Pre-orderShipping Late Summer 2026Pre-order →
EN | FR
Proudly Canadian

Your Cart

Compliance

Compliance posture

Canaro's policies are aligned with privacy and security frameworks relevant to Canadian and international customers.

PIPEDA

Canada's federal privacy law for the private sector; the baseline for how Canaro handles personal information.

  • Accountability Toccata Inc. is the privacy controller for Canaro customer data and accountable for compliance with PIPEDA's ten fair information principles.
  • Consent Personal information is collected, used, and disclosed only with the knowledge and consent of the individual, except where the law permits otherwise.
  • Limiting collection & use We collect only the personal information required to deliver the service and use it only for the purposes for which it was collected.
  • Access & correction Customers may request access to and correction of their personal information by emailing privacy@canaro.ca.

SOC-2 compliant infrastructure

Canaro runs on a SOC-attested cloud provider in Canada that maintains SOC 1, SOC 2, and SOC 3 reports.

  • Cloud-provider attestations All compute, storage, networking, and database services used by Canaro are part of our cloud provider's SOC 1/2/3 attestation scope. Reports are available under standard NDA.
  • Inheritable controls Physical security, environmental controls, and infrastructure availability are inherited from the cloud provider's attested controls.
  • Application-layer controls Canaro implements its own SOC 2-aligned controls on top of the cloud provider: encryption, access management, change management, monitoring, and incident response.
  • Roadmap Canaro is operating to SOC 2-aligned controls today; a formal Type II attestation will follow as the platform reaches the appropriate operational maturity.

GDPR-compatible posture

Designed to support the rights of EU/UK data subjects where Canaro is engaged across borders.

  • Data subject rights Right of access, rectification, erasure, restriction of processing, and data portability are supported on request.
  • Lawful basis Processing is performed under contract (service delivery), legitimate interest (operational telemetry), or consent (marketing communications).
  • Cross-border transfers Canaro stores all customer data in Canada. Where engagement requires a transfer, standard contractual clauses are used.
  • Data Processing Addendum A DPA is available on request for customers operating in the EU or UK.

Policy governance

Canaro maintains a written Information Security Policy Library reviewed and updated at least annually.

  • Policy library Twenty-one written policies covering security, HR, data handling, access control, credential management, cryptography, key management, secure SDLC, change management, patch management, incident response, backup and recovery, and supplier management.
  • Annual review Each policy is reviewed at least annually by the policy owner; reviews are recorded in the document history.
  • Trigger reviews Out-of-cycle reviews are triggered by significant security events, material changes in business operations, or new regulatory obligations.
  • Document availability The full policy library is available to enterprise prospects and customers under NDA; email security@canaro.ca to request a copy.

Have a security questionnaire?

We're happy to walk enterprise prospects through our controls, share a security overview, or complete a vendor assessment.

Canaro has not yet publicly launched. This Trust Centre reflects our current, reasonable expectations for the platform based on ongoing development and our policies, and its contents are subject to change without notice prior to public release.

Contact Us