Security & Sovereignty

Your data stays where you say. People see only their part.

You pick the region. Every role sees only what its job needs, and every action is logged.

The numbers your security review will ask for

The uptime and backup-deletion figures are contract terms. The signed agreement governs.

  • availability commitmentmeasured monthly, excluding scheduled downtime and force majeure 99.5%
  • to securely delete backup and archival copieson termination 90 days
  • minimum breach recordfor every safeguard breach, reported or not 24 months
  • on every connectionincluding the link from your site TLS 1.2+

Know where your data lives and who can reach it

  • You choose the region You pick it when you onboard. Canadian data stays in AWS Canada Central, in Montreal. US data stays in AWS US-East or US-West. Nothing crosses that border unless you configure it to.
  • Encrypted in transit and at rest TLS 1.2 or higher on every connection, including the browser session. Keys are managed on AWS KMS, with tenant-specific keys as an option.
  • Databases in a private network Private VPCs, not exposed to the internet. Only the platform backend can reach them.
  • Your site connects out The link runs from your site to mode40, so you do not open an inbound hole in your firewall.
  • Sign-in through AWS Cognito Cognito issues the session token and supports multi-factor authentication and password policies.
  • Your data stays in your tenant Isolation is enforced by tenant ID together with IAM policy. One customer's session cannot reach another customer's data.

Give each person the access their job needs

    • L. HaddadSigned in via SSO 09:02
    • Session refreshed
    • Signed in through company SSO

    One sign-in, matched to your company.

    Each company signs in at its own address, through single sign-on or a password where SSO is not in place. The session refreshes without a second login.

    How sessions and SSO work
    • Sites for T. Nakamura Brantford Plant 2 Windsor Plant 1
    • Line Lead role

    Two sites assigned, two sites shown.

    A person assigned to two plants sees exactly two, no matter which role they hold. The same role can be reused elsewhere without opening more sites than it should.

    How roles and sites work

If something goes wrong, or you leave

  • Account activity is logged AWS CloudTrail records activity across the account, and mode40 operates it.
  • Unauthorized access is watched for around the clock AWS GuardDuty monitors continuously, operated by mode40.
  • You get notified If a breach of mode40's security safeguards creates a real risk of significant harm, mode40 notifies the people affected and the Office of the Privacy Commissioner of Canada, under PIPEDA. That commitment sits in the licensing agreement.
  • Every breach is kept on record For at least 24 months, whether or not it had to be reported.
  • One address for a report Email privacy@mode40.com with Security in the subject line and enough detail to reproduce the issue. mode40 acknowledges good-faith reports and asks for reasonable time to fix an issue before it is disclosed elsewhere. Do not scan or test the Singularity for vulnerabilities without written permission.
  • Your data comes back or gets deleted On termination, mode40 returns your data in a mutually agreed format, or deletes it, on written request. Backup and archival copies are securely deleted within 90 days.

What we don't have yet

  • No SOC 2 or ISO 27001 today mode40 holds no third-party security certification. Neither a SOC 2 Type II nor an ISO/IEC 27001:2022 audit is underway. Both are on the roadmap without a committed date. Ask mode40 for the current status and plan.
  • PIPEDA is a stated commitment The licensing agreement commits mode40 to PIPEDA's breach-notification rule. No third party attests to it.
  • AWS's certifications belong to AWS The Singularity runs on AWS, and AWS holds its own infrastructure certifications. mode40 does not inherit them or offer them as an attestation of the Singularity.
  • No disaster-recovery plan published No documented plan, no published recovery point or recovery time target, and no public status page today. Ask mode40 before you write these into your requirements.
  • No provenance screen yet CloudTrail and GuardDuty cover the AWS account. No customer-facing screen traces a number back through its sources today. Treat provenance as an implementation topic.

Questions your security team will ask

Your IT team wants it in writing. We'll send it.

Where your data lives, how it's protected, and what happens if something goes wrong. All of it, including what we don't have yet.