FAQ
Frequently asked questions
Direct answers to the questions prospective clients ask us most — about what NorthSight Technologies does, how engagements run, compliance, and how to start.
About the firm
What does NorthSight Technologies do?
We're a senior AI engineering firm in Ontario, Canada. We build dependable LLM systems
(RAG, agentic
pipelines), AI workflow automation, and the
software around them for government and enterprise — under Canadian data residency and
Protected-B / AODA standards. We also perform
AI & software system audits. Every engagement begins
with a free introductory call.
Where are you located, and where do you work?
Based in Ontario, Canada; we work with clients across Canada and the US in North
American time zones. Through our allied practice SmartOps
in the UAE, we also cover Gulf/MENA hours — one firm, two offices.
Who will actually work on my project?
The co-founders: Kamran Khalil (Technical Architect, 15+ years) and
Muhammad Irfan (Applied AI / LLM Engineer, 13+ years). Principal-led delivery — no rotating
account managers, no offshore hand-offs. See About.
What makes NorthSight different from other AI consultancies?
Reliability as the product: every system ships with an evaluation harness so
quality is a measured number, not a vibe. Government-grade compliance (Protected-B, Canadian data
residency, AODA), senior principal-led delivery, and measured ~90% successful-run rates on
production LLM pipelines.
What industries do you work with?
Government and public sector, enterprises, and regulated industries. Our
principals' backgrounds span government-grade delivery in Canada, regulated healthcare
(HIPAA / ISO 27001 / ADHICS) in the UAE, and consumer software at scale (9M+ app downloads,
a Macworld "Best of Show").
Custom software & platforms
Do you build custom software beyond AI?
Yes — AI is one of our services, not the whole firm. We design and build custom web
and mobile applications, customer and staff portals, dashboards, CRMs and line-of-business systems,
with the same senior, principal-led engineering whether or not there's an LLM inside. Our team has
shipped consumer apps to millions and government-grade platforms.
Can you build regulated systems like healthcare portals?
Yes — patient and provider portals, booking and records interfaces, and other health
systems, built to the privacy and accessibility standards they require (PHIPA in Ontario,
HIPAA cross-border, AODA / WCAG). Our team led engineering in regulated healthcare
(HIPAA / ISO 27001 / ADHICS) before founding the firm.
Do you build back-office systems — invoicing, billing, HR?
Yes. Invoicing and billing apps, HR and onboarding systems, internal tools and admin
dashboards — and we integrate them with the systems you already run (CRM, ERP, payment, identity),
so data flows instead of being re-keyed.
Compliance & security
Can you meet Canadian data residency and Protected-B requirements?
Yes. We deliver under Canadian data residency and Protected-B handling standards,
with AODA-compliant (WCAG 2.0 AA) interfaces, and design LLM architectures so sensitive data stays
inside approved Canadian infrastructure — including self-hosted models where required. Details:
AI for government in Canada.
Can LLM systems really avoid sending data outside Canada?
Yes — via Canadian-region cloud AI services with private endpoints, or self-hosted
open-weight models on infrastructure you control. It must be designed in from the start; we treat
residency as an architecture decision, not a checkbox.
Do you sign NDAs and work under our security review?
Yes. NDAs are routine, and we're accustomed to procurement and security-review
processes in both government and enterprise settings.
Which compliance frameworks do you build to?
Canadian public sector: Protected-B handling and data residency. Privacy:
PIPEDA (federal), PHIPA (Ontario health information) and Quebec's Law 25.
Accessibility: AODA / WCAG 2.0 AA. Security assurance: SOC 2 and ISO 27001.
Health data across borders: HIPAA (US) and ADHICS (UAE) through our SmartOps practice.
We also align AI governance to the emerging ISO/IEC 42001 standard. Not every project needs
every framework — we scope the applicable set to your data and obligations. More on the
government AI page.
Engagements & pricing
How does an engagement start?
With a free 20-minute call: we discuss the failure or process costing you most.
From there we scope the engagement — audit, build, or fix — with measurable success criteria
defined up front. Email hello@northsight.ca.
How do you price your work?
Engagements are scoped and quoted based on size and access requirements. The first
20-minute call is free; audits and builds are quoted after it. Email
hello@northsight.ca for a scoped proposal.
Can you fix an existing AI system rather than rebuild it?
Usually, yes. We audit first, trace real failures to root cause, and retrofit the
reliability layer — structured outputs, validation gates, evals — onto what you have. Rebuilds are
recommended only when the audit shows the architecture can't get there.
Do you build the software around the AI too?
Yes — full-stack product build is a core service: native and cross-platform apps,
web platforms, dashboards and system integrations (Python, APIs, AWS/Azure). We ship the whole
solution, not just the prompt.
How do I contact NorthSight?
Email hello@northsight.ca, call or
WhatsApp +1 (647) 914-4834, or book a call from the homepage. For UAE/MENA
engagements: smartops.ae.