CMBCanada Minute Books
Sign inCreate account
Security

Security built into the record system.

Canada Minute Books is designed for corporate records that can contain ownership, director, shareholder, signature and other sensitive information. Security controls are therefore treated as part of the application architecture rather than an add-on.

Corporation-scoped authorization

User permissions are evaluated separately for every corporation. Access to one client or company does not automatically grant access to another.

Multi-factor authentication

Authenticator-app TOTP, recovery codes, session management and security-event history provide additional account protection.

Private document storage

The production architecture is designed to encrypt uploaded documents before private storage and require authorization for every retrieval.

Document integrity & history

Document versions retain SHA-256 integrity information and historical copies rather than silently replacing previous records.

Malware scanning

Production configuration is designed to fail closed if the required document malware-scanning service is unavailable.

Audit & security events

Important account, document, corporate-action and administrative events are recorded for accountability and troubleshooting.

Session & recovery controls

Password changes and resets can revoke existing sessions, and users can review and remotely revoke active sessions/devices.

Data portability

Authorized users can generate organized exports of corporate records without CMB retaining an unencrypted export archive on the server.

Production hardening

The production application is designed to require HTTPS, strong environment secrets, private storage, database access controls, malware scanning, rate limiting, security headers, backup verification and restore testing before commercial operation.

Retention and deletion

Corporate minute-book records are not automatically deleted by generic retention jobs. Privacy or deletion requests involving corporate records are tracked for authorized review because legal or corporate-record retention requirements may apply.

Data processing and hosting

Production infrastructure, data-processing locations, third-party processors and backup locations should be documented in the final production privacy materials before public commercial launch.

Security is a shared responsibility. Customers remain responsible for protecting their login credentials, enabling appropriate account security, choosing suitable professional permissions and ensuring the corporate information they enter is accurate.

Responsible disclosure

A dedicated vulnerability-reporting contact should be published as part of the final production deployment and legal review.

© Canada Minute Books.Privacy · Terms