Trust

What you can verify, and where to find it.

Sovereignty is a promise that only means something if the trust surface is visible. This page collects the jurisdiction, certifications, sub-processors, and contacts that back the claims we make elsewhere on the site.

Jurisdiction & residency

Canadian company, Canadian data.

Canadian jurisdiction

Breqwatr is incorporated in Canada, owned by Canadians, and operates exclusively under Canadian jurisdiction. No foreign parent, no foreign control plane, no US CLOUD Act exposure. Court orders affecting customer data must originate in a Canadian court.

Data residency

Workloads, snapshots, logs, and operational telemetry stay in Canadian regions. Because we run our own hardware and network, no third-party sub-processor touches your workload data, and it doesn't cross the border without your explicit, written instruction. In most cases, it can't.

Breqwatr does not take backups on your behalf. Snapshots and volumes you create stay in Canadian regions, but keeping a recoverable copy is yours to own.

Certifications and frameworks

What we hold, and what we align to.

FrameworkStatusDetails
ISO/IEC 27001:2022 Certified Our information security management system is certified to ISO/IEC 27001:2022. Certificate available on request. Ask via our contact form.
PIPEDA Aligned Federal privacy alignment; provincial regimes (PHIPA, Law 25, FOIP) apply on top depending on workload.
Vulnerability disclosure

Found something? Tell us.

We welcome responsible disclosure from security researchers. The disclosure channel and policy live at /.well-known/security.txt in the RFC 9116 format. We acknowledge reports within one business day, keep you updated through remediation, and do not pursue researchers acting in good faith.

Contacts

Who to email for what.

Procurement and audit

DPAs, audit packs, security questionnaires, sub-processor lists, and certification evidence: use our contact form and we'll route you.

Security disclosure

Vulnerability reports: /.well-known/security.txt.

Status and incidents

Live status: status.breqwatr.cloud.