Read once, reference often. Built for the controller, the auditor, and the compliance reviewer who need the answer in writing.
1. Nature of the service.
PolicyFX is software. It is not a bank, broker, dealer, money services business, or registered investment adviser. It does not execute foreign exchange transactions, hold client funds, or earn FX spread.
2. Indicative rates.
Rates shown in CoverageDesk, the dashboard, and reports are indicative only, drawn from public reference data including Bank of Canada series and third-party market feeds.
They are not executable, may be delayed, and are not evidence of the rate available to you at any moment. Your bank quotes the executable rate at the moment of trade.
3. Policy recommendation logic.
Default coverage ratios and maturity buckets are aligned to Association for Financial Professionals treasury practice, adapted for Canadian SMB use.
Defaults are a starting point. The written policy your team enters is the source of truth for every coverage flag and report.
4. Materiality threshold.
Recommendations and reports suppress activity below the CAD materiality threshold you set. Below-threshold exposures stay visible in the ledger but do not raise coverage flags.
5. Audit trail.
Every coverage flag traces to three things: a ledger entry, a forward-contract entry, and a written policy clause. Audit history exports to CSV and PDF.
6. Sub-processors.
Current list:
- Supabase Inc. (database and authentication, region ca-central-1)
- Stripe Payments Canada Ltd. (subscription billing)
- Resend Inc. (transactional email)
- Vercel Inc. (application hosting, ca-central-1)
- Google LLC (PolicyFX business email and documents through Google Workspace; DNS through Porkbun)
7. Data residency.
Operational tenant data is hosted in Canada, ca-central-1, Montreal. Limited operational metadata, including authentication tokens, billing identifiers, and transactional email content, is handled by sub-processors that may operate in the United States.
See the Privacy policy and "PIPEDA and data residency."
8. Security practices.
TLS 1.2 or higher in transit. AES-256 at rest. Row-level security at the database layer. Input validated at every boundary. Audit logging on all administrative actions.
9. Limitations.
PolicyFX does not support non-deliverable forwards, exotic options, or cryptocurrency pairs.
Phase 1 covers the five G10 deliverable pairs used by Canadian importers and exporters: USD/CAD, EUR/CAD, GBP/CAD, EUR/USD, GBP/USD.
10. Changes to this library.
Versioned and dated. Prior versions kept on request.
For any disclosure not covered here, write to info@policyfx.ca.