For your due diligence
Security, stated the way auditors read it.
Operating across two countries makes data handling an explicit contractual matter, not an assumption. This page states the posture; the engagement agreement is where it becomes binding.
Posture
Three commitments a contract can hold.
- Data residency is a term, not a default
- Which hub handles your data, which hub may access what, and under which conditions — agreed in the contract, because Canaan operates in two jurisdictions.
- Processor on your instructions
- Personal data processed in Malaysia is governed by the Personal Data Protection Act 2010. Canaan operates as a data processor, with handling terms set out in the engagement agreement.
- Your audit scope, our evidence
- Access logging, decision audit trails and reporting configured to the evidence your auditors expect — confirmed during design, not discovered during the audit.
Where your data lives
Two hubs, one contractual boundary.
Canaan runs two owned delivery centres in different jurisdictions. Which hub handles your data, which may access what, and under which conditions is written into your engagement agreement — never left to a default.
Kuala Lumpur
Malaysia · Headquarters
ASEAN coverageGoverned by Personal Data Protection Act 2010
Gulistan
Uzbekistan · Delivery centre
CIS coverageGoverned by Terms set in your engagement agreement
Delivery partners in other markets are contracted separately and never presented as Canaan facilities.
On the floor
The controls your questionnaire will ask about.
Control
- Physical access
- Badged entry and visitor logging at both owned hubs, with production floors separated from general office space.
- Clean desk, clean screen
- Clean-desk and clean-screen practice on production floors that handle client data.
- Endpoint & access control
- Managed endpoints with role-based access — people hold the access their queue requires, nothing broader.
- Data in transit
- Client systems reached over encrypted connections, with credentials issued per person and never shared.
Documentation
Shared on request, with their scope stated.
We do not publish certificates or policy documents on this website. Tell us what your review needs and we will send what applies to the work you are scoping — under NDA where you want one.
Anything we send names the sites and services it covers. A certificate covering one hub does not cover the other, and we will not let you read it as though it did.
You will hear from an operations lead within one business day.
Request our documentationWhat buyers usually ask us for
- Certification & registration records
- Certificates, their scope statements — which sites and services each one covers — and current validity, for whichever standards and registrations apply to the work you are scoping.
- Security & data-handling policies
- The documentation behind the controls on this page: how data is held, who may access it at which hub, and what your own auditors would be shown.
- Registry & contract documents
- SSM registration records, and the engagement terms your legal team reads before signature — including the data-residency clause for your programme.
Client references are available under NDA on the same basis.
The questions your security review will ask
Anything more specific than these is better answered against your own questionnaire than in general terms here.
Send us your security questionnaire.
We would rather answer it during evaluation than negotiate it after signature.