Mizo Named Runner-Up in ConnectWise IT Nation PitchIT Competition 2025 Read the full press release

Security Posture Assessment

Last updated on July 12th, 2026


Executive Summary

Purpose

Mizo is a Software-as-a-Service (SaaS) provided by Mizo Technology Inc. that integrates with customers’ data and leverages AI capabilities. We recognize the importance of safeguarding our customers’ data and maintaining a robust security posture. This Security Posture Assessment and Security Maturity Statement outlines the internal controls, policies, and procedures we have implemented to align with internationally recognized standards such as ISO/IEC 27001. SOC 2 TYPE I/II and FedRAMP/NIST SP 800-53.

This document is not a certification or attestation. Instead, it offers an overview of our current practices and commitments to continuous improvement in information security, privacy, and operational excellence. It is designed to instill confidence in our customers, partners, and stakeholders by demonstrating our alignment with recognized best practices.

We welcome client inquiries and are prepared to provide additional evidence or walkthroughs under a suitable non-disclosure agreement (NDA). Please contact us for more information.

Highlights

The company demonstrates a good security posture. Notably:

  • Implementation of a mature Information Security Management System (ISMS) aligned with recognized best practices.
  • Clearly defined policies and procedures covering all major control domains.
  • A continuous improvement methodology, including ongoing risk assessment, incident response testing, and compliance readiness.
  • Deployment of software engineering best practices across their operations and processes.

Scope & Objectives

Scope

Our Security Assessment covers all operations related to:

  • Operation and maintenance of our internally developed SaaS platform, which interacts with partner and client MSP data
  • Application codebase and architecture
  • Hosting infrastructure
  • Internal management of systems and administrative tools

Objectives

  1. Align our current processes with the requirements and best practices outlined in ISO/IEC 27001:2022, SOC 2 TYPE I/II and FedRAMP/NIST SP 800-53
  2. Identify any gaps or opportunities to strengthen our Information Security Management System (ISMS)
  3. Provide prospective and current clients with a comprehensive overview of our security posture

Reference Frameworks & Methodology Overview

Overview of ISO/IEC 27001:2022

ISO/IEC 27001:2022 is an international standard for managing information security, designed to protect the confidentiality, integrity, and availability of information. The standard revolves around implementing an Information Security Management System (ISMS) and is built on risk-based thinking.

Key Elements:

  • ISMS Framework: Establish policies and procedures to manage risks and ensure information security
  • Risk Assessment: Identify, evaluate, and treat risks systematically
  • Controls: Implement security controls across 14 domains, including access control, cryptography, incident management, and supplier relationships
  • Continuous Improvement: Periodic audits and reviews to ensure the effectiveness of security measures

Overview of SOC 2 Type I/II

SOC 2 (System and Organization Controls) Type I/II focuses on the operational and security controls of a service organization, ensuring it meets trust service principles (TSPs). SOC 2 is particularly relevant for SaaS providers managing customer data.

Trust Service Principles:

  1. Security: Protect systems from unauthorized access (mandatory for SOC 2)
  2. Availability: Ensure systems are available to meet contractual obligations
  3. Processing Integrity: Ensure systems process data accurately and free from errors
  4. Confidentiality: Protect confidential data
  5. Privacy: Manage personal data per customer expectations and regulations

Overview of FedRAMP / NIST SP 800-53

FedRAMP (Federal Risk and Authorization Management Program) is a U.S. government-wide initiative designed to standardize the security assessment, authorization, and continuous monitoring of cloud services. FedRAMP is particularly relevant for cloud service providers (CSPs) seeking to host or process U.S. federal data.

Key Objectives:

  • Standardized Security Approach: Establish a consistent framework for managing risks across federal agencies.
  • Baseline Controls: Derive security controls from NIST SP 800-53, ensuring confidentiality, integrity, and availability of data.
  • Authorization & Continuous Monitoring: Provide a streamlined authorization process (ATO) and require ongoing audits to maintain compliance.
  • Federal Agency Confidence: Enable federal agencies to quickly identify, adopt, and reuse FedRAMP-authorized cloud solutions without repeating lengthy security assessments.

Overview of Software Engineering Best Practices

Software Engineering Best Practices encompass a set of principles, methodologies, and processes aimed at improving the quality, efficiency, and maintainability of software development. These practices ensure consistent, scalable, and error-resistant systems while fostering collaboration and adaptability across teams.

Key Elements:

  • Code Quality: Emphasize clean, modular, and well-documented code to improve readability and reduce errors
  • Version Control: Use tools like Git to track changes, enable collaboration, and maintain a history of code modifications
  • Automated Testing: Implement unit, integration, and system tests to catch bugs early and ensure software reliability
  • Agile Methodologies: Adopt iterative development cycles, continuous feedback, and adaptability to changing requirements
  • DevOps Integration: Combine development and operations through CI/CD pipelines, automated deployments, and infrastructure as code
  • Security Practices: Incorporate secure coding principles, regular code reviews, and vulnerability scanning to safeguard software from threats
  • Documentation and Communication: Maintain clear documentation and foster open communication among stakeholders to align goals and expectations

Compliance Frameworks Alignment

ISO/IEC 27001:2022

Sub-SectionISO/IEC 27001:2022 ReferenceKey Implementation Points
4.1 Governance & LeadershipNot explicitly statedSecurity Steering Committee (SSC) composed of key executives, meets quarterly for ISMS, risk, and compliance reviews
Information Security Manager (ISM) oversees daily security operations, policies, and incident response
4.2 Policy ManagementNot explicitly statedInformation Security Policy reviewed annually by SSC and updated as needed
Acceptable Use Policy (AUP) defines acceptable use of organizational assets; must be acknowledged by employees at onboarding and annually
4.3 Risk Assessment & TreatmentA.6, A.8, A.15Risk Assessment Process: Formal procedure evaluates likelihood & impact; conducted bi-annually or upon major changes
Risk Treatment: Risks scored, documented in Risk Register, and treated (mitigate/accept/transfer/avoid)
SSC Reviews high-impact risks monthly to ensure actions are tracked
4.4 Asset ManagementA.8Asset Inventory: Automated discovery integrated with CMDB (tracks hardware, software)
Data Classification: Public, Internal, Sensitive, Confidential, with defined handling procedures
Disposal & Decommission: Wiping per NIST 800-88, formal disposal certificates required
4.5 Access ControlA.9Access Management Policy: Least privilege; MFA required for admin/remote access
User Lifecycle: Onboarding (role approvals), Offboarding (access revoked within 24 hours, automated checks)
Privileged Access Reviews: Quarterly, disable unnecessary or dormant accounts, log and store admin actions for one year
4.6 Cryptography & Secure CommunicationsA.10Cryptographic Controls: AES-256 for data at rest; TLS 1.2/1.3 in transit; HSMs for critical key management
Key Management: Formal policy for key generation, distribution, rotation, and revocation
Key Rotation: Annually or if compromise is suspected
4.7 Physical & Environmental SecurityA.11Data storage: All data is hosted securely in the cloud and is not stored or accessible on-site. Access to our office is strictly controlled; all visitors must be accompanied by authorized personnel at all times.
4.8 Operations SecurityA.12Operational Procedures: Change management (documented workflow, peer reviews, rollback); release mgmt. (bi-weekly SaaS deployments with CI/CD)
Logging & Monitoring: Logs forwarded to SIEM for near real-time anomaly detection
4.9 Communications SecurityA.13Network Security: Segmented networks (prod, test, corporate); VPN + MFA for production access
Secure Data Transfer: SFTP/HTTPS enforced for data exchange; email DLP to detect/flag sensitive data
4.10 System Acquisition, Development & MaintenanceA.14Secure Development: Adherence to OWASP Top 10 and SANS 25
4.11 Supplier RelationshipsA.15Suppliers: We exclusively use SaaS vendors with proven maturity and reliability, such as Microsoft, ensuring high standards of security and compliance.
4.12 Information Security Incident ManagementA.16Incident Response Plan: Defines roles, responsibilities, escalation, detection, containment, eradication, recovery
Testing & Drills: Bi-annual tabletop exercises (ransomware/insider threat); post-incident reviews and root cause analyses
Incident Log: Central ticketing of security events and responses
4.13 Business Continuity ManagementA.17Business Impact Analysis (BIA): Identifies critical processes, defines RTO/RPO, updated annually
Disaster Recovery (DR): Redundant infrastructure in separate data centers; annual DR drills to validate restore procedures
4.14 ComplianceA.18Regulatory/Contractual Compliance: Monitoring data protection laws (GDPR, etc.), fulfilling client obligations
Audit & Review: Annual ISMS audits; external audits (financial) can verify some security measures

SOC 2 Type I/II

CategorySub-SectionKey Implementation Points
SecurityAccess ControlAccess control: Role-based access control (RBAC) for all systems and environments
Access rights: Principle of least privilege enforced for all access levels
Authentication: Multi-factor authentication (MFA) on critical systems
SecurityIncident ResponseIncident response: Defined incident response plan (roles & responsibilities)
Testing & Drills: Bi-annual tabletop exercises (ransomware/insider threat); post-incident reviews and root cause analyses
Process improvement: Post-incident reviews for process improvement
SecuritySystem HardeningSecurity testing: Regular vulnerability scans and penetration tests
AvailabilitySystem MonitoringMonitoring: 24/7 system monitoring with automated anomaly alerts
AvailabilityDisaster Recovery & Business ContinuityDisaster Recovery Plan: Fully documented and tested disaster recovery plan (DRP)
Backups & Retention: Encrypted offsite backups with periodic restoration tests
AvailabilityScalable InfrastructureInfrastructure: Cloud-native architecture for high availability and quick recovery
Redundancy: Redundancy in critical systems to prevent single points of failure
Processing IntegrityQuality Assurance (QA)Testing practices: Automated + manual testing to ensure functional and security requirements
Deployment procedure: Continuous integration/continuous deployment (CI/CD) with automated checks
Processing IntegrityData AccuracyData Validations: Data validation mechanisms at input
Error Handling: Redundant error-handling processes to prevent data corruption
ConfidentialityData EncryptionEncryption: Data encrypted in transit (TLS 1.2+) and at rest (AES-256)
ConfidentialityData MinimizationMinimum Data Collection Policy: Only necessary data is collected for business purposes
Retention Policies: Regular reviews of retention policies to ensure regulatory compliance
ConfidentialityThird-Party Risk ManagementVendor Risk: Vendor assessments for security/confidentiality compliance
Data Protection: Contracts include data protection agreements
PrivacyPrivacy ProgramData Privacy: Privacy policies aligned with Loi 25 (Québec) and relevant regulations
Data Handling: Transparent data handling practices communicated to clients and end users
PrivacyData Subject RightsData Subject Rights: Mechanisms allowing individuals to access, correct, or delete their data
Data Processes: Processes to handle requests within regulatory timelines
PrivacyTraining & AwarenessTraining: Ongoing security/privacy training for all team members
Awareness: Regular awareness campaigns to reinforce best practices

FedRAMP / NIST SP 800-53

CategorySub-SectionKey Implementation Points
SecurityAccess ControlAccess control: Role-based access control (RBAC) for systems and environments
Access rights: Principle of least privilege enforced at all access levels
Authentication: Multi-factor authentication (MFA) on critical systems
SecurityIncident ResponseIncident response: Defined plan with roles and responsibilities
Testing & drills: Regular tabletop exercises (e.g., ransomware/insider threat scenarios)
Process improvement: Post-incident reviews and root cause analyses
SecuritySystem HardeningVulnerability scans: Regular scans to identify security weaknesses
Penetration tests: Scheduled tests to probe for exploitable vulnerabilities
AvailabilitySystem MonitoringMonitoring: 24/7 system surveillance with automated anomaly alerts
AvailabilityDisaster Recovery & Business ContinuityDR Plan: Fully documented and tested disaster recovery plan (DRP)
Data backup: Regular backups with encrypted offsite storage
Restoration tests: Periodic validations to confirm backup integrity
AvailabilityScalable InfrastructureCloud architecture: Cloud-native design to ensure high availability
Redundancy: Built into critical systems to prevent single points of failure
Processing IntegrityQuality Assurance (QA)Testing framework: Automated and manual testing (unit, integration, regression, security)
CI/CD pipelines: Enforce automated checks to maintain code quality
Processing IntegrityData AccuracyValidation: Mechanisms at input points to ensure correctness
Error handling: Designed to prevent data corruption
ConfidentialityData EncryptionTransport encryption: TLS 1.2+ for data in transit
At-rest encryption: AES-256 for stored data
ConfidentialityData MinimizationMinimal collection: Only strictly necessary data is collected
Retention reviews: Regular checks of data retention policies to ensure compliance
ConfidentialityThird-Party Risk ManagementVendor assessments: Ensure security/confidentiality compliance
Data protection: Contracts include data protection agreements
PrivacyPrivacy ProgramPolicy alignment: Meets Loi 25 (Québec) and other relevant regulations
Transparency: Data handling practices communicated to clients/end users
PrivacyData Subject RightsAccess & correction: Mechanisms for individuals to manage their data
Timely response: Requests handled within regulatory deadlines
PrivacyTraining & AwarenessSecurity training: Ongoing education for all team members
Awareness campaigns: Reinforce best practices regularly
PrivacyData Handling & AI TrainingData usage: Data is used strictly for operational needs (no repurposing)
AI model training: No data is used for model training

Software Engineering Best Practices

CategoryKey Implementation Points
Commitment to Secure and Local HostingCanadian Hosting Exclusivity: All platform operations hosted within Canada, ensuring data remains in-country and compliant with local regulations
Data Residency Assurance: Cloud providers guaranteeing Canadian data residency, assessed against ISO/IEC 27001/SOC 2
Performance and Redundancy: Scalable Canadian infrastructure for low latency, data integrity, and high availability
Responsible AI IntegrationPrivacy-First AI Practices: AI services do not use customer data for training; each model is isolated for a single instance
AI Model Management: Secure deployment with restricted access; data minimization at input; temporary data is encrypted in transit/at rest and purged after use
Data Collection: Only strictly required data is collected for Mizo functionality to ensure minimal data exposure
Data Usage: Data is used strictly for operational needs and not repurposed for any external or unauthorized use
Advanced Development and Security PracticesRigorous Testing Framework: Continuous automated and manual testing (unit, integration, regression, security) to identify issues early
Code Quality Standards: Peer-reviewed code, static/dynamic analysis tools, and secure coding guidelines to prevent vulnerabilities and maintain high standards
Dependency Management & Supply Chain SecurityDependency Scanning & Updates: Frequent scanning of third-party libraries; automated updates to address known exploits
Supply Chain Integrity: Trusted/verified sources only, with proactive monitoring and rapid response to emerging threats in the supply chain
Leveraging Trusted Partners with Canadian OperationsMicrosoft Shared Responsibility Model: For SaaS, leverage Microsoft security foundation while securing configurations and data; for IaaS, secure OS, apps, and network configurations
Compliance Through Partnership: Microsoft’s ISO/IEC 27001, SOC 2, GDPR compliance plus Canadian-hosted infrastructure ensures adherence to local regulations and high operational confidence
Data Protection & Retention PoliciesEncryption Standards: Data in transit (TLS 1.2+) and at rest (AES-256), with secure key management (KMS)
Retention Policies: Retain only necessary data for operational/legal requirements; securely delete outdated/unnecessary data to meet privacy regulations

Data Subprocessors

As part of its operations, Mizo collects and stores data in order to perform its function. Mizo enforces a minimum data collection policy. All collection is further restricted through API scopes and permissions when connecting integrations.

Section 1. Core Service Subprocessors

The following Sub-Processors are engaged by Provider in the delivery of the core Service. All Sub-Processors in this Section process Customer Data exclusively within Canada.

ProviderUsageData CollectedData Center
Microsoft AzureCloud hosting, infrastructure, LLM Inference, Logs and security servicesTicket summary and analysis, KB summary and analysis, company contact information, user accountsCanada
MongoDB, Inc.Database serviceTicket summary and analysis, KB summary and analysisCanada
QDrant, Inc.Database serviceTicket summary and analysis, KB summary and analysisCanada
Okta, Inc.Authentication and authorizationDirect user accounts, Direct user emailsCanada

Section 2. Business Operations Subprocessors

The following Sub-Processors are engaged by Provider for internal business operations. These Sub-Processors are located in the United States.

ProviderUsageData CollectedData Center
Twilio, Inc.Email and SMS notification delivery (Ex: Password resets)Names, email addresses, notification identifiersUnited States
Microsoft 365Internal business communicationsStaff names, email addresses, communication metadataUnited States
PipeDrive, Inc.CRM and sales pipeline managementCustomer contact names, email addressesUnited States
Lemlist, Inc.Email marketing and outreachContact names, email addressesUnited States

Incident Handling

CategoryKey Implementation Points
DisclosureInitial notification: Within 48 hours of breach confirmation to all affected customers
Preliminary assessment: Impact assessment included in initial notification
Dedicated contact: Incident response contact assigned to each affected customer
Follow-up reports: Detailed reports within 14 business days (root cause, scope, remediation, customer actions)
Customer ResponsibilityRegulatory notification: Customers remain responsible for notifying their end-clients and regulatory authorities as required by applicable laws (PIPEDA, state breach notification laws, etc.)
Incident Response ProcessDocumentation: Documented incident response plan with defined escalation paths
Monitoring: 24/7 monitoring capabilities
Testing: Regular tabletop exercises to validate response procedures

Data Export

CategoryKey Implementation Points
Standard Export PackageTicket data: All ticket triage data and AI analysis
Knowledge base: Articles and embeddings
Integration settings: Sanitized of credentials
Analytics: Historical analytics and reporting data
Audit logs: Related to customer data
Export Formats & DeliveryFormat: JSON (structured machine-readable format)
Delivery: Secure encrypted download link
Standard datasets: Within 5 business days
Large datasets: (>100GB) within 10 business days
Request method: Submit via support ticket
Data DestructionDestruction certificate: Attesting to complete data deletion
Production deletion: Within 30 days of account termination or customer request
Backup deletion: Within 90 days of account termination or customer request
Certificate details: Includes data types, deletion date, and authorized signatory

Penetration Testing

Mizo engages qualified independent security firms to conduct annual penetration testing covering application, API, and infrastructure layers. Testing follows industry-standard methodologies (OWASP, PTES).

Latest Assessment

Last testSeptember 2025
Testing firmVumetric (a TELUS Security company)
Next scheduledSeptember 2026

Scope

  • Application Layer
  • API Layer
  • Infrastructure

Requesting the Report

Penetration test summaries are available to customers under NDA upon written request. Contact [email protected] to request a copy of the report findings summary.


Recovery Objectives

Tthe following are design targets reflecting Mizo’s infrastructure architecture. They are not guaranteed SLA commitments and their non-attainment does not give rise to Service Credits.

TargetValueDescription
Recovery Time Objective (RTO)12 hoursMaximum target time from confirmed Service disruption to restoration of functionality
Recovery Point Objective (RPO)6 hourMaximum target data loss window, based on hourly incremental backup cadence

Backup Schedule

TypeFrequencyRetention
IncrementalHourly7 days
FullDaily90 days

Infrastructure

  • Primary region: Azure Canada Central
  • DR region: Azure Canada East (replication only)
  • Encryption: AES-256 at rest for all backup data
  • DR testing: Conducted at least annually and upon any material infrastructure change

Incident Response Contacts

Mizo’s current incident response contacts are listed below.

RoleContactAvailability
Security Lead[email protected]Business Hours (Mon–Fri, 9–5 ET)
Urgent Escalation[email protected]P0/P1 — commercially reasonable best efforts outside Business Hours. Add Urgent notice to the email
CEO (final escalation)[email protected]As needed

Reporting a Security Incident or Vulnerability

  1. Email [email protected] with a description of the issue
  2. For P0/P1 severity, also include and Urgent notice in the email
  3. Mizo will acknowledge receipt within 48 Business Hours for security reports.

Privacy Officer

NameRoleContactAvailability
Mathieu TougasPrivacy Officer[email protected]As needed

Submitting a Privacy Request

  1. Email [email protected] with a description of your request (e.g., access, correction, deletion, portability)
  2. Include the name and email address of the data subject, if applicable
  3. Mizo will acknowledge receipt within 5 Business Days and respond substantively within 15 Business Days, or as required by Applicable Privacy Law, whichever is shorter

Roadmap Findings, Improvements & Roadmap

Major Strengths

StrengthDetails
Established Best PracticesFrom inception, the team implemented industry-leading standards for development, security, and operations, ensuring robust processes and scalable practices
Streamlined EfficiencyLeveraging the team’s expertise, workflows are designed to maximize productivity and minimize overhead, enabling rapid delivery without compromising quality
Cloud-Native ArchitectureA commitment to modern, cloud-native technologies has resulted in high availability, seamless scalability, and reduced operational complexity
Rapid AdaptabilityLeveraging extensive experience, the team quickly pivots and adapts to changes, embracing continuous learning and improvement

Opportunities for Improvement

OpportunityDetails
Enhanced DocumentationWhile processes are efficient, formalizing and expanding documentation can further support scalability, onboarding, and knowledge sharing
Diversity of ExpertiseIntroducing new team members with complementary skills or perspectives could bring improved approaches to problem-solving
Tooling OptimizationRegularly evaluating and fine-tuning the current tech stack ensures the team is leveraging the most effective tools for productivity and collaboration.

Roadmap

TimeframeObjectives
Q1 2026• Align more closely with SOC 2 Type II Trust Principles to serve US-based clientele
Q4 2026• Pursue SOC 2 Type II Certification

Revision History

VersionDateAuthorNotes
1.2.12026/07/02Mathieu Tougas• Updated Corportate Entity Name
1.2.02026/04/07Mathieu Tougas• Added Penetration Testing, Recovery Objectives and Incident Response sections. Update subprocessor format
1.1.12026/03/18Mathieu Tougas• Updated data subprocessors
1.1.02025/11/21Mathieu Tougas• Added Incident Handling and Data Export sections
• Updated roadmap timelines
1.0.12025/01/10Mathieu Tougas• Updated data subprocessors
1.0.02024/10/15Gabriel Blais-Bourget• Initial version