For financial institutions

Trust & Security

We are asking financial institutions to put their members' data through software we wrote. This page says what we do about that, and what we have not done yet.

Who we are

ENOM Technologies Inc. is a corporation registered in the Province of Alberta, Canada. Our office is at 103-11440 Ellerslie Road SW, Edmonton, Alberta. Business number and corporate registry details are available on request.

Where data lives

Member data is processed and stored in a Canadian region — a data centre in Toronto, Canada. We do not replicate production data outside Canada.

How we build

  • Access to production systems is limited to named individuals and requires multi-factor authentication.
  • Credentials and keys are held in a managed secrets store, never in source control.
  • All traffic is encrypted in transit; data is encrypted at rest.
  • Changes reach production through version control, and every release must pass an automated build and type-check before it can deploy.
  • We do not log, store or transmit authentication secrets in plain text.

Certifications — current status

We hold no third-party security certification today. We are a small firm that has not yet taken a production financial deployment, and we would rather say so than imply otherwise.

Ahead of any production engagement we will complete:

  • SOC 2 Type I, then Type II over the following observation period.
  • An independent penetration test of the platform, with the report available to clients under NDA.
  • Cyber liability and errors-and-omissions insurance at coverage levels agreed with the client.

For a pilot or proof of concept using test data only, none of the above is on the critical path. For production member data, all of it is, and we will not ask a client to waive it.

Accessibility

We aim to build against WCAG 2.1 Level AA, and a formal accessibility audit is on our roadmap below. If you encounter a barrier, write to support@enomtechnologies.ca and we will respond within five business days.

Security contact

Security questions, vulnerability reports and vendor due-diligence questionnaires: support@enomtechnologies.ca.

On our roadmap

Things we are building toward and will only claim once they ship:

  • SOC 2 Type I and Type II, independent penetration test, and cyber/E&O insurance.
  • A formal WCAG 2.1 AA accessibility audit.
  • Bilingual (English and French) interface, disclosures and notifications.
  • Cost-of-borrowing disclosure presented before a member consents, and retained afterwards.