Maple & Sand
Maple & SandProcurement Intelligence
Trust Center

Security & compliance, transparently.

Procurement data is sensitive. We hold ourselves to recognized international standards across the North America–GCC corridor and tell you exactly where we stand.

Current status:Maple & Sand is actively pursuing SOC 2 Type II and ISO/IEC 27001. We are not yet certified — this page describes our live program and the controls already in place, and we will publish report dates here as audits complete.

Frameworks

Standards we measure against

SOC 2 (Type II) Ready

Ready
Trust Services Criteria

Controls in place; independent audit of security, availability & confidentiality controls underway.

ISO/IEC 27001

Ready
Information Security Mgmt

Building our ISMS toward certification of the platform and operations.

GDPR

Compliant / Aligned
European Union

Lawful-basis processing, data-subject rights, and transfer safeguards.

PIPEDA

Compliant / Aligned
Canada

Consent, accountability, and access principles for personal information.

Saudi PDPL

Compliant / Aligned
Kingdom of Saudi Arabia

Data-residency and processing aligned to SDAIA's Personal Data Protection Law.

UAE PDPL

Compliant / Aligned
United Arab Emirates

Federal Decree-Law No. 45 of 2021 personal-data handling principles.

Controls In Place Today

How we protect your data

Encryption in transit

All traffic is served over TLS with HSTS preloading; plaintext HTTP is refused and upgraded.

Access control

Admin access is gated by short-lived signed JWTs with least-privilege scopes and forced-strong production secrets.

Secure file handling

Uploads are stored outside the web root with random names, extension allow-listing, and magic-number signature validation — never client-trusted MIME.

Hardened delivery

Content-Security-Policy, anti-clickjacking, nosniff, COOP, and a locked-down Permissions-Policy ship on every response.

Data minimization

We collect only what a procurement match requires, apply defined retention windows, and purge attachments on deletion.

Abuse resistance

Per-IP rate limiting and honeypot anti-spam protect registration and authentication endpoints.

Data Residency & Transfers

Cross-border by design, lawful by default

Operating between Canada and the GCC means personal data may move across borders. We map every transfer to an appropriate safeguard — contractual clauses, consent, or local-residency handling — so data stays protected under whichever of GDPR, PIPEDA, Saudi PDPL, or UAE PDPL applies.

Read the full privacy policy
Canada
PIPEDA
EU
GDPR
GCC
PDPL

Need our security package or a DPA?

Procurement and security teams can request our controls overview, data-processing addendum, and audit status. We'll share our SOC 2 report the moment it's available.