Trust & compliance

How we handle security, privacy and reliability.

This page sets out the areas property owners ask us about. Specific claims are held as placeholders until legal and compliance confirm exact wording.

Status: draft. No certification, audit outcome or compliance status on this page is asserted as fact. Each item marked [VERIFY] requires written confirmation before it goes live.

Data security practices

  • [VERIFY] Encryption in transit and at rest — confirm exact standards and scope.
  • [VERIFY] Access control and least-privilege model for staff accounts.
  • [VERIFY] Data hosting region and whether resident data stays in Canada.
  • [VERIFY] Backup, retention and deletion schedule.

Privacy & PIPEDA

  • [PIPEDA COMPLIANCE STATUS — VERIFY] Do not state or imply compliance until confirmed.
  • [VERIFY] What resident personal information is collected and why.
  • [VERIFY] Data processing agreement available to property owners.
  • [VERIFY] Process for resident access and deletion requests.

Uptime & reliability

  • [VERIFY] Target uptime figure and whether it is contractual.
  • [VERIFY] Offline behaviour — what residents and carriers can still do.
  • [VERIFY] Monitoring, incident response times and status page.
  • [VERIFY] Maintenance window policy.

Carrier integrations & certifications

  • [VERIFY] Which carrier integrations are live in Canada.
  • [VERIFY] Any formal carrier certification or approval — do not claim without proof.
  • [VERIFY] How carrier access credentials are issued and revoked.

Support model

  • [VERIFY] Support hours, channels and time zones.
  • [VERIFY] Response and resolution targets by severity.
  • [VERIFY] On-site service coverage and install partner regions.
  • [VERIFY] Escalation path for property teams.

Certifications

Security standards our platform maintains

Accessa lockers run on the Koloni platform, which maintains the following security and privacy standards.

ISO 27001 compliant badge

ISO 27001 compliant.

Koloni maintains ISO/IEC 27001, the international standard for information security. It sets out the specification for an effective ISMS (information security management system), addressing people, processes and technology.

GDPR & CCPA badge

GDPR & CCPA.

Koloni maintains GDPR and CCPA compliance for all partners. These frameworks govern how organizations must handle personal data — names, phone numbers and addresses — in an integrity-friendly way.

PCI compliant badge

PCI compliant.

Koloni is PCI compliant and manages internal processes to maintain that compliance. PCI DSS is the set of requirements ensuring companies that process, store or transmit credit card information keep a secure environment.

SOC 2 compliant badge

SOC 2 compliant.

Koloni has developed and maintains a high level of security processes and procedures, with documented internal processes for data breaches, password security and managing the internal team.

Our customers

Organizations that trust Accessa

Campuses, housing providers, venues and property teams across Canada rely on Accessa lockers every day.

Centre Bell logo
Tim Hortons logo
St. Joseph's College, University of Alberta logo
Canada Life Place logo
Campus Suites logo
Kingston Frontenac Housing Corporation logo
Integris Student Living logo
Coca-Cola logo

Questions from due diligence

Need our answers in writing?

Send us your security questionnaire or procurement checklist and we'll respond with what we can confirm today.

Talk to us about security and procurement

We'll connect you with the right people for privacy, hosting and support questions.