Effective date: July 23, 2026 · SparkSolutions, Mississauga, Ontario, Canada
1. Our security practices
Core practices applied across SparkSolutions systems include:
- Encryption of data in transit (TLS) across all public endpoints
- Least-privilege access control and role separation on internal systems
- Dependency and vulnerability management as part of the engineering pipeline
- Audit logging on systems that handle business or personal data
- Security review as a required gate before production deployment
2. Client data
Client data handled during engagements is governed by contractual confidentiality obligations and our internal Security & Data Handling Standard. Access is limited to team members working on the engagement, and data is returned or destroyed at engagement close per the applicable agreement.
3. Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in a SparkSolutions website or product, please email ignite@sparksol.ca with the subject line "Security Disclosure", including steps to reproduce. We commit to acknowledging reports within two business days, keeping you informed of remediation progress, and not pursuing legal action against good-faith research that avoids privacy violations, data destruction, and service disruption.
Questions about this policy may be directed to ignite@sparksol.ca.