App Intelligence Trust Center

Security Vulnerability Reporting

Responsible Disclosure

How to report a potential vulnerability responsibly and safely.

Effective: August 5, 2026 App Intelligence British Columbia, Canada
Plain-language policy

This page is intended to make App Intelligence practices understandable. Project-specific contracts and legal requirements may add to or replace parts of this policy.

1. Reporting a Concern

We appreciate good-faith reports that help protect App Intelligence systems and users. Send a concise report to appintelligence.ca@gmail.com with the subject line “Security Disclosure.”

Include the affected URL or system, a description of the issue, reproducible steps, expected and observed behaviour, potential impact, and any supporting screenshots or logs that do not expose unnecessary personal or confidential information.

2. Good-Faith Research

Limit testing to systems you reasonably believe are controlled by App Intelligence and avoid actions that could harm users, damage data, interrupt service, create cost, reduce availability, or violate privacy.

Do not use social engineering, denial-of-service techniques, physical attacks, destructive testing, credential stuffing, spam, malware, extortion, or access to data beyond the minimum necessary to demonstrate the issue.

3. Protecting Information

Stop testing and notify us promptly if you encounter personal information, credentials, confidential client information, or data that does not belong to you.

Do not copy, retain, alter, download, transmit, or publicly disclose such information except for the minimum evidence required in the private report.

4. What to Expect

We will make a reasonable effort to acknowledge a credible report, investigate the concern, request clarification when needed, and communicate when appropriate.

Response and remediation time will depend on severity, complexity, ownership of the affected system, third-party involvement, and available resources. This policy does not create a promise of payment, employment, reward, or a specific response deadline.

5. Public Disclosure

Give us a reasonable opportunity to investigate and address the issue before any public disclosure. Coordinate disclosure timing with us and avoid publishing information that could enable abuse or expose users.

6. Scope Limitations

This page does not authorize testing of client-controlled systems, third-party services, production accounts, vendor infrastructure, or systems that App Intelligence does not own or operate.

When a concern affects a third party, report it to the appropriate owner.

7. Safe-Harbour Limitation

App Intelligence intends to respond constructively to good-faith research that follows this policy. However, this page is not legal advice, does not bind third parties, and does not authorize conduct that violates applicable law or another party’s rights.

Questions

Contact App Intelligence

Contact us about this policy at appintelligence.ca@gmail.com.

Open Contact Page