Skip to main content
io4 Technologies

Trust Center

The security of your data is our business.

io4 is a Microsoft Solutions Partner, compliant with Law 25, and applies enterprise-grade security practices. Here's how.

Our internal practices

Six rules we apply to ourselves.

Strong authentication

MFA required for any access to client environments.

Principle of least privilege

Granular, audited client access, automatically revoked at the end of the mandate.

End-to-end encryption

Client data encrypted at rest and in transit. Centralized secrets vault.

Audit and logging

Every action by an io4 expert on a client environment is logged and auditable.

Regular penetration testing

Our infrastructure and processes are audited by third parties every year.

Vetted subcontractors

All our subcontractors sign confidentiality and Law 25 compliance commitments.

Hosting and jurisdiction

Your data stays in Canada.

Unless explicitly agreed otherwise, all data processed as part of our mandates is hosted exclusively in the Microsoft Canada Central and/or Canada East regions, or Microsoft France for our European clients. io4's internal tools (CRM, projects, communications) use the same Canadian regions. Our subcontractors are vetted and contractually commit to comply with Law 25.

Frequently asked questions

Frequently asked questions about security and compliance.

Can't find your answer? write to us.

  • Certification is under audit. Information management practices are already aligned with the standard, but io4 does not claim the certification before obtaining it — this page states the actual status, not the intention.

  • Only the people assigned to your engagement, with named accounts, limited to the scope required and revoked at the end. The principle of least privilege also applies to delegated administrative accounts on your tenant.

  • You are notified without delay, with established facts rather than a preliminary assessment. io4 documents the incident in the format Québec's privacy commission expects and gives your officer what they need for their register.

    See Law 25 support
  • Yes. Vendor security questionnaires are answered within five business days. For a documentation-based audit, io4 provides the architecture, internal policies and the list of subprocessors with access to data.

  • Microsoft as the primary host, in the Canadian or French regions depending on the client. The full list of subprocessors with potential access is provided on request, before signature, and kept current during the engagement.

Let's talk about your project

30 minutes to frame what matters.

A direct conversation with one of our experts. No commitment, no pressure. You leave with a clear, reasoned perspective on your situation.

Or call us directly:+1 888 285 9583
Free assessment