Everything, in One Place.
Security, privacy, compliance, and legal — the documents a procurement or security team needs before working with us, all in one place.
Security & Compliance
Where we stand — encryption, human oversight, subprocessors, and the standards we're working toward.
ReadPrivacy Policy
What we collect, why, and the choices you have. Built on PIPEDA and Alberta PIPA.
ReadData Processing Agreement
How we process your data as your processor — available to sign for any engagement.
ReadSubprocessors
The third parties that help us deliver the service, with purpose and region.
ReadMessaging (SMS) Terms
Consent, message types, frequency, rates, and how to opt out of texts.
ReadAcceptable Use Policy
The rules for using our sites, products, and AI features safely and legally.
ReadCookies & Tracking
Essential cookies plus privacy-friendly, cookieless analytics — no advertising or cross-site tracking.
ReadAccessibility
Our commitment to WCAG 2.1 AA and how to request an accommodation.
ReadTerms of Service
The terms that govern use of our site and services.
ReadAI Ethics
The principles behind how we build and deploy AI responsibly.
ReadThe Questions We Settle in Writing.
These get answered for your project specifically and written into the scope agreement, because the honest answer differs by build. We would rather set them out as questions than publish a blanket promise that would not hold for every engagement.
Where is it hosted, and where does the data sit?
Named per project, along with the region. Our standing infrastructure and the region of every subprocessor we use are listed on the Security & Compliance page; your build's specific hosting is agreed in the scope rather than assumed from that list.
Who can see and do what?
Role-based access with least privilege is how we build — office, field and management each get the view they need. Which roles exist, and what each one can read and change, is decided with you during discovery and written down.
What does any AI feature actually process?
Which data a feature sends to a model, which provider handles it, and what a person reviews before anything reaches a customer or a ledger. We do not train models on your data. Where AI drafts something with a real cost of being wrong, a human approves it.
What are the backups, and what does restoring look like?
Backup frequency, retention and the restore procedure are set per project against what the business can actually tolerate losing. We would rather agree that explicitly than leave you to discover it during an incident.
Who owns the system and the data in it?
You do. The software is built for your business, and the data in it is yours and exportable on request. Export format and how you get it are part of the agreement, not a favour asked later.
What happens if we stop working together?
Agreed up front: what you keep, how the data comes out, and what handover involves. A build you own is not much use if leaving is undefined.
What does support actually cover once it is live?
What we monitor, what counts as a fix versus a change, and what response you can expect — set out in the operating arrangement. We operate what we ship rather than handing over a repository.
Will you sign our DPA or complete our security questionnaire?
Yes. A Data Processing Agreement is available for any engagement, and we complete vendor-security questionnaires. Send yours and we will answer it straight, including the parts where the honest answer is that we do not hold a given certification.
We do not claim certifications we do not hold. SOC 2 Type II and ISO/IEC 42001 are standards we are working toward, and they are described that way on the Security & Compliance page, which also lists every subprocessor we use and the region it operates in.
Questions to Ask Any Software Vendor.Including Us.
Custom software can quietly become a dependency rather than an asset: you own something only one firm can maintain, and the ownership is nominal. These are the questions that expose it. Put them to us, and put them to whoever else you are talking to — a vendor who gets uncomfortable here is telling you something.
Do we get the source code?
Ask before you sign, and get the answer in writing. Our position is that the software is built for your business and what happens to the code is settled in the scope agreement rather than left vague — but do not take that, or any vendor's marketing page, as the commitment. The commitment is the clause in the agreement you sign.
Could another developer maintain this without you?
This is the question that separates an asset from a dependency, and it is worth asking us directly. A build that only its author can maintain is a liability no matter what the brochure calls it. Ask what would be handed over, in what form, and whether the agreement permits a third party to work on it.
Where does it run, and could it run somewhere else?
The platforms we build on and the region each operates in are listed on the Security & Compliance page. Whether a given build is deployed into infrastructure you control is a scoping decision — ask for it explicitly if portability matters to you, because it changes how a system is built, not just where it is hosted.
Has it been independently penetration tested?
We do not publish a penetration test report. If that is a requirement for your engagement, raise it early — it is a reasonable thing to ask for and a reasonable thing to scope and pay for, and we would rather tell you that plainly than let you assume one exists.
Nothing above is a contractual commitment — a marketing page is not the place to make one, and you should not accept one from any vendor on that basis. What is written here is how we will answer when you ask, and what ends up in your agreement is what actually binds.
Systems Running in Production.
The most useful trust signal we have is software that has been in daily use by real businesses. Every figure below is reported by the business running the system, not independently audited.
4 hrs → 20 min
Zebra Landscaping · live in production
Read it2–3 hrs → minutes
A demolition contractor · live in production
Read itFive systems → one
Kilt Contracting · live in production
Read it“We were scaling and needed real systems behind it. AltaPro AI built us our own platform from scratch — jobs, crews, clients, map view, syncs to our books. Didn't have to explain how the trades work, they already knew it. Built fast, changes handled same way. Does exactly what we needed.”
“Great experience working with AltaPro AI. Haruun and his team were easy to work with, responsive, and really took the time to understand what we needed. Everything was handled professionally and we're really happy with how it turned out. Would definitely recommend them.”
“Helpful, Professional & Provide Great Service.”
Quotes are published as written by the reviewer and attributed to the client company. We publish no star ratings, review counts or aggregate-rating markup anywhere on this site.
For procurement & security teams
Need a DPA or a Security Review?
Send us your vendor-security questionnaire, request a Data Processing Agreement, or ask anything about how we handle data. We answer straight.
