Security & data residency
What we do, what we test, and — because it matters more — what we do not claim.
Customer data is hosted on Microsoft Azure in Canadian regions. Products are multi-tenant with isolation enforced in the data access layer and verified by an automated test suite. Data is encrypted in transit and at rest. You can export everything at any time.
How we handle your data
Data residency
Application data and file storage sit in Azure Canadian regions. Some operational services — email delivery, payment processing — may process limited data elsewhere; we will name the providers relevant to your engagement on request.
Tenant isolation
One deployment serves many organizations. Isolation is enforced in the data access layer rather than trusted to application code, and an adversarial test suite attempts cross-tenant access on every change. A failure blocks the release.
Encryption
TLS in transit. Encryption at rest through Azure platform services. Secrets held in managed key storage rather than configuration files.
Access control
Role-based access within each organization. Administrative access by our staff is limited to what support requires and is logged.
Websites we build
Public sites are static. There is no content management system running on the public site, which removes an entire category of vulnerability and patching burden.
AI and your data
Where AI features process your content, it is to perform the task you asked for. Your data is not used to train third-party models, and we do not permit our providers to do so.
What we do not claim
We do not hold SOC 2 Type II or ISO 27001 certification. We are a small company, those audits are expensive, and we would rather tell you plainly than imply coverage we do not have.
What we can do is walk you or your IT provider through the actual controls, answer a security questionnaire honestly, and tell you where we would be weaker than a large vendor. If certification is a hard requirement for your organization, we are not the right choice yet — and we will say so rather than waste your procurement cycle.
If you believe you have found a security issue, email hello@2labs.ca with the details. We will acknowledge within two business days. We will not pursue action against anyone who reports a genuine issue in good faith and does not access or alter other customers’ data.
Security questions
Where is our data stored?
In Microsoft Azure Canadian regions.
Is our data separated from other customers?
Yes. The products are multi-tenant with tenant isolation enforced in the data access layer and covered by an automated test suite that runs on every change.
Do you use our data to train AI models?
No, and we do not permit our providers to either.
Can we get our data out?
Yes, at any time, in a documented format. There is no exit fee.
What happens if there is a breach?
We will notify affected customers and the appropriate regulator where a breach creates a real risk of significant harm, and tell you what we know as we know it.
Do you have SOC 2 or ISO 27001?
Not today. We are a small company and we would rather say so than imply otherwise. We can walk you through our actual controls.
Need to complete a security review?
Send us the questionnaire. We will answer it honestly, including the parts where the answer is no.