A practical view of Northern Inference's security posture for procurement teams: AWS Canada inherited controls, Canadian-region routing, per-request custody, and the work underway toward formal SA&A.
Northern Inference runs on AWS infrastructure in ca-central-1 (Montreal). The physical security, datacenter operations, host operating system, hypervisor, network fabric, and AWS service implementation fall within AWS's own compliance program. Their attestations apply to the substrate that runs us.
These attestations form the inherited-controls baseline we operate on top of. For procurement reviews, we can identify the AWS Artifact reports and inherited-control areas that map into the customer evidence package.
The remainder of the ITSG-33 and Cloud Guardrails surface is operated by Northern Inference. The split below is intentionally concrete: controls that are live today, controls being formalized for procurement evidence, and controls that activate with a formal enterprise assessment.
Tier 3 (managed_canadian_cloud) routes through AWS Bedrock and Azure OpenAI in Canadian regions only. Residency fails closed: a deployment whose underlying region drifts is refused service, not silently rerouted.
Gateway model responses carry unsigned X-NI-Resolved-Region, X-NI-Resolved-Jurisdiction, X-NI-Resolved-Provider, and X-NI-Credential-Source route summaries. The portal and custody API return the canonical digest and, when signing is available, Northern Inference's Ed25519 signature for the route NI selected up to the provider boundary. Provider evidence governs execution inside the provider.
When enabled, names, emails, phone numbers, and identifiers are detected before prompts leave our infrastructure, replaced with realistic fakes, and restored in responses.
State-changing admin actions record to an indefinite-retention audit_logs table with actor, IP, user-agent, category, severity, and full detail. Filterable and exportable.
CloudFront in front of every customer-facing endpoint. Origin reachable only from CloudFront IP ranges via iptables and ipset, refreshed daily. SSH key-only. MFA on every IAM principal.
TLS 1.2 minimum on every customer endpoint. RDS, S3, and EBS encrypted with AWS-managed keys. BYOK provider credentials encrypted with Fernet keys held in AWS Secrets Manager.
Formal ITSG-33 PBMM control-by-control mapping. Each control is classified as inherited, implemented, shared, planned, or not applicable. Available to procurement teams under NDA as the package matures.
Information Security, Incident Response, Vulnerability Management, Access Control, Change Management, Backup, Cryptography, Supply Chain Risk, Personnel Security, and Acceptable Use policies. Formal review cadence is part of the procurement evidence package.
Planned continuous evaluation of AWS resources against PBMM-aligned rules, including root MFA, CloudTrail coverage, encrypted storage, and public-exposure checks.
Managed rule sets covering OWASP, bot control, and IP reputation. CloudFront is already in front of customer-facing endpoints; WAF managed rules are part of the hardening roadmap for Protected B workloads.
Continuous evidence tooling across cloud, source control, and operational systems. Activated when a formal enterprise assessment requires auditor-ready evidence collection.
Independent security testing by a qualified Canadian firm. Scheduled to align with the scope and evidence requirements of the customer assessment.
The ~250 controls in the Protected B Medium Medium Medium baseline break out into four columns when applied to Northern Inference:
/ni-platform/* log groups and state-changing admin actions record to audit_logs. Immutable log export is part of the in-progress hardening work.Northern Inference does not yet hold an Authority to Operate from any federal department. An ATO is a department's risk acceptance of a specific deployment, not a portable vendor certification, so the assessment is completed with the customer and assessor for the workload in scope.
If your team is evaluating Canadian-residency LLM infrastructure for a Protected B workload, the contact for SA&A engagement is trust@northerninference.ca. We can support a Protected B Medium Medium Medium review with the operational controls already live in production and the formal documentation package in progress.
Procurement, audit evidence, and SA&A engagement: trust@northerninference.ca.
Security disclosure: abuse@northerninference.ca.
General inquiries: hello@northerninference.ca.
Security · Privacy Policy · Terms of Service · Acceptable Use Policy