Security and privacy, in plain words
Information is stored and processed in Canada, encrypted, and deleted once you’ve filed it. Here is exactly what that means — including the limits.
- 🇨🇦 Stored in CanadaAWS Montréal
- 🔐 Encryptedat rest and in transit
- 🗑️ Deleted on schedule35 days at most
- 📋 Every action loggedexportable audit trail
Stored in Canada
Every record, file, answer and login lives in Amazon Web Services’ Montréal region (ca-central-1). The service is set up so it cannot be deployed anywhere else.
Encrypted
At rest with a dedicated encryption key, and in transit with HTTPS only.
Scanned
Uploads land in a separate quarantine store and are scanned for malware; your team can only open clean copies.
Deleted on a schedule
Files: when filed, a set time after download, or unclaimed — 35 days at most, never backed up. Names and contact details: 90 days after a request closes. Database backups age out 35 days later. Audit log: 2 years.
Signed in twice
Every user needs a password and an authenticator-app code. Breached passwords and risky sign-ins are blocked.
Upload-only links
A link can only upload. It never shows other files or other people.
Every action on record
Who sent, opened, uploaded, downloaded and deleted what — without personal details in the log. Your admins can export it.
Nothing sensitive in messages
Emails and texts carry your organization’s name, the secure link and its expiry — the first name only if you turn that on.
You stay in charge
Your organization is responsible for the personal information it collects, under PIPEDA or the provincial law that applies to you (for example BC PIPA). SealDrop is your service provider and handles it only on your instructions, under a data processing agreement. We never sell data, use it for advertising, or train AI on it. The tools the SealDrop team uses show account settings and counts only — never people, files or answers.
Being precise
- Emails and texts pass through the recipient’s own email or phone provider, which may be outside Canada — that is why they carry nothing sensitive.
- The web certificate for our addresses (domain names only, no data) is issued in AWS’s US East region, as required by the content network.
- There is no official certification for PIPEDA or BC PIPA. We say “built to help you meet your obligations”, and give you the documents to check it: the privacy policy, a data processing agreement and a privacy impact summary.
- Health information may also fall under provincial health privacy laws; clinics and practitioners stay the custodian of their records.
- Our hosting provider’s ISO 27001 and SOC 2 certifications are AWS’s own, not SealDrop’s.
Privacy questions: reach our Privacy Officer at privacy@sealdrop.ca.
Questions
Is the information stored in Canada?
Yes. SealDrop stores and processes it in AWS’s Montréal region and cannot be deployed to another region.
Who can see the documents?
Only signed-in staff of your own organization. The tools the SealDrop team uses show account settings and counts only — never people, files or answers.
Can we get a data processing agreement?
Yes. Every customer signs a data processing agreement that makes SealDrop its service provider.