Security & Privacy

GoComply stores compliance documentation for financial and insurance advisors. This page explains, in plain language, the protections that are in place today. It intentionally avoids technical detail that would not help you assess the platform.

Where your files live

GoComply's database and document storage are hosted in Amazon Web Services (AWS) data centres through our managed cloud infrastructure provider, which holds SOC 2 Type 2 and ISO 27001 certifications. Files are not stored on personal computers, email inboxes or third-party e-signature services.

Authentication

Access to GoComply requires an account with an email address and a password that must meet minimum strength requirements. New accounts must confirm their email address before the workspace becomes available.

Permission-based access

Every client, document, meeting note and uploaded file is associated with the advisor account that created it. Database access rules enforce that association for reading, creating, updating and deleting records, so your account cannot reach another advisor's client information.

Private, individually encrypted documents

Uploaded, filled and signed documents are stored in private storage that is not publicly browsable. In addition to the hosting provider's encryption, GoComply encrypts each file with its own AES-256-GCM key before storing it, so a copy of the storage alone does not reveal any document.

Secure transmission

Traffic between your browser and GoComply is served over HTTPS-secured connections.

Temporary document access

When you open or download a document, GoComply issues a short-lived, time-limited link instead of a permanent public file address. Links expire automatically.

System-secret protection

Payment credentials, encryption keys, the digital-seal key and other service keys are held server-side and are never exposed to the browser. Sensitive operations on client and document data are validated on the server.

Two-step verification

Advisors can require a 6-digit code from an authenticator app at every sign in. When it is on, client records stay locked to the account until the second step is completed. Advisors can also sign out of every device at once from Settings.

Electronic signatures and audit trail

Signing links are long random codes stored only as fingerprints, expire automatically and can require an emailed one-time code, which is itself stored as a keyed fingerprint. Signing and downloads are rate-limited. Each document stage carries a SHA-256 fingerprint that is rechecked before it is shown or downloaded, and every audit event is linked to the previous one so a changed or removed entry is detected. Signed documents and audit entries cannot be edited or deleted.

Encryption and backups

Data is encrypted in transit with HTTPS and encrypted at rest, including backups, by GoComply's hosting provider. The database is backed up automatically every day by the hosting provider. Signed documents are retained as immutable records.

Security reviews

Application dependencies and security configurations are reviewed as the platform evolves, and identified issues are addressed as part of ongoing development.

Incident reporting

If you believe you have found a security issue, or you suspect unauthorized access to your account, email info@gocomply.ca with a description of what you observed. Please do not include client personal information in your report.

Data-deletion requests

You can delete client records and documents from within your workspace. To request deletion of your account and its associated data, email info@gocomply.ca from the address on your account.

Privacy and security contact

Privacy and security enquiries can be sent to info@gocomply.ca.

No platform can promise absolute security. GoComply does not claim any certification, and the protections described here are the controls implemented in the product, not a guarantee of outcomes.