Beware of scam messages claiming to be from Altis recruiters. We never ask for payments or sensitive information. Verify emails come from an official @altis.com address. Click here for scam tips.

Altis logo

Find Work

Hire

Company
About Us

The story, values, and people behind Altis.

Join Our Team

Build meaningful work with a team that cares.

Community

Making a positive impact beyond the workplace.

Diversity

Building an inclusive workplace and workforce.

Differentiators

Discover the Altis difference.

Altis in The News

Stories, recognition, and updates from Altis.

Three person talking in office
Specialities

Our Specialties

TechnologyProfessional ServicesFinance & AccountingAdministrative & SupportFederal Government

View All

Our Industries

Retail, Manufacturing and Logistics
Financial Services
Non-Profit & Associations
Healthcare
Broader Public Sector

View All

Our Skillsets

Audit, Risk & Compliance
Artificial Intelligence (AI)
Project Management
Cybersecurity
Marketing & Communications

View All

Our Services

Contract HiringPermanent HiringHigh-volume Hiring

Testing & Validation

Payroll Services
Learn

Blogs

AI
Company News
Newest
Lifestyle
For Job Seekers
For Employers
Diversity

Interview Guides

HR ProfessionalsHelp Desk TechniciansAdministrative SupportInternal Auditors and Risk AdvisorsLegal Assistants and Clerks

View All

Altis Case Studies

From Uncertain Interviews to Confident Hiring Decisions
From Competitive Search to Long-Term Partnership
Helping a Non-Profit Secure a Senior Finance Hire in a Competitive Market
Helping an International Boarding School Find the Right Student Residence Manager
Filling a Critical Property Management Role in Under 12 Days

View All

Employer Reports & Webinars

Reports & Webinars
How to resign from a job professionally

For Job Seekers

How to resign from a job professionally

Read More

Contact

Login

en
fr

Login

Vulnerability Disclosure Policy

Effective Date: September 30, 2026

Our Approach

Protecting our systems and the information entrusted to Altis is a responsibility we take seriously. If you become aware of a potential security vulnerability or other security concern involving Altis, we want to hear from you.

This Vulnerability Disclosure Policy provides a clear way to report potential security issues so our team can review them and take appropriate action. It is intended to support responsible reporting and does not provide authorization to test, access or attempt to compromise Altis systems.

What to Report

This policy applies to systems owned, operated or managed by Altis. Reports involving third-party platforms, services or systems may be referred to the appropriate provider or handled in coordination with that provider where appropriate.

Examples of issues to report include:

  • A potential vulnerability that could allow unauthorized access to an Altis website, system or account
  • An issue that could expose, alter or compromise information without authorization
  • A security weakness involving authentication or access controls
  • Unexpected system behaviour that you believe could create a security risk
  • Another potential technology security issue that could affect Altis systems or the information they process

You don't need to determine whether an issue is a confirmed vulnerability before reporting it. If you're unsure, you can still let us know and our team will review it.

Please do not attempt to investigate a potential issue beyond what you encountered or observed.

Vulnerability Research

We recognize that security professionals and researchers can play an important role in identifying potential vulnerabilities.

If you identify a potential vulnerability involving Altis, we encourage you to report it through the process below. This policy does not authorize security testing or provide permission to access Altis systems, accounts or information beyond what is otherwise publicly available or authorized.

If you're unsure whether a particular activity is permitted, please contact us before proceeding.

How to Report a Security Issue

If you believe you've identified a potential security vulnerability or security concern involving Altis, please submit it through our Reporting a Concern form and select Security or Vulnerability Concern.

To help us understand and investigate the issue, please include:

  • A clear description of what you observed
  • The affected Altis website, system or URL, if known
  • Any steps that may help us understand or reproduce the issue
  • Relevant supporting information, such as screenshots or technical details
  • Your contact information so we can follow up if clarification is needed

Please don't include passwords, credentials, personal information, customer information or other sensitive data in your submission.

If a reported vulnerability involves or may have resulted in the unauthorized access, use, disclosure, loss or compromise of personal information, the report will also be managed in accordance with Altis's privacy incident response procedures and referred to the Privacy Office, as appropriate.

What You Can Expect From Us

When we receive a security report, we'll review the information provided and determine the appropriate next steps.

You can expect us to:

  • Acknowledge your report within three business days ‍
  • Review and investigate the reported concern ‍
  • Contact you if needed for additional information or clarification ‍
  • Take appropriate action based on our findings

The time required to investigate and address an issue will depend on its nature and complexity. Where appropriate, we'll keep you informed as the issue is reviewed.

High-risk or urgent reports may be escalated internally to the appropriate technical, security, privacy or leadership teams, depending on the nature of the concern. Reports involving or potentially affecting personal information may also be referred to the Privacy Officer in accordance with Altis' privacy incident response procedures.

While we strive to provide timely updates, we may not be able to share detailed information about our investigation, remediation activities or security controls where doing so could create security, confidentiality or privacy risks.

Responsible Reporting

We ask that anyone reporting a potential security issue acts responsibly and avoids taking actions that could put people, information or systems at risk.

Please do not:

  • Attempt to access, modify, download or delete information that doesn't belong to you
  • Attempt to gain unauthorized access to Altis systems or accounts
  • Conduct physical security testing of Altis offices or infrastructure
  • Use social engineering techniques, including phishing, against Altis employees, candidates or customers
  • Conduct Denial-of-Service (DoS) testing or otherwise disrupt Altis systems or services
  • Use automated scanning or probing of Altis systems without prior authorization

If you encounter personal, customer or other sensitive information, please stop and report the issue without copying, downloading or sharing that information.

Please do not publicly disclose the issue or share details with others until Altis has had a reasonable opportunity to review and address the concern, unless disclosure is required by law.

Questions or Security Concerns

If you're unsure whether something should be reported, we'd rather you let us know.

Please use our Reporting a Concern form to submit a potential security issue.

Changes to This Policy

We may update this policy as our systems, security practices or reporting processes evolve.

‍

Your next step starts here.

Discover new opportunities and take the next step toward your future with confidence.

Hire Talent

Find Your Next Job

Recruiting

Find work
Hire
Specializations

Resources

Learn
Candidate FAQs
Client FAQs

Company

About
Diversity
Join the Team
Contact

Follow Us

Facebook
Linkedln
YouTube
Instagram

© 2026 Altis. All rights reserved.

Privacy PolicyAccessibility PolicyCookie & Tracking Technologies Policy