Security Policy

This Security Policy outlines our commitment to safeguarding information and the measures taken to protect against unauthorized access, disclosure, alteration, and destruction.

Last modified: July 17, 2026

Wren AI Security Policy

Overview and Scope

Canner, Inc. ("Canner," "Wren AI," "we," "us," or "our") is committed to protecting customer data and maintaining the confidentiality, integrity, and availability of the systems we operate. This Security Policy describes the safeguards used for Wren AI Cloud and other services hosted and managed by Canner (collectively, the "Canner-Hosted Services").

Customer-managed, private-cloud, self-hosted, and air-gapped deployments may use different controls because the customer controls the infrastructure, configuration, access, and operations. Security responsibilities for those deployments are governed by the applicable customer agreement and deployment documentation.

No security program can eliminate every risk. We regularly review our safeguards and update them as our Services, technology, and threat environment evolve.

Data Protection

Data at Rest

For Canner-Hosted Services, customer data at rest is protected using AES-256 encryption or equivalent safeguards provided by the applicable hosting and storage services. Access to encryption systems and protected data is restricted according to role and business need.

Data in Transit

Data transmitted between supported clients and Canner-Hosted Services is protected using current Transport Layer Security (TLS) protocols. Connections to customer-managed data sources and third-party integrations may also depend on the protocols and configurations supported by those systems.

Product and Application Security

Vulnerability Management

We use a risk-based vulnerability-management process that may include automated scanning, dependency analysis, security testing, and remediation based on severity and potential impact. The scope and frequency of testing depend on the system, release, and risk involved.

Penetration Testing

We periodically conduct penetration testing of defined Canner-Hosted Services and supporting infrastructure. The scope of each assessment is based on risk and is documented for that assessment. Eligible customers may request available assessment information, subject to confidentiality and security restrictions.

Secure Development

Our software-development lifecycle includes peer review, automated build and deployment controls, source-code analysis, dependency scanning, and security review appropriate to the nature and risk of a change. Production releases pass through controlled continuous-integration and deployment processes.

Risk Management and SOC 2

Canner maintains a risk-management and control program informed by the SOC 2 Trust Services Criteria. Wren AI Cloud is included within the defined scope of Canner's SOC 2 Type II examination. The applicable report, rather than this public summary, defines the systems, controls, and review period covered by the examination. Eligible customers may request the current report under appropriate confidentiality terms.

Enterprise Security

Security Education

Personnel receive security and privacy training during onboarding and periodically thereafter. Additional guidance or training may be provided based on role, system access, or changes in risk.

Identity and Access Management

Access to production systems and sensitive information is limited according to role, least privilege, and legitimate business need. We use multifactor authentication to protect access to critical internal systems and sensitive environments, and we periodically review access permissions.

Vendor Security

We use a risk-based process to evaluate service providers that may access customer data or support critical operations. Reviews may consider the type of data involved, access level, security practices, contractual protections, compliance documentation, incident history, and business criticality. The depth and frequency of review depend on the vendor's risk profile.

Incident Response

Preparation and Response

Canner maintains processes for identifying, reporting, investigating, containing, and remediating suspected security incidents. Personnel are instructed to promptly report suspicious activity and potential security events through established internal channels.

Service availability and material operational incidents are communicated through the Wren AI Cloud Status Page when appropriate.

Notification

If a security incident affects personal data or customer data, we will notify affected customers, individuals, or authorities as required by applicable law and our contractual obligations. The timing and content of a notification depend on the nature of the incident, available information, legal requirements, and the needs of the investigation.

Reporting a Security Concern

To report a suspected vulnerability or security concern, email privacy@cannerdata.com with the subject line "Security Report." Please include enough information for us to understand and reproduce the issue, but do not include personal data, credentials, access tokens, or confidential customer information in the initial message.

Do not exploit a vulnerability, access or modify data that does not belong to you, disrupt the Services, or use social engineering, denial-of-service testing, or destructive techniques. We will review good-faith reports and respond as appropriate based on severity and reproducibility.

Data Privacy

Our collection, use, disclosure, and retention of personal data are described in the Wren AI Privacy Policy. If a customer uses Wren AI to process personal data, responsibilities may also be governed by the applicable customer agreement and data processing agreement.

Contact

For questions about this Policy or our security practices, contact:

Canner, Inc., 16192 Coastal Highway, Lewes, Delaware 19958, United States

Email: privacy@cannerdata.com

Updates to This Policy

We may update this Security Policy to reflect changes to our Services, safeguards, or legal and regulatory obligations. We will publish the updated version on this page and revise the "Last modified" date.