Trust centre
Security, privacy, accessibility and legal information in one place.
WCAG 2.2 AA
The CredScape application conforms to WCAG 2.2 Level AA.
Read the accessibility statementSecurityScorecard: A, 100/100
A perfect score on SecurityScorecard's independent external security rating, as of October 2, 2026.
View our live scorecardHECVAT 4.1.6
Self-assessment available to institutions on request.
Request itCanadian privacy law
Built for PIPEDA, British Columbia's PIPA and Quebec's Law 25.
Read the privacy policyData stored in Canada
Customer data is stored in Canada (Supabase, Montreal region; our own server in Quebec). Some services process data elsewhere; each is listed on the subprocessors page.
View subprocessors
Who you are contracting with
CredScape is operated by CredScape Market Intelligence Inc., a federally incorporated Canadian company under the Canada Business Corporations Act, registered extraprovincially in British Columbia. The company is based in Kelowna, British Columbia.
Where your data lives
We store account records, the program corpus and search indexes in Canada, in the ca-central-1 region, on managed PostgreSQL. Our own search server is in Quebec. Some supporting services, such as email, analytics, error monitoring, billing and support, process data outside Canada. Each is listed on our subprocessor page.
Privacy law that governs us
We operate under British Columbia's Personal Information Protection Act (PIPA) as the governing provincial statute, alongside PIPEDA federally. Our privacy documentation is specific to this framework and describes the obligations that apply to a British Columbia company handling Canadian institutional data.
Published policies:
- Privacy Policy
- Terms of Service
- Acceptable Use Policy
- Data Requests, Corrections and Takedowns
- Privacy Governance Policy
- Subprocessors
Access controls
Every table in our application schema enforces PostgreSQL Row Level Security. This prevents an account from reading another organization's records even if an application-layer check is missed.
Every account has these protections:
- Minimum password length of 12 characters.
- Leaked-password protection, which rejects credentials found in known breach corpora.
- Re-authentication required before a password change.
- Sessions expire after 7 days of inactivity and have a maximum duration of 30 days regardless of activity.
Time-based one-time password (TOTP) multi-factor authentication is available on every account.
Backups
Database backups run daily on managed infrastructure with a 7-day retention window. We also keep weekly off-platform backups for 90 days and test restores quarterly. Our recovery point and recovery time objectives are each 24 hours.
Incident handling
We maintain a written incident response procedure and a breach register. We retain breach records for 5 years, which satisfies both the PIPEDA 24-month requirement and Quebec's Law 25.
How we treat the corpus
We collect the offering data in CredScape from public sources. Our Methodology and Sources and Coverage pages explain what the corpus covers and how it is built. Institutions can use these pages to assess the evidence base before relying on it. Institutions can request corrections or removal of their own records through our Data Requests process.
Contact
Security questions and vendor review requests: support@credscape.io. Report a vulnerability to security@credscape.io. Privacy enquiries: privacy@credscape.io.