ClearGlassInc · Canada–U.S. Desk · 8 September 2026
30-Day Canada–U.S. Control Diagnostic
If you cannot replay the decision, you do not control the system. Print this page to PDF.
Week 1 — Boundary inventory
- List systems storing Canadian personal information or U.S. sensitive / government-related data.
- List every AI tool, agent, copilot, and automation that can read those systems.
- List vendors with administrative, support, or model-training access.
- Mark each item: jurisdiction, classification, owner, last review date.
Week 2 — Compulsion and copy risk
- Write the legal basis and foreign-access notice for each outbound transfer.
- Trace copies: logs, tickets, analytics exports, embeddings, eval sets, backups.
- Flag any path where a country-of-concern person could reach bulk U.S. sensitive data.
- Confirm disaster-recovery replicas sit on the same sovereignty map.
Week 3 — Agent and workflow gates
- For each agent: owner, tools, write permissions, human gate, kill switch.
- Disable production-write paths with no owner and no replayable log.
- Add purpose-of-use to the highest-privilege service accounts.
- Treat model copies as classified with the source record.
Week 4 — Executive evidence pack
- Sovereignty map (one page).
- Top ten residual risks ranked by blast radius.
- Agent inventory and dual-jurisdiction notification matrix.
- 90-day hardening sequence, reviewed by legal, security, and operations together.
Four questions for the assessment call
- Where does the data live, including copies?
- Who can compel it, and who can retrieve it without a ticket?
- Which identities — human and machine — may act?
- Can you replay what happened when it matters?
Not legal advice. Not a claim of FedRAMP, CMMC, CPCSC, CCCS, SOC 2, or ITAR authorization. ClearGlass Inc. · Burlington, Ontario.