Free, and nothing to sign up for
Everything we give away
No email gate, no newsletter, no form in the way. If you can use any of this without ever speaking to us, that is a good outcome and we would rather you had it.
Where do you stand?
Ten questions about whether you could show it, not whether you feel secure. Five minutes. Nothing you answer leaves your browser. You get the gaps back in the order we would fix them.
Take the self-check →The control set
All thirty-six governance controls we assess against, with the evidence each one requires and what it maps to in PIPEDA, Quebec’s Law 25, OSFI and the CCCS baseline. Published in full so you can work through it yourself.
Read the control set → Stay currentWhere to watch
The five sources worth following if you are accountable for this in a Canadian organisation, Canadian regulators first, and the one board question that goes with each of them.
See the list → PatternsWhat bad looks like
The seven failures we keep finding in Canadian organisations — the unassessed supplier, the account with no second factor, the backup nobody restored. Described as patterns, with the question a board should ask about each.
See the seven → CrosswalkISO 27001 mapped to Canadian law
Twenty-seven Annex A controls from ISO/IEC 27001:2022 mapped to the PIPEDA, Law 25, OSFI and CCCS obligations they actually help you evidence. The part every international toolkit leaves to you.
Open the crosswalk →The first hour
What to do in the sixty minutes after you realise something has gone wrong, and the notification decision tree for both Canadian regimes. Complete, free, and in English and French.
Read the runbook → Paid · from $165The three runbook modules
If the free one above is useful, these are the rest: eighteen procedures across incident response, everyday operations and AI oversight. English and French Canadian, PDF and Word. Buying one does not stop us assessing you — buying a documentation pack does.
See what is in them → CrosswalkSOC 2 mapped to ISO 27001
Your American customer wants a SOC 2 and you have ISO 27001. All thirty-eight criteria mapped, with what carries over, what does not, and the one genuine gap. Free, complete, no email address.
Read the crosswalk →Staff awareness posters
Free printable one-page posters on AI-powered scams, PIPEDA, Quebec Law 25 and passwords — in English and in French. Five points each, written for the people who never read the policy. No sign-up and no email address required.
Download the posters →



AI acceptable use policy
A short, adoptable policy covering approved tools, what must never be pasted into one, and the Quebec Law 25 duties that apply when software makes decisions about people. Adapt it and we will review your version free.
Read the template → TemplatePrivacy breach response policy
What to do in the first hour, who decides whether it has to be reported, and what goes in the breach register — the record PIPEDA requires you to keep for two years and Quebec for five. Most organisations we assess cannot produce one.
Read the template → TemplateThird-party and vendor review
How to tier your suppliers, what evidence to demand before you sign, what Quebec Law 25 requires before personal information leaves the province, and the vendor register you should be able to produce within the hour.
Read the template →Worth reading
The one security change worth making this quarter
If you could do exactly one thing, multi-factor authentication on corporate email would almost certainly be it. Why, in plain terms, and what it actually stops.
Your AI assistant will not break your file permissions
It will faithfully surface everything your permissions already allow — which is a different problem, and a larger one. What Microsoft’s own documentation says, and what it means for your file shares.
How exposed is a Canadian small business, really?
The honest answer is further than most owners believe, and the gap between belief and evidence is where the risk lives. What the numbers show.
A hundred companies warned about AI attacks. Who would answer?
The useful question is not whether they are right. It is who in your business would pick up the phone, and whether they would know what to do next.
Why we give it away
A method you cannot inspect is not a method
Plenty of firms will score your organisation against a standard they will not show you, and hand you a number you cannot check. We think that is the wrong way round. If our control set is any good it survives being read by the people we assess.
More coming: awareness posters you can print, and three Canadian policy templates with a free review.
When you want a second pair of eyes
Everything above is yours whether or not you ever contact us. If you want someone independent to work through it with you, the first conversation costs nothing and carries no obligation.