Trust & Security

How we protect your systems and data.

Security is what we do for clients, and we hold ourselves to the same standard. This page explains our practices and how to report a security concern.

Our security practices

Every client environment we manage, and our own, follows the same baseline controls.

  • Multi-factor authentication on all administrative and remote access
  • Least-privilege access: people and tools get only the access their task requires
  • Encrypted backups, in transit and at rest, with regular restore testing
  • Scheduled patching of operating systems, applications and network devices
  • Endpoint protection and continuous monitoring with alerting
  • Documented incident response and business continuity procedures
  • Confidentiality commitments for everyone with access to client systems

Privacy

We collect only the personal information needed to respond to enquiries and deliver our services, and we handle it in line with Canada's PIPEDA and Quebec's Law 25. Read our privacy policy.

Report a security concern

If you believe you've found a vulnerability in a Hanatech system or website, email security-reports@hanatechinc.com.

  • Describe the issue and the steps to reproduce it
  • Include the affected address or system
  • Give us reasonable time to fix it before sharing it publicly
  • Don't access, change or delete data that isn't yours

We aim to acknowledge reports within three business days. Our machine-readable contact file is at /.well-known/security.txt.

Technology partners

Bell, Cisco, Dell and Microsoft.