Security · Last updated 2026-06-07

Security Disclosures

Vencer Group operates managed security for clients across Canada and internationally. We take vulnerability reports seriously, respond quickly, and treat researchers with respect.

01Our security posture

Eleven years without a client breach. NOC/SOC in Calgary and Singapore.

02Vulnerability disclosure

We aim to respond within five business days.

03How to report

Email security@vencergroup.com. PGP available on request. See /.well-known/security.txt.

04What to include

Steps to reproduce, affected assets, and any supporting detail.

05What you can expect from us

Acknowledgement, a status path, and respectful handling.

06Scope

In: vencergroup.com and subdomains, public infrastructure and products. Out: client-managed systems, third-party services, physical and social engineering, DoS, and spam or brute-force.

07Bug bounty

There is no paid program at this time.

08Safe harbor

Good-faith research within scope will not be pursued legally.

09Acknowledgments

No public acknowledgments at this time.

Questions?

We answer in plain English, and quickly. Email security@vencergroup.com or use general inquiries.