What this page means
This Trust Centre is informational. Controls depend on the purchased service, selected providers, client requirements, and written agreement. A signed agreement may impose stricter or more specific requirements.
We do not claim SOC 2 or ISO certification, guarantee uninterrupted service, or promise that every provider stores data in Canada.
Security and access
Our approach may include least-privilege access, role-appropriate administration, multi-factor authentication where supported, encryption in transit and at rest where supported, controlled credential handling, and documented removal or transfer of delegated access.
Environment and data separation
Public demonstrations and development work should use synthetic or specifically approved test data. Client production information should be used only in approved environments and workflows with documented access and handling expectations.
Privacy and data location
We collect only what the work needs and use it for approved purposes. We can host a client deployment in Canada on infrastructure operated by SturdyCloud or on DigitalOcean infrastructure.
If you prefer another cloud provider, we can deploy to Microsoft Azure or Amazon Web Services. Google Cloud support is coming soon. We choose the provider and region with the client, based on data residency, integrations, performance, and regulatory requirements. We document material requirements for retention, deletion, backup, recovery, and cross-border processing before they become part of the service.
Read the privacy policy.
On-site hardware
SturdyCloud can source, install, and manage physical hardware at a client site. This gives the client direct physical control of the deployment. Before we order the equipment, we agree on site readiness, connectivity, access, power, security, backup, recovery, monitoring, maintenance, and support.
A solution can run on-site, in the cloud, or across both.
Providers and integrations
A client implementation may rely on cloud, communications, voice, AI, document, signing, payment, monitoring, or support providers. Providers are considered for security, privacy, reliability, data handling, accessibility, and operational fit. Material dependencies should be identified in the applicable proposal or statement of work.
Reliability, backup, and continuity
Availability, backup, recovery, monitoring, support, and exit arrangements depend on the selected service. Required recovery targets, support windows, ownership boundaries, and restoration responsibilities must be confirmed in writing.
Responsible AI
AI assists with defined tasks and remains subject to human review. Higher-risk uses require stronger testing, review, approval, and escalation. AI should not independently make legal, financial, employment, health, safety, or other material decisions.
Read the AI usage and data governance policy.
Accessibility
SturdyCloud builds accessibility into the work from the start. We use the four WCAG principles: Perceivable, Operable, Understandable, and Robust. For client-facing experiences, we design and test toward WCAG 2.2 Level AA. The work may include semantic structure, keyboard access, visible focus, colour contrast, responsive reflow, reduced motion, captions, transcripts, and clear link names.
When an implementation focuses on a specific vision, hearing, motor, or cognitive need, we can select relevant WCAG 2.2 Level AAA criteria and add user testing. We agree on the criteria, user journeys, test methods, and evidence in writing. Level AAA is not a practical blanket target for every page or product.
Automated and technical checks do not establish formal conformance or identify every barrier. Accessibility feedback can be sent to contact@sturdycloud.ca.
Incident and inquiry handling
Security, privacy, AI, procurement, and accessibility concerns can be sent to contact@sturdycloud.ca. We assess reported issues, contain impact where needed, and update controls or documentation when appropriate.