StackTrue works inside client cages and racks. Security is part of the service, not an add-on. This page explains how we handle data and how to report a potential issue.
Email info@stacktrue.ca with the subject line “Security Report”. Include the affected URL or system, reproduction steps, and any supporting output. We acknowledge reports within two business days.
Please do not run automated scans that degrade service, access data that is not yours, or attempt social engineering against our staff or clients. We do not currently run a paid bug bounty, but we credit researchers who report responsibly.
Client-owned infrastructure we service is out of scope — report those issues to the asset owner.
We regularly receive vague messages claiming to have found errors on our site, usually from free mail accounts, offering to send screenshots. These are almost always phishing or lead-generation attempts. A legitimate report includes specifics — a URL, a step, an output — as described above.
We can provide insurance details, technician background information, and NDA templates during procurement.
Contact us →