Canadian rules and buyers

What can Canadian security companies legally claim in marketing?

Canadian law does not ban bold security marketing. It bans claims that mislead, and it requires a proper test behind any statement about how well a product performs. This page explains what that means for words like unhackable, 100% protection and military-grade, and how to keep the evidence ready before anyone asks.

By the ShoutEx Team · Updated October 2026 · Facts checked October 7, 2026
If a claim describes performance, the test comes first, the proof stays on file, and the wording matches what the test showed.Marketing for Cybersecurity Companies · Updated October 2026
s. 74.01
The Competition Act section on false or misleading representations and untested performance claims
$10 million
Maximum first-order penalty for a corporation, or 3 times the benefit if greater (Competition Bureau)
June 20, 2025
Date private parties gained access to the Competition Tribunal for deceptive marketing cases

What can Canadian security companies legally claim in marketing?

What can Canadian security companies legally claim in marketing?

Anything that is true, not misleading in its overall impression, and, where it describes performance or effectiveness, backed by an adequate and proper test completed before the claim went public. That rules out most absolute statements such as "unhackable" or "stops all ransomware", because no test can show a product defeats every attack.

Statements about features, integrations, certifications you actually hold, and dated results from a described test are generally fine. The risk sits in superlatives, totals and words that imply a level of protection nobody has measured. This is general information, not legal advice; check with counsel.

ShoutEx view: security vendors are unusually exposed here. Buyers in the category read claims for a living, competitors watch each other closely, and a single incident at a customer can turn last year's tagline into evidence. Getting the claims right is also how you earn trust with the engineers who evaluate you, which is the theme of messaging without fear.

Which parts of the Competition Act apply to security claims?

Two paragraphs of section 74.01 of the Competition Act do most of the work. Paragraph (1)(a) covers any representation to the public that is false or misleading in a material respect. Paragraph (1)(b) covers a representation about the performance, efficacy or length of life of a product that is not based on an adequate and proper test, and it puts the proof on the person making the representation.

For a security company, almost every product claim is a performance claim: detection rates, response times, blocked attacks, reduced alert volume, time to deploy. Under (1)(b) the question is not whether the claim turned out to be true, but whether a proper test existed when you made it.

The Competition Bureau's guidance on performance claims sets out what that means in practice:

  • Timing. The test must be done before the claim is made, not assembled after a complaint.
  • Where claims live. Labels, websites, social media, metadata keywords and online ads all count, so hidden keyword fields and alt text are in scope.
  • What a proper test looks like. Controlled, limiting subjective judgment, reflecting real use, and supporting the general impression of the ad.
  • What does not count. Broad claims drawn from partly relevant tests, results that may be due to chance, evidence from similar products, technical manuals or anecdotes.
  • The key question. The Bureau asks advertisers to consider: "What is the general impression conveyed by my ad?"

General impression matters most for security copy. A footnote saying "in internal testing" does not rescue a headline that says "blocks every phishing attack", because the headline is what a reader takes away.

Which security claims cause the most trouble?

The riskiest claims are totals, guarantees and borrowed authority. The table pairs each with what you would need to show and a narrower wording to consider. The rewrites illustrate form only; each still needs its own evidence.

Claim on the pageWhy it is riskyWhat you would need on fileNarrower wording to consider
"Unhackable" or "hack-proof"Implies no possible compromise; no test can show thatNothing would be enoughDescribe the specific control, such as hardware-backed keys for admin accounts
"Stops all ransomware"A total across an open-ended, changing set of threatsA test against every variant, which cannot exist"Detected the encryption behaviour in each of the 60 samples we tested in May 2026" (illustrative)
"100% protection"A measured-sounding number with no method behind itA defined scope where 100% was actually observedState the scope, sample and date, or drop the number
"Military-grade encryption"Borrowed authority with no defined meaningNothing specific to point toName the algorithm, key length and who controls the keys
"Detects threats 10x faster"A comparison needs a fair, documented test against a named baselineTest design, baseline, dataset, dates, results"Median alert time of 4 minutes in our June 2026 test of 200 simulated intrusions" (illustrative)

Illustrative example written by ShoutEx for this guide, not a benchmark. Short formats raise the stakes, because there is no room for context. Compare two search ads for the same fictional cloud posture product.

Example · risky vs scoped ad
cloud security posture management canada
Weak ad
Sponsored
BBluefjordbluefjord.example › cspm
#1 Cloud Security Platform | Eliminates All Misconfigs | Guaranteed Compliance

Military-grade protection for every cloud. Never breached. Start your trial today.

  • "#1" is a ranking with no source; "eliminates all" is a total no scan can prove.
  • "Guaranteed compliance" promises an audit outcome the vendor does not control.
  • "Never breached" describes the vendor, not the product, and can age overnight.
Stronger ad
Sponsored
BBluefjordbluefjord.example › cspm
Cloud Posture for AWS & Azure | Checks Mapped to CIS | Price Includes All Fees

Find risky cloud settings across accounts. See which checks we run and how we test them.

  • Says what the product does and where it works.
  • Points to the list of checks and the method rather than a total.
  • The price claim only works if the advertised price really includes every mandatory fee.
Weak vs stronger: the weak ad is deliberately non-compliant to show what to avoid. Bluefjord is fictional. More compliant copy across service types is on security ad examples.

How do you build a claim-substantiation file?

Keep one folder, owned by marketing and reviewed by product and legal, with an entry for every performance claim in public use. The point is speed: when a prospect, a journalist, a competitor or the Bureau asks, you can show the evidence the same day.

  1. Inventory the claims. Website, ads, marketplace listings, decks, datasheets, analyst briefings, metadata keywords and alt text.
  2. Classify each one. Feature fact, certification, customer statement or performance claim. Only the last needs a test record.
  3. Attach the test. Method, dataset or scenario, dates, who ran it, raw results, and any limits the tester noted.
  4. Check the general impression. Read the claim cold. Does the headline promise more than the test showed?
  5. Set an expiry. Threats and products change, so give every test a review date and retire claims past it.
  6. Log approvals. Who signed off, when, and which version of the copy.
Claim file entryOne row per performance claim in public use
FieldExample entry
Claim text"Flagged 58 of 60 credential-phishing samples in our April 2026 test"
Where it appearsHomepage hero, Google Ads headline set B, product datasheet v3
Test methodControlled replay of 60 samples against default policy, no tuning
DatasetSamples collected January to March 2026, list held by research team
Run byInternal research team; method reviewed by an outside tester
Review dateOctober 2026
Approved byHead of product, counsel, head of marketing
Illustrative example written by ShoutEx for this guide, not a benchmark.
ShoutEx rule

Write the claim from the test report, never the other way round.

Marketing teams often draft the headline first and ask product to find evidence later. Reverse it: read what the test actually showed, then write the strongest sentence that test supports.

What are the penalties, and who can bring a case?

The Bureau's performance claims guidance lists administrative monetary penalties for individuals of up to the greater of $750,000 ($1 million for each later order) or 3 times the benefit, and for corporations up to the greater of $10 million ($15 million for each later order) or 3 times the benefit, or 3% of annual worldwide gross revenues if the benefit cannot be determined. Those are maximums, not typical outcomes, but they make the cost of a careless tagline real.

Enforcement no longer depends only on the Bureau. According to its guide to the June 2024 amendments, private access to the Competition Tribunal for deceptive marketing came into force on June 20, 2025, so competitors and others can bring cases themselves. In a crowded category where rivals read each other's websites closely, that changes the risk.

If you are unsure about a specific claim before a launch, the Commissioner offers binding written opinions for a fee under section 124.1. ShoutEx view: for most security marketing, a clear proof file and counsel's review of the few headline claims you rely on are the practical first steps.

Do pricing and discount rules apply to security software?

Yes. The drip pricing provision in subsection 74.01(1.1) treats a price that cannot be attained because of fixed obligatory charges or fees as false or misleading, unless the charges are imposed by federal or provincial law. For a SaaS vendor, that means the advertised monthly or per-seat price should already include any mandatory platform, onboarding or support fee.

The Bureau's 2024 guide also says businesses must be able to show that discount claims are genuine. A "was $X, now $Y" offer on a security plan needs records showing customers really paid the higher price. The same guide notes that environmental claims need substantiation, which matters if you market lower energy use for on-premises appliances.

How this plays out for trial-to-paid pricing is covered on free trials and PLG. If you list on cloud marketplaces, check that each listing price matches what customers pay, as described in partners and marketplaces. This is general information, not legal advice; check with counsel.

What should you track to keep claims clean?

Treat claims hygiene like patching: a regular cycle with a short list of numbers that show whether it is happening.

Claims hygiene trackerReview every quarter and before major launches
MeasureTargetWhere it lives
Performance claims with a test on fileAll of themClaim file
Claims past their review dateNoneClaim file
Absolute or superlative words in live copyNoneSite and ad copy audit
Price claims that include every mandatory feeAll of themPricing page, ads, listings
Ads disapproved for claimsNoneAd platform policy reports
Sales slides using unapproved claimsNoneDeck library review
Source: ShoutEx planning template for Canadian security companies.

Positioning work makes this easier, because a company that has chosen its problem can make specific claims about it. See positioning for security companies and trust signals for the proof that sits alongside your claims.

Frequently asked questions

Is it illegal to call a security product unhackable?

It can breach the Competition Act if the claim is false or misleading in a material respect, and no test can show a product cannot be compromised. This is general information, not legal advice; check with counsel.

What is an adequate and proper test?

The Competition Bureau describes it as controlled, limiting subjective judgment, reflecting real use and supporting the general impression of the ad. It must be done before the claim is made.

Do the rules apply to metadata and keywords?

Yes. The Bureau's guidance says claims include labels, websites, social media, metadata keywords and online ads.

Can a competitor take us to the Competition Tribunal?

Since June 20, 2025, private parties, including competitors, can bring deceptive marketing cases to the Competition Tribunal, according to the Bureau's guide to the 2024 amendments.

What are the maximum penalties for misleading claims?

For corporations, up to the greater of $10 million ($15 million for each later order) or 3 times the benefit, or 3% of annual worldwide gross revenues if the benefit cannot be determined.

Does a footnote fix an absolute headline?

Usually not. The Bureau asks about the general impression of the ad, and a headline promising total protection sets that impression regardless of small print.

Can we say military-grade encryption?

It has no defined meaning, so it tells buyers nothing they can check. Name the algorithm, key length and who controls the keys instead.

Do SaaS prices have to include all fees?

Mandatory fees should be included in the advertised price unless they are imposed by federal or provincial law. Leaving them out is drip pricing under the Competition Act.

Can we get advance certainty on a claim?

The Commissioner offers binding written opinions for a fee under section 124.1 of the Competition Act. Ask counsel whether it suits your situation.

Who should own the claim file?

Marketing usually maintains it, product or research supplies the test evidence, and counsel reviews the claims you rely on most.

Sources & further reading

Regulations, platform policies and market data change. These sources let you check the facts on this page, last checked October 7, 2026.