This page is intended to make App Intelligence practices understandable. Project-specific contracts and legal requirements may add to or replace parts of this policy.
1. Security Approach
App Intelligence applies security measures according to the context, sensitivity, architecture, users, and risk of a system. Security is considered throughout discovery, design, implementation, deployment, monitoring, and maintenance.
No organization can guarantee that a system will never experience a vulnerability, outage, or unauthorized event.
2. Engineering Practices
Depending on the engagement, practices may include least-privilege access, environment separation, secure configuration, secrets management, input validation, authentication and authorization controls, dependency review, transport encryption, logging, backups, monitoring, rate limiting, and security-focused testing.
3. Access and Credentials
Credentials, API keys, tokens, and administrative access should be shared through appropriate secure methods and limited to authorized people. Clients remain responsible for access they control and for promptly removing access that is no longer required.
4. Data Protection
We aim to minimize sensitive data, restrict access, and use safeguards appropriate to the information and system. Specific encryption, backup, residency, retention, recovery, and compliance requirements must be identified and agreed upon for each project.
5. Dependencies and Third Parties
Modern software depends on libraries, cloud providers, APIs, hosting services, repositories, and other third parties. We may review and update dependencies where included in scope, but cannot guarantee the security or continuous availability of third-party services.
6. Monitoring and Incident Response
Where included in the service scope, systems may use health checks, logs, telemetry, alerts, incident records, backups, and recovery procedures. The monitoring and response commitments for a client system should be defined in the applicable agreement or operating plan.
7. Client Responsibilities
Clients are responsible for identifying regulatory, contractual, industry, data-classification, insurance, residency, and internal security requirements before delivery. Clients must also manage their users, credentials, devices, internal networks, and authorized administrators.
8. Reporting a Vulnerability
Potential vulnerabilities affecting appintelligence.ca or an App Intelligence-controlled system should be reported through our Responsible Disclosure page. Do not publicly disclose an unresolved issue or access data beyond what is necessary to demonstrate the concern.
9. Contact
General security questions may be sent to appintelligence.ca@gmail.com.
Questions
Contact App Intelligence
Contact us about this policy at appintelligence.ca@gmail.com.
Open Contact PageThese materials are general business information and are not a substitute for legal advice. App Intelligence should obtain professional legal review before relying on them for a specific contract, regulated service, or compliance obligation.