HarbourScan

Map your organization's sovereignty exposure

Enter your SaaS tools. See which fall under foreign jurisdiction, CLOUD Act exposure, and compliance gaps. Free. 2 minutes. No account required.

Check Your Stack →

Free · Browser-based · No signup required

Example scan output
3
CLOUD Act
1
Review
1
Canadian
Slack
US · CLOUD Act
Salesforce
US · CLOUD Act
Microsoft 365
US · CA res. available
Notion
US · CLOUD Act
Clio
Canadian
3 tools require TIAs · 0 documented

Built on the 715-tool Canadian Technology Sovereignty Index

When a regulator, procurement officer, or partner asks “which of your SaaS vendors are subject to foreign jurisdiction?” — most organizations cannot answer. HarbourScan produces that answer in minutes.

How it works

Four steps — from free self-assessment to ongoing compliance intelligence.

01
Free scan
Map your stack in your browser. Select your tools, see your jurisdictional exposure map. Free, private, nothing stored.
02
Snapshot
Need a formal answer? The Sovereignty Snapshot delivers a professional assessment with Sovereignty Scores and an executive summary. From $350.
03
Documentation
Need to prove compliance? Full documentation package with TIA guidance, remediation roadmap, and board-ready deliverables. From $2,000.
04
Monitoring
Need to stay compliant? Continuous vendor ownership monitoring, regulatory tracking, and quarterly sovereignty status reports. From $200/mo.
Why Upper Harbour
715-tool database
Every assessment draws on the Canadian Technology Sovereignty Index — the most comprehensive jurisdictional dataset for Canadian technology. We don't start from scratch. We start from verified corporate registry data.
Canadian-specific
Built for Law 25, PIPEDA, and Canadian procurement requirements. Not a US GRC platform repurposed for the Canadian market. The analysis accounts for the CLOUD Act, provincial variations, and the regulatory landscape that actually governs your data.
Independent
No vendor affiliations. No paid placements. No commercial relationships with the SaaS tools we assess. Our analysis is independent because our business model doesn't depend on the vendors we're evaluating.
HarbourScan in action
Mikayla Stewart

We were quoted $20,000+ from a privacy consultant. The sovereignty audit gave us everything — the jurisdictional map, the TIAs, the full compliance record — for a fraction of the cost.

Mikayla Stewart, Co-Founder · Athena Collective
11 tools · 9 TIAs · 0 replaced Read case study →
Choose your level

Every engagement starts with a free scan. From there, choose the documentation your organization needs.

Free
HarbourScan

“I need to see what we’re exposed to.” — Enter your tools and see your jurisdictional exposure instantly. The initial scan runs entirely in your browser.

What you get
  • Jurisdictional exposure breakdown by risk level
  • CLOUD Act exposure count
  • Tool-by-tool risk classification
  • Applicable regulatory framework for your province
  • Total compliance gap count and severity
  • TIA requirement count (Quebec organizations)
What you'll know
  • How exposed your stack is — and how urgently it needs attention
  • Which tools are under foreign jurisdiction
  • Whether your province’s regulations require immediate action
  • The scale of the documentation gap you’re facing
From $350
Sovereignty Snapshot
A documented answer you can send when it matters.

“Someone asked and I need an answer.” — A professional sovereignty assessment you can produce when a regulator, partner, or procurement officer asks about your cross-border data exposure. Delivered in 5 business days.

Deliverables
  • Full jurisdictional exposure map
  • CLOUD Act risk classification per tool
  • Sovereignty Score for each assessed tool
  • Gap identification with severity ratings
  • Executive summary PDF
When you need this
  • A board member or partner asks about your data sovereignty posture
  • You’re responding to an RFP with sovereignty requirements
  • You need a defensible answer faster than a full compliance engagement
  • You want to scope the problem before committing to full documentation
Purchase Snapshot — $350 → PDF report · Delivered in 5 business days · No call required
From $2,000
Compliance Documentation
A full record you can stand behind legally.

“We need to prove compliance.” — The structured compliance record for regulators, auditors, and procurement evaluators. Board-ready deliverables that demonstrate defensible process. Delivered in 10–15 business days.

Deliverables
  • Everything in the Sovereignty Snapshot
  • Transfer Impact Assessment guidance per tool
  • Register of Processing Activities
  • Prioritized remediation roadmap
  • Regulatory framework mapping (province-specific)
  • Board-ready compliance document
When you need this
  • Law 25 requires written TIAs — not just awareness
  • Procurement officers ask for compliance documentation
  • You’re preparing for audit or regulatory review
  • Penalties reach $25M or 4% of worldwide turnover
Book a Scoping Call → We’ll scope based on your scan results
From $200/mo
Sovereignty Monitoring
Keeps your documentation from quietly going stale.

“We need to stay compliant as things change.” — Without monitoring, your compliance documentation can become inaccurate the moment a vendor is acquired or shifts hosting. Monitoring keeps your record current so a point-in-time assessment doesn’t quietly become a liability.

What’s included
  • Continuous vendor ownership monitoring
  • Infrastructure change alerts
  • Regulatory development tracking
  • Sovereignty Score updates
  • Quarterly compliance status report
  • New tool assessment as your stack evolves
Why ongoing matters
  • Canadian SaaS companies are acquired regularly — shifting jurisdiction for every client
  • Vendors launch (and retire) Canadian data centre regions
  • The CPPA will change federal requirements when enacted
  • A point-in-time audit goes stale within months
Discuss Monitoring → Usually added after a Snapshot or Documentation engagement

Map your stack. Understand your sovereignty exposure.

Most organizations complete the scan in under 10 minutes. No account required. Choose the level of documentation you need after you see your results.

Want to discuss your situation first? Book a scoping call · View pricing

1
Profile
2
Stack
3
Results
Step 1 of 3

Tell us about your organization

Most organizations start here when a regulator, partner, or procurement review asks how their SaaS vendors handle data. The initial scan runs entirely in your browser.

Step 2 of 3

Select your tools

Search for the SaaS tools your organization uses. We'll map each one to its parent jurisdiction. Add as many as apply.

0
Selected
0
Exposed
0
Review
0
Non-Exposed
0
Canadian
Your Results

Sovereignty exposure map

Based on the 0 tools you selected, here's your organization's jurisdictional exposure.

Your Stack — Jurisdictional Exposure

Most organizations discover at least one foreign-controlled SaaS tool processing personal data without documented safeguards. If your organization were asked to produce a defensible processing inventory today — could you?

Get your results by email

We'll send a summary of your scan — jurisdiction breakdown, CLOUD Act exposure, and compliance gaps — within one business day.

No spam. Just your scan results and a note from the founder.

Full report ready
Get your Sovereignty Snapshot

Your scan results are ready to be documented.

The Sovereignty Snapshot turns these results into a PDF you can hand to your board, attach to a procurement response, or produce when a client, partner, or regulator asks how you manage cross-border data exposure.

Covers every tool in your stack — parent jurisdiction, CLOUD Act status, risk classification, compliance gaps, and remediation priorities.

$350
One-time · PDF report · Delivered in 5 business days
How organizations use the Snapshot
→ Attach to vendor risk assessments
→ Include in Law 25 / PIPEDA compliance documentation
→ Provide during procurement or security reviews
→ Answer board or executive questions about SaaS jurisdiction risk
Buy Snapshot →
PDF report · Delivered in 5 business days · No call required