Skip to main content
Sovereign Security Delivery

Canadian Data Residency & Sovereign Security

100% of testing infrastructure, client deliverables, and assessment communications remain strictly within Canadian borders. Zero offshore subcontracting, ever.

AWS ca-central-1 Storage Canadian Citizen Consultants Canadian Legal Jurisdiction
The Regulatory Imperative

Why Data Residency Is Non-Negotiable in Canada

When you hire a security assessment firm, you are granting access to production environments, proprietary codebases, and customer databases. Exposing this information to offshore workers or foreign cloud servers exposes your business to severe compliance and legal risks.

Quebec Law 25 Compliance

Transferring personal information outside Quebec triggers mandatory Privacy Impact Assessments (EFVP) and strict statutory liabilities. We keep all engagement operations strictly within Canada.

Public Sector & BPS Mandates

Canadian municipal, provincial, and broader public sector (BPS) entities require security vendors to prove data sovereignty under Canadian Centre for Cyber Security (CCCS) profiles.

Zero Offshore Subcontracting

Many consultancies sell local expertise but quietly farm penetration testing to low-cost overseas teams. Lorikeet Security Canada exclusively employs Canadian personnel residing in Canada.

Concrete Guarantees

The Lorikeet Security Canada Sovereign Charter

1. In-Country Cloud Storage

All client data, attack surface inventories, and final PDF deliverables are stored in Canadian cloud regions (AWS Canada Central - Montreal/Calgary) with AES-256 KMS encryption.

2. Canadian Citizen Consultants

Your systems are tested by verified Canadian citizens based out of our Calgary and Toronto hubs. We do not use international gig-worker crowds or third-party agencies.

3. Canadian Governing Law

All engagement contracts, Master Services Agreements (MSAs), and Non-Disclosure Agreements (NDAs) are governed exclusively under the provincial laws of Alberta or Ontario.

4. Background Checks & Screening

Every consultant undergoes comprehensive Canadian criminal background checks, identity verification, and strict confidentiality screening prior to client deployment.

5. Guaranteed Cryptographic Shredding

Upon engagement sign-off, all staging test artifacts, temporary capture files, and credential caches are cryptographically wiped following NIST SP 800-88 sanitization standards.

6. 100% Billing in Canadian Dollars

We bill transparently in CAD. Canadian clients avoid volatile exchange rates, cross-border credit card processing fees, and complex US withholding tax (W-8BEN) forms.

Common Inquiries

Data Residency FAQ

Do you offer signed Data Processing Agreements (DPAs) reflecting Canadian law?

Yes. We provide Canadian-governed DPAs that explicitly guarantee Canadian data residency, PIPEDA compliance, and breach notification obligations under Alberta PIPA and Quebec Law 25.

Where are your penetration testing attack systems hosted?

Our dedicated, hardened attack proxies and scanner nodes originate exclusively from Canadian IP blocks hosted in Montreal, Toronto, and Calgary datacentres.

Can you accommodate on-site testing in Calgary or Toronto?

Yes. Our consultants deploy directly to client offices, private datacentres, and energy facilities across Calgary, Toronto, and province-wide in Alberta and Ontario for internal and wireless assessments.

Work with a True Canadian Security Partner

Local accountability, sovereign data guarantees, and elite technical capabilities.