Legal

Trust & Security

Last updated: August 7, 2026

CanVest One holds sensitive financial information, so security is treated as a core part of the product, not an afterthought. This page describes, honestly, the practices we actually have in place today.

We use many industry-standard security practices similar to those used by modern financial technology platforms. We are a growing company and do not claim bank-level security, formal certification (e.g., SOC 2 Type II), or regulatory approval unless and until that is independently verified — this page will be updated if and when that changes.

Our practices

Encryption

All data is encrypted in transit using TLS (HTTPS) and encrypted at rest in our database. Your session tokens are handled by industry-standard JWT-based authentication.

Authentication

Sign-in is handled by Supabase Auth. Passwords are never stored in plain text — they are hashed using industry-standard algorithms before being saved.

Multi-factor authentication (MFA)

You can add an authenticator app (TOTP), a passkey (WebAuthn), or recovery codes in Settings → Security. Sensitive actions — like exporting your data or deleting your account — require a fresh MFA step-up check, even if you’re already signed in.

Role-based access

Row-level security (RLS) policies on our database ensure your data is only ever queryable by your own account. Administrative access is limited to a small number of authorized roles and is itself audit-logged.

Rate limiting

Sensitive and high-traffic endpoints (login, signup, password reset, AI requests, exports) are rate-limited per account and per IP address to reduce abuse and automated attacks.

Audit logging

Security-relevant events — sign-ins, MFA changes, account deletion, data export and erasure requests, admin actions — are written to an audit log we can review if something looks wrong.

Security monitoring

Application errors and anomalies are monitored in real time through our error-tracking and observability stack, so issues are surfaced quickly rather than discovered by chance.

Secure institution connections

On Pro, linking a bank or brokerage is handled by regulated third-party providers (Plaid, SnapTrade) using read-only, revocable tokens. Your institution login credentials are never entered into, or stored by, CanVest One.

Privacy controls

Your Privacy Center lets you review and withdraw optional consents, request a full data export, submit a correction, or start a formal erasure request — all without contacting support.

Account deletion

You can permanently delete your account and data at any time from Settings → Danger Zone (protected by an MFA step-up check), or submit a formal erasure request through your Privacy Center that we process within 30 days.

Data export

Request a complete export of your CanVest One data as a JSON file from your Privacy Center at any time — your profile, accounts, transactions, budgeting, goals, tax document records, AI conversations, and consent history.

Security updates

Dependencies and infrastructure are kept current, and known vulnerabilities are patched as they’re identified as part of our normal engineering process.

Incident response

If we identify a security incident affecting your personal information, we will investigate, take steps to contain it, and notify affected users and the appropriate authorities as required under PIPEDA.

Where to manage your security

  • Settings → Security — manage MFA, passkeys, and recovery codes
  • Privacy Center — manage consents, request a data export, correction, or erasure
  • Settings → Danger Zone — permanently delete your account

Report a security concern

If you believe you’ve found a security vulnerability or have a concern about the safety of your account, please contact us directly rather than posting it publicly — we take these reports seriously and will respond as quickly as we can.

CanVest One

Email: hello@cvone.ca

Privacy Policy →Terms of Service →← Back to home