← Back to home

Security at BrokerPlus

Your clients' data is the foundation of your business. We built BrokerPlus to protect it.

Canadian Data Residency

All data is processed and stored on Amazon Web Services (AWS) servers in Canada. Your client information never leaves Canadian jurisdiction.

  • Region: Canada (Montreal) on AWS
  • Compliant with Canadian data sovereignty requirements
  • PIPEDA-aligned data handling practices

What Data We Handle

BrokerPlus works with your mortgage book data (maturity dates, rates, balances, property values, and client contact information) to surface refinance and renewal opportunities. We don't process sensitive financial documents like pay stubs, tax returns, or bank statements.

Encryption

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Authentication is handled through secure OAuth 2.0 (we never store your passwords).

Access Controls

Strict role-based access ensures everyone sees only what they should:

  • Brokers/agents see only their own clients and deals
  • Brokerages see activity across their agents, but never another brokerage's data

This supports both PIPEDA's access limitation requirements and FSRA's expectation that brokerages maintain oversight of their agents.

Audit Trail

Every action is logged - every file access, every outreach sent, every report generated. Timestamped and immutable.

This helps you meet FINTRAC's record-keeping requirements and gives you a clear paper trail if FSRA ever comes asking.

Data Retention & Deletion

We maintain a formal data retention policy. You can request deletion of your data at any time, and we'll comply promptly. When you are offboarded, your data is purged (we don't hold onto it).

Breach Response

We maintain a documented incident response plan in line with PIPEDA's mandatory breach notification requirements. If something ever goes wrong, we notify affected parties and the Privacy Commissioner as required by law.

Cyber Insurance

BrokerPlus carries cyber liability insurance to protect both us and our customers.

Your Data, Your Control

  • We don't sell your data
  • We don't share it with third parties beyond what's needed to operate the platform
  • We don't use your data to train AI models
  • You can export or delete your data at any time

Compliance Summary

RequirementHow We Address It
PIPEDACanadian residency, consent practices, encryption, access controls, breach response plan, right to deletion
FSRARole-based access supporting brokerage oversight, full audit trail, secure client communications
FINTRACAudit logging with timestamps supports brokers' 5-year record-keeping obligations
Data SovereigntyAll data processed and stored in Canada (Montreal region)

Questions?

Email us at support@getbrokerplus.ca (we take every security question seriously).