Trust Center

How we keep your data safe, what we can attest to today, and how to request the documents your security team needs.

Last updated: May 13, 2026

Security posture

These are the controls in place on the platform today. Each links to the underlying documentation.

Encryption at rest

ZFS native encryption (AES-256-GCM) on every host pool. All desktop disks, snapshots, and shared-drive contents inherit it.

Per-host keys, offsite-backed-up, rotatable via zfs change-key.

Encryption in transit

TLS terminated by Caddy with Let's Encrypt certificates for every regional endpoint. Streaming uses wss://.

Inter-server management traffic runs over a WireGuard mesh (ChaCha20-Poly1305).

Tenant isolation

One Incus project + one OVN logical network per organization. Network ACLs default-deny cross-tenant traffic.

Per-org shared drives use isolated S3 credentials with bucket-scoped policies.

Authentication

JWT auth, two-step login, TOTP-based 2FA with recovery codes. Enterprise SSO via SAML 2.0 / OIDC plus SCIM 2.0 provisioning.

Rate limiting: 10/min per IP and 5/min per email on login.

Audit logging

30+ event types covering authentication, desktop lifecycle, VPN, storage, SSO, and admin actions. Tenant-scoped for org admins.

Webhook delivery (HMAC-SHA256 signed) for SIEM forwarding.

Session recording

Optional, Enterprise-only. Recordings are stored on the encrypted ZFS pool and access-gated by signed URLs.

Disabled by default. Enabling is org-admin-controlled and audit-logged.

Vulnerability disclosure

Coordinated disclosure: 5-business-day acknowledgement, 10-day triage with CVSS 3.1, 90-day default disclosure window.

Safe harbor for good-faith research against your own org.

Incident response

Tiered SLAs from Critical (1-hour first response, 4-hour customer notice) through Low. GDPR Article 33 72-hour notification target.

Notification reaches the org's primary administrator first.

For the long form, see our Security documentation, Encryption at Rest, and Privacy Policy.

Compliance roadmap

We publish our standing honestly. Anything not marked Live we have not yet earned. Please do not treat it as such.

FrameworkStatusNotes
GDPR (DPA)LiveData Processing Addendum available on request. Standard Contractual Clauses included.
CAIQ (CSA self-assessment)In progressv4 questionnaire in preparation. Available to customers under NDA when complete.
SIG LiteIn progressShared Assessments SIG Lite response in preparation.
HIPAA-ready + BAAPlannedTechnical controls (encryption, access, audit) are in place. BAA execution and HIPAA operational policies are scheduled. Not yet eligible for PHI workloads; contact us before signing.
SOC 2 Type IPlannedTargeted within the next 12 months. Trust Services Criteria scope: Security, Availability, Confidentiality.
SOC 2 Type IIPlannedFollows Type I after a 6-12 month observation window.
ISO 27001PlannedAligned to ISO 27001 control families through our SOC 2 work. Formal certification not yet scheduled.
PCI-DSSNot pursuedWe do not store cardholder data. Payments are handled by Stripe (PCI-DSS Level 1).
FedRAMPNot pursuedNot on the near-term roadmap. Reach out if you have a federal use case so we can plan around it.

Documents and questionnaires

The artifacts below are available to customers and prospects. Anything not yet published can be requested directly.

Data Processing Addendum (DPA)

GDPR-compliant DPA with Standard Contractual Clauses. Available for execution.

Request
Subprocessor list

Current third-party processors and their roles. Always published in our Privacy Policy.

View
CSA CAIQ v4

Cloud Security Alliance self-assessment. Shared under NDA once complete.

Request
Shared Assessments SIG Lite

Standardized vendor security questionnaire. Shared under NDA once complete.

Request
Custom questionnaires

Most enterprise security questionnaires can be answered from our CAIQ / SIG responses. For anything outside that scope, write to us.

Request

Data residency

Desktops and their associated shared-drive contents stay in the region you select when provisioning. Account metadata (organization records, user profiles, billing artifacts) is processed in the United States. Cross-region replication of shared drives is opt-in per share.

Reporting and contact

Security issue

Report a vulnerability or suspected security incident.

security@canvex.io
Legal / privacy / DPA

Privacy requests, DPA execution, GDPR/CCPA inquiries.

legal@canvex.io
Abuse

Report content or activity that violates our Acceptable Use Policy.

abuse@canvex.io
DMCA / copyright

Submit a DMCA notice to our designated agent.

dmca@canvex.io

For broader policy detail, see our Terms of Service, Privacy Policy, and Acceptable Use Policy.