Skip to content
Security & compliance

Built for Law 25, end to end.

NotarIA's data resides in Canada (Montréal) and never leaves the country. The AI runs through Vertex AI (Gemini) in a Canadian region, with no retention — with encryption, an immutable audit trail and strict per-practice isolation, a design built for Québec's Law 25.

The guarantees, point by point

Data residency in Canada

Hosted in Montréal; the AI runs via Vertex AI (Gemini) in a Canadian region; no egress outside Canada.

End-to-end encryption

Data encrypted in transit and at rest.

Immutable audit trail

Who accessed, generated or approved what, and when — hash-chained and verifiable.

Per-practice isolation

PostgreSQL Row-Level Security: no query ever crosses a practice's boundary.

Zero-retention LLM gateway

No client data is retained by the AI provider.

Microsoft Entra identity

Single sign-on (SSO) and MFA, or email + password + two-factor authentication.

Frequently asked questions

Is NotarIA compliant with Law 25?

NotarIA is built for Law 25: data residency in Canada, minimization, immutable audit, consent management and access/deletion rights. A practice's compliance also depends on its own practices.

Where is the data hosted?

In a Canadian region (Montréal). The AI runs through Vertex AI (Gemini) in Canada; no data leaves the country.

How is each practice's data isolated?

Through PostgreSQL Row-Level Security and application filtering: no query crosses a practice's boundary. An immutable audit and Microsoft Entra authentication add to this.

Want a security-focused demo?

We are happy to walk through the residency and audit architecture.

Assistant — not legal advice. The notary reviews, signs and decides on every act.

Security & Law 25 — data hosted in Canada | NotarIA