Trust Center

Built for German data protection.

The Trust Center collects all the facts about data residency, security and data processing in one place. 

AI runs in Germany, no US provider Hosted in Germany / EU Data processing under Art. 28 GDPR
How Canvas works

Two scenarios need to be distinguished: software development and hosting

AspectSoftware developmentOperations (hosting)
AI model in use
Model choiceChoice of several models (local and cloud) no model in use
ProcessesSource code, schemas, build artifactsYour application data in live operation
Real personal data in the normal case
Anonymization modulenot applicable
Synthetic data generationnot applicable
Processing inGermany / EUGermany / EU

In normal operation, an AI model processes only code, not real personal data. Which data ends up in which environment is your decision and responsibility as the controller; Canvas separates development, staging and production environments and provides the controls to keep real data out of development. If real data does reach an AI model there, for example during debugging, the model choice becomes relevant for data protection.

Data residency & hosting

Your data stays in Germany

Processing and storage exclusively in Germany or the EU/EEAStandard
Hosted by Hetzner Online GmbH, GermanyDE
Transfer to a third country in the default configurationnone

For details, see the data processing agreement (DPA) (Section 11, Annexes AVV-2 to AVV-4).

AI models & data protection

A local model as the default, residency transparent per model

Canvas offers a choice of AI models for software development that you can enable per project. By default we use a self-hosted Qwen on German servers.
External models are used exclusively via EU regions and EU legal entities, never via US endpoints. Your data is not used for training.

ModelPurposeProvider / routeResidency
QwenCode generation (builder agent)Self-hosted on Canvas infrastructureLocal, Germany
MistralImage recognition, e.g. screenshots during developmentMistral AI, API in the EUEU (France)
Claude (Anthropic)More powerful model, optionalAWS Bedrock, EU regionEU

You control the model selection per repository, with a visible privacy profile for each model. Processing outside the EU only happens if you explicitly choose it for an application, and then under appropriate safeguards (SCCs / EU-US DPF).

Each model has a detail page with versions, data paths and evidence: Qwen (local), Mistral (EU), Claude via AWS Bedrock (EU).

Technical & organizational measures

Security under Art. 32 GDPR

CategoryMeasures
Infrastructure
  • Hosting and data residency exclusively in Germany or the EU/EEA
  • Tenant separation across all environments, dedicated services in production
  • Encryption at rest (AES-256)
  • Encrypted WireGuard network overlay, "default-deny" per tenant
  • Encrypted, tenant-separated backups, off-site in Germany
Organization
  • Personnel bound to confidentiality, training and awareness
  • Role and permission concept, personal accounts only
  • Documented architecture decisions and security incident procedures
  • Management and contractual binding of subprocessors
Access & transfer
  • Internal role-based access control on the least-privilege principle
  • Privileged Canvas access with multi-factor authentication, via dedicated, encrypted company devices and a private network overlay; no public exposure
  • Transport encryption (TLS); secrets encrypted and managed outside the code
Product security
  • Security and quality gates before changes are merged (secret scanning, configuration checks)
  • Runtime threat detection with automatic response
  • Logging with a retention of 30 or 90 days
  • Privacy by default: isolation, "default-deny", minimal permissions

Full list of measures: DPA, Annex AVV-2.

Subprocessors

Who is involved

ProviderPurposeLocationThird-country transfer
Hetzner Online GmbHInfrastructure hostingGermanynone
Mistral AIImage recognition (screenshots during development)EU (France)none
Amazon Web Services (Bedrock)Claude model (Anthropic), optionalEU regionnone

We announce changes at least 30 days in advance; you have a right to object for important data protection reasons (DPA Section 6, Annex AVV-3).

Data subject rights, deletion & incidents

Control stays with you

Legal documents & contact

Everything in writing

Questions about privacy and security: support@canvas.software. Responsible entity: Canvas AILabs GmbH, Knorrpromenade 8, 10245 Berlin, HRB 289368 (Amtsgericht Charlottenburg).