Security

Security built for your company.

Canu connects to important business systems, so security is built into every layer of the product — from authentication and encrypted connections to permissions, approvals, and audit history.

Encrypted connections
Least-privilege access
Approval controls
Audit history
Secure infrastructure

Overview

Your data stays protected.

Canu only accesses the information needed to perform the tasks you authorize. Connections, credentials, agent actions, and company data are protected using modern security practices.

Encryption

Encrypted in transit and at rest

Data transmitted between Canu and connected services is protected using encrypted HTTPS/TLS connections. Sensitive stored data is also encrypted at rest using secure managed infrastructure.

Secure connections

Credentials stay protected

Canu uses OAuth and secure credential-management systems wherever integrations support them. You never need to hand your account passwords to Canu.

Permission controls

Only the access Canu needs

Connections follow least-privilege principles, so Canu receives only the permissions required for the actions your company enables.

Approval controls

You stay in control

Sensitive or higher-impact actions can require explicit human approval before Canu executes them.

Connections

Secure connections to your tools

Canu connects through secure APIs and OAuth flows wherever they are available. Raw account passwords are never requested or stored.

QuickBooks logo
QuickBooks
Stripe logo
Stripe
AWS logo
AWS
Slack logo
Slack
Canu agent
OpenAI logo
OpenAI
HubSpot logo
HubSpot
Google Workspace logo
Google Workspace
Microsoft logo
Microsoft

Canu connects through secure APIs and OAuth flows whenever possible.

1

You authorize

You choose which company systems Canu can connect to.

2

Canu receives limited access

Canu only receives the permissions required for the tasks you enable.

3

You can disconnect anytime

Connections can be revoked from the Canu Connections page.

Credentials

Canu does not need your passwords.

Whenever an integration supports OAuth or token-based authentication, Canu uses that secure authorization flow instead of asking for account passwords.

Your companyOAuth / secure API authorizationCanuAuthorized service

Access tokens and integration credentials are stored using secure encrypted credential infrastructure and are never exposed in the frontend or client-side code.

Agent permissions

An AI agent should never have unlimited access.

Canu's capabilities are grouped into permission tiers. Your company decides which tiers Canu is allowed to use, per integration.

Read

  • View expenses
  • Read usage
  • Analyze contracts
  • Review subscription activity

Prepare

  • Prepare cancellation
  • Draft vendor outreach
  • Create recommendations
  • Generate cost-saving actions

Execute

  • Cancel a subscription
  • Change a service configuration
  • Send an approved message
  • Modify a vendor setting

Execution permissions are separate from read permissions.

Granting Canu the ability to read your spend never implies the ability to change it.

Approvals

Important actions can require your approval.

Canu recommends

Remove 12 inactive Slack seats

Expected savings
$144/mo
Risk
Low
Affected users
12

Companies configure which types of actions Canu may execute automatically and which must be approved by a human first.

High-impact actions default to requiring approval, and approval checks are enforced on the backend — not in the browser.

Agent safety

Built for agent safety

Canu does not let an AI model perform arbitrary actions. The agent operates through a controlled tool layer where every action passes permission and approval checks.

Restricted tools

The agent can only call integrations and actions explicitly exposed to it.

Permission checks

Before execution, the system verifies whether the workspace allows that action.

Approval gates

Actions requiring human approval pause until a person approves them.

Verification

After execution, Canu checks whether the expected result actually occurred.

AI decisionPermission checkApproval if requiredExecuteVerify

Data privacy

Your company data is your company data.

Canu only uses connected company information to provide the Canu product and perform the agent tasks you authorize.

  • Company data is not publicly exposed.
  • Access is scoped to the appropriate workspace, enforced server-side.
  • You can remove integrations and revoke access at any time.
  • Sensitive credentials never appear in application logs or frontend interfaces.

AI providers

How AI is used

Canu uses AI models to understand company information, analyze financial and operational data, identify opportunities, and decide which authorized tools to use. The model never receives unrestricted access to your infrastructure — tool access is mediated by Canu's backend permission system.

AI modelCanu secure tool layerPermission + approval checksConnected service

Infrastructure

Secure infrastructure

Backend-only secrets

API keys and integration secrets stay server-side and are never shipped to the browser.

Environment isolation

Production credentials are stored separately from development environments.

Encrypted communication

All application and API traffic uses HTTPS/TLS.

Database protections

Encrypted storage, authenticated database access, and strict server-side authorization on every request.

Logging

Important security and agent events are recorded without logging sensitive credentials.

Backups

Secure backups for critical company data where applicable.

Audit history

See what Canu did.

Every meaningful agent action leaves a visible audit trail — the user, the action, the time, the integration, its status, the approval source, and the verified result.

9:42 PMCanu analyzed AWS usage· Canu agentAWSCompleted
9:45 PMRecommendation created· Canu agentCanuPending approval
9:51 PMGrant approved action· Grant (Admin)CanuApproved
9:52 PMAWS configuration updated· Canu agentAWSExecuted
9:55 PMSavings verification started· Canu agentAWSVerifying
10:02 PM$420/month savings verified· Canu agentAWSVerified

Account

Protecting your Canu account

Access to the Canu workspace itself is protected with standard account security controls.

Secure authenticationAvailable
Email verificationAvailable
Strong password requirementsAvailable
Session managementAvailable
Password reset protectionAvailable
Google OAuth loginAvailable
MFAPlanned
SSOPlanned

Workspace access

Coming Soon

Workspace-level access controls

Multiple employees will be able to use Canu without identical permissions. These roles are not yet available in the product.

Admin

Can manage connections, permissions, and approvals.

Approver

Can review and approve agent actions.

Member

Can view analysis and interact with Canu.

Viewer

Read-only access.

Disconnect anytime.

Workspace admins can revoke an integration directly from Canu's Connections page. When disconnected:

  • Canu stops making new requests to that integration.
  • Stored access tokens are revoked or securely removed.
  • Tasks depending on that integration stop.
  • The activity log records the disconnection.
Manage connections

Architecture

How a Canu action actually flows

Every action travels the same path — from an authorized connection, through permissions and approvals, to a verified, logged result.

Connected services

QuickBooks / Stripe / AWS / Slack / OpenAI

Secure OAuth + API layer

Encrypted credential store

Canu backend

Permissions engine

AI agent

Approval engine

Authorized action

Audit log + verification

Security incidents

If Canu identifies suspicious access, compromised credentials, or another security issue, affected access is disabled and investigated as quickly as possible. You always have a clear way to report a security concern.

Found a security issue?

We appreciate responsible disclosure from security researchers and users. Please contact our security team with details about the issue and steps to reproduce it.

Compliance

Security and compliance

As Canu grows, we plan to continue formalizing our security program and pursue industry-standard security reviews and certifications appropriate for our customers. The items below are not yet in place.

SOC 2

Planned

Penetration testing

Planned

SSO

Planned

MFA

Planned

RBAC

Planned

FAQ

Security questions, answered

Connect your company with confidence.

Canu is designed so your AI agent gets the access it needs — and nothing more.