SECURITY

We can see your data. We can never touch it.

Reconciliation is a trust exercise. Here is exactly how we handle your data — stated plainly, nothing overclaimed.

Data handling

Canko connects to Shopify and Stripe using read-only API scopes. We can read orders, payouts, fees and refunds; we cannot create, modify, refund, or move money. Transaction data needed to compute a match is processed in memory and only the reconciliation result is stored — not your customers' payment credentials.

Encryption

  • In transit: TLS 1.2+ on every connection
  • At rest: AES-256 on all stored reconciliation data
  • API credentials stored in an isolated secrets vault

Access controls

  • Two-factor authentication on every account
  • Role-based access for multi-client and multi-store accounts
  • Audit logging of every data access event

Compliance posture

We're being straight with you: SOC 2 Type II is in progress, not yet certified. We run on SOC 2-compliant cloud infrastructure and follow the controls today, with independent audit underway. We won't claim a badge we don't hold.

Questions from your security team?

We're happy to walk your IT or security reviewer through our scopes, encryption and data flows directly. Get in touch and we'll set it up.