Canero

Security Architecture

Enterprise-grade security

From encryption and access control to audit logging and compliance, Canero is built for organizations with demanding security requirements.

Security capabilities

Core security properties across infrastructure, access control, and data protection.

Encryption
  • AES-256 at rest for all data
  • TLS 1.3 in transit for all connections
  • Encryption keys managed via cloud KMS
  • No unencrypted storage of sensitive data
Access Control
  • Role-based access controls
  • Least-privilege principle throughout
  • Separate access levels for different functions
  • No standing access to customer data by Canero staff
Audit Logging
  • Append-only audit trail for all administrative events
  • Every support access session logged
  • Immutable audit records
  • Exportable for compliance review
Infrastructure
  • Hosted on enterprise-grade cloud infrastructure
  • Isolated deployment per tenant
  • Automated security patching
  • Regular vulnerability scanning

Authentication & authorization

Flexible authentication options designed for enterprise security requirements.

Available

Email & Password

Standard authenticated login with secure password hashing and session management.

Planned

SSO / SAML

Enterprise SSO integration for organizations using identity providers like Okta or Azure AD.

Available

Role-Based Access

Configurable roles for admins, reviewers, and leaders - each with appropriate data access.

Trust & security posture

Canero's security capabilities and compliance roadmap.

Available

Encryption at Rest

Available

Encryption in Transit

Available

Audit Logging

Available

Role-Based Access Controls

Available

DPA

Data Processing Agreement available for enterprise customers.

On Request

Security Questionnaire

Available upon request.

Planned

SOC 2 Type II

Planned

SSO/SAML

Security questions?

We're happy to complete security questionnaires, arrange security reviews, or discuss specific requirements with your team.