CanalClear publishes the controls evidenced by the application and current hosting configuration. These controls reduce risk; they do not guarantee regulatory approval or authority acceptance.
Transport security and application-level protection are described below without extending claims beyond the current implementation.
Application-managed credentials and tokens are encrypted with AES-256-GCM before storage where the relevant service requires it. Database-at-rest controls are provided by the managed database provider.
Production pages and APIs are served over HTTPS through the hosted application stack. Transport behavior can depend on the hosting and browser configuration.
Our application runs on managed hosting and uses managed PostgreSQL and object-storage services. Provider certifications and controls are not certifications of CanalClear.
The application exposes runtime health endpoints and records application events used by the product. Monitoring and incident visibility are described on the public status page.
Vessel filing data is sensitive. The categories and retention commitments are described in the Privacy Policy and may vary by feature and account state.
We store vessel particulars, filing status, compliance scores, and submission history — the minimum required to provide compliance automation. We do not store cargo manifests beyond what is needed for canal-specific filing forms.
Retention follows the commitments in the Privacy Policy and the deletion behavior implemented for the relevant record type. Contact us before relying on a retention period for a regulatory record.
CanalClear does not sell vessel or filing data. Service providers may process data as needed to host, secure, deliver, or support the service, as described in the Privacy Policy.
Authentication, authorization middleware, subscription checks, and record ownership checks are applied at the application boundary.
Protected pages and filing endpoints use authentication and, where applicable, subscription or role checks. The public pages and health endpoints are intentionally unauthenticated.
Each account operates in an isolated data context. Routes scope account data through authenticated user and ownership checks. No security design can eliminate every implementation or configuration risk.
Third-party credentials (Suez Canal SCA login) are stored with AES-256-GCM encryption and are intended to remain server-side rather than being returned in normal API responses.
User passwords are hashed with bcrypt (cost factor 12). We enforce minimum password requirements and support secure password reset via time-limited tokens.
Enterprise ops desks need fine-grained control. CanalClear enforces role boundaries at the API layer — not just the UI.
Each user is assigned exactly one role. Roles control what canals they can access, what filings they can create, and what they can approve.
Every filing moves through a defined lifecycle. State transitions are logged immutably — no overwriting, no data loss.
We don't reinvent infrastructure security — we rely on providers whose entire business is staying ahead of threats.
CanalClear runs on managed hosting with provider-managed TLS and deployment controls. Provider controls are not a CanalClear certification or guarantee.
The operational database is a managed PostgreSQL service. Its provider controls, region, backup configuration, and recovery options can change and should be confirmed for a specific account or contract.
Backup and recovery availability follows the configured managed-provider service. CanalClear does not promise a particular backup frequency, retention period, recovery point, or recovery time on this page.
Generated PDFs and export documents are stored in Cloudflare R2 with private access. Signed URLs are used for document retrieval — files are not publicly accessible without authentication.
We're building toward formal security certifications while operating under industry-standard practices today.
All data encrypted at rest and in transit. OAuth tokens and Suez credentials use AES-256-GCM. HTTPS enforced sitewide.
API-gated waterway access per subscription tier. Middleware-enforced on all filing engine endpoints. No cross-account data leakage.
A formal SOC 2 Type II audit is PLANNED. No certification is currently represented by this page.
A signed Data Processing Agreement may require a separate review. Contact us before relying on a DPA, transfer mechanism, or residency commitment.
Third-party penetration testing is PLANNED. Timing, scope, and any resulting report are not committed on this page.
The public status page reports runtime health and available incident history. It is not an uptime warranty.
Runtime health is available at /status. Capability coverage is maintained at /authorities.
Hosting and storage locations depend on the current providers and configuration. Confirm location requirements before sending regulated or contractual data.
Managed PostgreSQL storage. Current provider region and recovery configuration are not a substitute for a contracted residency or backup commitment.
Object storage is used for generated documents and exports where enabled. Access depends on application authorization and signed retrieval behavior.
Stripe processes payment information under Stripe's own terms and privacy documentation. CanalClear does not store full card numbers in its application records.
If you operate under GDPR or another privacy regime, contact security@canalclear.org before processing data that requires a particular region, DPA, or transfer mechanism. Availability is subject to a separate review and is not guaranteed.
We welcome responsible disclosure from security researchers. If you've found a vulnerability, here's how to reach us.
If you discover a security issue in CanalClear, please contact us at security@canalclear.org. Include as much detail as possible — affected URL, description of the vulnerability, and steps to reproduce (if applicable).
Enterprise security reviews and contract requirements can be discussed case by case. Availability is not a certification, residency, or authority-acceptance promise.