Skip to main content

PII-free architecture

Your customers stay invisible.

Mechanus IQ never receives customer names, addresses, phone numbers, email, or SIN. The dealer strips PII at source before the CSV ever leaves the DMS. Employees enter the system only as anonymous dealer-assigned personnel codes. Every one of the 1044 detection vectors operates on operational data, not personal data.

Sample column surface

Representative slice of the deal log ingestion schema. Dealer-side export templates enforce the left column (stripped) is never present.

TreatmentColumnReason
strippedCustomer first and last nameStripped at dealer export
strippedCustomer addressStripped at dealer export
strippedCustomer phone, email, SINStripped at dealer export
strippedEmployee nameReplaced by dealer-assigned anonymous personnel code
keptDeal #, stock #, RO #Operational identifier, no PII
keptDeal gross, reserve, product attachOperational financial data
keptAdvisor personnel codeAnonymous code assigned by dealer
keptLender identifierInstitutional, not personal
keptFunded date, statusOperational event data
keptVIN (optional)Dealer decides; not required by MIQ

Residency

  • Data never leaves AWS ca-central-1.
  • LLM inference is routed through AWS Bedrock, which keeps inference inside the Canadian boundary.
  • Backups, snapshots, and disaster recovery all in-region.

Regulatory fit

  • PIPEDA: the system was architected to avoid the compliance footprint, not just meet it.
  • FINTRAC: reporting thresholds and data classification align with the federal AML framework.
  • BC RIA 2027: appearance-style product review, GAP, warranty, and proposed Rule 7(25) disclosure fields are already in the diagnostic surface.
Back to infrastructure