Request access
Security

Security and confidentiality

Last updated: 26 July 2026

You entrust Vizir with files and identity documents covered by your professional confidentiality obligations. This page sets out the measures in place, the undertakings that are contractually binding on us, and the limits of the service. References in brackets are to our terms of service, which govern.

  • Your files are hosted in Canada and encrypted
  • No other firm can see your files
  • A file is seen by one person, two under dual validation
  • Every access, including read-only, is logged for 7 years
  • Encrypted backup copies, kept away from the main hosting
  • You get all your files back, free of charge, even if you leave
  • What the agent remembers stays with you and serves no other firm
  • AI analysis is yours to switch on and off
  • Nobody addresses your client in your place

1. Hosting, encryption and backups

Your files and your clients' documents are hosted in Canada. They are encrypted in transit and at rest (s. 10.2). Traffic between your browser and the service is HTTPS only.

We maintain encrypted backups hosted outside our primary infrastructure, the decryption key for which is held by at least two designated people. This separation addresses the case where the primary infrastructure becomes unavailable or compromised: files remain recoverable without depending on that single infrastructure or on a single person.

Independently of these measures, we recommend that you keep an up-to-date copy of your files outside the service. You remain responsible for retaining your files under your professional obligations.

2. No other firm can see your files

Each firm is isolated from the others. Partitioning does not rest on the user's role alone: on every read or write, the service verifies that the requested object belongs to the firm requesting it. A request for another firm's file is refused, even when it comes from an otherwise legitimate account.

At the database level, access is deny by default: tables are not readable through a public or anonymous key. On the client side, each person sees only the file that concerns them, never another client's, including within the same firm.

3. Access to your account

Access is named: one professional licence gives entitlement to one account, and each member of your firm has their own. Sharing credentials is prohibited by the terms of service, precisely because it would make the audit log unusable.

Multi-factor authentication will be offered on every account. It will remain the firm's choice: if it does not suit your organisation, you will be able to switch it off. The option exists, the constraint does not.

4. Access by Vizir staff

The service includes a human review of documents. It is performed by Vizir staff. This review is not subcontracted to an outside vendor.

  • Access is limited to what is strictly necessary, on a least-privilege basis (s. 10.3).
  • Every person is bound by a written confidentiality undertaking.
  • Access is named and logged, including the opening of a document's content.
  • File content is never used for any purpose other than providing the service.

Who sees a file

A file is handled by the person responsible for it, and by a second person only if your firm has enabled dual validation. The team performing that review is deliberately small and works on a least-privilege basis: no one opens a file without a service reason. We do not, however, claim that a technical barrier prevents another authorized staff member from accessing it: what we do guarantee is that every access is named and written to the audit log, including a plain read, and that the log is provided to you on request. You can therefore verify for yourself, file by file, who opened it and when.

Vizir is published by a Quebec company and its management is in Quebec. Part of the team works from France. This access from outside Quebec is declared in our privacy policy, framed by contract and covered by a privacy impact assessment, in accordance with section 17 of Law 25.

If your firm is established outside Quebec, that framing does not change: it then answers to the regime that concerns you, PIPEDA or the Alberta or British Columbia statute as the case may be, which likewise require the provider to offer comparable protection by contract. The province-by-province map of regimes is on the Compliance page.

5. Third-party requests

This is the clause that most directly protects your professional obligations. If a third party, whether an authority, a court or an individual, asks Vizir for access to information in a file, Vizir, unless legally prohibited (s. 10.4):

  • does not act on it of its own initiative and notifies you without delay, so that you can assert professional secrecy or your confidentiality obligations and exercise your remedies
  • objects to the disclosure and cooperates with you in contesting it
  • where disclosure remains legally required, limits it to the strict minimum

You remain in control of asserting confidentiality for your clients. Vizir never substitutes itself for you on this point.

6. Audit log

Every action on a file, as well as the opening of a document's content, is written to a tamper-proof audit log kept for seven years (s. 10.2). The log records who did what, on which file and when. You can obtain a copy of it on request.

That duration is not a commercial choice: it is what allows you, years after a filing, to demonstrate the diligence exercised on a file if your regulator, your college, your insurer or your client asks.

7. AI-assisted analysis

Assisted analysis is a firm-level setting that can be switched on and off. With it off, the service remains fully functional: collection from the client, the checklists of documents required by the program, bundle assembly and deadline tracking do not depend on it.

When it is on:

  • it produces an assisted reading of a document, always subject to the human review described in point 4
  • no decision about a file is ever made automatically
  • your file content is never used to train a model
  • every call is logged (file concerned, timestamp, purpose) and capped per file
  • processing takes place in the United States: this transfer is framed by contract and covered by the assessment required under section 17 of Law 25

What "your agent learns" actually means

We present Vizir as an agent that learns the way you work. That promise and the undertaking above do not contradict each other, but the distinction deserves to be stated plainly.

Your agent remembers your instructions, your handling preferences and your document library. These are stored in your firm's own space, much as an internal memo would sit in your records: you can review them, change them and delete them, and they are never reused for another firm.

Training a model is a different operation, which alters a shared model using data. No model is trained, fine-tuned or specialised on your files or on your clients' documents. In other words, what your agent knows about your firm remains data that belongs to you and that you can erase, not a capability acquired by a model from which others would benefit.

8. Retention, deletion and getting your files back

You choose how long documents are retained: prompt deletion after the bundle is delivered, or long retention where your professional obligations require it. In both modes, metadata (document type, dates, fingerprint, versions) and the audit log are kept for seven years (s. 10.2).

Your files and the content you upload remain yours and your clients'. Vizir acquires no rights in that content, other than the technical licence strictly necessary to provide the service.

On request, at any time and not only when you leave, we hand you back at no cost the entirety of your files, your clients' documents and the corresponding audit log, in a format you can open and archive elsewhere. There is no exit fee, no waiting period and no proprietary format designed to keep you with us.

9. Incident handling

In the event of a confidentiality incident, Vizir applies the procedure required by Law 25: mitigation measures, entry in the incident register, and notification of the Commission d'accès à l'information and of the persons concerned where the law requires it (s. 10.5).

You are notified without delay and in writing. You are the professional on the file: you must be able to inform your client, your regulator or your college, and your insurer, within your own deadlines.

10. Providers and transfers outside Quebec

We use a limited number of providers. Your files remain hosted in Canada; the only processing carried out outside Quebec is set out below.

ProcessingPurposeFile documents involved
AI-assisted analysisAssisted reading of a documentYes, the document analysed. Can be switched off by your firm
Delivery of the public siteDisplaying the public pagesNone
Internal access-request alertTelling us a request was submitted on the public siteNone
Card paymentsBilling your subscriptionNone. Card numbers never pass through our servers in readable form

The platform sends no email. Alerts and reminders appear on screen, in the dashboard and in the case timeline: no email leaves the application, neither to your firm nor to your clients, and no case data passes through an email delivery service. The only thing that remains is the internal alert telling us that an access request was submitted on the public site.

Each disclosure outside Quebec is framed by contract and covered by a privacy impact assessment (s. 17, Law 25). The named, current list of providers is set out in the privacy policy.

11. Scope of the service

Vizir is a management, collection and document-preparation service. For files handled in the platform, Vizir acts as a service provider to your firm: the firm remains responsible for its clients' information, and Vizir processes it solely on the firm's behalf and on its instructions.

  • Vizir provides no immigration advice and represents no one before the authorities. Advice, strategy and the decision belong exclusively to lawyers, notaries and licensed consultants (s. 91 IRPA).
  • The portal asks your client for documents and points out what is missing. It never answers on the substance: any such question is escalated to you.
  • No filing is ever made in your name. Validation before filing is yours.

12. Verification of admitted professionals

Access to the service is reserved for licensed professionals. We verify every licence at its official source before opening an access, and one licence gives entitlement to one account only. The registers we consult are public; you can run the same checks:

13. Certifications, documents and contact

SOC 2 and ISO/IEC 27001 certification are on our roadmap. In the meantime, the measures described on this page are not declarative: they appear in our terms of service and are contractually binding on us, which no certification replaces.

If your regulator, your college, your insurer or your internal policy requires a specific document before an access is opened, we provide and sign it before receiving a single document: a subcontracting agreement, a named confidentiality undertaking, a written description of our security measures, a return-of-data clause.

The person responsible for the protection of personal information is named, with direct contact details, in article 1 of our privacy policy. Publisher: 9566-4629 Québec inc., NEQ 1182097924.