Skip to content

Security vulnerability disclosure policy

Last updated: September 12, 2026

Introduction

Updated for 2026 Canadian Security Standards

Tridacom IT Solutions (“we,” “us,” “our,” “Tridacom”) is committed to ensuring the security of our users and their data. This Security Vulnerability Disclosure Policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities and to convey our preferences for submitting discovered vulnerabilities to us.

We encourage you to read this policy carefully before attempting to discover vulnerabilities or submitting reports.

Policy purpose

This policy describes:

What systems and types of research are covered under this policy
How to submit vulnerability reports to us
What information to include in your report
How long we ask security researchers to wait before publicly disclosing vulnerabilities
According to the Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026, vulnerability discovery and responsible disclosure are key components in strengthening Canada's cyber defenses.

Scope

This policy applies to the following systems and services owned, operated, or maintained by Tridacom IT Solutions:

In-scope systems:

Though we develop and maintain other internet-accessible systems or services, we ask that active research and testing only be conducted on the systems and services covered by the scope of this document. If there is a particular system not in scope that you think merits testing, please contact us at security@tridacom.com to discuss it first.

Authorization

If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized, we will work with you to understand and resolve the issue quickly, and Tridacom IT Solutions will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known.

To comply with relevant data protection regulations including the General Data Protection Regulation (GDPR) and the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), we ask that you:

  • Make every effort to avoid privacy violations and disruption to others' use of our systems
  • Immediately stop if you encounter any personally identifiable information (PII) and report this finding to us
  • Do not use vulnerabilities to access, modify, or delete data beyond what is necessary to confirm the vulnerability
  • Do not transfer, store, or process any data obtained during your research outside of the communication with our security team

Guidelines

Under this policy, "research" means activities in which you:

Acceptable testing activities

  • Notify us as soon as possible after you discover a real or potential security issue
  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data
  • Only use exploits to the extent necessary to confirm a vulnerability's presence
  • Provide us a reasonable amount of time to resolve the issue before you disclose it publicly
  • Perform testing only on in-scope systems, and respect systems and activities which are out-of-scope

Important notice

Once you've established that a vulnerability exists or encounter any sensitive data (including personally identifiable information, financial information, or proprietary information or trade secrets of any party), you must stop your test, notify us immediately, and not disclose this data to anyone else.

Reporting a vulnerability

We accept vulnerability reports through the following channels:

Email submission

For standard vulnerability reports

Send your reports to security@tridacom.com

For a report containing sensitive details, contact security@tridacom.com first to arrange a suitable way to share it.

What we need in your report

To help us triage and prioritize submissions, we recommend that your reports include:

  • Vulnerability description - Describe the location the vulnerability was discovered and the potential impact of exploitation
  • Reproduction steps - Detailed description of the steps needed to reproduce the vulnerability (proof of concept scripts or screenshots are helpful)
  • Impact - Your assessment of the severity and potential impact of the vulnerability
  • Suggested mitigation - If possible, include suggestions for how to fix or mitigate the vulnerability
  • Contact information (optional) - We accept anonymous reports, but including your contact information helps us collaborate with you if we need additional information

Disclosure timeline

We follow industry standard practices for vulnerability disclosure timelines:

1-2 business days: Initial acknowledgment of your report
7-10 business days: Preliminary assessment and validation of the vulnerability
30-90 days: Time for us to develop and deploy a fix, depending on complexity
Public disclosure: We ask that you wait at least 90 days from the time of your initial report before publicly disclosing any information about the vulnerability

Our expectations

When you choose to share your contact information with us, we commit to the following:

Timely acknowledgment

We will acknowledge receipt of your vulnerability report within 1-2 business days and provide you with a reference number for tracking.

Transparent communication

To the best of our ability, we will confirm the existence of the vulnerability and be transparent about the steps we are taking during the remediation process, including issues or challenges that may delay resolution.

Open dialogue

We will maintain an open dialogue with you to discuss issues and keep you informed about our progress addressing the vulnerability.

Privacy and confidentiality

We will protect your personal information and keep your identity confidential unless you permit us to identify you.

Information sharing

Information submitted under this policy will be used for defensive purposes only – to mitigate or remediate vulnerabilities. If your findings include newly discovered vulnerabilities that affect all users of a product or service and not solely Tridacom, we may share your report with the Canadian Centre for Cyber Security or affected vendors, where it will be handled under their coordinated vulnerability disclosure process. We will not share your name or contact information without express permission.

Researcher protection

Tridacom IT Solutions is committed to protecting security researchers who make good faith efforts to comply with this policy. We recognize the valuable role that the security research community plays in helping us maintain the security of our systems.

Our commitment to researchers

  • No legal action - We will not pursue or recommend legal action against researchers who act in good faith and comply with this policy
  • Support against claims - If a third party initiates legal action against you for activities consistent with this policy, we will make clear that your actions were authorized
  • Public recognition (optional) - With your permission, we may publicly acknowledge your contribution to our security
  • Responsible handling - We will handle vulnerability reports with appropriate care and attention to ensure your research does not increase risk
  • Clear guidance - We provide clear scope and guidelines to help you conduct research safely and legally

Safe harbor

When conducting vulnerability research according to this policy, we consider this research to be:

  • Authorized by Tridacom within the scope of this policy for systems we own or control. This authorization does not bind third parties or guarantee protection from criminal prosecution.
  • Exempted from restrictions in our applicable Terms of Service and/or Acceptable Use Policy that would interfere with conducting security research
  • Allowed under the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls
  • Exempt from restrictions in our Terms & Conditions that would prohibit you from reporting security vulnerabilities

Regulatory compliance

Tridacom IT Solutions prioritizes compliance with applicable laws and industry standards for handling security vulnerabilities. This policy has been developed to align with:

Canadian standards and requirements

  • Personal Information Protection and Electronic Documents Act (PIPEDA) - We ensure all vulnerability research adheres to Canadian privacy laws.
  • Canadian Centre for Cyber Security Guidelines - Our policy aligns with the recommendations outlined in the National Cyber Threat Assessment 2025-2026.
  • Criminal Code of Canada - Research must remain within the authorized scope and comply with applicable law. This policy cannot grant immunity from prosecution.

International standards

  • General Data Protection Regulation (GDPR) - Our vulnerability handling processes comply with GDPR requirements for data protection.
  • ISO/IEC 29147:2018 - We follow international standards for vulnerability disclosure.
  • ISO/IEC 30111:2019 - Our internal vulnerability handling processes align with these international guidelines.

Industry frameworks

  • NIST Cybersecurity Framework - Our security practices are informed by the NIST framework.
  • SOC 2 Standards - Our security vulnerability management processes are designed to support SOC 2 standards.
  • OWASP Guidelines - We follow secure development and vulnerability management best practices recommended by OWASP.

According to the Canadian Centre for Cyber Security's 2025-2026 recommendations, organizations should "establish and maintain formal vulnerability disclosure programs to encourage responsible reporting of security vulnerabilities." This policy demonstrates our commitment to this best practice.

Acknowledgment

Tridacom IT Solutions values the contributions of security researchers who help keep our systems secure. We believe in recognizing those who have helped us improve our security posture.

How we recognize researchers

With your permission, we may acknowledge your contribution in one or more of the following ways:

  • Listing your name or handle on our security acknowledgments page
  • Providing a certificate of appreciation for significant discoveries
  • Acknowledging your contribution in the release notes when we fix a reported vulnerability
  • Offering a reference letter confirming your contribution to our security (upon request)

Your privacy is important to us. We will only publicly acknowledge your contribution with your explicit permission, and you may choose to remain anonymous or use a pseudonym.

Questions

Questions regarding this policy may be sent to security@tridacom.com. We also invite you to contact us with suggestions for improving this policy.

Additional resources

For more information about our security practices and policies, you may find these resources helpful:

Policy changes

We may update this policy from time to time. The latest version of this policy will always be available at https://tridacom.com/legal/security-policy.

When we make significant changes to this policy, we will:

  • Update the "Last updated" date at the top of this page
  • Place a notice on our website
  • Send an email to researchers who have previously reported vulnerabilities to us (if we have their contact information)

Document change history

VersionDateDescription
1.0February 1, 2026Initial issuance of Security Vulnerability Disclosure Policy

By submitting a vulnerability to us, you agree to comply with the latest version of this policy at the time of submission.