Skip to content

Security Practices

Screening data is some of the most sensitive information there is. Here's how we actually protect it: no buzzwords, no overclaiming.

Last updated: July 16, 2026

Our approach

We apply safeguards proportionate to the sensitivity of the information we handle, building on the operating experience of our parent company, Quality Credit Reporting, which has handled sensitive personal data under applicable privacy law since 1992. This page describes our actual practices. We don’t claim certifications we don’t hold.

Encryption

Data is encrypted in transit between your browser and our systems, and sensitive documents, such as ID copies and consent records, use authenticated AES-256 encryption at rest. Production also has a fail-closed deployment check requiring verified disk, snapshot and backup encryption.

Access control

Access to candidate information is limited by role to the people who need it to do their work, following the principle of least privilege. Every report carries a full append-only audit trail, so there is a record of who handled an order and what was done. Staff accounts require two-factor authentication, and financial documents are not available to investigators.

Data residency

Candidate data is hosted within North America. Our Privacy Policy describes how information is collected and shared, and our Data Retention Policy covers how long it’s kept.

Our people

Screening is performed by trained specialists who work under confidentiality obligations. Every report is reviewed and signed off by a person before release. Nothing reaches an employer unchecked.

Service providers

Where service providers help us operate the platform, vendors that handle personal information are bound by contractual confidentiality and security obligations consistent with this page.

Incident response

We investigate any suspected security incident and keep records of privacy breaches as PIPEDA requires. Where a breach of security safeguards creates a real risk of significant harm to individuals, we notify the affected individuals and the Office of the Privacy Commissioner of Canada as soon as feasible, and provincial regulators where their laws require it.

Documents, resilience and monitoring

Uploaded files are identified by their actual content, scanned for malware, served only as sandboxed downloads and never trusted from a filename or browser-provided media type. The production portal is configured to refuse startup until encrypted backups, monitoring and infrastructure encryption have been verified by the system owner.

Reporting a concern

If you believe you’ve found a security issue with our website or platform, or have a question about these practices, contact us at order@qcsl.com. We take every report seriously.