Late on a Friday night in July, someone signed up for Canner and uploaded a cloned sign-in page — a pixel-faithful copy of a well-known cloud service's login screen, built to collect other people's passwords. We caught it and took it down within fifteen minutes. It didn't matter. The crawler had already been by, and because customer apps were served as subdomains of our main domain, Google Safe Browsing flagged the parent. By the time we'd finished, Chrome was showing a full-page red Dangerous site warning on our marketing site, our dashboard, and every application our customers hosted with us.
Removing the content was the fast part. What consumed the rest of the weekend — two overnight security reviews, a stolen identity three time zones away, and a second wave of abuse that arrived before the first was resolved — is the part worth writing down. It says something uncomfortable about how much of a Canadian company's reach is decided somewhere else.
The flag was correct
Everything after this depends on one admission: Google was right. There was genuine credential-harvesting content on our infrastructure, and someone who reached that page could have lost the keys to their email and everything behind it. We would rather be caught than missed.
Nor was Google at fault for our being a target. Fast signup and instant deploys are useful to a developer in Trois-Rivières and, unavoidably, to someone assembling a phishing kit. Managing that is our job, and we have done a good deal of it. So this isn't a complaint about being flagged — it's an account of what being flagged did.
Two reviews after midnight
With the content gone and the platform swept, we did the only thing the process allows: submitted the domain for review, and waited.
The first result came back late that night — failed. The strange part was where it pointed. The sample URLs weren't the phishing; they were two pages of our own internal tooling — the console our team uses to inspect a held deployment. It had been doing its job a little too well, faithfully displaying the captured markup of the cloned page so a human could examine it. And to an automated classifier, a page rendering a cloned login form is a cloned login form. We had briefly reproduced the thing we were removing.
We rebuilt the tool so it never renders captured markup — evidence stays redacted and behind an explicit click. We tried to reply to the review to explain; the reply errored. The warning cleared on its own — and then, about twenty-six hours after the page had first gone live, a second flag landed and put the wall back up.
There is a particular texture to refreshing a security console after midnight to find a decision you can't speak to reversed, then reinstated, on a clock you don't control. None of it was malicious. It simply wasn't built to include us.
The name on the account
One detail from that first night stayed with us more than the outage did.
The account behind the phishing had signed up with a real email address — one that belonged to a known academic in Poland. She hadn't done any of this. Her email had been compromised and used as a ready-made, already-trusted identity: a working mailbox clears signup verification, which is exactly what makes a stolen one worth having. She was the first victim, before anyone's password was ever at risk.
So we tried to warn her — deliberately not through the address on the account, since whoever controlled that inbox was the problem. We reached her university department and asked them to pass word to her directly.
It is a small thing against a credential operation of that scale. But it is the part of the weekend we are least conflicted about. Upstream of the flag and the interstitial and the review queue was a real person whose name was being used, and none of the systems adjudicating this had a slot for her at all.
The sequel
Abuse doesn't arrive once and stop. Before the weekend was out, two fresh accounts stood up twenty near-identical sites between them — a gambling network of the kind built for search engines rather than people, each page quietly funnelling visitors elsewhere.
This time we saw the shape of it almost immediately, took all twenty offline, and suspended both accounts the same day — then tightened detection so the next network like it trips automatically instead of on a second glance. It was the clearest proof we got that the hardening we'd done under pressure worked: the second wave never reached the point the first one did.
One decision, three systems
Here is the structural fact the weekend made concrete. A Safe Browsing determination isn't a website warning; it is an input to an ecosystem, and it reached three unrelated parts of our business at once.
The browser.Chrome carries roughly two-thirds of the global market, and the same list feeds Firefox and Safari. A flag isn't a ranking penalty you optimise around — it is an interstitial engineered so visitors don't click through. A customer whose storefront runs on us was effectively closed for the duration, having done nothing.
The advertising.Our ad account was flagged in turn, for pointing at a “compromised destination.” The acquisition channel switched off at the same instant as the site — the same company adjudicating both, on the same signal.
The email. Mail carrying our domain became far likelier to be filtered. The message we most needed to send — telling customers what had happened and that their data was untouched — was itself degraded by the flag it was about. There is something absurd about an incident notice that the incident makes undeliverable.
Three systems, one decision, no review between them — because there is no independence to invoke. It is one company operating the browser, the ad market, and, through Gmail, much of where the mail lands.
The asymmetry
What stings is the shape. We removed the cause in fifteen minutes. Restoring what the flag disabled was never ours to schedule: you submit a request and wait — a day, sometimes more — with no queue position, no case officer, no one to tell the content is gone, here is the evidence before the re-crawl gets to you.
Set that beside a domestic regulator. If a Canadian authority ordered a business shut for a day and a half, there would be a statutory basis, a named decision-maker, a right of reply, an appeal, and a remedy if they were wrong. None of that exists here — not through bad faith, but because the mechanism was never built to contain it. Our ability to serve Canadian customers, on Canadian hardware, under Canadian law, was suspended and restored on a timetable set entirely outside the country.
Why this is a sovereignty problem, not a Google problem
It would be easy, and wrong, to read this as an argument against Safe Browsing. The list is a public good, phishing is a real harm, and the flag was accurate.
The problem is concentration. A single foreign company's automated judgment can, in one motion, make a Canadian business unreachable in the dominant browser, unable to advertise, and unable to reliably email its own customers — with no domestic equivalent at any layer. No Canadian browser, no ad market of consequence, no mail-reputation system. When the judgment is right, we absorb it and improve, which is what we did. When it is wrong, the same machinery applies with the same force, and the recourse is identical: submit a form, wait.
We usually argue sovereignty in terms of data — where it lives, whose courts can compel it. That is right but incomplete. Data residency is one dependency; reachabilityis another, and more immediate. It does not matter whose jurisdiction your database sits in if a browser elsewhere decides your visitors shouldn't arrive. A clinic, a credit union, a municipality all sit on the same dependency, and most find out the way we did.
What we changed
Structural problems want structural answers. Two shipped.
Customer apps moved to their own domain. Safe Browsing judges a registrable domain as a unit — which is exactly why one page reached everyone. Customer applications now live at your-project.canner.app, wholly separate from our main site, so a future incident is contained to the app that caused it. Existing apps keep their old address for good.
Deploys are checked before they go live. Every build now passes a pre-publication scan for the fingerprints of credential-harvesting and doorway content, alongside the sandboxing and abuse controls already in the pipeline. Anything suspicious is held and never published, pending a human. We tuned it against real abuse and every legitimate site we host — it catches the bad and holds none of the good, and, as the gambling network found, it now trips on the second wave, not just the first.
Neither makes us immune; determined abuse gets through on every platform, including the ones a thousand times our size. What they change is the blast radius, and how fast we see it.
The honest conclusion
We were hosting phishing. We were flagged for it. Both true, neither unfair.
And yet: a Canadian company, serving Canadian customers on hardware in Quebec, had its website, its advertising, and its email switched off together by one automated decision made elsewhere — and switched back on when that decision was revisited on someone else's schedule. Every step was defensible. The aggregate is a small business with little say in whether it can be reached, and an academic an ocean away who never knew her name was on any of it.
We built Canner because we think it matters where infrastructure lives and whose law governs it. This weekend taught us the dependency is wider than the database. It runs through the browser that renders your site, the market that sells your ads, and the filter that decides whether your mail arrives. We have reduced our exposure where we can. Most of it is not ours to reduce — and that, more than any complaint about being caught, is the thing worth talking about.