Enterprise Security

Your vessel data is
treated like a ship in port — with the highest care

CanalClear publishes the controls evidenced by the application and current hosting configuration. These controls reduce risk; they do not guarantee regulatory approval or authority acceptance.

TLS 1.2+ in transit
AES-256-GCM at rest
Managed hosting controls
Subscription-gated access
Privacy policy commitments
RBAC + 6-state approval workflow
SOC 2 audit — PLANNED

Encryption at every layer

Transport security and application-level protection are described below without extending claims beyond the current implementation.

Encryption at Rest

Application-managed credentials and tokens are encrypted with AES-256-GCM before storage where the relevant service requires it. Database-at-rest controls are provided by the managed database provider.

AES-256-GCM for application-managed secrets

Encryption in Transit

Production pages and APIs are served over HTTPS through the hosted application stack. Transport behavior can depend on the hosting and browser configuration.

HTTPS transport for public application traffic

Secure Cloud Hosting

Our application runs on managed hosting and uses managed PostgreSQL and object-storage services. Provider certifications and controls are not certifications of CanalClear.

Managed hosting — provider controls apply

Real-time Monitoring

The application exposes runtime health endpoints and records application events used by the product. Monitoring and incident visibility are described on the public status page.

Runtime health and incident visibility

We store what we need,
no more

Vessel filing data is sensitive. The categories and retention commitments are described in the Privacy Policy and may vary by feature and account state.

What We Store

We store vessel particulars, filing status, compliance scores, and submission history — the minimum required to provide compliance automation. We do not store cargo manifests beyond what is needed for canal-specific filing forms.

Retention Policy

Retention follows the commitments in the Privacy Policy and the deletion behavior implemented for the relevant record type. Contact us before relying on a retention period for a regulatory record.

No Third-Party Data Sharing

CanalClear does not sell vessel or filing data. Service providers may process data as needed to host, secure, deliver, or support the service, as described in the Privacy Policy.

Waterway-gated access by subscription

Authentication, authorization middleware, subscription checks, and record ownership checks are applied at the application boundary.

Enforcement Architecture

Protected pages and filing endpoints use authentication and, where applicable, subscription or role checks. The public pages and health endpoints are intentionally unauthenticated.

Account Isolation

Each account operates in an isolated data context. Routes scope account data through authenticated user and ownership checks. No security design can eliminate every implementation or configuration risk.

Encrypted Credentials

Third-party credentials (Suez Canal SCA login) are stored with AES-256-GCM encryption and are intended to remain server-side rather than being returned in normal API responses.

Password Security

User passwords are hashed with bcrypt (cost factor 12). We enforce minimum password requirements and support secure password reset via time-limited tokens.

Waterway access scoped to role

Enterprise ops desks need fine-grained control. CanalClear enforces role boundaries at the API layer — not just the UI.

Four Roles, Four Permission Levels

Each user is assigned exactly one role. Roles control what canals they can access, what filings they can create, and what they can approve.

6-State Approval Workflow

Every filing moves through a defined lifecycle. State transitions are logged immutably — no overwriting, no data loss.

Built on established cloud infrastructure

We don't reinvent infrastructure security — we rely on providers whose entire business is staying ahead of threats.

Application Hosting — Render

CanalClear runs on managed hosting with provider-managed TLS and deployment controls. Provider controls are not a CanalClear certification or guarantee.

Managed hosting controls

Database — Neon PostgreSQL

The operational database is a managed PostgreSQL service. Its provider controls, region, backup configuration, and recovery options can change and should be confirmed for a specific account or contract.

Neon PostgreSQL — automated branching and PITR

Provider Recovery Controls

Backup and recovery availability follows the configured managed-provider service. CanalClear does not promise a particular backup frequency, retention period, recovery point, or recovery time on this page.

Provider recovery options — confirm current terms

File Storage — Cloudflare R2

Generated PDFs and export documents are stored in Cloudflare R2 with private access. Signed URLs are used for document retrieval — files are not publicly accessible without authentication.

Private bucket — signed URL retrieval only

Where we are and where we're going

We're building toward formal security certifications while operating under industry-standard practices today.

Complete

Encryption Standards (AES-256-GCM + TLS 1.2+)

All data encrypted at rest and in transit. OAuth tokens and Suez credentials use AES-256-GCM. HTTPS enforced sitewide.

Complete

Subscription-Based Access Control

API-gated waterway access per subscription tier. Middleware-enforced on all filing engine endpoints. No cross-account data leakage.

PLANNED

SOC 2 Type II Certification

A formal SOC 2 Type II audit is PLANNED. No certification is currently represented by this page.

PLANNED

GDPR Data Processing Agreement (DPA)

A signed Data Processing Agreement may require a separate review. Contact us before relying on a DPA, transfer mechanism, or residency commitment.

PLANNED

Penetration Testing Program

Third-party penetration testing is PLANNED. Timing, scope, and any resulting report are not committed on this page.

We back our availability with transparency

The public status page reports runtime health and available incident history. It is not an uptime warranty.

Runtime status endpoint
LIVE
API response time
Runtime data
Public status page
LIVE
Incident communication
Policy-dependent
Maintenance notifications
No fixed promise

Runtime health is available at /status. Capability coverage is maintained at /authorities.

Where your data lives

Hosting and storage locations depend on the current providers and configuration. Confirm location requirements before sending regulated or contractual data.

Primary Database

Managed PostgreSQL storage. Current provider region and recovery configuration are not a substitute for a contracted residency or backup commitment.

File Storage

Object storage is used for generated documents and exports where enabled. Access depends on application authorization and signed retrieval behavior.

Payments

Stripe processes payment information under Stripe's own terms and privacy documentation. CanalClear does not store full card numbers in its application records.

EU / GDPR Note

If you operate under GDPR or another privacy regime, contact security@canalclear.org before processing data that requires a particular region, DPA, or transfer mechanism. Availability is subject to a separate review and is not guaranteed.

Report vulnerabilities to us directly

We welcome responsible disclosure from security researchers. If you've found a vulnerability, here's how to reach us.

How to Report

If you discover a security issue in CanalClear, please contact us at security@canalclear.org. Include as much detail as possible — affected URL, description of the vulnerability, and steps to reproduce (if applicable).

Need a security review for your fleet operation?

Enterprise security reviews and contract requirements can be discussed case by case. Availability is not a certification, residency, or authority-acceptance promise.