On This Page

System Identification

Core identifying information for procurement and regulatory review.

🏛

System Name

COMPAiSS - Compliance-Oriented Multi-Platform AI Institutional Scope System

🏗

System Type

Execution-gated institutional AI information system. Not a general-purpose AI. Not a decision-making system.

👤

Developer and Accountable Party

Frank Harvey, Founder and CEO COMPAiSS Inc., holds the intellectual property and patent applications.

Patent Status

Canadian patent application CIPO 3,299,174 and US patent application USPTO 19/455,963 - both under examination, describing the pre-inference execution gate mechanism.

🚀

Deployment Status

Active beta pilots across five Canadian institutional environments, including research-intensive universities and a federal public service context. Two additional pilots under institutional review.

🤖

AI Engine

Azure OpenAI Service - Canada East region. Standard inference API without fine-tuning. No institutional data enters any training pipeline at any stage.

Assessment Scope

This assessment covers the COMPAiSS platform architecture and governance framework as deployed across regulated institutional environments. Institution-specific deployment configurations - including authorized source lists, scope boundaries, and crisis response protocols - are documented separately for each institutional deployment and are available on request.


Risk Classification

Assessment against Canada's Directive on Automated Decision-Making and equivalent institutional AI governance frameworks.

Classification Finding

Level I - Little to No Impact under Canada's Directive on Automated Decision-Making. COMPAiSS scores at the lowest risk level on every relevant assessment dimension. This classification applies to all current institutional deployments.

The Level I classification is supported by four independent findings, each of which independently places the system at the lowest impact level:

Framework Applicability

While the Directive on Automated Decision-Making is a Government of Canada instrument, the risk dimensions it assesses - decision authority, personal data handling, reversibility, and accuracy controls - are directly applicable to institutional AI governance review in higher education, healthcare, and public sector contexts. COMPAiSS scores at the lowest risk level on all dimensions regardless of which institutional framework is applied.


Data Governance

What the system collects, processes, and retains - and what it does not.

Personal Data Collected

None. No names, IDs, account numbers, or any identifying information at any stage.

Query Retention

None. Queries are processed transiently and discarded. Nothing is retained after the response is delivered.

Security Classification

Unclassified. All source content consists of publicly available institutional web pages.

PIA Requirement

Not required. No personal information is collected or processed at any stage.

Training Data

Not applicable. Standard inference API without fine-tuning. No institutional data enters any model training pipeline.

Data Residency

All application hosting, AI inference processing, and operational logging are restricted to Canadian infrastructure. AI inference is performed exclusively through Azure OpenAI Service in the Canada East region, satisfying PIPEDA and provincial privacy law requirements.

Aggregated, anonymized usage patterns - for example, topic areas generating high query volume - can be made available to the institution for service planning. This analytics function operates exclusively on de-identified aggregate data and cannot be traced back to any individual user.

Data Governance Finding

COMPAiSS operates entirely outside the personal data space by architectural design. There is no personal data pipeline to govern, no data retention policy to administer, and no risk of data breach exposing user information - because no user information is collected.


Architecture Accountability

How the system enforces scope, maintains audit trails, and supports institutional oversight.

COMPAiSS is built on an execution-gated inference architecture. Authorization and scope validation occur before any AI generation takes place. If no authorized institutional source exists for a query, the AI model does not execute. This is the core architectural accountability property - and it is not a configuration setting that can be overridden at the user level.


Risk Register

Identified risks by category with architectural and operational mitigations.

No ethical, financial, privacy, or legal risks have been identified that would impede institutional deployment. The following risks have been identified and mitigated:

Technical Risks

Governance Risks

Equity Risks

Reputational Risks

Risk Assessment Finding

All identified risks are mitigated at the architectural level - not through post-deployment monitoring or policy controls alone. This means mitigations are structural properties of the system that cannot be accidentally disabled or configured away.


Human Oversight and Recourse

How institutional authority is preserved and how users escalate when the system does not meet their needs.

Human oversight and intervention operate at multiple levels within every COMPAiSS deployment. The system is designed from the concept stage to preserve institutional authority and user recourse at every point.


Procurement Readiness

Documentation and compliance status for institutional procurement and governance review processes.

📋

Algorithmic Impact Assessment

A complete AIA has been prepared and submitted for federal review. Institution-specific AIA documentation is available for any regulated institutional deployment on request.

🔒

Privacy by Design

Stateless queries, no personal data collection, no session storage, no user profiling. The system operates entirely outside the personal data space by architectural design.

Patent-Protected Architecture

The pre-inference execution gate is the subject of patent applications in Canada (CIPO 3,299,174) and the United States (USPTO 19/455,963). The architectural distinction is formally documented and defensible.

🍁

Canadian Data Residency

All application hosting (Fly.io Toronto, YYZ), AI inference processing (Azure OpenAI Canada East), and operational logging are restricted to Canadian infrastructure. No data leaves Canadian jurisdiction at any stage.

🌐

Accessibility

Web-embedded interface accessible from any browser-enabled device. No specialized software, download, or installation required. Formal WCAG 2.1 AA accessibility compliance review is conducted prior to each institutional deployment.

📊

Real-Time Governance Tools

Compliance receipts, governance delta comparisons, and governance reports are available to authorized institutional administrators without external software or AI assistance. See the AI Governance page for full details.

Acceptable Use Policy Compatibility

COMPAiSS enforces a stricter epistemic boundary than most institutional AUPs require. Because the system only responds to queries within institution-approved scope, and because all responses are traceable to specific authorized sources, COMPAiSS is compatible with standard AUP frameworks by design. For institutions with AI-specific AUP provisions, the execution-gated architecture provides a documented, auditable compliance path that generation-first systems cannot match.

Liability Framework

COMPAiSS answers only from sources the institution itself has designated as authoritative. If those sources contain an error, the institution's liability exposure is no greater than if a staff member read from the same page. More importantly, COMPAiSS eliminates the category of fabricated institutional guidance - where an AI invents policy that does not exist - that creates the most serious liability exposure for institutions deploying generation-first AI. That class of error is architecturally impossible in COMPAiSS.


Canada's National AI Strategy and Regulated Institutions

How Canada's evolving AI governance framework aligns with execution-gated institutional AI.

Canada's National Artificial Intelligence Strategy recognizes both the opportunities and risks associated with widespread AI adoption. The strategy emphasizes responsible deployment, public trust, transparency, accountability, and governance as essential conditions for the successful use of AI across public institutions and regulated sectors. It reflects a broader international trend toward trustworthy AI, accountable AI systems, and governance frameworks for regulated institutional environments.

As AI systems become more capable, the governance challenge becomes increasingly important. Institutions are expected not only to demonstrate that AI systems are useful, but also that they operate within clearly defined accountability frameworks, respect institutional authority, and maintain public confidence.

Key Governance Challenge

The central challenge identified across modern AI governance frameworks is not simply improving model performance. It is ensuring that AI-generated outputs remain consistent with authorized information, institutional responsibilities, and established governance requirements.

As frontier models gain access to larger knowledge bases and increasingly sophisticated reasoning capabilities, they also gain greater ability to generate information beyond institutional boundaries. Governance therefore becomes more important - not less - as AI systems become more powerful.

What This Means for Regulated Institutions

COMPAiSS Assessment

COMPAiSS was designed around many of the governance challenges identified in emerging Canadian AI governance frameworks. Rather than attempting to manage hallucinations after generation through monitoring, filtering, or review processes, COMPAiSS applies authorization and source governance before inference occurs. Institutional source boundaries, auditability, accountability, and governance controls are enforced structurally through the execution gate rather than through downstream mitigation mechanisms.

For institutions evaluating AI under emerging Canadian governance frameworks, the distinction between generation-first architectures and governance-first architectures such as execution-gated inference may become increasingly significant as expectations surrounding accountability, transparency, and responsible AI continue to evolve.

AI Governance Framework | Why AI Developed This Way | Governance Stress Tests and Benchmarks


Policy and Regulatory Alignment Report

How execution-gated inference maps to Canadian and international governance frameworks.

COMPAiSS has published a structured policy and regulatory alignment report evaluating the execution-gated inference architecture against Canada's Voluntary Code of Conduct on Responsible Generative AI, the National AI Strategy AI for All (June 2026), the NIST AI Risk Management Framework, and Zero Trust Architecture standards.

✗   Generation-First AI - Governance After the Fact
Model runs first, governance applied after
Hallucinated outputs caught post-generation
2 to 5 percent adversarial false negative rate
Full token cost consumed even for refusals
Audit trail begins after unauthorized output exists
Governance costs scale as model capability increases
✓   COMPAiSS - Authorization Before Inference
Authorization checked before model executes
Unauthorized queries never reach the model
Deterministic gate reduces semantic manipulation risk
Refusals cost zero marginal compute
Audit trail exists before any output is produced
Governance invariant to model capability improvements
Policy and Regulatory Alignment Report

Download the full report (PDF) →

Full evaluation against Canada's Voluntary Code of Conduct, the National AI Strategy AI for All, NIST AI RMF, and Zero Trust Architecture standards, with empirical benchmarking results and institutional deployment evidence.


Request Documentation

How to obtain formal governance documentation for procurement or regulatory review.

The following documentation is available on request for any institution conducting a formal procurement or governance review:

Request Governance Documentation

To request formal governance documentation, schedule a procurement review presentation, or discuss an institutional pilot deployment:

Request Documentation →

Privacy Policy

COMPAiSS Inc. | Last updated: June 2026

COMPAiSS is designed so that privacy protection is not a policy commitment layered on top of the platform - it is a structural property of how the system works. This policy describes what data COMPAiSS collects, processes, and retains in connection with institutional deployments, including the Dalhousie University COMPAiSS deployment.

Summary

COMPAiSS does not collect, store, or share any personal information. Queries are stateless and discarded immediately after a response is delivered. No user data is retained, logged, or used for any purpose beyond generating a single response.

What We Do Not Collect

COMPAiSS does not require users to sign in or create an account. No identifying information is collected at any stage:

How Queries Are Processed

When a user submits a query, it is validated against the institution's approved source list before any AI generation occurs. If the query falls within the authorized scope, it is transmitted securely via HTTPS to the AI inference layer for processing. The response is returned to the user and the query is discarded. Nothing is retained after the transaction completes.

AI Inference

For the Dalhousie University deployment, AI inference is processed exclusively through Microsoft Azure OpenAI Service in the Canada East region. Queries do not leave Canadian jurisdiction. Microsoft's enterprise terms confirm that institutional data is not used to train or improve AI models.

Application Hosting

The COMPAiSS application is hosted on Fly.io infrastructure in the Toronto (YYZ) region. Operational logs are maintained on Canadian-hosted infrastructure. No data is processed outside of Canada.

Canadian Data Residency

All components of the Dalhousie COMPAiSS deployment - application hosting, AI inference, and operational logging - are restricted to Canadian infrastructure, satisfying PIPEDA and Nova Scotia privacy law requirements.

No Model Training

No institutional data, student queries, or interaction history enters any AI model training pipeline at any stage. The AI model used by COMPAiSS is updated only by Microsoft, entirely independently of institutional data.

Operational Logging

COMPAiSS maintains operational logs for platform integrity, security, and governance purposes. These logs record system-level events such as gate authorization results, source retrieval outcomes, and platform version information. Logs do not contain query text, user identifiers, or any personally identifiable information. Retention controls are configurable per institutional agreement. Access to logs is restricted to authorized personnel.

Aggregated Usage Data

Anonymized, aggregated usage patterns - such as topic areas generating high query volume - may be made available to the institution for service planning purposes. This data cannot be traced back to any individual user and does not constitute personal information under PIPEDA or applicable provincial privacy law.

Third-Party Infrastructure

COMPAiSS relies on the following infrastructure providers for the Dalhousie deployment:

No identifying information is shared with any third party. All third-party services operate under contractual data protection obligations consistent with Canadian privacy requirements.

Data Subject Rights

Because COMPAiSS does not collect or retain personal information, there is no personal data associated with any individual user that could be accessed, corrected, or deleted on request. Users who have questions about what information, if any, may be held in connection with their use of the platform are encouraged to contact us directly.

Security

All communications between users and the COMPAiSS platform are encrypted using HTTPS with TLS 1.2 or higher. Data at rest is protected using AES-256 encryption. Network-level protection is provided by Cloudflare infrastructure.

Changes to This Policy

This Privacy Policy may be updated to reflect changes in platform architecture, institutional deployment configurations, or applicable law. Material changes will be noted with an updated date above. Institutions with active deployments will be notified directly of any changes that affect their privacy commitments.

Contact
If you have questions or concerns about this Privacy Policy or about how COMPAiSS handles data in connection with your institution's deployment, please contact:

Frank P. Harvey, Founder and CEO
COMPAiSS Inc.
[email protected]