Security

Canium's security guarantee is architectural, not contractual. The system is designed so that even Canium's own engineers have zero technical ability to access message content, encryption keys, or your password — under any circumstance.


Threat Model — What Canium Protects Against

Canium's encryption architecture protects users from:

What Canium Does Not Protect Against

Canium does not protect against:

Always On

Encryption applies to every call and every message — audio, video, and text — automatically, from the first session. There is no mode to enable, no feature that requires turning it off, and no path that bypasses it. If encryption cannot be established, no content is sent. Canium fails closed.

Standards and Compliance

Standard / FrameworkStatus
PIPEDAArchitecture designed for compliance
Communications data residencyCanada — messaging, encryption keys, and channel content
Billing data residencyPer payment processor — currently US-based; Canadian processor migration planned for enterprise/government clients requiring full billing-data residency
IETF RFC 9420 (MLS)Implemented via OpenMLS
IETF RFC 9807 (OPAQUE)Implemented via opaque-ke, an independently reviewed open source library.
NIST ML-KEM-768 (FIPS 203)Hybrid post-quantum KEM (X-Wing combiner with X25519) for all MLS message key establishment and DRA recovery envelopes
AES-256-GCMMessage encryption
CCCS / Government of CanadaTarget market; procurement readiness in progress

Audit Trail

Every cryptographic state-change operation emits a structured audit event. These include authentication events (login success/failure, password change, reset), key material events (key package consumption, fallback key use), and any DRA disclosure operations. Audit logs are available to your compliance officers.


Compliance →

Canadian sovereignty, lawful access, and the DRA architecture.

How It Works →

MLS, OPAQUE, and post-quantum key establishment, end to end.