Skip to content
Talk to us

For your due diligence

Security, stated the way auditors read it.

Operating across two countries makes data handling an explicit contractual matter, not an assumption. This page states the posture; the engagement agreement is where it becomes binding.

Posture

Three commitments a contract can hold.

Data residency is a term, not a default
Which hub handles your data, which hub may access what, and under which conditions — agreed in the contract, because Canaan operates in two jurisdictions.
Processor on your instructions
Personal data processed in Malaysia is governed by the Personal Data Protection Act 2010. Canaan operates as a data processor, with handling terms set out in the engagement agreement.
Your audit scope, our evidence
Access logging, decision audit trails and reporting configured to the evidence your auditors expect — confirmed during design, not discovered during the audit.

Where your data lives

Two hubs, one contractual boundary.

Canaan runs two owned delivery centres in different jurisdictions. Which hub handles your data, which may access what, and under which conditions is written into your engagement agreement — never left to a default.

Kuala Lumpur

Malaysia · Headquarters

ASEAN coverage

Governed by Personal Data Protection Act 2010

Contract term

Gulistan

Uzbekistan · Delivery centre

CIS coverage

Governed by Terms set in your engagement agreement

Delivery partners in other markets are contracted separately and never presented as Canaan facilities.

On the floor

The controls your questionnaire will ask about.

Control

Physical access
Badged entry and visitor logging at both owned hubs, with production floors separated from general office space.
Clean desk, clean screen
Clean-desk and clean-screen practice on production floors that handle client data.
Endpoint & access control
Managed endpoints with role-based access — people hold the access their queue requires, nothing broader.
Data in transit
Client systems reached over encrypted connections, with credentials issued per person and never shared.

Documentation

Shared on request, with their scope stated.

We do not publish certificates or policy documents on this website. Tell us what your review needs and we will send what applies to the work you are scoping — under NDA where you want one.

Anything we send names the sites and services it covers. A certificate covering one hub does not cover the other, and we will not let you read it as though it did.

You will hear from an operations lead within one business day.

Request our documentation

What buyers usually ask us for

Certification & registration records
Certificates, their scope statements — which sites and services each one covers — and current validity, for whichever standards and registrations apply to the work you are scoping.
Security & data-handling policies
The documentation behind the controls on this page: how data is held, who may access it at which hub, and what your own auditors would be shown.
Registry & contract documents
SSM registration records, and the engagement terms your legal team reads before signature — including the data-residency clause for your programme.

Client references are available under NDA on the same basis.

The questions your security review will ask

Anything more specific than these is better answered against your own questionnaire than in general terms here.

Ask us directly

Send us your security questionnaire.

We would rather answer it during evaluation than negotiate it after signature.