- Name a Privacy Officer.
- Have written policies and procedures for a privacy breach.
- Give people a way to raise and resolve a complaint.
- Follow the special rules for employee information.
Our own handling of your account data is described in the privacy policy.
PHIPA: Ontario health information
PHIPA is Ontario's Personal Health Information Protection Act, in force since 2004. It sets the rules for collecting, using and disclosing personal health information in the province.
Under PHIPA the health-care provider that collects the data is the custodian. Patients give their consent to that custodian, not to the hosting company, and compliance is the custodian's to hold. PHIPA sets no data-residency rule. A host like CACloud acts for the custodian, and the Information and Privacy Commissioner of Ontario expects the host to support the custodian's duties.
For a custodian hosting health information with us, that means:
- We notify the custodian of any privacy breach right away.
- We provide a plain-language description of the services we deliver.
- We keep an audit trail that records use of the database.
- We prepare a written risk assessment of the system.
- We maintain our own written privacy policies.
What Canadian residency means here
A "Canada region" on a foreign cloud puts the disks in Canada. Residency at CACloud goes further, and each part of it is a checkable fact.
- The operator is Canadian. CACloud is run by Canadian Web Hosting, with a postal address in Vancouver, BC, Canada.
- The facilities are Canadian. Servers sit in named buildings in Toronto and Vancouver. The addresses are on the data centres page.
- The owner is Canadian. The registered company is iDigital Internet Inc., incorporated in British Columbia in 1998 and owned by a Canadian citizen. There is no foreign parent above it. What that does and does not mean under foreign law is set out on the about page.
- The law is Canadian. PIPEDA applies federally; PHIPA applies to Ontario health information. Canadian law decides, in Canadian courts.
- The support is Canadian. The people who can touch your server work from those same facilities and log every access.
About this page
Earlier versions of this page described the same audit program under older attestation standards, which have since been retired and replaced by the SOC 2 framework. SOC 2 is what the group reports against today, and a SOC 2 engagement produces a report, not a certificate.
The address of this page keeps its old name because it has been linked from other sites for years, and a moved page would break those links. The name in the address is history; the report described above is current.
Need the SOC 2 report for a vendor review?
Email sales with your company name and what you are assessing. We can also answer a security questionnaire or a privacy impact assessment.