Security and hosting

This page brings together what we do with the data we host for you: where it is stored, who can access it, what role AI models play, what falls under Law 25 and what you get back at the end of an engagement.

Day-to-day operations are described on the Managed infrastructure page.

Where your data is stored

Your source systems, such as your ERP or CRM, stay where they are. We host the synced copies of their data, your definitions and what we deliver in Canada, in an environment we operate and secure.

For a development engagement, the applications, models and data we deliver are also hosted in Canada.

Before go-live, we clarify with you the hosting requirements, the data models can access and the operating responsibilities.

AI models and third-party components

The AI model used and where it runs are defined with you, according to how sensitive the data is. How sensitive information is handled is defined according to the data and the model used.

If you connect an external assistant such as Claude, ChatGPT or Copilot, it only receives the results of queries the person is allowed to make. What it receives is processed under its provider's terms. For more sensitive data, a sovereign agent hosted in Canada can answer instead.

A solution may also depend on our internal tools or on third-party components. Those dependencies are set out in the agreement.

Who can access your data

In your organization, each person, agent or automation only reaches the data its role allows. Every query and every run is logged: who asked for what, when, and from which sources.

At Rosecape, only the people who operate your solution have access, and only when needed. That access is role-based and logged. There is no routine human access to client data.

Law 25 and your responsibilities

We document with you where data is processed, who can access it and which personal information is involved. We put in place access control, query traceability and data kept in Canada.

This supports your obligations under Quebec's Law 25 and, elsewhere in Canada, under the federal or provincial law that applies. Your organization's compliance remains your responsibility.

To take stock of AI governance in your company, see our 7-dimension checklist or take the self-assessment.

What you own at the end of an engagement

You remain the owner of your data and your definitions. The code built for you belongs to you.

If you leave Rosecape, your data and the deliverables that belong to you, such as code, can be handed over with their documentation. The transfer arrangements and the dependencies needed to run the solution are set out in the agreement.

Operations and incidents

We monitor the infrastructure and apply updates. Support, backup and recovery arrangements are set out in the operating agreement.

For an example of how we work, read our analysis of the LiteLLM supply-chain attack. It describes how we checked and secured our environments. It is our own account and has not been verified by an independent audit.

Your security and hosting questions

We review your hosting and access requirements with you, then propose a plan.