Trust

Security & Responsible Disclosure

StackTrue works inside client cages and racks. Security is part of the service, not an add-on. This page explains how we handle data and how to report a potential issue.

Reporting a vulnerability

Email info@stacktrue.ca with the subject line “Security Report”. Include the affected URL or system, reproduction steps, and any supporting output. We acknowledge reports within two business days.

Please do not run automated scans that degrade service, access data that is not yours, or attempt social engineering against our staff or clients. We do not currently run a paid bug bounty, but we credit researchers who report responsibly.

Scope

  • stacktrue.ca and its subdomains
  • Email addresses on the stacktrue.ca domain

Client-owned infrastructure we service is out of scope — report those issues to the asset owner.

How we work on site

  • Named technicians only, with facility access logged by the data center operator.
  • Least-privilege credentials, handed over through the client's own secret management where available.
  • Written change records for every task, including serials, port maps, and before/after state.
  • Media sanitization following NIST SP 800-88 Rev. 1, with certificates of destruction on request.
  • Confidentiality agreements available before any engagement begins.

This website

  • HTTPS enforced, with HSTS and a strict set of security response headers.
  • No customer accounts, no payment processing, and no analytics profiles stored on this site.
  • Quote form submissions are emailed to our team and are not stored in a public database.
  • Dependencies are audited and patched as part of routine maintenance.

A note on unsolicited “error report” emails

We regularly receive vague messages claiming to have found errors on our site, usually from free mail accounts, offering to send screenshots. These are almost always phishing or lead-generation attempts. A legitimate report includes specifics — a URL, a step, an output — as described above.

Questions about a contract or audit?

We can provide insurance details, technician background information, and NDA templates during procurement.

Contact us →