SnapFixx

Vulnerability Disclosure Policy

Last updated: August 2026 · Template pending legal review — not yet legal advice.

We welcome reports from security researchers. If you believe you have found a vulnerability in a SnapFixx system, we want to hear from you.

How to report

Email security@snapfixx.ca with:

What we commit to

StageOur target
Acknowledge your reportWithin 3 business days
Initial assessment and severityWithin 10 business days
Progress updatesEvery 14 days until resolved
Remediation of critical issuesAs quickly as practicable, prioritised above other work

Safe harbour

If you make a good-faith effort to comply with this policy while researching, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly. If a third party brings action against you for activity conducted under this policy, we will make it known that your actions were authorised.

Scope

In scope: snapfixx.ca and its subdomains, the SnapFixx and SnapFixx Pro mobile applications, and our public APIs.

Out of scope: findings from automated scanners without demonstrated impact, social engineering of our staff or professionals, physical attacks, denial-of-service testing, spam, and vulnerabilities in third-party services we do not control.

Please do not

Recognition

We do not currently operate a paid bug bounty. We do maintain a acknowledgements list and will credit you there if you would like, once the issue is resolved.

Privacy incidents. If your report involves personal information, we treat it as a potential privacy breach under PIPEDA and Quebec Law 25 and will follow our breach-notification obligations, which may include notifying the Office of the Privacy Commissioner of Canada and affected individuals.