App Intelligence Trust Center

Secure and Observable Engineering

Security Policy

The security principles that guide App Intelligence website and software work.

Effective: August 5, 2026 App Intelligence British Columbia, Canada
Plain-language policy

This page is intended to make App Intelligence practices understandable. Project-specific contracts and legal requirements may add to or replace parts of this policy.

1. Security Approach

App Intelligence applies security measures according to the context, sensitivity, architecture, users, and risk of a system. Security is considered throughout discovery, design, implementation, deployment, monitoring, and maintenance.

No organization can guarantee that a system will never experience a vulnerability, outage, or unauthorized event.

2. Engineering Practices

Depending on the engagement, practices may include least-privilege access, environment separation, secure configuration, secrets management, input validation, authentication and authorization controls, dependency review, transport encryption, logging, backups, monitoring, rate limiting, and security-focused testing.

3. Access and Credentials

Credentials, API keys, tokens, and administrative access should be shared through appropriate secure methods and limited to authorized people. Clients remain responsible for access they control and for promptly removing access that is no longer required.

4. Data Protection

We aim to minimize sensitive data, restrict access, and use safeguards appropriate to the information and system. Specific encryption, backup, residency, retention, recovery, and compliance requirements must be identified and agreed upon for each project.

5. Dependencies and Third Parties

Modern software depends on libraries, cloud providers, APIs, hosting services, repositories, and other third parties. We may review and update dependencies where included in scope, but cannot guarantee the security or continuous availability of third-party services.

6. Monitoring and Incident Response

Where included in the service scope, systems may use health checks, logs, telemetry, alerts, incident records, backups, and recovery procedures. The monitoring and response commitments for a client system should be defined in the applicable agreement or operating plan.

7. Client Responsibilities

Clients are responsible for identifying regulatory, contractual, industry, data-classification, insurance, residency, and internal security requirements before delivery. Clients must also manage their users, credentials, devices, internal networks, and authorized administrators.

8. Reporting a Vulnerability

Potential vulnerabilities affecting appintelligence.ca or an App Intelligence-controlled system should be reported through our Responsible Disclosure page. Do not publicly disclose an unresolved issue or access data beyond what is necessary to demonstrate the concern.

9. Contact

General security questions may be sent to appintelligence.ca@gmail.com.

Questions

Contact App Intelligence

Contact us about this policy at appintelligence.ca@gmail.com.

Open Contact Page