Legal
Trust & Security
Last updated: August 7, 2026
CanVest One holds sensitive financial information, so security is treated as a core part of the product, not an afterthought. This page describes, honestly, the practices we actually have in place today.
Our practices
Encryption
All data is encrypted in transit using TLS (HTTPS) and encrypted at rest in our database. Your session tokens are handled by industry-standard JWT-based authentication.
Authentication
Sign-in is handled by Supabase Auth. Passwords are never stored in plain text — they are hashed using industry-standard algorithms before being saved.
Multi-factor authentication (MFA)
You can add an authenticator app (TOTP), a passkey (WebAuthn), or recovery codes in Settings → Security. Sensitive actions — like exporting your data or deleting your account — require a fresh MFA step-up check, even if you’re already signed in.
Role-based access
Row-level security (RLS) policies on our database ensure your data is only ever queryable by your own account. Administrative access is limited to a small number of authorized roles and is itself audit-logged.
Rate limiting
Sensitive and high-traffic endpoints (login, signup, password reset, AI requests, exports) are rate-limited per account and per IP address to reduce abuse and automated attacks.
Audit logging
Security-relevant events — sign-ins, MFA changes, account deletion, data export and erasure requests, admin actions — are written to an audit log we can review if something looks wrong.
Security monitoring
Application errors and anomalies are monitored in real time through our error-tracking and observability stack, so issues are surfaced quickly rather than discovered by chance.
Secure institution connections
On Pro, linking a bank or brokerage is handled by regulated third-party providers (Plaid, SnapTrade) using read-only, revocable tokens. Your institution login credentials are never entered into, or stored by, CanVest One.
Privacy controls
Your Privacy Center lets you review and withdraw optional consents, request a full data export, submit a correction, or start a formal erasure request — all without contacting support.
Account deletion
You can permanently delete your account and data at any time from Settings → Danger Zone (protected by an MFA step-up check), or submit a formal erasure request through your Privacy Center that we process within 30 days.
Data export
Request a complete export of your CanVest One data as a JSON file from your Privacy Center at any time — your profile, accounts, transactions, budgeting, goals, tax document records, AI conversations, and consent history.
Security updates
Dependencies and infrastructure are kept current, and known vulnerabilities are patched as they’re identified as part of our normal engineering process.
Incident response
If we identify a security incident affecting your personal information, we will investigate, take steps to contain it, and notify affected users and the appropriate authorities as required under PIPEDA.
Where to manage your security
- Settings → Security — manage MFA, passkeys, and recovery codes
- Privacy Center — manage consents, request a data export, correction, or erasure
- Settings → Danger Zone — permanently delete your account
Report a security concern
If you believe you’ve found a security vulnerability or have a concern about the safety of your account, please contact us directly rather than posting it publicly — we take these reports seriously and will respond as quickly as we can.
CanVest One
Email: hello@cvone.ca