Union data is the most sensitive data there is. Here's how we protect it.
Unionsuite holds salaries, contact details, and grievances. Here is exactly how that data is kept safe: where it lives, who touches it, and how you get it back.
Data Security & Compliance Report
Our full security architecture and control environment — single-tenant isolation, encryption in transit and at rest, passwordless access control, per-record audit trails, and the complete data lifecycle — mapped control-by-control to the SOC 2 Trust Services Criteria and ISO/IEC 27001:2022, on certified Canadian infrastructure.
Architecture and single-tenant isolation
- Every union gets its own isolated database, file storage, and web address. Nothing is co-mingled with another union's data in a shared table or bucket.
- Isolation is architectural, not a policy toggle: another union's configuration, import, or error cannot reach your data.
- Each workspace updates on its own schedule, so one union's change never disturbs another's.
Authentication and access control
- Passwordless sign-in: you receive a one-time, rate-limited code by email, there are no passwords to leak, reuse, or phish. Only addresses on your union's access list can request a code.
- Role-based permissions: 4 base roles refined by 47 granular capabilities, down to which blocks of a member profile someone can see, so a role can edit contact details while never seeing salary.
- The server enforces who-sees-what, regional scoping is applied to every list and export, not just hidden on screen, and an optional second sign-in step is available.
Data protection
- Encryption in transit and at rest.
- Row-level security in the database, so records are filtered at the data layer regardless of the request.
- Automatic backups, plus a manually saved copy of the data before every bulk operation, and signed, time-limited links for file access.
- 99.9% uptime, guaranteed in writing. No unplanned outages since launch, on enterprise-grade systems (Supabase + Vercel).
Data residency
- Member personal data is stored in Canada, in a Canadian data centre, on every plan, not only Enterprise.
- Limited operational data (such as error diagnostics) may be processed by subprocessors outside Canada under their contractual safeguards; member records stay hosted in Canada.
Subprocessors and their certifications
- Supabase, managed Postgres database, file storage, and authentication, in a Canadian region; runs on SOC 2 / ISO 27001-certified infrastructure.
- Vercel, application hosting and CDN; runs on SOC 2-certified infrastructure.
- Resend, transactional and bulk email delivery. Sentry, error and performance monitoring.
- Anthropic (Claude), powers the optional AI assistant. Each subprocessor is bound by contract and may use your data only to provide its service to us; we give advance notice before changing a subprocessor that handles member data.
Monitoring, audit logs, and certification roadmap
- Per-record audit logs tie every create, edit, and delete to a person, with who, what, and when; grievance cases keep their own history.
- We monitor errors and performance continuously so problems are caught early.
- Unionsuite is hosted on SOC 2- / ISO 27001-certified infrastructure (Supabase, Vercel). Independent third-party certification of Unionsuite itself is planned; we do not claim Unionsuite holds SOC 2 or ISO 27001 today. Our handling is aligned with PIPEDA.
AI data handling
- The optional AI assistant reads only Unionsuite's own product documentation: the help manual and the public pricing and offer pages. That is the entire scope of what it can see.
- It has no access to your union's data. It cannot read or look up member records, grievances, messages, files, or audit logs, and it makes no automated decisions about members.
- Member data is never sent to, shared with, or used to train Anthropic's or any other third party's AI models.
- AI is entirely optional. If your union would rather not use it, we leave it off, and the platform runs fully without it.
Responsible disclosure and breach notification
- Found a vulnerability? Report it to security@unionsuite.net and we'll work with you to confirm and fix it.
- If a breach affects your union's data, we will notify your union without undue delay, with what we know and what we're doing about it.
Six claims, and exactly what's behind them.
A reviewer shouldn't have to take a checklist's word for it. Here is what each promise on this page actually means.
One union, one setup
Every union runs its own separate setup: its own database, file storage, web address, and email address. There is no shared database, so another union's setup cannot reach your data. The separation is structural, enforced by the architecture rather than by policy.
- A database, storage, and hosting just for your union, never shared
- The database blocks all direct access by default; browsers read and write nothing on their own
- Verified email addresses, so every email leaves under your union's name
- Each union updates on its own, so one union's upgrade never disturbs another's
Sign-in without passwords
Staff sign in with a one-time 6-digit code we email them. There are no passwords to leak, reuse, or phish. Only addresses on the union's access list can even ask for a code, and strict limits on attempts make guessing impractical. "Trust this device" keeps a personal machine signed in for 60 days.
- Code requests are refused for any email not on the access list
- Limits: 5/min and 20/hour per network, 5 per 10 minutes per email
- Trusted devices stay signed in for 60 days, and you can revoke them anytime
- An optional second sign-in step for unions that want one
47 access settings, scoped to role, region, and branch
Four base roles, admin, regional VP, branch executive, member, refined by 47 named access settings, down to which blocks of a member profile someone can see. A role can edit contact fields while never seeing salary. Regional VPs are held to their own region by the server, in every list and export, no matter what the request asks for.
- Each profile block controlled on its own: salary, home address, and sensitive dates each separate
- Per-person changes can override role settings, managed live in Role Management
- Changes apply in about 30 seconds, with no rebuild
- The server enforces who-sees-what; it isn't just hidden on screen
Everything leaves a trail
Every create, edit, and delete is tied to a person. Hand edits and bulk imports land in the same member history log, with who, what, and when. Grievance case files keep their own history log, deadline extensions included. Before any import applies, the whole list is saved as a spreadsheet to a dated location, a guaranteed point you can recover from.
- Member and branch history logs; imports are tied to a person just like hand edits
- A history log per grievance case; agreed extensions stamped and logged
- A saved copy of the list before every bulk import
- A safety check: the apply stops if a colleague edited the data during your review
Hosted in Canada
Member data is stored in Canada, in a Canadian data centre, scrambled both while it travels and while it sits. It runs on managed infrastructure with automatic backups, plus manual saved copies before every bulk operation. No unplanned downtime since launch.
- Canadian data centre for member data
- Data scrambled in transit and at rest
- Automatic backups, plus manual saved copies before bulk operations
- 99.9% uptime, guaranteed, on enterprise-grade infrastructure
If you ever leave, you leave with everything
Leaving is planned, and the order is deliberate: export first, revoke second, delete last. You get a full copy of your database, every stored file, and plain spreadsheet files anyone can open, handed over and confirmed in writing. Then we delete it on a date we agree on. Long before that day, you can export any list to spreadsheet, Excel, or PDF yourself, any time.
- A planned exit: export first, revoke second, delete last
- A full export on request at any time, no charge, no hassle
- Export anything yourself to spreadsheet, Excel, and PDF, anytime
- Deletion on an agreed schedule, confirmed in writing
Ask us anything, including the hard questions.
Vendor questionnaire, privacy review, or a board that wants specifics: a real person answers, fast.