Fast, secure access to your data — 100% in Canada.

Data sovereignty means your information is subject to Canadian law, processed by Canadians, on infrastructure Canadians control — with no foreign court, agency, or parent company able to compel its disclosure. Nimble is one of the few document management and intelligence platforms in Canada built that way from the ground up: 100% Canadian-owned, three Protected B certified facilities, private Canadian AI, and zero CLOUD Act exposure. Twenty-plus years of experience delivering the speed and usability your teams need — backed by the security and sovereignty your compliance requires.

Data Residency ≠ Data Sovereignty

This is the single most important distinction in the conversation, and one most cloud providers blur deliberately.

  • Data residency means your data is physically stored in Canada.
  • Data sovereignty means your data is under Canadian jurisdiction — stored, processed, and governed by Canadian law, with no foreign legal reach.

Most major cloud providers — including AWS, Microsoft Azure, and Google Cloud — are US-owned companies subject to the US CLOUD Act. Even with a “Canada region” setting, the parent company remains subject to US courts and US law enforcement. The US government can legally compel them to produce data, regardless of where servers are physically located. A Canadian data centre doesn’t protect you from US jurisdiction.

Nimble is different. We are 100% Canadian-owned, with no foreign parent company, no US holding structure, and no cross-border legal exposure. Your data is processed by security-cleared Canadian staff in Protected B facilities, using entirely Canadian infrastructure. There is no foreign court that can compel Nimble to hand over your data.

Why Canadian Organizations Choose Sovereign Infrastructure

For government departments, healthcare providers, financial institutions, and any organization holding records about Canadian citizens, sovereignty isn’t a procurement checkbox — it’s a defensible legal posture. The reasons Canadian organizations are moving to sovereign infrastructure include:

  • Meeting public-sector procurement requirements that exclude foreign jurisdictional exposure.
  • Complying with PIPEDA, PHIPA, FIPPA, and other Canadian privacy laws that demand provable control.
  • Reducing legal exposure under the US CLOUD Act, US FISA, and other extraterritorial laws.
  • Maintaining public trust and accountability for records about Canadians.
  • Protecting confidential commercial, health, and personal data from foreign discovery.
  • Building AI capability on infrastructure that doesn't expose customer data to public models or foreign API endpoints.

The Nimble Difference

Fast and accurate access

Your teams need documents found in seconds, not days. Nimble delivers same-day digitization, AI-powered search, and instant access through SmartCloud — our secure portal. Fast implementation, too: branded instances deployed in as little as two business days from contract signing.

20+ years of knowledge and experience

Founded in 2003, Nimble has spent over two decades solving document management challenges for Canada's most demanding organizations. Our team combines deep expertise in federal, provincial, healthcare, and enterprise operations with hands-on experience processing millions of pages annually.

Canadian ownership and facilities

100% Canadian-owned with no foreign parent — your data is never subject to the US CLOUD Act. Three Protected B certified facilities across Canada: Aurora, ON (HQ and main processing), Ottawa, ON (federal operations), and Winnipeg, MB (western region). A Québec City sales office supports federal Québec and Québec provincial clients. Security-cleared Canadian staff at every level.

Sovereign Canadian technology

Nimble Intelligence — our private AI — runs on Canadian infrastructure only. No API calls to OpenAI, Google, Azure, or any US-based service. Document processing, classification, extraction, and search all happen entirely within Canada, on infrastructure we control. AI models are trained on your data, on your terms, in your jurisdiction.

Full visibility and total control

RFID-tracked physical document handling. Timestamped logs and exception reporting. Role-based access and end-to-end audit trails. Custom metadata schemas and retention rules. We make it easy to stay compliant, stay in control, and stay audit-ready.

Compliance and Certifications

Your data is protected with enterprise-grade security and regulatory compliance.

Compliance StandardStatusDescription
PIPEDACompliantPersonal Information Protection and Electronic Documents Act — Canada's federal privacy law.
PHIPACompliantPersonal Health Information Protection Act — Ontario's health privacy legislation.
FIPPACompliantFreedom of Information and Protection of Privacy Act — provincial public-sector privacy.
ITSP.10.033 (ITSG-33)CompliantIT Security Risk Management — Government of Canada's IT security standard.
SOC II Type IIAuditedIndependent audit of security controls and operational processes.
Protected BCertifiedGovernment of Canada's classification for information that could cause serious injury if compromised.
AODAAccessibleAccessibility for Ontarians with Disabilities Act.

How Nimble Compares to US-Owned Providers

NimbleUS-Owned Providers (AWS, Azure, Google Cloud)
Ownership and jurisdiction
100% Canadian-owned, Canadian jurisdiction.
Parent company subject to US CLOUD Act jurisdiction.
CLOUD Act exposure
None.
US government can legally compel data disclosure.
Facilities
Protected B certified, located in Canada.
Data may be replicated across global infrastructure.
Staff
Canadian clearance holders only.
Staff may not hold Canadian security clearances.
Cross-border data transfers
Zero.
"Canada region" does not change parent company jurisdiction.
AI processing
Private Canadian AI. No foreign API calls.
May rely on shared foundation models and infrastructure outside Canada.
Audit and disclosure obligations
Canadian law only.
Foreign disclosure obligations under US law.

Who We Serve

Nimble supports Canadian organizations that rely on secure, sovereign data environments:

  • Federal, provincial, and municipal government — departments, agencies, and Crown corporations.
  • Healthcare institutions and regulatory bodies — hospitals, regional health authorities, payer organizations.
  • Financial services and insurance — banks, credit unions, insurers, asset managers.
  • Utilities, infrastructure, and energy — operators with long-lived asset documentation and regulatory exposure.
  • Legal and professional services — firms with confidentiality and audit obligations.
  • Education and research — universities, school boards, research institutions.

Frequently Asked Questions

What is data sovereignty?+

Data sovereignty means your data is subject to the laws and governance of the country where it's collected, stored, and processed. In Canada, this means your records, processing, AI models, and audit trail all fall under Canadian law and are not subject to foreign jurisdiction — including the US CLOUD Act.

What's the difference between data residency and data sovereignty?+

Data residency means your data is physically stored in Canada. Data sovereignty means your data is under Canadian jurisdiction — stored, processed, and governed by Canadian law, with no foreign legal reach. A "Canada region" setting from a US-owned cloud provider gives you residency but not sovereignty.

Does the US CLOUD Act apply to Canadian customer data stored in Canadian data centres?+

Yes, if the cloud provider is US-owned. The US CLOUD Act allows US law enforcement to compel US-headquartered companies to produce data they control, regardless of where it is physically stored. This applies to AWS, Microsoft Azure, Google Cloud, and other US-owned providers — even when their Canadian regions are used.

Is Nimble subject to the US CLOUD Act?+

No. Nimble is 100% Canadian-owned with no US parent company, no US holding structure, and no cross-border legal exposure. There is no foreign court that can compel Nimble to disclose your data.

What laws does Nimble comply with?+

Nimble is compliant with PIPEDA (Canada's federal privacy law), PHIPA (Ontario's health privacy law), FIPPA (provincial public-sector privacy), ITSP.10.033 (formerly ITSG-33; Government of Canada IT security risk management), SOC II Type II (independent security audit), and operates Protected B certified facilities. AODA accessibility standards are also supported.

Where is Nimble's infrastructure located?+

Nimble operates three Protected B certified facilities in Canada: Aurora, ON (headquarters and main processing), Ottawa, ON (federal operations), and Winnipeg, MB (western region). All processing, storage, and AI inference happen on Canadian infrastructure. A Québec City sales office supports federal Québec and Québec provincial clients with bonded pickup to Ottawa.

Does Nimble's AI use OpenAI, Google, or Microsoft services?+

No. Nimble Intelligence — our private AI — runs entirely on Canadian infrastructure. There are no API calls to OpenAI, Google, Azure, or any US-based AI service. Document classification, extraction, and search all happen within Canada, on infrastructure Nimble controls.

Can Nimble guarantee that my data won't leave Canada?+

Yes. All operations — physical document handling, scanning, indexing, AI processing, storage, and access — happen in Canadian facilities operated by security-cleared Canadian staff. There are no offshore data flows and no foreign-owned infrastructure dependencies.

How does Nimble handle physical documents?+

Physical documents are tracked with RFID at every stage of handling, with timestamped logs, exception reporting, and chain-of-custody documentation. Originals are returned, stored, or destroyed with certificate of destruction — your choice.

Is Nimble's AI trained on customer data?+

Yes, but on your terms. Nimble Intelligence models can be trained on your data within your jurisdiction, controlled by your retention and access rules. No customer data is used to train models for other customers or shared outside your environment.

Does Nimble work with the private sector or only government?+

Both. Nimble serves federal, provincial, and municipal governments alongside healthcare institutions, financial services, insurance, legal, energy, utilities, and education. Any organization that needs sovereign Canadian infrastructure for its records and AI is a fit.

How fast can Nimble deploy a sovereign environment?+

Branded SmartCloud instances can be deployed in as little as two business days from contract signing. Full project onboarding (with pickup, digitization, and integration) varies by scope and is fixed during discovery.

What's the difference between Nimble and a Canadian government cloud certified by the Canadian Centre for Cyber Security?+

Government cloud certifications cover infrastructure security and configuration. They do not change the jurisdictional status of the parent company. A CCCS-certified AWS region is still operated by Amazon Web Services Inc., a US-headquartered company subject to US law. Nimble is Canadian at the company level — not just at the data centre level.

Ready to Secure Your Data Under Canadian Law?

Book a 20-minute call with our solutions team to walk through your sovereignty requirements — jurisdiction, compliance, AI use, and integration — and see what a sovereign Canadian environment would look like for your organization.

Book a Consultation