Skip to main content
SparkSolutions

Legal

Security & Disclosure

Security is an architectural property of everything SparkSolutions builds — including this website and the platforms we deliver for clients. We also welcome the security research community's help in keeping them safe.

Effective date: July 24, 2026 · SparkSolutions, Mississauga, Ontario, Canada

1. Our security practices

Core practices applied across SparkSolutions systems include:

  • Encryption of data in transit (TLS) across all public endpoints
  • Least-privilege access control and role separation on internal systems
  • Dependency and vulnerability management as part of the engineering pipeline
  • Audit logging on systems that handle business or personal data
  • Security review as a required gate before production deployment

2. Client data

Client data handled during engagements is governed by contractual confidentiality obligations and our internal Security & Data Handling Standard. Access is limited to team members working on the engagement, and data is returned or destroyed at engagement close per the applicable agreement.

3. Reporting a vulnerability

If you believe you have found a security vulnerability in a SparkSolutions website or product, please email ignite@sparksol.ca with the subject line "Security Disclosure". To help us respond quickly, please include:

  • A clear description of the issue and its potential impact
  • The affected URL, product, or component
  • Step-by-step instructions to reproduce it, and any proof-of-concept
  • Your name or handle if you would like to be credited

4. Our commitment to researchers

We commit to acknowledging your report within two business days, keeping you informed of remediation progress, and not pursuing legal action against good-faith research that follows this policy. We ask that you give us a reasonable opportunity to fix an issue before disclosing it publicly.

5. Scope and ground rules

Good-faith testing must avoid privacy violations, data destruction, service disruption, and any access to data that is not your own. Please do not run automated scans that degrade service, attempt social engineering of our staff or clients, or access, modify, or delete other people's data. If you are unsure whether something is in scope, ask us first.

6. Recognition

We are grateful to the researchers who help keep SparkSolutions and our clients secure. With your permission, we are happy to credit you for valid reports. As a young company we do not yet run a paid bounty program, but we recognize and thank every researcher who reports responsibly.

Questions about this policy may be directed to ignite@sparksol.ca.