01Our security posture
Eleven years without a client breach. NOC/SOC in Calgary and Singapore.
02Vulnerability disclosure
We aim to respond within five business days.
03How to report
Email security@vencergroup.com. PGP available on request. See /.well-known/security.txt.
04What to include
Steps to reproduce, affected assets, and any supporting detail.
05What you can expect from us
Acknowledgement, a status path, and respectful handling.
06Scope
In: vencergroup.com and subdomains, public infrastructure and products. Out: client-managed systems, third-party services, physical and social engineering, DoS, and spam or brute-force.
07Bug bounty
There is no paid program at this time.
08Safe harbor
Good-faith research within scope will not be pursued legally.
09Acknowledgments
No public acknowledgments at this time.
Questions?
We answer in plain English, and quickly. Email security@vencergroup.com or use general inquiries.