Current stage

Early-stage product preparing for controlled pilots

CanvasClaude has application-level security controls in code. Formal certification, independent audit, and deployment-specific assurances remain future work and are not presented as completed.

Implemented in the product

Current controls

Authentication

The API implements bcrypt password hashing, signed access and refresh tokens, and request rate limiting.

Tenant-Aware Data Access

Core models carry tenant identifiers and service tests exercise tenant-scoped access. This is an implemented control, not a certification.

Engineering Checks

Automated tests, linting, type checks, dependency review, and secret scanning support the development workflow.

What we do not claim

Transparent boundaries

  • No SOC 2 or ISO 27001 certification is currently claimed.
  • No independent penetration test is currently claimed.
  • No GDPR, CCPA, HIPAA, uptime, backup, or data-residency guarantee is claimed on this page.
  • Deployment-specific controls must be confirmed before production or regulated-data use.

Before broader deployment

Verification roadmap

  1. Document production hosting, backups, retention, and incident response before paid pilots.
  2. Commission independent security testing when pilot scope and data sensitivity require it.
  3. Pursue formal compliance only after customer requirements justify the cost and scope.

Have a security requirement?

Share the use case, data sensitivity, and deployment needs before starting a pilot.

Contact CanvasClaude