GuardsArm ComplianceBuilt for Canadian frameworks from the ground up
Not a US platform retrofitted for Canada — a platform that starts with HIA, POPA/ATIA, AER Directive 084, and PCI DSS as first-class frameworks.
Platform Overview
- Deployment
- SaaS
- Data residency
- Canada only
- Status
- Early Access
- Pricing
- Contact for pricing
- Canadian frameworks
- 4 mapped
Framework Coverage
4 Canadian frameworks mapped today, with more in progress.
Health Information Act (HIA)
Alberta’s primary healthcare privacy statute. Control catalogue mapped with safeguard requirements as first-class obligations — not an afterthought bolt-on.
POPA / ATIA
Protection of Privacy Act and Access to Information Act obligations for Alberta municipalities. Built for the exact obligations city governments and regional authorities face.
AER Directive 084 / 2024
Alberta Energy Regulator cybersecurity requirements for energy operators. Pre-mapped so operators aren’t interpreting technical regulation into controls manually.
PCI DSS v4.0.1
Payment card industry standard. Control catalogue derived directly from GuardsArm’s active delivery engagements — built from what auditors actually check.
PIPEDA / Law 25
Federal private-sector privacy law and Quebec’s Law 25. Partial mapping in progress.
ISO 27001 / SOC 2
International standards. Manual setup available for early access customers on request.
Capabilities
Honest status by capability. Live ships today; Roadmap items are planned for general availability.
| Capability | Status | Notes |
|---|---|---|
| Framework control catalogue | Live | HIA, POPA/ATIA, AER 084, PCI DSS v4.0.1 |
| Policy library (templates) | Live | Pre-built policy templates per framework |
| Framework dashboards | Live | Compliance posture view per framework |
| Evidence management | Roadmap | Manual upload available in early access |
| Continuous monitoring | Roadmap | AWS / Azure / O365 integrations planned |
| Risk register | Roadmap | — |
| Audit evidence packages (PDF / ZIP) | Roadmap | Export model planned |
| Vendor risk management | Roadmap | — |
Why not Vanta, Drata, or Auditboard?
Those platforms were built for US compliance — SOC 2, HIPAA, FedRAMP. They don’t know what HIA is. They don’t have POPA mapped. AER Directive 084 doesn’t exist in their control libraries.
A Calgary hospital or Alberta municipality using Vanta spends months manually translating US-centric controls to Canadian obligations — and often gets it wrong.
GuardsArm Compliance starts where Canadian organizations actually live. Every control, every policy template, every mapped safeguard reflects how Canadian regulators and auditors actually ask the questions.