The Trust Center collects all the facts about data residency, security and data processing in one place.
| Aspect | Software development | Operations (hosting) |
|---|---|---|
| AI model in use | ||
| Model choice | Choice of several models (local and cloud) | no model in use |
| Processes | Source code, schemas, build artifacts | Your application data in live operation |
| Real personal data | in the normal case | |
| Anonymization module | not applicable | |
| Synthetic data generation | not applicable | |
| Processing in | Germany / EU | Germany / EU |
In normal operation, an AI model processes only code, not real personal data. Which data ends up in which environment is your decision and responsibility as the controller; Canvas separates development, staging and production environments and provides the controls to keep real data out of development. If real data does reach an AI model there, for example during debugging, the model choice becomes relevant for data protection.
For details, see the data processing agreement (DPA) (Section 11, Annexes AVV-2 to AVV-4).
Canvas offers a choice of AI models for software development that you can enable per project. By default we use a self-hosted Qwen on German servers.
External models are used exclusively via EU regions and EU legal entities, never via US endpoints. Your data is not used for training.
| Model | Purpose | Provider / route | Residency |
|---|---|---|---|
| Qwen | Code generation (builder agent) | Self-hosted on Canvas infrastructure | Local, Germany |
| Mistral | Image recognition, e.g. screenshots during development | Mistral AI, API in the EU | EU (France) |
| Claude (Anthropic) | More powerful model, optional | AWS Bedrock, EU region | EU |
You control the model selection per repository, with a visible privacy profile for each model. Processing outside the EU only happens if you explicitly choose it for an application, and then under appropriate safeguards (SCCs / EU-US DPF).
Each model has a detail page with versions, data paths and evidence: Qwen (local), Mistral (EU), Claude via AWS Bedrock (EU).
| Category | Measures |
|---|---|
| Infrastructure |
|
| Organization |
|
| Access & transfer |
|
| Product security |
|
Full list of measures: DPA, Annex AVV-2.
| Provider | Purpose | Location | Third-country transfer |
|---|---|---|---|
| Hetzner Online GmbH | Infrastructure hosting | Germany | none |
| Mistral AI | Image recognition (screenshots during development) | EU (France) | none |
| Amazon Web Services (Bedrock) | Claude model (Anthropic), optional | EU region | none |
We announce changes at least 30 days in advance; you have a right to object for important data protection reasons (DPA Section 6, Annex AVV-3).
Questions about privacy and security: support@canvas.software. Responsible entity: Canvas AILabs GmbH, Knorrpromenade 8, 10245 Berlin, HRB 289368 (Amtsgericht Charlottenburg).