Security
Last updated: June 20, 2026
Arkipel is a platform by Toucan Solutions Inc. This page describes how we protect your data.
Your data is sent using HTTPS
All communications between you and Arkipel are encrypted and transmitted via HTTPS (TLS). No data is sent in plain text over the network.
Where your data is stored
Your data is currently hosted on Digital Ocean servers, with data centers in Canada (Toronto). The hosting location of each community may vary according to the needs of the client organization; Arkipel may be deployed in other jurisdictions (including the United States or Europe) as needed. In all cases, your data remains governed by this policy and by the laws applicable to the hosting jurisdiction.
Our application databases are not encrypted at rest — the information you add to the platform is active in our databases and subject to the same protection and monitoring as the rest of our systems. Sensitive fields, such as digital signing private keys, are encrypted at the application level. Files that you upload are stored on disk or a cloud storage service and are not encrypted at rest. Our database backups are encrypted.
Backups and resilience
Production data is backed up at least every 24 hours, with redundant copies stored securely. Our Recovery Point Objective (RPO) is less than 24 hours of data loss. In case of incident, we have disaster recovery procedures to restore access quickly.
Access control
Each user has access based on their roles and permissions within their network. Sessions are protected against common attacks (CSRF, session fixation, replay). Passwords are hashed with bcrypt.
Internal access
A limited number of Toucan Solutions employees (DevOps team) can access production data for technical support and maintenance. For development, we use anonymized datasets. We are in the process of implementing server access logging for traceability. No employee accesses data without a legitimate business reason.
Data sovereignty
Unlike traditional centralized platforms, Arkipel guarantees that each community retains ownership and control of its data. Your information is neither sold, shared with third parties, nor used for advertising purposes.
Security updates
Our servers and dependencies are updated regularly with the latest security patches. Patches for critical vulnerabilities are applied within a maximum of 72 hours.
Continuous monitoring
We monitor platform availability, exceptions, performance, and logs via AppSignal. We do not currently use an intrusion detection system (IDS), but we are working to strengthen our monitoring capabilities.
Breach notification
To date, we have never had a data breach. If a data breach involving personal information were to occur, Toucan Solutions commits to notifying affected users and the relevant regulatory authorities (including the Commission d’accès à l’information du Québec) within a maximum of 72 hours.
Vulnerability reporting
If you discover a security vulnerability on our platform, we encourage you to inform us immediately at security@arkipel.co. We treat all reports with the utmost attention and recognize community contributions to the security of our services.
Want to know more?
For any additional questions about our security practices, contact us through our Contact page.