Security Posture Assessment
Last updated on July 12th, 2026
Executive Summary
Purpose
Mizo is a Software-as-a-Service (SaaS) provided by Mizo Technology Inc. that integrates with customers’ data and leverages AI capabilities. We recognize the importance of safeguarding our customers’ data and maintaining a robust security posture. This Security Posture Assessment and Security Maturity Statement outlines the internal controls, policies, and procedures we have implemented to align with internationally recognized standards such as ISO/IEC 27001. SOC 2 TYPE I/II and FedRAMP/NIST SP 800-53.
This document is not a certification or attestation. Instead, it offers an overview of our current practices and commitments to continuous improvement in information security, privacy, and operational excellence. It is designed to instill confidence in our customers, partners, and stakeholders by demonstrating our alignment with recognized best practices.
We welcome client inquiries and are prepared to provide additional evidence or walkthroughs under a suitable non-disclosure agreement (NDA). Please contact us for more information.
Highlights
The company demonstrates a good security posture. Notably:
- Implementation of a mature Information Security Management System (ISMS) aligned with recognized best practices.
- Clearly defined policies and procedures covering all major control domains.
- A continuous improvement methodology, including ongoing risk assessment, incident response testing, and compliance readiness.
- Deployment of software engineering best practices across their operations and processes.
Scope & Objectives
Scope
Our Security Assessment covers all operations related to:
- Operation and maintenance of our internally developed SaaS platform, which interacts with partner and client MSP data
- Application codebase and architecture
- Hosting infrastructure
- Internal management of systems and administrative tools
Objectives
- Align our current processes with the requirements and best practices outlined in ISO/IEC 27001:2022, SOC 2 TYPE I/II and FedRAMP/NIST SP 800-53
- Identify any gaps or opportunities to strengthen our Information Security Management System (ISMS)
- Provide prospective and current clients with a comprehensive overview of our security posture
Reference Frameworks & Methodology Overview
Overview of ISO/IEC 27001:2022
ISO/IEC 27001:2022 is an international standard for managing information security, designed to protect the confidentiality, integrity, and availability of information. The standard revolves around implementing an Information Security Management System (ISMS) and is built on risk-based thinking.
Key Elements:
- ISMS Framework: Establish policies and procedures to manage risks and ensure information security
- Risk Assessment: Identify, evaluate, and treat risks systematically
- Controls: Implement security controls across 14 domains, including access control, cryptography, incident management, and supplier relationships
- Continuous Improvement: Periodic audits and reviews to ensure the effectiveness of security measures
Overview of SOC 2 Type I/II
SOC 2 (System and Organization Controls) Type I/II focuses on the operational and security controls of a service organization, ensuring it meets trust service principles (TSPs). SOC 2 is particularly relevant for SaaS providers managing customer data.
Trust Service Principles:
- Security: Protect systems from unauthorized access (mandatory for SOC 2)
- Availability: Ensure systems are available to meet contractual obligations
- Processing Integrity: Ensure systems process data accurately and free from errors
- Confidentiality: Protect confidential data
- Privacy: Manage personal data per customer expectations and regulations
Overview of FedRAMP / NIST SP 800-53
FedRAMP (Federal Risk and Authorization Management Program) is a U.S. government-wide initiative designed to standardize the security assessment, authorization, and continuous monitoring of cloud services. FedRAMP is particularly relevant for cloud service providers (CSPs) seeking to host or process U.S. federal data.
Key Objectives:
- Standardized Security Approach: Establish a consistent framework for managing risks across federal agencies.
- Baseline Controls: Derive security controls from NIST SP 800-53, ensuring confidentiality, integrity, and availability of data.
- Authorization & Continuous Monitoring: Provide a streamlined authorization process (ATO) and require ongoing audits to maintain compliance.
- Federal Agency Confidence: Enable federal agencies to quickly identify, adopt, and reuse FedRAMP-authorized cloud solutions without repeating lengthy security assessments.
Overview of Software Engineering Best Practices
Software Engineering Best Practices encompass a set of principles, methodologies, and processes aimed at improving the quality, efficiency, and maintainability of software development. These practices ensure consistent, scalable, and error-resistant systems while fostering collaboration and adaptability across teams.
Key Elements:
- Code Quality: Emphasize clean, modular, and well-documented code to improve readability and reduce errors
- Version Control: Use tools like Git to track changes, enable collaboration, and maintain a history of code modifications
- Automated Testing: Implement unit, integration, and system tests to catch bugs early and ensure software reliability
- Agile Methodologies: Adopt iterative development cycles, continuous feedback, and adaptability to changing requirements
- DevOps Integration: Combine development and operations through CI/CD pipelines, automated deployments, and infrastructure as code
- Security Practices: Incorporate secure coding principles, regular code reviews, and vulnerability scanning to safeguard software from threats
- Documentation and Communication: Maintain clear documentation and foster open communication among stakeholders to align goals and expectations
Compliance Frameworks Alignment
ISO/IEC 27001:2022
| Sub-Section | ISO/IEC 27001:2022 Reference | Key Implementation Points |
|---|---|---|
| 4.1 Governance & Leadership | Not explicitly stated | • Security Steering Committee (SSC) composed of key executives, meets quarterly for ISMS, risk, and compliance reviews • Information Security Manager (ISM) oversees daily security operations, policies, and incident response |
| 4.2 Policy Management | Not explicitly stated | • Information Security Policy reviewed annually by SSC and updated as needed • Acceptable Use Policy (AUP) defines acceptable use of organizational assets; must be acknowledged by employees at onboarding and annually |
| 4.3 Risk Assessment & Treatment | A.6, A.8, A.15 | • Risk Assessment Process: Formal procedure evaluates likelihood & impact; conducted bi-annually or upon major changes • Risk Treatment: Risks scored, documented in Risk Register, and treated (mitigate/accept/transfer/avoid) • SSC Reviews high-impact risks monthly to ensure actions are tracked |
| 4.4 Asset Management | A.8 | • Asset Inventory: Automated discovery integrated with CMDB (tracks hardware, software) • Data Classification: Public, Internal, Sensitive, Confidential, with defined handling procedures • Disposal & Decommission: Wiping per NIST 800-88, formal disposal certificates required |
| 4.5 Access Control | A.9 | • Access Management Policy: Least privilege; MFA required for admin/remote access • User Lifecycle: Onboarding (role approvals), Offboarding (access revoked within 24 hours, automated checks) • Privileged Access Reviews: Quarterly, disable unnecessary or dormant accounts, log and store admin actions for one year |
| 4.6 Cryptography & Secure Communications | A.10 | • Cryptographic Controls: AES-256 for data at rest; TLS 1.2/1.3 in transit; HSMs for critical key management • Key Management: Formal policy for key generation, distribution, rotation, and revocation • Key Rotation: Annually or if compromise is suspected |
| 4.7 Physical & Environmental Security | A.11 | • Data storage: All data is hosted securely in the cloud and is not stored or accessible on-site. Access to our office is strictly controlled; all visitors must be accompanied by authorized personnel at all times. |
| 4.8 Operations Security | A.12 | • Operational Procedures: Change management (documented workflow, peer reviews, rollback); release mgmt. (bi-weekly SaaS deployments with CI/CD) • Logging & Monitoring: Logs forwarded to SIEM for near real-time anomaly detection |
| 4.9 Communications Security | A.13 | • Network Security: Segmented networks (prod, test, corporate); VPN + MFA for production access • Secure Data Transfer: SFTP/HTTPS enforced for data exchange; email DLP to detect/flag sensitive data |
| 4.10 System Acquisition, Development & Maintenance | A.14 | • Secure Development: Adherence to OWASP Top 10 and SANS 25 |
| 4.11 Supplier Relationships | A.15 | • Suppliers: We exclusively use SaaS vendors with proven maturity and reliability, such as Microsoft, ensuring high standards of security and compliance. |
| 4.12 Information Security Incident Management | A.16 | • Incident Response Plan: Defines roles, responsibilities, escalation, detection, containment, eradication, recovery • Testing & Drills: Bi-annual tabletop exercises (ransomware/insider threat); post-incident reviews and root cause analyses • Incident Log: Central ticketing of security events and responses |
| 4.13 Business Continuity Management | A.17 | • Business Impact Analysis (BIA): Identifies critical processes, defines RTO/RPO, updated annually • Disaster Recovery (DR): Redundant infrastructure in separate data centers; annual DR drills to validate restore procedures |
| 4.14 Compliance | A.18 | • Regulatory/Contractual Compliance: Monitoring data protection laws (GDPR, etc.), fulfilling client obligations • Audit & Review: Annual ISMS audits; external audits (financial) can verify some security measures |
SOC 2 Type I/II
| Category | Sub-Section | Key Implementation Points |
|---|---|---|
| Security | Access Control | • Access control: Role-based access control (RBAC) for all systems and environments • Access rights: Principle of least privilege enforced for all access levels • Authentication: Multi-factor authentication (MFA) on critical systems |
| Security | Incident Response | • Incident response: Defined incident response plan (roles & responsibilities) • Testing & Drills: Bi-annual tabletop exercises (ransomware/insider threat); post-incident reviews and root cause analyses • Process improvement: Post-incident reviews for process improvement |
| Security | System Hardening | • Security testing: Regular vulnerability scans and penetration tests |
| Availability | System Monitoring | • Monitoring: 24/7 system monitoring with automated anomaly alerts |
| Availability | Disaster Recovery & Business Continuity | • Disaster Recovery Plan: Fully documented and tested disaster recovery plan (DRP) • Backups & Retention: Encrypted offsite backups with periodic restoration tests |
| Availability | Scalable Infrastructure | • Infrastructure: Cloud-native architecture for high availability and quick recovery • Redundancy: Redundancy in critical systems to prevent single points of failure |
| Processing Integrity | Quality Assurance (QA) | • Testing practices: Automated + manual testing to ensure functional and security requirements • Deployment procedure: Continuous integration/continuous deployment (CI/CD) with automated checks |
| Processing Integrity | Data Accuracy | • Data Validations: Data validation mechanisms at input • Error Handling: Redundant error-handling processes to prevent data corruption |
| Confidentiality | Data Encryption | • Encryption: Data encrypted in transit (TLS 1.2+) and at rest (AES-256) |
| Confidentiality | Data Minimization | • Minimum Data Collection Policy: Only necessary data is collected for business purposes • Retention Policies: Regular reviews of retention policies to ensure regulatory compliance |
| Confidentiality | Third-Party Risk Management | • Vendor Risk: Vendor assessments for security/confidentiality compliance • Data Protection: Contracts include data protection agreements |
| Privacy | Privacy Program | • Data Privacy: Privacy policies aligned with Loi 25 (Québec) and relevant regulations • Data Handling: Transparent data handling practices communicated to clients and end users |
| Privacy | Data Subject Rights | • Data Subject Rights: Mechanisms allowing individuals to access, correct, or delete their data • Data Processes: Processes to handle requests within regulatory timelines |
| Privacy | Training & Awareness | • Training: Ongoing security/privacy training for all team members • Awareness: Regular awareness campaigns to reinforce best practices |
FedRAMP / NIST SP 800-53
| Category | Sub-Section | Key Implementation Points |
|---|---|---|
| Security | Access Control | • Access control: Role-based access control (RBAC) for systems and environments • Access rights: Principle of least privilege enforced at all access levels • Authentication: Multi-factor authentication (MFA) on critical systems |
| Security | Incident Response | • Incident response: Defined plan with roles and responsibilities • Testing & drills: Regular tabletop exercises (e.g., ransomware/insider threat scenarios) • Process improvement: Post-incident reviews and root cause analyses |
| Security | System Hardening | • Vulnerability scans: Regular scans to identify security weaknesses • Penetration tests: Scheduled tests to probe for exploitable vulnerabilities |
| Availability | System Monitoring | • Monitoring: 24/7 system surveillance with automated anomaly alerts |
| Availability | Disaster Recovery & Business Continuity | • DR Plan: Fully documented and tested disaster recovery plan (DRP) • Data backup: Regular backups with encrypted offsite storage • Restoration tests: Periodic validations to confirm backup integrity |
| Availability | Scalable Infrastructure | • Cloud architecture: Cloud-native design to ensure high availability • Redundancy: Built into critical systems to prevent single points of failure |
| Processing Integrity | Quality Assurance (QA) | • Testing framework: Automated and manual testing (unit, integration, regression, security) • CI/CD pipelines: Enforce automated checks to maintain code quality |
| Processing Integrity | Data Accuracy | • Validation: Mechanisms at input points to ensure correctness • Error handling: Designed to prevent data corruption |
| Confidentiality | Data Encryption | • Transport encryption: TLS 1.2+ for data in transit • At-rest encryption: AES-256 for stored data |
| Confidentiality | Data Minimization | • Minimal collection: Only strictly necessary data is collected • Retention reviews: Regular checks of data retention policies to ensure compliance |
| Confidentiality | Third-Party Risk Management | • Vendor assessments: Ensure security/confidentiality compliance • Data protection: Contracts include data protection agreements |
| Privacy | Privacy Program | • Policy alignment: Meets Loi 25 (Québec) and other relevant regulations • Transparency: Data handling practices communicated to clients/end users |
| Privacy | Data Subject Rights | • Access & correction: Mechanisms for individuals to manage their data • Timely response: Requests handled within regulatory deadlines |
| Privacy | Training & Awareness | • Security training: Ongoing education for all team members • Awareness campaigns: Reinforce best practices regularly |
| Privacy | Data Handling & AI Training | • Data usage: Data is used strictly for operational needs (no repurposing) • AI model training: No data is used for model training |
Software Engineering Best Practices
| Category | Key Implementation Points |
|---|---|
| Commitment to Secure and Local Hosting | • Canadian Hosting Exclusivity: All platform operations hosted within Canada, ensuring data remains in-country and compliant with local regulations • Data Residency Assurance: Cloud providers guaranteeing Canadian data residency, assessed against ISO/IEC 27001/SOC 2 • Performance and Redundancy: Scalable Canadian infrastructure for low latency, data integrity, and high availability |
| Responsible AI Integration | • Privacy-First AI Practices: AI services do not use customer data for training; each model is isolated for a single instance • AI Model Management: Secure deployment with restricted access; data minimization at input; temporary data is encrypted in transit/at rest and purged after use • Data Collection: Only strictly required data is collected for Mizo functionality to ensure minimal data exposure • Data Usage: Data is used strictly for operational needs and not repurposed for any external or unauthorized use |
| Advanced Development and Security Practices | • Rigorous Testing Framework: Continuous automated and manual testing (unit, integration, regression, security) to identify issues early • Code Quality Standards: Peer-reviewed code, static/dynamic analysis tools, and secure coding guidelines to prevent vulnerabilities and maintain high standards |
| Dependency Management & Supply Chain Security | • Dependency Scanning & Updates: Frequent scanning of third-party libraries; automated updates to address known exploits • Supply Chain Integrity: Trusted/verified sources only, with proactive monitoring and rapid response to emerging threats in the supply chain |
| Leveraging Trusted Partners with Canadian Operations | • Microsoft Shared Responsibility Model: For SaaS, leverage Microsoft security foundation while securing configurations and data; for IaaS, secure OS, apps, and network configurations • Compliance Through Partnership: Microsoft’s ISO/IEC 27001, SOC 2, GDPR compliance plus Canadian-hosted infrastructure ensures adherence to local regulations and high operational confidence |
| Data Protection & Retention Policies | • Encryption Standards: Data in transit (TLS 1.2+) and at rest (AES-256), with secure key management (KMS) • Retention Policies: Retain only necessary data for operational/legal requirements; securely delete outdated/unnecessary data to meet privacy regulations |
Data Subprocessors
As part of its operations, Mizo collects and stores data in order to perform its function. Mizo enforces a minimum data collection policy. All collection is further restricted through API scopes and permissions when connecting integrations.
Section 1. Core Service Subprocessors
The following Sub-Processors are engaged by Provider in the delivery of the core Service. All Sub-Processors in this Section process Customer Data exclusively within Canada.
| Provider | Usage | Data Collected | Data Center |
|---|---|---|---|
| Microsoft Azure | Cloud hosting, infrastructure, LLM Inference, Logs and security services | Ticket summary and analysis, KB summary and analysis, company contact information, user accounts | Canada |
| MongoDB, Inc. | Database service | Ticket summary and analysis, KB summary and analysis | Canada |
| QDrant, Inc. | Database service | Ticket summary and analysis, KB summary and analysis | Canada |
| Okta, Inc. | Authentication and authorization | Direct user accounts, Direct user emails | Canada |
Section 2. Business Operations Subprocessors
The following Sub-Processors are engaged by Provider for internal business operations. These Sub-Processors are located in the United States.
| Provider | Usage | Data Collected | Data Center |
|---|---|---|---|
| Twilio, Inc. | Email and SMS notification delivery (Ex: Password resets) | Names, email addresses, notification identifiers | United States |
| Microsoft 365 | Internal business communications | Staff names, email addresses, communication metadata | United States |
| PipeDrive, Inc. | CRM and sales pipeline management | Customer contact names, email addresses | United States |
| Lemlist, Inc. | Email marketing and outreach | Contact names, email addresses | United States |
Incident Handling
| Category | Key Implementation Points |
|---|---|
| Disclosure | • Initial notification: Within 48 hours of breach confirmation to all affected customers • Preliminary assessment: Impact assessment included in initial notification • Dedicated contact: Incident response contact assigned to each affected customer • Follow-up reports: Detailed reports within 14 business days (root cause, scope, remediation, customer actions) |
| Customer Responsibility | • Regulatory notification: Customers remain responsible for notifying their end-clients and regulatory authorities as required by applicable laws (PIPEDA, state breach notification laws, etc.) |
| Incident Response Process | • Documentation: Documented incident response plan with defined escalation paths • Monitoring: 24/7 monitoring capabilities • Testing: Regular tabletop exercises to validate response procedures |
Data Export
| Category | Key Implementation Points |
|---|---|
| Standard Export Package | • Ticket data: All ticket triage data and AI analysis • Knowledge base: Articles and embeddings • Integration settings: Sanitized of credentials • Analytics: Historical analytics and reporting data • Audit logs: Related to customer data |
| Export Formats & Delivery | • Format: JSON (structured machine-readable format) • Delivery: Secure encrypted download link • Standard datasets: Within 5 business days • Large datasets: (>100GB) within 10 business days • Request method: Submit via support ticket |
| Data Destruction | • Destruction certificate: Attesting to complete data deletion • Production deletion: Within 30 days of account termination or customer request • Backup deletion: Within 90 days of account termination or customer request • Certificate details: Includes data types, deletion date, and authorized signatory |
Penetration Testing
Mizo engages qualified independent security firms to conduct annual penetration testing covering application, API, and infrastructure layers. Testing follows industry-standard methodologies (OWASP, PTES).
Latest Assessment
| Last test | September 2025 |
| Testing firm | Vumetric (a TELUS Security company) |
| Next scheduled | September 2026 |
Scope
- Application Layer
- API Layer
- Infrastructure
Requesting the Report
Penetration test summaries are available to customers under NDA upon written request. Contact [email protected] to request a copy of the report findings summary.
Recovery Objectives
Tthe following are design targets reflecting Mizo’s infrastructure architecture. They are not guaranteed SLA commitments and their non-attainment does not give rise to Service Credits.
| Target | Value | Description |
|---|---|---|
| Recovery Time Objective (RTO) | 12 hours | Maximum target time from confirmed Service disruption to restoration of functionality |
| Recovery Point Objective (RPO) | 6 hour | Maximum target data loss window, based on hourly incremental backup cadence |
Backup Schedule
| Type | Frequency | Retention |
|---|---|---|
| Incremental | Hourly | 7 days |
| Full | Daily | 90 days |
Infrastructure
- Primary region: Azure Canada Central
- DR region: Azure Canada East (replication only)
- Encryption: AES-256 at rest for all backup data
- DR testing: Conducted at least annually and upon any material infrastructure change
Incident Response Contacts
Mizo’s current incident response contacts are listed below.
| Role | Contact | Availability |
|---|---|---|
| Security Lead | [email protected] | Business Hours (Mon–Fri, 9–5 ET) |
| Urgent Escalation | [email protected] | P0/P1 — commercially reasonable best efforts outside Business Hours. Add Urgent notice to the email |
| CEO (final escalation) | [email protected] | As needed |
Reporting a Security Incident or Vulnerability
- Email [email protected] with a description of the issue
- For P0/P1 severity, also include and Urgent notice in the email
- Mizo will acknowledge receipt within 48 Business Hours for security reports.
Privacy Officer
| Name | Role | Contact | Availability |
|---|---|---|---|
| Mathieu Tougas | Privacy Officer | [email protected] | As needed |
Submitting a Privacy Request
- Email [email protected] with a description of your request (e.g., access, correction, deletion, portability)
- Include the name and email address of the data subject, if applicable
- Mizo will acknowledge receipt within 5 Business Days and respond substantively within 15 Business Days, or as required by Applicable Privacy Law, whichever is shorter
Roadmap Findings, Improvements & Roadmap
Major Strengths
| Strength | Details |
|---|---|
| Established Best Practices | From inception, the team implemented industry-leading standards for development, security, and operations, ensuring robust processes and scalable practices |
| Streamlined Efficiency | Leveraging the team’s expertise, workflows are designed to maximize productivity and minimize overhead, enabling rapid delivery without compromising quality |
| Cloud-Native Architecture | A commitment to modern, cloud-native technologies has resulted in high availability, seamless scalability, and reduced operational complexity |
| Rapid Adaptability | Leveraging extensive experience, the team quickly pivots and adapts to changes, embracing continuous learning and improvement |
Opportunities for Improvement
| Opportunity | Details |
|---|---|
| Enhanced Documentation | While processes are efficient, formalizing and expanding documentation can further support scalability, onboarding, and knowledge sharing |
| Diversity of Expertise | Introducing new team members with complementary skills or perspectives could bring improved approaches to problem-solving |
| Tooling Optimization | Regularly evaluating and fine-tuning the current tech stack ensures the team is leveraging the most effective tools for productivity and collaboration. |
Roadmap
| Timeframe | Objectives |
|---|---|
| Q1 2026 | • Align more closely with SOC 2 Type II Trust Principles to serve US-based clientele |
| Q4 2026 | • Pursue SOC 2 Type II Certification |
Revision History
| Version | Date | Author | Notes |
|---|---|---|---|
| 1.2.1 | 2026/07/02 | Mathieu Tougas | • Updated Corportate Entity Name |
| 1.2.0 | 2026/04/07 | Mathieu Tougas | • Added Penetration Testing, Recovery Objectives and Incident Response sections. Update subprocessor format |
| 1.1.1 | 2026/03/18 | Mathieu Tougas | • Updated data subprocessors |
| 1.1.0 | 2025/11/21 | Mathieu Tougas | • Added Incident Handling and Data Export sections • Updated roadmap timelines |
| 1.0.1 | 2025/01/10 | Mathieu Tougas | • Updated data subprocessors |
| 1.0.0 | 2024/10/15 | Gabriel Blais-Bourget | • Initial version |