Built for the trust your licence depends on. Explained plainly.

Advisors are trusted with their clients’ health and finances. Here is exactly how EGEAN protects that information, with no claims we can’t back up.

Torontoservers and databases
Canadadocuments and backups
2 layersof encryption on client identity
MFAon every account

Safeguards on every account. Not a premium tier.

Encryption in transit and at rest
TLS on every connection and encryption on stored data, plus an extra application-level layer for client identity details, email message bodies, conversations and documents, which we are extending to all client notes and records.
Mandatory multi-factor authentication
Every user signs in with a second factor. It cannot be switched off for convenience.
Role-based access
Principals, advisors, assistants and compliance roles each see only what their role allows.
Strict separation between firms
Each firm’s data is kept apart from every other firm’s, enforced in the database, not just the screens.
A tamper-evident audit log
Significant actions are recorded with who did it and when, and audit records are kept for seven years as part of the compliance record.
An insured company
EGEAN InsureTech carries its own business insurance.

Consent and privacy, built into the workflow.

PIPEDA and CASL obligations are part of how EGEAN works day to day, not a policy document nobody opens.

Real screen from EGEAN. The clients are made up.

EGEAN consent view with email and text consent per client
Consent, per client and channel
Email and text consent is recorded against each client, implied consent expires on schedule, and sending is blocked until consent is on file.
Access requests
Advisors can retrieve what is held on a client so a data-access request can be answered.
Retention you control
Your firm decides when eligible records are deleted. Deleted records sit in a recycle bin for 30 days, then are permanently removed.
Breach response
If a breach creates a real risk of significant harm, we notify the affected firm and, where the law requires, the Privacy Commissioner and the people affected.

Security questions.

In Canada. Our servers and databases are in Toronto, documents are stored in Amazon Web Services’ Canada (Central) region, and backups are kept in Canada. A few service providers process limited information outside Canada; our Privacy Policy lists them.

Only people your firm has given a role, and only what that role allows. Every user signs in with multi-factor authentication, and significant actions are logged.

No. We do not sell or rent client data, and we never use it for advertising or marketing profiles.

No. This describes our platform and practices. Your firm remains responsible for the information it collects; talk to your compliance advisor about how EGEAN fits your obligations.

No third-party certifications such as SOC 2 or ISO 27001 are claimed at this time. This page will change only once one is formally obtained.

Have a security question before you commit? Ask us anything.

Contact us