Resource

Where Does Your Alert Data Go? A Canadian SOC’s Guide to Data Sovereignty, AI Oversight and Vendor Due Diligence

Get the Whitepaper

Preview of the whitepaper titled "Where Does Your Alert Data Go? A Canadian SOC's Guide to Data Sovereignty, AI Oversight and Vendor Due Diligence" by D3 Security

Download Resource

Guide for Canadian public sector
15-minute read

Security telemetry is some of the most sensitive data a public body holds, and it increasingly passes through platforms that store it, process it and reason over it somewhere other than where it was collected. This guide gives Canadian SOC leads a plain-language way to answer the questions their privacy office, procurement team and auditors are now asking, and a twelve-question vendor checklist written to be copied into an RFP. It applies to any vendor, from any country, including Canadian ones.

Eight pages. . Available in English; French edition to follow.

01

What the guide covers

The five places alert data actually goes

Where it’s stored, where it’s processed (including AI inference, which is often somewhere else), who owns the vendor and what law they answer to, who can access it in support and operations, and what happens at contract end. Most vendor answers cover one of the five.

The twelve-question vendor checklist

For each question, the answer you want, the answer that needs follow-up, and the answer that should end the conversation. Formatted to be copied into an RFP or a security questionnaire, and meant to be asked of every vendor, foreign or Canadian.

The AI oversight question, in Canadian terms

What the federal Directive on Automated Decision-Making and provincial privacy commissioners’ guidance actually ask of AI that shapes consequential action, where SOC tooling sits relative to their scope, and the three properties a platform needs before a reviewer can govern it: findings graded by evidence, human oversight logged with identity, and one record per incident.

The one-page version for small teams

Five questions for municipalities, transit and utility authorities and police services boards that run security with a handful of people and no privacy office, including what to ask a managed provider on your behalf.

02

If you only have time for five questions

The short version from the guide. Name the country in the answer to each one.

  1. Where is our data stored, and where is the AI run?
  2. Can we turn the AI off for the things we are not comfortable automating?
  3. Show us the record for one closed alert. Can a councillor or a deputy minister read it?
  4. Who at your company can log into our environment, and from where?
  5. What do we get back if we leave, and how fast is it deleted?

If your SOC is run by a managed provider, ask the provider the same five questions about the platform they use for you. The obligation stays with the public body.

03

Who it’s written for

Federal departments and agenciesSOC leads and departmental security officers preparing a privacy impact assessment or an internal write-up structured like an Algorithmic Impact Assessment.
Provincial ministries, health authorities, crown corporationsTeams working under provincial privacy statutes with residency expectations, and shared-services SOCs serving many organisations.
Municipalities, transit and utilitiesSmall teams with large operational-technology exposure and a council that will want a plain explanation after an incident. Also the MSSPs that serve them.

The guide is vendor-neutral through its first six sections. An appendix shows how D3 Morpheus, built by a 100% Canadian company with Canadian hosting, answers the twelve questions, as one worked example. About Morpheus for Canadian public sector

04

Common questions

Does the Directive on Automated Decision-Making apply to security alert triage?

In most cases, no. The Directive covers automated systems that make or support administrative decisions about people, extended in 2023 to internal services such as security screening of employees. Security-alert triage generally sits outside that scope. The guide treats the Directive and its Algorithmic Impact Assessment as the right set of questions rather than a hard obligation, and recommends confirming with your departmental privacy or ATIP office.

Is this guide only relevant to foreign vendors?

No. The twelve questions are meant to be asked of every vendor, including Canadian ones. Canadian ownership answers the ownership and jurisdiction questions and nothing else; a Canadian vendor can still process data abroad, run global support, or fail the contract-end question. Many foreign vendors answer the checklist well through Canadian hosting and clear contracts.

Where does AI inference usually happen, and why does it matter?

Often in a different region from where the data is stored, because platforms call external model providers to summarise or investigate alerts. That makes the model provider’s region a processing location for your data. The guide recommends asking specifically where inference runs, which providers are involved, and whether it can be constrained to Canada or to your own infrastructure.

Can I use the checklist in an RFP?

Yes. Section four is formatted as a table with the question, the good answer, the follow-up answer and the walk-away answer, so it can be copied into a procurement document or a security questionnaire and the responses scored consistently across vendors.

Get the guide

Written to be forwarded to your privacy officer and your procurement lead.

Send me the guide See how Morpheus answers the twelve questions on a live investigation

D3 Security builds Morpheus, the agentic SOC platform. Vancouver, Canada. This guide is provided for information and does not constitute legal advice.


Powering the World’s Best SecOps Teams

Ready to see Morpheus?