Procurement

Vendor Information

Basic vendor and product information for procurement registration, vendor assessment, and contract review.

Product Overview

Product nameSafe For The Office™
Product categoryWorkshop facilitation software — SaaS
Primary use caseRunning structured workplace activities — icebreakers, polls, retrospectives, trivia, and similar exercises — with professional teams
Target usersFacilitators, HR teams, managers, L&D professionals, consultants, and team leaders
Participant modelParticipants join via browser — no account, no app download, no email address required
Product websitewww.safefortheoffice.ca

Ownership and Contact

Owner / OperatorRichard Pylychuk
Business typeIndependent software product
Country of operationCanada
Procurement contactContact form
Privacy contactContact form
Security disclosureContact form

Hosting and Infrastructure

Cloud providerAmazon Web Services (AWS)
Primary regionca-central-1 — Canada (Montréal, Québec)
Data residencyAll persistent production data is hosted in Canada
ComputeAWS EC2 — single instance, ca-central-1
DatabaseAWS RDS PostgreSQL 16 — ca-central-1, private subnet
Secrets managementAWS Secrets Manager — credentials never stored in code
TLS / HTTPSEnforced on all connections — Let's Encrypt certificates
Deployment pipelineGitHub Actions with AWS OIDC — no long-term access keys

Deployment Model

Safe For The Office™ is a hosted SaaS platform. Customers do not install or manage any software. Facilitators access the platform through a web browser. Participants join workshop sessions through a browser using a room code — no installation, account, or email address is required.

The platform is operated and maintained by the product owner. Updates are deployed automatically through a continuous delivery pipeline. Customers receive updates without any action required on their part.

Data Residency Summary

All persistent production data — facilitator accounts, workshop room records, audit logs, and operational events — is stored in Canada using AWS infrastructure in the ca-central-1 region (Montréal, Québec).

The deployment pipeline uses GitHub Actions, which processes application code only — not user data. No user data is transmitted outside Canada as part of the deployment process.

Safe For The Office™ does not currently use third-party email delivery, payment processing, or analytics services that process user data. If any such service is added in the future, it will be disclosed in the Privacy Policy before it is activated.

For full infrastructure details, see the Data Residency policy.

Certifications and Standards

Safe For The Office™ has not pursued formal security certifications such as SOC 2, ISO 27001, or FedRAMP. The platform implements security controls appropriate to its scale and use case, but these controls have not been independently audited against a formal certification framework.

The platform is designed to support organizations operating under PIPEDA requirements. For PIPEDA alignment documentation, see the PIPEDA Alignment page.

Organizations with formal certification requirements should contact us to discuss their specific needs.

Privacy Architecture Summary

Safe For The Office™ uses a privacy-first architecture. The key privacy property is that participant answers are never stored — not in a database, not in logs, not anywhere. Participant data exists only in active server memory during a live session and is permanently gone when the session ends.

This is enforced at the database schema level — the tables that would be required to store participant data do not exist. It is not a configuration option.

For full privacy documentation, see the Privacy Policy and the Data Handling policy.

Last reviewed: October 2026