Security vulnerability disclosure policy
Last updated: September 12, 2026
Introduction
Updated for 2026 Canadian Security StandardsTridacom IT Solutions (“we,” “us,” “our,” “Tridacom”) is committed to ensuring the security of our users and their data. This Security Vulnerability Disclosure Policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities and to convey our preferences for submitting discovered vulnerabilities to us.
We encourage you to read this policy carefully before attempting to discover vulnerabilities or submitting reports.
Policy purpose
This policy describes:
Scope
This policy applies to the following systems and services owned, operated, or maintained by Tridacom IT Solutions:
In-scope systems:
- *.tridacom.com - Our primary domain and all its subdomains
- *.tridacomit.com - Secondary domain and all its subdomains
- tridacom.ca and the following subdomains:
- app.tridacom.ca
- portal.tridacom.ca
- api.tridacom.ca
- Tridacom public source-code repositories. Contact our security team for the current repository URL and to confirm scope before testing.
- Mobile applications developed and released by Tridacom
Out of scope systems
Any service not expressly listed above is excluded from scope and is not authorized for testing. This includes third-party services we use but do not control directly. Vulnerabilities found in systems from our vendors should be reported directly to the vendor according to their disclosure policy.
Though we develop and maintain other internet-accessible systems or services, we ask that active research and testing only be conducted on the systems and services covered by the scope of this document. If there is a particular system not in scope that you think merits testing, please contact us at security@tridacom.com to discuss it first.
Guidelines
Under this policy, "research" means activities in which you:
Acceptable testing activities
- Notify us as soon as possible after you discover a real or potential security issue
- Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data
- Only use exploits to the extent necessary to confirm a vulnerability's presence
- Provide us a reasonable amount of time to resolve the issue before you disclose it publicly
- Perform testing only on in-scope systems, and respect systems and activities which are out-of-scope
Prohibited activities
The following test methods are not authorized:
- Network denial of service (DoS or DDoS) tests
- Physical testing (e.g., office access, open doors, tailgating)
- Social engineering (e.g., phishing, vishing)
- Any test types that might harm the reliability or integrity of our systems
- Tests that impact other users or customers of our systems
- Tests on systems or applications that are not explicitly listed as in-scope
Important notice
Once you've established that a vulnerability exists or encounter any sensitive data (including personally identifiable information, financial information, or proprietary information or trade secrets of any party), you must stop your test, notify us immediately, and not disclose this data to anyone else.
Reporting a vulnerability
We accept vulnerability reports through the following channels:
Email submission
For standard vulnerability reports
Send your reports to security@tridacom.com
For a report containing sensitive details, contact security@tridacom.com first to arrange a suitable way to share it.
What we need in your report
To help us triage and prioritize submissions, we recommend that your reports include:
- Vulnerability description - Describe the location the vulnerability was discovered and the potential impact of exploitation
- Reproduction steps - Detailed description of the steps needed to reproduce the vulnerability (proof of concept scripts or screenshots are helpful)
- Impact - Your assessment of the severity and potential impact of the vulnerability
- Suggested mitigation - If possible, include suggestions for how to fix or mitigate the vulnerability
- Contact information (optional) - We accept anonymous reports, but including your contact information helps us collaborate with you if we need additional information
Disclosure timeline
We follow industry standard practices for vulnerability disclosure timelines:
Our expectations
When you choose to share your contact information with us, we commit to the following:
Timely acknowledgment
We will acknowledge receipt of your vulnerability report within 1-2 business days and provide you with a reference number for tracking.
Transparent communication
To the best of our ability, we will confirm the existence of the vulnerability and be transparent about the steps we are taking during the remediation process, including issues or challenges that may delay resolution.
Open dialogue
We will maintain an open dialogue with you to discuss issues and keep you informed about our progress addressing the vulnerability.
Privacy and confidentiality
We will protect your personal information and keep your identity confidential unless you permit us to identify you.
Information sharing
Information submitted under this policy will be used for defensive purposes only – to mitigate or remediate vulnerabilities. If your findings include newly discovered vulnerabilities that affect all users of a product or service and not solely Tridacom, we may share your report with the Canadian Centre for Cyber Security or affected vendors, where it will be handled under their coordinated vulnerability disclosure process. We will not share your name or contact information without express permission.
Researcher protection
Tridacom IT Solutions is committed to protecting security researchers who make good faith efforts to comply with this policy. We recognize the valuable role that the security research community plays in helping us maintain the security of our systems.
Our commitment to researchers
- No legal action - We will not pursue or recommend legal action against researchers who act in good faith and comply with this policy
- Support against claims - If a third party initiates legal action against you for activities consistent with this policy, we will make clear that your actions were authorized
- Public recognition (optional) - With your permission, we may publicly acknowledge your contribution to our security
- Responsible handling - We will handle vulnerability reports with appropriate care and attention to ensure your research does not increase risk
- Clear guidance - We provide clear scope and guidelines to help you conduct research safely and legally
Safe harbor
When conducting vulnerability research according to this policy, we consider this research to be:
- Authorized by Tridacom within the scope of this policy for systems we own or control. This authorization does not bind third parties or guarantee protection from criminal prosecution.
- Exempted from restrictions in our applicable Terms of Service and/or Acceptable Use Policy that would interfere with conducting security research
- Allowed under the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls
- Exempt from restrictions in our Terms & Conditions that would prohibit you from reporting security vulnerabilities
Limitation of authority
Please note that if your security research involves the networks, systems, information, applications, products, or services of another entity (such as our service providers or customers), that third-party may determine its own response to security reports, which may include legal action. We cannot and do not authorize security research in the name of other entities.
Regulatory compliance
Tridacom IT Solutions prioritizes compliance with applicable laws and industry standards for handling security vulnerabilities. This policy has been developed to align with:
Canadian standards and requirements
- Personal Information Protection and Electronic Documents Act (PIPEDA) - We ensure all vulnerability research adheres to Canadian privacy laws.
- Canadian Centre for Cyber Security Guidelines - Our policy aligns with the recommendations outlined in the National Cyber Threat Assessment 2025-2026.
- Criminal Code of Canada - Research must remain within the authorized scope and comply with applicable law. This policy cannot grant immunity from prosecution.
International standards
- General Data Protection Regulation (GDPR) - Our vulnerability handling processes comply with GDPR requirements for data protection.
- ISO/IEC 29147:2018 - We follow international standards for vulnerability disclosure.
- ISO/IEC 30111:2019 - Our internal vulnerability handling processes align with these international guidelines.
Industry frameworks
- NIST Cybersecurity Framework - Our security practices are informed by the NIST framework.
- SOC 2 Standards - Our security vulnerability management processes are designed to support SOC 2 standards.
- OWASP Guidelines - We follow secure development and vulnerability management best practices recommended by OWASP.
According to the Canadian Centre for Cyber Security's 2025-2026 recommendations, organizations should "establish and maintain formal vulnerability disclosure programs to encourage responsible reporting of security vulnerabilities." This policy demonstrates our commitment to this best practice.
Acknowledgment
Tridacom IT Solutions values the contributions of security researchers who help keep our systems secure. We believe in recognizing those who have helped us improve our security posture.
How we recognize researchers
With your permission, we may acknowledge your contribution in one or more of the following ways:
- Listing your name or handle on our security acknowledgments page
- Providing a certificate of appreciation for significant discoveries
- Acknowledging your contribution in the release notes when we fix a reported vulnerability
- Offering a reference letter confirming your contribution to our security (upon request)
Your privacy is important to us. We will only publicly acknowledge your contribution with your explicit permission, and you may choose to remain anonymous or use a pseudonym.
Questions
Questions regarding this policy may be sent to security@tridacom.com. We also invite you to contact us with suggestions for improving this policy.
Additional resources
For more information about our security practices and policies, you may find these resources helpful:
Policy changes
We may update this policy from time to time. The latest version of this policy will always be available at https://tridacom.com/legal/security-policy.
When we make significant changes to this policy, we will:
- Update the "Last updated" date at the top of this page
- Place a notice on our website
- Send an email to researchers who have previously reported vulnerabilities to us (if we have their contact information)
Document change history
| Version | Date | Description |
|---|---|---|
| 1.0 | February 1, 2026 | Initial issuance of Security Vulnerability Disclosure Policy |
By submitting a vulnerability to us, you agree to comply with the latest version of this policy at the time of submission.
