SecureAware
Regulatory Compliance

CRTC, CASL & PIPEDA Compliance Framework

How Group 4 Networks and SecureAware align with Canadian telecom, anti-spam, and privacy regulations for ethical SMS and voice phishing simulation testing.

Last updated: February 2026

About This Document

SecureAware is an enterprise security awareness and phishing simulation platform operated by Group 4 Networks. This document outlines our commitment to regulatory compliance under Canadian law — specifically the Canadian Radio-television and Telecommunications Commission (CRTC) regulations, Canada's Anti-Spam Legislation (CASL), and the Personal Information Protection and Electronic Documents Act (PIPEDA). Our platform conducts authorized, ethical SMS phishing (smishing) and voice phishing (vishing) simulations to help organizations measure and reduce human security risk.

CASL

Canada's Anti-Spam Legislation (CASL)

How SecureAware aligns with CASL requirements for commercial electronic messages and phishing simulation.

Consent & Authorization

  • All SMS phishing simulations are conducted only with explicit written authorization from the client organization
  • Client service agreements include clear disclosure that phishing simulation testing will be conducted on their employees
  • Employment contracts and IT security policies are recommended to include notice of security awareness testing as a condition of participation
  • Express consent is obtained through formal engagement agreements between Group 4 Networks and the client prior to any campaign launch
  • Client organizations are responsible for establishing appropriate consent with their employees, which may include implied consent through existing employment relationships

Message Identification & Transparency

  • All simulation campaigns are traceable to Group 4 Networks / SecureAware as the authorized testing provider
  • Post-simulation educational reveal pages clearly identify SecureAware and the purpose of the test
  • Campaign records maintain full sender identification, timestamps, and content logs for audit purposes
  • Clients receive complete documentation of all messages sent during each campaign

Opt-Out & Unsubscribe Mechanisms

  • Recipients can be excluded from future simulations at any time via the platform's opt-out controls
  • Kill switch functionality allows immediate termination of any active campaign
  • Opt-out requests are processed within the platform and honored for all subsequent campaigns
  • Rate limiting controls prevent excessive message delivery to any individual recipient

Record Keeping

  • SecureAware maintains audit-grade logs of all consent records, campaign activity, and recipient interactions
  • Consent documentation includes when, how, and by whom authorization was granted
  • All campaign data is retained in accordance with CASL's record-keeping requirements
  • Compliance export functionality enables organizations to produce records for regulatory review

CASL Penalties

Violations of CASL can result in administrative monetary penalties of up to $1 million for individuals and $10 million for businesses per violation. Group 4 Networks takes these obligations seriously and maintains rigorous compliance controls across all SecureAware operations.

CRTC

Canadian Radio-television and Telecommunications Commission (CRTC)

How SecureAware aligns with CRTC telecom regulations for SMS and voice-based testing.

SMS Telecom Compliance

  • All SMS messages are sent through licensed, CRTC-compliant telecommunications service providers (Twilio)
  • Message delivery adheres to Canadian carrier requirements including proper sender identification
  • Rate limiting and throttling controls prevent excessive message volumes that could trigger carrier-level filtering
  • SecureAware does not use spoofed, unassigned, or unauthorized phone numbers for SMS delivery
  • Simulation messages are designed to test awareness — not to harvest actual personal information or credentials

Voice (Vishing) Telecom Compliance

  • All voice calls are initiated through CRTC-compliant telecommunications infrastructure (Twilio Programmable Voice)
  • Caller ID information is transmitted accurately and not spoofed or falsified
  • Voice simulations are delivered through Twilio's infrastructure which supports STIR/SHAKEN caller authentication as required by the CRTC
  • Call recordings and transcripts are maintained as audit evidence where applicable
  • Webhook-secured event logging provides complete call lifecycle documentation

Section 7 & Section 9 Considerations

  • CASL Section 7 prohibits altering transmission data or installing programs without consent — SecureAware simulations do not install any software or alter transmission data on recipient devices
  • CASL Section 9 liability provisions are addressed through formal authorization agreements that clearly define Group 4 Networks' role as an authorized testing provider
  • Simulated phishing landing pages are educational in nature and do not collect, store, or transmit actual credentials
  • All testing is conducted under documented business purpose: cybersecurity awareness training and human risk assessment

Anti-Spam & Nuisance Call Protections

  • Campaign frequency controls prevent recipients from receiving excessive test communications
  • 30-second cooldown periods between campaign sends prevent message flooding
  • 2-second rate limiting on tracking endpoints prevents abuse
  • Kill switch functionality enables immediate cessation of any campaign at any time
PIPEDA

Personal Information Protection and Electronic Documents Act (PIPEDA)

How SecureAware protects personal information and respects employee privacy rights.

Data Collection & Purpose Limitation

  • SecureAware collects only the minimum personal information necessary for security awareness testing: name, email, phone number, and organizational role
  • Data collection purposes are clearly disclosed in client service agreements and privacy documentation
  • Simulation results (click rates, report rates, call interactions) are collected strictly for security training and risk assessment purposes
  • No actual credentials, passwords, or sensitive financial information is collected during simulations

Consent & Transparency

  • Client organizations provide consent for employee testing through formal service agreements
  • Organizations are advised to include security awareness testing disclosure in employee privacy policies and IT acceptable use policies
  • Employees are informed that security awareness testing programs exist within their organization (general notice, not specific test timing)
  • Post-simulation educational reveals provide transparency about the test and its purpose

Data Security & Safeguards

  • All personal information is stored in encrypted PostgreSQL databases with access controls
  • Multi-tenant architecture ensures strict data isolation between client organizations
  • Unique token-based tracking prevents cross-tenant data access or leakage
  • UUID validation on all tracking and webhook endpoints prevents unauthorized access
  • One-time tracking ensures each interaction is recorded once, minimizing data exposure

Data Retention & Access

  • Campaign data is retained only for the duration agreed upon in client service agreements
  • Client organizations can request complete data exports or deletion at any time
  • Individual employees can request access to their personal data through their employer
  • Aggregated and anonymized reporting is available to minimize personally identifiable information exposure
Ethical Framework

Ethical Phishing Simulation Standards

Group 4 Networks' commitment to safe, responsible, and ethical security testing.

Written Authorization

Every simulation campaign requires documented, signed authorization from the client organization before any testing begins.

Safe Simulations

Simulations are designed to measure awareness — not to cause harm, collect real credentials, or disrupt business operations.

Educational Purpose

Every simulation ends with an educational reveal that explains what happened, why it matters, and how to recognize real attacks.

Non-Punitive Approach

Results are used for training and organizational risk assessment. We recommend clients use results for education, not disciplinary action.

Data Minimization

We collect only what's necessary for testing. No actual credentials, financial information, or sensitive personal data is captured.

Governance Controls

Rate limiting, opt-out mechanisms, kill switches, and campaign frequency controls ensure responsible operation at all times.

Frameworks

Security Framework Alignment

SecureAware is designed to support organizations in meeting requirements across industry-recognized security frameworks.

CIS Controls

v8

Supports Control 14 (Security Awareness and Skills Training) by providing measurable phishing simulation campaigns and human risk scoring.

NIST Cybersecurity Framework

CSF 2.0

Aligns with the Protect function (PR.AT - Awareness and Training) through regular security awareness testing and risk measurement.

ISO 27001 / 27002

2022

Supports Annex A controls for information security awareness, education, and training (A.6.3) with documented evidence and metrics.

NIST SP 800-53

Rev. 5

Addresses AT-2 (Literacy Training and Awareness) and AT-3 (Role-Based Training) through targeted, role-stratified phishing simulations.

Important Disclaimer

This document is provided for informational purposes only and does not constitute legal advice. Group 4 Networks and SecureAware make reasonable efforts to align our platform and operations with applicable Canadian regulations including CASL, CRTC telecom regulations, and PIPEDA. However, client organizations retain full responsibility for ensuring their use of SecureAware complies with all applicable laws, including obtaining appropriate employee consent, maintaining required documentation, and adhering to their own regulatory obligations. Telecommunications compliance (including STIR/SHAKEN) is managed by our infrastructure provider (Twilio) as a licensed telecom service provider. We recommend consulting with qualified Canadian legal counsel specializing in CASL, privacy, and telecom law before launching phishing simulation programs. Regulatory requirements may change; this document reflects our understanding as of the date indicated above.

Questions About Our Compliance Framework?

Group 4 Networks is committed to operating SecureAware in full alignment with Canadian regulatory requirements. Contact our team to discuss compliance, request documentation, or schedule a regulatory review session.

compliance@g4ns.comg4ns.com