Trust Posture

Trust @ Manera

Where we are on compliance, who we share data with, and how to reach us about security or privacy. Updated quarterly. If anything here is stale, write us — we'll fix it within a business day.

Compliance posture (May 2026)

SOC 2 Type II
Vendor selected. Type I observation window starts H2 2026. Type II report planned 2026 H2 / 2027 H1.
In progress
ISO/IEC 27001
On roadmap; gap assessment scheduled after SOC 2 Type I.
Roadmap
Quebec Loi 25 (Bill 64)
Privacy officer designated; explicit-consent flows in place; breach-notification procedure documented.
Compliant
GDPR (EU/UK customers)
Standard Contractual Clauses for international transfers; signed DPA available on request.
Compliant
PIPEDA (Canada federal)
Mandatory breach-reporting workflow integrated with the mesh incident pipeline.
Compliant

Sub-processors

The third parties below process data on our behalf to deliver the Manera Intelligence mesh. We give 30 days' notice before adding any new sub-processor with access to customer data.

Security disclosure

If you've found a security issue affecting any Manera surface, please report it. We investigate every report and respond within one business day.

Machine-readable
/.well-known/security.txt
PGP key
Coming soon — request via email

We follow coordinated disclosure. Please do not exploit a finding beyond what is necessary to demonstrate it. We don't pursue legal action against good-faith researchers.

Status & incidents

Live mesh status (per-petal uptime, sync latency, public surfaces) is visible at /status and /flagships/status. No login required.

For active incidents we keep an updated bulletin at [email protected]; subscribe by emailing that address. A self-serve subscriber-managed status page is on the roadmap.

Privacy & data rights

Privacy policy: /privacy · Terms of service: /terms · Acceptable use: /acceptable-use · Data processing addendum: /data-protection (or by request to [email protected]).

To exercise an access / rectification / erasure / portability / objection / consent-withdrawal request under Loi 25, GDPR, CCPA/CPRA, PIPEDA, LGPD, PDPA, or DPDPA — write to [email protected]. We respond within the timeframes required by your local law.

Trust Doctrine

The 10 binding commitments we make to every customer about billing, refunds, spend caps, dark patterns, and data ownership are at /trust-doctrine. If we ever break one, write us at [email protected] and we'll make it right.

Legal architecture · how we got here

Every Manera flagship runs the same legal architecture — one constituted entity, one DPA, one set of sub-processors, one privacy operator, one set of terms. Talent Intel inherits its licensing-firewall posture directly from Bidit®, our consumer marketplace whose disclaimers, fee structure, and platform-vs-agent distinction were vetted in 2026 against Quebec consumer protection law (CQLR c. P-40.1), federal placement-agency law, FINTRAC obligations for cross-border payment flows, and U.S. Department of Labor guidance on platform versus agency status.

The same firewall reads in both products: Manera is never in the money path between buyer and seller. On Bidit, the consumer pays the vendor directly — we never escrow. On Talent Intel, the employer pays the bounty directly to the candidate (or the referrer) — we never collect, escrow, or remit. The structural firewall is what lets us be a SaaS information & matching platform, not a regulated employment agency or money-services business.

For private-beta customers (current state), we operate on the LexiWorld pre-cleared legal stack — a structured cross-mesh review of the entire posture against employment-law, privacy, and consumer-protection statutes in Quebec and the EU. Before any NBC-class enterprise contract, we engage Quebec employment counsel for a paid human review on top of the LexiWorld pre-clearance. Until then, the doctrine is: ship the firewall, ship the disclosures, never claim a regulated status we don't hold.

Deep dives

For longer-form treatments of how we think about compliance:

DPA + BAA available as a PDF on request. Email [email protected] with your jurisdiction and use case — we'll send a signature-ready document within one business day.

Last updated: 2026-05-03 · Reviewed quarterly · Maintained by Manera Technologies Inc., {{ juris if juris is defined else 'Québec, Canada' }}

← Manera Technologies Inc. · Pricing · Status · Privacy · Terms · Report a security issue