The posture, in plain terms.
This page exists so your security team can assess MAIA before anyone books a call. Everything stated here is literally true at the time of publication — including what is still in progress. Detailed artefacts, architecture reviews, and questionnaire responses are available under NDA.
Security & compliance, itemised.
Canadian data residency by default. Deployments run in Canadian cloud regions, in your environment, or air-gapped on-premise for classified work.
Architecture mapped to PBMM (Protected B, Medium Integrity, Medium Availability) controls for public-sector deployments. Assessment artefacts available under NDA.
Program in progress. Control environment operating; independent attestation window underway. Status shared candidly in any security review.
PIPEDA-aligned handling of personal information; FIPPA-ready configurations for BC public bodies and provincial equivalents elsewhere.
TLS 1.2+ in transit; AES-256 at rest. Secrets managed via cloud KMS; no credentials in code or logs.
Role-based access control on every surface, SSO/SAML available, least-privilege service accounts, full security-event logging.
Every AI-drafted decision carries its evidence: source signals, reasoning chain, policy applied, and the human who approved it — sealed in a tamper-evident, hash-linked ledger.
Critical actions require human authorisation by design. Autonomy is bounded by explicit policy gates your operators control — never a black box.
Read the paperwork.
The public documents below apply to every deployment. Security questionnaires (including custom formats) are answered as part of any briefing.
Asked in every review.
Where is our data stored?
In Canada by default. Deployments run in Canadian cloud regions, in your own environment, or fully air-gapped on-premise for classified work. Any movement of personal information outside Canada requires your explicit written authorisation.
Is MAIA SOC 2 certified?
Our SOC 2 Type II program is in progress: the control environment is operating and the independent attestation window is underway. We share the current status candidly in any security review, and our Trust Center will state the moment attestation is complete.
Can MAIA run air-gapped or in a classified enclave?
Yes. The sovereign configuration deploys with in-enclave model serving, no external dependencies in the decision loop, and updates delivered as verified artefacts. What breaks when the internet is removed: nothing in the operating loop.
How are AI decisions audited?
Every AI-drafted decision carries its evidence — source signals, reasoning chain, policy applied, and the human who approved it — sealed into a tamper-evident, hash-linked ledger before consequential actions execute. Determinations are replayable months later, exactly as they ran.
Is customer data used to train models?
No. Customer data is not used to train shared or foundation models. Models that learn from your operation learn inside your tenancy, for your tenancy.
Can our security team send a questionnaire?
Yes — including custom formats. Security questionnaires are answered as part of any briefing, with the engineers who built the system in the room. Detailed artefacts and architecture reviews are available under NDA.
Put your hardest questionnaire in front of us.
We answer security reviews directly, with the engineers who built the system in the room.
Request a briefing ↗