OneZero / Ontario growth systems

Security and Privacy Approach

Security and privacy are design and operating responsibilities, not badges added at launch. OneZero identifies the people, information, systems, vendors, access, decisions, retention, and failure paths that shape an appropriate project plan.

Ask before connecting

Use only the data, access, and vendors the workflow actually needs.

The controls for a public marketing page differ from a client portal, internal assistant, health-administration workflow, payment connection, or multi-role custom application. Scope should match the sensitivity and consequence of the system.

What we will not pretend: This page describes an approach, not a certification, legal opinion, penetration-test result, regulatory guarantee, insurance statement, or promise that every possible control applies to every project.

Choose a useful path

Three boundaries to define early

Information

What data enters, where it comes from, and why

Identify public, confidential, personal, financial, health, employee, client, and operational information before a tool or vendor is selected.

Read the website Privacy Policy

Access

Who can see, change, approve, export, and delete

Use named roles, least necessary access, separate environments, appropriate authentication, logging, and an offboarding route.

Review ownership and handover

Operation

Who monitors, updates, recovers, and responds

Plan software updates, vendor changes, backups, logs, errors, support, retention, incident contacts, and recovery before launch.

See the delivery process

Questions included in responsible discovery

The project record should make the proposed data flow and operational owner inspectable.

  • Purpose, minimum necessary fields, source, accuracy, consent, and lawful authority
  • Classification, storage, processing, transfer, backup, retention, deletion, and export
  • User roles, authentication, authorization, credentials, devices, vendors, and administrator access
  • Development, test, staging, and production separation and representative test data
  • Encryption and transport expectations supported by the selected architecture and vendors
  • Logging, monitoring, dependency updates, vulnerability handling, incident contact, recovery, and communication
  • Human review, prohibited uses, source boundaries, evaluation, and escalation for AI-assisted work

The client remains an essential control owner

OneZero can design and implement agreed controls, document assumptions, and support operations. The client controls business policy, authorized users, source accuracy, account access, staff behaviour, consent, legal basis, retention decisions, and sector obligations unless a written agreement assigns a specific responsibility otherwise.

Use specialists when the consequence demands it

Legal, privacy, compliance, accessibility, security, clinical, engineering, payment, insurance, and regulatory review may require appropriately qualified specialists. Their requirements can be incorporated into scope, testing, and acceptance.

A controlled path

Security and privacy through the project

  1. Discover the boundary. Inventory users, data, systems, vendors, devices, environments, decisions, threats, obligations, and prohibited uses.
  2. Define proportionate controls. Record responsibilities, access, architecture, retention, logging, testing, support, acceptance, and unresolved risks.
  3. Build and verify. Use controlled access, appropriate test data, review gates, dependency checks, acceptance cases, and specialist evidence where scope requires it.
  4. Operate and change responsibly. Maintain accounts, vendors, software, logs, backups, source knowledge, user access, incidents, and change records after launch.
Plain answers

Questions buyers usually ask

Is OneZero certified to a security standard?

No certification is claimed on this page. If a project requires a specific certification, audit, control framework, or vendor qualification, that requirement must be raised and verified during procurement and scope.

Can you guarantee a system is secure or compliant?

No responsible provider can promise zero risk or blanket compliance. OneZero can implement and document agreed controls, test defined requirements, disclose known limits, and work with qualified reviewers.

Will our information be used to train AI?

No such use is assumed. Any AI vendor, model, retention, training, processing, data-location, and opt-in terms must be explicitly reviewed for the proposed workflow before private information is connected.

Can you sign our security or data agreement?

Requirements can be reviewed during procurement. Acceptance depends on the actual services, vendors, responsibilities, insurance, legal terms, and ability to meet the stated controls.

Next best step

Put the sensitive questions on the table before the demo.

Tell us who uses the proposed system, what information it touches, what a failure would mean, and which policies or specialist requirements already apply.

Discuss a controlled build Read ownership and handover