Security and compliance
This page describes the security measures in place today on the PPN Source platform. It is written for clients, partners and teams that assess our practices before entrusting us with press releases or personal information.
Last updated : September 4, 2026
At a glance
Hosted in Canada
The application and the database are hosted in Toronto.
Encrypted everywhere
TLS 1.2 minimum in transit, automatic encryption of the database at rest.
Role-based access
Four access levels and server-side authorization of every action.
Daily backups
The database is backed up every day, with seven days of retention.
Law 25
Designated privacy officer, published privacy policy and incident procedure.
Embargoes honoured
A scheduled release stays invisible until the planned minute.
Hosting and data location
Platform data is split between two infrastructure providers, in the following regions:
- Application
- DigitalOcean App Platform, Toronto region (Canada)
- Database
- DigitalOcean managed PostgreSQL, Toronto region (Canada)
- Media (images, videos, documents)
- Amazon S3, US East 2 region (Ohio, United States), delivered through the CloudFront CDN
Account-related personal information (name, email, contact details, orders) therefore resides in Canada. Media files attached to press releases, which are meant for public distribution, are stored in the United States. Our privacy policy states that information may be processed outside Quebec.
Encryption
In transit
- Every page and the API are served over HTTPS; the minimum supported version is TLS 1.2.
- The connection between the application and the database is encrypted, TLS 1.2 minimum.
- Media delivered by CloudFront is served over HTTPS.
- The HSTS header (one year, subdomains included, preload list) forces browsers to use HTTPS.
At rest
- The managed database is encrypted automatically by the provider, backups included.
- Media on Amazon S3 is encrypted server-side by default.
- Passwords are never stored in clear text: they are hashed with bcrypt.
Access control
Account authentication
- Sign-in with email and password, or delegated sign-in through Google, Facebook or Microsoft (OAuth 2). In the latter case, PPN Source stores no password at all.
- Brute-force protection: limited number of attempts and temporary lockout.
- Password reset through a link sent by email, valid for a limited time.
- Server-side sessions, expired after a period of inactivity; HttpOnly cookies.
- The API uses revocable bearer tokens, issued at sign-in and pruned daily once expired or revoked.
- Public forms (contact, sign-up, media upload) are protected by an anti-bot check.
- Security headers sent on every response: enforced Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
Two-factor authentication
Two-factor authentication is not offered on PPN Source accounts. Users who want it can sign in through Google, Facebook or Microsoft and benefit from the two-factor authentication configured on that account.
Roles and permissions
- Four access levels: visitor, authenticated user, channel administrator (Premium client) and PPN Source administrator.
- Least-privilege principle: a user only accesses their own data, orders and publications. A channel administrator accesses a restricted panel, filtered to the channels they manage.
- Granular rights per channel (contributor, manager, approver) and per organization (member, manager), granted by an administrator or by the entity’s manager.
- Only an administrator can appoint a channel manager or promote an administrator. The channel-administrator role is removed automatically as soon as the person no longer manages any channel.
- Every action is checked server-side by authorization rules, regardless of what the interface displays.
Audit trail
The following events are recorded with a timestamp:
- Administrator activity log
- Centralized log of administrative actions, with the user, action, target, IP address and timestamp of each entry. Available in the admin area, kept without time limit.
- Application logs and errors
- Streamed to New Relic from the INFO level up; every exception is reported there. 30-day retention.
- Sessions and tokens
- Each active session keeps the user, IP address, browser and last activity. Each API token keeps its creation and revocation dates.
- Business history
- Email sendings per press release, delivery events (delivered, opened, bounced), wallet transactions, orders with their author, and invoices.
- Reversible deletions
- Users, channels, organizations, press releases, email addresses and coupons are soft-deleted, with the deletion date.
- Systematic timestamps
- Creation and last-modification dates on all data.
Backups and continuity
- Frequency
- The database is backed up automatically every day by DigitalOcean.
- Retention
- Seven rolling days.
- Restore
- Restore from any retained backup, through the provider’s console.
- Media
- Amazon S3 replicates every file across several sites within the region.
- Scheduled-task recovery
- If the server is unavailable when a scheduled publication is due, it is carried out as soon as the server restarts, with the planned date, and never twice.
Availability
We do not publish an uptime figure: it has not been measured continuously over the last twelve months.
Law 25 compliance
PPN Source complies with Quebec’s Act respecting the protection of personal information in the private sector, as amended by Law 25, and with Canada’s Anti-Spam Legislation. Our practices are detailed in our privacy policy.
Person in charge of the protection of personal information
410 Saint-Nicolas Street, Suite 236, Montréal (Québec) H2Y 2P5
Retention and deletion
Personal information is kept only as long as necessary for the purposes for which it was collected, or for the periods required by law. It is then destroyed or anonymized. Anyone can request access to their information, its rectification, portability, de-indexing or deletion, and withdraw consent at any time, by writing to the person in charge above.
Confidentiality incident management
Every confidentiality incident is recorded. When it presents a risk of serious injury, PPN Source notifies the Commission d’accès à l’information du Québec and the persons concerned, and takes reasonable measures to limit its consequences. Anyone who believes their rights have not been respected may file a complaint with the Commission d’accès à l’information du Québec.
Embargoed press releases
A press release can be prepared, approved, then published automatically at the chosen date and time. Until then, it is protected as follows:
- The release is stored in the database in an unpublished state. Until the publication date is reached, it appears nowhere on the site: not in listings, not in RSS feeds, not in search results.
- Anyone who knows the page address gets an “access forbidden” message. Access before publication is restricted to authorized persons.
- An automated process checks every minute for releases whose time has come. Publication happens between 0 and 60 seconds after the chosen time, never before.
- The reference time is Coordinated Universal Time (UTC); the date shown on the public page is in Eastern Time.
- Once the release is live, search engines are notified and the announcement emails and notifications go out within seconds. The system records what has been done: a release can be neither published nor announced twice.
Providers and subcontractors
The following third-party services take part in running the platform:
- DigitalOcean
- application and database hosting (Toronto)
- Amazon Web Services
- media storage (S3) and delivery (CloudFront)
- Cloudflare
- DNS and web traffic protection
- SendGrid
- transactional emails and press release announcements
- Stripe
- card payments; no card number ever passes through our servers
- Zoho
- invoicing
- New Relic
- application logs and error monitoring
- delegated sign-in, anti-bot check and audience measurement (after consent)
Contact us
For any question about these practices, to report a vulnerability or to exercise your rights, write to us. We acknowledge receipt within 2 business days.