2Labs Advisory
2Labs hosts customer data on Microsoft Azure in Canadian regions. Products are multi-tenant with isolation enforced in the data access layer and verified by an automated adversarial test suite. Data is encrypted in transit and at rest, customers can export everything at any time, and 2Labs does not use customer data to train AI models. 2Labs does not currently hold SOC 2 or ISO 27001 certification.
Trust

Security & data residency

What we do, what we test, and — because it matters more — what we do not claim.

Customer data is hosted on Microsoft Azure in Canadian regions. Products are multi-tenant with isolation enforced in the data access layer and verified by an automated test suite. Data is encrypted in transit and at rest. You can export everything at any time.

How we handle your data

Data residency

Application data and file storage sit in Azure Canadian regions. Some operational services — email delivery, payment processing — may process limited data elsewhere; we will name the providers relevant to your engagement on request.

Tenant isolation

One deployment serves many organizations. Isolation is enforced in the data access layer rather than trusted to application code, and an adversarial test suite attempts cross-tenant access on every change. A failure blocks the release.

Encryption

TLS in transit. Encryption at rest through Azure platform services. Secrets held in managed key storage rather than configuration files.

Access control

Role-based access within each organization. Administrative access by our staff is limited to what support requires and is logged.

Websites we build

Public sites are static. There is no content management system running on the public site, which removes an entire category of vulnerability and patching burden.

AI and your data

Where AI features process your content, it is to perform the task you asked for. Your data is not used to train third-party models, and we do not permit our providers to do so.

Being straight about it

What we do not claim

We do not hold SOC 2 Type II or ISO 27001 certification. We are a small company, those audits are expensive, and we would rather tell you plainly than imply coverage we do not have.

What we can do is walk you or your IT provider through the actual controls, answer a security questionnaire honestly, and tell you where we would be weaker than a large vendor. If certification is a hard requirement for your organization, we are not the right choice yet — and we will say so rather than waste your procurement cycle.

Reporting a vulnerability

If you believe you have found a security issue, email hello@2labs.ca with the details. We will acknowledge within two business days. We will not pursue action against anyone who reports a genuine issue in good faith and does not access or alter other customers’ data.

Security questions

Where is our data stored?

In Microsoft Azure Canadian regions.

Is our data separated from other customers?

Yes. The products are multi-tenant with tenant isolation enforced in the data access layer and covered by an automated test suite that runs on every change.

Do you use our data to train AI models?

No, and we do not permit our providers to either.

Can we get our data out?

Yes, at any time, in a documented format. There is no exit fee.

What happens if there is a breach?

We will notify affected customers and the appropriate regulator where a breach creates a real risk of significant harm, and tell you what we know as we know it.

Do you have SOC 2 or ISO 27001?

Not today. We are a small company and we would rather say so than imply otherwise. We can walk you through our actual controls.

Need to complete a security review?

Send us the questionnaire. We will answer it honestly, including the parts where the answer is no.