Jmoor sits across privacy, payments, anti-money-laundering, and statutory payroll and tax. We meet those obligations by design and give you the documentation to meet yours. Here’s our full posture — with honest status on what’s certified and what’s in progress.
Compliance at a glance
PCI-aligned payments, FINTRAC registration, and sanctions screening.
PIPEDA-aligned, with GDPR-style transparency and CCPA/CPRA where applicable.
Approved to file statutory payroll and tax on behalf of employers.
Formal attestation underway; controls documented and monitored today.
Jmoor operates at the intersection of several regulated domains — privacy, payments, anti-money-laundering, and statutory payroll and tax. We build the platform to meet those obligations by design, and we give customers the transparency and documentation they need to meet their own.
Compliance is treated as an ongoing program rather than a one-time checkbox: obligations are mapped to concrete controls in the product, those controls are monitored, and our posture is reviewed as regulations and the platform evolve.
This page describes Jmoor’s compliance program and the frameworks it is designed around. It is informational and not legal advice; your own obligations depend on your jurisdiction, industry, and how you use the platform.
Jmoor’s program is built around the frameworks most relevant to a Canadian-built financial platform serving businesses internationally:
| Framework / registration | Scope | Status |
|---|---|---|
| PIPEDA (Canada) | Personal information protection & breach reporting | Aligned |
| GDPR-style transparency (EU) | Data-subject rights & lawful processing principles | Aligned, where applicable |
| CCPA / CPRA (California) | Consumer privacy rights | Aligned, where applicable |
| PCI DSS | Card acceptance via certified processors (SAQ-A posture) | Aligned; Level 1 in progress |
| SOC 2 Type II | Security, availability & confidentiality controls | In progress |
| CRA Authorized Representative | Filing on behalf of employers with the Canada Revenue Agency | Active |
| FinTRAC registration | Anti-money-laundering / financial-transactions reporting | Registered |
Where a status is “in progress,” Jmoor is designed and operated to the intent of that framework today, and formal certification is being pursued. We publish accurate status rather than certification claims we have not yet earned.
Jmoor’s handling of personal information is designed with reference to Canadian privacy law (PIPEDA), GDPR-style transparency principles, and U.S. expectations such as CCPA/CPRA where applicable.
What that means in practice
Because Jmoor moves money, it operates within payments and anti-money-laundering frameworks and integrates the controls those frameworks expect.
Card data is captured and tokenized by PCI-DSS-certified processors, keeping Jmoor aligned with a PCI DSS SAQ-A posture; raw card numbers are not stored by Jmoor. Payment flows use idempotency and signed, de-duplicated webhooks end to end.
Jmoor is registered with FINTRAC and applies AML-oriented controls including customer identification, monitoring for suspicious activity, and record-keeping appropriate to the services provided.
Jmoor screens against sanctions and watchlist data (using OpenSanctions and comparable sources) to help prevent prohibited transactions and relationships.
Jmoor computes and prepares statutory payroll and tax obligations, and — as a CRA Authorized Representative — is approved to file on behalf of employers with the Canada Revenue Agency.
Coverage
Filings are computed and prepared ready-to-file; where direct government submission requires customer credentials or authorization, those steps are performed with the customer’s consent and are clearly indicated in-product.
Jmoor is built in Canada and primarily hosts customer data in Canadian infrastructure. Where a service depends on a third-party sub-processor operating in another region, that relationship is governed by appropriate contractual and technical safeguards. Customers with specific residency requirements can contact us to discuss their needs.
Jmoor relies on a limited set of vetted sub-processors to deliver the service — principally certified payment processors and rails, infrastructure and email providers. Sub-processors are selected and reviewed for their own security and compliance posture, and are bound by contractual obligations covering confidentiality and data protection.
Payment orchestration spans certified processors including VoPay, Finix, Helcim, Checkout.com, Mollie, Airwallex, Wise, and Lithic. A current sub-processor list is available to customers on request.
Request the sub-processor listJmoor is pursuing SOC 2 Type II attestation of its security, availability, and confidentiality controls, and maintains internal control documentation in the meantime. On request and under appropriate confidentiality terms, we can provide security and compliance documentation to support customer due diligence.
Available to customers on request
For compliance questions, documentation requests, data-subject requests, or due-diligence inquiries, contact our compliance team. We aim to respond promptly and to support your review process.
Contact complianceJmoor Compliance Team