Integrated IT Support · Compliance & Trust

Compliance & Trust

ARIA and Integrated IT Support Inc. are not currently SOC 2, ISO 27001, or HIPAA certified. Below is our honest security posture, the readiness self-assessments we maintain internally, and our policy disclosures. We intend to pursue formal certification as we scale — and we will never claim a certification we do not hold.

Current posture

HostingNetlify (SOC 2 Type II)
Data residencyUS/EU edge · Canadian tenant routing on request
Encryption in transitTLS 1.2+ (monitored daily)
Encryption at restAES-256 (Netlify Blobs)
PII redactionAt the edge (email, SIN/SSN, card, phone)
Tenant isolationPer-tenant audit logs · internal controls self-test
Vulnerability disclosureActive program · security/disclosure
SOC 2Not certified · internal self-assessment only · no external audit contracted
ISO 27001Not certified · internal self-assessment only · no external audit contracted
PIPEDAInternal self-assessment (not an external audit)
GDPR Article 22Automated-decision notice published

Self-assessment tools

SOC 2 · AICPA TSC

SOC 2 Readiness Self-Assessment

Track readiness across Common Criteria (CC1-CC9) + Availability, Confidentiality, Processing Integrity, Privacy. Progress saved locally. Export when engaging an auditor.

Open tool →
ISO 27001 · Annex A

ISO 27001 Readiness Self-Assessment

Walk through Annex A controls: organizational (A.5), people (A.6), physical (A.7), technological (A.8). Score tracked per domain.

Open tool →
PIPEDA · Canada

PIPEDA Readiness Self-Assessment

Personal Information Protection and Electronic Documents Act self-assessment for Canadian organizations. 10 fair information principles.

Open tool →
GDPR Art. 22 · PIPEDA

Automated Decision-Making Notice

What ARIA decides automatically, what it doesn't, your rights under GDPR Article 22 and PIPEDA, opt-out path, model disclosure, audit logging.

Read notice →

Pre-filled questionnaires (for procurement)

Policies

How to request more

For SIG-Full, vendor risk questionnaires, DPAs, or a Type II report scoped to your procurement timeline: email ahmad.wasee@iisupp.net or book a 15-min call at iisupp.net/book.

Disclaimer

Content on iisupp.net and its sub-sites is general information only. Any troubleshooting step, instruction, tool, estimate or data taken from this site is used at your own risk, and information may be out of date — please do your own due diligence before acting on it.

No published guide can account for every factor in a live environment. If the system matters, don’t guess — call (647) 581-3182 and have it done safely. Full disclaimer · terms · privacy.