153 Base Solutions Inc. home Contact us

Compliance, stated honestly.

We hold no security or quality certifications. What we do have is a set of practices drawn from the standards Canadian public sector buyers ask about, and a willingness to tell you exactly where we fall short.

  • No security certifications
  • Practices documented
  • Gaps stated up front

Frameworks we work to

What we align to.

Alignment, not certification. Each of these shapes how we build and operate; none of them is a badge we hold.

Certification held

What we hold.

One certification, issued by an independent council, with a number you can quote and dates you can check. It is a supplier certification, not a security or quality one, so the list of what we do not have, further down this page, still stands.

Certified CAMSC Supplier

Issued by
Canadian Aboriginal and Minority Supplier Council (CAMSC)
Certification
Certified CAMSC Supplier
Type
Regular Supplier
Certificate number
A-20457
Issued
22 September 2026
Expires
22 September 2027

CAMSC is affiliated with the National Minority Supplier Development Council (NMSDC). To confirm the certificate is current, contact CAMSC through camsc.ca. This section comes off the site automatically on the expiry date.

Security

How we handle security.

SOC 2 Trust Services Criteria

We are not SOC 2 certified and hold no attestation report. We operate to practices drawn from the Trust Services Criteria, covering security, availability and confidentiality, because they are a sensible baseline rather than because we can produce a report against them.

  • Access to client systems is least-privilege, individually named, and revoked when an engagement ends.
  • Multi-factor authentication on every account that touches client infrastructure.
  • Change management through version control, with review before anything reaches production.
  • Backups taken on a schedule and restores tested, rather than assumed.
  • Logging and monitoring on hosted systems, with a defined incident response path.

If your requirement is for a supplier holding a current SOC 2 Type II report, we do not meet it. We would rather tell you that now than at evaluation.

ISO/IEC 27001

Not certified. We follow information security management practices consistent with the standard: asset inventory, access control, secure development, supplier management and incident handling. There is no accredited audit behind them.

ITSG-33 and Government of Canada guidance

For federal engagements we work to the control expectations in ITSG-33, the Communications Security Establishment’s IT security risk management framework, and follow CSE cryptographic guidance for protocols and algorithms in transit and at rest. We can support a Security Assessment and Authorization process as the technical supplier, though the authorisation itself rests with the department.

CIS Controls

Our internal baseline follows the CIS Critical Security Controls at Implementation Group 1, which is the level proportionate to an organisation of our size. We can describe our position against each control on request.

Data classification and residency

We are set up to handle information up to Protected A under Canadian government classification. We do not currently hold the facility screening required for Protected B, and would need to obtain it before an engagement at that level.

Client hosting can be provisioned in Canadian regions where residency is required. Note that this website itself is currently hosted in the United States; that is disclosed in our privacy policy and is being addressed.

AI

How we handle AI work.

Where inference runs

We host inference in Canada. Client documents and prompts are not sent to a United States API. Where a requirement calls for Canadian data residency, AI work does not become the exception that breaks it.

Frameworks we work to

  • ISO/IEC 42001, the AI management system standard. We follow its practices. Not certified.
  • NIST AI Risk Management Framework, used to structure how we identify and document model risk.
  • TBS Directive on Automated Decision-Making. We can supply the technical input an Algorithmic Impact Assessment requires, though the assessment itself belongs to the institution.

How we build

  • Retrieval before generation, so answers are grounded in your material and carry citations.
  • An evaluation set built before launch, with quality measured rather than asserted.
  • Human checkpoints in front of any consequential action an agent can take.
  • Audit logging of model inputs and outputs, so a decision can be reconstructed.
  • Interfaces built to the same WCAG 2.1 AA target as everything else, including streaming responses a screen reader announces correctly.

What we do not do

  • No fine-tuning. Most problems presented as fine-tuning problems are retrieval or prompting problems. Where fine-tuning is genuinely the answer, we will say so and point you elsewhere.
  • No training on your data. Your material answers your questions; it does not improve a model.
  • No automated decisions about people without a human in the loop, whatever the requirement says.

Privacy

Privacy and data protection.

PIPEDA

We handle personal information in line with the Personal Information Protection and Electronic Documents Act: consent for collection, use limited to the stated purpose, retention limits, access and correction on request, and breach notification where there is a real risk of significant harm. Our own practices are set out in the privacy policy.

Privacy Act and Privacy Impact Assessments

Where we build or host systems for federal institutions, we work within the obligations the Privacy Act places on the institution, and can supply the technical input a Privacy Impact Assessment requires: data flows, storage locations, retention, and access controls.

Quebec Law 25

For clients serving Quebec residents we build to Law 25’s requirements on tracking technologies, including profiling technology being off by default and consent being obtained rather than assumed.

CASL

Any email function we build for a client is built to require express or implied consent, with identification and unsubscribe handling, as Canada’s Anti-Spam Legislation requires.

Accessibility

The one we can evidence.

This is the area where we can show evidence rather than describe intent.

  • WCAG 2.1 Level AA is our default conformance target for delivered interfaces.
  • EN 301 549 is the ICT accessibility standard referenced in public sector procurement, and is adopted in Canada as a National Standard.
  • Accessible Canada Act. We build to support the obligations it places on federally regulated entities.
  • AODA covers Ontario’s requirements, which reach many private organisations as well as public ones.

Our own site is audited and the results published, including what is unfinished. See the accessibility statement. It is a working example of the conformance reporting we provide on client engagements.

Standing

Business, screening and languages.

Business standing

  • 153 Base Solutions Inc., incorporated in Ontario, Canada.
  • Commercial general liability and professional liability insurance, with certificates available on request.
  • WSIB coverage as required in Ontario.
  • No conviction or circumstance that would make us ineligible under the federal Integrity Regime.

Personnel security screening

We do not currently hold organisational screening under the Contract Security Program, and no personnel hold active Reliability Status or higher. We are prepared to obtain screening as a condition of award where a contract requires it, and will say so plainly in a bid rather than imply we already have it.

Official languages

We deliver in English. We can build and maintain bilingual English–French interfaces, and engage professional translation for content, but we are not a bilingual organisation internally. Where a requirement demands francophone service delivery, we would partner rather than overstate.

Subcontracting and teaming

We work as a subcontractor to prime vendors on technical and accessibility scope. For larger requirements this is often the right structure, and we will say when it is.

Read this part first

What we do not have.

Suppliers usually list what they hold. It is more useful to state what we do not, so you can rule us out quickly if it matters.

  • No SOC 2 report. Type I or Type II.
  • No ISO/IEC 27001 certification.
  • No PCI DSS attestation. We do not handle cardholder data; payment work is delegated to a compliant processor.
  • No organisational or personnel security screening currently held.
  • No Protected B facility.
  • No standing offer or supply arrangement in place.

Where a mandatory criterion calls for any of the above, we do not meet it, and we will not submit a response implying otherwise. Where a criterion asks how a supplier operates rather than what it holds, everything above is what we would put in writing.

Need something evidenced that is not here?

Tell us the criterion and we will answer it straight, including when the answer is that we do not meet it. We would rather lose a bid than win one on a claim we cannot support.