Platform security

Security practices built for field reporting data

Incident and inspection reports often include photos, locations, and operational detail. Built by emAPPetizer Inc., 1st Reporting protects that data with encryption in transit, strong access controls, and clear privacy commitments—so IT and compliance teams can evaluate us with confidence.

Certification

ISO/IEC 27001:2022

MSECB has assessed and certified the management system of emAPPetizer Inc. in accordance with ISO/IEC 27001:2022.

MSECB ISO/IEC 27001:2022 management system certification mark
Issued to
emAPPetizer inc.
Certification body
MSECB
Certificate No.
C1105-ISMS395-C2-04-24
Certified since
2021-03-19
Valid from
2024-04-18
Valid until
2027-03-18

Certification scope

The certification scope is limited to data belonging to emAPPetizer and its customers using their SaaS services, as well as employees’ personal data. This confidential data can be found on data centers, SharePoint, and backups residing in the infrastructure covered by the certification perimeter, in accordance with the Statement of Applicability (SoA), Ver. 1.6 dated 2024-03-04.

Subject to annual surveillance audits.

What procurement and IT teams ask first

ISO/IEC 27001:2022

Our information security management system is independently certified by MSECB. Certificate No. C1105-ISMS395-C2-04-24, valid through 2027-03-18.

Encrypted in transit

Communications with our services use encrypted channels (HTTPS/SSL). Payment details are encrypted before they are submitted through our payment providers.

Access controls

Accounts require individual user credentials. Internally we use private-key server authentication, multi-factor authentication, and IP whitelisting to harden access to infrastructure.

Hosted in Canada

Application hosting is provided by Microsoft in Canada. We document subprocessors—including payments, email, and support tooling—in our Privacy Policy.

We do not sell your data

emAPPetizer Inc. does not sell personal information to third parties. Data is used to operate the product, support customers, and improve the service as described in our Privacy Policy.

How we protect reports and accounts

These practices are summarized from our published Privacy Policy so security reviewers have a clear starting point. For questionnaires, DPAs, or deeper architecture reviews, contact sales.

Account authentication

Users access 1st Reporting with individual logins and passwords. Optional sign-in with Microsoft 365, Google, or Apple is available where enabled for your organization.

Infrastructure safeguards

Web servers are reachable over HTTPS and SSH. Server authentication uses private keys rather than passwords, with multi-factor authentication and internal IP whitelisting.

Payments

Card payments are processed by Stripe (or PayPal where used). Payment details are encrypted with SSL before submission; we do not store full card numbers on our application servers.

Retention and deletion

We retain account and service data while your account is active and as needed to provide the service or meet legal obligations. When you request deletion or close an account, data is removed from active systems; backup copies are erased on their scheduled lifecycle.

Privacy rights

Depending on your jurisdiction, you may request access, correction, deletion, or other privacy rights. Contact privacy@emappetizer.com—we respond within thirty days.

AI features

If you use AI-powered features such as Template Genie, we process the inputs you provide to generate templates, suggestions, or summaries as described in the Privacy Policy.

Enterprise security reviews

Need a security questionnaire, vendor risk form, or data processing discussion for procurement? Our team works with IT and compliance stakeholders during evaluation. Share your requirements and we will respond with the documentation we can provide—including our ISO/IEC 27001:2022 certificate.

Full privacy details

Subprocessors, cookies, international transfers, and user rights are documented in our Privacy Policy—the source of truth for how emAPPetizer Inc. handles personal information.

Evaluating 1st Reporting for your organization?

Start a trial to see the product, or talk with our team about security, compliance, and rollout for your field operations.

Security FAQ

Are you ISO 27001 certified?

Yes. emAPPetizer Inc. holds an ISO/IEC 27001:2022 certificate issued by MSECB (Certificate No. C1105-ISMS395-C2-04-24), valid from 2024-04-18 through 2027-03-18, subject to annual surveillance audits. You can download the certificate from this page or request validation from MSECB at info@msecb.com.

Where is 1st Reporting hosted?

Application hosting is provided by Microsoft in Canada. Other service providers (for example payments, email, and support) are listed in our Privacy Policy with their locations and privacy links.

Do you sell customer data?

No. We do not and will not sell personal information to third parties.

How is data encrypted?

Communications with our services are encrypted in transit. Payment details are encrypted with SSL before submission to our payment gateway providers.

Can we complete a security questionnaire?

Yes. Contact sales with your questionnaire or vendor risk requirements and we will work through the review with your IT or compliance team.

Who do we contact about privacy or security questions?

For privacy requests, email privacy@emappetizer.com. For sales or vendor security reviews, use Contact Us or Book a Demo and mention security documentation.