Last updated: March 7, 2026
Table of Contents
01
AtlasBrokers is built with security at its core. We implement industry-leading security practices across our infrastructure, application, and operations to protect your data and maintain your trust.
02
We maintain rigorous security certifications and continuously work toward additional compliance frameworks to protect your data at the highest industry standards.
Annual audit of security, availability, and confidentiality controls. Certification achieved for platform infrastructure and data handling processes.
International standard for information security management systems (ISMS) covering risk assessment and treatment.
Fully compliant with Canada's Personal Information Protection and Electronic Documents Act, including privacy policy, consent management, breach notification, and DSAR procedures.
Payment Card Industry Data Security Standard for handling cardholder data securely.
03
We use multiple layers of encryption to protect your data:
04
Multiple layers of encryption protect your data at every stage of its lifecycle, from initial transmission to long-term storage.
All stored data is encrypted using AES-256-GCM with hardware-backed key management.
All network traffic is encrypted with TLS 1.3, enforcing perfect forward secrecy.
Sensitive personal and financial data is end-to-end encrypted from client to database.
Data Encryption Flow
05
Our infrastructure is designed for reliability, performance, and security:
06
We implement robust authentication mechanisms:
07
We follow the principle of least privilege across all systems:
08
Our multi-layered access control framework ensures that only authorized personnel can access sensitive systems and data, with full audit trails on every action.
Granular RBAC with predefined roles (Admin, Editor, Viewer) and custom permission sets. Access is granted based on the principle of least privilege.
MFA is enforced for all administrative accounts using TOTP authenticator apps, hardware security keys (WebAuthn/FIDO2), or SMS backup codes.
Enterprise SSO integration via SAML 2.0 and OpenID Connect. Supports identity providers including Okta, Azure AD, and Google Workspace.
Automatic session expiration after 30 minutes of inactivity. Concurrent session limits, forced logout on password change, and secure cookie handling (HttpOnly, SameSite, Secure flags).
09
We adhere to Canadian and international compliance frameworks:
10
We proactively identify and address security vulnerabilities:
11
We are committed to regular security assessments as part of our ongoing security program. This includes periodic testing of our web application, API endpoints, and cloud infrastructure.
12
We welcome responsible security disclosures. If you discover a vulnerability, please contact security@atlasbrokers.ca. We are committed to working with researchers to resolve issues promptly.
Report a Vulnerability13
Our defence-in-depth architecture ensures multiple layers of protection between users and sensitive data, with security controls at every tier.
Client Layer
Edge Layer
Application Layer
Service Layer
Data Layer
Browser
HTTPS Only
CSP Headers
SRI Integrity
CDN / WAF
DDoS Protection
Rate Limiting
Bot Detection
Next.js App
Auth Middleware
Input Validation
CSRF Protection
API Layer
JWT Tokens
RBAC Checks
Audit Logging
Encrypted DB
AES-256
Row-Level Security
Automated Backups
14
We maintain a comprehensive incident response plan:
15
We prioritize rapid detection and response to security incidents. Our incident response process includes automated monitoring, defined escalation procedures, and post-incident reviews to continuously improve our security posture.
Affected users will be notified via email and our status page will be updated during any active incidents.
16
We are transparent about where your data is stored and processed:
17
All primary data is stored exclusively within Canada, ensuring full compliance with PIPEDA and provincial privacy legislation. Our infrastructure is designed for low-latency access across all Canadian provinces.
Cloud Infrastructure
Hosted on enterprise-grade cloud infrastructure with Canadian data residency.
Disaster Recovery
Automated backups with geographic redundancy.
18
Have a security concern or want to report a vulnerability? Contact our security team:
Security Reports security@atlasbrokers.ca
Privacy Inquiries privacy@atlasbrokers.ca
Company AtlasBrokers Inc.
Location Canada