Security

Security Statement

ADVISOR411 INC.

Effective Date: January 1, 2025Last Updated: July 7, 2026

1. Overview

Advisor411 Inc. ("Advisor411," "we," "us," or "our") uses administrative, technical, and organizational safeguards to protect information handled through the Advisor411 platform.

This statement summarizes the security practices we use to support customer trust, data protection, and responsible operation of our web application and related systems.

2. Scope

This statement applies to information stored, processed, or transmitted by Advisor411 systems, including customer account information, platform usage data, client inquiries, and advisor information made available through the platform.

It also applies to employees, contractors, service providers, and infrastructure components that support the Advisor411 web application, analytics tools, and operational workflows.

3. Data Handling and Protection

Advisor411 classifies and handles data based on sensitivity, source, business purpose, and customer commitments. Customer information and account-related data are treated as confidential and access is restricted to authorized personnel.

Advisor information sourced from public or licensed datasets is still protected with safeguards designed to preserve integrity, prevent unauthorized alteration, and limit platform access to permitted users.

  • Data is encrypted in transit using TLS.
  • Production data stores use provider-managed encryption at rest where supported.
  • Access to production data is limited based on business need.
  • We avoid collecting sensitive information that is not needed to provide the platform.

4. Access Control

Access to Advisor411 systems is granted on a least-privilege and need-to-know basis. Administrative and production access is limited to authorized personnel and reviewed as operational needs change.

  • Role-based access controls are used for application and administrative workflows.
  • Privileged access is restricted and protected by strong authentication controls, including multi-factor authentication where supported.
  • Access changes are made when team members change roles or no longer require access.

5. Infrastructure and Application Safeguards

Advisor411 uses reputable cloud, database, authentication, and application service providers that maintain their own security programs and infrastructure controls.

We maintain application safeguards intended to reduce unauthorized access, protect account sessions, and support secure handling of customer data. Systems and dependencies are updated as part of normal engineering operations.

6. Monitoring and Logging

Advisor411 logs relevant platform activity, administrative activity, and system events to support security monitoring, troubleshooting, auditing, and incident investigation.

Logs are retained based on operational, security, and legal needs. Access to logs is restricted to authorized personnel.

7. Vendor and Third-Party Management

Advisor411 relies on selected third-party providers for hosting, data storage, authentication, analytics, communications, and related platform services.

We review vendors for appropriate security and privacy practices before use and limit data shared with vendors to what is needed for the service they provide. Vendor relationships may be governed by contractual, technical, and operational controls depending on the nature of the service.

8. Retention, Backups, and Recovery

Advisor411 retains information for as long as needed to provide the platform, satisfy legal or contractual obligations, resolve disputes, support security, and maintain business records.

Backup and recovery procedures are maintained to support business continuity and reduce the risk of data loss. Backup retention and deletion follow defined operational lifecycles.

9. Incident Response

Advisor411 maintains incident response procedures for identifying, investigating, containing, remediating, and reviewing suspected security or confidentiality incidents.

Where required by applicable law, Advisor411 notifies affected clients, individuals, regulators, and other relevant parties following a security or confidentiality incident. This may include obligations under PIPEDA, Quebec privacy legislation, and other laws that apply to the incident.

10. Compliance and Review

Advisor411 designs its security and privacy practices to support Canadian B2B vendor expectations and applicable privacy obligations, including PIPEDA and Quebec privacy legislation where applicable.

This statement is reviewed periodically and updated as our platform, operations, vendors, legal requirements, and threat landscape evolve.

11. Contact

For questions about this Security Statement or security-related vendor assessments, contact:

Advisor411 Inc.

Toronto, Ontario, Canada

Email: security@advisor411.com

© 2026 Advisor411 Inc. All rights reserved.