Information Security Policy, Solutions Sparkops Inc.
Effective October 9, 2026, reviewed every year.
- Scope: our clients' data and the company's financial data, including bank data read through Plaid.
- Owner: Carlos Martins, President, carlos@sparkops.ca. He is also responsible for the protection of personal information.
- Access: every access is individual and limited to what is needed.
- Workstations: encrypted disk, firewall enabled, automatic security updates, session locked when unattended.
- Secrets: API keys and tokens are kept outside any code repository, in files readable only by their owner. Never sent by email. Revoked at the slightest doubt.
- Automation: our software agents have only the access they need. None of them signs in on a person's behalf or makes a payment.
- Bank data: read-only access, no automated money movement.
- Transmission: always encrypted, with TLS 1.2 or better, through recognized cloud providers.
- Retention: accounting records are kept for six years, as required by tax law, then deleted. Bank access that is no longer used is revoked.
- Incidents: every incident is logged. A confidentiality incident that presents a risk of serious injury is reported to the Commission d'accès à l'information and to the persons concerned.