Security, privacy, and compliance.
Canaro is built by Toccata Inc. in Saskatoon and runs entirely on Canadian infrastructure. This page documents our security controls, compliance posture, and supporting documentation, and is updated as they change.
- Where does customer data live?
- All customer data is stored and processed in Canada. An organization-level policy prevents infrastructure from being created outside Canadian regions.
- Is it encrypted?
- Data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit, including device telemetry over MQTT-TLS. Deprecated cryptographic algorithms are prohibited by policy.
- Are you SOC 2 certified?
- Our cloud provider maintains SOC 1, SOC 2, and SOC 3 attestations, available under NDA. Canaro operates SOC 2-aligned controls at the application layer; a formal Type II audit is planned.
- What happens if you lose a database?
- The production database runs across two availability zones with automatic failover. Point-in-time recovery covers the last 30 days, monthly snapshots are retained for 12 months, and restore procedures are tested quarterly.
- Who else touches our data?
- Canaro uses two subprocessors: Amazon Web Services and Stripe. The full list and our vetting process are published on the Subprocessors page. Customer data is never sold.
- What if something goes wrong?
- Systems are monitored continuously. Affected customers are notified within 72 hours of confirmed impact, and each incident receives a documented post-incident review within 5 business days.
Built in Canada. Hosted in Canada.
Every byte (accounts, telemetry, billing, backups) is stored in Canada. An organization-level policy prevents any infrastructure from being created outside Canadian regions; the restriction is enforced at the infrastructure layer.
Canadian regions only
Compute, storage, database, and IoT resources locked to Canadian regions.
Domestic backups
Encrypted snapshots stay inside Canadian zones; no cross-border replication.
No exports without consent
Sensor and account data never leave the platform unless you export them.
Trust Centre sections
Each section is updated as controls change.
Encryption, access, recovery
TLS on every connection, RBAC with quarterly access reviews, multi-AZ failover. The technical controls in detail.
Certification & factory testing
FCC, ISED, UL/CSA where required. Every unit is tested end-of-line in Saskatoon before it ships.
People, monitoring, incidents
Background checks, 24/7 alerting, documented playbooks, and a 72-hour customer-notification commitment.
PIPEDA, SOC 2 posture, policy
PIPEDA alignment, SOC 2 posture, and policy governance, including current certification status.
Residency, retention, your rights
What we keep, for how long, and how to get it back or have it deleted.
Subprocessor list
AWS and Stripe: what each does, where they run, and how they're vetted.
Reporting a vulnerability
Coordinated disclosure with a safe-harbour clause. Two-business-day acknowledgement.
Documents
Documentation for vendor reviews and security assessments. If you need something that isn't listed, email security@canaro.ca.
Privacy policy
How we collect, use, and protect personal data.
Read policyInformation Security Policy Library
Twenty-one written policies covering security, HR, data, access, cryptography, SDLC, and incident response. Available under NDA.
Request the libraryCloud-provider attestation reports
SOC 1 / SOC 2 / SOC 3 reports for our underlying cloud infrastructure, available under standard NDA.
Request reportsSystem status
Real-time operational status of every Canaro service.
View status pageVendor security questionnaire
Send us your questionnaire and we'll complete it within five business days.
Email securityVulnerability disclosure
Coordinated disclosure of security issues, safe-harbour clause and SLAs.
Disclosure processHave a security questionnaire?
We're happy to walk enterprise prospects through our controls, share a security overview, or complete a vendor assessment.
Canaro has not yet publicly launched. This Trust Centre reflects our current, reasonable expectations for the platform based on ongoing development and our policies, and its contents are subject to change without notice prior to public release.