How DPAs work with CanaryVaults today

Plain answers first.

  • A signed Data Processing Agreement is provided per Enterprise contract. If your organization needs a DPA, email hello@canaryvaults.com or use the contact form, and one will be executed as part of the agreement.
  • For all plans, the practical data-handling commitments — what is collected, where it is stored, and how export and deletion work — are documented in the privacy policy.
  • Data export and account deletion are self-service from account settings; no ticket or email round-trip is required to exercise them.

Certifications: the honest state

No badges that do not exist.

  • CanaryVaults does not currently hold SOC 2 (Type I or Type II), ISO 27001, or HIPAA attestation.
  • No third-party audit is currently scheduled. When one is, the timeline will be published on this page and in the changelog — until then the honest answer is: timeline TBD.
  • What exists today instead: documented security posture, a public incident log, structured audit logging of security-relevant account activity, and self-service GDPR-style export and deletion.

Related trust surfaces