Straight answers for your security review
Where the data lives, how it is protected, who can reach it and what is recorded when they do. Everything below describes the product as it runs today.
Six things to know
Hosted in Canada
Production runs in Microsoft Azure's Canada Central region. Backups are copied to a second Canadian region and kept for 35 days. There is no US or EU deployment, and the product will not label an account with a region it cannot store it in.
Encrypted in transit and at rest
Every connection uses TLS. Stored credentials, integration secrets and authenticator keys are encrypted with AES-256; recovery codes, one-time links and directory tokens are kept only as one-way hashes, so nobody at Solidlio can read them back.
Your directory decides who gets in
Single sign-on with Microsoft Entra ID or Google Workspace, directory provisioning from Entra ID or Okta, and authenticator-app two-factor for password accounts. Enforce SSO for an organization and password sign-in stops working for it.
Least privilege by default
Six role levels and per-organization membership decide what every request may touch. A provider reaches the clients that granted it access and nothing else; a client's staff never see provider-internal notes.
An audit trail nobody can edit
Every administrative action is recorded with who, what, when and from where. There is no way to change or delete an entry through the product, and co-management events are written to both sides so neither depends on the other's records.
Privacy rights, self-served
Anyone with a login can request a copy of their personal data or ask for it to be erased from their own portal page, on every plan. Each request has a 30-day deadline and a report of what was affected.
Hosted in Canada, with the exceptions named
Our hosting is in Canada. A small number of optional features rely on providers outside it, and a residency answer that leaves them out is not an answer.
| Feature | Where the provider is | What that means for you |
|---|---|---|
| AI features | United States | Ticket and document text sent for analysis. Can be left switched off. |
| Email delivery | United States | Outbound notifications and inbound email-to-ticket. |
| Card and bank payments | United States | Payment details go to the payment processor, never to Solidlio. |
Self-service on every plan, from every portal
A right that needs a support ticket is a request. These do not.
- Self-service export
- Anyone with a login can request a copy of their personal data as JSON or CSV from their own portal page, on every plan, without raising a ticket.
- What the export holds
- Their profile, memberships and roles, their tickets and their own comments, time entries, notifications, sign-in history, consents and previous requests.
- What it leaves out
- Other people's words on records they touched, and anything that would expose credentials.
- Erasure
- Runs against a published list of record types, stating what is deleted, what is anonymised and what is kept for a legal or financial reason, and returns a report of what was affected.
- Deadlines
- Every request carries a 30-day deadline, so the queue shows what is overdue rather than leaving it to be discovered.
Where we stand on certification
Solidlio produces the audit and privacy records that SOC 2, ISO 27001, PIPEDA and GDPR programmes rely on. Tridacom IT Solutions Inc. does not yet hold a SOC 2 or ISO 27001 certification for Solidlio, and we would rather say so here than let you find out in a questionnaire.
Every control described on this page is documented in detail in the linked feature pages, so your own advisers can assess them. If your procurement needs a formal report, raise it with us early.
What we will send you
- Answers to your security questionnaire, in writing
- The sub-processor list with locations and purposes
- Our terms of service and privacy policy
- A walkthrough of the audit trail and privacy tooling on a live account
What security reviews usually ask
Are you SOC 2 or ISO 27001 certified?
Not yet. Solidlio produces the audit and privacy records those programmes rely on, and Tridacom IT Solutions Inc. documents its controls openly on this page and in the feature pages it links to. If your procurement process needs a formal report, tell us early and we will discuss timing with you.
Can we choose a US or EU hosting region?
Not at present. Solidlio runs in Canada. An account cannot be labelled with a region it does not run in, so you will never be told your data is somewhere it is not.
Which features send data outside Canada?
AI assistance, outbound email delivery and card and bank payments each use a provider in the United States. AI assistance can be switched off entirely. The full sub-processor list names each provider, what it receives and why.
Can an administrator edit or delete the audit trail?
No. There is no way to change or remove an audit entry through the product. The two exceptions are narrow and recorded: a privacy erasure removes the person's IP address and browser details from their entries while keeping the action, and an optional retention policy can purge old entries for tenants not under legal hold.
If our provider and we disagree about when they had access, who has the record?
Both of you. Every co-management event is written to both accounts, so either side can show when access began, who granted it, who ended it and when the billing relationship moved.
Is the product accessible?
Accessibility is part of how we build. The product is developed against WCAG 2.2 AA, tested with automated tooling and keyboard walkthroughs, and this website has its own accessibility statement. A third-party audit of the product has not yet been completed; if you need a conformance report, ask us.
Send us the questionnaire before the demo.
Most of it is answered on this page and the pages it links to. The rest we will answer in writing.