Compliance

Statutes, frameworks, and standards PostingPal aligns to. Items marked GAC Edition refer to the dedicated Canadian deployment, delivered before any Protected B data is loaded.

Met In progress Roadmap
FrameworkScopeNotes
PIPEDAPrivacy — private sectorPrivacy notice, access, correction, self-serve deletion, breach-notification commitment.
Official Languages ActEN/FR bilingualUI, emails, and public pages available in English and French. Ongoing parity for every new view.
Accessible Canada Act — WCAG 2.1 AAWeb accessibilitySemantic HTML, contrast, keyboard navigation, ARIA labels. Conformance audit scheduled before pilot.
ITSG-33 (Annex 3A)GC security controlsSSP/TRA/PIA mapped for GAC Edition, delivered with a sponsoring security authority before any Protected B pilot.
Protected BGC security categoryGAC Edition target. Canadian-region data, enforced MFA, Canadian-hosted AI.
SOC 2 Type 1Service controlsPlanned in parallel with GAC Edition.
OAuth 2.0 / OIDCFederated authGoogle and Apple today; SAML 2.0 GC SSO and PKI on roadmap.
TLS 1.2+ / AES-256EncryptionIn transit and at rest, including photo storage and backups.
Row-Level Security (RLS)AuthorizationPer-inventory isolation enforced by Postgres.
Append-only audit logTraceabilityInvitations, member changes, deletions, exports. Downloadable as CSV.
PCI DSS Level 1 (Stripe)PaymentsNo card data on our servers.

More detail: /security · /privacy · /vendor

Last updated May 15, 2026.