Security & Compliance

Your clients' financial lives live here. We act like it.

CanyonOps is built for a regulated industry by people who work in one. Here's exactly how your data is protected, and what to ask us for when your due diligence needs more.

Data Protection

Protected by design, not by promises.

Encrypted everywhere

AES-256 encryption at rest and TLS in transit. System passwords and access keys are kept in dedicated, locked-down storage, never in code.

Isolated per firm

Strict per-firm separation: your data is never visible to another firm — by design, not just by policy.

Need-to-know access

Role-based access within your firm, and tightly limited, logged access on our side. Nobody browses client data out of curiosity. The system won't let them, and the log would show it.

Audit & Records

Proof accumulates while you work.

Most tools bolt an "audit log" on later. CanyonOps was built by an advisor who's been through the worst version of a records question, so proof happens automatically as the work gets done.

  • Permanent audit trail — every action timestamped and attributed; history can't be silently rewritten
  • Tamper-evident exports — every evidence pack carries a verifiable integrity seal
  • SEC 204-2-aligned retention — with dual-control deletion holds: no single person, including us, quietly deletes records
  • Evidence on demand — per-client reports, firm summaries, communication logs, fee justification. One click
app.canyonops.ai/audit-trail
Audit trail · Anderson Family
Permanent record
Jul 24 · 09:12 JC approved 3 AI suggestions · source: meeting transcript Jul 22
Jul 24 · 09:12 Task created · Roth Conversion — $85K November → assigned SM, due Nov 14
Jul 23 · 16:40 SM completed subtask · Pull Dec 31 balances and YTD income
Jul 22 · 14:05 Meeting logged · Annual Review · attendees recorded
Jul 21 · 08:30 Evidence pack generated · SHA-256 ✓ · 5 files
Every row is permanent. That's the point.

AI Data Handling

What the AI sees — and what it never does.

Your data serves your firm

Transcripts and client records are processed to generate suggestions for you — not to train models.

A person approves, always

AI output is a draft. Nothing becomes part of your records until a person at your firm approves it, and the approval itself is logged.

Traceable, not a black box

Every suggestion links to its source line in the transcript. If you can't see where it came from, it doesn't get saved.

SOC 2, on the clock.

Our SOC 2 Type I audit engagement is targeted for Q4 2026, with Type II on the 2027 roadmap. Until the report exists we won't wave the logo — but we'll gladly walk your compliance consultant through our controls today. The security pack includes an systems overview, control summary, and sub-processor list.

Request it

Practical Answers

The due-diligence checklist, pre-answered.

Sub-processors

Current list available on request; changes are communicated in advance so your compliance file stays current.

Data portability

Your data exports with you if you leave: tasks, notes, history, audit trail. No hostage-taking.

Incident response

Documented response process with client notification consistent with law and contract. You hear it from us, promptly, not from the news.

Responsible disclosure

Found something? security@canyonops.ai — we respond fast and credit researchers who help us.

Want the details? Email security@canyonops.ai for our security practices and sub-processor list. Compliance consultants welcome — bring your questionnaire.

Diligence done? See the product.

Twenty minutes with the founder, on the live system that runs his practice, audit trail and all.