Pre-orderShipping Late Summer 2026Pre-order →
EN | FR
Proudly Canadian

Your Cart

Operations

Operational security

The operational practices that keep the platform safe day-to-day, from the people we hire to the way we ship code.

Personnel security

Vetted, trained team members with access provisioned by role and revoked on day one of departure.

  • Background checks Identity verification and criminal record checks (where lawful) before access to customer data, production systems, or admin interfaces is granted.
  • Onboarding training Mandatory security awareness training within 30 days of start, covering acceptable use, phishing, password hygiene, data handling, incident reporting, physical security, and privacy obligations.
  • Annual refresher All employees and contractors complete annual refresher training. Completion is tracked in personnel records.
  • Onboarding access Access is provisioned strictly by role and approved by the user's manager.
  • Offboarding All system access is revoked within 24 hours of termination or contract expiration. Equipment is returned within 5 business days.

24/7/365 monitoring

Continuous logging, alerting, and a dedicated security event log for all auth-related activity.

  • Application logs Structured logs from every service are centralized with at least 30-day retention; security-relevant events retained for 12 months.
  • Security events log Dedicated table records auth successes and failures, permission denials, API-key usage, and rate-limit hits, including source IP, user agent, request path, and timestamp.
  • Admin audit log Every administrative impersonation and admin mutation is recorded with actor identity, action, and target.
  • Rate-limit telemetry Per-customer rate-limit hits are recorded in the security event log and surfaced via response headers so client apps can throttle gracefully.
  • Automated alerts Real-time alerts on database health, application error rates, integration failures, and unusual cost signals; escalated to on-call.
  • Log integrity Logs live in a separate, append-only repository with restricted access. Tampering is prevented through write-only IAM scoping.

Incident response

Documented playbooks, severity-driven response, and a 72-hour customer-notification SLA.

  • Severity classification Critical: active breach, data exfiltration, ransomware. High: attempted breach, exploited vulnerability. Medium: suspicious activity, policy violation. Low: minor anomalies.
  • Response phases Detection → Containment (short and long-term) → Eradication → Recovery → Post-incident review.
  • Playbooks Pre-defined response procedures for unauthorized access, ransomware, denial-of-service, phishing, and suspicious-activity alerts.
  • Customer notification Affected customers are notified within 72 hours of confirmed impact (or sooner where contractually required), with the nature of the incident, data affected, actions taken, and recommended customer actions.
  • Post-mortem A blameless post-mortem is completed within 5 business days of incident closure. Lessons learned feed back into policies and procedures.

Change management & SDLC

Every production change goes through review, automated testing, staging, and a documented rollback path.

  • Version control All source code in Git with tagged release versions. No untagged or undocumented deployments to production.
  • Code review Peer review on every change; reviewing for correctness, security, and adherence to coding standards.
  • Automated testing Hundreds of unit and integration tests run on every push; failure blocks the build before any image is published.
  • Static analysis Dependency vulnerability scanning and static analysis run continuously. Every container image is scanned at build time.
  • Release flow development → review → tests (unit + integration) → staging → production. Emergency changes are documented within 48 hours.
  • Rollback Every release has a documented rollback procedure. Critical defects trigger immediate rollback to the previous task definition revision.

Have a security questionnaire?

We're happy to walk enterprise prospects through our controls, share a security overview, or complete a vendor assessment.

Canaro has not yet publicly launched. This Trust Centre reflects our current, reasonable expectations for the platform based on ongoing development and our policies, and its contents are subject to change without notice prior to public release.

Contact Us