Trust Centre

Welcome to the GuardMe Trust Centre.

In today’s rapidly evolving digital landscape, we are committed to safeguarding the security and privacy of all data entrusted to us. Whether you're an individual or represent an institution, your data matters—and we take its protection seriously.

On this page, you'll discover how GuardMe leverages enterprise-grade privacy & security techniques and conducts thorough audits of our applications, systems, and networks to ensure the confidentiality, integrity, and availability of your information.

Compliance Security Privacy Legal

Photo of two employees

Compliance

ISO-logo-27001   ISO-logo-27701   ISO-logo

ISO 27001 is a globally recognized standard for building and implementing a strong information security management system (ISMS) that helps organizations protect sensitive data, manage risks, and comply with international standards such as GDPR.

GuardMe was first certified under this standard in 2022 and has consistently maintained full compliance since then, adhering to all requirements and best practices.

ISO 27701 is also an international standard, but one that serves as a privacy extension to ISO 27001. Its primary purpose is to help organizations establish, implement, maintain, and continually improve a Privacy Information Management System (PIMS).

By building on the existing ISMS framework with privacy-specific requirements and controls, this certification (first achieved by GuardMe in 2023 and repeated yearly thereafter) provides assurance to stakeholders that any personal data entrusted to us is managed in compliance with all international privacy regulations.

The American Institute of Certified Public Accountants (AICPA) is the professional organization responsible for developing and maintaining the SOC (System and Organization Controls) reporting framework. SOC 3 was created by the AICPA to help organizations demonstrate their commitment to strong internal controls across five key areas: security, availability, processing integrity, confidentiality, and privacy.

By undergoing an extensive independent audit and achieving SOC 3 attestation in 2024, GuardMe affirms its dedication to maintaining robust operational controls and safeguarding customer data. SOC 3 compliance offers transparent assurance to customers, clients, partners, and the public that GuardMe’s systems are designed and operated with high standards of security and reliability.

Security

At GuardMe, we design our systems with security in mind from the ground up—leveraging industry best practices, modern technologies, and rigorous internal standards. From infrastructure to application development, every layer is built to protect your data and ensure service integrity. By working to identify risks, respond to incidents, and uphold the highest standards of protection, we ensure a resilient and secure environment that safeguards our people, assets, and reputation against evolving threats.

Infrastructure security

GuardMe hosts its backup data and current call centre on servers in our Canadian Data Centre with strict physical and environmental controls. Access is controlled through pre-clearance requirements, graduated levels of entry, and coded access. Further, our Data Centre ensures additional layers of protection by utilizing backup power, enhanced HVAC systems, and waterless fire suppression.

Our network architecture is built with security and resilience in mind and ensures separation by required function and security level. We use a variety of architectural methods including purpose-based physical segmentation and air-gapping where required. This allows GuardMe to isolate systems, enforce strict access controls, and minimize risk. We utilize multiple levels of firewalls and intrusion detection to prevent threats. Redundancy and DDoS protection ensure high availability, while Zero Trust principles guide our access policies.

We partner with leading cloud providers who offer robust security controls and compliance certifications. Their infrastructure is regularly audited and aligned with global standards, and we ensure that they meet all contractual and industry security requirements, including maintaining data sovereignty in Canada.

Application security

Security is integrated into every phase of our development process, from design to deployment. We follow secure coding practices and conduct regular threat modeling.

All code undergoes peer review and automated testing to catch vulnerabilities early. We also use static and dynamic analysis tools to ensure code quality and security. As well, our Quality Assurance (QA) department reviews and tests our code base while dedicated QA automation analysts identify, test, and triage security vulnerabilities.

We regularly scan to quickly identify out-of-compliance or potentially vulnerable systems, and apply patches based on severity and risk. Our team tracks emerging threats and responds quickly to new advisories.

Data protection

In line with industry best practices, all electronic communications between you and GuardMe are encrypted. In addition, all data at rest is also encrypted, using AES 256-bit key encryption.

Encryption keys are managed securely using centralized key management systems. Access to keys is tightly restricted and logged for auditability.

Client data is logically separated to prevent cross-tenant access. Access is based on job function, granted on a least privilege basis, and regularly reviewed.

Identity & access management

Access to our network is restricted on an explicit need-to-know basis, utilizes the principle of least privilege, is frequently audited and monitored, and is controlled by our IT team.

Permissions are assigned based on roles to ensure GuardMe personnel only access what they need, in order to minimize risk.

MFA is required for access to all GuardMe systems, whether by GuardMe or client personnel, adding an extra layer of protection against unauthorized access.

Monitoring & incident response

Our systems are regularly monitored for suspicious activity using automated tools and human oversight. Alerts are triaged and investigated in real time.

We maintain a detailed Incident Response Plan that is regularly tested and updated. Our team is trained to respond quickly and effectively to any security event.

In the event of a breach, we follow clear protocols to protect the personal information under our control. GuardMe ensures that we notify all affected parties promptly and within the timeframes specified by the stakeholder’s requirements and in line with all applicable data protection legislation.

Security testing & audits

In addition to our internal scanning and testing, we employ external security experts to perform a broad penetration test across GuardMe’s network. These tests help identify and remediate vulnerabilities before they can be exploited.

Our security controls are independently audited against industry standards. Certifications like SOC 3 and ISO 27001 demonstrate our commitment to best practices.

Availability & continuity

GuardMe has implemented, and continues to improve, a full business continuity process to ensure we can maintain or quickly resume critical operations during and after disruptive events, thereby minimizing downtime and protecting stakeholder trust. Our Business Continuity Plan is regularly updated, and all staff are trained on how to respond appropriately in an emergency.

GuardMe has a disaster recovery program that returns our systems to full operation in the case of a disaster. This is accomplished through building a robust technical environment, creating a Disaster Recovery Plan, and conducting regular testing activities.

Employee security awareness

All employees complete privacy & security training during onboarding and yearly thereafter. Training covers phishing, data handling, and secure practices.

We monitor for unusual behavior and enforce strict access controls to reduce insider risk. Employees are held accountable through clear policies and audits.

Our acceptable use policies define how systems and data should be handled. These policies are reviewed regularly and agreed to annually by all staff.


Privacy

The robust privacy program run by GuardMe adheres to specific guidelines to protect the personally identifiable information (PII) and personal health information (PHI) we may collect, process, or disclose during our normal business operations. All legal and contractual requirements that apply to GuardMe’s business are reviewed annually, and any changes or updates are immediately actioned for implementation.


Legal compliance

The following sections describe the legislation that GuardMe accords with, including provincial, federal, and international acts.

PIPEDA is a Canadian law that focuses on ten fair information principles that underlie the rules for the collection, use, access, and disclosure of personal information. The legislation has undergone several changes since its enactment in 2000, driven by evolving technology, global data protection standards, and the need to address emerging risks associated with data handling in the digital economy, but GuardMe has remained in compliance with every update.

GuardMe also complies with various pieces of provincial privacy legislation, including:

  • British Columbia
    • Freedom of Information and Protection of Privacy Act
    • E-Health Personal Health Information Access and Protection of Privacy Act
  • Alberta
    • Freedom of Information and Protection of Privacy Act
    • Health Information Act
  • Saskatchewan
    • Freedom of Information and Protection of Privacy Act
    • Health Information Protection Act
  • Manitoba
    • Freedom of Information and Protection of Privacy Act
    • Personal Health Information Act
  • Ontario
    • Freedom of Information and Protection of Privacy Act
    • Personal Health Information Protection Act
  • New Brunswick
    • Right to Information and Protection of Privacy Act
    • Personal Health Information Privacy and Access Act
  • Nova Scotia
    • Freedom of Information and Protection of Privacy Act
    • Personal Health Information Act
  • Prince Edward Island
    • Freedom of Information and Protection of Privacy Act
  • Newfoundland & Labrador
    • Access to Information and Protection of Privacy Act
    • Personal Health Information Act

GuardMe’s business approach has been anchored by a strong commitment to privacy, security, compliance, and transparency. This approach includes supporting our customer and client compliance with EU data protection requirements, such as those set out in the General Data Protection Regulation (“GDPR”).

If GuardMe collects, transmits, hosts, or analyzes personal data of EU citizens, GDPR requires us to use third-party data processors who guarantee their ability to implement the technical and organizational requirements of the GDPR.

Although the United Kingdom has withdrawn from the European Union, the European Commission has adopted adequacy decisions that ensure personal data can flow freely from the European Union to the United Kingdom, where it benefits from an essentially equivalent level of protection to that guaranteed under EU law.

Privacy-related policies

Our detailed Privacy Notice describes how GuardMe protects the data it collects, processes, and discloses.

Privacy Notice

This notice provides detailed information about how and when we use cookies on GuardMe websites, as well as how to control and delete them.

Cookie Notice

This policy provides directions and guidance for responding to breaches of personal information.

Privacy Breach Policy

This policy contains information regarding the privacy program in place at GuardMe.

Privacy Policy for Websites



Privacy assurance features

Privacy by Design is a methodology for proactively embedding privacy into information technology, business practices, and networked infrastructures. These measures are designed to anticipate and prevent privacy invasive events before they occur.

GuardMe’s privacy and data protection program follows this unified approach to ensure that all personal data is fully protected while it is under our control.

GuardMe has tools to assist with individual requests and other obligations under applicable privacy and data protection laws and regulations, such as data access, correction, portability, deletion, and objection.

Any individual who seeks to exercise their data protection rights can complete a Data Access Request Form. Upon receipt of this Data Subject Access Request (DSAR), we will review the individual’s request against our industry guidelines (such as data retention) and then respond within thirty (30) days.

GuardMe operates an advanced set of access and encryption features to ensure client and customer data is effectively protected. We do not access or use client or customer data for any purpose other than providing, maintaining, and improving our services and as otherwise required by applicable law. Additional information is available here.

GuardMe fully complies with internationally recognized frameworks, including ISO and SOC 3. Our certifications are described here.


Your choice regarding cookies on this site