What can Canadian security companies legally claim in marketing?
Canadian law does not ban bold security marketing. It bans claims that mislead, and it requires a proper test behind any statement about how well a product performs. This page explains what that means for words like unhackable, 100% protection and military-grade, and how to keep the evidence ready before anyone asks.
What can Canadian security companies legally claim in marketing?
Anything that is true, not misleading in its overall impression, and, where it describes performance or effectiveness, backed by an adequate and proper test completed before the claim went public. That rules out most absolute statements such as "unhackable" or "stops all ransomware", because no test can show a product defeats every attack.
Statements about features, integrations, certifications you actually hold, and dated results from a described test are generally fine. The risk sits in superlatives, totals and words that imply a level of protection nobody has measured. This is general information, not legal advice; check with counsel.
ShoutEx view: security vendors are unusually exposed here. Buyers in the category read claims for a living, competitors watch each other closely, and a single incident at a customer can turn last year's tagline into evidence. Getting the claims right is also how you earn trust with the engineers who evaluate you, which is the theme of messaging without fear.
Which parts of the Competition Act apply to security claims?
Two paragraphs of section 74.01 of the Competition Act do most of the work. Paragraph (1)(a) covers any representation to the public that is false or misleading in a material respect. Paragraph (1)(b) covers a representation about the performance, efficacy or length of life of a product that is not based on an adequate and proper test, and it puts the proof on the person making the representation.
For a security company, almost every product claim is a performance claim: detection rates, response times, blocked attacks, reduced alert volume, time to deploy. Under (1)(b) the question is not whether the claim turned out to be true, but whether a proper test existed when you made it.
The Competition Bureau's guidance on performance claims sets out what that means in practice:
- Timing. The test must be done before the claim is made, not assembled after a complaint.
- Where claims live. Labels, websites, social media, metadata keywords and online ads all count, so hidden keyword fields and alt text are in scope.
- What a proper test looks like. Controlled, limiting subjective judgment, reflecting real use, and supporting the general impression of the ad.
- What does not count. Broad claims drawn from partly relevant tests, results that may be due to chance, evidence from similar products, technical manuals or anecdotes.
- The key question. The Bureau asks advertisers to consider: "What is the general impression conveyed by my ad?"
General impression matters most for security copy. A footnote saying "in internal testing" does not rescue a headline that says "blocks every phishing attack", because the headline is what a reader takes away.
Which security claims cause the most trouble?
The riskiest claims are totals, guarantees and borrowed authority. The table pairs each with what you would need to show and a narrower wording to consider. The rewrites illustrate form only; each still needs its own evidence.
| Claim on the page | Why it is risky | What you would need on file | Narrower wording to consider |
|---|---|---|---|
| "Unhackable" or "hack-proof" | Implies no possible compromise; no test can show that | Nothing would be enough | Describe the specific control, such as hardware-backed keys for admin accounts |
| "Stops all ransomware" | A total across an open-ended, changing set of threats | A test against every variant, which cannot exist | "Detected the encryption behaviour in each of the 60 samples we tested in May 2026" (illustrative) |
| "100% protection" | A measured-sounding number with no method behind it | A defined scope where 100% was actually observed | State the scope, sample and date, or drop the number |
| "Military-grade encryption" | Borrowed authority with no defined meaning | Nothing specific to point to | Name the algorithm, key length and who controls the keys |
| "Detects threats 10x faster" | A comparison needs a fair, documented test against a named baseline | Test design, baseline, dataset, dates, results | "Median alert time of 4 minutes in our June 2026 test of 200 simulated intrusions" (illustrative) |
Illustrative example written by ShoutEx for this guide, not a benchmark. Short formats raise the stakes, because there is no room for context. Compare two search ads for the same fictional cloud posture product.
Military-grade protection for every cloud. Never breached. Start your trial today.
- "#1" is a ranking with no source; "eliminates all" is a total no scan can prove.
- "Guaranteed compliance" promises an audit outcome the vendor does not control.
- "Never breached" describes the vendor, not the product, and can age overnight.
Find risky cloud settings across accounts. See which checks we run and how we test them.
- Says what the product does and where it works.
- Points to the list of checks and the method rather than a total.
- The price claim only works if the advertised price really includes every mandatory fee.
How do you build a claim-substantiation file?
Keep one folder, owned by marketing and reviewed by product and legal, with an entry for every performance claim in public use. The point is speed: when a prospect, a journalist, a competitor or the Bureau asks, you can show the evidence the same day.
- Inventory the claims. Website, ads, marketplace listings, decks, datasheets, analyst briefings, metadata keywords and alt text.
- Classify each one. Feature fact, certification, customer statement or performance claim. Only the last needs a test record.
- Attach the test. Method, dataset or scenario, dates, who ran it, raw results, and any limits the tester noted.
- Check the general impression. Read the claim cold. Does the headline promise more than the test showed?
- Set an expiry. Threats and products change, so give every test a review date and retire claims past it.
- Log approvals. Who signed off, when, and which version of the copy.
| Field | Example entry |
|---|---|
| Claim text | "Flagged 58 of 60 credential-phishing samples in our April 2026 test" |
| Where it appears | Homepage hero, Google Ads headline set B, product datasheet v3 |
| Test method | Controlled replay of 60 samples against default policy, no tuning |
| Dataset | Samples collected January to March 2026, list held by research team |
| Run by | Internal research team; method reviewed by an outside tester |
| Review date | October 2026 |
| Approved by | Head of product, counsel, head of marketing |
Write the claim from the test report, never the other way round.
Marketing teams often draft the headline first and ask product to find evidence later. Reverse it: read what the test actually showed, then write the strongest sentence that test supports.
What are the penalties, and who can bring a case?
The Bureau's performance claims guidance lists administrative monetary penalties for individuals of up to the greater of $750,000 ($1 million for each later order) or 3 times the benefit, and for corporations up to the greater of $10 million ($15 million for each later order) or 3 times the benefit, or 3% of annual worldwide gross revenues if the benefit cannot be determined. Those are maximums, not typical outcomes, but they make the cost of a careless tagline real.
Enforcement no longer depends only on the Bureau. According to its guide to the June 2024 amendments, private access to the Competition Tribunal for deceptive marketing came into force on June 20, 2025, so competitors and others can bring cases themselves. In a crowded category where rivals read each other's websites closely, that changes the risk.
If you are unsure about a specific claim before a launch, the Commissioner offers binding written opinions for a fee under section 124.1. ShoutEx view: for most security marketing, a clear proof file and counsel's review of the few headline claims you rely on are the practical first steps.
Do pricing and discount rules apply to security software?
Yes. The drip pricing provision in subsection 74.01(1.1) treats a price that cannot be attained because of fixed obligatory charges or fees as false or misleading, unless the charges are imposed by federal or provincial law. For a SaaS vendor, that means the advertised monthly or per-seat price should already include any mandatory platform, onboarding or support fee.
The Bureau's 2024 guide also says businesses must be able to show that discount claims are genuine. A "was $X, now $Y" offer on a security plan needs records showing customers really paid the higher price. The same guide notes that environmental claims need substantiation, which matters if you market lower energy use for on-premises appliances.
How this plays out for trial-to-paid pricing is covered on free trials and PLG. If you list on cloud marketplaces, check that each listing price matches what customers pay, as described in partners and marketplaces. This is general information, not legal advice; check with counsel.
What should you track to keep claims clean?
Treat claims hygiene like patching: a regular cycle with a short list of numbers that show whether it is happening.
| Measure | Target | Where it lives |
|---|---|---|
| Performance claims with a test on file | All of them | Claim file |
| Claims past their review date | None | Claim file |
| Absolute or superlative words in live copy | None | Site and ad copy audit |
| Price claims that include every mandatory fee | All of them | Pricing page, ads, listings |
| Ads disapproved for claims | None | Ad platform policy reports |
| Sales slides using unapproved claims | None | Deck library review |
Positioning work makes this easier, because a company that has chosen its problem can make specific claims about it. See positioning for security companies and trust signals for the proof that sits alongside your claims.
Frequently asked questions
Is it illegal to call a security product unhackable?
It can breach the Competition Act if the claim is false or misleading in a material respect, and no test can show a product cannot be compromised. This is general information, not legal advice; check with counsel.
What is an adequate and proper test?
The Competition Bureau describes it as controlled, limiting subjective judgment, reflecting real use and supporting the general impression of the ad. It must be done before the claim is made.
Do the rules apply to metadata and keywords?
Yes. The Bureau's guidance says claims include labels, websites, social media, metadata keywords and online ads.
Can a competitor take us to the Competition Tribunal?
Since June 20, 2025, private parties, including competitors, can bring deceptive marketing cases to the Competition Tribunal, according to the Bureau's guide to the 2024 amendments.
What are the maximum penalties for misleading claims?
For corporations, up to the greater of $10 million ($15 million for each later order) or 3 times the benefit, or 3% of annual worldwide gross revenues if the benefit cannot be determined.
Does a footnote fix an absolute headline?
Usually not. The Bureau asks about the general impression of the ad, and a headline promising total protection sets that impression regardless of small print.
Can we say military-grade encryption?
It has no defined meaning, so it tells buyers nothing they can check. Name the algorithm, key length and who controls the keys instead.
Do SaaS prices have to include all fees?
Mandatory fees should be included in the advertised price unless they are imposed by federal or provincial law. Leaving them out is drip pricing under the Competition Act.
Can we get advance certainty on a claim?
The Commissioner offers binding written opinions for a fee under section 124.1 of the Competition Act. Ask counsel whether it suits your situation.
Who should own the claim file?
Marketing usually maintains it, product or research supplies the test evidence, and counsel reviews the claims you rely on most.
Sources & further reading
Regulations, platform policies and market data change. These sources let you check the facts on this page, last checked October 7, 2026.