Security & compliance, transparently.
Procurement data is sensitive. We hold ourselves to recognized international standards across the North America–GCC corridor and tell you exactly where we stand.
Current status:Maple & Sand is actively pursuing SOC 2 Type II and ISO/IEC 27001. We are not yet certified — this page describes our live program and the controls already in place, and we will publish report dates here as audits complete.
Standards we measure against
SOC 2 (Type II) Ready
ReadyControls in place; independent audit of security, availability & confidentiality controls underway.
ISO/IEC 27001
ReadyBuilding our ISMS toward certification of the platform and operations.
GDPR
Compliant / AlignedLawful-basis processing, data-subject rights, and transfer safeguards.
PIPEDA
Compliant / AlignedConsent, accountability, and access principles for personal information.
Saudi PDPL
Compliant / AlignedData-residency and processing aligned to SDAIA's Personal Data Protection Law.
UAE PDPL
Compliant / AlignedFederal Decree-Law No. 45 of 2021 personal-data handling principles.
How we protect your data
Encryption in transit
All traffic is served over TLS with HSTS preloading; plaintext HTTP is refused and upgraded.
Access control
Admin access is gated by short-lived signed JWTs with least-privilege scopes and forced-strong production secrets.
Secure file handling
Uploads are stored outside the web root with random names, extension allow-listing, and magic-number signature validation — never client-trusted MIME.
Hardened delivery
Content-Security-Policy, anti-clickjacking, nosniff, COOP, and a locked-down Permissions-Policy ship on every response.
Data minimization
We collect only what a procurement match requires, apply defined retention windows, and purge attachments on deletion.
Abuse resistance
Per-IP rate limiting and honeypot anti-spam protect registration and authentication endpoints.
Cross-border by design, lawful by default
Operating between Canada and the GCC means personal data may move across borders. We map every transfer to an appropriate safeguard — contractual clauses, consent, or local-residency handling — so data stays protected under whichever of GDPR, PIPEDA, Saudi PDPL, or UAE PDPL applies.
Read the full privacy policyNeed our security package or a DPA?
Procurement and security teams can request our controls overview, data-processing addendum, and audit status. We'll share our SOC 2 report the moment it's available.