Canadian data residency
Production services and customer data are hosted in Microsoft Azure Canada Central.
Confirm the selected Azure region and any external provider paths during procurement.Security & trust
UnionStack brings tenant scope, identity, permissions, private file handling and secure integration patterns together so teams can connect their work without treating access as an afterthought.
Account access in practice
The connected account centre brings email verification, linked sign-in providers, password controls and recent sign-in history into view. These screenshots show a demonstration account.
Demonstration account shown with two-factor authentication disabled.
Demonstration sign-in history shown. Network locations are unavailable in this view.
A layered model
A trustworthy union platform needs more than a secure sign-in. The organization context, the user’s authority, the requested record, any stored object and every integration path all participate in the decision.
Production services and customer data are hosted in Microsoft Azure Canada Central.
Confirm the selected Azure region and any external provider paths during procurement.Reads are filtered to the active tenant and writes reject records that do not match tenant context.
Tenant context is part of the persistence boundary, not only a user-interface filter.Application and API operations remain subject to the authenticated user, tenant, roles and applicable record rules.
Connected records do not remove the distinct permissions around sensitive work.Tenant-specific containers disable public access and validate object paths before storage operations.
Private documents are served through authorized application paths rather than public containers.Governed object content is protected with tenant-keyed authenticated AES-GCM envelopes before it is written to blob storage.
Key management and operating procedures remain part of the production deployment review.Developer integrations use OAuth 2.0 authorization code flow with PKCE and tenant-aware access.
An API client does not become a path around application authorization.Procurement review
Use these prompts to keep an evaluation specific to the environment, providers and workflows your union expects to operate.
Which data remains in Canada, and which enabled providers process data elsewhere?
How is organization context applied to reads, writes, files and background work?
Which roles, scopes and record rules protect the workflow being evaluated?
Where are transport, platform and application-layer protections applied?
How are public publishing and authenticated member experiences kept distinct?
Which requirements need current documentation or an executed agreement?
Shared responsibility
Technology supplies boundaries. Administrators still decide who receives access, what is published and when those decisions need to be reviewed.
Model responsibilities before assigning broad access.
Test with representative accounts and revisit access as duties change.
Keep credentials, provider keys and recovery paths out of shared records.
Verify public and member visibility before promoting content.
Repeat the review when workflows, integrations or providers change.
Buyer questions
Confirm environment-specific controls and contractual requirements during procurement.
UnionStack production services and customer data use Microsoft Azure Canada Central for Canadian data residency. Enabled external providers should be reviewed separately.
Tenant-specific object containers disable public access, validate paths and can apply tenant-keyed authenticated encryption before storage.
No. API requests operate with tenant and user context and remain subject to the applicable authorization rules.
No. Relationships can remain connected while module, role and record-level rules restrict who may access sensitive information.
Secrets belong in protected server-side configuration and key-management boundaries, never in public content or browser bundles.
No. Public publishing and authenticated member access are distinct choices and should be tested independently.
No certification is claimed without separate current evidence. Request documentation for any contractual, regulatory or assurance requirement.
Next step
Try a real workflow with the 30-day trial, or request a guided walkthrough with UnionStack.
Credit card required. Automatic billing after 30 days.