Encryption by default
Traffic runs over HTTPS and data at rest is encrypted at our hosting providers.
How we protect the data, access and availability of our sites and platforms.
Updated: August 2026
To report a vulnerability, ask about our controls or request our security documentation as part of a tender, write to us.
info@poledigital.caTraffic runs over HTTPS and data at rest is encrypted at our hosting providers.
Every access is named, protected by two-factor authentication and limited to real need.
A documented process governs detection, remediation and communication.
Section 01
Security is treated as a design requirement, not a final step. It is owned by Pôle Digital Inc.'s technical leadership and reviewed at every significant change to our platforms.
Our practices align with recognized frameworks - OWASP for application development, least privilege for access, and Québec and Canadian personal information protection requirements.
Section 02
Access to environments, databases and hosting consoles is named, revocable and logged.
Section 03
Communications between your browser and our services are encrypted in transit (TLS). Data at rest is encrypted by our hosting and database providers.
Application secrets - API keys, tokens, service passwords - are kept in dedicated vaults, never in source code. We apply minimization: only the data necessary for the request is collected and retained.
Section 04
Our platforms rely on established cloud providers, with redundancy, automated backups and environment isolation.
When a project requires it, we favour data hosting in Canada and document any transfers to other jurisdictions.
Section 05
Every change goes through code review, automated tests and traceable deployment. Dependencies are monitored and updated to fix known vulnerabilities.
The site's forms validate data server-side, apply rate limiting and protect against injection and automated submissions.
Section 06
Administrative access and sensitive operations are logged. Alerts flag application errors, abnormal traffic spikes and suspicious authentication attempts.
Logs are retained for a limited period, sufficient to analyze an incident, then deleted.
Section 07
In the event of a security incident, we apply a documented process: immediate containment, impact assessment, remediation, then root-cause analysis.
Section 08
We select our vendors - hosting, transactional email, analytics tools, artificial intelligence services - based on their security and privacy commitments.
Data is shared only with the providers necessary for delivery, under agreements governing their use. Recipient categories are detailed in our privacy policy.
Section 09
If you discover a flaw on one of our sites or platforms, write to info@poledigital.ca with a description, reproduction steps and, if possible, technical evidence.
We ask that you not exploit the flaw beyond demonstration, not access data that is not yours, and allow us a reasonable period to fix it before any publication. We acknowledge receipt promptly and keep the reporter informed of the fix.
A security question
We answer security questionnaires and provide the documentation required by your procurement or compliance processes.