How Phi Core handles your data

Phi Core is consumption intelligence for IT solution providers: it reads the systems you already run and returns the specific next action with the dollar value attached. This page is how it handles the data it reads.

Data handling

Phi Core connects to your CRM with a read-only credential, inquire scope only. It holds no write, create, update or delete permission on any system of yours.

It reads commercial records only, and no end-user identity fields. The platform reads; it does not own.

Health Assessment Engine reads vendor-side telemetry you are already entitled to as a partner; nothing is installed in your customer's environment.

Residency and isolation

Residency is a deployment choice, not a fixed property of the product. It is declared at provisioning, per tenant, based on what your own obligations require, and confirmed in writing before go-live. The platform is cloud-first and not tied to a single provider or region.

Each customer gets a dedicated tenant, not a shared environment. Isolation is enforced at the database layer and verified with negative-control tests rather than assumed.

Residency is not sovereignty

Canadian residency on a US-incorporated hyperscaler remains exposed to the CLOUD Act, which lets US authorities compel a US provider to produce data wherever it is stored. PIPEDA does not mandate Canadian residency. Hard residency requirements come from FIPPA, the health sector, Quebec's Law 25 and government procurement, which is exactly the customer profile this platform serves.

Only a customer-owned or Phi-operated deployment escapes that exposure. On a managed surface, external key custody is the only technical approximation, and it is an approximation. Deployment into a customer-owned cloud tenant is available as a separate engagement, so your end-customer pricing data never leaves infrastructure you control. We will tell you exactly where the line is.

Compliance roadmap

SOC 2 Type I first, then Type II. We will state a target window when we can hold it.

Subprocessors and deletion

Current production tenant

FunctionSubprocessor
HostingAmazon Web Services
DatabaseAmazon Web Services
Object storageAmazon Web Services

This table covers the current production tenant and is updated as it changes. The subprocessors for a given engagement are confirmed before go-live.

Confidentiality, intellectual property, retention and deletion are governed by the Master Services Agreement, executed before go-live.

Questions from a security or procurement review are welcome.