A compliance platform for Quebec IT departments and a luggage tracker for travellers: on paper, nothing connects them. Their markets, buyers and sales cycles are strangers to each other — deliberately so. Each product owns its brand, its domain and its roadmap.
What they share sits underneath: one technical foundation and one founding constraint. Azure Canadian region, infrastructure fully described as code, compliance built in from the start rather than bolted on later. That base was built once, then reused.
The consequence is economic: each subsequent product costs less than the last. Infrastructure, deployment pipelines, the authentication layer and the compliance framework already exist. What remains to build is the product itself.
01 — SOVEREIGNTY
Data stays in Canada
Our product platforms run on Azure canadacentral. Law 25 and PIPEDA on the Canadian side, GDPR on the European side. A constraint accepted on day one, never retrofitted.
02 — EVERYTHING IS CODE
Reproducible infrastructure
Terraform, Bicep, Azure Policy, CI/CD pipelines. Any environment can be recreated identically, tested and audited. That is what lets a small team ship two products.
03 — EVIDENCE
Traceable to the source
Every compliance requirement links back to its originating recommendation — CIS Azure v6, AWS v7, GCP v5, ISO 27001. An auditor can verify without reconstructing the reasoning.