AltaCom — Managed IT Services Calgary
Security

Security Policy & Responsible Disclosure

AltaCom takes the security of our systems and client data seriously. If you believe you have found a security issue in one of our services, please let us know — we will work with you to resolve it quickly.

Last updated: May 2026 · Contact: security.reporting@altacom.ca

Reporting a Vulnerability

If you discover a security vulnerability in any AltaCom system, website, or service, we ask that you report it to us responsibly before public disclosure.

Email your report to security.reporting@altacom.ca with a clear description of the issue, steps to reproduce it, and any relevant screenshots or proof-of-concept code. We treat all reports as confidential.

Our Response Commitment

We will acknowledge receipt of your report within 2 business days.

We aim to provide an initial assessment within 5 business days and to resolve confirmed vulnerabilities within 30 days, depending on severity. We will keep you informed throughout the process.

What We Ask of Researchers

Act in good faith. Do not access, modify, or delete data that does not belong to you. Do not perform denial-of-service attacks, spam, or social engineering against our staff or clients.

Give us reasonable time to respond before any public disclosure. We appreciate coordinated disclosure and will work with you to ensure issues are addressed before details become public.

Recognition

We do not currently operate a paid bug bounty programme. However, we genuinely appreciate responsible researchers who help us improve our security posture.

With your permission, we are happy to acknowledge your contribution publicly once the issue has been resolved.

Scope

In scope: www.altacom.ca and any subdomain operated by AltaCom, the Payload CMS admin interface, and any public-facing API endpoints.

Out of scope: third-party services we use (Microsoft 365, Azure, DigitalOcean), social engineering attacks, physical security, and issues already known to us.

Legal Safe Harbour

AltaCom will not pursue legal action against researchers who discover and report security vulnerabilities in good faith, in accordance with this policy.

We consider responsible security research to be a valuable contribution to the security community and to our clients.

Found something? Let us know.

Send vulnerability reports to security.reporting@altacom.ca

PGP key available on request.

Get a Free IT Audit →