Compliance hub

Compliance by design. Verifiable. Auditable.

tonia is the gated, audited, redacting router for every AI request.

Sensitive data stays in Canada.

tonia applies your rules before anything is sent to a model provider.

Your organization
Governance in CanadaSensitive data blocked
Authorized request
Model provider

How tonia meets each obligation.

Canada's Bill 25 (formerly Bill 64) modernised the private-sector Act respecting the protection of personal information. The obligations applicable to tonia are:

Bill 25 obligations and tonia posture
ObligationArticletonia posture
Privacy Officer designatedart. 3.1Yes — contact published in the privacy policy
Incident registerart. 3.8Maintained since incorporation, CAI-ready format
PIA before any cross-border transferart. 17PIA template provided; sensitive categories blocked before any cross-border send
Granular consentart. 12Granular in the portal and in the cookie banner
Right to data portabilityart. 27Structured JSON / CSV export from the portal
Automated right to be forgottenart. 28.1Automatic cessation of processing once the stated purpose expires

Sanctions

For an organisation that contravenes Bill 25:

  • Penal sanctions (art. 90.12): up to 25 M CAD or 4 % of worldwide turnover, whichever is greater.
  • Administrative sanctions (art. 90.1): from 10 M CAD or 2 % of worldwide turnover.
  • Civil sanctions: statutory damages of at least 1,000 CAD per affected person, without proof of harm (art. 93.1).

Why Canadian residency isn't enough.

The US Clarifying Lawful Overseas Use of Data Act (2018) — the CLOUD Act — compels any company subject to US law to produce data — regardless of where that data is physically stored.

"Azure OpenAI Canada Central" — the illusion

Microsoft servers in Toronto store your data in Canada. Microsoft Corp. (Washington) remains subject to the CLOUD Act. A US subpoena served on Microsoft Corp. compels disclosure of the data — including the bytes physically in Toronto. If the subpoena carries a gag order, Microsoft cannot even tell you.

Vendors subject to the CLOUD Act:

  • OpenAI (Delaware)
  • Anthropic (Delaware)
  • Google / Gemini (Delaware)
  • Microsoft / Azure / Copilot (Washington) — including the Canada Central region
  • AWS / Bedrock (Delaware)

Vendors out of CLOUD Act reach:

  • tonia Local — physical on-site tonia in Canada, no US entity in the data path
  • Mistral (France) — subject to GDPR but out of CLOUD Act reach
  • Cohere (Toronto) — Canadian entity, out of CLOUD Act reach for Canada-hosted inference

Canadian federal privacy law.

For clients in Canada outside Québec, tonia complies with the Personal Information Protection and Electronic Documents Act (PIPEDA). Bill 25 compliant — you're already above the federal bar.

SOC 2 and ISO 42001.

Status as of 2026:

  • SOC 2 Type I: in progress, report target Q4 2026.
  • SOC 2 Type II: 6-month observation starts once Type I is obtained (Security, Availability, Confidentiality).
  • ISO 42001: in progress, audit scheduled Q4 2026.
  • Bill 25 compliance: by design (see section 1).