Skip to content
Canada's compliance evidence layer for healthcare and regulated SMBsBuilt for Canadian healthcare and privacy frameworks

Security protects. Compliance proves.

Clinical systems manage care. CSM turns your environment into continuous, audit-ready compliance evidence.

Built for Canadian healthcare and privacy frameworks including PHIPA, HIA, PIPA, and Law 25
  • Audit failure risk starts with missing evidence
  • Incomplete documentation creates inspection exposure
  • CSM keeps the proof package continuously ready
My entry point
View compliance output Book a demo
evidence-package.csm/clinic
PHIPA · HIA · PIPA · Law 25
Evidence generated
Privacy policy approvedPENDING
Staff attestations signedPENDING
Incident plan readyPENDING
Vendor records currentPENDING
Evidence package sealedPENDING
Sealing package…
Demonstrable accountability
CSM · CLINIC
Privacy policy approved
CERTIFIED
CSM · CLINIC
Staff attestations signed
CERTIFIED
CSM · CLINIC
Incident plan ready
CERTIFIED
CSM · CLINIC
Vendor records current
CERTIFIED
CSM · CLINIC
Evidence package sealed
CERTIFIED
Auto-assembled · 0/5PHIPA · HIA · PIPA · Law 25
Why now
30 days
to a documented program
$25M
max Law 25 fine · ON, QC active
72h
breach notice — SickKids ruling
The phrase
"Demonstrable accountability."
The IPC's own term in Decision 298 for what every regulated organization must now build. We made it accountability infrastructure.
The category gap

EMRs and security tools are necessary. They are incomplete.

Clinical systems manage care. Security tools protect infrastructure. Neither one continuously produces the compliance evidence a regulated organization needs when a buyer, insurer, or regulator asks for proof.

EMRs / clinical systems
Care delivery layer
  • Store patient data
  • Support care delivery
  • Manage clinical records
  • Do not produce compliance evidence
Security tools
Protection layer
  • Protect systems and infrastructure
  • Detect threats and anomalies
  • Generate technical telemetry
  • Do not generate audit-ready proof
CSM
Compliance evidence layer
  • Converts system activity into structured evidence
  • Continuously produces audit-ready outputs
  • Connects operational systems to compliance requirements
  • Keeps proof ready before the request arrives
CSMCSM turns operations into proof

This section separates system categories. EMRs and security tools remain essential; CSM connects them to the evidence outputs compliance conversations actually require.

The category definition

Security protects.
Compliance proves.

CSM is the compliance evidence layer between your systems and your regulatory obligations. It does not replace your EMR or security tools; it connects them to compliance outcomes.

Security tools
Huntress · CrowdStrike · Defender
What it does
  • Block malware on endpoints
  • Detect intrusions in logs
  • Patch known CVEs
What it can't do
  • Explain what the activity proves
  • Produce compliance evidence packages
  • Connect controls to obligations
  • Answer a review without manual reconstruction
THIS IS US
CybershieldMaple
The evidence layer
What it does
  • Collect evidence from operational systems
  • Structure proof into reviewable outputs
  • Track attestations and approvals
  • Generate audit-ready packages continuously
Evidence layer

Systems create activity. CSM turns that activity into organized, reviewable proof. It does not replace your EMR or security tools; it connects them to compliance outcomes.

Evidence output preview

This is what compliance evidence looks like as it is generated.

CSM records the proof trail as work happens: audit logs, policy events, staff attestations, vendor reviews, and sealed packages that can be handed to the next reviewer.

Audit logsSystem events converted into reviewable records
AttestationsStaff and policy approvals captured as proof
PackagesEvidence outputs assembled continuously
Evidence events · Generated
0/6 events
Staff training attestation captured for 14 users
Training2m ago
LOGGED
Compliance evidence package signed and sealed
Audit pack1h ago
LOGGED
Privacy impact evidence assembled for review
PIA3h ago
LOGGED
Vendor accountability record logged: Microsoft Azure
Vendor1d ago
LOGGED
Privacy policy approval timestamped and versioned
Policy2d ago
LOGGED
Incident response readiness check recorded
Response4d ago
LOGGED
EVIDENCE OUTPUTGenerated · Signed · Versioned
Compliance exposure surface

Your obligations change
across Canada.

Compliance exposure is not just geography. It changes by province, sector, customer, and data flow. CSM helps teams see where obligations apply and what evidence each environment must be ready to produce.

PHIPA · ACTIVE
ABBCMBNBNLNSNTNUONPEQCSKYT
Covered todayLive in 2026RoadmapFederal overlay · PIPEDA
Active framework
PHIPA
Decision 298 AMPs · Aug 2025
REGULATORIPC
PROVINCESON
CSM COVERAGE100% of handbook items automated
EVIDENCE OUTPUTSPolicies · IRP · BAAs · Training log · SRA
Exposure principle
A clinic, an MSP portfolio, and a health tech vendor can operate across the same map with different evidence obligations. CSM adapts the proof layer to the environment you actually run.
Who We Serve

Built for every stakeholder in Canadian healthcare.

From independent clinics to multi-tenant MSP consoles, from Series A diligence packs to insurer renewals — one platform adapts to your compliance reality.

Health Tech Startups
RPM · AI scribes · Telemedicine
Healthcare Clinics
Dental · Medical · Physio — ON, AB, BC, QC
MSPs
Multi-tenant · Pan-Canadian
Advisors & Lawyers
Brokers · Privacy counsel
Accountability infrastructure · Every control

The governance controls every Canadian healthcare organization needs to demonstrate.

Built on the IPC handbook, mapped to PHIPA, HIA, PIPA, and Law 25. Every control applies to clinics in Ontario, Alberta, BC, and Québec.

Security Risk Assessment
IPC chapter 4
Privacy Impact Assessments
PIA · Law 25 ÉFVP
Breach Response
72-hr IPC workflow
Vendor BAA Registry
PHI vendors · Renewal
Staff Training & Attestations
IPC chapter 5
Evidence Packages
Insurer · IPC · Hospital
Accountability Mapping
PHIPA · HIA · PIPA · Law 25
Evidence Integrity

Every record is timestamped, signed, and immutable.

Chain of Custody

Every governance action is linked to the prior event, creating an unbroken evidentiary chain from day one to the moment of audit.

Signed Attestations

Staff training, policy approvals, and vendor reviews produce signed records. No unsigned evidence enters the repository.

Versioned Governance History

Every policy iteration is retained. Regulators and auditors can inspect the full history of your governance program — not just its current state.

Auditor-Proof by Design

Because records are immutable and versioned, there is nothing to reconstruct under pressure. Your accountability state is continuously documented, not assembled after the fact.

Two product lines · One continuous compliance OS

From daily endpoint telemetry
to a sealed Quebec certification.

The Endpoint Intelligence Platform builds the evidence base every day. The BCH TGV Pipeline converts that evidence into formal certification with BC-MSSS. Together they replace the spreadsheet sprawl that locks healthcare technology out of the $35B Quebec market.

EIP · Always on

Endpoint Intelligence Platform

Continuous compliance monitoring and evidence generation. Delivered through MSPs. Maps daily telemetry into the policy automation regulators expect to see.

  • PHIPA / HIA / PIPA / Law 25 mapping
  • Policy authoring with handbook templates
  • Staff training log + attestations
  • Vendor BAA registry + renewal
  • 72-hour breach response workflow
  • Insurer & hospital evidence packs
BCH TGV · Certification

BCH TGV Pipeline Automation

End-to-end Quebec SSSS certification workflow. From first BC-MSSS contact through post-cert continuous monitoring. AU3 MFA, Secure Vault, 15-day pentest remediation gate.

  • Org profile + NEQ + probity intake
  • 200+ criteria · auto-tracked
  • PIA Assistant (Law 25)
  • Secure Vault — no SMTP attachments
  • Two-phase auditor remediation loops
  • Annual self-decl + biennial DR
How it works

From silence
to a sealed certificate.

Output · Sealed evidence pack
STEP 1 / 4
CSM · PHIPA
IPC OF ONTARIO
PHIPA Compliance Report
DEMONSTRABLE
ISSUED 2025 · v1.0
CSM · HIA
OIPC ALBERTA
HIA Privacy Program
READY
ISSUED 2026 · v2.0
CSM · LAW25
CAI · QUÉBEC
Programme Loi 25
FR-NATIF
ISSUED 2027 · v3.0
CSM · TGV
BC-MSSS · SANTÉ QUÉBEC
Attestation TGV
CERTIFIED
ISSUED 2028 · v4.0
The IPC handbook, automated

The May 2025 handbook
is the software spec.

We didn't write a generic GRC tool and adapt it for Canada. We took every chapter of the Privacy Management Handbook for Small Health Care Organizations and turned it into a control, a template, and a piece of evidence in our database.

HANDBOOK → CONTROLS100% mapped
Ch. 1Accountability framework12 controlsauto
Ch. 2Privacy policies & notices8 controlsauto
Ch. 3Consent & individual rights9 controlsauto
Ch. 4Security risk assessment (SRA)14 controlsguided
Ch. 5Staff training & attestations6 controlsauto
Ch. 6Vendor / BAA management11 controlsauto
Ch. 7Breach response (72h)7 controlsauto
Ch. 8Audit & continuous improvement9 controlsauto
Where CSM shows up
IPC Decision 298·OIPC Alberta·CAI · Law 25·BC-MSSS · Santé Québec·Sherweb · Pax8·IAPP Canada
Plans & Pricing

Flexible, Transparent Pricing for Canadian SMBs

Choose the AI-powered protection plan that best fits your business needs. All plans offer a 14-day free trial and can be canceled anytime.

Accountability Maturity Benchmark

See how your current program measures up
against the IPC's 2025
Accountability Framework.

We provide the benchmark; you decide the path forward. A 30-minute governance readiness assessment anchored to your jurisdiction, your regulatory exposure, and the specific evidence the IPC would ask for today.

What you walk away with
  • A governance gap map for your province
  • An evidence inventory: what you have and what's missing
  • What a sealed evidence package looks like for your next audit
  • A 30-day path to demonstrable accountability