Security & data

What is true today, who is responsible for each property, and what isn't done yet. Where a fact could be read two ways, the narrower reading is the one meant.

Status

One firm in production: the practice Cairn was built for. It has not been through an independent security audit and holds no certification. Both statements will change here the day they change in fact.

Hosting

Cairn runs entirely on Cloudflare: Workers for application code, Durable Objects for each firm's live data, D1 and KV for supporting data, and R2 for documents. There are no servers to patch and no self-managed databases. Backups run nightly.

Two subprocessors touch client data: Cloudflare, which hosts everything, and Resend, which delivers the emails Cairn sends to clients and therefore handles their names and email addresses. There are no others.

Tenant isolation

Each firm is one tenant with its own Durable Object. The tenant a request belongs to is resolved from the authenticated session and never from anything the request itself can specify: no tenant identifier in a URL, header, or body is honoured. Cross-tenant addressing is structurally impossible rather than blocked by a check.

This property is enforced in continuous integration. A permanent test gate runs on every merge, and a change that could allow one tenant to read another's data fails the build.

Encryption

Two separate parties provide encryption, and the distinction matters.

Cloudflare
encrypts R2 and Durable Object storage at rest. That is a property of the platform, not of Cairn.
Cairn
adds field-level encryption on account numbers and social insurance numbers, so they are not readable in storage even to someone with access to the underlying store.

All traffic is served over TLS. Cairn does not describe itself as "encrypted at rest" without saying whose encryption is meant.

Data held

Cairn holds the working record of the practice: household and client identity (including, briefly, social insurance numbers; see known gaps), review dates and confirmations, meeting notes, action items, document checklists and the documents themselves, and onboarding and transfer status. It does not hold portfolio holdings, transactions, or performance data. A firm's data is exportable. Deletion of a firm's data on termination is being built, and is listed below as a known gap.

AI

There is no AI in the product. No language model, vector store, or model API is called anywhere in the application, and the codebase carries no dependency on one. Given the same inputs, Cairn produces the same output every time.

AI was used to write the code. Cairn's builder used AI coding tools throughout development, with the code reviewed, tested, and owned by him. This is stated here so it does not surface as a discrepancy later.

Scale

Two tests describe the platform's shape. They are checks that the design holds, not throughput benchmarks, and should not be read as capacity claims.

  • One tenant carrying 2,000 households, roughly thirty times the size of the practice it was built for.
  • Sixty tenants operating concurrently, with twelve writing to the same household identifier and each reading back only its own.

The stated design target is 500 to 1,000 advisor seats across roughly 200 firms.

Known gaps

The following are open. They're listed here so a review starts with them rather than finds them.

01Data residency is not pinned to Canada.
Cairn runs on Cloudflare, and data placement follows the platform's defaults rather than a contractual commitment to Canadian residency. Constraining it is being assessed; nothing here claims a remedy that hasn't been verified.
02No independent security assessment.
Cairn has not had a penetration test or third-party audit, and holds no certification, including SOC 2. What exists instead is automated: every change must pass a permanent cross-tenant isolation suite, secret scanning and a dependency audit before it can merge. That is not a substitute for someone trying to break in.
03A firm cannot yet be deleted.
A firm's access can be suspended completely, but its data is not yet removed on termination. Deletion is a stated product requirement, designed and not yet built.
04Encryption is narrow.
Cloudflare encrypts all storage at rest. Cairn additionally encrypts account numbers and social insurance numbers at the field level. Other record content — names, contact details, balances, meeting notes — relies on the platform's encryption and on each firm's data being held in its own isolated store.
05Social insurance numbers are held briefly, not never.
A SIN is collected when an account is opened, stored encrypted, and removed at submission or after 120 days, whichever comes first. It never appears in backups. The platform's point-in-time recovery retains deleted data for roughly 30 more days.
06Client email is not archived by the dealer.
Email Cairn sends on an advisor's behalf goes through a sending service rather than the firm's own mail system, so it doesn't appear in the advisor's sent items or the dealer's compliance archive. Cairn keeps a permanent copy of every message on the client's record. Sending through the firm's own mail system is the intended fix and requires the dealer's consent.
07Backup restores are not yet proven on a schedule.
Every firm's data is backed up nightly and a restore has been verified, but the weekly automated restore check is not yet confirmed running.
08US-dollar accounts are counted at face value.
Totals do not yet convert USD balances, so a book holding them reports a total that differs by the exchange rate.
09Client questionnaire links last 90 days.
A link lets a client fill in a form; reading anything back requires a separate code sent to them by email. A forwarded link can submit information, not read it.
10Firm setup is done by hand.
Adding and configuring a firm is currently an operator task, not a self-service process, and configuration changes made this way are not yet captured in the audit trail.
11One firm in production.
Multi-firm operation is built and tested; it has not yet run with more than one live firm.

What is not claimed

No customer counts, no testimonials, no uptime figures, no SOC 2 or any other certification, and no number that hasn't been measured. If a figure appears on this site, the method behind it is stated with it.

Questions

Write to hello@cairnsystems.ca. Questions are answered by the person who built it, which is faster than it sounds.