Skip to main content
Pôle Digital
Security practices

Security

How we protect the data, access and availability of our sites and platforms.

Updated: August 2026

Security contact

To report a vulnerability, ask about our controls or request our security documentation as part of a tender, write to us.

info@poledigital.ca

The essentials in three points

Encryption by default

Traffic runs over HTTPS and data at rest is encrypted at our hosting providers.

Least-privilege access

Every access is named, protected by two-factor authentication and limited to real need.

Managed incidents

A documented process governs detection, remediation and communication.

Section 01

Security governance

Security is treated as a design requirement, not a final step. It is owned by Pôle Digital Inc.'s technical leadership and reviewed at every significant change to our platforms.

Our practices align with recognized frameworks - OWASP for application development, least privilege for access, and Québec and Canadian personal information protection requirements.

Section 02

Access control

Access to environments, databases and hosting consoles is named, revocable and logged.

Two-factor authentication
Mandatory on administrative accounts, code repositories and cloud consoles.
Roles and segregation
Rights are assigned by role, with separation of development, test and production environments.
Periodic review
Accounts and permissions are reviewed regularly and removed as soon as an engagement ends.

Section 03

Data protection and encryption

Communications between your browser and our services are encrypted in transit (TLS). Data at rest is encrypted by our hosting and database providers.

Application secrets - API keys, tokens, service passwords - are kept in dedicated vaults, never in source code. We apply minimization: only the data necessary for the request is collected and retained.

Section 04

Hosting and infrastructure

Our platforms rely on established cloud providers, with redundancy, automated backups and environment isolation.

When a project requires it, we favour data hosting in Canada and document any transfers to other jurisdictions.

Section 05

Secure development and deployment

Every change goes through code review, automated tests and traceable deployment. Dependencies are monitored and updated to fix known vulnerabilities.

The site's forms validate data server-side, apply rate limiting and protect against injection and automated submissions.

Section 06

Logging and monitoring

Administrative access and sensitive operations are logged. Alerts flag application errors, abnormal traffic spikes and suspicious authentication attempts.

Logs are retained for a limited period, sufficient to analyze an incident, then deleted.

Section 07

Incident management

In the event of a security incident, we apply a documented process: immediate containment, impact assessment, remediation, then root-cause analysis.

Notification
Affected clients are informed without undue delay, with the known facts and measures taken.
Legal obligations
Any confidentiality incident presenting a serious risk is handled in accordance with applicable Québec requirements.
Continuous improvement
Each incident leads to lasting technical or organizational fixes.

Section 08

Vendors and processors

We select our vendors - hosting, transactional email, analytics tools, artificial intelligence services - based on their security and privacy commitments.

Data is shared only with the providers necessary for delivery, under agreements governing their use. Recipient categories are detailed in our privacy policy.

Section 09

Report a vulnerability

If you discover a flaw on one of our sites or platforms, write to info@poledigital.ca with a description, reproduction steps and, if possible, technical evidence.

We ask that you not exploit the flaw beyond demonstration, not access data that is not yours, and allow us a reasonable period to fix it before any publication. We acknowledge receipt promptly and keep the reporter informed of the fix.

A security question

Need our controls for your file?

We answer security questionnaires and provide the documentation required by your procurement or compliance processes.

  • Encryption in transit and at rest on all our platforms
  • Two-factor authentication mandatory on administrative access
  • Documented process for reporting and fixing vulnerabilities