The rules we build by.

Six commitments that shape every system we ship, and the Canadian law they answer to.

The rules we build by

Six commitments that shape every system Nezam AI ships, and the Canadian law they answer to. Not badges. Working rules, written down where clients can hold us to them.

PIPEDA: privacy as a design input

PIPEDA is Canada's federal privacy law for commercial activity. Any Nezam build that touches personal information (a tenant application, a caller's phone number, a customer record) is designed to PIPEDA's ten principles from day one: what information the workflow actually needs, where it lives, who can see it, how long it is kept, and how it is deleted. Every build is handed over with those answers written down. Legislation: https://laws-lois.justice.gc.ca/eng/acts/P-8.6/index.html

CASL: consent-first outreach

CASL governs commercial electronic messages in Canada. Anything we build that sends email or SMS is consent-first, clearly identified, and easy to leave: consent status lives in the workflow itself, sequences suppress anyone who has withdrawn consent, and an unsubscribe takes effect across the whole system. Legislation: https://laws-lois.justice.gc.ca/eng/acts/E-1.6/index.html

You own the code

Every engagement ends with the client holding the keys: repositories, accounts, credentials, and documentation all transfer at handoff. No lock-in. If Nezam disappeared tomorrow, the systems would keep running and any competent developer could pick them up.

Auditable and reversible

Every automated decision leaves a record the client can read: what came in, what the system did, what it handed to a person. Every system has an off switch that does not take the operation down with it. If we cannot explain what a system did and why, we do not ship it.

A human gate on judgment

Automate the intake, never the judgment. AI handles intake, routing, drafting, and documentation. Decisions about people (approving an applicant, waiving a fee, anything that touches someone's home or money) stay with people, by design.

Your data stays in your stack

Nezam does not run a warehouse of client records. Systems are built inside the client's own accounts: their CRM, phone platform, accounting software, and database. Access is granted, scoped, and revocable. When an engagement ends there is nothing to hand back, because the data never left.

What we do not claim

Nezam does not hold SOC 2 or ISO certifications and does not display marks it has not earned. Those audit programs exist for software vendors hosting customer data on their own infrastructure at scale. Nezam's builds run inside client systems, on platforms that carry their own compliance programs. Where an engagement calls for that class of attestation, we say so plainly and design around platforms that hold it.