Trust Center
Data Processing Agreement
Last updated: July 14, 2026. This page describes how DPAs are handled today. It is a statement of current practice, not a template contract.
How DPAs work with CanaryVaults today
Plain answers first.
- A signed Data Processing Agreement is provided per Enterprise contract. If your organization needs a DPA, email hello@canaryvaults.com or use the contact form, and one will be executed as part of the agreement.
- For all plans, the practical data-handling commitments — what is collected, where it is stored, and how export and deletion work — are documented in the privacy policy.
- Data export and account deletion are self-service from account settings; no ticket or email round-trip is required to exercise them.
Certifications: the honest state
No badges that do not exist.
- CanaryVaults does not currently hold SOC 2 (Type I or Type II), ISO 27001, or HIPAA attestation.
- No third-party audit is currently scheduled. When one is, the timeline will be published on this page and in the changelog — until then the honest answer is: timeline TBD.
- What exists today instead: documented security posture, a public incident log, structured audit logging of security-relevant account activity, and self-service GDPR-style export and deletion.