Disclaimer: PermitAssure provides digital review, workflow and decision-support capabilities. Final interpretations, approvals and regulatory decisions remain the responsibility of the applicable Authority Having Jurisdiction and its authorized professionals.
Our trust framework
Secure by Design
Security considerations are built into the architecture, not added afterward.
Human Authority
Qualified professionals retain authority over interpretation and approval.
Explainable Findings
Findings are linked to evidence, requirements and confidence indicators.
Controlled Data Use
Data boundaries, retention and access are configured and enforced.
Auditable Decisions
Every decision and override is recorded for accountability.
Continuous Evaluation
AI-assisted components are monitored and evaluated on an ongoing basis.
Security
PermitAssure's security architecture is designed to align with enterprise and government expectations. Controls can be configured for tenant isolation, environment separation and secure API access.
- Canadian hosting options
- Encryption in transit and at rest
- Identity and access management
- Tenant isolation
- Secure APIs and environment separation
- Backup, recovery and business continuity practices
Privacy & data residency
Canadian hosting options and data-residency configurations are available to support jurisdictional and organizational requirements. Retention and data-boundary controls can be configured per deployment.
- Canadian data-residency options
- Configurable retention controls
- Defined data boundaries per deployment
- Role-based access to sensitive information
Auditability
Every finding, override and decision is designed to be traceable — supporting internal review, appeals and regulatory accountability.
- Rule-version tracking and effective-date history
- Complete audit logs of reviewer actions and overrides
- Segregation of duties across roles
Accessibility
PermitAssure is designed to WCAG 2.2 AA principles — keyboard support, semantic structure, sufficient contrast and status indicators that do not rely on colour alone.
Read the Accessibility Statement →How to read a PermitAssure finding
Every check resolves to one of six statuses — never a silent pass or fail.
Trust FAQ
Does PermitAssure approve permits automatically?
No. PermitAssure provides digital review, workflow and decision-support capabilities. Final interpretations and approvals remain the responsibility of the applicable Authority Having Jurisdiction and its authorized professionals.
How is AI output distinguished from human decisions?
AI-assisted findings are labelled with confidence indicators and source references, and are clearly distinguishable from confirmed human decisions in the workspace and in reports.
What happens when the system is uncertain?
Uncertain or ambiguous findings are labelled "Uncertain" or "Requires Professional Review" and escalated for qualified human review rather than resolved automatically.
Can reviewers override AI-assisted or automated findings?
Yes. Human override is a core control. Overrides are recorded in the audit log along with the reviewer and rationale.
Where is data hosted?
Canadian hosting options are available and can be configured per deployment. Specific hosting arrangements are confirmed during onboarding.
Is PermitAssure certified to a specific standard?
PermitAssure’s architecture is designed to align with recognized security and privacy practices. Achieved certifications will be listed here once confirmed — none are currently claimed.