Help Center

Requesting Security Documentation (SOC 2, DPA, ISO 27001)

  • Updated

    ~ minute read

This article explains which security and compliance documents Canto makes available and how to access them.


The Canto Trust Center

Canto's security documentation is available through the Trust Center at trust.canto.com. All prospects and customers can request access to see what documentation exists and which compliance frameworks Canto covers.

Viewing or downloading individual documents requires requesting access first. Click Get access on the Trust Center and submit a request. Once access is granted, documents can be viewed and downloaded directly from the portal.

Please note:

The Trust Center is the first place to go for any enterprise security review or vendor questionnaire. It covers Canto's compliance posture across SOC 2, ISO 27001, HIPAA, GDPR, PIPEDA, TX-RAMP, Accessibility, and the EU AI Act, as well as product security, infrastructure, data privacy, and policy documentation.


Available documents

The following documents are available through the Trust Center or on direct request. All Trust Center documents require access before they can be downloaded.

Document How to request it What it covers
SOC 2 Type 2 Report Trust Center (access required) Canto's annual third-party audit confirming security, availability, and confidentiality controls are operating effectively. Most commonly requested by enterprise IT and security teams.
ISO 27001:2022 Report Trust Center (access required) Certificate and report confirming Canto's information security management system meets the ISO/IEC 27001:2022 standard.
HIPAA Report Trust Center (access required) Canto's HIPAA compliance documentation. For customers who also need a Business Associate Agreement (BAA), contact your Account Manager or sales representative — see below.
Security Whitepaper Trust Center (access required) Overview of Canto's security architecture, controls, and practices. Useful for technical due diligence and security questionnaire preparation.
CAIQ Trust Center (access required) Consensus Assessment Initiative Questionnaire. A CSA standard self-assessment of Canto's cloud security controls. Full-length version.
CAIQ Lite Trust Center (access required) Abbreviated version of the CAIQ. Covers the same control areas with fewer questions — suitable for initial-stage vendor assessments.
HECVAT Lite Trust Center (access required) Higher Education Community Vendor Assessment Toolkit (Lite). For higher education institutions completing a vendor security review.
Data Flow Diagram (DFD) Trust Center (access required) Visual representation of how data moves through Canto's systems, including integrations and subprocessor touchpoints.
Network Diagram Trust Center (access required) Overview of Canto's network architecture and infrastructure topology.
Data Processing Agreement (DPA) Contact your Account Manager or Sales Specialist The binding legal agreement governing how Canto processes personal data on your behalf. Not available through the Trust Center — see below.

Data Processing Agreement (DPA)

The DPA is the binding legal agreement that sets out how Canto processes personal data on your behalf. It is not available through the Trust Center.

To request the DPA, contact your Account Manager or Sales Specialist directly.

Please note:

The DPA is incorporated by reference into the standard Canto customer agreement. Existing customers whose contracts already include a DPA can request a signed copy from their Account Manager at any time.


Frequently asked questions

I submitted an access request on the Trust Center. What’s next?
You will receive an email notification when access is granted. If you haven't heard back, contact your Account Manager or submit a support request via the Help Center.


Do I need an NDA to access documents on the Trust Center?
Some documents may require a signed NDA before access is granted. 


Is a Business Associate Agreement (BAA) available for HIPAA compliance?
Yes. Canto signs BAAs with customers who will store electronic protected health information (ePHI) in Canto. To request a BAA, contact your Account Manager or sales representative.


I need to complete a security questionnaire. Where do I start?
Start with the CAIQ or CAIQ Lite on the Trust Center — these are pre-completed responses to standard cloud security questions and will answer most questionnaire items directly. The Security Whitepaper and Data Flow Diagram are also useful supporting documents. Visit trust.canto.com and request access to begin.


Who do I contact if I can't find the document I need?
Contact your Account Manager or Sales Specialist. If you don't have a direct contact, submit a request via the Help Center with a description of what you need.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request