Our commitments
Security controls
These are the safeguards running across the platform, from encryption and isolation to monitoring and training. The FAQ below explains each in plain language.
Data security 5 controls
- ✓Encryption in transit. HTTPS with TLS 1.2 or higher for users and between platform components.
- ✓Encryption at rest. AES-256 across database, file storage and backups.
- ✓Client isolation at the database layer. Row-level security policies enforced by the database engine, independent of application code.
- ✓Continuous encrypted backups. Point-in-time recovery for the database on AWS-managed infrastructure.
- ✓Eleven-nines storage durability. Files and backups in Amazon S3, stored redundantly across availability zones.
Access control 5 controls
- ✓Role-based access (RBAC). Least-privilege roles down to project, workspace, work process and record level, managed by your administrators.
- ✓Managed identity service. Authentication runs on AWS's managed identity service, with an individual named account for every user.
- ✓MFA for your users. Supported and enforceable across your organization at your discretion. SSO integration is available on request as a paid add-on.
- ✓Need-to-know internal access. Administrative access to production client data limited to named individuals, for support, incident response and agreed implementation work.
- ✓Privileged access logging. Operations that bypass normal tenancy controls are written to a separate audit log: who, when and why.
Application security 4 controls
- ✓Secure development lifecycle. Automated dependency and vulnerability scanning built into the build.
- ✓Security review of every change. Code review with security checks enforced before anything ships.
- ✓Highest-risk controls tested automatically. Client isolation, audit immutability and authentication are covered by automated tests that run on every change.
- ✓Append-only audit trail. Every record edit, approval and status change logged; the database rejects updates and deletes to the log.
Infrastructure & operations 4 controls
- ✓AWS-hosted, region of your choice. Agreed during implementation, with Canadian residency (ca-central-1) available.
- ✓Financially backed infrastructure SLAs. The AWS services beneath the platform each carry a financially backed AWS service level agreement.
- ✓Continuous monitoring. Logging, automated alerting and threat detection through AWS-native security services.
- ✓Incident response process. Identification, containment, investigation, remediation and post-incident review.
Data privacy 4 controls
- ✓You own your data. Files, records and extracted data remain your property; using the platform transfers no ownership to us.
- ✓Data minimization. We collect user account details plus what appears in the business content you bring in, nothing more.
- ✓PIPEDA compliance support. For Canadian clients, we support compliance with PIPEDA and provincial privacy laws.
- ✓Export and deletion on exit. Full export in standard formats for 30 days after termination, then secure deletion through the backup cycle.
Organizational security 3 controls
- ✓Security & privacy training. All personnel with production access complete it at onboarding and annually.
- ✓Confidentiality obligations. Binding on everyone with access to client data.
- ✓Reviewable privileged-access log. We walk your security team through it on request.
AI governance
AI in ImProHQ works under the same discipline as everything else on the platform. Every model must meet the same bar before it processes client data, and your people make the final call on every result.
Data boundaries 4 controls
- ✓No training on client data. Every model runs under no-training terms that the model companies publish themselves (OpenAI, Anthropic). We never use one client's data in another client's AI features.
- ✓Zero data retention. Model providers process the request and retain nothing.
- ✓Enterprise access only. Models run through business services or inside our own AWS environment; client data never touches consumer AI apps.
- ✓Minimum data per request. The AI reads the content being processed and that workflow's reference data, nothing more.
Oversight & control 4 controls
- ✓Human decision authority. AI extracts, deterministic rules validate, and your qualified people approve. Nothing is auto-approved.
- ✓Per-work-process control. You can enable, restrict or turn off AI for each work process independently.
- ✓Pinned model versions. Upgrades are tested for data handling and output quality before rollout.
- ✓Accuracy measured on your content. Extraction is tuned and measured against your real formats before a workflow goes live, and reviewer corrections keep improving it.
Subprocessors
Client data is handled by our cloud infrastructure and the AI models used for your deployment. Every subprocessor is independently audited; their attestations are published on their own compliance portals, linked below.
| Provider | Purpose | Location | Independent attestations |
|---|---|---|---|
| Amazon Web Services | Hosting, storage, database, authentication, email delivery | Your deployment's agreed AWS region; Canadian residency (ca-central-1) available | SOC 1/2/3, ISO 27001/27017/27018 and more |
| AI model company (per deployment) | AI extraction and analysis for your workflows | United States | SOC 2 Type 2, ISO 27001, ISO/IEC 42001: trust.openai.com · trust.anthropic.com |
Frequently asked questions
These are the questions IT and cybersecurity teams most often ask us when evaluating ImProHQ, answered directly, so our enterprise clients can complete their review quickly. If your team needs more, we will complete your vendor security questionnaire or meet with them directly.
Hosting & data protection
Q1Where is our data stored, and can we choose the region?
ImProHQ is a cloud SaaS platform hosted entirely on Amazon Web Services. Your deployment's AWS region is agreed during implementation; your data is stored and processed in that region. Canadian data residency (AWS ca-central-1) is available for clients with Canadian residency requirements, subject to AWS service availability in the region.
Q2Is our data encrypted?
Yes, both in transit and at rest. All traffic between users and the platform runs over HTTPS with TLS 1.2 or higher, and the same encryption protects traffic between platform components. All stored data is encrypted with AES-256, covering the database, document storage, and backups.
Q3How is our data separated from other ImProHQ clients?
Client separation is enforced at the database layer, not just in application code. Every database query runs under row-level security policies enforced by the database engine, so it can only ever return your organization's data. This holds independently of the application code above it, giving defense in depth rather than a single point of failure.
Within your environment, what each of your own users can access is controlled by role (Q13).
Q4Is there an audit trail of changes and user actions?
Yes. Every change is recorded with who made it, what changed and when: record edits, approvals, status changes and other user actions.
The audit trail is append-only. It cannot be edited or deleted by anyone, including ImProHQ administrators; the database itself rejects any attempt. For processes like inspection acceptance and sign-offs, this gives you a complete history you can rely on.
Data ownership & privacy
Q5Who owns the data we put into ImProHQ?
You do. Documents, records, reports, attachments, extracted data and anything else you upload or generate in ImProHQ remain your property. Joras Technologies owns the platform and its software; using the platform transfers no ownership of your data to us.
Your data is treated as confidential and used only to deliver the service to you. The only third parties that process it are the subprocessors required to operate the service (Q18), each bound by the same confidentiality and data-protection obligations.
Q6What personal information does ImProHQ handle?
Deliberately little; we practice data minimization. The platform stores user account details (name, work email) and whatever personal information appears inside your business documents, for example inspector names, signatures and certification numbers on inspection reports. That information is protected by the same encryption, tenancy isolation and access controls as all other client data, and is processed only to deliver the service. For Canadian clients, we support compliance with PIPEDA and provincial privacy laws.
Q7What happens to our data if we stop using ImProHQ?
On termination or expiry, your data is available for export in usable, standard formats (structured data plus your original documents) for 30 days. After the export window it is securely deleted from production systems, and from backups as the backup rotation cycle completes. You can also export your data yourself at any time during the subscription.
How ImProHQ uses AI
Q8Which AI models process our data?
ImProHQ is built on a constellation of enterprise-grade AI models: frontier models (the family behind tools like ChatGPT and Claude), open-weight models, and models fine-tuned for specific workflows. We select the best model for each task, and every model must meet the same bar before it processes client data:
- No training. Your inputs and outputs are never used to train the model.
- Zero data retention. Data is used to process the request and is not retained by the model company.
- Independently certified. SOC 2 Type 2, ISO 27001 and ISO/IEC 42001, the AI management standard; see trust.openai.com, trust.anthropic.com and aws.amazon.com/compliance.
- Enterprise access only. Models run through business services or inside our own AWS environment. Client data never touches free or consumer AI apps such as the public ChatGPT.
Q9Will our data be used to train AI models?
No, never. The AI model companies cannot train on your data (Q8), and we do not use your data to train models that benefit any other company. Your documents, prompts, extraction rules and configurations stay inside your environment, and one client's information is never used in another client's AI features. This is a design principle of the platform.
The AI model companies publish this commitment themselves: OpenAI's enterprise privacy page and Anthropic's privacy center both state that business customer data is not used to train their models.
Where we fine-tune a model on your data, for example extraction tuned to your report formats, the model is trained and hosted on AWS Bedrock inside our own AWS environment, and it serves only you. AWS Bedrock's data protection commitments state that customer content is not used to train the underlying models and is never shared with model providers.
Q10What data does the AI use?
Only the information its task needs. When AI processes an inspection report, it reads that report and the reference data configured for that workflow, nothing more. Each request carries the minimum data required: the principle of least privilege, applied to AI.
AI operates inside the same boundaries as everything else on the platform: your environment only, under the same database-enforced isolation (Q3). There is no shared AI memory or knowledge base spanning clients.
Q11AI can make mistakes. How do you make sure results are accurate?
It can, and we design for that. No AI output reaches a decision without passing through checks that are not AI:
- The AI only extracts. It reads a document and fills the fields defined for the workflow. Every value is stored beside its source document, so checking any value takes one glance.
- Deterministic rules verify. Extracted values are validated against your business rules and reference data by conventional software: same input, same result, every time.
- Your people decide. Anything that fails a check, is missing or looks uncertain goes to your subject-matter experts. Nothing is auto-approved.
Extraction accuracy is measured against your real documents before a workflow goes live, and every AI value and human correction is in the audit trail (Q4). Accuracy also improves over time: the corrections your reviewers make are used to tune extraction for your document formats and your use case, and any model tuned on your data serves only you (Q9).
Q12Can we decide where AI is used?
Yes, per work process. AI can be enabled, restricted or turned off for each work process independently, so you adopt it at the pace your governance allows. The platform's workflow, records and audit functions work the same either way.
Model versions are pinned in production; upgrades are tested for data handling and output quality before rollout, and every model must meet the same bar before it touches client data (Q8).
Access & authentication
Q13Can we control what our users can see and do?
Yes. Access within your environment is role-based (RBAC). Your administrators assign each user a role, and roles determine what that user can see and do, down to the project, workspace, work process and record level. A field inspector, a QC reviewer and an executive each get exactly the access their job needs, and nothing more: the principle of least privilege.
Roles and permissions are set up with you during implementation, and your administrators manage users and roles afterwards without needing us.
Q14Do you support MFA and enterprise SSO?
MFA: yes, today.Authentication runs on AWS's managed identity service with individual named accounts; multi-factor authentication is supported and can be enforced for all of your users at your discretion.
SSO: available on request, as a paid add-on. SSO is not part of the standard subscription. Where an enterprise deployment requires integration with your identity provider (e.g., Microsoft Entra ID via SAML/OIDC), it is scoped and priced separately as part of the implementation plan.
Q15Who at Joras Technologies can access our data?
Only the engineers who operate the platform, and only for operational need. Administrative access to production client data is limited to named individuals on a need-to-know basis, used solely for legitimate purposes (support, incident response, agreed implementation work). Privileged operations that bypass normal tenancy controls are themselves written to a separate audit log: every such access is recorded with who, when and why, and we can walk your team through that log in a security review. All personnel with production access complete security and privacy awareness training at onboarding and annually, and are bound by confidentiality obligations.
Reliability, continuity & incidents
Q16Is our data backed up? What about availability and recovery?
Backups: continuous and encrypted. Automated backups run continuously on AWS-managed infrastructure, encrypted like all data at rest, with point-in-time recovery for the database. Documents and backups are held in Amazon S3 storage, which is designed for 99.999999999% (eleven nines) object durability, with data stored redundantly across multiple availability zones.
Availability: financially backed at the infrastructure layer. The AWS services beneath the platform (compute, database, storage) each carry a financially backed AWS service level agreement.
Q17How do you detect and respond to security incidents?
We maintain an incident response process covering identification, containment, investigation, remediation and post-incident review. Platform and infrastructure activity is continuously logged and monitored through AWS-native security services, with automated alerting and threat detection to surface suspected incidents early.
Assurance & working with us
Q18Who are your subprocessors?
Client data is handled by our cloud infrastructure (AWS) and the AI models used for your deployment. Every subprocessor is independently certified (SOC 2, ISO 27001 and related standards), and their audit reports are available from the compliance portals linked below.
| Provider | Purpose | Their attestations |
|---|---|---|
| Amazon Web Services | Hosting, storage, database, authentication, email delivery | SOC 1/2/3, ISO 27001/27017/27018, and more |
| AI model company (per deployment, see Q8) | AI document extraction and analysis | SOC 2 Type 2, ISO 27001, ISO/IEC 42001 (e.g. trust.openai.com, trust.anthropic.com) |
Q19Do you perform vulnerability scanning and penetration testing?
Vulnerability scanning: yes.Automated dependency and vulnerability scanning is built into our secure development lifecycle (SDLC), security checks are enforced in code review, and the platform's highest-risk controls (client isolation, audit immutability, authentication) are covered by automated tests that run on every change.
Penetration testing: scoped per engagement. If your organization requires independent third-party penetration testing as a condition of deployment, we will scope it into the engagement, and results are shared with your team under NDA.
Q20Our organization doesn't have an AI policy yet. Can you help?
Yes. Many of our clients are adopting AI-enabled tools for the first time, often without an internal AI governance framework in place. We can share a starter framework for an enterprise AI usage policy, grounded in the NIST AI Risk Management Framework and OWASP guidance for AI applications, along with the evaluation questions we see IT teams ask of AI vendors. It is yours to adapt as you see fit. We are also glad to join a working session with your IT, cybersecurity or governance team.
Documents & evidence
What we publish openly, and what we share directly with your review team on request.