Pre-orderShipping Late Summer 2026Pre-order →
EN | FR
Proudly Canadian

Your Cart

Security

How we protect data

Defence-in-depth across encryption, identity, infrastructure, and recovery, built on a SOC-attested cloud provider in Canada.

Encryption

Strong encryption everywhere; in transit, at rest, and across every tier of the platform.

  • In transit TLS 1.2+ on every network connection: HTTPS for the dashboard and API, MQTT-TLS for device telemetry, TLS for VPN. Minimum 256-bit encryption.
  • At rest, databases AES-256 encryption on the production database cluster, including all replicas, automated backups, and snapshot stores.
  • At rest, object storage AES-256 encryption on every storage bucket holding firmware, telemetry archives, or attachments.
  • Connection pooling The connection-pool layer enforces TLS; no plaintext database connections from any compute layer.
  • Approved algorithms Industry-standard, current cryptography only. Legacy primitives (MD5, SHA-1 for signing, DES, RC4) are explicitly prohibited in policy and absent from the codebase.

Identity & access

Role-based access following least privilege, with NIST-aligned credentials and TOTP MFA available for every user.

  • Authentication Customer accounts authenticate through a managed identity provider using a zero-knowledge password protocol so credentials never leave the client. Refresh tokens are rotated; access tokens expire within an hour.
  • MFA Time-based one-time password (TOTP) MFA is available on every account through any standards-compliant authenticator app. Required for production and admin access.
  • Password standards Aligned with NIST SP 800-63B: 12-character minimum, no mandatory periodic rotation, breach-list checks at creation, throttling on repeated failures.
  • RBAC Four account roles (owner, admin, operator, viewer) plus capability-based scoping for client dashboards. Permissions are evaluated on every API call.
  • Multi-tenant isolation Every query is filtered by the authenticated customer ID at the application layer. Client dashboards are further restricted to a device whitelist.
  • Quarterly access reviews Access lists are reviewed every quarter; access not required for business purposes is revoked. Role changes and terminations trigger access removal within 24 hours.

Infrastructure

Hardened cloud environment in Canada, locked down at the network, identity, and edge layers.

  • Network All workloads run inside a dedicated VPC with private subnets for the data layer. Only NAT and load balancers are reachable from the public internet.
  • Network segmentation Least-privilege ingress rules at every layer. The database is reachable only from authorized internal services; never from the public internet.
  • Edge & rate limits Automatic DDoS protection at the cloud-provider edge. Application-layer rate limiting enforces per-customer quotas on every API call. Managed web-application firewall rules cover common OWASP vulnerabilities, SQL-injection patterns, and known-bad IP reputation.
  • IAM Every workload runs under a least-privilege role. No long-lived credentials are stored in the codebase.
  • Secrets management Database credentials, payment-processor API keys, and JWT signing material live in a managed secrets vault; never in source code or environment files committed to Git.
  • Patch cadence Critical vulnerabilities patched within 7 days, medium within 30, low within 90. Every container image is scanned for known vulnerabilities at build time.
  • Region lock An organization-level policy prevents any infrastructure from being created outside Canadian regions.

Resilience & recovery

Multi-AZ database, point-in-time recovery, and 12-month monthly snapshots; all encrypted, all in Canada.

  • Multi-AZ database The production database is deployed across two Canadian availability zones with synchronous replication. Failover is automatic on AZ outage.
  • Point-in-time recovery Continuous transaction-log backup gives a 30-day point-in-time recovery window; restore the database to any second within the last 30 days.
  • Long-term snapshots A managed backup vault stores monthly snapshots for 12 months, encrypted with a dedicated key that rotates annually.
  • Recovery objectives Recovery point objective (RPO) of 24 hours for critical systems. Restore procedures are tested quarterly and documented.
  • Deletion protection Production database has deletion protection enabled. A final snapshot is taken on any decommission.

Have a security questionnaire?

We're happy to walk enterprise prospects through our controls, share a security overview, or complete a vendor assessment.

Canaro has not yet publicly launched. This Trust Centre reflects our current, reasonable expectations for the platform based on ongoing development and our policies, and its contents are subject to change without notice prior to public release.

Contact Us