Security at TRANSiA
Last updated September 4, 2026
Encryption
TLS in transit and encryption at rest, with region-scoped keys.
Access control
Role-based access, least privilege, and MFA for sensitive roles.
Tamper-evident audit
A hash-chained audit log records privileged actions and AI decisions.
Data residency
Personal data stays in-region within Canada.
Fraud & risk
Transaction scoring, chargeback handling and anomaly monitoring.
Responsible disclosure
A bug-bounty program rewards researchers who report issues.
Reporting a vulnerability
We welcome responsible disclosure. If you believe you've found a security issue, email security@transia.ca with steps to reproduce. Please do not access data that isn't yours or degrade the service. We aim to acknowledge within 48 hours.
Compliance
We align our controls with SOC 2 principles and operate under Canadian privacy law (PIPEDA). Regional compliance frameworks are tracked and reviewed continuously.