Not just a badge — here's specifically what protects your account, your leads' information, and your business data on Northline.
Every password is hashed with bcrypt before it touches our database. Even Northline staff can't see your actual password — only its hash.
Your login session is stored in a cookie that JavaScript running on any page can't read — a key defense against session theft (XSS attacks).
10 login attempts per 15 minutes per IP address. Slows password-guessing attacks to a crawl.
Login checks run at consistent speed whether or not an account exists, so response time can't be used to guess valid emails.
| Provider | What they handle | Notes |
|---|---|---|
| Database & hosting | Account data, lead conversations, billing status | Operated with Canadian data residency |
| Anthropic PBC | AI processing of conversation content | Operational logs auto-delete after 7 days; inputs/outputs not used for model training; covered by Anthropic's DPA with Standard Contractual Clauses |
| Payment processor (planned) | Billing for paid plans | Northline never stores full card numbers |
Full detail in our Privacy Policy, Sections 7–8.
We maintain an internal incident-response plan covering containment, individual notification, and reporting to the Office of the Privacy Commissioner of Canada — not just a policy promise.
Access, export, and deletion requests are handled through a dedicated tool with a permanent audit trail, so we can demonstrate compliance, not just claim it.
Canceled accounts, inactive leads, and old job applications are deleted on a defined schedule rather than retained indefinitely.
Not an anonymous inbox — someone is accountable for how your data is handled, and reachable directly.
We'd rather explain it directly than have you guess.
Contact us