Canonset

Security overview · version 0.1 draft

Draft: marked items are being set up for our pilot deployment.

Your data stays in one place, and only the people who need it can see it.

Client data lives in one database on Amazon RDS in US West (Oregon) and can be reached only through our web app. Each person sees only what their role needs. We use no shared documents and no public links, and no AI lab owns any part of Canonset.

Own code sandbox
Submitted code never runs on a hosted sandbox service.
No passwords
Sign-in by one-time email code or passkey; nothing to leak or reuse.
No trackers
No analytics or tracking services in the app.
Independent
No AI lab holds equity or a board seat.

Where data lives

  • Application: Amazon Web Services: Amazon EC2 in US West (Oregon), reached only through Amazon CloudFront. Database: managed PostgreSQL on Amazon RDS, US West (Oregon). Code-test runner: our own isolated containers on a dedicated Amazon EC2 server, US West (Oregon).
  • Encrypted in transit with TLS from browsers to Amazon CloudFront, from CloudFront to our web server, and from the web server to the database. Encrypted at rest on all AWS storage: server disks, the database and file storage.
  • Our web server accepts traffic only through Amazon CloudFront, which filters it with a web application firewall (AWS WAF) and AWS's DDoS protection. CloudFront caches only our public site files; pages and data are never cached.
  • AWS is the only third party that stores or processes client data. GitHub holds our source code, never client data. The app uses no analytics or tracking services.
  • Client data enters as task files (JSONL or CSV) uploaded in the app. It leaves only as exports the client downloads. It is never kept in shared documents, email attachments or public links.

Running submitted code

Code and tests that experts write run only in our own containers, never on a hosted sandbox service. Containers run under gVisor for an extra layer of kernel isolation.

  • Fresh container

    Created for each check, deleted afterwards

  • No network

    Code cannot call out or be reached

  • Read-only system

    Only a scratch folder is writable; nothing mounted from the host

  • Unprivileged

    Runs as a normal user with every Linux capability removed

  • Hard limits

    1 CPU · 512 MB memory · 128 processes

  • Time-boxed

    30 seconds per test run

The app reaches the runner only with a secret token, over a private network inside our AWS account, and the runner accepts connections only from our web server. The runner keeps nothing. Results, including up to 16,000 characters of test output per run, are saved in our database with the answer.

Who can see what

PersonCan access
Client usersOnly their own organization's projects, progress and exports.
ExpertsOnly projects in their approved field, and only the task they are working on (one at a time per project). They are not shown the client's name.
Reviewers (senior experts)Answers in their own fields, never their own work. Experts appear under per-project pseudonyms.
Our operations team (1 person)All projects, to set them up, price them and monitor them.

Delivered data identifies experts only by per-project pseudonyms.

Accounts and access

  • The server checks the user's role on every page and action. Exports are served only to the client that owns the project.
  • There are no passwords. People sign in with a one-time code emailed to them (valid 10 minutes, stored only as a hash), and can add two-factor login with an authenticator app. Staff sign in with a passkey.
  • Sessions are kept in our database, so they can be revoked, and in httpOnly, Secure cookies. They last up to 7 days; staff sessions end after 12 hours, or 30 minutes idle.
  • Sign-in attempts are rate-limited per visitor, and each code allows five tries.
  • Staff confirm their passkey again before payouts, data exports, new client accounts and access changes.
  • Two-factor login is required on every company account: email, code hosting, cloud hosting and database. being set up
  • Every staff action, and every time staff view or export client data, goes into an append-only audit log: who, what, when, from which address, and what changed. The database rejects edits and deletions, and entries are kept at least a year.
  • Direct production database access is limited to one named person.

Experts

  • All experts are located in the United States.
  • Every expert passes a screening test and human approval, then signs a contractor agreement with confidentiality and IP-assignment terms before their first task. being set up
  • All work happens inside our platform.
  • A written policy forbids using AI to do the work. We enforce it with hidden test tasks that have known answers, flags for unusually fast or short work and AI-style writing, and reviewer checks. An expert is removed on the first confirmed case.

Use, retention and deletion

  • A client's data is used only for that client's project. It is never shared with other clients or used to train models.
  • We keep client data for the project plus 30 days, then delete it automatically. On request, made from the project page or by email, we delete it sooner, within 7 days, and it leaves our automated backups within 7 days. We confirm deletion in writing, and the audit log records it. Invoices stay as financial records, with amounts and the project's name only.

Incidents

We notify affected clients within 72 hours of confirming a security incident, at the contact named in the contract. Security contact: security@canonset.com being set up.

Independence

Canonset is independent. No AI lab owns equity or holds a board seat. We do not work for organizations headquartered in, or at least 50% owned or controlled from, China (including Hong Kong and Macau), Russia, Iran, North Korea, Cuba or Venezuela, directly or through resellers. We screen every client's parent company against US government restricted-party lists. being set up

Planned controls

Not in place yet. We will list each one here with its date once it is scheduled.

  • SOC 2 Type II auditPlanned
  • Single sign-on (SAML) for client companiesPlanned
  • Retention settings per clientPlanned
  • Independent penetration testPlanned

Want to see the work itself? Every open sample shows the checks it passed.