generated: '2026-08-09' method: searched probe: true url: https://trust.canoeintelligence.com/ platform: Vanta public_compliance_page: https://canoeintelligence.com/implementation-data-security/ certifications: - SOC 2 Type II certification_note: Canoe states on its public Data Security & Implementation page that it "undergoes an annual SOC2 type 2 audit". The report itself is behind the Vanta trust-center request flow; no other certification (ISO 27001, PCI DSS, HIPAA, FedRAMP) is named on any anonymously reachable Canoe page. published_controls: - Principle of least privilege with periodic access review - Role-based permissions - HTTPS-only platform access - Multi-factor authentication enforced - Password complexity enforcement - API IP filtering - Identity federation / SSO (SAML 2.0) - User access groups - 30-minute session timeout; session id not in the URL - Encryption in transit (TLS 1.2+) and at rest (AES-256) - Sensitive documents accessible only inside the application, never emailed - Cloud infrastructure vulnerability scanning - Network and web application penetration testing - Cloud security configuration assessment - Audit logging of all data access and extraction events - Data residency controls; on-premise and private-cloud deployment options - No model training on client data without explicit contractual authorisation evidence: - source: https://trust.canoeintelligence.com/ status: 200 kind: trust-center detail: HTML title "Canoe Intelligence Trust Center"; Vanta-hosted SPA (og:image app.vanta.com), content rendered client-side - source: https://canoeintelligence.com/implementation-data-security/ status: 200 kind: compliance-page keywords: - SOC2 type 2 - penetration testing - MFA - least privilege - encryption - source: https://canoeintelligence.com/llms-full.txt status: 200 kind: llms-full detail: '"Key management aligned with SOC 2 Type II requirements"' note: probe-security-programs.py recorded trust=none because the Vanta trust center renders client-side and its served HTML carries no compliance keywords. The trust center is real and was verified by hand; the certification list is limited to what Canoe states on anonymously readable pages.