Compliance
Last updated: September 11, 2026
CanRouter AI is a Canadian reseller of AI services provided by our upstream partners (OpenAI, Google, Meta, Anthropic, xAI, Nous Research, DeepSeek, Alibaba (Qwen), ByteDance (Doubao), Z.AI (GLM), Moonshot (Kimi), MiniMax, Tencent (Hunyuan), Baidu (ERNIE), iFlytek (Spark), Xiaomi, 01.AI, Black Forest Labs (FLUX), Midjourney, Kuaishou (Kling), PixVerse, Shengshu (Vidu), Suno, SiliconFlow, and other model vendors served through our partner platform). This page documents our compliance program openly and completely — for our customers, our partners, and anyone evaluating us. If something on this page is inaccurate or unclear, tell us and we will fix it: [email protected].
Our reseller obligations and how we meet them
As a reseller we commit to six obligations. Each is listed below with exactly what we do in practice.
1. Customer reviews and intended use cases
- Every registration must describe the intended use case (minimum 20 characters) and explicitly accept the Acceptable Use Policy — acceptance is recorded with a timestamp and the policy version (currently 1.0).
- New accounts enter a pending review state and are reviewed by our staff against the intended use case. Accounts can be used while the review is underway; this is disclosed here so the process is transparent.
- Approval confirms the account. Rejection disables the account and revokes all active sessions and API keys immediately.
- Customers who registered before this program was introduced were reviewed and grandfathered as approved.
- Every review decision is audit-logged with the reviewer, timestamp, and decision note.
2. Preventing credential sharing, abuse, fraud, and prohibited content
- The Acceptable Use Policy explicitly prohibits credential sharing: keys and accounts are personal and must never be shared, sold, or resold.
- API keys can be bound to an IP allowlist, so a leaked key is unusable from other networks.
- Rate limits are enforced per API key and per account (requests and tokens per minute), and spending caps are enforced per key and per month per account.
- A content moderation endpoint is available for screening, and prohibited content categories are listed in the AUP.
- Keys can be revoked instantly by the customer or by our staff; all administrative actions are audit-logged.
3. First-line technical and customer support in Canada
- Our first-line support team is based in Canada and is the initial point of contact for account, billing, and API issues.
- Support hours: 9:00–17:00 Eastern Time, Monday through Friday.
- Response targets: within 1 business day for normal tickets, within 4 business hours for service-down or billing-blocked issues.
- Tickets can be opened from the dashboard or by email; complex upstream issues are escalated to the provider on your behalf.
4. Managing customer access, security, and usage limits
- Account status is managed by staff: disabled accounts cannot log in and cannot call the API.
- API keys support enable/disable, revocation, expiry dates, model allowlists, RPM limits, and spending caps — all visible to the customer in the dashboard.
- Account-level monthly spend caps stop all billable API usage once the limit is reached.
- Administrative changes to accounts, balances, and keys are audit-logged.
5. Canadian privacy and data protection (PIPEDA)
- We operate in alignment with the Personal Information Protection and Electronic Documents Act (PIPEDA): data minimization, stated purposes, retention limits, and safeguards appropriate to sensitivity.
- Passwords are stored only as Argon2id hashes; API key secrets only as one-way hashes shown once; upstream credentials encrypted at rest.
- You may request access to, correction of, or withdrawal of consent for your personal information; we respond within 30 days.
- Full details, including data residency and escalation to the Office of the Privacy Commissioner of Canada, are in the Privacy Policy.
6. Ensuring customers understand and comply with usage restrictions
- Acceptance of the Acceptable Use Policy is a required, separate step at registration — recorded with timestamp and version.
- The AUP is published at all times and states the prohibited content categories, the credential-sharing prohibition, and the enforcement ladder.
- Continued use of the service constitutes acceptance of the usage restrictions; violations are handled through the enforcement ladder described in the AUP.
Platform capability disclosure
Capabilities our partner and customers may ask about, with honest status. We do not claim anything we have not built.
Customer-level API keys
ImplementedEach customer account can create, restrict, and revoke its own API keys (dashboard and API), with per-key limits, model allowlists, and IP allowlists.
Separate customer accounts
ImplementedEvery customer has an isolated account with its own balance, ledger, API keys, usage history, and support tickets.
Automated usage and billing APIs
ImplementedProgrammatic usage, logs, balance, and top-up endpoints, plus signature-verified payment webhooks; the dashboard shows the same figures as the ledger.
Enterprise rate limits
ImplementedPer-key RPM, per-account RPM and TPM, per-model RPM, and per-IP RPM limits, configurable per customer.
Per-customer budgets and spending limits
ImplementedMonthly account spend caps and per-key spending limits, both enforced at request time.
White-label or co-branded services
Not implementedNot offered today. Customers use the CanRouter AI platform and API surface as published.
Dedicated channels or resources
Not implementedAll customers share the same upstream capacity and routing today; no dedicated channels are sold.
Financial integrity
All billing is ledger-backed and auditable: every balance change has a corresponding immutable transaction record with idempotency guarantees, so credits can never be awarded or consumed twice. Refunds are processed through the same ledger with a full audit trail.
Security practices
Passwords are hashed with Argon2id; API keys are stored as one-way hashes; upstream credentials are encrypted at rest; all administrative actions are audit-logged; security headers are enforced on every response.
Export controls
The service may be subject to export control laws. Customers must not use the service in sanctioned jurisdictions or for sanctioned end uses.
Related documents
- Acceptable Use Policy — prohibited content, credential sharing, enforcement ladder.
- Privacy Policy — PIPEDA alignment, data residency, retention, and your rights.
- Support — Canada-based first-line support, hours, and response targets.
- Data Processing Agreement — available for customers who require it.
Contact
Compliance questions: [email protected]. We respond to lawful requests in accordance with applicable law.