Responsible disclosure
Security Contact
Last reviewed August 9, 2026
Report potential vulnerabilities to security@teravanceintelligence.ca. Do not use the sales inquiry form for security reports.
What to include
- The affected hostname, page, endpoint, or feature.
- A clear description of the observed behaviour and security impact.
- Minimal reproduction steps, dates, and relevant non-sensitive evidence.
- A safe way to contact you if you want a response.
Please avoid
- Accessing, downloading, modifying, or retaining information that is not yours.
- Disrupting service, testing availability limits, sending spam, or using denial-of-service techniques.
- Social engineering, physical intrusion, credential attacks, malware, or automated scans that create excessive traffic.
- Publishing the issue before we have had a reasonable opportunity to investigate and reduce risk.
What you can expect
We aim to acknowledge a credible report within two business days, assess severity, preserve evidence, and provide periodic updates when practical. Timelines for a repair depend on risk and complexity. We do not currently offer a bug bounty or promise payment.
Sensitive reports
Ordinary email is not appropriate for secrets, credentials, customer records, or exploit data that could cause harm. Begin with a minimal description and ask us to arrange a protected exchange method.
Immediate safety
If you believe an account is actively compromised, stop using the affected session and contact the designated support route. This page is not an emergency service.