Skip to content

Trust center

Infrastructure-grade compliance. Proudly Canadian.

Forismo is designed for teams that handle sensitive communications — including legal professionals. Our security and privacy infrastructure meets Canadian federal and provincial requirements, with a roadmap to full US compliance.

Certifications & compliance

PIPEDA CompliantActive

Compliant with Canada's Personal Information Protection and Electronic Documents Act. All 10 fair information principles implemented.

CASL CompliantActive

Built-in consent management for commercial electronic messages. Express opt-in, sender identification, and unsubscribe mechanisms.

Quebec Law 25Active

Compliant with Quebec's privacy law including mandatory Privacy Impact Assessments, data portability, and cross-border adequacy assessments.

SOC 2 Type IIn Progress

AICPA Service Organization Control report covering Security, Availability, and Confidentiality trust service criteria.

SOC 2 Type IIPlanned

Extended observation period audit demonstrating sustained control effectiveness over time.

ISO 27001Planned

International standard for information security management systems (ISMS).

Data residency

Primary data location: Canada

All customer data is stored in the AWS Canada (Central) region (ca-central-1) via Supabase. Your messages, contacts, files, and conversation metadata never leave Canadian soil for storage.

Cross-border processing

When AI features are enabled (with explicit consent), message content may be temporarily processed by AI providers in the United States. Data is transmitted via encrypted channels, stripped of unnecessary identifiers, and not retained by AI providers beyond the processing request.

Security measures

Encryption
  • AES-256 encryption at rest for all stored data
  • TLS 1.3 (minimum 1.2) for all data in transit
  • Per-workspace encryption key isolation
  • End-to-end encryption option for privileged channels
Access Control
  • Row-level security (RLS) policies on all data tables
  • Branch-scoped participant access control
  • Role-based access (founder, member, guest, AI)
  • Conversation-level invite authority restrictions
Audit & Monitoring
  • Immutable audit trail for all actions (communication_events)
  • Dedicated compliance audit log for privacy operations
  • Real-time monitoring for breach detection
  • Exportable logs for regulatory review
Data Protection
  • Message immutability with timestamped addenda pattern
  • Legal hold capability to prevent deletion during litigation
  • Configurable retention policies per data type
  • Certified deletion with audit proof

Sub-processor list

The following third-party service providers process personal information on behalf of Forismo. All sub-processors are bound by Data Processing Agreements (DPAs).

ProviderPurposeLocationDPACertifications
SupabaseDatabase infrastructure, authentication, file storageCanada (AWS ca-central-1)SignedSOC 2 Type II
VercelApplication hosting, edge functions, CDNGlobal (edge network)SignedSOC 2 Type II
Modulate.aiVoice transcription (Velma STT)United StatesSignedSOC 2 Type II
xAIGrok AI summaries and server-side semantic analysisUnited StatesSignedSOC 2 Type II
TwilioSMS and voice channel delivery via Twilio PSTNUnited StatesSignedSOC 2 Type II
ResendTransactional email deliveryUnited StatesSignedSOC 2 Type II

Exercise your rights

Under PIPEDA, Quebec Law 25, and CCPA/CPRA, you have the right to access, correct, delete, or port your personal information. Submit a request:

  • Through your account settings (Settings > Privacy)
  • By emailing privacy@forismo.com
  • We acknowledge requests within 48 hours and fulfill within 30 days

Documentation

Contact

For security inquiries: security@forismo.com
For privacy inquiries: privacy@forismo.com
For legal inquiries: legal@forismo.com

Forismo

Communication, simplified.

UpperOps™ — Run dispatch, workflow, and job coordination in one unified system.

UpperBooks™ — Invoicing simplified. AI-powered. Human-controlled.

Forismo Messaging — Context-aware messaging across app, SMS, email, and voice.

Forismo Training — Practical learning and Red Seal exam prep for skilled professionals.

Forismo Communities — Verified professional networks built on structured conversation.

Product

© 2026 Forismo. All rights reserved.