Pre-orderShipping Late Summer 2026Pre-order →
EN | FR
Proudly Canadian

Your Cart

Vulnerability Disclosure

Vulnerability disclosure

We welcome coordinated disclosure of security issues. Email us with details; we'll acknowledge promptly, work with you on a fix, and credit your finding if you'd like.

Email security@canaro.ca

How disclosure works

  • Email us Send vulnerability details, reproduction steps, and impact assessment to security@canaro.ca.
  • Acknowledgement We acknowledge receipt within two business days.
  • Triage & remediation Our security team triages the issue, validates impact, and works on a fix. Critical issues are addressed within 7 days; medium within 30; low within 90.
  • Coordinated disclosure We aim to publish a fix before any public disclosure. We'll keep you informed of the timeline and credit you in our advisory if you wish.

What's in scope

Anything reachable on a canaro.ca / cabinpulse.com domain, the public API at api.canaro.ca, the firmware running on Canaro hubs, and the dashboard at app.canaro.ca.

Out of scope
  • Denial-of-service attacks against production
  • Spam or social-engineering attacks against employees
  • Issues requiring physical access to a customer's hub or property
  • Vulnerabilities in third-party services we don't control

Safe harbour

We won't pursue legal action against researchers acting in good faith. Good faith means: you avoid privacy violations, data destruction, or service disruption; you only interact with accounts you own or have explicit permission to test; and you give us a reasonable window to fix issues before public disclosure.

Have a security questionnaire?

We're happy to walk enterprise prospects through our controls, share a security overview, or complete a vendor assessment.

Canaro has not yet publicly launched. This Trust Centre reflects our current, reasonable expectations for the platform based on ongoing development and our policies, and its contents are subject to change without notice prior to public release.

Contact Us