CivicEnforce — NBV & MTI Enforcement Management Platform

Demo for Metro Vancouver RFP 26-0316

Demonstration only — not an official Metro Vancouver production system. All data is fictional.

Audit & Security

Security, privacy and records controls proposed for the CivicEnforce platform, together with the live audit trail from this demonstration session.

This is a demonstration environment. QuickHands does not claim SOC 2 or ISO 27001 certification for this demo, and the controls described below represent the proposed production architecture rather than an audited, certified deployment.

Data residency

Canada

MFA coverage (demo)

100%

Audit events retained

7 years

Recovery objective

RPO 1h / RTO 4h

Security & privacy controls

Proposed production posture

Canadian data residency

All application data, documents and backups are proposed to reside in Canadian regions (Canada Central with Canada East failover). No data leaves Canada in the proposed architecture.

Encryption

AES-256 encryption at rest for database, object storage and backups; customer-managed keys supported with periodic rotation.

TLS 1.2+ in transit

All public and integration traffic is served over TLS 1.2 or higher with modern cipher suites and HSTS enabled.

Entra ID, MFA and RBAC

Staff authenticate with Microsoft Entra ID single sign-on and multi-factor authentication. Role-based access control governs module, record and field permissions.

Comprehensive audit logging

Append-only logs capture authentication, record access, changes, evidence views, exports and administrative configuration, retained for seven years.

Backup and recovery

Hourly incremental and nightly full backups with point-in-time recovery. Target RPO 1 hour, RTO 4 hours; restores tested quarterly.

Monitoring and alerting

Continuous availability, performance and security monitoring with alerting to a 24/7 on-call rotation and a status page for stakeholders.

Staging and UAT environments

Separate development, staging and UAT environments with anonymized data and a controlled release path into production.

Data export and portability

Administrators can export the full dataset and documents in open formats on request, supporting FOI responses and exit transition.

Secure destruction

Retention schedules drive certified destruction of records and media, with destruction certificates recorded in the audit log.

Live audit trail

Actions taken in this demonstration session are appended here.

  • 2026-09-24, 8:02:00 a.m.SIGN_IN (Entra ID + MFA)CivicEnforced.nguyen
  • 2026-09-24, 8:31:00 a.m.EVIDENCE_VIEWNBV-2026-001284m.okafor
  • 2026-09-24, 9:05:00 a.m.BACKUP_COMPLETE (Canada Central)civicenforce-prodsystem
FOIPPA-aligned privacy practices
Least-privilege access
Quarterly restore testing
Penetration testing proposed annually