Skip to main content
Canopus Bank — Less friction. More progress.
Why Canopus Investors Partners Future customers Governance
The friction question Insights Regulatory position
Start a conversation
Legal and regulatory

Security and responsible disclosure

We welcome good-faith reports that help protect the website and its visitors.

Effective: 31 July 2026Website: www.canopusbank.com

On this page

1. How to report2. Scope3. Good-faith testing rules4. What you can expect5. Good-faith assurance6. Rewards and recognition7. Fraud, impersonation and urgent concerns

1. How to report

Email suspected vulnerabilities to security@canopusbank.com. Include the affected URL or component, a clear description, reproducible steps, observed impact and any safe evidence available.

Do not include unnecessary personal data, credentials, private keys or data obtained from other users.

2. Scope

This policy currently covers the public website at www.canopusbank.com and first-party assets served from that domain. It does not authorise testing of third-party providers, email infrastructure, regulators, advisers or unrelated systems.

3. Good-faith testing rules

Please:

  • avoid accessing, changing, deleting or exfiltrating data that is not your own;
  • stop testing and report promptly if sensitive data becomes visible;
  • avoid denial-of-service, traffic flooding, spam, social engineering, physical intrusion or malware;
  • use the minimum testing necessary to demonstrate the issue;
  • do not publicly disclose an unresolved vulnerability before a reasonable remediation period and coordinated discussion;
  • comply with applicable law.

4. What you can expect

We aim to acknowledge credible reports, assess severity, request clarification where necessary and communicate a remediation path. Response times may vary because the project is pre-launch and not operated as a live bank.

5. Good-faith assurance

Where you comply with this policy and applicable law, we do not intend to pursue action solely for the authorised security research described here. This statement is not a waiver by third parties and cannot authorise conduct that the law prohibits.

6. Rewards and recognition

No bug-bounty payment or reward is promised. Any acknowledgement is discretionary and subject to legal, confidentiality and security considerations.

7. Fraud, impersonation and urgent concerns

Report suspected impersonation, fraudulent payment requests or misuse of the Canopus name to the same security address. Do not send funds or credentials in response to unsolicited communications.

Canopus Bank

A proposed Seychelles banking project being designed to reduce the institutional friction between money, trust, governance and international business.

For you
Investors Partners Future customers Contact
Explore
Why Canopus The friction question Governance Insights
Connect

investors@canopusbank.com
Investor relations

partners@canopusbank.com
Partnership opportunities

hello@canopusbank.com
General enquiries

Pre-launch regulatory notice: Canopus Bank is a proposed Seychelles banking project in development. It is not currently authorised to conduct banking business, accept deposits, provide payment services or offer virtual asset services. Any launch or service remains subject to incorporation, licensing and regulatory approvals. Nothing on this website is an offer, solicitation, recommendation or financial advice.
© 2026 Canopus Bank. All rights reserved.
Terms of use Privacy Cookies Accessibility Security Complaints

This website uses essential browser storage to remember your cookie choice. No advertising cookies are used, and analytics are disabled in this build.

Privacy by design

Cookie settings

We have kept the default deliberately simple. This build uses only essential local storage to retain your preference. It does not activate advertising, behavioural profiling or third-party analytics.

Essential storageAlways active

Stores the fact that you have made a cookie choice. It is not used to identify you across other websites.

Read the cookie notice