CANIMA, INC.
SECURITY & VULNERABILITY DISCLOSURE POLICY
Effective Date: 05/06/2026
1. OUR COMMITMENT TO SECURITY
At Canima, we are building an AI-powered penetration testing platform that helps organizations identify and remediate security vulnerabilities. Security is core to everything we do. We are committed to maintaining the highest standards of security for our platform, our customers’ data, and the broader security community.
2. OUR SECURITY PRACTICES
Canima implements comprehensive security measures across our platform and organization, including:
Infrastructure: Our platform is hosted on enterprise-grade cloud infrastructure with SOC 2 Type II-certified providers. We employ network segmentation, intrusion detection, and continuous monitoring.
Data Protection: All data in transit is encrypted using TLS 1.2 or higher. All data at rest is encrypted using AES-256 or equivalent. We implement strict access controls and multi-factor authentication.
Application Security: We conduct regular internal and third-party security assessments of our own platform. Our development practices include secure code review, automated vulnerability scanning, and dependency monitoring.
Organizational Security: All employees undergo background checks and security awareness training. Access to systems and data follows the principle of least privilege.
Compliance: Canima maintains relevant industry certifications and undergoes regular third-party audits.
3. RESPONSIBLE VULNERABILITY DISCLOSURE
We greatly value the contributions of security researchers, ethical hackers, and anyone who takes the time to identify potential security issues in our platform. If you believe you have discovered a security vulnerability in Canima’s platform or website, we encourage you to report it to us responsibly.
3.1 How to Report. Please send your findings to [email protected]. Include as much detail as possible: a description of the vulnerability, steps to reproduce, potential impact, and any supporting evidence (screenshots, proof-of-concept code, etc.).
3.2 What to Expect. We will acknowledge receipt of your report within 48 business hours. Our security team will investigate the issue and work to validate and remediate it. We will keep you informed of our progress and notify you when the issue is resolved.
3.3 Our Commitment to Reporters. We will not take legal action against security researchers who discover and report vulnerabilities in good faith and in accordance with this policy. We will work with you in good faith to understand and resolve the issue. We will publicly acknowledge your contribution (with your permission) if the vulnerability is confirmed and remediated.
3.4 Guidelines for Researchers. When conducting research, please: (i) avoid accessing, modifying, or deleting data that does not belong to you; (ii) do not disrupt or degrade our services; (iii) do not test against accounts you do not own without authorization; (iv) do not engage in social engineering, phishing, or physical attacks against Canima employees; (v) give us reasonable time to investigate and address the vulnerability before disclosing it publicly; and (vi) do not exploit the vulnerability beyond what is necessary to demonstrate the issue.
3.5 Out of Scope. The following are generally out of scope for this disclosure policy: findings from automated scanners without manual validation; denial-of-service testing; social engineering of Canima employees; physical security assessments; and vulnerabilities in third-party services that we integrate with (please report those to the respective provider).
4. SECURITY INCIDENT RESPONSE
In the event of a security incident affecting our platform or customer data, Canima maintains a documented incident response plan. We commit to: promptly investigating and containing the incident; notifying affected customers in accordance with our contractual obligations and applicable law; providing regular updates during active incident response; conducting a thorough post-incident review and implementing lessons learned.
5. CONTACT
For security-related inquiries or to report a vulnerability:
Security Team Email: [email protected]
General Inquiries: [email protected]
Website: https://canima.com