COMPANY

Trust and Security

CredScape holds institutional data and a research corpus that customers rely on for planning decisions. This page sets out how that data is governed, where it lives, and who controls access to it.

A dean asking a reasonable question, such as who else in the province teaches this and at what price, has had no efficient way to answer it.

Who you are contracting with

CredScape is operated by CredScape Market Intelligence Inc., a federally incorporated Canadian company under the Canada Business Corporations Act, registered extraprovincially in British Columbia. The company is based in Kelowna, British Columbia.

Where your data lives

All application data is stored in Canada, in the ca-central-1 region, on managed PostgreSQL. Customer data is not replicated outside Canada.

Privacy law that governs us

We operate under British Columbia's Personal Information Protection Act (PIPA) as the governing provincial statute, alongside PIPEDA federally. Our privacy documentation is written against that framework rather than a generic international template, so the obligations it describes are the ones that actually apply to a British Columbia company handling Canadian institutional data.

Published policies:

Access controls

Every table holding customer or organizational data enforces PostgreSQL Row Level Security, so an account cannot read another organization's records even if an application-layer check were missed. Row Level Security is enabled on all public tables without exception.

Account protections enforced on every account:

  • Minimum password length of 12 characters.
  • Leaked-password protection, which rejects credentials found in known breach corpora.
  • Re-authentication required before a password change.
  • Sessions expire after 7 days of inactivity, and are hard-capped at 30 days regardless of activity.

Tenant isolation

Access is scoped to the organization. Seats are managed by your own administrator, who can add and remove members without contacting us, so access ends when your internal offboarding says it ends rather than when a support ticket is processed.

Backups

Database backups run daily on managed infrastructure with a 7-day retention window.

Incident handling

We maintain a written incident response procedure and a breach register. Breach records are retained for 5 years, which satisfies both the PIPEDA 24-month requirement and Quebec's Law 25.

How we treat the corpus

The offering data in CredScape is collected from public sources. We publish what the corpus covers and how it is built on our Methodology and Sources and Coverage pages, so an institution can assess the evidence base before relying on it. Institutions can request corrections or removal of their own records through our Data Requests process.

Contact

Security questions, vendor review requests, and privacy enquiries: support@credscape.io

Bring clarity to your next decision.

See the market context behind your next continuing education decision.

Get notified