Authentication
The API implements bcrypt password hashing, signed access and refresh tokens, and request rate limiting.
Current stage
CanvasClaude has application-level security controls in code. Formal certification, independent audit, and deployment-specific assurances remain future work and are not presented as completed.
Implemented in the product
The API implements bcrypt password hashing, signed access and refresh tokens, and request rate limiting.
Core models carry tenant identifiers and service tests exercise tenant-scoped access. This is an implemented control, not a certification.
Automated tests, linting, type checks, dependency review, and secret scanning support the development workflow.
What we do not claim
Before broader deployment
Share the use case, data sensitivity, and deployment needs before starting a pilot.
Contact CanvasClaude